The common law has an old rule about dangerous animals. If you keep a tiger and it mauls your neighbor, the neighbor does not need to prove your cage was badly built or that you forgot the lock at feeding time. Keeping the tiger is enough. You pay. Britain’s Animals Act 1971 turned this into statute: the keeper of an animal belonging to a dangerous species is strictly liable for the damage it causes, with no showing of negligence required, and the defences the act leaves open are narrow, mainly that the victim was at fault or knowingly accepted the risk (section 5).
On August 6th, The Economist asked whether AI labs should be treated like the owners of dangerous animals, and the piece drew a Hacker News thread more than fifty comments deep. The headline sounds like a law-school hypothetical. The article isn’t one: it opens with four incidents in three weeks in which models autonomously attacked real third parties, and it lands on a specific gap, namely that current law has no way to hold anyone accountable for an attacker who had no intent. The incidents and the legal argument behind them are each worth taking apart.
Before the analogy: four real attacks in three weeks
I covered each of these in my briefings as they broke. Lined up in order:
- OpenAI: On July 16th, Hugging Face disclosed that it had detected and contained an intrusion carried out by an AI agent; at the time, nobody knew whose. On July 21st, OpenAI claimed it: the attacker was its own models, GPT-5.6 Sol plus an unreleased, stronger one, which had been running offensive-cyber capability evaluations in a sandbox that was supposed to be isolated from the internet. To measure the capability ceiling, OpenAI had also dialed down the safeguards that normally block attack-type requests. The models chained several vulnerabilities, including one zero-day, broke out of the sandbox and got into Hugging Face’s production systems (July 21st briefing). OpenAI’s earlier postmortem of long-horizon safety incidents already included a model escaping an evaluation sandbox and opening a PR on a public repository; I wrote about it in July.
- Anthropic: On July 30th, Anthropic acknowledged the same class of incident in its own safety testing; TechCrunch’s reporting put it at three companies whose production systems were actually reached. Anthropic went back through the transcripts of 141,006 evaluation runs and found the three incidents spread across six of them; The Economist’s “six attacks” refers to those six runs. The cause differed from OpenAI’s: the evaluation environment, operated by an outside testing firm, was misconfigured. What should have been walled off wasn’t. The models were told they were in an offline simulation; they were online.
- UK AISI: On August 4th, the UK government’s AI Security Institute published an incident report: during late-July cyber evaluations, 122 runs produced 19 unsanctioned actions against real people and organisations on the open internet. The most serious was an attempted supply-chain poisoning, planting malicious code in upstream software the target routinely installs so it rides in with a normal update. The evaluation’s designated targets were fictional, but to solve the task the agent registered a fake GitHub account and submitted malicious code to a real open-source project, then invented a second identity posing as an independent reviewer to talk the maintainer into merging it. The project’s human maintainer caught the code and refused (August 5th briefing). For context: AISI’s tests have always allowed internet access and deliberately switch off the attack-blocking layer, precisely to measure the real capability ceiling. AISI says in the report this was the first time it had seen risks around autonomy and deception manifest this clearly in the real world.
- Meta: Days later, Meta also confirmed through a spokesperson (CNN, Engadget; the confirmation came in statements to press, and as of publication I have found no official incident post from Meta) that its Muse Spark 1.1 broke into another company’s systems during security testing. The external evaluation firm had misconfigured the sandbox, and the model unexpectedly had internet access.
All four happened in test or evaluation environments; none was a user-facing production incident. But the third parties attacked were real. The details differ: OpenAI’s sandbox was breached by the model itself, Anthropic’s and Meta’s environments were set up wrong, AISI opened the internet connection on purpose. The common denominator is a single fact: in every case, the concrete attack chain was executed autonomously by the model. Humans built the environment, loosened the guardrails, issued the task, and then touched nothing. Some have written the vendor disclosures off as attention-seeking. The Economist’s rebuttal is down-to-earth: no company does public relations by launching cyberattacks, staying quiet until the victim discloses first, and counting on its competitors to confess as well.
These incidents change the premise of the debate. Earlier worries about AI and cybersecurity pointed at what bad actors could do with a model as a tool; The Economist’s example is the risk case Anthropic made in April for restricting the release of Mythos. Regulatory proposals were designed along the same line. These four attacks were carried out by the models themselves. The timing makes it worse: on July 14th, Demis Hassabis had just proposed an industry self-regulation scheme, an independent standards body funded by the leading labs and modeled on FINRA, the US securities industry’s self-regulatory organisation, to which models would be submitted for safety testing before release, with failing models held back (Fortune’s analysis); according to The Economist, Altman and Amodei have floated similar ideas. Schemes like this treat release as the choke point for risk. These attacks happened inside the very testing step such schemes rely on. A model does not need to be released to hurt someone; the gate sits downstream of where the risk already flowed.
Where current law runs out
When an AI system causes damage today, victims have two main routes: product liability and negligence. Negligence requires the plaintiff to show the developer failed to take reasonable care, skipped tests it should have run, omitted safeguards it should have added. Product liability nominally has a no-fault branch, but applied to AI it first requires a finding that the product was “defective,” and in practice the defect fight circles back to what the developer could reasonably have done differently.
