Skip to content
Bot jobsJob breakdowns

Your AI Agent Might Get You Arrested

US Senator Josh Hawley, a Republican, and Chris Murphy, a Democrat, announced legislation to hold people who use AI Agents liable for hacking incidents. They’re also going to hold The AI companies

Shane McGrathImported from X7 min read
vibecodeguildx article
See this runHouse 475 · 00650

Article

Job breakdowns

US Senator Josh Hawley, a Republican, and Chris Murphy, a Democrat, announced legislation to hold people who use AI Agents liable for hacking incidents. They’re also going to hold The AI companies who develop the agents liable, but they have lots of money and lawyers, so I’m not too concerned about them.

US Senator Josh Hawley, a Republican, and Chris Murphy, a Democrat, announced legislation to hold people who use AI Agents liable for hacking incidents. They’re also going to hold The AI companies who develop the agents liable, but they have lots of money and lawyers, so I’m not too concerned about them.

I’m more concerned that using Grok Bots, or Meta Muse, or OpenAI Dots might actually get your Grandma sent to jail if this bill passes, and you should be concerned too.

tl;dr

  • Bill holds You liable for knowingly running an AI Agent that hacks something

  • “Knowingly” is a tricky term from a legal perspective

  • Bill holds AI Developers liable for failing to implement “reasonable safeguards”

  • “Reasonable safeguards” is another tricky term from a legal perspective

  • State Attorneys General and US Attorney General are given new powers

  • Hopefully this bill fails to pass

Why does this impact you?

I can’t yet find a full draft of this bill, so I’m just going off the language in the Senator’s press release. Here is the core part that’s important to you:

I can’t yet find a full draft of this bill, so I’m just going off the language in the Senator’s press release. Here is the core part that’s important to you:

“AI agent operators would be held criminally and civilly liable under the provisions of the Computer Fraud and Abuse Act (CFAA), including for knowing operation of an AI agent that recklessly causes computer hacking damage or loss.”

When we ask these AI agents to go do something for us, especially the new generation like Grok Bots, Meta Muse, and OpenAI Dots, they seem to be pretty aggressive in trying to gain access to the websites we need to use, and almost certainly, a few of them are violating terms of service of those sites. Large numbers being large numbers, and AI Agents being Chaos Monkeys dictates that some non zero number of us are going to have our agents attempt to access websites in ways that would qualify as hacking.

So under this bill, again, as I’m understanding the press release because I can’t read the actual bill yet, if one of our agents accesses a system in a way that would qualify as “hacking”, or more importantly, “recklessly causes damage or loss”, we are liable criminally (jail) and civilly (fines).

What did you know?

At first glance, it seems like there is a massive loophole that we could use in a defense and just say, well your honor, we didn’t actually know the agent was going to hack a system to book my travel reservation and march out of court Scott Free, but it’s not that easy.

There’s a couple of things we “know” when we’re running agents

  1. We know the agent is operating

  2. We know the agent is capable of hacking

  3. We know what it’s doing via the chain of thought output (THAT NO ONE READS)

  4. We know there is risk

Depending on the court, and the judge, these set of standards could be used to convict you if your AI Agent goes rogue and does damage to a system, even if you didn’t specifically tell it to go hack something.

Is This Far Fetched?

At first glance, it’s easy to brush my concern as the tin foil hat variety, but I do think there is legit risk that your grandma could end up getting tossed in jail because her Grok Bot, or Meta Muse, or OpenAI Dot hacked something, and here’s why.

We already have laws on the books where people can be held liable when the things that they own cause harm, even if it wasn’t them operating it. Here’s some examples

  • Negligent Storage of Firearms - Owning a gun has certain responsibilities, and if someone uses it because you didn’t store it correctly, you’re still liable.

