Why Agentic AI Breaks Traditional Liability Assumptions

Agentic AI systems differ from earlier generative or analytical tools because they act on a user's behalf with limited human supervision, choosing sub-tasks, executing multi-step plans, and committing transactions or messaging third parties without a real-time operator clicking "approve." That autonomy is exactly what makes them commercially attractive — and exactly what scrambles the usual contract liability rules. If a procurement bot negotiates a price outside a negotiated range, or an autonomous workflow remits a wire transfer to a fraudulent counterparty, the question "who pays?" has no obvious answer under standard master service agreements drafted before 2023.

Also worth reading: What is autonomous software risk management and how do organizations legally mitigate it? · What are the most effective autonomous software liability mitigation strategies for enterprises deploying agentic AI? · What are the current agentic legal system governance standards for autonomous AI in professional practice?

Under common law and U.S. commercial code principles, a principal is generally bound by acts of an agent acting with actual or apparent authority. But courts have spent decades defining "agent" in human terms, and most agency statutes were enacted before a non-human entity could plausibly claim to exercise judgment. As Mayer Brown and Clifford Chance have both noted in 2025 advisories, this produces a documented "liability gap" — situations where the harm is real, the cause is identifiable, yet no party has a clean contractual or statutory path to be held accountable. The gap is widest when the agent's decision deviates from the operator's instructions but still falls within the system's design parameters.

For practical purposes, liability for an AI agent's conduct tends to land first on the entity that deployed it, because that party selected the model, set the autonomy threshold, and profited from the action. The vendor that built and trained the model is the second-tier target, followed by the data or tool provider whose integration failed. Whether the deploying party can push the loss upstream depends almost entirely on what its contract says.

The Five Buckets of Liability a Contract Should Address

Lawyers at Clifford Chance, Mayer Brown, and Foley & Lardner have converged on a similar taxonomy of exposure that any implementation contract should map. First, tort and negligence exposure — a customer sues the deploying enterprise for harm caused by a bad AI decision. Second, contractual liability to third parties — the AI's autonomous action creates a binding commitment to a counterparty that the enterprise must honor or pay damages for breaching. Third, regulatory and statutory fines, including sector-specific penalties under financial services, healthcare (HIPAA), consumer protection, and emerging AI statutes. Fourth, data protection and privacy violations, especially under GDPR Articles 5 and 22, which restrict solely-automated decisions with legal effects on EU data subjects. Fifth, intellectual property infringement, where an agent's autonomous output reproduces protected text, code, or imagery.

Each bucket calls for a different drafting technique. Indemnities work well for third-party claims. Caps and insurance schedules handle catastrophic exposure. Representations and warranties are useful for design defects, but largely useless for autonomous conduct that was not a defect at design time. Service-level agreements can describe expected accuracy, but rarely serve as a basis for liability once the system is operating within agreed parameters yet still causes loss.

The mistake many legal teams make is to copy a SaaS agreement and add a one-line "AI addendum." That approach fails because SaaS liability usually presumes a human user makes the consequential decision, with the software supplying information. The reverse is true for agentic systems.

Standard Contract Clauses That Need Rewriting

Three clauses in the typical enterprise technology agreement carry the heaviest weight when an AI agent acts autonomously. The first is the limitation of liability. A standard 12-month fee cap is almost always inadequate for an agent that can transact at machine speed across thousands of decisions per day. Sophisticated buyers now negotiate either a higher cap (often 3x annual fees), a separate AI-specific cap, or a per-incident basket uncapped for certain categories such as data breach, willful misconduct, or third-party IP infringement. Vendors push back, but the size of recent enterprise deals has given buyers meaningful leverage.

The second is indemnification scope. Most contracts indemnify against third-party IP claims and confidentiality breaches, but rarely against losses caused by the AI's autonomous decisions. The 2025 Bloomberg Law analysis of enterprise deals found that fewer than one in three contracts contained an indemnity covering an agent's unintended actions. Buyers should request a specific indemnity for "unintended autonomous actions," defining the term precisely so it does not swallow ordinary software bugs.

The third is the warranty. Traditional warranties say the product conforms to documentation. For agentic systems, that warranty is functionally meaningless because documentation cannot enumerate every action. Instead, agreements increasingly include a behavioral warranty: the system will operate within defined guardrails, will not exceed stated authority thresholds, and will log actions to an audit-grade standard. The enforceability of behavioral warranties is untested, but their inclusion shifts the conversation at the negotiating table and creates evidence of risk allocation.

ClauseStandard SaaS TreatmentAgentic AI Best Practice
Liability cap12 months of fees3x annual fees or AI-specific carve-outs
Indemnity scopeIP infringement, confidentialityAdd "unintended autonomous action" indemnity
WarrantyConformance to documentationBehavioral warranty within guardrails
Audit rightsAnnual financial auditReal-time action logs, decision-trace access
Insurance$5–10M general liability$25M+ tech E&O plus cyber coverage
TerminationConvenience + material breachAdd "loss of autonomy control" trigger
## The Vendor's Side: Disclaimers and Risk Shifting

Vendor-side counsel has responded with an expanding set of risk-shifting mechanisms that buyers must read carefully. Output disclaimers — language stating that AI outputs are not professional advice — are now standard, but their enforceability varies by jurisdiction. Some U.S. courts have treated them as meaningful; others, particularly in consumer-facing cases, have voided similar language as unconscionable.

A more aggressive vendor technique is the "no agency" clause, asserting that the AI is a tool rather than an agent and that the customer bears all responsibility for actions taken through the tool. This is commercially convenient for vendors but legally questionable under agency doctrine, where actual authority is determined by the principal's manifestations to third parties, not by private recitals. In a dispute with an end customer of the deploying enterprise, such a clause will not necessarily protect the vendor.

Vendors also increasingly require customers to maintain specified insurance minimums — often $25 million in technology errors and omissions coverage plus a comparable cyber tower — as a condition of operating the agent at higher autonomy levels. This approach has the side effect of filtering out undercapitalized customers and shifting subrogation risk to commercial insurers, where it is at least aggregated and priced.

Finally, vendors are starting to publish "autonomy tier" schedules, with Tier 1 (assistive), Tier 2 (supervised autonomous), and Tier 3 (fully autonomous) deployments triggering different liability allocations. This is a meaningful innovation because it lets each side price and insure risk separately.

Insurance, Allocation, and the Role of Carriers

Specialty insurance markets have moved faster than contract law. By mid-2025, at least seven major underwriters — including AIG, Munich Re, and Beazley — were offering AI-specific liability products or endorsements. Premiums for $10 million of AI coverage typically range from $75,000 to $250,000 annually depending on the autonomy tier, sector, and claims history.

A useful development is the "AI liability waterfall," a contractual allocation that mimics insurance layering: the deploying enterprise pays the first $X (deductible equivalent), the vendor pays the next $Y, and insurance picks up amounts above. This structure is increasingly common in deals over $5 million in annual contract value. It works because it converts an open-ended tort question into a defined contractual priority, which both sides can price.

Carriers also want specific representations about human-in-the-loop controls, audit logging, and pre-deployment testing. A deal that lacks these features will either be declined for coverage or priced 40–60% higher. The insurance market is therefore functioning as a private regulator, effectively setting minimum operational standards for agentic deployments.

Common Mistakes That Create Liability Gaps

The most frequent drafting error is treating an AI agent agreement as a software license. License liability is typically capped at fees paid, which is wildly insufficient when an autonomous system can incur millions in damages in hours. The second mistake is failing to define "autonomous action" or "decision" in the contract, leaving the question to be litigated. The third is neglecting to specify which party's compliance program governs the deployment — for example, who is responsible for GDPR Article 22 compliance when the agent makes credit decisions about EU residents.

Another common error is omitting kill-switch and intervention rights. If a counterparty can show that the deploying enterprise knew an agent was malfunctioning and could have disabled it, courts may apply a higher standard of care. Contracts should grant explicit intervention rights to both the deploying enterprise and the vendor, with defined response times (often 24 hours for non-emergency, one hour for active harm).

A subtler mistake is ignoring third-party terms of service. If the agent interacts with an external platform — say, an e-commerce marketplace — and violates that platform's acceptable-use policy, the deploying enterprise may have no recourse against the AI vendor for the resulting suspension or termination. The contract should require the vendor to maintain a current map of third-party platform policies and to notify customers when changes occur.

