For two years the standard corporate posture on AI agent risk was a shrug. If the model does something wrong, surely the model provider is on the hook, or the vendor, or somebody. Through 2026 that shrug stopped working. Courts on two continents have now drawn the line, and the line runs straight through the company that deployed the agent.
the chatbot that invented a policy
The foundational case is small in dollars and enormous in principle. In Moffatt v. Air Canada, an airline chatbot told a grieving customer he could claim a bereavement discount retroactively. No such policy existed. When the customer sued, Air Canada argued the chatbot was, in effect, a separate entity responsible for its own statements. The tribunal called that submission “remarkable” and rejected it outright. The company owned what its bot said. The payout was small. The precedent was not.
the support bot that made up a rule
A year later, an AI support agent at a fast-growing developer tool told users the company had adopted a one-device-per-subscription policy. It had not. The claim spread across Hacker News and Reddit before a founder corrected it publicly. No lawsuit, but a live demonstration that an agent can manufacture a policy your company then has to publicly disown. Reputational loss is loss.
the overview that became the author
The sharpest ruling landed in 2026. The Munich I Regional Court held that Google is directly liable for false statements in its AI Overviews, because the overview is Google's own content and not a protected list of search results. It is widely read as the first decision holding an AI firm liable for AI-generated speech. The reasoning matters far beyond Google: when your system generates a new, substantive statement rather than pointing at a source, you are the publisher of it.
the hiring tool that became everyone's problem
Then there is aggregation. In the Mobley v. Workday litigation, claims proceeded against the vendor as an “agent” of its customers because employers had delegated actual screening decisions to the AI. Thousands of employers ran the same tool. One model's behavior became thousands of companies' legal exposure at once. Insurers have a name for this shape. It nearly broke cyber insurance after ransomware, and AI agent liability has it built in from day one.
And the volume is already here. Ravelin's 2026 Agentic Commerce and Fraud Report found that 44 percent of merchants are already integrating agentic protocols, while liability for a fraudulent purchase or an unauthorized refund made by an agent remains, in the report's framing, completely unclear.
“hallucinated commitments bind you. generated statements make you the publisher. delegated decisions make you the principal.”
Put the map together and the destination is unambiguous. The degree of authority you delegate to an agent is now a liability dial. Aggregated deployments turn one model's bad day into a class action.
The uncomfortable part is that your existing insurance most likely does not respond to any of it, because the standard market started excluding exactly these events in 2026. That is the subject of the next article. For now, the single takeaway: when your agent gets it wrong, the law increasingly says you pay. The only open question is whether you transferred that risk before the claim, or after.
draft content for company-building. case studies and figures are illustrative and are not an offer of insurance or legal advice. cited events and frameworks are drawn from public 2026 sources.