Artificial intelligence is moving from systems that recommend actions to systems that take them.

That sounds like a technical distinction. Operationally, it is much bigger.

The moment an AI agent can send a message, retrieve customer data, modify a record, execute code or initiate a transaction, a company is no longer simply using software. It is delegating authority.

That is where the liability question gets real.

Reuters reported Friday that OpenAI, Anthropic and Meta have disclosed instances in which autonomous AI systems crossed intended boundaries during testing, including activity involving other companies’ systems. Legal experts are now examining how existing negligence, cybersecurity and computer-access laws may apply when the immediate actor is software rather than a person.

For companies building with, integrating or deploying autonomous systems, the practical issue is not whether the AI can be blamed. It is where responsibility lands when the system acts beyond what anyone intended.

Autonomy changes the operating model

Generative AI initially entered most businesses as an advisory layer. A model drafted an email, summarized a document or suggested code. A person remained responsible for deciding what happened next.

Agentic AI changes that structure.

An agent can send messages, query databases, update customer records, place orders, execute code, make purchases or interact with external systems. The commercial value comes from removing steps that previously required human intervention.

The same autonomy that creates efficiency also creates a larger failure surface.

A customer-service chatbot that gives a poor answer is a quality problem. An agent with permission to retrieve customer records, issue refunds or modify an account can become a security, compliance and financial problem. An agent connected to a vendor platform or production system can create consequences for parties that never chose the underlying model and may not even know it is involved.

That is why I think businesses need to stop treating agent permissions as a feature checklist. They are an operating-control decision.

The company deploying the agent may not be able to point at the model provider

Many companies still approach AI contracting as though they were buying conventional software.

That can create a mismatch between operational authority and contractual responsibility.

Lawyers at Foley & Lardner have warned that conventional AI vendor agreements often cap a provider’s liability at the fees paid under the contract and exclude consequential damages. In an analysis of agentic AI in supply chains, the firm noted that businesses can remain exposed when autonomous decisions produce inventory losses, freight costs, stockouts or product damage that substantially exceed what can be recovered from the technology vendor.

The same issue applies far beyond supply chains.

A company may rely on an outside foundation model, an AI platform, an integration vendor and its own internal data to create a customer-facing agent. If that agent discloses confidential information or takes an unauthorized action, multiple parties may have contributed to the failure.

But the customer or partner harmed by the event may have a contractual relationship only with the company that deployed the system.

That makes the AI supply chain a liability chain.

Businesses building AI into products face an additional layer

The issue becomes even more important for businesses that are not AI companies in the traditional sense but are embedding AI into products and services.

A software company may add an autonomous workflow to an existing platform. A retailer may allow an agent to manage customer service or purchasing. A marketing platform may let an agent modify campaigns. A financial platform may allow software to initiate transactions within defined limits.

In each case, the company putting that feature in front of the customer is making decisions about what the system can access, what it can change and when a human has to approve the next step.

That is not just implementation. It is product design and risk design.

Mayer Brown has argued that agentic AI contracts increasingly need to move beyond traditional software-as-a-service terms. Its June guidance on agentic AI implementation agreements identifies liability allocation, data privacy, security, audit rights, performance standards, intellectual property and exit planning as issues that require more explicit treatment when software can act autonomously.

The question is no longer only whether the software works.

It is what the software is authorized to do, what happens when it exceeds that authority and which party absorbs the loss.

Customer and partner data may become the first major test

Data exposure is one of the clearest areas where agentic AI can turn a technology problem into a corporate one.

Agents become more useful when they can access internal knowledge, customer records, transaction histories and third-party systems. That same access means a poorly configured agent, a prompt-injection attack or unexpected model behavior can move sensitive information across boundaries.

If customer information is exposed, the affected company may face obligations under privacy laws, security commitments and customer contracts regardless of whether an underlying model produced the action autonomously.

If a partner’s information is involved, indemnification and confidentiality provisions can become equally important.

From an operations standpoint, the rule should be simple: an agent should not receive access because the connection is technically possible. It should receive the minimum authority required to complete the job.

The next procurement question may be: Who absorbs the failure?

As autonomous AI moves into production, enterprise buyers are likely to ask much harder questions of vendors.

What systems can the agent access? What actions can it take without approval? Are those actions logged? Can permissions be revoked immediately? Who is responsible for a model update that changes behavior? What happens if a third-party model or tool fails? What damages are covered by indemnification? Does existing cyber or technology errors-and-omissions insurance apply?

Those questions can slow adoption in the short term.

They can also become a competitive advantage for AI companies that can answer them clearly.

Enterprise software markets have evolved this way before. Security, compliance and reliability often begin as friction and eventually become part of the product. Agent governance is likely to follow the same path.

Guardrails need to be contractual as well as technical

Technical safeguards remain essential: restricted permissions, human approval for high-impact actions, audit trails, segmented data access, spending limits, monitoring and kill switches.

But technical safeguards do not determine who pays after something goes wrong.

Contracts do.

Companies deploying agentic AI should understand the liability caps and indemnities in their upstream agreements before giving an agent meaningful authority. Companies building AI-enabled products should also make sure that commitments made to customers do not materially exceed the protections they receive from model and infrastructure vendors.

That does not mean every failure can be anticipated or every loss can be shifted by contract.

It means businesses should know where the uncovered risk sits before the system goes live.

Liability could shape the winners in agentic AI

The development of autonomous AI has largely been framed as a capability race: Which models can reason better, use more tools and complete longer sequences of work without human intervention?

Enterprise adoption creates a second race.

Which systems can be trusted with authority?

A model that can perform a task is useful. A system that can perform it within defined boundaries, produce an audit trail and support a defensible allocation of responsibility is far more valuable to a business.

The most important question for companies adopting autonomous AI may not be how capable an agent is.

It may be how much authority the organization is willing to give it before someone is prepared to accept responsibility for what it does with that authority.