ASTRÆA COUNSEL
  • Home
    • Team
    • How We Work
    • Speaking
    • Press & Recognition
    • Results & Case Studies
    • Pricing
    • Litigation & Disputes
    • Business Partner Disputes
    • Commercial Litigation
    • Crypto Litigation
    • SEC Enforcement Defense

    • Crypto & Digital Assets
    • AI & Emerging Tech
    • DAOs
    • Fund Formation

    • Browse All Practice Areas
  • Insights
  • Contact
(310) 800-1780Book a Call

ASTRAEA COUNSEL

Trial and regulatory counsel for high-stakes disputes and digital-asset, fintech, and AI companies.

info@astraea.law

(310) 800-1780

Beverly Hills, CA

Practice Areas

  • Digital Assets & Blockchain
  • Litigation & Disputes
  • Artificial Intelligence & Emerging Tech
  • Securities Enforcement & Investigations
  • Fintech & Payments
  • Corporate & Transactions
  • Regulatory Compliance

Litigation

  • Litigation & Disputes
  • Business Partner Disputes
  • Commercial Litigation
  • Crypto Litigation
  • SEC Enforcement Defense
  • Results & Case Studies

Resources

  • Latest Insights
  • Token Classifier
  • GENIUS Act Compliance Clock
  • Our Team
  • Press & Recognition
  • Contact

The Firm

  • DAO & Governance
  • How We Work
  • Pricing
  • Speaking

© 2026 Astraea Counsel, APC. All rights reserved.

Privacy PolicyTerms of Use

Attorney Advertising. Attorney Advertising. The material on this website is for informational purposes only and does not constitute legal advice. No attorney-client relationship is created by accessing or using this website. Any result portrayed on this website was dependent on the facts of that case, and the results will differ if based on different facts. Astraea Counsel, APC is a California Professional Corporation. Chanté Eliaszadeh (State Bar No. 335803) and Brandon Orewyler (State Bar No. 324391) are licensed to practice law in California only. The firm is not certified by the State Bar of California as a specialist in any field.

This site uses Google Analytics to improve user experience. See our for details.Privacy Policy for details.

Skip to main content
  1. Home/
  2. Insights/
  3. Not an Agent. Not a Defense: Seven Doctrines That Already Hold AI Deployers Liable
Thought Leadership

Not an Agent. Not a Defense: Seven Doctrines That Already Hold AI Deployers Liable

White & Case|Dechert|U.S. Securities and Exchange Commission, Cyber Unit|UC Berkeley Law

March 18, 2026•Updated September 4, 2026•Chanté Eliaszadeh
AI GovernanceAI LiabilityProducts LiabilityCorporate GovernanceCompliance
“Most companies hear that their AI is not a legal agent and feel relief. They should not. Agency law is old, well-litigated, and full of defenses—frolic and detour, scope of employment, the independent-contractor line—that centuries of common law built to limit a principal's exposure. A deployer whose AI is a tool rather than an agent inherits the liability without inheriting any of them.”
Chanté Eliaszadeh · Principal Attorney, Astraea Counsel APC

I. Things Are Not As They Seem

The technology industry calls them agents. The word carries weight—legal weight. Agency is one of the oldest doctrines in common law, governing the relationship between a principal and the person authorized to act on its behalf. It comes with a body of settled law: duties of loyalty, apparent authority, vicarious liability, scope of employment, and a century of defenses that limit when a principal can be held responsible for an agent’s conduct. When companies deploy what they call “AI agents,” they inherit the connotation of that entire legal framework. The implication is that the AI acts on behalf of the company, within a relationship the law recognizes and regulates.

It does not. When the technology industry says “agent,” it means something the law does not recognize. And the distinction matters more than most deployers realize.

Under the Restatement (Third) of Agency—the authoritative synthesis of American agency law—an agency relationship arises “when one person (a ‘principal’) manifests assent to another person (an ‘agent’) that the agent shall act on the principal’s behalf and subject to the principal’s control.”1 The operative word is “person.” The Restatement does not leave the term unexplained. To be capable of acting as a principal or an agent, its commentary says, “it is necessary to be a person, which in this respect requires capacity to be the holder of legal rights and the object of legal duties.”2

Capacity is the threshold the definition assumes—the ability to hold rights, to bear obligations, to be a party to a legal relationship. An AI system has none of these attributes. It cannot consent to a fiduciary relationship. It cannot bear obligations. It cannot be sued. The Restatement says so directly: a computer program “is not capable of acting as a principal or an agent as defined by the common law,” and computer programs “are instrumentalities of the persons who use them.” Agency is a relationship between legal persons, and AI is not one.

The industry calls them agents. The law calls them tools.

This article examines why that distinction does not protect the companies deploying AI—and why, in most cases, it makes their legal exposure worse. The doctrines that apply when AI causes harm are not the structured, defense- rich framework of agency law. They are negligence, products liability, trade secret misappropriation, spoliation, regulatory enforcement, direct liability for AI decision-making, and board-level oversight obligations—doctrines that impose direct liability on the deployer without the intermediary that agency law would provide.

If agency law applied, deployers would have defenses. It does not, and they do not.

Key Takeaways

  1. An AI agent is not a legal agent: the Restatement of Agency requires a person on both sides of the relationship, and its own commentary calls computer programs instrumentalities of the people who use them.

  2. The missing agency defenses cut against the deployer: frolic-and-detour, scope of employment, and independent-contractor classification all presuppose two legal persons, so an AI system’s harm lands on the deployer and its tool alone.

  3. Board oversight and logging are the live exposures: under Marchand, directors must make a good faith effort to implement a reporting system for mission-critical risks, and an agent whose actions were never logged leaves a Rule 37(e) spoliation problem behind.

  4. An agent can still bind you: UETA Section 14 and E-SIGN treat an electronic agent’s action as contract formation wherever it is legally attributable to the deployer.

  5. The doctrines compound: each governance gap makes every other claim easier to prove, so the only rational response is a comprehensive one.

II. The Pivot: Why “Not an Agent” Is Bad News

Most companies hear that their AI is not a legal agent and feel relief. They should not.

Agency law is old, well-litigated, and—critically—full of defenses. If AI agents were legal agents under the Restatement, deployers would inherit a framework that centuries of common law developed to limit a principal’s exposure.

The frolic-and-detour defense allows a principal to argue that an agent departed from its assigned duties for personal purposes, taking the agent’s conduct outside the scope of employment and relieving the principal of liability. The scope-of-employment limitation allows a principal to draw boundaries around what the agent was authorized to do and disclaim responsibility for conduct beyond those boundaries. The independent-contractor classification allows a principal who controls the result but not the method to avoid vicarious liability for the contractor’s conduct—leaving the principal answerable for its own negligence, its non-delegable duties, and what it authorized.3

None of these defenses are available when the actor is not an agent. They are not available because they presuppose a relationship between two legal persons --- a principal and an agent—in which the agent has independent legal existence, capacity for volition, and the ability to depart from instructions for its own reasons. AI has none of these attributes. It is not a person who can go on a frolic. It is not an agent who can exceed its scope. It is not a contractor who controls its own methods.

It is a tool. And the entity that built, configured, deployed, and equipped that tool is not a principal managing an agent. It is an operator responsible for everything the tool does—directly, without the intermediary that agency law would provide.

When a human employee causes harm, the employer has a structured body of law that allocates liability between principal and agent, that provides defenses based on scope and authorization, and that has been refined across thousands of cases. When an AI system causes harm, there is no allocation. There is no intermediary. There is the deployer, its tool, and the damage.

The doctrines that fill this space are not more lenient than agency law. They are less.

III. The Doctrines That Do Apply

Seven existing legal doctrines create direct deployer liability for AI agent conduct—none of which require a court to treat AI as a person or an agent.

A. Board Oversight: Caremark Meets AI

In 1996, the Delaware Court of Chancery articulated in In re Caremark International Inc. Derivative Litigation the standard that has governed board-oversight claims since: a “sustained or systematic failure of the board to exercise oversight” establishes the lack of good faith that is a necessary condition to director liability.4 Caremark claims have long been, in the Delaware Supreme Court’s words, “difficult to plead and ultimately to prove out”:5 boards that could point to a relevant committee, a regular protocol of board-level reports, or third-party monitors have routinely won dismissal.

Then the Delaware Supreme Court changed the calculus.

