AI Ethiek & Governance

AI agent liability: who is liable when an AI agent causes harm?

Geert Haisma

An AI agent can never be liable itself: liability always rests with a person or organisation. There is no separate EU law on AI liability, because the proposal was withdrawn in 2025. For personal injury and private property damage caused by software placed on the market after 9 December 2026, the manufacturer is liable without fault; for business losses, your client will usually hold you, the deployer, to account through contract or tort.

Man met beide handen tegen zijn gezicht en gebogen hoofd, over wie witte binaire nullen en enen heen vallen

In short

  • An AI agent is not a legal person. The question is always which person or organisation is liable.
  • The EU's AI Liability Directive was withdrawn (Official Journal, 6 October 2025). There is no separate EU regime for harm caused by AI.
  • The revised Product Liability Directive (EU) 2024/2853 explicitly treats software as a product. It applies to products placed on the market or put into service after 9 December 2026.
  • That directive only covers harm to natural persons: personal injury, damage to private property and loss of private data. Purely commercial losses fall outside it.
  • Commercial losses are a matter of national contract and tort law. In the Netherlands that means Articles 6:74 and 6:162 of the Civil Code. Whoever can show what the agent did, and who approved it, is in the strongest position.

Who is liable when an AI agent causes harm?

AI agent liability depends on two questions: what kind of harm occurred, and what is the injured party's relationship with you?

An AI agent is software that takes steps on its own. It looks things up, places an order, sends a message or changes a record. When that goes wrong, the injured party looks for someone to pay. That is never the agent itself.

Three roles keep coming back:

  • The manufacturer or provider. Whoever develops the software or places it on the market under its own name. The AI Act calls this the provider; product liability law calls it the manufacturer.
  • The deployer. The organisation that uses the agent under its own authority. This is the AI Act's term.
  • The injured party. Your client, a third party without a contract, or a consumer.

Is there an EU law on AI agent liability in 2026?

No. The European Commission proposed an AI Liability Directive in 2022, but announced its withdrawal in the February 2025 work programme because no agreement was in sight. It left open whether a new proposal or a different approach will follow. The withdrawal was published in the Official Journal on 6 October 2025 (C/2025/5423).

What does change is product liability. The revised directive (EU) 2024/2853 treats software, and therefore AI systems, as products. Alongside it, ordinary national contract and tort law keeps applying. The AI Act mainly governs what a system must do before and while it is used; it does not set rules on compensation.

Who is liable in which scenario?

This overview gives the main picture under EU law, with Dutch law as the national example. Other member states have their own contract and tort rules. It does not replace legal advice on a specific case.

ScenarioWho is liableLegal basisWhat the injured party must prove
The agent causes personal injury, or damage to the private property or private data of a natural personThe manufacturer of the software, including one that developed it for its own use. If the manufacturer is outside the EU, also the importer or authorised representativeProduct liability, Directive (EU) 2024/2853defect, damage and causation; no fault needed. Courts can presume defect or causation
The defect sits in a component, such as the language model or a connected serviceThe manufacturer of the end product, and also the maker of the defective component; they are jointly and severally liablesame, Articles 8 and 12same
You substantially modify the agent and then put it into serviceYou, because you are then treated as the manufacturerArticle 8(2) of the directive; for high-risk AI also Article 25 AI Actsame
The agent makes a mistake in work for your client, such as a wrong order or incorrect adviceYou, towards your client. You may then seek recourse against your vendor, as far as your contract allowsBreach of contract (in the Netherlands: Article 6:74 Civil Code)a failure in performance attributable to you, and loss
The agent harms a third party you have no contract with, for example through an inaccurate publication or discriminatory screeningYou, if the act can be attributed to youTort (in the Netherlands: Article 6:162 Civil Code); for personal data also Article 82 GDPRwrongfulness, attribution, damage and causation
A provider or deployer of high-risk AI fails to comply with the AI ActThe party that breaches the obligationAI Act: supervision and fines. In civil cases the breach can count towards a defect or wrongfulnessdepends on the legal basis

What changes on 9 December 2026?

