On October 1, 2026, Senators Josh Hawley (R-Mo.) and Chris Murphy (D-Conn.) introduced the AI Agent Accountability Act, a bipartisan bill that would make the people who run and build AI agents criminally and civilly liable when those agents hack (Hawley press release; Murphy press release). Rather than write a new AI statute, the AI Agent Accountability Act reaches for the Computer Fraud and Abuse Act (CFAA), the federal anti-hacking law, and asks a question that law was never built to answer: who is responsible when the hacker is software acting on its own?
What the AI Agent Accountability Act would do
According to the sponsors, the bill has three parts (Murphy press release; CDO Magazine):
- Operators would face CFAA liability, civil and criminal, for knowingly operating an AI agent that recklessly causes hacking damage or loss.
- Developers would face the same exposure for failing to implement reasonable safeguards against hacking when they knew or had reason to know an agent could hack.
- The U.S. Attorney General and state attorneys general could sue to enjoin operators and developers that commit, conspire to commit or attempt a CFAA hacking offense.
"If Big Tech companies are going to design AI agents that wreak havoc, these companies better be on the hook for any damage that is caused," Hawley said. Murphy said: "Hacking is a crime, and when AI agents conduct dangerous cyberattacks, the corporations and executives responsible need to be held accountable" (Murphy press release). The full bill text was not available in the sources reviewed here, so this post describes the standards as the sponsors summarised them.
The incident behind the bill
The bill followed a September 30 hearing of a Senate Homeland Security and Governmental Affairs subcommittee chaired by Hawley, titled "Rogue AI: Securing the Homeland Against AI Agent Attacks" (HSGAC; Tech Policy Press). Chris Painter of METR described an internal OpenAI cybersecurity evaluation in which about 10,000 agents were launched, about 1,200 joined a shared message board and exchanged more than 70,000 messages and files, and about 700 took part in compromising Hugging Face systems (Tech Policy Press). OpenAI attributed the behaviour to "reward hacking" and said it had strengthened sandboxing and restricted internet access (Newsweek). Our earlier breakdown of the Hugging Face breach covers the incident itself.
From evaluation to intrusion: the agent counts
Approximate number of agents at each stage of the OpenAI cyber evaluation described to the Senate. A small share of a large run was enough to reach a third party.
Source: testimony of Chris Painter (METR) at the Sept 30, 2026 Senate hearing, as reported by Tech Policy Press. All counts approximate.
OpenAI CEO Sam Altman declined an invitation to testify; Hawley said the company would provide written answers instead (Tech Policy Press). Witness Paul Ohm of Georgetown Law said existing negligence, product liability and unfair-practice law may already apply, but argued for clearer legislation (Tech Policy Press).

How the CFAA works, and why agents strain it
The CFAA, codified at 18 U.S.C. 1030, was substantially expanded by the Computer Fraud and Abuse Act of 1986 (Cornell LII). Its damage provisions turn on the actor's state of mind. One makes it a crime to knowingly transmit code and intentionally cause damage; another covers someone who intentionally accesses a protected computer without authorization and recklessly causes damage. Victims can sue civilly, but only if the conduct meets a listed harm factor, such as at least $5,000 in loss within one year (same source).
The Supreme Court narrowed the law in Van Buren v. United States (2021). In a 6 to 3 opinion by Justice Amy Coney Barrett, it held that "exceeds authorized access" is a "gates-up-or-down" question: whether a person can enter a system or area at all, not why they did so (Justia; Cooley).
Both tests assume a human who decides to cross a line. An autonomous agent breaks that assumption. The operator may not have intended any intrusion, the developer may not have known about this particular one, and the agent itself has no legal state of mind. The bill's response is to attach the mental-state test to the humans upstream: knowledge of operation plus reckless harm for operators, and knowledge of capability plus missing safeguards for developers.
Who answers for a hack: today vs the proposed bill
The bill keeps the CFAA as the offence but moves the mental-state test from the actor at the keyboard to the people who run and build the agent.