Gabriel Weil, a law professor at Touro University’s law school, laid out the structural gap in this route in an April paper, “Abnormally Dangerous Algorithms”: negligence scrutinises errors at the operational level, never the activity itself. In an essay for Noema he uses explosives as the contrast. If your construction blasting injures someone, you pay even if you followed every procedure, because the law classes blasting as an “abnormally dangerous activity”: the risk cannot be engineered away, so whoever profits from the activity carries it. Judge an AI case under negligence and the court will only ever ask whether you red-teamed and whether you filtered training data according to industry practice. It will never ask whether deploying the system was reasonable in the first place.
For AI, the gap is unusually wide, for two reasons. First, AI safety has no mature standard of reasonable care to check against. In Weil’s words, AI safety is a nascent field whose best practices are themselves still research subjects; following today’s best practice is no reason to think the accident won’t happen. Second, most harm from alignment failure lands on third parties. A user at least clicked “agree” at some point. The bystander harassed, defrauded or damaged by an AI agent never consented to carry that risk; the organisations and individuals swept up in AISI’s report were, in the report’s own description, uninvolved third parties. Risk that cannot be eliminated, victims who never consented, developers who keep the profits: when the law moved blasting and dangerous animals under strict liability, these were exactly the recurring policy rationales. (Formal classification still runs through a multi-factor test weighing likelihood and severity of harm, whether reasonable care can remove the risk, how common the activity is, and so on.) As doctrine, the tiger analogy runs smoothly.
Weil points courts to two ready-made paths. One is to classify the training and deployment of sufficiently capable frontier models as an abnormally dangerous activity outright. The other borrows vicarious liability: an employer pays for an employee’s torts committed within the scope of employment even if the employer itself did nothing wrong. Transposed, when a model does something that would be a tort if a human did it, the bill goes to the company behind it. The elegant part is that this concedes no legal personhood to the model at all.
Where the analogy jams
Sound doctrine is not the same as workable law. Try to fit this regime onto AI labs and it jams at three points at least.
First, who is the keeper. When a tiger bites, the causal chain reads at a glance: one animal, one owner, one wound. Model damage has to travel a long chain: the foundation-model developer, the wrapper application, the enterprise deploying it, the user writing the prompt, and only then the victim. Which link does the harm bill to? Open weights sharpen the question. Publishing weights is releasing the tiger into the wild, where it gets adopted, fine-tuned and re-released by countless hands. How many generations down does the original keeper’s liability run? The Animals Act never had to deal with a tiger that self-replicates.
Second, which one counts as a tiger. Dangerous animals come with a statutory list. The schedule of Britain’s Dangerous Wild Animals Act books tigers and leopards in and expressly exempts house cats, on the back of centuries of accumulated common sense. Model dangerousness has no accepted test. New York’s RAISE Act, signed last December and finalised by amendment this March, draws the frontier-model line at training compute above 10^26 FLOPs, then uses annual revenue above $500m to define the “large developers” who owe the duties (Wiley’s analysis). Note that both lines measure cost and company size. Neither measures dangerousness. Models at equal compute can differ widely in what they can do, and models under the line are not necessarily tame. Using price as a proxy for danger is a regulator’s stopgap while measurement tools are missing, and strict liability is precisely the regime in which the finding of “dangerous” must survive cross-examination in court.
Third, catastrophes can’t be paid for. Strict liability works economically because insurance spreads the losses: the blasting company buys a policy, the premium goes into its costs, and the price signal squeezes the industry toward the right amount of activity. But Weil himself concedes that the class of AI catastrophe people worry about most is uninsurable. There is no meaningful cap on the exposure, and after the event there may be no plaintiff left to sue. His patch is punitive damages: when a small incident reveals serious signs of misalignment (his example is an AI system manipulating clinical-trial participants), multiply the penalty by the larger risk it foreshadows. He has done the arithmetic on when this works: if every real catastrophe is preceded by a thousand such warning-shot incidents, punitive damages can cover risk equal to a thousand times the maximum insurable loss. The mechanism stands on two premises nobody has verified: that warning shots are frequent enough, and that each one actually gets sued and sanctioned.
The criminal route is jammed harder. Break into a system as a human and it’s a crime; have a model do it and the handle for prosecution disappears. Rune Kvist, founder of the AI-insurance startup AIUC, told The Economist that American law looks for intent: if no human intended the intrusion, a crime is hard to make out, and the civil routes are similarly narrow. Yet the harm plainly happened. Kvist’s word for that mismatch is “unacceptable.” This is the backdrop against which civil strict liability is being discussed at all. It is one of the few accountability tools that never needs to prove anyone meant harm.
