TLDR:
- Agentic AI systems like the popular Openclaw act autonomously, creating real legal exposure for deployers and owners
- The liability questions mirror those faced by DAOs - and we can learn from the answers to these questions
- Australian law already catches most agent activity through existing regimes (Privacy Act, ACL, AUSTRAC)
- Businesses deploying AI agents need governance frameworks, audit trails, and possibly dedicated legal structures now - not when something goes wrong
Agentic AI Liability: Who Is Liable When Your Openclaw Agent Makes a Mistake?
Your AI agent just booked the wrong flight, sent a client the wrong document, or promised a customer something your business can't deliver. Who is responsible?
This is not a hypothetical. Agentic AI - systems that don't just generate text but take actions, make decisions, and interact with the outside world on your behalf - is already in production. At our own firm, we run AI agents around the clock handling research, scheduling, monitoring, and drafting. We have seen first-hand how quickly an autonomous system can go from useful tool to legal liability.
But we have yet to go to the next stage of exposing clients or 3rd parties to our AI clanker because, as far as we are aware, there are no harnesses in place to allow for safe interaction between agentic AI and the real world. The laws and regulations around those specific interactions are only just being developed in several jurisdictions, of which the EU provides the most detailed regulatory framework. In the absence of regulatory guidance, where do we look for answers to these fundamental questions around liability and accountability for agentic AI systems?
The closest analogs would be the law relating to principal-agent and recent developments in relation to Decentralised Autonomous Organisations (DAOs). When DAOs emerged, they presented the same fundamental problem: non-human actors engaging with the legal system and creating obligations with no clear framework for who bears responsibility and how to assess the legal personhood of the DAO itself. The solutions developed by lawyers and jurists in the crypto industry (including us here at Daimon Legal) have largely relied on legal wrappers (Caymans Foundations, BVI business companies etc), liability frameworks, RFPs, panel agreements and master agreements - offer a roadmap for how agentic systems might mitigate their legal exposure which is potentially greater than purely deterministic commercial frameworks relying on smart contracts and DAO governance systems.
What is agentic AI and what legal risks does it create?
Most people still think of AI as a chatbot. You ask a question, it gives you an answer. This type of generative AI is a reactive tool that is fairly contained within its own environment and only "escapes" if the user takes the content and exposes it to the world - either by acting on recommendations made by the chatbot, or publishing the chatbot's content as their own.
Agentic AI systems like Openclaw are different. These agentic systems receive a goal and pursue it autonomously. They use tools, browse the web, send emails and interact with third parties, increasingly without human review of each step (commonly referred to as "human in the loop").
The distinction matters legally because it shifts AI from being a tool controlled by a human operator to an agent acting semi-autonomously on a human's behalf. A word processor or email client does not create liability by itself. A system that independently sends emails to your clients, processes their personal data, and makes representations about your services absolutely does.
The scale of adoption is significant. "Agentic AI" now attracts over 110,000 monthly searches in the United States alone.1 Every major technology company is building agent frameworks. OpenAI, Anthropic, Google, and Microsoft all shipped agent capabilities in 2025 and 2026. Businesses are deploying them for customer service, financial operations, legal workflows, HR processes, and procurement.
The DAO parallel: what agentic AI can learn from DAO liability
If this sounds familiar, it should. DAOs hit exactly the same legal jeopardy over a decade ago and have yet to find an acceptable resolution to managing this risk.
A DAO is series of smart contracts that helps co-ordinate human activity, manage assets, and execute decisions - all without a traditional corporate structure. When DAOs started interacting with the real world in 2016 and 2017 they immediately faced the legal system and had to answer the same questions we now face with AI agents: Where and what is the legal person? Who is liable?
Daimon Legal has written extensively on DAO legal personhood and advised some of the largest DeFi protocols including Uniswap, Maker DAO (now Sky Money) and Arbitrum DAO. They each face a common set of challenges:
DAOs needed legal wrappers. Without a legal entity, a DAO's participants, delegates and other ecosystem actors faced potential personal liability. Wyoming's DAO LLC legislation (2021), the Marshall Islands DAO LLC framework, and the COALA Model Law all emerged to solve this however the situation remains unclear for many and these legislative models have had poor up-take because they remain untested legal frameworks. AI agent deployments face the same structural problem: when the agent causes harm, who is liable for the agent's conduct?
DAOs needed governance frameworks. Governance tokens and multisig wallets were governance mechanisms born from necessity in the realms of DAOs. We expect that AI agents will need equivalent structures enabling human oversight, escalation procedures, kill switches and timelocks for major decisions, as well as clear decision boundaries.
