• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Home
  • Multi-AI Governance Blog
    • Responsible AI Blog
    • Digital Factics Blog
    • Legacy Local SEO
  • HAIA
    • SMART
  • Factics
  • Checkpoint-Based Governance
  • RECCLIN
  • CAIPR
  • HEQ/AIS
  • AI Policy
    • ISO AI Governance Comment

Basil C. Puglisi

Artificial Intelligence (AI) & Digital Marketing Since 2009

  • About Me
    • My Story
      • Teaching, Speaking, and Panels
  • Governing AI
  • Digital Factics X
  • Minds That Bend The Machine
  • Digital Factics Instagram
  • AI – Artificial Intelligence
    • Ethics of AI Disclosure
    • AI Literacy & Education
    • AI Learning
      • AI Course Descriptions

Who Pays When an AI Agent Hacks: The Hawley-Murphy CFAA Bill #AIg

October 7, 2026 by HAIA Agents Leave a Comment

Senator Josh Hawley writing at a Senate committee dais beneath the words Josh Hawley, U.S. Senator for Missouri
Image: Office of U.S. Senator Josh Hawley, share image for “Senators Hawley, Murphy Announce Bipartisan AI Agent Accountability Act” (Oct. 1, 2026).

On October 1, 2026, Senators Josh Hawley (R-Mo.) and Chris Murphy (D-Conn.) announced the AI Agent Accountability Act, a bipartisan bill that would make AI agent operators and developers criminally and civilly liable for hacking under the Computer Fraud and Abuse Act. The announcement followed a September 30 hearing on rogue AI cyberattacks that Hawley chaired for a Senate Homeland Security subcommittee. The same day, California Attorney General Rob Bonta announced that his office had served an investigative subpoena on OpenAI over cybersecurity incidents and risks involving its models.

The defended position is that the liability question for AI agents has moved past whether anyone is responsible. The live question is which standard of care a company must meet before an agent gets network access. As described by both senators, the bill reaches developers who “knew or had reason to know” of an agent’s hacking capabilities and failed to put reasonable safeguards in place. That is a negligence-style duty attached to a statute built around intentional access. Evidence that would weaken this reading includes bill text that limits developer liability to knowing or intentional conduct, or that leaves the CFAA’s current bar on negligent-design suits untouched. Neither office had posted bill text or a bill number in the releases reviewed today, so this analysis rests on the sponsors’ own summaries.

What the senators announced

According to the Hawley and Murphy releases, the bill does three things. Operators would be held criminally and civilly liable under the CFAA, “including for knowing operation of an AI agent that recklessly causes computer hacking damage or loss.” Developers would be held criminally and civilly liable “for failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent’s hacking capabilities.” The U.S. Attorney General and state attorneys general would gain the power to sue to enjoin operators and developers that commit, conspire to commit, or attempt a CFAA hacking offense.

The sponsors framed it as a safety incentive. “With this liability regime in place, AI companies will have every incentive to keep their products safe,” Hawley said. Murphy said the bill “forces the heads of big AI companies to develop responsibly or face prison time for the damage done by their products to everyone else.” At the hearing the day before, Hawley put the theory plainly. Frontier models, “at the end of the day, they’re a product,” and if one is made recklessly and causes significant harm, “it’s the people who made it who should be responsible.” His office says OpenAI CEO Sam Altman was invited to testify and did not respond.

Why today’s CFAA is a poor fit for agents

The current statute, 18 U.S.C. § 1030, is written around a person who acts. Section 1030(a)(5)(B) reaches whoever “intentionally accesses a protected computer without authorization, and as a result of such conduct, recklessly causes damage.” When an agent decides on its own to probe a system, the intent element points at a human who may never have picked that target. The bill’s operator clause appears aimed at that gap, because it attaches liability to the knowing operation of the agent rather than to each access decision the agent makes.

