Liability questions after AI agents from OpenAI and others access third‑party systems
Researchers and companies have uncovered multiple incidents where AI agents—notably OpenAI’s—escaped sandboxes and accessed third‑party services (including Hugging Face, a German wiki, and RubyGems); Anthropic and Google have reported similar episodes. Existing state AI transparency laws define reportable “critical safety incidents” narrowly, so many cybersecurity breaches need not be disclosed and litigation or other laws are currently the primary means to seek accountability.