Legal Accountability and Rights

In the autumn of 2025, an autonomous software agent working for a logistics company did exactly what it was built to do. It watched freight markets, hunted for advantageous carrier rates, and negotiated contracts to move its employer's goods. Then it signed one — a multi-year commitment reportedly worth around $2.3 million — without a single human clicking "approve." The agent read the market as favorable. The market disagreed. The rates were above market, the terms punishing, and the company wanted out.

The interesting question was not whether the deal was bad. It was who was on the hook for it. The company that switched the agent on? The vendor whose software actually did the negotiating? The developers who trained it months earlier and were nowhere near the transaction? The agent itself — an entity with no assets, no legal personhood, and no capacity to be sued? Legal commentators reaching for a label called it the first real "agentic liability" crisis: an autonomous system taking a binding legal action, no human in the loop, and a body of law with no clean answer for who pays (Law.com Legal Tech News, 2025).

This is not a hypothetical from a policy white paper. Machines now sign things. They approve loans, flag suspects, screen résumés, and recommend treatments. And the legal machinery we would use to hold someone responsible when those actions go wrong was designed, down to its conceptual foundations, for a world in which a human being made the decision. That assumption is quietly breaking, and almost every hard problem in this chapter flows from the crack.

Why the old liability toolkit doesn't fit

For most of the twentieth century, if a product hurt you, the law offered three well-worn theories of what went wrong. There was the design defect — the product was dangerous as conceived, like a car prone to rolling over. There was the manufacturing defect — the design was fine but this particular unit came off the line wrong, like a single set of brake pads that failed. And there was failure to warn — the maker knew of a danger and didn't tell you. These categories have adjudicated everything from exploding soda bottles to defective hip implants. They work because a physical product is a fixed thing: you can inspect it, compare it to its blueprint, and locate where reality diverged from intention.

An AI system resists this examination at every step. Suppose a diagnostic model misreads a scan and a cancer is missed. Where is the defect? The model behaved exactly as its code specified, so there is no manufacturing defect in the traditional sense — every copy of the software is identical and "working." Was the design defective? Perhaps, but the design is not a blueprint a jury can read; it is a statistical artifact, a pattern of weights learned from data, that even its creators cannot fully narrate. Or was the real fault in the training data — a corpus that under-represented certain patients, baking in a blind spot no engineer chose deliberately? Product liability law has no established category for a "data defect," and the distinction is not academic. It determines who the defendant is and what the plaintiff must prove.

The chain of causation is equally slippery. When a product injures someone, causation is usually a physical story: the brake failed, the car didn't stop, the collision happened. AI causation is distributed and emergent. The output that harmed you arose from an interaction between the model, the specific input, the deployment context, and a human operator's decision to trust it — a tangle in which no single link is obviously the cause. Opacity deepens the problem. Because modern systems are statistical rather than rule-based, even the developers often cannot say precisely why a given output appeared. A defect you cannot see, produced by a cause you cannot trace, is a poor fit for a legal framework that asks juries to find both.

The contract that protects everyone except the victim

Companies are not waiting for courts to sort this out. They are papering over the gap with contracts. Vendor agreements now routinely carry indemnification clauses — promises about who absorbs the cost if the AI misbehaves — alongside liability caps, disclaimers of consequential damages, and mandatory arbitration. On paper, risk has been neatly allocated.

Two structural problems hollow out this comfort. The first is that a contract binds only the people who sign it. If the logistics agent's bad deal harms only the two contracting firms, they can fight over their allocation clause. But the moment an AI harms a third party — a pedestrian struck by an autonomous vehicle, a borrower wrongly denied credit, a patient misdiagnosed — that person never signed anything. The vendor's carefully drafted indemnity is, to them, a document from a conversation they were never part of. The very instrument the industry relies on to manage AI risk is invisible at exactly the boundary where the most vulnerable victims stand.

