Agentic AI goes beyond generating content or recommending actions: it can plan, make decisions, use tools and execute tasks with limited human intervention. That autonomy creates significant opportunities, but also raises a fundamental legal question: when an AI agent causes loss, who is responsible?
What is agentic AI?
Artificial intelligence, in its broadest sense, refers to software that performs tasks normally associated with human intelligence: recognising patterns, generating content, making predictions and recommending courses of action.
Agentic AI goes further. An agentic AI system can plan steps, make decisions, use tools and take actions to achieve a goal, sometimes with limited or no human intervention. It may combine large language model reasoning with deterministic tools such as APIs, database queries, code execution or transaction systems, breaking complex objectives into sub-tasks and adjusting its approach based on intermediate results.
Rewards and risks
Agentic AI can automate workflows across customer service, software development, financial analysis, decision-making and real-time execution. It can digest large amounts of information, plan multiple steps and act quickly. But things can (and do) go wrong. Agentic AI may misunderstand instructions, pursue the wrong objectives, hallucinate facts, call the wrong tool, exceed its permissions, disclose confidential data or execute a bad trade. The more powerful the agentic AI, the greater the potential harm. As a beloved comic book character famously said: “with great power comes great responsibility”. So, when a (powerful) agentic AI acts, who should be held responsible?
Legal personality and attribution
In most jurisdictions, a precondition for legal liability is legal personality. Only a recognised legal person (a natural person, a company or another entity recognised by law) can owe duties, be sued, pay damages or possess legally relevant intent. AI agents do not have independent legal personality. They cannot own property, enter contracts in their own right, or be held liable.
Therefore, liability for the acts of an AI agent must be attributed upstream to a recognised legal person. The difficult question is not simply whether someone should be liable, but which particular legal person(s) should bear responsibility: the programmer, the model developer, the end user, and/or the regulated institution that deployed the system?
What court cases tell us
Agentic AI is new and litigation can take years. Not surprisingly, therefore, there does not appear to be a single court case that is directly on point. However, several decisions across common law jurisdictions point in a general direction. Courts do not treat software or AI as an independent legal actor. They look through the system to the human or corporate actor that designed, deployed, authorised, used or benefited from it. Attribution becomes harder as systems become less deterministic and more autonomous, but the basic instinct of the common law is to identify the responsible legal person(s).
In Quoine Pte Ltd v B2C2 Ltd [2020] SGCA(I) 2, the Singapore Court of Appeal considered contracts formed autonomously through deterministic algorithmic trading software with no direct human involvement in the execution of individual trades. A failure in Quoine's systems ultimately led to trades being executed at approximately 250 times the prevailing market rate. The majority held that, for the purposes of analysing unilateral mistake in contracts formed by deterministic algorithms, the relevant state of mind was that of the programmer at the time the program was written. While instructive, this case concerned deterministic software and did not directly address liability or attribution issues arising from non-deterministic or agentic AI systems.
Thornton v Shoe Lane Parking Ltd [1971] 2 QB 163 confirmed, decades before modern AI, that contracts can be formed through automated machines. The legal relationship, however, remained between the car park operator and the customer, with the machine serving only as the mechanism through which offer and acceptance occurred. The case provides an early foundation for the modern view that, even where technology executes a transaction, legal rights and obligations generally attach to the human or corporate parties behind the system.
In Tyndaris SAM v MMWWVWM Ltd [2020] EWHC 778 (Comm), the English High Court considered procedural applications arising from a dispute concerning an AI-powered investment management strategy. The underlying claims were framed in contract and misrepresentation against the investment manager and its counterparty, rather than against the AI system itself. The proceedings therefore proceeded on the conventional basis that any legal rights and liabilities attached to the human and corporate actors behind the technology, not to the technology itself.
