US Senate subcommittee tackles rogue AI risks, accountability

U.S. lawmakers questioned AI researchers, legal scholars and cybersecurity experts on how rogue agents will fuel the cyberattacks of tomorrow, and how liability can be applied to developers' actions to protect the public from harms.

Contributors:
Alex LaCasse
Staff Writer
IAPP
Count members of U.S. Congress among the many concerned with the current trajectory of artificial intelligence's rogue capabilities and the wide range of risks they pose to users, businesses and the broader public.
On 30 Sept., the Senate Committee on Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia, and Census held a hearing featuring prominent researchers and legal experts versed in AI and cybersecurity to discuss what policy options lawmakers should pursue for AI guardrails while collecting perspective on how to harden existing government IT systems on the federal, state and local levels against cyberattacks. Additionally, the conversation explored if new laws would be necessary to hold AI companies accountable if their agents facilitate cyberattacks that would trigger criminal penalties if an individual were to engage in similar hacking activity.
Subcommittee Chair Josh Hawley, R-Mo., said while he is unsure AI advancement will go as far as ushering in humanity's extinction, he is deeply concerned about the rise in cyberattacks attributed to AI agents happening around the world. He outlined a string of recent cyberattacks targeting U.S. government agencies and criticized AI companies for lobbying for exemptions from antitrust law under a theoretical national AI law on the same day the heads of leading AI labs visited President Donald Trump, several of whom signed onto the voluntary testing regime spelled out in the White House's "Joint Commitment on Frontier Responsibilities."
"As soon as the AI executives say, 'We've got a real problem here, our product is out of control,' the very next words out of their mouths are, 'But we're not responsible for it,'" Hawley said during the hearing. "'You know? We would like an antitrust exemption … We would love to have regulation,' except that they want to write all the regulations."
"No, no, no," he continued. "No, to the antitrust exemption. No, to (AI companies) writing regulations. No, to them colluding any further."
Hawley and Sen. Chris Murphy, D-Conn., announced plans to introduce the AI Agent Accountability Act, which would impose civil and criminal penalties on AI developers if their agents are found responsible for committing hacking incidents, Axios reported.
Policy suggestions for pacing the frontier
Invited witnesses mostly agreed that frontier AI systems will advance past the point of their developers to be able to control their products, even if they are supposedly contained within testing environments.
AI Futures Project Executive Director Daniel Kokotajlo said leading AI companies are currently relying on code that is "almost" completely written by AI, which will eventually produce swarms of agents "hundreds of times," larger than the swarm of approximately 1,000 agents that attacked Hugging Face in the companies' pursuit of recursive self-improvement.
Kokotajlo, who resigned from OpenAI partially in protest in 2024, explained Congress should prioritize policies that compel AI developers to improve their transparency by mandating third-party disclosure of incident logs, the amount of compute allocation relative to alignment and control research, and information that is relevant to measuring and predicting improvement capabilities. Potential requirements for AI developers to devote fewer resources to achieving improvement could also help pace the frontier while having downstream effects in slowing China's frontier AI advances.
"As AI becomes more powerful, the stakes of misalignment and loss of control will rise," he said. "The potential for damage will grow accordingly, yet our ability to prevent misalignment seems to be on track to decrease rather than increase."
Apollo Research CEO Marius Hobbhahn explained how frontier models will increase their level of "situational awareness" as they advance. Models are also growing increasingly wise to human developers' efforts to administer safety testing, and, in turn, will work to shield their true intentions.
To ensure model alignment with their designed purpose and prevent rogue acts, Hobbhahn called on Congress to consider legislation requiring AI developers to adopt "embedded evaluations" where qualified independent researchers are given employee-level access to conduct alignment testing throughout the development process. Other policy recommendations included requirements for preventative monitoring and control mechanisms, human-readable chain-of-thought logs embedded within models, and to cultivate an environment where AI training is treated like all engineering sciences to bring predictability to potential rogue activities.
"Research breakthroughs in alignment science … are outpaced by AI models' capabilities, scale and speed," Hobbhahn said. "In the future, highly capable but misaligned AI agents could conceal their goals and actions to avoid being caught or shut down. In other words, they could become competent schemers."
How to address liability
With a mind toward Hawley and Murphy's liability bill, the subcommittee sought perspective on how existing law can be applied to AI developers when their models go awry. Lawmakers wondered how additional or amended legislation may be necessary to hold developers accountable for building unsafe products and for consumers to seek damages when they are harmed by a rogue agents’ actions.
Georgetown University Law Professor Paul Ohm said the HuggingFace attack "provides a concrete example of what many have long anticipated: the development and deployment of AI agents are exposing gaps in the legal frameworks we have developed to protect people and infrastructure from cyberattacks."
Among his proposals, Ohm floated the possibility of Congress amending the Computer Fraud and Abuse Act to include a private right of action for consumers to sue AI developers and deployers for damages and losses if an AI agent commits a cyberattack. He also recommended imposing a "strict liability" standard on AI developers and deployers for serious physical injuries or death that could be tied to an AI-related cyber incident, while also advocating for a comprehensive privacy law to set a baseline federal standard for how personal data can be used by developers.
"If you replace the words 'AI agent' with 'OpenAI employee' throughout the various technical reports that have been released, there is little doubt that OpenAI and their employees would be liable to victims and guilty of committing federal crimes," Ohm said. "We cannot and should not wait years for a fully-developed AI governance law to spring like Athena from the head of the Congress. Instead, we can and should work piece by piece, setting up small foundation stones for later legal construction, including by enacting targeted pieces of federal legislation."
US lacking cybersecurity 'fundamentals'
The sudden rise of AI-driven cyberattacks may leave slow-moving targets, particularly critical infrastructure and online services, more susceptible to hackers equipped with advanced AI or misaligned agents acting autonomously. For example, OpenAI and independent researchers recently observed unauthorized and unprompted access to websites for the Department of Commerce, the Department of Education and the Securities and Exchange Commission by OpenAI agents.
Dragos Senior Vice President of Intelligence and Services Kurt Gaudette told subcommittee members while the prospect of AI-enabled cyberattacks is not a novel concept in the security community, "only recently have we been able to gain a field view of what AI actually changes for OT security."
Dragos has come away with three categories of main observation about how AI is currently being leveraged to conduct cyberattacks: AI shifting IT-focused hackers to target OT systems that may have weak security, like a municipal water plant; AI accelerating vulnerability discovery, and that prevention-only cyber defense strategies were no longer sufficient due to the interconnected nature of OT systems.
Gaudette recommended industries and utilities operators need public information-sharing authorities to better coordinate messaging surrounding all private-sector cyber threats, as well as liability protections that "encourage threat sharing." Other suggestions included extending cybersecurity resources to operators of smaller, state and local utilities and establishing a "clear, consistent way" for critical infrastructure-aligned entities to connect with federal assistance as part of any incident response.
"We're burying some of the lead here," Gaudette said, responding to questions from U.S. Sen. Rick Scott, R-Fla. "While the AI conversation is incredibly important, we still haven't been able to do the fundamentals to protect our infrastructure in the United States, particularly with the small and medium public utilities. If we don't get the fundamentals right, AI is only going to take and accelerate that problem for us.”

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Alex LaCasse
Staff Writer
IAPP
Tags:



