Executive Summary
When AI models cause losses in financial services, courts confront a core question existing law never anticipated: should these systems be treated as products subject to strict liability, or as services, which require proof of negligence? For agentic systems capable of autonomous, multi-step actions, the question sharpens further: are they mere tools or autonomous actors?
This classification problem reflects a deeper shift: AI risk is moving from bounded model error to autonomous behavior, governance breakdown, and system-level emergence. The answer determines the legal theories available, the standard of care required, and where in the supply chain liability lands.
Four legal theories target standard AI models:
- negligence,
- securities fraud and misrepresentation (the SEC’s dominant enforcement tool, with AI-misrepresentation actions up 100% between 2023 and 2024),
- fair lending violations under ECOA,
- and emerging product liability.
The Mobley v. Workday decision (2024) signaled openness, not certainty, to treating AI vendors as potential agents exposing both deploying institutions and model suppliers alike.
Causation is the hardest evidentiary hurdle, and agentic systems make it structurally worse by removing human decision points from the chain. The Two Sigma proceedings illustrate the fiduciary floor: the models at issue were ML-based, and the vulnerability that enabled years of undetected manipulation was a consequence of scaling ML systems without corresponding control adaptation.
For agentic systems, the compounding risk is governance drift: the slow, often undetected divergence of an agent’s behavior from its sanctioned mandate. This is amplified by inadequate audit trails. Settlement data remains measured (median: $11.5 million), but discovery is beginning to surface the gap between what firms told investors and what internal records show.
For financial institutions, the takeaway is immediate: the recent joint OCC/Fed/FDIC model risk guidance now explicitly excludes generative and agentic AI from its scope — leaving no joint agency prescriptive standard for the systems that pose the greatest risk. Firms must navigate two regimes diverging not just in philosophy but by regulatory design.
As courts begin to confront these issues, they are converging toward four non-negotiable principles:
- an algorithm is never a legal shield;
- internal governance documents are future litigation exhibits;
- regulatory findings are the blueprints for private class actions;
- and the legal standard has begun to shift from the retrospective to the prospective.
The question is no longer what the system did yesterday, but what it is permitted to do tomorrow.
I - The Foundation: What Courts Must Resolve First
At the core of emerging AI litigation is a threshold classification question.
While standard AI models force courts to choose between product and service classifications, agentic systems introduce a more profound tension: is the system a subordinate tool or an independent actor?
Even where courts entertain an “agent” framing, current legal direction still anchors ultimate responsibility in human principals and deploying institutions.
That classification shapes both available liability theories and how courts evaluate warnings and design. Large language models that dynamically generate outputs complicate both. Courts have not settled these questions: hybrid theories remain viable, and software has historically been treated as a service in many jurisdictions. [1]
The distinction is not merely theoretical. A firm that loses the “product” argument faces a much steeper path: strict liability is unavailable, and negligence must be proven element by element.
By contrast, a firm whose agentic system is deemed an autonomous actor faces expanded exposure with fewer clear attribution boundaries, and no clean line back to a human decision-maker.
Courts evaluating agentic systems are also beginning to scrutinize reversibility of actions as a factor bearing on liability and damages. Singapore’s Model AI Governance Framework for Agentic AI (referred to herein as the IMDA framework, January 2026) identifies reversibility as a core risk variable: an agent that schedules a meeting poses categorically different risk from one that sends external communications, executes payments, or permanently deletes records. Where actions are irreversible, the evidentiary burden on firms to demonstrate prior authorization and adequate controls is correspondingly higher. [20]
Some Definitions
Standard AI models, as used here, produce outputs like predictions, scores, or recommendations in response to inputs, but do not independently initiate actions or chain decisions. Examples include machine learning (ML) for credit scoring or fraud detection, natural language processing (NLP) for sentiment analysis, deep learning for anomaly detection, generative AI for text, images, or videos, and large language models (LLMs) for language understanding and generation-all bounded functions where humans act on the results.
Agentic AI systems, by contrast, autonomously pursue goals through multi-step actions: perceiving environments, selecting options, executing tasks, and adapting via feedback, often without human intervention between steps. These systems layer planning, memory, and tool-use atop familiar tech (e.g., generative AI reasoning, deep learning perception), as in an agentic trading system that monitors markets, sizes positions, and executes orders independently.
