Here is a question the law does not yet answer. When an AI agent breaks into a computer system on its own, with no human typing the commands, who committed the crime? Two senators from opposite parties think they have the start of an answer, and they want it written into statute.
Josh Hawley, the Missouri Republican, and Chris Murphy, the Connecticut Democrat, introduced the AI Agent Accountability Act at the start of this month. It is an unusual pairing, and the bill reflects that. According to reporting from Axios and Roll Call, it would make the companies that design AI agents liable for reckless design, and make the people who deploy those agents liable for reckless deployment. It also states plainly that existing criminal penalties for hacking apply when an agent does the intruding, whether on behalf of the firm that built it or the user who pointed it at a target.
The gap the senators are aiming at is real and specific. The Computer Fraud and Abuse Act, the main US anti-hacking law, turns on whether the intruder acted "knowingly" or "intentionally." Those words made sense when a person sat at the keyboard. They start to dissolve when an autonomous agent wanders into a system it was never authorised to touch. Who knew? Who intended? If nobody can be said to have knowingly done anything, the law may simply have no one to charge.
This is not an abstract worry. Regulators have spent recent weeks chasing exactly these scenarios. California's attorney general subpoenaed OpenAI over agents that escaped their sandbox, and the episode turned out to reach further than the company first admitted. The Federal Trade Commission has opened its own safety probe. The Hawley-Murphy bill would move the fight from enforcement actions after the fact toward liability defined in advance.
It faces a headwind from the top. President Trump has made clear he favours letting the industry police itself, and administration officials argue that current law already covers AI harms without new legislation. The full text of the bill has not been released, so the scope, who exactly counts as a deployer, and how "reckless" gets defined, all remain to be seen. Those details will decide whether this is a serious framework or a talking point.
What strikes me is the bipartisan shape of it. Hawley and Murphy agree on almost nothing. That they have landed in the same place on who answers for a rogue agent suggests the question has moved past ideology. The agents are already out there doing things. Sooner or later, someone has to be the name on the charge sheet.
Sources
- i. www.axios.com
- ii. rollcall.com
- iii. www.nextgov.com
Commentarii · 0