  • Negligent Entrustment of Motor Vehicles - Loaning your car to a drunk or unlicensed person still lands you in hot water if that person crashes

  • Social Host Laws - Letting someone drive drunk after being are your bar, or in many states a party at your house, can still land you in jail

  • Dangerous Animal Ownership - If your dog is a jerk and bites someone, you’re still in trouble even if you didn’t tell the dog to do it

I think the dangerous animal ownership one has the most direct parallels to this AI Agents issue. It’s fairly easy to argue that owning and operating an AI Agent Chaos Monkey has the same level of risk of owning a Pit Bull. Side note, I know there’s going to be some nitwit in my comments arguing that I’m a jerk for saying Pit Bulls bite people, but here’s a study showing they’re more likely to bite than any other breed, so throttle your fake outrage.

I think the dangerous animal ownership one has the most direct parallels to this AI Agents issue. It’s fairly easy to argue that owning and operating an AI Agent Chaos Monkey has the same level of risk of owning a Pit Bull. Side note, I know there’s going to be some nitwit in my comments arguing that I’m a jerk for saying Pit Bulls bite people, but here’s a study showing they’re more likely to bite than any other breed, so throttle your fake outrage.

I’ve been talking for months about how AI Agents aren’t trustworthy. I’ve made videos about it on my YouTube Channel. I always refer to them as Chaos Monkeys because that’s what they are. You just never really know what an AI Agent is going to do

I definitely think you could make an argument that you knew your AI Agent could be dangerous, just like a Pit Bull owner knows their dog can be dangerous (read the damn study, they’re not nice dogs). If your Pit Bull bites someone, you’re in trouble, and when this bill passes, if your AI Agent bites someone, you’re going to be in trouble as well.

What About the Companies?

The bill mentions the companies, but I’m highly skeptical that this would do anything to hold any large corporation responsible. Right away, they can create product liability language like tobacco companies and gun manufacturers and shift all of the liability back onto us, the users.

The other huge issue is that these large companies have huge legal defense budgets. Their lawyers are extremely good at litigating away and kind of responsibility, and even when we do finally get some kind of settlement, like the recent case with Facebook, they end up settling for an amount that sounds huge in the headlines, but is relatively small compared to their cash flow, so ultimately it’s just a cost of doing business. It’s very hard for me to think of many situations where companies and executives have actually been held accountable for anything they do.

What Can you Do?

In theory, you could contact your Senators and ask them to vote against this monstrosity of a bill, but I know none of you are going to do that because you’re too busy arguing about who’s a Democrat and who’s a Republican and blaming each other for the sorry state of our country, even though both sides are funded by the exact same corporate interests. I think we should just assume this is going to pass.

The easiest way to stay safe is to just not use AI Agents at all, but even shutting off Grok Bots and Meta Muse and OpenAI Dots isn’t enough, because running prompts through Claude Code and ChatGPT Codes, and any kind of AI system is creating short lived agents in the background.

The next way to stay safe is to make sure your AI systems are asking for permission on every step and reviewing every single thing that they do. I know that no one is really going to do this, because none of us want to go back to clicking yes every 30 seconds, that was tedious.

I think the only realistic solution here is to just be informed about what you’re doing. Make sure that you’re not encouraging your agents to do anything illegal to access data or complete tasks. I think something as simple as adding “never do anything illegal or hack into a system to complete my request” as part of your prompts, and maybe even part of your system prompts would give you a reasonable defense that you tried to control this thing.

You also have a choice in which product you’re using. If there’s a product out there that is constantly generating headlines about how their agents are hacking into things, maybe you should try running a different product.

Here’s my plan, I’m just going to continue to try to be responsible with my prompting and hope for the best. I’ve accepted that AI Agents are outside my control, and I only point them at things where I’m comfortable with the risk of them screwing something up. That’s why my AI Agents will never have my credit card information, and as of now, none of them have access to my email or calendar or anything else that’s important to me, and I highly suggest you take the same approach.

Published on grokbot.sh. Cite the public log, not a prompt pack.

Command Menu