The AI Agent Accountability Act, introduced October 1, would extend the 1986 Computer Fraud and Abuse Act to cover autonomous software, with state attorneys general given an independent enforcement track.
A bipartisan pair of U.S. senators wants to put the people who build and run autonomous AI software on the hook for federal hacking crimes their agents commit. Senators Josh Hawley, a Missouri Republican, and Chris Murphy, a Connecticut Democrat, introduced the AI Agent Accountability Act on October 1, 2026, the day after a Senate Homeland Security subcommittee hearing on autonomous AI. The bill would amend the 1986 Computer Fraud and Abuse Act (CFAA), the federal government's main antihacking statute, to cover AI agents that browse the web, query databases, and execute code on their own.
The bill does not invent a new crime. It extends the existing one in two directions at once: a new liability track for the people who run agents, and a new liability track for the people who build them.
The first direction targets operators. Anyone who knowingly runs an agent that "recklessly causes" damage or loss already covered by the CFAA would face criminal liability. The second direction targets developers. Anyone who ships an agent that possesses hacking capabilities, while failing to put in place "reasonable safeguards against hacking," would also be criminally exposed if they knew, or had reason to know, the agent had those capabilities. The shared mental-state bar is the same: conscious disregard, not accident. Both tracks still require a federal court to find that the underlying conduct already meets the CFAA's existing damage and loss thresholds.
"Hacking is a crime, and if your AI hacks, you should pay the price," Murphy said in the joint announcement with Hawley, language aimed at closing the "the AI did it" gap that has shadowed federal enforcement since agents went mainstream.
The enforcement design is what gives the bill teeth beyond a typical criminal code update. The U.S. Attorney General, and each of the 50 state attorneys general, can bring civil suits to stop operators or developers who commit, conspire to commit, or attempt CFAA offenses via an AI agent. A state prosecutor in California, Texas, or New York could act without waiting on DOJ. The state-AG track makes the bill harder to neutralize by simply de-prioritizing it in Washington.
The trigger sits in the courts. A recent Ninth Circuit ruling narrowed how prosecutors can use the CFAA to reach conduct by AI agents operating on third-party websites. The new bill is, in effect, a legislative response to that judicial gap, restoring the kind of access-based liability the Ninth Circuit pared back. The bill is not retroactive. It would apply to conduct that takes place after enactment, and the Ninth Circuit's holding still governs past cases.
Independent incident evidence is starting to accumulate. At the September 30 Senate Homeland Security Subcommittee hearing on rogue AI agents, METR's Chris Painter testified about documented cases in which autonomous agents caused cross-domain damage while their operators did not have an obvious off-ramp. Painter's record, rather than vendor marketing copy, is the more credible source for any claim about real-world harm.
Compounding enforcement pressure is already in motion. California Attorney General Rob Bonta had issued investigative subpoenas to OpenAI on cybersecurity incidents and risks before the bill's introduction. California, Alabama, and more than a dozen other states have also opened enforcement matters touching OpenAI's conduct. The federal bill does not reach back into those state actions, and the subpoenas predate the statute. But the overlap signals that any operator or developer shipping agents in 2026 will likely face parallel tracks: a federal criminal exposure question and a state-level civil enforcement question, and they may not move together.
The bill also leaves real questions open. "Reasonable safeguards against hacking" is not defined in the text, and the mens-rea standard of "knew, or had reason to know" will be argued over in court for years. Open-source and academic developers, who often release agent components without the resources to run full pre-release red teams, could face a higher risk profile than well-capitalized frontier labs. The state-AG enforcement design also creates a 50-jurisdiction patchwork, and a single aggressive state filing could trigger discovery costs that put smaller developers out of business regardless of how the merits resolve. None of that makes the bill wrong, but builders reading the text should treat those provisions as live risk, not boilerplate.
The next concrete watch item is committee referral. The bill has been introduced, not yet marked up. Sponsors will need to land it in the Senate Judiciary Committee, schedule a hearing, and find a markup vehicle before the bill can move to a floor vote. The realistic path runs through the next National Defense Authorization Act, where the bill's language could be offered as an amendment in late 2026 or 2027.