Insight

Agentic AI Liability: Who Is Responsible When AI Causes Harm?

← All Insights

Agentic AI and other forms of autonomous artificial intelligence put long-standing liability doctrines to the test. Although there are several challenges and potential accountability gaps, our existing legal framework still provides a largely workable foundation. Nevertheless, selective legislative measures aimed at complementing and adapting private law tools and corporate liability structures are desirable.

The Promises and Perils of Agentic AI

Agentic AI – along with autonomous AI more generally – has the potential to deliver significant gains in efficiency, convenience, and innovation. Agentic AI refers to a class of computational systems, often modular and built on large language models (LLMs), that are defined by their autonomy, their ability to pursue complex goals with minimal supervision, and their capacity to adapt to their environment. Agentic AI systems can coordinate workflows by independently initiating actions, adjusting to evolving circumstances, and working alongside other AI or human operators to accomplish defined goals. The technology marks a paradigm shift, with AI evolving into autonomous systems that are capable of self-sustained decision-making.

Agentic AI is emerging across a wide range of applications and is expected to become widely used. In business it could include the automated resolution of customer complaints, negotiation and execution of contractual terms, screening and hiring of employees, direct communications with regulators and third parties, deployment of marketing campaigns, and various oversight and security tasks. In consumer-facing settings, agentic AI may act on users’ behalf, rather than merely offering suggestions. For instance, agentic systems could autonomously pay bills, manage investments, purchase groceries, or book travel arrangements.

While there are many potential benefits to agentic AI, there are also significant risks. The technology may exhibit the same types of weaknesses as other types of AI, including bias, errors, and hallucinations. It is also vulnerable to data poisoning and knowledge manipulation. Additionally, however, agentic AI’s autonomy and cascading structure of linked systems arguably also exacerbate general AI risks. Heightened risks of agentic AI specifically lie in its capacity to generate harm at great speed and scale, but also in the growing difficulty of attributing liability and securing legal recourse.

Attribution of (Agentic) AI Harms and Corporate Liability

AI in general, and agentic AI in particular, raise novel questions of legal responsibility. Which parties are liable when AI causes harm? This is not just a theoretical or academic question anymore. The dark side of AI and algorithms has already surfaced in several contexts. Examples include allegations that AI chatbots have caused suicides; social media algorithms negatively affected student health; automated hiring tools discriminated against job applicants; or self-driving cars caused accidents. Additional and new AI-related harms will surely materialize.

In light of these developments, we must ask whether the law is equipped to appropriately assess and allocate responsibility for actions by AI, especially in its autonomous and agentic forms. Often, claims will be brought against corporations, which means this is in great part a question of corporate liability. While there are several well-established doctrinal tools that could serve as potential bases for imposing responsibility even for autonomous AI, some fundamental hurdles present themselves.

An important challenge is that liability frameworks in tort and corporate law are geared towards human actions and states of mind. Intention, negligence, and the concept of causation include elements of foreseeability, which may be difficult to prove in the AI context. After all, if harm is not foreseeable, it may not lead to liability under systems of fault-based liability, which are commonly used. Even in the case of strict liability there may still be elements of fault, such as when it comes to assessing whether a product was ‘defective’ in a legal sense. Therefore, liability gaps could arise when humans lose the ability to understand and predict AI actions. The link between autonomous AI-induced harm and individual actions, inactions, and fault may become too tenuous, leaving those harmed by AI without recourse.

This is especially true for legal systems – such as Canada, the UK, and several European jurisdictions – where corporate liability strictly depends on attribution of unlawful behaviour by its human agents. US law, in contrast, offers more flexible tools. Some US courts have developed approaches that steer away from ‘personalized’ corporate liability towards ‘depersonalized’ liability. These approaches tend to rely on concepts such as collective fault or a recognition of direct duties of corporations to ensure reasonable safety levels. Both are better suited than focusing on individual fault for attributing AI-related harms to legal entities.

Liability of AI Developers, Manufacturers, and Deployers

The most promising approach to legal accountability for harms by autonomous and agentic AI without direct human involvement is to cast the net wide. AI agents cannot be defendants because they lack legal personality, while immediate users are not present and/or have limited influence. The focus should therefore be on unlawful behaviour of connected entities behind AI. Key candidates in this respect include the businesses that develop, deploy, or manufacture AI systems. This does not mean that every occurrence of AI-induced harm should lead to liability (although some scholars are in favour of strict AI liability). Rather, the question is whether existing doctrines continue to provide adequate tools to assign responsibility.

  • Developers, based on negligence doctrines, could be liable for AI design flaws, inadequate training, insufficient testing, or failure to provide adequate warnings.
  • Sellers and distributors of AI systems may, according to some courts, also be treated as manufacturers, in which case they are subject to product liability claims for defects, inadequate warnings, or unsafe instructions.
  • Deployers that make AI available within their organization may be accountable for negligence in selecting, monitoring, and operating AI. This approach could draw a parallel to negligent hiring and supervision of employees and contractors.

