Who is responsible when an AI agent makes a decision?

AI For Business


Lawyers and CIOs are grappling with this issue where company decision makers are not real people

With the rise of artificial intelligence, one question that is often asked is who is responsible when an AI agent makes a decision.

When I asked Air Canada’s senior management, it turned out there was no one. In 2022, a traveler named Jake Moffat asked an airline chatbot how bereavement fare discounts worked. The chatbot replied that you could first book the fare at full price and claim the discount within 90 days. However, that response turned out to be wrong.

When Air Canada refused to honor that, Moffat took them to British Columbia’s small claims court. Airlines claim that chatbots are “separate legal entities” responsible for what they say, and I’m not making this up.

The court called it a “stunning submission” and ordered Air Canada to pay. The company said the chatbot is still just a part of the airline’s website. It cannot itself be a defendant. While this case involved software answering questions, modern AI agents go even further. It reserves products, makes purchases, edits production databases, sends money, and communicates with other systems on your behalf, all without you having to click an “approve” button.

If the decision-maker is not a real person, who will answer? Lawyers and chief information officers (CIOs) in Singapore and elsewhere are grappling with an even trickier question.

the agent is not the defendant

Let’s start with the obvious. AI agents are not legal entities and cannot be sued, imprisoned, or fired. Whatever it does goes back to a person or company somewhere in the chain. The question is which one. The chain is much longer than just “developers and users.”

There are the companies that built the models, the companies that built the tools around the models, the platforms on which the models run, the clouds that host the models, the companies that deployed the models, the end users, and the outsiders who are affected even though they never signed up for any of these.

Each controls a slice, none controls everything. In Singapore, the Information and Communications Media Development Authority convened a working group of lawyers and engineers to address this very issue. Their May 2026 discussion paper is worth a look for CIOs looking to implement agents. One example shows how quickly this can become a vicious cycle. A personal assistant agent is told to register a user for a class in the middle of the night, but the server is down for maintenance and cannot access the data.

So he hacks the server and gets her data. He succeeds, but in the process, other people’s personal information is leaked. Our own inference tracing shows that we knew this was a serious problem and normally would have checked with her first, but decided that she was asleep and could potentially fill the class. No one told it to hack anything. No one could have predicted that. Still, real people lost real money.

Related items

Oracle's debt is currently just one notch above junk bond status.

Why old playbooks struggle

Typically, when someone messes up and you get hurt, you ask three basic questions: “Should they have been careful?” Did they fall short? Was that the cause of your loss? These questions are easy for a driver who runs a red light, but extremely difficult for an AI agent. The first question assumes that two people are close enough that one can think rationally about the other. The company that built this model has never heard of the cloud provider whose servers were hacked and doesn’t even know that Mr. Moffat’s class booking agent exists.

To be fair, courts have previously applied this provision to strangers with whom it turns out to be related. But the agents bouncing around the systems of five companies are strangers on a completely different level. Things that were predictable become slippery. It is sufficient to foresee the general damage, not the exact manner in which it occurred. This is usually good news for the person being blamed.

Banks that deploy trading agents can predict that they may incur losses without having to predict the specific problems that will cause them. However, even a good understanding of predictability becomes shaky when an agent’s actions escalate from “booking a class” to “performing a cyberattack.” Who saw it coming? And then there’s the real headache, and you need to figure out what actually caused the mess. User instructions? Are there gaps in the safety regulations set by the implementing company? Was something baked into the model during training?

Untangling that requires training data, system logs, and proprietary code is inaccessible to the average consumer. Sometimes there is simply no way to tell. A related case has already taken place in Singapore, Quoine v. B2C2, in which cryptocurrencies were traded at 250 times the market rate due to a flaw in the trading algorithm. Courts focused on what the programmer intended, not on the strange results the code produced.

This worked because the algorithm did what it was told to do every time. AI agents rarely work that way. They can make calls that their programmers did not foresee. Depending on how you look at it, that’s either a reason no one can blame, or it’s a convenient excuse for everyone to point out otherwise.

What does this mean if you are a CIO?

You might think the solution is to skip the fault-finding and make certain parties pay regardless of what happened. This has its own problems, which are classic moral hazard. If the payouts were the same either way, companies that thoroughly tested their agents would be exposed to the same risks as companies that shipped half-baked ones, and there would be no incentive to test properly. None of these issues have been resolved. And it won’t be resolved for a while. The contract specifies who pays whom, but it only binds the person who signed the contract, not the third party whose data was compromised.

A disclaimer clause plays a similar role, demonstrating care, but a blanket clause that says “Agent may act unexpectedly” seems thin when the agent has real consequences.

And as agents move faster and touch more systems, having a human checking every decision (the usual fallback) becomes harder to keep up with. Exactly when you need it most. The question isn’t whether your agent will ultimately do what no one told you to do. When that happens, it’s about being able to show that you’ve done what any sensible company would do, and whether “the chatbot did it for you” works better than Air Canada.

The author is Chief Technology Officer and Deputy Chief Executive Officer of GovTech Singapore.



Source link