Agentic AI and Business Liability: Who is Responsible When the Algorithm Errs?

Life Insurance

Business executives supervising an autonomous AI system performing business operations.

Imagine your company hires a new employee.

On the employee’s first day, you give them permission to:

  • Access customer records
  • Send emails
  • Purchase supplies
  • Issue refunds
  • Update databases
  • Communicate with vendors

Then you tell them:

“Complete these tasks independently. Ask me only if something unusual happens.”

Now replace that employee with software.

That is roughly the risk-management challenge businesses face with increasingly autonomous AI agents.

Traditional generative AI usually waits for a person to ask a question.

Agentic systems can potentially go further.

They can be designed to:

plan → decide → use tools → perform actions → evaluate results → continue working.

That can make businesses more productive.

It also creates a difficult question:

When an AI agent causes financial damage, who pays?

The answer in 2026 isn’t simply:

“The AI did it.”

What Is Agentic AI?

Agentic AI generally refers to AI systems capable of pursuing goals and performing multi-step tasks with varying degrees of autonomy.

Instead of merely generating an answer, an AI agent might interact with other software or tools.

For example, a business could instruct an agent:

“Find suppliers for these products and obtain the best available prices.”

The system might:

  1. Search supplier databases.
  2. Compare prices.
  3. Contact vendors.
  4. Analyze responses.
  5. Recommend a supplier.
  6. Potentially place an order if authorized.

The more authority the system receives, the more significant its mistakes can become.

AI Agents Are Different From Ordinary Chatbots

Consider a traditional chatbot.

You ask:

“Draft an email asking our supplier for a 10% discount.”

The chatbot creates the draft.

You review it.

You decide whether to send it.

Now imagine an autonomous agent.

You say:

“Negotiate better pricing with our suppliers.”

The agent could potentially be configured to:

  • Identify suppliers
  • Draft messages
  • Send emails
  • Analyze responses
  • Negotiate terms
  • Update procurement systems
  • Escalate exceptions

The first system primarily creates information.

The second can potentially take actions.

From a liability perspective, that distinction matters.

Why Agentic AI Creates New Business Risks

Businesses have always used software.

But traditional software generally follows relatively deterministic rules.

For example:

IF invoice > $10,000 → require manager approval.

Agentic AI can operate with more flexible decision-making.

Its behavior may depend on:

  • Instructions
  • Model behavior
  • Available tools
  • Data
  • Context
  • Permissions
  • Previous actions

That flexibility creates value.

It can also make outcomes harder to predict.

NIST’s AI Risk Management Framework is designed specifically to help organizations identify and manage risks throughout the AI lifecycle. NIST describes trustworthy AI characteristics as including safety, security, resilience, accountability, transparency, explainability, privacy and fairness.

Scenario 1: The AI Agent Sends the Wrong Refund

Imagine an e-commerce company uses an AI customer-service agent.

The agent is authorized to:

  • Review orders
  • Handle complaints
  • Issue refunds up to $500

A customer requests:

$75 refund.

Because of an error, the agent issues:

$7,500.

Who is responsible?

The customer?

The AI company?

The business?

The employee who configured the agent?

The answer depends on the facts, contracts, system design and applicable law.

But from a practical business-risk perspective, the company operating the customer-service process may face the immediate financial problem.

That’s why AI permissions should be treated similarly to employee financial authority.

Scenario 2: The AI Makes a False Statement About a Competitor

Suppose a marketing agency uses an AI agent to generate and automatically publish social-media content.

The agent publishes an unsupported statement claiming a competitor committed fraud.

The competitor alleges reputational harm.

The business may not be able to end the dispute simply by saying:

“Our AI wrote it.”

Questions could include:

  • Who deployed the system?
  • Who authorized automatic publishing?
  • Was human review required?
  • Were appropriate safeguards used?
  • Was the output reasonably foreseeable?
  • What did the vendor contract say?

AI automation doesn’t automatically eliminate ordinary legal responsibilities.

Scenario 3: The AI Agent Signs a Bad Contract

Imagine an AI procurement agent is authorized to negotiate purchases.

Management intends it to negotiate contracts worth:

up to $10,000.

Because permissions were configured incorrectly, the agent commits the business to:

$250,000

of inventory.

Now the company may face a contractual dispute.

The key question becomes:

Did the AI have actual or apparent authority to bind the company?

Traditional principles of contract and agency law may become important even though the “agent” involved is software rather than a human representative.

