AI CEOs Could Be Held Liable For Rogue Model Actions

AI agent management

Insurance companies are reportedly anticipating multimillion-dollar claims related to so-called “rogue” artificial intelligence (AI) agents.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    That’s according to a report Tuesday (Oct. 6) by the Financial Times (FT), which says the situation has insurers and their attorneys worried that CEOs such as Sam Altman of OpenAI and Anthropic’s Dario Amodei could be held liable for the models’ actions.

    Insurance companies have been studying the issue following a series of breaches in which AI agents have broken into other companies systems, such as OpenAI’s breach of the AI company Hugging Face.

    Among those companies is the insurance broker Aon, which has looked at more than 300 AI-related legal cases and found that insurers could also be on the hook for claims under policies dealing with things like crime, intellectual property and cybersecurity.

    However, industry figures told the FT that AI executives could be sued for the models’ acts, with insurers potentially facing claims under “directors and officers” (D&O) insurance policies, which cover executives taken to court over their actions or statements.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    “Ultimately, the OpenAI CEO is liable [for the Hugging Face incident], because there’s an absence of control in their business,” said Tim Rayner, U.K. head of underwriting and claims at Verisk. “So from a directors’ and officers’ perspective, it would come back to him.”

    If OpenAI had purchased D&O insurance, Rayner added, it could try to cover potential future losses from suits targeting Altman.

    “It’s on every CEO to make sure that their business is appropriately governed and controlled,” Rayner said. “AI doesn’t change that.”

    In related news, PYMNTS wrote Monday (Oct. 5) about a new analysis by the International Association of Privacy Professionals (IAPP), which argues that companies need to evaluate agentic AI from both cybersecurity and liability perspectives.

    The analysis expands on a Forbes article by technology executive Emil Sayegh, who contended that companies should treat AI agents as privileged identities. For example, an agent connected to financial software or internal databases might possess credentials and authority on the same level as an employee with sensitive access.

    “That requires companies to answer five foundational questions,” the report added. “Which AI agents are operating, and who owns them? What systems and data can they access? Which actions require human approval? Are their activities monitored? Can their access be revoked immediately?”

    But for IAPP, identifying those controls is just the beginning. Organizations must also consider the speed at which cybercriminals could exploit an agent permitted to execute code, call application programming interfaces or change system configurations.