top of page

Agentic AI in Business: Who Is Legally Responsible When AI Makes Decisions?

  • Writer: Support Legal
    Support Legal
  • 11 minutes ago
  • 5 min read

Artificial intelligence is moving beyond tools that simply respond to instructions. The next stage is agentic AI: systems capable of analysing information, setting objectives, making decisions and taking actions with limited human intervention.

 

Businesses may use agentic AI to approve transactions, manage customer interactions, assess risk, negotiate with suppliers, monitor compliance or make operational decisions. As these systems become more autonomous, an important legal question arises: who is responsible when the AI makes the wrong decision?

 

The short answer is that the AI itself is unlikely to be legally responsible. Responsibility will generally continue to rest with the human beings and legal entities that develop, deploy, control or benefit from the system.

 

Agentic AI and the Question of Responsibility

Traditional AI systems typically perform a defined task based on human instructions. Agentic AI is different because it may make decisions across multiple stages, adapt to changing circumstances and take actions without requiring approval for every individual step.

 

This creates a potential accountability gap. If an AI agent approves an unsuitable transaction, sends confidential information to the wrong recipient, makes a discriminatory decision or causes financial loss, responsibility may involve several parties.

 

The developer may be responsible for defects in the system. The business deploying the AI may be responsible for inadequate testing, supervision or controls. Employees may be responsible if they misuse the system or fail to follow established procedures.

 

The fact that an AI system acted autonomously will not necessarily remove the responsibility of the organisation that chose to deploy it.

 

The UAE's Approach: Accountability, Oversight and Transparency

The UAE has adopted a policy-driven approach to AI governance that emphasises ethical and responsible development and use of artificial intelligence. The UAE Charter for the Development and Use of Artificial Intelligence highlights principles including transparency, human oversight, governance and accountability.

 

These principles are particularly relevant to agentic AI. The more autonomy a system has, the more important it becomes for businesses to establish clear controls over what the system may do, what decisions require human approval and who is responsible for monitoring its actions.

 

The UAE's current AI governance approach also emphasises safety, privacy and accountability rather than treating AI as a technology that operates outside existing legal responsibilities. The UAE's National Cyber Security Policy for AI further addresses governance, infrastructure protection, algorithm security, operational safety and threat monitoring.

 

Existing Laws May Already Apply

The absence of a single comprehensive AI liability law does not mean that businesses operate without legal obligations.

 

Existing laws may apply depending on the activity and the harm caused. Contract law may become relevant where an AI agent enters into or performs contractual arrangements. Consumer protection rules may apply to automated customer decisions. Employment laws may be relevant where AI is used in recruitment, performance management or workplace decisions. Financial services, competition, intellectual property, cybersecurity and sector-specific regulations may also apply.


Data protection is particularly important. Under the UAE Personal Data Protection Law, individuals have rights in relation to decisions resulting from automated processing, including decisions that have legal or similarly significant effects. The law also provides for human involvement in reviewing certain automated decisions.

 

Accordingly, a business cannot necessarily avoid responsibility by arguing that an AI system made the decision independently.

 

Who May Be Responsible?

Responsibility will depend on the facts and the role played by each party.

The business deploying the AI will often be the primary focus because it selected the system, defined its purpose and allowed it to operate within the organisation. If the business failed to conduct appropriate testing, establish safeguards or monitor the system, it may face legal and commercial consequences.

 

The technology provider may also face responsibility where the harm results from a defect, failure to meet contractual obligations or inadequate security.

 

Employees and managers may remain responsible for decisions made within their authority, particularly where they ignored warning signs, misused the system or failed to comply with internal procedures.

 

The central principle is that responsibility should be allocated according to control, decision-making authority and the ability to prevent or reduce the risk.

 

Human Oversight Cannot Be Merely Symbolic

A common mistake is to appoint a human reviewer without giving that person the information, authority or time necessary to challenge an AI decision.

 

Effective human oversight requires more than simply having a person somewhere in the process. The organisation should understand what the AI is permitted to do, identify decisions that require human intervention and establish procedures for reviewing, reversing or escalating decisions.

 

The level of oversight should also reflect the risk. An AI agent recommending office supplies may require limited supervision. An AI agent making decisions affecting a person's employment, finances, access to services or legal rights requires significantly stronger controls.

 

Contracts and AI Governance

Businesses using agentic AI should carefully allocate responsibility through contracts.

Agreements with AI providers should address system performance, data protection, confidentiality, cybersecurity, intellectual property, audit rights, incident reporting and liability.

 

The business should also establish internal AI governance policies covering approved uses, access controls, human approval requirements, recordkeeping and escalation procedures.

 

Maintaining records of significant AI decisions may become particularly important. If a business cannot explain why an AI agent took a particular action, it may face difficulties responding to customer complaints, regulatory investigations or legal claims.

 

The Risk of Autonomous Action

Agentic AI creates a new category of operational risk because the system may take action rather than merely provide information.

 

An AI agent may send an email, execute a transaction, change a database record or communicate with a third party. This creates a need for technical and legal safeguards, including limits on the agent's authority, approval thresholds, access controls and the ability to stop or reverse its actions.


Businesses should therefore treat agentic AI more like an employee or automated decision-making process with defined authority than as ordinary software.

 

The Future of AI Liability

As agentic AI becomes more widely used, legal disputes are likely to focus less on whether AI can be blamed and more on whether the people and organisations behind the system acted reasonably.


Key questions may include whether the AI was properly tested, whether the business understood its limitations, whether adequate safeguards were in place and whether human oversight was genuinely effective.

 

For UAE businesses, the developing AI governance environment reinforces an important principle: innovation does not eliminate accountability.

 

The organisation that deploys an AI system cannot simply say that “the AI made the decision.” Legal responsibility will depend on who designed the system, who deployed it, who controlled its operation and who failed to prevent foreseeable harm.

 

Agentic AI may transform how businesses operate, but the legal framework will continue to require accountability from the humans and companies that place these systems into the real world. The future of AI governance will therefore not be about preventing businesses from using autonomous systems. It will be about ensuring that autonomy is accompanied by appropriate controls, transparency and clearly allocated responsibility.

Comments


bottom of page