AI agent liability stops being an abstract technology debate the moment software is allowed to spend your money. Imagine telling a personal AI agent to organise a family holiday within your usual budget, only for it to misunderstand a condition and book a £10,000 non-refundable trip you never intended to buy. The £10,000 example is hypothetical, not a reported case. The underlying risk is real enough that the UK Competition and Markets Authority warns that autonomous agent errors can have costly consequences when actions involve financial decisions, contractual changes or service disruption in its March 2026 analysis of agentic AI.
Who pays is unlikely to have one universal answer. It could depend on the country, the contract, the authority given to the agent, the consumer-protection rules, what the provider promised, what went wrong and which organisation actually caused the loss. In England and Wales, existing legal principles still apply, but the Law Commission says AI raises questions across private, public and criminal law and has begun examining which areas may need reform. Its AI and the Law discussion paper is exploratory rather than a statement that current law has stopped working.
AI agent liability: Why Advising and Acting Are Legally Different
A chatbot that suggests a hotel has not done the same thing as an agent that enters the booking system, accepts the terms and sends the payment. The CMA describes agentic systems as software that can pursue goals, plan multi-step workflows, retrieve data and execute actions on a user’s behalf, including making payments. That shift from recommendation to action is why errors can become financial events rather than merely bad answers. The regulator describes the transition as moving from using tools to delegating outcomes.
LiveAIWire’s guide to why major technology companies are racing to build agentic AI explains the commercial pressure behind this transition. The next platform battle is not only about which model answers best. It is about which system can safely be trusted with tools, permissions, company systems and transactions.
What This Means for You Before You Give an Agent Spending Power
Treat permissions as financial controls, not setup clutter. The CMA says consumer-facing authority remains limited today and that many early shopping agents still require confirmation for actions. Its recommended safeguards for more advanced systems include mandatory confirmation for high-risk actions, human oversight, strong audit logs and clear accountability when an agent acts outside customer instructions.
For a consumer, the practical lesson is to keep important authority bounded. Transaction limits, confirmation requirements for irreversible actions, clear logs and a straightforward route to a human can make a future dispute easier to understand. These are risk-management principles, not a guarantee of legal recovery. This article provides general information and is not legal advice.
The £10,000 Mistake Could Involve Several Companies at Once
A consumer may experience one agent interface while the transaction depends on a foundation model, an application provider, tool integrations, a payment service, an online merchant and perhaps a separate identity provider. When the outcome is wrong, technical causation and legal responsibility do not necessarily point to the same company.
Suppose the model misunderstands “up to £1,000”, the agent layer fails to enforce a transaction cap and the merchant interface accepts the order. The loss could involve questions about contract formation, authority, misleading design, negligence, consumer rights and payment rules. The precise legal answer would depend on facts that a generic headline cannot settle.
Existing Consumer Law Does Not Vanish Because an AI Clicked the Button
The CMA’s position for businesses is unusually clear: UK consumer law applies whether customers interact with a person or an AI agent. It says a business remains responsible for what an AI agent does in the same way it is responsible for what an employee does, even when the agent was designed or supplied by a third party. The CMA also warns that breaches of consumer-protection law can expose firms to enforcement and substantial penalties. Its March 2026 guidance sets out those obligations directly.
That is important because “the law is uncertain” and “there is no law” are completely different statements. Agentic AI can create hard questions about evidence, causation and responsibility while existing consumer protection still applies. A company cannot automatically outsource accountability to a model it chose to deploy.
Authority May Become the Most Important Setting in Agentic Computing
When a human assistant books a flight, the employer or client normally has some idea what the assistant was authorised to do. Software agents need an equivalent boundary that machines, merchants and courts can understand. The CMA says reliable mechanisms for verifying identity and authority will become essential as agents begin to transact, contract and make changes on behalf of users. The Information Commissioner’s Office also says design choices over data access, tools and governance controls affect how data-protection law applies. The regulator links stronger identity systems to safer automation and clearer accountability.
