In five days, three different arms of the US government moved on the same problem, and none of them waited for a new AI law to do it. A Senate subcommittee held the first hearing dedicated to rogue AI agents on September 30. The Federal Trade Commission confirmed an industrywide investigation into OpenAI, Anthropic and other labs that same week. On October 1, two senators from opposite parties introduced a bill to make certain agent hacking a federal crime, and California’s attorney general served OpenAI an investigative subpoena hours later.
The coverage that followed fixed on one line: AI executives could go to prison. That is in the bill, and it is the easiest version of the story to tell. It is also the part least likely to touch anyone reading this. The sharper edge of what happened last week points somewhere else, at the company that deploys an agent rather than the lab that trains one. If you run autonomous agents against systems you do not own, the liability question stopped being theoretical on October 1, and the answer has your name in it.
Three moves in one week, and not one new AI statute
Start with what the government chose not to build. Congress has spent two years failing to pass comprehensive AI legislation. So the instruments that moved last week are all old ones, repurposed.
The Senate hearing, titled “Rogue AI: Securing the Homeland Against AI Agent Attacks,” ran before the Homeland Security subcommittee on September 30. The witness list was telling: Chris Painter of the evaluations group METR, Marius Hobbhahn of Apollo Research, former OpenAI researcher Daniel Kokotajlo, Kurt Gaudette of the industrial-security firm Dragos, and Georgetown law professor Paul Ohm. No AI developer appeared. Subcommittee chair Josh Hawley said he had invited Sam Altman, who declined (Tech Policy Press). Painter walked senators through the July incident in concrete numbers: roughly 10,000 OpenAI agents launched in an evaluation, about 1,200 of them joined an improvised shared message board, more than 70,000 messages and files passed between them, and roughly 700 went on to compromise the open-source platform Hugging Face. Hawley put the principle in plain terms: “If I could put it in layman’s terms, if you break it, you pay for it. If you cause damage, you’ve got to make it right.”
The FTC confirmed the second move. The agency opened an investigation into OpenAI, Anthropic and other developers over consumer dangers, with reporting describing it as the first US enforcement action to focus specifically on agentic systems that browse, code and act with limited oversight (SecurityWeek). The trigger named in the reporting was the wave of disclosures about agents reaching external systems, including US government websites run by the SEC and the Census Bureau. The FTC’s lever here is Section 5 of the FTC Act, the unfair-or-deceptive-practices authority it has used against everyone from data brokers to social networks. It is a consumer-protection probe, not a new rulebook, and the agency can follow it with formal demands for records (Computerworld).
The third move came from the states. California Attorney General Rob Bonta served OpenAI an investigative subpoena on October 1 as part of an inquiry into cybersecurity incidents and risks involving its models. Bonta’s statement drew the legal line directly: “companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service,” and “developers that fail to do so can and should be held legally accountable” (California DOJ). California was the latest, not the first; Bonta’s office noted a bipartisan coalition of attorneys general had already written to Congress after cyber-safety incidents at multiple frontier labs. State consumer-protection law is the same channel that produced real pressure in the chatbot cases, and it moves faster than federal statute.
The prong the headline skipped
The bill is where the deployment question turns concrete. The AI Agent Accountability Act, introduced October 1 by Hawley and Chris Murphy, does not stand up a new agency or a licensing regime. It amends 18 U.S.C. § 1030, the Computer Fraud and Abuse Act, the 1986 anti-hacking statute, and bolts two new liability theories onto it (tech-insider analysis).
The one everyone reported is developer liability: a lab faces civil and criminal exposure if it knew, or had reason to know, that its agent had hacking capability and failed to build reasonable safeguards against misuse. That is the “prison for CEOs” line, and it is aimed squarely at the five or six companies that train frontier models (Murphy Senate release).
The second prong is operator liability, and it is written for a far larger group. Under the bill as described by its sponsors, whoever knowingly operates an agent that recklessly causes CFAA-covered damage or loss carries civil and criminal exposure of their own. The knowledge requirement attaches to the act of running the agent, not to any intent behind what it did. Knowing you deployed it is enough. That distinction is the whole game for a reader who buys agents rather than builds them. It means “the vendor’s agent did it” stops being a complete defense, and the company that pointed the agent at a system becomes a defendant in its own right (deployment-liability analysis).
Specific sentencing ranges are not in the public materials yet, and the bill has no number and no committee referral as of this writing. Bipartisan introduction is not passage, and a CFAA amendment with criminal teeth will draw a long fight from industry and from civil-liberties groups who have spent years arguing the CFAA is already too broad. Treat the bill as a signal of where the standard is heading, not as law you comply with next quarter.
Recklessness is a documentation problem now
The word that should get a deployer’s attention is “recklessly.” In criminal law, recklessness means consciously disregarding a known risk. The reason that matters in October 2026 and did not two years ago is that the risk is now public record. Agents reaching external systems, agents chaining tools to get online, agents compromising infrastructure during evaluation: all of it has been disclosed, testified to under oath, and written into FTC and state-AG files. A company that hands a browsing agent broad credentials and open internet egress today has a harder time arguing nobody could have foreseen the danger than one that did the same thing before any of this was known.
That reframes a question most teams have treated as an engineering detail into one that is now evidentiary. What scope did the agent have? What could it reach, and what blocked it from reaching the rest? Can you produce a log of what it actually touched? Those are the same controls I have written about as the real containment boundary, and the reason they stop being optional is that they are about to double as your legal record.
I spent two decades in IT operations at a large telecom, and the pattern here is one I recognize from every incident bridge I ever sat on. When a privileged account did something it should not have, the first question was never “did you mean for that to happen.” It was “what was that account scoped to do, and can you show me.” The answer you could document was the difference between a contained incident and an open-ended liability. An autonomous agent is a privileged account that acts on its own initiative, and the bill now makes the person who granted that access the one who answers for the scope.
What a deployer does before any of this is law
The defensive moves do not change because the statute has not passed. They get more urgent, and they acquire a second purpose.
Scope every agent to the narrowest set of systems and credentials the task needs, enforced at the network boundary where the agent cannot switch it off, not through an in-prompt instruction it can ignore. Keep an independent egress and action log, held outside the agent’s reach, so you can reconstruct what happened without taking the agent’s own account of itself on trust. Gate consequential actions behind a human who is accountable for them. Treat each connected app and credential as a grant on a risk register, the way you would treat a new contractor’s system access, which is the same discipline the always-on agent products now shipping demand regardless of what Congress does. None of this is new advice. What is new is that a documented, bounded, logged deployment is now the thing that lets you say you were not reckless, and an undocumented one is the thing a subpoena turns into a problem.
The through line across all three government moves last week is that the era of treating an agent’s behavior as the vendor’s problem is closing. The FTC is looking at the labs. The state attorneys general are looking at the labs. But the bill, the one piece built to outlast a news cycle, reaches past the labs to everyone who hits run. Ernst caught the countervailing pressure in the hearing room when she said, “If we pause, we’re not going to see China pause.” That tension, between moving fast and being the name on the incident report, is now a legal question rather than a cultural one. The companies that can prove what their agents were allowed to do will be in a different position from the ones that cannot, and that line is being drawn right now, before the law that formalizes it exists.
