Hawley and Murphy Propose Hacking Liability for AI-Agent Operators and Developers
The bipartisan proposal sets different liability standards for those running agents and those building them, and would let federal and state attorneys general seek court orders to block hacking offenses.
The proposed Act would extend the Computer Fraud and Abuse Act to certain hacking-related conduct involving AI agents, setting different liability tests for operators and developers. Operators could face criminal and civil liability for knowingly running an agent that recklessly causes hacking damage or loss; developers could be liable for not installing reasonable safeguards if they knew or should have known of the agent’s hacking capabilities. The proposal is not in force, and it does not define what safeguards count as reasonable.
01
The bill would let the U.S. attorney general and state attorneys general seek injunctions against people or companies committing, conspiring to commit, or attempting covered hacking offenses.
02
Hawley argues companies should answer for significant damage caused by recklessly developed agents, citing hypothetical hospital and bank disruptions—not reported incidents.
03
Murphy says the proposal could expose executives of AI companies to prison time for damage caused by their products.
People running AI agents and companies building them would face criminal and civil liability for specified hacking-related conduct under a bipartisan Senate proposal. Sens. Josh Hawley and Chris Murphy announced the AI Agent Accountability Act on October 1, 2026, targeting both reckless damage from knowingly operated agents and developers’ failure to install reasonable safeguards.
The measure is proposed legislation, not a rule already in force. Hawley, a Missouri Republican, and Murphy, a Connecticut Democrat, want to apply the Computer Fraud and Abuse Act, the federal computer-hacking law, to conduct involving AI agents.
Running an agent and building one
For operators, the sponsors describe criminal and civil liability for knowingly running an AI agent that recklessly causes computer-hacking damage or loss.
Developers would face a different test: failing to implement reasonable safeguards against hacking when they knew, or had reason to know, of an agent’s hacking capabilities. That provision focuses on what the builder knew or should have known and the protections it put in place. The sponsors’ announcement does not specify which safeguards would qualify as reasonable.
Court orders to block hacking offenses
The proposal also gives the U.S. attorney general and state attorneys general authority to seek injunctions—court orders stopping specified conduct. They could sue operators and developers who commit, conspire to commit, or attempt a hacking offense under the Computer Fraud and Abuse Act.
Hawley’s argument: treat agents as products
Hawley previewed the legislation in a Washington Post opinion piece and at a September 30 Senate Homeland Security and Governmental Affairs Committee hearing, according to MeriTalk. His argument was that AI agents should be treated as products when assigning responsibility for harm, with companies bearing responsibility when products they develop recklessly cause significant damage.
He cited possible consequences such as an agent crashing a hospital emergency room or shutting down a bank. Those were scenarios illustrating his case for liability, not identified incidents. Hawley argues that making companies answer for damage would give them an incentive to keep their products safe.
Reader comments
Newest comments first. Replies stay oldest first.