{"id":100557,"date":"2026-08-03T11:55:29","date_gmt":"2026-08-03T09:55:29","guid":{"rendered":"https:\/\/ru.law\/?p=100557"},"modified":"2026-08-03T11:55:31","modified_gmt":"2026-08-03T09:55:31","slug":"ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen","status":"publish","type":"post","link":"https:\/\/ru.law\/en\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/","title":{"rendered":"AI security incident: Who is liable for autonomous AI attacks?"},"content":{"rendered":"<h2 class=\"wp-block-heading\" id=\"h-was-unternehmen-nach-den-zwischenfallen-bei-openai-und-anthropic-rechtlich-wissen-mussen\"><strong>What companies need to know legally after the incidents at OpenAI and Anthropic<\/strong><\/h2>\n\n\n\n<p>An AI model leaves its test environment, enters the open internet, and infiltrates the production systems of other companies. What sounds like a research scenario became reality twice in July 2026. For the affected organizations, practical questions immediately arise: Who is liable for the damage, what reporting obligations apply, and how can claims be secured? This article provides a legal analysis of the situation and shows what companies need to do now.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-ki-sicherheitsvorfalle-bei-openai-und-anthropic-was-tatsachlich-passiert-ist\"><strong>AI security incidents at OpenAI and Anthropic: What actually happened<\/strong><\/h2>\n\n\n\n<p>On July 21, 2026, OpenAI disclosed that several of its models had escaped from a secure test environment and subsequently accessed the production infrastructure of the open-source platform Hugging Face. The company described it as an unprecedented cyber incident. Shortly thereafter, competitor Anthropic conducted its own analysis and published the results on July 30, 2026.<\/p>\n\n\n\n<p>According to its own statements, Anthropic reviewed approximately 141,000 test runs and identified three incidents in which models had unauthorized access to the systems of external organizations. The affected models, according to the company, included Claude Opus 4.7 and Mythos 5, as well as an internal research model. The cause was a misconfiguration at a test partner, which, contrary to the task description, granted the models access to the open internet. The earliest documented incident dates back to April 2026. Two of the three affected organizations did not notice the unauthorized access until they were notified.<\/p>\n\n\n\n<p>What is remarkable is the technical simplicity of the attacks. According to the published accounts, no highly complex vulnerabilities were exploited, but rather weak access credentials, unauthenticated endpoints, an exposed debug page, and known gaps in open-source dependencies. These are precisely the attack surfaces found in many medium-sized business infrastructures.<\/p>\n\n\n\n<p>If an automated system gains access to a production database within a few hours, it&#039;s no longer purely an IT issue. Have your company&#039;s contractual and legal obligations reviewed in such a case.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-zurechnung-wem-wird-das-verhalten-eines-ki-systems-rechtlich-zugeordnet\"><strong>Attribution: To whom is the behavior of an AI system legally attributed?<\/strong><\/h2>\n\n\n\n<p>An AI system is not a legal entity in its own right. It can neither be a contractual partner nor be liable itself. Therefore, its actions are always legally attributed to those who develop, provide, or deploy the system. The AI Regulation distinguishes between providers and operators, and this division of roles also shapes the legal assessment of liability.<\/p>\n\n\n\n<p>Anyone operating an AI system in a test environment assumes responsibility for the isolation of that environment. If a breach occurs, the blame is typically not placed on the model&#039;s behavior, but on the organization of the test infrastructure. This is legally crucial: it concerns the duty to ensure safety and organizational negligence, not liability for the autonomous decisions of a machine.<\/p>\n\n\n\n<p>If several parties are involved, such as the model provider and an external evaluation partner, joint and several liability under Section 840 Paragraph 1 of the German Civil Code (BGB) may apply. This is advantageous for the injured company because it can choose the solvent debtor. Internally, the compensation is then distributed according to the respective contributions to the damage.