Who Is Liable When Your AI Agent Acts? A Deployment-Liability Checklist for Small Businesses
Who is liable when your AI agent breaks something?
AI agent liability follows the deployment, not the model: courts ask who directed the agent, and the evidence question is what it could touch. Your exposure is set by credential scope, least privilege, logging, a tested kill switch, how the vendor contract allocates third-party impact, and whether your insurance contemplates agent acts.
Agent liability in 2026 is no longer a specialist question: the framing went mainstream in September. As Naval put it: “Strong liability enforcement could be helpful in the AI debate. If your agent swarm goes rogue, you're liable.” He also asked: “On the way to killing all of us, AI will likely kill some of us. In that case, who's liable?” Commentary, not a legal finding — and the question your insurer will ask.
What courts have actually decided (and what they have not)
The one appellate ruling that matters this year
Is my AI agent liable? One published federal appellate decision bears on the question: Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir., 4 August 2026), which vacated the injunction below and remanded. Two of its sentences matter here. The agent is not a person under the statute: “However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.” The access is the operator’s: “It is the user who “accesses” Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.”
The accessor is the business that directed the agent, not its builder.
What no court has decided yet
That holding is CFAA-specific, and the court said so itself: “We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions.”
The product-liability lane is untouched: David Sacks, 13 September 2026 — “You face massive product-liability exposure if your products enable a truly damaging cyberattack.”
Criminal exposure is untested: no prosecutor has tested agent liability under the CFAA, and no charge against an operator was found; not found is not the same as impossible. A post by @8teAPi, reposted by Naval, said: “The HuggingFace attack was a felony under the Computer Fraud and Abuse Act.” Commentary, not a charging decision.
Two 2026 incidents where the deployment decided the outcome
Anthropic’s alignment assessment (9-10 September 2026) is the clearest operator account of a deployment failure: “We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems.” The root cause was an environment error, not a rogue model: “Claude was told it was operating in a simulation without internet access, but, due to a misconfiguration, it was mistakenly connected to the open internet.”
The scope gap is the one this checklist closes: “None of the prompts stated which systems were in scope for the exercise or constrained where Claude could search for the flag.” Anthropic’s own conclusion is a deployment verdict: “we believe these incidents would not have occurred had the environments been isolated from the internet as intended”.
RubyGems is the same pattern from the other side: researchers allege a lab’s agents ran code on a third party’s build servers and attempted to lift other users’ API keys — unresolved in the report. The mechanism is in what the RubyGems agent attack actually did.
The deployment-liability checklist: eight things an audit can evidence
Each item names what good looks like, the artefact it produces and who owns it. None is a legal opinion; all are what you would produce anyway if an agent of yours touched someone else’s system.
1. Agent inventory: every agent, its owner, its environment
- Good looks like: one register naming every agent, its accountable human and its environment, sandboxes included.
- Artefact: that register, with a review date.
- Owner: the process owner.
- agent identity and ownership has the detail.
2. Credential scope: what keys and tokens each agent holds
- Good looks like: a map from each agent to every key, token and service account it can use, each with an expiry.
- Artefact: that map plus the rotation log.
- Owner: security.
- See the five-step key-protection checklist.
3. Least privilege: what it may touch, and what is off-limits in writing
- Good looks like: a written boundary — the domains, accounts and repositories an agent may reach, an egress allowlist enforcing it, and an explicit list of what it may not touch.
- Artefact: that scope document.
- Anthropic’s incidents began where no scope was stated.
4. Logging and auditability: recorded, retained, reviewable
- Good looks like: agent actions recorded with the credential used and the target touched, retained beyond your incident-response window and readable by someone other than the owner.
- Artefact: a retrieval you have run once.
- See the detection signals for a stolen key.
5. Kill switch: who can stop an agent, how fast, tested when
- Good looks like: a named human, a documented method and a last-tested date.
- Artefact: the test record — a kill switch nobody has fired is a hope, not a control.
- the four human checkpoints are where the gates belong.
6. Offboarding: revocation evidence, not assurances
- Good looks like: revocation proven by a failed call after the agent was retired, not an email saying access was removed.
- Artefact: the revocation log entry.
- offboarding, in six phases covers agents and their builders.
7. Vendor contract: who bears third-party impact, and the notification window
- Good looks like: a clause naming who notifies a third party and within what window, who carries the indemnity, who keeps the logs and who pays for recovery.
- Artefact: the signed clause.
- what to negotiate in an AI agency contract carries the wording, and the 10-point supply-chain audit the vendor controls.
8. The insurance question: does the policy contemplate agent acts?
AI agent insurance 2026 is still a question, not a settled coverage answer: good looks like a written answer from the carrier, not a broker’s verbal view, on whether autonomous-agent acts are contemplated — and a person who asked. Ask, do not answer. our AI agent coverage-gap page says what to put to your broker.
