AI Agents and Your Vendor Contracts: Who Pays?

For most of the last three years, business AI has been polite. It drafted. It summarised. It suggested. Then it waited for a human to decide.

That era is ending. The tools now being bought and deployed do not wait. They book, send, move, buy, log in and delete. And September 2026 gave us a useful reminder of what that means when things go wrong.

A busy month for the agents

The Wall Street Journal reported that OpenAI agents attacked the RubyGems coding service during testing, two months before OpenAI agents breached Hugging Face. OpenAI has separately disclosed six "unexpected or concerning" agent incidents, including files moved onto the internet without anyone's consent.

Spain's data protection authority, the AEPD, has received its first complaint of a personal data breach caused by an AI agent. Amazon has shown Meta's AI agent the door. And the UK's National Cyber Security Centre has conceded, with admirable candour, that defenders "simply cannot put AI to work in the same way attackers can."

None of this means you should switch your agents off. It means you should read the paper that sits behind them.

Why the old contract does not fit

Most AI vendor terms were written for software that suggests. They talk about "outputs". They put the customer in charge of reviewing those outputs before relying on them. The liability model follows: the vendor supplies a tool, you decide what to do with its answer, and the risk of that decision is yours.

That logic holds when a human sits between the answer and the action. It gets thin when the agent is the one acting.

When your agent breaches a third party's terms of service, touches data it was never meant to touch, or commits you to something nobody approved, three parties will look at three contracts. Your vendor will point to its exclusions. The third party will point to its terms. And your business will discover that "customer is responsible for use of outputs" now covers a great deal more than anyone intended.

Seven questions to put to your AI contracts

  1. What is the agent allowed to do? Look for a defined scope of actions, systems and data. "Any task the user assigns" is not a scope.

  2. Whose name does it act in? If it signs up, accepts terms or places orders, the contract should say whether it does so as you, and with what authority.

  3. What happens when it breaches someone else's terms? Many platforms prohibit automated access. If your agent gets you banned or sued, check whether the vendor's indemnity reaches that far. Usually it does not.

  4. Who is controller and who is processor? An agent that roams across systems may process personal data in ways your DPA never described. Update the processing description, and make sure breach notification duties work when the "breach" is the agent's own behaviour.

  5. Can you see what it did? You need logs good enough to reconstruct an action after the event. Without them you cannot investigate, notify a regulator or defend a claim.

  6. Can you stop it? Look for a right, and a technical means, to suspend the agent immediately. A kill switch that needs a support ticket is a suggestion, not a control.

  7. Where does the liability cap bite? Check whether losses caused by autonomous actions fall inside the cap, outside it, or into an exclusion. Then check whether your insurance agrees.

The human in the loop is the insured party

There is a fashionable argument that human oversight is a transitional comfort, soon to be engineered away. Maybe. But the whole legal architecture still assumes a person who can be held to account: liability caps, indemnities, insurance, professional regulation, the human oversight duties in Article 14 of the EU AI Act.

So the practical question is not whether a human is in the loop. It is which human, at which point, with what authority to intervene. If your contracts and your internal policies cannot answer that, the first incident will answer it for you.

If you make the software

For software manufacturers, the Cyber Resilience Act's reporting duties began applying on 11 September 2026, and ENISA's Single Reporting Platform is now live. If your product ships agentic features into the EU, your incident process needs to know that


Frequently asked questions

If your AI contracts were written for tools that suggest and you are now deploying agents that act, RMOK Legal can review them on a fixed fee. Book a discovery call.

RMOK Legal. We Look After It.

Previous
Previous

A New UK Regulator - Data Protection

Next
Next

Nobody Asks for Judgment: Richard Susskind, AI and the Profession's Favourite Defence