By that date the new Product Liability Directive must be transposed into national law. It applies to products placed on the market or put into service after that date. Five points matter for AI:

  1. Software is a product. The directive names software explicitly (Article 4). According to its recitals this includes AI systems and software supplied as a service in the cloud. Providers of AI systems are treated as manufacturers.
  2. Building for your own use makes you a manufacturer. An organisation that develops an agent itself and puts it into service falls within the definition (Article 4, point 10).
  3. Learning and updates count. Whether a product is defective depends partly on its ability to keep learning after it is placed on the market (Article 7). A manufacturer cannot argue that "the defect arose later" when the defect comes from a software update, a missing security update or a substantial modification within its control (Article 11(2)).
  4. Proof gets easier. Courts can order the disclosure of evidence (Article 9). Where technical complexity makes proof excessively difficult, they can presume a defect or causation (Article 10).
  5. No contracting out. Towards the injured person, liability cannot be limited or excluded by contract (Article 15).

In the Netherlands the directive will be implemented in the Civil Code through bill 36906 (Implementatiewet richtlijn herziening productaansprakelijkheid). The bill was submitted on 2 March 2026. On 2 October 2026 it had not yet been passed by the House of Representatives.

Why are business losses outside product liability?

The directive protects natural persons and covers only three types of damage: death and personal injury, damage to property not used exclusively for professional purposes, and destruction or corruption of data not used for professional purposes (Article 6). Pure economic loss, privacy infringements or discrimination do not by themselves trigger liability under the directive.

Yet most mistakes an agent makes in an office cause exactly that kind of commercial loss: a wrong order, a missed deadline, incorrect advice. Ordinary rules apply to those, illustrated here with Dutch law:

  • Towards your client: the contract. Every attributable failure in performance creates a duty to compensate (Article 6:74 Civil Code). Dutch law has rules on auxiliary persons (Article 6:76) and on unsuitable auxiliary objects (Article 6:77). An agent is not a person, and whether software counts as an "object" is not settled. The idea behind those rules is clear, though: whoever chooses a tool generally bears the risk that it turns out to be unsuitable.
  • Towards third parties: tort. Anyone who wrongfully causes harm to another must compensate it if the act can be attributed to them (Article 6:162 Civil Code). Attribution is possible without fault, when the cause is at your risk by law or by generally accepted views.
  • Towards your vendor: your own contract. Between businesses, limitations of liability are common. Check what your vendor does and does not guarantee before you let the agent work for your clients.

What does the AI Act require from organisations deploying AI agents?

The AI Act does not regulate compensation. It does define the care you are expected to take, and that matters when something goes wrong.

  • For everyone: take measures that support the AI literacy of your staff (Article 4). For AI that interacts with people or generates content, transparency rules apply to providers and in some cases to deployers too (Article 50). More in Article 50 of the AI Act and AI literacy under the EU AI Act.
  • For high-risk AI: use the system according to its instructions, assign human oversight to people with the right competence and authority, monitor its operation and keep the logs for at least six months (Article 26). Whether an agent is high-risk depends on its purpose. Annex III lists, among others, recruitment and selection, creditworthiness assessment and access to essential services.
  • Watch the role switch: whoever puts their name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk, becomes its provider (Article 25).

Following the July 2026 amendment, the requirements for high-risk AI under Annex III apply from 2 December 2027. For systems under Annex I the date is 2 August 2028 (Regulation (EU) 2026/1744).

How can you limit the liability risk of AI agents?

Whether a case falls under product liability or ordinary law, the question is always whether you can show what the agent did and why. This checklist helps:

  • Define what the agent may do: which systems, which actions and up to what amount.
  • Have a person approve every action that changes, orders or sends something.
  • Log every step: the question, the model, the sources consulted, the action and who approved it.
  • Check your contracts in both directions: what do you promise your client, and what does your vendor guarantee you?
  • Do not substantially modify an agent without realising that this can make you its manufacturer or provider.
  • Ask your insurer whether your professional or general liability policy covers harm caused by AI.
  • Keep a register of the AI systems you use and of incidents involving them.

