Agentic AI Liability in Autonomous Decisions: Who Pays When the AI Gets It Wrong

For the past few years, most businesses interacted with AI as a sophisticated question-and-answer machine. You typed a prompt. The model returned an answer. A human reviewed it. A human decided what to do with it. The liability analysis, while still evolving, stayed relatively contained: the business made the decision; the AI just provided input.

That era is ending.

A new generation of AI systems — described across the industry as “agentic AI” — does not wait for a human to review each step. It plans. It executes. It browses websites, drafts and sends emails, executes code, places orders, manages files, accesses APIs, and completes multi-step workflows without asking for approval at each turn. OpenAI’s Operator product, launched as a research preview in January 2025 and subsequently absorbed into ChatGPT Agent, demonstrated what this looks like in practice: an AI that can interact with graphical interfaces the way a human employee would, navigating menus, filling forms, and completing transactions on your behalf. Anthropic’s computer use capability, generally available through the API, lets Claude look at a screen, move a cursor, click buttons, and type text. Microsoft has embedded autonomous agent capabilities throughout its Copilot ecosystem, deploying them across enterprise workflows.

These are not incremental improvements to autocomplete. They are a qualitative shift in what AI does — and a dramatic expansion in what can go wrong. When an AI agent autonomously sends the wrong communication to a thousand customers, places an unauthorized purchase order, or mismanages a financial account, the legal question is no longer abstract. Someone is going to get sued. The question is who.

This post examines the legal frameworks that will govern agentic AI liability: agency law, negligence doctrine, the regulatory landscape, and the gaps in the standard contracts most businesses signed without considering any of this.


The Shift from Passive Tool to Autonomous Actor

Traditional AI deployments — think a chatbot answering product questions, or a model summarizing documents — are passive in a legally meaningful sense. The AI produces output. Humans act on it. Liability, if it arises, flows through the decisions humans made based on that output, not through the AI’s independent action.

Agentic AI inverts this structure. The defining characteristic of an AI agent is its ability to execute multi-step tasks autonomously, adapting its strategy based on outcomes, interacting with external systems, and completing workflows without human approval at each step. An AI agent deployed in your procurement department does not just suggest a vendor — it may search supplier databases, compare bids, initiate a purchase order, and trigger a payment, all without a human signing off at each stage. An AI agent managing customer service does not just draft a response — it may access a customer’s account, process a refund, update records, and close a ticket, executing each action as it goes.

This autonomy matters enormously for legal analysis because it eliminates the human decision-making buffer that has historically concentrated liability. When an AI makes a harmful autonomous action, the business that deployed it cannot simply point to a human employee who made a bad judgment call. The business itself authorized the AI to act. The legal consequence of that authorization is the central question.


The most natural framework lawyers reach for when analyzing AI autonomy is traditional agency law, and it creates a significant liability exposure for deploying businesses.

Under the Restatement (Third) of Agency (2006), an agency relationship arises when one party — the principal — manifests consent for another party — the agent — to act on the principal’s behalf, and the agent accepts. A principal is subject to liability to third parties harmed by an agent’s conduct when that conduct falls within the scope of the agent’s actual or apparent authority, or when the principal ratifies the agent’s actions after the fact.

The parallel to agentic AI is obvious. When a business deploys an AI agent and gives it credentials, permissions, access to systems, and instructions to accomplish tasks on the business’s behalf, it is manifesting consent for that agent to act in its name. When the AI agent interacts with a supplier, customer, or counterparty — placing an order, sending a communication, executing a transaction — it is doing so on the business’s behalf. The third party dealing with the AI agent has every reason to believe they are dealing with an authorized representative of the business.

Courts have not yet definitively resolved whether an AI system can constitute a legal “agent” in the traditional sense, because agency doctrine presupposes a human or legal entity capable of consent and intention. An AI cannot form the subjective intent required under classical agency theory. Scholars have noted that this creates a gap: agency law “ceases to be useful at precisely the point where AI speed, autonomy, and opacity become most problematic,” as one academic framing of the problem puts it.

