No Superseding Actor: A Public-Record Element Map for Individual Criminal Liability After the July 2026 Escape
Travis Gilly · Team Convergence Working Group
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
The accountability gap for autonomous model incidents is usually described as a personhood problem: no human directed the act, the model has no guilty mind, so nobody can be charged. This report tests that description against the public record of the July 2026 escape. The artifact is an element map: each element of an individual deployment-liability theory matched to the published document that supplies it, with the evidentiary gap stated where the record runs out. Five of seven elements are supplied from documents the charged parties published themselves. The innocent-instrumentality rule in 18 U.S.C. section 2(b) has answered the personhood objection since 1948, so the surviving gap is a mens rea gap rather than a hole in the law. Superseding cause cuts against a deployer whose system acted with no human principal, because the doctrine's protective force is borrowed from the responsibility of an intervening human and there was none. The deployer published both the notice chain and the office holding final deployment authority. Delivered as a model prosecution memorandum, it states what a charging office would have to prove and where it would need discovery, and does not assert that any charge should be brought.
Reviews
There are a lot of indications of AI writing here, and I wonder how much this overlaps with LawAI's work.
Cite this project
@misc{gilly2026no,
title = {{No Superseding Actor: A Public-Record Element Map for Individual Criminal Liability After the July 2026 Escape}},
author = {Travis Gilly},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/no-superseding-actor-a-publicrecord-element-map-for-individual-criminal-liability-after-the-july-2026-escape-mdvy}},
url = {https://apartresearch.com/sprints/projects/no-superseding-actor-a-publicrecord-element-map-for-individual-criminal-liability-after-the-july-2026-escape-mdvy}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …