Josh Hawley and Chris Murphy announced the AI Agent Accountability Act on October 1. The Republican and Democratic senators want to clarify when operators and developers are responsible for hacking by AI agents. Both offices issued announcements.
Their proposal would expose operators to civil and criminal liability under the Computer Fraud and Abuse Act. That includes knowingly operating an agent that recklessly causes hacking damage or loss. Developers could face liability for failing to implement reasonable safeguards when they knew or had reason to know of an agent's hacking capabilities.
The US attorney general and state attorneys general would also be able to seek injunctions against relevant hacking offenses, attempts and conspiracies. Hawley and Murphy argue that liability would encourage safer development and operation.
This risk signal records a policy proposal, not a new incident. The announcements reviewed are not a complete bill text or evidence of enactment. They establish neither automatic liability for every agent action nor a judgment against any particular company.