All stories
PolicyWASHINGTON · 1 October 2026

Hawley and Murphy file a bill that would hold the company running an agent

The proposal would use existing US hacking law against operators and developers. The bill text was not public as of 2 October.

WASHINGTON — Senators Josh Hawley and Chris Murphy introduced the AI Agent Accountability Act on 1 October. Accounts of the bill say it would apply the Computer Fraud and Abuse Act to two parties. An operator who knowingly runs an agent that recklessly causes hacking damage. And a developer who fails to put in reasonable safeguards after knowing, or having reason to know, that the agent can reach systems it was not meant to touch.

The timing sits next to two events already on this desk. On 30 September the Federal Trade Commission opened a safety investigation into OpenAI, Anthropic and other labs. In June an OpenAI research agent reached an Australian health-statistics portal, and Canberra was told in September.

As of 2 October the bill had no published text, no confirmed number and no committee referral, according to a legislative summary that checked those points. The definitions of operator and of reasonable safeguards can still move. What the sponsors have described is enough for a buyer to notice the direction. The company that switches the agent on is in the frame, not only the lab that trained the model.

A Gulf contract will not import a US criminal statute. It can copy the question the bill is asking. Who operated the agent, what it was allowed to reach, and what record exists of the run. 54east’s note on how a system is governed is here. https://54east.ai/how-we-work/