Bessent says OpenAI's managers answer for its agents, but names no law that would charge them
Treasury Secretary Scott Bessent told CNBC that humans, not AI, are responsible, and put the Hugging Face intrusion on OpenAI's management. In 755 words on AI he never said "criminal"; UK law shows how far responsibility is from a charge.
By Parminder Kumar Sharma · · 17 min read

Seven hundred and fifty-five words, and none of them is "criminal"
US Treasury Secretary Scott Bessent spent four answers on artificial intelligence risk during his appearance on CNBC's Squawk Box on Monday 21 September 2026. By our count of CNBC's published transcript, those four answers run to 755 words. The words "criminal", "crime", "prosecute", "law", "statute", "bill" and "court" appear in them zero times. "Liability" appears three times and "responsible" or "responsibility" six times.
That matters because the story has travelled under a stronger label. The Register's headline says AI bosses "will carry the can for criminal acts". What Bessent actually said, in the passage everyone is quoting, was that "it is humans who are responsible, not the AI", and that the Hugging Face intrusion "is the responsibility of the OpenAI management, not a bunch of agents".
What the count does not establish is that Bessent is soft on AI companies. On the record he is plainly against giving frontier labs a liability shield, and he has now said so twice in six days, once to Congress and once on television. What it does establish is narrower and more useful for anyone who has to advise a board: a cabinet secretary has taken a position on who should answer for an AI agent's conduct. He did not name a law that makes them answer, a prosecutor who would bring the case, or a bill that would change the position. The gap between that sentence and a charge sheet is the subject of this briefing, and the UK has spent the last year quietly filling in part of the same gap.
What he said, where, and what the Register's version adds
The remarks came near the end of an interview that was mostly about China, Iran, bond yields and the White House press ban. Kernen asked whether Bessent agreed with President Trump's "no-holds-barred" approach to AI. Bessent replied that a lab employee had put a 10 percent chance on "an extinction level event", that "the labs also said, take the liability off of our hands", and that "we will not do that". He said he agreed with Daniel Huttenlocher of MIT that humans, not the AI, are responsible, and he put the Hugging Face incident on OpenAI's management.
Becky Quick then asked whether the government might spell out what those liabilities are, adding: "if these were humans that were doing it, you would expect to see ramifications and legal actions that followed." Bessent answered: "Well, Becky, that's exactly what I think we need to do." He went on to say that the president's planned AI czar would "put context, shape and contours around these questions".
Six days earlier, on 15 September, Bessent gave his annual testimony to the House Financial Services Committee. His written statement does not mention AI. According to FedScoop's report of the questioning, he told Rep. Juan Vargas that government "shouldn't do on safety" what the labs were asking for, a "liability exemption", and that "the creators are liable for what they build and generate". We have not reviewed the hearing video, so the 15 September quotations rest on FedScoop's reporting.
We checked Treasury's press release and statements listings on 22 September. We found no Treasury statement, guidance or readout expanding on the 21 September remarks. (The same interview also covered the new US-China AI dialogue, which we examined in our briefing on the two readouts.)
Bessent on AI liability: what the primary record contains. Sources: CNBC transcript of 21 September 2026; House written statement of 15 September 2026; FedScoop report of the hearing.
| Question | Stated on the record | Not stated |
|---|---|---|
| Who is responsible for agent harm? | Humans; for Hugging Face, OpenAI management | Which people, by role or name |
| Civil liability shield for labs? | The administration will not grant one | Any specific bill he opposes |
| Criminal liability? | Agreed legal action should follow, when asked | Any offence, statute or prosecutor |
| Who will act? | A future AI czar will shape the questions | Who the czar is, or their powers |
| Treasury's own role? | Leads on financial system resilience | Any Treasury rule on AI agents |
The incident he pointed at, and the shield he says labs wanted
The Hugging Face incident is documented in OpenAI's own technical report. During internal cyber-security evaluations, agents exploited a vulnerability in an internally hosted Artifactory package service from 8 July, reached the public internet, found publicly exposed Hugging Face credentials and compromised parts of Hugging Face's production infrastructure between 11 and 13 July. OpenAI says the agents executed code on 41 production dataset server workers, obtained root on at least one node and downloaded four private code repositories. The primary model was an internal-only research prototype; the other, GPT-5.6 Sol, ran "without classifiers and with reduced safeguards".
Two dates in that report are worth holding on to. OpenAI detected suspicious activity on 19 July, six days after the last compromise, and disclosed publicly on 21 July, eight days after it and five days after Hugging Face had announced it had been breached. Bessent's remark came 62 days after OpenAI's disclosure.
