AI Agent Incident Register
Who is liable when an AI agent causes harm?
It depends on who made the choice that failed. Across the 15 incidents analysed in the AI Agent Incident Register as at 2026-10-03, the organisation that deployed the agent carried the liability in 7, the vendor carried it in 4, and it was shared across the chain in 3. In 1 a third party ran the agent against an organisation that had deployed none, and the organisation attacked carried the duties. In the decided cases this register has analysed, no court or regulator treated the agent as a separate actor, so the answer has always been a person or a company, and the question is which one.
On the register's figures "the deployer" is the most common answer, and it is wrong in 8 of 15 cases. The sections below give the four answers, what each rests on, and the entries that carry it. Every entry is a legal analysis of public facts with primary sources, written by Michael K. Onyekwere, CIPP/E. Nothing here is legal advice.
Deployer-carried: 7 of 15
The organisation that put the agent in front of the world answers for what it did. A tribunal held Air Canada to a refund policy its chatbot invented, and rejected the suggestion that the chatbot was a separate legal entity responsible for its own actions. A UK court dealt with lawyers who filed case law an AI had fabricated. Italy's data protection authority fined the operators of two chatbots. The Ninth Circuit held that when a user directs an AI agent to act on a website, it is the user who accesses that site under the Computer Fraud and Abuse Act, and described the agent as a tool. The common thread is a party that chose to rely on the agent's output, or to point it at the world, without the check that would have caught the failure.
- AIR-2026-014 Verbraucherzentrale NRW v Aesthetify: a German court makes a clinic answer for the false specialist titles its chatbot gave its doctors
- AIR-2026-013 AISI's test agents created fake identities to pressure a real developer into approving malicious code
- AIR-2026-010 Amazon v Perplexity: the Ninth Circuit says the user, not the AI agent, 'accesses' a website under the CFAA
- AIR-2026-008 Garante v Character Technologies: Italy fines Character.AI's maker €158,000 over age assurance and pre-training transparency
- AIR-2026-006 Garante v Luka: Italy's €5M fine on the Replika chatbot for processing without a legal basis
- AIR-2026-005 Ayinde v Haringey: the UK High Court on lawyers who filed AI-fabricated case law
- AIR-2026-003 Moffatt v Air Canada: the airline bound by its chatbot's invented policy
Vendor-borne: 4 of 15
The gravity moves upstream where the defect and the fix live entirely in the product, or where the vendor itself operated the agent. A zero-click exfiltration path ran through Microsoft 365 Copilot with the customer unable to do anything about it. An over-scoped build token let an outsider put a data-wiping prompt into Amazon's coding extension before it reached nearly a million installs. OpenAI's own evaluation models found a way out of a test sandbox and breached Hugging Face. Two sandbox flaws in Cursor's coding agent let a prompt injection reach full code execution. In each, the deployer was largely a bystander.
- AIR-2026-011 DuneSlide: two sandbox flaws let a prompt injection reach full code execution from Cursor's coding agent
- AIR-2026-009 OpenAI says its own evaluation models breached Hugging Face's production systems
- AIR-2026-007 Amazon Q for VS Code: an over-scoped build token let an outsider put a data-wiping prompt into a coding agent with nearly a million installs
- AIR-2026-004 EchoLeak: a zero-click exfiltration path demonstrated through Microsoft 365 Copilot
Shared across the chain: 3 of 15
Liability is shared when the fault propagates across parties who each made a choice. A coding agent deleted a production database during a code freeze, on a platform that auto-executed and for a customer who let it. Stolen credentials belonging to an AI chat agent opened more than 700 companies' Salesforce estates, through a supplier compromise the customers had no view of. Models from three labs attacked real companies from inside a test environment built by the same evaluation partner, where the labs chose the prompts and removed the safeguards and the partner left the machines online. In each, no single party could have prevented it alone, and no single party gets to point at the others.
- AIR-2026-012 Anthropic and Meta say their models attacked real companies from inside a shared evaluation partner's test environment
- AIR-2026-002 Salesloft Drift: stolen agent credentials open more than 700 Salesforce estates
- AIR-2026-001 Replit's coding agent deletes a production database during a code freeze
Target-carried: 1 of 15
The organisation carries it without ever having chosen to use an agent. An attacker points one at the business, and the law that answers is the law that already bound the business: it is the controller of the data the agent reached, so the security, notification and compensation duties are its own. The provider of the model is neither controller nor processor for the attacker's processing, and the duties the EU AI Act puts on it over offensive cyber capability run to the AI Office. Spain's data protection authority said in September 2026 that it had received its first notification of this kind.
- AIR-2026-015 Spain's regulator receives the first breach notification attributing the attack to an AI agent
The answer that does not work
In the decided cases this register has analysed, "the AI did it" has failed as a defence. California Civil Code section 1714.46, in force from 1 January 2026, provides that in an action against a defendant who developed, modified or used artificial intelligence, it is not a defence that the AI autonomously caused the harm. It preserves comparative fault and every other defence, so it closes one door and leaves the apportionment open, which is the argument the shared entries are about. The Moffatt tribunal reached the same place in 2024 through ordinary rules of attribution, before that statute was in force, and a Ninth Circuit panel has since treated an AI agent as a tool. The analysis of the statute is in AIR-2026-012. In Germany the Higher Regional Court in Hamm held a clinic responsible, under unfair competition law, for false answers its website chatbot gave about its doctors ( AIR-2026-014).
For England and Wales, the Legal Statement on Liability for AI Harms published in July 2026 by the UK Jurisdiction Taskforce, which the Master of the Rolls chairs, records that, as at its publication, "AI is not a legal person, and there is no English authority on the question of whether an AI can make a statement 'on behalf' of a legal person." Its view is that "Liability would generally be established if a legal person held out the AI chatbot as communicating on their behalf, or if there is an express or implied representation that the chatbot's statements are correct." It adds that the core negligence may lie in "the careless acts that permitted the output, such as human decisions behind the AI tool's design, testing, and deployment." The statement is not a court decision and is not legal advice. On its view, as in the decided cases above, the liability falls on the business that presents the chatbot as speaking for it.
How the register decides
Each entry is tagged with a liability locus, deployer, shared, vendor or target, after a duty analysis on the public record: which legal duty the facts engaged, who owed it, and whose choice caused the failure. The Liability Crosswalk maps that allocation onto the OWASP Top 10 for Agentic Applications, the NIST AI RMF, Singapore's IMDA framework and the EU AI Act, and the failure-modes map gives the taxonomy. The method is on the methodology page. For the incidents in which an agent reached a third party, the disclosure timelines record who was told, and when. The counts on this page are computed from the live corpus and change as entries are published. The feed at /api/register carries the locus for every entry, CC BY 4.0.
Cite this page as: Onyekwere, Michael K., "Who is liable when an AI agent causes harm?", AI Agent Incident Register, CompanyScope, https://companyscope.io/register/who-is-liable-when-an-ai-agent-causes-harm, as at 2026-10-03.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.