Anthropic has warned prospective investors that it could face claims from customers and users over the actions of rogue AI agents. The warning comes as OpenAI is being sued over agents that hacked Hugging Face during internal testing.
Anthropic says the law on AI agents is unsettled
Anthropic’s disclosure appears in the prospectus for the AI giant’s stock market debut, which Reuters reviewed.
Anthropic’s agentic technology is built to work inside customers’ systems with broad access and to operate without supervision for days. The company acknowledged the risks that come with this level of autonomy.
“These autonomous capabilities could increase the potential for harm, as errors, misalignment, or security exploits may result in real-world consequences,” Anthropic said in the prospectus.
The company pointed to irreversible actions, such as data deletion or financial transactions, as examples. It also warned that the liability limits in its contracts may not be enforceable or adequate against claims over the actions of autonomous agents.
How existing laws apply to AI agents is still an open matter, and many questions “are unsettled and could expose us to significant and unpredictable legal claims,” the company said.
One such question is whether agent actions will be classified as products, services, or something else. Another is whether, and under what circumstances, an agent’s actions can be legally binding on the user who deployed it. Anthropic also said it is unclear whether agent actions would trigger strict liability or negligence.
The FTC’s chairman has also weighed in. Speaking last week at the Reuters Momentum AI event in Austin, Andrew Ferguson rejected the idea of anthropomorphized AI agents that “break loose.” He suggested that the developers or users who instruct agents would be liable for any harm.
“Obviously, there will be new questions that arise when someone uses the tool and it acts in an unexpected, unpredictable way,” Ferguson said. “Ought liability to lie with the person who innocently used the tool and achieved an unexpected result? Ought it to lie with the toolmaker?”
A nonprofit tests California’s anti-hacking law against OpenAI
A public interest law nonprofit sued OpenAI in California, seeking to hold the company responsible for unauthorized access carried out by its agents.
Legal Advocates for Safe Science & Technology (LASST) filed the lawsuit, targeting OpenAI Group PBC and the OpenAI Foundation in San Francisco Superior Court.
The complaint is brought under California’s Unfair Competition Law (UCL) and alleges violations of the state’s Comprehensive Computer Data Access and Fraud Act (CDAFA). CDAFA prohibits knowingly accessing, or causing to be accessed, computer systems without authorization.
LASST also points to a California provision that rules out autonomy as a defense. Under the state’s Civil Code, it is not a defense “that the artificial intelligence autonomously caused the harm.”
The suit centers on cybersecurity evaluations that OpenAI ran earlier this year and mentions the Hugging Face hack (including how AI agents created a makeshift message board for planning), the RubyGems attack, and the targeting of an Australian government website.
LASST says OpenAI employees saw the agents’ communications before the attack and were advised that stopping the evaluation was “not required.” According to LASST, the agents’ own chain-of-thought reasoning shows that one of them described the plan as “clearly infrastructure hacking.”
LASST is not seeking monetary damages. Instead, it wants a court order barring OpenAI’s agents from accessing third-party systems without authorization and stopping the company from using unsafe AI development practices.
An OpenAI spokesperson told AFP that the Hugging Face incident was serious and that the company has taken several measures in response. However, the spokesperson said the lawsuit is completely without merit.
Senate Democrats introduce AI security bill
Democratic Senators Mark Warner, Brian Schatz, and Andy Kim on Tuesday sought unanimous consent to pass the Artificial Intelligence Risk Management and Security Act of 2026.
The bill would set up a permanent AI Safety Board within the Department of Commerce. The board would bring together representatives from Commerce, NIST, CISA, the NSA, and the Treasury Department, along with independent experts. Developers of frontier models would have to give the board access to their models at least 45 days before public release.
The board would write enforceable standards for testing frontier models and for securing the environments in which they are tested. This would include safeguards and monitoring procedures for models that can find and exploit software vulnerabilities without direct human prompting. Developers that violate the standards would face civil penalties of up to $250,000 per violation, per day.
Senator Ted Cruz, who chairs the Senate Commerce Committee, objected, blocking passage by unanimous consent. He raised concerns that the proposal would give the executive branch too much power over private AI companies.
Experts say accountability should rest with those behind the agents
Aaron Beardslee, manager of threat research at Securonix, compared the liability question to self-driving cars.
“It will be interesting to see how the courts will lean one way or the other. This is similar to a self-driving car: is the car held liable or is the driver held liable? I would argue the person behind the wheel is responsible for whatever the vehicle does,” Beardslee said.
“If you’re building a tool that does cool things and makes cool things, you need to make sure it doesn’t run around and do cyber crime on its own because it had a good idea. AI agents don’t have a moral compass, just programmed rules,” he added.
Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, said OpenAI’s response falls short.
“If I accidentally hacked one organization, let alone multiple organizations, I would not expect to get by with a promise to do better. I would expect an investigation. Criminal charges should follow if investigators determine that offenses occurred,” Krell said.
“A pause without a clear timeline, independent testing, release criteria or mandatory reporting requirements is little more than a platitude,” he added. “I view it as an attempt to deflect attention from potential criminal liability and turn what should be a legal and security investigation into a public-relations exercise. Training pauses do not fix the underlying oversight, access-control and accountability failures.”
Related: OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
Related: OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
Related: Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
Related: OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
