# Signed, Deployed, Sued: Why Your Standard Contract Offers Zero Protection Against Agentic AI Liability

## The Setup: A Contract Written for a Different Era

A mid-sized financial services firm in Sydney signed a technology agreement in early 2024. Standard terms, negotiated over two weeks, covering a suite of software tools that automated portions of their client onboarding and compliance workflow.

Eighteen months later, an AI agent embedded in that software began autonomously routing client verification requests, sending follow-up communications, and making preliminary eligibility decisions none of which were anticipated by a single line in the original contract.

When a routing error led to incorrect eligibility notices being sent to a group of clients, the question the in-house legal team asked was straightforward: *Who is liable for what the AI did?* The answer their contract gave them was: *you are, almost entirely.*

This is not a hypothetical edge case. It is, according to Clifford Chance's February 2026 briefing on [agentic AI and the liability gap](https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2026/02/agentic-ai-and-the-liability-gap-your-contracts-may-not-cover.html), exactly the position most businesses are in deploying agentic AI systems under legacy technology contracts that were written for passive, predictable software firmly under human control.

## Why Agentic AI Changes Everything About Contract Risk

The distinction matters. Traditional software responds to instructions a human clicks, the software executes. Agentic AI is different in kind: it can initiate tasks, make decisions across connected systems, and take real-world actions without a human authorizing each step. Where a customer support AI agent might verify account status, reset passwords, and send follow-up communications automatically, an AI agent dealing with travel plans might compare prices, scan a calendar, and book flights as part of an end-to-end process.

Analysts forecast that throughout 2026, businesses will embed AI agents deeper into operations, granting them more authority over high-stakes activities including executing financial transactions, placing orders, managing supply chains, and screening job applicants. Yet many of these systems are still deployed under legacy technology contracts written for passive, predictable software firmly under human control.

The downstream risk is quantifiable. AI has the potential to generate harm at scale, and liability provisions that were suitable in the context of traditional IT system procurement are unlikely to be adequate for AI systems they should be tested against scenarios in which the AI makes an erroneous or discriminatory decision that causes economic loss, personal injury, or regulatory sanction.

And the regulatory environment is catching up fast. The new EU Product Liability Directive, to be implemented by EU member states by December 2026, explicitly includes software and AI as "products," allowing for strict liability if an AI system is found to be "defective."

For the Sydney firm's legal team, that background made the answer to their liability question more uncomfortable and pointed directly to the contract they hadn't updated.

## The Standard Contract's Four Structural Failures

Running the original technology agreement against the firm's actual AI usage exposed four gaps that the firm's outside counsel flagged as immediate remediation priorities.

**The "as-is" disclaimer was doing too much work.** Many SaaS agreements for AI products open with an extensive, all-caps disclaimer that the service is provided "as-is, with all faults," with AI providers arguing they cannot offer performance warranties given the probabilistic nature of AI. That disclaimer was written for a tool that generates outputs. Applied to an agent that sends legally consequential communications to clients, it effectively transferred all liability for those actions to the firm.

**The liability cap covered the wrong number.** Under many technology agreements governing agentic AI, these caps typically limit the supplier's total liability at the fees paid by the customer meaning that if an AI agent incorrectly authorizes a supplier payment, misprices a product, or issues misleading communications, the customer bears the risk.

**There was no authority limit on what the AI could do.** The contract authorized the software; it said nothing about what decisions the software's embedded agents were and weren't permitted to make autonomously. No dollar threshold, no escalation requirement, no kill-switch obligation.

**The dispute mechanism assumed a human decision-maker.** Every indemnification provision in the agreement was written around actions taken by the vendor's personnel not actions taken by an autonomous system operating between prompts.

## The Six Clauses That Fill the Gap

Counsel spent three weeks redrafting the technology agreement around six clauses designed specifically for agentic deployment. Each one addresses a specific failure mode the original contract ignored.

### 1\. A defined AI authority limit in writing

Manufacturers and businesses deploying agentic AI should establish clear thresholds with respect to dollar values, volume quantities, and routing changes that the agent must escalate to human review. This is not an aspiration it needs to be a contractual obligation, binding on both sides.

**What the clause should do:** Define categories of action the AI agent is permitted to take autonomously, categories that require human review before execution, and categories that are outside the system's authorized scope entirely. Attach these as a schedule so they can be updated without redrafting the whole agreement.