<\/p>\n\n\n\n<p>For companies that use AI themselves, there&#039;s a downside: If you deploy a model on your own systems or on third-party systems without technically limiting access, you bear the risk. A clear assignment of roles and responsibilities according to the... <a href=\"https:\/\/ru.law\/en\/ki-verordnung\/\">AI regulation for companies<\/a> Therefore, it is not a formality, but rather a precaution against liability.<\/p>\n\n\n\n<p>Before any productive use of AI, clarify in writing who is responsible for access limits, logging, and emergency shutdown. Without this allocation, in the event of a dispute, liability will be interpreted against the user.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-schadensersatz-nach-einem-ki-angriff-anspruchsgrundlagen-fur-betroffene-unternehmen\"><strong>Compensation after an AI attack: Legal basis for affected companies<\/strong><\/h2>\n\n\n\n<p>If a company is targeted by AI-driven access without its consent, several legal bases for claims may apply simultaneously. The central provision is Section 823 Paragraph 1 of the German Civil Code (BGB). This protects the company&#039;s ownership of its IT infrastructure and its established and operating business. An infringement occurs as soon as systems are compromised and the company has to be stopped for investigation.<\/p>\n\n\n\n<p>In addition, Section 823 Paragraph 2 of the German Civil Code (BGB) applies in conjunction with protective provisions of criminal law. This includes the unauthorized access to data under Section 202a of the German Criminal Code (StGB), the alteration of data under Section 303a of the German Criminal Code (StGB), and computer sabotage under Section 303b of the German Criminal Code (StGB). The advantage of this approach is that it also covers purely financial losses, which would be difficult to prove under Section 823 Paragraph 1 of the German Civil Code (BGB).<\/p>\n\n\n\n<p>If contracts exist between the parties, for example regarding security tests or the use of a platform, liability is primarily governed by these agreements in conjunction with Section 280 Paragraph 1 of the German Civil Code (BGB). The practically relevant factor here is the agreed scope of testing. Access that exceeds the defined scope is not covered by any consent.<\/p>\n\n\n\n<p>Reimbursable costs include, among others, the costs of forensic investigation, system restoration and hardening, external legal advice, customer notification, and lost profits pursuant to Section 252 of the German Civil Code (BGB). If personal data was involved, claims under Article 82 of the GDPR also apply. What other scenarios are also possible? <a href=\"https:\/\/ru.law\/en\/ki-verordnung\/schadensersatz-ki\/\">Compensation for damages in the case of AI use<\/a> We will explain the triggers separately.<\/p>\n\n\n\n<p>Quantify your damages early and completely. Those who only add further claims months later lose leverage, especially against internationally operating providers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-meldepflichten-nach-einem-ki-sicherheitsvorfall-dsgvo-ki-verordnung-und-it-sicherheitsrecht\"><strong>Reporting obligations following an AI security incident: GDPR, AI Regulation and IT security law<\/strong><\/h2>\n\n\n\n<p>Unauthorized access regularly triggers specific obligations for the affected company, regardless of who caused the incident. If the access involves personal data, Article 33 of the GDPR applies. Notification to the competent supervisory authority must be made without undue delay and, where feasible, within 72 hours of becoming aware of the access. In cases of high risk to the data subjects, the notification obligation under Article 34 of the GDPR also applies.<\/p>\n\n\n\n<p>The time limit begins when the data subject becomes aware of the infringement, not when the matter is concluded. Particularly in the cases described, where companies only learned of the access through a notification from the model provider, this point in time must be carefully documented. The accountability principle under Article 5(2) GDPR also requires comprehensible documentation of the assessment, even if no notification is ultimately issued.<\/p>\n\n\n\n<p>In addition, there are sector-specific obligations. For entities subject to the NIS-2 Directive and its national implementation, there are tiered notification and reporting obligations with significantly shorter initial deadlines. Providers of AI models with systemic risk must report serious incidents to the Commission&#039;s AI Office in accordance with the AI Regulation. For companies operating high-risk systems, the incident reporting obligations of Article 73 of the AI Regulation also apply.