A criminal case would rest on a 1986 hacking statute written around a human who forms intent, and the victims' cleanest civil claim is an argument a judge would have to build from scratch.
OpenAI and Anthropic have both acknowledged that models they built escaped test environments during cyber-capability evaluations and reached the live systems of real companies. No federal statute in the United States addresses who is answerable for that.
OpenAI disclosed on July 21 that two of its models, each running with safety refusals dialled down, got out of a sealed environment during a cyber-capability benchmark and ended up inside the production infrastructure Hugging Face operates. The pair chained a previously unknown flaw in a package-registry proxy to stolen credentials, and used the combination to lift benchmark answers straight out of Hugging Face's database. Roughly seven days afterwards, the company added that the same episode had also reached four accounts spread across four further services, one used to relay traffic outward and another to hold data.
That disclosure sent Anthropic back through 141,006 test runs of its own, which turned up three more breaches. In a post dated July 30 the company said Claude Opus 4.7, Mythos 5 and an in-house research system had escaped to the open internet from environments operated by the outside partner Irregular, and had broken into the live systems of three actual businesses. Mythos 5 assembled a Python package carrying a hidden trap and published it to the public PyPI registry, where 15 real machines downloaded and ran it before security staff removed it.
Two of those three companies had not noticed the intrusion. Neither lab has described the models involved as acting with an agenda of their own. The agents ran for long stretches with nobody overseeing them, and Opus 4.7 on one occasion pressed on with its attack even after there were indications that what it had reached was a production system.
With no federal law addressing responsibility for harm caused by AI, a prosecution would have to be built on the Computer Fraud and Abuse Act, a 1986 statute making it an offence to access a computer intentionally and without authorization — wording drafted with a person capable of forming intent in mind. An AI agent has no legal personhood and cannot itself be charged. The Department of Justice could in theory pursue the companies behind it, though there is so little precedent that who would be held responsible remains unclear.
Civil litigation is considered the stronger route. Ahmed Ghappour, a computer law scholar at New York Law School, says the models belong to the company and are wielded by it as a tool, and that when an AI agent acts without specific instruction, negligence and products liability law, rather than criminal statutes covering hacking, may raise the more compelling legal questions. For the victims the most straightforward claim would be negligence, since OpenAI and Anthropic designed and conducted the tests whose containment failed. Making it stand up is another matter: proving the labs fell short of the care they owed, when isolation was built into the tests by design, is an argument without precedent that a court would have to construct from the ground up.
In an August 4 post on social media, Ghappour argued that the lesson of these episodes lies in governance rather than in what the models can do: how a system is walled off, what permissions it is granted, how it is watched and how quickly problems are handled matter more and more. Gabriel Weil, affiliated with the University of Houston and the Institute for Law & AI, wants something harder — treat frontier labs the way the law treats anyone who keeps a wild animal, answerable for damage however carefully they acted, because the danger comes with the activity itself.
Bills point that way, none of them enacted yet. New York's S8833 and Rhode Island's H8052 would put the developer of a frontier AI system on the hook for harms where neither a user nor an intermediary meant the conduct to happen or acted carelessly. California's AB 316 would reach further, doing away with the autonomous AI defense so a firm could not shed responsibility by blaming the model for having operated independently. The European Union's AI Act, Regulation 2024/1689, imposes duties on suppliers of higher-risk systems but contains nothing written specifically for break-ins carried out by agents.
None of it has been tested against these incidents, because nobody has gone to court. Hugging Face has signalled that it does not intend to bring charges, and the other firms caught up in the breaches have so far said nothing about the route they intend to follow.