The categories above may overlap in practice. Additionally, concurrent involvement of several players, such as is common in the multi-actor ecosystem of AI, raises complex questions of joint and several liability. Additionally, plaintiffs will face significant evidentiary obstacles in cases involving harms linked to algorithmic systems.

Emerging Judicial Responses to AI Liability and Algorithmic Harms

Emerging case law on liability for algorithms and AI provides early hints as to how courts are approaching this area. These cases provide insights that we can extrapolate to potential future disputes involving ‘more agentic’ AI with high degrees of autonomy. Notably, courts do not ask whether AI actions were wrongful in themselves or if AI could have its own legal personhood. Rather, they focus on organizational conduct, including the design and features of an AI system, control over it, risk management, and the terms of any delegation of decision-making.

Cases can usefully be grouped under three functional lenses:

  • (1) AI as an information interface
  • (2) AI as a risk-creating system
  • (3) AI as a delegated decision-maker

Each group tests existing liability frameworks in a different way, yet across all three, a brief overview suggests that courts have found those frameworks broadly adequate.

Where AI systems function as information interfaces, courts have held businesses responsible for incorrect or misleading outputs generated by their AI tools, treating those outputs as originating from the deploying organization. At the same time, courts have declined to impose strict liability on developers simply for releasing systems known to be capable of error, emphasizing instead the role of warnings, disclaimers, and the standard of care taken to reduce harmful outputs. Practical examples in this category include cases dealing with alleged misrepresentation and defamation. For instance, a British Columbia tribunal found that Air Canada was responsible for incorrect information provided by a chatbot on its website, while a US court granted summary judgment in favor of OpenAI in a case that sought to hold it liable for allegedly defamatory ChatGPT generated statements.

In the risk-creation category, courts have concluded that deploying an AI system can give rise to a duty of care toward third parties harmed by it. They have relied on tools such as common law negligence, products liability, and consumer protection laws for assessing responsibility. Examples include AI chatbot and social media algorithm litigation, seen in both the United States and Canada, in which courts have held defendants liable or declined to dismiss claims that algorithmic design features or AI generated outputs caused physical, mental, or economic harms. For instance, a Florida district court found that social media platforms owed a duty to take appropriate precautions in connection with releasing an AI chatbot that allegedly contributed to a suicide. Finally, products liability claims against autonomous vehicle developers have been allowed to proceed where design flaws and causal connection to accidents were adequately pleaded.

In the category of AI as a delegated decision-maker, an early case conditioned the permissibility of an algorithmic tool for judicial sentencing on it remaining advisory rather than determinative. The court required adequate safeguards and human judgment to remain the ultimate arbiter. A recent case from Australia similarly indicated that human judgment is a ‘red line’ when it comes to the use of AI by corporate boards and managers. Another recent decision appears to have moved beyond that framework, indicating that an AI developer or vendor may face liability towards third parties on the basis that organizations using its tool delegated core functions (in this case hiring decisions) to an AI system. The court did not object to AI functioning as a decision-maker per se – a stance which arguably may become inevitable with the rise of agentic and autonomous AI. The concern was with the process and outcomes the AI produced rather than delegation itself.

Agentic AI Governance and Regulation

The discussion above suggests that existing private law tools are fundamentally resilient and capable of addressing harms caused by autonomous and agentic AI. Nevertheless, there are several fragilities that could evolve into full-blown cracks. A weakness lies at the structural level of corporate attribution, which in part still depends on individual fault instead of fully embracing depersonalized approaches. Accountability gaps also remain in various other areas, from uncertainties on how to define AI and articulate standards for developers and deployers, to difficulties in proving foreseeability and causation relating to opaque algorithmic systems. Additional challenges are posed by the complexities of multi-actor AI ecosystems as well as jurisdictional fragmentation created by AI systems operating across borders.

These challenges call for legislative and regulatory measures, which however remain nascent and underdeveloped in view of the potentially drastic scope and magnitude of AI harms. Effective regulatory responses will require a combination of ex-ante preventative measures and ex-post rules on liability and compensation. These need to be complemented with appropriate AI governance best practices and prudent agentic AI governance frameworks within organizations, the latter focusing on agent boundaries and authority, risk management and controls, auditing and monitoring, and accountability mechanisms.

Conclusion

Agentic AI and other forms of autonomous AI have the potential to strain long-standing doctrines of fault, causality, attribution, and corporate responsibility. Yet, the early trajectory of litigation suggests that the foundations of private law remain intact, with courts, if they deem it appropriate, retaining the ability to allocate accountability to entities that design and deploy AI. But pressures do exist. Traditional corporate attribution doctrines remain conceptually tethered to individualized fault in ways that may sit uneasily with complex algorithmic decision-making. Plaintiffs also confront profound informational asymmetries when harm emerges from opaque models, and contractual waivers tend to reallocate technological risk onto consumers and weaker parties. In addition to the need for internal agentic AI governance, there is therefore a case for regulation of AI liability.

This Insight is based in part on my article on corporate responsibility for agentic AI.