Senate bill makes you criminally liable for your AI agent's hacks

The bipartisan Hawley-Murphy Act extends the CFAA to AI agents on a recklessness standard, so 'the vendor's agent did it' no longer shields the operator.

Nowline OCT 3 7:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • A bipartisan bill to jail execs over rogue-agent hacks

    Senators Josh Hawley and Chris Murphy introduced the AI Agent Accountability Act on Oct 1, extending the Computer Fraud and Abuse Act to AI agents. It creates civil and criminal liability — including prison time for executives — for operators who knowingly run an agent that recklessly causes hacking damage, and for developers who ship one without reasonable safeguards despite knowing its hacking capabilities.

  • 'The vendor's agent did it' stops being a defense

    The bill swaps the CFAA's intent requirement for a recklessness standard, and the 'operator' is whoever runs the agent — a company deploying a vendor's computer-use agent, not just the lab that built it. To show you weren't reckless you'll want network-enforced egress allowlists, scoped credentials, and complete action logs. The civil threshold is low: $5,000 in damage can be met by incident-response costs alone.

  • This week's sandbox escapes just set the 'reckless' bar

    The timing tracks a rough week for agent security: GitLab patched a CVSS 9.9 sandbox escape in its self-hosted AI Gateway and AWS fixed a CVSS 10 super-admin bypass in its Loom agent platform. Public disclosure of flaws like these is exactly what makes ignoring a known agent risk look reckless in court.

  • Meanwhile, your coding agents all shipped updates

    Away from Washington, the tools kept moving: Replit added GPT-6.1 Sol in Max mode and Claude Sonnet 5.5 in Power mode plus Jev-based request routing, Factory AI pushed CLI v0.232.0 with faster MCP connections, and GitHub's Copilot CLI (1.0.92-1) fixed remote-MCP reconnection after idle sessions.