AI Controls and Governance

Can I be held accountable for what an AI agent does?

This question tends to arrive in the first person, at a specific moment: your name has just gone on something. You signed off an agent's deployment. You used one in work delivered under your professional duty. You've become the person an agent unofficially belongs to. The organisational question — where responsibility lands inside a company when an agent gets something wrong — is a different question, covered in [Who is responsible when an AI agent makes a wrong decision?](https://www.engramic.ai/resources/who-is-responsible-when-an-ai-agent-makes-a-wrong-decision). This page is about you: your legal, professional, and contractual position as an individual.

One note before the detail. This page is information, not legal advice. Liability rules differ by jurisdiction, profession, and contract, and they are changing quickly. For your own exposure, speak to counsel.

The honest answer to the question is yes, in most jurisdictions. The more useful answer is what your position turns on when the question becomes real — and it is not the thing most people preparing for it are preparing.

The Defence that Has Been Closed

The intuition many people quietly hold is that an agent's autonomy creates distance. The system decided, so the person didn't. The legal direction of travel runs the other way: autonomy is not a defence, because accountability frameworks have declined to create a category of harm that belongs to the software.

California made this explicit. Since 1 January 2026, a defendant who developed, modified, or used an AI system cannot assert, in a civil action, that the system autonomously caused the harm. The law does not create automatic liability — a claimant still has to prove causation and foreseeability, and the ordinary defences still apply. What it removes is the distance. The EU reached a related position through product law: the revised Product Liability Directive treats software, explicitly including AI systems, as products under a strict liability regime from December 2026. And even where legislation has retreated — Colorado enacted the most comprehensive deployer regime in the United States, then scaled it back and delayed it in May 2026 — what survives the revision is a record of how AI was used and a person or organisation identifiable as responsible for it. Jurisdictions disagree about how much process to require. None of them is moving toward "no one answers".

Where the Exposure is Personal, not Organisational

Professional duty does not delegate. If you hold a licence or owe a professional standard — law, medicine, accountancy, engineering — using an AI system does not dilute the duty, because regulators and courts treat output you relied on as your work. The American Bar Association's guidance makes the point bluntly: whatever level of review a lawyer chooses to apply to AI output, the lawyer remains fully responsible for the result. The enforcement record backs it. One liability underwriter has tracked over seven hundred US incidents of attorneys sanctioned or disciplined for filing AI-fabricated content, with individual penalties reaching six figures. Medicine runs the same way, with a twist worth noticing: responsibility for an AI-assisted error stays with the physician, and a physician who overrides an AI recommendation is increasingly expected to justify the disagreement. The duty cuts in both directions. The tool is invisible to it.

Contractual exposure flows downhill. AI vendors generally transfer liability to the deploying organisation through their terms — which is why vendors rarely appear as defendants when their output causes harm. Inside the organisation, sign-off becomes the allocation mechanism: the deployment approval, the budget authority, the named owner in the risk register. And there is an insurance wrinkle most people discover late. Professional indemnity carriers have begun writing AI exclusions into their policies. The exposure you assumed was insured may not be, and the time to find out is before an incident, not during one.

Then there is the designation itself. Emerging accountability regimes converge on requiring a clearly identified responsible human or organisation, and courts and regulators have grown impatient with diffuse responsibility: the claim that nobody specifically was watching reads less like a defence and more like an admission. Designated responsibility is what makes governance workable. It is also what concentrates the question on a name. If the name is yours, the rest of this page is about what you want to exist when the question arrives.

If Your name is on an Agent

Four things are worth doing before any of this is urgent, and all of them are mundane. Know specifically what you approved, not approximately — "I signed off the procurement agent" is a different position from "I approved this scope, with these constraints, on this date." Insist that the operating context the agent works from is recorded somewhere retrievable and versioned, rather than living in a prompt file someone edits in place. Read your indemnity and insurance position now, including any AI exclusions, while it is a contract question rather than a claims question. And treat every sign-off as the creation of evidence, because that is what it becomes the day something goes wrong.

Engramic's approach

How Engramic Approaches it

There are multiple ways to implement this. This is one approach.

Engramic is where the operating context an agent works from is authored before the agent acts — the goals it was given, the constraints it was under, the decisions it was built from — with changes preserved alongside what they replaced. When a question about a specific agent's conduct arrives at a specific person, what that person retrieves is the record of what the agent was given and what was approved, as it stood at the time.

The scope of that claim matters. Engramic does not change your legal position; your jurisdiction, your profession, and your contracts do that. What it changes is what you can produce when that position is examined: a record created before the agent acted, rather than a reconstruction assembled after the question arrived.