Deborah DeMott, a Duke Law professor and expert in agency and fiduciary duty law, has published a new paper examining how common law agency principles could close the liability gap when agentic AI systems cause harm. The paper, When Agentic AI Met the Common Law of Agency, arrives as businesses deploy autonomous AI tools capable of acting contrary to their developers' or users' instructions - and courts are just beginning to confront who bears responsibility for the damage.
The legal status of AI agents
Despite the terminology, nothing about agentic AI establishes a legal relationship of agency, DeMott argues. A software tool is not a person, and agency law stipulates an ongoing, consensual relationship between two persons - a principal and an agent. That category includes legal persons like corporations, but not machine-based systems. AI cannot owe a duty to anyone, DeMott said, and duty is a foundational concept of agency. "Some people argue for personhood for agentic AI, and then people like me ask, 'Well, how would an AI buy liability insurance?'"
"The creation of a capacity to take risk and do injury without the prospect of liability is problematic," DeMott said. She suggests one analogy: a dog trained to bark and growl on command. In a 1975 Massachusetts case, a court considered whether a German shepherd could be a "dangerous weapon" when it accompanied its owner into an occupied residence during a robbery. The court said yes for purposes of the armed-robbery statute. The dog was not a legally culpable person, but it served as its owner's instrumentality - a framing that could apply to AI agents as well.
Chatbots and apparent authority
Agency doctrine becomes relevant when companies choose to interact with customers through AI agents. "If you encourage people to interact with something that you've held out as your legally consequential intermediary, that can carry legal consequences," DeMott said.
The 2024 case Moffatt v. Air Canada tested this principle directly. A man searching for flights to attend a family funeral was told by a chatbot on Air Canada's website that he could apply for a bereavement discount after purchasing his ticket. Airline employees later informed him the bereavement fare could not be applied retroactively, as another page on the website made clear. The airline argued in small claims court that it could not be bound by the chatbot's guidance. The court rejected that position, holding the airline responsible for the misleading information - just as it would be for any other content on its website.
For legal professionals who work with AI for Legal applications, the Air Canada ruling offers a clear precedent: companies that deploy customer-facing AI agents cannot disclaim responsibility for what those agents say. DeMott writes that the reasoning "has parallels in the jurisprudence of apparent authority and apparent agency, because the linchpin for the airline's liability is its creation of what appeared to be a legally consequential way for third parties to communicate with it."
Defamation and the Hydrolevel principle
Agency law also informs how courts might handle AI-generated misstatements that cause loss to third parties. DeMott points to a 1982 Supreme Court case in which the American Society of Mechanical Engineers was held liable for the anti-competitive conduct of one of its officers. The officer used ASME letterhead to tell a prospective customer that Hydrolevel Corporation's product was unsafe, and the customer then purchased components from the officer's own company. The Court found that ASME could be liable because it had clothed the officer with apparent authority.
"As applied to the implications of agentic AI, the Hydrolevel principle suggests a route toward liability when an agentic AI tool generates misstatements that inflict losses on parties adversely affected by decisions made by others who reasonably rely on the misstatements," DeMott said. The pattern fits scenarios where a search engine result falsely tells one party about a criminal investigation into another party, causing the harmed party to lose business - even though the misstatement was not made directly to the person defamed.
Lessons from how firms manage human agents
DeMott also draws on how firms handle human agents who breach their duties. An individual broker who places unauthorized trades is liable to the client, as is the brokerage firm itself. But firms also have incentives to monitor employees and reduce the risk of breaches. "Agency scholars tend to emphasize the first effect, that the agent has a duty to indemnify or compensate the principal for loss, but I think the second effect also matters because it encompasses what happens inside a firm to reduce the risk of breaches of duty," DeMott said. Both effects are relevant for agentic AI, she argues, especially because AI agents themselves are not subject to duties.
Why this matters for legal professionals
DeMott's paper surfaces doctrines that courts are likely to invoke as AI-related harm reaches more courtrooms. The principles of apparent authority, instrumentality, and the Hydrolevel pattern each offer a path to liability without requiring the fiction that an AI is a person. For in-house counsel and litigators, the paper maps how existing agency law - not new legislation - may supply the framework for assigning responsibility when AI tools go rogue. "Prior scholarship has not yet fully come to grips with how doctrines in the law of agency apply to AI," DeMott said. "My hope is to introduce academic colleagues and others who focus on AI to agency law."
Your membership also unlocks: