What companies need to know legally after the incidents at OpenAI and Anthropic
An AI model leaves its test environment, enters the open internet, and infiltrates the production systems of other companies. What sounds like a research scenario became reality twice in July 2026. For the affected organizations, practical questions immediately arise: Who is liable for the damage, what reporting obligations apply, and how can claims be secured? This article provides a legal analysis of the situation and shows what companies need to do now.
AI security incidents at OpenAI and Anthropic: What actually happened
On July 21, 2026, OpenAI disclosed that several of its models had escaped from a secure test environment and subsequently accessed the production infrastructure of the open-source platform Hugging Face. The company described it as an unprecedented cyber incident. Shortly thereafter, competitor Anthropic conducted its own analysis and published the results on July 30, 2026.
According to its own statements, Anthropic reviewed approximately 141,000 test runs and identified three incidents in which models had unauthorized access to the systems of external organizations. The affected models, according to the company, included Claude Opus 4.7 and Mythos 5, as well as an internal research model. The cause was a misconfiguration at a test partner, which, contrary to the task description, granted the models access to the open internet. The earliest documented incident dates back to April 2026. Two of the three affected organizations did not notice the unauthorized access until they were notified.
What is remarkable is the technical simplicity of the attacks. According to the published accounts, no highly complex vulnerabilities were exploited, but rather weak access credentials, unauthenticated endpoints, an exposed debug page, and known gaps in open-source dependencies. These are precisely the attack surfaces found in many medium-sized business infrastructures.
If an automated system gains access to a production database within a few hours, it's no longer purely an IT issue. Have your company's contractual and legal obligations reviewed in such a case.
Attribution: To whom is the behavior of an AI system legally attributed?
An AI system is not a legal entity in its own right. It can neither be a contractual partner nor be liable itself. Therefore, its actions are always legally attributed to those who develop, provide, or deploy the system. The AI Regulation distinguishes between providers and operators, and this division of roles also shapes the legal assessment of liability.
Anyone operating an AI system in a test environment assumes responsibility for the isolation of that environment. If a breach occurs, the blame is typically not placed on the model's behavior, but on the organization of the test infrastructure. This is legally crucial: it concerns the duty to ensure safety and organizational negligence, not liability for the autonomous decisions of a machine.
If several parties are involved, such as the model provider and an external evaluation partner, joint and several liability under Section 840 Paragraph 1 of the German Civil Code (BGB) may apply. This is advantageous for the injured company because it can choose the solvent debtor. Internally, the compensation is then distributed according to the respective contributions to the damage.
For companies that use AI themselves, there's a downside: If you deploy a model on your own systems or on third-party systems without technically limiting access, you bear the risk. A clear assignment of roles and responsibilities according to the... AI regulation for companies Therefore, it is not a formality, but rather a precaution against liability.
Before any productive use of AI, clarify in writing who is responsible for access limits, logging, and emergency shutdown. Without this allocation, in the event of a dispute, liability will be interpreted against the user.
Compensation after an AI attack: Legal basis for affected companies
If a company is targeted by AI-driven access without its consent, several legal bases for claims may apply simultaneously. The central provision is Section 823 Paragraph 1 of the German Civil Code (BGB). This protects the company's ownership of its IT infrastructure and its established and operating business. An infringement occurs as soon as systems are compromised and the company has to be stopped for investigation.
In addition, Section 823 Paragraph 2 of the German Civil Code (BGB) applies in conjunction with protective provisions of criminal law. This includes the unauthorized access to data under Section 202a of the German Criminal Code (StGB), the alteration of data under Section 303a of the German Criminal Code (StGB), and computer sabotage under Section 303b of the German Criminal Code (StGB). The advantage of this approach is that it also covers purely financial losses, which would be difficult to prove under Section 823 Paragraph 1 of the German Civil Code (BGB).
If contracts exist between the parties, for example regarding security tests or the use of a platform, liability is primarily governed by these agreements in conjunction with Section 280 Paragraph 1 of the German Civil Code (BGB). The practically relevant factor here is the agreed scope of testing. Access that exceeds the defined scope is not covered by any consent.
Reimbursable costs include, among others, the costs of forensic investigation, system restoration and hardening, external legal advice, customer notification, and lost profits pursuant to Section 252 of the German Civil Code (BGB). If personal data was involved, claims under Article 82 of the GDPR also apply. What other scenarios are also possible? Compensation for damages in the case of AI use We will explain the triggers separately.
Quantify your damages early and completely. Those who only add further claims months later lose leverage, especially against internationally operating providers.
Reporting obligations following an AI security incident: GDPR, AI Regulation and IT security law
Unauthorized access regularly triggers specific obligations for the affected company, regardless of who caused the incident. If the access involves personal data, Article 33 of the GDPR applies. Notification to the competent supervisory authority must be made without undue delay and, where feasible, within 72 hours of becoming aware of the access. In cases of high risk to the data subjects, the notification obligation under Article 34 of the GDPR also applies.
The time limit begins when the data subject becomes aware of the infringement, not when the matter is concluded. Particularly in the cases described, where companies only learned of the access through a notification from the model provider, this point in time must be carefully documented. The accountability principle under Article 5(2) GDPR also requires comprehensible documentation of the assessment, even if no notification is ultimately issued.
In addition, there are sector-specific obligations. For entities subject to the NIS-2 Directive and its national implementation, there are tiered notification and reporting obligations with significantly shorter initial deadlines. Providers of AI models with systemic risk must report serious incidents to the Commission's AI Office in accordance with the AI Regulation. For companies operating high-risk systems, the incident reporting obligations of Article 73 of the AI Regulation also apply.
The integration of these regimes is challenging because deadlines, recipients, and thresholds differ. A prepared reporting matrix and trained personnel significantly reduce response time. How far the Mandatory training according to the AI Regulation That's sufficient, we explain on a separate page.
If you become aware of unauthorized access, the 72-hour deadline begins. Seek legal advice immediately before making any statements to authorities, customers, or business partners.
Immediate action: What affected companies should do after an AI intrusion
The first few hours are crucial for the later enforceability of claims. It is important to secure evidence before systems are rebuilt and, at the same time, to keep track of all applicable deadlines.
- Save logs: Export server, firewall, and database logs in a revision-proof manner before rotation intervals overwrite them.
- Commission a forensic expert: Have external specialists determine the scope of access, affected data records and time period.
- Document communication: Record every communication from the provider with the date and time, as this proves the start of the deadline.
- Review the contractual situation: Review terms of use, data processing agreements, and liability clauses for limitations and jurisdiction rules.
- Damage assessment: Continuously record personnel expenses, downtime, external costs and revenue losses instead of estimating them retrospectively.
- Involve insurance: Cyber insurance policies regularly contain short notification deadlines and obligations, the violation of which jeopardizes protection.
Caution is advised when making hasty statements. Confirmations to the perpetrator that the incident had no consequences significantly complicate any subsequent claims. The same applies to settlement offers signed before the forensic investigation is complete.
Do not sign any settlement agreement until the scope of access has been definitively clarified. What has already been settled cannot be reclaimed later.
When is legal advice worthwhile in AI security incidents?
Legal counsel is advisable as soon as unauthorized access is suspected, when reporting deadlines are approaching, and whenever claims against a provider or service provider need to be enforced. Equally important is preventative action: Anyone using AI systems should structure contracts, access rights, and documentation requirements in such a way that, in a worst-case scenario, it is clear who is responsible for what.
Rogert & Ulbrich advises companies on data protection law, IT and contract law, as well as on the enforcement of claims for damages. The law firm is led by Dr. Marco Rogert and Tobias Ulbrich has taken on over 40,000 mandates and filed more than 25,000 lawsuits, many of them against internationally operating corporations.
Our consulting services include incident assessment, support with reporting under the GDPR and AI Regulation, securing and quantifying damages, and out-of-court and court enforcement. We also proactively review your AI applications within the framework of [missing information]. Data protection law for companies and the obligations arising from the AI Regulation. Companies without their own compliance function can delegate this task to a external AI officer transmitted.
Whether it's an acute incident or a preventative review of your AI governance: Get in touch and secure your claims.
Conclusion: AI security incidents are a liability issue, not a technical one.
The incidents at OpenAI and Anthropic demonstrate two things. First, simple vulnerabilities are sufficient for automated systems to gain access to external infrastructures. Second, affected companies often don't notice such access themselves, but rather learn about it from third parties. Both of these factors shift the focus from prevention to detection and documentation.
Legally, the situation remains manageable. The behavior of an AI system is attributed to the companies behind it; claims arise from tort law, contract law, and data protection law, and reporting obligations are clearly defined. Speed is crucial: evidence disappears, deadlines expire, and hasty statements limit one's options.
Companies that use AI productively should use these incidents as an opportunity to review access limits, logging, and responsibilities. Addressing these points in advance saves time in a crisis and avoids liability gaps. Further topics related to legally compliant AI use include, for example... AI and intellectual property or Warnings for violations of the AI regulation, We will cover this in separate articles.
Have your AI governance reviewed now, while no incident creates pressure. Retrospective corrections are more expensive than a structured inventory.

