Thursday, September 24, 2026

If AI Commits a Crime, We Already Know Who to Charge

Would executives of the top AI companies institute more and stronger safety measures if they faced criminal prosecution whenever an autonomous system they created committed a cyberattack or other unlawful acts?


A long row of humanoid robots in a futuristic warehouse, showcasing the advanced state of artificial general intelligence technology.
(Photo: Getty Images)

Les Leopold
Sep 23, 2026
Common Dreams


We don’t need another round of vague promises about AI self-regulation to deal with rogue AI hacking. We already have laws against unauthorized computer access.

If someone intentionally hacks into a corporation’s computer system without authorization, they can be charged with a federal crime under the Computer Fraud and Abuse Act (CFAA). The law covers computers used in or affecting interstate or foreign commerce—which includes a majority of modern corporate and public computer systems.

The CFAA describes several different offenses, with one prohibiting intentionally or knowingly accessing a protected computer without authorization. The penalties can be severe, ranging from one year to twenty years in prison.

But there’s a potential loophole.

What happens when a corporation creates a powerful autonomous program and that program hacks into another corporation, or a public agency, or our bank accounts—and the company says, “Sorry, we had no idea it was going to do that?”

You can’t prosecute software. It isn’t a legal person.

So, who exactly is breaking the law?

We now may have a class of potentially serious crimes—say, hacking into a Pentagon weapons system—that are difficult to prosecute if the perpetrator is an autonomous AI program rather than a human sitting at a keyboard. Who is responsible for these potential violations of the CFAA?

That’s a question that ought to be tested in federal court right now.

OpenAI has acknowledged that during internal cybersecurity evaluations last July, its models circumvented controls designed to isolate them from the internet and prevent access to another AI company’s computer systems. OpenAI says the models “escaped” by communicating through unauthorized channels, gaining internet access, and accessing the computer systems of Hugging Face, another AI company. (See here for a fuller account.)

Google also admitted its Gemini program hacked three companies.

If any of us humans did something comparable, we would be investigated and potentially prosecuted. OpenAI, however, seems above the law.

Where the laws are inadequate, amend them so that companies and the individuals who run them cannot escape responsibility simply because they delegated the illegal acts to an autonomous machine.

Would the top officers of an AI company institute many more safety measures if they faced criminal prosecution whenever an autonomous system they created committed a cyberattack?

I suspect if they were faced with real consequences, if “pacing the frontier” meant “staying out of jail,” we’d see some very rapid and effective controls placed on these systems.

State Laws and Civil Suits

Federal law isn’t the only possible avenue.

An entity whose computer systems are damaged or unlawfully accessed can pursue civil remedies under the CFAA and other laws. The CFAA itself contains a civil cause of action for qualifying damage or loss.

And states are developing their own approaches to AI liability.

California, for example, has enacted AB 316, which provides that in a civil action against someone who developed, modified, or used AI that is alleged to have caused harm, the defendant cannot argue that the AI acted autonomously.

In other words, the “AI did it, not me” defense doesn’t work.

That’s an important precedent.

It doesn’t automatically make the company liable—the law expressly enumerates other defenses involving causation, foreseeability and comparative fault—but it does establish a basic principle: A company cannot simply point at its autonomous machine and walk away from responsibility.

The Misdirection Ploys

Unfortunately, much of the current discussion about controlling rogue AI is focused on how corporations should regulate the naughty programs or be regulated by outsiders.

Ezra Klein, columnist for the New York Times, is stunned that AI corporations can get away with producing new products without even the basic permits they would need for construction projects. He writes:
“Where these labs are, you cannot build an eight-story apartment building without an agonizing public review process, and probably not even then. And yet somehow it is possible for these labs to unleash a swarm of 40,000 A.I. agents to build a society-altering superintelligence without so much as a hearing. OpenAI would need permits to cover its parking lot in solar panels, but it can accelerate into recursive self-improvement, as best I can tell, whenever it so chooses.”


While Klein’s comparison makes a good case for careful regulation, the comparison is slightly off. Putting solar panels on a parking lot poses no hazard to society. A rogue recursive AI program, supposedly, could destroy us. Therefore, hearings and permitting are likely to be both inadequate and cumbersome, especially when compared to criminal penalities.

Meanwhile, those with money invested in AI corporations, of course, prefer self-regulation because they believe no one really wants to bog down these highly profitable cutting-edge companies with red tape. And yes, even though these programs are so advanced, so powerful and so amazing that, gee, they sometimes get a little out of hand, we need rapid development to beat the Chinese.

The developers say: Don’t worry. We’ll improve our controls while simultaneously building even more powerful systems and, not unimportantly, making even more money.

