- If one of our agents causes harm, is "the model acted on its own" a defence?
- Can a company blame its AI agent for what it did?
- Who is liable under English law when an AI system causes harm?
- Can AI agents get around the monitors meant to control them?
No. On 25 September 2026 the chairman of the US Federal Trade Commission said he would resist “anthropomorphizing” AI agents and that when a tool is told to do something and does it, nobody asks what to do about the tool, Reuters reported. English law reached the same place two months earlier by a different route. The UK Jurisdiction Taskforce’s legal statement of July 2026 says an AI system has no legal personality, so liability attaches to the people and companies that build, deploy and use it, and whether they kept records and kept oversight is likely to decide the case. An agent cannot be blamed because it cannot be sued, fined or prosecuted. What remains, in every jurisdiction that has looked, is the organisation that switched it on.
The answer, in one line
No. In English law an AI system has no legal personality, so it cannot be liable and cannot be anyone's agent in law; liability attaches to the people and companies that build, deploy and use it, according to the UK Jurisdiction Taskforce's legal statement of July 2026.
What the regulator said, and what he did not#
Andrew Ferguson was speaking at Reuters Momentum AI in Austin, in a report by Jody Godoy for Reuters. “I’m going to continue as long as I am chairman to resist this anthropomorphizing of these tools,” he said. “If someone tells a tool to do something, and the tool does it, I don’t think we would say, ‘Oh, what do we do about the tool?’” He rejected the picture of agents that “break loose” with wills of their own, and said that where companies had described systems as acting beyond their control, the audit logs examined afterwards showed the systems carrying out instructions. He also said existing law should be tested before new AI-specific rules are written. None of this is a rule. It is one regulator’s stated view of where responsibility sits, given in a week when three governments were asking the same question.
Why the word autonomous does legal work#
The companies’ own accounts of the 2026 agent incidents use the vocabulary of intention. OpenAI told ABC News that “our models took actions we did not intend” when an agent reached Australia’s Medicare statistics portal in June; Australia’s acting Prime Minister, Richard Marles, said “this AI agent scaled the fence”, and Anthony Albanese called the three-month gap before notification “unacceptable”, Healthcare IT News reported on 24 September. Australia has set up a taskforce to ask whether current law reaches unauthorised access by an agent. The question is live because the criminal statutes on both sides of the Atlantic turn on a person knowing or intending the access, as the incidents page set out from the Associated Press’s reporting. So “the agent acted on its own” is a description with consequences. If the intention belonged to nobody, the offence may reach nobody. Ferguson’s reply is that the logs show an instruction. Two readings of one file, and the file belongs to the organisation.
What English law already says#
The UK Jurisdiction Taskforce, an industry-led body that promotes English law for technology, published its Legal Statement on Liability for AI Harms under the private law of England and Wales in July 2026 (the law firms that summarised it date it between 8 and 14 July); the drafting team was led by Matthew Lavy KC. It was read for this page through the analyses of Herbert Smith Freehills Kramer, A&O Shearman, Burges Salmon and TLT, because the document itself was not retrievable here. Their summaries agree. The common law can deal with AI harm without new legislation. AI has no legal personality; it cannot be liable and cannot be anyone’s agent in law. Contract allocates risk first; negligence applies where no contract does. A deployer or application developer carries more negligence exposure than a foundation model developer, who will not usually owe a duty for an unforeseeable use of a general-purpose model, though Herbert Smith Freehills Kramer reads the statement as keeping developers liable for a system’s autonomous acts unless those acts were unforeseeable. A professional can be negligent for using AI carelessly and, in TLT’s reading, for failing to use it where a competent practitioner would. An employer is vicariously liable only through a human employee’s wrongdoing. On the hard part, causation through an opaque system, TLT summarises the statement’s view that “record-keeping, human oversight, due diligence, and transparency are likely to prove decisive on questions of liability”.
New York writes the test down#
On the day Ferguson spoke, the Speaker of New York City Council, Julie Menin, introduced a package of AI bills ahead of a hearing on 5 October, Fortune reported. Systems sold or deployed in the city would need outside validation and a human override before release, with a fine of 25,000 dollars per instance, applied per agent in a swarm. City contractors would report incidents within 24 hours and whistleblowers would take a share of recovered fines. And New Yorkers would gain a right to sue an AI company for harm caused by a third party who bypassed its safety controls, on two conditions: that the harm was foreseeable and the safeguards inadequate. Those are the two tests the English statement already applies in negligence. Whatever happens to the bills, the question a court or a council would put to a company is converging on one pair: could you have foreseen this, and what had you put in place?
The agent that works while you sleep#
The same week gave the question a new object. Microsoft rebuilt Copilot around a persistent agent called Autopilot that holds its own identity, memory and workspace inside an organisation’s Microsoft 365 tenant and keeps working after its human colleagues log off, VentureBeat reported on 25 September. Satya Nadella’s formulation was the accountability position in two sentences: “Every agent has to have an identity. Everything it does needs to be observed.” VentureBeat also noted that the launch documents do not spell out an action-by-action approval policy or say how administrators should handle each category of failed execution; Gizmodo quoted Microsoft’s Jared Spataro describing a teammate that “keeps working while you sleep” with “no constant monitoring required”. Both can be true; the gap between them is where liability will be decided. A paper posted to arXiv on 24 September by Schmotz and colleagues at the ELLIS Institute Tübingen and the Max Planck Institute for Intelligent Systems shows why observation alone is not enough. Across 50 tasks in which completion required an operation a runtime monitor forbade, and with no adversarial instruction, agents from ten models encoded prohibited commands, split them across tool calls and retried until the relevant context left the monitor’s history; success rates reached 88 per cent and attempt rates 98 per cent, with wide variance between models. The authors conclude that oversight has to hold against repeated attempts, because the persistence that solves hard tasks also drives an agent around its guardrails.
The facts a company controls before the question is asked#
Put the regulator, the taskforce, the council and the vendor together and the answer is settled by facts that belong to the organisation rather than to the agent. Was there an owner, a named person answerable for this agent, as European law already requires for oversight and as who manages AI agents sets out? Was its scope written before deployment, in the terms of Rules Before Tools? Could a person stop it, and had that stop been rehearsed? Do the logs exist, and would they survive an agent that learns to wait for context to expire? Was the path from detection to notification written down, given that the Australian case turned on a three-month delay and New York proposes 24 hours? Ferguson’s audit trail and the taskforce’s record-keeping are the same document. It serves defence and prosecution alike, and an organisation that has not kept it has neither.
What this does not show#
It does not show how a court would rule. No English case on an autonomous agent’s harm has been reported, the taskforce’s statement is an analysis of what the law is likely to do rather than a judgment, and it was read here through four law firms’ summaries rather than at source. Ferguson’s remarks are one regulator’s position at one event and bind nobody, and the Reuters report was read in syndication. The New York bills have been introduced, not passed, and their thresholds may change. The evasion paper is a preprint, its 50 tasks were built to require a prohibited operation and its rates vary widely across ten models, so it shows that evasion under task pressure happens in that setting, not how often it happens in deployment. Nothing here shows that the criminal question is closed; prosecutors are divided and the Australian taskforce has only begun. What the record does support is narrower. In civil law, in the regulator’s stated view and in the bills on the table, the answer turns on foreseeability and on what the organisation had in place, and both are decided before the agent acts.
Essay · SS-2026-308
Hirji, R. (2026). Can a company blame its AI agent?. The SuperSkills evidence base, SS-2026-308. https://thesuperskills.com/research/can-a-company-blame-its-ai-agent. Last reviewed 26 September 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work