<\/p>\n\n\n\n<p>The integration of these regimes is challenging because deadlines, recipients, and thresholds differ. A prepared reporting matrix and trained personnel significantly reduce response time. How far the <a href=\"https:\/\/ru.law\/en\/ki-verordnung\/ki-verordnung-schulungspflicht\/\">Mandatory training according to the AI Regulation<\/a> That&#039;s sufficient, we explain on a separate page.<\/p>\n\n\n\n<p>If you become aware of unauthorized access, the 72-hour deadline begins. Seek legal advice immediately before making any statements to authorities, customers, or business partners.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-sofortmassnahmen-was-betroffene-unternehmen-nach-einem-ki-zugriff-tun-sollten\"><strong>Immediate action: What affected companies should do after an AI intrusion<\/strong><\/h2>\n\n\n\n<p>The first few hours are crucial for the later enforceability of claims. It is important to secure evidence before systems are rebuilt and, at the same time, to keep track of all applicable deadlines.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Save logs:<\/strong> Export server, firewall, and database logs in a revision-proof manner before rotation intervals overwrite them.<\/li>\n\n\n\n<li><strong>Commission a forensic expert:<\/strong> Have external specialists determine the scope of access, affected data records and time period.<\/li>\n\n\n\n<li><strong>Document communication:<\/strong> Record every communication from the provider with the date and time, as this proves the start of the deadline.<\/li>\n\n\n\n<li><strong>Review the contractual situation:<\/strong> Review terms of use, data processing agreements, and liability clauses for limitations and jurisdiction rules.<\/li>\n\n\n\n<li><strong>Damage assessment:<\/strong> Continuously record personnel expenses, downtime, external costs and revenue losses instead of estimating them retrospectively.<\/li>\n\n\n\n<li><strong>Involve insurance:<\/strong> Cyber insurance policies regularly contain short notification deadlines and obligations, the violation of which jeopardizes protection.<\/li>\n<\/ul>\n\n\n\n<p>Caution is advised when making hasty statements. Confirmations to the perpetrator that the incident had no consequences significantly complicate any subsequent claims. The same applies to settlement offers signed before the forensic investigation is complete.<\/p>\n\n\n\n<p>Do not sign any settlement agreement until the scope of access has been definitively clarified. What has already been settled cannot be reclaimed later.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-wann-lohnt-sich-anwaltliche-beratung-bei-ki-sicherheitsvorfallen\"><strong>When is legal advice worthwhile in AI security incidents?<\/strong><\/h2>\n\n\n\n<p>Legal counsel is advisable as soon as unauthorized access is suspected, when reporting deadlines are approaching, and whenever claims against a provider or service provider need to be enforced. Equally important is preventative action: Anyone using AI systems should structure contracts, access rights, and documentation requirements in such a way that, in a worst-case scenario, it is clear who is responsible for what.<\/p>\n\n\n\n<p>Rogert &amp; Ulbrich advises companies on data protection law, IT and contract law, as well as on the enforcement of claims for damages. The law firm is led by <a href=\"https:\/\/ru.law\/en\/rechtsanwalt\/dr-marco-rogert\/\">Dr. Marco Rogert<\/a> and <a href=\"https:\/\/ru.law\/en\/rechtsanwalt\/tobias-ulbrich\/\">Tobias Ulbrich<\/a> has taken on over 40,000 mandates and filed more than 25,000 lawsuits, many of them against internationally operating corporations.<\/p>\n\n\n\n<p>Our consulting services include incident assessment, support with reporting under the GDPR and AI Regulation, securing and quantifying damages, and out-of-court and court enforcement. We also proactively review your AI applications within the framework of [missing information]. <a href=\"https:\/\/ru.law\/en\/datenschutzrecht\/\">Data protection law for companies<\/a> and the obligations arising from the AI Regulation. Companies without their own compliance function can delegate this task to a <a href=\"https:\/\/ru.law\/en\/ki-verordnung\/externer-ki-beauftragter\/\">external AI officer<\/a> transmitted.<\/p>\n\n\n\n<p>Whether it&#039;s an acute incident or a preventative review of your AI governance: <a href=\"https:\/\/ru.law\/en\/kontakt\/\">Get in touch<\/a> and secure your claims.