AI agent liability is the question of who answers when an autonomous system takes an action that causes harm, and the short answer is that it lands on the people and companies behind the agent rather than on the agent itself. An agent that spends money, sends communications, modifies records, or agrees to terms is not merely generating output for a human to review. It is acting. That single change breaks the assumption sitting underneath most software contracts, which were written for tools that returned a suggestion and left every consequential decision to a person.
The gap is easy to miss because it opened quickly. A vendor ships agentic features into an existing product, a customer enables them, and the relationship is still governed by an agreement drafted when the product could only summarize and recommend. Nobody renegotiated. The capability changed and the paper did not.
Where AI agent liability actually lands
Existing law is less unsettled here than the discourse suggests. When a business deploys a tool that causes harm, responsibility generally follows the business that deployed it, and long-standing agency principles make a principal answerable for acts taken by an agent within the scope of authority it was given. Autonomy does not create a gap in that chain so much as it raises the question of how much authority was delegated and whether the delegation was reasonable.
What this means practically: "the model did it on its own" is a weak position. The decisions that matter were made earlier, by humans, when someone chose to deploy the agent, defined what it was permitted to do, and decided how much oversight to place around it. Those are the facts a regulator, a counterparty, or a court will examine, and they are all documentable in advance. The related question of liability for AI errors generally, including what recent cases signal, is covered in who is liable when AI makes a mistake.
Scope of authority, the clause most deployments lack
If an agent can act, its contract needs to say what it is allowed to do, in terms specific enough to be enforced. That means naming the permitted actions rather than describing them generally, setting quantitative ceilings where money or volume is involved, listing the actions that always require a human approval step, and stating plainly whether the agent has authority to bind either party to anything. An agent that can accept terms, issue refunds, or commit to delivery dates without an explicit ceiling is an open-ended delegation, and open-ended delegations are exactly what agency law treats as binding.
The corollary is worth stating: silence is not a limit. If the agreement does not restrict what the agent may do, a counterparty can reasonably argue the delegation was broad.
Autonomy is not a defense. Every decision that matters was made by a human before the agent ever ran: what it may do, how far it may go, and who checks.
Interruption, logging, and human review
Three operational controls carry most of the legal weight, and each should appear in the contract rather than living only in an engineering document.
The ability to stop an agent mid-task matters because harm from an acting system compounds while a purely advisory system's harm does not. Someone has to be able to halt it, and the agreement should say who holds that ability and how quickly it takes effect. Logging matters because a dispute about an agent turns entirely on reconstructing what it did and on whose instruction, which is impossible after the fact unless actions, inputs, and approvals were recorded at the time. Retention periods belong in the contract. Human review matters because the categories of action that require a person in the loop, typically anything irreversible, anything above a financial threshold, and anything touching a regulated decision, should be defined rather than left to the deploying team's discretion in the moment.
Indemnity, caps, and the vendor conversation
When an agent operates inside a customer's systems or acts toward a customer's counterparties, the risk allocation deserves more attention than a standard software agreement gives it. Work through who indemnifies whom for actions the agent takes, and be specific about whether that covers actions the agent was authorized to take, actions outside its defined scope, or both. Ask whether the liability cap makes sense against the magnitude of what an acting system can do, since a cap set at twelve months of fees may be sensible for a tool that returns text and badly mismatched for one that can move money. Confirm what your own upstream model provider commits to, which is a different negotiation covered in AI vendor and model provider contract terms. And check whether your insurance responds to autonomous action at all, because many technology policies were not written with it in mind.
What to fix this quarter
Inventory every agentic capability actually running, including features enabled by default in tools you already pay for. For each one, write down what it can do, what it cannot, what requires approval, and what is logged. Compare that against the contract governing it and close the distance. Where you are the vendor, put the limits in your terms; where you are the customer, ask for them. The broader compliance surface, including how state rules are moving, sits in US state AI laws in 2026 and the governance groundwork in the AI startup legal checklist.
- AI agent liability generally follows the business that deployed the agent; autonomy is not a defense.
- Agency principles make a principal answerable for acts within the authority it delegated, so undefined authority tends to read as broad authority.
- Name permitted actions, set quantitative ceilings, and list what always requires human approval.
- Put interruption capability, logging, retention, and human-review triggers in the contract, not only in an engineering doc.
- Revisit indemnity and liability caps: a cap sized for software that returns text may be wrong for software that can spend money.
- Audit agentic features already enabled in tools you use, then close the gap between what they can do and what the paper says.
The organizations that handle this well are not the ones with the most cautious agents. They are the ones that decided, in writing and in advance, exactly how much authority they were delegating and who was accountable when it was used.
Related reading: who is liable when AI makes a mistake, AI vendor contract terms, and the enterprise AI sales checklist. Or start a conversation about the agents you already have in production.
Common questions
Who is liable when an AI agent takes a harmful action?
Responsibility generally lands on the business that deployed the agent rather than on the agent or the model itself. Long-standing agency principles make a principal answerable for acts taken within the scope of authority delegated to an agent, and product and negligence theories reach the company that put the system into use. The practical consequence is that the decisive facts are human decisions made before the agent ever ran: whether deploying it was reasonable, what authority it was given, what controls surrounded it, and whether those choices were documented. Specific outcomes depend on jurisdiction and facts.
What contract terms does an autonomous AI agent need?
At minimum: an explicit scope of authority naming permitted actions, quantitative ceilings where money or volume is involved, a list of actions requiring human approval, and a clear statement of whether the agent may bind either party. Alongside those, address the ability to interrupt or halt the agent and who holds it, logging of actions and approvals with a stated retention period, and indemnity and liability caps sized to what an acting system can actually do rather than to what advisory software could do.
Is 'the AI acted autonomously' a defense?
It is a weak position. Autonomy describes how an action was executed, not who chose to delegate the authority to execute it. The questions that decide responsibility are whether deployment was reasonable, how much authority the system was given, what oversight was in place, and whether the deploying organization followed its own controls. Legislatures and regulators have been moving to close any perceived gap here, so founders should assume that deploying an agent transfers execution, not accountability.
Do existing software contracts cover AI agents?
Frequently not. Most were drafted for software that returned output for a human to act on, so they assume a person makes every consequential decision. When a vendor adds agentic capability to an existing product, the capability changes while the agreement stays the same, leaving authority limits, approval requirements, logging, and risk allocation unaddressed. The practical step is to inventory the agentic features actually running, including ones enabled by default, and compare what each can do against what its governing contract says.