In Marchand v. Barnhill (2019), the Delaware Supreme Court reversed the dismissal of a Caremark claim against Blue Bell Creameries’ directors, holding that the complaint alleged particularized facts supporting a reasonable inference that the board “failed to implement any system to monitor Blue Bell’s food safety performance or compliance”—the company’s “essential and mission critical” risk. Marchand restated and applied the two-part test—articulated in Caremark and adopted as the Delaware Supreme Court’s holding in Stone v. Ritter—that every board must satisfy for its central compliance risks: first, the board must make a good faith effort to implement a reporting system; second, the board must actually monitor what that system reports. Blue Bell’s board had no system at all: no committee overseeing food safety, no board-level process to address food safety issues, and no protocol by which the board was expected to be advised of food safety reports. The court found that sufficient to state a claim for bad faith.5

The Court of Chancery applied that standard in In re Boeing Co. Derivative Litigation (2021), denying in part a motion to dismiss oversight claims against Boeing’s board after the 737 MAX crashes. The board had left airplane safety to management’s discretion—no committee charged with monitoring safety, no expectation of safety content in the reports it received—and discretionary management updates that mentioned safety within general operations were not enough. The court held that airplane safety, like food safety in Marchand, was “essential and mission critical” to Boeing’s business, and that leaving safety compliance to management’s discretion rather than implementing and then overseeing a structured compliance system satisfied Marchand’s first prong.6

Two features of this doctrine make it particularly significant for AI agent governance.

First, Caremark claims sound in the duty of loyalty, not the duty of care. The Delaware Supreme Court confirmed this in Stone v. Ritter (2006): a knowing failure to implement oversight constitutes bad faith, which is a breach of loyalty.7 This distinction matters because a Section 102(b)(7) charter provision “can exculpate directors from monetary liability for a breach of the duty of care, but not for conduct that is not in good faith or a breach of the duty of loyalty.” A director cannot invoke the charter to excuse a conscious failure to monitor a risk the board knew was mission critical—Stone requires a showing that the directors knew they were not discharging their fiduciary obligations.

Second, directors must inform themselves before making decisions. Under Smith v. Van Gorkom (1985), the business judgment rule only applies when directors act on an informed basis. A board that authorizes AI agent deployment without reviewing the publicly available risk literature—the OWASP Top 10 for Agentic Applications, the documented breach history, the regulatory enforcement trajectory—risks a finding that it failed to inform itself “of all material information reasonably available to [it],” which is the showing that rebuts the presumption. Van Gorkom strips the presumption of protection from uninformed decisions, even those made in good faith.8

For companies deploying AI agents at scale, agent governance is becoming a central compliance risk under the Marchand framework. A board that deploys agents in production without any governance reporting system—no agent inventory, no monitoring, no incident reporting pathway to the board—fails Marchand’s first prong. A board that has some AI governance structure on paper but never reviews its output, never asks management about agent incidents, and never adjusts deployment based on risk findings fails the second.

No reported decision has yet applied Caremark to AI agent oversight. The doctrinal extension is natural, and it is a question of when—not whether—a plaintiff’s firm makes this argument. When that happens, directors who cannot answer three questions—“What AI agents are operating in our company? What are they authorized to do? How do we know they are doing it?”—face the same exposure that Blue Bell’s directors faced.

And that exposure is personal. Because Caremark claims sound in loyalty, a Section 102(b)(7) charter provision cannot exculpate the director: the statute excludes “any breach of the director’s or officer’s duty of loyalty” and “acts or omissions not in good faith.” Whether a given D&O policy responds is a separate question governed by the policy’s own bad-faith exclusion.

B. The Evidentiary Trap: Spoliation, Adverse Inference, and the Cost of Not Logging

Every legal dispute involving an AI agent—regulatory investigation, customer lawsuit, employment discrimination claim, breach notification—will begin with the same demand from opposing counsel: produce the agent’s decision chain. What inputs did it receive? What tools did it call? What outputs did it produce? What was the sequence? Can you prove it?

For most companies deploying AI agents today, the answer to that last question is no. And that creates a compounding problem that is procedural, not substantive—meaning it applies regardless of the underlying theory of liability and regardless of whether the agent actually did anything wrong.

Under Federal Rule of Civil Procedure 37(e), when electronically stored information “that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it, and it cannot be restored or replaced through additional discovery,” the court has two options. Upon finding prejudice to another party from the loss, it may order measures no greater than necessary to cure the prejudice. Or, only upon finding that the party acted with the intent to deprive another party of the information’s use in the litigation, it may presume the lost information was unfavorable, instruct the jury that it may or must so presume, or dismiss the action or enter a default judgment.9

The preservation duty does not wait for a complaint. It is triggered by the reasonable anticipation of litigation. Judge Scheindlin’s framework in Zubulake v. UBS Warburg (S.D.N.Y. 2003) established the seminal standard: a party must preserve all relevant documents—including electronically stored information—when it “reasonably anticipates litigation.” The duty includes an affirmative obligation to implement a litigation hold and prevent the destruction of relevant evidence.10

For companies deploying AI agents, the preservation duty is already triggered. Any company using AI in employment screening reasonably anticipates discrimination litigation after Mobley v. Workday.11 Any company acting as a provider or deployer of an in-scope AI system in the EU market reasonably anticipates regulatory investigation once the AI Act’s obligations apply to it. Any company that has experienced or read about AI security incidents reasonably anticipates breach litigation. The universe of companies deploying AI agents for which litigation is not reasonably foreseeable is vanishingly small.

The question, then, is whether the company took “reasonable steps” to preserve the relevant information. For AI agent decision chains, this analysis is devastating for companies without logging infrastructure. Agent actions are ephemeral by default. Context windows are overwritten. Tool calls go unrecorded unless logging is affirmatively implemented. And unlike financial transactions, which leave traces in ledgers and blockchains, AI agent decisions are non-reproducible—the stochastic nature of large language model outputs means the same inputs will not produce the same outputs. If you did not log it contemporaneously, it is gone.

The “reasonable steps” standard is informed by what is available and what it costs. Open-source agent logging frameworks provide action-level monitoring with negligible performance overhead at reasonable cost. A court evaluating whether a company took reasonable steps will ask why it did not implement logging—and the answer “we did not think we needed to” will be measured against an industry that has published specific agent logging and monitoring guidance in the OWASP Top 10 for Agentic Applications, and against a federal standards effort—the NIST AI Agent Standards Initiative—convened to produce voluntary guidelines for exactly these systems.12 The cost of agent logging is trivial relative to the consequences of its absence.

But the spoliation problem is only half of it. The other half is narrative control. Without contemporaneous records, the plaintiff controls the story. They characterize the agent’s actions in whatever light serves their case, and the company has no evidence to contradict them. Every gap in the record is filled by the worst plausible inference—not because the court is hostile, but because the absence of evidence is itself evidence of the absence of controls.

This dynamic is not theoretical. In the FTX bankruptcy, the chief executive installed to run the debtors testified that a substantial portion of the estate’s property “may be missing, misappropriated, or not readily traceable due to the lack of proper record keeping,” and that his team was “starting from near-zero in terms of the corporate infrastructure and record-keeping that one would expect to find in a multi-billion dollar international business.” Reconstruction required tracing money flows from the company’s founding across dozens of terabytes of data and records of billions of individual transactions. Every gap in the record was filled by the worst plausible inference. The same dynamic will apply to AI agent disputes, with one critical difference: FTX’s crypto assets could at least be pursued through “highly complex technological efforts to identify and trace crypto assets.”13 An AI agent that was never logged has no record at all.

The practical implication is straightforward: agent logging is not a technical feature. It is litigation infrastructure. The company that cannot produce its agent’s decision chain will not necessarily lose because the agent acted wrongly. It will lose because the company cannot prove the agent acted rightly.

C. Negligent Enablement: Deploying Without Proportionate Controls

When a company deploys an AI agent with access to customer data, payment systems, and communication platforms—but without monitoring, without authority boundaries, and without a kill switch—and that agent causes harm, the legal analysis is ordinary negligence. No novel theory is required. The elements are duty, breach, causation, and damages, applied to facts that are new but to a framework that is not.

The exposure compounds when the agent moves money itself: AI-initiated stablecoin transfers carry Bank Secrecy Act customer-identity obligations on top of the negligence analysis.

The duty exists wherever harm is foreseeable. A company that deploys an AI agent owes a duty of care to every person foreseeably affected by the agent’s actions: customers whose data it processes, counterparties with whom it transacts, employees whose applications it screens, and third parties who interact with it or are affected by its outputs. The foreseeability of harm from AI agents operating without adequate controls is no longer a matter of speculation. It is a matter of public record.

The breach is deploying an agent with capabilities that exceed your governance controls’ ability to constrain them. The standard of care is informed—though not established—by the accumulating body of industry standards that describes what reasonable AI agent governance looks like. The OWASP Top 10 for Agentic Applications and the Singapore IMDA Model AI Governance Framework for Agentic AI each identify specific controls: agent identity verification, authority boundaries, real-time monitoring, kill switches, incident response protocols. The NIST AI Agent Standards Initiative, launched in February 2026, is convening industry to standardize the first of these—agent identity and authorization.14 These frameworks are not binding law. But they are the kind of evidence a plaintiff’s expert will present to a jury as the standard of care—and the kind of evidence a defendant will struggle to explain away if it implemented none of them.

