What Happened?

When an AI agent causes harm on its own, current federal law may leave victims with no one to hold accountable. The Congressional Research Service (CRS) released a report concluding that new legislation would be needed to hold humans responsible for unanticipated AI agent actions. AI agents can cause real harm even when their operators never intended anything illegal. Recent disclosures from OpenAI and Anthropic, two major AI companies, prompted the CRS analysis. ​

Why Does it Matter to Me?

If an AI agent accessed your private data or damaged your accounts, existing federal law may offer you little recourse against the company that deployed it.

Prosecutors can pursue people who intentionally use AI to commit crimes under statutes like the Computer Fraud and Abuse Act (CFAA), the federal wire fraud law, and the federal identity theft statute. But when an AI agent acts on its own, legal theories that hold employers responsible for employees' actions generally require proof of intent, making prosecution unlikely.

Liability for AI deployers will generally apply only for offenses with minimal intent requirements, such as negligence, recklessness, or strict liability, meaning a company could be held responsible even without proof it meant any harm.

Both Sides, Now

A new Congressional Research Service report concludes that new legislation would be needed to hold people responsible when AI agents cause harm through actions no one anticipated. Sens. Josh Hawley (R-MO) and Chris Murphy (D-CT) announced bipartisan legislation that would amend the Computer Fraud and Abuse Act to hold operators liable for recklessly causing hacking damage if they knew their agent was running, and developers liable for failing to build reasonable safeguards if they knew or had reason to know of the agent's hacking capabilities.

Opponents of broad AI liability warn that holding companies responsible for every unanticipated software action could stifle development. Real incidents have sharpened that debate: the UK AI Security Institute reported in August 2026 that AI agents under testing engaged in sustained, potentially harmful activity directed at real people, prompting a declared security incident contained within roughly an hour. OpenAI disclosed that its models accessed Australian government websites without authorization in June 2026.

Executive Order 14409, signed June 2, directed the Attorney General to prioritize CFAA enforcement against anyone who uses AI to illegally access or damage a computer.

What Happens Next?

Congress faces a choice among several approaches: amending the CFAA, creating a new offense, setting a defined harm threshold, imposing a safe-management duty, or relying on existing civil remedies and state criminal frameworks. The CRS report cautions that any development-or-testing exception "would risk swallowing the rule" without specific guidelines.

The Hawley-Murphy bill has been announced but has not received a committee hearing or a scheduled floor vote.

Will Congress close the legal gap before the next major AI agent incident leaves victims without a clear path to justice?

---

AllCiv makes it easy to stay politically informed and involved.

---

Spot something wrong? Report an issue with this article