Companies act through others. Until artificial intelligence, those others were people. Today, AI agents can receive objectives, interact with systems, and act with some autonomy, from handling claims and generating orders to executing transactions.

The question is no longer whether technology can do this, but who is liable when an AI agent makes a mistake, exceeds its instructions, or causes harm. Mexican law has addressed a similar question for decades in relation to human agents.

Under Articles 1918 and 1924 of the Federal Civil Code, legal entities and employers may be liable for damages caused by their representatives or employees in the exercise of their functions. Article 11 of the Federal Labor Law similarly provides that directors, administrators, managers, and others performing management or administrative functions represent and bind the employer in labor relations.

Under Article 315 of the Commercial Code, contracts entered into by a factor within the scope of the entrusted business may bind the principal even when the factor exceeded authority or abused the principal’s trust. The key consideration is not always whether the agent acted correctly, but whether the act fell within the entrusted sphere of activity.

From Human Agents to AI Agents

Although an AI agent is neither an individual nor a legal entity (and technological autonomy does not make it an employee, mandatory, commercial factor, or legal representative), someone may still be responsible for its actions. As long as AI agents are not legal subjects, the analysis shifts from who physically executed the action to who authorized the system to act, with what capabilities, limits, and controls.

Mexican law has long recognized electronic contracting. Articles 80 and 89 Bis of the Commercial Code govern contracts formed through technological means and prevent legal effect, validity or enforceability from being denied solely because information is contained in a Data Message. Article 90 adds that, under the statutory conditions, a Data Message is presumed to originate from the sender when transmitted by an information system programmed by or on behalf of that sender to operate automatically.

Although Article 90 predates generative and agentic AI, it already allows an automatically generated message to be attributed to a sender under certain conditions. It does not make the system a legal subject; it establishes attribution. Whether that message forms a contract or binds a company despite exceeding internal limits remains a separate question.

What Happens When the Agent Gets It Wrong?

Consider an AI agent authorized to interact with customers that offers a nonexistent discount or confirms unapproved commercial terms. The company might invoke mistake as a defect of consent under the Federal Civil Code, while the counterparty might rely on the attribution of the electronic communication and the appearance of authority created by the company’s channels and permissions. The outcome will depend on the circumstances, making the design of technological permissions legally significant.

In 2024, a Canadian tribunal held Air Canada responsible for inaccurate information provided by its chatbot, rejecting the airline’s attempt to distance itself from a customer-facing system it had deployed. Although the decision is not binding in Mexico and involved a chatbot rather than a comparable autonomous agent, it illustrates that using technology to interact with third parties does not necessarily break attribution to the organization that deployed it.

Article 1913 of the Federal Civil Code establishes strict liability for mechanisms, instruments, devices or substances that are inherently dangerous under the statutory circumstances. Software is unlikely to fall within that category merely because it uses AI; for an AI agent, risk may arise instead from its capabilities and permissions.

The analysis could change, however, when an AI agent controls industrial machinery, vehicles, energy infrastructure or other mechanisms that may qualify as dangerous. Automation would not necessarily dilute liability; it could instead change how we identify the decisions and controls that led to the harm.

From Powers of Attorney to Technological Permissions

Corporate governance has traditionally relied on powers of attorney, approval matrices, financial thresholds, and segregation of duties. Agentic AI adds a second layer: technological capacity to execute. A company may limit an executive’s authority while allowing that executive to deploy an AI agent capable of transactions beyond those limits, creating a gap between legal and technological architecture.

Traditional authority matrices must coexist with technological permission matrices. If a transaction above a threshold requires additional approval, the system (not only the policy) should prevent its execution. Legal limits increasingly need to be technically enforceable.

This is more than a technology best practice. Corporate directors may be liable to the company under applicable corporate law, and Mexico’s Securities Market Law expressly imposes duties of diligence on directors of publicly traded corporations. As AI agents gain authority to commit resources, interact with third parties, and execute critical processes, their authorization, supervision, and control may become relevant to assessing whether the company was managed diligently.

Subject to Article 26, Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties recognizes a right to object to certain automated processing that evaluates personal aspects without human intervention and produces unwanted legal effects or significantly affects an individual’s interests, rights, or freedoms.

The Vendor Will Not Absorb All the Risk

Companies should not assume that a technology provider will bear consequences when an AI agent fails. The vendor remains responsible for its contractual obligations and legally attributable conduct, while the user company decides how to select, configure, and supervise the system, including its use cases, data access, and permissions.

AI agreements must reflect this allocation of responsibility. Traditional provisions on service levels, intellectual property, confidentiality, cybersecurity and limitations of liability remain important but may be insufficient for systems capable of acting. Contracts should also address autonomy, authorized actions, controls, incident management, and traceability.

Traceability is both a governance and an evidentiary issue. Just as companies reconstruct who made a human decision, their authority, and available information, they must be able to reconstruct an AI agent’s instructions, permissions, inputs, actions, and human intervention. Article 1298-A of the Commercial Code reinforces this need by directing courts assessing Data Messages to consider primarily the reliability of the methods used to generate, store, communicate, or preserve them. Auditability may therefore become essential evidence of what the system did.

Automation Does Not Make Responsibility Disappear

Mexico’s AI legal framework is fragmented, not empty. Although a comprehensive framework remains under development, existing rules already govern automated and AI enabled activities. Attribution, contracting, liability, and corporate diligence will therefore remain central to disputes involving agentic AI.

Technological autonomy is not legal autonomy. As long as AI agents are not legal subjects, saying “the AI did it” begins rather than ends the inquiry: who deployed the system, what capacity and limits it had, and what controls were in place.

Corporate governance has long determined which people may bind a company; agentic AI adds the question of which systems may do so. Authority matrices must therefore coexist with technological permission matrices, and delegation must include traceability.

The transformation is not merely that machines can act, but that companies allow them to act on their behalf, a delegation of corporate power that carries responsibility.