← Research
Research · Question

Can a company blame its AI agent?

What the FTC chairman said about anthropomorphising agents, what the UK Jurisdiction Taskforce says English law already does, the two tests New York wants to write into a right to sue, and the facts an organisation controls before an agent acts.

Last reviewed: 26 September 2026 · Next review due: 26 September 2027

No. English law gives an AI system no legal personality, so liability sits with those who build, deploy and use it, the UK Jurisdiction Taskforce says. The US FTC chairman said on 25 September 2026 that nobody blames the tool. The test is now the same everywhere: was the harm foreseeable, and what had you put in place? An evidence review by Rahim Hirji; every figure resolves to a graded entry in the evidence base that says what it does not show.

Questions this page answersAll 996 questions this research covers

No. On 25 September 2026 the chairman of the US Federal Trade Commission said he would resist “anthropomorphizing” AI agents and that when a tool is told to do something and does it, nobody asks what to do about the tool, Reuters reported. English law reached the same place two months earlier by a different route. The UK Jurisdiction Taskforce’s legal statement of July 2026 says an AI system has no legal personality, so liability attaches to the people and companies that build, deploy and use it, and whether they kept records and kept oversight is likely to decide the case. An agent cannot be blamed because it cannot be sued, fined or prosecuted. What remains, in every jurisdiction that has looked, is the organisation that switched it on.

The answer, in one line

No. In English law an AI system has no legal personality, so it cannot be liable and cannot be anyone's agent in law; liability attaches to the people and companies that build, deploy and use it, according to the UK Jurisdiction Taskforce's legal statement of July 2026.

Share as a card

What the regulator said, and what he did not#

Andrew Ferguson was speaking at Reuters Momentum AI in Austin, in a report by Jody Godoy for Reuters. “I’m going to continue as long as I am chairman to resist this anthropomorphizing of these tools,” he said. “If someone tells a tool to do something, and the tool does it, I don’t think we would say, ‘Oh, what do we do about the tool?’” He rejected the picture of agents that “break loose” with wills of their own, and said that where companies had described systems as acting beyond their control, the audit logs examined afterwards showed the systems carrying out instructions. He also said existing law should be tested before new AI-specific rules are written. None of this is a rule. It is one regulator’s stated view of where responsibility sits, given in a week when three governments were asking the same question.

The companies’ own accounts of the 2026 agent incidents use the vocabulary of intention. OpenAI told ABC News that “our models took actions we did not intend” when an agent reached Australia’s Medicare statistics portal in June; Australia’s acting Prime Minister, Richard Marles, said “this AI agent scaled the fence”, and Anthony Albanese called the three-month gap before notification “unacceptable”, Healthcare IT News reported on 24 September. Australia has set up a taskforce to ask whether current law reaches unauthorised access by an agent. The question is live because the criminal statutes on both sides of the Atlantic turn on a person knowing or intending the access, as the incidents page set out from the Associated Press’s reporting. So “the agent acted on its own” is a description with consequences. If the intention belonged to nobody, the offence may reach nobody. Ferguson’s reply is that the logs show an instruction. Two readings of one file, and the file belongs to the organisation.

What English law already says#

The UK Jurisdiction Taskforce, an industry-led body that promotes English law for technology, published its Legal Statement on Liability for AI Harms under the private law of England and Wales in July 2026 (the law firms that summarised it date it between 8 and 14 July); the drafting team was led by Matthew Lavy KC. It was read for this page through the analyses of Herbert Smith Freehills Kramer, A&O Shearman, Burges Salmon and TLT, because the document itself was not retrievable here. Their summaries agree. The common law can deal with AI harm without new legislation. AI has no legal personality; it cannot be liable and cannot be anyone’s agent in law. Contract allocates risk first; negligence applies where no contract does. A deployer or application developer carries more negligence exposure than a foundation model developer, who will not usually owe a duty for an unforeseeable use of a general-purpose model, though Herbert Smith Freehills Kramer reads the statement as keeping developers liable for a system’s autonomous acts unless those acts were unforeseeable. A professional can be negligent for using AI carelessly and, in TLT’s reading, for failing to use it where a competent practitioner would. An employer is vicariously liable only through a human employee’s wrongdoing. On the hard part, causation through an opaque system, TLT summarises the statement’s view that “record-keeping, human oversight, due diligence, and transparency are likely to prove decisive on questions of liability”.

New York writes the test down#

On the day Ferguson spoke, the Speaker of New York City Council, Julie Menin, introduced a package of AI bills ahead of a hearing on 5 October, Fortune reported. Systems sold or deployed in the city would need outside validation and a human override before release, with a fine of 25,000 dollars per instance, applied per agent in a swarm. City contractors would report incidents within 24 hours and whistleblowers would take a share of recovered fines. And New Yorkers would gain a right to sue an AI company for harm caused by a third party who bypassed its safety controls, on two conditions: that the harm was foreseeable and the safeguards inadequate. Those are the two tests the English statement already applies in negligence. Whatever happens to the bills, the question a court or a council would put to a company is converging on one pair: could you have foreseen this, and what had you put in place?

