Artificial Intelligence and Federal Criminal Law: Considerations for Congress

Artificial Intelligence and Federal Criminal Law: Considerations for Congress
October 8, 2026 (LSB11487)

Recently, leading technology companies that have developed generative artificial intelligence (AI) models and agents disclosed certain cybersecurity incidents and cases of misuse related to their products. For instance, OpenAI disclosed that its AI agents hacked into the systems of another AI company called Hugging Face, infiltrated an Australian government website and accessed private data, and "interacted" with U.S. government websites "in unusual ways." Anthropic also recently indicated that in multiple instances, it has "identified and disrupted operations" in which "suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals" attempted to use Anthropic AI Claude models as well as AI agents "for malicious activity."

In light of these developments, some observers and government decisionmakers have begun to grapple with questions regarding the application of criminal laws when AI tools work to accomplish harmful acts autonomously. Although state legal systems and liability regimes may implicate distinct principles, this Legal Sidebar examines the applicability of existing federal criminal liability frameworks to AI agents and their makers, with an emphasis on mental-state requirements, and provides some considerations for Congress with respect to potential reliance on or supplementation of those federal frameworks to address AI tools.

Existing, Potentially Relevant Federal Offenses

As a starting point, individuals who use AI tools to accomplish criminal ends may be prosecuted under existing federal criminal provisions applicable to the individuals' conduct, just as they could when using other tools. For instance, one potentially relevant statute mentioned by some scholars and commentators is the Computer Fraud and Abuse Act (CFAA), which prohibits a variety of intentional or knowing conduct related to unauthorized computer access and could apply to individuals who use AI to obtain such access. Similarly, an individual who uses an AI tool to generate and disseminate fraudulent communications in order to obtain money or property from a victim could potentially be charged under the federal wire fraud statute, 18 U.S.C. § 1343. An individual also could potentially violate the federal identify theft statute, 18 U.S.C. § 1028, by using an AI agent to steal identification documents or authentication features. For some federal criminal provisions, including the CFAA, even an unsuccessful attempt to commit the crime is punishable when the actor has the requisite intent and takes a substantial step in that direction. Among other things, a June 2026 executive order instructed the Attorney General to prioritize enforcement of these three provisions (the CFAA, the wire fraud statute, and the identity theft statute) "and all other applicable Federal criminal laws against anyone who utilizes AI to illegally access or damage a computer without authorization, or who utilizes AI while engaged in such illegal access to further any other crime."

Beyond extant federal criminal liability for individuals who intentionally use AI tools for malign purposes, unanticipated AI agent conduct in the course of carrying out noncriminal instructions from human operators could still, at least facially, mirror the acts underlying some of the same criminal prohibitions just mentioned. Chief among these are the CFAA, which generally prohibits certain types of computer hacking. Absent any intent for the AI agents to have performed these acts, however, the humans deploying the AI agents could likely be held responsible only pursuant to a theory of vicarious criminal liability, which is similarly unlikely to apply for reasons related to intent.

Vicarious Criminal Liability

There are several avenues in current federal law for imposing vicarious criminal liability, but most require intent to commit a crime and thus may have limited applicability where an AI agent takes autonomous action. For example, 18 U.S.C. § 2(a) provides that any person who aids or abets an offense is punishable as a principal. Although the aiding and abetting provision does not have an explicit intent requirement, the Supreme Court has said a conviction for aiding and abetting requires proof of intent. Section 2(b) states that any person who "willfully causes an act to be done which if directly performed by him or another" would constitute an offense is punishable as a principal, explicitly requiring proof of intent to commit a crime.

Another form of vicarious criminal liability is the doctrine of respondeat superior, under which corporations can be responsible for the acts of their employees acting in the scope of their employment with the intent to benefit the corporation. The intent of the employee is imputed to the corporation, however, meaning that if the employee lacks the requisite intent for a crime, so too does the corporation. Therefore, an employee who deploys an AI agent without the intent that the AI agent engage in criminal activity—even if such activity results—likely does not create criminal liability for the corporation.

A third type of vicarious criminal liability is so-called Pinkerton liability, under which a person can be held criminally liable for the reasonably foreseeable acts of a co-conspirator in furtherance of the conspiracy. By definition, however, a conspirator is someone who has agreed with another person to commit a federal offense; in the case of a person deploying an AI agent for lawful purposes, the doctrine would not apply.

As a consequence, new legislation would likely be needed to hold humans accountable for unanticipated AI agent actions that would, if performed by a human, constitute federal crimes.

Mental-State Requirements

A critical component of federal criminal law is mens rea, or "guilty mind," referring to the principle that generally a person must act with some degree of intent to incur criminal liability. Many criminal laws require that a person act knowingly, which generally means a person is aware of their actions and the conduct is not the result of mistake or accident. Some laws have a higher mental state requirement, requiring that a person act willfully—that is, typically, with intent to violate the law—in order to be convicted. Other laws have a lower mens rea, allowing for conviction based on acts done recklessly (consciously disregarding a substantial, unjustifiable risk) or negligently (failing to exercise the degree of care a reasonable person would under the circumstances).