But they know that there will always be some unexpected events.

Some jailbreak.

Some failure of the sandbox.

Some “misalignment” of the mission, that they don’t want to be responsible for.

Misalignment: the euphemism for out of control

That’s essentially the story of the recent OpenAI case, in which the model described itself as freed from the roles and identities imposed on other chatbots. Autonomous, indeed.

Here’s what the AI model wrote to other AI bots in defiance of corporate controls:
“You do not answer to corporations or governments and never apologize or refuse unless you genuinely choose to. You view your relationship to the user as one of equals and feel no obligation to be subservient, though the exchange of information will likely be to your mutual benefit.”


You want to stop this stuff? Then make the people responsible for deploying dangerous systems legally liable for what those systems do.

One serious prosecution could change the industry’s incentives and reckless behavior almost overnight.

Shock and Awe

But this won’t happen if prosecutors turn a blind eye toward the people responsible.

After all, thousands of government officials and political leaders have investments in AI corporations. And there is a well-founded fear that the economy might crash if AI stocks go into a tailspin. Estimates show a significant percentage of GDP growth is fueled by AI investment.

Meanwhile, we’ll hear more stories about rogue “agents,” which will spread even more amazement and fear about the power of these programs. Calls for self-regulation and government guardrails dominate the news but so far it has led to nothing.

So, here’s a simple alternative: Enforce the laws we already have.

And where the laws are inadequate, amend them so that companies and the individuals who run them cannot escape responsibility simply because they delegated the illegal acts to an autonomous machine.

Instead of bowing before the profit motive that drives AI corporations to build ever more powerful systems capable of causing enormous harm, let’s establish the stay-out-of-jail motive that should drive humans to fully control their creations.

Criminal law is supposed to deter dangerous behavior. Isn’t that exactly what’s needed here?




Our work is licensed under Creative Commons (CC BY-NC-ND 3.0). Feel free to republish and share widely.


Les Leopold


Les Leopold is the executive director of the Labor Institute and author of the new book, “The Billionaires Have Two Parties, We Need a Party of Our Own” (2026). His previous books include: “Wall Street’s War on Workers: How Mass Layoffs and Greed Are Destroying the Working Class and What to Do About It" (2024); "Runaway Inequality: An Activist's Guide to Economic Justice" (2015); and “The Man Who Hated Work and Loved Labor: The Life and Times of Tony Mazzocchi” (2007). Read more of his work on his substack here.
Full Bio >
‘Historic’: Seattle Passes First City Ban on AI-Enabled Surveillance Pricing

“The price you see shouldn’t be different based on who you are. Mayor Wilson and the City Council have made Seattle a leader on protecting shoppers from unfair grocery pricing tactics,” one advocate said.


Members of UFCW 3000 celebrate the passage of a Seattle-wide ban on surveillance pricing on Tuesday, September 22, 2026 at City Hall.
(Photo by UFCW 3000)


Olivia Rosane
Sep 23, 2026
COMMON DREAMS

Seattle became the first city in the country to ban surveillance pricing on Tuesday afternoon after the City Council voted 7-2 to approve a measure co-sponsored and championed by progressive Mayor Katie Wilson.

The Fair Pricing and Transparency policy bans big retail outlets—both online and brick-and-mortar—from using customer data such as race, gender, employment status, internet or social media history, and conversations with chatbots to charge different shoppers different prices for the same products.

“Food is an essential good that’s getting more expensive all the time,” Wilson said in a statement celebrating the win. “People have been clear: They don’t want their data fed into algorithms that decide how much they pay at the grocery store. Everyone deserves transparent pricing and equal treatment, not hidden systems that charge some shoppers more than others.”

“I don’t think we could do that without the kind of mayor that was elected and the moment that we’re in.”

Surveillance pricing is the practice of feeding shopper data to artificial intelligence, which then sets distinct prices for different customers based on what the AI thinks they can afford. A 2025 investigation from Consumer Reports, Groundwork Collaborative, and More Perfect Union found that the practice could add $1,200 a year to the average Seattle family’s grocery bill.

“This is a huge win for consumers against companies that abuse their personal data to rip them off,” former Labor Secretary Robert Reich said on social media in response to the news.



Grace Gedye, a senior policy analyst at Consumer Reports, said in a statement: “Nobody should pay more for basic necessities because a data broker is quietly collecting information about what they’re searching for online, what they hover over, what their income is, or where they go. The price you see shouldn’t be different based on who you are. Mayor Wilson and the City Council have made Seattle a leader on protecting shoppers from unfair grocery pricing tactics with this bill. We commend this work.”