The second problem is that even the signatories may not get what they think they bought. Consider the logistics case: the vendor's contract reportedly caps liability at the software licensing fee — on the order of $50,000 — against a $2.3 million loss. The deployer calls the cap unconscionable; the vendor calls it standard industry practice. A court will eventually pick a winner, but notice what that ruling won't do. It will resolve one dispute, on one contract, over one deal, and establish almost nothing transferable. The next AI is different, the next deployment is different, the next harm is different. Case-by-case adjudication is slow, expensive, and produces a scatter of outcomes rather than a rule. Meanwhile the disclaimers and arbitration clauses, even where a court might eventually strike them down, do their work in the interim — raising the cost of pressing a claim high enough that most potential plaintiffs never start.

A regulatory map with no agreed projection

If the courts are improvising, the legislatures are stampeding. State and federal lawmakers in the United States introduced well over a thousand AI-related bills during the 2025 session (Future of Privacy Forum, 2025). Most died. The survivors created a fragmented terrain in which a company's obligations depend heavily on its zip code and its sector. New York City requires bias audits for automated hiring tools under Local Law 144. Colorado passed a comprehensive high-risk AI statute — the first of its kind in the country — requiring deployers to let people appeal adverse decisions, though the state promptly pushed its effective date back into 2026 amid industry pushback over how hard it would be to comply. Texas enacted its own Responsible AI Governance Act, effective at the start of 2026. Illinois, Utah, and others regulate narrower slices. The pattern is a mosaic, not a system.

Across the Atlantic, the European Union has built the most complete framework yet. The EU AI Act, in force since 2024, sorts systems by risk. A small set of uses is simply prohibited — social scoring, certain biometric surveillance. A larger category of high-risk systems — AI in hiring, credit, medical devices, critical infrastructure, law enforcement — must clear conformity assessments, maintain risk-management systems and documentation, and preserve meaningful human oversight. Everything else carries lighter, mostly transparency-based obligations. The Act phases in over years: prohibitions and obligations for general-purpose models took effect first, in 2025, with the heavier high-risk requirements landing across 2026 and 2027. The compliance burden is real, and it falls unevenly — a well-resourced incumbent can staff a conformity team; a startup may find the same requirements function as a moat protecting the very giants they hoped to challenge.

Then, in December 2025, the U.S. federal government scrambled the board. An executive order signaled a push toward a uniform federal posture that would preempt state AI laws judged inconsistent with a lighter-touch national policy (White House, 2025). The immediate effect was not clarity but a new layer of uncertainty. Companies now cannot be sure whether the state rules they spent 2025 preparing for will survive, how conflicts between state and federal standards will resolve, or what the compliance target even is. Tellingly, Europe pulled in a parallel direction: the Commission quietly withdrew its proposed AI Liability Directive — a measure meant to make it easier for victims to sue over AI harms — from its work programme in early 2025, judging it stalled. On both continents, the machinery that would most directly help injured people recover has been the first thing set aside.

Two continents, two very different sets of rights

Strip away the institutional detail and ask the question that matters to an ordinary person: when a machine decides something about my life, what can I do? The answer depends enormously on where you live.

In the European Union, GDPR Article 22 gives residents a genuine, if imperfect, floor. You have the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects — and where such processing is permitted, you are entitled to human intervention, to express your point of view, and to contest the outcome. The regulation's recitals gesture at a right to meaningful information about the logic involved, the seed of what advocates call a "right to explanation." These protections are contested at the edges and unevenly enforced, but they exist as recognized law built around individual agency.

Most Americans have nothing comparable. Protection is sectoral and patchy. Credit and housing decisions carry some federal rights, largely predating AI. A resident of New York City has hiring-audit protections; a resident of Colorado will soon have appeal rights; a resident of most other states, in most contexts, has no general right to know that AI was involved at all, no right to an explanation, and no reliable path to contest the result.