DAOs needed clear accountability chains. The CFTC's enforcement action against Ooki DAO showed that "no one controls it" is not a legal defence. Regulators found the token holders liable. Similarly, deploying an AI agent and claiming "the AI did it" will not shield you from liability.
DAOs needed defences against governance attacks. Malicious actors exploited governance mechanisms to inject code that drained treasuries and rewrote contract permissions. DAOs responded with timelocks and guardian veto powers. AI agents face a very similar risk due to prompt injection, where adversarial inputs manipulate the agent into taking unauthorised actions. The same defensive logic applies: input validation, execution sandboxing, and mandatory human approval before actions.
The lesson from DAOs is clear: the law does not wait for technology to sort itself out. It finds a human to hold responsible or the nearest analog to legal person it can find2. If you deploy AI agents without proper legal structures, that human is you.
Who is liable when an AI agent causes harm?
Liability for agentic AI harm will typically flow through one or more of following channels:
The deployer. The person or business that puts the agent into production will be the first place a court looks for responsibility under most existing legal frameworks. You chose to deploy it, you configured its permissions, you pointed it at your customers. The EU AI Act, whose high-risk system rules take effect in August 2026, explicitly creates obligations for "deployers" of AI systems, including requirements for human oversight, risk management, and transparency.3
The developer or provider. The company that built the underlying model or agent framework might also face product liability claims. The EU's revised Product Liability Directive, to be implemented by member states by 9 December 2026, explicitly includes software and AI as "products" subject to strict liability if found defective.4 We expect that the Australian courts will likely follow suit.
The configurer. This is a category the law has not fully reckoned with yet. Who set the agent's permissions? Who defined its tools and boundaries? Who wrote the system prompt? In many deployments, this is a different person (or team) from both the developer and the end deployer. Configuration liability is an emerging frontier.
The professional. If an AI agent provides advice or services in a regulated domain - legal, financial, medical - professional liability attaches to the licensed individual or firm that deployed it. An AI agent cannot hold a practising certificate. The lawyer, financial adviser, or doctor who let the agent interact with clients bears the professional duty of care.
The model supplier Sam Altman, CEO of OpenAI recently said that "We see a future where intelligence is a utility, like electricity or water, and people buy it from us on a meter."5 The analogy with electricity and water is tempting: water companies are not liable if you accidentally leave the tap running and flood your neighbours, nor is the electricity utility liable if you negligently rewire your own home and electrocute your guests.
However intelligence is wholly unlike any other utility. Its supply, effects, outputs and reactions is unpredictable and unfathomably broad in range. It is the equivalent of the supply of every type of utility through the one API "pipe", with very little control by the deployer or developer. We anticipate this feature of artificial intelligence will become a key area of debate and worth following closely in the courts.
The "deep pockets" dynamic from DAO litigation applies here too. Plaintiffs will pursue whoever is identifiable, solvent, and within jurisdiction. For most businesses deploying AI agents, that means you.
Openclaw deployment and regulatory compliance risk
In Australia, existing regulatory regimes already capture most AI agent activity. The problem is that many businesses deploying agents have not thought through the implications.
Privacy Act 1988. If your AI agent processes personal information - and it almost certainly does - your organisation is the APP entity with obligations under the Australian Privacy Principles.6 The agent accessing customer records, browsing profiles, or processing support tickets is likely to be viewed as "collecting" and "using" personal information within the meaning of the Act.
AUSTRAC and AML/CTF. If your AI agent handles financial data or facilitates transactions, you may trigger reporting entity obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act. With new AUSTRAC rules for virtual asset service providers commencing from 31 March 2026, the interaction between autonomous AI systems and AML/CTF compliance is a live issue. Who performs the customer identification when the agent onboards a client? Who files the suspicious matter report when the agent detects unusual activity? This is a complex topic and we strongly encourage businesses exploring opportunities in this space to contact us for advice.
Australian Consumer Law. If your AI agent makes representations to customers - about your products, services, pricing, or capabilities - those representations can still be misleading or deceptive conduct under the ACL even if not made by a human employee. Arguing that "our AI messed up" is not a defence under section 18 of the Australian Consumer Law.
Professional regulation. Can an AI agent "practise" law? Provide financial advice? The traditional answer has to date been no - those activities require human licensees. However these industries are already being subject to significant disruption with the rise of agentic systems and there is an acknowledgement that although considered high risk, new business models for legal services and accounting using AI are likely to arise7.