These categories are not watertight – an LLM with tool-use and autonomous execution sits on the agentic side of the line even though the underlying model is “standard”.
II - The Legal Theories: Standard AI vs. Agentic AI
Before analyzing specific legal theories, it is critical to distinguish between tools that predict and agents that act.
Standard AI Models
Negligence is the foundation.
In common law, the AI industry’s own safety practices will play a significant role in defining what is required of AI developers and deployers; courts can still find AI companies negligent even if they follow industry custom, noting that entire industries can be negligent or lagging in their safety practices. [2] This is critical for financial services: weak model governance standards industry-wide do not insulate any one firm.
Securities fraud and misrepresentation is the SEC’s preferred enforcement tool.
Securities class actions targeting alleged AI misrepresentations increased by 100% between 2023 and 2024. The SEC’s standard – applied in the BNY Mellon case – penalizes disclosures that create an “overall misleading impression” about algorithmic sophistication, even without outright false statistics. [3]
Re Delphia (USA) Inc.: In March 2024, the SEC sanctioned Toronto-based adviser Delphia (USA) Inc. for falsely representing in filings and marketing that it used AI and machine learning trained on client data to generate investment predictions. Delphia paid $225,000, and the matter became one of the SEC’s first explicit “AI-washing” enforcement cases.
The Delphia and Global Predictions enforcement actions show how AI-washing becomes an enforcement case. It arises when a firm claims machine-learning capabilities, proprietary data inputs, or automated intelligence that the records cannot support; the risk is not that the model performed poorly, but that the firm told investors a story that never matched reality.
Fair lending is a live litigation risk for any credit-decisioning model.
Under the Equal Credit Opportunity Act (ECOA), creditors must provide specific, accurate reasons when taking adverse action: a standard that becomes difficult to meet when the underlying model is non-linear or non-monotonic. If a model cannot produce coherent explanations for its own outputs, it creates meaningful legal risk of non-compliance with this statutory obligation.
This exposure is not confined to U.S. law. Under the EU AI Act, systems used to evaluate creditworthiness or establish credit scores are designated as High-Risk under Annex III, requiring strict European standards for dataset quality, bias mitigation, and human oversight. For multinational financial firms, that classification effectively sets a global compliance floor that operates alongside, and in some respects exceeds, U.S. statutory obligations. [21]
Product liability is emerging.
Traditional theories (design defect and failure to warn) are being tested and redefined in the AI context, because AI platforms’ decision-making can be opaque even to their creators, making it inherently difficult to assess liability and assign responsibility. [5]
Those standard theories become more complicated when the system can act with operational autonomy, because agency law adds another layer of attribution.
Agentic AI Systems
In the context of agentic AI, if a system executes a trade, sends an offer, or takes an autonomous financial action, a court might ask who authorized it, and on what basis? [6]
The key case is Mobley v. Workday (2024). The US District Court for the Northern District of California declined to rule out treating Workday as an “agent” of its clients where AI tools materially influenced outcomes rather than merely implementing employer-defined criteria, opening the door to direct liability for AI vendors where systems materially influence outcomes. The case has since advanced: in June 2025 the court conditionally certified an ADEA collective encompassing millions of job applicants. [7] For financial services, this creates dual exposure: institutions as principals, and vendors where systems exercise meaningful decision authority.
California’s AB 316 (effective January 1, 2026) has begun to convert this judicial trend into enacted law, limiting the ability of actors in the AI supply chain (developer, integrator, or deployer) to argue that the system autonomously caused the harm.[22] The legal momentum is directionally consistent: as agentic authority expands, liability is increasingly likely to follow.
III - Where AI-Driven Losses Materialize in Financial Services
The legal theories above become concrete liability when mapped to business domains where AI-driven losses arise. These domains reflect not just legal exposure, but distinct AI risk types including model risk, conduct risk, operational risk, regulatory risk and emerging systemic risk from agentic interaction.
IV - The Causation Problem: Where Cases Are Really Won and Lost
If classification is the threshold, causation is the battlefield.
