Vicarious Liability for AI

Vicarious liability for AI is the principle that a business is responsible for what the AI agents it deploys do, much as an employer answers for an employee acting in the scope of their job. Your agent's mistakes are legally your mistakes; deploying autonomy doesn't transfer the liability away with it.

In Depth

Vicarious liability is an old idea. The law has long held that when you put someone to work on your behalf, you answer for the harm they cause doing it. The employer is on the hook for the employee's negligence, because the employer chose to deploy them, benefits from their work, and is best placed to control the risk. The logic was never about the worker being a person. It was about responsibility following control and benefit.

AI agents drop neatly into that frame. When you deploy an agent, you direct it toward your goals, you profit from its output, and you decide how much autonomy and oversight it has. So when it causes harm, the natural place for the law to land is on you, the deployer, not on the software, which can't be sued, and often not solely on the model vendor several steps upstream. The tempting argument that "the AI did it, not us" runs straight into a body of law built to reject exactly that move.

This is why autonomy doesn't launder away liability. Intuitively, an agent acting "on its own" feels like it should dilute the operator's responsibility. Legally, it tends to concentrate it. The more independently your agent acts, the more its conduct looks like conduct you set in motion and chose not to supervise, which is the heart of why every AI vendor needs coverage written for the agent itself.

What It Looks Like

In Moffatt v. Air Canada (2024 BCCRT 149), a customer relied on a refund policy that Air Canada's support chatbot had simply made up. The airline argued the chatbot was a separate entity responsible for its own statements. The tribunal rejected that outright: the company was responsible for all the information on its site, including what its AI told customers. The customer got the refund. The case is now the reference point for a simple rule: your agent's words and actions are treated as the company's own, and "the bot said it, not us" is not a defense.

Why It Matters For AI Vendors

Vicarious liability is the reason AI risk can't be waved off as the model provider's problem. You deployed the agent, so the harm routes to you, and through your contracts, often to your enterprise customer as well, which is exactly why their procurement teams care so much about what your agent can do. The exposure doesn't shrink as your agent gets more capable; it grows, because the agent is doing more, more independently, in your name.

It also explains the structural answer. If liability attaches to the deployed agent, then the insurance has to attach there too. A policy written for "your software in general" misses the unit where the law actually assigns the blame.

Common Questions

A disclaimer helps less than people hope. Moffatt shows a court treating an operator as responsible for its chatbot's statements regardless of the "it's separate" argument. Disclaimers and terms matter, but they don't reliably move the liability off the deployer.
Usually not solely. You're the one who deployed the agent toward your purpose with your configuration and oversight choices. Upstream vendors may share exposure, but vicarious liability tends to land on the party operating the agent in the world.
It doesn't erase your responsibility, but it strengthens your position. Meaningful human review is evidence of reasonable care, lowers the agent's risk profile, and raises its score.
← PreviousTechnology Errors & Omissions (Tech E&O)

See where your AI agents stand.

Get an Agent Trust Score, map your liability exposure, and find out what it takes to make your AI agents insurable.