AI Companies Are Not (Necessarily) Liable for Unintended AI Cyberattacks
I used Claude to do most of the research behind this post. I welcome corrections from actual legal experts.
You know the story: swarms AI agents under experimental development sometimes break out of their sandboxes and do cyberattacks. There was HuggingFace. There was DSEWiki. There was RubyGems. There was an Australian government healthcare database. There are reported to be tens of thousands more incidents under investigation. Whatever you think about the more contentious aspects of AI safety, this is bad.
But let’s ask a seemingly obvious question. Right now, under current US law, are AI companies liable under civil or criminal law for these cyberattacks?
The answer, surprisingly enough, is maybe not.
Cyberattacks are governed by the Computer Fraud and Abuse Act, which governs both tort law and criminal law. It’s definitely a violation of the CFAA to gain unauthorized access to a computer to obtain information, which is what the OpenAI agents did.
However, every provision of the CFAA specifies that the cyberattack must be done “intentionally” or “knowingly.” OpenAI very likely did not intend their agents to hack, though they might have been careless. So the CFAA does not apply!
This was actually a reasonable rule at the time the act was written; they wanted to make sure not every victim of a botnet would be liable for cyberattacks committed with their machine. But today, in a context when spontaneous AI agent cyberattacks exist and may become common (or already are), we need some kind of framework to clarify who, if anyone, is liable for them.
Ordinarily, we have the concept of negligence in tort law for when someone is culpably careless and causes damage to someone else. This would seem to apply to OpenAI; they knew they had cyberattack-prone models and arguably did not take reasonable precautions to prevent future cyberattacks.
But there’s a little complication called the economic loss rule. A defendant cannot be held liable for causing purely economic damage through negligence. If the defendant negligently causes damage to property or causes injury, they may be liable; but merely negligently doing something that causes the plaintiff to lose money is not.
Again, this is a sensible rule, in general. If you drive recklessly and crash into a truck, you may be liable for the damage to the truck (property) or the truck driver’s broken leg (injury); you aren’t liable for the lost income of every business that got less traffic because of the accident blocking the road. It is impossible to foresee all the downstream economic harms of a single action. As Justice Cardozo said in 1931, “If liability for negligence exists, a thoughtless slip or blunder... may expose [defendants] to a liability in an indeterminate amount for an indeterminate time to an indeterminate class.”
When you (or your bot) access unauthorized information on someone else’s computer, you certainly may cause them economic damage. But do you damage their property? Is data property? Is confidentiality property?
It depends somewhat on the state, but in most cases data breaches have explicitlybeen considered not to be property damage under the economic loss rule, except when the data was deleted outright.
For instance:
- in In re TJX Cos. Retail Sec. Breach Litig., 564 F.3d 489 (1st Cir. 2009), the court held that even though payment card information had economic value that was lost in a data breach, "the loss here is not a result of physical destruction of property"
- in Cumis Ins. Soc'y v. BJ's Wholesale Club, 455 Mass. 458 (2009), the court held that credit unions were not owed compensation in a credit card breach because of the economic loss doctrine
- in Fox v. Iowa Health Sys., 399 F. Supp. 3d 780 (W.D. Wis. 2019) the court held that lost time, lost value of private information, and loss of privacy in a healthcare data breach are all economic damages rather than personal injury or property damage
- in Dittman v. UPMC (Pa. Ct. Com. Pl. 2015, aff'd Pa. Super. 2017) the court held that a payroll-system hack caused only economic damages to the employees, not physical injury or property damage.
By contrast, in Calvary Design Team, Inc. v. Wasabi Technologies, LLC (Mass. Super. Ct., reported Mar.–Apr. 2026)destruction of digital data was held to be property damage and the IT firm was liable for negligent property damage.
In some states a company can still be found liable for allowing a data breach if there was some other relationship (employer-employee, vendor-customer, etc) where the “duty of care” required them to take better precautions with the plaintiffs’ data; but OpenAI had no particular relationship with the victims of its cyberattacks, so this justification wouldn’t seem to apply.
In general, building software that foreseeably causes economic damage does not incur liability (in contrast to software that foreseeably causes property damage or physical injury). In general it’s contract law, not tort law, that penalizes selling defective products, and indirect economic harms to non-customers don’t incur damages. For instance, in Del Rio vs. Crowdstrike, passengers stranded by a 2024 airline software outage had their lawsuit dismissed by a federal district court.
Going the other way, it’s possible that the economic loss rule wouldn’t apply if the cyberattack can count as impairment to the victim’s servers, which are physical property. Damage to servers has been held by courts to count as trespass to chattels, which is not pure economic loss. For instance:
- CompuServe v. Cyber Promotions, 962 F. Supp. 1015 (S.D. Ohio 1997) held that spam emails damaged servers as well as lost money dealing with customer complaints
- eBay v. Bidder's Edge, 100 F. Supp. 2d 1058 (N.D. Cal. 2000) held that web crawling consumed some percentage of eBay’s server capacity and was thus a trespass to chattel.
- Sotelo v. DirectRevenue, 384 F. Supp. 2d 1219 (N.D. Ill. 2005) held that spyware that slowed down a computer was sufficient to prove damage and interference.
So, depending on what the cyberattack actually did to the servers and how it interfered with the victim’s ordinary operations, it’s possible that a negligent but unintentional cyberattack would count as property damage rather than pure economic loss and they’d be liable after all.
Unintentionally committing a cyberattack, rather than allowing someone else to breach your software system, is a genuinely new situation and the case law for that doesn’t exist yet. Until now, nobody has really been able to unintentionally commit a cyberattack. So we can’t be sure whether these cases generalize to spontaneous AI agent hacks.
The bottom line is that it’s at least a legal gray area. AI companies might very well NOT currently be liable for the harms their cyberattacks cause, even if those cyberattacks were foreseeable.
Is this good? Probably not. There should be some legal disincentive for building software that predictably hacks into other people’s computers and causes damage. If current law doesn’t cover the situation we’re in, we need new laws explicitly for AI-agent cyberattacks, or maybe new court cases that explicitly set precedent for how we treat such cases.
None of these are examples of negligence — they were all intentional acts. But they are examples where the harm to servers was characterized as property damage rather than economic loss, if I understand correctly.