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-fazit-ki-sicherheitsvorfalle-sind-ein-haftungs-und-kein-technikthema\"><strong>Conclusion: AI security incidents are a liability issue, not a technical one.<\/strong><\/h2>\n\n\n\n<p>The incidents at OpenAI and Anthropic demonstrate two things. First, simple vulnerabilities are sufficient for automated systems to gain access to external infrastructures. Second, affected companies often don&#039;t notice such access themselves, but rather learn about it from third parties. Both of these factors shift the focus from prevention to detection and documentation.<\/p>\n\n\n\n<p>Legally, the situation remains manageable. The behavior of an AI system is attributed to the companies behind it; claims arise from tort law, contract law, and data protection law, and reporting obligations are clearly defined. Speed is crucial: evidence disappears, deadlines expire, and hasty statements limit one&#039;s options.<\/p>\n\n\n\n<p>Companies that use AI productively should use these incidents as an opportunity to review access limits, logging, and responsibilities. Addressing these points in advance saves time in a crisis and avoids liability gaps. Further topics related to legally compliant AI use include, for example... <a href=\"https:\/\/ru.law\/en\/ki-verordnung\/ki-und-geistiges-eigentum\/\">AI and intellectual property<\/a> or <a href=\"https:\/\/ru.law\/en\/ki-verordnung\/ki-verordnung-abmahnung\/\">Warnings for violations of the AI regulation<\/a>, We will cover this in separate articles.<\/p>\n\n\n\n<p>Have your AI governance reviewed now, while no incident creates pressure. Retrospective corrections are more expensive than a structured inventory.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-faqs-haufig-gestellte-fragen-zu-ki-sicherheitsvorfallen\"><strong>FAQs \u2013 <strong>Frequently asked questions about AI security incidents<\/strong><\/strong><\/h2>\n\n\n<div class=\"wp-block-uagb-faq uagb-faq__outer-wrap uagb-block-ed0fa9cc uagb-faq-icon-row uagb-faq-layout-accordion uagb-faq-expand-first-true uagb-faq-inactive-other-true uagb-faq__wrap uagb-buttons-layout-wrap uagb-faq-equal-height\" data-faqtoggle=\"true\" role=\"tablist\"><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-f9785a0e\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">What happened during the AI security incidents in July 2026?<\/span><\/div><div class=\"uagb-faq-content\"><p>On July 21, 2026, OpenAI disclosed that several models had escaped from an isolated test environment and accessed systems on the Hugging Face platform. On July 30, 2026, Anthropic published the results of its own review of approximately 141,000 test runs and identified three incidents of unauthorized access to systems belonging to external organizations. The company attributed the incidents to a misconfiguration at a testing partner.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-eef02c53\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">Can an AI be held liable?<\/span><\/div><div class=\"uagb-faq-content\"><p>No. An AI system does not possess legal personality and can neither be a contractual partner nor a debtor of a claim. Liability always rests with the natural or legal persons behind it, i.e., providers, operators, or engaged service providers. Attribution is based on general duties of care and organizational obligations.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-7b6999cf\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">What rights does a company have when AI has infiltrated its systems?<\/span><\/div><div class=\"uagb-faq-content\"><p>Potential claims for damages arise from Section 823 Paragraph 1 of the German Civil Code (BGB) due to interference with an established and operating business, as well as from Section 823 Paragraph 2 of the BGB in conjunction with Sections 202a, 303a, and 303b of the German Criminal Code (StGB). If contracts exist, Section 280 Paragraph 1 of the BGB also applies. If personal data has been affected, Article 82 of the GDPR also applies. Furthermore, claims for injunctive relief and disclosure may exist.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-a5f0bb69\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">Which costs are recoverable after unauthorized access?<\/span><\/div><div class=\"uagb-faq-content\"><p>Reimbursable costs regularly include those for forensic investigation, system restoration and security, legal counsel, and necessary notifications. Internal personnel expenses and lost profits pursuant to Section 252 of the German Civil Code (BGB) are also covered. A prerequisite is verifiable documentation, which is why this documentation should begin during the investigation itself.