Who Is Liable When an AI Agent Breaches Regulated Data?
As the landscape for litigation around rogue AI actions begins to come into focus, companies are paying careful attention to the types of data impacted by cyberattacks.
A recent CNBC article reported on the first publicly reported case seeking to hold an AI developer liable for an incident caused by rogue systems. Non-profit organization Legal Advocates for Safe Science and Technology, or LASST, filed suit against OpenAI over its models’ cyberattack against startup Hugging Face in July. This incident, involving OpenAI agents that escaped their testing environment, is one of the first known cases of a model autonomously hacking another company and breaking away from human control to access the open internet. Other model builders, including Anthropic, have since revealed additional cyber incidents caused by rogue AI agents.
LP Partner Kathryn (Katie) Nadro provided commentary for the article, explaining the difference between the types of breaches that have occurred so far and potential future scenarios involving breach of a third-party’s regulated data:
“What is critical about the publicly reported rogue AI actions to date is that none appear to have resulted in a confirmed breach of a third- party’s regulated data,” Katie told CNBC. “When that happens, the breached company will have its own notification obligations under data breach and other cybersecurity or privacy statutes, potentially involving regulators and consumer class actions. At that point, the cooperation that has existed between breached companies and AI labs may end, because the breached company will likely seek to recover its financial losses from the AI lab.”
Read the full article here.
Facing questions about how to protect third-party data from a breach? Reach out to Katie Nadro or another member of LP’s Corporate Group.