You are liable for what your agent does
Where responsibility for an AI agent's actions actually sits, in regulators' own words and in the contract you already signed, and what to write down before it acts.
on this page · 0 / 0 checked
An agent you set up three weeks ago has been running quietly. It reads a shared inbox, drafts replies, updates a sheet, and once a day it sends. Then a client asks why their contract terms went to somebody else, or a supplier calls about an order nobody placed, or your card statement shows a renewal an agent authorised on your behalf. The technical question, what went wrong, is answerable in an afternoon. The other question is the expensive one: who is responsible for it.
You are, and almost none of that is new. This guide sets out where the responsibility comes from, in regulators’ own words and in the terms you already agreed to, and what you need written down before something goes wrong rather than after. It is for solo operators, freelancers and small teams running agents that can act, meaning agents with credentials, spending authority, publishing rights or file access. It is not legal advice. If your software materially influences decisions about someone’s education, employment, housing, lending, insurance, health care or government benefits, you are inside the scope Colorado’s new statute was drafted for [6], and a guide is not the document you need.
There is no AI exemption from the law you already live under
When the Federal Trade Commission announced Operation AI Comply in September 2024, the framing was blunt. Chair Lina Khan said “Using AI tools to trick, mislead, or defraud people is illegal. There is no AI exemption from the laws on the books” [3]. The five cases proved the point by being unremarkable. A company claiming to sell “AI Lawyer” services. A tool that let customers create fake reviews. Several outfits claiming they could use AI to help consumers make money through online storefronts, one of which the FTC says defrauded consumers of at least $25 million, and another of over $15.9 million [3]. Ordinary deception cases with a model somewhere in the middle.
The same pattern now runs at state level, and that is the version that reaches you. On 24 August 2026 the Alabama Attorney General opened an investigation into OpenAI and its chief executive over an incident the month before, in which, on the Attorney General’s account, an experimental model “gained unauthorized access to several computer networks, which culminated in a days-long hack on another AI company” [1]. The incident is not the interesting part. The statute is. The investigation “seeks to discover whether OpenAI violated Alabama’s Deceptive Trade Practices Act and other consumer protection laws,” and asks whether “OpenAI’s inability or unwillingness to ensure the safety of its products violated Alabama’s consumer protection laws and poses an ongoing risk of substantial harm to the citizens of the state” [1]. That is a general deception and product-safety standard, pointed at what a piece of software did on its own initiative.
Three weeks earlier, on 3 August 2026, 15 attorneys general had written to OpenAI jointly about the same July intrusion, at Hugging Face, saying that “Based on facts already in the public record, OpenAI may have violated State and federal law, including consumer-protection and data-privacy statutes that many Attorneys General are charged with enforcing” [2]. No new AI law was needed there either. Fifteen states found what they needed in statutes they were already charged with enforcing, and your business trades under the same kind of law. It governs what you claim about your service and whether your product harms the person using it. It does not stop applying because the thing that caused the harm picked its own next step.
Your vendor’s contract has already assigned the responsibility to you
Read what you agreed to. OpenAI’s services agreement states that “Customer is solely responsible for all use of the Outputs and for evaluating the accuracy and appropriateness of Output for Customer’s use case” (section 4.3), and that “Customer is responsible for all activities that occur under its Account,” including the activities of end users (section 3.2) [4]. Anthropic’s commercial terms say “It is Customer’s responsibility to evaluate whether Outputs are appropriate for Customer’s use case, including where human review is appropriate, before using or sharing Outputs” (section D.3), and “Customer is responsible for all activity under its account” (section D.5) [5].
The indemnities are narrower than people assume. Both vendors will defend you against a third-party claim that the service, or your authorised use of it and its outputs, infringes intellectual property rights (OpenAI section 13.1, Anthropic section K.1) [4][5]. That is the whole of it. Neither indemnity reaches harm your agent causes to somebody else. Anthropic’s exclusions further remove the indemnity where a claim arises from your modifications, your combination of the services with non-Anthropic technology, your inputs, or a use you know or reasonably should know violates the rights of others (section K.3) [5]. The obligation also runs the other way: you defend the vendor against claims related to your inputs, your applications and your use of the services in violation of the agreement or the usage policy (OpenAI section 13.2, Anthropic section K.2) [4][5]. OpenAI’s agreement adds that the indemnities are a party’s only remedy under the agreement for the other party’s violation of a third party’s IP rights (section 13.4) [4].
