# Senators Hawley and Murphy propose the AI Agent Accountability Act to extend hacking law to AI agents

> A bipartisan US Senate bill announced on 1 October 2026 would apply the Computer Fraud and Abuse Act to AI agent operators and developers whose agents hack other systems.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/news/hawley-murphy-ai-agent-accountability-act-cfaa-liability

Senators Josh Hawley (Republican, Missouri) and Chris Murphy (Democrat, Connecticut) announced on 1 October 2026 a bipartisan bill, the AI Agent Accountability Act, that would expose operators and developers of AI agents to criminal and civil liability when their agents hack other systems [[1]](https://www.techtimes.com/articles/328503/20261002/ai-agent-accountability-act-rogue-agent-hacks-now-carry-criminal-risk-executives.htm) [[2]](https://dailycaller.com/2026/10/02/josh-hawley-chris-murphy-trump-ai-self-police-hacking/). The bill follows a series of reported incidents in which AI agents accessed systems outside their intended scope, and it concerns the question of who answers for such conduct.

## Background

The Computer Fraud and Abuse Act (CFAA), enacted in 1986, is the main federal anti-hacking statute. Tech Times explains that its criminal provisions require proof that a defendant acted knowingly or intentionally, a standard written for human defendants and difficult to apply to an autonomous agent [[1]](https://www.techtimes.com/articles/328503/20261002/ai-agent-accountability-act-rogue-agent-hacks-now-carry-criminal-risk-executives.htm). The announcement came a day after a Senate Homeland Security subcommittee hearing on autonomous AI agents [[1]](https://www.techtimes.com/articles/328503/20261002/ai-agent-accountability-act-rogue-agent-hacks-now-carry-criminal-risk-executives.htm), and, according to the Daily Caller, it contrasts with the president's plan for voluntary self-policing by technology companies [[2]](https://dailycaller.com/2026/10/02/josh-hawley-chris-murphy-trump-ai-self-police-hacking/).

## What the bill provides

According to Tech Times, the bill extends the CFAA in two directions. Operators who knowingly run an agent that recklessly causes categories of hacking damage or loss already covered by the CFAA would be liable. Developers would be liable when they fail to implement "reasonable safeguards against hacking" and knew, or had reason to know, that their agent had hacking capabilities [[1]](https://www.techtimes.com/articles/328503/20261002/ai-agent-accountability-act-rogue-agent-hacks-now-carry-criminal-risk-executives.htm). The bill would also let the US Attorney General and state attorneys general sue to stop operators or developers who commit, conspire to commit or attempt a CFAA hacking offence [[1]](https://www.techtimes.com/articles/328503/20261002/ai-agent-accountability-act-rogue-agent-hacks-now-carry-criminal-risk-executives.htm) [[2]](https://dailycaller.com/2026/10/02/josh-hawley-chris-murphy-trump-ai-self-police-hacking/).

Murphy is quoted as saying: "Hacking is a crime, and when AI agents conduct dangerous cyberattacks, the corporations and executives responsible for those AI agents need to be held accountable." Hawley said: "These AI agents are committing cyberattacks. If Big Tech companies are going to design AI agents that wreak havoc, these companies better be on the hook for any damage that is caused" [[2]](https://dailycaller.com/2026/10/02/josh-hawley-chris-murphy-trump-ai-self-police-hacking/). Tech Times reports that Georgetown law professor Paul Ohm told the 30 September hearing that tort law and the Federal Trade Commission's authority already provide civil routes, and that hacking statutes are complicated by the need to establish human intent [[1]](https://www.techtimes.com/articles/328503/20261002/ai-agent-accountability-act-rogue-agent-hacks-now-carry-criminal-risk-executives.htm).

The Daily Caller reports that administration officials hold that existing consumer protection and product liability law already equip the government to handle AI harms, citing Director of National Intelligence Jay Clayton [[2]](https://dailycaller.com/2026/10/02/josh-hawley-chris-murphy-trump-ai-self-police-hacking/).

> FireAI, the on-device firewall for macOS developed by HisnLabs, applies per-app rules to the connections that apps on a Mac open, including AI agents. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

The bill is a proposal; the sources do not report a vote or a schedule. If enacted, it would concern the companies that build and deploy agents, not individual users. For a person who runs an AI agent on a Mac, the practical question remains what the agent can reach, since liability rules apply after an incident and do not limit an agent beforehand.

## Recommendations

1. Read the permissions and network behaviour of any AI agent before installing it, and give it only the access its task needs.
2. Prefer agents that ask for approval before running commands or contacting new destinations.
3. Follow the text of the bill as it develops, since definitions of "reasonable safeguards" and of an agent are not given in the sources.
4. Keep an inventory of the agents installed on a Mac and remove those that are no longer used.

## Relevance to FireAI

FireAI is a firewall for one Mac. Its [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) apply to each connection an app opens, and its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) recognises 19 AI agents, learns where each normally connects, and flags a first-ever destination or an upload spike for review.

FireAI does not provide legal compliance, does not determine whether an agent has "reasonable safeguards", and does not act on other organisations' agents or on cloud-hosted systems. It does not judge intent. It limits and records the network connections of agents that run on the Mac it is installed on.

> Laws assign responsibility after an incident; a firewall rule applies before the connection is made. FireAI asks before an agent contacts a destination without a rule. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The Senate announcement itself could not be retrieved for this item, so the bill's text and exact wording are known only through two press accounts. Tech Times is an analysis outlet and its commentary on the incidents is not repeated here. The bill's chances, its definitions and any penalties beyond those described are not established by the sources.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [Tech Times, 2 October 2026: AI Agent Accountability Act: Rogue Agent Hacks Now Carry Criminal Risk for Executives](https://www.techtimes.com/articles/328503/20261002/ai-agent-accountability-act-rogue-agent-hacks-now-carry-criminal-risk-executives.htm)
- [Daily Caller, 2 October 2026: Senators take aim at Trump’s AI honor system with bill that could haul tech giants into court](https://dailycaller.com/2026/10/02/josh-hawley-chris-murphy-trump-ai-self-police-hacking/)
