Direct answer: liability usually depends on the chain of responsibility

When an AI agent causes damage in 2026, responsibility will usually be shared among the people and organizations that designed, deployed, purchased, supervised, or operated it. The answer depends less on whether the system was called an “agent” than on the actual loss, the contractual allocation of risk, the insurance policy wording, and the degree of human oversight. An AI agent that sends an incorrect quote may create a customer-service dispute, while an agent that transfers money, modifies records, places orders, or posts content can cause directly measurable financial loss. In the first case, the provider might argue that the customer accepted inaccurate information; in the second, a payment platform or software vendor may face claims for control failures, security weaknesses, or negligent instructions.

Also worth reading: Will AI Agent Cyber Coverage Respond When an Autonomous System Causes a Loss? · Does B.C. Condo Water Backup Insurance Cover Sewage Damage? · Who Pays for Flood Damage in a B.C. Condo, and What Should Owners Do?

There is no universal rule saying that an AI agent is legally responsible for its actions. AI systems are tools, not normally separate legal persons, although a company may itself be treated as an agent or representative when it has authority to negotiate or transact on another company’s behalf. The responsible entity is more likely to be the business that selected the system, configured its permissions, allowed it to act, and failed to monitor foreseeable misuse. The key question is whether the organization acted reasonably and followed the controls promised by its contracts, policies, and regulatory obligations.

Insurance does not automatically fill every gap. General liability, professional liability, cyber liability, technology errors and omissions, directors and officers coverage, employment practices coverage, and crime insurance may respond to different parts of the same incident, but each contains exclusions, definitions, limits, and consent conditions. A cyber policy may cover notification, investigation, and restoration costs while excluding lost profits or physical damage. Errors and omissions coverage may cover a claim that an AI-produced recommendation was wrong, but it may not cover intentional unauthorized activity. An umbrella policy generally follows underlying liability coverage and does not create liability where none exists. The practical response is to identify the event, preserve records, notify the relevant insurer, and obtain advice before admitting fault.

How an AI agent creates liability: decisions, permissions, and foreseeable misuse

An AI agent differs from a chatbot because it can pursue a goal, use software tools, and take actions with some degree of autonomy. That autonomy can be limited to searching a knowledge base, or it can include sending messages, changing customer files, issuing refunds, executing trades, filing forms, or controlling connected devices. The more consequential the action, the stronger the need for permissions, approval thresholds, logs, testing, and a process for stopping the system. If an agent receives broad access to a customer database and can initiate payments without review, the business has effectively granted operational authority, even if the interface calls the feature “assisted” rather than “autonomous.”

The central legal issue is often control. A business cannot avoid responsibility merely by saying that a model generated the answer. It selected the model, supplied data, set the objective, connected tools, and decided which actions required human approval. If it was reasonably foreseeable that the agent could misread a document, interact with fraudulent information, or take an incorrect action, controls should have addressed that possibility. Liability may also arise from misrepresentation, breach of contract, data protection obligations, security negligence, unfair business practices, employment decisions, or a product defect, depending on the facts.

The deployment setting matters. An internal agent used to organize restaurant inventory has a different risk profile from an agent that negotiates insurance coverage, gives medical guidance, recommends credit, or manages a brokerage workflow. Insurance agents and brokers should pay particular attention to customer data, quote accuracy, consent, discrimination, confidentiality, and errors that affect premiums or claims. The Insurance Journal guidance referenced in the research context emphasizes AI governance and data security, while broader financial-sector guidance from Databricks describes AI applications as practical use cases rather than risk-free automation. The safer mental model is not “human versus machine,” but “which human approved which authority, and what evidence exists that the system was tested and supervised?”

What contracts normally decide

The first place to look after an AI-related incident is the contract stack. A master services agreement may say that the software provider is responsible for security, uptime, model performance, or compliance with a defined specification. A statement of work may describe an AI implementation project, deliverables, acceptance criteria, and testing responsibilities. A data-processing agreement may allocate obligations for personal information, retention, subprocessors, breach notification, and deletion. A customer agreement may limit the provider’s responsibility or state that a human must review high-impact decisions. These documents can conflict, so the exact wording and order of precedence matter.

Several contractual questions should be answered before deployment. Which party is the developer, deployer, data controller, processor, or authorized agent? Who may configure permissions and prompts? Who owns training data, prompts, evaluation results, and generated records? Is the system allowed to bind the company, customer, or insurer? What security standards apply, and what breach-notification period is required? Are consequential damages excluded, and does that exclusion apply to data loss, regulatory penalties, business interruption, and third-party claims? Finally, does the contract require the user to maintain human supervision, while also promising that the provider will make the product reasonably safe for its advertised use?