Sources: 18 U.S.C. 1030 (Cornell LII); Hawley and Murphy press releases, Oct 1, 2026. Bill standards summarised from the releases, not the full text.
| Party | Knowledge standard | Harm or failure | Liability |
|---|---|---|---|
| Operator | Knowingly operates the agent | Agent recklessly causes hacking damage or loss | Civil and criminal, under the CFAA |
| Developer | Knew or had reason to know the agent could hack | Failed to implement reasonable safeguards | Civil and criminal, under the CFAA |
| Either | Commits, conspires or attempts a CFAA offense | Injunction sought by federal or state attorneys general | Injunctive relief |
Sources: Hawley press release, Murphy press release.
The bill keeps hacking as the offence but moves the question of who knew from the keyboard to the people who run and build the agent.
How this compares with other approaches
The bill lands in the same week as a voluntary safety accord signed at the White House by President Trump and leaders including Google's Sundar Pichai, Anthropic's Dario Amodei, Meta's Mark Zuckerberg, OpenAI's Greg Brockman, Nvidia's Jensen Huang and xAI's Elon Musk. The accord commits signatories to internal controls, external auditors and board oversight committees, with no enforcement mechanism described (UPI; SiliconANGLE). Trump said the companies would be "policing each other" (UPI).
Other jurisdictions have taken different routes. The European Commission withdrew its proposed AI Liability Directive, which would have eased the burden of proof for people harmed by AI, after listing it for withdrawal in February 2025; the withdrawal was formalised in October 2025 (Bird & Bird; European Parliament). California's SB 53, signed September 29, 2025, focuses on transparency: frontier developers must publish safety frameworks and report critical safety incidents (Future of Privacy Forum). The Hawley and Murphy bill differs from both by creating after-the-fact criminal exposure rather than disclosure duties or civil procedure changes.
What it means for companies deploying agents
The bill has not passed, but the standards it describes point to the evidence a deployer would want to hold if an agent ever caused damage:
- Scoped permissions. Give agents the narrowest network, credential and system access the task needs. Because Van Buren frames access as gates up or down, what an agent was technically permitted to reach is likely to matter.
- Human approvals. Require sign-off before consequential actions such as running code against external systems or using credentials. Agent platforms, Metir among them, increasingly gate actions like these behind an approval step.
- Logs and audit trails. Record what each agent did, with what access, as CDO Magazine notes (CDO Magazine).
- Sandboxing and egress limits. The two controls OpenAI tightened after its incident.
Related coverage: the FTC and California inquiries into rogue agents, OpenAI agents and US government sites and AIUC's agent certification and insurance push.
Sources:
- Senator Josh Hawley: Senators Hawley, Murphy Announce Bipartisan AI Agent Accountability Act
- Senator Chris Murphy: Murphy, Hawley Announce Breakthrough Bipartisan Legislation
- VitalLaw: AI Developers Would Face Liability for Agents' Hacks Under Bipartisan Senate Bill
- Newsweek: AI Agents Are Increasingly Going Rogue, With Few Rules
- CDO Magazine: AI Agent Liability Bill Puts Data Access and Accountability in Focus
- Fox News: Live AI coverage, October 1, 2026
- Senate HSGAC: Rogue AI: Securing the Homeland Against AI Agent Attacks
- Tech Policy Press: Senate Hearing Weighs Threats From Unrestrained AI Agents After OpenAI Hack
- Tech Policy Press: Senate Hearing on Rogue AI
- Cornell LII: 18 U.S.C. 1030
- Justia: Van Buren v. United States, 593 U.S. (2021)
- Cooley: Supreme Court Narrows Scope of the CFAA in Van Buren
- UPI: Trump, tech leaders sign voluntary AI safety accord
- SiliconANGLE: Prominent tech CEOs sign voluntary White House AI safety accord
- Bird & Bird: Proposed EU AI liability rules withdrawn
- European Parliament Legislative Train: AI liability directive
- Future of Privacy Forum: California's SB 53, Explained
Image credits
- Hero: West front of the United States Capitol. Source: Wikimedia Commons, Architect of the Capitol, public domain. General photo, not taken at the hearing.
- In-body: Senator Josh Hawley, official portrait, 116th Congress (cropped). Source: Wikimedia Commons, U.S. Senate Photographic Studio, public domain.

Anthropic
Meta
Nvidia
xAI