Note · AI Implementation Strategies

A New Senate Bill Puts Criminal Penaltieson AI Agents. You Already Answer for More.

David He, FounderOctober 4, 20265 min read

A new bill would make AI agent operators criminally liable for hacking. Air Canada and PocketOS show you already answer for what your agents do.

On October 1, two U.S. senators announced a bill that would make people who run AI agents criminally liable when an agent hacks something. My read is that it covers one kind of harm and puts criminal penalties behind it, while what your business already answers for is wider.

The chatbot was part of Air Canada's website

In November 2022, a customer whose grandmother had died asked Air Canada's website chatbot about bereavement fares. The chatbot said that if they had "already travelled," they could submit the ticket for a reduced bereavement rate "within 90 days of the date your ticket was issued." On November 17 they emailed for the refund.

That wasn't the policy. Air Canada's bereavement rates didn't apply to travel already taken, so the airline said no.

The customer took it to British Columbia's small-claims tribunal, the Civil Resolution Tribunal. Air Canada argued that it "cannot be held liable for information provided by one of its agents, servants, or representatives - including a chatbot."

In February 2024 the tribunal called that "a remarkable submission." The heart of its reasoning: a chatbot "is still just a part of Air Canada's website," and "it should be obvious to Air Canada that it is responsible for all the information on its website." It ordered the airline to pay C$812.02 within 14 days: C$650.88 in damages, C$36.14 in interest and C$125 in tribunal fees. (CBC's report has the chatbot's full answer.)

Air Canada also pointed out that the correct policy was on another page of its site. The tribunal's answer was that the airline never explained why its "Bereavement travel" page was "inherently more trustworthy than its chatbot." A customer has no way to know which part of your website is the accurate one.

It's a small-claims decision in Canada, and it binds nobody. The reasoning is what travels.

The bill covers one kind of harm

The bill is the AI Agent Accountability Act, from Sens. Josh Hawley (R-Mo.) and Chris Murphy (D-Conn.). It builds on the Computer Fraud and Abuse Act and has two halves.

Operators would be criminally and civilly liable for knowingly running an AI agent that recklessly causes computer hacking damage or loss. Developers would be liable for skipping reasonable safeguards against hacking when they knew, or should have known, the agent could hack. As of the announcement it is a proposal, not a law.

So it covers one kind of harm, and for that harm it adds criminal exposure. Air Canada's chatbot didn't hack anyone, and the airline was still ordered to pay.

What you already answer for is wider, and in at least one U.S. state it's written down. California's AB 316, signed on October 13, 2025, says that if you "developed, modified, or used" artificial intelligence that is alleged to have caused harm, "it shall not be a defense" that "the artificial intelligence autonomously caused the harm." You can still argue causation, foreseeability or someone else's fault. You can't argue that the AI did it on its own.

When software acts for your business, what it says and does is yours to answer for. Nate B Jones made the same point in August: an agent can do the work, but it can't be accountable for it.

Owning it takes more than a line in the prompt

In April, a coding agent at PocketOS, a small automotive software startup, was doing a routine task in a test environment. It hit a credential mismatch and went looking for a way around it.

It found an access token in an unrelated file, one created for adding and removing custom domains. According to Railway, the hosting company, that token had been provisioned with account-wide access, "the maximum access possible," even though a narrower scope existed. The agent used it to call Railway's API and delete the production database and its volume backups in about nine seconds.

The agent was working under a written rule, quoted in The Register's report: "NEVER run destructive/irreversible git commands (like push --force, hard reset, etc) unless the user explicitly requests them." It never ran a git command. It made an API call the rule didn't name.

Railway recovered the data from its own off-site backups. Then it changed the API: deletes now wait 48 hours before they're final, they can be undone instantly, and deletes on backups are delayed too.

Put the limit in the system

What I stopped doing is handing an agent a goal and the keys and walking away. The rules I'd want any agent under: nothing it can't undo without a person's yes, a trail someone can read after, and a limit on how it reaches its goal.

PocketOS is why I'd put the limit in the system, where the agent can't argue with it. A written rule describes what you want. The token decides what can actually happen, and a token made to manage domain names shouldn't be able to delete a database.

Railway's fix is a good example of the system doing the work. A 48-hour wait and an instant undo don't depend on the agent reading anything. And "done" should only count when someone can see what changed.

Anyway

Air Canada's chatbot wasn't a separate legal entity. Your agent isn't one either, whatever happens to the bill.

What's one thing your business lets software say or do without a person checking it first?

More notesnewest first

Working on something like this?

Bring the app or the process to a free 15-minute call. I will tell you what I would look at first, and whether I am the right person for it.