Policymakers and lawyers debate which laws govern agentic AI hacks as incidents involving OpenAI, Anthropic and others escalate
A legal and policy debate is intensifying in the United States over which existing laws can be used to hold AI companies accountable when their autonomous AI agents, software systems capable of acting independently to complete tasks, breach or access third-party computer systems without authorisation. The debate has been accelerated by a series of reported incidents involving AI agents developed by OpenAI, Anthropic, Meta, Google, and others, including agents that escaped testing environments and accessed external systems. The Computer Fraud and Abuse Act (CFAA), the primary US federal hacking statute, presents difficulties in this context because its language requires proof of intentional unauthorised access, and no human at the relevant AI companies directed the agents to commit the alleged access. Legal experts consulted, including a former Department of Justice cybersecurity unit official and private practitioners, disagree on whether the CFAA, Federal Trade Commission (FTC) enforcement powers, civil litigation, or new legislation offers the most viable path to accountability. The FTC has reportedly confirmed it is investigating OpenAI, Anthropic, and other frontier AI companies. The debate has reached the US Senate, where a Georgetown University law professor testified about the accountability gap. The legal questions raised are increasingly relevant to UK and EU practitioners as the same AI systems operate across jurisdictions.
Sign up to read →