CompanyScope
by Janus Compliance

AI Agent Incident Register

Who is liable when an AI agent causes harm?

It depends on who made the choice that failed, and the public record now lets that be measured. Across the 12 incidents analysed in the AI Agent Incident Register as at 2026-09-17, the organisation that deployed the agent carried the liability in 5, the vendor carried it in 4, and it was shared across the chain in 3. Courts and regulators have so far declined to treat the agent as a separate actor, so the answer is always a person or a company, and the question is which one.

Most commentary answers this question with "the deployer". On the register's figures that is the most common answer and it is wrong in 7 of 12 cases. The sections below give the three answers, what each rests on, and the entries that carry it. Every entry is a legal analysis of public facts with primary sources, written by Michael K. Onyekwere, CIPP/E. Nothing here is legal advice.

Deployer-carried: 5 of 12

The organisation that put the agent in front of the world answers for what it did. A tribunal held Air Canada to a refund policy its chatbot invented, and rejected the suggestion that the chatbot was a separate legal entity responsible for its own actions. A UK court dealt with lawyers who filed case law an AI had fabricated. Italy's data protection authority fined the operators of two chatbots. The Ninth Circuit held that when a user directs an AI agent to act on a website, it is the user who accesses that site under the Computer Fraud and Abuse Act, and described the agent as a tool. The common thread is a party that chose to rely on the agent's output, or to point it at the world, without the check that would have caught the failure.

Vendor-borne: 4 of 12

The gravity moves upstream where the defect and the fix live entirely in the product, or where the vendor itself operated the agent. A zero-click exfiltration path ran through Microsoft 365 Copilot with the customer unable to do anything about it. A drive-by pull request put a data-wiping prompt into Amazon's coding extension before it reached nearly a million installs. OpenAI's own evaluation models found a way out of a test sandbox and breached Hugging Face. Two sandbox flaws in Cursor's coding agent let a prompt injection reach full code execution. In each, the deployer was largely a bystander.

Shared across the chain: 3 of 12

Liability is shared when the fault propagates across parties who each made a choice. A coding agent deleted a production database during a code freeze, on a platform that auto-executed and for a customer who let it. Stolen credentials belonging to an AI chat agent opened more than 700 companies' Salesforce estates, through a supplier compromise the customers had no view of. Models from three labs attacked real companies from inside a test environment built by the same evaluation partner, where the labs chose the prompts and removed the safeguards and the partner left the machines online. In each, no single party could have prevented it alone, and no single party gets to point at the others.

The answer that does not work

"The AI did it" has now been tested and it fails. California Civil Code section 1714.46, in force from 1 January 2026, provides that in an action against a defendant who developed, modified or used artificial intelligence, it is not a defence that the AI autonomously caused the harm. It preserves comparative fault and every other defence, so it closes one door and leaves the apportionment open, which is the argument the shared entries are about. The Moffatt tribunal and the Ninth Circuit reached the same place through ordinary rules of attribution before any statute did. The analysis of the statute is in AIR-2026-012.

How the register decides

Each entry is tagged with a liability locus, deployer, shared or vendor, after a duty analysis on the public record: which legal duty the facts engaged, who owed it, and whose choice caused the failure. The Liability Crosswalk maps that allocation onto the OWASP Top 10 for Agentic Applications, the NIST AI RMF, Singapore's IMDA framework and the EU AI Act, and the failure-modes map gives the taxonomy. The method is on the methodology page. The counts on this page are computed from the live corpus and change as entries are published. The feed at /api/register carries the locus for every entry, CC BY 4.0.

Cite this page as: Onyekwere, Michael K., "Who is liable when an AI agent causes harm?", AI Agent Incident Register, CompanyScope, https://companyscope.io/register/who-is-liable-when-an-ai-agent-causes-harm, as at 2026-09-17.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe - free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.