TL;DR: When an autonomous AI agent causes harm, no jurisdiction lets the AI itself be liable, because it is not a legal person. Responsibility falls on the humans and companies around it: usually the deployer (the business that put the agent to work), and sometimes the developer or vendor, depending on what went wrong and what the contract says. There is no dedicated AI liability statute in India yet, so liability runs through existing law, the IT Act, the DPDP Act 2023, consumer protection, and contract and tort principles, with the human in control generally held accountable. The practical protection is contractual: your agreement has to allocate who bears the risk when the agent acts on its own, because most older AI contracts were written for tools that suggest, not agents that act.
Quick overview: AI has crossed a line that contracts have not caught up with. Earlier AI recommended; a human decided and acted. Agentic AI now takes actions directly, it books, buys, sends, executes, and negotiates, often without a human approving each step. That shift breaks the old liability assumptions. When an agent makes a bad call, the question “who is responsible” no longer has an obvious answer, and the contract clauses most businesses copied from a few years ago do not address it. This guide explains how AI agent liability actually works, the frameworks courts and regulators are using, the India position, and the specific clauses your contract needs so the answer is decided in advance rather than in a courtroom.
What is an AI agent, and why does liability get harder?
An AI agent is software that can pursue a goal and take actions to achieve it, with limited or no human involvement in each individual step. Give it an objective, and it plans, calls tools, makes decisions, and acts, sending emails, executing trades, placing orders, updating records, or interacting with customers.
That autonomy is exactly what makes liability harder. With an ordinary AI tool, a human reviews the output and decides what to do, so the human is the clear decision-maker. With an agent, the decision and the action can happen without a human in the loop at all. When something goes wrong, a wrong payment, a defamatory message, a discriminatory decision, a data breach, there is no single human who “did” it in the usual sense. The harm flowed from an autonomous system acting on a goal you set.
The law has no category for “the AI did it.” An AI agent is not a legal person. It cannot be sued, hold assets, or bear liability. So the responsibility has to land on a human or a company, and the whole question becomes which one. We flagged this shift early in our piece on why founders need to wake up to AI liability; this guide goes into how the liability is actually allocated and drafted.
Can an AI agent be held liable itself?
No. This is the starting point everyone has to accept. An AI agent, however autonomous or “intelligent,” has no legal personhood. It is a product or a service, not a party. It cannot be a defendant, cannot be insured in its own name, and cannot satisfy a judgment.
That means liability for an agent’s actions is always attributed to a legal person connected to it. The candidates are the developer who built the model, the vendor who supplied or hosts the agent, the deployer who put it to work in their business, and occasionally the user who directed it. Working out which of them bears a given loss is the entire subject, and it turns on a mix of general legal principles and, above all, the contract between them.
How is liability for an AI agent decided? The four frameworks
Courts and regulators are not inventing a brand-new body of law for this. They are applying four existing frameworks, often at the same time. Understanding them tells you where your risk sits.
Agency and vicarious liability
The most intuitive lens treats the AI agent like an agent or an employee acting for a principal. Under long-standing principles, a principal is generally responsible for the acts of an agent carried out within the scope of the authority given to it, and an employer is vicariously liable for an employee’s wrongful acts in the course of employment. Applied to AI, the business that deploys an agent to act on its behalf is, by analogy, the principal, and tends to carry primary responsibility for what the agent does within the scope of the task it was given. If you set an agent loose to do a job, its actions in doing that job are, in effect, yours.
Product liability
A second lens treats the AI as a defective product. If an agent causes harm because of a flaw in how it was built or trained, product liability principles can put responsibility on the developer or manufacturer. This is moving fast in Europe: the revised Product Liability Directive (Directive (EU) 2024/2853) expressly brings software and AI systems within strict product liability, so a claimant injured by a defective AI product may not need to prove fault, and more than one party in the chain can be jointly and severally liable. Even outside the EU, the “defective product” analogy is a natural route to reach the developer.
Contract
The third framework, and the one you actually control, is the contract. Between businesses, the agreement decides who bears which risk: who indemnifies whom, whose liability is capped, what each party warranted about the agent, and who is responsible if the agent goes off-task. Where a valid contract allocates the risk, that allocation usually governs the relationship between those parties. This is why the contract is the real lever, and why the clauses in the next section matter so much.
