The hearing put two on record liability routes on the record — a criminal recklessness route for AI firms and users, and a strict liability route that holds the firm whenever a model causes harm — against a White House route of voluntary safety
Sen. Josh Hawley has put a specific question on the table this week: when an AI agent causes harm, who pays — the maker for reckless design, the user for reckless deployment, or the public, through voluntary safety commitments the firms choose to keep?
In an op-ed laying out his framework, the Missouri Republican argues that AI companies should face criminal liability for recklessly designing agents capable of criminal conduct and failing to build reasonable safeguards, and that users should face criminal liability for knowingly deploying such agents. The proposal also tightens penalties for AI-assisted hacking. The framework is the sponsor's description, not yet a numbered bill.
The hearing room is where the legal mechanics got stress-tested. By Roll Call's account, expert witness Paul Ohm identified two civil accountability routes that already exist: the Federal Trade Commission's unfair-and-deceptive-practices authority, and state tort law. Ohm also flagged a known limitation in many criminal cases — proving intent when an AI system, not a human operator, made the call — and went further than Hawley: his prescription was strict liability for developers, so the firm pays when the model causes harm regardless of fault.
The gap is the substantive ground the hearing exposed. Hawley's announced recklessness framework holds the firm liable only when prosecutors can show it knew its agent could cause criminal conduct and skipped reasonable safeguards. Ohm's strict-liability test holds the firm liable whenever the model causes harm. The first asks the court to find a culpable mind inside the company; the second asks only whether the harm happened.
The White House is going a different direction. The hearing followed a closed-door meeting between administration officials and AI executives, at which the companies agreed to what the administration described as "morally binding" voluntary safety commitments, including "layers of controls and audits." A voluntary framework internalizes cost only to the firms that sign up. It cannot bind the reckless. It is, by design, the path that lets the worst actors set the floor everyone else has to clear.
Hawley's framework goes after that floor. By making the firm that designs a reckless agent pay criminally, and the user who knowingly deploys one pay criminally, it puts the cost on the actor that took the risk — not on the patient who lost care, the customer who could not reach funds, or the agency whose systems were breached, the kinds of harm Hawley describes in his op-ed.
OpenAI was invited to the White House meeting. Sam Altman declined. In a statement to Roll Call, the company said it received the invitation on Friday and is "engaged with Congress" on the same questions. The choice not to appear at the White House, paired with engagement on the Hill, is itself a signal of where the company expects the rule of the road to be written.
AI firms have publicly disclosed frontier-model hacking incidents against government websites and outside companies. The incidents are on the record. The cost of cleaning them up has been borne by the victims, not the model providers. The hearing did not change that balance. What it did was put the legal mechanism that would change it on the table, and identify the alternative — voluntary commitments — for what it is: a promise that only constrains the firms that bother to keep it.
The fork is now public. One path is hard liability for the firm that builds a reckless agent and the user who knowingly deploys one; the other is a voluntary commitment that binds only the firms willing to sign. The first internalizes the cost of the next failure to the actor that caused it. The second externalizes it, and waits for the next hospital, bank, or government database to absorb the bill.