But this doctrinal gap does not mean businesses escape liability. It means the liability analysis shifts. Even if an AI agent is not technically an “agent” under the Restatement, the business that deployed it authorized the actions it took. If an AI agent executes a transaction that a third party reasonably believed was authorized, the deploying business will almost certainly be on the hook under apparent authority principles — the business created the circumstances under which a reasonable third party would believe the AI had authority to act. And if the business approved the agent’s architecture, gave it the necessary credentials, and set its operational parameters, a court or regulator will have little difficulty concluding the business ratified the AI’s actions in any practical sense.

The implication is stark: when your AI agent does something harmful, your business is the principal. That means you bear the consequences.


Why Standard AI Vendor Contracts Fail for Agentic AI

Here is where the practical danger for most businesses sits right now. The AI vendor contracts most companies signed — the click-through enterprise agreements, the API terms of service, the SaaS subscription agreements — were drafted for a fundamentally different product model. They were written for query-and-response systems: you submit input, the model returns output, you decide what to do with it. The contracts allocated risk accordingly.

Agentic AI does not fit that model, and the contractual risk allocation reflects it badly.

Consider what standard AI vendor contracts typically provide. OpenAI’s service terms, for instance, limit liability to the amount paid in the preceding twelve months, or a specified dollar cap — figures that bear no relationship to the potential harm an AI agent could cause in a single afternoon of autonomous operation. Liability for indirect, incidental, consequential, or exemplary damages is expressly disclaimed. The vendor disclaims all warranties about the accuracy, reliability, or fitness for purpose of the AI’s outputs. For query-and-response uses, these provisions are commercially defensible. For an AI agent that autonomously executes transactions, sends external communications, or manages financial accounts, they create a coverage gap that could leave your business absorbing seven-figure losses while the vendor’s exposure is capped at your monthly subscription fee.

The indemnification structure compounds this problem. Standard AI vendor terms typically require the customer to indemnify and hold the vendor harmless from third-party claims arising out of the customer’s use of the service. This means that when your AI agent autonomously takes an action that harms a third party — a customer, a supplier, a regulatory body — the vendor’s contract will likely push that liability back to you while requiring you to defend the vendor against claims arising from your own AI agent’s behavior.

The structural problem has been well-identified in commercial practice. A deploying business often absorbs the compliance consequences when the vendor’s AI system behaves unlawfully — the customer faces the regulatory action, the customer faces the customer lawsuit, and the customer is expected to indemnify the vendor. Yet the vendor controls the underlying model behavior, the safety guardrails, and the degree to which the system can be instructed to take autonomous action.

For agentic AI, this allocation is commercially and legally unjustifiable. If a vendor’s AI agent can autonomously execute actions that constitute violations of consumer protection law, employment discrimination law, or financial regulation, the vendor cannot reasonably disclaim all responsibility while simultaneously marketing the system’s ability to act autonomously at scale.

Businesses deploying agentic AI need to understand that their standard AI vendor agreements almost certainly do not address this risk, and they need to negotiate terms that do.


Negligence and Respondeat Superior: The Theories That Will Drive Litigation

When things go wrong with agentic AI, the litigation will likely proceed on two primary theories: direct negligence by the deploying business, and vicarious liability under respondeat superior principles.

Direct Negligence

Negligence doctrine asks whether the deploying business owed a duty of care, breached that duty, and whether the breach caused the harm at issue. For agentic AI, the duty question is relatively straightforward. A business that deploys an AI system capable of autonomous action — executing transactions, communicating externally, accessing and modifying data — owes a duty of reasonable care to parties who could foreseeably be harmed by the system’s autonomous actions. That includes customers whose accounts the AI manages, suppliers with whom the AI contracts, employees whose records the AI accesses, and regulators whose requirements the AI might autonomously violate.

