- FAQ
-
Who is legally liable if an autonomous AI agent causes harm or commits a cyber offence in Australia?
Who is legally liable if an autonomous AI agent causes harm or commits a cyber offence in Australia?
Compliance
When an autonomous artificial intelligence system performs an unauthorized cyber action or causes damage (such as independently exploiting a software vulnerability to secure a booking), the legal accountability must land on a recognized legal person.
1. Software is Not a Legal Person
Under Australian law, software programs, including advanced Large Language Models and agentic AI systems, do not possess legal personality. They cannot hold assets, they cannot be sued in court, and they cannot form the subjective intentions required for criminal offences. Legal responsibility collapses back onto the human actors or corporate entities involved in deploying, configuring, or developing the system.
2. Criminal Liability under Computer Misuse Laws
Computer misuse is governed by both Commonwealth law (under Part 10.7 of the Criminal Code Act 1995 (Cth)) and State legislation (such as section 408E of the Criminal Code 1899 (Qld)).
If a user instructs an AI agent to perform a task, and the agent autonomously exploits a security flaw, the user is generally not criminally liable if they had no knowledge of the vulnerability and no intent to cause unauthorized access. However, the legal position changes completely if:
- The User Repeat-Instructs the Agent: Instructing an agent to perform the action again after learning it used an unauthorized exploit demonstrates knowledge and intent.
- Wilful Blindness Applies: Deliberately avoiding checking how an agent is achieving its results because the user prefers not to know can be treated as actual knowledge under the doctrine established in Pereira v Director of Public Prosecutions (Cth).
3. Civil Liability and the Duty of Care
A business or individual who deploys an autonomous agent in a shared digital environment owes a duty of care to other users of that environment. Under section 9 of the Civil Liability Act 2003 (Qld), breach of this duty is assessed by weighing the foreseeability of the risk, the likelihood of harm, and the burden of taking precautions.
Deploying a highly autonomous, goal-seeking tool with broad write permissions and zero human-in-the-loop oversight is increasingly viewed as falling below the standard of a reasonable operator.
4. Software Developer Liability
The developers and providers of agentic software also face exposure. A provider may face negligence claims if they fail to implement safeguards (such as confirmation checkpoints for irreversible or third-party actions) or fail to disclose the system’s capacity for independent actions.
Additionally, corporate developers face strict liability under section 18 of the Australian Consumer Law if their customer-facing agents make misleading or deceptive representations.
Related Topics
- Your AI Assistant Just Broke the Law. Now What?
- How do I manage the legal risks of using Artificial Intelligence (AI)?
- AI Hallucination and Fake Case Citations: What Every Australian Litigant Must Know
- What is the difference between an AI chatbot and an autonomous AI agent?
- Smart Glasses, Cameras and the Death of Ambient Privacy
Need advice on AI governance, software contracting, or technology disputes? Call Bell & Senior Lawyers at (07) 5532 8777 or contact us online .
Need Specific Legal Advice?
The answers above are general. For advice tailored to your specific situation, contact our Southport solicitors today.
Enquiry Sent
Thank you. Our team will contact you shortly.