These cases, and many others like them around the world, do not provide a settled liability framework for agentic AI. But they do establish a general direction of travel: the law attaches consequences to legal persons around the technology, not to the technology itself. For modern agentic AI, where behaviour may be non-deterministic and outputs cannot be traced to a single line of code, new principles (or at least novel applications of existing principles) will likely be needed. The starting point, however, remains that liability is imposed on people and institutions, not machines.
Liability standard
Once responsibility is attributed to one or more legal persons, a separate question arises: what standard of liability applies? Possible standards range from strict liability, negligence and recklessness to knowing or intentional wrongdoing.
In May 2026, Singapore's Infocomm Media Development Authority (a statutory board under Singapore's Ministry of Digital Development and Information) published a discussion paper on legal responsibility for AI agents, consolidating views from government, academia, private practice and industry. It did not reach firm conclusions but identified some key issues. In July 2026, the UK Jurisdiction Taskforce (UKJT) published a non-binding legal statement on liability for AI harms under the private law of England and Wales. Prepared by a group of leading practitioners and academics following a public consultation process, the statement seeks to provide greater legal certainty and predictability regarding civil liability for AI-related harms under English law in an area where relatively few cases have reached the courts. Unlike Singapore's 2026 discussion paper, the UKJT statement addresses AI liability more broadly rather than focusing specifically on agentic AI, although much of its analysis can be applied in the agentic AI context.
Both the Singapore paper and the UKJT statement found that existing legal frameworks (particularly the law of contract and negligence) may address many agentic AI-related scenarios but need adaptation. Contract is an important starting point in the legal analysis because the AI supply chain is often connected by a web of legal agreements. The freedom of contract principle generally means that one party can voluntarily agree to be liable for an AI agent’s actions and omissions, and the scope of liability can be adjusted through warranties, indemnities and limitation clauses. But contract is less useful in the case of third-party victims who lack privity.
Where there is no applicable contract, the Singapore paper and the UKJT statement discussed turning to the law of negligence to determine liability for harm caused by AI. To recover damages for negligence, a claimant generally needs to show that another legal person owed them a duty of care, failed to act with reasonable care, and that this failure foreseeably caused loss. Yet, negligence may present difficulties in the context of agentic AI. Proving breach, causation and foreseeability may be difficult when an autonomous, non-deterministic system produces outputs that cannot easily be reverse-engineered. After all, what constitutes reasonable care in respect of a system whose behaviour the deployer cannot really predict?
Strict liability was discussed in the Singapore paper as one possible policy response, drawing on analogies to dangerous activities and Rylands v Fletcher, which established, over 150 years ago, that strict liability may apply when a person brings onto their land, in the course of a non-natural use of that land, something likely to do mischief if it escapes, and it does escape and causes damage. Some consider strict liability useful for victim compensation and certainty. But others worry it could deter agentic AI deployment and would treat careful and careless actors alike.
Vicarious liability and agency-based theories of liability are constrained because AI agents are not legal persons. As explained in the UKJT statement, traditional doctrines of vicarious liability are difficult to apply directly to AI systems, although an employer may still be vicariously liable where harm results from a human employee's use of AI in the course of employment.
Some commentators analogise agentic AI to animal liability. In common law jurisdictions, liability for domesticated animals typically requires fault or knowledge of dangerous propensity, while strict liability may apply to wild animals because the keeper has introduced an inherently unpredictable risk into the community. A low-risk, predictable AI tool might be analogous to a domesticated animal, while a highly autonomous agentic AI system with broad real-world permissions might be closer to something more powerful and dangerous.
Ultimately, the debate is not only about who should be liable when agentic AI causes harm, but where the law should allocate responsibility on the spectrum between fault-based and strict liability in a manner that both promotes innovation and ensures adequate protection for those who suffer loss.
In the European Union, Article 101 of the EU AI Act should be taken into consideration: from 2 August 2026, the European Commission may impose fines on providers of general-purpose AI models of up to 3 per cent of their total worldwide annual turnover or €15 million, whichever is higher. This requires a breach of their obligations under the EU AI Act. Those obligations include the management of systemic risks and cybersecurity risks (Article 55 of the EU AI Act). Even though AI agents are not explicitly regulated, AI agents fall under the scope of the EU AI Act and some may well be considered high-risk AI systems.
