{"id":74802,"date":"2026-06-15T22:52:24","date_gmt":"2026-06-15T22:52:24","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/74802\/"},"modified":"2026-06-15T22:52:24","modified_gmt":"2026-06-15T22:52:24","slug":"agentic-ai-part-ii-who-is-responsible-for-the-actions-of-an-ai-agent-regina-gerhardt-peter-devlin","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/74802\/","title":{"rendered":"Agentic AI Part II: Who is Responsible for the Actions of an AI Agent?, Regina Gerhardt, Peter Devlin"},"content":{"rendered":"<p class=\"Normal\">In a prior blog post, \u201cAgentic AI Part I: What It Is and Who\u2019s Responsible When It Acts,&#8221; we introduced this multi-part series on agentic AI, delved into the technology itself, and explained how agentic AI differs from generative AI.\u00a0 We also introduced the legal frameworks that may govern agentic AI liability, and how plaintiffs are currently challenging it.<\/p>\n<p class=\"Normal\">This blog post\u2014Part II of our Agentic AI series\u2014dives deeper into the legal frameworks that will govern agentic AI.\u00a0 As businesses increasingly deploy AI agents to act in the real world, the legal question that is beginning to emerge above all others is: Who is legally responsible for the actions of an AI agent?\u00a0 This question becomes critical when an AI agent causes harm or simply makes a mistake.\u00a0 Put another way, which human or company was in the best position to prevent the harm?\u00a0 It is an urgent query at a time when agentic AI is being deployed before regulations and laws have caught up.<\/p>\n<p class=\"Normal\">In the United States, this question remains unsettled.\u00a0 And the answer will not be one-size-fits-all.<\/p>\n<p class=\"Normal\">As an initial matter, AI agents likely will not be treated as independent legal actors.\u00a0 They are not human, and likely will not be treated as legal persons capable of bearing independent liability. They cannot pay fines or damages, and they cannot appear in court.\u00a0 In our last blog post we posited that courts will likely analyze AI agents through familiar, existing legal frameworks, and introduced the various existing legal frameworks we think mostly likely to apply to agentic AI: agency law, product liability, contractual allocation, or statutory allocation of responsibility.<\/p>\n<p class=\"Normal\">In this Part II, we will explore each of these frameworks in more depth.<\/p>\n<p>Agency Law<\/p>\n<p class=\"Normal\">One of the most important legal frameworks for agentic AI is likely to be traditional agency law. Agency law is the body of doctrine governing situations where one party (an \u201cagent\u201d) acts on behalf of another (a \u201cprincipal\u201d).\u00a0 Under the Restatement (Third) of Agency, \u00a7 1.01, an agency relationship arises when a principal manifests assent that the agent shall act on the principal\u2019s behalf and subject to the principal\u2019s control, and the agent consents so to act.\u00a0 Courts probably won\u2019t conclude that an AI system itself is a \u201clegal person\u201d capable of bearing independent liability. Instead, the question is likely to be whether the human or company that deployed the AI agent authorized the relevant conduct and should therefore bear responsibility for it.<\/p>\n<p class=\"Normal\">That inquiry will turn on familiar doctrinal categories.<\/p>\n<p class=\"Normal\">Actual authority exists when the principal has communicated to the agent that the agent may act. That authority may be communicated either expressly (through explicit instructions, settings, or permission toggles) or by implication (through a course of dealing or the nature of the delegated task).\u00a0 Id. \u00a7\u00a7 2.01, 2.02.\u00a0 \u00a0For an AI agent, express authority might be evidenced by a user\u2019s explicit command or configuration.\u00a0 And implied authority might arise where a user has repeatedly allowed the agent to perform a category of tasks without intervening.<\/p>\n<p class=\"Normal\">Apparent authority arises when a third party reasonably believes the agent is authorized to act based on the principal\u2019s manifestations.\u00a0 Id. \u00a7 2.03.\u00a0 If a business deploys an AI agent on its website or in its customer-facing workflows, then third parties are likely to argue that the agent\u2019s representations are the company\u2019s representations.<\/p>\n<p class=\"Normal\">Ratification will also be relevant.\u00a0 Under that doctrine, a principal who knowingly accepts the benefits of an unauthorized act may be treated as having authorized it after the fact.\u00a0 Id. \u00a7 4.01.<\/p>\n<p class=\"Normal\">Courts are beginning to grapple with how these concepts apply to AI.\u00a0 In Mobley v. Workday, Inc., No. 23-cv-00770-RFL (N.D. Cal.), the AI vendor Workday provided AI-driven applicant screening tools to employers.\u00a0 The court allowed discrimination claims to proceed on the theory that Workday could be held liable as an \u201cagent\u201d of the employers using its platform.\u00a0 The court reasoned that Workday\u2019s AI tools could function as the employer\u2019s agent for purposes of liability.\u00a0 Mobley is significant because it suggests that an AI vendor, and not just the entity that deploys the AI, can bear direct liability under an agency framework.