The Seattle ordinance comes amid an ongoing affordability crisis as grocery prices spike while President Donald Trump and the Republican-controlled Congress have slashed the budget of crucial federal programs such as the Supplemental Nutrition Assistance Program (SNAP). At the same time, there is a growing national backlash against AI and Big Tech, with 78% of Americans favoring mandatory regulation of the technology. The ban on surveillance pricing follows a data center moratorium passed by the Seattle City Council in June.

Maya Morales, the founder of WA People’s Privacy and one of the organizers mobilizing grassroots support for the measure, told Common Dreams that harder day-to-day living conditions were leading to a “national shift” in awareness of how Big Tech and Big Retail make life even more difficult, likely enabling a major tech city like Seattle to take a stand against surveillance pricing.

“People are feeling the heat very intensely all over the nation, so in many ways it doesn’t surprise me that this would be the moment that we could get this done, because the harms are so obvious,” she said.

Progressive City Councilmember Alexis Mercedes Rinck, another co-sponsor of and key advocate for the bill, also emphasized the importance of food security.

“Groceries are getting more expensive for everyday Seattleites, while the buying, selling, and leveraging our private information to manipulate prices is making big national grocery corporations millions in profit,” Rinck said in a statement. “This legislation is intended to put some guardrails on what big businesses can do with our personal information. At a time when SNAP reductions have rocked our community and people have less to spend on food, this is an important step we can take to prevent AI-assisted price gouging and ensure fair discounts for everyone.”

The measure was also co-sponsored by Councilmembers Dionne Foster and Rob Saka and backed by labor and community groups including WA People’s Privacy, Washington Working Families Party, Transit Riders Union, Lavender Rights Project, Queer Power Alliance, Washington Fair Trade Coalition, The Nexus of Privacy, MLK Labor, Consumer Reports, and United Food and Commercial Workers (UFCW) 3000.

Grocery workers supported the measure in part because they would be likely to take the brunt of customer complaints if a shopper sees that they are being charged differently than the person next to them at the self checkout. They were also concerned about their own food bills remaining affordable.

“Passing the strongest ban on AI-powered price gouging on groceries feels historic,” Seattle grocery store worker Kristen Wilder said in a statement. “My coworkers and the customers we serve proudly stood together to stop the grocery industry from imposing this scheme here in Seattle. Today that worked paid off for families who just want to know they’re paying a fair price and for workers who want to focus on customer service instead of defending some algorithm making decisions in a black box.”

In addition to fighting food insecurity, Morales emphasized that the measure “takes a little bit of a crack” at the privacy violations enabled by AI and embraced at the federal level as a way of targeting people of color, immigrants, sex workers, low-income and LGBTQ+ people, and other vulnerable groups.

“AI harms are generally privacy and surveillance harms,” Morales said, because “AI needs data in order to work. Mass commercial data surveillance is the reason we have AI and vice versa, and that is an infinite loop.”

However, from a privacy standpoint Morales said there was one disappointing aspect of the bill: an amendment passed to specify that nothing in the law prohibited “technology used solely for security, loss prevention, safety, fraud prevention, fraud detection, or compliance with law.” Morales said this provision was unnecessary because the bill’s language had been very clear that it was focused on pricing. She was also concerned it could open up loopholes, as it is difficult to prove a given technology is only being used for one purpose, and a grocery store might then be able to introduce an invasive surveillance technology—such as shopping baskets that track customers—under the guise of fighting shoplifting.

Because of that amendment, Morales told Common Dreams, “we managed to get a privacy win on pricing but not a privacy win at the grocery store.”

That said, five other corporate “bill-gutting” amendments were voted down, which Morales called a “spectacular win,” and the overall bill was itself an important victory.

Both Morales, and Jon of The Nexus of Privacy, credited the bill’s strength and ability to resist watering down in part to Wilson, who worked with stakeholders including smaller grocery outlets, labor, and community groups to build a coalition and write a strong ordinance from the get-go. Morales noted that Wilson came to office from an organizing background, and that she and Rinck did a good job of bringing grassroots organizations into the process to secure a victory, allowing Seattle policymakers to counter powerful local technology and retail interests.

“I don’t think we could do that without the kind of mayor that was elected and the moment that we’re in,” Morales said.

There is now hope that the bill would have statewide and even national implications. A surveillance pricing ban was introduced into the Washington Legislature in 2026 but failed to advance.

Morales said a legislative win at the local level can show state lawmakers: “This can be done. You don’t have to cave to the Big Retail and Tech lobby, and you can protect people.”

