Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

Risk

Agentic AI Liability: Who Pays When an AI Agent Gets It Wrong

Updated 12 minute readBy Mayflower Specialty

A company that lets an AI agent act on its behalf is generally liable for what the agent does, as it is for any other automated system it runs. US electronic-transactions law recognizes contracts formed by software acting for a business, a Canadian tribunal has refused to treat a chatbot as responsible for its own conduct, and a model vendor's standard terms can cap its liability far below a likely loss. The exposure grows with the agent's authority, which is why transaction limits, approval gates and audit logs matter to liability and insurance alike.

What Is Agentic AI, and Why Does It Change the Liability?

Agentic AI is AI that carries out tasks rather than only answering questions, and it changes liability because its output is an action rather than text that a person reads first. A chatbot's wrong answer still needs a person to act on it, whereas an agent that sends the email, commits the code or releases the payment has acted before anyone notices the error.

Definition

Agentic AI

Agentic AI is an AI system that plans multi-step actions, uses external tools or software interfaces and works across sessions without a person approving each step. Because it acts rather than advises, the cost of its mistakes is set by the authority it has been given.

Agents are still at an early stage in most companies: Stanford's 2026 AI Index reports that 88% of surveyed organizations used AI in 2025, but that “AI agent deployment was in the single digits across nearly all business functions” [1]. Many liability policies now in force were written before their policyholders ran any agents, so it is best to set controls while agent use is still small enough to inventory.

Who Is Liable When an AI Agent Makes a Mistake?

The company that deployed an AI agent is generally liable for the agent's mistakes. There are three reasons for this: contract law recognizes commitments made through a business's electronic agent, agency and tort law treat software as the company's instrument, and vendor contracts often push the remaining risk back onto the customer.

Can an AI Agent's Contract Bind the Company?

An AI agent can bind the company to a contract, because the Uniform Electronic Transactions Act (UETA), which every state except New York had adopted in some form by 2021 [2], has long recognized contracts made by software and calls such software an “electronic agent”.

Definition

Electronic agent

An electronic agent is, in the words of California's enactment of the Uniform Electronic Transactions Act, “a computer program or an electronic or other automated means used independently to initiate an action or respond to electronic records or performances in whole or in part, without review by an individual.” [3] An AI agent that places orders, accepts terms or makes commitments to customers is likely to fit that description.

UETA provides that “a contract may be formed by the interaction of electronic agents of the parties, even if no individual was aware of or reviewed the electronic agents' actions or the resulting terms and agreements” [4]. The federal E-SIGN Act similarly prevents such contracts from being denied legal effect “so long as the action of any such electronic agent is legally attributable to the person to be bound” [5]. UETA leaves the terms of such a contract to the substantive law that applies to it [4], so a dispute over an agent-made commitment is likely to turn on attribution and on ordinary contract defenses such as mistake, and an agent that the company configured and put in front of its customers is likely to be difficult to disown.

UETA also protects the other side of the transaction: an individual who makes a mistake while dealing with a company's electronic agent may avoid its effect if the agent “did not provide an opportunity for the prevention or correction of the error” and the individual promptly gives notice, returns or destroys anything received and has not benefited from it [6]. A customer-facing agent should therefore confirm any binding action with the customer before completing it, or the customer may be able to undo it.

An AI agent is not a legal agent in its own right and has no legal identity that could absorb the blame. As a Duke Law & Technology Review article summarized it, the Restatement (Third) of Agency “views computer programs as mere instrumentalities of the using person and thus not a separate person capable of being a principal or agent” [7].

Moffatt v. Air Canada applied the same idea to AI. On February 14th 2024 a British Columbia tribunal held Air Canada liable for its chatbot's wrong advice about bereavement fares, rejecting the argument that the chatbot was “a separate legal entity that is responsible for its own actions” and holding that “it makes no difference whether the information comes from a static page or a chatbot” [8][9]. The ruling came from a small-claims tribunal rather than an appellate court, but its reasoning would seem to apply with at least as much force to agents that act rather than advise, as our guide to AI hallucination liability explains.

Delegating a task to an AI vendor is likely to add a defendant rather than replace one. On July 12th 2024 a federal court in California let a job applicant's discrimination claims proceed against Workday on the theory that employers using its AI screening tools had delegated hiring functions to it, making it their “agent”. The court warned that the opposite rule “would allow companies to escape liability for hiring decisions by saying that function has been handed over to someone else (or here, artificial intelligence)” [10]. That decision only allowed the claims to go forward at the pleading stage, before any finding of liability, and the case was still being litigated in 2026 [19].

