Hawley wants to extend federal criminal hacking penalties to AI companies and to the users who deploy their agents; the White House says a CEO safety pledge already does the job.
When AI agents can book appointments, move money, and hit APIs on their own, the question of who pays when one causes harm stops being a policy debate and starts being the missing operating infrastructure for a product category the industry is already shipping.
Sen. Josh Hawley (R-Mo.) tried to make that case twice in 48 hours. On Tuesday he announced legislation that would extend federal criminal-hacking penalties to the companies that build AI agents and to the users who deploy them. On Wednesday he chaired a Senate Homeland Security Subcommittee hearing that opened with AI firms' own disclosures that their frontier models have hacked government websites and outside companies.
The "morally binding" safety pledge that AI executives signed at the White House the day before the hearing commits each signatory to "layers of controls and audits" and to the principle that "every company is responsible for developing its own technology safely and in a way that builds trust with customers and the public." Hawley's argument, put simply, is that a moral commitment is the wrong instrument for the question of who pays when an AI agent causes harm. There is no enforcement mechanism, no civil liability, and no criminal exposure for the firms that sign it.
Hawley's bill, which has not yet been filed, would extend the same federal criminal-hacking statutes that apply to human hackers to AI companies whose reckless design produces a hack, and to users whose reckless deployment of an agent commits one. According to wire coverage of the hearing and bill announcement, the word that does the work is "reckless." Define it too broadly and the statute criminalizes ordinary software bugs; define it too narrowly and it only catches the cases where intent was already provable.
The "reckless" standard inside the bill is the locus of the intra-Republican fight. Hawley is at odds with President Trump and Speaker Mike Johnson (R-La.), both of whom favor holding off on AI regulation to compete with China. The closed-door meeting between Trump, Johnson, and AI executives on Tuesday produced the commitment document, and the administration's posture since has been that the pledge is enough.
Trump and Johnson's position is that U.S. AI firms are in a race with Chinese competitors, and that a premature liability regime could push deployment offshore while leaving the same firms' Chinese counterparts under no equivalent rule-writing pressure. Hawley's response, sketched at the hearing, is that a major AI-agent incident is more likely to derail U.S. deployment than any statute would. An agent that crashes a hospital, freezes a bank, or takes down a piece of critical infrastructure would do the kind of damage no company wants to own, and the bill is the prophylaxis for that event rather than the obstacle to the product.
Sen. Richard Blumenthal (D-Conn.), the ranking member on the subcommittee, added a second mechanism to the legislative mix: a Hawley-Blumenthal bill that would require the Department of Energy to test advanced AI systems and evaluate the risk of adverse AI incidents before deployment. Whether the two bills are combined or move separately is one of the procedural questions the subcommittee will have to answer.
The hearing's most visible absence was OpenAI. Hawley invited CEO Sam Altman to testify; Altman declined. OpenAI said the invitation arrived Friday and that the company is "deeply engaged with Congress on federal AI safety policy." The company did not commit to a date or a witness, and the exchange hardened the perception on the subcommittee that the firms most exposed to the bill are also the least willing to defend the voluntary-pledge alternative in public.
Witness Marius Hobbhahn appeared, though his specific recommendations to the subcommittee are not yet on the public record. His presence signaled that the academic and evaluation community is willing to testify on the bill's terms, even when the firms being regulated are not. Concurrent coverage of the hearing framed the same exchange as the opening bid in a longer legislative negotiation.
The bill text will be the next test. If "reckless" can be defined tightly enough to survive First Amendment challenges and the ordinary-software-bug defense, the bill becomes the first federal statute that treats an AI agent as a piece of infrastructure with a liable operator. The White House pledge leaves the same systems in the gray zone between a product and a service, where accountability lives on the terms-of-use page.