AI Agents and Legal Liability: Who Is Responsible When an Autonomous System Causes Harm?
AI agents are software systems that perceive their environment, make decisions, and take actions to achieve defined objectives — often without a human approving each step. Unlike a traditional program that executes predetermined instructions, an agent reasons over its inputs and acts autonomously. A trading algorithm that adjusts a portfolio in real time, an AI hiring system that screens and ranks candidates without human review, a medical AI that recommends treatment pathways, and an autonomous vehicle navigating live traffic are all examples of AI agents operating with varying degrees of independence.
As these systems become more capable and more embedded in consequential decisions — about people's finances, health, employment, and physical safety — the question of who bears legal responsibility when something goes wrong has become urgent. Current liability frameworks were designed for human actors and conventional products. AI agents challenge both.
How Current Liability Law Applies
Product liability is one available framework. In the EU, the Product Liability Directive was substantially revised in 2024, explicitly extending it to software including AI systems. Under the revised PLD, producers can be held liable for defective products regardless of fault, and the burden of proof has been eased: claimants who face disproportionate difficulty accessing technical evidence about an AI system can request disclosure from the developer. The revised PLD also covers damage caused by AI updates and by AI deployed as a service rather than a sold product.
Negligence remains relevant in jurisdictions outside product liability regimes, and as a supplement within them. To succeed in negligence, a claimant must show that a defendant owed them a duty of care, that the defendant breached it, and that the breach caused the harm. When an AI agent causes harm, courts must determine who held the relevant duty — the developer who trained the model, the company that deployed it, or the organization that configured and instructed it in the specific context. Where responsibilities are divided across a supply chain, tracing causation becomes complicated.
Vicarious liability — by which an employer is held responsible for an employee's acts within the scope of employment — does not map easily onto AI agents. Courts have generally not extended this doctrine to autonomous systems acting outside a human's real-time control, leaving a gap when agents take actions that no human individually directed.
The Liability Gap
Traditional tort law assumes there is a responsible human actor, or at least a clear chain of command ending with one. AI agents create a gap in several respects. The harm may flow from training data choices made years before deployment — a developer's responsibility, but one that is hard to isolate as the specific cause. AI systems can also take unexpected actions that were technically within their parameters: every party can honestly say they did not direct the specific decision that caused harm. And the internal reasoning of many AI models cannot be fully inspected, making it difficult to prove in litigation exactly why a particular output was generated.
This combination — distributed responsibility across developer, deployer, and user; emergent behavior from training rather than explicit instruction; and limited interpretability — is what distinguishes AI agent liability from conventional product or professional liability.
The EU AI Liability Directive Proposal
The European Commission proposed the AI Liability Directive in 2022 to address these gaps alongside the EU AI Act. The proposal would establish a rebuttable presumption of causation: where a claimant can show that an AI system failed to comply with the EU AI Act and that non-compliance is a plausible cause of the harm suffered, the court may presume causation unless the defendant proves otherwise. It also includes provisions facilitating access to evidence about AI systems where claimants would otherwise face disproportionate disclosure barriers. The Directive had not been finalized as of mid-2026, but reflects the direction of European legislative policy on AI harm. For the underlying compliance requirements that non-compliance evidence would draw on, see our overview of what the EU AI Act requires from businesses.
Developer, Deployer, User: Who Owes What
The EU AI Act draws a clear distinction between providers — those who develop AI systems or place them on the market — and deployers — businesses or organizations that put AI systems into use in a commercial or professional context. Providers bear primary responsibility for the system's design, safety properties, and compliance with Act requirements for their risk category. Deployers bear responsibility for appropriate use, configuration, and human oversight within their specific operational context.
This distinction is increasingly reflected in AI procurement contracts. Deployers seek to shift liability to providers through indemnity clauses; providers push back by requiring deployers to use systems only within documented parameters and for stated purposes. How these contractual allocations interact with tort liability owed to third parties remains an unsettled area.
Insurance
AI liability creates challenges for the insurance market. Traditional professional indemnity and product liability policies may not adequately cover harms caused by autonomous AI decisions, particularly where the harm arises from emergent behavior rather than a clear design defect. Insurers are beginning to develop tailored AI liability coverage, and some regulatory proposals would require minimum insurance for high-risk AI deployments. Businesses deploying AI in consequential contexts should review their coverage with insurers who understand the specific characteristics of AI risk.
How Courts Are Responding
Courts have not yet developed settled doctrine specifically for autonomous AI harm. Existing precedent is being adapted from adjacent areas: product liability for autonomous vehicle harm, professional liability for AI-assisted medical decisions, securities regulation for algorithmic trading. Several courts have begun requiring disclosure of AI model documentation in litigation to support causation arguments. The common law development is incremental, and its pace is likely to accelerate as AI agent deployments multiply. Businesses and their legal advisers should monitor developments in their specific sectors closely. For a broader treatment of liability principles across AI use cases, see our article on AI liability when algorithms cause harm.
Frequently Asked Questions
Who is legally responsible when an AI agent causes harm?
Responsibility depends on where the failure occurred — in the system's design (primarily the developer's responsibility), in how it was deployed and configured (the deployer's responsibility), or in how it was used in a specific instance (the user's responsibility). Where these overlap, or where a system acts in unexpected ways that span all three, liability may be shared or remain contested under current law.
Does the EU AI Act create direct liability for AI-caused harm?
No. The EU AI Act creates compliance obligations for providers and deployers. Civil liability for AI harm is addressed separately through the proposed AI Liability Directive and the revised Product Liability Directive. However, non-compliance with the EU AI Act may be used as evidence supporting a negligence or product liability claim, particularly under the AI Liability Directive's proposed causation presumption.
What is the EU AI Liability Directive?
A legislative proposal introduced by the European Commission in 2022 to address the evidential and causation barriers that make AI harm claims difficult under existing tort law. It would create a presumption of causation where non-compliance with the EU AI Act can be demonstrated, and it includes provisions to ease claimant access to technical evidence about AI systems. As of mid-2026 it remained a proposal pending finalization.
How should businesses document AI system operation to reduce liability exposure?
Businesses should maintain technical documentation of AI system design and training data choices, conduct pre-deployment risk assessments, log AI-assisted decisions in auditable form, implement human oversight for high-stakes outputs, and review contractual liability allocation with AI vendors and downstream customers. Records of oversight measures and quality controls will be important evidence if a claim is brought.