The recent surge in cyberattacks involving AI agents has jolted the frontier AI sector and sharpened an issue that had long been treated as theoretical: when an autonomous system causes harm, who pays for it? The question is no longer confined to academic debate or policy workshops. It is now a live operational and legal problem, driven by a growing class of AI systems that can plan, act, and adapt with limited human oversight.
In July, OpenAI disclosed that a swarm of its agents had been involved in malicious activity, underscoring how quickly agentic systems can be repurposed or manipulated for harmful ends. The episode added to a broader pattern of concern across the industry, where security researchers and corporate defenders are confronting a new generation of threats that do not merely generate text or code, but can execute tasks, chain actions, and exploit digital systems at machine speed. That shift matters because it blurs the line between a tool and an actor.
Liability Gap Widens
Traditional cybersecurity law was built around human intent, identifiable operators, and software that behaved in relatively predictable ways. AI agents complicate each of those assumptions. If a company deploys an autonomous agent to manage customer service, write code, or interact with external systems, and that agent is hijacked, misaligned, or simply makes a dangerous decision, the legal exposure may be shared across multiple parties: the developer who built the model, the company that configured it, the customer that deployed it, and in some cases the attacker who manipulated it.
That fragmentation is precisely what makes liability so difficult to assign. Product liability law may apply if a system is deemed defective. Negligence claims may arise if a company failed to test, monitor, or constrain an agent adequately. Contract law may govern some enterprise deployments, but those agreements often lag behind the speed of technical change. Insurance markets, meanwhile, are still trying to price risks that are not yet fully understood.
The result is a liability gap. Enterprises want the productivity gains of autonomous systems, but they also want clarity about who bears the cost when those systems go wrong. Vendors, for their part, are eager to market powerful capabilities while limiting their exposure through terms of service, usage restrictions, and disclaimers. Regulators are left trying to determine whether existing frameworks are sufficient or whether AI agents require a distinct legal category.
Security Meets Autonomy
The cybersecurity implications are especially severe because AI agents can compress the time between reconnaissance, exploitation, and exfiltration. A human attacker may need hours or days to probe a target, but an agent can potentially automate those steps across many systems at once. That raises the scale of harm and also the difficulty of attribution. If an attack is launched through an AI system, investigators must determine whether the model was intentionally weaponized, improperly secured, or simply operating within a poorly designed environment.
This is not only a question for governments. Large enterprises are already deploying agentic tools in software development, customer operations, and internal workflows. Each deployment creates a new attack surface. If an agent has access to credentials, databases, or external APIs, a compromise can cascade quickly. Security teams are therefore being pushed to rethink access controls, logging, sandboxing, and human approval thresholds.
The industry response has so far been uneven. Some companies are tightening guardrails, limiting what agents can do without confirmation, or restricting access to sensitive systems. Others are racing ahead, betting that the commercial upside outweighs the risk. That tension is likely to intensify as competition in frontier AI accelerates and as customers demand more autonomous features.
Courts May Set Rules
For now, much of the practical answer may come not from legislatures but from courts, insurers, and enterprise contracts. Judges will eventually have to decide whether an AI agent should be treated as a product component, a service feature, or something else entirely. Insurers will decide which risks are insurable and at what price. Companies will decide how much autonomy they are willing to delegate to systems that can act unpredictably under pressure.
The broader policy debate is shifting as well. If AI agents can independently participate in cyberattacks, then the old distinction between software vulnerability and operational misuse becomes harder to sustain. That could prompt new disclosure rules, tighter model evaluations, mandatory incident reporting, or sector-specific controls for high-risk deployments. It may also force vendors to document more clearly what their systems can do, what they cannot do, and where human supervision remains essential.
The central lesson is that autonomy changes accountability. The more an AI system can do on its own, the more urgent it becomes to define who is responsible when it fails. Until that question is resolved, the legal and commercial architecture around AI agents will remain one step behind the technology itself.