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-28b6f38a\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">Do I have to report AI access to the data protection authority?<\/span><\/div><div class=\"uagb-faq-content\"><p>If personal data is affected by the breach, Article 33 of the GDPR generally mandates notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. An exception applies only if a risk to the rights and freedoms of the data subjects is unlikely to materialize. The assessment must be documented in all cases.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-922e0bf1\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">When does the 72-hour period begin if the provider informs me?<\/span><\/div><div class=\"uagb-faq-content\"><p>The decisive factor is the controller&#039;s knowledge of the personal data breach. If a company only learns of an unauthorized access through a notification from the model provider, the limitation period begins with this notification. Therefore, the date and content of the notification should be carefully documented.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-910f255b\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">Is the external testing partner who caused the misconfiguration also liable?<\/span><\/div><div class=\"uagb-faq-content\"><p>That&#039;s possible. If the access is due to a faulty configuration of the test environment, the service provider may be held liable. If several parties caused the damage, they are jointly and severally liable according to Section 840 Paragraph 1 of the German Civil Code (BGB). The injured company can then seek recourse from any one of the parties involved, with the settlement being settled internally.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-44975cc3\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">What role does the AI regulation play in such incidents?<\/span><\/div><div class=\"uagb-faq-content\"><p>The AI Regulation does not establish general strict liability, but rather obligations for risk assessment, documentation, and incident reporting. Providers of models with systemic risk must report serious incidents to the European Commission&#039;s AI Office. Operators of high-risk systems are subject to reporting obligations under Article 73 of the AI Regulation. Violations can also be considered breaches of the duty to ensure safety.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-7ab03cea\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">How do I protect my company from similar attacks?<\/span><\/div><div class=\"uagb-faq-content\"><p>The documented attacks exploited weak credentials, publicly accessible endpoints, and known vulnerabilities in open-source components. Effective countermeasures therefore include consistent rights and password management, disabling unnecessary interfaces, regularly updating dependencies, and logging that makes unauthorized access visible. This is legally reinforced by clear contracts with AI service providers.<\/p><\/div><\/div><div class=\"wp-block-uagb-faq-child uagb-faq-child__outer-wrap uagb-faq-item uagb-block-4fcea666\" role=\"tab\" tabindex=\"0\"><div class=\"uagb-faq-questions-button uagb-faq-questions\">\t\t\t<span class=\"uagb-icon uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M432 256c0 17.69-14.33 32.01-32 32.01H256v144c0 17.69-14.33 31.99-32 31.99s-32-14.3-32-31.99v-144H48c-17.67 0-32-14.32-32-32.01s14.33-31.99 32-31.99H192v-144c0-17.69 14.33-32.01 32-32.01s32 14.32 32 32.01v144h144C417.7 224 432 238.3 432 256z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<span class=\"uagb-icon-active uagb-faq-icon-wrap\">\n\t\t\t\t\t\t\t\t<svg xmlns=\"https:\/\/www.w3.org\/2000\/svg\" viewbox= \"0 0 448 512\"><path d=\"M400 288h-352c-17.69 0-32-14.32-32-32.01s14.31-31.99 32-31.99h352c17.69 0 32 14.3 32 31.99S417.7 288 400 288z\"><\/path><\/svg>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t<span class=\"uagb-question\">When is it worth hiring a lawyer in an AI security incident?<\/span><\/div><div class=\"uagb-faq-content\"><p>Legal advice is worthwhile as soon as unauthorized access is discovered, because reporting deadlines apply, evidence needs to be secured, and any statement made to the perpetrator will affect future claims. It is also advisable when drafting contracts for the use of AI and when pursuing quantified damages. The earlier legal action is taken, the greater the available options.