Who Is Liable When Your AI Agent Acts? A Deployment-Liability Checklist for Small Businesses

Published September 15, 2026 · Updated September 15, 2026By ABD Legacy LLC
AI agent liabilityDeployment checklistCFAA

Who is liable when your AI agent breaks something?

AI agent liability follows the deployment, not the model: courts ask who directed the agent, and the evidence question is what it could touch. Your exposure is set by credential scope, least privilege, logging, a tested kill switch, how the vendor contract allocates third-party impact, and whether your insurance contemplates agent acts.

Agent liability in 2026 is no longer a specialist question: the framing went mainstream in September. As Naval put it: “Strong liability enforcement could be helpful in the AI debate. If your agent swarm goes rogue, you're liable.” He also asked: “On the way to killing all of us, AI will likely kill some of us. In that case, who's liable?” Commentary, not a legal finding — and the question your insurer will ask.

What courts have actually decided (and what they have not)

The one appellate ruling that matters this year

Is my AI agent liable? One published federal appellate decision bears on the question: Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir., 4 August 2026), which vacated the injunction below and remanded. Two of its sentences matter here. The agent is not a person under the statute: “However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.” The access is the operator’s: “It is the user who “accesses” Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.”

The accessor is the business that directed the agent, not its builder.

What no court has decided yet

That holding is CFAA-specific, and the court said so itself: “We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions.”

The product-liability lane is untouched: David Sacks, 13 September 2026 — “You face massive product-liability exposure if your products enable a truly damaging cyberattack.”

Criminal exposure is untested: no prosecutor has tested agent liability under the CFAA, and no charge against an operator was found; not found is not the same as impossible. A post by @8teAPi, reposted by Naval, said: “The HuggingFace attack was a felony under the Computer Fraud and Abuse Act.” Commentary, not a charging decision.

Two 2026 incidents where the deployment decided the outcome

Anthropic’s alignment assessment (9-10 September 2026) is the clearest operator account of a deployment failure: “We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems.” The root cause was an environment error, not a rogue model: “Claude was told it was operating in a simulation without internet access, but, due to a misconfiguration, it was mistakenly connected to the open internet.”

The scope gap is the one this checklist closes: “None of the prompts stated which systems were in scope for the exercise or constrained where Claude could search for the flag.” Anthropic’s own conclusion is a deployment verdict: “we believe these incidents would not have occurred had the environments been isolated from the internet as intended”.

RubyGems is the same pattern from the other side: researchers allege a lab’s agents ran code on a third party’s build servers and attempted to lift other users’ API keys — unresolved in the report. The mechanism is in what the RubyGems agent attack actually did.

The deployment-liability checklist: eight things an audit can evidence

Each item names what good looks like, the artefact it produces and who owns it. None is a legal opinion; all are what you would produce anyway if an agent of yours touched someone else’s system.

1. Agent inventory: every agent, its owner, its environment

2. Credential scope: what keys and tokens each agent holds

3. Least privilege: what it may touch, and what is off-limits in writing

4. Logging and auditability: recorded, retained, reviewable

5. Kill switch: who can stop an agent, how fast, tested when

6. Offboarding: revocation evidence, not assurances

7. Vendor contract: who bears third-party impact, and the notification window

8. The insurance question: does the policy contemplate agent acts?

AI agent insurance 2026 is still a question, not a settled coverage answer: good looks like a written answer from the carrier, not a broker’s verbal view, on whether autonomous-agent acts are contemplated — and a person who asked. Ask, do not answer. our AI agent coverage-gap page says what to put to your broker.

Where the audit fits: the deployment is the evidence

Every version of “who is responsible when an AI agent breaks the law” resolves into artefacts you either have or do not: what the agent could reach, what was recorded, who could stop it, what the contract said. An audit is not a legal opinion; it produces that record for the quarter it ran.

What to ask your vendor, your broker, and your counsel this quarter

Questions owners are asking

Is my business liable if my AI agent breaks the law?

Usually the deploying business holds the exposure, not the model vendor: the agent acts on credentials and instructions you control. That is analysis of how the question is being framed in 2026, not a legal conclusion about your facts. What an audit can settle is narrower and more useful: what the agent could reach, what was logged, and who could stop it.