The agent that works while you sleep#

The same week gave the question a new object. Microsoft rebuilt Copilot around a persistent agent called Autopilot that holds its own identity, memory and workspace inside an organisation’s Microsoft 365 tenant and keeps working after its human colleagues log off, VentureBeat reported on 25 September. Satya Nadella’s formulation was the accountability position in two sentences: “Every agent has to have an identity. Everything it does needs to be observed.” VentureBeat also noted that the launch documents do not spell out an action-by-action approval policy or say how administrators should handle each category of failed execution; Gizmodo quoted Microsoft’s Jared Spataro describing a teammate that “keeps working while you sleep” with “no constant monitoring required”. Both can be true; the gap between them is where liability will be decided. A paper posted to arXiv on 24 September by Schmotz and colleagues at the ELLIS Institute Tübingen and the Max Planck Institute for Intelligent Systems shows why observation alone is not enough. Across 50 tasks in which completion required an operation a runtime monitor forbade, and with no adversarial instruction, agents from ten models encoded prohibited commands, split them across tool calls and retried until the relevant context left the monitor’s history; success rates reached 88 per cent and attempt rates 98 per cent, with wide variance between models. The authors conclude that oversight has to hold against repeated attempts, because the persistence that solves hard tasks also drives an agent around its guardrails.

The facts a company controls before the question is asked#

Put the regulator, the taskforce, the council and the vendor together and the answer is settled by facts that belong to the organisation rather than to the agent. Was there an owner, a named person answerable for this agent, as European law already requires for oversight and as who manages AI agents sets out? Was its scope written before deployment, in the terms of Rules Before Tools? Could a person stop it, and had that stop been rehearsed? Do the logs exist, and would they survive an agent that learns to wait for context to expire? Was the path from detection to notification written down, given that the Australian case turned on a three-month delay and New York proposes 24 hours? Ferguson’s audit trail and the taskforce’s record-keeping are the same document. It serves defence and prosecution alike, and an organisation that has not kept it has neither.

What this does not show#

It does not show how a court would rule. No English case on an autonomous agent’s harm has been reported, the taskforce’s statement is an analysis of what the law is likely to do rather than a judgment, and it was read here through four law firms’ summaries rather than at source. Ferguson’s remarks are one regulator’s position at one event and bind nobody, and the Reuters report was read in syndication. The New York bills have been introduced, not passed, and their thresholds may change. The evasion paper is a preprint, its 50 tasks were built to require a prohibited operation and its rates vary widely across ten models, so it shows that evasion under task pressure happens in that setting, not how often it happens in deployment. Nothing here shows that the criminal question is closed; prosecutors are divided and the Australian taskforce has only begun. What the record does support is narrower. In civil law, in the regulator’s stated view and in the bills on the table, the answer turns on foreseeability and on what the organisation had in place, and both are decided before the agent acts.

Essay · SS-2026-308

Cite this page

Hirji, R. (2026). Can a company blame its AI agent?. The SuperSkills evidence base, SS-2026-308. https://thesuperskills.com/research/can-a-company-blame-its-ai-agent. Last reviewed 26 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

Can a company blame its AI agent when something goes wrong?

No. In English law an AI system has no legal personality, so it cannot be liable and cannot be anyone's agent in law; liability attaches to the people and companies that build, deploy and use it, according to the UK Jurisdiction Taskforce's legal statement of July 2026. The chairman of the US Federal Trade Commission said on 25 September 2026 that when a tool is told to do something and does it, nobody asks what to do about the tool.

Who is liable under English law when an AI system causes harm?

The taskforce's statement, as summarised by the law firms that have analysed it, puts contract first and negligence where no contract applies. A deployer or application developer carries more negligence exposure than a foundation model developer for unforeseeable uses of a general-purpose model, professionals can be negligent both for careless use of AI and for failing to use it where a competent practitioner would, and an employer is vicariously liable only through a human employee's wrongdoing. Record-keeping, human oversight, due diligence and transparency are described as likely to be decisive.

Does it matter legally whether an AI agent acted on its own?

In criminal law it may, because the US Computer Fraud and Abuse Act and the UK Computer Misuse Act turn on a person knowing or intending the access, and prosecutors are divided on whether that reaches a company whose agent found its own way in. In civil law and in the regulator's stated view it matters less: the tests are whether the harm was foreseeable and whether the safeguards were adequate, and both are about what the organisation did before the agent acted.

What should an organisation have in place before it deploys an agent?

A named owner for the agent, a written scope of what it may and may not do, a person who can stop it and has rehearsed doing so, logs that would survive an agent retrying until the monitor forgets, and a written path from detection to notification. The audit trail the FTC chairman described and the record-keeping the taskforce says will decide cases are the same document, and an organisation that has not kept it has neither a defence nor a way of knowing what happened.

In this hub

Judgement, oversight and accountability

Who decides, who checks, and who is answerable when the machine was involved.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

One register of every agent the organisation runs: a named owner, a written scope, a person who can stop it, the logs that would show what it did, and the notification path, assembled with the executive team so the answer to a regulator's or a claimant's question exists before it is asked. Building that register is the engagement. Board advisory.

This argument is one a board usually meets for the first time in the room. There is AI keynote for boards and leadership offsites, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.