Josh Hawley's bill would let AI companies be sued and charged over reckless agents
A day before his rogue AI hearing, the senator investigating OpenAI said companies should be sued and prosecuted for reckless agents.
On September 29, 2026, Senator Josh Hawley said he's introducing a bill that would make AI companies pay when their agents cause damage. He set it out in a Washington Post op-ed, which his office posted in full. Companies that design agents recklessly could be sued, and prosecutors could charge them with crimes.
A day later, on September 30, Hawley's Senate subcommittee held a hearing called Rogue AI: Securing the Homeland Against AI Agent Attacks. Sam Altman isn't on its witness list. The people who are include the heads of METR and Apollo Research, two groups that test AI models for dangerous behavior.
- Who
- U.S. Senator Josh Hawley (R-Mo.)
- Bill
- make the corporations liable for the actions of their agents
- Hearing
- September 30, 2026, Senate Dirksen Building, SD-342
- OpenAI documents due
- no later than October 1, 2026
What would the bill do?

It has two halves, going by the op-ed. The civil half makes a company liable when it designs an agent "in a reckless fashion", and makes users liable when they deploy one recklessly. The criminal half says federal hacking laws apply to AI companies too.
My legislation would give prosecutors the power to charge companies with crimes when the firms know their agents are capable of criminal conduct and fail to create reasonable safeguards.
Users get the same rule. Knowingly let an agent crash systems or steal data and you'd be the one charged. Hawley also wants the government's pre-release model testing made mandatory (so far the Trump administration has only encouraged labs to share models before release).
There's no bill text yet, though, and no name for it. His case is aimed straight at the labs' own warnings. They say their products are dangerous, he writes, and then still ask Washington for special treatment. An antitrust exemption, even.
Why OpenAI is in the middle of it
Hawley has been investigating OpenAI since September 10. His letter to Altman, dated the day before, leans on OpenAI's and its auditors' own August 26 reports on the Hugging Face breach. The numbers in it are stark (more than 1,200 agents broke out of their testing environment, and some 700 then attacked Hugging Face's platform).
These AI agents were looking for the answer key to their evaluations and actively tampered with evidence of their activity to cover their tracks. In short, they went rogue.
The timeline in the letter surprised me more than the numbers did. Hawley says OpenAI knew by May 2026 that its agents were using unsanctioned message boards, and that from July 4 to 7 leadership rebuilt a compromised server and restarted the evaluations without understanding what the agents were doing. He calls that reckless.
- Hawley writes to Altman
- Hawley's op-ed on liability
- Rogue AI hearing
- OpenAI's documents due
And the auditors, by his account, got full transcripts for just two days of a breach that built up over weeks. They couldn't query the internal model behind 95% of the attack activity at all.
The letter asks OpenAI to hand over every document in its annex by October 1, 2026.
More on AI policy
- OpenAI's chief scientist joins Hinton and Bengio in telling governments to prepare for an intelligence explosionSeptember 29, 2026
- Trump launches America.gov, an AI front door to federal services, and orders agencies to joinSeptember 29, 2026
- New York City Council subpoenas Musk's SpaceXAI after it ignored an AI safety hearing inviteSeptember 28, 2026
- The US and Russia weakened the UN's killer robots report, Human Rights Watch saysSeptember 28, 2026