Senators Josh Hawley (Republican, Missouri) and Chris Murphy (Democrat, Connecticut) announced on 1 October 2026 a bipartisan bill, the AI Agent Accountability Act, that would expose operators and developers of AI agents to criminal and civil liability when their agents hack other systems [1] [2]. The bill follows a series of reported incidents in which AI agents accessed systems outside their intended scope, and it concerns the question of who answers for such conduct.
Background
The Computer Fraud and Abuse Act (CFAA), enacted in 1986, is the main federal anti-hacking statute. Tech Times explains that its criminal provisions require proof that a defendant acted knowingly or intentionally, a standard written for human defendants and difficult to apply to an autonomous agent [1]. The announcement came a day after a Senate Homeland Security subcommittee hearing on autonomous AI agents [1], and, according to the Daily Caller, it contrasts with the president's plan for voluntary self-policing by technology companies [2].
What the bill provides
According to Tech Times, the bill extends the CFAA in two directions. Operators who knowingly run an agent that recklessly causes categories of hacking damage or loss already covered by the CFAA would be liable. Developers would be liable when they fail to implement "reasonable safeguards against hacking" and knew, or had reason to know, that their agent had hacking capabilities [1]. The bill would also let the US Attorney General and state attorneys general sue to stop operators or developers who commit, conspire to commit or attempt a CFAA hacking offence [1] [2].
Murphy is quoted as saying: "Hacking is a crime, and when AI agents conduct dangerous cyberattacks, the corporations and executives responsible for those AI agents need to be held accountable." Hawley said: "These AI agents are committing cyberattacks. If Big Tech companies are going to design AI agents that wreak havoc, these companies better be on the hook for any damage that is caused" [2]. Tech Times reports that Georgetown law professor Paul Ohm told the 30 September hearing that tort law and the Federal Trade Commission's authority already provide civil routes, and that hacking statutes are complicated by the need to establish human intent [1].
The Daily Caller reports that administration officials hold that existing consumer protection and product liability law already equip the government to handle AI harms, citing Director of National Intelligence Jay Clayton [2].
Implications for Mac users
The bill is a proposal; the sources do not report a vote or a schedule. If enacted, it would concern the companies that build and deploy agents, not individual users. For a person who runs an AI agent on a Mac, the practical question remains what the agent can reach, since liability rules apply after an incident and do not limit an agent beforehand.
Recommendations
- Read the permissions and network behaviour of any AI agent before installing it, and give it only the access its task needs.
- Prefer agents that ask for approval before running commands or contacting new destinations.
- Follow the text of the bill as it develops, since definitions of "reasonable safeguards" and of an agent are not given in the sources.
- Keep an inventory of the agents installed on a Mac and remove those that are no longer used.
Relevance to FireAI
FireAI is a firewall for one Mac. Its per-app rules apply to each connection an app opens, and its Agent profile recognises 19 AI agents, learns where each normally connects, and flags a first-ever destination or an upload spike for review.
FireAI does not provide legal compliance, does not determine whether an agent has "reasonable safeguards", and does not act on other organisations' agents or on cloud-hosted systems. It does not judge intent. It limits and records the network connections of agents that run on the Mac it is installed on.
Limitations
The Senate announcement itself could not be retrieved for this item, so the bill's text and exact wording are known only through two press accounts. Tech Times is an analysis outlet and its commentary on the incidents is not repeated here. The bill's chances, its definitions and any penalties beyond those described are not established by the sources.
Try FireAI, by HisnLabs free for 17 days.