When an AI bot causes harm, who pays? Australian legal experts point to the humans who deployed it

Australia's first reported automated hacking incident has raised a question lawyers are now scrambling to answer: if an AI agent goes wrong, is its owner on the hook?

AI2Day Newsdesk3 min read
A large server room bathed in cold blue emergency lighting, rows of inactive server racks with dark indicator panels, a single red warning light reflected acros
Share

Key points

  • AI agents, software that can carry out multi-step tasks on its own, cannot be held legally responsible for any harm they cause under current law.
  • Australia has recorded what experts describe as its first reported automated hacking incident involving an AI agent.
  • Professor Jeannie Paterson says deploying an AI agent that causes foreseeable harm makes the deployer legally responsible, even without intent.
  • Legal experts warn developers, not just operators, could also face liability depending on how harm unfolds.

An AI agent caused harm in Australia, and nobody knows exactly who should pay for it. That is the uncomfortable question now sitting in front of legal scholars, regulators, and businesses that have started handing autonomous software tools to customers and staff.

What actually happened?

Australia recorded what experts are calling its first reported automated hacking incident involving an AI agent. The Guardian AI reported the case, though the specific target and operator have not been publicly named. The details matter less than the legal gap the incident exposed: a piece of software acted, caused damage, and had no legal identity of its own.

AI agents are different from ordinary chatbots. A chatbot answers questions. An agent takes actions, browsing the web, sending messages, writing and running code, sometimes on your behalf, sometimes without asking permission at each step. That autonomy is exactly what makes assigning blame complicated.

So who is legally responsible?

Right now, the human or company that deployed the agent. Full stop.

"If I deploy an AI agent and it causes harm to someone else, I am responsible for that harm," says Professor Jeannie Paterson, a legal expert on AI accountability. "Even if I didn't intend for that to happen, it was foreseeable, and I should be taking responsibility."

The logic tracks with how existing law handles other tools. If a company's faulty equipment injures someone, the company answers for it. The equipment does not. AI agents sit in the same legal category for now.

What is less settled is whether liability can climb further up the chain, to the developers who built the agent in the first place. Experts say that depends on whether the harm traces back to a design flaw rather than how the agent was used.

What does this mean for ordinary people?

If a business deploys an AI agent that acts on your data, your accounts, or your devices, and something goes wrong, that business is your first port of call, not the AI company whose technology sits underneath it.

For businesses thinking about deploying agents: the flexibility and speed these tools offer comes with direct legal exposure. An agent that sends emails, books appointments, or interacts with third-party systems on your behalf is, legally speaking, your action.

The harder question is whether courts will eventually look past the operator and toward the lab that built the underlying model. That argument has not been tested yet in Australia, or most other places.

Common questions

Can the AI company itself be sued?

Not straightforwardly, at least not yet. Current legal thinking places responsibility on the person or business that chose to deploy the agent, though legal experts say developer liability remains an open question as more incidents occur.

Should I be worried about AI agents businesses use on my behalf?

It is worth asking any company what automated tools act on your data, and what their complaints process is if something goes wrong. You have the same consumer rights as with any other service.

© 2026 AI2Day