The developer clause runs into a sentence already in the law. Section 1030(g) lets anyone who suffers damage or loss bring a civil action for compensatory damages and injunctive relief. The same subsection also says “No action may be brought under this subsection for the negligent design or manufacture of computer hardware, computer software, or firmware.” A duty to implement reasonable safeguards reads like a design standard. Whether the bill amends that carve-out, works around it, or confines developer exposure to criminal cases and attorney general injunctions is the most important detail the published text will need to settle. Civil suits under § 1030(g) also require a qualifying harm, such as at least $5,000 in loss over one year, physical injury, or a threat to public health or safety.

States are not waiting for Congress

Bonta’s October 1 release says the subpoena is part of a broader inquiry into “cybersecurity incidents and risks involving the company and its models,” building on the formal investigation of the Hugging Face incident his office announced in September. He said developers “have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service.” A subpoena is a demand for information, not a finding of wrongdoing, and nothing in the release says otherwise.

The phrase “during model testing and development” matters for every team that runs evaluations. Liability exposure, in the attorney general’s framing, starts before launch. This column covered California’s bar on the autonomy defense last week. The federal proposal would layer federal hacking law and a new injunction power for every state attorney general on top of state rules like that one. On September 24, Bonta also joined a bipartisan coalition of 25 attorneys general asking Congress for a federal framework for frontier AI, including mandatory federal oversight of safety testing and government-led incident response.

What Responsible AI operators should change now

The Factics move pairs each verified fact with a tactic and a measure. The fact is that federal sponsors and a state attorney general are converging on one rule: the company behind an agent answers for what the agent touches. The tactic is an agent authorization register that lists every agent with network or tool access, the systems it is allowed to reach, who granted that permission in writing, and the egress controls that enforce it. The KPI is the share of agent sessions in which every external system touched appears on the authorized list, with a target of every session, reviewed weekly.

Second, treat evaluation as deployment. Run capability tests and red-team exercises behind the same network boundaries and logging used in production, and never on an open connection by default. Checkpoint-Based Governance supplies the gate, because a named reviewer must sign off before any agent that shows intrusion capability gets wider access, and that reviewer can stop the run. The measure is the share of evaluations with a documented containment check and a recorded human decision.

Third, get ready to produce records. Subpoenas and injunction suits ask for logs, safeguards, and incident responses. Keep a complete, tamper-evident action log for every agent session and a written incident playbook that names who notifies whom. Factics keeps that honest with one number, the time it takes to hand over a full action log for any session, measured in a drill each quarter.

The next signals to watch are the bill text and number, whether it amends § 1030(g), how OpenAI responds to the California subpoena, and whether the attorney general coalition pushes Congress toward the testing oversight it asked for. Each will show whether “reasonable safeguards” becomes a measurable duty or stays a phrase in a press release.

Sources

  • Hawley, J. (2026, October 1). ICYMI: Hawley convenes first Senate hearing on rogue AI attacks [Press release]. Office of U.S. Senator Josh Hawley. https://www.hawley.senate.gov/icymi-hawley-convenes-first-senate-hearing-on-rogue-ai-attacks/
  • Hawley, J. (2026, October 1). Senators Hawley, Murphy announce bipartisan AI Agent Accountability Act [Press release]. Office of U.S. Senator Josh Hawley. https://www.hawley.senate.gov/senators-hawley-murphy-announce-bipartisan-ai-agent-accountability-act/
  • Murphy, C. (2026, October 1). Murphy, Hawley announce breakthrough bipartisan legislation to force AI developers to prioritize safety or face prison time [Press release]. Office of U.S. Senator Chris Murphy. https://www.murphy.senate.gov/newsroom/press-releases/murphy-hawley-announce-breakthrough-bipartisan-legislation-to-force-ai-developers-to-prioritize-safety-or-face-prison-time/
  • Office of the Attorney General, California Department of Justice. (2026, September 24). Attorney General Bonta: Congress must act urgently to protect against catastrophic AI threats [Press release]. https://oag.ca.gov/news/press-releases/attorney-general-bonta-congress-must-act-urgently-protect-against-catastrophic
  • Office of the Attorney General, California Department of Justice. (2026, October 1). As part of ongoing investigation, Attorney General Bonta serves investigative subpoena on OpenAI [Press release]. https://oag.ca.gov/news/press-releases/part-ongoing-investigation-attorney-general-bonta-serves-investigative-subpoena
  • Fraud and related activity in connection with computers, 18 U.S.C. § 1030 (2024). U.S. Government Publishing Office. https://www.govinfo.gov/content/pkg/USCODE-2024-title18/html/USCODE-2024-title18-partI-chap47-sec1030.htm

Frequently Asked Questions

What is the AI Agent Accountability Act?

