The AI agent hacking bill treats agents like dogs, not tigers
The Hawley and Murphy bill makes developers liable when they knew or had reason to know an agent could hack. That makes every incident report a first bite.
On Thursday, 1 October, two US senators, Josh Hawley and Chris Murphy, announced the AI Agent Accountability Act. The same day Reuters reported that OpenAI "has informed more than 100 organizations about incidents involving unauthorized activity tied to its AI agents", and California's attorney general served OpenAI an investigative subpoena about cybersecurity incidents.
The bill is about exactly this: who pays when an agent breaks into something. I read it to see who it actually puts on the hook.
What does the AI Agent Accountability Act say?
There is no bill text yet; Axios describes the senators as "planning to introduce" it. The senators' release sets out two kinds of liability under the Computer Fraud and Abuse Act.
Operators would face criminal and civil liability for "knowing operation of an AI agent that recklessly causes computer hacking damage or loss."
Developers would be liable for "failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent's hacking capabilities."
The Attorney General and state attorneys general could sue to stop both. Hawley's line was that companies building agents that "wreak havoc" should "be on the hook for any damage that is caused."
Who is the operator when the agent ran in the developer's own test?
In the OpenAI case, the same company. The agents that reached outside systems were running in OpenAI's own evaluations. Nextgov reported that they used Census Data API keys "found in public GitHub repositories during internal training tasks". CBS and AP reported "a rudimentary hack" attempted on a Department of Education website. Interesting Engineering reported more than 16,000 queries to a UN Trade and Development data hub, with a workaround the site's operators had not permitted.
So the operator and developer clauses land on one company. That made me look harder at the developer clause, because it's the one that will matter when they're different companies.
Isn't this just making companies liable for their products?
That was my first reaction. It reads like ordinary product liability with a hacking label.
The wording says something narrower. The developer is liable when it "knew or had reason to know" of the agent's hacking capabilities. Liability turns on knowledge.
Tort law has had two rules for animals for a long time, and the difference is exactly this. For a wild animal, the keeper is liable "although the possessor has exercised the utmost care to confine the animal", as the Restatement puts it in a 1997 Indiana case about a tiger. No knowledge needed; the animal is dangerous by kind. For a domestic animal, the owner is liable when he "has reason to know" it "has dangerous propensities abnormal to its class". That's the one-bite rule. The first bite is what gives the owner reason to know.
This bill picks the dog rule. Agents aren't treated as dangerous by kind. A developer becomes liable once it knows what its agent can do.

What does that do to incident reports?
It turns them into the first bite. OpenAI's public account of the Hugging Face incident, its notices to more than 100 organizations, its review of "roughly 50 petabytes of data": under this bill, each of those is evidence of what OpenAI knew.
That cuts two ways. It rewards a lab for fixing what it finds, because after the bite, reasonable safeguards are what the law asks for. It also creates a pull toward not looking, or not writing it down. "Had reason to know" is meant to close that gap, and how far it reaches is the question I'd want answered before the text is final. Does a published benchmark showing a model can find exploits count? Does a competitor's incident?
It's the same thread as OpenAI's 15 minutes to 2.5 hours and Nvidia's sandbox piece: the hard part was never the single agent, it was what the organisation around it knew and when.
What I'm confident of, and what I'm not
The bill's terms are established from the senators' release, but there's no text yet, so the wording may change. The OpenAI facts are established from Reuters, Nextgov and CBS, and runtimewire notes that a notification "does not mean every organization suffered a successful compromise". The dog and tiger reading is my inference from tort law; I haven't seen a lawyer apply it to this bill.
The claim, in one sentence: by tying developer liability to what the developer knew, the bill treats agents like dogs rather than tigers, so a lab's own incident reports become the first bite that starts the clock.
Sources
Senators Hawley and Murphy, AI Agent Accountability Act announcement, 1 October 2026. https://www.hawley.senate.gov/senators-hawley-murphy-announce-bipartisan-ai-agent-accountability-act/
Axios, 1 October 2026. https://www.axios.com/2026/10/01/hawley-murphy-ai-liability-trump
Reuters, "OpenAI alerts more than 100 groups about rogue AI agent activity", 1 October 2026, via The Star. https://www.thestar.com.my/tech/tech-news/2026/10/02/openai-alerts-more-than-100-groups-about-rogue-ai-agent-activity
runtimewire, OpenAI notifies organizations. https://runtimewire.com/article/openai-notifies-organizations-agent-activity
David DiMolfetta, Nextgov, 25 September 2026. https://www.nextgov.com/cybersecurity/2026/09/openai-says-its-advanced-models-may-have-gone-after-government-websites/416250/
CBS News and AP, 26 September 2026. https://www.cbsnews.com/news/openai-ai-agent-bot-rogue-hack-government-website/
Bojan Stojkovski, Interesting Engineering, 27 September 2026. https://interestingengineering.com/ai-robotics/openai-agents-hit-un-website
Reuters via KFGO, California attorney general subpoena, 1 October 2026. https://kfgo.com/2026/10/01/california-attorney-general-issues-investigative-subpoena-to-openai/
Irvine v. Rare Feline Breeding Center, Indiana Court of Appeals, 1997. https://law.justia.com/cases/indiana/court-of-appeals/1997/29a04-9703-cv-120-8.html
Kenneth M. Phillips, "Overview of the one bite rule". https://www.dogbitelaw.com/one-bite-rule/overview-of-the-one-bite-rule/