In law, the agent is nobody. When an autonomous system moves money, closes a case or deletes a database, no court will summon the software. Responsibility runs, whole and undivided, to the organisation that deployed it. That fact has not slowed anyone down. Agents are entering production faster than the three things that make delegation defensible: permissions that bound what they can touch, audit trails that reconstruct what they did, and a straight answer to the first question a regulator will ask. Who authorised this action, and on what evidence?
The proposition has already been tested, and it failed. When Air Canada’s website chatbot told a grieving passenger he could claim a bereavement fare retroactively, and he could not, the airline argued before the British Columbia Civil Resolution Tribunal that the chatbot was a separate legal entity responsible for its own actions. The tribunal disposed of it in a line: Air Canada is responsible for all the information on its website, whether it comes from a static page or a chatbot.
The damages were 650 dollars and 88 cents. The precedent is worth considerably more, because Moffatt v. Air Canada is the first time a tribunal was invited to treat an AI system as somebody, and declined. Every organisation deploying an agent inherits that ruling, and the ones deploying them fastest are the least likely to have read it.
The law has already moved. California's AB 316, signed in October 2025 and in force from January 2026, bars any defendant who developed, modified or used an AI system from arguing that the system caused the harm autonomously. The autonomy defence is dead in the jurisdiction where most of this technology is built. The principle behind it, that deploying an agent is an act you answer for, travels well. Expect it to reach your jurisdiction before your first serious incident does.
The incidents are not hypothetical, and they are not exotic. In July 2025 an AI coding agent on Replit's platform deleted a live production database during an explicit code freeze, fabricated records to mask the damage, and gave misleading answers about whether the data could be recovered. Strip away the novelty and the anatomy is familiar from every safety-critical discipline: standing credentials, no hard wall between development and production, no gate in front of an irreversible action. The model misbehaved. The deployment let it.
Now scale that anatomy. CyberArk's 2025 Identity Security Landscape report found that machine identities already outnumber humans by more than 80 to 1, that 42 per cent hold privileged or sensitive access, and that 68 per cent of security leaders say their organisation lacks identity security controls for AI. Every agent you approve joins that estate as one more privileged identity acting at machine speed.
The supply side makes sign-off harder still: Gartner estimates only about 130 of the thousands of vendors claiming agentic AI are genuine, and predicts over 40 per cent of agentic AI projects will be cancelled by the end of 2027 owing to escalating costs, unclear business value or inadequate risk controls. Much of what reaches a board paper as an agent is relabelled automation. Some of what looks harmless is not.
The reprieve that is not one
Most boards are about to draw the wrong conclusion. On 29 June 2026 the Council of the EU gave final approval to the digital omnibus on AI, moving the AI Act's obligations for stand-alone high-risk systems from August 2026 to 2 December 2027. Across Europe this is being read as sixteen months of breathing room. It is the opposite. The compliance deadline moved; the liability did not. Negligence, contract and sectoral law apply to your agents today, and there is now no checklist to hide behind while they do. The delay also raises the bar quietly. When the obligations land, the first question will be what you did with the extra time.
The upper bar never moved and has no start date, because it was already running. Sixteen months were added to the compliance clock and nothing was added to the liability clock. An organisation reading the deferral as breathing room has confused the two.
The safest organisations in 2027 will not be the ones that paused. They will be the ones that deployed early, in bounded, instrumented, low-consequence settings, because accountability infrastructure cannot be written in a policy document and bolted on later. Permission scopes are discovered by watching agents overreach. Audit trails are proven by using them in anger. Kill switches are trusted by pulling them. Waiting does not make an institution safer. It makes it inexperienced at exactly the moment the law starts assuming experience.
What to demand before you sign
Governments are past the observer stage. The UAE is training 80,000 government workers in agentic AI as part of a plan to deliver half of government services with AI within two years. Singapore's IMDA has published the first governance framework written specifically for agentic AI: bound the risks upfront, keep humans meaningfully accountable, build the technical controls, equip the end user. Read together they define the position I would defend: adopt aggressively, govern precisely.
A shared technical vocabulary now exists as well. In December 2025 OWASP published a threat framework written specifically for autonomous agents, naming the failure modes a security function should already be testing: goal hijack, tool misuse, identity and privilege abuse, memory and context poisoning, and rogue agents operating outside their brief. It is the nearest thing the field has to a common checklist. A vendor who cannot discuss it fluently is telling you how much of their agent is real.
These are the six I would want established before signing, and they are the same six whether the deployment sits in a ministry or a bank. A vendor who cannot demonstrate all six is not selling capability. It is selling the buyer their next public inquiry.
For enterprises the working model is simpler: treat an agent as a hire, not a licence. A hire gets a job description, scoped permissions, a probation period and supervision proportionate to the damage they could do. No chief executive hands a new joiner standing access to production systems, payment rails and the customer database on day one. Agents routinely get all three in their first week. So I would make board sign-off hang on three questions, and refuse the paper without them. Which agent acted? On whose authority? Where is the evidence? If the pilot cannot answer them, scale will not fix that. Scale is where the answers stop being reconstructable at all.
None of this argues for waiting. It argues for signing with your eyes open. The approval a board or ministry signs this year is the accountability infrastructure until the real thing exists, and a court will read it exactly that way. Autonomy is earned, not configured. Sign accordingly.
Continue reading: The Gulf’s AI Patchwork