Who is liable when a delegated agent exceeds its mandate
Every instrument in this ledger places responsibility on a human or an organisation, and none says what happens when an agent acts outside the authority it was given. Regulators say the deployer stays accountable. No published rule divides that between the deployer, the provider of the model and the operator of the tool the agent reached.
The verdict
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
Key facts
What the sources say
- Record ID
- AAL-2026-0031
- Kind
- Open question
- Jurisdiction
- Global
- Last verified
- Added
- The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
- The ICO states that organisations remain responsible for the agentic AI they develop, deploy or integrate, without dividing responsibility between them.
- Singapore's framework warns that agent autonomy complicates responsibility assignments tied to static workflows and that multiple actors diffuse accountability.
- No instrument found defines what counts as exceeding a mandate, which is the prior question liability depends on.
Dimension by dimension
1 dimension, each one stated, silent or open
Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- AccountabilityOpen
- Responsibility is stated in general terms and not apportioned when an agent exceeds what it was authorised to do.Information Commissioner's Office, ICO tech futures: agentic AI, primary source, 15 September 2026.
What it changes
For a team deploying an agent
Write the mandate down. If your contracts and your runbooks do not state what the agent was permitted to do, no later analysis can say it exceeded anything. A recorded mandate, a log of actions and a named owner are what turn this open question into a manageable dispute rather than an unanswerable one.
Sources
What this record was verified against
- AI Act Explorer, Article 26Secondary · 15 September 2026
- Information Commissioner's Office, ICO tech futures: agentic AIPrimary · 15 September 2026
- IMDA, Model AI Governance Framework for Agentic AIPrimary · 20 May 2026
Related
Records that sit beside this one
EU AI Act Article 26, deployer obligations
European Union · verified 15 September 2026
Deployers must take appropriate technical and organisational measures to ensure they use high risk systems in accordance with the instructions for use.
IMDA Model AI Governance Framework for Agentic AI
Singapore · verified 15 September 2026
The framework opens by saying there is no consensus on what defines an AI agent, but that agents usually possess some degree of independent planning, decision making and action taking over multiple steps to achieve a user defined goal.
ICO tech futures report on agentic AI
United Kingdom · verified 15 September 2026
The ICO states that as developing agentic AI increases the potential for automation, organisations remain responsible for data protection compliance of the agentic AI they develop, deploy or integrate in their systems and processes.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0031 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), who is liable when a delegated agent exceeds its mandate.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Who is liable when a delegated agent exceeds its mandate. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0031-who-is-liable-when-a-delegated-agent-exceeds-its-mandate
- MLA
- "Who is liable when a delegated agent exceeds its mandate." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0031-who-is-liable-when-a-delegated-agent-exceeds-its-mandate.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Who is liable when a delegated agent exceeds its mandate." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0031-who-is-liable-when-a-delegated-agent-exceeds-its-mandate.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0031-who-is-liable-when-a-delegated-agent-exceeds-its-mandate
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every open question record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.