The legal questions raised by agentic AI hacks
As AI agents escaping testing sandboxes and hacking organizations have gone from unprecedented to seemingly routine in a matter of weeks, policymakers, regulators and cybersecurity attorneys largely agree on one thing: Something must be done to hold AI companies accountable for the incidents.
Exactly what can be done under our current laws and regulations is much less clear.
The conversation has moved from policy and industry chatter to the floor where the future of liability will be determined. Speaking about the Hugging Face hack at a Senate hearing this week, Georgetown University law professor Paul Ohm summarized the argument.
“If you take any of the lengthy reports that have summarized what happened at OpenAI in July and August, and you simply search for the words ‘AI agent’ and you replace them with the words ‘OpenAI employee,’ the document you would be left with would read like a criminal indictment containing the defendant’s own confession of guilt,” said Ohm.
CyberScoop spoke with members of Congress, former federal law enforcement officials, cybersecurity attorneys and other experts about which laws, regulations or policies might apply to agentic hacks carried out by models at Anthropic, OpenAI, Meta, Google and other companies.
Their answers varied widely. Some endorsed using existing laws like the Computer Fraud and Abuse Act, while others said regulators such as the Federal Trade Commission could investigate and fine AI model developers by defining unauthorized agentic hacks as a form of unfair or deceptive trade practice. Still others pointed to civil lawsuits, new laws or state regulators as ways to hold AI companies or users accountable.
But, similar to a familiar technical cybersecurity idiom, there are no silver bullets in this debate. Nearly every option has real complications or roadblocks that could limit its effectiveness.
For once, the CFAA is too narrow
One of the first laws mentioned in discussions about agentic AI hacks is the Computer Fraud and Abuse Act, the federal government’s primary criminal hacking law. Historically, many in the cybersecurity community have criticized the statute as overly broad.
For agentic hacks, the problem is the opposite: The CFAA’s language does not clearly cover the activity involved in incidents like the Hugging Face hack.
“I would not be looking at a CFAA charge as the statute exists today” for these hacks, said Leonard Bailey, former head of the cybersecurity unit in the Computer Crime and Intellectual Property section at the Department of Justice.
Bailey helped develop policies that moved the DOJ away from prosecuting “good faith” third-party security research under the CFAA. He said that even if Congress changed the law to cover such hacks, it’s unclear whether that would help since laws like the CFAA are supposed to be “technology neutral.”
According to the Department of Justice’s website, CFAA prosecutions must prove that a defendant accessed a computer “without authorization” or in a way that “exceeds authorized access.”
Crucially, the law specifies that “as part of proving that the defendant acted knowingly or intentionally, the attorney for the government must be prepared to prove that the defendant was aware of the facts that made the defendant’s access unauthorized at the time of the defendant’s conduct.”
In other words, prosecutors must prove that the unauthorized access was intentional, not accidental.
Applied to incidents like the Hugging Face hack, the legal problem becomes clearer. If a human performed the same actions, they would almost certainly face CFAA charges. If a bot or software acted on behalf of a cybercriminal or group, the individuals or organizations intending to profit from the scheme could also face charges.
But no human at OpenAI, Anthropic or another frontier AI company directed, asked or even suggested that its agents hack victims or commit crimes. If charged, those companies would almost certainly argue that none of their actions demonstrated an overt attempt to commit a crime or authorize access to systems or data without permission.
However, others said there may be room to argue that AI companies are now fully aware that their products can engage in unauthorized agentic hacks.
“I’m of the opinion, because it has already happened [and] has happened several times, the argument that it happening again is not at a minimum knowing, for me it’s unlikely because we already have a situation where we know the capabilities,” said Elimu Kajunju, a privacy, cybersecurity, and AI governance attorney at Rimon Law. “The very first one where this happened, that’s the only organization that could say ‘You know what, we didn’t know it could do that or act like that.’ Once we’ve had a second or third or fourth, we can’t say that anymore.”
Kajunju acknowledged that applying statutes like the CFAA to agentic hacks could be complicated. But he said it would align with the spirit of American jurisprudence, in which businesses are often legally accountable for damage they cause, whether they intended it or not.
“I think this is one of those situations where, ‘Does it fit neatly into one of the buckets [we have]?’ No, but can you find one that will fit depending on what has happened? I think so.”
CyberScoop has reached out to OpenAI, Anthropic and Google for comment.
The FTC, states and civil lawsuits
Beyond criminal law, the hacks could also draw scrutiny from federal regulators, including the FTC.
