Who's Liable When AI Agents Go Rogue?
AI agents are no longer hypothetical. They book travel, execute trades, draft contracts, manage customer interactions, and increasingly take actions with real financial and legal consequences — often without a human reviewing each step. The operational shift from AI-as-tool to AI-as-actor has happened faster than the legal infrastructure surrounding it.
The core problem is straightforward: when an AI agent causes harm — a wrongful cancellation, a biased decision, a fraudulent transaction executed autonomously — existing liability frameworks were not designed to answer who bears responsibility. Was it the developer who built the model? The company that deployed it? The business that gave it access to sensitive systems? Or the end user who initiated the task?
None of the existing categories map cleanly, and courts, regulators, and enterprises are beginning to confront that gap in real time.
The legal ambiguity stems partly from how AI agents are architected. A typical agentic deployment involves a foundation model from one vendor, an orchestration layer from another, custom instructions or fine-tuning from the deploying organization, and integration into third-party systems the agent can act upon. When something goes wrong, tracing causality through that stack is not straightforward. Each layer introduces behavior the others did not fully specify.
Traditional product liability law assumes a discrete product with a definable defect. Software liability has historically been narrow, with vendors shielded by terms of service and limitation-of-liability clauses. Neither framework accounts well for systems that learn from context, adapt to instructions, and take probabilistic actions that no single party explicitly authorized.
Early legal disputes are already surfacing. Cases involving autonomous hiring tools, AI-generated financial advice, and automated content moderation decisions are testing whether courts will treat AI outputs as the acts of the deploying organization or as something more analogous to the behavior of a contractor or third party. The outcomes are inconsistent, jurisdiction-dependent, and not yet generating the kind of precedent enterprises can plan around.
For businesses deploying AI agents, the practical implications are significant. Contracts with AI vendors are increasingly contested terrain — buyers want indemnification for agent-caused errors, while vendors resist assuming liability for downstream use cases they did not control. Insurance markets are beginning to price AI operational risk, but coverage terms are still being negotiated industry by industry.
Compliance teams are being asked to audit agent behavior without established audit standards. Legal teams are drafting terms of service for agent-mediated services without clear precedent. Security teams are flagging agent access permissions as a liability surface, not just a security one.
Regulators are moving, but unevenly. The EU AI Act creates some liability hooks, particularly for high-risk applications, but its agent-specific provisions remain vague on multi-party deployments. In the United States, the Federal Trade Commission has signaled interest in deceptive or harmful autonomous system behavior, but no unified federal framework exists. Sector-specific regulators — in finance, healthcare, and employment — are interpreting their existing mandates to cover AI agents, creating a patchwork that enterprises operating across sectors must navigate simultaneously.
The deeper signal here is that liability clarity is becoming a precondition for enterprise adoption at scale. Organizations willing to deploy agents aggressively in this ambiguous environment are implicitly absorbing risk they cannot yet fully price. Those that wait for settled law may wait a long time.
What is emerging, slowly, is a working assumption: that the deploying organization — the entity that put the agent into operation and granted it access — will bear primary accountability in most jurisdictions, regardless of where in the stack the error originated. That assumption is not yet law, but it is shaping how risk-conscious enterprises are structuring their AI deployments, their vendor contracts, and their internal governance around agentic systems.
Sources: — MIT Technology Review (https://www.technologyreview.com/2026/09/28/1145197/whos-liable-when-ai-agents-go-rogue/)