### 2\. A tiered liability cap with AI-specific carve-outs

The standard single-cap structure doesn't work for agentic AI because the potential harm categories are too varied. The modern compromise is the "supercap" — an intermediate ceiling, commonly two to five times the general cap or a negotiated fixed amount, applied to the highest-risk categories like data breach and privacy claims. For agentic AI, the highest-risk categories extend beyond data breach to include autonomous financial transactions, client-facing communications, and regulatory submissions.

Key carve-outs from any cap should include third-party IP infringement, data breaches, and regulatory violations caused by the AI with consequential damages (including lost profits from AI errors) specifically addressed rather than left to a generic exclusion.

**What the clause should do:** Create three tiers general cap (fees paid), supercap (two to five times general, for data and privacy incidents), and uncapped categories (gross negligence, willful misconduct, fraud, and intentional misuse of the system). Specify whether the cap is mutual or unilateral.

### 3\. A performance warranty tied to the agent's actions, not just the software

A BPO-style approach would include performance warranties applied both to the work of the people who create, monitor, and maintain the AI agents, and expressly also to the work performed by AI agents themselves. This shifts the conversation from "the software does what it does" to "the system should perform in accordance with agreed standards."

**What the clause should do:** Require the vendor to warrant that the AI agent will operate within its documented authority limits, escalate when required, and maintain audit logs of every autonomous decision. Tie the warranty breach remedy to something concrete, not just a right to terminate.

### 4\. A human oversight and override requirement

The GSA's proposed federal AI contract clause, issued in March 2026, would require contractors to permit a means for the government to implement human oversight, intervention, and traceability as minimum requirements. The same logic applies in commercial agreements. Public-sector and enterprise buyers increasingly request clauses committing vendors to transparency, fairness, and human oversight provisions that may reference applicable AI regulations, codes of conduct, or organizational frameworks for responsible AI use.

**What the clause should do:** Specify that the vendor must provide a real-time monitoring dashboard, a documented manual override capability, and a documented process for disabling specific agent functions without terminating the whole service. Allocate liability clearly for losses that occur when overrides are unavailable or delayed.

### 5\. An indemnification clause that names AI outputs explicitly

AI vendors often seek to limit their indemnification obligations differently from standard IT contracts typically disclaiming responsibility for outputs generated in response to user prompts, particularly where the customer modifies, customizes, or fine-tunes the model. The reverse risk is equally real: the customer needs indemnification for third-party claims arising from the vendor's AI taking unauthorized actions or producing outputs that cause harm.

A limitation of liability generally applies only to direct damages and not to indemnification obligations for third-party claims but only if the language is drafted to make clear that indemnification obligations are not constrained by the general liability cap. Many standard contracts blur this line, and the ambiguity usually resolves against whoever has less negotiating leverage.

**What the clause should do:** Separately list what the vendor indemnifies (third-party IP claims, data breaches, regulatory sanctions caused by system failures) and what the customer indemnifies (misuse outside authorized parameters, prohibited inputs). Make explicit that indemnification obligations operate outside the general liability cap.

### 6\. An AI-specific data and output ownership provision

Questions about AI use are now appearing as part of the underwriting and renewal process for certain liability and cyber insurance policies and downstream non-compliant service providers or contractors may taint any upstream use of data, creating liability. Ownership of the agent's outputs and of the logs recording how those outputs were generated can determine whether the customer can defend a regulatory investigation or a client complaint.

**What the clause should do:** Confirm that all inputs, outputs, and audit logs belong to the customer. Prohibit the vendor from using customer data or outputs to train models or improve products. Require certified deletion of all data within a defined period after termination.

## The AI Contract Clause Checklist at a Glance

| Clause | What It Does | Key Drafting Point |
| --- | --- | --- |
| Authority limits | Defines what the AI can do autonomously vs. what requires human sign-off | Attach as an updatable schedule |
| Tiered liability cap | Creates separate exposure levels for different risk categories | Specify supercap amounts and uncapped categories |
| Performance warranty | Holds the vendor to standards for agent actions, not just software uptime | Tie to audit log and escalation obligations |
| Human oversight | Requires override capability and monitoring access | Allocates liability when override fails |
| AI-specific indemnification | Covers third-party claims from agent outputs | Keeps indemnity outside the general cap |
| Data and output ownership | Assigns all inputs, outputs, and logs to the customer | Requires certified deletion on termination |

## What the Major Legal AI Platforms Are Building — and Where the Gap Remains

[Harvey](https://www.harvey.ai/solutions/transactional) is increasingly used by transactional teams to review AI-related representations and warranties in vendor agreements, flag deviations from precedent, and generate structured issue lists from redlines. [Legora](https://legora.com/solutions/ma) brings its Tabular Review feature to large-scale contract review, comparing terms across multiple agreements and flagging discrepancies against a standard form. Both are genuinely useful for identifying whether an AI clause is present, whether key defined terms are consistent, and whether a standard playbook provision is missing from a draft.

