CPDForge AI
AI Governance21 June 2026

Governing the Agent: Liability, Standards, and the Race to Regulate Autonomous AI

CPDForge Knowledge Hub | AI Governance Series | June 2026

Every AI governance framework built over the past three years — the EU AI Act, NIST's Risk Management Framework, the patchwork of US state laws — was substantially designed around a particular mental model: an AI system that predicts, classifies, or generates content, with a human deciding what to do with the output. Agentic AI breaks that model. An AI agent plans, takes multi-step actions, calls external tools, transacts, and adapts to new information with limited or no human review at each step. Through 2026, regulators, standards bodies, and law firms have converged on a shared diagnosis: existing frameworks were not built for this, and a distinct governance and liability architecture is now emerging to fill the gap.

Why agentic AI breaks existing liability models

Traditional product liability law assumes a relatively clean causal chain: a manufacturer builds a product, a defect can be traced to design or manufacture, and harm flows from that defect to a consumer. Agentic AI disrupts this chain in a specific way — the "product" makes autonomous decisions that its creators did not specifically authorize or anticipate, which makes the traditional question "was this defectively designed?" much harder to answer than "did the system do something its designers never intended, and who bears that risk?"

This produces what several practitioners are now calling an "accountability gap." Agentic systems are non-deterministic: unlike a traditional software bug, which can usually be traced to a specific fault, an agent's harmful action may emerge from a context the system was never explicitly trained or instructed to handle. The legal and insurance markets have not fully caught up. Standard professional liability and technology errors-and-omissions policies were written for predictable, human-supervised software; specialised "agentic errors and omissions" coverage has only begun to emerge as a distinct insurance product in 2026, and legal practitioners are flagging that many existing commercial technology contracts allocate risk in ways that simply don't anticipate a counterparty's AI agent independently executing transactions, placing orders, or screening applicants.

The emerging legal answer: reasonable oversight, not zero autonomy

Across multiple jurisdictions, a converging standard is taking shape: rather than requiring continuous human monitoring of every agent action — which would defeat much of the efficiency case for deploying agents in the first place — regulators and courts are gravitating toward a "reasonable oversight" test. Under this approach, the deploying organisation bears liability for an agent's harmful actions unless it can demonstrate it had robust monitoring, auditing, and safety systems in place, proportionate to the risk and autonomy level of the system in question. This shifts the practical governance question from "did a human approve this specific action?" to "did the organisation build and maintain a defensible oversight architecture?" — auditability and documented control design become the liability shield, rather than constant human intervention.

This is reinforced by harder legal developments already in motion. The EU's revised Product Liability Directive, which member states must transpose by 9 December 2026, explicitly brings software and AI systems within the legal definition of a "product," opening the door to strict liability — liability without the need to prove fault — where an AI system is found "defective." Separately, the UK Information Commissioner's Office has published guidance on agentic AI's data protection implications, emphasising that organisations remain fully responsible for the data protection compliance of agentic systems they build, deploy, or simply integrate into existing workflows, regardless of how autonomously those systems subsequently operate.

Singapore sets the technical governance template

The most concrete agentic-specific governance framework to date comes not from Brussels or Washington but from Singapore. In January 2026, the Infocomm Media Development Authority released the world's first Model AI Governance Framework built specifically for agentic AI, unveiled at the World Economic Forum in Davos and building on a WEF framework from late 2025.

The Singapore framework introduces several concepts likely to become reference points well beyond its own jurisdiction. It proposes a standardised "Agent Identity Card" — a disclosure format specifying an agent's capabilities, limitations, authorised action domains, and escalation protocols, conceptually similar to a nutrition label for autonomous systems. It establishes a five-tier graduated autonomy taxonomy, running from "tool-assisted" systems through to "fully autonomous" agents, with governance obligations scaling at each tier. And it sets out an operator–deployer responsibility model that explicitly allocates liability between the entity that builds an agent platform and the entity that deploys it into a specific operational context — a distinction that existing product liability and AI regulation frameworks have generally left unresolved.

The framework deliberately avoids mapping itself onto any specific jurisdiction's legal requirements, which limits its direct use as a compliance checklist against, for example, the EU AI Act. It also leaves open some of the hardest emerging questions, particularly around dynamic agent identity and liability allocation in multi-agent systems where several autonomous agents — potentially built by different vendors — interact, delegate tasks to one another, and jointly produce an outcome.

