At his blog, Schneier on Security, public-interest technologist Bruce Schneier writes:
AI agents are agents of the person or organization that deploys them—and should be treated by the law as such. If a company hired human writers to write its summaries, that company would be liable for inaccuracies in those summaries. If a company’s human agent signed contracts in the company’s name, that company would be bound by those contracts. And if a doctor gave dangerously wrong medical advice, they would be liable for malpractice.
To allow businesses to hide behind the excuse of faulty AI in those same circumstances would be a massive handout to companies, and would introduce disastrous incentives for corporate misbehavior. Why hire human writers, lawyers or doctors when AIs are not only cheaper, but also absolve employers whenever they make a mistake?
Schneier’s point reinforces—from a legal liability angle—my apprehension about AI agents (see “Why AI Agents Fill Me with Dread,” 24 June 2026). Although I see plenty of room for ambiguity when it comes to AI-generated content, when AI agents are actively engaged in tasks that could have harmful results, I believe whoever deployed the agent should bear legal responsibility for its actions. We, as a society, cannot create a situation in which agentic misbehavior has no legal or financial consequences.
The corollary to that is that those of us who use the agents to do something for us are liable for the results.
I would guess (not much of a guess) that the licensing agreement puts all of the responsibility on the end user.
Caveat Emptor!
David
I agree - and there is some of the difficulty - If I ask a teenager to do something - there is little guarantee the result will be what I expected. The result may be better or worse, depending upon the instructions given and the monitoring done.
So too with AI.
Caveat Emptor.
David
If I ask an agent to do something and he screws it up, or does something unethical or illegal in the process, yes, I can be liable.
But if he does something entirely on his own, like buying himself a car with the corporate credit card that’s meant for business use only, the company can and will hang him out to dry.
I think AI agents are going to be similar. If you order it to do something, and it does a bad job, well, sorry, you’re out of luck.
But if it does something completely unexpected and unwanted because its algorithm jumped to an incorrect conclusion, there will be lawsuits, and the results of that suit will be far from clear.
Maybe. It’s also possible that if the company was negligent in giving a card to a known fraudster then they may be liable as well. Same with AI agents. If you know that AI agents have a tendency to do things that are illegal and still give them the power to, you may well be liable for it.
(If you know someone has a tendency to drive drunk, don’t give them car keys)
This is the same argument for why we must never allow robot warfare, as was recently trialled in the Ukraine with an autonomous drone that killed Russian soldiers. The people who allow robot warfare are directly liable for the robots’ decisions of whom to kill.
Not one more Russian soldier would die there if Putin ordered his army out of an occupied sovereign nation he invaded for no good reason. Let’s be very clear about who the aggressor is and who carries the responsibility for all this senseless suffering. This is not an AI or robot problem, the problem is one ruthless autocratic madman. Putin. The sooner he goes away, the better for the entire world.
I think that whether and when liability incurs…is pretty much unknown at this point because the legal frameworks, etc will come out of lawsuits and regulations and legislation most of which hasn’t happened yet. I do agree with Adam’s basic premise…it still makes errors and if one has to check everything then it is easier to just do it yourself.
Let’s try to keep this to issues surrounding legal liability rather than sliding into the topic of AI in warfare.
As much as I’m clearly on the side of using the legal system to hold companies responsible for their actions, I do worry that settlements or fines will simply be seen as another cost of doing business in a field with too much money sloshing around.
I don’t disagree, but there was just a story in the Seattle Times stating that managers use AI as a way to shirk responsibility—when the AI is wrong, it’s someone else’s problem (the IT department, or senior management pushing AI, or the AI lab…). You might say there’s a gap between theory and practice here.
We already sign away most of our rights when using software. I suppose the question is if someone sends me an Excel spreadsheet, what chance is there that it won’t be read correctly by Excel or Numbers. We assume that the relevant companies won’t get it wrong.
Everyone’s in CYA mode, but the more we can hold people responsible for what they produce—however they choose to produce it—the better off society will be.
Companies definitely try to reduce or eliminate their liability for software errors with the so-called “clickwrap contracts,” so it has been heartening to see the courts holding them liable in the case of their AI agents.
Full disclosure, my company now not only employs an AI Agent, but also crafts custom ones for our commercial unified communications customer base.
I agree companies should be responsible for their agents. But I think the analysis is overly simplistic. Society has plenty of precedent for 3rd party liability. If I rent a Tesla from Hertz and it drives me off a bridge, I will sue (at least) Hertz, for sure. But Hertz may sue Tesla.
Thank you for brining a lawyer’s perspective into this discussion. Agentic AI is not the “vanilla-flavored software” of decades past, where software and systems engineering tools can be applied to design for “known-known’s” and mitigate “known-unknowns.” Depending on the complexity of the software, will generate the required certification. Whether Numbers or Excel has a bug is one thing. If a flight control system on a transport category airplane has a bug in it, is completely different set of consequences. Regardless, the systems engineering approach is about the same at a top level.
I use Anthropic Claude and I’m pleased with the corporate responsibility that Anthropic seems to manifest. (My reason for going with them was that they were one of the few companies that actually paid out for pirating copyrighted material.) I’ve also been very pleased to use Claude on a very tight leash.
Agentic AI, in general, as Bruce Schneier notes, is closer to producing what a human would produce, and thus I expect that the old, vanilla-flavored assurances of click-through agreements based on “…promise, we worked it really hard to look for bugs…,” is no longer relevant. And, thus, I’m looking forward to seeing real guardrails built for agentic AI. I may keep a short leash on Claude, but my use cases are pretty simple. As use cases expand in complexity, the ability to keep the leash short is unreliable.
When Air Canada’s chatbot gave incorrect information to a traveller, the airline argued its chatbot is “responsible for its own actions”.
[…] The British Columbia Civil Resolution Tribunal rejected that argument, ruling that Air Canada had to pay Moffatt $812.02 (£642.64) in damages and tribunal fees. “It should be obvious to Air Canada that it is responsible for all the information on its website,” read tribunal member Christopher Rivers’ written response. “It makes no difference whether the information comes from a static page or a chatbot.”