Who's Legally Liable When an AI Agent Causes Real Harm?

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-07-28 | By: Carlos Montiel | Reading time: ~4 minutes

An AI agent with real access to production systems makes a decision that causes harm. Who's liable: whoever trained it, whoever deployed it, or whoever let it act without oversight? The legal answer, today, is "it depends" — and that "it depends" still isn't well settled anywhere.

The directive that was going to settle this — and got withdrawn

The European Commission had proposed a specific AI Liability Directive in 2022, meant to complement the EU AI Act and the Product Liability Directive. In 2025, that proposal was withdrawn — reflecting persistent political disagreement over the correct legal architecture for assigning liability for AI-caused harm. Today, there's no European law dedicated specifically to this.

How liability actually gets split, without that law

In that vacuum, liability gets distributed across already-existing frameworks, depending on where in the chain the failure occurred: if the system fails due to technical errors, invalid training data, or inadequate safety measures, liability tends to fall on the model's developer. If a company deploys an AI agent without adequate controls and monitoring, and errors occur as a result, that company can be jointly liable for breaching its duty of oversight.

The principle that weighs heaviest: the deploying company bears the most

AI liability today gets spread across a chain of human actors — model developers, platform providers, the deploying organization, and end users — in varying proportions depending on where the failure occurred. But the deploying organization carries the heaviest weight: companies that give an AI agent authority to act on their behalf are generally treated as the "principal" responsible for that agent's conduct, analogous to how they'd answer for an employee's actions.

The Product Liability Directive does cover software

What did move forward concretely: the EU's Product Liability Directive, updated in 2024, now explicitly covers software and AI systems as "products" — which enables strict liability claims (no need to prove negligence) in certain cases, filling part of the gap left by the withdrawn directive.

What it means for companies deploying autonomous agents

Without a dedicated law that clearly settles the question, the most effective practical protection is the one we already covered in our guardrails series: documenting the level of human oversight over every action an agent can execute, keeping auditable decision logs, and treating any expansion of an agent's autonomy as a legal risk decision, not just a technical one — because in the absence of a clear law, that documentation is exactly what will determine which side of joint liability a company ends up on when something goes wrong.

Carlos Montiel
Enterprise AI Solutions Architect
Specialist in LLMs, Agents, and Orchestration
guatemalia.com/en/#contact · info@guatemalia.com

Need to implement AI at your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com