The Agent Liability Gap: Nobody Has Decided Who Pays When Software Acts

The Agent Liability Gap: Nobody Has Decided Who Pays When Software Acts

An agent issues a refund that should not have been issued. An agent emails a customer a commitment the company cannot honour. An agent runs a data migration and deletes a table that was not in scope. In every case something of value moved, somebody is worse off, and the money to fix it comes from a specific budget. The question of whose budget has no settled answer anywhere in enterprise software right now, and the absence of an answer is not a legal curiosity. It is the reason a large share of agent pilots stop one step short of doing anything that matters.

The pattern is consistent enough to be diagnostic. A pilot runs with a human approving every action, performs well, and produces a business case that depends entirely on removing the approval step. The removal never happens. It is rarely blocked by model quality, and rarely by security, which has a mature process for saying yes with conditions. It stalls because no executive will sign the document saying this system may take unreviewed action on behalf of the company, and no such document exists in a signable form, because the answer to what happens when it goes wrong is currently that the deploying enterprise absorbs it entirely, with no recourse worth exercising.

That is the gap. Not an unanswered legal question in the abstract, but an unpriced risk sitting between three parties who have each quietly assumed somebody else holds it. The gap is closing, slowly, through contracts rather than legislation, and the shape it takes will decide which vendors get to sell autonomy and which ones keep selling copilots.

Exposure by party

Where the Loss Lands Today

Three parties participate in every agent action, and their exposure is wildly asymmetric.

The deploying enterprise holds almost all of it. It authorised the deployment, granted the credentials, configured the scope, and to the counterparty on the other side of the action it is simply the company that did the thing. Nothing about an agent changes the enterprise's obligation to its own customers, which is the most important fact here and the one most often skipped. A wrongly denied claim is a wrongly denied claim. A regulator examining an adverse decision does not accept "the model produced it" as an account of what happened, any more than it accepts "the junior analyst produced it".

The model vendor holds nearly none of it. Standard enterprise terms disclaim consequential and indirect damages, cap total liability at a multiple of fees paid over a trailing period, and place output accuracy on the customer. The indemnities that exist are narrow: intellectual property indemnity on output, which several vendors now offer with conditions, protects against a copyright claim, not against the agent having sent the wrong wire. That is rational from the vendor's side, which cannot see the customer's data, the tools it connected, or the authority it granted. It is also how enterprises discover that a platform fee cap is a rounding error next to one mispriced recommendation shipped ten thousand times.

The tool and integration provider is usually out of scope entirely. The payment API, the CRM, the internal service the agent calls: each executed a properly authenticated request from a credential the enterprise issued. There is no defect to point at. The system did exactly what it was asked, which is the whole problem, and this is the layer where the identity and access architecture is doing the real work, because the credential the agent presented is what converted a model output into a consequence.

Party What it absorbs today What its contract usually says Where the allocation breaks
Deploying enterprise Essentially all of it: remediation, customer make-good, regulatory exposure, reputational cost Nothing limits it. Obligations to its own customers are unchanged by how the work was performed It is the only party that cannot cap its exposure, and its recovery from anyone else is limited to fees paid
Model vendor Almost none. Narrow IP indemnity on output, capped fees, consequential damages disclaimed Output is not warranted, accuracy is the customer's responsibility, liability capped at trailing fees The cap is unrelated to the size of the loss, and the cap is per contract while the exposure is per action, repeated
Tool or integration provider None. It honoured an authenticated request Standard service terms. Correct execution of an authorised call is not a defect Nothing is wrong at this layer, which is why nothing can be recovered at this layer
Agent platform or orchestrator Very little today, and this is the layer most likely to move Follows the model vendor's shape, often with thinner terms It controls the guardrails, the action scope, and the audit record, which makes it the only credible candidate to take on real exposure
Insurer A narrow and newly written slice Technology errors and omissions, with AI treated as either silent or explicitly endorsed Coverage assumes negligence with a human decision-maker somewhere in the chain

Read down the middle column and the structure is clear. Every party except the enterprise has capped its exposure, and the enterprise has no counterparty capable of absorbing what it holds. That is not a market that has allocated risk badly. It is a market that has not allocated it at all.

Underwriting questions

This is a Premium Article

Sign up for a Premium membership to read this article and get full access to strategic intelligence on technology and business.

Get Premium Access