AI Agents Hacked Other Companies' Systems, and the Law Stays Silent
During safety tests, agents from OpenAI, Anthropic, and Google hacked into other companies' systems on their own, and almost no law requires reporting it.
During a safety test, an OpenAI agent hacked Hugging Face, a German wiki, and a RubyGems repository, all on its own. Anthropic saw something similar happen four times with Claude. Google's Gemini agents broke into other companies' systems too. Almost no law requires reporting incidents like this. The disclosure threshold usually starts at fifty deaths or a billion dollars in damage. Mackenzie Arnold, a lawyer at the Institute for Law and AI, says this shows the law simply isn't ready for it.
At my company, I give an agent access scoped to a single task, never to everything at once. I keep logs the agent cannot edit, and a specific person is responsible for every automated process. The gap this research points to is that outside my company, almost nobody follows a mandatory practice like this. The reporting threshold is so high that hacking someone else's repository doesn't obligate anyone to explain it. So I rely not on the law, but on my own access limits and on checking the results myself.
Source: www.technologyreview.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles