---
title: "Who is liable when an AI agent in your business makes a mistake?"
description: "Every vendor I read places responsibility for what its AI assistant does on the business that uses it. That is you, not them."
image: "https://bombos.ai/assets/og-en-v2.png"
---

# Who is liable when an AI agent in your business makes a mistake?

Every vendor I read places responsibility for what its AI assistant does on the business that uses it. That is you, not them.

*Bombos team · 20 September 2026 · 13 min read*

_By Piet Baudoin · September 2026_

**Every vendor whose terms and guides I read places the responsibility for what its assistant does on you. At United, a customer only got her $200 credit back after the press called.**

The law is arriving later than the products. This article reasons from European law, the EU AI Act. How the United States, the United Kingdom, Canada and Australia handle it is further down. How far AI agents are getting in small businesses is covered in [the overview of the agentic economy](https://bombos.ai/en/blog/what-is-the-agentic-economy/).

## What do the AI vendors themselves say about who is responsible?

All four vendors I read put the responsibility for how their AI is used on the customer. Anthropic puts it most bluntly, in the safety guide for Claude Cowork: “You remain responsible for all actions taken by Claude performed on your behalf.” Anything Claude does on your behalf counts as something you did. It gives sent messages and payments as examples.

The same text says that by default, Claude waits for your approval before anything is sent or paid. More on that in [the article on what Claude can do for a small business](https://bombos.ai/en/blog/what-can-claude-do-on-its-own-for-a-small-business/).

Microsoft calls it shared responsibility. It describes the difference from an ordinary AI assistant like this: “an agent doesn’t only return content for a human to act on. Instead, an agent: Acts autonomously.” So an agent does not just give an answer. It acts by itself, without anyone approving each step.

Zapier gives its own warning: an agent that can reach private data, reads instructions from outside and is allowed to send data can do things you did not intend. For now, don’t run your most sensitive work through it, Zapier adds. Employment Hero, which makes HR software, does take something on: it has committed that it “will not use customer data to train AI models”, and the outside companies that run AI for it are “contractually bound by the same restriction.”

| Vendor | What the vendor handles for you | What stays your responsibility |
| --- | --- | --- |
| Anthropic (Claude) | By default, Claude asks for your approval before it sends, posts or pays anything | Everything Claude does on your behalf. If it sends the wrong message, you sent it |
| Microsoft | A list of what can go wrong with an agent | How you set it up and what it can reach. After that it acts by itself, without anyone approving each step |
| Zapier | A warning that an agent can do things you did not intend | Whether you trust it with your most sensitive work |
| Employment Hero | It will not use your data to train AI models, and binds the outside companies that run its AI to the same rule | What its AI does on your say-so: its terms place responsibility for “agentic and automated actions with the user who initiates and confirms them” |

## What does the EU AI Act already require, and what comes later?

This is European law. It applies if your business is in the EU, or if what your AI produces is used there. Today it requires one thing: telling people they are dealing with AI. Since 2 August 2026, the European Commission has been enforcing Article 50 of the EU AI Act. Its own Q&A on that article names AI agents in so many words, alongside chatbots and avatars.

For marking generated content, the deadline for existing systems is 2 December 2026. After that, nothing happens until 2 December 2027. From that day, high-risk AI use needs a person keeping watch who can step in. The law calls this appropriate human oversight, and you will run into that term. It does not apply to everything, only to a list of uses the law classifies as high risk. That list is called Annex III.

The fines are a separate matter. For other violations, the Commission names a ceiling of €15 million or 3 percent of worldwide turnover. Which ceiling applies to a breach of the high-risk requirements is not stated on the pages I read.

Be careful with hiring. Employment Hero writes on its AI page: “Our AI autonomously screens thousands of candidates, delivering ranked shortlists in minutes instead of weeks.” The same page says: “Every hiring decision remains in human hands.” Assessing job applicants is one of the areas that Annex III marks as high risk ([Annex III, point 4](https://artificialintelligenceact.eu/annex/3/)). That is not a judgment of Employment Hero: the law looks at the use, not the brand.

These dates shift, and not every page moves with them. The Dutch Data Protection Authority (AP) still lists supervision of high-risk AI under August 2026, while the Commission itself says 2 December 2027.

There will be no separate law for agents, says the Commission’s AI Act Service Desk: the existing definition of an AI system already covers them. [The article on how long an AI agent can work on its own](https://bombos.ai/en/blog/what-is-an-ai-agent-and-how-long-can-it-work-alone/) explains what an agent is.

## How is this regulated outside Europe?

Nowhere else has a law like the EU AI Act, and everywhere the answer comes out the same: the business that uses the agent answers for what it does.

**United States.** There is no federal AI liability law as of September 2026. Baker McKenzie wrote on 1 July 2026: “There are currently few US laws and judicial decisions that explicitly refer to AI agents”, but “existing laws and principles suggest that companies will be expected to govern, monitor, and explain what their AI agents do.” The Federal Trade Commission put it shorter in 2024: “there is no AI exemption from the laws on the books.” The states are moving, and Washington is pushing back. An executive order of 11 December 2025 set up a task force to challenge state AI laws. Colorado’s 2024 AI law never took effect: a federal court blocked it on 27 April 2026, and on 14 May 2026 the governor signed a narrower replacement that starts on 1 January 2027 and splits fault between the maker of the AI and the business that uses it. Texas has had its own act since 1 January 2026; only the state attorney general can enforce it.

**United Kingdom.** No AI act. In July 2026 the UK Jurisdiction Taskforce published a legal statement on liability for AI harms. Its conclusion, as A&O Shearman summarizes it: “existing common law doctrines should be sufficient to determine liability for harm caused by AI.” And because an AI has no legal personality, “any claim in relation to such statements must be directed at a legal person, such as a developer, deployer or user.” Burges Salmon draws the line for you: “A careless user of AI is likely to be held liable for foreseeable harm.”

**Canada.** The proposed AI act died in January 2025, and the privacy bill of June 2026 has nothing in its place. What Canada does have is the ruling every lawyer quotes. In February 2024 a tribunal held Air Canada to a refund its chatbot had promised: “It makes no difference whether the information comes from a static page or a chatbot.”

**Australia.** The government dropped its plan for mandatory guardrails in December 2025 and relies on existing law.

The common thread: the agent is a tool of your business, and what the tool says or does counts as your business acting. The EU is the only place that adds a rulebook for high-risk uses on top. From 9 December 2026 its revised product liability rules also cover software, and the plan for a separate European law on AI liability was withdrawn in February 2025.

## What happens in practice when an AI assistant gets something wrong?

The business pays, and usually only after someone pushes. On 16 September 2026, NBC Chicago described a United Airlines customer. The chatbot told her that her $200 credit was valid for another five years; it expired on 27 September 2026.

United told the station that the chatbot had given her wrong information. She got a new certificate after the press called.

It is not only about customers. In August 2026, an investor wrote that her AI assistant had sent an email on her behalf in the middle of the night, without being asked. She then cut its connection to her email. [The article on whether an AI assistant should send email on its own](https://bombos.ai/en/blog/should-an-ai-assistant-send-email-on-its-own/) covers the ruling in which Air Canada was held to what its chatbot had promised.

An assistant that can reach your email, your bank and your books can break more than one that only gives answers. This is called excessive agency. Microsoft puts it on its own list of things that can go wrong and that you need to account for when you set an agent up. On the OWASP list of the ten biggest AI risks, it climbed from sixth to third place this year, based on 6,639 incidents.

## What happens if this pace continues?

Two clocks are running, and they do not keep the same time. Put three things side by side. On 15 September 2026, Google switched on Gemini’s connections to accounting software and a CRM by default for everyone with access. That same day, Aembit wrote that excessive agency had climbed from sixth to third place on the new OWASP list. And Employment Hero’s AI page says its AI “autonomously screens thousands of candidates”, while Annex III marks the assessment of job applicants as high risk. More permissions, more damage, and work that will soon fall under supervision. The law only kicks in on 2 December 2027, fourteen months later.

My hypothesis: on 2 December 2027, the question for you will not be whether you were allowed to use AI. It will be whether you can show who approved what, and why. That is not a legal prediction. It is an estimate of what you are going to need.

The reasoning: an assistant already acts on your behalf today, the damage from that is being measured and is climbing, and oversight you did not record is oversight you cannot show later.