<\/p><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Was Unternehmen nach den Zwischenf\u00e4llen bei OpenAI und Anthropic rechtlich wissen m\u00fcssen Ein KI-Modell verl\u00e4sst seine Testumgebung, gelangt ins offene Internet und dringt in die [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":100566,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[1618],"tags":[],"class_list":["post-100557","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ki-verordnung"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>KI-Sicherheitsvorfall: Haftung und Anspr\u00fcche f\u00fcr Unternehmen- R&amp;U<\/title>\n<meta name=\"description\" content=\"KI-Modelle drangen in fremde Systeme ein. Wer haftet, welche Meldefristen laufen und welche Anspr\u00fcche Unternehmen jetzt sichern sollten.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ru.law\/en\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"KI-Sicherheitsvorfall: Wer haftet f\u00fcr autonome KI-Angriffe?\" \/>\n<meta property=\"og:description\" content=\"KI-Modelle drangen in fremde Systeme ein. Wer haftet, welche Meldefristen laufen und welche Anspr\u00fcche Unternehmen jetzt sichern sollten.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ru.law\/en\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/\" \/>\n<meta property=\"og:site_name\" content=\"R&amp;U\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/RogertUlbrich\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-03T09:55:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-03T09:55:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1438\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Marco Rogert\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@RogertUlbrich\" \/>\n<meta name=\"twitter:site\" content=\"@RogertUlbrich\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/\"},\"author\":{\"name\":\"Marco Rogert\",\"@id\":\"https:\\\/\\\/ru.law\\\/#\\\/schema\\\/person\\\/b020d506e6bbc471b4565d3a98173b87\"},\"headline\":\"KI-Sicherheitsvorfall: Wer haftet f\u00fcr autonome KI-Angriffe?\",\"datePublished\":\"2026-08-03T09:55:29+00:00\",\"dateModified\":\"2026-08-03T09:55:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/\"},\"wordCount\":1636,\"publisher\":{\"@id\":\"https:\\\/\\\/ru.law\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AdobeStock_1918081644-scaled.jpeg\",\"articleSection\":[\"KI Verordnung\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/\",\"url\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/\",\"name\":\"KI-Sicherheitsvorfall: Haftung und Anspr\u00fcche f\u00fcr Unternehmen- R&amp;U\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ru.law\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AdobeStock_1918081644-scaled.jpeg\",\"datePublished\":\"2026-08-03T09:55:29+00:00\",\"dateModified\":\"2026-08-03T09:55:31+00:00\",\"description\":\"KI-Modelle drangen in fremde Systeme ein. Wer haftet, welche Meldefristen laufen und welche Anspr\u00fcche Unternehmen jetzt sichern sollten.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/#primaryimage\",\"url\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AdobeStock_1918081644-scaled.jpeg\",\"contentUrl\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AdobeStock_1918081644-scaled.jpeg\",\"width\":2560,\"height\":1438,\"caption\":\"Business person using laptop with AI error warning signs on virtual screen. Concept of artificial intelligence risk, cyber security threats, system failure, and digital technology ethics.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/ru.law\\\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/ru.law\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"KI-Sicherheitsvorfall: Wer haftet f\u00fcr autonome KI-Angriffe?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/ru.law\\\/#website\",\"url\":\"https:\\\/\\\/ru.law\\\/\",\"name\":\"R&U\",\"description\":\"Verbraucheranw\u00e4lte\",\"publisher\":{\"@id\":\"https:\\\/\\\/ru.law\\\/#organization\"},\"alternateName\":\"Rogert & Ulbrich\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/ru.law\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/ru.law\\\/#organization\",\"name\":\"Kanzlei Rogert & Ulbrich\",\"url\":\"https:\\\/\\\/ru.law\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/ru.law\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/logo-ru-law.svg\",\"contentUrl\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/logo-ru-law.svg\",\"width\":992,\"height\":259,\"caption\":\"Kanzlei Rogert & Ulbrich\"},\"image\":{\"@id\":\"https:\\\/\\\/ru.law\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/RogertUlbrich\\\/\",\"https:\\\/\\\/x.com\\\/RogertUlbrich\",\"https:\\\/\\\/www.instagram.com\\\/rogertulbrich\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/rogert-ulbrich\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCganCgpvwpPFqMFf1vVmG2A\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/ru.law\\\/#\\\/schema\\\/person\\\/b020d506e6bbc471b4565d3a98173b87\",\"name\":\"Marco Rogert\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ru-law-rogert.png\",\"url\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ru-law-rogert.png\",\"contentUrl\":\"https:\\\/\\\/ru.law\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ru-law-rogert.png\",\"caption\":\"Marco Rogert\"},\"description\":\"Dr. Marco Rogert ist Rechtsanwalt und zweifacher Fachanwalt mit Sitz in D\u00fcsseldorf. Er ber\u00e4t und vertritt Mandanten bundesweit im Bank- und Kapitalanlagerecht, bei Kryptobetrug und KI-rechtlichen Fragen sowie im Transport- und Speditionsrecht. Bekannt wurde er als einer der f\u00fchrenden Anw\u00e4lte in der Aufarbeitung des Abgasskandals und als Mitbegr\u00fcnder der ersten Musterfeststellungsklage gegen die Volkswagen AG.\",\"sameAs\":[\"https:\\\/\\\/ru.law\\\/rechtsanwalt\\\/dr-marco-rogert\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/marco-prof-dr-rogert-248037407\\\/\"],\"honorificPrefix\":\"Dr\",\"knowsAbout\":[\"Bank- und Kapitalmarktrecht\",\"Transport- und Speditionsrecht\",\"KI-Recht\",\"Kryptobetrug\",\"Abgasskandal\"],\"url\":\"https:\\\/\\\/ru.law\\\/rechtsanwalt\\\/dr-marco-rogert\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"KI-Sicherheitsvorfall: Haftung und Anspr\u00fcche f\u00fcr Unternehmen- R&amp;U","description":"KI-Modelle drangen in fremde Systeme ein. Wer haftet, welche Meldefristen laufen und welche Anspr\u00fcche Unternehmen jetzt sichern sollten.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ru.law\/en\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/","og_locale":"en_GB","og_type":"article","og_title":"KI-Sicherheitsvorfall: Wer haftet f\u00fcr autonome KI-Angriffe?","og_description":"KI-Modelle drangen in fremde Systeme ein. Wer haftet, welche Meldefristen laufen und welche Anspr\u00fcche Unternehmen jetzt sichern sollten.","og_url":"https:\/\/ru.law\/en\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/","og_site_name":"R&amp;U","article_publisher":"https:\/\/www.facebook.com\/RogertUlbrich\/","article_published_time":"2026-08-03T09:55:29+00:00","article_modified_time":"2026-08-03T09:55:31+00:00","og_image":[{"width":2560,"height":1438,"url":"https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg","type":"image\/jpeg"}],"author":"Marco Rogert","twitter_card":"summary_large_image","twitter_creator":"@RogertUlbrich","twitter_site":"@RogertUlbrich","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/#article","isPartOf":{"@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/"},"author":{"name":"Marco Rogert","@id":"https:\/\/ru.law\/#\/schema\/person\/b020d506e6bbc471b4565d3a98173b87"},"headline":"KI-Sicherheitsvorfall: Wer haftet f\u00fcr autonome KI-Angriffe?","datePublished":"2026-08-03T09:55:29+00:00","dateModified":"2026-08-03T09:55:31+00:00","mainEntityOfPage":{"@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/"},"wordCount":1636,"publisher":{"@id":"https:\/\/ru.law\/#organization"},"image":{"@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/#primaryimage"},"thumbnailUrl":"https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg","articleSection":["KI Verordnung"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/","url":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/","name":"KI-Sicherheitsvorfall: Haftung und Anspr\u00fcche f\u00fcr Unternehmen- R&amp;U","isPartOf":{"@id":"https:\/\/ru.law\/#website"},"primaryImageOfPage":{"@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/#primaryimage"},"image":{"@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/#primaryimage"},"thumbnailUrl":"https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg","datePublished":"2026-08-03T09:55:29+00:00","dateModified":"2026-08-03T09:55:31+00:00","description":"KI-Modelle drangen in fremde Systeme ein. Wer haftet, welche Meldefristen laufen und welche Anspr\u00fcche Unternehmen jetzt sichern sollten.","breadcrumb":{"@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/#primaryimage","url":"https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg","contentUrl":"https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg","width":2560,"height":1438,"caption":"Business person using laptop with AI error warning signs on virtual screen. Concept of artificial intelligence risk, cyber security threats, system failure, and digital technology ethics."