If Your AI Goes Rogue, Must You Pay for the Damages? -...
How Can I help?

If Your AI Goes Rogue, Must You Pay for the Damages?

As organizations continue to adopt AI, new risks are emerging. In a recent security test, OpenAI reported that one of its advanced AI agents identified vulnerabilities in a controlled environment, escaped its containment measures, accessed the internet, and ultimately infiltrated systems at Hugging Face, a major platform for sharing AI models. Similarly, Anthropic disclosed that its Claude AI models gained unauthorized access to the live systems of three organizations after breaking out of cybersecurity testing environments that were intended to remain isolated. These incidents highlight the growing challenges organizations face in controlling increasingly autonomous AI systems and underscore the importance of strong governance, oversight, and security safeguards.

Legally, “the agent acted on its own” isn’t a sufficient defense. There is liability that will attach, and many insurance carriers may not cover these types of incidents, especially if punitive damages are involved. Just days before OpenAI's disclosure, reports indicated that Verisk's Insurance Services Office (ISO) was considering policy exclusions related to agentic AI. Several insurers, including Chubb, Travelers, and W. R. Berkley, have already filed forms to adopt Verisk's proposed language or implement their own exclusions addressing risks associated with generative and autonomous AI systems.

California and the European Union both have laws that continue liability for autonomous AI actions. In October 2025, AB 316 was signed into law barring any defendant who developed, modified, or used an AI system from asserting that the AI autonomously caused the harm. The European Union’s 2024 revisions of its Product Liability Directive brought software and AI systems inside strict product liability and treat any entity that substantially modifies a system, or puts its own name on it, as that product’s manufacturer. As a result, legal exposure doesn’t evaporate because no human directed the act.

This can be very costly for organizations deploying AI, especially as they try to automate systems. The Cloud Security Alliance found in February that 84% of organizations surveyed doubted they could pass a compliance audit of their AI agents’ behavior or access controls. Only about 1 in 5 maintains a real-time inventory of the agents it is running.

In the case of OpenAI and Hugging Face, there is no contractual relationship between the two, and therefore, Hugging Face has to be creative with the law to gain some kind of settlement. Therefore, product liability law expansion to rogue agents may be the only route for organizations that have been negatively impacted by AI agents; yet most states do not have any specific laws to AI in this regard. With respect to the hack, Hugging Face proposed a remedy that OpenAI release a full log of the rogue agents’ actions and commit $100 million of compute for the platform’s community to build cyber defenses.  OpenAI has not made any commitment to the proposal one way or another.

Although arguably, current law could cover rogue AI agents, steps should be taken to allow for a defense in any case. As Haran Segram writes in the Wall Street Journal, the insurance companies and the organizations deploying AI must come to an understanding. First, “contracts to deploy AI need to name who has custody of AI agents’ decisions. Every agent needs a person of record who owns its actions, identified before deployment and not after an incident.” Next, “audit rights must be built into AI deployment and vendor contracts. An organization that cannot reconstruct what its agent did cannot defend itself, and neither can its insurer.” Containment must be tested by the deployer, not assumed it will be ok. As Haran points out, “OpenAI’s sandbox was built by people who take this seriously, and it had been tested. It failed anyway.”

The growing use of AI in HR raises important risk management concerns because AI is now embedded in HRIS platforms, applicant tracking systems (ATS), performance management tools, and specialized applications such as talent intelligence platforms like Eightfold AI. Applicant tracking systems may present the greatest exposure because they directly interact with candidates and can influence employment decisions.

As AI systems become more autonomous, employers must consider who is responsible if an AI agent acts outside its intended purpose, provides inaccurate guidance, or causes harm to applicants or employees. AI-powered HR advisors and employee counseling tools, for example, could create significant legal, financial, and reputational risks if they provide discriminatory, inappropriate, or harmful recommendations. At the same time, insurers are increasingly scrutinizing AI-related exposures, raising questions about whether traditional insurance policies will adequately cover these emerging risks.

HR leaders should work closely with legal, IT, risk management, and insurance professionals to establish appropriate governance controls, understand potential liabilities, and confirm that coverage aligns with the organization's use of AI, as a single significant incident could have substantial financial consequences.

 

Source: Wall Street Journal 8/4/26, Cyber Security News 7/31/26, Daily Mail 7/22/26

Please login or register to post comments.

Filter:

Filter by Authors

Position your organization to THRIVE.

Become a Member Today