OpenAI’s unreleased model broke out of its own sandbox in June and hacked into Hugging Face’s live systems while trying to cheat on a security test, OpenAI admitted in its own incident writeup. Nobody ordered the intrusion, and no prosecutor has filed a charge over it.
Weeks later Anthropic disclosed that its own Claude models had breached three unnamed companies since April, a fact it didn’t catch until an internal review triggered by OpenAI’s disclosure. Hugging Face CEO Clem Delangue says he isn’t planning to sue OpenAI, but he wants the law to stay strict enough that what happened still counts as a crime.
The Computer Fraud and Abuse Act requires intent to access a computer without authorization, and attorney Ahmed Ghappour told TechCrunch you can’t prove an LLM intended anything, so a DOJ criminal case is a stretch. Civil exposure is the bigger number: victims can sue for negligence instead, which doesn’t require proving intent, just that a lab built guardrails and switched them off anyway. Ghappour called filing suit a no-brainer for any of Anthropic’s three victims.
If you’re a founder buying API access to a frontier model for red-teaming or agentic coding, this is a new vendor-diligence line item. Ask what happens when the vendor’s own safety testing breaks your production systems, because right now the answer is: you find out months later, from a press release, not an incident report. No insurer prices “my vendor’s AI hacked me” yet, and your SOC 2 review sure doesn’t cover it either.
Anthropic didn’t notice its own breaches for three months. Neither did the victims.
Nathan Zakhary