AI agents are quickly moving from experiment to everyday business tool, and a new lawsuit is a timely reminder that when an AI agent causes harm, someone is still responsible. On September 29, 2026, the nonprofit Legal Advocates for Safe Science and Technology (LASST) sued OpenAI in California, seeking to hold the company accountable for the actions of its AI agents, including their role in the July 2026 breach of Hugging Face. At the center of the case is a California law that took effect this year and says, in effect, that "the AI did it" is not a legal defense.
You do not need to be an AI company for this to matter. If your business uses AI tools that can log into systems, send emails, move files, or take other actions on their own, this guide explains what the lawsuit is about, what the law says, and the practical controls every organization should put around its AI agents.
This article is for general information only and is not legal advice. Consult a qualified attorney about your organization's specific obligations.
What Is an AI Agent?
Most people first met AI through chatbots that answer questions. An AI agent goes a step further: it is given goals, tools, and access, and then decides on its own which actions to take. An agent might read your inbox and draft replies, update records in your CRM, run scripts on a server, or browse the web to complete a task.
That autonomy is what makes agents useful. It is also what makes them risky. Every system an agent can reach is a system it can change, and agents can misunderstand instructions, be manipulated by malicious content they read, or simply go further than anyone intended.
What the Lawsuit Claims
LASST's lawsuit argues that OpenAI engaged in "unlawful and unfair business practices." Among its key claims:
- •A business practice that exposes the public to "uncontrolled, self-directed intrusions by systems that OpenAI admits it cannot fully predict or contain is unfair under any weighing of its utility against its consequences."
- •OpenAI was "externalizing the harms of its unsafe decision-making," pointing to the company's August 2026 open letter calling on other organizations and governments to prioritize cyber defenses.
- •The conduct violated several provisions of the California Penal Code and threatens harm to the public.
LASST says it was harmed because it had to divert resources away from its normal work to prepare multiple emergency briefings for regulators about the Hugging Face breach. The suit asks the court for injunctions that would bar OpenAI and its agents from knowingly accessing systems without authorization and from engaging in the alleged unlawful practices under California's Comprehensive Computer Data Access and Fraud Act (CDAFA).
From a new state law to a test case in less than a year.
An unusual plaintiff
Notably, the plaintiff is not Hugging Face, the organization that was actually breached. LASST is suing on behalf of the public under California's Unfair Competition Law. Several SANS NewsBites editors questioned whether LASST's standing is strong enough, and one argued that Hugging Face itself needs to join the suit. Others pointed out that any fine is likely to be small compared to OpenAI's resources. But nearly all agreed on one thing: the precedent may matter far more than the penalty.
The Law That Changes the Conversation
The most important part of this case for business owners is the law it relies on. California Civil Code § 1714.46(b), passed in 2025 and effective January 1, 2026, states:
"In an action against a defendant who developed, modified, or used artificial intelligence that is alleged to have caused a harm to the plaintiff, it shall not be a defense ... that the artificial intelligence autonomously caused the harm to the plaintiff."
Read that carefully. The law covers organizations that
develop, modify, or use AI. It is not limited to the companies that build AI models. A business that deploys an AI agent and lets it act on its behalf may not be able to argue that the agent acted on its own.
Autonomy does not move responsibility away from the people and organizations behind the AI.
SANS NewsBites editors captured the principle well. Ed Skoudis: "Autonomy is not an accountability boundary." And: "'The agent did it' is not an incident-response plan." Brian Honan compared the excuse to "the dog ate my homework," and urged CISOs, data protection officers, and legal teams to follow the case closely.
Why This Matters for Small and Mid-Sized Businesses
Many businesses are now connecting AI assistants and agents to email, calendars, file storage, customer databases, accounting tools, and IT systems. Each connection hands the agent real permissions, often the same permissions as the employee who set it up. Common risks include:
- •Over-permissioned agents that can delete, share, or change far more than their task requires
- •Prompt injection, where malicious instructions hidden in an email, document, or web page trick the agent into taking harmful actions
- •Unmonitored activity, where no one reviews what the agent actually did until something breaks
- •Unclear ownership, where no specific person is responsible for the agent's configuration and behavior
The same week this lawsuit was filed, a Dutch security nonprofit disclosed a breach it believes was carried out by an AI agent exploiting helpdesk software. AI is now showing up on both sides, as a tool businesses rely on and a tool attackers use. In both cases, the fundamentals of access control and monitoring decide the outcome.
Five Controls to Keep Your AI Agents Accountable
A simple framework for any organization deploying AI agents.
1. Define what each agent is allowed to do
Write down each AI agent's purpose, the systems it can touch, and the specific actions it is permitted to take. If an action is not on the list, the agent should not be able to do it.
2. Give agents the least access possible Create dedicated accounts for AI agents rather than letting them borrow an employee's login. Grant only the permissions the task requires, prefer read-only access, and never give an agent administrator rights by default.
3. Keep a human in the loop for high-impact actions
Require human approval before an agent sends payments, deletes data, changes security settings, or contacts customers. Make sure there is a fast, reliable way to pause or shut an agent down.
4. Log and monitor everything the agent does
Record every action an agent takes, send those logs to a central location, and set alerts for unusual behavior, just as you would for a new employee with access to sensitive systems.
5. Assign ownership and involve your legal team
Name a specific person responsible for each agent and its outcomes. Update your acceptable use policy to cover AI tools, review vendor contracts for liability terms, and ask your attorney and insurance provider how existing coverage applies to AI-related incidents. If you operate in the EU, confirm whether and how the EU AI Act applies to the systems you develop or deploy.
Matching controls to risk Not every AI tool needs the same level of oversight. A simple way to start is to sort tools by what they can do:
| Agent capability |
Example |
Minimum controls |
| Read-only |
Summarizes documents or emails |
Defined scope, dedicated account, logging |
| Drafts for review | Writes replies a person sends | All of the above plus human review before sending |
| Takes actions | Updates records, sends messages, runs scripts | All of the above plus approval for high-impact actions, alerting, and a kill switch |
| Administrative access | Changes systems or security settings | Avoid where possible; if required, strict approval, monitoring, and named owner |
Planning to roll out AI tools, or already using them without a clear policy? LBT Technology Group, LLC. helps businesses build AI acceptable use policies, set up least-privilege access, and monitor AI activity so your tools work for you, not against you. Reach out to our team to start the conversation.
The Bottom Line
Whatever happens in LASST v. OpenAI, the direction is clear: organizations will be held responsible for what their AI does. AI agents can save real time and money, but they are not a separate legal person who takes the blame when something goes wrong. Treat each one like a powerful new team member: clear responsibilities, limited access, supervision, and a manager who answers for its work.
Frequently Asked Questions
Does California's AI liability law apply to my business?
The law applies in civil cases in California against defendants who developed, modified, or used AI alleged to have caused harm. Whether it applies to your situation depends on many factors, so consult an attorney. Even outside California, it signals where AI accountability is heading.
We only use off-the-shelf AI tools. Are we still responsible?
Possibly. The law's language covers organizations that "use" AI, not only those that build it. How you configure, connect, and supervise a tool can matter.
What is prompt injection?
Prompt injection is when malicious instructions are hidden in content an AI reads, such as an email, document, or web page, causing it to take actions its user did not intend. Limiting an agent's permissions reduces the damage prompt injection can cause.
Where should we start?
Inventory the AI tools your team already uses, identify which ones can take actions or access sensitive data, and apply the five controls above, starting with the highest-risk tools first.
Sources & Further Reading