What they're not set up to do is the harder advisory work: deciding *how* an authority-limit schedule should be structured for a specific AI deployment, or whether a proposed supercap amount is commercially reasonable given the nature of the agent involved. That analysis depends on understanding both the governing law and the specific operational context which is why contract review tools and legal judgment aren't interchangeable. They're complementary.

## Where Multi-Jurisdiction Tools Like Ovviously Fit

For the solo and small-firm practitioners who handle a significant share of commercial contract work particularly across India, the UK, US, Canada, and Australia the challenge isn't access to a checklist. It's access to jurisdiction-specific drafting support that reflects how courts in each jurisdiction treat liability caps, indemnification carve-outs, and autonomous system warranties. [Ovviously](https://ovviously.com) is built around exactly that gap: legal research and drafting assistance anchored to the authorities and conventions of the relevant jurisdiction, rather than generic templates that assume US Delaware law governs everything. When reviewing or drafting AI clauses for an agentic deployment, the six-point framework above applies regardless of jurisdiction — but the specific wording of each clause matters enormously depending on governing law.

## The Verdict: What the Firm's Redrafted Agreement Looked Like

The Sydney firm's revised technology agreement added 14 pages to a contract that had originally run 22. Most of that length was schedules the authority-limit schedule, the data ownership annex, and the audit log specification. The substantive clause changes were smaller: the liability section gained two pages; the indemnification section gained three.

Six months after the redrafted agreement went into effect, the same AI system made another routing error — a lower-stakes one, affecting fewer clients. The outcome was different: the error was logged, the override was invoked by the firm's operations team within hours, the vendor's indemnification obligation covered the client remediation cost, and the regulatory notification was completed using the audit log the vendor was now contractually required to maintain.

No litigation. No bar complaint. One internal post-mortem and a small schedule update.

## FAQ: AI Clauses and Agentic Liability

**What is an AI clause in a commercial contract?** A contractual provision that specifically addresses the use of artificial intelligence in the delivery of services or software — covering ownership of outputs, liability for AI errors, data use restrictions, and performance obligations tied to AI behavior.

**Why don't standard technology contracts cover agentic AI?** Standard technology agreements were written for software that executes human instructions. Agentic AI initiates actions autonomously, which creates liability exposure that "as-is" disclaimers and single-cap structures weren't designed to address.

**What is a supercap in a liability clause?** An intermediate liability ceiling — typically two to five times the general cap — applied to specific high-risk categories like data breaches or privacy incidents, giving customers meaningful protection on the risks they care most about while keeping the vendor's total exposure insurable.

**Who owns the outputs of an AI agent?** This is a negotiated question — and the answer varies by agreement. The best practice is to specify in the contract that all inputs, outputs, and audit logs belong to the customer, and that the vendor may not use them for model training or product improvement.

**What is a human-in-the-loop requirement in an AI contract?** A contractual obligation requiring the vendor to maintain override and monitoring capabilities, so that a human can intervene in, pause, or disable specific AI agent actions without terminating the whole service.

**Does the EU AI Act affect commercial AI contracts?** The EU Product Liability Directive, due for implementation by December 2026, explicitly covers software and AI as "products," meaning a defective AI system could give rise to strict liability claims in EU member states. Commercial contracts should be reviewed against this framework, particularly for any AI deployment affecting EU customers or data.

## The Bottom Line

Agentic AI is being deployed today under contracts written for software that waits for instructions. The liability gap that creates is real, and it's already surfacing in disputes. Closing it doesn't require starting from scratch — it requires six targeted additions to a standard technology agreement, each one matched to a specific failure mode that "as-is" disclaimers and fee-based caps were never designed to cover. The firms getting this right are the ones who reviewed their contracts before the agent acted, not after.

*This article is for general informational purposes only and does not constitute legal advice. AI contract provisions should be tailored to the specific deployment and reviewed against the applicable governing law and regulatory framework.*
