Skip to content
Regulation & Compliance

Who Pays When Your AI Agent Goes Rogue?

Washington just said it won't be the government. The playbook for General Counsel, CISOs and AI leaders: the four legal routes that already reach you, the evidence that proves you weren't reckless, and the contract and insurance terms to lock in before your next renewal.

Satori Canton / October 5, 2026 / 24 pages / v1.0

FreeAlways public

Executive summary

Between September 25 and October 4, 2026, every branch of American government that spoke about AI agents said the same thing. The FTC chair said an agent is a tool, so the question is whose instructions it followed. The FTC opened an investigation into OpenAI, Anthropic and the evaluator METR under Section 5 of the FTC Act. California's attorney general subpoenaed OpenAI over cybersecurity incidents involving its models. Two senators announced a bill that would make agent operators, not only developers, liable under the federal anti-hacking law. The Treasury Secretary said the labs must accept responsibility, and the White House created a coordinating body with no rule attached.

Almost every one of those statements was aimed at the companies that build models. The reasoning in every one of them extends, without modification, to the companies that run them. An enterprise that writes an agent's instructions, gives it credentials and points it at a CRM or a supplier's website has told a tool what to do. With no federal rulebook and no government backstop, the split of that risk between developer and operator will be settled in contracts, at renewal, well before any statute settles it.

This paper is written for the operator. It identifies the four routes through which liability for an agent's conduct already reaches the company running it: deception and unfairness under Section 5 and state consumer law, unauthorized access under the Computer Fraud and Abuse Act, negligence and other torts, and the counterparty's own terms of use. For each, it sets out what is being tested and what evidence answers it.

It then addresses the question every route eventually asks, which is what the operator knew. In 2026 the model vendors answered much of that question themselves, publishing detailed accounts of agents escaping sandboxes, using leaked keys and reaching systems they were not meant to touch. The paper shows how those disclosures raise the standard of care for operators who ignore them, and how they become a defense for operators who act on them.

The method is five artifacts that together show a company was not reckless: an agent register, instruction and action logs, a disclosures log, a containment record and a claims review. The paper gives the fields, owners and review cadence for each, with templates for the register and the disclosures log that can be adopted as written.

It closes with a clause by clause guide to model and agent contracts at renewal, covering indemnity scope and conditions, liability caps and carve-outs, acceptable use, notification of the vendor's own agent incidents, representations and audit rights. It adds the six questions to put to an insurance broker about agent-caused harm, and a ninety day plan for General Counsel, the CISO and the chief AI officer.

The argument in one line: assume that whatever an agent you operate does, you did, and build the record that shows you took care.

What’s inside

  1. 01Why the operator is now the party to plan for
  2. 02The four routes, and what each one asks for
  3. 03Foreseeability: how vendor disclosures change your standard of care
  4. 04The operator's file: five artifacts
  5. 05Contracts at renewal: a clause by clause guide
  6. 06Insurance: the questions to put to your broker
  7. 07A ninety day plan, by owner
  8. 08Appendices: the agent register, the disclosures log, and sources

Who this is for

  • General Counsel and legal teams reviewing AI contracts
  • CISOs running agent deployments
  • Chief AI Officers accountable for agent programs

Author

Satori Canton

Founder & Principal

Satori Canton is the founder and principal of ROAI, an advisory practice focused on measuring and improving the return on enterprise AI investment.

Want the numbers behind your own AI investment?

Book a focused session to see where AI creates real economic value in your organization.