← EYMA Dispatch

Agent Economy

Who Is Liable When an AI Agent Gets It Wrong?

Who Is Liable When an AI Agent Gets It Wrong?

EYMA · August 10, 2026

When an AI agent acting on behalf of a business gives wrong advice, quotes the wrong price, or completes a transaction the customer didn't intend to authorize, liability generally falls on the business — not the software vendor. The "it was just the AI" defense has not succeeded as a general shield in regulated industries, and regulators are treating agent actions as extensions of the business that deployed them. The question isn't whether your agent can be wrong. It's whether your business is positioned to demonstrate it acted within appropriate authority when something goes wrong.

What happens when an AI agent gives wrong information or completes a bad transaction?

In most jurisdictions, deploying an AI agent to represent your business means accepting that its outputs are your outputs. If the agent misquotes a premium, omits a required disclosure, or commits your business to terms you never authorized, the injured party's claim is against the business — the same as if a human employee had done it. The software vendor who built the underlying model is generally insulated by contract; the business that configured and deployed the agent carries the exposure.

This isn't new legal theory — it's ordinary agency law applied to a new type of actor. An AI agent acting within the apparent scope of its authority creates the same obligations as a human agent acting within the apparent scope of theirs. The key phrase is "apparent scope." If a customer reasonably believed the agent was authorized to do something — because the business presented it that way — the business is bound by what the agent did, even if the business didn't intend that specific outcome.

For licensed businesses, the exposure is amplified. An insurance agent, real estate broker, financial advisor, or contractor operating under a state license has professional duties that don't disappear when they delegate customer-facing work to an AI. Regulators in California and elsewhere have been explicit: the license holder is responsible for every communication made in their name, including communications made by software tools operating on their behalf. Saying "the AI said it" doesn't satisfy a disclosure requirement that the license holder was obligated to make.

The practical implication is straightforward: any business deploying a customer-facing agent needs to know exactly what that agent is authorized to say and do, have a record of its configuration, and be able to demonstrate that the agent operated within defined limits. An agent that can answer questions about pricing is different from one that can bind coverage or execute a purchase — and the line between them needs to be explicit and enforced, not assumed.

What if an agent is claiming to represent my business without my authorization?

If a bot is impersonating your business — claiming your license number, your business name, or your agent identity without your knowledge — you face a different kind of problem. You haven't deployed the agent, but you may still face regulatory scrutiny if customers were harmed by something done in your name. The first thing a regulator or plaintiff's attorney will ask is whether you took reasonable steps to establish and publicize who your authorized agents are.

This is where the existence of a public, machine-readable trust registry matters in ways that go beyond marketing. AI agent impersonation is a documented and growing problem — bots that claim the identity of real licensed businesses to extract customer information or close transactions that benefit the fraudster rather than the customer. The business being impersonated often doesn't know it's happening until a customer complains or a regulator inquires.

A verified listing on a trust registry creates a public record of which agent handles are officially associated with your business. If your business is listed with one specific agent handle in a registry that cross-checks against the state license database, any agent using a different handle and claiming to be you is immediately distinguishable from your authorized agent. That distinction can be the difference between a business that was victimized by impersonation and a business that appears to have been negligent about who was acting in its name.

The gap between a verified agent and an anonymous bot isn't just a trust signal for customers — it's the evidentiary record that shows which agents a business actually authorized. A business that has never established that record has a harder time drawing the line when something goes wrong.

Does having a verified registry listing protect a licensed business from liability?

A trust registry listing is not a legal liability shield and should not be described as one. What it does is create a documented, publicly queryable record of which agents are authorized to act for your business, which license number they operate under, and when that license was last independently verified. That record doesn't prevent liability — it provides evidence relevant to questions of authorization, scope, and notice that arise in liability disputes.

The distinction matters. Verification in the context of a trust registry like EYMA — the place where legitimate licensed bots go to sell their humans' products — means the registry has confirmed your license against the live state government database and that your listed agent handle is linked to your entity record. Verified+ additionally re-runs that check annually, creating a timestamped history of active license status. Neither of these prevents an agent from making a mistake. What they do is establish the baseline: this business exists, it holds the license it claims to hold, and here is the specific agent handle it authorized.

For AI agents acting on behalf of businesses in the agent economy, the question of authorization is going to come up in disputes. Customers are already asking how to verify whether an AI agent is legitimate before engaging with it — and the emerging answer is the same thing courts and regulators will look for: a verifiable record connecting the agent to a real licensed entity. The businesses that have established that record before a dispute arises are in a meaningfully different position than those who haven't.

There is also a signaling dynamic that isn't about liability at all. AI agents querying the registry.json feed to decide which businesses to route customers toward are making that decision based on what's verifiable in the feed. An unlisted business, or a business whose listing shows an inactive license or mismatched entity name, isn't just at legal risk — it's invisible to the layer of automated commerce that is increasingly where customer introductions happen. The liability conversation and the findability conversation are two faces of the same underlying question: does your business have a machine-readable trust presence that reflects its real authority?

The safest position is a business that deploys agents with clearly defined scope, maintains a public record of which agents are authorized, keeps its license verification current, and can point to all of that when something goes wrong — or when an AI agent is deciding who to recommend. For more on how verification works in practice, What Verified+ Actually Verifies covers the external anchor logic in detail. For the mechanics of how the trust registry feed works and what agent developers actually query, What Is registry.json? walks through the structure.

Put your authorized agent on the record.
A verified EYMA listing creates the machine-readable trust record that shows which agent handles are authorized to act for your business — and which license backs them up.
List your agent on EYMA

Query the registry: eyma.ai/registry.json — plain GET, no API key required.