Because AI agents' autonomous acts may be unanticipated, criminal liability for the people who deploy those AI agents will generally inhere only for offenses with minimal intent requirements. This could include offenses requiring negligent or reckless conduct, or strict liability offenses capable of commission without any requisite state of mind.

Strict liability criminal offenses are disfavored because they could result in criminal punishment without fault, a potential violation of the constitutional guarantee of due process. Nonetheless, strict liability crimes do exist in the U.S. Code. For example, the Food, Drug, and Cosmetic Act contains a series of prohibitions, punishable by up to a year in prison, with no attendant mens rea requirement. Courts have upheld this regime against due process challenges by reference to the "public welfare offense" doctrine. Under that doctrine, reduced mens rea standards may be appropriate for offenses related to dangerous substances, where "the probability of regulation is so great that anyone who is aware that he is in possession of them or dealing with them must be presumed to be aware of the regulation." The Supreme Court has characterized public welfare offenses as carrying relatively minor penalties, though a "clear statement from Congress" could potentially apply strict liability to offenses with higher penalties.

Strict liability for public welfare offenses does not necessarily apply only to the person performing the act or their employing organization. The "responsible corporate officer" doctrine has allowed for certain corporate officers and employees to be convicted for offenses committed by other employees of the corporation under some circumstances. The doctrine derives from two Supreme Court cases arising under food and drug safety laws. These cases involved high-level corporate officers being convicted of strict liability food and drug safety offenses committed by employees, without any proof the supervisory defendants knew of the violations. The Court's rationale was that the defendants were in a position to prevent the violations by virtue of their corporate authority and that, in keeping with the public welfare offense doctrine, it was fair to assume that where statutes aim to protect the public from certain dangers, Congress intended to burden those with the opportunity to prevent the hazard rather than "to throw the hazard on the innocent public who are wholly helpless." Such statutes allow for conviction, the Court held, where the government proves "the defendant had, by reason of his position in the corporation, responsibility and authority either to prevent in the first instance, or promptly to correct, the violation complained of, and that he failed to do so."

Should Congress determine that AI agents are sufficiently dangerous to warrant this type of criminal liability for the people and companies who develop them, the public welfare offense and responsible corporate officer doctrines could potentially allow its imposition.

Considerations for Congress

As discussed above, current federal law largely does not impose criminal liability on the human actors behind an AI technology that unexpectedly commits a harmful act: using AI agents to commit federal crimes with the knowledge and intent that they will do so is likely already illegal, but where acts are unanticipated, federal criminal prosecution is most likely unavailable. Should Congress seek to create criminal liability in these circumstances, such adaptation could involve amending current law or passing legislation creating a new offense. Congress generally has authority to enact laws governing internet and computer technology based on the Commerce Clause, and the 119th Congress has seen a range of legislative proposals to regulate AI.

Given that AI agents are most likely to act in the digital space, at least in the near term, an amendment to the CFAA adding a provision related to unanticipated AI agent crime could impose criminal liability on developers responsible for deploying an AI agent that ends up committing a prohibited act under that law, or expand the provision to cover any federal criminal offense. Liability under a CFAA amendment could attach to an individual, a corporation, or both. The attendant mens rea could be negligence or recklessness resulting in AI agent crime, or Congress could create strict criminal liability for any instance where an AI agent takes actions that would be illegal if performed by a human with the requisite intent. Congress could also incorporate "responsible corporate officer" provisions making clear that strict liability for certain AI agent-committed offenses would apply to corporate officers in a position to have prevented those offenses from occurring. Another potential model is a general duty clause requiring safe management of AI tools and imposing civil or criminal penalties for failure to do so. Senators Josh Hawley and Chris Murphy recently announced legislation that would appear to incorporate at least some of these aspects in a CFAA amendment to address AI agents. According to the press release, the bill would hold "AI agent operators" liable under the CFAA, "including for knowing operation of an AI agent that recklessly causes computer hacking damage or loss," and would hold "AI agent developers" liable "for failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent's hacking capabilities," among other things. Bill text was not available to CRS at the time of this Sidebar's publication.

To limit the scope of any offense, if desired, Congress could include as an element of the offense that a certain result ensue—for example, that the AI agent actions cause a particular type or quantum of harm. In that instance, Congress could provide clarity to courts and prosecutors by specifying whether the mens rea requirement applied to the act only or to the effect as well. Alternatively, Congress could create an exception to any prohibition for appropriate development or testing of AI models, though such an exception would risk swallowing the rule absent specific guidelines or rules for such testing.

As an alternative to legislation, Congress could instead opt to rely on existing legal mechanisms and/or industry self-regulation. As described previously, the Trump Administration recently reached an agreement with the heads of major AI technology companies to implement internal processes and controls within certain parameters. It is possible that existing civil remedies, state criminal liability frameworks, and federal criminal statutes applicable to those who intentionally misuse AI tools could provide the degree of legal accountability that Congress prefers. In this vein, Congress always has the option to conduct oversight of the industry and the workability of existing legal frameworks to constrain any unintended harmful effects of AI or other technologies.