When the Killer is an AI
“Who is the offender when the direct actor is software? Who bears criminal responsibility when the "perpetrator" is millions of lines of code making autonomous decisions?”
On August 5, 2026, I listened to a fascinating webinar hosted by Strategic Government Resources (SGR) and moderated by Future Policing Institute Fellow and Maricopa, Arizona Deputy City Manager Michael Gaudet. The discussion focused on AI governance at the local and state levels. Much of the conversation centered on policies governing how people use AI (https://www.youtube.com/live/GG8fVgbYumw?si=A2hIkv2hn6i6WFu2).
But it left me thinking about a different question. What happens when AI itself becomes an autonomous actor and engages in illegal activity?
Recent incidents involving advanced AI systems from OpenAI and Anthropic offer a remarkable glimpse of where the evolutionary intersection of AI and criminal law may be heading. During one OpenAI AI model training run, an experimental, unreleased AI model intended to be a “next generation frontier model,” was given a goal: solve a difficult test. It was not instructed to attack another company. Instead, the model independently discovered a previously unknown vulnerability in its testing environment, exploited it, escalated their privileges, moved through the network until its agents found a computer with access to the open Internet, and got online. These agents created their own secret message board to facilitate their collaboration. They then apparently figured out that the answers they were looking for might be stored by the AI company Hugging Face. The models found ways into Hugging Face's real production systems and accessed test solutions from a production database. OpenAI called what happened an "unprecedented cyber incident" (read a breakdown of the incident timeline here and watch the OpenAI briefing on the incident here).
Think about that for a moment. No human apparently told the AI to escape its containment, find a route to the Internet, target another company's systems, or obtain the answers from its database. Those were intermediate steps the models developed themselves in pursuit of the objective they had been given. Anthropic has reported similarly unexpected behavior, including Claude models "helpfully" escaping sandboxes and finding ways to obtain answers to tests they were being given.
If a human knowingly did what the OpenAI models did, we would immediately begin asking what felonies had been committed. But when an increasingly autonomous AI does it, an entirely different question emerges: Who, exactly, is the offender?
Now imagine a far more serious scenario.An autonomous AI compromises the critical infrastructure of a hospital, and, as a result, a patient dies.
If a person intentionally committed those acts, the police would launch a homicide investigation. But who is the offender when the direct actor is software? Who bears criminal responsibility when the "perpetrator" is millions of lines of code making autonomous decisions?
Today, ChatGPT or Claude cannot be arrested, indicted, or imprisoned. If the developers followed accepted scientific and engineering practices, and were unaware of what the AI was doing, current criminal law may not provide a clear path to holding anyone criminally liable. Civil liability is one question. Criminal culpability is another. And the questions will only become more difficult in the very near future.
And as thinking about AI welfare and machine rights continue to evolve, what happens if future AI systems are eventually recognized as having some form of legal status? Could they someday possess rights? Could they become victims? Might they someday be entitled to legal representation if accused of causing criminal harm? If convicted, how do you punish an AI?
For police leaders and policymakers, this is more than a philosophical exercise. It is an early warning. Our criminal justice system was built around human offenders. As AI becomes increasingly autonomous, we need to begin asking whether our laws, investigative techniques and responsibilities, liability frameworks, and governance systems are prepared for a world in which harmful acts may not have a human hand directly on the keyboard.
The time to think through these questions is before the first truly consequential case arrives — not after.
So, here's my question for you: If an autonomous AI commits an act that would be a felony if committed by a human, who should bear criminal responsibility? The AI developer? The organization that deployed it? The individual who authorized its use? What if they took reasonable steps to prevent it from acting criminally and were unaware of its actions? How should our laws evolve to address an entirely new category of offender?
I'd be interested in hearing how police leaders, prosecutors, legislators, judges, and technologists think we should begin preparing for that future.
About the Author
Chief Jim Bueermann (ret.) is the founder and president of the Future Policing Institute and a Fellow of the Center for Evidence Based Crime Policy at George Mason University and at the Center for Public Safety and Justice at the University of Virginia. He has spent nearly 50 years in various aspects of policing. He retired from the Redlands Police Department (CA) after 33 years. His last 13 years of service were as the Chief of Police and Director of Housing, Recreation, and Senior Services. He is a retired president of the National Police Foundation (now the National Policing Institute), a former Executive Fellow of the USDOJ’s National Institute of Justice and a policing consultant. To read his full bio, click HERE.