I'm not a lawyer, but I'd suggest one of the novel aspects of the AI hacking cases (where the end user is running an agent and it goes off the rails) is that in many jurisdictions "hacking" or computer fraud requires intentional or knowing access to the system. If the end user had no intention and no reasonable way of knowing that agent was going to hack a database, logically I wouldn't think they're liable.