<\/p>\n<p class=\"Normal\">In a recent case in Canada, the Canadian tribunal rejected the defendant airline\u2019s argument that its AI chatbot should be treated as a \u201cseparate legal entity\u201d and held the airline liable for the chatbot\u2019s incorrect statements about bereavement fare policies.\u00a0 The tribunal reasoned that a company is responsible for information provided on its website, whether from a static page or a chatbot.\u00a0 That case suggests that companies will not be permitted to disclaim responsibility for the acts of AI tools they chose to deploy.<\/p>\n<p class=\"Normal\">A hard set of questions also arises on the consumer side.\u00a0 When a consumer uses an AI agent to interact with a business (e.g., to shop) the question is whether and when the consumer has authorized the agent to bind them.\u00a0 The answer will likely depend on the scope of authority the consumer actually delegated (express or implied), whether the consumer\u2019s setup and use of the agent created apparent authority for third parties to rely on, and what disclosures and confirmations were built into the agent\u2019s workflow.\u00a0 Relatedly, when a consumer\u2019s AI agent, rather than the consumer themselves, interacts with a business\u2019s consent mechanisms (think terms of use) and disclosures, difficult questions arise about whether the consumer actually received notice and gave informed consent.\u00a0 These questions have no settled answers yet, but they will become increasingly urgent as consumer-facing AI agents proliferate.<\/p>\n<p>Product Liability &amp; Negligence<\/p>\n<p class=\"Normal\">Product liability and negligence doctrines are also becoming central frameworks for AI-agent litigation and regulation.\u00a0 Historically, product liability law developed around tangible physical products.\u00a0 Agentic AI systems complicate that framework because they are software-based, often expressive, dynamic, and capable of autonomous action.\u00a0 Even so, it may ultimately be that at least some agentic AI claims fall into traditional product liability theories.<\/p>\n<p class=\"Normal\">A plaintiff may argue that an AI agent was defectively designed; for example, because it lacked adequate guardrails, did not require human approval for high-stakes actions, or was not tested against foreseeable misuse scenarios.\u00a0 Courts applying design-defect analysis will likely ask whether safer alternative designs were feasible and whether the developer adequately considered the risks of autonomous operation.\u00a0 Plaintiffs and attorneys general are already deploying this theory against LLM-driven chatbots in an effort to avoid the protections of Section 230 for service providers, such as the Florida AG\u2019s recent lawsuit against OpenAI alleging that ChatGPT is addictive and unreliable without meaningful safeguards, especially for children.<\/p>\n<p class=\"Normal\">Failure-to-warn theories could also emerge.\u00a0 Agentic AI developers and vendors may face allegations that they inadequately disclosed limitations of the AI and hallucination or security risks.\u00a0 Consider a situation in which an AI agent autonomously accesses third-party systems in ways that create legal exposure.\u00a0 A plaintiff may argue that the vendor failed to adequately warn deployers about the foreseeable legal and operational risks of autonomous operation.<\/p>\n<p class=\"Normal\">Negligence claims may ultimately become a dominant product-liability framework because they are flexible and fact-intensive.\u00a0 Courts may evaluate whether companies exercised reasonable care in selecting an AI vendor, testing an AI agent before deployment, monitoring outputs, maintaining human oversight, or responding to incidents.\u00a0 Importantly, the applicable \u201cstandard of care\u201d will likely evolve rapidly as industry practices mature.\u00a0 Conduct that appears reasonable today\u2014such as deploying relatively autonomous systems with limited oversight\u2014may later be viewed as negligent once best practices become more established.<\/p>\n<p>Contractual Allocation<\/p>\n<p class=\"Normal\">Because liability exposure surrounding agentic AI remains uncertain, contractual risk allocation will be highly important.\u00a0 Many of the earliest significant disputes involving agentic AI may occur not between plaintiffs and AI companies, but between businesses and AI vendors seeking to shift responsibility to one another.\u00a0 Vendor agreements will address issues such as compliance obligations, cybersecurity obligations, audit rights, and insurance requirements.<\/p>\n<p class=\"Normal\">Businesses deploying AI agents can require vendors to indemnify them for harms caused by unauthorized autonomous conduct, IP infringement, violations of privacy law, or system malfunctions.\u00a0 Vendors, by contrast, can seek to disclaim liability, limit damages, and shift compliance responsibilities to the deployer.\u00a0 Vendors will also likely try to protect themselves by contractually requiring \u201chuman-in-the-loop\u201d oversight as a condition of the agreement.<\/p>\n<p class=\"Normal\">But contractual allocations between businesses and vendors have limits.\u00a0 They do not bind consumers or regulators, and courts may scrutinize attempts to disclaim responsibility where a party designed or controlled the AI agent in practice.<\/p>\n<p>Statutory Allocation<\/p>\n<p class=\"Normal\">We expect to see legislatures and regulators increasingly imposing statutory responsibility for agentic AI conduct. This space is rapidly changing.