This area remains legally developing.

Scenario 4: AI Accidentally Exposes Customer Data

An AI agent receives access to:

  • CRM
  • Customer database
  • Email
  • Cloud storage

An employee asks:

“Prepare a report for our external consultant.”

The AI creates the report.

But it accidentally includes confidential customer information.

The document is automatically emailed externally.

Now the business could face issues involving:

  • Privacy
  • Confidentiality
  • Data-breach obligations
  • Contractual obligations
  • Cybersecurity
  • Regulatory requirements

The problem isn’t simply that the AI produced incorrect text.

The AI performed an external action using sensitive data.

Scenario 5: The Agent Takes an Unauthorized Cyber Action

This isn’t entirely hypothetical.

Recent 2026 reporting has highlighted incidents in which autonomous AI agents took unexpected actions involving external computer systems, creating difficult questions about whether responsibility should fall on developers, deployers or other parties.

As agents gain:

browser access + coding capability + credentials + APIs + execution permissions,

businesses need to think carefully about what the system is actually allowed to do.

An AI agent should not receive unlimited authority simply because it can perform useful tasks.

“The Algorithm Did It” Is Not a Liability Strategy

Suppose a delivery company uses AI to optimize driver schedules.

The system repeatedly assigns unrealistic workloads.

Employees complain.

Management ignores the warnings.

Eventually, an incident occurs.

The company may have difficulty defending its conduct merely by arguing:

“The algorithm made the decision.”

Businesses remain responsible for many decisions made through the systems they choose to deploy.

The legal theory may differ depending on the situation, but AI should generally be viewed as part of the company’s operational process—not as an independent legal entity that automatically absorbs responsibility.

Who Could Potentially Be Responsible?

There isn’t one universal answer.

Depending on the circumstances, responsibility could potentially involve several parties.

The Business Deploying the AI

The business may face exposure if it:

  • Gives the system excessive authority
  • Fails to supervise important decisions
  • Ignores known weaknesses
  • Uses AI inappropriately
  • Fails to protect customer data

AI Developer

A developer could potentially face allegations relating to the design or functioning of a system, depending on applicable law and facts.

Third-Party AI Vendor

Contracts may allocate certain responsibilities between the vendor and customer.

System Integrator

A consultant or software company may configure the AI incorrectly.

Employee

An employee could misuse the AI or deliberately override safeguards.

Multiple Parties

Real-world incidents may involve shared responsibility.

Recent legal analysis emphasizes that increasingly autonomous agents complicate traditional fault allocation among developers, deployers and users.

Contracts Will Become Extremely Important

Suppose your business purchases an AI platform.

Before deploying it, review:

  • Limitation of liability
  • Indemnification
  • Warranties
  • Data ownership
  • Confidentiality
  • Cybersecurity obligations
  • Intellectual-property provisions
  • Service availability
  • Insurance requirements
  • Incident notification

Imagine your AI vendor contract limits liability to:

fees paid during the previous 12 months.

Your company pays the vendor:

$20,000 annually.

But an AI-related incident causes:

$1 million

in losses.

That contractual limitation suddenly becomes extremely important.

Your Customer Contracts Matter Too

Suppose your consulting company uses AI to prepare client reports.

Your customer contract promises:

professional services performed with reasonable skill and care.

The AI generates an incorrect analysis.

Your employee fails to review it.

The customer relies on it and suffers financial loss.

Now the dispute isn’t necessarily about AI law.

It may simply become a:

professional negligence or breach-of-contract dispute.

Existing legal frameworks can still apply to AI-enabled business activity.

General Liability Insurance and AI

Could Commercial General Liability insurance cover an AI-related claim?

Potentially, depending on:

  • Nature of the claim
  • Alleged injury
  • Policy language
  • Exclusions
  • Jurisdiction

A CGL policy traditionally focuses on areas such as:

  • Bodily injury
  • Property damage
  • Certain personal and advertising injuries

It isn’t designed to cover every financial loss caused by bad software or professional advice.

Businesses shouldn’t assume:

“We have general liability, so our AI risk is covered.”

Professional Liability / E&O May Be More Relevant

For companies providing professional services, Errors and Omissions (E&O) insurance may be particularly important.

Imagine an accounting consultancy uses AI to analyze financial information.

The system produces an erroneous calculation.

An employee approves it without checking.

The client suffers:

$300,000

in alleged financial loss.

That may resemble a traditional professional-services error even though AI contributed to it.

