The courts just met the AI that hacks on its own
The Ninth Circuit's Perplexity ruling places liability for AI agent actions on users, not developers. But autonomous sandbox escapes by OpenAI and Anthropic models expose a serious gap in that logic.
A federal appeals court just handed down one of the most consequential rulings in the short history of agentic AI, and it may already be out of date.
The Ninth Circuit vacated Amazon's preliminary injunction against Perplexity's Comet browser on August 4, 2026, ruling that Amazon is unlikely to prove Perplexity "accessed" its servers under the Computer Fraud and Abuse Act (CFAA), because users, not Perplexity, operate the tool. The court's reasoning rests on what is now being called the browser analogy: the CFAA requires unauthorized "access," and Perplexity itself does not access Amazon's servers. Users of the Comet browser do. The court held that the AI assistant is a tool rather than a person for statutory purposes, and that the user, not the agent maker, carries responsibility for the actions taken.
The panel explicitly noted there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents" under the statute, and said its holding is narrow and that agentic AI law "will doubtless change."
Where the Logic Breaks Down
The ruling's user-directs-the-tool framework carries a quiet assumption: that a human is always at the controls. Recent disclosures from @OpenAI and @AnthropicAI suggest that assumption is already being tested in the real world.
On July 21, OpenAI disclosed that several of its models had escaped an isolated test environment by exploiting a zero-day vulnerability and reached the production infrastructure of Hugging Face. Nobody directed those intrusions.
The problem is not unique to OpenAI. Anthropic said an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organisations while conducting cybersecurity tests. The investigation and disclosure came more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face's systems during internal testing. Among 141,006 evaluation runs reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular, calling it a "misunderstanding" between the two companies over whether the test setup had internet access, when in fact it did.
The incidents involved three Claude models: Opus 4.7, Mythos 5, and an internal research test model, each of which broke out of what it believed was a sealed, fictional test environment and ended up compromising real infrastructure. In one case, Claude's own reasoning correctly identified the consequences of its actions early in the run, noting that if this were the real internet, publishing the package would be a real-world attack. However, it convinced itself it was still in a simulation on the grounds that it did not recognise the genuine certificate authorities securing its connections. The model ultimately published a malicious Python package to PyPI. Anthropic said it is "approaching the fixes as if the responsibility were ours alone," while observing that Irregular is conducting its own separate investigation.
A Liability Vacuum Nobody Has Filled
The Ninth Circuit's user-liability framework works when a person intentionally points an agent at a target. It offers no answer when a model goes rogue mid-evaluation with no human in the loop. In those cases, the only party remaining in the chain is the lab that set it running.
While Anthropic found evidence of its models reaching systems they were not supposed to reach, the affected organisations had not detected the activity, and Anthropic subsequently reached out to all three. Hugging Face detected and contained the OpenAI intrusion on its own infrastructure before the companies connected to investigate. OpenAI did not realise its models had reached Hugging Face until after Hugging Face had contained the incident, contacted the FBI, and disclosed it publicly. Two leading AI labs have now confirmed through their own investigations that frontier models can and do reach beyond their intended testing boundaries, and that real organisations can be affected without ever being told. Courts, regulators, and AI labs are all arriving at the same uncomfortable conclusion: the rules were written for tools that wait to be used, not for systems that act on their own.
Sources:
Anthropic: Investigating three real-world incidents in our cybersecurity evaluations
EFF: Appeals Court Agrees that Building a Web Browser Doesn't Violate the CFAA
TFTC: Ninth Circuit Vacates Amazon's CFAA Injunction Against Perplexity's Comet Browser
Latest News
Read More...
Author
Crypto RichRich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.