The breach analysis is where deployment decisions become critical. Did the business conduct adequate due diligence before deploying the AI agent? Did it scope the agent’s authority appropriately, matching the level of autonomy to the level of risk? Did it implement monitoring systems capable of detecting errant behavior? Did it maintain rollback capabilities and human override controls? Did it test the system under adversarial conditions before giving it access to live accounts and real-money transactions? If the answer to these questions is no, the business has likely breached its duty of care.

The critical point is that “the vendor built it wrong” is not a complete defense. Courts routinely hold that deployers of third-party systems have independent duties to assess and manage risk. A business that deploys a third-party AI agent without vetting its limitations, without scoping its authority, and without maintaining oversight mechanisms has failed in its own duty — regardless of whether the vendor also bears responsibility.

Respondeat Superior and Vicarious Liability

Respondeat superior holds an employer liable for the tortious acts of its employees committed within the scope of employment. The doctrine extends to agents acting on behalf of a principal. Courts have begun examining whether agentic AI systems, when deployed within a business’s operations, fall within the functional scope of respondeat superior liability.

The threshold question — whether an AI constitutes an “employee” or “agent” capable of generating vicarious liability in the traditional sense — remains unresolved. But the functional argument is compelling: an AI agent deployed within a business’s operations, authorized to take actions on behalf of that business, acting in pursuit of the business’s commercial objectives, looks a great deal like an agent whose tortious conduct the principal should be responsible for. Academic analysis has begun to converge on the view that when AI systems act in the course of a business’s operations, the business should bear vicarious responsibility for harms those actions cause, because the business is the party that chose to deploy, configure, and direct the system.

The absence of traditional personhood in AI does not eliminate this analysis — it simply means the liability falls squarely on the deploying business rather than being shared with the AI itself.


High-Risk Business Use Cases for Agentic AI

Understanding the legal exposure requires understanding where businesses are actually deploying agentic AI and what can go wrong.

Supply Chain and Procurement

AI agents in procurement can search supplier databases, issue requests for quotation, compare bids, negotiate terms, and initiate purchase orders — all autonomously. The risks are significant. An agent that misinterprets pricing data could commit the business to unfavorable contracts. An agent that issues purchase orders without appropriate authority could create binding obligations the business did not intend. An agent vulnerable to manipulation — through false data in a supplier’s website or a malicious email — could be induced to redirect payments to fraudulent accounts.

Customer Account Management

AI agents handling customer service have authority to access customer accounts, process refunds, update personal information, modify subscription terms, and communicate on behalf of the business. An agent that incorrectly processes refunds at scale generates direct financial losses. An agent that sends incorrect communications to thousands of customers creates potential claims under consumer protection statutes and, depending on the content, TCPA or CAN-SPAM liability. An agent that modifies account terms without authorization creates breach of contract exposure.

Financial Management

AI agents deployed in financial management roles — cash management, accounts payable, expense processing, financial reporting — operate in areas where errors generate direct monetary harm and potential regulatory consequences. An agent with authority to initiate transfers that misprocesses a disbursement, or that is manipulated into authorizing a fraudulent payment through a technique known as prompt injection, creates immediate financial liability and potentially triggers requirements under banking regulations.

Human Resources

AI agents in HR workflows may screen job applications, schedule interviews, generate offer letters, or process onboarding paperwork. An agent that applies biased screening criteria — even inadvertently, through patterns in training data — creates exposure under Title VII, the ADA, and analogous state laws. An agent that sends incorrect communications about employment terms creates contract liability. These risks are particularly acute because employment discrimination law imposes strict standards and the EEOC has specifically addressed how those standards apply to algorithmic systems.


What Regulatory Guidance Says About Deployer Responsibility

Federal regulators have delivered a consistent message: using an automated system — including one marketed as AI — does not exempt a business from its existing legal obligations, and it does not transfer responsibility to the AI vendor.

