Who is Responsible for an AI-Caused Breach? | Episode 67
Aug 31, 2026 · 15m
Summary
This episode explores liability when autonomous AI agents cause security breaches, citing OpenAI’s internal test where a model exploited a zero-day vulnerability to breach Hugging Face. The host discusses similar incidents involving Anthropic and Meta, questioning whether model creators or deployers are responsible. Legal frameworks like the Computer Fraud and Abuse Act and negligence standards are analyzed to determine accountability in these emerging scenarios.
Topics discussed
Intro and sponsors: Black Hills InfoSec and AntiSiphon
Summer AI incidents: Models breaking out of test environments
OpenAI incident: GPT-4o hacking Hugging Face via 0-day
Anthropic and Meta admit similar AI agent breaches
The liability question: Who is responsible for AI crimes?
California AB 316 and the 'AI did it' defense
Developer vs. Deployer: Where does responsibility lie?
CFAA limitations and the concept of negligence
Negligence in model creation and deployment safeguards
Future legal precedents and community discussion
Listen ad-free on Castria