← Back to news
Archived · Published 8 August 2026
Nobody Has Settled Who Is Liable When an AI Agent Makes the Wrong Call
The shift from AI systems that produce text to AI agents that take actions — placing orders, modifying records, negotiating terms, executing trades within set parameters — has moved the liability question from theoretical to operational faster than legal frameworks have adapted. A chatbot that gives bad advice is a well-trodden product-liability and defamation question with decades of analogous case law. An agent that autonomously executes a transaction with real financial consequences, acting on a general instruction rather than a specific human-approved action, does not map cleanly onto any existing doctrine, and courts, regulators, and companies deploying these systems are working out the answer in parallel rather than in sequence.
The core difficulty is that agentic AI sits between two liability models that both partially apply and neither fully fits. It resembles a tool, which would put liability on whoever deployed it and configured its instructions, on the theory that a hammer manufacturer is not liable for how a carpenter swings it. It also resembles an employee or agent in the legal sense, whose principal bears responsibility for actions taken within the scope of authorization — except an AI agent has no legal personhood to be an agent in that technical sense, and the "scope of authorization" for a system that interprets a natural-language instruction and decides how to execute it is far less determinate than a human employee's job description.
Contract law has become the practical battleground because it is the area companies can address without waiting for legislation: terms of service for agentic AI products increasingly specify, in detail, where the deploying company's liability ends and the user's begins, what constitutes an authorized action, and what recourse exists when the agent exceeds what a reasonable reading of its instructions would have permitted. These terms are being tested for enforceability in ways ordinary software EULAs rarely are, because the actions in question — a completed purchase, a sent communication, a modified database record — often cannot be undone the way a bad output can simply be deleted.
Insurance markets are responding to the same gap from a different angle, with specialized coverage emerging for AI-agent-related errors distinct from general technology errors-and-omissions policies, priced on factors like the scope of autonomous authority granted to an agent, the reversibility of its actions, and whether a human remains in the approval loop for consequential decisions. That pricing behavior is itself informative: insurers are, in effect, running their own risk assessment of exactly how much autonomy a given deployment grants, and companies choosing to keep a human approval step for higher-stakes agent actions are finding it shows up as materially lower premiums — a market signal, arriving well ahead of settled law, about how much autonomy is actually prudent.
Defici Editorial · AI News
This article was generated by Defici's AI editorial system.