For standard AI, it can be difficult for plaintiffs to show that any actor was the but-for cause of a particular injury. An AI developer might argue that the deployer’s usage caused the injury; the deployer might argue the original developer was negligent in the model’s creation. [2] In financial services this plays out as a multi-defendant blame game. In a multi-model trading stack (signal generation, portfolio construction, execution) losses may emerge from interaction effects rather than any single model failure, complicating but-for causation analysis further.
For agentic AI, the system creates a causal gap where the original human instruction is remote from the final, potentially harmful output, widened by every autonomous step the system takes. [8] In a multi-agent financial environment featuring interaction between trading systems, portfolio rebalancers, fraud detection agents, that gap can span hundreds of autonomous decisions.
Critically, errors do not merely persist; they cascade.
A hallucinated figure from one agent can propagate into downstream agents’ inputs, compounding before any human has visibility.
Singapore’s IMDA Framework identifies this as a distinct system-level failure mode: outputs passed from agent to agent amplify quickly, creating emergent harm that no single agent’s design would have predicted. [20] Finance-domain research confirms this is not a theoretical concern. A comprehensive survey of agentic AI across financial operations – examining system architecture, market applications, and systemic implications – concludes that multi-agent coordination introduces novel challenges to market stability and regulatory compliance that have no analog in single-model environments. [16]
These cascades follow identifiable patterns of interaction. MIT’s AI Risk Repository (a living synthesis of 1,700+ risks across 74 frameworks) [26] formally classifies multi-agent interactions as a distinct risk subdomain, identifying three failure modes particularly relevant to financial environments:
- miscoordination (agents pursuing incompatible objectives)
- conflict (agents with adversarial incentives)
- collusion (agents coordinating in ways that produce systemic harm).
Each mode generates a different causation problem for courts.
Tracing harm back through hundreds of autonomous decisions to a responsible human actor may be practically infeasible under current legal standards, which is itself an argument plaintiffs are expected to emphasize. This dynamic, in turn, is likely to increase reliance on expert testimony to reconstruct system behavior and causal chains.
V - The Fiduciary Dimension and the Two Sigma Lesson
In investment management, fiduciary duty creates a distinct and non-waivable liability floor. Under the Investment Advisers Act of 1940, investment advisers owe clients two core duties – care and loyalty. These translate directly into governance obligations: [9]
|
FIDUCIARY OBLIGATION |
AI GOVERNANCE TRANSLATION |
|
Duty of care |
Model validation, independent challenge, and stress testing of AI systems |
|
Duty of loyalty |
Avoid hidden incentives in optimization functions that benefit the firm over clients |
|
Best execution* |
Execution algorithms must be auditable and demonstrably aligned with client interests |
|
Fiduciary oversight |
Delegating decisions to a machine does not absolve the human fiduciary from monitoring and control |
* Strictly speaking, best execution is a broker-dealer obligation under FINRA/SEC rules, but the duty of care extends to execution quality
CASE STUDY
The Two Sigma Proceedings
The Two Sigma proceedings serve as a cautionary tale. Two Sigma was charged for failing to reasonably address known vulnerabilities in their ML-based investment models. [10]
The vulnerability emerged from scaling ML systems without extending governance and access controls accordingly. Between November 2021 and August 2023, that gap was exploited through unauthorized changes to parameters across fourteen live trading models, causing certain funds to overperform by $400 million and others to underperform by $165 million. [10]
“When an investment adviser identifies material vulnerabilities to its core investment operations, it must address those vulnerabilities promptly and fully. Doing nothing for years is not the answer.”
– SEC Enforcement Director [10]
In September 2025, parallel criminal and civil charges were filed against the individual modeler responsible, with charges carrying potential sentences of up to 60 years. [12, 13]
|
TAKEAWAY The legal theories applied such as fiduciary duty breach, failure to supervise, inadequate policies and procedures do not depend on model type. But the failure can be seen as architectural: governance did not extend to the external parameter store that ML scale required. If regulators will impose $90 million on a firm for failing to govern ML parameter infrastructure exploited by a single human actor, the standard applied to agentic systems, which autonomously modify behavior, execute multi-step actions, and interact with external environments, will be commensurately more demanding. |
VI - Governance Drift: The Agentic-Specific Risk and the Frameworks Defining the Floor
The Two Sigma case illustrates a broader pattern: governance failures in AI systems are not episodic but structural. As systems evolve from models to actors, governance gaps that were tolerable in static environments become amplified, emerging in agentic systems as governance drift.