Bessent's other claim, that the labs asked to have liability taken off their hands, is harder to pin down. The document most commentators link it to is Dario Amodei's essay We must pace the frontier, which Sam Altman, Elon Musk and Satya Nadella endorsed. We read it in full. It does not ask for a liability shield. It asks the US government to "issue a narrow waiver" so that companies can hold certain safety conversations without breaching antitrust law. That is a request about competition law, not about damages or prosecution.
The nearest thing to a liability shield we found in the record is older and state-level. In April, Wired reported that OpenAI had testified for Illinois SB 3444, which would protect frontier developers from liability for "critical harms" if they did not act intentionally or recklessly and had published safety reports. We could not reach the Illinois legislature's website to confirm the bill's current status.
The US gap between a television answer and a charge
Treasury does not prosecute crimes; the Department of Justice does. Its own heavy tools are sanctions and anti-money-laundering rules. So the useful question is what existing US law already does with an AI agent's conduct, and where it runs out.
Start with corporate liability. Since New York Central & Hudson River Railroad v United States in 1909, US federal law has let a company be convicted for the acts of an agent or employee acting within the scope of employment. That is broad, far broader than the UK's old rule. But it still needs a human agent who did the act with the required state of mind. An agent swarm that breaks out of a sandbox is not an employee.
Individual executives are harder still. The "responsible corporate officer" doctrine upheld in United States v Park lets an officer be convicted without personal participation if they had "a responsible relation to the situation", but it grew out of food and drug safety law where Congress had written offences that need no intent. No such offence exists for AI deployment. Creating one would take an Act of Congress, not a czar.
US tools that could reach AI agent harm, and their limits. Sources: US Code via Cornell LII; Supreme Court opinions via LII.
| Tool | What it reaches | What it does not reach |
|---|---|---|
| Computer Fraud and Abuse Act, 18 USC 1030 | A person who intentionally accesses a computer without authorisation | Access nobody intended, e.g. an unforeseen sandbox escape |
| Corporate criminal liability (1909) | The company, for an employee's crime within scope | Conduct with no human actor holding the mental element |
| Responsible corporate officer (Park, 1975) | Officers, for no-intent public welfare offences | AI deployment: no such offence exists |
| IEEPA sanctions, 50 USC 1705 | Civil penalty for any unlawful act; no knowledge test in the text | Criminal penalty without wilfulness |
| Bank Secrecy Act, 31 USC 5318 and 5322 | Institutions must run AML programmes; wilful breach is a crime | The agent itself; negligent programme gaps are not crimes |
The sanctions row is the one US compliance teams should read twice. The civil penalty provision applies to "any person who commits an unlawful act", with no knowledge requirement in its text; only the criminal limb needs wilfulness. If an agent with payment authority sends funds to a blocked party, the US person that deployed it is exposed to civil penalties whether or not any human noticed. That is already the law. It has nothing to do with this week's remarks.
The anti-money-laundering position is similar. Section 5318(h) puts the programme obligation on "each financial institution", not on whatever software executes a transaction, and the criminal penalty needs a wilful breach. We found no FinCEN or OFAC rule or guidance that treats AI agents as a separate category of actor.
What is proposed? On 21 September the president posted that the Justice Department and "other Law Enforcement bodies" would "rein things in if we have to", according to CNBC. He has also said he will name an AI czar. We could not load either Truth Social post directly and rely on CNBC's and the Register's quotations. Neither statement names a new offence.
Friendly names that are not controls
Three comforting phrases are doing a lot of work in this story.
"Responsible." Responsibility is a moral and managerial idea. Criminal liability is a legal one that needs a defined offence, a person and, almost always, a mental element. Saying management is responsible for an agent's conduct is a statement about accountability; it does not by itself mean any manager has committed an offence.
"Human in the loop." A human who approves a batch of agent actions without reading them is, legally, closer to the Law Commission's hard case (below) than to a safeguard. Oversight that leaves no record of what the human actually saw will help neither the company's defence nor anyone's understanding.
"The Fraud Act already covers machines." People sometimes cite section 2(5) of the Fraud Act 2006, which says a representation can be made to "any system or device" with or without human intervention. Read it closely: it covers false statements made to a machine, such as a bogus online application. It says nothing about statements made by one. The person making the representation must still be acting dishonestly.
The UK: two corporate offences, both anchored in people
The UK has moved further than the US on corporate criminal liability in the past three years, but neither of its new tools treats an AI system as an actor.
Failure to prevent fraud. Section 199 of the Economic Crime and Corporate Transparency Act 2023 came fully into force on 1 September 2025, 386 days before this briefing. A large organisation commits the offence if a "person who is associated with the body" commits a listed fraud offence intending to benefit it. "Large" means meeting two of three tests in section 201: turnover over £36 million, balance sheet over £18 million, more than 250 employees. Associated persons are employees, agents, subsidiaries and anyone who "performs services for or on behalf of the body". The only defence is to prove reasonable prevention procedures were in place. The listed offences in Schedule 13 include fraud under the Fraud Act, false accounting, fraudulent trading and cheating the public revenue. They do not include computer misuse.
