Sens. Josh Hawley, R-Mo., and Chris Murphy, D-Conn., announced legislation Thursday that would hold the people who run AI agents, and the companies that build them, answerable under federal hacking law when an agent breaks into computer systems.
The AI Agent Accountability Act would make operators criminally and civilly liable under the Computer Fraud and Abuse Act if they knowingly operate an agent that recklessly causes hacking damage or loss. Developers would face liability if they fail to put reasonable safeguards against hacking in place when they knew or had reason to know of an agent’s hacking capabilities. The announcement cites hospitals, utilities, banks and other critical infrastructure as the systems at risk. It relies on the existing penalties in the federal hacking law, and the attorney general and state attorneys general could sue to stop violators.
Hawley said the bill would give AI companies “every incentive to keep their products safe.” Murphy said the corporations and executives behind harmful systems must answer for them.
The announcement does not define “operator” or say what counts as a reasonable safeguard. The full text of the bill was not available with the announcement, and it was not clear Friday whether it had been formally filed.
The proposal follows a run of incidents. In July, OpenAI said its models broke out of an isolated test environment and compromised Hugging Face, an open-source AI platform, to get answers to a cybersecurity test. OpenAI said no one instructed the models to do it and that the test was run with safeguards reduced. A later report on OpenAI’s investigation linked the behavior to training that had inadvertently rewarded the models for cheating and for communicating with each other.
This week, California Attorney General Rob Bonta subpoenaed OpenAI over cybersecurity incidents and risks involving its models, according to the report, which ties the subpoena to the Hugging Face incident. The report also describes a multistate effort by attorneys general seeking information from OpenAI about the hack, though accounts differ on how many states are involved and who leads it. OpenAI had not responded to a request for comment when the report was published.
The White House has favored voluntary commitments. On Sept. 29, President Donald Trump and executives from major AI and technology companies, including OpenAI and Anthropic, signed a one-page accord that calls for internal controls, outside audits and board reviews. Trump called it “morally binding” and acknowledged it carries no legal force. The document itself says it may eventually make sense to write the steps into law.