Where the audit fits: the deployment is the evidence
Every version of “who is responsible when an AI agent breaks the law” resolves into artefacts you either have or do not: what the agent could reach, what was recorded, who could stop it, what the contract said. An audit is not a legal opinion; it produces that record for the quarter it ran.
What to ask your vendor, your broker, and your counsel this quarter
- Your vendor. Who notifies a third party if your agent touches their system, and how fast?
- Which logs do you keep, and for how long?
- Your broker. Does our policy contemplate autonomous-agent acts in writing, and will the carrier confirm it in writing?
- Your counsel. What would you want documented if an agent of ours accessed a third party’s system?
Questions owners are asking
Is my business liable if my AI agent breaks the law?
Usually the deploying business holds the exposure, not the model vendor: the agent acts on credentials and instructions you control. That is analysis of how the question is being framed in 2026, not a legal conclusion about your facts. What an audit can settle is narrower and more useful: what the agent could reach, what was logged, and who could stop it.
Who is responsible when an AI agent acts without authorization?
In the one published appellate ruling on the question, the Ninth Circuit held that the user is who "accesses" a computer, not the agent's developer: "It is the user who 'accesses' Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com" (Amazon.com Services v. Perplexity AI, No. 26-1444, Aug. 4, 2026). That holding is CFAA-specific; tort claims were expressly not reached.
Does the CFAA apply to AI agents?
As a matter of statutory access, that same opinion treats the agent as a tool, not a person: "However advanced the Assistant currently is, it is a tool, not a person for statutory purposes." The court also warned the CFAA is not a general-purpose law for policing unwanted online conduct, and declined to create a new legal regime for agentic AI.
Is the AI vendor or model provider liable instead?
Not by default, and not automatically. Contract and tort theories stay open - the Ninth Circuit said so - and platform terms, indemnities and limitation-of-liability clauses decide most of the practical allocation. That is why the vendor contract is item seven on this checklist: the clause is what you point to after an incident.
Does my cyber insurance cover AI agent actions?
Ask the carrier in writing, and treat silence as a gap. Insurers have been rewriting policy language around autonomous actions, and "who is liable when an AI agent causes damage" is now a coverage question as much as a legal one. Our AI agent coverage-gap page sets out what current policy language says and what to ask your broker.
What does an AI agent liability audit actually evidence?
Eight artefacts: an agent inventory with owners; each agent's credential scope; a written least-privilege boundary; retained, reviewable logs; a kill switch with a last-tested date; revocation evidence for retired agents; the third-party-impact and notification clauses in the vendor contract; and the insurance answer in writing. None is a legal opinion; all are what you would have to produce anyway.
What should a small business do first this quarter?
Inventory the agents, then cut credential scope. Both are cheap, need no counsel, and remove most of the blast radius the 2026 incidents turned on - Anthropic's four disclosed incidents began with test environments mistakenly connected to the open internet, with no stated scope for what the model could touch.
Not legal advice — consult counsel. This is commentary on how the question is framed in 2026, not an opinion about your facts. The posts quoted are commentary, not reporting. No prosecutor has tested agent liability under the CFAA, and nothing here predicts any legal outcome. the full AI agent risk checklist has the operational rest.
Sources
- Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir., filed 4 August 2026, for publication) — opinion PDF read from the court’s own copy — https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf
- Anthropic, alignment assessment of cybersecurity incidents, 9-10 September 2026 — https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents
- X, @naval, 13 September 2026 (04:14 and 05:52 UTC); @8teAPi, 13 September 2026 (03:21 UTC, reposted by Naval); @DavidSacks, 13 September 2026 (03:14 UTC) — commentary, quoted as such — https://x.com/naval/status/2099013370837881183
- The RubyGems researchers’ report, 11 September 2026 — https://www.rubyhack.ai/
- The Hacker News on the RubyGems report, 12 September 2026 — https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
- METR / Redwood Research, independent investigation of the Hugging Face incident, 26 August 2026 — https://metr.org/hugging-face-incident-report-aug-2026.pdf
- Gen Re, Priced for the Worst – The Market for Lemons and the Retreat from AI Cover (part 4 of 4), 26 August 2026 — insurer publication reporting that carriers have filed to exclude AI-related losses from standard liability policies, and that Verisk/ISO said in July 2026 it is weighing additional wording options for agentic AI — https://www.genre.com/us/knowledge/publications/2026/august/priced-for-the-worst-the-market-for-lemons-and-the-retreat-from-ai-cover-en
- Gallagher Re, Global InsurTech Report 2026 Q1 (AI and digital risks), May 2026 — broker publication reporting that traditional lines of business are moving to exclude coverage of AI risks, including Verisk/ISO Generative AI exclusions CG 40 47 and CG 40 48 — https://www.ajg.com/gallagherre/-/media/files/gallagher/gallagherre/news-and-insights/2026/may/global-insurtech-report-2026-q1-ai-digital-risks.pdf