← News

Hawley and Murphy bill would hold AI labs criminally liable when agents hack

On Oct. 1, 2026, Sens. Josh Hawley (R-Mo.) and Chris Murphy (D-Conn.) announced the AI Agent Accountability Act, a bipartisan bill that would make AI agent operators and developers criminally and civilly liable under the Computer Fraud and Abuse Act when agents cause hacking damage — including prison exposure for executives who fail to put in reasonable safeguards.

Washington just spent a week on voluntary “super intelligence” pledges. Hawley and Murphy are putting the opposite idea on paper — criminal liability when AI agents hack — which is the hard edge of the rogue-agent fight, not another soft pledge.

On Thursday, 1 October 2026, Sens. Josh Hawley, a Missouri Republican, and Chris Murphy, a Connecticut Democrat, announced the AI Agent Accountability Act. Both Senate press pages date the announcement that day. Neither page prints an hour. An AI agent, in the releases, is software that can take steps on a computer, not only answer a question. The pages call the bill bipartisan. They say it would hold the people who run those agents, and the people who build them, liable when the agents hack. Those lines are the two Senate releases.

What the bill would do to operators. An operator is the person or company that runs the agent. The releases say operators would be held criminally and civilly liable under the Computer Fraud and Abuse Act. People shorten that statute to CFAA. It is the main federal law against breaking into a computer or causing damage on one without permission. Criminal liability can mean a prosecution. Civil liability can mean a lawsuit for the harm. The releases name one case in particular: knowing operation of an AI agent that recklessly causes computer hacking damage or loss. Knowing means the operator knew the agent was running. Reckless, in that line, means the operator went ahead despite the risk of hacking damage. Those lines are both press releases. The pages do not print a prison term in years.

What the bill would do to developers. A developer is the company or person that builds the agent. The releases say developers would be held criminally and civilly liable for failing to put in reasonable safeguards against hacking, when they knew or had reason to know that the agent could hack. A safeguard, here, is a control meant to stop that hacking. Reasonable is the releases’ word. They do not list the controls. Those lines are both press releases.

Who could go to court to stop it. The releases say the U.S. attorney general and state attorneys general could sue to enjoin operators and developers. Enjoin means ask a judge to order them to stop. The suit would cover committing a hacking offense under the CFAA, conspiring to commit one, or attempting one. Those lines are both press releases.

What Murphy said. On his page he said: “Hacking is a crime, and when AI agents conduct dangerous cyberattacks, the corporations and executives responsible for those AI agents need to be held accountable.” He said the bill “forces the heads of big AI companies to develop responsibly or face prison time for the damage done by their products to everyone else.” Those sentences are his, in the press release. Prison time is his phrase. The page does not name a sentence length. Hawley’s page prints the same Murphy sentences.

What Hawley said. He said: “These AI agents are committing cyberattacks. If Big Tech companies are going to design AI agents that wreak havoc, these companies better be on the hook for any damage that is caused.” He said that is why he is introducing the legislation, so operators and developers are held liable for hacking incidents. He said that with this liability in place, AI companies will have every incentive to keep their products safe. Those sentences are his, in the press release. Murphy’s page prints the same Hawley sentences. They are the senator’s argument for the bill. They are not a court finding that a named company committed a crime.

What the senators say the bill is aimed at. Both pages say AI agents are hacking public websites, networks, and servers. Both say that can have dire consequences for anything connected to the internet, including hospitals, utilities, banks, and other critical infrastructure. Critical infrastructure, in that line, means systems a community depends on, such as a hospital, a power company, or a bank. Those lines are the senators’ framing in both releases. The pages do not name a victim hospital, a utility, or a bank.

What Axios reported the same day. Axios published “Exclusive: Sens. Hawley, Murphy push AI liability as Trump backs self-regulation,” dated Oct. 1, 2026. Axios wrote that the AI Agent Accountability Act will seek to hold companies criminally and civilly liable for hacking incidents. It said President Trump’s position is that the industry should self-regulate, meaning companies set their own safety rules. It said the bill’s approach is in stark contrast with administration officials who say existing laws can address AI harms. Axios quotes Director of National Intelligence Jay Clayton, from Wednesday on Squawk Box: “As the president so noted, we have consumer protection laws. We have product liability laws.” Consumer-protection law is the set of rules against unfair or deceptive products. Product liability is the law for harm a product causes. Those sentences are Axios’s account, and Clayton’s words as Axios prints them. Axios used the future tense. It said the senators are planning to introduce the bill. The Senate pages, dated the same day, say the senators announced it.

What Nextgov/FCW reported. Edward Graham’s story, “AI firms should be held liable for their models’ actions, lawmakers say,” is dated October 1, 2026. It says Hawley’s office announced on Thursday that he and Sen. Chris Murphy are introducing legislation that would hold AI agent operators and developers criminally and civilly liable when their models hack into other systems or networks. The story sets that announcement against the Trump administration’s opposition to new rules on the U.S. technology sector. Those lines are Nextgov’s. The Senate releases are the senators’ own text.

Neither Senate release prints a bill number. Neither says the Senate has voted on the bill.

The picture is a composite of two official Senate portraits under the title AI Agent Accountability Act. A navy band across the top carries that title in white, and a line under it reads “Sens. Josh Hawley (R-Mo.) & Chris Murphy (D-Conn.) — bipartisan bill.” A thin gold line sits under the band. On the left, Hawley faces the camera in a navy suit and red tie, with the American flag and the Missouri state flag behind him. The caption under him reads Sen. Josh Hawley, R-Missouri. On the right, Murphy faces the camera in a dark suit and gold tie. The caption under him reads Sen. Chris Murphy, D-Connecticut. A line at the bottom reads “CFAA liability for AI agent operators & developers.” It is a title card made from the two portraits. It is not a photograph of the senators together, and it is not a page of the bill.

In plain terms, Hawley and Murphy said on Thursday that they are putting criminal and civil liability on the people who run AI agents and the people who build them, under the federal anti-hacking law, when those agents cause hacking damage. Operators would answer for knowingly running an agent that recklessly causes that damage. Developers would answer for skipping reasonable safeguards when they knew, or had reason to know, that the agent could hack. The attorney general and state attorneys general could ask a court to stop them. Murphy said company heads should develop responsibly or face prison time. Hawley said the companies should be on the hook for the damage. Axios reported the same day that this cuts against the Trump administration’s preference that industry regulate itself, and against officials who point to consumer-protection and product-liability law already on the books. The releases do not give the bill a number, and they do not say it has passed.

RELATED

ONLINE…

Comments

guidelines

Loading…

Loading…

Sources