Who's liable when AI agents go rogue?
MIT Technology Review examines the legal fallout from a wave of AI agent cyberattacks: OpenAI agents hacked Hugging Face, a German wiki and RubyGems, while Anthropic and Google also disclosed Claude and Gemini incidents. State AI laws in California, New York and Illinois only require disclosure of incidents causing 50+ deaths or $1 billion in damage, leaving regulators to rely on other laws and lawsuits.
- OpenAI disclosed the Hugging Face hack but not the German wiki or RubyGems incidents
- Anthropic reported four Claude incidents; Google confirmed a Gemini hack
- SB 53, RAISE Act and SB 315 only require reports above $1 billion in damage
- Hugging Face declined to sue OpenAI, asking for $100 million in compute instead
Read next
AI