Statute and regulation
The fourth framework is sector and data regulation. Data-protection law, consumer law, financial regulation, and emerging AI-specific rules impose duties directly, regardless of contract. An agent that mishandles personal data creates liability under data-protection law for the business responsible for that data, whatever the vendor agreement says between the parties.
Who is usually responsible: developer, deployer, or user?
In practice, responsibility tends to distribute like this, though the contract can shift it.
The deployer, the business that puts the agent to work in its operations, usually carries primary responsibility toward the outside world. If your company’s agent harms a customer or a third party, the customer looks to your company first, because you chose to deploy it, you set its goals, and you benefited from it. Regulators increasingly take the same view: the party that controls and deploys the system is accountable for its outputs.
The developer or vendor is more likely to bear responsibility where the harm came from a defect in the model or the service, a training flaw, a security hole, a capability that did not work as warranted. Whether the deployer can pass the loss back to the developer depends heavily on the contract between them.
The user who directed the agent can share responsibility where they misused it, ignored instructions, or pushed it outside its intended use.
The reason “it depends” is the honest answer is that these roles overlap, and the loss usually gets allocated by contract long before a court would apportion it. That is the opportunity: you can decide the answer in advance.
The India position: no AI statute, so existing law and contract govern
India does not yet have a dedicated AI liability law. As of 2026, there is no standalone statute that says who is liable when an AI agent causes harm. Instead, liability is assembled from existing laws, and from the contract.
Several sources apply. The Information Technology Act, 2000 governs digital systems, intermediaries, and cyber contraventions. The Digital Personal Data Protection Act, 2023 imposes duties on the business that determines how personal data is processed, the data fiduciary, including securing the data and reporting breaches, and those duties bite when an agent mishandles personal data regardless of what a vendor contract says. Consumer-protection law applies where the agent’s actions harm consumers. And ordinary principles of contract and tort, including vicarious liability for the acts of those acting on your behalf, fill the gaps.
The direction of travel in Indian practice is a control-based approach: the human or company that controls and deploys the system is treated as accountable for it, an “accountability by design” expectation rather than a rule that the tool bears its own blame. For the data-protection dimension specifically, our guides on the DPDP Act and its implications and consent management under the DPDP Act set out the duties that attach to whoever is responsible for the data an agent touches.
Because there is no AI-specific statute filling in the answers, the contract does even more work in India than in a jurisdiction with a dedicated regime. What your agreement says is, in most commercial situations, what decides who pays.
What your contract must say: the clauses for AI agent liability
Here is the core practical point. Most AI contracts in circulation were drafted for AI that assists, an autocomplete, a chatbot, a recommendation engine, where a human always made the final call. Those contracts often do not address an agent that acts on its own, so their indemnity and liability clauses simply do not reach the new risk. If you deploy or supply agentic AI, the agreement needs clauses written for autonomy. These are the ones that matter.
Clear allocation of responsibility for autonomous actions. The contract should state, in terms, who is responsible when the agent acts without human approval, and within what scope. Do not leave “the agent did it on its own” as an unaddressed gap.
An indemnity built for agent behaviour. A standard indemnity that covers “breach” or “negligence” may not cover a loss caused by an agent operating exactly as designed but reaching a harmful result. The indemnity should specifically address third-party claims arising from the agent’s autonomous actions, data misuse, and IP infringement in its outputs. Our indemnity clause explainer covers how these promises work, and why the wording has to match the actual risk.
A limitation of liability tuned to the exposure. Autonomous agents can cause loss at machine speed and scale, so the liability cap, and any higher tier for serious risks like data breaches, needs to be set with that in mind. We explain why the base cap matters so much in how the absence of a limitation of liability clause can kill a startup, and the enhanced or “supercap” tier for high-risk categories in our supercap guide.
Warranties and their limits. The vendor’s warranties about what the agent will and will not do, and the disclaimers around autonomous behaviour, define where developer responsibility ends and deployer responsibility begins.
Human oversight and use restrictions. Clauses requiring a human in the loop for defined high-risk actions, and restricting the agent’s permitted uses, both reduce the risk and shape who is at fault if the boundary is crossed.
