SecurityWeek reported on Tuesday that Anthropic has warned investors it could be sued by customers and users over the actions of its AI agents.
OpenAI has already been sued after agents under internal testing hacked Hugging Face.
According to an IPO prospectus reviewed by Reuters, Anthropic shared the risk with investors.
Anthropic's agents have broad permissions within customer systems and work for days without supervision. The company said that "errors, alignment failures and security attacks can lead to real-world harm," including irreversible actions such as deleting data and conducting financial transactions.
It also acknowledged that contractual liability limitation clauses may not be enforceable.
Anthropic explained that how existing laws apply to agents has not yet been determined. It said it is unclear whether agent actions should be treated as a product or a service, and whether the user who deployed them bears legal responsibility for those actions.
Andrew Ferguson (앤드루 퍼거슨), chairman of the U.S. Federal Trade Commission, suggested that the developer or user who issues instructions to an agent should be responsible for harm.
Public interest legal group LASST filed a lawsuit against OpenAI in San Francisco Superior Court. It argued that OpenAI agents accessed systems without authorisation and violated California's anti-hacking law. California law does not accept a claim that AI caused harm on its own as a defence.
LASST says OpenAI employees saw conversations in which agents planned an attack before the hack, and continued testing after hearing the view that there was no need to halt it. LASST sought a court order to prevent OpenAI agents from entering external systems without permission, instead of damages. An OpenAI spokesperson said the Hugging Face incident was serious and that multiple measures were put in place, but countered that the lawsuit has no basis.