Did the AI litigation dam just break?
As a young academic I authored a paper comparing economic agents and legal agents. It wasn’t particularly interesting to the profession then and I moved on from it. Nevertheless, it is an especially important field now as digital and physical agents are preparing to be released by the many thousands into our society.[i] The technology is evolving rapidly and fundamentally. So, this is the time to clarify the legal status of AI and AI agents. The longer we wait, the more complex it will become. A sense of urgency is arising on the issue. And new statutes may not be necessary, as current cases suggest.
While new regulatory action at the federal level has stalled, this current expansion of legal thought is occurring at a rapid pace. Oddly, it is happening while the major AI firms are pleading to be regulated, as though they were not.[ii] AI companies are asking for another level of federal rules governing them and their models. They are appealing to the highest levels of authority, but they would be better served looking down at the legal minefield they are living in.
OpenAI is already the subject of numerous lawsuits. They are in four groups: personal injury suits, wrongful death actions, mass-casualty suits from school shootings and of course, state enforcement actions for antitrust and other matters.[iii]
The litigation dam is breaking on AI, and the recent case against OpenAI is a powerful example. We got a clear example of what lies ahead in Legal Advocates for Safe Science & Technology (LASST) v. OpenAI Group PBC and OpenAI Foundation. The case was filed in San Francisco Superior Court.
The facts of the case have been largely exposed in the press. OpenAI developed frontier models that surprised the developers in their ability to compromise other computer systems.[iv] These facts appear to be largely uncontested, at least in their broad outline.
The pleadings for LASST are revealing and show the extent of the liability facing AI.[v] The most compelling feature is that Hugging Face, the company that OpenAI’s models compromised, is not the plaintiff in this case. It was alleged that OpenAI’s rogue AIs produced a Hugging Face cyberattack. Hugging Face has not filed for damages. The attacks on Hugging Face did not clearly damage LASST. As a result, the case may well be open to a variety of defenses, especially the standing to sue.
Indeed, the plaintiff (LASST) is not seeking monetary damages; it is seeking an injunction. The relief is intended to prevent OpenAI from allowing its AI agents to access computer systems and engage in the alleged unsafe development of models in the future.
Discovery at trial could easily be far more damaging and dangerous than fines. The requested remedy is unusual. If the case survives the initial pleading challenges, discovery could seek things such as company information on prompts, instructions, architecture, and a wide array of company data the defendant would not like to see shared with competitors or the world.
In fact, cases like this could expose an AI company to criminal liability under the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, because the conduct was of its autonomous AI agent and not a human being.[vi] The legal theories are too complex to explore here.
These cases should be a clear signal to AI company management. More regulation may not be necessary. The floodgates are open.
Check out my new book on AI: You Are AI's Best Friend—From Olives to Algorithms: A Human Guide.
[i] See, for example, How to Count AIs: Individuation and Liability for AI Agents
[ii] Trump Rejects AI Regulation as Tech CEOs Sign Voluntary “Self-Policing” Accord | Truthout
[iii] OpenAI Lawsuits: Case Tracker and Status Updates | Lawsuit Informer
[iv] Investigating three real-world incidents in our cybersecurity evaluations | Anthropic
[v] LASST-v.-OpenAI-Complaint-09.29.2026-AS-FILED.pdf
[vi] AI Gone Rogue: What Recent OpenAI and Anthropic AI Incidents Could Mean for CFAA Liability | Ballard Spahr