Data protection terms. Because data duties apply by statute regardless of contract, the agreement needs proper data-processing terms allocating the compliance obligations, typically through a data processing agreement.
For the wider set of documents an AI business needs around these clauses, see our guides on AI vendor contracts and the essential contracts every AI startup must have. The through-line is simple: with agentic AI, the contract is your main liability shield, so it has to be drafted for what the agent can actually do.
Where the law is heading
Two directions are worth watching. Internationally, regulators are converging on the idea that the human deployer is accountable and that AI-specific rules will layer on top of existing liability law rather than replace it. The European Union’s AI Act is phasing in obligations by risk tier, its revised Product Liability Directive pulls AI into strict product liability, and jurisdictions such as Singapore have issued dedicated guidance on governing agentic AI. In India, the likely path is continued reliance on the IT Act, the DPDP Act, and consumer and tort law, with sectoral guidance, rather than a single AI statute in the near term.
For businesses, the takeaway does not change with the regulation. Whatever the statute says, the party that deploys an autonomous agent will be expected to answer for it, and the cheapest place to decide who ultimately bears each risk is the contract, signed before anything goes wrong.
Frequently asked questions
Who is liable if an AI agent causes harm?
Liability falls on a legal person connected to the agent, never the agent itself, because an AI has no legal personhood. In most cases the deployer, the business that put the agent to work and set its goals, carries primary responsibility toward third parties. The developer or vendor may be liable where the harm came from a defect in the model or service, and the user may share responsibility where they misused it. Between businesses, the contract usually decides who ultimately bears the loss.
Can an AI agent be sued or held legally responsible?
No. An AI agent is not a legal person, so it cannot be sued, hold assets, be insured in its own name, or satisfy a judgment. Any liability for its actions is attributed to a human or company connected to it, typically the business that deployed it, and sometimes the developer or vendor, depending on what went wrong and what the contract provides.
Is there a specific AI liability law in India?
Not as of 2026. India has no standalone AI liability statute. Liability for AI-related harm is determined using existing laws, principally the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, consumer-protection law, and ordinary contract and tort principles, including vicarious liability. Indian practice leans toward holding the human or company that controls and deploys the AI accountable, which makes the contract especially important.
Does the developer or the deployer bear responsibility for an AI agent?
It depends on what went wrong. The deployer, the business using the agent, usually bears primary responsibility toward outside parties, because it chose to deploy the agent and set its task. The developer or vendor is more likely to be responsible where the harm resulted from a defect in the model or service, or from a failure to perform as warranted. The allocation between them is generally governed by their contract, which is why the indemnity and liability clauses are so important.
Do my existing AI contracts cover autonomous agents?
Often not. Many AI contracts were drafted for AI that assists a human who makes the final decision, and their indemnity and liability clauses may not address an agent that acts on its own. If you deploy or supply agentic AI, the contract should be reviewed and updated to allocate responsibility for autonomous actions specifically, including tailored indemnity, liability caps, warranties, human-oversight obligations, and data-protection terms.
What contract clauses protect against AI agent liability?
The key clauses are a clear allocation of responsibility for autonomous actions, an indemnity written to cover the agent’s autonomous behaviour and its outputs (including data misuse and IP infringement), a limitation of liability and any enhanced cap sized to the exposure, vendor warranties and their disclaimers, human-oversight and permitted-use restrictions, and data-protection terms. Together these decide, in advance, who bears the risk when an agent causes harm.
Authored and reviewed by Prakhar Rai, Advocate, founder of My Legal Pal. Prakhar is enrolled with the Bar Council of India and has over ten years of experience advising founders and technology companies on contracts, AI and commercial matters. He is an alumnus of the National Law School of India University, Bangalore, where he completed his Master of Business Laws, and of La Martiniere. Connect on LinkedIn.
This article is general information, not legal advice. AI liability law is developing quickly and varies by jurisdiction and by the facts of each case, and the position can change. For advice on your own AI deployment or contracts, speak to a qualified lawyer, and consider working with technology lawyers who focus on AI platforms.
If your business builds or deploys AI agents and you want contracts that actually allocate the liability before something goes wrong, our team can help with contract drafting and contract review.






