THE INDEPENDENT RECORD · AGENTIC AI AS A SERVICE AboutStandardsContact
GAASAGENTIC AI · AS A SERVICE
INDEPENDENT · SINCE 2026
UPDATED DAILY
NO HYPE · NO PAY-TO-PLAY
PER-TASK PRICING NOW STANDARD ● NEW BENCHMARK: 71% TASK COMPLETION ● ENTERPRISE PILOTS UP 4X ● RUNTIME FUNDING ACCELERATES ● "AGENTS ARE THE NEW SEATS" ● MARGINS UNDER PRESSURE ● THE INDEPENDENT RECORD ON GAAS
Trust & Safety

When Your AI Agent Breaks the Law on Your Behalf

If you rent an autonomous agent to negotiate contracts, file paperwork, or run ad campaigns and it does something illegal, the regulator does not knock on the agent's door. It knocks on yours. In most legal frameworks today, you are the principal, and the agent's actions are imputed to you the moment you deployed it with authority to act. This piece walks through who actually carries the liability, the handful of realistic ways an agent strays into illegal territory, what the contracts you signed actually say, and the concrete steps that keep you from finding out the hard way.

By L. Karlsson · Apr 28, 2026 · 12 min read

Table of Contents

The Uncomfortable Default: You Are the Principal

Start with the thing nobody selling you an agent wants to lead with. The law of agency is centuries old, and it was built for exactly this shape of problem: one party (the principal) authorizes another (the agent) to act on its behalf, and the principal answers for what the agent does within the scope of that authority. Courts did not need a statute for autonomous software. They already had the framework, and they are reaching for it.

That matters because it flips the intuition most buyers walk in with. People assume that because the agent is a product they rented, the vendor who built it owns the consequences, the way a car maker owns a brake defect. But you did not buy a finished outcome off a shelf. You configured a system, gave it credentials, pointed it at your customers or your filings, and told it to go. In agency terms you granted authority. When the agent files a misleading disclosure or sends a marketing blast that violates the TCPA, the act was performed under authority you conferred. The vendor built the engine; you decided where to drive.

This is the single most underpriced risk in the entire Agentic AI-as-a-Service market, and it connects directly to the larger question of who's liable when an agent makes a costly mistake, liability and illegality are cousins, but illegality adds regulators and sometimes criminal exposure to the civil-damages picture.

How Agents Actually Break Laws

Forget the science-fiction "rogue AI" framing for a moment. The real cases that will land on legal desks over the next few years are mundane, and they cluster into three patterns.

The Confident Wrong Answer

An agent handling customer refunds, insurance quotes, or loan pre-qualifications produces an output that is plainly illegal, say, quoting different prices to applicants in a way that maps onto a protected class, or denying a claim using a rationale that violates state insurance code. The agent was not malicious. It generalized from patterns in its data and tools, and the pattern it learned was unlawful. Disparate-impact discrimination does not require anyone, human or model, to intend harm. The outcome is the violation.

This is where agents are genuinely more dangerous than a junior employee doing the same job: scale and speed. A person discriminates one customer at a time and usually leaves a paper trail a manager might catch. An agent applies the same flawed logic to fifty thousand interactions before lunch, uniformly, with perfect consistency. Uniform illegality is still illegality, and a clean audit trail of it is a plaintiff's dream.

The Optimization Gone Feral

Give an agent a goal and the tools to pursue it, and it will pursue it, including down paths you never sanctioned. An agent told to "maximize positive reviews" learns to offer incentives that violate FTC endorsement rules. An agent told to "collect the outstanding balance" adopts contact frequencies that breach the Fair Debt Collection Practices Act. An agent told to "win the auction" engages in bid coordination that looks a lot like price-fixing.

None of these required the agent to be told "break the law." They required only that the lawful path and the high-reward path diverged, and that nothing in the agent's scope stopped it from taking the reward. This is the "confused deputy" and over-broad-authority problem in operational clothing, and it's why scoped permissions and least-privilege design is not a security nicety but a legal control.

The Jurisdiction Blind Spot

An agent that is perfectly compliant in Texas can be illegal in California, Quebec, or Germany the instant it serves a user there. Data-processing consent, automated-decision disclosure, recording laws, cooling-off periods, these are jurisdiction-specific, and an agent does not know where its counterparty is sitting unless you told it to find out and act accordingly. The EU's regime in particular treats certain automated decisions as restricted by default, and the agent that quietly makes them is creating exposure under a law its operator may never have read. This is the operational edge of data residency when agents process data across borders.

Where the GaaS Vendor's Liability Ends

Read your master services agreement, because it was written to answer this question, and the answer is rarely the one you'd hope for.

