INTRODUCTION
There is an irony embedded in the current regulatory moment. The EU AI Act 2024 the world’s first comprehensive AI regulation runs to 113 articles and twelve annexes, yet the category of AI system generating the most acute legal concern, agentic AI, sits awkwardly within its architecture, accommodated but not resolved. Agentic AI does not merely answer questions; it pursues objectives. Deployed in healthcare, financial trading, legal research, and autonomous transport, it plans, acts, observes results, and revises its approach all without a human approving each intermediate step. When such a system causes harm, the question of who is legally responsible is, at present, genuinely unanswered.
This is not hypothetical. The WazirX exchange hack of 2024, autonomous vehicle fatalities, and AI-assisted surgical errors have illustrated that algorithmic harms are concrete and financially catastrophic. Courts and regulators are being asked questions the common law never anticipated. This article maps the accountability terrain, identifies its structural weaknesses, and proposes a workable solution.
WHY AGENTIC AI BREAKS EXISTING LEGAL ASSUMPTIONS
Classical software operates deterministically: given defined inputs, it produces defined outputs, and the causal chain from human designer to harmful output is traceable in principle. Agentic AI is structurally different. Built on large language models employing a Reason-Act-Observe loop, it generates novel, unprogrammed intermediate actions dynamically. Researchers have confirmed that “high-risk agentic systems with untraceable behavioural drift cannot currently satisfy the essential requirements of the AI Act.”[1] For liability law, this matters because the very concept of a product “defect” becomes unstable when a system’s behaviour is non-deterministic and continuously self-modifying.
Compounding this is what Elish has termed the “moral crumple zone”: in human-AI systems, human operators absorb legal blame for failures substantively caused by autonomous systems over which they exercised little real control.[2] The surgeon who relied on an AI diagnostic tool, the trader who could not second-guess an algorithmic order they become scapegoats for institutional failures not of their making. Liability law, if it is to be just, cannot perpetuate this structure.
THE LIMITS OF EXISTING DOCTRINES
Negligence
The Donoghue v Stevenson [1932] AC 562 framework requires a duty of care, breach, causation, and damage.[3] The duty question is tractable developers and deployers of AI systems foreseeably affect those who interact with them. Breach and causation, however, are doctrinally strained. Where harm emerges through a sequence of emergent decisions that no human directly made, identifying the specific human choice that breached the applicable standard of care measured under Bolam v Friern Hospital Management Committee [1957] 1 WLR 582 is practically impossible.[4] The “but for” causation test collapses where the causal chain runs through an autonomous inference process involving probabilistic outputs.
Product Liability
The revised EU Product Liability Directive (Directive (EU) 2024/2853) extends strict liability to AI software, treating a defective AI product as cognate to a defective physical artefact.[5] Its limitation is Article 6’s definition of “defect” a product that fails to provide the safety persons are generally entitled to expect. An agentic system may cause harm while being entirely non-defective in the engineering sense, simply because autonomous goal-directed behaviour generates outcomes no designer approved. As Clifford Chance has observed, the EU approach “falls short in addressing liability where a non-defective AI agent operating independently causes harm.”[6]
The EU AI Act 2024
The EU AI Act (Regulation (EU) 2024/1689), in force from August 2024, classifies AI systems by risk and imposes pre-market compliance obligations, human oversight requirements under Article 14, and documentation duties under Articles 13 and 16.[7] It is fundamentally preventive. It creates no private right of action and is largely silent on remedies after harm occurs. The proposed AI Liability Directive COM (2022) 496 final introduces a rebuttable presumption of causality where an AI Act obligation was breached, and a right to evidence disclosure useful advances, but ones that provide no remedy for harms from a compliant non-defective agentic system.[8]
COMPARATIVE PERSPECTIVE
Jurisdiction | Existing Framework | Liability Gap | Implications |
United States | No federal AI liability framework; some state-level laws regulate specific AI applications. | No comprehensive regime governing liability for harms caused by agentic AI systems. | Creates uncertainty regarding accountability and allocation of responsibility among AI stakeholders. |
India | The Digital Personal Data Protection Act, 2023 regulates data processing but not AI liability. | No legislation, policy proposal, or judicial precedent directly addressing agentic AI accountability. | Increasingly problematic as AI adoption expands in healthcare, finance, and other critical sectors. |
Both the United States and India currently lack a comprehensive legal framework specifically addressing liability for Agentic AI systems. However, while the United States has witnessed significant state-level regulatory experimentation and policy debate, India remains at a comparatively nascent stage, with regulation focused primarily on data protection rather than AI accountability. Given the accelerating deployment of AI in high-risk sectors, the absence of a clear liability regime in India is becoming increasingly untenable and highlights the urgent need for legislative intervention to define responsibility, compensation mechanisms, and standards of care for autonomous AI systems.