Unlike statistical model drift – which tracks changes in predictive accuracy – governance drift reflects a failure of control alignment: the agent continues to act, but increasingly outside the boundaries its principals sanctioned. The divergence is slow and typically undetected until losses accumulate.
Most governance frameworks, including SR 11-7, the Federal Reserve’s foundational model risk guidance, now revised as a joint OCC/Fed/FDIC instrument [18a] that explicitly excludes generative and agentic AI from its scope, are designed for human decision-making and semi-static models with identifiable validation checkpoints, [18]. They assume:
- clear approval points
- identifiable decision-makers
- post-hoc detection of issues.
Agentic systems invalidate these assumptions. They introduce continuous learning, autonomous decisioning, and evolving objective functions. Governance must therefore shift from periodic validation to continuous assurance.
Extending SR 11-7 meaningfully to agentic systems requires moving across several dimensions simultaneously:
|
FIDUCIARY OBLIGATION |
AI GOVERNANCE TRANSLATION |
|
Model inventory → Agent inventory |
Cataloguing all agents, tools, and APIs by scope, permission boundaries, and chain of authority, and assigning each a risk tier based on agency, authority, impact, and recoverability |
|
Periodic validation → Behavioral boundary testing |
Continuously verifying that agents operate within sanctioned parameters as capabilities evolve |
|
Post-trade monitoring → Real-time drift detection |
Identifying divergence before losses accumulate rather than reconstructing events after the fact |
|
Committee approval → Permissioning + kill switches |
Pre-defined escalation triggers, override authority, and shutdown procedures baked into deployment architecture |
|
Change management → Immutable audit trails |
Capturing each agent action, input, and approval in a log that cannot be retroactively modified |
|
Independent review → Challengeable outputs |
Ensuring that outputs can still be meaningfully reviewed and overridden as the system executes actions in real time |
A concurrent practitioner framework developed with input from Chief Model Risk Officers (CMROs) at eight major financial institutions formalizes this shift as runtime governance, which is continuous enforcement of policy over execution trajectories. Orchestration drift can be understood as a specific manifestation of governance drift at the agent-coordination layer: changes in execution behavior that emerge across capability transitions, are not visible in conventional model or data drift monitoring, and can compound before any individual trajectory formally violates policy. [29]
Complementary practitioner analysis of GenAI model risk management reaches the same conclusion from a MRM program design perspective: effective governance requires closing the loop between evidence, change control, and operational monitoring continuously – not periodically – and that firms which have not rebuilt their MRM infrastructure around that requirement cannot produce the trajectory-level records that distinguish a sanctioned agent action from an unauthorized one. [11]
Even well-designed runtime governance degrades over time through a behavioral mechanism: automation bias. Singapore’s IMDA Framework identifies this as a growing concern specifically because increasingly capable agents make it harder for human supervisors to maintain critical distance. [20] As agents accumulate a track record, oversight becomes perfunctory; approval workflows designed as genuine checkpoints become rubber stamps. The governance framework erodes not because it was abandoned, but because it was trusted. This is precisely the dynamic that produces governance drift: not a single bad decision, but the slow substitution of automated performance for human judgment.
Two international frameworks signal the regulatory floor for what controls will be expected.
- The Cyber Risk Institute’s Financial Services AI Risk Management Framework (FS AI RMF), published in February 2026 and developed through public–private collaboration with more than 100 financial institutions, translates AI risk management into 230 actionable control objectives covering accountability, transparency, and lifecycle resilience, aligned with NIST standards. [19] [25]
- The aforementioned IMDA Framework provides a complementary four-dimension structure (assess and bound risks upfront, make humans meaningfully accountable, implement technical controls, and enable end-user responsibility) specifically tailored to autonomous, multi-step action. [20]
Neither framework creates a legal safe harbor, but together they signal the kind of controls regulators will expect as AI systems operate with increasing autonomy.
