“It wasn’t me, it was the AI agent” may not help companies avoid civil or criminal liability under a new bipartisan legislative proposal.
U.S. Senators Josh Hawley (R-Mo.) and Chris Murphy (D-Conn.) have announced the proposed AI Agent Accountability Act, which seeks to hold AI-agent operators and developers liable for hacking incidents.
According to the senators’ announcement, the proposal would:
Hold AI-agent operators liable. Operators could face criminal and civil liability under the Computer Fraud and Abuse Act (CFAA), including for knowingly operating an AI agent that recklessly causes computer-hacking damage or loss.
Hold AI developers liable. Developers could face criminal and civil liability for failing to implement reasonable safeguards against hacking when they knew or had reason to know about an AI agent’s hacking capabilities.
The proposal would also authorize the U.S. Attorney General and state attorneys general to seek injunctions against AI-agent operators and developers that commit, conspire to commit, or attempt to commit a hacking offense under the CFAA.
The proposal reflects a broader regulatory and enforcement trend toward holding AI developers and deployers accountable for inadequate design and safeguards.