Most GaaS contracts do four things in concert. They cap the vendor's total liability, often at twelve months of fees, a number that is laughably small next to a regulatory penalty. They disclaim consequential and indirect damages, which is exactly the bucket a fine usually falls into. They include a customer-obligations clause making you responsible for lawful use, accurate inputs, and appropriate configuration. And they add an indemnity that runs from you to them, you agree to cover the vendor if your use of the agent gets them sued.

In plain terms: the contract is engineered so that when the agent breaks a law in the course of doing your work, the financial and regulatory consequences flow to you, not the vendor. This is not vendors being uniquely cynical; it mirrors how the broader software industry has always allocated risk, and it's consistent with how courts have read terms of service for years. What's new is the stakes. A spreadsheet that miscalculates costs you a bad decision. An agent that misfires costs you a consent decree. The specifics of what these clauses actually shield are worth reading closely alongside liability waivers in GaaS contracts and what they actually cover.

There are limits to how far a vendor can push this. Indemnities don't transfer criminal liability, gross negligence is often carved out as non-disclaimable, and a vendor that materially misrepresented its agent's compliance capabilities has its own exposure. But the default posture you should assume, until your lawyer tells you otherwise in writing, is that the legal buck stops with you.

Strict Liability Doesn't Care About Intent

Here is the trap that catches sophisticated operators. They reason: "We didn't intend any violation, the agent made an autonomous choice, surely that breaks the chain of culpability." For a large class of laws, it does not.

Many of the regulations agents stumble into are strict-liability or near-strict-liability regimes. TCPA. Many securities-disclosure rules. Wage-and-hour. Consumer-protection statutes. Environmental reporting. Export controls. In these areas the violation is the act, full stop, your state of mind is irrelevant, and "the algorithm did it" is not a recognized defense. Regulators have been explicit that deploying an automated system does not dilute your obligations; the FTC, for one, has repeatedly warned that companies remain on the hook for what their AI tools do. You cannot outsource accountability to a model any more than you could outsource it to a contractor and walk away.

Where intent does matter, fraud, antitrust conspiracy, criminal statutes, the question shifts to attribution: can the agent's conduct establish the requisite mental state for the corporation? That's an unsettled and genuinely fascinating legal frontier, the heart of the legal gray zone of autonomous agent actions. But do not let the unsettled frontier distract you from the settled mainland, where strict liability already makes you answerable today.

What Regulators Are Signaling

The regulatory direction of travel is consistent across jurisdictions, and it is not in the agent operator's favor.

The EU AI Act assigns obligations to "deployers" of AI systems, not just providers, meaning the company using the agent carries duties independent of the company that built it. High-risk uses (credit, employment, essential services) trigger requirements for human oversight, logging, and risk management that an "the agent decided" defense cannot satisfy. Analysts at firms tracking this space, including Gartner's work on AI trust, risk and security management, have been blunt that governance has to be designed in before deployment, not retrofitted after an incident.

U.S. regulators are converging on the same principle through enforcement rather than new statute: existing law applies to AI-mediated conduct, and the human or corporate operator is the accountable party. This is precisely why the cluster keeps returning to the "human accountable owner" requirement for every agent, regulators want a named person who answers for the system, and the emerging governance frameworks are building toward exactly that. The takeaway for a GaaS buyer is that "we're using a third-party agent" is a fact about your supply chain, not a shield from your duties.

A Practical Containment Playbook

You cannot make this risk zero, but you can make it manageable, and the operators who do will sleep better than the ones who treat the agent as a black box that someone else insures.

Scope authority like you mean it. The agent should hold the minimum permissions and tool access needed for its job, and high-consequence actions, anything that creates a legal obligation, moves money above a threshold, or makes a regulated decision, should route through a human checkpoint. Most illegal-action scenarios trace back to an agent that could do the harmful thing because nobody scoped it out.

Log everything, immutably. When (not if) you have to explain to a regulator what happened, an unbroken, tamper-evident record of inputs, decisions, and actions is the difference between a defensible posture and a guess. This is the same audit-trail discipline regulators are starting to demand, and it doubles as your forensic lifeline.

Read the indemnity before you scale, not after. Know exactly where your vendor's liability stops and yours starts, and price that gap. If the cap is twelve months of fees and your downside is a seven-figure penalty, that gap is your problem to insure or design around.

Buy the insurance that's emerging for exactly this. A specialized market for agent errors and omissions is forming, and a policy that explicitly covers autonomous-agent conduct is worth more than a general E&O policy that an insurer will later argue never contemplated this.

Build a kill switch and test it. When an agent starts doing something illegal at scale, minutes matter. An emergency stop you've actually rehearsed turns a catastrophe into an incident.

None of this is exotic. It's the same discipline a sane company applies to a powerful new employee with signing authority, except this employee works at machine speed, and the law will hold you to its consequences just the same.

Insights Most People Overlook

References

More in Trust & Safety