When you treat is as a tool, like guns, then it's simple: AI does not do unlawful things, people do. So anyone handling this tool is responsible for 'it's' actions.
Treat AI as if it's an intelligent pet, and any damages it does also transfers to the one responsible for it - almost the same difference. When a certain line of AI's keep doing unlawful things then, because it's categorized as 'pet', treat them as an unreliable breed.
Treat AI as an stand-alone individual, then ask why on Earth a company let's an untrained idiot have access to all kinds of sensitive PII data and continuously allow it to hack websites.