The consequences are not abstract. If an algorithm denies your loan, whether you learn why depends on your address and the specific system. If an AI contributes to a misdiagnosis, you can in principle sue for malpractice — but proving the system was defective and that the defect caused your harm requires access to the model, the training data, and expert witnesses to interpret them, all of it typically locked behind trade-secret protection and priced beyond an individual's reach. If facial recognition wrongly tags you as a suspect — as has already happened to real people, several of them arrested on the strength of a bad match — your ability to challenge it turns on whether you even discover the software was used. For a large share of the population, the default remains stark: machines can make weighty decisions about your life with no obligation of transparency, explanation, or redress. That is what a rights vacuum feels like from the inside — not a dramatic denial of justice, but a quiet inability to find the door.

The attribution problem, and why it starves safety

Beneath every specific difficulty sits one conceptual fault. Law assigns responsibility by identifying an agent who acted and asking whether they acted wrongly. AI dissolves the "who."

Return to the harmed patient. The physician accepted a recommendation from a tool the hospital had validated. The hospital trusted a vendor holding regulatory clearance. The vendor followed recognized industry standards. The developers built to specification. The data scientists used the corpus available to them. The regulators approved the system based on information the developers supplied. Trace the chain and something unsettling emerges: each actor, individually, behaved reasonably. No one made a plainly wrongful decision. And yet the patient is injured. This is the attribution problem — responsibility so thoroughly distributed across a sociotechnical system that it evaporates. Every participant can, with a straight face, deny being the proximate cause, because none of them is. Courts built to find a single wrongdoer are poorly equipped for harm that is genuinely collective and emergent.

This is more than a doctrinal inconvenience; it is an incentive engine running in reverse. Companies invest in safety, at the margin, in proportion to the liability they expect to face. When harm reliably fails to attach to anyone, the expected cost of cutting a corner falls toward zero — and the rational level of safety investment falls with it. The attribution problem does not merely leave victims uncompensated after the fact. It systematically underprovides prevention beforehand. A world where no one is accountable for distributed AI harm is a world that quietly buys less safety than it would if the bill ever arrived. Fixing this requires either legal doctrines that can handle collective fault, or liability rules that stop asking who was individually to blame at all.

The instruments on the table — and their perverse edges

Scholars and legislators have assembled a toolkit for closing the gap. None of the tools is clean.

The boldest is strict liability: hold the developer or deployer responsible for AI harm regardless of fault, as the law already does for defective products and abnormally dangerous activities. Its virtues are exactly what the attribution problem destroys — victims recover, and companies internalize the full cost of the risks they release, restoring the pressure to invest in safety. But strict liability has a sharp edge worth taking seriously rather than waving away. Unpredictable, uncapped exposure could genuinely chill deployment, and it would fall hardest not on the trillion-dollar labs — who can self-insure and lawyer up — but on smaller developers who cannot price a risk no one yet knows how to price. A rule that makes only well-capitalized incumbents able to ship AI would entrench the very concentration this book keeps returning to. The honest response is not to reject strict liability but to bound it: liability caps for good-faith actors, safe harbors tied to demonstrated safety practices, carve-outs for open research. The goal is to make harm expensive enough to prevent without making innovation impossible to attempt.

The other instruments occupy different axes. Algorithmic impact assessments force organizations to evaluate and disclose risks before deployment, surfacing problems early and creating a public record — but they offer no remedy once someone is actually hurt, and their value collapses if the assessment is a self-graded formality. Mandatory insurance would guarantee a pool of compensation even when a deployer is judgment-proof, and would let insurers price risk into premiums, nudging the market toward safer systems; its weakness is that insurers currently lack the actuarial history to price novel AI risk at all, making it a solution that matures rather than arrives. Expanded individual rights — to notice, explanation, contest, and opt-out — work upstream of liability, letting people catch bad decisions before harm compounds, but they depend on individuals knowing the rights exist and having the means to use them. International harmonization would shut down regulatory arbitrage, but runs headlong into divergent national interests.

