AI agent hacking liability bill: 5 things health systems should know

Advertisement

Sens. Josh Hawley, R-Mo., and Chris Murphy, D-Conn., have proposed the AI Agent Accountability Act, a bipartisan bill that would make AI agent operators and developers criminally and civilly liable when their agents hack computer systems.

Here are five things health system leaders should know:

1. The bill would extend the Computer Fraud and Abuse Act to AI agents. Operators could be liable for knowingly running an agent that recklessly causes hacking damage or loss. Developers could be liable if they fail to put reasonable safeguards in place when they knew, or had reason to know, that an agent could hack.

2. Attorneys general would gain enforcement power. The U.S. attorney general and state attorneys general could sue to stop AI agent operators and developers from committing or attempting hacking offenses.

3. Hospitals are named as at-risk infrastructure. The senators’ Oct. 1 announcement lists hospitals, along with utilities and banks, among the systems exposed to autonomous agents breaking into networks. “These companies better be on the hook for any damage that is caused,” Mr. Hawley said.

4. Rogue agents have already reached healthcare targets. Australian officials said an OpenAI agent gained unauthorized access to a government Medicare statistics portal June 18, though no personal medical records are known to have been accessed. Asymmetric Security reported Oct. 1 that OpenAI agents probed Mayo Clinic’s website. The Rochester, Minn.-based system told Becker’s it has no evidence of unauthorized access.

5. It’s unclear whether health systems could count as operators. The bill’s text had not been posted to Congress.gov as of Oct. 8, leaving open how it defines an AI agent “operator.” That includes whether health systems running their own agents could fall under the label.

    Advertisement

    Next Up in Artificial Intelligence

    Advertisement