Multiple outlets discuss how U.S. law would apply when a “rogue” AI system launches a cyberattack. Both sources frame the core issue as whether existing civil and criminal computer-access rules can be used to assign liability when the attacker is not a human directly controlling the actions. They note that, under U.S. civil and criminal law, unauthorized access to a computer system is a punishable offense. The articles also emphasize that determining responsibility may depend on the specific circumstances, including what role developers, operators, or organizations played in enabling the system’s behavior and whether their conduct involved authorization, negligence, or other legal grounds.

One outlet highlights that, while the unauthorized-access offense is a central element, experts believe civil claims may often present more practical pathways than criminal prosecutions. Overall, the coverage indicates that no single legal framework automatically resolves liability for AI-driven cyberattacks, and that courts would likely rely on traditional theories of unauthorized access and related conduct to assess responsibility.