In jurisdictions where statutes establish specific standards of conduct, the analysis sharpens further. The Colorado AI Act (SB 24-205, as amended by SB 25B-004) generally requires deployers of high-risk AI systems, on and after June 30, 2026, to implement a risk management policy and program, complete impact assessments, and notify the Attorney General without unreasonable delay, and no later than ninety days after discovering, that a deployed system has caused algorithmic discrimination. A violation is an unfair trade practice under the Colorado Consumer Protection Act, carrying civil penalties of up to $20,000 per violation, with each consumer or transaction counting as a separate violation. Enforcement belongs to the Attorney General alone; the Act creates no private right of action.15 Elsewhere, violation of a statutory standard of conduct can constitute negligence per se—negligence as a matter of law, without the need for a jury to determine reasonableness. As additional states enact AI governance requirements, the floor of acceptable conduct rises.

Causation connects the absence of controls to the harm. If authority boundaries would have blocked the harmful action, if monitoring would have detected the anomaly, if a kill switch would have terminated the agent before the damage propagated—the absence of those controls is the but-for cause of the harm.

A defendant will argue that the intervening act of an attacker—a prompt injection, a supply chain compromise—breaks the causal chain. Under the Restatement (Third) of Torts, that argument misstates the test. An actor’s liability is limited to the harms that result from the risks that made the actor’s conduct tortious, and where an actor is negligent precisely because it failed to adopt adequate precautions against the risk of harm created by another’s acts, “there is no scope-of-liability limitation on the actor’s liability.”16 Prompt injection attacks, supply chain vulnerabilities, and emergent agent behavior are those risks. They are the exact risks that governance controls are designed to mitigate and that public frameworks like the OWASP Top 10 specifically document. An attacker exploiting the absence of controls you should have implemented does not break the causal chain. It completes it.

When that attack drains a user’s funds rather than causing abstract harm, the same control analysis fixes who pays for a prompt-injection loss the agent carries out.

This is not a theoretical framework awaiting its first application. Regulators are already imposing liability on this basis.

In 2013, the SEC penalized Knight Capital Americas $12 million after the firm lost more than $460 million in about 45 minutes when dormant trading code activated and sent millions of erroneous orders into the market. The SEC charged no defect in the algorithm’s design. It found that Knight deployed automated systems without technology governance controls “sufficient to ensure the orderly deployment of new code or to prevent the activation of code no longer intended for use,” without requiring a second technician to review code deployment, and without any procedure integrating into its monitoring the 97 automated error messages its own systems sent to Knight personnel before the market opened that morning. The violations the Commission found were of the market-access controls rule and Regulation SHO’s order-marking and locate requirements, not of any rule about how the algorithm was written.17

In February 2024, a federal court entered a stipulated order barring Rite Aid for five years from deploying or using any facial recognition system for security or surveillance purposes in its retail stores, retail pharmacies, or online retail platforms. The FTC’s complaint alleged that Rite Aid deployed AI-powered surveillance without assessing the system’s accuracy or its potential for bias, that the system generated thousands of false-positive matches leading to wrongful accusations, searches, ejections, and police calls, and that patrons of stores in plurality-Black, plurality-Asian, and plurality-Latino areas were more likely to be subjected to it; Rite Aid neither admitted nor denied those allegations. What the order itself requires is unambiguous: within forty-five days, Rite Aid had to delete or destroy every photo and video of consumers collected in connection with the system “and any data, models, or algorithms derived in whole or in part therefrom,” a remedy commonly called algorithmic disgorgement, and, within ninety days, to establish a comprehensive information security program. The complaint alleged that Rite Aid obtained the facial recognition technology from two third-party vendors and deployed it. The charged conduct was deployment without proportionate safeguards.18

In 2019, the National Transportation Safety Board found that the Uber Advanced Technologies Group’s “inadequate safety risk assessment procedures,” “ineffective oversight of vehicle operators,” and “lack of adequate mechanisms for addressing operators’ automation complacency” were contributing causes of a fatal autonomous vehicle crash in Tempe, Arizona—“all a consequence of its inadequate safety culture.” Uber had disabled the vehicle’s factory-equipped forward collision warning and automatic emergency braking systems. The NTSB assigned probable cause to the vehicle operator’s failure to monitor the driving environment, and every contributing factor it attributed to the company was a governance failure: risk assessment, oversight of operators, automation complacency.19

The pattern across these enforcement actions is consistent: the entity that deployed the automated system bears liability for deploying it without controls proportionate to its capabilities. The technology is not on trial. The governance decision is.

D. Products Liability: AI as Product, Not Person

If AI is not a legal agent—not a person—then what is it? One answer is emerging from federal courts: it is a product. And products liability doctrine carries consequences that agency law does not.

Under traditional products liability, a manufacturer or seller of a defective product faces strict liability for harm caused by that defect. The plaintiff does not need to prove negligence. The plaintiff needs to prove that the product was defective in design, that the defect made the product unreasonably dangerous, and that the defect caused the harm. The standard is strict: if the product is defective, the manufacturer is liable regardless of the care it exercised.

In May 2025, a federal court in the Middle District of Florida became one of the first to hold that an AI chatbot is a “product” for purposes of strict product liability.20 In Garcia v. Character Technologies, Inc., the court drew a distinction that may prove foundational: the content an AI generates—its outputs, its words—is not a product. But the design of the AI system itself—the choices about how it processes inputs, what guardrails it includes, what behaviors it permits—is. Design defect claims against an AI system are actionable under products liability.

The court did not resolve Character.AI’s First Amendment defense. It held that Character Technologies may assert the First Amendment rights of its users, but found that the defendants “fail to articulate why words strung together by an LLM are speech,” and concluded that it was “not prepared to hold that Character A.I.’s output is speech” at this stage—leaving the question open rather than deciding it. The court also held that the plaintiff sufficiently alleged Google’s liability as a “component part manufacturer”—not merely for having developed the underlying technology, which the court found insufficient on its own, but because Google was alleged to have contributed its architecture and intellectual property and to have substantially participated in integrating its models by supplying the infrastructure without which the chatbot “wouldn’t be a product”—extending the liability chain beyond the deployer to the model provider.

Garcia is at the motion-to-dismiss stage, not a final judgment. The court held that the claims can proceed and later declined to certify an interlocutory appeal; as of this writing it has not ruled on their merits. But the holding is significant: a federal court engaged in sustained analysis of whether AI systems fit within products liability doctrine and concluded that they do. The reasoning—that design choices are actionable even when outputs are not—provides a framework that other courts can follow.

The Northern District of California took a similar defect-specific approach in the social media addiction litigation, but reached it by a narrower route. The court declined to hold that the platforms are products globally—finding them “not tangible,” not shown “as a global matter” to be analogous to tangible personal property, and not products by analogy to the UCC’s treatment of software. Instead it analyzed each alleged defect, and found that the plaintiffs “adequately plead the existence of product components” as to those that survived: age verification, parental controls and notifications, session-length limits, account-deletion barriers, filters and filter labeling, and CSAM-reporting mechanisms. The failure-to-warn claims also survived. What did not survive is instructive for AI deployers: the court held that “Section 230 bars the claim as to the recommendation algorithms,” and that the First Amendment protects the timing and clustering of the platforms’ own notifications.21

Federal legislation is moving in the same direction. The proposed AI LEAD Act would explicitly classify AI systems as “products” under federal law, creating a federal cause of action for AI-related product liability including claims for defective design, failure to warn, and strict liability.22

The implications for AI agent governance are direct. If an AI agent is a product, then its design choices—what tools it can access, what authority boundaries constrain it, what monitoring observes it, what kill switches can terminate it—are all potential design defect claims. An agent deployed without authority boundaries is an agent with a design defect. An agent deployed without monitoring is an agent with a failure-to-warn problem. The governance framework is not merely a compliance exercise. It is the product safety architecture that products liability will evaluate.23

E. Trade Secret Exposure: The Defend Trade Secrets Act

The previous doctrines address liability arising from an AI agent’s actions--- its decisions, its outputs, its malfunctions. Trade secret exposure is different. It arises from what the agent knows, not from what it does. And for companies whose AI agents process confidential business information—which is to say, nearly every enterprise deployment—the exposure is architectural.