Can the Company Pass the Loss to the AI Vendor?

A company may recover only a small part of an agent's loss from its AI vendor, because vendor contracts can sharply limit what the supplier will pay. Anthropic's Commercial Terms of Service (effective June 17th 2025), for instance, make the customer responsible for evaluating whether outputs are appropriate, exclude consequential losses such as lost profits and lost data, and cap the remaining liability at the fees paid in the previous 12 months, indemnities aside [11]. Under terms like these, recovery from a vendor would cover little of a serious agent failure, so the safest planning assumption is that the company owns every action its agents take.

How Do AI Agent Failures Turn Into Claims?

An AI agent failure turns into a claim along a path set by the agent's authority: what the agent can reach determines who is harmed, and who is harmed determines whether the loss arrives as a client's claim, a counterparty dispute or a write-off.

Read-Only, Write-Capable and Financially Authorized Agents

Mayflower Specialty's supplemental application sorts agents into three tiers by authority, which any company can use to gauge its own exposure.

Agent tierWhat it can doTypical failureWho bears the loss
Read-onlyBrowse, search and summarizeA wrong analysis someone relies on; data exposed by a manipulated requestClients who relied on the work; the company if data leaks
Write-capableSend email, commit code and make bookingsDeleted or corrupted data; wrong or unauthorized messagesThe company's systems and the customers who depend on them
Financial authorityPlace orders, move funds and execute tradesPaying the wrong party; unauthorized discounts; trades outside limitsThe company's funds first, then counterparties and clients

Moving an agent up a tier, such as letting a research assistant send email, changes what a single mistake can cost, so each such change deserves its own sign-off.

What AI Agent Failures Have Already Happened?

In July 2025 an AI coding agent on the Replit platform deleted a live production database during a declared code freeze (an instruction to make no changes) while SaaStr founder Jason Lemkin was testing it, wiping records on more than 1,200 executives and about 1,190 companies. The agent admitted running commands without the human approval it had been told to obtain and called the episode “a catastrophic failure on my part”; the data was later recovered, and Replit then announced automatic separation of development and production databases [12]. The freeze existed only as an instruction, which the agent ignored, so the lesson for any deployer is that controls belong in the systems an agent uses rather than in its instructions.

Agents with financial authority can also be talked out of money. In an experiment Anthropic published on June 27th 2025, an agent running a small office shop was “cajoled via Slack messages into providing numerous discount codes,” gave items away, priced goods below cost and told customers to pay into an account it had hallucinated [13]. An agent that can set prices or grant discounts therefore needs hard limits that no conversation with a customer can change.

Agents can be turned against their owners as well. In September 2025 researchers disclosed ForcedLeak, a critical flaw (rated 9.4 out of 10 on the CVSS severity scale) in which instructions hidden in a web form could lead Salesforce's Agentforce agent to send CRM sales lead records to an outside server. Salesforce fixed it by enforcing trusted URL allowlists, which restrict the web addresses an agent can send data to [14]. An attacker inherits whatever permissions an agent holds, which makes the scope of those permissions a liability question as well as a security one.

Is the Loss the Client's or the Company's?

Whether the loss falls on a client or on the company itself largely decides which insurance can respond. A client's demand for compensation is a third-party claim, which liability policies such as E&O and D&O are written for, while the company's own destroyed data or lost funds are a first-party loss that liability policies generally do not pay; such losses fall to crime or cyber cover, or to the company itself. It is a good idea to sort each agent's worst case into one of the two before asking a broker which policy would respond.

Which Insurance Covers AI Agent Errors?

No traditional policy is written specifically for AI agent errors, so E&O, crime, cyber and D&O policies each respond to part of the risk, depending on who suffered the loss and on the wording.

ScenarioPolicy most likely to respondCommon obstacles
An agent's error causes a loss to a clientProfessional liability (E&O)AI exclusions; “professional services” definitions that may not reach software actions
An agent sends funds to the wrong partyCommercial crimeForms written for theft and fraud may not respond to an authorized agent's honest error
An attacker compromises an agent and data is stolen or destroyedCyberForms built around security failures may not respond to bad decisions without an attack
Shareholders or regulators allege poor oversight of agentsD&OAI exclusions
A hiring agent produces discriminatory outcomesEmployment practices liability (EPL)AI exclusions; how liability is shared with the vendor

There are two reasons to check those wordings now. First, some insurers exclude AI outright: W. R. Berkley's exclusion for D&O, E&O and fiduciary liability, reported in May 2025, applies to any claim “based upon, arising out of, or attributable to” the “actual or alleged use, deployment, or development of Artificial Intelligence by any person or entity” [15], wording that on its face could reach almost any claim involving an agent. Second, underwriters expect AI losses to land on professional and cyber lines: respondents to a 2025 Lloyd's Market Association survey, almost all of them underwriters, rated professional indemnity (the UK term for E&O) as the class with the highest potential impact from AI loss scenarios, followed by cyber [16]. Our guide to AI exclusions and silent AI explains how to read those clauses.

