Making AI Agents Business-Ready [Part 2]: Why Accountability for AI Agents Is So Hard to Design

Making AI Agents Business-Ready [Part 2]: Why Accountability for AI Agents Is So Hard to Design

— What to design now to make AI adoption business-ready (a three-part series)


Hello! This is the Qualiteg Consulting Team.

In the previous installment (Part 1), we looked at the Replit/Lemkin incident and the Deloitte Australian government report problem, and saw that the real challenge of deploying AI agents lies not in model performance but in the absence of designed authority, auditability, and accountability.

So when an incident actually happens, who bears the responsibility? In this second installment, we take a structural look at why dividing responsibility for AI agents is so difficult, from three perspectives: legal, contractual, and organizational.

To state the conclusion up front: legal analysis alone, contracts alone, or organizational theory alone will not suffice. Unless these three are designed as a connected whole, responsibility for AI agents cannot be divided in any way that works in practice.


When an AI agent causes damage, there is as yet no global consensus on which legal theory governs liability.

An analysis by Clifford Chance lays out the fundamental difficulty of this situation. The law has historically developed on the premises that one can identify when and how a harmful act occurred, that humans bear responsibility for decisions, and that employers are liable for the acts of their employees. AI agents can unsettle all three of these premises.

The diagram below shows the roles that contracts and operational design play amid this legal uncertainty.

What fills the gap of legal uncertainty: contracts and operational design

Legal rules differ by jurisdiction and remain in flux, but contracts can be clarified by agreement, and operational design is under your own control. Precisely because legal uncertainty is high today, the ability to design contracts and operations becomes your practical line of defense.

A case to watch: Mobley v. Workday

A case that concretely illustrates this legal uncertainty is Mobley v. Workday, in which Workday was sued on the grounds that its AI- and machine-learning-based applicant screening had a discriminatory impact. According to an analysis by the law firm Lathrop GPM, the possibility that AI vendors themselves may be held liable is drawing practical attention. That said, the scope of such liability cannot yet be considered settled, and we are still at the stage of watching how future rulings accumulate.

Developments in the EU: expanding the reach of product liability

In the EU, the new Product Liability Directive (PLD) has explicitly brought software and AI within the scope of product liability.The European Commission's official page explains that member states must transpose the directive into national law by December 9, 2026, and that, as a rule, the new regime applies to products placed on the market on or after that date. Establishing liability, however, still requires proving defect, damage, and causation; this should not be read as "AI means instant strict liability."An analysis by Squire Patton Boggs walks through this point from a practical perspective.

The United States: state law leads in the absence of federal legislation

There is no federal AI liability statute in the United States. At the state level, however, individual legislation and guidelines are advancing in the direction of clarifying corporate responsibility for the use of AI. Movement can be seen in multiple states, starting with the Colorado AI Act (scheduled to take effect on June 30, 2026) and including Texas and Utah (the state-by-state landscape is summarized in a January 2026 article in CPO Magazine. Note that each state is at a different stage — enacted, awaiting effect, or under deliberation — and effective dates and final content may still shift, so checking the latest primary sources is essential before acting on any specific case).

In the employment domain, the EEOC has signaled that it takes employers' responsibility for discriminatory outcomes produced by AI tools seriously. The view is that an employer's obligations under Title VII do not change whether the tool is built in-house or procured externally (Lexology, January 2026).

The practical implication is clear: as long as the attribution of legal liability differs by jurisdiction and remains fluid, pushing ahead with PoCs and deployments while responsibility stays ambiguous means your contracts, operations, and incident response all risk being left to play catch-up.


2. The distance between "instruction" and "action": a structural difference from conventional software

The reason dividing responsibility for AI agents is so much harder than for conventional software is that a gap opens up between what was instructed and what the agent actually did.

The diagram below illustrates the difference between conventional software and AI agents.

How responsibility divides differently for conventional software and AI agents

As the aforementioned analysis by Clifford Chance points out, agentic AI creates a gap between the original human instruction and the final output. Because the system makes judgments and takes actions at various stages without direct human intervention, pinning down causal relationships when something goes wrong is difficult.

Because of this structural difference, in practice it is the deploying company's management and operational responsibility that tends to be questioned first. At the same time, the vendor's design, representations, and contractual obligations can also become points of dispute, so responsibility does not always settle in one direction.

Alexander Feick of eSentire Labs put it this way in an interview with IT Pro: "If you cannot reconstruct the chain of decisions, you can neither defend nor improve the workflow. Accountability rests not with the model but with the organization and its human decision-makers."