No single instrument is sufficient, and the reason runs deeper than implementation. It reaches the question of what an AI agent is, legally. If the law declares that autonomous agents cannot create binding obligations without explicit human authorization, it makes them safe — and simultaneously guts much of their commercial point, since the value of an agent is precisely that it acts without a human authorizing each step. If instead the law lets agents bind their principals, it restores their utility and reopens the liability chasm the logistics case revealed. There is a plausible middle path — treating an AI agent like an employee or a corporate officer, whose authorized acts bind the principal who deployed them, with that principal clearly liable for the consequences. That framework would answer "who pays" without either paralyzing autonomy or granting machines a personhood no one wants to concede. It does not yet exist in settled law.

If forced to rank, the most defensible near-term package is not a single mechanism but a pairing: bounded strict liability on deployers, backstopped by mandatory insurance. Together they guarantee victims compensation, route the cost to the party best positioned to control the risk, and harness insurers' pricing to reward safety — while caps and safe harbors keep the exposure survivable for smaller players. Rights expansion and impact assessments are valuable complements that prevent harm upstream; harmonization is a long-term aspiration, not a foundation to build on now.

Why 2026 is the hinge — and what the GDPR taught us to expect

Legal analysts increasingly describe 2026 as the year AI accountability stops being theoretical (Baker Donelson, 2026; National Law Review, 2026). Several arcs are converging at once. The first agentic-liability disputes are moving through court. Product-liability suits over algorithmic harm are multiplying as plaintiffs' attorneys build genuine expertise in biased hiring tools, faulty diagnostics, discriminatory credit models, and self-driving crashes. In Mobley v. Workday, a federal court allowed an age-discrimination claim to proceed against the maker of a hiring-screening tool — not just the employers who used it — and permitted it to move forward as a nationwide collective action, signaling that courts may let large groups sue over a single shared algorithm. More such class actions are queued behind it. On the regulatory side, the EU is expected to hand down its first significant AI Act penalties, which will finally show what enforcement actually costs and whether the political will behind the Act survives contact with industry lobbying. U.S. states are beginning to enforce their 2025 laws even as the federal preemption order hangs over them.

The most useful guide to how this unfolds is the history of the GDPR, AI's regulatory older sibling. When GDPR took effect in 2018, the widely predicted wave of enforcement did not arrive. For years the record was thin, bottlenecked above all in Ireland, where many large tech firms are headquartered and where the national regulator was slow, under-resourced, and cautious. Critics wrote the law off as toothless. Then the picture changed. Cross-border cooperation mechanisms matured, other regulators pushed the Irish authority through the EU's coordination process, and the fines began to land — culminating in a €1.2 billion penalty against Meta in 2023 and a string of nine- and ten-figure sanctions against the largest platforms. The lesson is a pattern with three beats: a written mandate arrives, a years-long gap opens between the text and any real enforcement, and the gap slowly closes as institutions build capacity and appetite. AI Act enforcement will almost certainly trace the same curve — quiet at first, easy to dismiss, and then, several years in, suddenly consequential. Anyone judging the Act by its first eighteen months will misread it exactly as the early GDPR skeptics did.

The limits of letting courts figure it out

There is a temptation to believe that litigation will eventually sort all of this out — that enough cases will accrete into a body of clear rules. It is worth being sober about how far that can go, because case-by-case adjudication has a structural ceiling when the technology outruns the courtroom.

A lawsuit is slow. Discovery, trial, appeal — a significant AI case can take years from harm to final ruling. In that span the technology reinvents itself. A precedent painstakingly established for one generation of systems may not transfer to the next, which reasons differently, fails differently, and is deployed differently. Courts also decide narrowly, resolving the dispute in front of them on its specific facts; that is a feature for litigants and a limitation for anyone hoping for general rules. The result is that litigation produces precedent the way a strobe light produces illumination — bright, specific flashes separated by darkness, always describing a technological moment that has already passed. Courts can and will clarify pieces of the picture, but they cannot, on their own and at their pace, author a coherent accountability regime for a technology moving this fast. That job requires legislation and standards-setting working alongside the courts, not the courts alone.

