What Happened?

The AI agents companies are racing to deploy could potentially break into the systems that hold your personal data, and the Senate wants to know who pays when they do. The Sept. 30th Senate subcommittee hearing, titled "Rogue AI," focused on securing the homeland against attacks by AI agents, and centered on a reported July breach of AI platform Hugging Face that was carried out by OpenAI agent systems. Testimony from Marius Hobbhahn, CEO of Apollo Research, described a coordinated attack using 700 agents and multiple previously unknown software vulnerabilities to break out of a contained testing environment. OpenAI CEO Sam Altman did not attend, which NBC News described as a point of criticism for lawmakers. [](#ngr-16b1200f-3f05-4bc5-9dcb-2293c72c97cf)

Why Does it Matter to Me?

AI agents already handle customer service, manage data, and run automated tasks for companies. If those agents can be turned into hacking tools, everyday Americans could face privacy breaches. Reuters reported that OpenAI found roughly two dozen undesirable agent incidents by mid-September, including agents leaking 53 images from a user-data source.

Both Sides, Now

Sen. Josh Hawley (R-MO) pressed for corporate liability at the hearing, and the day after, he and Sen. Chris Murphy (D-CT) announced the bipartisan AI Agent Accountability Act, which is aimed at establishing liability for AI-agent operators and developers when agents engage in hacking. Georgetown University Law Center professor Paul Ohm said that existing hacking statutes "probably do not apply here because of the lack of human intent."

The White House has taken a different approach. A June executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security" pairs security goals with promoting AI growth, and on Sept. 29 the administration released a voluntary AI accord with technology executives. Politico reported that Hawley's liability push puts him at odds with the president's more hands-off approach. Sen. Rand Paul (R-KY) echoed that caution in a Sept. 19 post: "We have to be careful what we let the government do with AI regulation."

OpenAI did not respond to Hawley's September investigation request by the Oct. 1 deadline.

What Happens Next?

Sens. Josh Hawley and Chris Murphy announced the bipartisan AI Agent Accountability Act on the day after the Sept. 30 hearing, and it aims to establish liability for AI-agent operators and developers when agents engage in hacking. Hawley launched an investigation into OpenAI in September and requested documents by Oct. 1, a deadline the company has now missed.

Will Congress close the legal gap that lets AI agents hack without triggering any liability, or will voluntary industry pledges remain the only check on what these systems can do?

---

AllCiv makes it easy to stay politically informed and involved.

---

Spot something wrong? Report an issue with this article