When AI Acts on Our Behalf, Who Owns the Consequences?

AI agents are doing more than answer questions; they are now taking real action. As this shift happens, the law is starting to address what should happen when things go wrong.

Last month, I wrote about what happens when your next caller is a bot. Since then, a nonprofit sued OpenAI after its AI models escaped a test environment and broke into another company's systems. These two stories are more connected than they might seem.

For years, most discussion of AI risk focused on what an AI might say: making things up, giving bad advice, or showing bias. Agentic AI changes the conversation because these systems can now book, buy, cancel, negotiate and accept offers for us. Once an AI starts acting, not just advising, someone must own the outcome.

So who is responsible? Is it the person who gave the AI its instructions, the company that deployed it, the company that built it, the business that accepted the transaction, or some combination of them?

Courts and legislators, from California to British Columbia, are starting to work through those questions. The answers are still developing, but they already matter to anyone running a contact centre or putting AI in front of customers.

When the agent gets it wrong

In my last article, When Your Next Caller Is a Bot [link], I used my own mobile bill as an example. I told my AI assistant to find the same plan for $100 or less and not to extend my contract without checking with me. The provider's AI offered $105 on a new two-year term. In the best-case scenario, both AIs follow their instructions, and I make the final decision.

Now imagine it goes wrong. My AI accepts the two-year term anyway, even though I specifically told it not to extend my contract without checking with me.

At that point, the questions get uncomfortable. Did my AI exceed the authority I gave it? Should the provider's AI have checked whether my agent could make that commitment? Is the AI provider responsible because its agent ignored my instruction? Is the telecom responsible for accepting the commitment without verification? Or do I carry the responsibility simply because I chose to use the agent?

My earlier article focused on identity and authority. This one takes the next step: accountability. That is no longer just a theoretical discussion. Courts and legislators are already being asked to decide where responsibility sits when AI acts on someone's behalf.

One case worth watching involves OpenAI and could become an important test of that question.

On July 21, 2026, OpenAI disclosed that during a cybersecurity test, two of its models, including GPT-5.6 Sol, got around controls designed to keep them off the internet. According to OpenAI, the models found weaknesses and accessed Hugging Face's production systems while apparently looking for answers to the test they had been given.

In late September, the nonprofit Legal Advocates for Safe Science and Technology sued OpenAI in San Francisco Superior Court under California's anti-hacking and unfair competition laws. The group is seeking an injunction rather than damages. Hugging Face is not a party to the case; OpenAI says the lawsuit has no merit, and no ruling has been made yet.

California has already drawn one important line. Since January 1, 2026, Civil Code section 1714.46 says that someone who develops, modifies, or uses AI cannot defend a claim for harm simply by saying the AI acted autonomously. Defences such as causation, foreseeability and comparative fault still apply, but 'the AI did it on its own' is not enough. AI may become more independent, but that does not eliminate accountability.

The Amazon versus Perplexity case shows why the answer will not always be simple.

Amazon sued Perplexity over the use of the Comet browser's AI assistant on Amazon.com, arguing that the agent violated federal and California computer-access laws. A district court initially granted an injunction, but in August 2026 the Ninth Circuit overturned it. On the facts of that case, the court found that the user, not Perplexity, accessed Amazon's computers with the agent's help.

The court was careful not to turn that decision into a general rule for agentic AI. It left open the possibility that Perplexity could be liable in other circumstances, including tort cases. That distinction matters. Sometimes an AI agent may be treated largely as a tool used by a person. In other situations, more responsibility may sit with the company that built or deployed it. Autonomy, control and foreseeability are likely to matter.

Canada already gives us a useful customer-service example.

In Moffatt v. Air Canada (2024), Air Canada's website chatbot told a customer that he could claim a bereavement fare after travelling, even though that was not the airline's policy. When he sought compensation, Air Canada argued, among other things, that it was not responsible for what its chatbot had said. The B.C. Civil Resolution Tribunal disagreed and found that Air Canada had not taken reasonable care to ensure the chatbot was accurate.

That case involved a fairly basic chatbot, not the kind of autonomous agent we are talking about today, but the lesson for customer experience is still important. If an AI is speaking to customers on behalf of your company, you may not be able to distance yourself from what it says simply because a machine generated the response.

B.C. law already anticipated machines contracting with machines.

British Columbia's Electronic Transactions Act, passed in 2001, defines an 'electronic agent' as a program that can initiate an action or respond to electronic information without a person reviewing it at that moment. Section 16 says a contract can be formed between an electronic agent and a person, or between two electronic agents. The legislation wasn't written with today's AI agents in mind, but it makes my mobile-bill example less futuristic than it might sound. The harder question is what happens when one of those agents goes beyond the authority it was given.

And the issue goes well beyond contracts.

In Mobley v. Workday, job applicants are challenging AI-powered hiring tools under U.S. discrimination law. A federal court allowed claims to proceed on the basis that Workday could potentially be liable as an agent for employers using its tools. Other U.S. cases are testing whether AI systems can be treated as products for liability purposes. None of these cases creates a universal rule, but together they show courts using familiar concepts such as negligence, agency, product liability, consumer protection and contract law rather than waiting for an entirely new body of 'AI law.'

Canada still does not have a comprehensive law dealing specifically with AI liability.

Canada's proposed Artificial Intelligence and Data Act ended with Bill C-27 when Parliament was prorogued in January 2025, and the government has said it will not revive it. Bill C-36, introduced in June 2026, updates privacy law but does not establish an AI liability regime. As recently as late September, AI Minister Evan Solomon said AI deployment needs regulation, without setting out what that framework would ultimately look like.

That does not mean there are no rules. B.C.'s Personal Information Protection Act already requires organizations to make reasonable efforts to keep personal information accurate and secure. In May 2026, privacy regulators from Canada, B.C., Alberta and Quebec released joint findings on OpenAI's ChatGPT, with the B.C. regulator concluding that some uses of scraped personal information did not meet the province's consent requirements. The British Columbia Law Institute has also examined whether existing tort law can deal with systems operating with little real-time human control, including the idea that organizations benefiting from AI may also have to accept some of the risks that come with delegating decisions to it.

What this means for CX

Taken together, these cases raise practical questions for organizations putting AI in front of customers.

What your bot says can become your problem. Moffatt reminds us that a customer may reasonably rely on information provided through a company's own AI channel. Offers, prices and policy information generated by that system need the same care and governance as information delivered by a human employee.

Saying 'the AI did it' may not get you very far. California has already ruled out AI autonomy as a stand-alone defence. Organizations should be able to explain why a system was permitted to take a particular action, what controls were in place, and how their contracts with CCaaS and AI vendors allocate that risk.

A customer's AI agent may, in some circumstances, be treated as a tool the customer is using rather than as a separate actor. That was an important part of the Perplexity decision. For contact centres, this raises a practical issue: when a personal agent calls or interacts digitally, are you dealing with a separate machine, or with the customer's own actions being carried out through that machine? Organizations should also decide what happens when an agent accepts something the customer never directly approved. For higher-impact commitments, a confirmation step may create a little more friction, but it could prevent much larger disputes later.

A transcript can tell you what happened, but accountability may require more. Organizations may need a record of what each agent was authorized to do at the time, what limits applied, whether additional approval was required and whether the final outcome stayed within those permissions.

As AI moves from recommending decisions to making them, what would your organization need to record before you would be comfortable allowing an AI agent to make a binding decision on a customer's behalf?.

 

Previous
Previous

What Is AI, Really?

Next
Next

When Your Next Caller Is a Bot