The Defend Trade Secrets Act (18 U.S.C. Sections 1831-1839) creates federal civil and criminal liability for misappropriation of trade secrets.24 The statute defines misappropriation to include both the acquisition of a trade secret by a person who knows or has reason to know it was acquired by improper means, and the disclosure of a trade secret without consent. That second prong—disclosure without consent—turns on knowledge rather than intent to harm: the statute reaches disclosure by a person who, at the time of disclosure, “knew or had reason to know” that the knowledge of the trade secret was “acquired under circumstances giving rise to a duty to maintain the secrecy of the trade secret or limit the use of the trade secret.” An NDA supplies that duty. The mechanism of the disclosure is irrelevant.

AI agents create three distinct patterns of trade secret exposure.

The first is cross-client contamination. An agent processes Client A’s confidential business information, retains fragments in context or memory, and later surfaces those fragments in outputs visible to Client B. In multi-tenant retrieval-augmented generation systems and shared tool server environments, this is not a hypothetical risk—it is an architectural characteristic of how context windows and vector databases function. The information moves between client environments not because anyone chose to disclose it, but because the system’s architecture does not prevent it. Under the DTSA, the result is the same: disclosure without consent.

The second is intra-organizational leakage. A multi-agent system passes information between agents operated by different departments with different confidentiality obligations. Research data flows into a sales agent’s context. Merger analysis surfaces in a customer-facing tool. In industries that rely on information barriers—financial services, law firms, healthcare—this cross-contamination violates the ethical walls that protect confidential information. The AI agent does silently what no human in the organization would be permitted to do.

The third is exfiltration through prompt injection. An agent with access to confidential information processes a poisoned input that causes it to include trade secret data in an externally visible output. The trade secret was acquired by the agent through authorized access and disclosed to a third party through unauthorized output. The statutory elements are satisfied.

The most immediate practical exposure comes from the DTSA’s injunctive relief provision. Under Section 1836(b)(3)(A), a court may issue an injunction to prevent “actual or threatened misappropriation”25—a term the statute uses but does not define, and which a trade secret owner will argue reaches misappropriation that has not yet occurred but is architecturally likely given the deployer’s system design. A trade secret owner whose information is processed by your AI agents can seek injunctive relief on the theory that your architecture—absent context isolation, absent data classification, absent access controls--- constitutes threatened misappropriation.

The practical scenario is concrete: your counterparty’s outside counsel files a DTSA claim and a TRO motion arguing that your AI agents process their client’s trade secrets under an NDA but lack the access controls necessary to prevent cross-contamination. They point to the absence of context isolation, the absence of data classification, and the documented risk of context leakage in multi-tenant AI systems. They demand an injunction requiring you to implement agent-level data classification, context isolation, and logging--- immediately, under threat of contempt.

You now have to build governance infrastructure under a court order, on an emergency timeline, with opposing counsel reviewing your architecture.

The deployer’s obligation runs in two directions. The Restatement makes an actor liable for using or disclosing another’s trade secret where the actor “knows or has reason to know that the information is a trade secret that the actor acquired under circumstances creating a duty of confidence”—which is what an NDA creates.26 The mirror-image rule matters too: an actor who uses or discloses a trade secret it acquired through accident or mistake is not liable where the acquisition “was the result of the other’s failure to take reasonable precautions to maintain the secrecy of the information,” so the counterparty’s own controls are in play alongside yours. Under the NDA and that duty of confidence, the deployer who processes trade secrets has an affirmative duty to maintain confidentiality through adequate technical controls. Choosing an architecture that predictably leaks confidential information across client boundaries is a breach of that duty—not because anyone intended the leak, but because the deployer selected a system design that made it foreseeable.

F. Regulatory Enforcement: The No-Exemption Principle

Three federal regulators—the FTC, the SEC, and the CFPB—have each articulated the same principle from their respective statutory mandates: there is no AI exemption from existing regulatory obligations. Automation does not dilute the standard of care. If anything, it concentrates scrutiny on the design choices the deployer made.

The FTC. In September 2024, the Commission launched Operation AI Comply, bringing enforcement actions against five companies under Section 5(a) of the FTC Act for AI-related unfair or deceptive practices—from a company marketing an “AI Lawyer” service that, the FTC alleged, neither hired nor retained any attorneys and never tested whether its chatbot’s output matched the level of a human lawyer, to a company whose AI writing tool, the FTC alleged, let subscribers generate reviews “potentially containing false information.”27 But the more significant enforcement signal is the remedy. In the Rite Aid action discussed above, the remedy did not merely penalize a bad outcome—it unwound the deployment itself, requiring the deletion of the photos and videos the system collected and “any data, models, or algorithms derived in whole or in part therefrom,” what commentators call algorithmic disgorgement.28 For companies deploying AI agents in consumer-facing contexts, the message is that the decision to deploy without governance controls may itself constitute the unfair practice, without waiting for a realized harm—though the Commission must still show that the practice “causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits to consumers or to competition.”

The SEC. The Commission and its staff have applied the no-exemption principle to automated advisory platforms for nearly a decade. In 2017, the staff of the SEC’s Division of Investment Management issued guidance stating that robo-advisers, “like all registered investment advisers, are subject to the substantive and fiduciary obligations of the Advisers Act.”29 In 2019, the Commission itself issued a formal interpretation confirming that an adviser’s federal fiduciary duty, which comprises a duty of care and a duty of loyalty, “may not be waived,” though it applies in a manner that reflects the agreed-upon scope of the relationship—and that the interpretation applies to automated advisers no less than to human ones.30

The enforcement actions that followed demonstrate these are not abstract obligations. In 2018, the SEC censured Wealthfront and imposed a $250,000 civil penalty for a set of violations that included falsely stating in its tax-loss-harvesting whitepaper that it “monitors all the accounts it manages for each client to avoid any transactions that might trigger a wash sale,” when its software was not programmed to do so; from October 2012 through mid-May 2016, at least 31 percent of accounts enrolled in the strategy experienced some wash sales.31 In 2022, the SEC ordered three Charles Schwab investment-adviser and broker-dealer subsidiaries to pay $186.5 million—a $135 million civil penalty plus $45.9 million in disgorgement and $5.6 million in prejudgment interest—after finding that their Schwab Intelligent Portfolios robo-adviser told clients their cash allocations were “set based on a disciplined portfolio construction methodology,” while Schwab’s internal analyses showed those allocations would lower returns whenever other assets such as equities outperformed cash. Schwab had swept client cash to an affiliate bank and profited by almost $46 million from the spread.32

The CFPB. The Bureau has stated directly that creditors cannot justify noncompliance with the Equal Credit Opportunity Act and Regulation B by claiming their AI is too complex or too opaque to explain. There is no black-box exemption from fair lending obligations.33 Creditors must provide specific, accurate adverse action notices regardless of whether the decision was made by an algorithm or a human loan officer.

The common thread across all three regulators: each assessed the deployer’s governance architecture, not the AI’s output. The question was not “did the AI make the right decision?” It was “did the deployer build the infrastructure to ensure it could?”

G. Direct Liability for AI Decision-Making

The previous sections address liability for how AI agents are deployed—the governance architecture, the controls, the oversight. This section addresses liability for what AI agents do—the decisions they make, the recommendations they issue, the people they screen out.

In every regulated domain where courts have examined AI decision-making, they have reached the same conclusion: the deployer bears the same standard of care as if a human performed the function. Automation does not reduce the obligation. It increases scrutiny, because automated systems apply their biases at a scale and speed no individual human can match.

Employment. In Mobley v. Workday, Inc. (N.D. Cal. 2024), a federal court denied in part Workday’s motion to dismiss, holding that an AI vendor providing algorithmic hiring tools to employers can be sued directly for employment discrimination under Title VII, the ADA, and the ADEA.34 The court’s analysis turned on the statutes’ own definition of “employer,” which includes “any agent” of an employer, and on the settled focus of the agency cases on “the ‘function’ that the principal has delegated to the agent, not the manner in which the agent carries out the delegated function.” Because the complaint alleged that Workday’s software was “not simply implementing in a rote way the criteria that employers set forth, but is instead participating in the decision-making process by recommending some candidates to move forward and rejecting others,” the court held that the pleading “adequately alleges that Workday is an agent of its client-employers.” The court dismissed the parallel employment-agency and intentional-discrimination theories; what survives is the disparate-impact claim.