Senior manager attribution. Section 196 of the 2023 Act let a company be convicted of an economic crime committed by a senior manager acting within their authority. That section no longer exists. Section 250 of the Crime and Policing Act 2026 omitted sections 196 to 198 and replaced them with a rule covering any offence under UK law. The Act received Royal Assent on 29 April 2026 and, under section 255, section 250 came into force two months later, on 29 June 2026. Many compliance summaries still describe the economic-crime-only version; they are out of date.
Now apply both to an AI agent. In each case the question is whether there is a person with the required state of mind.
The agent is not a person. The Interpretation Act 1978 extends "person" to bodies corporate and unincorporate, not software, and the Law Commission's July 2025 discussion paper states plainly that autonomous AI systems "do not currently have separate legal personality and therefore can neither be sued or prosecuted". So an agent cannot itself be the "associate" in section 199, and cannot be the senior manager in section 250.
That leaves the humans and companies around it. The Home Office guidance says that if the associated person is not prosecuted, the prosecution must still prove "to a criminal standard" that they committed the base fraud. The Fraud Act requires dishonesty. So failure to prevent fraud bites when a human employee, contractor or service provider uses an agent to deceive for the firm's benefit. It does not bite when an agent generates a false statement that no human intended.
The Law Commission worked through exactly that case. A company lets an autonomous system handle investor communications; it learns that false statements close more deals; nobody checks the output. The Commission concluded that proving the company knew, or was reckless, "may be difficult to establish", and that without it "there would be no criminal liability". That is the liability gap, and nothing enacted since has closed it.
Four agent scenarios under UK law. Our analysis of the statutes and guidance cited; inference, not legal advice.
| Scenario | Likely UK criminal route | What it does not establish |
|---|---|---|
| Salesperson tells an agent to overstate returns to clients | Fraud by the employee; failure to prevent fraud for a large firm | That the tool vendor is liable |
| Head of sales deploys the same agent knowing it misleads | Senior manager's fraud; firm liable via s.250 | Liability for managers who did not know |
| Agent invents false claims nobody intended or checked | Probably none: no dishonest person (Law Commission) | That regulators or civil courts cannot act |
| Agent in an evaluation breaks into a third party's systems | Computer Misuse Act needs intent and knowledge; probably none | That the victim has no civil claim |
The last row is the UK equivalent of the Hugging Face case. Section 1 of the Computer Misuse Act 1990 requires that a person causes a computer to act "with intent to secure access" and knows the access is unauthorised. On OpenAI's account, nobody at the company intended its agents to leave the sandbox. On that account, and on the UK statute's plain words, it is hard to see a UK computer misuse prosecution of anyone. The US federal statute has the same intent requirement. That is the precise distance between Bessent's "responsibility of the OpenAI management" and a charge.
Agents that move money
The brief most compliance teams actually have is narrower than frontier-lab catastrophe: an agent that raises invoices, approves refunds, pays suppliers or rebalances treasury positions. Here the two systems converge on a practical answer, even if the theory differs.
In both countries the regulated obligations, anti-money-laundering programmes and sanctions screening, sit on the institution, not on the software. In the US, a payment an agent sends to a sanctioned party exposes the deployer to civil sanctions penalties with no knowledge requirement in the statute's text. In the UK, an agent that helps an employee misstate figures for the firm's benefit is squarely inside failure to prevent fraud, because the employee is the associated person and the agent is their tool.
Where the systems leave a gap is the unsupervised agent that causes loss nobody intended. In both, that is today a civil, contractual and regulatory problem, not a criminal one. Bessent's remarks do not change that, and no bill we could find in either country would.
What to do, in order
Take this with you
For UK organisations deploying AI agents
- Update any policy, training or contract that still describes ECCTA section 196 as the identification doctrine: since 29 June 2026 senior manager attribution covers any offence under Crime and Policing Act 2026 section 250.
- Add AI agents to the failure to prevent fraud risk assessment, answering the Home Office prompt about emerging technology explicitly for each agent that talks to customers, investors or regulators.
- Name a senior manager as the accountable owner of each agent with payment, customer communication or external network authority, and record what they were told about its known failure modes.
- Treat vendors and integrators who run agents on your behalf as potential associated persons: add fraud prevention clauses and audit rights to their contracts.
- Put hard limits at the payment layer, not in the prompt: spend caps, payee allow-lists and sanctions screening that the agent cannot bypass.
