Regulating Agentic Artificial Intelligence

Scholars debate how existing legal frameworks should adapt to the rise of autonomous AI agents.

Artificial intelligence (AI) systems are no longer confined to generating text or images on command. A new generation of AI systems known as “agentic AI” or AI agents, can perform relatively complex, multi-step tasks like browsing the internet, making purchases, and booking travel with minimal human oversight. OpenAI has launched an agent that performs browser tasks for users, and Google has developed prototypes that can navigate browsers and other digital environments. As these systems move from experimental tools to everyday assistants, their potential to cause harm raises urgent questions about legal accountability.

Last month, U.S. Senator Mark Warner (D-Va.) introduced the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act of 2026 (AI AGENT Act), which would establish a federal framework for consumer-facing AI agents, programs that use an AI model to autonomously plan, take actions, and use tools to complete a task, rather than just responding to a single prompt. The bill would require covered AI agents to operate under transparent, documented, scope-limited, and revocable user authorization and to maintain records of their actions. The AI AGENT Act would also direct the National Institute of Standards and Technology to identify technical standards for authentication and other interactions between AI agents and online platforms.

Existing legal frameworks do not account for autonomous AI agents. Tort law traditionally requires a clear causal link between human intent and harmful outcomes, but AI agents can produce results that no individual programmed or anticipated, complicating efforts to assign fault. Consumer protection statutes assume that a human buyer receives disclosures and exercises informed judgment before a transaction—assumptions that break down when an AI agent makes purchasing decisions on a user’s behalf without meaningful human review. Meanwhile, most laws concerning the delegation of authority or responsibilities presume that legally recognized actors delegate authority to legally recognized agents through relationships governed by strictly defined legal duties.

AI agents strain each of these legal doctrines. They make decisions that are neither explicitly programmed nor entirely foreseeable. The agents also operate at a speed and scale that outpace conventional regulatory oversight. Developers, and malignant actors, can influence AI agents in ways that do not fit existing legal categories. For example, a developer can configure a shopping agent to favor revenue-sharing retail partners through system prompts and tool integrations that a user never sees—a form of influence that does not map onto the clean delegation of authority that agency law presumes between a principal and their agent. AI agents remain vulnerable to adversarial manipulation, including cyberattacks that could redirect their behavior in ways that harm the users they serve.

Against this backdrop, scholars debate how the law should adapt. The stakes are high: if legal doctrine fails to keep pace with AI development, consumers may lack meaningful recourse when these systems cause harm.

In this week’s Saturday Seminar, scholars discuss how the law should govern AI agents and the regulatory challenges they pose.

  • In a recent article in the North Carolina Journal of Law & Technology, Maarten Herbosch of KU Leuven argues that AI agents do not necessitate a fundamental overhaul of tort law but rather targeted refinements. Herbosch challenges what he calls “technological exceptionalism”—the assumption that AI is uniquely disruptive—by showing how it can be addressed in existing law. Herbosch contends that AI’s distinctive liability problems are limited to complex systems and systems that generate benefits for third parties. He proposes treating flawed or substandard AI training data as a manufacturing defect, aligning AI liability with established products liability doctrine. He also contends that causation challenges in AI cases resemble problems that medical malpractice law already addresses.
  • In a recent article in the Berkeley Technology Law Journal, Deven Desai and Mark Riedl, both of the Georgia Institute of Technology, argue that legal concerns about AI agents are best addressed through computer science rather than new rules modeled on human agents. They contend that the technical infrastructure connecting AI agents and developers already constrains the former in ways arguably stronger than the traditional legal discipline of human agents. They argue that agency law’s conception of loyalty should inform developers’ approach to value alignment. They also propose that developers build AI that can explain its own behavior, so that users can identify and correct agent mistakes after the fact and, before the agent acts, receive an account of its plan to catch problems preemptively.
  • In a recent article in the German Law Journal, Christoph Busch of the University of Osnabrück argues that European Union consumer law must adapt to AI agents. Busch explains that AI agents can make purchases based on user’s preferences, challenging laws designed around human decision-making. Busch warns that current disclosure mandates assume that people evaluate product information—an assumption that fails when AI agents make purchasing decisions. Busch also cautions that hidden or malicious instructions embedded in web content, as well as other adversarial attacks, could trick AI agents into making purchases that conflict with users’ instructions. Busch urges policymakers to begin designing consumer law that works for humans and machines.
  • In a recent article in the Fordham Law Review, Cullen O’Keefe, at the Institute for Law and AI, and several coauthors argue that developers should design AI agents that are meant for use in high-stakes settings to automatically comply with legal requirements. They call these systems “Law-Following AIs,” which should refuse illegal actions even when doing so would advance their principals’ goals. O’Keefe and his coauthors propose imposing legal duties directly on AI agents without necessarily granting them legal personhood. Because AI systems can already reason about natural-language laws, they contend that future agents may be able to identify applicable law, track legal changes, and seek help in difficult cases without developers having to translate each rule into code.
  • In a forthcoming article in the UC Irvine Law Review, Christina Lee of the University of San Diego School of Law argues that agency law must evolve to govern AI agents. She coins the term “shadow principals” for developers who design and market these agents. She argues that shadow principals fall outside existing agency law categories, meaning courts have no clear basis for imposing certain duties on developers that would otherwise protect users and third parties. Agency law, she contends, does not account for the persistent yet obscured influence that shadow principals exercise over AI agents. She proposes reconfiguring existing fiduciary duties, such as an agent’s duty of loyalty to a principal, to account for shadow principals.
  • In a recent article in the University of Toronto Law Journal, Samuel Becher of the City University of Hong Kong and Benjamin Alarie of the University of Toronto Faculty of Law argue that AI agents could transform legal systems in three ways. First, AI agents could democratize access to legal knowledge. Second, they could reconstitute legal authority through “algorithmic constitutionalism,” where AI systems themselves embed and enforce constitutional norms rather than courts alone interpreting them. Third, they could shift the legal profession from reactive adjudication toward preventive intervention, using AI agents to flag legal risks before harm occurs. Becher and Alarie conclude that design choices along these dimensions will determine whether AI agents serve the public interest.