{"id":149885,"date":"2026-08-24T21:17:24","date_gmt":"2026-08-24T21:17:24","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/149885\/"},"modified":"2026-08-24T21:17:24","modified_gmt":"2026-08-24T21:17:24","slug":"when-an-ai-agent-acts-for-the-company-who-is-liable","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/149885\/","title":{"rendered":"When an AI Agent Acts for the Company, Who Is Liable?"},"content":{"rendered":"<p>Companies act through others. Until artificial intelligence, those others were people. Today, AI\u00a0agents can receive\u00a0objectives, interact with systems, and\u00a0act with\u00a0some autonomy,\u00a0from handling claims and generating orders to\u00a0executing transactions.<\/p>\n<p>The question is no longer whether technology can do this, but\u00a0who is liable when\u00a0an AI agent makes a mistake, exceeds its instructions, or causes harm. Mexican law has addressed a similar question for decades in relation to human agents.<\/p>\n<p>Under Articles 1918\u00a0and 1924\u00a0of the Federal Civil Code,\u00a0legal entities\u00a0and employers may be liable for damages caused by their representatives or employees in the exercise of their\u00a0functions. Article 11 of the Federal Labor Law similarly provides that directors, administrators, managers, and\u00a0others performing management or administrative functions\u00a0represent and bind the employer in\u00a0labor relations.<\/p>\n<p>Under Article 315 of the Commercial Code, contracts entered into by a\u00a0factor within the scope of the\u00a0entrusted business\u00a0may\u00a0bind the principal even when the factor exceeded authority or abused the principal\u2019s trust. The key consideration is not always whether the agent acted correctly, but whether the act fell within the entrusted sphere of activity.<\/p>\n<p>From Human Agents to AI Agents<\/p>\n<p>Although an AI agent is neither an individual nor a legal entity (and\u00a0technological autonomy\u00a0does not make it an employee, mandatory, commercial factor, or legal representative), someone may still be\u00a0responsible for its actions. As long as AI agents are not legal subjects, the analysis shifts from who physically executed the action to who authorized the system to act, with what capabilities, limits, and controls.<\/p>\n<p>Mexican law has\u00a0long\u00a0recognized electronic contracting. Articles\u00a080\u00a0and 89 Bis\u00a0of the Commercial Code\u00a0govern contracts\u00a0formed through technological means and prevent legal effect, validity or enforceability from being denied solely because\u00a0information\u00a0is contained in a Data Message. Article 90 adds that, under the statutory conditions, a Data Message is presumed to originate from the sender when transmitted by an information system programmed by or on behalf of that sender to operate automatically.<\/p>\n<p>Although Article 90 predates generative and agentic AI, it already\u00a0allows an automatically generated message\u00a0to be attributed to a sender under certain conditions. It does not make the system a legal subject; it establishes attribution. Whether that message forms a contract or binds a company despite exceeding internal limits remains a separate question.<\/p>\n<p>What Happens When the Agent Gets It Wrong?<\/p>\n<p>Consider an AI agent authorized to interact with customers that offers a\u00a0nonexistent\u00a0discount or confirms\u00a0unapproved\u00a0commercial terms. The company might invoke mistake as a defect of consent under the Federal Civil Code, while the counterparty might rely on the attribution of the electronic communication and the appearance of authority created by the company\u2019s channels and permissions. The outcome will depend on the circumstances, making the design of technological permissions legally significant.<\/p>\n<p>In 2024,\u00a0a Canadian tribunal held Air Canada responsible for inaccurate information provided by its chatbot, rejecting the airline\u2019s attempt to distance itself from\u00a0a customer-facing\u00a0system it had\u00a0deployed. Although the decision is not binding in Mexico and involved a chatbot rather than a comparable autonomous agent, it illustrates that using technology to interact with third parties does not necessarily break attribution to\u00a0the organization that deployed it.<\/p>\n<p>Article 1913 of the Federal Civil Code establishes strict liability for mechanisms, instruments, devices or substances that are inherently dangerous under the\u00a0statutory\u00a0circumstances. Software is unlikely to fall within that category merely because it uses AI; for an AI agent, risk may arise instead from its capabilities and permissions.<\/p>\n<p>The analysis could change, however, when an AI agent controls industrial machinery, vehicles, energy infrastructure or other mechanisms that may qualify as dangerous. Automation would not necessarily dilute liability; it could instead change how we identify the decisions and controls that led to the harm.<\/p>\n<p>From Powers of Attorney to Technological Permissions<\/p>\n<p>Corporate governance has traditionally\u00a0relied on powers of attorney, approval matrices, financial thresholds, and segregation of duties. Agentic AI adds a second layer: technological capacity to execute. A company may limit an executive\u2019s authority while allowing that executive to deploy an AI agent capable of transactions beyond those limits, creating a gap between legal and technological architecture.<\/p>\n<p>Traditional authority matrices must coexist with\u00a0technological permission matrices. If a transaction above a threshold requires additional approval, the system (not only the policy) should prevent its execution. Legal limits increasingly need to be technically enforceable.<\/p>\n<p>This\u00a0is more than a technology best\u00a0practice. Corporate directors may be\u00a0liable to the company under applicable corporate law, and Mexico\u2019s Securities Market Law expressly imposes duties of diligence on\u00a0directors of publicly traded corporations. As AI agents gain authority to commit resources, interact with third parties, and execute critical processes, their authorization, supervision, and control may become relevant to assessing whether the company was managed diligently.<\/p>\n<p>Subject to Article 26,\u00a0Mexico\u2019s Federal Law on the Protection of Personal Data Held by Private Parties recognizes\u00a0a right to object to certain automated processing\u00a0that evaluates personal aspects without human intervention\u00a0and produces unwanted legal effects or significantly affects\u00a0an individual\u2019s interests, rights, or freedoms.<\/p>\n<p>The Vendor Will Not Absorb All the Risk<\/p>\n<p>Companies should\u00a0not assume that\u00a0a\u00a0technology provider will bear consequences when an AI agent fails. The vendor remains responsible for its contractual obligations and legally attributable conduct, while the user company decides how to select, configure, and supervise the system, including its use cases, data access, and permissions.<\/p>\n<p>AI agreements\u00a0must reflect this\u00a0allocation of responsibility. Traditional provisions on service levels, intellectual property, confidentiality, cybersecurity and limitations of liability remain important but may be insufficient for systems capable of\u00a0acting. Contracts should also address autonomy, authorized actions, controls, incident management, and traceability.<\/p>\n<p>Traceability is\u00a0both a governance\u00a0and an evidentiary\u00a0issue.\u00a0Just as companies reconstruct who made\u00a0a human decision, their\u00a0authority,\u00a0and available information, they must be able\u00a0to reconstruct\u00a0an AI agent\u2019s instructions, permissions, inputs, actions, and human intervention. Article 1298-A of the Commercial Code reinforces this need by directing courts assessing Data Messages to consider primarily the reliability of the methods used to generate, store, communicate, or preserve them. Auditability may therefore become essential evidence of what the system did.<\/p>\n<p>Automation Does Not Make Responsibility Disappear<\/p>\n<p>Mexico\u2019s AI legal framework is fragmented, not empty. Although a comprehensive framework remains under development, existing rules\u00a0already govern automated and AI enabled activities. Attribution, contracting, liability, and corporate diligence will\u00a0therefore remain central\u00a0to disputes involving agentic AI.<\/p>\n<p>Technological autonomy is not legal autonomy. As long as AI agents are not legal subjects, saying \u201cthe AI did it\u201d begins rather than ends the inquiry: who deployed the system, what capacity and limits it had, and what controls were in place.<\/p>\n<p>Corporate governance has\u00a0long\u00a0determined which people may bind a company; agentic AI adds\u00a0the question of\u00a0which systems may do so. Authority matrices must therefore coexist with technological permission matrices, and delegation must include traceability.<\/p>\n<p>The transformation is not\u00a0merely\u00a0that machines can act, but that\u00a0companies allow\u00a0them to act on their behalf, a delegation of corporate power that carries responsibility.<\/p>\n","protected":false},"excerpt":{"rendered":"Companies act through others. Until artificial intelligence, those others were people. Today, AI\u00a0agents can receive\u00a0objectives, interact with systems,&hellip;\n","protected":false},"author":2,"featured_media":149886,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,1075,17366,25,7537,73314,7255,73315,73316,73317,73312,20140,23192,73318,1081,73319,2112,73313,134,73320],"class_list":["post-149885","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-ai-cloud-data","tag-ai-liability","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-commercial-code","tag-corporate-governance","tag-data-message","tag-federal-civil-code","tag-federal-labor-law","tag-kwantiax-legal-consulting","tag-legal-liability","tag-legal-tech","tag-mexican-law","tag-mexico","tag-permission-matrices","tag-risk-management","tag-tania-zunai-agents","tag-technology","tag-traceabilityiga"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/149885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=149885"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/149885\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/149886"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=149885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=149885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=149885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}