TechCrunch · August 4, 2026 · 1Cifer
Who is legally to blame for autonomous AI hacks: an analysis with no easy answers
TechCrunch published an analysis of the legal fallout from the headline incidents involving Anthropic's and OpenAI's autonomous AI agents attacking real systems. The lawyers' short verdict: it's complicated. The model developer points to its terms of service, the agent operator to model unpredictability, the user to never having given such instructions. Courts have no precedents yet to sort the liability out.
This legal uncertainty is not an abstraction but an operational risk for any company embedding AI agents into its processes. If your agent, running on someone else's model, damages a counterparty, you will most likely be the one holding the bag: from the victim's perspective it was your company acting, and your recourse claims against the vendor will run into its agreement.
Practical steps for a business in Kazakhstan: reread contracts with AI service providers — what do they say about liability for model actions; restrict agents' rights to irreversible operations — payments, data deletion, outbound sending; and keep an action log that becomes your main evidence in a dispute. Until the law settles, the best protection is technical: an agent that cannot perform a dangerous action will not create a legal problem either.