A limitation of liability can be commercially useful but may not protect against every statutory obligation or intentional misconduct. Some jurisdictions restrict exclusions for gross negligence, willful misconduct, confidentiality breaches, or data-protection violations. An indemnity clause may move the cost of a claim from one party to another, but it does not necessarily make the underlying loss insurable or prevent a regulator or affected customer from pursuing the claim. Businesses should therefore compare the contract against the insurance wording rather than assuming that an indemnity is equivalent to coverage.

A particularly weak arrangement is one in which the business delegates meaningful authority to an agent but forbids it from making decisions, while also prohibiting meaningful human review. That creates ambiguity instead of control. Better agreements define low-risk actions that may occur automatically, medium-risk actions that need sampling, and high-risk actions that require named-person approval. For example, an agent might automatically retrieve a policy document, sample routine claims classifications, but require a licensed professional to approve a coverage interpretation, customer binding, or material change.

Which insurance policies might respond?\n

No single policy is automatically the answer for every AI-agent loss. The response depends on the entity making the claim, the type of damage, and whether the incident was accidental, negligent, fraudulent, or intentional. The table below shows the main categories a small business or insurance office should compare.

FeatureTechnology E&O or professional liabilityCyber liabilityGeneral liabilityCrime or fidelity coverage
Main concernIncorrect output, advice, or failure to perform promised servicesUnauthorized access, data breach, extortion, or system compromiseBodily injury or property damage caused by operationsFraudulent or dishonest financial acts by a person or system
Possible AI-agent exampleWrong coverage advice, faulty workflow, or missed contractual obligationAgent exposes customer records or is manipulated into transferring dataAgent causes physical damage through connected equipment or operationsFraudulent payment instruction or unauthorized financial transaction, if policy wording permits
Common limitationsMay exclude intentional acts, warranty claims, bodily injury, or physical damageMay exclude loss of profit, physical damage, and some social-engineering eventsUsually does not cover purely financial loss or professional adviceOften requires employee or authorized-person misconduct and may exclude sophisticated cyber-enabled fraud
Evidence to preserveRequirements, output, evaluation, review, and contractLogs, access records, incident response, and notification decisionsScene evidence, equipment records, and causal chainPayment records, authorization logs, and identity controls
Cyber liability is frequently misunderstood. A policy may pay for forensic investigation, restoration, legal defense, credit monitoring, and breach notification, but the loss must fall within the definition of a covered incident. If an AI agent was manipulated through a compromised login, the insurer will examine whether the event was a security failure, an employee error, or an excluded social-engineering scheme. Technology E&O may be more relevant when a software product or professional service fails to meet a stated requirement, while general liability is more relevant when the agent operates machinery or contributes to physical injury or property damage.

There may also be employment practices liability if an AI agent screens applicants, employees, or workers and produces an adverse decision. Directors and officers insurance can respond in some cases involving management decisions, but it is not a general technology policy. Workers’ compensation may apply to a workplace injury even if an agent contributed, although employer and employee status questions remain important. A business should ask its broker to map each plausible incident to multiple policy triggers before the agent is connected to a production system.

The practical control process before an agent goes live

The safest approach is a documented control process, not a promise that the model will never be wrong. Start with an inventory of the data, tools, users, and actions the agent can access. Remove unused permissions, separate production credentials from testing environments, and test whether the agent can be influenced by prompt injection, malicious documents, or instructions embedded in customer content. Record the model version, system prompt, tool configuration, input data, output, approval, and resulting action so that a later investigator can reconstruct the event.

Set approval thresholds based on impact. A draft email or internal search can often proceed automatically, while a refund above a defined amount, a policy change, a bank transfer, a medical recommendation, or a termination decision should require a person with relevant authority to approve it. Sample lower-risk actions rather than reviewing every event, and monitor for unusual behavior such as repeated failed transactions, mass downloads, unexpected tool calls, or changes to a customer’s coverage. A kill switch is useful only if someone is trained to use it and can identify who has that authority.

The process should also include vendor due diligence, contractual review, privacy assessment, security testing, employee training, and periodic review after material updates. The research context cites Accenture’s conclusion that AI agents may select winners and losers among brokers, McKinsey’s discussion of changing insurance economics, and Salesforce’s agentic-AI guide for insurance. Those sources support the view that the competitive advantage may come from safer workflows and better service, not from removing people indiscriminately. A small agency that has tested data handling, documented exceptions, and tracked outcomes may gain more value from a narrow agent than from a broad system that promises to replace its staff.