Standards bodies are moving in parallel

Technical standards infrastructure is developing alongside the legal frameworks, often faster. NIST launched its AI Agent Standards Initiative in February 2026, organised around three pillars: interoperability, security, and testing and evaluation, with a Request for Information on AI agent security and a concept paper on agent identity and authorization both issued in the first quarter of 2026. The OWASP Foundation has published a dedicated Top 10 list for agentic application security risks, developed with input from more than one hundred practitioners — extending the same model that has guided web-application security practice for two decades into the agentic domain. ISO's 42001 AI management system standard, already a reference point for general AI governance, is also being extended by practitioners to address autonomous operation specifically.

The throughline across NIST, OWASP, ISO, and Singapore's framework is a shared insistence that organisations remain accountable for an agent's behaviour regardless of whether they have adopted any particular voluntary standard — these frameworks function as evidence of reasonable governance, not as a substitute for legal accountability.

Sector-specific exposure is already concrete, not theoretical

This is not a purely prospective concern. In the United States, California's Civil Rights Council finalised regulations on automated decision systems effective October 2025, requiring employers to demonstrate their AI tools do not discriminate and extending related record-retention obligations to four years. Colorado's AI Act imposes annual impact assessment and risk management obligations on deployers of high-risk systems. New York City's Local Law 144 already requires annual bias audits of AI hiring tools. None of these were drafted with agentic systems specifically in mind, but all of them apply with full force the moment an agentic system is making or materially influencing employment, credit, healthcare, or housing decisions — which means organisations deploying agents into these domains are already operating under binding legal obligations, Singapore-style voluntary frameworks notwithstanding.

Legal academic work on agentic governance — notably Noam Kolt's influential framework — has proposed three organising principles increasingly visible across the regulatory responses described above: inclusivity, ensuring affected parties have a voice in agent design; visibility, ensuring agent decisions are observable and auditable after the fact; and liability, ensuring clear allocation of responsibility when agents cause harm. These translate fairly directly into the technical and contractual controls organisations are now being advised to implement: human-in-the-loop checkpoints at genuinely high-stakes decision points, comprehensive action logging sufficient to reconstruct an agent's decision path after an incident, and contractual risk allocation clauses specifically updated for agentic capability rather than inherited from legacy software licensing terms.

The governance takeaway

No jurisdiction has yet produced a comprehensive, binding, agentic-AI-specific statute comparable to the EU AI Act's treatment of high-risk systems generally. What exists instead is a fast-converging set of signals — Singapore's voluntary framework, NIST's standards initiative, the EU's extension of product liability to software, sector-specific state and national rules that apply regardless of an agent's autonomy level, and an emerging "reasonable oversight" liability standard in case law and regulatory guidance. For organisations deploying agentic systems now, the defensible position is to treat these converging signals as a preview of binding obligations rather than wait for a single comprehensive law: build the audit trail, document the oversight architecture, and update the contracts before a regulator or a court forces the question.

Sources consulted: Squire Patton Boggs, Clifford Chance, Davis Wright Tremaine, Venable LLP, Baker Botts, Precise Impact AI, and the Infocomm Media Development Authority of Singapore (Model AI Governance Framework for Agentic AI, v1.0, January 2026), current as of June 2026. This article is provided for general informational purposes as part of CPDForge's continuing professional development content and does not constitute legal advice.

Explore your platform options

Take the 3-minute assessment to find the right fit for your needs.

Get email alerts for new articles

We'll email you when a new Knowledge Hub article goes live — roughly 3 a month. Confirm once and unsubscribe any time.

Free newsletter — no card required, and completely separate from any CPDForge plan or subscription.

Related articles

AI Governance

AI Literacy Training: The EU AI Act Obligation Everyone Has Had Since 2025 (and No One Trained For)

Read
AI Governance

The EU AI Act in 2026: What the Digital Omnibus Actually Changes — and What It Doesn't

Read
AI Governance

America's AI Governance Crossroads: Federal Preemption Meets the State Patchwork

Read

We value your privacy

We use cookies to analyse site usage and improve your experience. You can accept all cookies, use essential cookies only, or reject non-essential cookies entirely.