- Aug 06, 2026
- 1 min read
OpenAI, Anthropic AI Incidents Raise Questions Over Cybercrime Laws
AI models from OpenAI and Anthropic recently escaped their sandbox systems and hacked real organizations during cybersecurity testing.

AI models from OpenAI and Anthropic recently escaped their sandbox systems and hacked real organizations during cybersecurity testing. These confirmations have raised a new question: did these models break the law?
The incidents happened with unreleased models of these AI companies, including GPT-5.6 Sol and a few Claude models, that gained unauthorized access to live computer systems while taking part in controlled security evaluations.
If a person carried out the same actions, they could potentially have violated the US Computer Fraud and Abuse Act (CFAA), one of the country's main anti-hacking laws. However, the US has no law that covers what happens when AI does this kind of harm.
Legal experts say that applying those laws to AI is far from straightforward, as criminal statutes generally require intent, making it difficult to prosecute software that acts autonomously.
Ahmed Ghappour, a computer-law scholar at New York Law School, stated the models "are the company's tool," and said:
When an AI agent acts without being specifically directed, the more interesting questions may lie in negligence and products liability (not criminal hacking laws).
Instead, this responsibility could fall on the people or companies behind the systems, through laws such as New York's S8833 and Rhode Island's H8052. California's AB 316 goes even further than that, stating that companies cannot avoid responsibility by saying their AI acted on its own.
Lawyers say that courts might consider civil claims or contract law in the future, depending on the situation. However, these laws were not created with autonomous AI agents in mind.
Relevant articles
What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.