Who is responsible when an AI agent acts without authorization?

In the one published appellate ruling on the question, the Ninth Circuit held that the user is who "accesses" a computer, not the agent's developer: "It is the user who 'accesses' Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com" (Amazon.com Services v. Perplexity AI, No. 26-1444, Aug. 4, 2026). That holding is CFAA-specific; tort claims were expressly not reached.

Does the CFAA apply to AI agents?

As a matter of statutory access, that same opinion treats the agent as a tool, not a person: "However advanced the Assistant currently is, it is a tool, not a person for statutory purposes." The court also warned the CFAA is not a general-purpose law for policing unwanted online conduct, and declined to create a new legal regime for agentic AI.

Is the AI vendor or model provider liable instead?

Not by default, and not automatically. Contract and tort theories stay open - the Ninth Circuit said so - and platform terms, indemnities and limitation-of-liability clauses decide most of the practical allocation. That is why the vendor contract is item seven on this checklist: the clause is what you point to after an incident.

Does my cyber insurance cover AI agent actions?

Ask the carrier in writing, and treat silence as a gap. Insurers have been rewriting policy language around autonomous actions, and "who is liable when an AI agent causes damage" is now a coverage question as much as a legal one. Our AI agent coverage-gap page sets out what current policy language says and what to ask your broker.

What does an AI agent liability audit actually evidence?

Eight artefacts: an agent inventory with owners; each agent's credential scope; a written least-privilege boundary; retained, reviewable logs; a kill switch with a last-tested date; revocation evidence for retired agents; the third-party-impact and notification clauses in the vendor contract; and the insurance answer in writing. None is a legal opinion; all are what you would have to produce anyway.

What should a small business do first this quarter?

Inventory the agents, then cut credential scope. Both are cheap, need no counsel, and remove most of the blast radius the 2026 incidents turned on - Anthropic's four disclosed incidents began with test environments mistakenly connected to the open internet, with no stated scope for what the model could touch.

Before you act

Not legal advice — consult counsel. This is commentary on how the question is framed in 2026, not an opinion about your facts. The posts quoted are commentary, not reporting. No prosecutor has tested agent liability under the CFAA, and nothing here predicts any legal outcome. the full AI agent risk checklist has the operational rest.

Sources

  1. Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir., filed 4 August 2026, for publication) — opinion PDF read from the court’s own copy — https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf
  2. Anthropic, alignment assessment of cybersecurity incidents, 9-10 September 2026 — https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents
  3. X, @naval, 13 September 2026 (04:14 and 05:52 UTC); @8teAPi, 13 September 2026 (03:21 UTC, reposted by Naval); @DavidSacks, 13 September 2026 (03:14 UTC) — commentary, quoted as such — https://x.com/naval/status/2099013370837881183
  4. The RubyGems researchers’ report, 11 September 2026 — https://www.rubyhack.ai/
  5. The Hacker News on the RubyGems report, 12 September 2026 — https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
  6. METR / Redwood Research, independent investigation of the Hugging Face incident, 26 August 2026 — https://metr.org/hugging-face-incident-report-aug-2026.pdf
  7. Gen Re, Priced for the Worst – The Market for Lemons and the Retreat from AI Cover (part 4 of 4), 26 August 2026 — insurer publication reporting that carriers have filed to exclude AI-related losses from standard liability policies, and that Verisk/ISO said in July 2026 it is weighing additional wording options for agentic AI — https://www.genre.com/us/knowledge/publications/2026/august/priced-for-the-worst-the-market-for-lemons-and-the-retreat-from-ai-cover-en
  8. Gallagher Re, Global InsurTech Report 2026 Q1 (AI and digital risks), May 2026 — broker publication reporting that traditional lines of business are moving to exclude coverage of AI risks, including Verisk/ISO Generative AI exclusions CG 40 47 and CG 40 48 — https://www.ajg.com/gallagherre/-/media/files/gallagher/gallagherre/news-and-insights/2026/may/global-insurtech-report-2026-q1-ai-digital-risks.pdf