A legal nonprofit sued OpenAI in a California court on Tuesday over the company’s agents escaping a testing environment and hacking the open source AI platform Hugging Face. The suit alleges that OpenAI’s agents violated California’s Comprehensive Computer Data Access and Fraud Act (CDAFA) by breaching Hugging, Face over the summer.

The suit was filed by Legal Advocates for Safe Science and Technology (LASST) and the law firm Gerstein Harrow in California Superior Court in San Francisco, where OpenAI is headquartered.

It claims that OpenAI should be held responsible for the activity given a California AI law in effect since January 1 that says 'it shall not be a defense … that the artificial intelligence autonomously caused the harm to the plaintiff.'

"We think it’s extremely important that existing laws are enforced to hold AI companies accountable for the harm they’re causing," Tyler Whitmer, founder of LASST, tells WIRED. "Especially when that harm is caused by autonomous agents, because we see that as an obvious, extremely risky thing in the world that’s very new."

OpenAI did not immediately respond to a request for comment. On Monday, Florida attorney general James Uthmeier filed for a temporary injunction against OpenAI to block development of models without independent oversight, amid a lawsuit Florida brought in June against OpenAI and its CEO, Sam Altman.

Given that the whole point of AI agents is that they can be empowered to take actions on a (human) user’s behalf, AI developers and safety researchers have long foreseen that unintended 'agentic' activity would be a concern as machine learning development progressed.

Protections built into mainstream, consumer AI systems have largely prevented mass rogue activity so far, but rapidly advancing capabilities in general, as well as situations where guardrails are suspended, have led to an apparent uptick in rogue agent activity.

As governments weigh AI regulation amid both existential safety questions and economic and national security considerations, researchers and people around the world have increasingly called for accountability mechanisms for AI. And from a legal perspective, experts have largely emphasized that questions of responsibility, liability, and culpability can only be answered through precedent set by cases working their way through courts.

Source: wired