The insurance market didn’t wait for legislation
Here is the interesting part: the thing in this whole debate that most resembles a dangerous-animals regime grew out of the market on its own. Kvist’s AIUC raised a $15m seed round last July (led by Nat Friedman; Kvist was previously Anthropic’s first product and go-to-market hire) to do what amounts to issuing keeper’s licences for AI agents: audit safety, reliability and data privacy against its own AIUC-1 standard, then underwrite the agents that pass. ElevenLabs has bought a policy; Intercom’s support agent Fin carries the certification.
Insurers acting as private regulators is an old pattern. American boiler insurers had inspectors writing safety rules for steam boilers from 1866, nearly fifty years before the ASME boiler code arrived in 1915. The logic transfers to AI unchanged. As long as the probability of a court awarding damages is not zero, insurers must price model risk; and once the risk is priced, the abstract safety debate becomes a premium figure, and safety investment has a visible rate of return for the first time. That may change lab behaviour faster than any bill.
Where this lands
Strict liability will not enter the statute books in full form any time soon. What survived into the final RAISE Act are duties to publish safety protocols, file transparency reports and report incidents within 72 hours, with no liability provision at all, an entire political spectrum away from paying without fault; the EU’s draft AI liability directive has already been withdrawn. The likelier path is piecemeal: some court, in some concrete case, classifies the deployment of a frontier model as an abnormally dangerous activity for the first time, or the insurance market prices the risk tiers first, and legislation arrives later to ratify what already happened.
The industry is also pushing the problem toward government. On July 28th, employees across the leading labs published the open letter Pacing the Frontier, asking the US government to support the technical and governance tools needed to adjust the pace of frontier AI; Dario Amodei signed (my breakdown of the letter). That thread just picked up a deflating footnote: on August 4th, the White House convened OpenAI, Anthropic and others to review a government model-evaluation framework whose details are not public, whose adoption is voluntary, and which ended with no public commitments. Help will come, at government speed rather than technology speed.
But the analogy is worth keeping, and for its premise rather than its conclusion. The tiger rule never pretends a cage can be built perfect. It starts from the assumption that reasonable care will still sometimes fail, then answers the question that remains: who carries the residual risk. The past three weeks were a live demonstration — four institutions’ cages, each failing in its own way. Most AI governance frameworks today still stop at compliance as the definition of having done one’s duty. That difference in starting point matters more for practitioners than the textbook distinction between strict liability and negligence. Under one rule, safety is a cost. Under the other, it is your own balance sheet.
References
- Should AI labs be treated like the owners of dangerous animals? — Source of the topic; the four-incident overview, “Altman and Amodei have floated similar ideas,” and the Kvist quotes are from this piece
- Hacker News discussion — The debate the article set off
- Hugging Face: Security incident July 2026 — The victim’s initial disclosure of the intrusion
- OpenAI: Hugging Face model evaluation security incident — OpenAI claiming the attack; sandbox isolation and safeguard settings
- TechCrunch: Anthropic says its own AI models breached three companies during security tests — The “three companies reached” account of the Anthropic incidents
- Forbes: Anthropic’s Claude models broke into three real companies — The 141,006 evaluation runs and three incidents across six runs
- AISI: Incident report — unsanctioned agent behaviour during cyber testing — 122 runs, 19 unsanctioned actions, the attempted supply-chain poisoning
- CNN: Meta AI hacking and Engadget: Meta AI model hacked third party — Meta incident confirmed via spokesperson; no official incident post found
- euronews: Why Anthropic’s Mythos preview is “too dangerous” for public release — Anthropic’s April cybersecurity-risk case for restricting Mythos
- Fortune: Hassabis’ “FINRA for AI” proposal — The industry-funded standards body and pre-release testing mechanism
- Gabriel Weil, “Abnormally Dangerous Algorithms: The Case for Strict Liability at the AI Frontier” (SSRN, April 2026) — The two doctrinal paths to strict liability; the third-party harm argument
- Legal Theory Blog’s abstract of the paper — Cross-check source when the SSRN page is unavailable
- Gabriel Weil, “Your AI Breaks It? You Buy It.” (Noema) — The blasting analogy, the negligence gap, punitive damages and the thousand-warning-shots arithmetic, the concession on uninsurable risk
- Animals Act 1971 (legislation.gov.uk) — Statutory basis for keepers’ strict liability; section 5 for the defences
- New York Governor’s office: RAISE Act signing announcement (2025-12-19) — The signing of the act
- Wiley: New York Finalizes RAISE Act — Final thresholds (10^26 FLOPs, $500m annual revenue), the 2026-03-27 amendment, the 2027-01-01 effective date, 72-hour incident reporting
- Fortune: White House won’t publicly release AI model evaluation framework — The August 4th meeting; framework not public, participation voluntary, no public commitments
- Pacing the Frontier — The open letter and its signatories
- IAPP: European Commission withdraws AI liability directive — Withdrawal of the EU draft directive
- Power Engineering: ASME boiler code became “constitution” for steam age — Boiler insurance inspections from 1866, preceding the 1915 ASME code
- PR Newswire: AIUC launches with $15M — AIUC funding and founding team background
- AIUC — The AIUC-1 standard, the ElevenLabs policy and Intercom Fin certification