From workflow automation to civil, criminal and regulatory liability: how to govern AI agents, delegated authority, data and human oversight in the enterprise.
It cannot assume legal responsibility for having performed it.
Automation creates competitive advantage only when the company can assign authority, limits, controls, evidence and remedies before the agent acts in the real world.
A company configures an AI agent to manage purchase requests, select suppliers, prepare contract drafts and confirm orders within a spending threshold. The agent interprets an ambiguous request, selects an unsuitable counterparty and generates an order on terms that were not anticipated. The supplier accepts. The issue emerges only when the invoice, a contractual dispute or a data-access request arrives.
The question is not merely whether the AI “made a mistake”. The legally relevant question is who decided to use the agent, who configured it, what authority was delegated to it, what controls were in place and who was under a duty to intervene.
An AI agent is not an employee, a consultant or a legally responsible person. It is an automated system deployed within the company’s organisational context. Liability therefore depends on the quality of the delegation, human oversight, the vendor chain and the ability to reconstruct what happened.
The seven decisions before delegating a process to AI
An AI agent should be treated as an operational component of the business process, not merely as a chatbot. Every access right and delegated authority requires a verifiable perimeter.
Use case
Which process the agent automates and for what purpose.
Authority
Permitted actions, spending thresholds and escalation.
Data access
Data, documents and systems accessible to the agent.
Human oversight
Who supervises, approves and may suspend.
Transparency
Disclosure to customers, users and counterparties.
Vendor chain
Model, platform, APIs, tools and data.
Incident response
Logs, alerts, stop actions, remedies and notifications.
An AI agent is not a chatbot
An AI model generates text, classifications or predictions. An AI agent can plan activities, use connected tools and act within a workflow. The distinction becomes critical when the agent accesses CRM, ERP, email, calendars, repositories, payment systems or corporate databases.
| Element | Function | Business example |
|---|---|---|
| AI model | Generates content, analysis or predictions. | An LLM drafting an email or contract. |
| AI agent | Plans and performs actions through tools. | Researches suppliers, completes an order and sends a communication. |
| Tools and APIs | Enable the agent to act on the process. | CRM, ERP, email, calendars and payment systems. |
| Corporate policies | Define limits, thresholds and prohibitions. | Mandatory approval above a defined spending threshold. |
| Human owner | Supervises, validates and intervenes. | Legal, CFO, procurement manager or process owner. |
The AI agent’s liability flow
The agent is the operational point of the workflow; liability, however, arises from the company’s policies, configuration, access rights and oversight.
Who answers when automation goes wrong?
There is no single answer. Liability depends on the harm, the contractual relationship, the agent’s actual configuration, the authority delegated to it and the conduct of the people involved.
| Party | Potential liability area | Example |
|---|---|---|
| Using company | Contractual, tort-based, administrative or regulatory. | The agent sends an incorrect communication or confirms an unauthorised order. |
| Configurator or process owner | Professional, organisational or disciplinary, as applicable. | Grants excessive access or imposes inadequate instructions. |
| AI provider | Contractual and, where applicable, regulatory. | A platform or model fails to comply with warranties, SLAs or applicable obligations. |
| Employee user | Disciplinary and, where relevant, civil or criminal. | Circumvents controls, discloses data or uses the agent for unlawful purposes. |
| Tool provider | Primarily contractual. | A CRM, ERP or API returns incorrect data or enables a defective function. |
Civil, criminal and regulatory liability
Civil liability: harm, contract and evidence
Towards customers and counterparties, the company may be liable where an agent generates an incorrect communication, confirms an order, processes data inconsistently with applicable requirements or produces harmful output. Internally, employees and consultants may be called to account within the limits of their role and instructions. Across the vendor chain, SLAs, warranties, liability limitations, indemnities and security obligations determine the ability to recover losses.
The agreement with the AI provider does not eliminate the company’s liability towards the customer: it primarily determines who may seek a remedy within the contractual chain.
Criminal liability: an agent does not commit offences
An AI agent is not criminally liable. It may, however, be the instrument through which a person commits, facilitates or automates unlawful conduct: unauthorised access, disclosure of confidential information, fraud, document manipulation, deceptive use of synthetic content or breach of trade secrets.
In the most serious cases, the analysis must focus on the conduct of natural persons and, where the legal requirements are met, on potential corporate liability. Technology may make an unlawful act faster or less transparent; it does not transfer liability onto itself.
AI Act: the company is often the deployer
A company that uses an AI system under its authority for professional purposes may qualify as a deployer. The AI Act imposes specific obligations primarily on high-risk systems and, from 2 August 2026, transparency obligations on AI systems that interact with people, unless the artificial nature of the interaction is obvious in the context.
The Commission’s transparency guidelines expressly address AI agents capable of interacting with people in performing activities such as managing correspondence, making bookings, negotiating or concluding contracts and executing purchases.
For high-risk systems, the deployer must, among other things, use the system in accordance with instructions, assign competent human oversight, monitor its operation and manage logs under its control.
Red flags requiring immediate action
Excessive access
The agent can send emails, modify records, make payments or access data without proportionate thresholds or authorisations.
No useful logs
The company cannot reconstruct prompts, tools used, data accessed, actions performed and human approvals.
Absent transparency
Customers or counterparties interact with the agent without being informed where the context requires disclosure.
Opaque vendor chain
The model, platform, APIs, subprocessors and terms of use are not mapped.
Outdated policies
Agent use is real, but policies, delegations and staff training do not yet reflect it.
No stop action
There is no technical and organisational procedure to suspend the agent, contain an incident and activate remediation.
AI Agent Governance Review
This checklist is indicative. It helps determine whether the company has designed automation as a governed function, rather than merely as a technology experiment.
Is the AI agent governed before it acts?
Important notice. This article is provided for general information only and does not constitute legal advice. Civil, criminal, employment, privacy, contractual and regulatory issues must be assessed in light of the specific use case, parties involved, data processed, connected systems and applicable jurisdictions.

// Commenti