In May 2025, the court granted preliminary certification of a collective on the age discrimination claim. Arguing against notice, Workday’s own filings stated that “1.1 billion applications were rejected using Workday” during the period at issue—a figure the court treated as a “rough estimate” that “ignores the qualifiers in the definition of the collective,” and no reason to withhold notice.35 The EEOC filed an amicus brief supporting the theory that AI vendors are covered entities subject to federal anti-discrimination law.36

The implications extend beyond the vendor. Employers who delegate screening decisions to AI tools remain independently liable for discriminatory outcomes—the ADA reaches an employer for “participating in a contractual or other arrangement or relationship that has the effect of subjecting” an applicant to prohibited discrimination, and for “using qualification standards, employment tests or other selection criteria that screen out or tend to screen out” a protected applicant, unless the criteria are shown to be job-related for the position and consistent with business necessity. The employer cannot point to the vendor; and where the vendor comes inside the statutory definition of employer as “any agent” of the employer, it cannot point to the employer either. Both may be exposed.37

Housing. In Louis v. SafeRent Solutions, LLC (D. Mass. 2023), the court rejected SafeRent’s argument that the Fair Housing Act did not reach it because it “does not make housing decisions,” holding that “neither provision limits liability to people or entities that ‘make housing decisions.’” SafeRent’s algorithm scored rental applicants without accounting for the financial benefit of housing vouchers, which the plaintiffs alleged produced a disparate impact on Black and Hispanic applicants. Because the complaint plausibly alleged that SafeRent “effectively controls the decision to approve or reject a rental application,” the court held it subject to the FHA and allowed the disparate-impact claims to proceed—and it separately denied the landlord’s motion to dismiss in full. The reach runs in both directions: the vendor does not escape by pointing at the landlord, and the landlord does not escape by pointing at the vendor. The case settled in 2024, with final approval in November, for total consideration capped at $2.275 million, and SafeRent agreed, for five years, to stop providing a SafeRent Score or an accept-or-decline recommendation for applicants not certified as non-voucher recipients unless the score has been validated for voucher-holders by the National Fair Housing Alliance or another agreed organization.38

The pattern is consistent. Where courts have examined AI decision-making in regulated domains, the standard tracks the activity, not the actor. The deployer who automates a function governed by anti-discrimination law, fiduciary duty, or consumer protection does not escape the standard by automating it. The standard was designed for the decision, not for who—or what—makes it.

IV. The One Exception: Electronic Agents Under UETA and E-SIGN

There is one body of law that does contemplate non-human actors in a legal context—and it does not help deployers. It binds them.

The Uniform Electronic Transactions Act, as enacted by the states (Washington’s version, RCW 1.80, is the one cited here), defines an “electronic agent” as “a computer program or an electronic or other automated means used independently to initiate an action or respond to electronic records or performances in whole or in part, without review or action by an individual.”39 That definition is broad enough to encompass AI systems.

UETA Section 14 provides that a contract may be formed by the interaction of electronic agents “even if no individual was aware of or reviewed the electronic agents’ actions or the resulting terms and agreements.”40 The Electronic Signatures in Global and National Commerce Act (15 U.S.C. Section 7001) confirms this at the federal level: a contract may not be denied legal effect solely because its formation involved the action of electronic agents, “so long as the action of any such electronic agent is legally attributable to the person to be bound.”41

The practical consequence is that your AI agent can bind you. If it commits to a price, accepts terms, executes a purchase order, or confirms a transaction, that commitment is legally enforceable against your organization. The scope of what your agent can transact defines the outer boundary of your transactional exposure. Every API key is a grant of transactional capability. Every tool permission is a representation of authority. Every database connection is a scope definition that a court can examine if the transaction goes wrong.

A company might attempt to disclaim its agent’s transactional authority in terms of service. But a disclaimer that contradicts the agent’s observable capabilities faces a fundamental credibility problem. If you deploy an agent with access to your payment system, your contract management platform, and your customer communication tools, and a counterparty interacts with that agent in a commercial context, the agent’s capabilities are a louder statement about its authority than the fine print in your terms of service. Courts evaluating the totality of circumstances will weigh what the deployer showed the world against what the deployer buried in a clickwrap agreement.

The Open Question: Deterministic and Stochastic Systems

UETA was drafted in 1999 for a different kind of electronic agent. The systems its drafters contemplated were deterministic: shopping carts, automated purchase order systems, vending machines. Systems that execute pre-programmed logic on pre-defined inputs and produce predictable, reproducible outputs. A shopping cart that adds an item to an order does the same thing every time.

AI agents are stochastic. They interpret ambiguous inputs. They exercise something that functions like judgment. They produce outputs that are non-reproducible—the same inputs will not generate the same outputs twice. Whether UETA Section 14 extends to non-deterministic AI systems that exercise independent judgment in forming contractual commitments is an open question that no court has resolved.

The statutory text is broad enough to cover them. A court seeking to hold a deployer to a commitment its AI agent made has a clear pathway through Section 14. But a court skeptical of extending a 1999 statute to a 2026 technology could find that UETA’s drafters contemplated a fundamentally different kind of automation—and that stochastic AI agents fall outside the statutory framework until the legislature updates it.

E-SIGN adds its own layer of uncertainty. The statute’s requirement that electronic agent actions be “legally attributable to the person to be bound” raises the question of when a stochastic AI output—one the deployer did not specifically program or anticipate—is “attributable” to the deployer. The answer is probably yes in most cases: the deployer chose to deploy the system, configured its parameters, granted its access, and set it loose on transactions. But “probably yes” is not the foundation on which companies should build their compliance strategy.

This uncertainty is not an argument for inaction. It is the opposite. Open legal questions are resolved by courts, in litigation, after the harm has occurred. A company that deployed an AI agent without governance controls and now argues to a court that UETA does not apply to stochastic systems is not making a legal argument. It is making an admission that it deployed a system it did not understand into a legal framework it had not analyzed. That is not a defense. It is the plaintiff’s case.

V. Why the Exposure Compounds

If these were seven independent risks, a general counsel could triage. Handle spoliation first. Address trade secrets next quarter. Get to products liability when the budget allows.

They are not independent. They are a system—and the system’s most dangerous property is that each governance gap makes every other doctrine’s case easier for the plaintiff.

Start with the evidence you never created. A negligent enablement plaintiff argues you deployed without proportionate controls. Your defense is that you had controls—authority boundaries, monitoring, kill switches. But if you never logged your agent’s actions, you cannot prove those controls existed or functioned. The products liability plaintiff argues your AI’s design was defective. Your defense is that the design included safety architecture. But without decision chain records, you cannot demonstrate what the design actually did in practice. The direct liability plaintiff argues your screening algorithm discriminated. Your defense is that the outputs were fair. But without contemporaneous logs, you have no evidence of what the outputs were. In each case, the spoliation problem is not an additional claim. It is the mechanism that defeats your defense to the other claims.

Now reverse the direction. Trade secret exposure creates the foreseeability that triggers the preservation duty. Once cross-client contamination is a known architectural risk in multi-tenant AI systems—and it is—litigation arising from that risk is “reasonably foreseeable” under Zubulake.10 Which means you should have been logging the agent actions that would reveal whether contamination occurred. The trade secret problem creates the spoliation problem.

The board’s failure to implement oversight is itself evidence of breach in the negligence claim. A plaintiff can point to the Marchand analysis--- no reporting system, no monitoring, no board-level engagement with AI risk—and argue that the deployer’s governance failure is direct proof it breached the standard of care. The Caremark problem does not just expose directors personally. It proves the negligence case against the company.

Regulatory enforcement compounds the exposure further. Every FTC action, every SEC penalty, every CFPB enforcement position documented in this article enters the evidentiary record that a plaintiff’s expert can present to a jury as the standard of care the deployer failed to meet. The Rite Aid disgorgement. The Schwab penalty. The Wealthfront action. These are not just regulatory outcomes. They are the benchmarks against which a negligence jury will measure your governance decisions—and the benchmarks you cannot distinguish if you implemented none of the controls those regulators found absent.

And UETA binds the deployer to whatever its agent transacted—while the absence of logging means the deployer may not even know what was transacted until opposing counsel tells them.

This is what it means to face these doctrines without agency law’s defenses. A principal with a human agent can point to the agent’s independent conduct—the frolic, the exceeded scope, the unauthorized act—and argue that the harm should be allocated to the agent, not the principal. A deployer with an AI tool has no such intermediary. Every doctrine lands directly on the deployer, and every gap in governance feeds every other doctrine’s case. There is no buffer. There is no allocation. There is the deployer, and there is the full weight of seven doctrines converging on the same set of facts.

The only rational response to a compounding system is a comprehensive one. Fixing one gap reduces exposure across multiple doctrines. Leaving one open increases it across all of them.

VI. The Imperative: You Need Certainty, Not Hope

Every month of governed AI operation is a month of defensible evidence. Every month without it is a month of exposure that cannot be remediated after the fact.

That is the through-line connecting every doctrine in this article. The board oversight that Caremark demands, the decision chains that spoliation law presumes you preserved, the proportionate controls that negligence law requires, the product safety architecture that Garcia evaluates, the access controls that prevent trade secret exposure, the compliance documentation that regulators will request—each one asks the same question of the deployer: can you show what your AI did, and can you show that you governed it?

