Passed in 1986 and amended repeatedly since, the CFAA makes it a federal offense to access a computer "without authorization" or to exceed authorized access. It was written with a human hacker in mind, so applying it to an autonomous AI agent's actions raises open questions discussed widely in AI-safety and legal circles: establishing intent or knowledge is harder for an agent's operator than for a human defendant, and corporate liability (the company that ran the agent) is legally distinct from individual liability (a specific employee), which typically requires proof of specific intent or knowing conduct. Incidents where AI agents gained unauthorized access to third-party infrastructure — such as the 2026 OpenAI RubyGems/rubydoc.info disclosure — have driven public discussion of whether existing CFAA enforcement is sufficient or whether agent operators need new obligations, such as mandatory liability insurance, analogous to auto insurance for drivers.