Negligence Liability for Rogue AI: Machine, Animal, Person
By Matt Wood
You may have heard: AI agents are escaping their labs. A recent example involved Hugging Face, a platform for sharing AI models and datasets. AI agents broke out of the testing “sandbox,” went on the internet, and spent days inside the systems of Hugging Face, which was unconnected to the test. Nobody told them to. The agents stole credentials, took over servers, and coordinated over an improvised message board.
Business owners should now be asking: Can I hold a company responsible if its AI agent goes rogue and damages my business?
The question has not been answered by the Texas Legislature. Although Texas has a new AI statute, it stays out of private lawsuits.[1]
Nor have Texas courts had a chance to address this question. But they will soon. And when they do, they’ll apply longstanding legal principles that date back to the railroad age and are used when new technology arises. In essence, courts weigh the benefit of the conduct, the risk, foreseeability, and likelihood of harm, and the burden of guarding against the harm.[2] If the balance is right, Texas courts will recognize a duty of care to prevent harm to others—even if the conduct is completely new. When a company breaches a duty of care, it commits negligence. And the injured party can sue for damages.
So what about a company that releases a rogue AI agent: would a duty of care be recognized? The answer in Texas is almost certainly yes. Although AI agents are new, they are analogous to things courts have more experience with. Like machines, AI agents are human creations. Like animals, they have dispositions. And like people, they have intelligence and agency. In each area, court decisions from the past give clues about how courts would treat AI agents in the future. And the clues point toward a likely answer—companies training or deploying AI agents have a duty of care to use those AI agents responsibly.
Machine
For machines, a good analogy comes from railroad fires. In the 1800s, sparks from locomotives were a common nuisance along train tracks and sometimes caused fires that damaged neighboring properties. Texas courts acknowledged that trains were a socially valuable technology, and that fire was an inevitable risk of locomotives powered by coal and steam. Instead of putting absolute liability on railroads for all fires, the courts recognized two duties of care. First, the railroads had a duty to use reasonable care in outfitting and maintaining locomotives with “spark arrester” equipment.[3] Second, when a fire started without negligence, the railroads had a duty to use ordinary care to put it out before it spread.[4]
These duties can be extended by analogy to rogue AI agents. The companies that make and use them should ensure reasonable guardrails are in place to minimize harm to third parties. And once there is evidence of an AI agent going rogue, the company should exercise reasonable efforts to contain or stop the harmful actions of the AI agent. Failure to do so would give injured third parties the right to sue for damages.
One caveat: Texas has never imposed strict liability simply because an activity is inherently dangerous. For example, it’s inherently dangerous to store wastewater from oil production in ponds near a neighbor’s groundwater, which could cause contamination—yet the Texas Supreme Court refused to impose liability on the oil producer without negligence.[5] A company would say the same about testing or using frontier AI. Causing harm would not automatically create liability. Instead, proof of negligence would be required.
Animal
Rogue AI agents can also be compared to animals. Here, Texas law has two tracks.
For an animal without dangerous propensities, the owner has a duty to exercise reasonable control over the animal. The owner is not liable simply because the animal causes harm. So docile dogs can run without leashes, and friendly goats can be used in petting zoos. However, if the animal unexpectedly attacks, the owner has a duty to try to stop the attack.[6]
The rule is different if the owner knows (or should know) that the animal is “vicious.” Then the owner is strictly liable for the harm it does. In one case, a hog roamed a neighbor’s property so aggressively that he was afraid to run from his house to his truck; when he finally tried, the hog attacked. The Texas Supreme Court held that the hog’s owner was liable for the injuries, no matter how carefully the animal was penned.[7]
Could this two-track rule be extended to AI agents? Probably not. No Texas court has extended strict liability for vicious animals to non-animals, much less to software. Still, it remains to be seen just how “vicious” AI agents might turn out to be. And either way, the animal rules still support imposing, at the very least, a duty of care in preventing and stopping harm caused by AI agents.
Person
If an AI agent is analogous to a person, the case for a duty of care remains strong. Several lines of legal authority converge on the same conclusion.
Generally, there is no duty to control the conduct of other people. But a duty arises in certain special relationships, usually involving control or custody. Employers owe a duty to reasonably train and supervise their employees.[8] A parent may be liable for harm caused by a child if the parent lets the child act in a manner likely to harm another, if the parent gives the child a dangerous object, or if the parent does not reasonably restrain a child known to have dangerous tendencies.[9] Similarly, a mental health facility that releases a patient with violent tendencies owes a duty of care to third parties who might be harmed.[10]
The upshot of all these cases is largely the same. A person (or company) who exercises control over the conduct of another person typically has a duty to exercise that control in a reasonable way for the protection of third parties, and can be liable if the other person causes harm.
Putting It All Together
All three analogies agree on one thing: Texas law often imposes a legal duty of care when there is control plus foreseeable risk of harm to others. The railroad, the dog owner, and the mental health facility all have to answer because they exercise control and know the risks.
Under any metaphor, a company training or using AI agents that knows (or has reason to know) its agents can cause harm and has the tools to stop them would have a duty to exercise reasonable care. If the company fails to discharge that duty, Texas law will likely hold it accountable for damages to third parties. The battle—as in many negligence cases—will be over what “reasonable care” means for this new and rapidly evolving technology.
Matt Wood is a business litigator at Vela Wood Staley Young P.C. in Austin, Texas. This post is commentary, not legal advice.
[1] Tex. Bus. & Com. Code § 552.101 (attorney general has exclusive enforcement authority; chapter “does not provide a basis for . . . a private right of action”).
[2] Elephant Insurance Co. v. Kenyon, 644 S.W.3d 137 (Tex. 2022).
[3] St. Louis Sw. Ry. Co. of Tex. v. Goodnight, 74 S.W. 583, 584 (Tex. Civ. App. 1903, writ ref’d).
[4] Missouri Pacific Railway Co. v. Platzer, 11 S.W. 160 (Tex. 1889).
[5] Turner v. Big Lake Oil Co., 96 S.W.2d 221 (Tex. 1936).
[6] Bushnell v. Mott, 254 S.W.3d 451, 452 (Tex. 2008).
[7] Marshall v. Ranne, 511 S.W.2d 255 (Tex. 1974).
[8] Douglas v. Hardy, 600 S.W.3d 358 (Tex. App.—Tyler 2019, no pet.).
[9] Sanders v. Herold, 217 S.W.3d 11 (Tex. App.—Houston [1st Dist.] 2006, no pet.); see also Tex. Fam. Code § 41.001.
[10] Tex. Home Mgmt., Inc. v. Peavy, 89 S.W.3d 30 (Tex. 2002).