Agent Liability
The question of who bears *legal* responsibility when an AI agent's action harms a third party — a wrong decision, a data leak, a discriminatory outcome, a financial loss. The short answer is that 'the AI did it' is not a defense: an autonomous system is not a legal person, holds no assets, and can't be sued or fined, so liability flows to the humans and organizations in the chain. Three roles can be on the hook: the *provider/developer* who built and placed the agent or its model on the market (a product-liability posture), the *deployer/operator* who put it to use in their own operations (distinct obligations under the EU AI Act plus ordinary negligence exposure), and the *user* who directed a specific action. Two things matter most for anyone shipping agents: the deployer usually can't outsource the risk to the model vendor, and a tamper-evident audit trail is the primary evidence that you acted reasonably. Accountability infrastructure is liability insurance built in advance. *(General orientation, not legal advice — liability turns on jurisdiction, sector, and facts.)*
Example
A retailer deploys a third-party pricing agent that autonomously sets discriminatory prices. Even though a vendor built the model, the retailer — as deployer — is the one regulators and plaintiffs reach first: it chose to let the agent act on real customers, and under the EU AI Act it owed duties of human oversight and monitoring it can't delegate away.
Frequently asked questions
- If we use a vendor's model, isn't the vendor liable?
- Rarely in full. Vendor terms typically disclaim liability, and even where a developer shares responsibility, the *deployer* — the organization that chose to let the agent act on real customers and data — is usually the first party a regulator or plaintiff reaches. You can shift some risk by contract, but you can't contract your way out of your own oversight duties under frameworks like the EU AI Act.
- How does an audit trail reduce liability?
- Negligence and regulatory exposure turn on whether you acted *reasonably*. A tamper-evident audit trail with human oversight at high-risk actions is the concrete evidence that you did — and the required logging is itself a legal obligation for high-risk systems. Its absence, conversely, is often the clearest sign that you didn't.