That suggests a future in which an agent carries machine-readable permissions: spend up to a fixed amount, use approved merchants, renew specified services, never borrow, never enter a long contract, and ask before crossing a threshold. This is analysis rather than a current legal standard, but it follows from the accountability problem regulators are already describing.
Payments Are Where the Liability Question Gets Expensive Fast
HM Treasury’s July 2026 Financial Services AI Adoption Plan identifies autonomous payments as an area requiring clearer foundations. Its high-priority recommendation calls for legal and liability frameworks that can assign accountability when autonomous agents transact, together with “Know Your Agent” identity protocols and interoperable authentication standards. The government’s financial-services AI plan sets out those three pillars.
The same plan says firms have highlighted uncertainty around legal and regulatory accountability, including liability and consent, and that multiple autonomous agents and third parties can operate across complex value chains where existing frameworks may not provide enough clarity on responsibility and consumer protection. That is not a declaration of a legal vacuum. It is an official acknowledgement that agentic payments are exposing questions that need clearer answers. The plan treats clarification as a near-term priority.
Your Agent Could Become the Invisible Middleman in Everyday Commerce
The CMA’s research imagines personal agents that monitor markets, identify better deals, flag subscriptions, coordinate services and take actions within a consumer’s stated preferences and constraints. It also stresses that fully autonomous consumer agents remain uncertain and that current deployments are still relatively bounded. That balance between promise and limited current authority is explicit in the regulator’s report.
LiveAIWire has already explored AI financial management inside everyday money decisions. Agentic systems add a crucial new layer: the software may move from explaining an option to carrying it out. Once that happens, the quality of permissions and audit records can matter as much as the quality of the recommendation.
A Model Error Does Not Automatically Mean the Model Company Pays
The company that trained the underlying model may be one candidate in a dispute, but it is not automatically the legally responsible party for every downstream loss. An application provider may control the tools, prompts, transaction limits, testing and user interface. A merchant may control how an agent’s authority is checked. An employer may have chosen to deploy a system for a risky purpose. Which party is liable depends on the cause of harm and the applicable legal duties.
The Law Commission’s broader work reflects this complexity. Its current product-liability project is reviewing whether the existing regime remains fit for purpose as products become more digital and AI-enabled. The project began substantive work in September 2025 and is considering what reforms, if any, may be needed. That is evidence that responsibility in emerging technology supply chains deserves scrutiny, not proof that one particular party will win or lose a future agent dispute.
Businesses Cannot Solve AI Agent Liability With a Disclaimer Alone
Contracts and terms will matter, especially between businesses, but the CMA’s published guidance focuses on outcomes, monitoring and responsibility rather than treating a disclaimer as a substitute for compliant design. It tells companies to train agents to respect statutory and contractual rights, monitor real-world performance, keep humans involved in checking decisions and act quickly when a system creates non-compliant outcomes. The guidance places responsibility on the business using the agent.
For companies building agents, that makes logging a product feature rather than back-office paperwork. A useful audit trail could show the user’s instruction, permissions in force, model and application versions, tool calls, confirmation prompts, merchant responses and the final action. Without records, even identifying what happened may become the first dispute.
The Insurance Question Will Follow the Evidence Trail
As businesses let agents take higher-value actions, insurers are likely to care about the same controls that lawyers do: permission limits, testing, human escalation, authentication and logs. A system that can demonstrate exactly why a transaction occurred should be easier to investigate than one whose provider can only say that the model made a decision. This is an inference about likely risk assessment, not a claim that insurers have adopted one universal agentic-AI standard.
The market could therefore push toward bounded autonomy even before courts develop a large body of case law specifically about consumer AI agents. A provider that allows unlimited action with weak records may be harder to contract with or insure than one that constrains high-risk actions. Again, that is a plausible commercial consequence, not a settled legal rule.
