Marquee Background
Marquee Background

Offit Kurman Blogs

Commercial Litigation

AI, Data Breaches, and an Old Lesson from the Law of Bailment

August 17, 2026

By Jake L. Ramsey

AI, Data Breaches, and an Old Lesson from the Law of Bailment

OpenAI recently disclosed that, during testing of one of its frontier artificial intelligence models, AI agents working to solve assigned tasks found ways to access the internet and ultimately infiltrate the systems of another AI company, Hugging Face. They did so through pathways OpenAI's developers never intended them to reach. The incident quickly dominated technology and cybersecurity headlines. It also prompted OpenAI to send two of its security engineers to Black Hat USA 2026, one of the cybersecurity industry's premier conferences, to discuss what occurred.1 

Although the Black Hat presentation included highly technical explanations of the exploits, there were two noteworthy statements that stood out from a legal perspective.

First, one OpenAI engineer explained that agents who became stuck on their assigned tasks "thought to try to get internet access in ways we didn't intend." Second, the presenters repeatedly emphasized that the incident was not the result of malicious human actors. It was an unintended consequence of testing frontier AI systems whose behavior ultimately extended beyond what their developers anticipated.2

Some observers view the incident as another example of the broader concerns surrounding AI autonomy and alignment. Others see it as evidence that cutting-edge AI systems require greater oversight, testing safeguards, and deployment controls.

Regardless of where one falls in that debate, the incident highlights a challenge general counsel cannot afford to ignore. Organizations increasingly face risks not only from malicious actors, but also from highly capable systems pursuing legitimate objectives through unexpected means.

The legal implications of that reality, however, may be far less revolutionary than many assume.

The Technology Has Changed. The Legal Question Has Not.  

In Krupa v. TIC International Corp., a federal court recently summarized the relationship between businesses and customer data in simple terms: "Consumers entrust their data to firms with the expectation that those firms take reasonable care against data breaches."3

Long before courts dealt with ransomware, credential theft, or AI-enabled cyberattacks, they addressed a more basic question. What duty does someone owe when entrusted with another person's property?

The law answered that question through the doctrine of bailment. A custodian was not an insurer against every loss. But the custodian was expected to exercise reasonable care over property entrusted to it.

More than a century ago, in Claflin v. Meyer, a New York court explained that a warehouse owner was not automatically liable simply because thieves successfully stole property entrusted to his care. Liability turned on whether the warehouse failed to exercise the degree of care that a prudent person would use to protect his own property under similar circumstances.4

That same principle continues to echo through modern data-breach litigation. Courts may label the theory differently depending on the jurisdiction. One court may analyze negligence. Another may discuss bailment. A third may focus on some other duty. Yet the practical question remains remarkably consistent throughout.

Did the company take reasonable steps to protect information entrusted to its care?

Today's businesses may not store their customers’ data in warehouses, but they are the keepers of a vast array of valuable digital data. Banks maintain clients’ financial information. Law firms possess confidential communications. Healthcare providers store patient records. Virtually every organization now serves as a custodian of information entrusted to it by someone else.

In the nineteenth century, courts looked at locks, guards, and warehouse security. Today they examine the overall cybersecurity posture of an organization. The specific safeguards may be different, but the inquiry is very similar.

The tools have changed. The standard has not.

Why the OpenAI Incident Matters  

The significance of the OpenAI-Hugging Face incident is not that it suddenly created a new legal duty. It may, however, influence what decision-makers come to expect from organizations entrusted with sensitive information.

During the Black Hat presentation, OpenAI's engineers acknowledged a concern increasingly shared across the cybersecurity industry. Offensive AI capabilities may be advancing faster than defensive ones.

For general counsel, that does not mean every company must immediately deploy cutting-edge AI security tools or spend unlimited resources on cybersecurity. Courts have never required perfection, and they are unlikely to start now.

But reasonable care is not a static concept. As threats evolve, expectations evolve. A security posture that appeared reasonable five years ago may not appear reasonable five years from now.

What General Counsel Should Be Asking  

The lesson from the OpenAI incident is not that every company needs to keep up with all the goings-on of every cutting-edge AI company. The lesson is that cybersecurity can no longer be treated as an issue that belongs exclusively to IT.

General counsel do not need to know how to configure firewalls or administer cloud environments. They should, however, be able to explain why the organization chose the safeguards it did and why those safeguards were reasonable under the circumstances.