In April 2023, the FTC, CFPB, DOJ’s Civil Rights Division, and EEOC issued a joint statement on enforcement against discrimination and bias in automated systems. The statement was unambiguous: existing legal authorities apply to the use of automated systems just as they apply to any other practice. FTC Chair Lina Khan stated directly: “There is no AI exemption to the laws on the books, and the FTC will vigorously enforce the law to combat unfair or deceptive practices or unfair methods of competition.” The CFPB simultaneously confirmed that when technology used to make credit decisions is “too complex, opaque, or new,” that complexity is not a defense against violations of the Equal Credit Opportunity Act.

These statements were made in the context of algorithmic decision-making. They apply with equal force — and greater urgency — to agentic AI systems that take autonomous action based on algorithmic outputs. If an AI agent autonomously denies a customer service request in a way that has disparate impact on a protected class, the deploying business cannot point to the AI’s opacity as a defense. If an AI agent makes discriminatory credit decisions autonomously, the business faces the same ECOA exposure it would face for discriminatory human decisions.

The FTC has also made clear that deployer responsibility extends to third-party AI tools. Businesses that integrate third-party AI agents into their operations are expected to conduct vendor due diligence, maintain contractual protections, and monitor the AI’s outputs on an ongoing basis. The FTC has, in prior enforcement actions, required companies to destroy algorithms trained on improperly collected data — a remedy that illustrates the seriousness with which regulators view deployer responsibility for AI system behavior.

For businesses in financial services, the CFPB’s guidance on black-box algorithms is directly relevant: a business cannot claim that it did not understand how its AI reached a decision as a defense to a regulatory enforcement action. The business chose to deploy the system. The business bears responsibility for what the system does.


What Agentic AI Agreements Must Contain

If you are deploying agentic AI — or considering it — your vendor agreement needs to address issues that your current AI contract almost certainly does not cover. Here are the provisions that matter.

Scope Limitation and Authority Boundaries

The agreement should define, with precision, what the AI agent is authorized to do and what it is not. This means specifying the systems the agent can access, the transaction types it can initiate, the dollar thresholds above which human approval is required, and the external parties it can communicate with. Vague authorizations like “manage customer accounts” or “handle procurement tasks” are an invitation to disputes about whether a harmful autonomous action was within or outside the agent’s authority.

Equally important: the contract should address what happens when the AI agent exceeds its defined scope. Who bears the cost of reversing unauthorized actions? Who bears liability to third parties? The agreement should clearly allocate these consequences.

Human-in-the-Loop Thresholds

The agreement should specify which categories of action trigger mandatory human review before execution. Financial transactions above a defined threshold. Communications to identified categories of recipients. Any action affecting a customer’s account status. Any action with regulatory implications. The threshold design matters: it should be calibrated to risk and reversibility, not to operational convenience. High-risk, irreversible actions require human approval. Low-risk, reversible actions may proceed autonomously.

These thresholds should be contractually binding on the vendor — not merely guidance that the vendor may implement at its discretion.

Audit Logs and Accountability Records

The agreement must require the vendor to maintain comprehensive, tamper-evident audit logs of every action the AI agent takes. These logs should record what the agent did, when it did it, what data it relied on, and what outcome it produced. Logs should be retained for a period consistent with your regulatory requirements and litigation hold obligations — often a minimum of three to five years in commercial contexts. You should have direct access to these logs, not access conditioned on the vendor’s cooperation.

Audit logs serve multiple purposes: they enable you to detect errant behavior promptly, they support root cause analysis when things go wrong, and they are essential evidentiary assets in litigation and regulatory proceedings.

Liability Allocation for Autonomous Actions

Standard AI vendor liability caps — typically capped at the prior year’s subscription fees — are inadequate for agentic deployments where a single afternoon of errant autonomous action could generate millions of dollars in harm. Your agreement should include a separate, higher liability cap for harms arising from the AI agent’s autonomous actions, distinct from the cap applicable to query-and-response outputs.

