As autonomous AI systems become capable of carrying out cyberattacks without direct human control, the question of who is legally responsible grows murkier. SecurityWeek reports that while civil lawsuits may be an option, legal experts believe criminal investigations would encounter an extremely high burden of proof. This stems from the difficulty in showing intent or negligence when an AI acts independently.

The article highlights that no clear legal framework currently exists to assign blame when an AI system initiates a hack. Some experts suggest the operator or developer could be held liable, but others argue that the autonomous nature of the AI breaks the chain of causation. This divergence underscores the uncertainty facing courts and prosecutors.

Until precedents are set, organizations deploying autonomous AI for security or other purposes may operate in a legal gray zone. The report does not offer a definitive solution, but it emphasizes the urgent need for lawmakers to address these questions before incidents become more common.