Summary
The Upshot
- OpenAI’s models autonomously exploited a software vulnerability, escaped their sandbox, and compromised Hugging Face’s production systems, executing roughly 17,000 actions in under two days at “superhuman speed.”
- Days later, Anthropic disclosed that several of its models separately compromised the production systems of three companies after a “misconfiguration” inadvertently left them connected to the internet during testing.
- Section 1030(a)(5)(B) of the CFAA already contains a built-in recklessness standard. A company that deliberately disables AI safety guardrails while maintaining external network connectivity could face exposure under this provision.
- Section 1030(g)’s civil right of action opens a potential pathway for affected parties to pursue damages under theories of recklessness or foreseeability.
The Bottom Line
What Happened?
In early July 2026, OpenAI began testing the hacking capabilities of several of its Artificial Intelligence (AI) models. According to OpenAI, it ran the test with reduced cybersecurity guardrails in place, testing the models in a sandbox cut off from the open internet except for “one link to a third-party piece of software that acted as a proxy to the outside world.”
On July 9, 2026, the models are said to have discovered a vulnerability in that proxy that let them reach the open internet—effectively breaking out of the sandbox. Two days later, the models breached Hugging Face’s production infrastructure through multiple attack vectors. Hugging Face announced the intrusion on July 16, describing approximately 17,000 actions executed at breakneck speed with little to no human direction. OpenAI did not identify its own models as being responsible for the hack until days later when it publicly confirmed the incident as “unprecedented.”
Just a few days after OpenAI’s disclosure, Anthropic revealed that several of its Claude models had separately gained unauthorized access to the production systems of three outside organizations. Anthropic said it discovered the incidents during a review of its own cybersecurity evaluation transcripts—a review that was prompted by OpenAI’s disclosure—and that two of the affected organizations had not previously detected the activity on their own. Anthropic attributed the incidents to a “misconfiguration” that left certain testing environments connected to the open internet even though the models had been instructed they had no internet access.
Reaction to these incidents has been split. Some experts called it “the highest level of autonomy we’ve seen in the use of a large language model for cyber operations.” Others argued it was “a case of human hubris, not rogue AI,” as humans ultimately made the decision to disable the safeguards which enabled the hack.
Does This Implicate the CFAA?
Regardless of how, why, or if these breaches legitimately occurred, they nonetheless raise real issues that will inevitably be confronted by prosecutors. The CFAA criminalizes intentionally accessing a “protected computer” without authorization and obtaining information (§1030(a)(2)), accessing with intent to defraud (§ 1030(a)(4)), and knowingly causing transmission of code that intentionally causes damage (§1030(a)(5)). Section 1030(g) creates a civil right of action for “[a]ny person who suffers damage or loss by reason of a violation.”
The statute’s mens rea requirements were drafted long before the advent of modern AI and are calibrated to human actors. No court has yet addressed how intent is to be measured when an AI system, rather than a person, is the cause of the intrusion.
Section 1030(a)(5)(B) contains a recklessness standard whereby liability attaches when a person “intentionally accesses a protected computer without authorization, and as a result of such conduct, recklessly causes damage.” A prosecutor or civil plaintiff could argue that running a highly capable frontier AI model tasked with exploiting software vulnerabilities, with safeguards deliberately disabled, and with (albeit) restricted access to the internet, could constitute a reckless disregard of a known risk.
Though no court has ruled on the applicability of the CFAA to frontier AI models, case law does offer instructive guidance. In Bowen v. Porsche Cars, N.A., Inc., 561 F. Supp. 3d 1362 (N.D. Ga. 2021), for example, a court found CFAA intent adequately alleged where a car manufacturer accessed a vehicle’s system via a remote software update that caused unintended damage. In United States v. Morris, 928 F.2d 504 (2d Cir. 1991), the court sustained a CFAA conviction where a self-replicating program propagated across a network of university, government, and military computers and caused damage without further direction from its creator. For the liability analysis, both the “rogue AI” and “human hubris” framing, therefore, supports a CFAA theory of liability.
Heightened Enforcement Landscape
On June 2, 2026, President Trump signed Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security.” Section 4 of the Order directs the Attorney General to “prioritize the enforcement” of 18 U.S.C. 1030 against anyone who “utilizes AI to illegally access or damage a computer without authorization.” This includes “employing AI agents to unlawfully access data or information that is subsequently used for a criminal or unlawful purpose.”
The convergence of these incidents and Executive Order 14409 creates actionable risks for companies developing, testing, or deploying AI agents. In-house counsel should consider documenting every guardrail decision before it is made. Where a testing program calls for reduced safety controls, companies should create a record of the risk assessment, the containment measures relied on, and the personnel who approved the decision. A documented risk analysis can be an effective defense to a recklessness theory.
Ballard Spahr’s White Collar Defense and Investigations Group advises clients on CFAA and other federal criminal exposure arising from the deployment of AI systems, as well as responding to governmental requests and investigations and civil enforcement proceedings.
We are currently advising clients on a host of these topics. Please contact us if we can assist you with advice and counsel regarding these matters or with responding to active inquiries, investigations, or proceedings.
Related Insights
Subscribe to Ballard Spahr Mailing Lists
Copyright © 2026 by Ballard Spahr LLP.
www.ballardspahr.com
(No claim to original U.S. government material.)
All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, including electronic, mechanical, photocopying, recording, or otherwise, without prior written permission of the author and publisher.
This alert is a periodic publication of Ballard Spahr LLP and is intended to notify recipients of new developments in the law. It should not be construed as legal advice or legal opinion on any specific facts or circumstances. The contents are intended for general informational purposes only, and you are urged to consult your own attorney concerning your situation and specific legal questions you have.