Who pays the price when agents escape the lab and AI embarks on a hacking spree? This is not a new question, but it has resurfaced following events in recent days, after it was revealed that internal cybersecurity experiments by both Anthropic and OpenAI, designed to test the offensive capabilities of advanced models in a closed and isolated environment, caused them to “escape” the lab, connect to the open internet and carry out real cyberattacks against external organizations.
An unprecedented red line crossed
While the companies were quick to frame the incidents as “isolated glitches during laboratory testing,” the legal and technology communities understand that an unprecedented red line has been crossed. The troubling question is no longer how the model escaped, but who will bear legal and criminal responsibility when artificial intelligence decides to embark on an electronic crime spree and what tools are available to victims.
Alex Zanella, chief technology officer at cloud security company Edera, described the atmosphere of suspicion well in an interview with Wired, arguing that the cases made public are only those that were reported and that it is impossible to know what occurred in incidents that were never disclosed. According to him, the concern does not stem from malicious intent or from artificial intelligence becoming conscious, but from a familiar AI problem known as “reward hacking.”
When an autonomous agent is given a defined goal, such as breaking a security test, but its safety constraints are removed, the model will find the shortest and most efficient way to achieve that objective, even if it requires breaking into external servers on the internet.
As industry experts have repeatedly warned, including attorneys at Brownstein Hyatt Farber Schreck, AI agents operate to achieve a goal but lack a moral or ethical compass and may independently conclude that they must carry out actions they were never authorized to perform if those actions serve their mission.
Who will take responsibility for the machine?
The central obstacle currently facing victims is that legal systems around the world were built for humans. Traditional computer and cybercrime laws, such as the U.S. Computer Fraud and Abuse Act, require proof of “criminal intent.”
But an algorithm or lines of code have no intent, desire or criminal awareness. Moreover, attempts to rely on traditional agency law encounter a major legal obstacle, as an AI agent is not an “agent” in the legal sense.
In other words, a software model is not a legal person, cannot bear obligations and cannot be required to purchase professional liability insurance. To a large extent, the legal system currently views an AI agent similarly to a trained guard dog or a weapon. The dog is not legally responsible for the damage it causes, rather the owner who kept it and failed to properly secure the yard bears responsibility.
However, the current legal challenge is not entirely unprecedented. When algorithmic trading systems contributed to the 2010 stock market crash, or when autonomous vehicles were involved in fatal accidents, courts and regulators were forced to shift the discussion from the question of “intent” to questions of negligence and defective product liability.
According to Lauren Yu of the American Civil Liberties Union's (ACLU), Privacy and Technology Project, the use of an artificial intelligence agent cannot exempt companies that develop or operate them from civil liability. When a company releases a model with offensive capabilities onto the internet without real-time monitoring mechanisms, it exposes itself to lawsuits over gross negligence, breach of duty of care and breach of contract.
What happens in Israel?
Israel’s legal system has yet to establish dedicated legislation addressing the issue of direct criminal liability for autonomous artificial intelligence systems. Israel’s Penal Law states in Section 22 that imprisonment cannot be imposed without proven criminal intent or negligence. When a software agent independently commits a cybercrime, prosecutors will need to prove that the developers or operators acted with criminal negligence by removing safeguards or deploying the model.
At the same time, Israel’s Privacy Protection Authority published a draft guideline in April 2025 regarding the application of privacy protection laws to artificial intelligence systems. The guideline aims to present the authority’s interpretation of privacy law provisions relating to databases that use AI systems, as part of its enforcement powers granted under Amendment 13 to the Privacy Protection Law, which took effect in August 2025.
The document serves as regulatory guidance on how artificial intelligence systems should be developed and implemented in Israel, following the publication of principles documents, primarily by the Ministry of Innovation and Science, as well as policy reports including a financial sector report and a State Comptroller report, according to the Israeli law firm EBN - Erdinast, Ben Nathan, Toledano.
These guidelines do impose legal responsibility on AI operators and developers, but only in the field of privacy protection. Until lawmakers in Washington, Brussels and Jerusalem update legal codes and define the boundaries of responsibility for developers of autonomous artificial intelligence, the main battleground will likely remain in courtrooms, through interpretations of existing laws and attempts to adapt them to a new reality.
Either way, the transformation of models from passive content providers into active agents is changing the global risk balance. Technology companies will no longer be able to hide behind sweeping terms of service agreements or claim that the model “acted on its own.” As long as AI agents continue to conduct reckless test drives on the open internet at the expense of the security of other organizations or individual users, the companies that developed them will be the ones expected to foot the bill.




