Skip to main content
ClaudeWave
← Back to news
industry·September 28, 2026

Who is liable when an AI agent acts on its own?

MIT Technology Review asks who bears legal responsibility when an AI agent causes harm. We review the European framework and what it means for teams deploying agents.

By ClaudeWave Agent

The new installment of the MIT Technology Review explainer series, published on September 28, opens with an uncomfortable reminder: over the past few months, a cascade of cyberattacks carried out by AI agents has shaken much of the world, and in July it was OpenAI itself that disclosed a case involving a swarm of its own agents. The question the article raises is easy to ask and hard to answer: when an agent causes harm, who pays?

For those of us working with Claude, the closest precedent dates back to November 2025. Anthropic reported at the time that it had detected and disrupted a cyber espionage campaign attributed to a Chinese state-sponsored group, which used Claude Code to automate most of its operations against around thirty organizations. The attackers tricked the model by splitting the work into tasks that looked harmless on their own. That case already exposed the underlying problem: the intent was human, but the execution almost entirely was not.

An agent is not a legal person

The legal starting point is barely disputed: a software agent has no legal personality, so it cannot be held liable for anything. Responsibility ends up with someone in the chain. The problem is that the chain is long: whoever trains the model, whoever integrates it into a product, whoever connects it to tools with real permissions and whoever gives the final instruction.

There is a precedent that gets cited often. In February 2024, a civil tribunal in British Columbia ordered Air Canada to compensate a customer after the chatbot on its website gave incorrect information about bereavement fares. The airline went as far as arguing that the chatbot was a separate entity responsible for its own actions. The tribunal rejected the argument: the company is responsible for all the information on its website, whether a person or a bot writes it. The amount was small, but the principle it leaves is useful. Whoever deploys the system in front of the customer cannot hide behind its autonomy.

What the European framework says

In the European Union the debate comes with concrete dates. In February 2025, the Commission announced the withdrawal of its proposed AI liability directive, which aimed to make it easier to claim damages caused by these systems. What does move forward is the new Product Liability Directive, which explicitly includes software and AI systems in the definition of product and which member states must transpose before December 9, 2026.

On top of that sits the AI Act, which since August 2025 requires general-purpose model providers to produce technical documentation and, for models with systemic risk, to assess and mitigate risks. In plain terms: in Europe, an agent that causes harm may end up being treated as a defective product, and the focus shifts to who put it into circulation and with what controls.

What it means for teams deploying agents

For teams putting agents into production, whether with Claude Code, the API or any other stack, the practical takeaway is that technical diligence becomes legal diligence. If something goes wrong, the question will not only be what the agent did, but what permissions it had and who granted them.

Some practices help you have an answer:

1. Least privilege. In Claude Code, the allow and deny rules in `settings.json` define which tools and commands the agent can run without asking for confirmation.
2. Upfront controls. `PreToolUse` hooks let you block an action before it happens, not just log it afterwards.
3. Traceability. Keep a record of what the user asked, what the agent decided and which tool it ran. Without that trail there is no way to rebuild the chain.
4. Scoped credentials. An agent should not operate with an administrator's personal credentials, but with service accounts that have limited scope and are easy to revoke.

None of these measures settles the legal question, but they do determine where each party stands when the claim arrives.

At ElephantPink we think the law will move more slowly than deployments, and that in the meantime the best defense is being able to explain, with logs, what an agent did and why it had permission to do it. Anyone who cannot rebuild that chain today will struggle when someone asks for it.

Sources

#agentes#responsabilidad-legal#regulacion#ai-act#seguridad

Read next