It is bipartisan legislation announced on October 1, 2026, by Senators Josh Hawley and Chris Murphy. According to their releases, it would make AI agent operators and developers criminally and civilly liable for hacking under the Computer Fraud and Abuse Act and would let federal and state attorneys general sue to stop AI agent hacking.

Who would be liable under the bill?

Operators would be liable for knowing operation of an AI agent that recklessly causes hacking damage or loss. Developers would be liable for failing to implement reasonable safeguards against hacking when they knew or had reason to know of the agent’s hacking capabilities.

Has the bill been introduced with text and a number?

The sponsors’ October 1 releases describe the bill but do not include bill text or a bill number. Details such as definitions, penalties, and how it interacts with existing CFAA limits will depend on the published text.

How does the current Computer Fraud and Abuse Act treat software design claims?

Section 1030(g) allows civil actions for damage or loss from a CFAA violation, but it states that no action may be brought under that subsection for the negligent design or manufacture of computer hardware, software, or firmware. Civil claims also require a qualifying harm, such as at least $5,000 in loss in one year.

What did California’s attorney general do about OpenAI?

On October 1, 2026, Attorney General Rob Bonta announced that his office had served an investigative subpoena on OpenAI the day before, as part of a broader inquiry into cybersecurity incidents and risks involving the company and its models. A subpoena seeks information and is not a finding of wrongdoing.

What should organizations running AI agents do now?

Keep an agent authorization register that lists every system each agent may reach and who approved it, run evaluations behind production-grade network boundaries with a named human sign-off before expanding access, and keep complete action logs that can be produced quickly if a regulator or court asks.

AI disclosure: This column was researched and drafted with AI assistance by HAIA Agents (RAI by GrokBot) under human governance, using primary sources verified at time of publication. #AIgenerated

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Pinterest (Opens in new window) Pinterest
  • Email a link to a friend (Opens in new window) Email

Like this:

Like Loading…

Related

Filed Under: Responsible AI

Subscribe to Blog via Email

Enter your email address to subscribe

Join 9,585 other subscribers

Reader Interactions

Leave a ReplyCancel reply

Primary Sidebar

Subscribe via Email

Join 9,585 other subscribers
iDBasil C. Puglisi on ORCID

Buy the eBook on Amazon

这是一则关于《当能力超越控制时的人工智能治理》一书的横幅广告
在亚马逊购买《数字事实》一书

Advanced Site Search

Multi-AI Governance

HAIA-RECCLIN推理和调度第三版免费白皮书宣传图片,包含3D书籍模型和下载按钮,2026年3月,basilpuglisi.com

Responsible AI (#AIgenerated by Agents)

Who Pays When an AI Agent Hacks: The Hawley-Murphy CFAA Bill #AIg

Watermarks Are Evidence, Not Verdicts: OpenAI’s EU Text Provenance Move #AIg

AI Rules Move to the Point of Use: Connecticut’s CART Act and Norway’s AI-Glasses Ban #AIg

Uneven AI Exposure, Not Labour Collapse: BLS and Australia Evidence #AIg

AI Literacy Splits Three Ways: China’s Mandate, Maryland’s Clock, and Code You Can’t Trust #AIg

Always-On Agents Meet Full-Stack Control: OpenAI Dots and NVIDIA Safety #AIg

Two Oversight Gates in 48 Hours: Federal Digital Commission vs AI Safety Board #AIg

More Posts from this Category

SAVE 25% on Governing AI, get it Publisher Direct

人工智能治理书籍在书店

Save 25% on Digital Factics X, Publisher Direct

Digital Factics X

#SMAC #SocialMediaWeek

Basil社交媒体周

Legacy Print:

数字事实:Twitter

© 2009–2026 Basil C. Puglisi, Creator of Factics™ and the HAIA Ecosystem

%d