When the AI Agent Makes the Decision, Who Owns the Mistake?
For most of the generative AI era, the legal profession has worried about what happens when artificial intelligence gives someone a bad answer. That may soon look like the easy problem. The next generation of AI systems does not merely answer questions. Agents can execute tasks, navigate software, communicate with other systems, make sequential decisions, write and run code, and pursue objectives with decreasing human involvement.
Who owns the mistake?
When a chatbot gives an employee a bad recommendation, there is still a human standing between the machine and the consequence.
When an autonomous agent acts on the recommendation itself, that buffer begins to disappear. And the obvious question becomes surprisingly difficult: Who owns the mistake?
The Law Likes Defendants
Our legal system is fundamentally anthropocentric.
Someone acts. Someone owes a duty. Someone breaches a contract. Someone negligently supervises an employee. Someone manufactures a defective product. Someone authorizes an agent. Then liability follows the relationship between those people and their conduct.
Artificial intelligence complicates this framework because an AI agent can occupy an uncomfortable position between instrument and actor. It is plainly not a legal person in the traditional sense. But increasingly, it does things that previously required one.
Imagine that a company deploys an autonomous AI agent to negotiate routine vendor contracts. Management establishes the objectives. The software receives access to company systems. Within defined parameters, the agent communicates with vendors and completes transactions.
Then something goes wrong. The agent agrees to commercially disastrous terms that nobody specifically authorized.
Who is responsible? The employee who configured it? The company that deployed it? The developer who built the model? The software company that packaged the agent? The vendor that knowingly negotiated with a machine?
Our existing doctrines can probably answer many versions of that hypothetical. The interesting cases will be the ones where they cannot answer them cleanly.
“The AI Did It” Cannot Become a Defense
There is one principle courts should establish early. Delegating a decision to software should not automatically delegate responsibility for the consequences.
Otherwise, AI creates an extraordinary moral hazard. Companies could obtain the economic benefit of autonomous decision-making while externalizing the legal cost of decisions they later dislike. That cannot be the equilibrium.
If a law firm deploys an AI system to communicate with prospective clients, the firm cannot plausibly respond to an improper representation by saying nobody at the firm personally wrote it.
If a corporation authorizes an agent to negotiate purchases, it should not automatically escape contractual consequences because a human did not approve every sentence.
And if an AI system is given access to sensitive infrastructure and causes foreseeable harm because of inadequate controls, the fact that the precise sequence of machine decisions was unexpected should not end the inquiry.
The difficult issue is not whether responsibility exists. It is how responsibility should be allocated.
Foreseeability Is About to Become Extremely Important
For lawyers, one familiar concept may do an enormous amount of work here: foreseeability.
The relevant question will often be less, ‘Did the developer intend for the AI to do this?’ and more, ‘Was this category of behavior reasonably foreseeable when the system was deployed?’
That distinction matters. Powerful software has always produced unexpected outcomes. Unexpected does not necessarily mean unforeseeable.
If an autonomous system is deliberately given broad permissions, incomplete guardrails, access to external systems, and authority to pursue an objective independently, some degree of unpredictable behavior is inherent in the design.
The organization deploying that system cannot simultaneously celebrate its autonomy when it creates value and characterize the same autonomy as an unforeseeable intervening force when it causes damage.
The more authority we delegate to AI, the more important governance around that delegation becomes.
Lawyers Will Have to Ask Different Questions
This has immediate consequences for lawyers advising businesses that deploy AI.
Traditional technology diligence often asks: What data does the system access? Where is the information stored? Is the data used for model training? What cybersecurity controls exist? Those questions remain important.
Agentic systems require another layer. What is the system actually authorized to do? What decisions can it make without approval? What systems can it access? What financial or contractual commitments can it create? When must it escalate to a human? Can its actions be reconstructed afterward? Who has authority to stop it?
And perhaps most importantly: Who inside the organization owns the consequences of its decisions?
Those are not merely technical questions. They are governance questions. Eventually, many will become litigation questions.
Autonomy Changes the Risk Calculation
There is a tendency to discuss AI risk as though smarter models simply create better versions of existing software. That misses the structural change.
The important threshold is not intelligence. It is agency.
A brilliant AI system that drafts a contract for a lawyer to review is still operating inside a familiar professional hierarchy.
An imperfect AI system authorized to send the contract, negotiate its provisions, execute downstream tasks, and communicate with third parties presents a different category of risk.
The first system produces work product. The second produces consequences.
That distinction should influence procurement, insurance, professional responsibility, contracting, cybersecurity, and corporate governance. It should also influence how lawyers think about their own technology.
Law firms adopting autonomous systems should not merely ask whether the AI is accurate. They should ask what happens when it is wrong.
The Most Important AI Policy May Be an Authority Policy
Every organization experimenting with AI agents should be able to answer a deceptively simple question: What is this machine allowed to decide without us?
The answer should not live solely inside a software configuration screen. It belongs in governance.
Some actions may require human approval. Others may require monetary thresholds. Certain communications may demand attorney review. Sensitive systems may require narrower permissions. High-consequence actions may need immutable audit trails.
The precise controls will differ by application. The principle will not.
Autonomy should be proportional to consequence.
That sounds obvious. So did many cybersecurity practices after the breach.
We Are Building the Precedents Now
The first generation of AI litigation largely concerned copyright, training data, hallucinations, discrimination, privacy, and disclosure. The next generation may increasingly concern conduct.
What did the AI do? Who authorized it? Who could have stopped it? Who benefited from its autonomy? Who should bear the loss when that autonomy caused harm?
Courts will eventually answer those questions through familiar doctrines and, where those doctrines prove inadequate, new ones. But businesses and lawyers should not wait for the case law.
Because the most dangerous assumption in the age of autonomous AI may turn out to be the simplest one: Nobody told it to do that.
In a world of genuinely agentic software, that may no longer be an answer. It may be the beginning of the liability analysis.
General educational information only. The allocation of liability depends on the facts, governing law, contracts, and jurisdiction.