How we work at Prudai

Three examples of how we built human control and record-keeping into our software:

  • Into the register only after approval. In IRMA, AI proposals for risks, controls, process steps and draft policy only enter the register after a staff member has approved them. Every approved change is in the audit log. AI proposals are off by default.
  • Confirm first, then write back. ZIA can write back exactly one thing to the Nedap ONS care record system, a daily report. ZIA always asks the care professional to confirm first, and the connection is off by default.
  • Recording AI use in one place. Besides risks and controls, IRMA has an algorithm register, an incident register and registers for vendors and contracts. That puts in one place which AI you use, from which vendor, and what went wrong.

We apply the same control to models. A model may only run in production with us once it passes our compliance gate: contractual EU processing, an acceptable chain of processors and no vendor-mandated data retention that cannot be switched off, such as the 30 days Anthropic requires for Claude Fable. For how generative AI works under the hood, read what is generative AI?

For specialists

  • Withdrawal of the AILD. Proposal COM(2022) 496, withdrawn through the list in Official Journal C/2025/5423 of 6 October 2025. The reason is given in Annex IV to the 2025 work programme (COM(2025) 45): no foreseeable agreement; the Commission will assess whether another proposal or another approach is needed.
  • Scope of Directive 2024/2853. Article 2(1): products placed on the market or put into service after 9 December 2026. Article 2(2): free and open-source software outside a commercial activity is excluded. Article 2(4): contractual and other liability grounds remain. Article 21: Directive 85/374/EEC keeps applying to products placed on the market earlier.
  • Definitions. Article 4(9): putting into service is the first use in the EU in the course of a commercial activity. Recital 13: information is not a product, so the content of digital files and mere source code fall outside. Providers of AI systems within the meaning of the AI Act are treated as manufacturers.
  • Defect and proof. Article 7(2)(f) takes relevant safety requirements into account, including cybersecurity. Article 10(2): presumption of defect where evidence is not disclosed, where mandatory safety requirements are breached, or in case of an obvious malfunction.
  • Defences and time limits. Article 11(1)(e): development risk defence; member states may restrict it (Article 18). Article 12(2): no recourse against a micro or small software supplier where this was waived by contract. Limitation period three years (Article 16); expiry after ten years, or 25 years for latent personal injury (Article 17).
  • Dutch transposition. Bill 36906 inserts Article 6:184a into the Civil Code, with a definition of product that names software, and rewrites Articles 6:185 and 6:187 among others.
  • AI Act after Regulation (EU) 2026/1744. In force since 27 July 2026. High-risk under Annex III: 2 December 2027. Annex I: 2 August 2028. Article 50(2) for systems placed on the market before 2 August 2026: 2 December 2026.

Frequently asked questions

Can an AI agent itself be held liable?

No. An AI agent is not a person or legal entity and has no assets. Liability always rests with a person or organisation: the manufacturer, the provider or the organisation that deploys the agent.

What is the liability risk of deploying autonomous agents?

Mainly contractual liability towards your clients and tort liability towards third parties, for business losses. If you build the agent yourself or substantially modify it, product liability for personal injury and private damage comes on top. The more the agent may do without a person's approval, the harder it becomes to show that you took due care.

Am I liable if my vendor's software makes a mistake?

Towards your own client, usually yes: you accepted the assignment and chose the tool. You can then try to recover the loss from your vendor, as far as your contract allows. For personal injury and private property damage suffered by natural persons, the injured party can also claim from the manufacturer.

Can a vendor exclude product liability in its terms and conditions?

Not towards the injured person: the directive prohibits that (Article 15). Between businesses, agreements on recourse and limitation of liability remain possible.

Does my insurance cover harm caused by AI agents?

That varies by policy. Ask your insurer explicitly whether harm caused by the use of AI is covered by your professional or general liability policy, and get the answer in writing.

Sources

Want to know how to record your AI use in a way you can demonstrate, with an algorithm register, incidents and vendors in one place? See IRMA (in Dutch) or contact us.

Updated on 2 October 2026

Photo: geralt via Pixabay

AI ActAgentic AIAI in organizationsSovereign AI

Geert Haisma

Director

Geert Haisma is the co-founder and director of Prudai, an AI specialist that supports organizations in securely and custom-deploying generative AI for improved decision-making and process automation. With a background in public administration and years of experience in making organizations more successful, Haisma is the driving force behind Prudai's strategic and substantive direction.