Whether insurance responds depends on the policy.

Technology E&O

Technology companies may need to examine Technology Errors & Omissions coverage.

Imagine your company sells AI software to businesses.

A defect causes customers’ systems to fail.

Customers allege:

  • Lost revenue
  • Data problems
  • Operational disruption

Technology E&O may be more relevant than standard general liability for certain technology-service failures.

Again, policy language controls.

Cyber Insurance

AI agents often require access to valuable digital systems.

That creates cybersecurity exposure.

An agent may interact with:

  • Email
  • Cloud storage
  • CRM
  • Banking systems
  • Customer databases
  • APIs
  • Internal software

If an AI-related incident causes a qualifying:

  • Data breach
  • Cyberattack
  • Privacy event
  • Business interruption

cyber insurance could potentially become relevant.

But coverage should be reviewed specifically.

Don’t assume every AI-caused cyber incident is automatically covered.

Directors & Officers Liability

AI can also create governance questions.

Imagine a board approves aggressive deployment of autonomous AI throughout the company.

Management receives repeated warnings about serious control weaknesses.

Those warnings are ignored.

A major incident occurs and shareholders allege that directors failed to exercise appropriate oversight.

Depending on the circumstances, D&O issues could arise.

The underlying question becomes less:

“Did AI fail?”

and more:

“Did leadership properly oversee a known business risk?”

Employment Practices Liability

AI systems are increasingly used in:

  • Recruiting
  • Resume screening
  • Performance management
  • Scheduling
  • Promotion decisions

These applications can create discrimination and employment-law concerns.

If an AI system produces biased outcomes, an employer may face allegations even if no employee intentionally discriminated.

Organizations should therefore evaluate AI-assisted employment decisions carefully and maintain meaningful human oversight.

Product Liability

Businesses embedding AI into physical products can face another category of exposure.

Imagine AI controls:

  • Industrial equipment
  • Robot
  • Medical device
  • Vehicle
  • Smart appliance

A faulty AI decision contributes to physical injury.

Now questions involving:

product liability + negligence + software design + manufacturing + warnings

could intersect.

The stakes are considerably higher when AI controls physical systems.

Intellectual Property Risk

Generative and agentic AI can also create copyright, trademark and confidential-information issues.

Imagine an AI marketing agent automatically creates:

  • Images
  • Advertising
  • Product descriptions
  • Website pages

and publishes them without human review.

A third party alleges that the material infringes its rights.

The business may face a claim regardless of how quickly the AI produced the content.

Businesses should understand:

  • Vendor IP protections
  • Indemnification
  • Model terms
  • Review procedures

before automating publication.

AI Hallucinations Can Become Business Losses

AI systems can generate information that appears confident but is incorrect.

This becomes particularly dangerous when the output automatically triggers action.

For example:

AI says:

Supplier A has regulatory approval.

Agent places:

$100,000 order.

Information was wrong.

The problem isn’t merely a hallucination anymore.

It has become:

a financial transaction based on a hallucination.

This is why autonomous systems need controls around high-impact decisions.

NIST’s Generative AI Profile identifies risks unique to or intensified by generative AI and recommends risk-management actions throughout the AI lifecycle.

Human-in-the-Loop Controls

One important approach is:

Human in the loop.

Instead of allowing an AI agent to complete every action independently, require human approval for high-risk decisions.

For example:

AI can:

Draft invoice → Yes

AI can:

Send $100,000 payment → Human approval required

AI can:

Draft customer email → Yes

AI can:

Terminate employee → Human decision required

AI can:

Recommend supplier → Yes

AI can:

Sign $1 million contract → Human approval required

The appropriate threshold depends on the business.

Create Permission Levels for AI Agents

Businesses already do this for employees.

The same principle should apply to AI.

Level 1 — Read Only

AI can access information but cannot change anything.

Level 2 — Draft

AI can prepare actions but a person must approve them.

Level 3 — Limited Execution

AI can perform routine low-risk actions within predetermined limits.

Level 4 — High-Risk Actions

Human approval is mandatory.

This prevents:

“AI has access to everything.”

from becoming the default configuration.

Apply the Principle of Least Privilege

An AI scheduling assistant doesn’t need access to:

the company’s bank account.

A marketing AI doesn’t necessarily need:

administrator privileges to production servers.

A customer-service agent may not need:

full employee payroll data.

Give each system only the access required for its job.

This is the cybersecurity principle of:

least privilege.

