Ghappour is so confident in these arguments that, if he were representing any of the victims in these cases, he said it would be a “no brainer” to file a lawsuit against OpenAI or Anthropic. At the very least, he explained, he would send letters demanding that the AI companies preserve and share all of their internal records and documents about the hacks, such as incident response reports, and quantify the costs they incurred because of the breaches.
Then, if negotiations with the AI giants failed, he would bring a civil lawsuit based on the CFAA arguing that the AI companies were negligent, and violated privacy and confidentiality.
For now, it’s a game of chicken.
If one of the hacked companies files a civil suit, we will see where the legal case — and the law — lead. If prosecutors decide to bring criminal charges, unlikely as that may be, the outcome could have profound consequences and a potential chilling effect on security research and AI development more broadly.
Without any federal or nationwide AI liability laws, anyone bringing a lawsuit would have to make an entirely novel argument based on existing statutes. It would ultimately be up to a judge or jury to decide whether an AI company broke the law.
In place of a federal law, some states such as California, New York, and Rhode Island are rolling out laws with the goal of enshrining a simple principle: If an AI system or agent does something a human could be held liable for, then the companies that made the AI system should be held liable. These laws are not focused specifically on hacking, but on broader concepts of responsibility and safety in various situations.
As for who is to blame for an AI model’s cyberattack? Morally speaking, the responsibility rests with the executives who run the companies. Legally speaking, though? We’ll have to wait until someone sues to find out.
Discover more from NAIRAVOICE.COM.NG
Subscribe to get the latest posts sent to your email.

