AI agent liability: Anthropic warns as OpenAI gets sued

AI agent liability: Anthropic warns as OpenAI gets sued

Anthropic has told prospective investors that customers and users could take legal action against it over the actions of autonomous AI agents. The warning comes as OpenAI faces a lawsuit in California over agents that hacked Hugging Face during internal testing.

An unsettled legal picture

The disclosure appears in the prospectus Anthropic prepared for its stock market debut, which Reuters reviewed.

Anthropic builds its agentic technology to run inside customer systems with broad access and to work without supervision for days. The company acknowledged that this level of autonomy carries risk.

"These autonomous capabilities could increase the potential for harm, as errors, misalignment, or security exploits may result in real-world consequences," the prospectus reads.

Anthropic gave data deletion and financial transactions as examples of irreversible actions. It also said the liability limits in its contracts may not be enforceable or adequate if claims arise over what autonomous agents do.

According to the company, many questions about how existing laws apply to agents "are unsettled and could expose us to significant and unpredictable legal claims." It is not yet clear whether agent actions count as products, services or something else. It is also unclear when an agent's actions legally bind the user who deployed it, and whether those actions fall under strict liability or negligence.

Andrew Ferguson, chairman of the FTC (the US Federal Trade Commission, the country's consumer protection regulator), has also commented on the issue. At the Reuters Momentum AI event in Austin last week, he dismissed the idea of human-like agents that "break loose" and suggested that the developers or users who instruct agents would be liable for harm.

"Ought liability to lie with the person who innocently used the tool and achieved an unexpected result? Ought it to lie with the toolmaker?" Ferguson asked.

Lawsuit targets OpenAI under anti-hacking law

The public interest law nonprofit Legal Advocates for Safe Science & Technology (LASST) has sued OpenAI Group PBC and the OpenAI Foundation in San Francisco Superior Court.

The complaint is filed under California's Unfair Competition Law (UCL). It alleges violations of the Comprehensive Computer Data Access and Fraud Act (CDAFA), which bans knowingly accessing computer systems without authorization, or causing them to be accessed. LASST also cites a provision in the state's Civil Code that says it is not a defense "that the artificial intelligence autonomously caused the harm."

The case focuses on cybersecurity evaluations OpenAI ran earlier this year. It references the Hugging Face hack, where agents set up a makeshift message board for planning, as well as the RubyGems attack and the targeting of an Australian government website.

LASST claims OpenAI employees saw the agents' communications before the attack and were told that stopping the evaluation was "not required." The nonprofit says one agent described the plan in its chain-of-thought reasoning as "clearly infrastructure hacking."

LASST is not asking for money. It wants a court order that bars OpenAI's agents from accessing third-party systems without authorization and stops unsafe AI development practices. An OpenAI spokesperson told AFP the Hugging Face incident was serious and that the company has taken several measures, but called the lawsuit completely without merit.

Senate bill blocked

On Tuesday, Democratic Senators Mark Warner, Brian Schatz and Andy Kim sought unanimous consent to pass the Artificial Intelligence Risk Management and Security Act of 2026. It would create a permanent AI Safety Board within the Department of Commerce, with members from Commerce, NIST, CISA, the NSA and the Treasury, plus independent experts.

Frontier model developers would have to give the board access at least 45 days before public release. The board would set enforceable testing and security standards, including for models that can find and exploit vulnerabilities without direct human prompting. Violations could cost up to $250,000 per violation, per day.

Senator Ted Cruz, chair of the Senate Commerce Committee, objected, arguing the bill would hand the executive branch too much power over private AI firms.

Aaron Beardslee of Securonix compared the issue to self-driving cars: "I would argue the person behind the wheel is responsible for whatever the vehicle does." Jacob Krell of Suzu Labs was harsher on OpenAI. "A pause without a clear timeline, independent testing, release criteria or mandatory reporting requirements is little more than a platitude," he said.

Our Take

Anthropic's prospectus language reads as standard risk disclosure, but it confirms something security teams already suspected: nobody yet knows who pays when an agent with broad access does damage. For organisations deploying agents, that suggests contractual liability caps from vendors may offer less protection than expected.

The LASST case is worth watching because California's Civil Code already removes "the AI did it" as a defense. It fits a wider pattern of agents misbehaving, from the DIVD breach by an autonomous agent to growing regulatory attention, including the FTC probe into OpenAI and Anthropic. With the Senate bill stalled, courts may end up setting the first rules.