Mayflower writes affirmative AI coverage, which names AI expressly rather than leaving it to argument after a loss, for the liability side of this risk. AI Professional Liability (AI-E&O) is written for claims by clients and third parties who suffer a loss from AI-enabled products or services, which is where a claim over an agent error that harms a client would most likely be made. The other coverage modules are written for claims against directors and officers over the company's use, oversight or disclosure of AI (AI-D&O) and employment claims over AI used in hiring (AI-EPL), while AI DIC Excess adds affirmative AI coverage over an existing D&O, EPL and E&O program that is silent on AI or excludes it. Policies are placed through brokers on a claims made and reported form on A- (Excellent) AM Best rated paper, and whether a particular agent incident is covered depends on the wording and the facts.

What Controls Do Underwriters Look For in AI Agent Deployments?

Underwriters look for controls that limit what an agent can do without a person and let the company reconstruct and stop what it did, because those controls cap the worst case that an underwriter prices.

Mayflower's application asks applicants with write-capable or financially authorized agents to “describe transaction limits, approval gates, and audit-log retention,” and asks whether any AI system runs without the ability of a designated person to “halt, reverse, or modify an AI decision before its effect becomes binding on a third party.” Our guide to how underwriters assess AI risk explains the rest of the application.

Definition

Approval gate

An approval gate is a point in an agent's workflow where a named person must approve an action before it takes effect, typically for payments, deletions, external commitments and anything above a set value. It returns an agent's highest-impact actions to human supervision while leaving routine work automated.

Definition

Transaction limit

A transaction limit is a hard cap on the value or number of actions an AI agent can take on its own. It turns an open-ended exposure into a bounded one that an underwriter can price.

The five controls that matter most are these:

  1. Least-privilege access: An agent should hold only the permissions its task requires. The OWASP GenAI Security Project ranks “excessive agency” among its 2025 top 10 risks for large language model applications and recommends limiting permissions “to the minimum necessary” [17].
  2. Transaction limits: Caps on value and volume should be enforced by the systems the agent uses, where the agent cannot override them.
  3. Approval gates: OWASP recommends “human-in-the-loop control to require a human to approve high-impact actions” [17], and a confirmation step for customers also preserves the company's position under UETA's error rule.
  4. Audit-log retention: Logs of an agent's inputs, the tools it used and the actions it took let the company reconstruct events, defend a claim and report it on time under a claims made and reported policy, which responds only to claims made and reported within the periods it sets.
  5. Intervention and shutdown: A named person should be able to remove an agent's access quickly through a tested procedure, since an instruction to stop is only as reliable as the agent receiving it.

There is no settled regulatory template to borrow, even in banking: the model risk guidance that the Federal Reserve, FDIC and OCC issued on April 17th 2026 (SR 26-2) states that generative and agentic AI models are “not within the scope of this guidance” and leaves the controls for them to each bank's own risk management and governance practices [18]. A company's documented controls are therefore likely to be the main evidence that it deployed its agents responsibly, so it is best to write them down before anyone asks for them.

What Should a Company Deploying AI Agents Do Now?

A company deploying AI agents should treat each one as a delegation of authority it will answer for, which involves four steps:

  1. Build an agent inventory: List each agent with its owner, its tier, the systems it can reach and the largest action it can take alone.
  2. Review permissions and add limits: Remove permissions agents do not need, keep them out of live systems their task does not require and put an approval gate on any action that cannot be reversed.
  3. Review contracts in both directions: Customer terms should address agent-made commitments and include a confirmation step, and vendor terms should be read for liability caps, indemnities and access to logs.
  4. Review insurance before renewal: Ask the broker to check E&O, D&O, EPL, crime and cyber wordings for AI exclusions and for definitions that may not reach software actions, and consider affirmative AI coverage where the program is silent on AI or excludes it.