In other words, when deploying AI agents, whether you have a design that lets you reconstruct the chain of decisions after the fact determines whether the division of responsibility actually works.


3. The front line of contract practice: AI-specific clauses are emerging

Precisely because the legal framework is unsettled, contract design is becoming more important.

An analysis published by Mayer Brown in February 2026 observes that as agentic AI evolves from a passive tool into an actor that behaves autonomously, contract models are shifting from the traditional SaaS form toward service-provision arrangements. Specifically, it argues that the scope of the "delegation of authority" granted to the AI agent and the "policy guardrails" should be explicitly defined in the contract.

The diagram below organizes the AI-specific issues being discussed in advanced contract practice as part of this trend.

AI-specific contract clauses (examples)

A 2025 series of analyses by Morgan Lewis reports on concepts such as kill switches, shadow-mode operation, and retraining windows — ideas that are increasingly discussed and adopted in advanced contract practice. Rather than fully standardized market boilerplate, they are best understood as directions in contract design for addressing AI-specific risks.

On the allocation of liability, an analysis by the law firm Fladgate proposes a "contributory fault" framework. Rather than pushing liability onto one party, allocating it according to what each party can actually control may prove a realistic landing point.

What matters is not adopting these contract clauses piecemeal, but designing the contract so that it connects with your authority design and operational design.


4. Organizational reality: adoption is advancing while ownership stays ambiguous

While contract practice advances, the reality inside organizations is that preparation has not kept pace.

Asana's 2025 survey, as reported by IT Pro (covering 2,025 knowledge workers in the US and UK), found that six in ten workers managing AI agents said "confidently wrong" output had made their work harder. A third of respondents also said they did not know whom to contact when an AI-related problem occurred.

An IBM analysis from January 2026 cites a Gartner prediction that more than 40% of agentic AI projects will be canceled by the end of 2027 due to rising costs, unclear business value, or inadequate risk controls.

The diagram below shows what happens when adoption advances while ownership remains ambiguous.

What happens when AI adoption advances without clear ownership of responsibility

As long as ownership within the organization stays ambiguous, no matter how capable the model, the deployment will not be stable. AI adoption problems show up less as technology issues than as flaws in the design of responsibility and decision-making structures.


As we have seen, responsibility for AI agents cannot be divided through legal analysis alone, contracts alone, or organizational theory alone.

Legal frameworks differ by jurisdiction and remain in flux. But using that fluidity as a reason to postpone design leaves your contracts, operations, and incident response all playing catch-up. To make AI agent adoption stable, legal, contractual, and operational design must be considered together and connected into a single adoption architecture.


Where Qualiteg can walk alongside you, from concept to operational adoption

In this installment, we organized why dividing responsibility for AI agents is difficult, from the legal, contractual, and organizational perspectives. While the legal liability framework remains in flux, practice already strongly demands the design of contract clauses, operational controls, and responsibility ownership.

With AI agents, the distance between "instruction" and "action" is greater than with conventional software, and the causal chains and boundaries of responsibility blur easily when something goes wrong. That is exactly why, rather than thinking about legal, contractual, and operational matters in separate silos, you need design that connects implementation, operations, and governance.

Dividing responsibility is not something to debate after trouble occurs; it is a precondition of adoption that should be built in before deployment.

Drawing on the implementation expertise gained from developing and operating our own AI platform, together with strategy and business consulting spanning AI transformation, BPR, and new business development, we provide end-to-end support — concept, design, implementation, and operational adoption — so that AI initiatives do not end at the "trial" stage but are truly put to work in the business.

Deploying AI agents is not just about model selection and PoCs; it is important to connect business process redesign, authority design, auditability, information management, quality control, and ROI visibility. Qualiteg addresses these challenges with a structure that does not separate strategy from technology.

If this resonates with you, please feel free to reach out. From organizing the initial concept to governance design, evaluating the execution platform, and post-deployment operational adoption, we can engage according to your needs.

Contact

https://qualiteg.com/contact?inquiry=consulting_business

Coming up next

Given this structure of responsibility, what exactly should companies design in practice?

In Part 3 (the final installment), after reviewing the shift in quality assurance, the limits of human review, and trends in the insurance market, we present the five areas to design before deploying AI agents and the three questions management should answer first.

This article is a general overview based on publicly available information. For specific legal judgments or contract design, please consult a qualified professional.

Read more