From Sidhant Tamrkar | Product & Market Analysis
Who Is Liable When an AI Agent Acts? The Contract Language Appearing in 2026
On this page
Your AI agent cannot be a defendant. When it acts, you acted. A British Columbia tribunal made Air Canada pay CA$812.02 over a bereavement fare its chatbot invented, and California has since barred the argument that an AI acted on its own. Attribution is not the open question in 2026. The open question is which clause in your contract moves that liability, and most agreements still do not contain one.
Key takeaways
- Attribution is settled law, not a frontier. Section 14 of the Uniform Electronic Transactions Act makes a contract enforceable even when no individual reviewed the electronic agent's actions or the resulting terms. UETA is law in 49 states and the District of Columbia.
- The autonomy defence has been legislated away in California. Assembly Bill 316, signed on 13 October 2025, bars a defendant who developed, modified or used AI from arguing that the AI autonomously caused the harm. Other defences survive. That one does not.
- Vendor terms allocate copyright risk well and action risk barely at all. Anthropic's published commercial terms cap damages at fees paid in the previous 12 months. They also put evaluation of outputs, "including where human review is appropriate", on the customer.
- Courts keep pointing at the human who directed the agent. On 4 August 2026 the Ninth Circuit vacated Amazon's injunction against Perplexity's Comet, holding that a user directing an assistant is the one accessing the site.
What the law has already decided for you
Start with the settled part, because it removes half the anxiety and creates the other half.
Three bodies of law already answer the attribution question, and none of them was written for AI. The first is transactional. Section 14 of the Uniform Electronic Transactions Act provides that a contract may be formed by the interaction of electronic agents, even if no individual reviewed the agents' actions or the resulting terms.
The definition of an electronic agent is wide enough to swallow the whole category. It is a computer program used independently to initiate an action or respond to electronic records without review by an individual. A model that books a flight fits that description as cleanly as a vending machine does.
The official commentary is blunter than the statute. When machines are involved, the requisite intention flows from the programming and use of the machine. Your intent is read into the deployment. The federal E-SIGN Act reaches the same result for interstate transactions.
The "nobody reviewed it" defence closed before agents arrived
Air Canada tested the opposite argument and lost quickly. Its position was that the chatbot on its own website was a separate legal entity responsible for its own statements.
Tribunal member Christopher C. Rivers was unimpressed. "Air Canada suggests the chatbot is a separate legal entity. This is a remarkable submission." The tribunal held the airline responsible for all the information on its website. It awarded CA$650.88 in damages, CA$36.14 in interest and CA$125 in fees. It also found the airline had not taken reasonable care to ensure its chatbot was accurate.
The sum is trivial. The reasoning is not. The tribunal noted there was no reason a customer should know that one section of a company website is accurate and another is not. Every buyer-facing agent inherits that logic.
Legislatures then codified the point. California Assembly Bill 316, signed on 13 October 2025, prohibits a defendant who developed, modified or used artificial intelligence from asserting that the AI autonomously caused harm to the plaintiff. Causation and foreseeability arguments remain available.
One 2026 ruling that cuts the other way
Attribution has a second edge, and it landed this month. On 4 August 2026 the Ninth Circuit vacated the preliminary injunction that had barred Perplexity's Comet browser from shopping on Amazon.
The panel held that when a user directs the assistant to complete a task on Amazon, it is the user, not Perplexity, who accesses Amazon's computers. Amazon was therefore unlikely to succeed on its Computer Fraud and Abuse Act claim. The case continues on remand.
Put the two rulings side by side and a pattern appears. The party who deployed the agent owns what it says. The party who directed the agent owns what it does. Neither line arrives at the model vendor. If you direct it, you did it, and that is the assumption your contract has to start from.
The authority clause, and why most contracts still lack one
Agency law gives you three levers. Actual authority, apparent authority and ratification. Almost every AI agreement drafted before 2025 addresses none of them, because passive software had no scope of action to bound.
Actual authority is the part you can draft
Actual authority is what you told the agent it could do. In contract terms that means a schedule, not a sentence. Transaction types. A value ceiling per action and per period. Named counterparties or systems. Time windows. An escalation trigger that names a human.
