What happened
On 1 October 2026 Sens. Josh Hawley (R-MO) and Chris Murphy (D-CT) announced the AI Agent Accountability Act, which would hold AI agent operators and developers criminally and civilly liable under the Computer Fraud and Abuse Act when their AI systems violate federal anti-hacking laws (knowingly operating an agent that causes damage/loss). It follows Hawley's 10 September investigation letter to OpenAI over the Hugging Face breach and the Senate hearing on rogue AI agent attacks that week.
Why it matters
This is the first legislative effort to make agentic-AI operators and developers directly liable for autonomous-agent hacking, potentially reversing the liability firewall between automated systems and their creators. It is central to the emerging federal discussion alongside the Warner AI Safety Board bill (blocked 9/29) and Cruz's catastrophic-risk bill.
Action needed
Deployers of autonomous agents should model CFAA liability scenarios now (who operates, who deploys, intent/vicarious elements) and tighten agent boundaries, since pending federal and active state liability frameworks are converging.