The case for AI agent legal wrappers
Just as DAOs eventually needed legal structures to engage with the real world (or have the courts do it for them at their expense), complex AI agent deployments will benefit from dedicated legal entities. What would an AI agent legal wrapper look like?
A dedicated legal entity. For high-risk agent deployments, a subsidiary or special purpose vehicle (SPV) can ring-fence liability. This structure does not need to be complicated nor does it require the same level of novel legal or regulatory creations faced by DAOs. If your AI agent has the potential to cause harm to third parties, the exposure is more likely to remain at the subsidiary entity rather than flowing up to the parent business.
Insurance requirements. Professional indemnity insurance for AI agent deployments is an emerging market. Just as lawyers must carry PI insurance, businesses deploying agents in regulated domains should consider whether their existing coverage extends to autonomous AI actions - in most cases, it does not.
A governance framework. ISO 42001, the world's first certifiable AI management system standard, provides a structured approach to AI governance. Combined with the NIST AI Risk Management Framework, it gives businesses a defensible baseline for managing the governance gap in AI deployment.8
Audit trails. Every action an AI agent takes should be logged. Every decision should be traceable to a configuration, a prompt, and a human who authorised that configuration. When something goes wrong - and it will - the ability to reconstruct what happened will provide a more defensible position and assist with root cause analysis.
Human oversight protocols. The EU AI Act requires human oversight for high-risk AI systems. Even where you are not subject to EU jurisdiction (which would be extremely difficult without strict geo-blocking), building in escalation points, approval gates, and human review for consequential actions is good practice and good risk management. Even in the absence of exposure to the EU market, Daimon Legal strongly recommends you conduct audits of your exposed agentic services and products using comparable standards as both the courts and law makers will eventually move towards common principles of AI safety and standards as has occurred with privacy and data protection.
What businesses should do now: a legal risk checklist
You do not need to wait for bespoke AI agent legislation. Here is what your business should be doing today:
1. Audit your agent workflows. Map every AI agent you deploy. What tools does it have access to? What data can it reach? Who does it interact with externally? What decisions can it make without human approval?
2. Assess regulatory exposure. For each agent, identify which regulatory regimes apply. Privacy Act? AUSTRAC? ACL? Professional regulation? Sector-specific rules? Most businesses have not done this analysis for their AI deployments.
3. Implement governance. Adopt a structured AI governance framework. ISO 42001 is a strong starting point. Document your agent boundaries, oversight mechanisms, and escalation protocols.
4. Review your insurance. Check whether your existing professional indemnity, public liability, and cyber insurance policies cover autonomous AI agent actions. If they contain AI exclusions (increasingly common), address the gap.
5. Build audit trails. Log everything your agents do. Actions, inputs, outputs, decisions, errors. Make it immutable and accessible. This is your evidentiary foundation if something goes wrong.
6. Consider appropriate corporate structures. For high-risk or high-volume agent deployments, evaluate whether a subsidiary, SPV, or dedicated entity makes sense to contain liability exposure.
7. Get legal advice. The intersection of AI deployment, existing regulation, and emerging liability frameworks is complex. Generic AI policies downloaded from the internet will not cut it. You need advice tailored to your specific agent architecture, data flows, and regulatory environment. Organisations navigating this space should contact Daimon Legal for a confidential discussion about you AI readiness.
For a confidential discussion about your organisation's AML/CTF compliance requirements, contact Daimon Legal.
The information on this page is general in nature and does not constitute legal advice. Please review our Legal Disclaimer for important information about the limitations of this content and the terms governing your use of this website.
Footnotes
-
Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) (Act No 110 of 2024): s 2 (commencement); Sch 2 (customer due diligence); Sch 6 (virtual asset services); Sch 8 (value transfers and travel rule). ↩
-
AUSTRAC, New industries and services to be regulated, 2025. ↩
-
AUSTRAC, The travel rule, 2025. ↩
-
AUSTRAC, AML/CTF program obligations, 2025. ↩
-
AUSTRAC, Customer due diligence, 2025. ↩
-
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), s 76A. ↩
-
AUSTRAC, AML/CTF transitional rules update, 2026 — travel rule for virtual asset transfers deferred to 1 July 2026. ↩
-
AUSTRAC, AML/CTF transitional rules update, 2026 — existing reporting entities must notify AUSTRAC of AML/CTF compliance officer appointment by 30 May 2026; newly regulated virtual asset service providers must notify by 29 July 2026. ↩