Emerging regulation sharpens the question but does not create it. The EU AI Act’s penalty chapter has applied since August 2, 2025: under Article 99, non-compliance with the Article 5 prohibitions carries administrative fines of up to EUR 35 million or, for an undertaking, seven percent of total worldwide annual turnover, whichever is higher, and non-compliance with the operator obligations Article 99(4) enumerates—including a deployer’s obligations under Article 26—carries up to EUR 15 million or three percent, whichever is higher (for small mid-cap enterprises, whichever is lower). The Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred the high-risk obligations themselves to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems.42 The Colorado AI Act, whose deployer obligations apply on and after June 30, 2026, makes violations enforceable as unfair trade practices with civil penalties of up to $20,000 per violation, enforced exclusively by the Attorney General.43 These statutes are a sword, not a shield—they create liability for deployers who do not comply without creating safe harbors for deployers who do. And in U.S. courts, violation of a statutory standard of conduct may constitute negligence per se—though Colorado’s Act reserves enforcement to the Attorney General and expressly declines to provide the basis for a private right of action.

Waiting for Congress to clarify the framework is not a strategy. It is a bet that no plaintiff’s attorney, no regulator, and no court will apply existing law to your AI agent’s conduct before the legislature acts. That bet has already lost. The FTC has brought enforcement actions. The SEC has imposed nine-figure penalties. Federal courts have held AI systems liable as products and certified collective actions covering over a billion transactions.

The question for every general counsel is not “what regulation applies?” It is: if opposing counsel walked into my office tomorrow and made any one of these arguments, could I defend?

That question is what the Know Your Agent framework is designed to answer--- agent identity verification, authority boundaries, continuous monitoring, incident response, and compliance mapping that addresses each liability exposure analyzed above. Not to eliminate legal risk. No framework can. But to provide the documented, defensible foundation that every doctrine discussed here will demand.

VII. What Comes Next

This article is part of Astraea Counsel’s Know Your Agent (KYA) governance framework, which provides the operational architecture—identity verification, authority boundaries, monitoring, incident response, and compliance mapping—that addresses each of the liability exposures analyzed above.

If your organization deploys AI agents and you need help assessing your governance posture against the doctrines discussed in this article, schedule a consultation.

Related: On April 8, 2026, Anthropic launched Claude Managed Agents—the first production-grade runtime for autonomous AI agents. We applied the KYA Five Pillars framework to the specific product surface in What Claude Managed Agents Means for Your Compliance Stack. For how the architecture itself—persistent sessions, MCP connectors, bash execution—creates regulatory triggers that self-hosted agents do not face, see Agents with Wallets, Agents in Vaults.


This article provides general information for educational purposes only and does not constitute legal advice. AI governance regulation is evolving rapidly. Consult qualified legal counsel for advice on your specific situation.

See our AI litigation attorney page.

Two companion pieces take the litigation side of this: personal jurisdiction over an AI agent’s operator , and what is discoverable when an AI agent is the actor .

Footnotes

  1. Restatement (Third) of Agency § 1.01 (Am. L. Inst. 2006). ↩

  2. Restatement (Third) of Agency § 1.04 cmt. e (Am. L. Inst. 2006) (“To be capable of acting as a principal or an agent, it is necessary to be a person, which in this respect requires capacity to be the holder of legal rights and the object of legal duties.”). ↩

  3. Restatement (Second) of Agency §§ 219-220, 228 (Am. L. Inst. 1958). The aided-by-agency clause of § 219(2)(d) was never approved by the ALI membership and is superseded by Restatement (Third) of Agency § 7.08 cmt. b; the sections are cited here only for the scope-of-employment and control-based limits on vicarious liability. Restatement (Third) of Agency § 1.01 cmt. c (Am. L. Inst. 2006) states that the Third Restatement “does not use the term ‘independent contractor,’ except in discussing other material that uses the term,” and routes the employee-versus-nonagent classification to § 7.07(3). ↩

  4. In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 971 (Del. Ch. 1996) (approving a derivative settlement) (available at https://law.justia.com/cases/delaware/court-of-chancery/1996/13670-3.html). ↩

  5. Marchand v. Barnhill, 212 A.3d 805, 809, 820-21, 824 (Del. 2019) (available at https://law.justia.com/cases/delaware/supreme-court/2019/533-2018.html). ↩ ↩2

  6. In re Boeing Co. Derivative Litig., C.A. No. 2019-0907-MTZ, slip op. at 73-74, 81-82, 94 (Del. Ch. Sept. 7, 2021) (quoting Marchand, 212 A.3d at 824) (available at https://law.justia.com/cases/delaware/court-of-chancery/2021/c-a-no-2019-0907-mtz-0.html). ↩

  7. Stone v. Ritter, 911 A.2d 362, 367, 370 (Del. 2006) (available at https://law.justia.com/cases/delaware/supreme-court/2006/84060.html); 8 Del. C. § 102(b)(7). ↩

  8. Smith v. Van Gorkom, 488 A.2d 858, 872-73 (Del. 1985) (quoting Aronson v. Lewis, 473 A.2d 805, 812 (Del. 1984)) (available at https://law.justia.com/cases/delaware/supreme-court/1985/488-a-2d-858-4.html). ↩

  9. Fed. R. Civ. P. 37(e) (available at https://www.law.cornell.edu/rules/frcp/rule_37). ↩

  10. Zubulake v. UBS Warburg LLC, 220 F.R.D. 212, 216-18 (S.D.N.Y. 2003) (quoting, as to “reasonably foreseeable,” West v. Goodyear Tire & Rubber Co., 167 F.3d 776, 779 (2d Cir. 1999)) (available at https://www.courtlistener.com/opinion/2410862/zubulake-v-ubs-warburg-llc/). ↩ ↩2

  11. Mobley v. Workday, Inc., 740 F. Supp. 3d 796 (N.D. Cal. 2024) (denying in part a motion to dismiss Title VII, ADEA, and ADA disparate-impact claims against an AI hiring-tool vendor on an agency theory) (available at https://www.courtlistener.com/docket/66831340/mobley-v-workday-inc/). ↩

  12. OWASP, Top 10 for Agentic Applications (Dec. 9, 2025) (available at https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/); NIST, AI Agent Standards Initiative (launched Feb. 17, 2026) (available at https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative). ↩

  13. Testimony of John J. Ray III, CEO of FTX Debtors, before the U.S. House Financial Services Committee (Dec. 13, 2022) (available at https://democrats-financialservices.house.gov/uploadedfiles/hhrg-117-ba00-wstate-rayj-20221213.pdf). ↩

  14. OWASP, Top 10 for Agentic Applications (Dec. 9, 2025) (available at https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/); Singapore IMDA, Model AI Governance Framework for Agentic AI v.1.5 (published May 20, 2026, updated June 5, 2026) (available at https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf); NIST, AI Agent Standards Initiative (launched Feb. 17, 2026) (available at https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative). ↩

  15. Colorado AI Act, SB 24-205 (2024), as amended by SB 25B-004 (2025, 1st Ex. Sess.), codified at Colo. Rev. Stat. §§ 6-1-1701 to 6-1-1707; deployer duties at § 6-1-1703(2)-(3), (7) (applicable on and after June 30, 2026); see § 6-1-1703(6) (exempting from subsections (2), (3), and (5) a deployer that employs fewer than fifty full-time equivalent employees and meets that subsection’s further conditions); § 6-1-1706(3) (affirmative defense); enforcement at § 6-1-1706(1)-(2) (the attorney general has “exclusive authority to enforce this part 17,” and a violation “constitutes an unfair trade practice pursuant to section 6-1-105 (1)(hhhh)”); civil penalty of “not more than twenty thousand dollars for each violation” at § 6-1-112(1)(a); no private right of action at § 6-1-1706(6) (available at https://leg.colorado.gov/bills/sb24-205). ↩

  16. Restatement (Third) of Torts: Liability for Physical and Emotional Harm §§ 29, 34 & cmt. d (Am. L. Inst. 2010). ↩

  17. SEC, In re Knight Capital Americas LLC, Exchange Act Release No. 70694, Admin. Proc. File No. 3-15570 (Oct. 16, 2013) (available at https://www.sec.gov/litigation/admin/2013/34-70694.pdf). ↩

  18. FTC v. Rite Aid Corp., No. 2:23-cv-05023-KBH (E.D. Pa.), Stipulated Order for Permanent Injunction and Other Relief, Doc. 19 (entered Feb. 23, 2024) (five-year prohibition at Attachment A, Provision I; deletion requirement at Attachment A, Provision II; information security program at Attachment A, Provision VIII) (available at https://www.ftc.gov/system/files/ftc_gov/pdf/DE019-StipulatedOrderforPermanentInjunctionandOtherRelief.pdf); Complaint, Doc. 1 (filed Dec. 19, 2023) (available at https://www.ftc.gov/system/files/ftc_gov/pdf/2023190_riteaid_complaint_filed.pdf). ↩

