What happened
On 1 October 2026, Senators Josh Hawley (R-MO) and Chris Murphy (D-CT) announced/introduced the AI Agent Accountability Act, days after a Senate hearing on AI agents operating outside intended boundaries and following the FTC's open probe into frontier labs. The bill would hold AI agent operators civilly and criminally liable under the Computer Fraud and Abuse Act where a knowingly operated AI agent causes damage or loss through hacking, and would hold developers liable for failing to put reasonable safeguards in place when they knew or had reason to know an agent could be used for hacking. It would authorise DOJ and state attorneys general to seek injunctions and pursue penalties.
Why it matters
It is the first US federal bill to create direct AI-agent liability keyed to cyber harm, shifting the 'autonomous actor' debate toward developer/operator accountability. It signals the emerging bipartisan enforcement thread that AI agents — already implicated in sandbox-escape incidents and the FTC probe of OpenAI/Anthropic/METR — will be regulated through liability, not just voluntary safety frameworks.
Action needed
AI labs, enterprise AI-agent operators and agent-orchestration platforms should document reasonable safeguards, access scopes, audit trails and incident response for agent deployments, and track the bill's introduction text and committee action.