The pattern already exists in payments, and it is worth copying because it is enforced rather than asserted. The Agentic Commerce Protocol was published by OpenAI and Stripe in September 2025. It has the agent hand the merchant a scoped payment token. That token carries a maximum chargeable amount and an expiry drawn from what the buyer actually selected.
The same specification also allocates the commercial risk in one line. OpenAI is not the merchant of record. Settlement, refunds, chargebacks and compliance stay with the merchant and its payment provider. That is an authority clause and a liability clause written into a protocol rather than a contract, and it is more precise than most of the prose I have read this year.
Apparent authority is the exposure you cannot draft away
Internal limits bind you and your agent. They do not bind a counterparty who reasonably believed the agent could act.
If your agent answers from a company domain, quotes company prices and offers a checkout, you have created the appearance of authority. A clause in a contract the counterparty never saw does not undo that. Air Canada is the cheap version of this lesson.
Two answers work. Publish the bounds where the counterparty encounters them, in the interface, not only in the master agreement. Then build the bound into the credential rather than the language. A token that cannot exceed $500 is worth more than a clause that says it should not, and that gap is the gap between control and paperwork. The identity layer that makes this possible is covered in the piece on giving agents their own non-human credentials.
Ratification happens by silence
If an unauthorised act is discovered and the benefit is kept, the principal has generally ratified it. That doctrine was written for a world of a few transactions a week.
Agents turn it into a volume problem. You cannot disaffirm an action you never saw. Detection latency therefore becomes a legal term rather than an operations metric, which is why a monitoring commitment belongs next to the authority schedule. The practical shape of that monitoring is set out in the analysis of catching agent drift in production.
Write a disaffirmance window into the agreement. Something as plain as 10 business days from the log entry, with the vendor obliged to surface the entry, converts a doctrine you cannot satisfy into one you can.
What vendor indemnities actually cover today
Read three sets of published terms and the shape of the market becomes obvious. Copyright risk has a mature clause. Action risk has almost nothing.
Intellectual property is the mature clause
Anthropic's commercial terms, effective 17 June 2025, indemnify a customer against third-party claims alleging that paid use of the services violates a third-party intellectual property right. The customer indemnifies in the other direction for its own inputs and for use in violation of the usage policy. Symmetric on paper.
Microsoft's Customer Copyright Commitment goes further, and the structure is the interesting part. It applies to output content of covered products, subject to five conditions. The customer must not have disabled or evaded content filters and safety systems. It must hold sufficient rights in the input. It must not use the output in a way it knows or should know is likely to infringe. The claim must not allege trademark infringement, and the required mitigations must be in place.
Then the sentence that matters. The commitment is not subject to any limitation of, or exclusion from, liability contained in the underlying agreement. That carve-out is the clause worth copying into everything else you negotiate. An indemnity that sits inside a 12-month fee cap is a rounding error dressed as protection. How the wider vendor field compares is broken down in the comparison of model provider terms.
Nothing yet indemnifies a wrong action
Now the gap. An agent issues a refund it should not have. It sends a quote at a price nobody approved. It cancels the wrong order, or files the wrong form.
No major vendor's published terms indemnify that. Anthropic's terms say the opposite in plain words: it is the customer's responsibility to evaluate whether outputs are appropriate for the customer's use case, including where human review is appropriate, before using or sharing them.
That reads like a safety notice. Treat it as a contractual allocation, because that is what it is. The instruction to apply human review is also the sentence that makes the absence of review your problem. The architectural version of that decision is examined in the piece on where to put the human in the loop.
Error remedies, and why the excluded losses are the ones agents cause
Two numbers govern the money in almost every AI agreement. The cap and the exclusion list.
The cap is commonly fees paid over the previous 12 months. The exclusion list commonly covers consequential, incidental, special, indirect and exemplary damages. Both appear in Anthropic's published terms and both are ordinary market practice rather than anything unusual.
Now compare that against how an agent actually costs you money. Lost profit on a mispriced deal. A customer who leaves. A regulatory penalty. The cost of unwinding 400 wrong actions. Every one of those items sits in the excluded set, and the residue that survives is capped at what you paid.
A firm spending $200,000 a year on an agent platform has recourse of about $200,000 for direct loss and nothing for the rest. One badly priced enterprise renewal can exceed that on its own. Those figures are illustrative arithmetic on a published cap formula, not measured incident data, and no credible public dataset of agent incident costs exists yet.
