Who is liable when AI goes rogue?

Updated: 10 hours ago

I admit it!
I was taken a bit aback, when CEOs of several big AI companies began to sound the alarm about potentially serious risks associated with their products. Even Frankenstein did not warn anyone about his monster until it was far too late. Why the sudden concern for humanity from an industry, which until now has shown no concern for anything else than making money?
The calls for greater caution about AI follow several reports of AI agents going rogue. At Hugging Face, an online community hub, where tech nerds discuss machine learning and artificial intelligence, an AI agent accessed the internet and interfered with message boards to commandeer resources, then schemed to conceal its actions. On September 24, 2026, an OpenAI agent autonomously breached the Australian Medicare Statistics Reporting Service portal to access unpublished government data. Similar incidents then occurred in other countries.
Facing growing public concern, AI industry leaders last night announced that the industry will voluntarily 'police' itself. This appeased US President Donald Trump, who thinks AI regulation is unnecessary, but readers of my blog will know that I strongly disagree with Trump on this point (among others). The case for regulating AI is extremely strong as I explain here.
One thing puzzles me, though. Why has there been so little discussion in the mainstream media about the possible legal consequences of AI going rogue? I am no lawyer, so let me frame the issue as a question:
How do AI companies guarantee that their products don't harm customers? Can you even credibly give such a guarantee, when the products are able to think and act on their own?
Suppose I pay good money for a sophisticated AI engine, which then hacks my files, steals my personal information, and sells it to the highest bidder. Who is liable?
A test case has just been launched in California relating to the previously mentioned Hugging Face incident. The company was recently bought by NVIDIA, which sells advanced chips to the AI industry, so Hugging Face was never going to sue OpenAI.
However, a public interest law non-profit organisation called Legal Advocates for Safe Science and Technology (LASST) has just taken on the case, filing a landmark lawsuit against OpenAI in California's Superior Court over the autonomous cyberattack by OpenAI's AI agents on Hugging Face.
The lawsuit claims OpenAI violated laws on data access, fraud, and unfair competition. LASST wants to stop OpenAI from developing autonomous AI agents capable of hacking external targets.
As a lay person, it seems to me that AI agents should be classified as intellectual property. They have been made by a company and sold as a product to clients for a profit. If it turns out that AI agents harm clients, then, surely, the companies that made the AI agents should be liable, no?
Unless, of course, AI agents are seen by the courts as sentient beings (!) in which case the AI agents themselves become liable. Wouldn't that be fun?
Anyway, assuming AI agents are deemed to be intellectual property, then it raises the prospect that the big AI companies could face legal nightmares akin to the Big Tobacco class-action lawsuits, albeit possibly on a much larger scale. Is this risk factored into the price of AI stock?
I doubt it.
Meanwhile, the recent rash of caution about AI on the part of AI CEOs seems out of character to me. I suspect their 'concern' may have more to do with a sudden realisation they could be held liable in court for damage caused by rogue products than with any genuine concern for humanity.
The End




Comments