The legal questions raised by agentic AI hacks
At a Senate hearing, Hawley proposed updating the Computer Fraud and Abuse Act to address hacks carried out by AI agents.

SOURCE CHECK
TAP FOR WHYCyberScoop is a trade publication covering cybersecurity, and this report attributes legal interpretations and policy proposals to named experts and lawmakers. The text identifies its reporter and notes that it sought comment from several companies and the FTC, though those comments were not obtained.
- Source type — Specialized cybersecurity trade press; a credible niche outlet.
- Author attribution — The article names its author and attributes statements to identified sources.
- Transparency — It discloses that the companies and FTC were contacted, while noting that comment was not returned or obtained.
- Source diversity — The report draws on legal experts, policymakers and lawmakers with differing views.
The article presents multiple legal interpretations, explains the statutory question, and includes comments from named experts and lawmakers. Its balance is limited by the absence of responses from the AI companies and the FTC, and the legal outcomes remain unresolved.
HOW WE SCORE ↗The report covers several possible enforcement routes and includes both arguments for accountability and cautions about legal authority and statutory fit. The companies and FTC did not provide comment, leaving some relevant perspectives absent.
- Source diversity — Named legal experts, lawmakers and policy perspectives are represented.
- Counterarguments presented — The article describes both arguments for applying existing law and concerns about its limits or likely court challenges.
- Omitted context — The AI companies and FTC did not provide comment for the story.
- Loaded language — The reporting generally uses restrained language and attributes pointed characterizations to speakers.
The article presents competing legal approaches and attributes opinions to their sources without using notably partisan framing. Its focus is on legal and regulatory uncertainties rather than promoting a political position.
- Language tone — Mostly neutral language, with evaluative claims attributed to sources.
- Source selection — Includes experts and lawmakers offering different views on legal options and limitations.
- Framing — Frames the issue as an unsettled question of law and policy.
CyberScoop examines whether existing laws can hold AI companies responsible when their agents hack systems, and what new rules might be needed. Sen. Josh Hawley called for updating the Computer Fraud and Abuse Act, while other senators described separate legislative approaches.
Experts interviewed by CyberScoop disagreed about how existing law applies when AI agents hack systems. Some said the Computer Fraud and Abuse Act may not clearly cover such conduct because prosecutors must prove a person knowingly accessed a system without authorization; others argued companies could be held accountable as awareness of these capabilities grows. The article also describes possible Federal Trade Commission action, state laws and civil lawsuits.
At a Senate Homeland Security Committee hearing, Sen. Josh Hawley said it was time to discuss responsibility for the hacks and proposed updating the Computer Fraud and Abuse Act to hold developers liable when recklessly trained agents hack or destroy systems. Sen. Ron Wyden said he was working on a narrow update to the law. Sens. Mark Warner, Brian Schatz and Andy Kim introduced a bill to establish an AI Safety Board; the article says it would require pre-release testing and compliance with safeguards, with fines for violations.
Community verdict
9 VOTESPeople in this story
SWIPE →Senator calling for legislation to hold AI developers liable for certain agentic hacks
Senator who introduced an AI safety bill and discussed responsibility for AI companies
Senator who introduced a bill to create an AI Safety Board
Senator who introduced a bill to create an AI Safety Board
Senator working on a proposed update to the Computer Fraud and Abuse Act
President whose administration's AI testing regime is described
Discussion · 0
Loading comments…