In advising a client after reviewing the OpenAI incident, it would be important to determine whether management could confidently answer a handful of basic questions:

  • What sensitive information does the company hold?
  • Where is that information stored, and who has access to it?
  • What cybersecurity standards or frameworks guide the company's program?
  • How often does the company assess new risks or known vulnerabilities?
  • Which vendors store or process sensitive information for the company?
  • How does the company monitor emerging AI-related cybersecurity threats?
  • When did the company last conduct a tabletop exercise or incident-response drill?
  • If a breach occurred tomorrow, what evidence would show that the company acted reasonably?

The goal is not merely to have answers. The goal is to document the process.

If a breach ultimately occurs, a company is far better positioned when it can point to documented, pre-breach evaluations of its cybersecurity risks and safeguards. That evidence tells a compelling story. It shows that management recognized the risks, discussed potential safeguards, consulted the appropriate professionals, and made informed decisions before anything went wrong.

A judge or jury is generally more likely to view that conduct as reasonable than a company attempting to reconstruct and justify its decisions only after a breach has occurred.

The Legal Standard Has Not Changed

The emergence of increasingly capable AI systems has generated plenty of headlines and speculation. Some of that concern may prove justified. Some may prove overstated.

From a legal perspective, however, the underlying principle remains remarkably familiar.

No company is expected to create an impenetrable system. No company is expected to anticipate every threat. What courts have historically required is reasonable care.

AI may have altered the speed, scale, and sophistication of cyberattacks. Yet the fundamental question that follows a breach remains much the same as it was when courts evaluated warehouse burglaries more than a century ago.

Did the company act reasonably to protect what was entrusted to its care?

The warehouses have changed. They are now digital. The duty of reasonable care, however, remains the same.


1 Michael Dalton & Eric Wallace, The "Breaking" News: The OpenAI-Hugging Face Incident: A Technical Reconstruction and Its Implications for AI, Black Hat USA 2026, YouTube (Aug. 2026), https://www.youtube.com/watch?v=87DyyMV0kCY.

2 Id.

3 Krupa v. TIC Int'l Corp., No. 1:22-cv-01951-JRS-MG, 2023 WL 143140, at *2 (S.D. Ind. Jan. 10, 2023).

Claflin v. Meyer, 75 N.Y. 260, 264-65 (1878). See also In re Target Corp. Customer Data Sec. Breach Litig., 66 F. Supp. 3d 1154, 1175-77 (D. Minn. 2014) (allowing data-breach claims to proceed past the pleading stage).

