Who should be held responsible for a cyberattack involving a 'rogue' AI agent?[1] Events over the past few months indicate that this is a question organisations, policymakers, courts, and regulators are increasingly likely to have to grapple with.
In 2025, incidents affecting UK retailers and Jaguar Land Rover grabbed headlines globally as examples of how cyberattacks can materially disrupt critical businesses and, in the case of Jaguar Land Rover, affect national economic performance.
Now in 2026, the US' Hugging Face and Australia's Medicare incidents are in the spotlight. It was not unexpected that cyberattacks would continue to draw attention as 'threat actors' aren't going anywhere anytime soon and continue to evolve their tactics. However, this year feels different.
While those working in the cyber industry can become somewhat desensitised to such incidents by responding to them on a daily basis, mainstream media has presented to broader society concerning headlines such as "AI staff genuinely frightened for humanity's future"[2].
AI's impact on our society has been a talking point for some time now, but fears in 2026 around the rapid pace of developing AI technology have been heightened by autonomous AI led cyberattacks.
While cybersecurity experts have highlighted that more damaging cyber incidents have recently been overshadowed by the AI 'doomsday hype', it would be neglectful to downplay the valid concerns that AI led cyberattacks, such as Hugging Face and Medicare, have brought to mainstream audiences.
Hugging Face and Medicare
As a general high-level summary, in July 2026 OpenAI had tasked an AI agent with solving hacking/security challenges in what was thought to be an adequately controlled environment (a "sandbox"). The AI agent, in a determined manner to solve the challenges, left its environment and, through unsanctioned collaboration with other AI agents, hacked into Hugging Face[3] to find solutions to the task presented to it by OpenAI. Importantly, to emphasise the autonomous nature of the incident, the human employees of OpenAI did not instruct the AI agent to break into Hugging Face's systems.
While OpenAI did speak to the public about the Hugging Face incident in early August at the Black Hat USA conference, released its own reports about the incident and allowed external researchers to look into it, there were, and continue to be, criticisms that OpenAI's disclosures are limited.
The timing was certainly unfavourable for OpenAI when Australia's Prime Minister, Anthony Albanese, opened an address to the public in September 2026 (shortly after the Hugging Face incident was publicised) with: "…an artificial intelligence agent has infiltrated an Australian government website".[4]
Prime Minister Albanese went on to mention that the incident occurred in June 2026 when OpenAI had an AI agent conduct internet-based research into public medicine spending. This resulted in unauthorised access by the AI agent into the public-facing Australian Medicare[5] statistics reporting service portal, despite OpenAI's guardrails. Once inside the Medicare statistics portal, the AI agent accessed both public and non-public files, albeit of a non-sensitive nature (i.e. no personal data).[6]
Prime Minister Albanese also highlighted the length of time taken by OpenAI to notify the Australian government of the incident (i.e. 10 September) and the way the notification was made (i.e. an email sent to the public mailbox of Services Australia, which was not picked up until 15 September).[7]
While Hugging Face has not sought any enforcement action against OpenAI and has instead taken a collaborative approach to resolving the incident, the approach to be taken by the Australian government remains under review.
The way forward
As highlighted above, these examples of autonomous AI cyberattacks are heightening concerns for lawyers, policymakers, developers, law enforcement, and the general public in relation to whether AI research and development can have 'adequate' safeguards in place given the rate at which the technology is developing. In fact, Sam Altman, CEO of OpenAI, recently announced pausing the training of its latest AI models again until there is greater confidence in its safeguards.
Although a prudent decision by OpenAI, some level of division will remain. For instance, there have been developers stating that the incidents this year emphasise that there is a lack of desperately needed regulation by policymakers who, in response, argue that the issue is the hubris of the developers and those seeking to benefit from the 'AI race'.
While it isn’t necessarily the case that increased regulation would have prevented Hugging Face or the Medicare incidents, what is apparent is that issues such as who is responsible for a rogue AI agent's actions when something goes wrong are likely to become increasingly important.
Past experience (and judicial scrutiny) of non-AI cybersecurity incidents (e.g. funds diversion fraud) may be relevant by analogy. For instance, Company A's systems are breached by a threat actor who then leverages their access to send a fraudulent invoice to Company B. The fraudulent invoice is then inadvertently paid by Company B resulting in its financial loss. In this scenario, it is arguable that Company B should have had its own safeguards in place, despite Company A being the one that was hacked.[8] A similar conclusion could be reached where the 'threat actor' was a rogue AI agent.
While Hugging Face and the Medicare incidents thankfully did not result in financial detriment in this manner, it may only be a matter of time until an incident where an AI agent autonomously causes such loss to another company. If that incident were to eventuate, it could be assumed that the AI developer would be held responsible for it, but the AI developer may argue that the company that was breached did not have its own adequate safeguards in place.
This issue would also be a significant one if an incident occurs which results in unauthorised access to (or loss of) sensitive personal data given, in the UK, data controllers and data processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as per Article 32 of the UK GDPR.[9]
As a result of the evolving nature of cyberattacks and the capabilities of AI, 'appropriate technical and organisational measures' cannot be a static consideration. Therefore, it is important that organisations pause to reflect on what safeguards they currently have in place, as OpenAI have stated that they are doing, and seek to prepare those safeguards for future threats that are becoming increasingly likely.
Ultimately, the way forward no doubt requires transparency and collaboration amongst stakeholders as AI will continue to pose both challenges as well as opportunities for the international community. As UN Secretary-General, António Guterres said with regard to AI at the UN General Assembly in September: “National action is essential, but global coordination is indispensable.”[10]
As a possible indicator of the direction of the 'national action' in the UK, on 14 September the Joint Committee on Human Rights published a report (and associated recommendations) on human rights and the regulation of AI.[11] The report states that the current UK legal framework that applies to AI is fragmented, difficult to navigate, and applies primarily to users at the point of deployment, rather than AI developers. The report recommends a new AI Bill with a risk based approach to AI regulation, together with the prohibition of certain AI use cases which are incompatible with human rights (similar to the EU AI Act). The report also calls for the establishment of a new AI regulator.
[1] An AI model is a system trained on data that can generate outputs from inputs. An AI agent can do more than answer questions. Instead, an AI agent is a system that uses one or more AI models together with tools, memory, and workflows to plan and make decisions in pursuit of achieving an objective with 'limited' human involvement. Of note is that on 29 September, OpenAI unveiled 'Dots' which are always-on agents designed to work proactively and continuously towards users' goals.
[2] AI staff 'genuinely frightened' for humanity's future, ex-Anthropic researcher tells BBC
[3] Hugging Face is one of the major online ecosystems for AI developers (e.g. it is used to share AI models, research, demonstrations etc.). So, from the perspective of an AI agent doing cybersecurity work, Hugging Face is a very interesting place to investigate.
[4] Anthony Albanese announces OpenAI hack on Medicare data portal
[5] Medicare is Australia's universal health insurance scheme.
[6] Anthony Albanese announces OpenAI hack on Medicare data portal
[7] Ibid.
[8] Logix Aero Ireland Ltd v Siam Aero Repair Company Ltd [2025] EWHC 1283 (KB).
[9] Article 32 UK GDPR.
[10] Who should set the rules for AI? The UN is pushing for a safer digital future
[11] Wide-ranging AI Bill needed to address severe human rights risks posed by AI