
AI Agent Accountability Act Targets Hacking Liability
Published by AINave Editorial
Senators Josh Hawley and Chris Murphy are planning the AI Agent Accountability Act, a bill that would seek to hold companies criminally and civilly liable for hacking incidents involving AI agents. The proposal makes a practical question about agentic systems a legal one: when an AI agent hacks a system, who can be held responsible? The senators argue that existing law leaves that answer uncertain, according to Axios’s report on the planned legislation.
The proposal centers on responsibility, not a technical rulebook
The reported approach focuses on liability for harm rather than prescribing a particular way to build or test AI systems. A source familiar with the legislation told Axios that Hawley’s office sees liability as simpler than writing rules for technology that changes quickly. That is the office’s rationale, not evidence that the proposal would be simpler to apply or that liability would prevent incidents.
The available reporting does not spell out the bill’s legal test, penalty amounts, or how responsibility would be divided among developers, operators, and other companies. So the proposal signals a direction, but does not yet tell AI teams what conduct would trigger liability or what safeguards might meet a legal standard.
A disagreement over whether current law is enough
The bill contrasts with the Trump administration’s stated preference for industry self-regulation. Director of National Intelligence Jay Clayton argued that existing consumer-protection and product-liability laws, along with federal agencies, can address AI harms. Hawley and Murphy’s concern, as reported by Axios, is more specific: current law may not make clear who is liable when an agent hacks a system. The competing positions are about whether familiar legal frameworks can handle a new operational problem or whether Congress should clarify responsibility.
For builders, that distinction matters. A general claim that existing laws apply does not by itself settle which party bears responsibility when an agent acts through a product, service, or workflow. The bill’s significance will depend on the details of that allocation, which the reporting does not provide.
One bill in a crowded legislative field
Congress is also considering proposals on other parts of AI risk. Representatives Ted Lieu and Nathaniel Moran have a bill requiring a mechanism to shut down AI that poses catastrophic risk, while other bipartisan proposals address model testing, risk management, transparency, and cybersecurity. Separately, negotiations on Senate AI legislation were stalled as Congress approached election season, and Speaker Mike Johnson said the technology moves quickly enough to make consensus difficult, according to Axios.
The accountability proposal therefore enters a broader debate, not a settled regulatory framework. Its sharper focus on liability could make the question easier to state than a comprehensive set of technical rules. Whether it makes responsibility clearer in practice will turn on the bill text, especially how it defines a hacking incident and assigns responsibility across the people and companies involved.





















