Both the operator of the AI agent and whomever released it. I'm sure the user agreement that companies agree to would shift the blame onto the operator but I feel that both should be held accountable.
This really is just a tool and courts should treat it as such.
I'm going to propose the opposite: no one should be held accountable for an AI agent that acts maliciously by accident.