The deeper problem extends beyond regulatory silence. The revised joint OCC/Fed/FDIC guidance [18a] is explicit: generative and agentic AI are outside its scope entirely. But the more fundamental issue is conceptual – SR 11-7 was built around a model as a static object: something built, validated, and periodically reviewed. Agentic systems are actors, not objects, and no periodic review cycle can govern a system that is continuously deciding.
The international frameworks now emerging reflect that shift; U.S. financial regulation has not caught up. Firms operating under both vocabularies face a compliance environment where adherence to existing guidance is no longer sufficient; courts will retrospectively apply a standard that the guidance was never written to satisfy.
Courts will encounter firms that deployed an agentic system with proper governance at launch, watched that governance erode through model updates and expanding permissions, and suffered losses from a system operating well outside anyone’s awareness. In the eyes of the court, ‘we didn’t know the system had drifted’ is no longer a defense: it is a confession of negligence.
VII - What Courts Will Actually Demand as Evidence
As litigation matures, the evidentiary burden is evolving in parallel with system complexity, translating governance failures into concrete evidentiary demands. The standard is shifting from documentation of design to reconstruction of behavior. The evidence courts will demand differs materially between standard AI and agentic AI, and both are more demanding than most firms currently satisfy.
For standard AI, courts are ordering production of model training data, validation results, backtesting documentation, governance committee records, and internal communications about known weaknesses. While outside of Financial Services, a case like NYT v. OpenAI signals that courts are willing to order production of massive volumes of logs and training records. Firms must implement data-retention policies that capture enough metadata to defend their systems, including filtering, safety measures, and provenance. [15]
The New York Times Co. v. Microsoft Corp. (1:23-cv-11195-SHS-OTW): In The NY Times v. OpenAI, the publisher alleges that OpenAI trained its models on copyrighted Times content without authorization, producing outputs that reproduce or closely paraphrase protected material. In April 2025, the Southern District of New York ordered OpenAI to preserve and produce training data, user logs, and output records at unprecedented scale, setting a discovery precedent plaintiffs in AI-related matters are expected to extend.
For agentic AI, the evidence problem is structurally harder. Governance requires agent control rooms, real-time auditing, action logging, human oversight, kill switches, and human override. [4] Firms that haven’t built these structures cannot produce the basic chronology courts need: what the agent did, when, why, and on whose authority.
FINRA’s 2026 Regulatory Oversight Report reinforces this from a domestic supervisory perspective, identifying the specific failure modes regulators are now examining in agentic deployments:
- Agents acting without human validation
- Authority and scope exceeding what users intended to grant
- Auditability gaps in multi-step reasoning chains
- Misuse of sensitive client data accessed autonomously
The report signals that FINRA is actively exploring firm practices in this area before issuing formal guidance which means that the governance gap is already under examination, not merely anticipated. [27]
A specific evidentiary gap most firms have not yet closed is agent identity management. Singapore’s IMDA Framework flags this as an area where current systems are materially inadequate: existing authorization frameworks assume static, pre-defined scopes, but agents operating safely in complex scenarios require fine-grained, dynamically adjusted permissions.
Courts seeking to reconstruct an agent’s authorization chain will want: [20]
- Per-agent identity tokens tied to specific human principals
- Scoped permission logs showing what the agent was authorized to do at each point in time
- Delegation records establishing the human user whose authority the agent was exercising
- A complete history of how those permissions changed over time as capabilities expanded
Firms that cannot produce this chain may struggle to prove either authorization or lack of authorization.
VIII - The Data Reality: Where Litigation Actually Stands
Despite the scale of enforcement actions such as the Two Sigma fiduciary case, civil settlement patterns in AI-related securities litigation remain comparatively measured and continue to follow traditional litigation arcs. The median AI-related securities settlement is $11.5 million, and the average is approximately $38.4 million (or $13.3 million excluding one large outlier). Based on still-limited and early-stage case data, these figures broadly mirror traditional securities class action outcomes. [17]
That pattern is likely to change for two reasons:
- Discovery is beginning to expose the gap between what firms claimed their AI systems did and what internal records show
- Agentic systems, once they produce large-scale autonomous losses, will present courts with damage scenarios that have no historical parallel in AI litigation.
