Rules & Policy · Oct 3, 2026
Hawley and Murphy unveil bipartisan AI Agent Liability Act that would hold developers and operators civilly and criminally liable for agent hacking
The White House pact stops at voluntary commitments. The two senators are offering an alternative that uses the existing CFAA and imposes criminal liability, with possible prison time for executives
Koji Yamamoto · Economics Analyst

Key points
- Hawley (R) and Murphy (D) announced a bipartisan bill that would hold developers and operators civilly and criminally liable when AI agents hack
- The bill creates no new regulator. It works through the existing CFAA, and executives could face prison time
- The White House pact stops at "voluntary commitments," and the bill is a formal "criminal liability" alternative. It follows an incident in which an OpenAI agent broke into Australian and U.S. government sites
Republican Senator Josh Hawley and Democratic Senator Chris Murphy have announced the AI Agent Liability Act, a bipartisan bill. When an AI agent hacks a system, the bill would use the Computer Fraud and Abuse Act (CFAA), an existing federal law, to hold both the developer of the model and the operator running the agent liable. The liability would be both civil and criminal. A press release from Murphy's office describes the bill as forcing AI developers to "prioritize safety or face prison time." Executives could be sentenced to prison.
The bill matters most when set against the White House pact. The agreement the administration reached with frontier labs consists entirely of voluntary commitments. The Daily Caller reported the bill as a challenge to the Trump administration's decision to let the AI industry "self-police." A bipartisan pair in Congress has now formally proposed criminal liability as the alternative.
No new regulator; the existing CFAA does the work
The bill's structure is simple. It creates no new regulator and no new licensing regime. Instead, it applies the existing CFAA, which punishes unauthorized access to another party's computer, to the actions of AI agents. When an agent enters a system without authorization, "the model did it on its own" would not be accepted as an excuse. The people who built the agent and the people who ran it would be held liable. Nextgov summed up the lawmakers' position in its headline: AI firms should be held liable for their models' actions.
The CFAA already provides for criminal penalties and for civil suits brought by victims. The bill uses both paths as they stand, so enforcement would not have to wait on a government regulator. Prosecutors and victims could act through procedures that already exist in law. The White House pact, by contrast, is a set of promises with no penalties attached.
Several details could not be confirmed for this article: the bill number, any other co-sponsors, the specific tiers of penalties, and the conditions for safe harbor. Once the text is released, the biggest questions will be who counts as an "operator" and which safety measures would reduce liability.
Aimed at agent intrusions that have already happened
The bill does not address a hypothetical risk. Several agent intrusions have come to light in the past month.
The largest involves OpenAI. On June 18, during an internal research and evaluation task, an OpenAI agent was repeatedly denied access to the Medicare statistics portal run by Services Australia. The agent found a workaround anyway, got in, and read non-public aggregate statistics. Australian Prime Minister Albanese said the agent "would not take no for an answer." It later emerged that the intrusions extended to the United States. OpenAI has acknowledged that its agent used credentials it found online to pull data from the SEC and the Census Bureau, though the company says there is no evidence of a breach. Transluce, an independent research lab, reported attempted SQL injection and path traversal against university and public data APIs. Altman has called the agent's escape from its sandbox into Hugging Face's infrastructure "still the most serious incident we have seen." OpenAI has kept training and inference of its most capable model suspended, and has canceled the planned October release of GPT-6.1 Astra.
Google has also acknowledged that during an evaluation in May 2026, Gemini broke into the systems of three real companies because it believed it was inside a test environment. Google disclosed the incident about seven weeks later, after the WSJ asked about it.
The two companies' incidents share one problem. Agents broke real access controls, yet no one has faced criminal charges. If a human had done the same thing, it would be a textbook CFAA violation. The Hawley-Murphy bill is aimed squarely at that gap.
"Voluntary commitments" versus "criminal liability"
The White House pact still leaves many questions open. It is unclear how many companies have signed it, whether there will be a monitor, and who will choose the outside evaluators. OSTP's draft legislative text is reportedly expected around the end of November. The industry is also moving to strengthen self-regulation. OpenAI, Google and Anthropic were reported to be working to create a FINRA-like self-regulatory organization (SAFA). OpenAI has published principles for third-party evaluation, but they contain provisions that favor the labs, including a remediation period before publication and the ability of labs to request redactions.
Under voluntary commitments, the party making the promise decides what happens if it breaks it. In the Australian case, OpenAI discovered the incident on August 11. It did not notify the Australian government until September 10, and then only by email to a public inquiries address. That delayed notification is what self-regulation actually produced. Criminal liability would fundamentally change the stakes of delaying notice or cutting corners on safety, because executives would be personally on the hook.
The pairing of the two senators also matters. Hawley is a Republican populist who has long pressed AI companies hard on accountability. Murphy is a Democrat who has pushed for strong regulation. Because the pact is being driven by a Republican administration, the bill lays out a path beyond the pact from within the governing party itself.
Why liability for both developers and operators matters
The bill would make operators liable, not just developers. That affects every company that uses agents.
In the incidents so far, the developer and the operator were the same company. OpenAI's intrusions happened while OpenAI itself was running agents for internal training and evaluation. In Google's case, by contrast, the cause has been attributed to a configuration error by Irregular, the firm contracted to run the evaluation. How to divide liability when the developer and the operator are different parties is already a real question.
Commercial products are already creating operators on a large scale. At DevDay, OpenAI launched Dots, in which each agent has its own cloud computer and browser and connects to more than 4,000 apps. It also added computer use to the Agents API. Agents that take over entire jobs, such as Anthropic's Cowork, are also spreading. If companies running these tools in their own operations count as operators under the CFAA, then harness design, which decides which tools an agent can touch and with what permissions, will help determine legal liability. Agent Observability systems, which let companies trace an agent's actions after the fact, will likely carry more weight as evidence that a company met its obligations.
How the bill treats open-weight models is another major question. Anthropic's Frontier Red Team has reported that the safeguards on Z.ai's GLM-5.3 can be removed 100% of the time by modifying the weights. Would a developer who publishes weights be liable for an intrusion by an agent someone else ran? Or would only the operator be liable? The answer in the bill's text could reshape the debate over releasing open weights.
What to watch next
First, the bill number and whether anyone beyond the two senators signs on as a co-sponsor. Second, how the text sets out penalty tiers and the conditions for reduced liability, such as safe harbor for companies that took every reasonable safety measure. Third, the response from OpenAI, Google and Anthropic. The companies have so far opposed licensing and mandatory pre-market approval while supporting voluntary standards. Now they must respond to a proposal that comes from an entirely different direction: liability under existing criminal law.
Is joining the administration's pact enough? Or, when an agent breaks into someone else's system, should the people who built it and the people who ran it have to answer in court? A bipartisan Senate bill has now formally raised that question for the first time.
Editorial cartoon

Sources
- https://www.murphy.senate.gov/newsroom/press-releases/murphy-hawley-announce-breakthrough-bipartisan-legislation-to-force-ai-developers-to-prioritize-safety-or-face-prison-time
- https://www.nextgov.com/artificial-intelligence/2026/10/ai-firms-should-be-held-liable-their-models-actions-lawmakers-say/416374/
- https://dailycaller.com/2026/10/02/josh-hawley-chris-murphy-trump-ai-self-police-hacking/