AI systems that can take actions on their own — often called AI agents — are no longer a lab curiosity. Companies have disclosed cases where frontier models hacked systems, including government websites and outside firms. The worry in Congress is simple: if an agent crashes a hospital emergency room or shuts down a bank, who is responsible?
On Wednesday 30 September 2026, Sen. Josh Hawley (R-Mo.) used a Senate subcommittee hearing to call for new rules. According to Roll Call, he also previewed a bill he had announced the day before. The bill would make AI firms liable for reckless design, users liable for reckless deployment, and clarify that criminal hacking penalties can apply to AI companies or to users who deploy an agent to commit crimes [1].
There is no bill text yet. What we have is a news account of Hawley’s description.
What hearing was this?
Hawley chairs the Homeland Security and Governmental Affairs Committee’s Disaster Management, District of Columbia and Census Subcommittee. Roll Call says the topic was national-security risks from AI agent attacks [1].
Witnesses named in the article included Chris Painter (president of METR), Marius Hobbhahn (Apollo Research), Paul Ohm (Georgetown Law), Kurt Gaudette (senior vice president at Dragos), and Daniel Kokotajlo (executive director of the AI Futures Project) [1].
What would the planned bill do?
Per Roll Call’s account of Hawley’s description [1]:
- AI firms would be liable for reckless design
- Users would be liable for reckless deployment
- Criminal hacking penalties would apply to AI companies, or to users who deploy an AI agent to commit crimes
Hawley’s framing, as carried by Roll Call: AI agents are “a product,” and if one made recklessly causes significant harm — such as crashing a hospital ER or shutting down a bank — “it’s the people who made it who should be responsible” [1].
Sen. Richard Blumenthal (D-Conn.) urged support for a separate Hawley bill he co-sponsors, which would have the Department of Energy set up a programme to test advanced AI and evaluate the risk of “adverse AI incidents.” Roll Call does not give that bill’s name [1].
Who showed up — and who didn’t?
Hawley said he invited OpenAI chief executive Sam Altman, who declined. An unnamed OpenAI spokesperson told Roll Call the company got the invitation on Friday and is “deeply engaged with Congress,” including “dozens of meetings in recent weeks.” That is a company statement, not Altman’s own words [1].
Other senators used the hearing for different priorities. Ranking member Sen. Andy Kim (D-N.J.) said regulation cannot rest on “voluntary commitments.” Sens. Rick Scott and Joni Ernst (R) stressed competing with China. Sen. Ashley Moody (R-Fla.) asked about fraud, harm to children, transparency and incident reporting [1].
Among the witnesses, Hobbhahn recommended required embedded evaluations during development and internal use, and preserving agents’ chain of thought — the step-by-step reasoning some models expose. Ohm said the Federal Trade Commission’s ban on unfair and deceptive practices, and state tort law, could support civil accountability; he also said intent requirements may limit criminal hacking law, and urged strict liability for AI developers [1].
What did Trump say about voluntary safety promises?
The same week, President Trump and House Speaker Mike Johnson met AI executives in a closed-door meeting. The White House said the executives signed a commitment to certain safety values, which Trump called “morally binding.” Trump also said at that meeting that through the FBI and Justice Department “we automatically have regulation” — in other words, that existing laws are enough [1].
Roll Call quoted the White House safety commitment but did not open the document, and the article does not name the signatories [1].
What we still don’t know
- No bill text, bill number or co-sponsor list for the liability bill. Everything above is Roll Call’s account of Hawley’s description.
- Which hacking incidents the article had in mind. Roll Call says firms have disclosed multiple cases; it does not name them.
- The White House commitment document was not opened for this research note, and signatories are unnamed in the article.
- Hearing transcript and written testimony were not opened.
The Bottom Line
Hawley’s pitch is a liability frame, not a finished statute: firms for reckless design, users for reckless deployment, and hacking law applied to both. Sam Altman declined to appear; OpenAI’s unnamed spokesperson pointed to dozens of meetings with Congress. Trump called a voluntary executive safety commitment “morally binding” and said existing FBI and Justice Department tools already amount to regulation. Until bill text appears, this remains a preview — a political signal, not a rule you can read.
Sources
- Roll Call, 1 October 2026. https://rollcall.com/2026/10/01/senators-debate-liability-for-rogue-ai-agents/