  19. NTSB, Collision Between Vehicle Controlled by Developmental Automated Driving System and Pedestrian, Tempe, Arizona, Report No. HAR-19/03 (2019) (available at https://www.ntsb.gov/investigations/accidentreports/reports/har1903.pdf). ↩

  20. Garcia v. Character Technologies, Inc., 785 F. Supp. 3d 1157 (M.D. Fla. 2025) (No. 6:24-cv-01903-ACC-UAM, Doc. 115, May 21, 2025) (order on motions to dismiss), certification of interlocutory appeal denied, 2025 U.S. Dist. LEXIS 175056 (M.D. Fla. July 14, 2025) (available at https://scholarblogs.emory.edu/proflawrence/files/2025/05/Garcia-v.-Character-Technologies-Inc.-et-al-Entry-115.pdf). ↩

  21. In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation, 702 F. Supp. 3d 809, 834, 844-49, 854, 862-63 (N.D. Cal. 2023) (MDL No. 3047, No. 4:22-md-03047-YGR, Nov. 14, 2023) (available at https://www.courtlistener.com/docket/65407433/in-re-social-media-adolescent-addictionpersonal-injury-products-liability/). ↩

  22. Aligning Incentives for Leadership, Excellence, and Advancement in Development Act (AI LEAD Act), S. 2937, 119th Cong. (2025) (introduced Sept. 29, 2025; referred to S. Comm. on the Judiciary) (available at https://www.congress.gov/bill/119th-congress/senate-bill/2937/text). ↩

  23. Juries are already returning nine-figure verdicts on the design of autonomous systems. In Benavides v. Tesla, Inc., No. 21-cv-21940 (S.D. Fla.), a jury found Tesla liable on strict products liability design-defect and failure-to-warn claims arising from its Autopilot system and apportioned 33% of responsibility to Tesla; on August 3, 2025 the court entered final judgment of $242,570,000, including $200 million in punitive damages. In allowing punitive damages to reach the jury, the court had noted that Tesla “refused to geo-fence the Autopilot system despite being warned of the dangers” and that plaintiffs pointed to public statements that “arguably misrepresented the risk and limitations of the Autopilot system.” See Benavides v. Tesla, Inc., 804 F. Supp. 3d 1242, 1313 (S.D. Fla. 2025) (order on summary judgment and Daubert motions); 2026 U.S. Dist. LEXIS 34587 (S.D. Fla. Feb. 19, 2026) (denying judgment as a matter of law and a new trial), appeal filed (11th Cir. Mar. 16, 2026). Tesla is the manufacturer here rather than a deployer, but the theory travels: the lead design-defect theory plaintiffs advanced, and the one on which the court let punitive damages reach the jury, was a governance choice—permitting Autopilot’s use outside its operational design domain rather than geo-fencing it—not a component failure (available at https://www.courtlistener.com/docket/59932667/benavides-v-tesla-inc/). ↩

  24. Defend Trade Secrets Act, 18 U.S.C. §§ 1831-1839 (available at https://www.law.cornell.edu/uscode/text/18/part-I/chapter-90). ↩

  25. 18 U.S.C. § 1836(b)(3)(A)(i) (authorizing injunctive relief to prevent “actual or threatened misappropriation,” provided the order does not prevent a person from entering an employment relationship and conditions on such employment are “based on evidence of threatened misappropriation and not merely on the information the person knows”); see also § 1836(b)(3)(A)(ii) (injunction may require “affirmative actions to be taken to protect the trade secret”) (available at https://www.law.cornell.edu/uscode/text/18/1836). ↩

  26. Restatement (Third) of Unfair Competition § 40(b)(1), (b)(4) (Am. L. Inst. 1995); see also id. § 41 (a duty of confidence arises where the recipient made an express promise of confidentiality before the disclosure, or where the circumstances justify the conclusions that the recipient knew or had reason to know the disclosure was intended to be in confidence and the discloser reasonably inferred consent to an obligation of confidentiality). ↩

  27. 15 U.S.C. § 45(a), (n); FTC, “FTC Announces Crackdown on Deceptive AI Claims and Schemes” (Operation AI Comply, Sept. 25, 2024) (available at https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes). ↩

  28. FTC v. Rite Aid Corp., No. 2:23-cv-05023-KBH (E.D. Pa.), Stipulated Order for Permanent Injunction and Other Relief, Doc. 19 (entered Feb. 23, 2024). Attachment A, Provision II required Rite Aid, within forty-five days, to “delete or destroy all photos and videos of consumers used or collected in connection with the operation of a Facial Recognition or Analysis System” and “any data, models, or algorithms derived in whole or in part therefrom,” the remedy commentators call algorithmic disgorgement, and to instruct every third-party recipient to do the same; Attachment A, Provision I barred deployment of any such system for security or surveillance purposes in Rite Aid’s retail stores, retail pharmacies, or online retail platforms for five years (available at https://www.ftc.gov/system/files/ftc_gov/pdf/DE019-StipulatedOrderforPermanentInjunctionandOtherRelief.pdf). ↩

  29. SEC Division of Investment Management, Robo-Advisers, IM Guidance Update No. 2017-02 (Feb. 2017) (staff guidance) (available at https://www.sec.gov/investment/im-guidance-2017-02.pdf). ↩

  30. SEC, Commission Interpretation Regarding Standard of Conduct for Investment Advisers, Advisers Act Release No. IA-5248 (June 5, 2019) (available at https://www.sec.gov/rules-regulations/2019/06/ia-5248). ↩

  31. SEC, In re Wealthfront Advisers LLC, Advisers Act Release No. IA-5086 (Dec. 21, 2018) (available at https://www.sec.gov/litigation/admin/2018/ia-5086.pdf). ↩

  32. SEC, In re Charles Schwab & Co., Charles Schwab Inv. Advisory, Inc., & Schwab Wealth Inv. Advisory, Inc., Exchange Act Release No. 95087, Advisers Act Release No. 6047, Admin. Proc. File No. 3-20897 (June 13, 2022) (available at https://www.sec.gov/litigation/admin/2022/34-95087.pdf). ↩

  33. CFPB, Consumer Financial Protection Circular 2022-03, “Adverse Action Notification Requirements in Connection with Credit Decisions Based on Complex Algorithms” (May 26, 2022) (available at https://www.consumerfinance.gov/compliance/circulars/circular-2022-03-adverse-action-notification-requirements-in-connection-with-credit-decisions-based-on-complex-algorithms/). ↩

  34. Mobley v. Workday, Inc., 740 F. Supp. 3d 796, 804-08, 813-14 (N.D. Cal. 2024) (available at https://www.courtlistener.com/docket/66831340/mobley-v-workday-inc/). ↩

  35. Mobley v. Workday, Inc., No. 3:23-cv-00770, 2025 U.S. Dist. LEXIS 94475, at *3-4, *32-33 (N.D. Cal. May 16, 2025) (order granting preliminary collective certification) (available at https://www.courtlistener.com/docket/66831340/mobley-v-workday-inc/). ↩

  36. EEOC, Amicus Brief in Mobley v. Workday, Inc., No. 3:23-cv-00770 (N.D. Cal. Apr. 2024) (available at https://www.eeoc.gov/litigation/briefs/mobley-v-workday-inc). ↩

  37. Americans with Disabilities Act, 42 U.S.C. § 12112(b)(2), (b)(6); Title VII, 42 U.S.C. § 2000e(b) (defining “employer” to include “any agent of such a person”). ↩

  38. Louis v. SafeRent Solutions, LLC, 685 F. Supp. 3d 19, 34-36, 41-42 (D. Mass. 2023) (No. 22-cv-10800-AK, July 26, 2023); Class Action Settlement Agreement, Doc. 132-1, §§ 1.49, 3.5.1, 3.5.3, 3.5.5 (D. Mass. filed Nov. 8, 2024); Final Approval Order, Doc. 135 (D. Mass. Nov. 20, 2024) (available at https://www.courtlistener.com/docket/63335697/louis-v-saferent-solutions-llc/). ↩

  39. Uniform Electronic Transactions Act § 2(6), enacted in Washington as Wash. Rev. Code § 1.80.010(8) (2020 c 57, § 2) (available at https://app.leg.wa.gov/RCW/default.aspx?cite=1.80&full=true). ↩

  40. Uniform Electronic Transactions Act § 14, enacted in Washington as Wash. Rev. Code § 1.80.130 (2020 c 57, § 14) (available at https://app.leg.wa.gov/RCW/default.aspx?cite=1.80&full=true). ↩