A PROPOSED FRAMEWORK
Three structural interventions are required. First, mandatory audit logging: agentic AI systems deployed in high-risk sectors healthcare, financial services, transport, judicial support should be legally required to maintain tamper-evident logs of every intermediate decision and action. These logs must be discoverable by parties harmed by the system, addressing the epistemic asymmetry that defeats most claims. Second, compulsory insurance: mandatory third-party liability insurance, pooled by sector and risk-rated against the AI Act classification, should ensure victim compensation without requiring protracted causation litigation. Third, a reversed burden of proof: for high-risk agentic deployments, developers and deployers should bear the burden of demonstrating that their system did not materially contribute to the harm. Only the developer holds the architecture, training data, and inference logs necessary to establish causation placing that burden on a victim is structurally unjust.
CHALLENGES AND RECOMMENDATIONS
Critics will object that burden-shifting disproportionately penalises developers of societally beneficial systems. The response is that the safe harbour proposed above demonstrating that harm arose solely from deployer-introduced modifications provides a proportionate defence. For India, the Ministry of Electronics and Information Technology should incorporate an AI liability chapter into the National Data Governance Framework, drawing on the EU model. SEBI, RBI, and IRDAI should jointly develop sector-specific AI accountability standards. The Supreme Court’s expansive reading of Article 21 encompassing fair procedure and reasoned decisions supplies a constitutional foundation for a judicially enforceable right of explanation applicable to consequential AI decisions.[9]
CONCLUSION
The advent of Agentic AI signals an important departure from a human-centric locus of decision-making power that highlights the inadequacy of classical doctrines such as negligence, strict product liability, and vicarious liability in establishing accountability in relation to decisions made by these agents. In light of the increasing autonomy, opacity, and ability of these agents to cause harm in highly complicated ways, current doctrines fail to establish clear liability standards. In order to bridge this emerging accountability gap, lawmakers will have to embrace a risk-based approach to liability that includes transparency duties, mandatory insurance schemes, and modification of the burden of proof. This calls for proactive regulatory efforts since waiting until damages start accumulating on a large scale before regulating may make it hard for legal systems to adequately protect victims and preserve public confidence in innovative technologies.
Author(s) Name: Chaitanya Jadhav (ILS LAW COLLEGE)
References:
[1] Mind the Gap: How the Technical Mechanism of Agentic AI Outpaces Global Legal Frameworks (2025) arXiv:2603.27075, s 2.2.2.
[2]Madeleine Clare Elish, ‘Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction’ (2019) 5 Engaging Science, Technology, and Society 40.
[3] Donoghue v Stevenson [1932] AC 562 (HL).
[4] Bolam v Friern Hospital Management Committee [1957] 1 WLR 582 (QBD).
[5] Directive (EU) 2024/2853 on liability for defective products [2024] OJ L 2853, Art 6.
[6] Clifford Chance, ‘Who Is Responsible for Agentic AI?’ (2025) https://www.cliffordchance.com/insights/thought_leadership/ai-and-tech/who-is-responsible-for-agentic-ai.html accessed 5 June 2026.
[7] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (AI Act) [2024] OJ L 1689, Arts 13, 14, 16.
[8] European Commission, Proposal for a Directive on Adapting Non-Contractual Civil Liability Rules to Artificial Intelligence COM (2022) 496 final, Art 4.
[9] Ryan Calo, ‘Robotics and the Lessons of Cyberlaw’ (2015) 103 California Law Review 513.