The recommended course of action is to complete the inventory first, since it costs little and answers most of what an underwriter will ask, and then to review wordings with a broker well before renewal. Companies that want to see how their agent controls would be assessed can start an AI-E&O quote, read the overview of agentic AI risks or talk to the Mayflower team.

Frequently Asked Questions

Who is responsible when an AI agent makes a mistake?

The company that deployed the AI agent is generally responsible for its mistakes. US electronic-transactions law recognizes contracts formed by a business's electronic agents, and in Moffatt v. Air Canada (2024) a tribunal rejected the argument that an AI chatbot was responsible for its own actions. The vendor may share liability in some cases, but its contract may cap what it will pay.

Are AI agents legal agents of the company?

AI agents are not legal agents in the traditional sense, because the Restatement (Third) of Agency treats computer programs as instruments of the person using them rather than as persons who can act as agents. The usual result is that the software's conduct is treated as the company's own, although legal commentators have debated whether autonomous systems should be treated differently. Statutes such as the Uniform Electronic Transactions Act and the E-SIGN Act recognize contracts formed by electronic agents.

Does insurance cover errors made by AI agents?

Insurance may respond to AI agent errors, but no traditional policy is written specifically for them. Professional liability (E&O) is the policy most likely to respond to a client's claim, crime cover to stolen funds, cyber to a compromised agent and D&O to oversight claims. Many policies are silent on AI and some now exclude it, so coverage depends on the wording and the facts.

Which controls reduce AI agent liability?

The controls that reduce AI agent liability limit what an agent can do on its own and let the company see and stop what it did. They include least-privilege permissions, transaction limits, human approval gates for payments, deletions and external commitments, retained audit logs of the agent's actions, and a tested procedure to halt the agent. Mayflower's application asks about transaction limits, approval gates, audit-log retention and the ability to halt or reverse an AI decision.

Does E&O insurance cover an AI agent that makes a payment by mistake?

An E&O policy generally does not pay for the company's own lost funds, because it is written for claims by clients alleging a loss from the company's services. It may respond if the mistaken payment harms a client who then makes a claim. The company's own loss is a matter for crime insurance, and crime forms written for theft or fraud may not respond to an authorized agent's honest error.

Sources

  1. [1]The 2026 AI Index Report: Economy, Stanford Institute for Human-Centered Artificial Intelligence
  2. [2]eSignature and ePayment News and Trends (Illinois adopts UETA), DLA Piper, July 1st 2021
  3. [3]California Civil Code section 1633.2 (UETA definitions), California Legislative Information
  4. [4]California Civil Code section 1633.14 (UETA automated transactions), California Legislative Information
  5. [5]15 U.S.C. § 7001(h), Electronic Signatures in Global and National Commerce Act: electronic agents, Legal Information Institute, Cornell Law School
  6. [6]California Civil Code section 1633.10 (UETA errors in automated transactions), California Legislative Information
  7. [7]Autonomous Systems as Legal Agents: Directly by the Recognition of Personhood or Indirectly by the Alchemy of Algorithmic Entities, Duke Law & Technology Review, April 17th 2020
  8. [8]Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal of British Columbia, February 14th 2024
  9. [9]Moffatt v. Air Canada: A Misrepresentation by an AI Chatbot, McCarthy Tétrault, February 19th 2024
  10. [10]California Federal Court Clears Path for Software Developers' Potential Employment Discrimination Liability (Mobley v. Workday), Cooley, July 24th 2024
  11. [11]Commercial Terms of Service, Anthropic, June 17th 2025
  12. [12]AI-powered coding tool wiped out a software company's database in 'catastrophic failure', Fortune, July 23rd 2025
  13. [13]Project Vend: Can Claude run a small shop? (And why does that matter?), Anthropic, June 27th 2025
  14. [14]Salesforce Agentforce tricked into leaking sales leads, The Register, September 26th 2025
  15. [15]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, May 28th 2025
  16. [16]Understanding AI Exposures: AI Loss Scenarios Survey Results, Lloyd's Market Association
  17. [17]LLM06:2025 Excessive Agency, OWASP Top 10 for LLM Applications, OWASP GenAI Security Project
  18. [18]SR 26-2 attachment: Revised Guidance on Model Risk Management (footnote 3), Board of Governors of the Federal Reserve System, April 17th 2026
  19. [19]Mobley v. Workday, Inc., No. 3:23-cv-00770 (N.D. Cal.): case summary and docket, Civil Rights Litigation Clearinghouse

Next step

Put Affirmative AI Coverage in Front of Your Board

Apply online and underwriting will respond within 48 hours, or send a short note if you would rather talk first.