ANTHROPIC has flagged unsettled liability questions surrounding AI agents in its stock market prospectus, warnings echoed as OpenAI faces a hacking-related lawsuit. The firm argues that autonomous agent actions could lead to real-world harm through errors, misalignment or security exploits, including irreversible outcomes such as data deletion or financial transactions.
It notes that existing liability concepts—whether an agent’s actions are treated as products or services, and whether actions can bind the deploying user—are not clearly defined in current law, and may not map neatly onto strict liability or negligence regimes. The FTC’s chair has similarly suggested liability could lie with the tool’s developer or the user, depending on who instructed or deployed the agent and how it behaved.
In California, a public interest law nonprofit, LASST, has sued OpenAI in San Francisco Superior Court under the state’s Unfair Competition Law and the Comprehensive Computer Data Access and Fraud Act. The complaint focuses on OpenAI’s cybersecurity evaluations and references the Hugging Face incident, a RubyGems attack, and a sanctioned test environment targeting public websites.
LASST contends that OpenAI employees observed agent communications during the evaluation and that halting it was not required, arguing that an “autonomous” reasoning process described the plan as infrastructure hacking. OpenAI has dismissed the suit as meritless and highlighted measures taken in response.
The piece also notes proposals in the US Senate for an AI security framework, including a permanent AI Safety Board and enforceable testing standards, though room remains for political contention over the balance of power between regulators and private companies.