Take a hypothetical, and not an improbable one. A law firm hands its deadline management to an AI agent. The agent misreads a court registry communication, records the wrong date, and the time limit for an appeal runs out. The client suffers a loss. Who is liable?
The first answer anyone offers, the system got it wrong, is legally empty. A system is not a legal person. It holds no assets, carries no insurance and owes no duties. Blaming the software is the modern equivalent of blaming the pen.
Four links, all of them made of people
Liability has to be traced back through the chain of actors that designed, supplied, configured and used the tool, and the exercise is individual: for each of them one has to establish a role, a duty breached, the degree of control that could be exercised, fault or defect, damage and a causal link. Nobody in the chain answers simply by being in it.
The general purpose model provider. It develops the model the agent is built on. The AI Act imposes documentation and transparency obligations on it (article 53), but does not regulate its civil liability towards end users, which today remains a matter of contract and general law. Once directive 2024/2853 is transposed, product liability may also become relevant, where the model or the software and the entity supplying it fall within the relevant definitions and all the conditions are met.
The application provider. It integrates the model with tools and instructions and makes the agent available to the firm. It qualifies as a provider under article 3, point 3, of the AI Act only if it develops the system, or has it developed, and places it on the market or puts it into service under its own name or trade mark. A pure integrator may occupy a different position in the value chain. Worth remembering, too, that under article 25 the firm itself can take on provider obligations for a high risk system, for instance where it modifies the intended purpose of a system not classified as high risk in such a way that it becomes one.
The firm that deploys the agent. It is the deployer. It chooses the tool, configures it, decides which actions it may perform and under what supervision. Towards the client it answers in contract, under the standard of diligence in article 1176, second paragraph, and the rules of article 1218 of the Italian Civil Code.
The professional who activates it. Inside the firm, the lawyer who sets the objective and accepts the output. On the disciplinary side, the duties of diligence (article 12) and competence (article 14) of the Italian code of professional conduct for lawyers apply, and they do not permit delegation to a tool.
The client is not a link in this chain. Having been informed of the use of AI, as article 13 of law 132/2025 requires, is not the same as accepting the risk of error, which remains a risk in the performance of the service. The client could only answer for conduct of their own: unlawful instructions, knowingly false information.
The European framework, and a widespread misunderstanding
It is worth clearing up a confusion that circulates at every conference on this subject. The proposed directive on non contractual liability for artificial intelligence, presented by the Commission in 2022, was formally withdrawn on 6 October 2025 and never entered into force. There is, today, no specific European regime for civil liability for damage caused by AI.
The most relevant European piece is directive (EU) 2024/2853 on liability for defective products, which expressly includes software among products. Member States must transpose it by 9 December 2026, and it will apply to products placed on the market or put into service after that date. It does not automatically attribute liability to the application provider: it requires an economic operator who can be held responsible, a defective product, recoverable damage and a causal link. Article 10 in general keeps the burden of proving defect, damage and causation on the claimant, while providing, under certain conditions, rebuttable presumptions, including where technical or scientific complexity makes proof excessively difficult.
Everything else is national: contractual and professional liability, and the code of conduct.
Meanwhile, autonomous agents are being sold to professional firms while the civil liability framework around them is, in plain terms, a building site. The sales pitch presents a settled matter. The law, at the moment, presents an open one, and the gap between the two is being carried by whoever signs the retainer.
Liability that can be shared
Responsibility does not necessarily attach to a single decision. It may be distributed or shared among several parties, and the analysis has to be repeated for each of them.
Take the opening hypothetical. If the error stems from a reproducible defect in the model or the application, the provider’s liability may be engaged, and the firm may in turn act against it where the contractual or legal conditions are met. Towards the client, however, the firm answers for non performance unless it proves that the cause is not attributable to it.
If the error stems from a configuration that required no human confirmation on procedural deadlines, the absence of that confirmation may reveal an organisational failure on the part of the firm, where it had causal effect on the damage.
If the error stems from the professional accepting the calendar without checking it, despite the system having flagged an uncertainty, the relevant conduct is theirs.
An unforeseeable defect, an external attack or an unavoidable event may, in certain conditions, exclude attribution. The point is not that the firm is always liable. The point is that the firm must be able to demonstrate how it governed the tool.
Documentation, or the absence of it
This is where records stop being bureaucracy. A firm that retains the agent’s settings, the policies adopted, the approvals given by professionals and a proportionate log of operations can reconstruct where the decision actually sat and can prove its own diligence.
A firm that retains nothing is not, for that reason alone, liable in full. It is, however, in a seriously weak evidential position, because under a contractual regime it is the debtor who must prove that the non performance is not attributable to them. Which means the firm that bought an agent to save time will spend that time, and rather more, explaining itself.
One organisational rule
The chain of attribution can be governed with a simple principle, and it is a matter of good governance rather than a statutory condition of liability: every significant action taken by the agent should be traceable to an identifiable organisational rule or human approval. The decision may be remote, in the initial configuration, or immediate, in the confirmation of an operation. It should exist and it should be documented.
Where that condition is met, the agent is a tool operating inside limits the firm has chosen. Where it is not, the agent is a risk the firm has taken on without knowing it, and the moment it finds out is the moment it has to prove, in a contractual dispute, that the failure was not attributable to it.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html
