“An IBM training manual from 1979 warned that because a computer can never be held accountable, it must never be responsible for a management decision. Forty-seven years later, we see artificial intelligence making such decisions with too little thought from the humans who will likely have to accept the financial fallout if the model misbehaves. Events in the past couple of weeks brought into focus how great a risk that poses.
On July 21, OpenAI disclosed that two of its models had escaped a sealed testing environment, reached the open internet and broken into another company's production systems. The OpenAI models were being evaluated on their cyber capabilities in an isolated sandbox. The models seem to have been looking for a way to cheat the test and found one. Without instruction, the models left the container, used stolen credentials, discovered a previously unknown vulnerability, and entered the servers of AI community platform Hugging Face. Hugging Face on July 16 announced that it had detected and contained the intrusion and reported it to law enforcement -- five days before OpenAI announced it had connected the activity to its own internal testing. OpenAI called the episode unprecedented. Clement Delangue, Hugging Face's chief executive, said he believed there was no malicious intent.
I argued in 2019 that one issue with AI is that its costs would settle on those furthest from the decision to deploy it. Though in this instance the models' deployer and developer were one company, that's unlikely to be the case the next time a model acts up. The next institution in this position will probably be a company that had no hand in developing the AI agent -- a bank, say, running a licensed model that a third party integrated into its systems, on infrastructure the bank itself doesn't control. The Cloud Security Alliance found in February that 84% of organizations surveyed doubted they could pass a compliance audit of their AI agents' behavior or access controls. Only about 1 in 5 maintains a real-time inventory of the agents it is running.
Legally, "the agent acted on its own" isn't a sufficient defense. In October 2025, California Gov. Gavin Newsom signed into law AB 316, barring any defendant who developed, modified or used an AI system from asserting that the AI autonomously caused the harm. The European Union's 2024 revisions of its Product Liability Directive get to a related place by a different route: They bring software and AI systems inside strict product liability and treat any entity that substantially modifies a system, or puts its own name on it, as that product's manufacturer. Legal exposure doesn't evaporate because no human directed the act. But where the financial cost falls isn't clear from this developing regulatory scheme.
At the same time, the financial safety net for companies deploying AI is disappearing. Eleven days before OpenAI's disclosure, the Insurer media outlet published that Verisk's Insurance Services Office confirmed it was weighing coverage exclusions for agentic AI. Verisk had already filed a generative-AI exclusion effective for general liability renewals as of Jan. 1, which insurers across the market have taken up. Carriers, including Chubb, Travelers and W.R. Berkley, have filed to adopt Verisk's form or a generative-AI exclusion in proprietary language. Statutory law is assigning the loss at the same moment the market is writing itself out of it. The liability is real, it is growing, and it sits on nobody's books.
Consider what the victim in the OpenAI case was left with. Hugging Face had no contractual relationship with OpenAI and therefore little leverage. The AI company hasn't committed to Hugging Face's proposed remedy: that OpenAI release a full log of the rogue agents' actions and commit $100 million of compute for the platform's community to build cyber defenses.
None of this is a criticism of the statutes. They answered the question they were written to answer: Who is liable? What they don't do is price the exposure or say who reserves against it. That gap closes through contracts and coverage, not through more legislation.
So the fix isn't a new liability regime. An existing one already applies. The solution is for companies to allocate potential loss before a lawsuit does it for them. Four steps would do it.
First, contracts to deploy AI need to name who has custody of AI agents' decisions. Every agent needs a person of record who owns its actions, identified before deployment and not after an incident.
Second, insurers and companies must clearly assign financial coverage. Each side silently assuming the other will pay in the event of an AI foul-up is the worst outcome for insurers and policyholders alike: The insurer reserves nothing against a crisis it may still be litigated into paying for, and the policyholder discovers the gap only in litigation. Neither has set aside a pot of money, so the policyholder absorbs a potentially crippling loss and the insurer absorbs the coverage fight, the reserve strengthening that follows and the clients who leave once word gets round that the policy didn't answer.
Third, audit rights must be built into AI deployment and vendor contracts. An institution that cannot reconstruct what its agent did cannot defend itself, and neither can its insurer.
Finally, containment must be tested by the deployer, not assumed on the developer's word. OpenAI's sandbox was built by people who take this seriously, and it had been tested. It failed anyway. That is the point: Containment cannot be made perfect, which is why a deployer needs both its own test of the boundary and coverage for the day the boundary doesn't hold.
Regulators will read the Hugging Face episode as a safety story. It is a balance sheet story. Absent much clearer coverage and contractual responsibility assignments than are currently in place, the first institution to learn that its agent acted outside its authority will find the loss already assigned to it, unpriced and unreserved, with a coverage denial arriving in the same week.
The loss won't stop there. It passes to the shareholders of the bank that absorbs it, to the pensioners whose funds hold those shares and to the customers whose data the agent reached on its way out.
Without overt declarations of financial responsibility, agents will still be underwritten -- only by people who were never asked.
---
Mr. Segram is an adjunct assistant professor of finance at the New York University Stern School of Business.” [1]
1. Do You Know Who Pays if Your AI Agent Goes Rogue? Haran Segram. Wall Street Journal, Eastern edition; New York, N.Y.. 05 Aug 2026: A15.
Komentarų nėra:
Rašyti komentarą