Who Is Criminally Liable When an AI Agent Breaks Federal Law and Nobody Intended It? CRS Legal Sidebar LSB11487 of 8 October 2026 on the CFAA, Intent and the Responsible Corporate Officer Doctrine
What the Congressional Research Service published on 8 October 2026
Legal Sidebar LSB11487, "Artificial Intelligence and Federal Criminal Law: Considerations for Congress," asks what happens under federal law when an AI agent carrying out lawful instructions does something that would be a crime if a person did it. Its answer is direct. People who use AI tools to commit crimes on purpose can already be charged under the Computer Fraud and Abuse Act, the wire fraud statute and the identity theft statute. When nobody intended the act, CRS finds that federal prosecution is most likely unavailable.
Why intent blocks the usual routes
Aiding and abetting, corporate liability through employees and conspiracy liability all depend on someone's intent to commit a crime. An operator who deploys an agent for lawful work has none, so the agent's unexpected hacking leaves a gap in federal criminal liability. CRS concludes that new legislation would likely be needed to close it.
Which doctrine Congress could borrow
The Sidebar points to the public welfare offense and the responsible corporate officer doctrine, which the Supreme Court developed in two food and drug prosecutions, United States v. Dotterweich in 1943 and United States v. Park in 1975. Under them an officer with authority to prevent or promptly correct a violation can be convicted without proof that he knew of it. CRS sets out how Congress could write that model into the CFAA for AI agent developers and operators, and what limits it would need.