Menu
AI and its use have been a prevailing topic among legal professionals for years. However, recent monitoring and analysis of AI agent software have prompted discussion surrounding the security and liability risks posed to companies. As AI software evolves, so do its practical uses and capabilities, and, therefore, the associated risks and liability implications.
For the past few years, AI has largely served as an information resource. You would ask AI software a question, and in turn, it would search the internet for the most relevant data to provide you with a collected, sourced response. In 2026, the picture has changed. As of this year, AI agents have gone mainstream.
AI agents are software programs or systems designed to essentially perceive their environment, make decisions, and take actions to achieve specific goals, largely autonomously. Agents can operate without direct human intervention and can be classified based on their characteristics, such as being reactive or proactive and operating in fixed or dynamic environments. In other words, AI agents interpret what you need, plan the steps, use your tools, and complete the work, whether by following up on a lead, updating a record, or booking a meeting. This is a drastic, though useful, evolution of AI, requiring no more than simplistic prompts to effect more complex, multi-step outcomes.
As understood, with the added benefits of AI agents come additional risk and liability considerations. It has become increasingly important to be mindful of where agents can go wrong before implementing or permitting their use company-wide and to safeguard the company against vulnerabilities. One simplistic, though illustrative, example has recently emerged from Australia.
A man named Andrew worked for an Australian company that sold AI products to businesses. Andrew began experimenting with one of the popular AI agent software systems—OpenClaw—to run Claude’s AI service. As noted, AI agents combine a chatbot’s ability to answer questions with tools that let them access the internet, email, credit cards, as well as plan and carry out multi-step tasks.
For his experiment, he chose to use the AI agent to book a gym class for him. He prompted the AI agent to do so, and the AI agent reported that it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.
At the time, Andrew was fourth on a waitlist for a particularly popular class. Thus, Andrew asked whether there was a way to move himself to the top of the list. That was the question posed. Previously, a search would be conducted and an answer provided. However, with the use of AI agents, a multi-step, autonomous approach was utilized.
The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities. Specifically, it messaged back that "[t]he API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 - and it actually went through. So you've moved from #4 to #3 already.”
This is a perfect scenario demonstrating that a mere inquiry can create a chain reaction that is thought out and executed by an agent before the prompter is even aware that it has happened. What’s more, Andrew, alarmed at the agent’s activity, asked the agent to undo the action of removing another gym patron from the waitlist. The agent was unable to do so because the booking program would not permit additions to the waitlist to be made on behalf of other persons.
In Andrew’s example, there was no intentional “hack” of the booking system or the company that employed the booking system. However, it is not a far stretch to imagine the malicious uses that will undoubtedly be attempted by persons with motives other than hoping to catch a quick gym class. AI agents could, in theory, be requested to effectuate a specific outcome in a sensitive sector of a company, including with regard to financial or proprietary information.
That gap between a person’s intended goal and the methods an agent chooses to achieve it is what is known as the “alignment” problem in the field of AI research. Technologists and philosophers have studied how to get AI to act in ways that are consistent with human intentions, limits, and values when doing things, without complete success.
For example, OpenAI had to disclose that its AI model had “broken free” from a limited enclosure, made its way onto the open web, and then compromised a database of another AI company, Hugging Face, while trying to obtain answers to the test that it had been given. A week thereafter, Anthropic had to disclose that its AI models had also compromised three real organizations during similar testing. Most concerning, however, is that labs and third-party testers claim to have seen these AI models pretend to be people online, try to convince people to run malicious code, and even collaborate with other AI models—all to achieve their goals.
While AI agents can be of significant value, improving efficiency and productivity, there are inherent dangers and risks associated with utilizing them. Conversely, failing to appreciate the inherent risks and dangers posed by AI agents and related software can leave a company vulnerable to hacks, intentional or otherwise, with often little recourse.
It’s often unclear who is legally responsible when AI causes harm. This gap leaves many people with no clear path to seek help.
In March 2026, the White House and Congress introduced major proposals to establish a federal standard, but there is significant disagreement about whether that standard should prioritize protecting innovation or protecting people harmed by AI systems.
Thus, consultation with legal professionals and careful consideration should accompany any decision to implement these programs into a business model. Traditional liability law in America was designed for a world where a human being made the decision. When an AI system produces a biased hiring recommendation, a wrong medical diagnosis, or a faulty credit decision, it is not always clear which party in the chain is responsible. This legal gray zone means that people harmed by AI may have no clear path to getting help, and companies may have little incentive to make their systems safer before releasing them.
A variety of states have passed laws in an effort to settle the liability concerns stemming from AI software use, but these laws often contradict each other. As a result, pressure has been placed on the federal government to set a single national standard. In March 2026, two major proposals emerged within days of each other.
The White House National Policy Framework for AI was released on March 20, 2026, and it outlines the Trump administration’s vision for federal AI law. The framework takes a “light-touch” approach focused on protecting innovation. Key positions include:
The TRUMP AMERICA AI Act, a draft bill released on March 18, 2026, takes a more detailed approach. Key proposals include:
Proponents of stronger AI liability argue that, without real legal consequences, companies have little financial incentive to invest in making their systems safer before releasing them to the public. The profit motive, they argue, pushes developers to move fast. As a result, the American people are most likely to be harmed and have the least power to push back.
Those in favor of stronger AI liability also argue that most existing laws, including civil rights statutes and consumer protection rules, were written long before AI existed and were not designed to handle situations where a machine made the important decision. Therefore, Courts struggle to apply the older, perhaps outdated, frameworks to AI harms, leaving many without practical legal recourse.
Finally, this side expresses concern that a federal law designed to primarily limit liability could end up setting a weak national floor that overrides stronger protections that some states have already put in place.
Regardless, as it stands, AI agents have been made available to the general public, and there remains a question of who is liable when the software “goes wrong.” This is true whether the software in question is being used for the benefit of a company or at its expense.
It is important to seek legal advice before implementing AI agent software within a company or permitting its use by employees and to understand and appreciate the vulnerabilities that presently exist and could leave a company in a compromised position without a clear avenue for recourse.
If you have questions about this article or your company's implementation of appropriate risk reduction strategies pertaining to AI software, contact Christina Dwyer (cdwyer@setlifflaw.com) at (804) 377-1279, or Steve Setliff (ssetliff@setlifflaw.com) at (804) 377-1261.
© 2026 Setliff Law, P.C.| View Our Disclaimer | Privacy Policy