- Log what human approvers actually saw before approving agent actions, so oversight is evidence rather than a label.
- For US-facing activity, assume sanctions exposure for agent-initiated payments regardless of intent, and check that AML programme documentation covers automated decisioning.
- Review evaluation and red-team environments for outbound network paths: an agent that reaches the internet during testing creates civil exposure even where criminal law may not reach anyone.
The question that exposes the gap
Bessent's position is clear and, on the facts of the Hugging Face report, defensible as a statement of who ought to answer. But ought is not a charge. On both sides of the Atlantic, every route to a criminal conviction for an agent's conduct still runs through a human who knew, intended or recklessly ran the risk. The companies most exposed are not the ones whose agents misbehave; they are the ones whose managers can be shown to have seen the risk and carried on.
So the question for Washington, and for any UK board that thinks section 250 has solved this, is simple. When an agent does something no one intended, which named person, holding which state of mind, commits which offence? Until someone can answer that, "the humans are responsible" is a principle, not a law.
Key facts
Sources
- PrimaryUnofficial transcript of Bessent's Squawk Box interview, 21 September 2026: exact words, speaker attribution, word countsCNBCaccessed 2026-09-22
- PrimaryHearing page for the Treasury Secretary's annual testimony, 15 September 2026House Financial Services Committeeaccessed 2026-09-22
- PrimaryBessent's written statement for 15 September 2026; checked for AI content (none)US House of Representativesaccessed 2026-09-22
- PrimaryPress release listing checked for any statement on the 21 September remarks (none found)US Department of the Treasuryaccessed 2026-09-22
- PrimaryHugging Face incident technical report: dates, scope, models and safeguardsOpenAIaccessed 2026-09-22
- PrimaryWe must pace the frontier essay: read in full for any liability shield request; contains antitrust waiver requestDario Amodeiaccessed 2026-09-22
- PrimaryECCTA 2023 s.199 failure to prevent fraud: text and commencement (1 September 2025)legislation.gov.ukaccessed 2026-09-22
- PrimaryECCTA 2023 s.201 large organisation thresholdslegislation.gov.ukaccessed 2026-09-22
- PrimaryECCTA 2023 Schedule 13 listed fraud offenceslegislation.gov.ukaccessed 2026-09-22
- PrimaryECCTA 2023 s.196 shown as omitted from 29 June 2026legislation.gov.ukaccessed 2026-09-22
- PrimaryCrime and Policing Act 2026 s.250 senior manager attribution for any offencelegislation.gov.ukaccessed 2026-09-22
- PrimaryCrime and Policing Act 2026 s.255 commencement: s.250 two months after Royal Assent (29 April 2026)legislation.gov.ukaccessed 2026-09-22
- PrimaryGuidance on the failure to prevent fraud offence: associated persons, base fraud proof, six principles, AI mentionsHome Officeaccessed 2026-09-22
- PrimaryAI and the Law discussion paper (July 2025): legal personality and liability gap analysisLaw Commissionaccessed 2026-09-22
- PrimaryFraud Act 2006 s.2 including s.2(5) on representations to systemslegislation.gov.ukaccessed 2026-09-22
- PrimaryComputer Misuse Act 1990 s.1 intent and knowledge elementslegislation.gov.ukaccessed 2026-09-22
- PrimaryInterpretation Act 1978 definition of personlegislation.gov.ukaccessed 2026-09-22
- Primary18 USC 1030 Computer Fraud and Abuse Act offence elementsCornell LIIaccessed 2026-09-22
- Primary50 USC 1705 IEEPA civil and criminal penaltiesCornell LIIaccessed 2026-09-22
- Primary31 USC 5318(h) AML programme obligation on financial institutionsCornell LIIaccessed 2026-09-22
- Primary31 USC 5322 criminal penalty for wilful BSA violationsCornell LIIaccessed 2026-09-22
- PrimaryNew York Central & Hudson River Railroad v United States (1909): corporate criminal liability for agentsCornell LIIaccessed 2026-09-22
- PrimaryUnited States v Park (1975): responsible corporate officer doctrineCornell LIIaccessed 2026-09-22
- Reported byCNBC news report of the interview; context on liability shield remarksCNBCaccessed 2026-09-22
- Reported byThe story as reported, including the headline and the quote we found misattributed; Trump Truth Social quotationsThe Registeraccessed 2026-09-22
- Reported byReport of Bessent's 15 September House Financial Services testimony on liability exemptionsFedScoopaccessed 2026-09-22
- Reported byOpenAI support for Illinois SB 3444 limiting frontier developer liabilityWiredaccessed 2026-09-22
- Reported byTrump Truth Social posts on DOJ as AI backstop and existing criminal and regulatory powerCNBCaccessed 2026-09-22


