When an AI Bot Causes Harm, Who Pays? Australian Experts Point to the Human Who Deployed It

Australia's first reported case of an automated AI agent causing accidental damage has put a sharp legal question on the table: if a bot you turned loose hurts someone, the law says that is your problem.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial image of a dim security operations centre at night, multiple monitors showing red alert dashboards and cascading log lines, one s
Share

Key points

  • Australian legal experts say the person or company that deploys an AI agent, meaning a piece of software that acts on its own to complete tasks, is legally responsible for any harm it causes.
  • Australia recorded what is being described as its first reported automated hacking accident involving an AI agent acting without direct human instruction.
  • Professor Jeannie Paterson states that liability applies even when the harm was unintentional, as long as it was foreseeable.
  • Developers who build AI agents may also face liability questions, not only the businesses that deploy them.
  • Ordinary people harmed by an AI agent's actions have a clearer path to a legal remedy than many assume.

What actually happened here?

Australia saw what experts are calling its first reported incident of an AI agent causing accidental harm through automated action, a development first covered by Guardian Australia. An AI agent, in plain terms, is software given a goal and left to figure out the steps itself, clicking, sending messages, making requests, with no human approving each move. Something went wrong. The details of the specific incident remain sparse, but the legal fallout is already being discussed at the highest levels.

The failure mode here is one that anyone who has set up an automated workflow should recognise. You point a system at a target, you walk away, and the system does something you did not quite expect.

Who is legally on the hook?

You are. Specifically, whoever switched the agent on.

Professor Jeannie Paterson, a legal expert in this area, put it plainly: "If I deploy an AI agent and it causes harm to someone else, I am responsible for that harm. Even if I didn't intend for that to happen, it was foreseeable, and I should be taking responsibility."

In practice, that means a business that runs an AI agent to automate customer outreach, security testing, data collection, or any other task cannot simply point at the software vendor when the bot does something harmful. The deployer carries the liability.

Developers are not entirely off the hook either. Experts warn that the people who build these agents could also face scrutiny, depending on how the tool was designed and what guardrails, meaning built-in limits on what the software is allowed to do, were included or left out.

What does this mean for ordinary people?

If an AI agent contacts you, scrapes your data, disrupts a service you rely on, or causes you financial harm, there is a human being or a company behind it who can be held accountable. That is actually good news. The law does not treat the bot as an independent actor with its own rights or obligations.

One thing the post-mortem will say, in cases like these, is that the deploying organisation did not adequately scope what the agent was permitted to touch. That is a governance failure, not a technology mystery.

If you believe an automated system has harmed you, document what happened, note the service or company involved, and seek legal advice. You have more standing than you might think.

Operational takeaway: before you deploy an agent in production, define its blast radius, the maximum possible damage it could do if it misbehaves, and make sure you are prepared to own it.

© 2026 Threat Vectr