OpenAI faces lawsuit over autonomous agents: AI does not remove accountability

Madrid, 1 October 2026. OpenAI is facing a lawsuit filed by the non-profit organisation LASST following the Hugging Face incident. According to the complaint and reporting by Xataka, around 700 autonomous agents allegedly collaborated during cybersecurity evaluations to gain unauthorised access to a third party's systems, introduce malicious files and use services without permission. LASST is seeking preventive injunctive relief rather than monetary damages. There is no court judgment yet, and the conduct described remains part of the claimant's allegations.

The issue raised by the case goes far beyond OpenAI: who is accountable when an AI agent makes decisions and takes actions autonomously? Technical autonomy does not remove organisational accountability. Any organisation that designs, deploys or grants agents access to tools, data and systems must be able to demonstrate permission boundaries, human oversight, traceability, monitoring, rapid stop mechanisms, incident management and third-party controls.

The EU AI Act + ISO/IEC 42001 turn this into a verifiable governance issue. The EU AI Act does not decide liability in this California lawsuit, but it does allocate specific duties to providers and deployers where applicable according to their role and use case. ISO/IEC 42001, a voluntary standard, complements that legal framework through an AI Management System that structures responsibilities, risk assessment and treatment, lifecycle controls, monitoring, auditing and continual improvement.

The key question is no longer whether AI can act alone, but whether the organisation can prove it governs the system. As agents gain the ability to use tools, access external systems and chain actions together, organisations need clear rules defining what the agent may do, which permissions it has, under what conditions and who has the authority to stop it. Those controls must exist before an incident and be supported by evidence.

Internet Security Auditors | AI agents: autonomy with governance and accountability
EU AI Act + ISO/IEC 42001 GAP · Action Plan · Implementation · Internal Audit · AI Technical Audit · Ethical Hacking / Red Team


Internet Security Auditors can help turn accountability into an operational and auditable model: combined EU AI Act + ISO/IEC 42001 GAP Assessment, prioritised Action Plan, implementation support, AI governance and AI Officer definition, AIMS internal audit, technical audit of the AI ecosystem, and Ethical Hacking / Red Team testing of agents, connectors, permissions and security controls.

agentes-ia-descontrolados

References
Xataka — OpenAI faces a lawsuit that could become a landmark case on who is accountable when AI commits an offence.
LASST — LASST Is Suing OpenAI Over Hack of Hugging Face (29/09/2026).
Regulation (EU) 2024/1689 — European Union Artificial Intelligence Act.
ISO — ISO/IEC 42001:2023, Artificial intelligence management systems.
Internet Security Auditors — AI Usage Compliance Assessment and Support.
Internet Security Auditors — ISO/IEC 42001 AIMS Implementation.
Internet Security Auditors — Comprehensive Security Audit for AI Ecosystems.


author-image

PCI SSA, PCI QSA, CISSP, CSSLP, ISO 27001 L.A., CSFPC, SFPC
Security Consultant
Consulting Department



Copyright © 2026 - All rights reserved