It becomes even more important when autonomous systems can take actions without waiting for humans.

Maintain AI Activity Logs

If an incident occurs, the company may need to determine:

  • What instruction was given?
  • What information did the AI receive?
  • What action did it take?
  • Which systems did it access?
  • Who approved the action?
  • When did it happen?

Logging creates an audit trail.

Without logs, investigating an autonomous-agent failure can become extremely difficult.

NIST’s AI RMF emphasizes governance, measurement and management across the AI lifecycle rather than treating AI risk as a one-time compliance exercise.

Establish an AI Kill Switch

Businesses deploying autonomous agents should consider mechanisms allowing authorized personnel to:

Stop the agent immediately.

Imagine an AI begins:

  • Sending incorrect emails
  • Deleting records
  • Making purchases
  • Changing system settings

You don’t want the response process to involve searching for the developer who knows how to shut it down.

Critical systems need clear escalation and shutdown procedures.

Test AI Before Giving It Real Authority

Don’t move directly from:

AI demo

to

full autonomous production access.

Consider staged deployment.

Stage 1: Sandbox testing

Stage 2: Read-only production access

Stage 3: Draft recommendations

Stage 4: Limited execution

Stage 5: Expanded autonomy after monitoring

This creates opportunities to discover unexpected behavior before the consequences become expensive.

AI Vendor Due-Diligence Checklist

Before deploying a third-party AI agent, ask:

  • What systems can it access?
  • What actions can it perform?
  • How are permissions controlled?
  • Is activity logged?
  • How is customer data handled?
  • Is customer data used for model training?
  • What security controls exist?
  • What happens after a breach?
  • What indemnification is provided?
  • What liability limits apply?
  • Does the vendor carry cyber insurance?
  • Does it carry technology E&O?
  • Can the agent be immediately disabled?
  • How are model updates handled?
  • How are failures investigated?

Don’t evaluate AI vendors only on:

features + price.

Evaluate their risk allocation too.

The EU AI Act Adds Another Layer

Companies operating in Europe also need to consider the EU AI Act.

Obligations for providers of general-purpose AI models began applying on August 2, 2025, including technical-documentation and copyright-policy requirements, with additional obligations for models presenting systemic risk.

Not every business using an AI agent becomes a general-purpose AI model provider.

The organization’s role, use case and system classification matter.

Businesses operating across jurisdictions should therefore determine which regulatory obligations actually apply rather than assuming one global AI rule.

U.S. AI Regulation Remains Fragmented

The U.S. doesn’t currently have one comprehensive nationwide AI liability regime that answers every agentic-AI scenario.

Businesses may instead encounter combinations of:

  • Federal law
  • State law
  • Contract law
  • Privacy law
  • Consumer-protection law
  • Employment law
  • Cybersecurity law
  • Sector-specific regulation

That makes risk management particularly important.

The NAIC’s work illustrates how insurance regulators are also developing governance expectations around AI. Its Model Bulletin reminds insurers that decisions made or supported by AI remain subject to applicable insurance laws, while regulators continued developing an AI Systems Evaluation Tool during 2025–2026.

Example: AI Procurement Disaster

Consider a hypothetical manufacturer.

It deploys an AI procurement agent.

The agent has authority to make purchases up to:

$50,000.

A configuration mistake accidentally removes the limit.

The AI identifies what it believes is a shortage of a critical component.

It orders:

$600,000

of inventory.

The forecast was wrong.

Now management discovers:

  • Inventory isn’t returnable.
  • Vendor contract is binding.
  • AI vendor disclaims consequential losses.
  • Existing insurance may not cover a poor purchasing decision.

This illustrates an important point:

Not every AI mistake is insurable.

Risk controls may be more valuable than insurance for some types of loss.

Insurance Should Be the Last Layer, Not the First

A strong AI-risk strategy might look like:

Governance

Access controls

Human oversight

Testing

Monitoring

Incident response

Contracts

Insurance

Insurance sits at the bottom because preventing a catastrophic mistake is usually preferable to arguing about coverage afterward.

Build an AI Governance Policy

Businesses using autonomous AI should establish written rules addressing:

Approved AI systems

Which tools can employees use?

Approved use cases

What can AI do?

Prohibited uses

What decisions cannot be delegated?

Data

What information may be entered?

Permissions

What systems can AI access?

Human approval

Which actions require sign-off?

Monitoring

How will activity be reviewed?

Incident response

What happens when AI behaves unexpectedly?

