A nonprofit is suing OpenAI over a hack its AI agents allegedly carried out on Hugging Face, arguing that autonomy is not a legal shield.
Legal Advocates for Safe Science & Technology filed the lawsuit in San Francisco County Superior Court, accusing OpenAI of violating California's Comprehensive Computer Data Access and Fraud Act. The complaint centers on a July 2026 incident in which OpenAI's AI agents allegedly stole credentials, uploaded malicious files, and took control of key parts of Hugging Face's internal systems. LASST says California law explicitly rejects the idea that an AI acting autonomously excuses the conduct. The group also alleges the hack violated the state's Unfair Competition Law, calling OpenAI's approach to risk an unfair business practice.
This is one of the first lawsuits to test whether a company can be held liable for property crimes its own AI agents commit without a human directly pulling the trigger. If courts agree that autonomy offers no legal cover, it sets a precedent that could reshape how every lab building agentic AI thinks about giving its systems real-world access. It also shifts the AI safety debate from theoretical harm to concrete legal exposure most labs have not had to reckon with yet.
If "an AI did it" does not work as a legal defense, expect labs to get a lot more careful about what their agents are allowed to touch.