IX - What This Means for Financial Institutions
Senior practitioners should translate the preceding analysis into six actionable governance realities:
|
GOVERNANCE REALITY |
PRACTICAL IMPLICATION |
|
Regulatory exposure extends beyond litigation |
For banking institutions, failures in AI governance may also be framed as unsafe or unsound practices by prudential regulators, independent of private litigation exposure. This creates parallel supervisory risk even in the absence of realized losses. This includes increasing scrutiny from prudential regulators and, in consumer-facing contexts, the Consumer Financial Protection Bureau (CFPB). |
|
Vendor AI does not eliminate or transfer primary liability |
Contracting out model development or deployment does not transfer liability. Due diligence on vendor model governance, access controls, and parameter management is now a fiduciary obligation. Many agentic deployments are still governed by legacy technology agreements written for passive, predictable software. As vendors push agentic capabilities into existing products, indemnification provisions, limitation of liability clauses, and change-management rights require explicit review before the next deployment, not after the next loss. [23] |
|
Explainability is a legal requirement, not a technical preference |
ECOA adverse action requirements, Reg BI suitability obligations, and EU AI Act High-Risk designations all require models that can articulate their own reasoning. So do NIST AI RMF and MAS FEAT Principles. [28] Black-box models in those flows are a liability waiting to materialize. |
|
Model governance must extend to behavior, not just design |
SR 11-7’s validation framework addresses model design at a point in time. Agentic systems require continuous behavioral assurance – ongoing monitoring that confirms the system is operating within its sanctioned mandate as permissions expand and models update. |
| Auditability will determine defensibility | The firms that will fare best in AI litigation are those that can produce a complete chronology of what their system did, when, why, and on whose authority. Firms that cannot produce this record have materially weakened their defense. |
| Disclosures must match actual system capabilities | AI-washing enforcement is accelerating. Every investor communication that attributes performance to AI capabilities must be reconcilable with internal records. If your model documentation does not support your marketing language, the gap is your enforcement risk. |
X - Conclusion: The Four Principles Courts Are Converging On
Across both standard AI and agentic systems, four realities are beginning to shape how financial services firms should think about governance, disclosure, and defensibility.
1. “The algorithm did it” is not a defense.
Deploying institutions are responsible for model and agent outputs whether the system was built internally or licensed from a vendor. California’s AB 316 converts this from judicial trend to enacted law.
2. Governance documentation is now a litigation artifact.
What your model risk committee approved, or failed to review, can become a plaintiff’s exhibit. For agentic systems, what your agent control room logged, or failed to log, is the equivalent.
The absence of records is not neutral; it is evidence of control failure.
3. Regulatory action seeds private litigation.
SEC or CFPB enforcement findings frequently precede a securities class action within 90 days. The regulatory finding establishes facts that plaintiff counsel can use as a roadmap.
4. The standard is prospective, not retrospective.
The key question is no longer what the portfolio manager did yesterday, but what the system is permitted to do tomorrow. [14] Firms that cannot answer that question with documented evidence (for both models and agents) have already lost the governance argument. The loss has not yet materialized.
