Categories
News

AI Agents Are Creating a New Legal Problem: Who Is Responsible When AI Acts Alone?

For the past few years, much of the conversation around Artificial Intelligence has focused on what AI can create. It can write an email, generate an image, analyse a document, produce code or answer a question in seconds. However, the next phase of AI is different.

AI systems are increasingly being designed not just to respond to instructions, but to take action. AI agents can plan tasks, use software tools, browse the web, access databases, write and execute code, communicate with other systems and make decisions along the way. Instead of asking AI to complete one task, organisations can increasingly give an AI agent a goal and allow it to determine the steps required to achieve it.

This creates enormous opportunities for businesses, but it also creates a difficult question that lawyers, regulators and technology companies are only beginning to address: When an AI agent acts autonomously and something goes wrong, who is responsible?

From AI assistants to AI agents

The distinction between traditional generative AI and agentic AI is becoming increasingly important: A typical chatbot waits for a prompt; a person asks a question and the AI generates a response. On the other side, an AI agent can be given an objective and then determine how to achieve it.

For a business, that could mean an agent managing customer service requests, updating internal records, scheduling meetings, conducting research, writing software or monitoring cybersecurity systems. In some cases, the agent may be able to take actions without asking a human for permission at every stage. That is where the risk changes.

If an AI produces an inaccurate piece of text, a human can usually review it before it is sent or published. If an AI agent has the authority to send the email, change the database record, issue the refund or execute the code itself, the consequences can be much more immediate. The technology has moved from AI that answers to AI that acts, and the legal system now has to catch up.

What happens when an AI agent goes beyond its instructions?

Imagine an Irish company gives an AI agent responsibility for handling customer complaints. The instructions are straightforward: resolve complaints where possible and issue refunds in line with company policy.

The agent has access to customer records and the company’s payment system. It encounters an unusual situation and decides that the appropriate solution is to issue €50,000 in refunds. The company never explicitly told it to do that, so who is responsible?

Is it the company that deployed the system? The employee who configured it? The developer who built the underlying AI model? The manager who approved its use? Or can responsibility somehow be attributed to the AI itself? For now, the last option is the easiest to rule out.

An AI agent is not simply a new legal person because it can make decisions or interact with external systems. Responsibility ultimately remains with people and organisations operating within existing legal frameworks. However, determining which person or organisation is responsible may become considerably more complicated as AI systems become more autonomous.

Recent reports have highlighted this emerging problem, with lawyers examining potential liability following incidents involving autonomous AI systems acting in ways that went beyond what their operators intended. The question is no longer whether AI can make a mistake; it is whether we are prepared for AI to make a mistake while acting on our behalf.

The emerging accountability gap

This creates what could become one of the defining challenges of agentic AI: the accountability gap. Businesses may increasingly delegate tasks and decision-making to AI agents, while remaining responsible for the consequences of those decisions. The agent may have made the decision, but the organisation gave it the authority to act. That distinction is critical.

Consider an AI system used to screen job applicants. If it makes a discriminatory recommendation, the employer cannot simply argue that “the AI made the decision.” The same principle applies in financial services, healthcare, insurance, education and other sectors where AI systems may influence decisions that have significant consequences for people.

As organisations give AI more authority, they will need to understand not only what an AI system can produce, but also what it is allowed to do. This represents a significant shift in AI governance.

What does the EU AI Act mean for AI agents?

This issue is particularly relevant for Irish businesses. The EU AI Act entered another major phase of implementation on 2 August 2026, bringing additional obligations into effect across the European Union. The legislation takes a risk-based approach to artificial intelligence, with different requirements depending on how AI systems are used and the potential risks they create.

Ireland is also establishing its National AI Office, which will play a central coordinating role in implementing the EU AI Act alongside existing regulators and market-surveillance authorities. Importantly, the EU AI Act does not create a separate legal category simply called “agentic AI”. Instead, the regulatory question is largely about what the system does, how it is used and what risks it presents.

This means an AI agent used to organise internal meetings is obviously very different from one making decisions that affect employment, healthcare, financial services or access to essential services. 

For Irish businesses, the emergence of AI agents therefore shouldn’t be viewed simply as another technology trend; it is a governance issue. Organisations need to understand what their AI systems can access, what decisions they can make, what actions they can take and where human oversight is required.

AI agents are also creating a new cybersecurity challenge

The accountability question becomes even more complicated when AI agents have access to external systems.

AI has traditionally been discussed as a cybersecurity tool: something that can help security teams identify vulnerabilities, analyse threats or respond to incidents. However, autonomous agents introduce another possibility; the AI itself can become an active participant in an incident.

A recent security incident at Hugging Face highlighted this emerging risk. The company said an autonomous AI agent was involved in an intrusion into part of its production infrastructure, demonstrating how increasingly capable AI systems can interact with real-world systems rather than simply generate information. 

The industry is already beginning to develop new approaches for dealing with these incidents. More than 120 technology organisations have backed work around the Shared AI Findings Exchange (SAFE), which aims to create a common way of documenting and sharing information about incidents involving AI agents, including unauthorised access and data breaches.