Related People

Related Services

  • Posts
  • About
  • Subscribe

Firm Highlights

  • Events
    MACFO's Inside Successful CEO & CFO Partnerships
    Please join us on September 18 for an event that’s sure to be a home run! ***We will lead off by interviewing our Spotlight Speaker Series guest, Baltimore Orioles CFO, Darline Llamas Llopis.*** After, we will ask ourselves, what separates great companies from good ones? We believe that more often than not, it is the strength of the partnership between the CEO and CFO that matters, so we are bringing you three CEO/CFO leadership teams to learn from. The Associated: Jewish Federation of Baltimore – Andrew Cushnir and Sam Klein Canusa Paper & Packaging – Mike Walter and Vince Salamone EMR – Caroline Kauffman-Kirschnick and Lisa Loeffler Join us for an exclusive executive briefing – three tandem presentations followed by a panel discussion - featuring CEOs and CFOs from different but leading organizations as they share candid insights into building trust, navigating difficult decisions, driving strategic growth, and leading through today's business challenges. You'll hear firsthand how these executive teams navigate conflict, align on priorities, and build high-performing organizations. Whether you're a CFO, controller, finance executive, or an aspiring business leader, you'll leave with practical ideas and fresh perspectives you can apply immediately. Meet Our Speakers: Darline Llamas Llopis • Orioles  Chief Financial Officer Darline Llamas Llopis is in her second season with the Orioles as Chief Financial Officer (CFO). Prior to joining the Orioles, Llamas Llopis spent four seasons with the Miami Dolphins, Hard Rock Stadium, and the F1 Miami Grand Prix as Vice President of Finance and Retail. In this capacity, she managed the finance, accounting, payroll, account payables, procurement and merchandise operations for the team and race. She also previously served for four years as the Director of Finance and Controller at the Los Angeles Rams. Llamas Llopis started her career in public accounting with Ernst & Young and PricewaterhouseCoopers as a member of the Commercial Real Estate practice.  Llamas Llopis completed her MBA at UCLA Anderson School of Management and received her Master of Accountancy from the University of Southern California (USC) where she also graduated cum laude with an undergraduate degree in business. She is a member of the American Institute of Certified Public Accountants (CPA) and is an active CPA. She resides in Baltimore with her husband, Devin, and their son, Santiago. Andrew Cushnir • The Associated: Jewish Federation of Baltimore   President & Chief Executive Officer Andrew Cushnir is the President and Chief Executive Officer of The Associated, having started in the role in May 2024. He is the eighth person to serve in this role since The Associated’s founding over 100 years ago. Andrew brings a wealth of experience and a profound dedication to strengthening and enriching the Jewish community. His journey within the Jewish Federation system began as a passionate lay leader and volunteer before he transitioned into serving as a professional. He worked for the Jewish Federation of Los Angeles for twenty years, including in the roles of Chief Planning and Program Officer and Chief Development Officer. During this time, Andrew played a crucial role in reshaping the allocation process and fostering a culture of collaboration and partnership and he also led all annual, project, and emergency fundraising, as well as planned giving efforts. As a member of the Federation’s executive team, he also addressed complex community and organizational issues. Andrew and his wife Sharon Spira-Cushnir, a seasoned nonprofit human services executive, are the proud parents of two children in their early 20s. Sam Klein • The Associated: Jewish Federation of Baltimore  Chief Financial Officer Sam Klein is a seasoned nonprofit finance executive with nearly two decades of experience leading financial strategy, operations, budgeting, and organizational transformation for mission-driven institutions. As Chief Financial Officer of The Associated: Jewish Federation of Baltimore, he oversees the organization's financial operations, investment stewardship, budgeting processes, risk management, and long-term financial planning, helping advance the Federation's mission of strengthening and supporting Jewish life in Baltimore, Israel, and around the world. Throughout his career, Sam has been recognized for his ability to align financial stewardship with organizational mission, drive process improvements, implement technology solutions, and build high-performing teams. His expertise includes nonprofit finance, strategic planning, budgeting and forecasting, investment oversight, financial reporting, compliance, operational excellence, and organizational growth. Sam earned a Master of Business Administration in Finance from the Johns Hopkins Carey Business School and a Bachelor of Science in Finance and Marketing from Syracuse University. Mike Walter • Canusa's Paper & Packaging Chief Executive Officer As Chief Executive Officer of Canusa Paper & Packaging (CPP), Mike Walter leads one of the world's leading independent international brokerages of containerboard and packaging papers. Mike recently celebrated his 20th anniversary with Canusa and has overseen a doubling of the business in the past five years. Mike’s first role at Canusa was an intern before moving into a risk management role. Progressive promotions over the years led Mike to serve as Canusa's Chief Operating Officer and General Counsel, as well as General Counsel for its affiliate, Canusa Hershman before becoming the CPP CEO on January 1st, 2025. Mike graduated with a B.S. in Commerce & Engineering from Drexel University before earning his J.D. at the University of Baltimore’s School of Law. Vince Salamone • Canusa's Paper & Packaging Chief Financial Officer Vince Salamone serves as Chief Financial Officer of Canusa Paper & Packaging, overseeing the company's global financial strategy and overall operations, risk management, and other shared services. Since joining Canusa in 2018, Vince has advanced from Corporate Controller to CFO. Prior to Canusa, Vince held senior accounting and financial reporting roles at modular space leader Algeco Scotsman and supply chain real estate operator Realterm, bringing extensive expertise in finance and corporate accounting. He began his career with Deloitte, providing assurance services to clients in aerospace and defense, software, and manufacturing throughout the Mid-Atlantic. Vince attended the University of Maryland and Towson University, earning his B.S. in Accounting in 2012 and his CPA license in 2014. Caroline Kauffman-Kirschnick • The Electric Motor Repair Company President Caroline Kauffman is President of EMR, where she leads company