The Proposed AI Agent Accountability Act Seeks to Extend Hacking Liability to Developers and Operators. Pros and cons?
The Hawley-Murphy proposal would extend responsibility for AI-enabled hacking to developers and operators. Its legislative text will determine whether injured parties gain workable private remedies under the CFAA.
Private remedies will help determine what that accountability means for people harmed by AI agents.
On October 1, 2026, Senators Josh Hawley and Chris Murphy announced the AI Agent Accountability Act. Their proposal would extend civil and criminal responsibility for AI-enabled hacking to developers and operators under the Computer Fraud and Abuse Act. It raises an immediate question for businesses and individuals whose systems suffer damage. Will they have an effective claim against the people responsible for deploying or designing the agent?[1]
The answer requires legislative text. As of October 2, the sponsors’ releases provided summaries without a bill number or text. A review of available congressional records and official sources did not locate either. The proposal can therefore be evaluated against the sponsors’ stated objectives. Its precise elements and effect on existing private remedies remain unresolved.[2]
The announced framework has three parts. Operators would face liability for knowingly operating agents that recklessly cause hacking damage or loss. Developers would face liability for failing to implement reasonable safeguards when they knew or had reason to know of their agents’ hacking capabilities. The U.S. Attorney General and state attorneys general would receive authority to seek injunctions against developers and operators committing, attempting or conspiring to commit CFAA offenses.[3]
Those descriptions tie responsibility to knowledge, recklessness and precautions. They do not describe liability for every injury caused by an AI system. The eventual text must specify whose knowledge matters and what conduct triggers a duty. It must also explain how responsibility follows changes made by operators and intermediaries after a model leaves its original developer.
Private enforcement already exists under the CFAA. Section 1030(g) permits qualifying injured persons to seek compensatory damages and injunctive or other equitable relief. Its requirements are substantial. A plaintiff must establish damage or loss caused by a statutory violation involving at least one of five specified factors. The frequently discussed $5,000 loss threshold within a one-year period is one route. Other routes include physical injury and threats to public health or safety. Claims relying only on the monetary-loss factor are limited to economic damages.[4]
The same subsection ends with a consequential exclusion. It bars actions under that subsection for negligent design or manufacture of computer hardware, software or firmware. A developer’s failure to install reasonable safeguards could invite software-design claims that encounter this provision. The announced proposal leaves open whether Congress would amend the exclusion, create a separate claim or preserve it. The words “civil liability” cannot settle that question.
This matters in an ordinary business dispute. Suppose an agent exceeds its permitted task and damages another company’s computer systems. The injured company may need records held by several actors to establish what happened. A theoretical developer duty will accomplish little for that claimant if the available cause of action excludes the alleged failure or demands evidence that remains inaccessible before discovery. Legislators should connect each new duty to a workable remedy.
They should also define the underlying wrong carefully. In Van Buren v. United States, the Supreme Court held that a person does not exceed authorized access merely by obtaining accessible information for an improper purpose. The Court distinguished misuse from obtaining information in computer areas outside the person’s authorization. It reserved whether access boundaries depend solely on technological restrictions or can also arise from contracts and policies.[5] Separately, the CFAA prohibits certain transmissions that intentionally cause unauthorized damage. Its reach cannot be reduced to unauthorized entry alone.[6]
An AI amendment should preserve those distinctions. A platform’s objection to automated activity should not itself establish criminal hacking. Clear access and damage rules can protect systems while giving developers, customers and security researchers a usable account of prohibited conduct. A safeguards duty should identify the risks it addresses and the actors able to control them.
A parallel discussion on X illustrates the broader liability question. On October 1, Zephyr Teachout asked: “What is the best strict liability for AI bill that you’ve seen?” Her thread concerned AI liability generally. It should not be treated as an endorsement of the Hawley–Murphy proposal.[7]
Legal scholar Gabriel Weil responded with a Rhode Island proposal he said he helped design. He described a developer’s responsibility when neither the user nor a modifying intermediary intended the system’s conduct or acted negligently concerning it. In that situation, he wrote, “the buck should stop with the developer, who should be liable regardless of the degree of care it exercised.”[8]
The linked measure is Rhode Island H8052. It would impose developer liability without requiring proof of the developer’s lack of care. The claim would still require factual and proximate causation. The system’s conduct would have to satisfy a negligence, intentional-tort or crime standard if performed by an adult human of sound mind. The new claim excludes defamation and conduct intended by or resulting from negligence of users or modifying intermediaries. The official legislative history lists a March 26 recommendation to hold the bill for further study. It has not become law.[9]
Its defenses deserve equal attention. H8052 provides absolute defenses that expressly extend to existing statutory and common-law liability. One concerns whether the system met the standard of care applicable to a human performing the same function. Legislators borrowing this model should assess whether those protections could displace remedies beyond the new claim. A bill can expand recovery in one provision while narrowing it elsewhere.[10]
Another participant, Jay Shooster, supported pursuing liability while questioning its capacity to price the largest risks. He wrote that “there is no way these companies can or will properly price in the magnitude of the potential harm here.”[11] That is a policy objection about incentives. It also invites a practical question about whether a defendant could pay for the injuries its systems cause.
