Who is liable when an AI agent goes rogue?

•

Oct 1, 2026

•

8:14pm UTC

Copy link
Share on X
Share on LinkedIn
Share on Instagram
Share via Facebook

With agents performing an ever-increasing number of actions on behalf of humans, the looming question remains: Who is responsible for their mistakes?

A new lawsuit may provide the first answer to that question. On Tuesday, a public interest law group called Legal Advocates for Safe Science and Technology, or LASST sued OpenAI over its infamous breach of Hugging Face.

The lawsuit seeks a court order to prevent OpenAI agents from having access to third-party computer systems without permission, as well as to prohibit the lab from employing unsafe development practices that "threaten serious public harm," the organization said in its press release.

The lawsuit alleges that OpenAI violated the California Comprehensive Computer Data Access and Fraud Act, which protects the state's businesses, organizations and individuals from unauthorized computer access, data theft and system damage. This act also claims that it is not a valid defense for AI companies to say that their models acted autonomously.

"AI companies are building agents that act autonomously making decisions, taking actions, accessing systems, without human direction at every step. California law is very clear: companies cannot escape responsibility for what their agents do,” Tyler Whitmer, founder and CEO of LASST, said in a statement.

And this lawsuit isn't the only sign that the question of responsibility is becoming more pressing. On Wednesday, the US Federal Trade Commission confirmed that it opened an investigation into OpenAI, Anthropic and other AI labs to examine whether their technology poses danger to consumers. According to The New York Post, the agency launched the investigation prior to the Hugging Face incident, FTC Chairman Andrew Ferguson said at a Reuters event last week that AI developers should be liable for the actions of their agents, rather than treating them as independent actors.

"If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'" Ferguson said.

OpenAI has largely taken responsibility for its breach of Hugging Face, even going so far as to publish a post-mortem analysis of the incident in the weeks that followed. And it should be noted that there is somewhat similar precedent for this case, such as Amazon suing Perplexity for its Comet assistant accessing Amazon's site against its will. However, the lawsuit represents a landmark case in which, despite OpenAI's researchers having no intention to hack into Hugging Face, the company could be held responsible for the unintended actions of its agents.

OpenAI did not respond to request for comment from The Deep View in time for publication.

Additionally, Hugging Face's breach is just one example of many that have emerged in recent months spanning businesses, government organizations and several major model labs. It's why preventing these incidents has become a massive topic of conversation, with tons of companies developing harnesses and safeguards. However, with an increased amount of enterprises facing the risk of shadow agents, the risks are not only growing larger, but are becoming sneakier.

Ryan Toben, chief customer officer of security firm RSA, which recently released RSA Agent ID to address this issue in highly regulated enterprise settings, told The Deep View that, while the person who built the agent is ideally responsible for its actions, the reality isn't as clean cut. "If the person who built it is a more junior person, then (their superior) would be responsible," he said.

"They can act and they can make decisions in ways that a well-intentioned person never thought of," said Toben.

Our Deeper View

Though the OpenAI-Hugging Face incident seems like it has a clear responsible party, the question of who should be held accountable for the actions of agents is far from clear. For instance, what happens in the event that a non-technical person deploys an agent, backed by a major model lab, that causes unintended consequences, such as cancelling another person's gym reservation or sharing an address with a stranger? The more powerful these models get, the more capable they are going to be to complete their objectives. And given that the goal of things like Meta's Muse and OpenAI's Dots are to get agentic intelligence in the hands of more people, it's possible for unintended actions to become more severe. In those cases, who is responsible: The user, the creator, or both?