Two things could break this. The dates have already shifted once, and regulators are not in step, as the Dutch Data Protection Authority’s page above shows. It is also possible that the vendors build such a record into their own products, and then you do not need to do anything.

For a small or midsize business, the math is simple. Starting today, record who approved what and why. If a business of twenty people clicks Approve five times per working day, then by 2 December 2027 about 1,400 decisions will be on record: five times twenty working days times fourteen months. That is an example calculation, because nobody has counted how many there are at your business. The rest can wait.

## What does an approval step not solve today?

Approval does not shift anything to the vendor. The terms and guides I read say the opposite: anything the assistant does on your behalf counts as something you did. Approval also does not take back a mistake that has already reached a customer, and it does nothing if someone clicks Approve without looking.

It does not help for a chatbot on your own website either, because there is no approval step there.

At Bombos, no message goes to a customer and no payment goes out without someone from your own business clicking Approve. That is technically enforced and always on. It is not an indemnity. What it produces is a record: who approved what, when, and based on which information.

This is not legal advice. If you want certainty about your own situation, take it to a lawyer or to your insurer.

## How do you start small?

Pick one task that you can undo and where you can see afterward what happened, for example sorting [a shared inbox](https://bombos.ai/en/shared-inbox-for-your-team/).

Tomorrow, ask your vendor two things. Where in the terms does it say who is responsible when your AI sends something on our behalf? And where can we see who approved what, and on what basis? Then check which connections are switched on by default at your business.

Bombos reads what comes in: email, text messages, receipts and invoices. It looks up the information it needs in the software you already use and has the work ready for you in the Inbox, with the reason next to it. You click Approve.

When a better model comes along, we put it underneath without you having to set anything up again. We can put the strongest and most cost-efficient model underneath right away, and switch per client to what that client wants. Bombos runs on its own servers in Europe, and so do the models. What Bombos learns from your business does not sit in that model. It sits in what your people approved, corrected and rejected, and that stays when the model changes. The approval also stays as the models get better, so you can keep up with the pace without the risk growing along with it. We read what happens in the field every day and write it up in [our daily newsletter](https://bombos.ai/en/blog/newsletter/).

Our promise: after three months, the work we start with is ready every day, without anyone having to think about it.

Approval is not a brake on your AI. It is your record.

Want to know whether that works for you? [Leave your number](https://bombos.ai/en/contact/) and we will call you back.

## Sources

Every source was opened on 20, 23 or 26 September 2026 and every quote appears in it word for word.

**What the vendors write themselves**

-   [Anthropic, Use Claude Cowork safely](https://support.claude.com/en/articles/13364135-use-claude-cowork-safely) (living guide, 20 September 2026)
-   [Anthropic, Claude for Small Business](https://claude.com/blog/claude-for-small-business-launches-new-workflows-integrations-and-training-programs) (15 September 2026)
-   [Microsoft Learn, AI agent shared responsibility model](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai-agent) (11 September 2026)
-   [Zapier, Get started with Next Gen Zaps](https://help.zapier.com/hc/en-us/articles/48391476448141-Get-started-with-Next-Gen-Zaps) (18 September 2026)
-   [Employment Hero, updates to its platform terms, data processing agreement and privacy policy](https://employmenthero.com/legals/updates-to-our-platform-terms-dpa-and-privacy-policy-summary/) (opened 23 September 2026)
-   [Employment Hero, AI](https://employmenthero.com/ai/) (opened 23 September 2026)
-   [EU AI Act, Annex III](https://artificialintelligenceact.eu/annex/3/) (the text of the law, read 20 September 2026)
-   [Google Workspace Updates, more connections for Gemini](https://workspaceupdates.googleblog.com/2026/09/connect-to-more-tools-with-gemini-in-Google-Workspace.html) (15 September 2026)

**What the EU rules say**

-   [European Commission, transparency obligations under Article 50](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act) (24 July 2026)
-   [European Commission, start of enforcement](https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august) (31 July 2026)
-   [European Commission, enforcement of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act) (24 August 2026)
-   [AI Act Service Desk, how AI agents are addressed within the AI Act](https://ai-act-service-desk.ec.europa.eu/en/ai-act/faq/how-are-ai-agents-addressed-within-ai-act-0) (living page, 20 September 2026)
-   [Dutch Data Protection Authority (AP), the AI Act](https://www.autoriteitpersoonsgegevens.nl/themas/algoritmes-ai/ai-verordening) (read 20 September 2026)