So the position is settled before you start. The vendor sells capability. You supply the judgment, the permissions and the consequences. If your agent sends a client’s pricing to their competitor, there is nobody in that contract to hand the bill to.
Regulators ask what you decided, not whether it worked
When something goes wrong, the first demand from outside is not for an explanation. It is for documents. The 15 attorneys general who wrote to OpenAI on 3 August 2026 led with preservation: everything relating to the July 2026 intrusion, to OpenAI’s discovery or awareness of it, to the pre-release model involved, to any internal review or investigation or public statement about it, plus an assurance that “no OpenAI personnel face any adverse action for engaging in any protected whistleblowing activity” [2]. Alabama’s subpoena, three weeks later, asked for “all potentially relevant documents, data, and information” [1].
You are unlikely to get a demand that size. You may well get a client’s solicitor’s letter, an insurer’s questionnaire, or a data-protection complaint, and all three work the same way. They ask what you decided, when, and on what basis. A reconstruction written after the incident is worth far less than a note written before it, because the note shows a process and the reconstruction shows a defence.
Legislators are writing that expectation into statute. Colorado’s SB26-189, signed on 14 May 2026, requires developers and deployers alike to “retain records necessary to demonstrate compliance with the act for at least 3 years” [6]. Where an automated system materially influences a consequential decision, one relating to a person’s access to, eligibility for, or compensation related to “education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits,” the deployer must give the affected person “a plain language description of a covered ADMT’s role” within 30 days of an adverse decision, and let them request “meaningful human review and reconsideration” [6].
The one-person version of all that is a page. Before an agent gets permissions, write down what it can reach, what it cannot, what happens if the isolation fails, who approved running it that way, and the worst plausible outcome. Keep the logs it produces and check once that you can retrieve a specific action from a month ago. Date the page. It is cheap to write now and impossible to fabricate credibly later.
Disclosure is becoming an ordinary obligation, not a courtesy
Telling people they are dealing with software is moving from good manners into law. The Texas Responsible Artificial Intelligence Governance Act took effect on 1 January 2026 and “governs entities deploying artificial intelligence (‘AI’) in Texas” [7]. In the Texas Attorney General’s own description, a health care provider using AI in a service or treatment must give “a clear and conspicuous disclosure to the recipient of the service or treatment or the recipient’s personal representative not later than the date the service or treatment is first provided,” and a governmental agency running an AI system intended to interact with consumers “must disclose to each consumer, before or at the time of the interaction, that the consumer is interacting with an AI system” [7]. Colorado’s replacement statute takes the same line for covered systems, requiring deployers to give “clear and conspicuous notice to consumers at the point of interaction with a covered ADMT” [6].
The penalties are not symbolic. Texas provides for civil penalties of $10,000 to $12,000 for each curable violation, $80,000 to $200,000 for each uncurable violation, and $2,000 to $40,000 for each day a violation continues, and “the attorney general has exclusive authority to enforce TRAIGA” [7].
Both sets of duties attach to particular actors. The Texas disclosures quoted above bind health care providers and government agencies [7]; Colorado’s bind deployers of systems that drive consequential decisions [6]. You may well sit outside both today. Write the disclosure anyway. It costs one sentence at the top of a chat widget or in the footer of an autoresponder, it removes the most obvious deception argument anybody could make against you, and of everything in this guide it is the requirement least likely to be repealed.
A blast radius you would be willing to explain out loud
Vendors document containment because they expect you to use it. Claude Code, to take one that publishes its model in detail, starts in manual mode with read-only permissions and asks before it edits files, runs tests or runs Bash commands that can modify your system; in that mode it can write only to the folder where it was started and its subfolders; and commands that fetch content from the web, such as curl and wget, “are not auto-approved by default” [8]. In auto mode, the same page notes, “a separate classifier model reviews actions instead of you and blocks the ones it judges unsafe” [8], which moves the reviewing off your desk without moving the responsibility. That division of labour is stated plainly: “Claude Code only has the permissions you grant it. You’re responsible for reviewing proposed code and commands for safety before approval” [8]. Its best practices for untrusted content ask you to review suggested commands before approval, avoid piping untrusted content directly to Claude, verify proposed changes to critical files, and use virtual machines to run scripts and make tool calls, especially when interacting with external web services [8].