Additionally, the EU Product Liability Directive 2024/2853, which entered into force on 8 December 2024 and must be transposed into EU member state law by 9 December 2026, extends liability to software and AI systems and introduces strict liability rules for damage caused by defective digital products. The Directive modernises product liability law for the digital age. Software, AI systems and digital services are now expressly treated as products, regardless of whether they are stand-alone products or integrated into hardware. Free software may also give rise to liability. Liability is strict: manufacturers are liable where a product is defective and causes damage, without the claimant having to prove fault. Developers of agentic AI systems placed on the EU market after 9 December 2026 will need to prepare for stricter liability standards under the new regime.
Regulated financial institutions
Financial institutions have natural synergies with AI. They handle vast quantities of market data, client information and documentation. Robo-advisers existed before agentic AI, but agentic AI raises the stakes: an AI agent might not only recommend a course of action but directly implement it, placing orders, switching portfolios, drawing down loans, making payments or communicating binding instructions to counterparties.
General contract and tort law theories of responsibility and liability, as they evolve over time to account for agentic AI, would of course equally apply to financial institutions. But since financial institutions are highly regulated, the regulatory dimension and supervisory expectations are also relevant to the question of accountability.
The overarching principle across jurisdictions is that regulated financial institutions remain responsible for AI deployment. Guidance from international standard-setting bodies such as the International Organization of Securities Commissions increasingly emphasises that boards and senior management retain ultimate responsibility for the governance, oversight and risk management of AI systems, particularly where those systems are used in high-risk or customer-facing activities.
Hong Kong provides a useful example of how these international principles are translated into local supervisory expectations. The Hong Kong Monetary Authority has expressly stated that where AI applications make automated decisions on behalf of banks, “[t]he board and senior management of banks should appreciate that they remain accountable for all AI-driven decisions” and should ensure appropriate governance and risk management frameworks are in place. The Securities and Futures Commission of Hong Kong has similarly stressed that senior management of licensed corporations remains responsible for ensuring appropriate governance and oversight of AI systems used in regulated activities. The regulator notes that senior management responsibilities may extend across the AI lifecycle, including model development, validation, approval, ongoing review and monitoring.
Accordingly, while the precise contours of private law liability for agentic AI are still evolving, financial regulatory and supervisory expectations are becoming clearer: if an AI agent operating within a financial institution causes harm, regulators are likely to look first to the institution's board, senior management and governance framework, rather than to the technology itself, when determining where accountability should lie. But of course, liability and accountability are not the same thing and should not be conflated. Regulatory accountability may inform, but may not necessarily determine, where legal liability ultimately falls.
Conclusions
No comprehensive liability regime yet exists for agentic AI, and there remains no firm consensus on what the standard of liability should be. It is early days. In common law jurisdictions, absent statutory intervention, courts will develop principles over time on a case-by-case basis.
The question of who should be liable and when involves trade-offs and policy choices. A liability regime should not be so restrictive that it prevents society from benefiting from genuinely useful technology or stifles innovation. Deterring innovation at this stage of AI development would be especially unfortunate because, ironically, it may slow the very improvements that reduce the occurrence of errors and mistakes for which legal liability needs to be pursued in the first place. Therefore, the law must strike a balance that incentivises responsible deployment, rewards proportionate safeguards, and ensures that those harmed have realistic avenues of redress.
There are grounds for cautious optimism. The common law has adapted before, and it will do so again. The advent of trains in the nineteenth century helped shape modern tort principles of foreseeability and reasonable care. Mass manufacturing gave rise to product liability, epitomised by Donoghue v Stevenson. In each instance, new technology created new risks and the law eventually found workable principles. The law on agentic AI is likely to follow a similar path, although the pace of legal development may need to move faster than the snail in Mrs Donoghue’s ginger beer bottle nearly a century ago.