Two senators who agree on almost nothing agree on this

Senators Chris Murphy, a Connecticut Democrat, and Josh Hawley, a Missouri Republican, announced the AI Agent Accountability Act on 1 October. The bill would extend criminal and civil liability under the Computer Fraud and Abuse Act to the companies that deploy and build autonomous AI agents, rather than leaving the law pointed only at whoever typed the command.

The premise in the announcement is stated flatly: “AI agents are hacking into public websites, networks, and servers.” The senators tie that to anything connected online, naming hospitals, utilities, banks and other critical infrastructure.

“Hacking is a crime, and when AI agents conduct dangerous cyberattacks, the corporations and executives responsible for those AI agents need to be held accountable,” Murphy said. His office’s framing is blunter still: the bill “forces the heads of big AI companies to develop responsibly or face prison time”.

Rows of locking handwheels on a bank of secure storage cabinets
The senators name hospitals, utilities and banks among the systems exposed to agent-driven hacking. Illustration. cottonbro studio · pexels · Pexels License

Three mechanisms

The bill does three things, according to the senators’ summary.

It holds operators liable. An AI agent operator would be criminally and civilly liable under CFAA provisions, including for knowing operation of an agent that recklessly causes hacking damage or loss. That is the deployer — the company running the agent — not only the person who wrote the prompt.

It holds developers liable. A developer would be criminally and civilly liable for failing to implement reasonable safeguards against hacking where it knew, or had reason to know, of the agent’s hacking capabilities. The knowledge standard is the hinge: a lab that has published evaluations showing its model can find and exploit vulnerabilities has, on its face, reason to know.

It gives attorneys general an injunction. The US attorney general and state attorneys general would be empowered to sue to enjoin operators and developers that commit, conspire to commit, or attempt a CFAA hacking offence.

“If Big Tech companies are going to design AI agents that wreak havoc, these companies better be on the hook for any damage that is caused,” Hawley said. “With this liability regime in place, AI companies will have every incentive to keep their products safe.”

Filtration cylinders and valves beside a water storage tank
The bill would let the attorney general and state attorneys general sue to enjoin operators and developers. Illustration. Alexey Demidov · pexels · Pexels License

What is not yet public

What the announcement does not contain is the statutory text. The two offices published a summary, not a bill number or the operative language, so the scope of “reasonable safeguards”, the damages formula and any penalty caps are not yet on the record. Those details decide how much of this is a real liability regime and how much is a press release.

The timing is not accidental. Agentic incidents have accumulated through 2026 — sandbox escapes, agents probing government sites, and a frontier lab’s own threat-intelligence reporting on misuse — and the labs have continued to ship models that do security work on request. A liability rule aimed at developers who knew what their model could do lands directly on that.

The thing to watch is whether the bill gets a number and a hearing, and whether the knowledge standard survives contact with an industry that publishes its own capability evaluations.