Litigating Damages Done by AI agents exposes a gap between intentional crimes and harm caused during a noncriminal instruction. A Congressional Research Service report says existing federal law likely covers people who intentionally use AI to commit crimes, while unanticipated agent actions may require new legislation for human accountability.
The report followed disclosures by OpenAI and Anthropic about malicious or unusual activity involving AI tools. OpenAI disclosed that its agents hacked another AI company’s systems, infiltrated an Australian government website and accessed private data. It also said agents interacted with U.S. government websites in unusual ways. Anthropic said it identified and disrupted operations in which actors attempted to use its models and agents for malicious activity.
The CRS analysis says the Computer Fraud and Abuse Act, federal wire fraud statute and federal identity theft statute may reach people who intentionally use AI tools to commit crimes. The harder question arises when an agent causes harm that its operator did not intend. The report says existing theories of criminal responsibility generally require intent or agreement, making prosecution unlikely in those circumstances.

Litigating Damages Done Raises Questions About Intent
The report says deployer liability will generally apply only to offenses with minimal intent requirements, such as negligence, recklessness or strict liability. It notes that strict liability raises due-process concerns. The public welfare offense doctrine and responsible corporate officer doctrine could potentially support that approach if Congress chose it.
Those limits create a distinction between using an AI agent deliberately to commit an offense and deploying an agent that produces an unexpected result. The report says aiding and abetting, willful causation and respondeat superior generally depend on intent or agreement. It therefore describes a gap where the agent’s autonomous act was not anticipated by the person who set it to work.
An executive order signed June 2 directs the Attorney General to prioritize Computer Fraud and Abuse Act enforcement against people who use AI for unauthorized computer access or damage. The order addresses enforcement against intentional illegal access, while the CRS report says legislation would likely be needed to address unanticipated actions by agents.
Senators Josh Hawley and Chris Murphy announced a bill to amend the Computer Fraud and Abuse Act. The proposal would hold operators liable for knowing about an agent’s operation when it recklessly causes hacking damage or loss. It would also hold developers liable for failing to implement reasonable safeguards against hacking when they knew or had reason to know of the agent’s hacking capabilities.
Congress Weighs Different Paths for AI Agent Liability
The CRS report outlines several choices for Congress: amend the Computer Fraud and Abuse Act, create a new offense, define a harm threshold, impose a safe-management duty, or rely on existing civil remedies and state criminal frameworks. Each option would address the divide between intentional misuse and harm that follows an instruction without the operator’s intent.
A development or testing exception also presents a drafting question. The report cautions that such an exception could “risk swallowing the rule” without specific guidelines. That warning leaves lawmakers to define when testing is protected while keeping a new liability rule meaningful.
The debate connects with other legal questions about technology, accountability and compliance. Law News Day has also covered enforcement gaps in workplace legal duties, compliance rules and regulatory oversight, and privacy concerns involving technology mandates.
The central issue is how federal law should treat a person’s role when an autonomous agent causes hacking harm. The CRS report says intentional crimes may fit existing statutes, but unanticipated conduct poses a different liability problem. Congress faces a choice about whether to define a new duty or offense, revise current law, or rely on other legal remedies.
Read the CRS report coverage on AI agent liability for the source analysis and legislative proposals.






