The person or organization that deployed the AI agent is accountable, not the AI itself — because AI tools cannot hold legal or moral responsibility, and "it was just following instructions" is not a defense that shifts blame onto the software.
When an AI agent books the wrong flight, sends an email to the wrong client, or takes an action that harms someone, the accountability lands on whoever chose to give that agent the authority in the first place. That's the short answer, and it's the one most people are looking for when they ask this question.
The reason accountability works this way comes down to how these systems actually function. An AI agent doesn't have intent, understanding, or the capacity to weigh consequences — it follows patterns and instructions. Legal and ethical frameworks generally require a responsible party who could have chosen differently.
Since the agent can't choose differently in any meaningful sense, the choice belongs to the human or company that configured it, granted it permissions, and decided its outputs were acceptable. This is why the question "who's accountable" is really a question about deployment decisions, not about the AI's behavior.
If you gave an agent access to your calendar and your email, you made a decision about scope. If you didn't add a confirmation step before it sends messages, that was also a decision. Accountability follows those decisions.
A concrete example makes this clearer. Suppose a small business uses an AI agent to handle customer refund requests under a certain dollar amount. The agent misreads a policy document and issues a refund it shouldn't have.
The customer keeps the money. Who's accountable? The business, because the business decided the agent could issue refunds without human review.
The fix isn't to blame the model — it's to add a threshold where a human approves anything above a set amount, or to test the agent against edge cases before going live. According to our AI tool database, productivity tools like Notion AI and Slack AI are increasingly built into everyday workflows, which means more people are delegating small decisions to AI without thinking about where the accountability line sits. That line doesn't move just because the tool is convenient.
Here's where this gets genuinely tricky, and where honest limits matter. Accountability is clear when one person deploys one agent. It gets murky when an agent is built on top of another company's model, configured with a third party's plugin, and deployed inside a company where nobody fully understands the chain.
In those cases, the practical answer is that accountability is shared — but "shared" often means nobody feels responsible until something goes wrong. That's a real problem, not a solved one. The useful move is to decide in advance who owns the outcome when an agent acts.
Write it down. Name a person. If you can't name who's accountable for an AI agent's actions, that's a sign the agent has too much authority for the current setup.
You can read more about the specific risks of letting agents act on your behalf in our guide on whether it's safe to let an AI agent book, buy, or send things for you.
A tip that goes beyond the obvious: treat every AI agent like a new employee with a probation period. Give it narrow permissions, require confirmation for anything irreversible, and expand its authority only after you've seen how it handles the boring cases. The accountability question becomes much easier to answer when the agent's scope is small enough that a single person can reasonably oversee it.
The moment you can't explain what your agent is allowed to do, you've lost the thread — and that's when "it was just following instructions" starts sounding like an excuse rather than a fact.