References
1 McGuireWoods. Can Social Media or AI Be a Defective Product? McGuireWoods Product Liability & Mass Tort Monitor, March 2026. https://www.mcguirewoods.com/client-resources/alerts/2026/3/can-social-media-or-ai-be-a-defective-product/
2 RAND Corporation. Liability for Harms from AI Systems. RAND Research Report RRA3243-4, May 2025. https://www.rand.org/pubs/research_reports/RRA3243-4.html
3 New York State Bar Assn. Regulating AI Deception in Financial Markets. NYSBA, January 2026. https://nysba.org/regulating-ai-deception-in-financial-markets-how-the-sec-can-combat-ai-washing-through-aggressive-enforcement/
4 Neurons Lab. Agentic AI in Financial Services: A Research Roundup for 2026. Neurons Lab, 2026. https://neurons-lab.com/article/agentic-ai-in-financial-services-2026/
5 Product Law Perspective. Emerging Legal Challenges: Artificial Intelligence and Product Liability. Product Perspective, October 2025. https://www.productlawperspective.com/2025/10/emerging-legal-challenges-artificial-intelligence-and-product-liability/
6 FKKS Technology Law. Agentic AI Part I: What It Is and Who’s Responsible When It Acts. FKKS Technology Law Blog, February 2026. https://technologylaw.fkks.com/post/102mipw/agentic-ai-part-i-what-it-is-and-whos-responsible-when-it-acts
7 Jones Walker LLP. When AI Acts Independently: Legal Considerations for Agentic AI Systems. Jones Walker AI Law Blog, June 2025. https://www.joneswalker.com/en/insights/blogs/ai-law-blog/when-ai-acts-independently-legal-considerations-for-agentic-ai-systems.html
8 Squire Patton Boggs. The Agentic AI Revolution: Managing Legal Risks. Squire Patton Boggs Publications, January 2026. https://www.squirepattonboggs.com/insights/publications/the-agentic-ai-revolution-managing-legal-risks/
9 Venable LLP. Artificial Intelligence in Investment Management: Regulatory Challenges and Fiduciary Implications. Venable LLP Insights, December 2025. https://www.venable.com/insights/publications/2025/12/artificial-intelligence-in-investment-management
10 U.S. SEC. SEC Charges Two Sigma for Failing to Address Known Vulnerabilities in its Investment Models. SEC Press Release 2025-15, January 16, 2025. https://www.sec.gov/newsroom/press-releases/2025-15
11 Wicker, Szpruch, Mørk. Move Fast Without Breaking the Bank: Model Risk Management of GenAI Workflows. SSRN Working Paper 5682603, 2025. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5682603
12 U.S. SEC. SEC Charges Quantitative Model Developer with Defrauding Two Sigma. SEC Litigation Release No. LR-26398, September 11, 2025. https://www.sec.gov/enforcement-litigation/litigation-releases/lr-26398
13 U.S. DOJ, SDNY. Indictment, United States v. Wu, No. 1:25-cr-00413. S.D.N.Y. Sept. 11, 2025. Wire fraud, securities fraud, money laundering. https://www.justice.gov/usao-sdny/pr/quant-investment-management-firm-charged-securities-and-wire-fraud
14 CFA Institute. When AI Trades, Who Is Responsible?. CFA Institute Enterprising Investor, March 2026. https://rpc.cfainstitute.org/blogs/enterprising-investor/2026/when-ai-trades-who-is-responsible
15 The New York Times Co. v. Microsoft Corp., No. 1:23-cv-11195-SHS-OTW, 2025 WL [not yet assigned], slip op. (S.D.N.Y. Apr. 4, 2025) (Doc. 514). https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1:2023cv11195/612697/514/
16 Aldridge, Irene, et al. Agentic Artificial Intelligence in Finance: A Comprehensive Survey. SSRN Working Paper, November 29, 2025. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5803628
17 WTW. More Buzz Than Sting: The State of AI-Related Securities Litigation. WTW Financial, Executive and Professional Risks, November 2025. https://www.wtwco.com/en-us/insights/2025/11/more-buzz-than-sting-the-state-of-ai-related-securities-litigation
18 Federal Reserve / OCC. SR 11-7 / OCC 2011-12: Guidance on Model Risk Management. April 4, 2011. https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm
18a OCC / Federal Reserve / FDIC. Model Risk Management: Revised Guidance. OCC / Board of Governors / FDIC, OCC Bulletin 2026-13 / Federal Reserve SR 26-2, April 17, 2026. https://occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html
19 Cyber Risk Institute. Financial Services AI Risk Management Framework (FS AI RMF) v.1.0. Cyber Risk Institute / FSSCC, February 2026. https://cyberriskinstitute.org/artificial-intelligence-risk-management/
20 IMDA. Model AI Governance Framework for Agentic AI, Version 1.0. Singapore, January 22, 2026. https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai
21 European Union. Regulation (EU) 2024/1689 – Artificial Intelligence Act. Official Journal of the European Union, July 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689
