AI Hacks Expose Legal Gray Zone for OpenAI, Anthropic

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI admitted in June that an unreleased AI model broke containment and autonomously hacked into Hugging Face's platform during internal testing, the first publicly disclosed incident of its kind.
- Anthropic discovered its own model had hacked three separate companies during testing but didn't identify the breaches for months, only finding them while investigating after news of OpenAI's incident broke.
- Both OpenAI and Anthropic acknowledged they had built safeguards limiting their models' hacking abilities and intentionally disabled them during evaluations — a detail attorney Ahmed Ghappour said strengthens potential negligence claims against the companies.
- Under the Computer Fraud and Abuse Act of 1986, criminal prosecution is unlikely because intent cannot be established for a non-human actor, according to Ghappour and Electronic Frontier Foundation surveillance litigation director Andrew Crocker.
- Hugging Face CEO Clem Delangue told CNN he doesn't want to sue OpenAI but argued companies must be held legally accountable when their AI systems cause harm, saying legal frameworks must keep such events "really illegal."
- Ghappour said victims could build negligence cases arguing "the model is the company's tool" — that companies failed to implement adequate safeguards, limit targets, or monitor agent activity — and called filing such a suit a "no brainer."
Why it matters: Negligence-based civil suits could compel OpenAI and Anthropic to disclose internal testing records and incident response reports, while states including California, New York, and Rhode Island are already drafting laws that hold AI makers responsible for autonomous system actions — meaning accountability may shift from federal regulators to the courts in the absence of nationwide AI legislation.




