Who’s Liable When Your AI Agent Acts on Its Own?

Agentic AI (systems that execute transactions, modify data, or trigger workflows without human sign-off) has become the central AI governance question for regulators across the EU, UK and US in 2026. The consistent theme across jurisdictions is that liability doesn’t disappear into the machine: it stays with the organisation that deployed the agent, and increasingly with the vendor that built it. Businesses adopting agentic tools need a governance layer, not just a capability assessment.

Most AI governance conversations of the last few years have been about predictive or generative tools that produce an output for a human to review. Agentic AI is different in kind: it can act. That shift from adviser to actor is what regulators and courts internationally are now grappling with, and Australian businesses adopting these tools are not exempt from the question, and can no longer answer it on the basis that local law is silent.

“Execution Risk” Is the New Test

Where legal review of predictive AI focused on model accuracy (is the output correct, is it biased), agentic AI review has to focus on execution risk: what can this system actually do, autonomously, and what happens if it does the wrong thing at machine speed, before a human notices? A governance framework built only around output accuracy misses the risk entirely. The distinction is not theoretical. A generative tool that drafts an incorrect payment instruction produces a document a person still has to action. An agentic tool holding payment permissions executes it, and may execute it several hundred times before the overnight exception report runs. Same underlying error, materially different legal position: the first is a near miss, the second is a set of completed transactions the organisation has to unwind, explain to a counterparty, and potentially notify.

Where Liability Is Actually Landing

International developments point the same direction: the EU’s revised Product Liability Directive, Directive (EU) 2024/2853, which member states must transpose by 9 December 2026, brings software, including AI systems, within a no-fault strict liability regime as “products,” with rebuttable presumptions of defect and causation and court-ordered disclosure of technical evidence. With the separate AI Liability Directive proposal now withdrawn, product liability has become the primary EU route. In January 2026 the UK Information Commissioner’s Office became the first data protection regulator to publish on agentic AI, stating that “[i]n the context of data protection, AI agency does not mean the removal of human, and therefore organisational, responsibility for data processing.” That report is expressly not formal guidance (a dedicated agentic AI guideline and a statutory AI code of practice are on the ICO’s 2026–27 programme), but the direction is unambiguous, and the ICO singles out multi-vendor agentic supply chains as the hardest place to locate controllership. In the US, with no federal AI liability statute, the analysis is being run through existing doctrine (agency, negligence, product liability, contract), and lands in the same place: accountability runs to the humans and entities behind the agent, not the agent itself.

For Australian businesses, this means existing frameworks (contract law, negligence, the Privacy Act, Corporations Act and  sector-specific regulation) already apply to agentic AI’s actions. There is no liability gap simply because the technology is new. And on one front the law has already moved: from 10 December 2026, new APP 1.7, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), requires APP entities to disclose in their privacy policy where they use automated decisions that could reasonably be expected to significantly affect an individual’s rights or interests. An agent that approves, prices, refuses or restricts something for a customer is squarely within that description. It is a disclosure obligation rather than a prohibition, but it is a hard commencement date, not a phased rollout, and the OAIC’s guidance is still pending.

A Governance Layer That Actually Matches the Risk

  • Inventory every system in the business with agentic capability: the ability to act, not just advise.
  • Apply “human-on-the-loop” oversight proportionate to risk: full autonomy may be acceptable for low-risk logging tasks, but not for anything touching finances, contracts, or customer decisions.
  • Maintain audit trails sufficient to reconstruct what an agent did and why, after the fact.
  • Review vendor contracts for AI tools specifically for liability allocation. In practice, at best AI vendor paper is still written for a tool that recommends, not one that acts: warranties are limited to the software performing substantially in accordance with documentation, liability is capped at fees paid, and there is rarely anything addressing the consequences of an autonomous action the customer never approved. Silence in the contract does not mean silence in the risk; it usually means the risk has defaulted to you.

Standing this governance layer up, and keeping it current as the rules move, is where an ongoing fractional general counsel relationship earns its place, bringing AI use policies and oversight design under one accountable function.

Disclaimer

This article is general information only and is not legal advice. It discusses international regulatory and legal developments relevant to agentic AI, which continue to evolve rapidly. Obtain advice specific to your specific systems and circumstances before acting.

Share :

About the author

Kirsten Dilena

Kirsten Dilena is the founder and principal lawyer at DLC Legal, a boutique commercial and regulatory practice advising on governance, compliance, cybersecurity and data privacy law, and government procurement. With 20+ years of legal experience across government, defence, and commercial and emerging technology sectors, Kirsten helps regulated businesses build compliance architecture that is proportionate, defensible, and workable.