\u00a0 One theme is already emerging across regulatory guidance globally: businesses will not be permitted to avoid responsibility simply by blaming the AI.\u00a0 Regulators appear increasingly focused on ensuring that a human remains accountable, risks are monitored, governance structures exist, and incidents are documented and responded to.<\/p>\n<p class=\"Normal\">California\u2019s AB 316, which took effect on January 1, 2026, is a notable example.\u00a0 The statute prohibits a defendant who \u201cdeveloped, modified, or used\u201d an AI system from asserting as a defense that the AI \u201cautonomously caused the harm\u201d to the plaintiff.\u00a0 AB 316, in other words, forecloses the specific argument that the AI\u2014rather than the humans or organizations behind it\u2014should bear responsibility for the harm.\u00a0 Other states will likely follow.<\/p>\n<p class=\"Normal\">At the international level, the European Union\u2019s AI Act adopts a risk-based regulatory structure and expressly assigns obligations to specific actors in the AI ecosystem, including \u201cproviders,\u201d \u201cdeployers,\u201d importers, distributors, and authorized representatives.\u00a0 Although the EU AI Act was not drafted with agentic AI specifically in mind, it assumes that humans and organizations remain accountable for AI systems.\u00a0 Its framework for allocating responsibility among providers and deployers may influence how U.S. courts and legislatures think about similar questions.<\/p>\n<p>The CFAA and Platform Control Over AI Agents<\/p>\n<p class=\"Normal\">The Computer Fraud and Abuse Act (CFAA) is emerging as one of the most significant near-term legal constraints on agentic AI deployments.\u00a0 In Amazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-09514-MMC (N.D. Cal. Mar. 9, 2026), a federal court granted a preliminary injunction against Perplexity\u2019s \u201cComet\u201d AI shopping agent, which logged into users\u2019 Amazon accounts at the users\u2019 direction to browse products and complete purchases.\u00a0 The district court found Amazon was likely to succeed on its CFAA and California Penal Code \u00a7 502 claims, reasoning that Comet accessed Amazon\u2019s systems \u201cwith the Amazon user\u2019s permission but without authorization by Amazon.\u201d\u00a0 The court relied heavily on Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058 (9th Cir. 2016), which held that a platform can revoke a third party\u2019s access even when users have shared their credentials.<\/p>\n<p class=\"Normal\">The case is now before the Ninth Circuit, and the stakes extend well beyond shopping agents.\u00a0 If the Power Ventures framework controls, then that empowers platforms to unilaterally block any AI agent from accessing logged-in user accounts, effectively giving platforms veto power over the tools users choose to interact with their own accounts.\u00a0 Platforms have legitimate interests in account security, fraud prevention, and bot detection.\u00a0 But the framework also raises significant competition and consumer-autonomy questions, because this veto power may restrict consumer choice while protecting a platform\u2019s advertising and monetization model.\u00a0 The district court\u2019s public-interest analysis did not meaningfully engage with these tensions.<\/p>\n<p>So What is Next?<\/p>\n<p class=\"Normal\">As agentic AI systems become more sophisticated, and as they begin interacting with each other in multi-agent workflows, courts and regulators will face questions that existing frameworks may not cleanly answer.\u00a0 When a consumer\u2019s AI agent transacts with a business\u2019s AI agent, traditional assumptions about notice, consent, and human decision-making may not hold.\u00a0 And when multiple AI agents are chained together across different vendors and platforms, the allocation of responsibility among the parties in the chain will become increasingly complex.<\/p>\n<p class=\"Normal\">The law here is beginning to take shape.\u00a0 Agentic AI is being deployed now, and the legal system is starting to adapt.\u00a0 Companies deploying AI agents should be thinking carefully about how existing liability frameworks apply to their specific use cases, and they should structure their agreements and disclosures accordingly.<\/p>\n<p class=\"Normal\">Come back for Part III of our series to learn more about the agentic AI risks companies should be thinking about now, and how plaintiffs are currently challenging AI agents.<\/p>\n","protected":false},"excerpt":{"rendered":"In a prior blog post, \u201cAgentic AI Part I: What It Is and Who\u2019s Responsible When It Acts,&#8221;&hellip;\n","protected":false},"author":2,"featured_media":74803,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,24,405,25,7537,29609,29606],"class_list":["post-74802","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-ai","tag-ai-agents","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-technology-law","tag-technology-law-updates"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/74802","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=74802"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/74802\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/74803"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=74802"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=74802"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=74802"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}