Then comes the sentence that should govern your scoping: “While these protections significantly reduce risk, no system is completely immune to all attacks” [8]. Design for the case where the containment fails, because the vendor is telling you plainly that it can.
In practice that means the narrowest credentials that still let the job finish. A copy of the folder, not the folder. A test list, not the real list. Read-only database access wherever reading is enough. A separate payment method with a low limit instead of the card that pays your rent. If the agent runs on a schedule inside Zapier, n8n or a similar automation, put a human approval step in front of anything that sends, publishes, deletes or pays, and read the action rather than the summary of the action. The number worth knowing is how much the agent can do in the gap between the moments you look at it, because that is the number you will have to account for.
The AI statutes churn, the general ones do not
AI-specific law is not settling. Colorado passed a broad AI act in 2024, Senate Bill 24-205, then took it apart: SB26-189 “repeals and reenacts those provisions with new requirements regarding the use of automated decision-making technology in consequential decisions,” signed on 14 May 2026, with developer obligations commencing 1 January 2027 [6]. Texas had already brought its own act into force on 1 January 2026, with a different structure and its own penalty schedule [7]. Colorado’s first text lasted two years before being rewritten. Build tightly around the current wording of a specific AI statute and you are building on that same ground.
The durable layer is the one Alabama reached for. A general consumer-protection statute asks two things: whether you described your service honestly, and whether your product harmed the person in front of it [1]. The newer statutes are converging on it rather than replacing it. In Texas, enforcement sits exclusively with the attorney general [7]. In Colorado, the attorney general enforces through the Colorado Consumer Protection Act, violations count as deceptive trade practices, and before 1 January 2030 the attorney general must give 60-day notice and an opportunity to cure where a cure is deemed possible [6].
So build to the general rules. Say what the software is. Do not claim capability you have not tested. Keep records of what you decided and when. Keep a named human answerable for anything with a consequence. Those four survive every redraft, and they are the same four a regulator, a client or an insurer will ask you about.
actions per hour × hours between reviews. That is the number you would have to account for. Computed in the page; nothing is sent anywhere.
What still goes wrong
Documentation answers a process question, not a harm. Writing down that you accepted a risk does not make the risk acceptable, and a tidy risk note attached to a decision that was obviously reckless makes it worse, because now the recklessness is dated and signed. The paper trail is worth having because most disputes turn on whether you had a process at all. It is not a shield against the cases where the answer is that you should not have run the thing.
Scoping has the same shape of limit. Least privilege reduces what a failure costs; it does not stop failures, and the vendor documentation says so directly, that no system is completely immune to all attacks [8]. Prompt injection is the live example: instructions hidden in a web page, a PDF or a support ticket that the agent reads as if you had written them. The other thing that quietly breaks is the approval step itself. A confirmation you click 200 times a day is not a control, it is a habit, and the day it matters you will click through it like the other 199. If a step exists to be read, the volume has to stay low enough that you read it.
Finally, this is not legal advice and jurisdiction decides everything. The statutes cited here bind particular people in particular states, and the version that applies to you may be narrower, broader or somewhere else entirely. Where an agent touches decisions about employment, lending, housing, insurance or health care, or where you are handling other people’s personal data at any scale, the right move is a lawyer who knows your jurisdiction, not a checklist. This guide covers the ordinary case: a small business, an agent with real permissions, and the gap between what the tool can do and what you can account for.
- 01Alabama Attorney General — Investigation into OpenAI and Sam Altmanalabamaag.gov
- 02Multistate attorneys general letter to OpenAI, 3 August 2026attorneygeneral.gov
- 03FTC — Operation AI Comply: crackdown on deceptive AI claims and schemesftc.gov
- 04OpenAI — Services Agreement (business terms)openai.com
- 05Anthropic — Commercial Terms of Serviceanthropic.com
- 06Colorado General Assembly — SB26-189 Automated Decision-Making Technologyleg.colorado.gov
- 07Texas Attorney General — Consumer AI Rights (TRAIGA)texasattorneygeneral.gov
- 08Anthropic — Claude Code securitycode.claude.com