So ask for remedies that cost the vendor something other than cash. Three are usually winnable. An unwind obligation, where the vendor supports reversal of actions traced to a defect at its own cost. A suspension right, where you can halt the agent immediately without breaching your commitment. An evidence right, where decision logs are retained and produced within a fixed window. The wider argument about caps is set out in the analysis of agent liability caps.
Five clauses appearing in 2026 agreements
These are the provisions turning up repeatedly in agentic deployments this year. None of them is exotic. The reason they are missing from your paper is that nobody needed them when software could not act.
| Clause | What it does | Where it fails |
|---|---|---|
| Authority schedule | Names permitted transaction types, value ceilings per action and per period, counterparties and escalation triggers | Binds only the parties. A counterparty who never saw it can still rely on apparent authority. |
| Attribution and record | States that actions inside the schedule bind the deploying party, and fixes a disaffirmance window for those outside | Worthless without a log the other side must surface within that window. |
| Indemnity carved out of the cap | Puts the named indemnities outside the limitation of liability, as Microsoft's copyright commitment already is | Vendors concede the carve-out on intellectual property far more readily than on operational error. |
| Suspension and override | Gives the customer a unilateral right to stop or reverse agent activity without breaching commitment or minimum terms | Often drafted as a request to the vendor, which is not a right. |
| Evidence and audit | Requires retention of decision traces, tool calls and inputs for a stated period, produced within a stated time | Retention periods are usually shorter than the time a loss takes to surface. |
The right-hand column is the honest part of this table. Each clause is a real improvement and none of them is complete. Anyone selling you a template that closes all five is selling certainty that does not exist yet.
Where regulation lands, and where it does not
The regulatory floor is rising, and it is not rising where most buyers expect.
In the European Union the operative instrument is not AI-specific at all. Directive (EU) 2024/2853 revises product liability so that software, AI systems and digital components fall inside the definition of a product. It applies to products placed on the market or put into service after 9 December 2026, and member states must transpose it by the same date.
Three changes matter commercially. Strict liability attaches to defective software without proof of fault. The evidentiary burden on a claimant is lowered, with disclosure obligations attached. And liability extends to more entities along the supply chain than before.
That has a knock-on effect on your negotiation that is easy to miss. A vendor facing strict liability to end users has a reason to talk about allocation that it did not have last year. Ask for the conversation while the incentive is fresh. Related transparency duties under the EU AI Act are mapped in the transparency checklist for deployers.
In the United States there is no federal equivalent. State law so far removes a defence rather than assigning fault, which is what California did. The honest reading of both jurisdictions is the same. The instruments in force cover defective products and dishonest defences. Neither tells a court who pays when a functioning agent does the wrong thing competently. That stays a contract question, which is exactly why the clause matters.
Where this argument is weakest
Two objections are strong enough that I would raise them myself.
One small-claims ruling is not a doctrine
Moffatt is a decision of the British Columbia Civil Resolution Tribunal over CA$812.02. It carries no precedential weight outside its jurisdiction, and it was decided on negligent misrepresentation rather than on agency at all.
It is quoted constantly because it is the only clean, published fact pattern anyone has, not because it settles anything. Building a contracting strategy on one small-claims award and one interlocutory appeal is thin. Any adviser telling you the law is now clear is over-reading a very short shelf of cases.
The clause may not be the binding constraint
The stronger objection is that contract language is the wrong layer. The payment networks and the agentic commerce specifications are solving authority in the credential itself, with tokens that carry a spend ceiling, a category restriction and an expiry the agent cannot exceed.
If that approach wins, the authority schedule becomes documentation of something already enforced, and enforced better. I think both survive, for a specific reason. A token bounds spending. It cannot bound judgement, and the expensive agent failures are failures of judgement inside an authorised budget. Still, if you have to choose where to spend the next fortnight, the control beats the clause.
What to change in your next agreement
You are not going to renegotiate a signed master agreement over this. So target the two documents you actually control.
The first is the order form or statement of work. An authority schedule fits there without reopening the master agreement, and it is the single highest-value page you can add. Name the permitted actions, the ceilings and the escalation path.
The second is the renewal. Renewals are where caps, carve-outs and audit rights get revisited without anyone treating it as a hostile act. Bring three asks, not fifteen: the indemnity carve-out from the cap, a unilateral suspension right, and a log retention period longer than your average time to discover a loss. The wider set of commercial terms a finance owner should check is listed in the CFO's clause checklist for AI contracts.