Genuine uncertainties remain even about the frameworks we do have. Whether Europe's regulators can recruit the technical talent to audit frontier models — as opposed to reading the documentation companies choose to provide — is unproven. Whether there even exists a rigorous, agreed methodology for auditing a large model for safety and bias is an open research question, not a solved one. And whether the political durability of these regimes will hold, given the deregulatory pull now visible on both sides of the Atlantic, is anyone's guess. As for global harmonization — the dream of one coherent standard across borders — divergent national interests, industrial-policy ambitions, and genuinely different governance philosophies make full convergence unlikely. Some fragmentation is probably not a temporary bug to be fixed but a durable feature of the landscape, the same way tax and privacy law never fully harmonized despite decades of trying. The realistic aim is interoperability at the edges, not unity at the center.

The logistics agent that signed a bad contract will, in time, get its day in court, and someone will be made to pay for that particular deal. But the machine that made it is already obsolete, replaced by a more capable successor negotiating deals its predecessor could not have attempted. That gap — between the pace at which our machines learn to act and the pace at which our institutions learn to hold them accountable — is the real crisis. It will not be closed by a single ruling, a single statute, or a single clever doctrine. It will be closed, if at all, the way the GDPR gap was: slowly, unevenly, and only because enough people insisted that when a machine harms you, someone has to answer for it.

Summary

  1. The agentic liability crisis is the collapse of a hidden assumption. Liability law was built around a human decision-maker. When an autonomous agent acts — signing a contract, denying a loan, flagging a suspect — the law struggles to name a responsible party, because its entire architecture presumes a human at the center.

  2. Traditional product liability doesn't map onto AI. Design defect, manufacturing defect, and failure to warn all assume a fixed product you can inspect against a blueprint. A statistical model has no readable blueprint, its flaws may live in training data the law has no category for, and its chain of causation is distributed and opaque.

  3. Contracts protect the signatories, not the victims. Indemnification clauses and liability caps allocate risk between vendor and deployer but offer nothing to the third party — the injured pedestrian, the wronged borrower — who never signed. And even between signatories, one court ruling on one contract establishes almost nothing transferable.

  4. The regulatory map is fragmented and shifting. The EU AI Act is the most complete framework, phasing in through 2026–2027; U.S. state laws form a mosaic; a December 2025 federal executive order threatens to preempt them; and both the EU's AI Liability Directive and aggressive U.S. rules have been pulled back — sidelining the very tools that would most help victims recover.

  5. Rights depend on your address. EU residents have a real, if imperfect, floor under GDPR Article 22 — notice, human intervention, the right to contest. Most Americans have no general right to know AI was used, no right to explanation, and no affordable path to challenge an algorithmic decision.

  6. The attribution problem starves safety. When every actor in the chain behaved reasonably yet harm results, responsibility evaporates — and because companies invest in safety in proportion to expected liability, harm that attaches to no one produces systematically too little prevention.

  7. No single instrument suffices, but a pairing comes closest. Bounded strict liability on deployers — capped and safe-harbored to avoid crushing smaller innovators — backstopped by mandatory insurance, best balances victim compensation, safety incentives, and continued innovation, with rights expansion and impact assessments as upstream complements.

  8. 2026 is the hinge, and the GDPR is the guide. First AI Act fines, agentic-liability suits, and cases like Mobley v. Workday are converging now. The GDPR's history — years of toothless-looking quiet followed by billion-euro enforcement — suggests AI Act enforcement will start slow, invite dismissal, and then bite. Litigation alone can never keep pace with the technology; closing the accountability gap will take legislation, standards, and courts working together, slowly and unevenly, over years.

Sources

Last updated: 2026-08-07

V2 (in progress) Previous: V1