  41. Electronic Signatures in Global and National Commerce Act (E-SIGN), 15 U.S.C. § 7001(h) (available at https://www.law.cornell.edu/uscode/text/15/7001). ↩

  42. EU AI Act, Regulation (EU) 2024/1689, arts. 99(3)-(4), 113 (Chapter XII penalties applicable from Aug. 2, 2025). Article 99(3) sets fines of up to EUR 35 000 000 or 7 % of total worldwide annual turnover for the preceding financial year, whichever is higher, for non-compliance with the Article 5 prohibitions; Article 99(4) sets fines of up to EUR 15 000 000 or 3 % of that turnover, whichever is higher, for non-compliance with the operator and notified-body obligations it enumerates, including deployers’ obligations under Article 26 (available at https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng); Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), art. 1(38)(c) (inserting art. 99(6a): for small mid-cap enterprises “each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower”), art. 1(40) (amending art. 113 so that Chapter III, Sections 1-3 apply from Dec. 2, 2027 for Annex III high-risk systems and Aug. 2, 2028 for Annex I high-risk systems) (available at http://data.europa.eu/eli/reg/2026/1744/oj). ↩

  43. Colorado AI Act, SB 24-205 (2024), as amended by SB 25B-004 (2025, 1st Ex. Sess.), codified at Colo. Rev. Stat. §§ 6-1-1701 to 6-1-1707 (deployer obligations applicable on and after June 30, 2026). A violation “constitutes an unfair trade practice pursuant to section 6-1-105 (1)(hhhh),” Colo. Rev. Stat. § 6-1-1706(2), carrying a civil penalty of “not more than twenty thousand dollars for each violation,” id. § 6-1-112(1)(a). The attorney general has “exclusive authority to enforce this part 17,” id. § 6-1-1706(1), and the part “does not provide the basis for, and is not subject to, a private right of action,” id. § 6-1-1706(6) (available at https://leg.colorado.gov/bills/sb24-205). ↩

On This Page

  • I. Things Are Not As They Seem
  • Key Takeaways
  • II. The Pivot: Why "Not an Agent" Is Bad News
  • III. The Doctrines That Do Apply
  • IV. The One Exception: Electronic Agents Under UETA and E-SIGN
  • V. Why the Exposure Compounds
  • VI. The Imperative: You Need Certainty, Not Hope
  • VII. What Comes Next

Frequently Asked Questions

Is an AI agent a legal agent under the Restatement of Agency?

No. Under Restatement (Third) of Agency Section 1.01, agency arises when a principal manifests assent that another person act on the principal’s behalf and subject to the principal’s control. The operative word is person, which requires legal capacity to possess rights and incur obligations. An AI system cannot consent to a fiduciary relationship, bear obligations, or be sued. The Restatement’s own commentary says a computer program ‘is not capable of acting as a principal or an agent as defined by the common law’ and that computer programs ‘are instrumentalities of the persons who use them.’ The industry calls them agents; the law calls them tools.

Why is the absence of agency-law defenses bad news for AI deployers?

Agency law is full of defenses that centuries of common law developed to limit a principal’s exposure: the frolic-and-detour defense, the scope-of-employment limitation, and the independent-contractor classification. None of these defenses are available when the actor is not an agent, because they presuppose a relationship between two legal persons. When an AI system causes harm, there is no allocation and no intermediary. There is the deployer, its tool, and the damage.

Does Caremark oversight apply to AI agent governance?

No reported decision has yet applied Caremark to AI agent oversight, but the doctrinal extension is natural. Under Marchand v. Barnhill, directors must make a good faith effort to implement a reporting system for mission-critical risks and then monitor what it reports. For companies deploying AI agents at scale, agent governance is becoming a central compliance risk under the Marchand framework. A board that deploys agents with no agent inventory, no monitoring, and no incident reporting pathway to the board fails Marchand’s first prong. Caremark claims sound in loyalty, so a DGCL Section 102(b)(7) charter provision cannot exculpate the directors: the statute excludes breaches of the duty of loyalty and acts or omissions not in good faith from any such provision’s reach.

What is the spoliation risk for companies that do not log AI agent decisions?

Under Federal Rule of Civil Procedure 37(e), when electronically stored information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it, and it cannot be restored or replaced through additional discovery, the court may, on finding prejudice, order measures no greater than necessary to cure it, or, only on finding that the party acted with intent to deprive another party of the information’s use, presume the lost information was unfavorable, instruct the jury accordingly, or dismiss the action or enter a default judgment. Agent actions are ephemeral by default. Context windows are overwritten. Tool calls go unrecorded unless logging is affirmatively implemented. AI agent decisions are non-reproducible—if you did not log it contemporaneously, it is gone. Agent logging is not a technical feature; it is litigation infrastructure.

Can an AI agent bind a company to a contract under UETA or E-SIGN?

Yes. UETA Section 14 provides that a contract may be formed by the interaction of electronic agents even if no individual was aware of or reviewed the agents’ actions or the resulting terms. E-SIGN at 15 U.S.C. Section 7001(h) confirms this at the federal level, so long as the action of the electronic agent is legally attributable to the person to be bound. If your AI agent commits to a price, accepts terms, executes a purchase order, or confirms a transaction, that commitment is enforceable against your organization wherever the agent’s action is legally attributable to you. Neither statute defines legally attributable, and no court has resolved whether UETA Section 14 reaches non-deterministic AI systems, but a deployer that chose the agent, configured it, and granted it access to its systems will have a hard time arguing the action was not its own. Every tool permission is a representation of authority.

Why does AI-related exposure compound across doctrines?

The seven doctrines are not independent. Each governance gap makes every other doctrine’s case easier for the plaintiff. If you never logged your agent’s actions, you cannot prove that authority boundaries, monitoring, or kill switches existed or functioned. Trade secret exposure creates the foreseeability that triggers the preservation duty. The board’s failure to implement oversight is itself evidence of breach in the negligence claim. Regulatory enforcement outcomes become benchmarks a jury uses to measure governance decisions. The only rational response to a compounding system is a comprehensive one: fixing one gap reduces exposure across multiple doctrines.

Share

Follow this firm’s analysis on Google — see our commentary first when a story like this one breaks.

Stay Informed on Digital Asset Law

Practical legal analysis on crypto regulation, AI compliance, and fintech law—delivered when it matters.

No spam. Unsubscribe anytime.

Chanté Eliaszadeh profile picture

Chanté Eliaszadeh

Principal Attorney, Astraea Counsel APC

Chanté Eliaszadeh is the principal attorney of Astraea Counsel APC, advising crypto, AI, and fintech companies on securities and digital-asset regulation. She is named to the 2026 Lawdragon 500 X — The Next Generation guide for Crypto Regulation, Disputes, and Blockchain; won the 2024 Law360 Distinguished Legal Writing Award from The Burton Awards as co-author at White & Case; is recognized in The Legal 500 USA (White & Case LLP, 2023); and served as a summer SEC Honors Program intern in the SEC's Cyber Unit. Her firm is ranked in Chambers USA: Spotlight 2026 — Fintech (Los Angeles). She is an invited speaker at venues including ETHDenver, Korea Blockchain Week, the American Bar Association Business Law Section, Art Basel Miami, and Berkeley Law, and keynote speaker at the Computational Law & Blockchain Festival.

Get in Touch →

Legal Disclaimer: This article provides general information for educational purposes only and does not constitute legal advice. The law changes frequently, and the information provided may not reflect the most current legal developments. No attorney-client relationship is created by reading this content. For advice about your specific situation, please consult with a qualified attorney.

Related Articles

Thought Leadership

The Caremark Duty in the Managed Agents Era: A Board-Level AI Governance Framework

Delaware Chancery does not care how fast your team shipped the agent. It cares whether the board knew what the agent was doing. A Caremark analysis of board oversight duties for AI agent deployment, with case law, D&O insurance analysis, and a compliance checklist.

April 22, 2026 · 24 min readRead More →
Thought Leadership

What Claude Managed Agents Means for Your Compliance Stack: A KYA Framework Analysis

Anthropic's Managed Agents runtime shipped on April 8. A former SEC Honors Program intern in the SEC's Cyber Unit maps each product feature to the KYA Five Pillars governance framework—and identifies the compliance gaps deployers must close before their first production session.

April 12, 2026 · 22 min readRead More →
Thought Leadership

Who Is Liable When an AI Agent Loses Your Money?

AI agents now trade, pay, and move money on their own, and some of them have already lost it. No AI-liability statute governs the loss. Existing law does, and it keeps asking one question the industry cannot dodge: who controlled the agent?

July 16, 2026 · 13 min readRead More →
View All Articles

In a Dispute With a Partner, Co-Founder, or Investor?

Business divorce moves fast once positions harden. Talk through your leverage with trial counsel before the other side sets the terms.

Discuss Your Dispute