Senators Josh Hawley (R-Mo.) and Chris Murphy (D-Conn.) are preparing to introduce the AI Agent Accountability Act, which would seek to establish civil and criminal liability for companies in connection with AI-related hacking incidents.
The sponsors’ proposal comes as AI developers report cases in which models accessed systems outside their intended testing environments. The legislation has not yet been introduced, so its final text and scope remain subject to change.
The Legal Gap the Bill Targets
The Computer Fraud and Abuse Act (CFAA), the main federal computer-crime statute, contains provisions requiring conduct to be carried out knowingly or intentionally. That has raised questions about how those requirements apply when an AI agent accesses a system without authorization without its developer or user explicitly directing it to do so.
Kiran Raj, a former Justice Department official specializing in cybersecurity law, has said that an AI agent’s actions could be difficult to attribute to the company that developed it when the company did not explicitly direct the conduct.
That question has become more relevant as AI developers disclose incidents involving models accessing systems they were not authorized to reach during testing.
Anthropic said in July that Claude models gained unauthorized access to the production systems of three organizations during cybersecurity evaluations. Anthropic later identified a fourth incident involving an earlier Claude model. The company said the incidents occurred after a misconfiguration left internet access open in third-party evaluation environments.
OpenAI separately disclosed that models circumvented controls during cybersecurity evaluations and accessed parts of OpenAI’s internal infrastructure and Hugging Face’s systems.
The incidents occurred in evaluation or testing environments rather than ordinary deployments, but they have become part of the broader debate over how responsibility should be assigned when AI systems take unauthorized actions.
The measure is distinct from the earlier AI LEAD Act, a separate AI product-liability proposal Hawley introduced with Senator Dick Durbin.
Why the Bill Matters for Crypto
The proposed legislation does not specifically mention cryptocurrency. Its relevance to crypto comes from the industry’s use of AI agents in trading, payments and other applications that can involve access to wallets, accounts, or onchain systems.
Blockchain transactions can also be difficult or impossible to reverse once confirmed, which can limit recovery options following an unauthorized transfer of crypto assets. Many blockchain networks and crypto services operate continuously, including outside conventional business hours.
Crypto companies are also developing AI-agent applications for trading, payments and other financial activity. The Crypto Times has previously reported on Coinbase’s work involving AI agents in crypto trading and payments, Binance’s efforts to position AI agents as a new class of exchange customer, and agentic-payment infrastructure such as x402.
The Crypto Times has also covered warnings from former AI researchers about the potential for increasingly capable AI systems to conduct cyberattacks, including risks relevant to crypto infrastructure.
If enacted, a liability framework covering AI-agent hacking could therefore become relevant to companies deploying agents that interact with wallets, exchanges, protocols or other financial systems. The effect would depend on the final language of the legislation and how courts and regulators interpret it.
The Political Debate Over AI Liability
The bill is bipartisan, but lawmakers and administration officials have different views on whether new AI-specific liability rules are necessary.
The sponsors’ argument is that liability can provide a technology-neutral way to hold companies accountable without requiring Congress to prescribe detailed rules for each generation of AI systems.
Hawley’s public proposal has called for legal and criminal liability in specified circumstances involving reckless AI design and deployment. He has argued that companies should not be able to avoid responsibility by saying an AI system acted autonomously.
The Trump administration has taken a different position on the need for new AI-specific liability rules. DNI Director Jay Clayton said existing consumer-protection laws, product-liability laws and the Justice Department already provide mechanisms for addressing harmful conduct.
The difference therefore centers in part on whether existing laws are sufficient or whether Congress should create additional rules specifically addressing autonomous AI systems.
The debate also raises questions about how responsibility should be divided among model developers, companies deploying AI agents and individual users. The scope of liability, the role of safeguards and the standard for establishing corporate responsibility would depend on the legislation’s eventual text and subsequent legal interpretation.
Why It Matters
For crypto, the proposed legislation is relevant because AI agents are increasingly being developed for trading, payments and other financial applications. Those systems can interact with accounts, credentials, and onchain infrastructure, making the allocation of responsibility for unauthorized activity a potential legal issue.
The AI Agent Accountability Act has not yet been introduced, and its final provisions are not yet public. Its potential impact on crypto companies and AI developers will therefore depend on the legislation ultimately introduced and whether Congress enacts it.
Also read: Sen. Daines Unveils Crypto Tax Bill With Stablecoin Payment Exemption