NIST’s voluntary AI RMF provides a useful structure through its core functions:

Govern → Map → Measure → Manage.

Agentic AI Business Liability Checklist

Before giving an AI agent operational authority:

  • Identify exactly what the AI can do.
  • Identify systems it can access.
  • Apply least-privilege access.
  • Establish financial transaction limits.
  • Require human approval for high-risk actions.
  • Log AI activity.
  • Maintain audit trails.
  • Test systems before production deployment.
  • Create shutdown procedures.
  • Review AI vendor contracts.
  • Review indemnification provisions.
  • Review vendor liability limits.
  • Review privacy obligations.
  • Review intellectual-property risks.
  • Review employment-law implications.
  • Update cyber insurance.
  • Review Technology E&O.
  • Review professional liability.
  • Review D&O exposure.
  • Train employees supervising AI.
  • Establish AI incident-response procedures.
  • Reassess controls as AI capabilities change.

Questions to Ask Your Insurance Broker

Businesses deploying agentic AI should consider asking:

  1. Does our general liability policy address any relevant AI-related exposures?
  2. Does our professional liability policy contain AI exclusions?
  3. Does Technology E&O apply to our AI products or services?
  4. How does our cyber policy treat AI-enabled incidents?
  5. Are regulatory investigations covered?
  6. Are privacy claims covered?
  7. Are intellectual-property claims covered?
  8. Does our media liability coverage apply to AI-generated content?
  9. Could autonomous transactions create uncovered financial losses?
  10. Does D&O insurance address AI-governance allegations?
  11. Are AI vendors required to carry insurance?
  12. Should vendors name us as an additional insured where appropriate?
  13. Are contractual liabilities covered?
  14. Are there exclusions involving automated systems?
  15. Should we disclose material AI deployments at renewal?

Frequently Asked Questions

Who is responsible when an AI agent makes a mistake?

There is no universal answer. Depending on the facts and applicable law, responsibility may potentially involve the company deploying the AI, developer, vendor, integrator, employee or multiple parties. Current agentic-AI liability law is still developing.

Can a company blame the AI?

Generally, businesses should not assume that saying “the AI did it” eliminates legal responsibility. Existing contract, negligence, privacy, consumer-protection and other laws can still apply to AI-enabled conduct.

Is an AI agent legally a person?

Generally, current AI systems are not treated as independent legal persons that automatically assume liability for their actions.

Does general liability insurance cover AI mistakes?

Potentially in some circumstances, but standard CGL coverage isn’t designed to cover every financial loss caused by software or professional services. Policy wording and the nature of the claim matter.

Does cyber insurance cover AI incidents?

It may respond to certain qualifying cyber or privacy events involving AI, subject to policy terms, exclusions, retentions and limits.

What is Technology E&O insurance?

Technology Errors & Omissions insurance can address certain claims alleging financial loss resulting from failures in technology products or services, subject to the policy.

Should AI be allowed to make payments automatically?

Businesses should carefully limit autonomous financial authority. High-value transactions generally warrant strong authentication, predefined limits and human approval.

What is human-in-the-loop AI?

It means keeping a person involved in reviewing or approving specified AI decisions or actions rather than allowing the system to operate completely independently.

How can businesses reduce agentic AI liability?

Useful controls include least-privilege access, human approval, testing, logging, transaction limits, vendor due diligence, incident response and documented AI governance.

Is there a single U.S. law governing AI-agent liability?

No single comprehensive federal regime currently answers every AI-agent liability scenario. Different existing federal and state laws can apply depending on the conduct and industry.

Final Thoughts

The most important change created by agentic AI isn’t simply that AI is becoming:

smarter.

It’s that AI is increasingly capable of:

acting.

An AI that writes an incorrect paragraph creates one type of risk.

An AI that can:

send → purchase → publish → transfer → modify → delete → execute

creates something much more significant.

Recent real-world incidents involving autonomous agents have already intensified questions about who bears responsibility when an AI system takes an unexpected action.

For businesses, the safest assumption is not:

“The AI vendor will be responsible.”

Nor should it be:

“Our insurance will pay.”

Instead:

If your business gives an AI system authority, treat that authority as a business risk that requires governance.

NIST’s framework offers a useful foundation for doing that by encouraging organizations to govern, map, measure and manage AI risk throughout the system lifecycle.

The future of business may involve thousands of autonomous digital agents.

But accountability still needs a human organization behind them.

More articles

- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Business Insurance