See more of our coverage in your search results.
OpenAI CEO Sam Altman departs after a meeting with France's President Emmanuel Macron on the sidelines of the 81st United Nations General Assembly in New York, Wednesday, Sept. 23, 2026.
AFP via Getty Images
AI companies are sharing more news of their cutting-edge software behaving badly: potentially tens of thousands of safety incidents, some perhaps including criminal violations — which, if so, can be handled like any other crime, holding the humans behind the tools responsible.
However much the drama queens in tech, media and politics pretend otherwise, “rogue agents” are such only because programmers enable and even encourage it.
These tools aren’t uncontrollable, sentient creatures: The folks behind them are the decision-makers, to blame for whatever harm their products do.
For example, we now know that OpenAI actually disabled multiple “guardrails” in the testing that led to the much-reported Hugging Face incident, among other parameter-setting that opened the door to an AI “swarm” doing a better job of hacking the competition than the testers had expected.
And Sam Altman’s firm paid in cash for whatever damage it did to Hugging Face, avoiding litigation that would’ve cost far more — which shows that these companies have every motive to ensure they don’t do massive harm, lest they lose their shirts.
In another high-profile incident, a different “rogue AI” went after Australian government info, accessing data . . . that was already public. Had it done actual harm, we expect actual damages again would have been paid.
We’ve yet to see news of AI doing any hacking that even approaches what humans already do, including China’s regular raids on US government databases.
The most alarming tales of programs going wrong seem to involve “red team” testing where the companies are trying to get their models to go rogue; that’s why those same companies are now taking a break to add more and better controls to such “frontier” work.
Doing cutting-edge work doesn’t absolve you of criminal responsibility, nor does leaking word of possible violations to Axios or Reuters change that.
If this R&D winds up breaking laws (e.g., with unauthorized access), we should get a handle on what and how that’s happening and impose criminal and/or civil liability where due.
(Incidentally, smart companies should also be training up defensive AIs to protect against criminal hacking: There’s plainly big money to be earned in that, too.)
Programmers and execs may find it useful to talk about their models as if they’re self-willed, but they’re not: If AI agents get on the wrong side of the law, blame and charge the people responsible — their creators and owners.

47 minutes ago
3
English (US)