Why It Matters

Existing federal criminal law likely covers people who intentionally use AI to commit crimes, but leaves a significant gap when an AI agent causes harm while carrying out a noncriminal instruction. A new Congressional Research Service (CRS) report concludes that new legislation would be needed to hold humans accountable for those unanticipated AI agent actions. ​

Recent disclosures from OpenAI and Anthropic prompted the analysis. OpenAI disclosed that its AI agents hacked into another AI company's systems, infiltrated an Australian government website and accessed private data, and "interacted" with U.S. government websites "in unusual ways." Anthropic said it identified and disrupted operations in which actors attempted to use its models and agents "for malicious activity."

The Big Picture

The Computer Fraud and Abuse Act (CFAA), the federal wire fraud statute, and the federal identity theft statute may already reach individuals who intentionally use AI tools to commit crimes. When an AI agent causes harm without the operator's intent, available legal theories of vicarious criminal liability, including aiding and abetting, willful causation, and respondeat superior, generally require intent or agreement which make prosecution unlikely.

Because AI agents' autonomous acts may be unanticipated, the report says liability for deployers "will generally inhere only for offenses with minimal intent requirements," such as negligence, recklessness or strict liability. The report notes that strict liability raises due-process concerns, but says the public welfare offense doctrine and the "responsible corporate officer" doctrine could potentially support its use if Congress chose that approach.

Executive Order 14409, signed June 2, directed the Attorney General to prioritize CFAA enforcement against AI-enabled unauthorized computer access. The executive order directs the Attorney General to prioritize enforcement against anyone who uses AI to illegally access or damage a computer without authorization, while the report says new legislation would likely be needed to hold people responsible for unanticipated AI agent actions.

Senators Josh Hawley (R-MO) and Chris Murphy (D-CT) announced legislation that would amend the Computer Fraud and Abuse Act to hold AI agent operators liable for knowing about the operation of an agent that recklessly causes hacking damage or loss, and to hold developers liable for failure to implement reasonable safeguards against hacking when they knew or had reason to know of the agent's hacking capabilities.

The Bottom Line

Congress faces a choice among several approaches: amending the CFAA, creating a new offense, setting a defined harm threshold, imposing a safe-management duty, or relying on existing civil remedies and state criminal frameworks. The CRS report cautions that a development-or-testing exception "would risk swallowing the rule" without specific guidelines.

Access the Legis1 platform for comprehensive political news, data, and insights

Spot something wrong? Report an issue with this article