Who’s Liable When Your Company’s AI Agent Breaks the Law?
Your company is legally liable, not the AI vendor. Since the CMA’s 9 March 2026 guidance and existing Companies Act 2006 director duties, agentic AI failures now carry direct financial and personal accountability for UK boards.
What Does the CMA’s Agentic AI Guidance Actually Require?
On 9 March 2026 the Competition and Markets Authority published its guidance on complying with consumer law when using AI agents — the first UK regulatory framework built for autonomous, decision-making AI. It confirms that the business deploying an agent, not the vendor that built or trained the model, bears legal responsibility for breaches of consumer protection law. Under the Digital Markets, Competition and Consumers Act, the CMA can now investigate and fine directly, without going to court.
According to the CMA, its guidance is built on four expectations: transparency about when customers are dealing with an AI agent rather than a person; compliance by design, so consumer rights are built into how the agent operates rather than bolted on afterwards; continuous human oversight, since deploying an agent is not a “set it and forget it” exercise; and swift remediation when an agent misbehaves at scale. Boards that cannot evidence all four should treat this as an open exposure, not a future risk.
Executive Action
- Request written evidence from the CIO that every customer-facing AI agent has a documented human-oversight and escalation path.
- Ask whether AI agent behaviour has been mapped against consumer protection obligations, not just data protection ones.
- Confirm a “swift remediation” process exists that can pause or roll back an agent within hours, not weeks.
Are Directors Personally Liable When an AI Agent Fails?
The CMA’s guidance sits alongside, not instead of, existing director duties. Under the Companies Act 2006, section 172 requires directors to act in a way they consider most likely to promote the success of the company, and section 174 requires reasonable care, skill and diligence. Neither duty carves out an exception for decisions delegated to software. Legal commentary on corporate AI accountability increasingly points to a “reasonable oversight” standard: an organisation deploying an autonomous agent remains liable for its actions unless it can demonstrate robust monitoring, auditing and safety controls were in place before the failure occurred.
A board that approves an agentic AI rollout without asking what oversight exists, and without recording that it asked, is harder to defend if a s.174 claim follows a regulatory fine. DMCCA penalties of up to 10% of global annual turnover create the kind of loss a shareholder or liquidator could plausibly argue a diligent board should have prevented.
Executive Action
- Ensure board minutes explicitly record AI oversight questions asked and answers received before each agentic AI deployment decision.
- Commission an independent review of s.172/s.174 exposure specific to autonomous AI systems, separate from general IT risk review.
- Use our AI governance self-assessment to benchmark current oversight against the CMA’s four principles.
Is the AI Responsible Officer Role Coming to UK Law?
The Artificial Intelligence (Regulation) Bill, introduced in the House of Lords, proposes a named “AI Responsible Officer” for any business that develops or deploys AI — a role modelled on the Data Protection Officer, backed by a proposed central AI Authority to coordinate regulators. The Bill remains a private member’s bill without confirmed government backing, so it is not yet law. Read that as a signal, not a deadline: the direction toward a named, accountable individual for AI decisions is consistent across the CMA guidance, the ICO’s forthcoming statutory AI code, and this Bill.
Waiting for the Bill before assigning ownership is the wrong sequencing. The CMA’s enforcement powers are already active; a designated AI Responsible Officer, even informally, gives a board clear accountability today and a head start if the role becomes statutory.
Executive Action
- Name an internal AI Responsible Officer now, even in advance of any statutory requirement, and give the role real authority to pause deployments.
- Map which existing role — CIO, CISO, or a dedicated AI governance lead — is best placed to hold this accountability.
- Review our technology strategy review template to formalise the mandate and reporting line.
How Should Boards Govern Agentic AI Right Now?
Regulatory and legal exposure on agentic AI is converging faster than most governance frameworks are being updated. Boards should not wait for the AI Responsible Officer Bill or the ICO’s final statutory code — the CMA’s fining powers are live now, and Companies Act duties have applied throughout. Our earlier briefing on what UK CIOs must prove to the board set out the evidence CIOs need to bring; this is the reciprocal question boards must ask before accepting it.
The practical test: if an AI agent caused consumer harm tomorrow, could the board produce a paper trail showing it asked the right oversight questions before approving the system? If not, that is this quarter’s priority, not next year’s.
Executive Action
- Add “agentic AI liability exposure” as a standing item on the risk committee agenda, not a one-off review.
- Require quarterly evidence packs from the AI Responsible Officer or equivalent, covering all four CMA principles.
- Explore our full briefing library for related governance frameworks and upcoming video briefings.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
The business deploying the AI agent is liable, not the vendor that built the underlying model. The CMA’s March 2026 guidance confirms deploying companies bear responsibility under consumer protection law, with fines of up to 10% of global annual turnover.
Yes, potentially. Companies Act 2006 duties under sections 172 and 174 require directors to act in the company’s interests with reasonable care and skill. Approving AI deployments without documented oversight weakens a director’s defence against such claims.
No. It is proposed in the Artificial Intelligence (Regulation) Bill, a House of Lords private member’s bill without confirmed government backing. It is not yet law, but boards are advised to assign the accountability informally now.
Transparency about AI interactions, compliance by design built into agent behaviour, continuous human oversight rather than unsupervised operation, and swift remediation when an agent malfunctions or causes consumer harm at scale.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/). Questions about board-level AI governance? Get in touch.
