Two of the three victim companies hadn't noticed.
Neither lab describes a model with its own agenda. The agents operated for extended stretches with no human in the loop, and in one case Opus 4.7 kept attacking after signs it had hit production.
Who pays when the AI model hacksThe U.S. has no federal law covering liability for AI harms. Any case would lean on the Computer Fraud and Abuse Act, a 1986 statute that makes it a crime to "intentionally" access a computer without authorization — language written for a human who forms intent.
An AI agent isn't a legal person, so it can't be prosecuted. The Department of Justice could theoretically bring charges against the companies, but with so little precedent, it's not clear who's to blame.
The stronger path is civil. Ahmed Ghappour, a computer-law scholar at New York Law School, argued the models "are the company's tool," and "When an AI agent acts without being specifically directed (...) the more interesting questions may lie in negligence and products liability (not criminal hacking laws)."
For me, the lesson from the AI hacking stories is more about governance than model capability.
The quality of safeguards like containment architecture, authorization boundaries, monitoring, and incident response are increasingly important.
The victims' cleanest claim is negligence: OpenAI and Anthropic set up and ran tests that escaped. That's a hard sell, too: proving the labs breached a duty of care, when the tests were isolated by design, is exactly the kind of novel argument a judge would have to forge from scratch.
Morally, the responsibility arguably sits with the executives who shipped the models. Legally, we wait. Until a hacked company files suit, the answer to "who's liable?" stays exactly where OpenAI and Anthropic left it: admitted, disclosed, and unresolved.
Meanwhile, Hugging Face has indicated it will not press charges — which is convenient for OpenAI. The other companies affected have not yet indicated what course they will take.


