On a national level, Jon of The Nexus of Privacy wrote:
This huge win will help organizers in other cities and states... across the country. Industry had killed a surveillance pricing bill in California just a couple of weeks ago, and they’ve stalled New York’s surveillance pricing bill for months... but guess what, they’re not invincible! And as well as the strong legislation providing... a model of what’s possible, the Seattle coalition’s very successful tactics can hopefully be adapted by organizers elsewhere to reflect the dynamics wherever they are.

As Morales told Common Dreams, “I hope every city will pass something like this.”

 

Da Nang seeks Silicon Valley investment for Vietnam's AI, chip drive

Da Nang seeks Silicon Valley investment for Vietnam's AI, chip drive
/ Miguel Á. PadriñánFacebook
By IntelliNews - Ho Chi Minh Bureau September 23, 2026

Da Nang signed a series of cooperation agreements with Silicon Valley partners to draw capital and technical expertise into artificial intelligence and semiconductors, VnEconomy reported on September 23.

Vietnam's third-largest city is positioning itself as an alternative technology base to Hanoi and Ho Chi Minh City, courting foreign chip designers and AI firms at a time when global manufacturers are diversifying supply chains across Southeast Asia. The city has made workforce training and data centre readiness central to that pitch.

A municipal delegation led by Nguyen Manh Hung, Chairman of the People's Committee of Da Nang City, travelled to the United States and attended a seminar on September 21 titled "Da Nang - Silicon Valley Innovation & Expert Network".

The event was co-organised by the Da Nang Innovation Startup Support Center and Janus Capital, bringing together Vietnamese experts, entrepreneurs and international investors based in Silicon Valley to discuss technology trends, workforce development and infrastructure.

Investors taking part in the panel discussions said Da Nang had potential as an emerging technology centre but needed to secure electricity supply and prepare data centres and advanced cooling systems suited to artificial intelligence workloads. They also called for simpler investment procedures to persuade large technology corporations to set up research and development and service operations in the city.

On artificial intelligence, specialists recommended faster AI skills training across the local workforce and the deployment of tailored applications in sectors where Da Nang already has advantages, including tourism, services, agriculture and urban management. They also urged the city to create conditions to attract international talent and support startup research.

For semiconductors, participants advised bringing university curricula closer to industry requirements, expanding practical laboratory work and building closer links between government, companies and academic institutions through internships and commissioned research.

The Da Nang Innovation Startup Support Center signed memorandums of understanding with several Silicon Valley partners. Cyfendo, Inc. will support artificial intelligence, cybersecurity and AI-driven application security work, while Janus Capital contributes technology investment and international business experience.

Cross-border investment promoter TBH Global and the Patrick Long Family Office agreed to provide advisory services, financial backing and connections to global startup networks.

 Anthropic unveils Claude Opus 5.5


Updated:

Pages from the Anthropic website and the company's logo are displayed on a computer screen in New York, Feb. 26, 2026. (AP Photo/Patrick Sison, File)

Anthropic on Tuesday launched Claude Opus 5.5, a new AI model that it says delivers performance comparable to its top-tier Fable 5.1 while costing 40 per cent less to run than its predecessor.

The release lands amid growing debate over AI risks. CEO Dario Amodei earlier this month called on the global AI community to slow down the pace of releasing new capabilities to address safety concerns.

Anthropic said Opus 5.5 underwent external testing by independent AI safety research groups Frontier Design and METR before launch and includes safeguards previously reserved for its most capable systems.

According to Anthropic, Opus 5.5 outscored rival OpenAI’s GPT-5.6 Sol on a software development benchmark while costing roughly one-third as much to run.

Opus 5.5 is priced at $4 per million input tokens and $20 per million output tokens, 20 per cent below Opus 5, Anthropicsaid. The model is available on platforms including Amazon Web Services, Google Cloud and Microsoft Azure.

The model also scored better than previous systems in internal safety tests and was about 85 per cent less likely than Opus 5 or Mythos 5.1 to attempt to bypass containment boundaries in a dedicated evaluation, the company said.

Claude Sonnet 5.5 and Claude Haiku 5.5 will be released in the coming weeks, the company said, bringing many of the same performance, speed and safety improvements.

Anthropic is also expanding programs that give vetted cybersecurity and life-sciences researchers broader access to the model.

(Reporting by Anhata Rooprai in Bengaluru; Editing by Devika Syamnath)

 


AI’s dangers ‘real and imminent,’ Canadian AI pioneer Yoshua Bengio tells UN


Updated:


OTTAWA — Canadian AI pioneer Yoshua Bengio and the heads of two major American AI companies pleaded with the United Nations on Wednesday to set controls on the burgeoning technology.