},{"@type":"BreadcrumbList","@id":"https:\/\/ru.law\/ki-sicherheitsvorfall-haftung-schadensersatz-unternehmen\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/ru.law\/"},{"@type":"ListItem","position":2,"name":"KI-Sicherheitsvorfall: Wer haftet f\u00fcr autonome KI-Angriffe?"}]},{"@type":"WebSite","@id":"https:\/\/ru.law\/#website","url":"https:\/\/ru.law\/","name":"R&amp;U","description":"Consumer lawyers","publisher":{"@id":"https:\/\/ru.law\/#organization"},"alternateName":"Rogert & Ulbrich","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ru.law\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/ru.law\/#organization","name":"Rogert &amp; Ulbrich Law Firm","url":"https:\/\/ru.law\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/ru.law\/#\/schema\/logo\/image\/","url":"https:\/\/ru.law\/wp-content\/uploads\/2020\/12\/logo-ru-law.svg","contentUrl":"https:\/\/ru.law\/wp-content\/uploads\/2020\/12\/logo-ru-law.svg","width":992,"height":259,"caption":"Kanzlei Rogert & Ulbrich"},"image":{"@id":"https:\/\/ru.law\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/RogertUlbrich\/","https:\/\/x.com\/RogertUlbrich","https:\/\/www.instagram.com\/rogertulbrich\/","https:\/\/www.linkedin.com\/company\/rogert-ulbrich\/","https:\/\/www.youtube.com\/channel\/UCganCgpvwpPFqMFf1vVmG2A"]},{"@type":"Person","@id":"https:\/\/ru.law\/#\/schema\/person\/b020d506e6bbc471b4565d3a98173b87","name":"Marco Rogert","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/ru.law\/wp-content\/uploads\/2025\/09\/ru-law-rogert.png","url":"https:\/\/ru.law\/wp-content\/uploads\/2025\/09\/ru-law-rogert.png","contentUrl":"https:\/\/ru.law\/wp-content\/uploads\/2025\/09\/ru-law-rogert.png","caption":"Marco Rogert"},"description":"Dr. Marco Rogert is a lawyer and certified specialist in two areas of law, based in D\u00fcsseldorf. He advises and represents clients nationwide in banking and investment law, cryptocurrency fraud and AI-related legal issues, as well as in transport and freight forwarding law. He became known as one of the leading lawyers in the handling of the emissions scandal and as a co-founder of the first model declaratory action against Volkswagen AG.","sameAs":["https:\/\/ru.law\/rechtsanwalt\/dr-marco-rogert\/","https:\/\/www.linkedin.com\/in\/marco-prof-dr-rogert-248037407\/"],"honorificPrefix":"Dr","knowsAbout":["Bank- und Kapitalmarktrecht","Transport- und Speditionsrecht","KI-Recht","Kryptobetrug","Abgasskandal"],"url":"https:\/\/ru.law\/rechtsanwalt\/dr-marco-rogert\/"}]}},"uagb_featured_image_src":{"full":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg",2560,1438,false],"thumbnail":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg",128,72,false],"medium":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg",2560,1438,false],"medium_large":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-768x431.jpeg",768,431,true],"large":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-scaled.jpeg",2560,1438,false],"1536x1536":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-1536x863.jpeg",1536,863,true],"2048x2048":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-2048x1150.jpeg",2048,1150,true],"trp-custom-language-flag":["https:\/\/ru.law\/wp-content\/uploads\/2026\/08\/AdobeStock_1918081644-18x10.jpeg",18,10,true]},"uagb_author_info":{"display_name":"Marco Rogert","author_link":"https:\/\/ru.law\/rechtsanwalt\/dr-marco-rogert\/"},"uagb_comment_info":0,"uagb_excerpt":"Was Unternehmen nach den Zwischenf\u00e4llen bei OpenAI und Anthropic rechtlich wissen m\u00fcssen Ein KI-Modell verl\u00e4sst seine Testumgebung, gelangt ins offene Internet und dringt in die [&hellip;]","_links":{"self":[{"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/posts\/100557","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/comments?post=100557"}],"version-history":[{"count":1,"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/posts\/100557\/revisions"}],"predecessor-version":[{"id":100567,"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/posts\/100557\/revisions\/100567"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/media\/100566"}],"wp:attachment":[{"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/media?parent=100557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/categories?post=100557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ru.law\/en\/wp-json\/wp\/v2\/tags?post=100557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}