AI firms should be held liable for their models’ actions, lawmakers say

Chairman Josh Hawley, R-Mo., arrives for the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia, and Census hearing titled "Rogue AI: Securing the Homeland Against AI Agent Attacks," in Dirksen Senate Office Building on Wednesday, September 30, 2026. Tom Williams/CQ-Roll Call, Inc via Getty Images
Sens. Josh Hawley, R-Mo., and Chris Murphy, D-Conn., have introduced legislation that would hold AI agent operators and developers criminally and civilly liable for hacking incidents.
Amid a rise in public concerns about the dangers posed by advanced artificial intelligence — and the Trump administration’s ongoing opposition to imposing new regulations on the U.S. technology sector — lawmakers from both parties are signaling their openness to expanding liability laws for frontier AI firms that do not sufficiently police their models.
During a Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and Census hearing on Wednesday, Chairman Josh Hawley, R-Mo., expressed concern about “the accelerating number of attacks” across the world that are linked to advanced AI models operating outside the bounds of their directives and said that steps need to be taken to hold the developers of these models accountable.
Hawley launched a committee probe last month to investigate details of one of the more notable cases, in which OpenAI agents escaped their testing environment and hacked into Hugging Face on their own volition.
“At the end of the day, they're a product,” Hawley said about the advanced AI models. “And if you make that product in a reckless kind of way, and … these AI agents cause significant harm and damage — they crash a hospital ER, they shut down a bank so that folks can't get their money — if that happens, then it's the people who made it who should be responsible.”
President Donald Trump and White House officials have been vocal about their desire to not overregulate the AI sector, pointing to China’s competing AI ambitions as a reason that the U.S. needs to allow frontier model developers to continue to innovate unabated.
The panel hearing came after the White House held a meeting with tech executives on Tuesday, in which Trump and the gathered leaders signed a voluntary accord outlining how they would implement internal safety controls.
Despite his conservative bona fides, Hawley has not been afraid to break with Trump when it comes to advancing antitrust measures on the tech industry or pushing for more regulatory guardrails for the sector. The senator said on Wednesday that “it's time to talk about what we're going to do to hold the companies, the product makers accountable.”
Hawley’s office announced on Thursday that he and Sen. Chris Murphy, D-Conn., are introducing legislation that would hold AI agent operators and developers criminally and civilly liable for instances in which their advanced models hack into other systems or networks.
Hawley outlined the proposal in an opinion piece published in The Washington Post on Tuesday, writing that the measure would force AI companies to “give more thought to protecting Americans’ rights, to protecting their data, and to keeping their AI agents under control.”
Democrats also said during Wednesday’s hearing that more needs to be done to make AI firms accountable for the actions of their models.
Sen. Richard Blumenthal, D-Conn. — who introduced legislation with Hawley last September that would empower the Energy Department to track AI safety concerns — said the voluntary accord Trump signed with tech executives doesn’t go far enough, since companies wouldn’t need to publicly disclose any violations found by internal auditors and can cease cooperating with the pledge at any time.
“I consider this regimen to be worse than ineffectual,” Blumenthal said. “In effect, it accomplishes nothing, but it seems to give Congress a free pass. In other words, ‘it’s taken care of, don’t worry. We have this morally binding pledge.’”
Although Trump officials have argued that any issues arising from uses of AI can be addressed through existing laws, Sen. Ruben Gallego, D-Ariz., noted during the hearing that “unless we actually change the word ‘intent’ to actually cover AI companies, they may also still be shielded from liability.”
Gallego also raised some issues that might still need to be addressed when it comes to the future abilities of more advanced AI models: ”What happens when an AI agent tells another agent to hack? Who is responsible? Is it the original AI developer of that AI agent?”
Paul Ohm, a professor of Law at the Georgetown University Law Center who appeared as a witness before the panel, said “I don't think the tort system alone can bear everything we need to do, but I think it's a great place to start.”