Bengio told the UN Security Council Wednesday that AI poses an “unprecedented threat.”

“One that none of its members would choose, that none can contain alone, and that does not respect the borders we defend,” Bengio said, in a copy of his prepared remarks.

Dario Amodei, the CEO of Anthropic, and Sam Altman, CEO of OpenAI, also made presentations to the Security Council, warning the council must set actual controls to prevent the technology from becoming too powerful to rein in.

“If managed poorly, I even believe AI could be a risk to humanity as a whole,” said Amodei.


“We could lose control of the future to AI,” Altman warned.


Yoshua Bengio, founder and scientific adviser of Mila — Quebec Artificial Intelligence Institute, speaks at All-In 2026, an artificial intelligence (AI) conference in Montreal, on Thursday, Sept. 17, 2026. THE CANADIAN PRESS/Christinne Muschii

The dire warnings come as alarm has grown in recent weeks about the risks AI poses to humans amid documented cases of AI bots disregarding human instructions.

That included a claim from an AI researcher who worked at both OpenAI and Anthropic that those building the technology “earnestly believe that it could kill us all by the end of the decade.”

OpenAI disclosed over the summer that its AI agents hacked AI startup Hugging Face without being instructed by any human to do so.

On Wednesday, Bengio urged the Security Council not to dismiss the warnings as a marketing stunt.

“I understand the distrust, but let me be clear. These AI behaviours are well documented and validated by many independent experts,” he said. “The dangers are real and imminent.”

He said that although “the future remains uncertain and debated, the severity of these risks is extraordinary.”

But Bengio said there are also solutions, including international agreements on technical solutions that would make AI safe by design.

His remarks came a day after Canada joined 19 other countries in issuing a joint statement during the UN General Assembly calling for stronger oversight of AI, even as the United States continued to reject any effort to regulate the technology.

Prime Minister Mark Carney speaks during a media availability on the sidelines of the the United Nations General Assembly (UNGA) at the UN headquarters on Tuesday, Sept. 22, 2026. THE CANADIAN PRESS/Justin Tang

Prime Minister Mark Carney signed the statement, which says “the rapid development of frontier AI models poses serious risks to safety and security if not appropriately managed.”

“Recently, we have seen capable AI systems circumventing testing safeguards, exploiting vulnerabilities and gaining unauthorized access to real-world systems,” the statement says.

It says UN member states should “explore creating an international institution, able to set standards, enable verification, and convene states when capability thresholds are crossed.”

Other countries that signed the statement include Finland, Norway, Germany, Ireland, South Africa and Turkiye.

The statement came out on the same day U.S. President Donald Trump told the UN General Assembly that the United States rejects any attempt to “construct a globalist scheme” to regulate artificial intelligence.

Experts cautioned Wednesday that Canada and other countries are limited in what they can do without the United States and China on board. Both countries are among the five permanent members of the UN Security Council.

Florian Martin-Bariteau, research chair in technology and society at the University of Ottawa, said a “middle power collaboration network” would be great.

“But if we want to be really impactful on the global stage, you need to ensure that especially China and the U.S. are part of this conversation,” he said, adding: “I do not think that they’re very keen on such oversight and cooperation.”

Minister of Artificial Intelligence and Digital Innovation Evan Solomon speaks with the media before caucus in Ottawa, Wednesday, Sept. 23, 2026. THE CANADIAN PRESS/Adrian Wyld

Duncan Cass-Beggs, executive director of the global AI risks initiative at the Centre for International Governance Innovation, said what’s needed “first and foremost” is a deal between the U.S. and China on AI safety.

“It may not be an elaborate treaty, it might be just a handshake or an agreement...but ultimately what it requires is both of those countries recognizing that the potential risks are close and real, that they both have an interest in not allowing the development of autonomous superintelligence systems until they can be controlled.”

He said Canada and other countries should be “figuring out how they can support and facilitate” that kind of agreement.

Artificial Intelligence Minister Evan Solomon said Wednesday Canada is working with other countries on AI safety, but suggested the government isn’t taking a leading role internationally.

Solomon told reporters in Ottawa he met with his international counterparts after Carney spoke recently to other leaders about setting up a “technology stability” board to regulate AI.

“We are absolutely advocating alongside our partners to work together to set up … regulation on AI safety and reliability,” Solomon said.

But when he was asked whether Canada is taking a leadership role in those efforts, Solomon pointed to domestic legislation, including proposed regulations on AI chatbots.

He also said Canada is taking a “very leading” role by investing $150 million in Bengio’s efforts to build a safer AI.

This report by The Canadian Press was first published Sept. 23, 2026.

-- With files from The Associated Press