Who is liable when an agent commits its principal to something false or binding?
Two decisions point the same way and neither settles it. A Canadian tribunal held an airline to its chatbot's answer in 2024, and a German appellate court held a company to its chatbot's false credentials in 2026 while allowing a further appeal. Both are misrepresentation cases. No published decision found here holds that an agent's output formed a binding contract.
The verdict
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
Key facts
What the sources say
- Record ID
- AIL-2026-0034
- Kind
- Open question
- Jurisdiction
- Global
- Last verified
- Added
- The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
- The German appellate decision was decided under unfair competition law and the court allowed a further appeal because the attribution question is new.
- Both decided cases concern statements that misled, not agreements the agent formed on its principal's behalf.
- This ledger found no published decision holding that an agent's output concluded a contract binding its principal.
- The European Union's proposed dedicated AI liability instrument was withdrawn, leaving product liability and ordinary civil law to carry the question.
Dimension by dimension
2 dimensions, each one stated, silent or open
Accountability, Delegation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- AccountabilityReported
- Two tribunals have placed responsibility on the deploying company, which is the strongest published answer available and is not yet settled law.Justiz NRW, Oberlandesgericht Hamm press release on case 4 UKl 3/25, primary source, 12 May 2026.
- DelegationOpen
- No decision found here defines the scope of authority a principal grants an agent, which is the question contract law would need answered.McCarthy Tetrault, Moffatt v. Air Canada and misrepresentation by chatbot, secondary source, 19 February 2024.
What it changes
For a team deploying an agent
Assume you are bound by what your agent says, because that is how both decided cases came out. Then reduce what it can say: ground policy answers in published text, forbid the agent from offering terms, prices, refunds or eligibility it cannot quote, and keep every transcript. The cheapest control here is limits, and the record you keep is what decides the dispute.
Sources
What this record was verified against
- Justiz NRW, Oberlandesgericht Hamm press release on case 4 UKl 3/25Primary · 12 May 2026
- McCarthy Tetrault, Moffatt v. Air Canada and misrepresentation by chatbotSecondary · 19 February 2024
Related
Records that sit beside this one
A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity
Canada · verified 15 September 2026
The passenger asked the airline's website chatbot about bereavement fares and was told he could apply for the discount after flying, which the published policy did not allow.
A German appellate court held a company to specialist titles its chatbot invented, and allowed a further appeal
European Union · verified 15 September 2026
The court's press release records that the chatbot told users the company's two doctors held several specialist titles, including titles that do not exist.
Is an operator anywhere required to report that an agent acted beyond its authority?
European Union · verified 15 September 2026
Article 73 requires providers of high risk AI systems placed on the Union market to report any serious incident to the market surveillance authorities of the member states where it occurred.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0034 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), who is liable when an agent commits its principal to something false or binding?.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Who is liable when an agent commits its principal to something false or binding?. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0034-who-is-liable-when-an-agent-commits-its-principal
- MLA
- "Who is liable when an agent commits its principal to something false or binding?." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0034-who-is-liable-when-an-agent-commits-its-principal.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Who is liable when an agent commits its principal to something false or binding?." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0034-who-is-liable-when-an-agent-commits-its-principal.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0034-who-is-liable-when-an-agent-commits-its-principal
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every open question record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.