Practical Steps for Buyers and Vendors in 2026

For enterprise buyers procuring agentic AI in 2026, the starting point is a risk register specific to the use case, identifying the worst credible outcome, the dollar exposure, and the regulatory dimension. With that document in hand, four contractual levers typically drive most of the value: (1) a behavioral warranty tied to specific guardrails, (2) an unintended autonomous action indemnity, (3) an insurance and waterfall provision, and (4) intervention and kill-switch rights with measurable SLAs.

For vendors, the priority is to maintain a defensible autonomy framework that documents how decisions are made, logs them at audit quality, and constrains them within tested boundaries. Vendors who refuse to negotiate these terms are likely to lose deals to competitors who will, because the procurement, risk, and legal teams at large enterprises have internalized the gap after several high-profile 2025 incidents.

Both sides should plan for the regulatory shift underway. The EU AI Act, fully applicable to high-risk systems since August 2026, imposes specific obligations on both providers and deployers of AI systems, and fines for non-compliance reach €15 million or 3% of global turnover. The U.S. federal AI Agent Act, introduced in 2024 and the subject of ongoing debate, signals that consumer-facing autonomous agents will attract particular federal scrutiny. Singapore's IMDA discussion paper, published in 2025, explored analogous questions of responsibility and has been cited by other Asia-Pacific regulators. Contracts drafted today should be flexible enough to absorb new compliance obligations without requiring re-negotiation.

When Standard Contracts Are No Longer Enough

The honest answer to who bears liability for an agentic AI's autonomous action is: it depends on the contract, and most existing contracts are inadequate. Enterprises that signed AI addenda in 2023 or earlier should expect to renegotiate. The economics of doing so are favorable — a well-drafted allocation reduces the cost of insurance and accelerates procurement cycles. The economics of not doing so are severe — a single catastrophic incident can exceed the entire value of a multi-year contract.

For organizations evaluating new AI agents, the prudent path is to insist on the contract structure outlined above before any deployment exceeding Tier 1 autonomy. For organizations already operating agentic systems under older agreements, the prudent path is to commission a focused contract review — typically taking 30 to 60 days — and to negotiate amendments covering the same four levers. Outside counsel fees for such a review usually range from $50,000 to $200,000 depending on contract count and complexity, a small fraction of the exposure it addresses.

Liability for autonomous AI is not a problem to be solved by drafting alone. It is a problem to be allocated, insured, and continuously updated as the technology and the law evolve. The companies that treat allocation as a first-class architectural concern — rather than a footnote in the procurement process — will both deploy AI more aggressively and sleep better at night.

Frequently Asked Questions

What is the single biggest liability gap in current AI contracts? The gap between standard SaaS limitations of liability (often 12 months of fees) and the realistic loss exposure from an autonomous agent making thousands of decisions per day. The dollar mismatch is so large that the cap is functionally meaningless for major incidents.

Does an AI vendor's disclaimer actually protect them? Partially. Disclaimers are enforceable in many B2B contexts but weaker in consumer cases and against regulatory claims. They cannot override statutory obligations, and a "no agency" recital will not change how a court applies actual authority doctrine.

Is insurance available for agentic AI risk? Yes. Specialty AI liability coverage is offered by major underwriters with premiums typically between $75,000 and $250,000 annually for $10 million of coverage. Insurers are increasingly setting minimum operational standards.

What is the EU AI Act's impact on contracts? For high-risk AI systems, the Act imposes specific provider and deployer obligations. Fines reach €15 million or 3% of global turnover. Contracts should allocate responsibility for compliance, logging, and reporting between provider and deployer.

How quickly should existing AI contracts be updated? Within 6 to 12 months, especially if the contract contains no behavioral warranty, no unintended-action indemnity, and no autonomy-tiered allocation. The cost of a focused review is small relative to the exposure it addresses.

Quick Facts

  • Category: AI contract negotiation
  • Timeline: 30–60 days for a focused contract review; 6–12 months to update legacy agreements
  • Cost: $50,000–$200,000 for outside counsel review depending on contract count
  • Best for: Enterprises deploying Tier 2 or Tier 3 autonomous agents and their vendors