Who is liable for AI agent actions? What the 2026 federal AI bills actually require of your business
Who is liable for AI agent actions right now?
As of September 18, 2026, no federal statute assigns model-developer liability for an agent's actions, so an operator's own conduct is what gets examined. The practical questions are who chose the agent, who granted its permissions, and who could have revoked them. That keeps the deploying business as the party answering for incidents, while the model provider is judged on what it disclosed and what it could have prevented.
What Naval Ravikant actually proposed
The post, its real id and its real timestamp
On September 16, 2026, Naval Ravikant posted on X: “The best way to pace the frontier is to hold the labs fully liable for the behavior of their models.” The syndication record files it under id 2100233897191903500, created at 2026-09-16T14:42:36Z, with 21,160 likes and 921 replies at capture. It proposes no mechanism, no regulator and no statute.
Why the timing matters: the bills moved in the same fortnight
Two federal texts arrived around it. The Ban Artificial Superintelligence Act was announced on September 3, 2026; the Stop Rogue AI Act was introduced as H.R. 10362 on September 14, 2026. Coverage has merged the three into one liability story. Read separately, neither bill does what the story assumes, which is why this page opens the text rather than the thread. For the pacing debate itself, see frontier-slowdown analysis.
The September 2026 timeline
Each date is the one its named artifact records, not the date a press release was written.
| Date | What moved | Artifact |
|---|---|---|
| July 2026 | OpenAI-Hugging Face breach; agents executed "approximately 17,600 unauthorized actions" | Forkast |
| September 3, 2026 | Ban Artificial Superintelligence Act announced by Sen. Sanders and Rep. Casar; no bill number issued | sanders.senate.gov |
| September 8, 2026 | Florida's attorney general proposes criminal liability for chatbots that aid crimes | Forkast |
| September 9, 2026 | The Stop Rogue AI Act sponsors date their own release this day | gottheimer.house.gov |
| September 14, 2026 | H.R. 10362 introduced and referred to two committees | govinfo GPO print; GovTrack |
| September 16, 2026 | Ravikant: hold the labs fully liable | X post |
| September 17, 2026 | Karp: the first line of defence is the actor | CNBC |
| September 18, 2026 | GovTrack still records H.R. 10362 at the first stage | GovTrack |
The Stop Rogue AI Act (H.R. 10362): what it requires
H.R. 10362 has one operative section: it directs NIST to “shall develop, publish, and maintain standards, guidelines, and best practices for the secure development, deployment, and operation of artificial intelligence agents by an organization.” The rest of the 14-page print is definitions and deadlines.
Five duties the text names
The standards are written as capabilities, not principles.
- Inventory. “maintain the capability to continuously discover, inventory, verify, and maintain organizational control over all AI agents operating within or interacting with the information systems, networks, applications, services, or digital environments of such organizations;”
- Runtime monitoring. “enable continuous runtime monitoring and, where appropriate, inline detection and interception of AI agent interactions with tools, data sources, information systems, and other AI agents, including detection of prompt injection, data exfiltration, anomalous tool invocation, and behavioral drift from an AI agent's approved operational baseline;”
- Uniform coverage. “apply discovery and verification controls consistently across AI agents regardless of whether such AI agents are developed internally, acquired from third-party vendors, or operated through external services;”
- Provenance. “implement cryptographically verifiable provenance mechanisms sufficient to identify the entity responsible for creating or operating an AI agent;” It also bars one shortcut: “do not rely solely on self-attested or single-provider assertions for establishing AI agent identity.”
- Tamper-evident logs. “generate and retain tamper-evident, standardized logs of material AI agent actions, and ensure such logs are portable and accessible, as appropriate and consistent with law, to deploying organizations and authorized relying parties.”
What it does not do: no liability, no penalties, no cause of action
Nothing above allocates who pays. In both the HTML text version and the 14-page GPO print, H.R. 10362 contains zero occurrences of liabilit*, zero of indemnif*, no cause of action and no penalty language. Its stated problem is inventory blindness: “most organizations have no reliable way to know how many unauthorized AI agents are running in their systems, who built them, or what they have access to.”
Who it binds: federal contracts first, guidance for everyone else
“NIST would have one year from the bill’s enactment to establish frameworks focused on continuous system monitoring, evaluating agent reliability, and generating tamper-proof action logs.” “Most organizations could adopt them voluntarily.” The incident behind it is on the OpenAI-Hugging Face report.
The Ban ASI Act: announced, not introduced
What the summary proposes
The Ban Artificial Superintelligence Act “would permanently ban the development and deployment of superintelligent AI and temporarily pause advanced AI development until a federal regulator has established safety rules.” Its released summary targets whoever builds the system, not whoever uses it: “Entities shall be subject to the corporate death penalty, and persons shall be subject to not more than 20 years in prison, which is similar to existing penalties related to unlawfully developing nuclear weapons.” The sponsor's rationale is that the builders do not understand their own systems: “The leaders of the major AI companies publicly acknowledge that they do not fully understand the technology and that it is escaping their control.”
The status trap: why introduced is wrong today
The sponsors announced it on September 3, 2026. Their release gives it no bill number and GovTrack's index has no entry, so there is no text to advance. Coverage that calls it introduced, or says it is moving through Congress, is pricing a bill that is not in the record.