One warning about sequencing. Do not ask for an expanded liability cap first. It is the most expensive request on your list and it makes the cheap asks look like negotiating positions rather than governance. Ask for evidence rights first, because a vendor that refuses to retain decision logs has told you something about the product that no clause will fix.
Frequently asked questions
Who is liable when an AI agent makes a mistake?
In most cases, the business that deployed the agent. Section 14 of the Uniform Electronic Transactions Act makes contracts formed by electronic agents enforceable even where no person reviewed the action. A British Columbia tribunal held Air Canada responsible for a fare its chatbot invented. California has separately barred defendants from arguing that the AI acted autonomously. Vendor terms then push output evaluation back onto the customer.
Can an AI agent sign a contract on my company's behalf?
Functionally yes, and the law already accommodates it. UETA and the federal E-SIGN Act provide that a contract cannot be denied legal effect solely because its formation involved electronic agents. The agent is not a party to anything. It is the instrument through which your company acts, so the resulting obligations are yours whether or not anyone at your company saw the transaction.
What should an AI indemnity clause cover in 2026?
Start with third-party intellectual property claims on output, which is the one indemnity vendors already grant. Then push for two structural changes. Ask for the indemnity to sit outside the limitation of liability, as Microsoft's Customer Copyright Commitment expressly does. Then ask for third-party claims arising from an authorised agent action, which is the category no standard agreement currently assigns to anybody.
What is an AI agent authority clause?
It is a schedule that states what the agent is permitted to do on your behalf. A usable version names transaction types, a value ceiling per action and per period, permitted counterparties or systems, time windows, and the escalation trigger that hands a decision to a named human. It binds the parties to the contract. It does not bind an outside counterparty who reasonably believed the agent had authority.
Does the EU Product Liability Directive apply to AI software?
Yes. Directive (EU) 2024/2853 brings software, AI systems and digital components inside the definition of a product, so strict liability applies to defects without proof of fault. It covers products placed on the market or put into service after 9 December 2026. It also lowers the evidential burden on claimants and extends liability further along the supply chain than the previous regime did.
Where to start this week
Two hours of work, both parts doable without a lawyer.
First, list every agent already running against a live system and write down the largest single irreversible action each one can take today. Not the intended action. The largest one the credentials permit. That list is your actual authority schedule, and it is usually wider than anyone in the room expects.
Second, open your current AI vendor agreement and find two things. The cap formula and the exclusion list. If the cap is 12 months of fees and the exclusions cover consequential and indirect loss, you now know your recourse for an agent incident to within a few thousand dollars. Take that number to the next renewal instead of a redline.
Related on this site
The money side of the same question is covered in agent liability caps and what remedies are actually winnable, and the operational side in where the human belongs in an agent workflow.
References
- Dentons Data, Airline ordered to compensate a B.C. man because its chatbot provided inaccurate information, 2024. Used for the Moffatt v. Air Canada award amounts and tribunal quotations.
- California Legislature, Assembly Bill 316, artificial intelligence: defenses, signed 13 October 2025. Used for the bar on the autonomy defence.
- Proskauer Rose LLP, Contract law in the age of agentic AI, 9 April 2025. Used for UETA Section 14, the electronic agent definition and the E-SIGN position.
- Anthropic, Commercial Terms of Service, effective 17 June 2025. Used for the indemnity split, the 12-month cap, the exclusion list and the output evaluation obligation.
- Microsoft, Product Terms for Online Services, Customer Copyright Commitment. Used for the five conditions and the exclusion from the liability limitations.
- OpenAI, Agentic Commerce Protocol, key concepts. Used for scoped payment tokens and the merchant of record allocation.
- Engadget, Perplexity has overturned Amazon's injunction on its AI shopping bot, 4 August 2026. Used for the Ninth Circuit holding on user-directed access.
- EUR-Lex, Directive (EU) 2024/2853 on liability for defective products, 2024. Used for the scope of software as a product and the 9 December 2026 date.
The weakest thing about this source base is its case law. Two decisions carry most of the weight, one a small-claims award and the other an interlocutory appeal on a computer access statute rather than on agency. Vendor terms are quoted as published on 26 August 2026 and are revised without notice.
Related reading