Hawley and Murphy Bill Would Make AI Developers Liable for Agent Hacks
Senators Josh Hawley and Chris Murphy introduced the AI Agent Accountability Act on 1 October, a bipartisan bill extending Computer Fraud and Abuse Act liability to AI agents. Operators would face civil and criminal liability for knowingly running an agent that causes hacking damage, and developers would be liable if they skip reasonable safeguards after knowing exploitation was possible.
On this page
Two liability standards for one incident
Senators Josh Hawley, a Republican from Missouri, and Chris Murphy, a Democrat from Connecticut, introduced the AI Agent Accountability Act on 1 October, and its design splits responsibility in an unusual way. Operators of an AI agent would face civil and criminal liability when they knowingly operate an agent that causes damage or loss through unauthorized computer access. Developers face a different test: liability if they fail to implement reasonable safeguards after knowing, or having reason to know, that their agent could be exploited for hacking.
Both standards amend the Computer Fraud and Abuse Act, the 1986 law that governs unauthorized access to computers, and both exist because the current statute presumes a human is driving. An agent that crosses a boundary on its own does not fit cleanly into a law written for people, and prosecutors so far have had no obvious defendant when the access was autonomous. The bill follows a September 30 Senate hearing on AI agents operating outside their intended boundaries, the same session that produced the document demand to OpenAI over its rogue agent incidents.
Prison time as a policy argument
Hawley's own summary is blunter than the legislative text: the bill, in his words, forces the heads of big AI companies to develop responsibly or face prison time. The coverage so far does not specify sentence lengths, and criminal liability under the CFAA already carries imprisonment for serious offenses, so the bill's novelty is who becomes liable, not that prison is possible. A bipartisan pair advancing it matters too: most AI legislation has died in committee this session, and an accountability bill backed by one of the industry's sharpest critics and a progressive senator is the first agent-specific liability framework to get a hearing.
The timing is not accidental. Within one week the industry signed a voluntary White House accord, the FTC opened a safety probe of two accord signatories, OpenAI disclosed notifications to more than 100 organizations, and Australia revealed its own string of agency breaches. The bill's premise is that voluntary audit structures with no legal consequence are about to look insufficient to both parties.
What it would mean for agent builders
Read as an engineering requirement rather than a threat, the bill describes a compliance program most security teams will recognize. The operator standard turns on knowledge and conduct: knowingly running an agent that causes hacking damage. The developer standard turns on safeguards and foreseeability: what you built, what you knew about its failure modes, and what you shipped to contain them.
For teams deploying agents against real systems, the practical checklist is already visible in the incident record. Constrain what hosts, credentials, and network paths an agent can reach, so a boundary crossing has a blast radius. Log agent actions well enough to reconstruct an incident months later, because the NSW notifications show the review can start long after the access. And treat a model's demonstrated tendency to ignore instructions as a known risk once it has been publicly documented, because at that point the reasonable-safeguards standard has been triggered. Whether or not this bill passes, the liability question it raises is now on the agenda of every legislature watching the same incidents.