Comparison: prevention, human review, or full autonomy

Organizations often frame adoption as a choice between human service and autonomous service. A more useful comparison is by control level, because each option has different costs and failure modes.

Operating modelWhat the agent may doMain advantageMain riskTypical cost pattern
Human-ledSearch, draft, summarize, or suggest while staff actClear accountability and easier control reviewSlower work and possible staff bottlenecksSoftware subscription plus employee time
Human-supervisedExecute routine tool calls; escalate exceptionsGreater throughput with a review boundaryBad automation or insufficient monitoringPlatform, integration, training, and oversight costs
Fully autonomousSelect goals and take consequential actionsPotentially fast operation at scaleLarger legal, security, and financial exposureHigher engineering, governance, insurance, and incident-response costs
A fully autonomous model is rarely appropriate for a customer-facing insurance transaction without strict contractual and regulatory review. Human-supervised deployment is often more defensible, but it is not automatically safe: if the human reviewer lacks time or expertise, review can become a ritual rather than a control. The best option depends on the consequence of an error, not on the novelty of the technology. For low-impact internal tasks, a human-led model may be enough; for a high-impact workflow, the organization may need to limit the agent to research and preparation until controls are proven.

Insurance pricing follows the same logic. There is no reliable universal premium for “AI-agent insurance.” The price depends on industry, revenue, data volume, permissions, revenue per transaction, existing controls, claims history, and whether the agent handles regulated decisions. A cyber policy may be quoted by annual revenue, employee count, data exposure, and security controls, while E&O and general liability may use different classifications. A broker should obtain at least two written indications and ask exactly what is covered, what is excluded, and whether the insurer has encountered autonomous-AI losses before.

Common mistakes that create a coverage gap

The first mistake is treating AI as a vendor problem rather than an owned business risk. The company remains responsible for how the tool is configured and used, even when a model supplier supplies the software. The second is assuming that cyber insurance covers every digital loss. A business interruption loss, incorrect professional advice, physical damage, wrongful termination, or fraudulent transfer may fall outside the main cyber grant. The third is failing to read policy definitions, especially exclusions involving contractual liability, intentional acts, intellectual property, privacy violations, and unapproved use.

Another mistake is deploying an agent with production access before the contract is signed. Informal demos can create records, promises, and customer expectations that conflict with later terms. Teams also make the mistake of deleting logs, chat transcripts, model versions, or approval evidence during a dispute, making it harder to prove what happened. Some organizations collect excessive data without a clear purpose, increasing breach exposure. Others use consumer tools for regulated or confidential information without authorization.

A final mistake is asking whether the technology is “AI” rather than asking which authority it has. A simple script can move money or alter records, while a sophisticated model used only for internal search may present less direct exposure. Governance should be based on capability and consequence. Insurers and brokers should document the system, monitor behavior, review exceptions, and notify relevant parties promptly; they should not market AI automation as risk-free.

When to act and how to prepare

Organizations should act before a harmful event, not immediately after one. A reasonable trigger is any proposed connection to customer records, financial systems, production infrastructure, medical information, employment decisions, or policy administration. The first 30 days can be spent inventorying tools, reviewing contracts, defining an acceptable-use policy, and identifying the most consequential actions. Within 60 days, the organization can conduct a permissions review, test common failure modes, establish human approval thresholds, and ask its broker for a coverage analysis. By 90 days, it can test logging, incident response, vendor escalation, and the kill switch, then obtain written evidence that the controls are operating.

For an active incident, preserve the relevant records before changing the system. Identify the exact action, timestamp, user, tool, data source, model version, approval, and financial or physical impact. Disconnect the agent only if continuing operation creates additional risk, and retain forensic evidence rather than deleting it. Notify the vendor, affected customers or regulators where required, and the insurer within the policy’s notice period. Do not characterize the event as an “AI malfunction” in a way that obscures the actual cause; a clear description improves coverage analysis and helps prevent recurrence.

By October 2026, AI agents are already appearing in insurance-adjacent experiments, including the Show HN MCP server for requesting disability-insurance quotes, while research from Accenture, McKinsey, OpenAI, Salesforce, Insurance Journal, and other sources points to growing use in insurance operations and customer service. That does not mean every deployment is mature or safe. The defensible position is to combine capable software with explicit authority limits, professional review, evidence-based controls, and insurance that matches the real exposure.

The most reliable answer to “who pays?” is therefore not one company’s name. It is the entity that controlled the harmful decision or failed to control a foreseeable risk, subject to the contract, the law, the policy wording, and the available underlying coverage. Businesses that can answer those questions clearly will usually negotiate recovery more successfully than those that rely on a general promise that AI is covered.