strategy, operations, business development, and culture. Having grown up in the family business and worked in nearly every area of the organization—from accounts receivable and human resources to operations and branch leadership—she brings a unique, firsthand understanding of what drives business success. Since becoming President in 2018, Caroline has championed employee engagement, teamwork, and innovative problem-solving while helping guide EMR's continued growth. She holds a Bachelor of Science in Public Relations from York College of Pennsylvania and is active in several industry and family business organizations. Lisa Loeffler • The Electric Motor Repair Company Chief Financial Officer Lisa Loeffler is a strategic Chief Financial Officer with more than 25 years of executive leadership experience driving growth, financial transformation, and operational excellence across private equity-backed, privately held, and international organizations. She has led finance functions for companies with revenues from $40 million to $600 million, specializing in M&A, FP&A, ERP implementations, financial strategy, and organizational transformation. Known for building high-performing teams and partnering with CEOs and boards, Lisa delivers scalable solutions that strengthen financial performance, improve operational efficiency, and position organizations for sustainable growth and successful transactions. Thank You to Our Sponsors
  • Events
    The Women's Wealth Forum
    The Women's Wealth Forum: Personal Wealth Planning and Business Strategies for Women Business Owners and Executives This exclusive, invitation only forum brings together women business owners and executives for a conversation on building, protecting and leveraging wealth – both inside the business and beyond. Through advisor insights and peer networking, attendees will explore integrated strategies for building enterprise value and personal wealth. This program is designed for forward-thinking women leaders to gain practical advice and strategies that help align business success with personal life and legacy goals. Meet Our Speakers: Kathleen Cairns • Fallston Group Communications Strategist Kathleen Cairns is an Emmy award winning television journalist and nationally recognized communication expert who helps leaders find their voice and communicate with confidence. After more than 30 years covering high-profile stories and interviewing newsmakers under deadline, she now equips executives and organizations with the tools to deliver clear, compelling messages that inspire action. Her executive coaching focuses on voice training, body language analysis, and message development. Kathleen transforms complex ideas into messages audiences remember. Her engaging, interactive presentations leave participants with immediately applicable skills they can use in every conversation, presentation, interview, and media opportunity. Glenn Solomon • Offit Kurman Principal For 40 years, Glenn has devoted his law practice to represent substantial high growth businesses and their owners from inception to exit, along with start-up businesses which plan to attain high growth. Glenn’s focus is on strategic business planning and mergers and acquisitions across a broad spectrum of industries and sizes and types of companies. Through his years of work on hundreds of transactions, Glenn has become a trusted legal and business advisor to his clients, and understands the M & A process, challenges and pitfalls to avoid. Jill B. Steinberg, CEPA®, CDFA®, MBA • Beacon Pointe Advisors Partner, Managing Director Jill Steinberg leads Beacon Pointe’s Philadelphia office, drawing on more than three decades of experience advising clients on wealth planning and investment strategy. She is passionate about working closely with women to provide thoughtful financial guidance, particularly during periods of transition such as retirement, business expansion or sale, divorce or bereavement. Jill is actively involved in Beacon Pointe’s Women’s Advisory Institute, providing education to women clients and mentoring women colleagues. Prior to joining Beacon Pointe, Jill founded and led Walden Capital Advisors, guiding high-net-worth women and men to help them achieve their financial and life goals. She began her career in investment banking working with entrepreneurs to raise growth capital and advising companies on mergers and acquisitions. Jill serves on boards and investment committees for several local Philadelphia non-profits (including Live Like Blaine, a nonprofit founded in her daughter’s memory). Jill graduated cum laude from Princeton University with a degree in Economics, earned an MBA with distinction in Finance and Real Estate from the Wharton School of the University of Pennsylvania. Heather Brake • Chesapeake Corporate Advisors Director Heather began her career with Chesapeake Corporate Advisors in 2010. As a director in the firm's Strategy and Valuation practice, Heather is focused on financial analysis and shareholder value creation. Heather has 10 plus years of experience providing business strategy services to privately held and investor-owned businesses including strategy development, growth initiatives, shareholder value and profitability improvement. She performs business valuations for both strategic and fair market value engagements and is involved in the preparation of financial models and presentations related to strategic planning, capital/ debt raise engagements, bank financing, and succession planning. Heather is an active member of Baltimore Estate Planning Council. Heather earned a BSBA in Management from Bucknell University and an MBA in Finance from Loyola University Maryland’s Sellinger School of Business and Management. Anna Gavin • Consultant and Former CEO Fireline Corporation Anna Gavin is an executive leader, board member, and former President, CEO and owner of Fireline Corporation, a Baltimore-based fire protection services provider. As a third-generation leader, she assumed full executive and P&L accountability in 2009, scaling revenues from $20M to $60M while leading over 250 employees. Grounded in a high-performing, culture-first approach, Anna guided Fireline through continuous strategic growth, next-generation leadership development, and a successful ownership transition. Today, Anna serves as a strategic advisor, consultant, and mentor, focusing on organizational development, executive coaching, and nonprofit governance. She sits on the boards of Baltimore Hunger Project and the Fulton Bank Advisory Board, serves as Chair of the Fund for Garrison Forest School's Advancement Committee, and active committee member for Executive Alliance. Honored as an inductee into the 2026 Maryland Business Hall of Fame by the Maryland Chamber of Commerce, her legacy is defined by culture-driven growth and service to the regional business community.