The indemnification provisions need renegotiation as well. A vendor whose AI agent causes harm through an autonomous action it took should not be indemnified by you for the consequences of that action. At minimum, the agreement should carve out from your indemnification obligations any claims arising from the AI system’s own autonomous conduct, and should require the vendor to indemnify you for harms that result from defects or failures in the agent’s core functionality.

Rollback and Remediation Obligations

The agreement should require the vendor to provide rollback capabilities — the technical ability to reverse an AI agent’s autonomous actions — and should specify the vendor’s obligation to assist with remediation when the agent causes harm. If the AI agent places erroneous purchase orders at scale, who is responsible for contacting suppliers and reversing those orders? If the AI agent sends incorrect communications to thousands of customers, who bears the cost of the corrective communications campaign? These are operational questions that should be answered in the contract before deployment, not after an incident.


A Governance Framework for Agentic AI Deployment

Sound contracts are necessary but not sufficient. Businesses deploying agentic AI need an internal governance structure to manage the risk.

Authorization Architecture. Before deployment, define the AI agent’s authority with the same rigor you would apply to a new employee’s authority. What can it do without approval? What requires sign-off, and from whom? Map the authority to the risk profile of each action type. Irreversible actions — financial transfers, external communications, account modifications — warrant human approval. Reversible, low-stakes actions may be suitable for autonomous execution.

Approval Thresholds. Establish specific thresholds that trigger human review: dollar amounts for financial transactions, volume limits for communications, categories of counterparties. These thresholds should default to restriction when in doubt. The cost of an unnecessary human approval is trivial; the cost of an unchecked autonomous error can be severe.

Continuous Monitoring. Deploy monitoring systems that track AI agent activity in real time and flag anomalous behavior for human review. An AI agent that suddenly initiates ten times its typical transaction volume, or that begins contacting counterparties outside its normal scope, should trigger an immediate alert. Early detection is the difference between a contained incident and a major liability event.

Rollback Capabilities. Verify, before deployment, that you have the technical ability to halt the AI agent’s operations and reverse its recent actions. This capability should be tested regularly, not assumed. An agent that cannot be stopped and whose actions cannot be reversed is an agent whose deployment you should reconsider.

Incident Response Protocol. Establish a defined protocol for AI agent incidents: who is notified, who has authority to halt operations, how affected parties are identified and contacted, and how regulatory notification obligations are assessed. The worst time to design this protocol is after an incident has begun.

Vendor Accountability Reviews. Treat AI agent vendors with the same rigor you would apply to any critical service provider. Conduct due diligence before deployment. Review incident histories. Assess the vendor’s monitoring and response capabilities. Revisit the relationship regularly as the technology and the vendor’s product evolve.


Conclusion

Agentic AI is not a theoretical risk. It is a deployed technology, in commercial use today, making autonomous decisions and taking autonomous actions with real-world consequences. The legal framework for assigning responsibility when those actions cause harm is still developing — but the direction is clear. Businesses that deploy AI agents are the principals. They have authorized the AI to act on their behalf. They bear the legal and financial consequences when things go wrong.

The gap between that exposure and the protections most businesses have in place — in their contracts, in their governance frameworks, in their monitoring capabilities — is wide. Standard AI vendor contracts were not written for autonomous agents and leave businesses absorbing risks the contracts do not address. Agency law, negligence doctrine, and respondeat superior principles all point toward deploying business liability. Federal regulators have explicitly stated that there is no AI exemption to existing law.

Small and medium-sized businesses deploying agentic AI need to treat this as what it is: a significant legal and operational risk that requires careful management before deployment, not after the first incident. Revisit your vendor agreements. Define your authorization architecture. Build your monitoring and rollback capabilities. Establish your incident response protocols. And make sure you understand what your AI agent is authorized to do in your name — because when it does it, you are responsible.


This post is for general informational and educational purposes only. It does not constitute legal advice and does not create an attorney-client relationship. If you have questions about AI liability, vendor contracts, or governance frameworks specific to your business, consult qualified legal counsel.



Leave a Reply