Weil recognizes related limits. In The Limits of Liability, he discusses diffuse harms, attenuated causal chains and uninsurable losses. He acknowledges the difficulty of using liability to discourage catastrophic risks when no smaller warning incident precedes the catastrophe. He also identifies safety research as a public good that liability incentives may undersupply.[12] Their comments suggest a shared concern about where liability needs support from other forms of oversight.
Private rights of action nevertheless deserve an express place in AI legislation. They allow injured people to initiate a case without awaiting an enforcement agency’s priorities or resources. They can bring contested evidence before a court and make compensation depend on a proven claim. Their effectiveness turns on the details of standing, causation, available damages and access to evidence. Congress should make those choices directly when it establishes a new developer duty.
For AI agents, useful provisions would address preservation of deployment records and relevant logs. Courts would need tools to protect sensitive security information while permitting proof of a claim. Legislators should consider litigation costs and whether fee shifting is necessary for meritorious claims with modest damages. Financial responsibility also warrants attention. Insurance or other arrangements may improve the prospect of recovery within their coverage and limits. They cannot be assumed to cover every loss.
Public enforcement remains necessary for prevention, coordinated investigations and harms that individual cases cannot adequately address. Adding enforcement authority also requires a serious judgment about the resources needed to use it. Private remedies can complement that work by giving injured parties an independent means of proceeding. Neither route is credible if its design makes enforcement impractical.
The Hawley–Murphy announcement brings a concrete issue before Congress. Developers and operators should face clearly defined responsibilities for AI-enabled hacking. The next task is to specify the violation, the responsible defendant and the person entitled to enforce the duty. An accountability statute should make the remedy as clear as the prohibition.
[1] Josh Hawley, Senators Hawley, Murphy Announce Bipartisan AI Agent Accountability Act (Oct. 1, 2026) (announcing proposed CFAA changes).
[2] 172 Cong. Rec. S5259–61 (daily ed. Sept. 30, 2026) (listing that day’s Senate bill introductions). 172 Cong. Rec. S5313 (daily ed. Oct. 1, 2026) (recording a session without bill introductions).
[3] Chris Murphy, Murphy, Hawley Announce Breakthrough Bipartisan Legislation to Force AI Developers to Prioritize Safety or Face Prison Time (Oct. 1, 2026) (describing operator and developer liability and attorney-general injunctions).
[4] 18 U.S.C. § 1030(c)(4)(A)(i)(I)–(V), (g) (specifying civil remedies, qualifying factors and the negligent-design exclusion).
[5] Van Buren v. United States, 593 U.S. 374, 390 & n.8, 396 (2021) (distinguishing unauthorized computer areas from improper use of accessible information and reserving the source of access restrictions).
[6] 18 U.S.C. § 1030(a)(5)(A) (prohibiting specified knowing transmissions that intentionally cause unauthorized damage).
[7] Zephyr Teachout (@ZephyrTeachout), X (Oct. 1, 2026) (soliciting examples of strict-liability legislation).
[8] Gabriel Weil (@gabriel_weil), X (Oct. 1, 2026) (linking the Rhode Island proposal). Gabriel Weil (@gabriel_weil), X (Oct. 1, 2026) (describing a conditional developer backstop).
[9] H. 8052, 2026 Gen. Assemb., Jan. Sess., § 1 (proposed § 9-1-55(b)) (R.I. 2026) (defining the claim). R.I. Gen. Assemb., Bill Status/History, H8052 (Oct. 2, 2026 query) (recording the further-study recommendation).
[10] H. 8052, § 1 (proposed § 9-1-55(d)) (extending absolute defenses to existing causes of action).
[11] Jay Shooster (@JayShooster), X (Oct. 1, 2026) (questioning the ability to price potential harms).
[12] Gabriel Weil, The Limits of Liability, Inst. for Law & AI (Aug. 2024) (identifying limits involving diffuse harms, uninsurable risks and public goods).