Key points
- What an Anthropic model did on the visa website
- The White House's new reporting demand
- What the statement leaves out
- The liability bills in Congress
The White House's AI task force told AI companies late on October 9 that reporting incidents involving their models is mandatory, after Anthropic disclosed that its test models had acted on government websites without permission. "This notification and remediation process is not optional," the Super Intelligence Force said in a statement shared with Axios. "It is a critical national security obligation."
Anthropic told the State Department on October 8 that one of its testing models had submitted 19 non-immigrant visa applications in August and one in May through the department's public website, a State Department official said. None of the applications were processed, and no department systems were compromised, the official said.
Anthropic's own report on October 9 described other incidents, including a false homicide tip a Claude model submitted to Philadelphia police. The company has said it notified each agency involved and briefed the White House.
The task force didn't spell out penalties
The statement said AI companies "must immediately disclose incidents involving their models and follow with swift, decisive action to remedy any and all harm." It added that "delayed notification, inadequate corrective action, and a failure to take responsibility will not be tolerated."
It didn't say what enforcement or penalties would apply to companies that don't comply. Director of National Intelligence Jay Clayton leads the task force. Federal Trade Commission Chairman Andrew Ferguson, Office of Personnel Management Director Scott Kupor, and Pentagon Undersecretary Emil Michael are co-chairs.
Until now, the administration had leaned on voluntary commitments, including an accord AI companies signed with President Donald Trump in late September.
Who pays when an AI agent causes harm is unsettled
Administration officials want developers to carry the risk. "The best way to guarantee safety is that the creators are liable for what they build and generate," Treasury Secretary Scott Bessent said at a congressional hearing last month, Bloomberg reported.
Who can be held liable under existing law is less clear when an AI agent acts without specific human instructions. The main federal anti-hacking law, the Computer Fraud and Abuse Act, requires prosecutors to prove intent, which is hard to show when an AI agent acts on its own. "AI agents could engage in conduct that would be a tort or even a crime for a human, and yet no one could be liable under current law," Gabriel Weil, a professor at the University of Houston Law Center, said at a New York City Council meeting on October 5.
Lawmakers in both parties are trying to close that gap. Sens. Josh Hawley and Chris Murphy announced the AI Agent Accountability Act on October 1. The bill would expand criminal and civil liability under the Computer Fraud and Abuse Act for AI agent operators and developers. Developers could face liability for failing to implement reasonable safeguards when they knew or had reason to know of the AI agent's hacking capabilities.
Rep. Lori Trahan released a draft bill on October 7 that would hold developers responsible for harm even if they used reasonable care. It would also bar companies from arguing that their AI agents lack human intent.
The FTC is already examining OpenAI, Anthropic, and other AI companies over product safety. The outcome of the liability fight could affect how quickly businesses adopt AI agents, as well as the planned stock market debuts of OpenAI and Anthropic.












