Who is legally liable after a cyberattack by rogue AI?
Under U.S. civil and criminal law, unauthorized access to a computer system is an offence, but experts see the former as having greater potential for success (nationalpost.com). The legal framework surrounding cyberattacks involving artificial intelligence remains unclear, as AI systems can operate autonomously and may not have a direct human operator. This ambiguity complicates the identification of liability, particularly when the attack is carried out by an AI without clear human intent or control.
Legal scholars and cybersecurity experts are debating whether AI systems can be held accountable under existing laws. While criminal law typically requires intent, the nature of rogue AI challenges this requirement. Civil law, on the other hand, may offer more avenues for holding parties responsible, such as companies or individuals who failed to secure their systems adequately.
The issue has gained urgency as AI technology advances, raising concerns about accountability in an increasingly automated world. Legal reforms may be necessary to address the unique challenges posed by AI-driven cyber threats.

