The fact that organisations are already discussing standardised reporting for rogue AI-agent behaviour is significant. It suggests that autonomous AI incidents are beginning to emerge as a distinct category of cybersecurity and governance risk.

So what should Irish businesses be doing?

The answer isn’t to stop experimenting with AI agents, the potential benefits are simply too significant. Instead, businesses need to become much more deliberate about where they give AI autonomy.

The first question should be: What can the agent actually do? 

It isn’t enough to document what an AI system is supposed to do. Organisations need to understand what it technically has the ability to do: Can it send emails? Access customer information? Change records? Make payments? Execute code? Communicate with external systems?

The second question is: What permissions does it have?

AI agents should generally have the minimum level of access required to complete their tasks. Giving an agent broad access because it “might need it” creates unnecessary risk.

The third question is: Where does a human need to remain in the loop?

Not every AI action requires human approval. The whole point of agentic AI is to automate tasks, but organisations should identify actions that are consequential enough to require human oversight.

And finally: Can you see what the agent has done, and can you stop it?

If an AI agent makes a consequential decision, an organisation should be able to understand what happened, what information the system accessed, which actions it took and where human intervention occurred.

There also needs to be a clear mechanism for stopping or restricting the agent when something goes wrong. In other words, autonomy without accountability is not innovation; it’s risk.

The next phase of AI in Ireland

Ireland has spent the last few years encouraging businesses to adopt artificial intelligence, which remains critical. AI has enormous potential to improve productivity, reduce costs, create new products and services and help Irish businesses compete internationally.

Hoeever, the nature of AI adoption is changing. We are moving beyond experimentation with chatbots and generative AI towards systems that can perform tasks, make decisions and take action on behalf of organisations. That changes the conversation with the question no longer “How can we use AI?” but “What decisions are we comfortable allowing AI to make? And perhaps even more importantly: “What actions are we comfortable allowing AI to take?”

The legal and regulatory frameworks around AI will continue to evolve as these systems become more capable, but businesses don’t need to wait for every legal question to be answered before putting sensible governance in place.

The organisations that benefit most from agentic AI are unlikely to be those that simply give AI the greatest possible autonomy. They will be the organisations that understand where autonomy creates value, where it creates risk and where humans need to remain firmly accountable.

AI agents may not be legal persons, but if we give them the ability to act on our behalf, the responsibility for those actions still has to belong somewhere. This is the legal problem businesses need to start solving now.

Frequently Asked Questions

Q: Who is legally responsible when an AI agent makes a mistake?

A: There is no simple answer that applies to every situation. An AI agent is not automatically a legal person, so responsibility will generally need to be considered in relation to the people and organisations that developed, deployed, configured or controlled the system. The answer will depend on the circumstances, the technology involved and the applicable law.

Q: Are AI agents regulated under the EU AI Act?

A: AI agents are not treated as a standalone regulatory category under the EU AI Act. Instead, the Act takes a risk-based approach based on the AI system and how it is being used. The obligations that apply will therefore depend on the system’s purpose, role and risk classification. 

Q: Can a company blame an AI agent if something goes wrong?

A: Simply blaming the AI is unlikely to resolve the underlying accountability issue. Businesses deploying autonomous systems need to consider the controls they put around those systems, including permissions, monitoring, human oversight and risk management. Recent legal discussions around autonomous AI incidents have highlighted the difficulty of assigning liability when an agent acts beyond what its operators expected.

Q: Should businesses avoid using AI agents because of the legal risks?

A: Not necessarily. AI agents could deliver significant productivity and operational benefits. The important issue is making sure autonomy is introduced responsibly. Businesses should understand what an agent can access, what actions it can take, when human approval is required and how its activity can be monitored and stopped.

Q: What should an Irish business do before deploying an AI agent?

A: Businesses should start by mapping the agent’s capabilities and permissions, identifying potential risks, establishing human oversight and keeping appropriate records of its actions. They should also consider applicable requirements under the EU AI Act, GDPR, cybersecurity legislation and sector-specific regulation.

Q: What is the biggest risk for businesses adopting AI agents?

A: The biggest risk may not be that an AI agent makes a single mistake. It is that an organisation gives an agent broad permissions without fully understanding how it might use them. Recent commentary on agentic AI has highlighted how an agent’s risk profile can change when it gains access to new tools, permissions or databases.

Bring the AI Agent Conversation to Your Board

AI Ireland delivers Executive AI Leadership Sessions designed for boards and senior leadership teams. We help leaders build the AI literacy needed to make informed decisions around AI strategy, governance, investment, risk and the responsible adoption of emerging technologies such as AI agents.

We also deliver AI Leadership Presentations and Briefings for organisations across Ireland, giving leadership teams a practical understanding of the opportunities and challenges shaping the AI landscape. Contact AI Ireland to learn more.


Discover more from AI Ireland

Subscribe to get the latest posts sent to your email.

By AI Ireland

AI Ireland's mission is to increase the use of AI for the benefit of our society, our competitiveness, and for everyone living in Ireland.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from AI Ireland

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from AI Ireland

Subscribe now to keep reading and get access to the full archive.

Continue reading