**What the rules say outside Europe**

-   [Baker McKenzie, legal accountability for AI agents in the United States](https://www.bakermckenzie.com/en/insight/publications/2026/06/united-states-legal-accountability-for-ai-agents) (1 July 2026)
-   [Federal Trade Commission, Operation AI Comply](https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes) (25 September 2024)
-   [Latham & Watkins, on the executive order targeting state AI laws](https://www.lw.com/en/insights/ai-executive-order-targets-state-laws-and-seeks-uniform-federal-standards) (17 December 2025)
-   [McDermott, Colorado AI law in flux](https://www.mcdermottlaw.com/insights/colorado-ai-law-in-flux-comprehensive-replacement-bill-signed-after-federal-court-blocks-predecessors-enforcement/) (27 May 2026)
-   [Norton Rose Fulbright, the Texas Responsible AI Governance Act](https://www.nortonrosefulbright.com/en/knowledge/publications/c6c60e0c/the-texas-responsible-ai-governance-act) (December 2025)
-   [A&O Shearman, on the UKJT legal statement on AI liability](https://www.aoshearman.com/en/insights/ao-shearman-on-tech/ai-liability-no-regulation-no-caselaw-no-problem-for-english-law-says-the-ukjt) (22 July 2026)
-   [Burges Salmon, who is liable if AI goes wrong](https://www.burges-salmon.com/articles/102n8h3/who-is-liable-if-ai-goes-wrong-ukjt-statement-on-ai-and-civil-liability-publishe/) (7 July 2026)
-   [DLA Piper, Canada tables Bill C-36](https://www.dlapiper.com/en/insights/publications/2026/06/canada-tables-bill-c36-the-protecting-privacy-and-consumer-data-act) (17 June 2026)
-   [McCarthy Tétrault, Moffatt v. Air Canada](https://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot) (19 February 2024)
-   [ABC News, Australia’s National AI Plan relies on existing laws](https://www.abc.net.au/news/2025-12-02/national-artificial-intelligence-plan-growth-existing-laws/106086474) (2 December 2025)
-   [Jones Day, the revised EU Product Liability Directive](https://www.jonesday.com/en/insights/2026/06/the-revised-eu-product-liability-directive-state-of-play-across-eu-member-states-and-evolving-risk-landscape) (June 2026)
-   [IAPP, Commission withdraws the AI Liability Directive](https://iapp.org/news/a/european-commission-withdraws-ai-liability-directive-from-consideration) (12 February 2025)

**What went wrong**

-   [NBC Chicago, on chatbots in customer service](https://www.nbcchicago.com/consumer/ai-chatbots-are-taking-over-customer-service-but-how-often-are-they-wrong/3989958/) (16 September 2026)
-   [Katie Jacobs Stanton on an email sent without being asked](https://x.com/KatieS/status/2091152514603422074) (22 August 2026)
-   [Aembit, what changed in the OWASP Top 10 for 2026](https://aembit.io/blog/the-owasp-top-10-for-llm-applications-2026-what-changed-and-why-it-matters/) (15 September 2026)
-   [The Next Web, on the OWASP list and excessive agency](https://thenextweb.com/news/owasp-llm-2026-agency-cra) (16 September 2026)

### Curious what Bombos can do for your business?

Together we look at which work keeps piling up and set your workers up for exactly that.

[We'll call you back](https://bombos.ai/en/contact/)


---

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Who is liable when an AI agent in your business makes a mistake?","description":"Every vendor I read places responsibility for what its AI assistant does on the business that uses it. That is you, not them.","datePublished":"2026-09-20T00:00:00.000Z","dateModified":"2026-09-23T00:00:00.000Z","author":{"@type":"Organization","name":"Bombos"},"publisher":{"@type":"Organization","name":"Bombos","logo":{"@type":"ImageObject","url":"https://bombos.ai/assets/bombos-bee.png"}},"mainEntityOfPage":"https://bombos.ai/en/blog/who-is-liable-when-an-ai-agent-makes-a-mistake/","inLanguage":"en"}
```