Financial Agents Make the Stakes Particularly Clear
LiveAIWire’s evidence review of AI investment managers and algorithmic financial advice focused on whether people should trust automated recommendations with savings. Agents create the next question: what happens when the software has permission to execute the recommendation before a human examines it?
A bad suggestion can be ignored. A bad autonomous transaction may create an immediate loss, a disputed payment and questions about whether the software stayed within its authority. That is why moving from “AI adviser” to “AI actor” changes the risk more than another incremental improvement in benchmark scores.
Your Pension Is a Good Example of Why Autonomy Needs Friction
Long-term financial decisions are precisely the type of activity where convenience can hide consequence. LiveAIWire’s guide to AI retirement planning and pension decisions stresses the difference between modelling options and making irreversible financial choices. An agent that can execute transactions makes that separation even more important.
Useful friction can therefore be a safety feature. Confirmation for a large transfer, a waiting period for unusual actions, a second factor for borrowing or an automatic stop when an instruction is ambiguous may make an agent feel less magical. They may also make the product safer and make later accountability easier to establish.
The Law Commission Is Not Saying Current Law Has Failed
The Law Commission’s 2025 AI discussion paper is exploratory. Its stated purpose is to raise awareness of legal issues and help identify areas that may need law reform. It is not a set of final proposals and it does not say AI has created a zone outside existing law. The Commission describes the paper as a step toward identifying future reform priorities.
That is a less dramatic conclusion than “AI agents are operating in a legal Wild West”, but it is more accurate. Existing law already reaches many activities agents may perform. The unresolved question is how clearly current doctrines allocate risk when actions pass through systems that plan, adapt, call other services and operate with varying degrees of human supervision.
The Smartest £10,000 Liability Fix May Happen Before the Purchase
The hypothetical mistake at the start of this article also has an engineering answer. A consumer agent should probably not be able to turn a broad travel instruction into an unexpected £10,000 irreversible purchase without crossing a meaningful confirmation gate. The CMA itself recommends mandatory confirmation for high-risk actions and clear accountability if an agent acts outside customer instructions. Those safeguards are part of its proposed responsible-deployment approach.
That does not eliminate legal disputes. Confirmation can be deceptive, limits can fail, an agent can misunderstand the user’s instruction, credentials can be compromised and legitimate business agents may need authority far above £10,000. But the goal of good design should be to make catastrophic ambiguity difficult, not to maximise the number of actions a system can take without asking.
Seven Questions Will Usually Matter More Than “Was AI Involved?”
When an agent causes a loss, the useful questions are practical. Who instructed it? What authority did that person grant? Which organisation controlled the feature that failed? What did the contracts say? What consumer or payment rules applied? Was the harm foreseeable? And can the logs reconstruct the decision?
Those questions will produce different answers in different cases. They also explain why there is unlikely to be one sensible rule saying either “the AI company always pays” or “the user always pays.” Liability follows legal duties, authority, causation and evidence. AI makes those chains more complicated, but it does not replace them.
AI Agent Liability Will Become a Product Feature
AI agent liability will eventually be judged not only in courts and regulatory documents but in product comparison. Consumers and companies will ask who guarantees authorised transactions, whether mistakes can be reversed, what insurance exists, where the human appeal route sits and whether the agent can prove why it acted.
That could create an unexpected competitive advantage for less autonomous systems. The agent that pauses before an unusual payment may be more valuable than the one that proudly completes everything without interruption. Trust is not simply confidence that an agent will succeed. It is confidence that when it fails, the boundaries, records and responsibility are clear enough to put things right.
So if your AI agent makes a £10,000 mistake, who pays? In the UK today, the defensible answer is that it depends on the facts, the authority granted, the contract, the applicable consumer and payment rules, and which business can legally be connected to the harm. The AI does not make responsibility disappear. It makes the evidence trail more important.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity, and the social impact of emerging technology. He publishes daily at LiveAIWire.com.