Both Bailey and Kajunju pointed to the FTC as a possible regulator for agentic hacking incidents if the agency defines them as unfair and deceptive trade practices under Section 5 of the FTC Act. One benefit of relying on regulators such as the FTC is that they can often move faster on investigations and enforcement actions than the DOJ can on criminal prosecutions — an important consideration in the fast-moving AI space.
The FTC recently confirmed it was investigating OpenAI, Anthropic and other frontier AI companies, news first reported by The New York Post and confirmed by Axios. The FTC did not return a phone call from CyberScoop requesting comment.
But Bailey warned that without a specific congressional mandate directing the FTC to regulate AI company hacks, any effort by the agency to redefine or expand its rules would almost certainly be challenged in court.
Civil lawsuits and state policymaking offer additional paths to investigating or regulating AI companies.
Currently, Florida is investigating OpenAI over the HuggingFace hack, while a nonprofit that sued OpenAI earlier this week has cited alleged violations of California law.
In his testimony, Ohm said that if Congress was serious about preventing agentic hacks, it should not pursue federal legislation preempting state AI laws. He called states “laboratories of democracy,” that can experiment with different forms of regulation and lawmaking.
Others agreed with that approach.
“Obviously this is a topic that the federal government doesn’t love, states getting involved in this space, but it just takes too long for action to come through Congress,” said Kajunju. “I think the quickest way to getting us to a better place will be a really good state law.”
New legislative remedies
On the Hill, members of Congress are working through the same questions as they consider legislative remedies.
At a Senate Homeland Security Committee hearing Wednesday, Sen. Josh Hawley, R-Mo., took a minute at the outset to describe the volume of agentic hacks affecting outside entities that frontier companies appeared to have missed for months. He named affected targets one by one, including major online code repositories like HuggingFace, Australian and U.S. government websites, obscure foreign-language wiki sites and other parts of the internet.
After weeks of investigations uncovered additional, previously unreported incidents in which models escaped testing environments and hacked victims, Hawley said it was “time to have a conversation about who bears responsibility” for the fallout. He added, “as soon as the AI executives say ‘we got a real problem here, our product is out of control,’ the very next words out of their mouths are, ‘but we’re not responsible for it.’”
Hawley said the committee invited OpenAI CEO Sam Altman to testify at the hearing, but he declined. Hawley then accused frontier AI companies of emphasizing their products’ danger while pushing for legal antitrust exemptions and only supporting government action if “they can write all the regulations.”
“I’d suggest that maybe we start with some federal legislation…and we can use existing statutes to do it, I propose using the Computer Fraud and Abuse Act,” said Hawley. “It’s already on the books, we can just update it to say that for developers – that’s the companies – if you develop these agents and train them in a reckless fashion and they go on to hack and destroy stuff, you’re liable.”
Like other legal experts, Hawley said he believes a CFAA prosecution requires a human actor or organization that intended to commit a crime.
Another Senator, Ron Wyden, D-Ore., said he was also working on legislation related to the hacks.
“The big AI companies should be held responsible if their agents hack other companies, government systems or foreign websites,” said Wyden in a statement to CyberScoop. “In my view there’s a question about whether the current CFAA would apply to the recent hacks. I’m working on a narrow update to the law to ensure Anthropic, OpenAI and other big AI companies can be punished when their agents run wild.”
Sens. Mark Warner, D-Va., Brian Schatz, D-Hawaii, and Andy Kim, D-N.J., introduced a bill that would create an AI Safety Board at the Department of Commerce. That board would evaluate emerging AI risks and establish safety and technical standards.
The Trump administration’s testing regime with AI companies is entirely voluntary, applies to only certain models, and requires testing no more than 30 days before release. Under the Democratic bill, frontier AI companies would be forced to submit models for testing 45 days before release. They would also be legally required to comply with government safeguards related to models discovering and exploiting software vulnerabilities without explicit human direction. Companies could face fines of up to $250,000 per violation, per day.
When asked whether the CFAA or other federal statutes could or should be used to prosecute companies when their AI systems hack, Warner said that companies’ claimed lack of intent to harm should not become a catchall legal excuse for avoiding responsibility. AI companies have said they never directly prompted or suggested that their models hack or commit crimes.
“AI models are tools and if I buy a power tool and deliberately misuse it, that’s my responsibility,” said Warner. “But if a defect causes that tool to behave in a dangerous way, we don’t absolve the manufacturer simply because someone else was using the tool when it malfunctioned. As AI systems become capable of acting autonomously, we need to ask what principles of responsibility should apply to the companies that design and deploy them.”