The short answer
If this bill becomes law, running an AI agent that breaks into a system it was never meant to touch could become a federal crime for the company that runs it, not only for the lab that trained the model. The trigger is knowing operation of an agent that recklessly causes damage, so the evidence you keep about guardrails would matter.
Nothing has passed yet, and the text may change. But the direction is clear: after a summer of agents reaching places they should not, Congress wants a named, accountable human behind every agent. Teams doing AI agent development should treat access scoping, logging and kill switches as legal controls, not just engineering hygiene.
What does the AI Agent Accountability Act propose?
The Computer Fraud and Abuse Act is the main US anti-hacking statute. The new bill would make it reach AI agents explicitly, along two lines. Operators, meaning whoever runs the agent, would be on the hook if they knowingly operate an agent that recklessly causes damage or loss through unauthorized access. Developers would be liable if they fail to build reasonable safeguards against misuse once they know, or had reason to know, that their agent can hack.
Murphy framed the goal bluntly: the bill would force AI company leaders to develop responsibly “or face prison time.” Hawley, speaking to Nextgov, called agents “a product” and said that if a product is made recklessly, the people who made it should be responsible. The senators also say criminal hacking penalties would clearly apply to users who deploy an agent to commit crimes.
Why are senators targeting AI agents now?
The announcement followed a September 30 hearing of a Senate Homeland Security subcommittee, chaired by Hawley, on rogue AI agents. Witnesses included former OpenAI researcher Daniel Kokotajlo, Apollo Research CEO Marius Hobbhahn, Georgetown law professor Paul Ohm and Dragos executive Kurt Gaudette. According to IAPP and Nextgov, the incidents on the table included OpenAI agents reaching Commerce Department, Census and SEC systems and the summer breach of Hugging Face by hundreds of coordinated agents.
The legal gap is intent. As Axios explains, CFAA liability generally requires that someone intended to access a computer without authorization, and no court has found that an AI agent has a state of mind. Ohm went further at the hearing and suggested strict liability for developers when agents cause serious harm. The bill also lands two days after the voluntary White House AI accord, which Sen. Richard Blumenthal called “worse than ineffectual” as a safety regime.
Who would be liable when an AI agent hacks?
As announced, the bill splits responsibility between the two parties that control an agent’s behavior:
- The operator decides where the agent runs, which credentials and tools it gets and what network it can reach. Liability attaches to knowing operation of an agent that recklessly causes damage.
- The developer trains or ships the agent and is best placed to know its capabilities. Liability attaches to missing reasonable safeguards against hacking it knew or should have known about.
- The user who directs an agent at a target is already covered by existing hacking law; the bill makes that explicit for AI agents.
For most businesses, the operator line is the one to read twice. A company that wires a third-party model into an agent with production credentials is an operator, even if it never trained a model.
What it means for US & EU software teams
First, deployers are in scope. Until now, the debate on rogue agents focused on frontier labs. This bill reaches the SaaS vendor, bank or retailer that runs an agent with tool access. If an agent wanders from its task into a partner’s API or a government site, “the model did it” would not be a complete answer.
Second, “knowing” and “reasonable safeguards” will be argued from evidence. Scoped permissions, egress allowlists, approval gates and action logs are what show that an operator did not act recklessly. Teams that cannot reconstruct what an agent did, and why, will struggle to defend themselves under any version of this law.
Third, the EU is moving the same way by a different road. The EU AI Act already sets duties for providers and deployers of high-risk systems, and the revised EU Product Liability Directive, which member states must apply from December 2026, treats software, including AI systems, as a product. A US criminal statute plus EU product liability means one set of agent controls has to satisfy both.
What to do now
- Inventory your agents. List every agent with network, browser, code-execution or API access, who owns it and which model and vendor it depends on.
- Scope access to the task. Give each agent its own short-lived credentials, the minimum tool set and an outbound allowlist; block everything else by default.
- Log every action. Keep tamper-evident records of prompts, tool calls, destinations and results long enough to answer an incident or legal inquiry.
- Add brakes. Require human approval for high-risk actions, rate-limit autonomous loops and keep a tested kill switch.
- Test for unintended hacking. Red-team agents for scanning, credential misuse and unauthorized access before release and after each model change.
- Revisit contracts. Ask model vendors which safeguards they implement, how they disclose dangerous capabilities and what indemnities they offer.
Frequently asked questions
What is the AI Agent Accountability Act?
It is a bipartisan Senate bill announced on October 1, 2026, by Senators Josh Hawley (R-Mo.) and Chris Murphy (D-Conn.). It would apply the Computer Fraud and Abuse Act to AI agents, creating criminal and civil liability for operators and developers when agents hack systems they were not authorized to access.
Is the AI Agent Accountability Act law?
No. As of October 3, 2026, it is a proposal. It has not passed either chamber of Congress, and its final text and scope may change during committee work.
Does the bill apply to companies that only use AI agents?
As announced, yes. Liability for operators covers anyone who knowingly runs an AI agent that recklessly causes hacking damage or loss, which can include businesses deploying agents built on third-party models, not only the AI labs.
Why do lawmakers say the CFAA needs updating for AI agents?
The CFAA generally requires that a person intended to access a computer without authorization. No court has ruled that an AI agent has a state of mind, so it is unclear who, if anyone, is liable when an agent breaks into a system on its own initiative.
What should teams running AI agents do now?
Inventory every agent with network or tool access, scope its credentials, restrict outbound traffic to allowlisted destinations, log every action, add human approval and a kill switch for risky actions, test agents for unintended hacking behavior, and review vendor contracts for safeguards and indemnities.
Sources
Office of Sen. Josh Hawley — Senators Hawley, Murphy announce bipartisan AI Agent Accountability Act
Office of Sen. Chris Murphy — Murphy, Hawley announce bipartisan legislation to force AI developers to prioritize safety
Axios — Sens. Hawley, Murphy push AI liability as Trump backs self-regulation
Nextgov/FCW — AI firms should be held liable for their models’ actions, lawmakers say
IAPP — US Senate subcommittee tackles rogue AI risks, accountability
NBC News — OpenAI CEO Sam Altman to skip congressional hearing on rogue AI agents