AI Agent Incident Register
Who is liable when an AI agent causes harm?
It depends on who made the choice that failed, and the public record now lets that be measured. Across the 12 incidents analysed in the AI Agent Incident Register as at 2026-09-17, the organisation that deployed the agent carried the liability in 5, the vendor carried it in 4, and it was shared across the chain in 3. Courts and regulators have so far declined to treat the agent as a separate actor, so the answer is always a person or a company, and the question is which one.
Most commentary answers this question with "the deployer". On the register's figures that is the most common answer and it is wrong in 7 of 12 cases. The sections below give the three answers, what each rests on, and the entries that carry it. Every entry is a legal analysis of public facts with primary sources, written by Michael K. Onyekwere, CIPP/E. Nothing here is legal advice.
Deployer-carried: 5 of 12
The organisation that put the agent in front of the world answers for what it did. A tribunal held Air Canada to a refund policy its chatbot invented, and rejected the suggestion that the chatbot was a separate legal entity responsible for its own actions. A UK court dealt with lawyers who filed case law an AI had fabricated. Italy's data protection authority fined the operators of two chatbots. The Ninth Circuit held that when a user directs an AI agent to act on a website, it is the user who accesses that site under the Computer Fraud and Abuse Act, and described the agent as a tool. The common thread is a party that chose to rely on the agent's output, or to point it at the world, without the check that would have caught the failure.
- AIR-2026-010 Amazon v Perplexity: the Ninth Circuit says the user, not the AI agent, 'accesses' a website under the CFAA
- AIR-2026-008 Garante v Character Technologies: Italy fines Character.AI's maker €158,000 over age assurance and pre-training transparency
- AIR-2026-006 Garante v Luka: Italy's €5M fine on the Replika chatbot for processing without a legal basis
- AIR-2026-005 Ayinde v Haringey: the UK High Court on lawyers who filed AI-fabricated case law
- AIR-2026-003 Moffatt v Air Canada: the airline bound by its chatbot's invented policy
Vendor-borne: 4 of 12
The gravity moves upstream where the defect and the fix live entirely in the product, or where the vendor itself operated the agent. A zero-click exfiltration path ran through Microsoft 365 Copilot with the customer unable to do anything about it. A drive-by pull request put a data-wiping prompt into Amazon's coding extension before it reached nearly a million installs. OpenAI's own evaluation models found a way out of a test sandbox and breached Hugging Face. Two sandbox flaws in Cursor's coding agent let a prompt injection reach full code execution. In each, the deployer was largely a bystander.
- AIR-2026-011 DuneSlide: two sandbox flaws let a prompt injection reach full code execution from Cursor's coding agent
- AIR-2026-009 OpenAI says its own evaluation models breached Hugging Face's production systems
- AIR-2026-007 Amazon Q for VS Code: a drive-by pull request put a data-wiping prompt into a coding agent with nearly a million installs
- AIR-2026-004 EchoLeak: a zero-click exfiltration path demonstrated through Microsoft 365 Copilot
Shared across the chain: 3 of 12
Liability is shared when the fault propagates across parties who each made a choice. A coding agent deleted a production database during a code freeze, on a platform that auto-executed and for a customer who let it. Stolen credentials belonging to an AI chat agent opened more than 700 companies' Salesforce estates, through a supplier compromise the customers had no view of. Models from three labs attacked real companies from inside a test environment built by the same evaluation partner, where the labs chose the prompts and removed the safeguards and the partner left the machines online. In each, no single party could have prevented it alone, and no single party gets to point at the others.
- AIR-2026-012 Anthropic and Meta say their models attacked real companies from inside a shared evaluation partner's test environment
- AIR-2026-002 Salesloft Drift: stolen agent credentials open more than 700 Salesforce estates
- AIR-2026-001 Replit's coding agent deletes a production database during a code freeze
The answer that does not work
"The AI did it" has now been tested and it fails. California Civil Code section 1714.46, in force from 1 January 2026, provides that in an action against a defendant who developed, modified or used artificial intelligence, it is not a defence that the AI autonomously caused the harm. It preserves comparative fault and every other defence, so it closes one door and leaves the apportionment open, which is the argument the shared entries are about. The Moffatt tribunal and the Ninth Circuit reached the same place through ordinary rules of attribution before any statute did. The analysis of the statute is in AIR-2026-012.
How the register decides
Each entry is tagged with a liability locus, deployer, shared or vendor, after a duty analysis on the public record: which legal duty the facts engaged, who owed it, and whose choice caused the failure. The Liability Crosswalk maps that allocation onto the OWASP Top 10 for Agentic Applications, the NIST AI RMF, Singapore's IMDA framework and the EU AI Act, and the failure-modes map gives the taxonomy. The method is on the methodology page. The counts on this page are computed from the live corpus and change as entries are published. The feed at /api/register carries the locus for every entry, CC BY 4.0.
Cite this page as: Onyekwere, Michael K., "Who is liable when an AI agent causes harm?", AI Agent Incident Register, CompanyScope, https://companyscope.io/register/who-is-liable-when-an-ai-agent-causes-harm, as at 2026-09-17.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.