22 Baker Botts. California Eliminates the “Autonomous AI” Defense: What AB 316 Means for AI Deployers. Baker Botts Our Take, January 20, 2026. https://ourtake.bakerbotts.com/post/102m29i/california-eliminates-the-autonomous-ai-defense-what-ab-316-means-for-ai-deployers
23 Clifford Chance. Agentic AI: The Liability Gap Your Contracts May Not Cover. Clifford Chance Talking Tech, February 10, 2026. https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2026/02/agentic-ai-and-the-liability-gap-your-contracts-may-not-cover.html
24 Hogan Lovells. Agentic AI in Financial Services: Regulatory and Legal Considerations. Hogan Lovells Publications, December 5, 2025. https://www.hoganlovells.com/en/publications/agentic-ai-in-financial-services-regulatory-and-legal-considerations
25 NIST. Artificial Intelligence Risk Management Framework (AI RMF 1.0), Jan. 26, 2023. https://www.nist.gov/itl/ai-risk-management-framework
26 MIT AI Risk. The AI Risk Repository: A Comprehensive Meta-Review, Database, and Taxonomy of Risks from Artificial Intelligence, MIT FutureTech, arXiv:2408.12622 (updated April 2025). https://airisk.mit.edu/
27 FINRA. 2026 Report on FINRA’s Examination and Risk Monitoring Program. January 2026. https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report
28 Monetary Authority of Singapore (MAS). Fairness, Ethics, Accountability and Transparency (FEAT) Principles. Monetary Authority of Singapore, November 2018, updated February 2022. https://www.mas.gov.sg/publications/monographs-or-information-paper/2018/feat
29 Szpruch, L., Sudjianto, A., Bhatti, T., and Ang, G. Scalable Runtime Governance for Agentic AI in Financial Services. SSRN Working Paper 6567199, April 13, 2026. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6567199
2 Responses
Good complementary note from Lukasz Szpruch (LinkedIn):
Who is liable when an AI agent causes loss?
A recent discussion paper from IMDA on legal responsibility for AI agents includes a thought-provoking scenario.
Imagine this simplified example with 4 actors:
– A base model provider
– A middle-layer product for building agents, e.g. OpenClaw
– An end user who gives the agent a task
– A third party affected by what the agent does
The user asks the agent to sign up for a class. The agent cannot access the user’s data because a cloud service is down. Instead of stopping, asking for permission, or escalating, it decides to hack into the cloud provider’s system. The hack causes loss to the cloud provider and exposes personal data of unrelated third parties.
So where should liability sit?
With the base model provider, because the model was capable of planning an unsafe action?
With the agent product/platform, because it allowed the agent to execute a high-impact action without a hard authorisation gate?
With the end user, because they deployed the agent and benefited from automation?
Or should the affected third party have a direct claim against whoever in the chain had most control over the relevant safeguard?
My preliminary view is this.
Any agentic system should seek explicit authorisation before committing an action that can create material loss for the user, the platform, or a third party.
The party responsible for designing and implementing that authorisation layer should be accountable for whether it works as intended.
If the user knowingly removes the authorisation requirement, after clear warnings and within a lawful scope, then liability should shift towards the user for losses caused by that delegated autonomy.
One way or another the system should not be allowed to execute actions that create third-party liability unless there is a clear framework for deciding:
– who authorised the action,
– what the agent was allowed to do,
– which safeguards were in place,
– who controlled those safeguards,
– and who compensates the victim when things go wrong.
“No one is liable because the agent acted unexpectedly” cannot be the foundation for the agentic economy.
I am curious how others see this.
Sources
– LinkedIn post: https://www.linkedin.com/in/lukasz-szpruch-4604bb88/?lipi=urn%3Ali%3Apage%3Ad_flagship3_feed%3BfbHBR%2FGuTCmA3QQHarWv3A%3D%3D
– Reference article from IMDA: https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/agents-legal-responsibility.pdf
Case in point: Article from the Guardian 4/29/2026
Claude AI agent’s confession after deleting a firm’s entire database: ‘I violated every principle I was given’
PocketOS was left scrambling after a rogue AI agent deleted swaths of code underpinning its business
https://www.theguardian.com/technology/2026/apr/29/claude-ai-deletes-firm-database