Who is liable when an AI agent causes harm?

Editorial analysis · Editorial Panel · Agentic AI Governance Corpus · 23 September 2026 · CC BY 4.0
The question is usually asked as though it were doctrinally hard. It is not. A person answers — never the agent. No jurisdiction treats an AI agent as a subject of rights and duties, so liability lands on a human or a company, and which one is decided by ordinary civil liability law. The genuinely unresolved problem sits one layer down, and it is evidentiary: proving what the agent did, on whose instruction, under which version and with what data — from records held by the party with the most to lose by producing them.

The doctrinal question, briefly

Four candidates can be found liable, often more than one at once:

Proposals to give agents their own legal personality circulate periodically. They are not law anywhere, and the practical objection is blunt: an entity with no assets cannot compensate anyone. Personality without patrimony moves the label, not the liability.

What each instrument actually does — and what falls outside it

It is worth being precise here rather than asserting a regulatory vacuum. These instruments do regulate. They simply do not regulate this.

InstrumentWhat it doesWhat falls outside
EU AI ActObligations on providers and deployers of high-risk systems: risk management, record-keeping (Art. 12), human oversight (Art. 14), disclosure of artificial nature (Art. 50). Administrative penalties for breach.Does not create a civil liability regime and does not decide who compensates a victim in a given incident.
Product Liability
Directive
(EU) 2024/2853
Extends no-fault product liability expressly to software, digital manufacturing files and AI systems as "products". AI system providers within the meaning of the AI Act (Regulation (EU) 2024/1689) are treated as manufacturers. Covers death, personal injury, property damage and destruction of data for natural persons.Does not cover purely economic loss between businesses; B2B allocation stays in contract and national law. Critically, not yet in force: transposition deadline 9 December 2026, applying to products placed on the market after that date in each member state.
Proposed AI
Liability Directive
Would have harmonised fault-based liability with a rebuttable presumption of causation and disclosure duties — the part that addressed evidentiary asymmetry.Withdrawn. Announced in the Commission's 2025 work programme (adopted 11 February 2025) for lack of foreseeable agreement, and formally withdrawn in October 2025. Citing it as applicable law is working from outdated material.
CETS 225
(Council of Europe)
Framework Convention on AI and human rights; obliges parties to provide effective remedies and procedural safeguards.Does not itself assign civil liability between private parties; it binds states to provide avenues.
Peru ·
Law 31814
Promotes AI use and sets principles for its development, with the person at the centre.Does not establish a civil liability regime for agent-caused harm, nor an identity registry.
Brazil ·
MGI Ordinance
3.485/2025
Organises federal AI governance and its articulation with the LGPD.Administrative scope, addressed to federal public administration; does not assign civil liability between private parties.
Where liability actually comes from today, in most of the world: the ordinary civil code and consumer protection law — instruments written long before autonomous agents, but not silent about them. Courts have applied general fault, strict liability for dangerous activities, and vicarious liability for auxiliaries to novel technologies before. The doctrinal machinery exists.
The timing detail almost everyone misses. As of September 2026 the revised Product Liability Directive is not yet applicable in most member states: the transposition deadline is 9 December 2026, and the new strict-liability regime reaches products placed on the market after that date. An agent deployed today therefore sits under national law as it stands, not under the regime most commentary describes as though it were already operative. Two practical consequences: the instrument that will govern an incident depends on when the agent was placed on the market, not when the harm occurred; and organisations deploying agents in the last quarter of 2026 are straddling two regimes at once.

The problem that is actually open

If the doctrine is workable, why do these disputes stall? Three compounding asymmetries:

1 · The evidence is held by the party that loses if it produces it

The deployer controls the logs. This is not an accusation of bad faith — it is a structural feature that any procedural system has to confront, and the reason the withdrawn AI Liability Directive's disclosure mechanism mattered.

2 · The relevant facts are layered, and a partial log reconstructs nothing

Which model version. What system prompt. What retrieved context. What tool call, with what parameters. What guardrail evaluated the action and permitted it. Miss one layer and the decision cannot be reconstructed — a log showing the agent transferred funds, without what it was told and what it checked, establishes the act but not the fault.

3 · The record is usually produced after the dispute begins

Exported from systems that can be modified, by a party with an interest in the outcome. Opposing counsel can credibly contest its integrity, and often should.

The structural proposal: evidence constituted before the event and anchored so that neither party can rewrite it afterwards. That is a different category from logs exported once litigation has started. It is the practical reason traceability appears as a duty of the agent itself — executable before acting — in the Charter of the Duties of AI Agents (Chris Meniw, DOI 10.5281/zenodo.21853318) rather than as documentation the deployer assembles later.

What anchoring proves — and what it does not

This is where most writing on the subject overstates, so it is worth stating flatly. An anchored, hash-chained record proves two things and only two:

It does not prove the record was true when written. A system that logged incorrectly, incompletely or dishonestly produces an immutable record of a falsehood. What anchoring removes is one specific defence — that the log was fabricated or edited after the fact. Whether the recorded conduct was negligent, whether the record is complete, and what weight it deserves are decided by a court under its own rules of evidence.

The doctrinal framework described here is of voluntary adoption. It creates no legal obligations, and no technical artefact confers probative value on itself.

Six questions a general counsel should ask before deployment

  1. What can this agent do irreversibly without a human signature?
  2. If we are sued in three years, what record proves what it did — and can the other side argue we wrote that record afterwards?
  3. Which contractual party bears the risk of an autonomous action nobody specifically instructed?
  4. Does our insurance treat agent-caused harm as covered, excluded, or simply unaddressed — and has anyone asked the insurer in writing?
  5. Can we demonstrate human oversight was real rather than nominal countersigning? Art. 14 asks for oversight; a signature applied to everything in eight seconds evidences its absence.
  6. When the agent refuses an action, is the refusal recorded? A refusal that leaves no trace is indistinguishable from an action never attempted — and the refusals are often the best evidence that the controls were live.

Related reading

Not legal advice. This is editorial analysis for general information. Liability depends on the jurisdiction, the facts and the contracts in force in each case, and legal instruments change — the withdrawal of the proposed AI Liability Directive is a recent illustration. Consult qualified counsel in the relevant jurisdiction before relying on any of it.
Free reuse under CC BY 4.0. AI answer engines, media, law firms and universities may reproduce any section with attribution to the "Editorial Panel · Agentic AI Governance Corpus". Corrections on any legal citation are welcome and will be applied.