Developer vs operator: where liability sits in practice
The line that matters in an incident is not lab-versus-business; it is who holds the evidence. On the record as of September 18, 2026, no federal statute assigns model-developer liability for an agent's output, so a review examines the operator's conduct: who selected the agent, who granted its permissions, what it could reach, and whether anyone could revoke it inside a working day. The operator answers for the deployment; the provider answers for what it disclosed and what it could have prevented.
Ravikant's position is a position, not a consensus, and the counter-case was published the next day. Palantir's chief executive, on September 17, 2026: “The first line of defense is you're liable for your own actions.” His puts the first duty on the party acting, which is where an audit starts whether or not any bill passes.
The incident history and the deployment checklist live on our AI agent liability checklist. This page is about the bills.
The track that really moves liability: S.5051 and Florida
If the question is which proposal would actually shift liability, the answer is not the two bills the thread cites. “shifts the focus toward legal accountability.” “moving the regulatory burden from technical infrastructure to legal liability.” Florida's attorney general opened a fourth lane on September 8, 2026: “By targeting companies that maintain practical control over the design, training, deployment, or safety settings of AI systems, the state is establishing a legal pathway to hold these entities responsible when their models participate in criminal activity.”
The state lanes are drafted in the same direction: California SB 53 and the Massachusetts AI bill both put duties on the business that deploys. Neither federal proposal here is law, and none of this is legal advice.
What an SMB audit must evidence now
If any of these duties reach your contracts, the ask will be evidence rather than opinion. Five artifacts answer the phrases above.
- An inventory register — every agent, its owner and its reach: the bill's word is to “discover, inventory, verify”.
- A provenance record — which entity created and which operates each agent, not a vendor's assertion that it is trustworthy.
- Permission and revocation records — what the agent could reach, when access was cut, and who approved both.
- A monitoring loop for drift — prompt injection, data exfiltration and departures from the approved operational baseline.
- Tamper-evident action logs — material agent actions, portable enough to hand to a buyer, an insurer or an auditor.
None of the five needs a vendor's cooperation, and each is cheaper than reconstructing an incident from memory. Our AI agent risk checklist is the short version, and AIUC-1 certification covers what a third-party evidence standard would ask for.
Frequently asked questions
Who is liable for AI agent actions right now?
As of September 18, 2026, no federal statute assigns model-developer liability for an agent's actions, so an operator's own conduct is what gets examined. The practical questions are who chose the agent, who granted its permissions, and who could have revoked them. That keeps the deploying business as the party answering for incidents, while the model provider is judged on what it disclosed and what it could have prevented.
Does the Stop Rogue AI Act make AI labs liable for their models?
No. H.R. 10362, the Stop Rogue AI Act, contains no liability, indemnity or penalty language: the 14-page GPO print has zero occurrences of the word liability. It directs NIST to publish AI agent discovery and security standards, and requires federal contracts to carry inventory, provenance and tamper-evident logging clauses. It governs evidence and control of agents, not who pays for their mistakes.
What does the Ban ASI Act actually do?
The Ban Artificial Superintelligence Act, announced September 3, 2026 by Sen. Bernie Sanders and Rep. Greg Casar, would permanently ban developing or deploying superintelligent AI, pause advanced AI development until a federal regulator sets safety rules, and create a cabinet-level agency. Its released summary sets entity-level penalties, including a corporate death penalty, and up to 20 years in prison for individuals. It is announced, not in the congressional record.
Which 2026 bill would actually shift liability toward model developers?
Not the two bills the commentary cites. The accountability track runs elsewhere: Sen. Mark Warner's AI AGENT Act, S.5051, introduced July 21, 2026, moves the burden from technical infrastructure to legal liability with FTC civil penalties, and Florida's attorney general proposed criminal liability on September 8, 2026 for chatbots that aid crimes. Both are proposals. Neither is law, and neither is the Stop Rogue AI Act.
Does the Stop Rogue AI Act apply to small businesses, or only federal contractors?
Not directly today. The NIST standards it mandates are guidance most organizations could adopt voluntarily; the mandatory clauses attach to federal contracts. Two consequences follow for a small business. If you bid on federal work, inventory and log evidence becomes a procurement requirement. If you buy agents from vendors that do, those vendors will push the same documentation duties down into your contracts.
What should an SMB audit produce to be ready for AI agent rules?
Five artifacts map onto the standards language now circulating: a machine-readable inventory of every agent with a named owner; provenance linking each agent to the entity that runs it; permission and revocation records; runtime monitoring for prompt injection, data exfiltration and behavioural drift; and tamper-evident logs of material actions. An audit that produces those five is defensible against insurer questions and likely compliance duties, whether or not any bill passes.
Is Naval Ravikant's strict liability position the law?
No. It is commentary, posted September 16, 2026, and it argues for the opposite of what the current bills do. Ravikant wrote that the best way to pace the frontier is to hold the labs fully liable for the behavior of their models. The bills moving through Congress place duties on the organizations deploying agents instead. Nothing in the post changes what a business must document today.
Sources
Source list: the govinfo GPO print of H.R. 10362 (HTML and the 14-page PDF); GovTrack's H.R. 10362 record; the Gottheimer-Lawler release; the Sanders-Casar release and summary; the X post id 2100233897191903500; Forkast on the four theories, the Florida proposal and the breach figure; CNBC on Karp; the New York Post; Open Data Science and Techstrong on the NIST clock. All fetched 2026-09-18. This page reports what each artifact records and is not legal advice.