Invest1 distinct publisher3 min readPublished
There is no federal AI agent liability law, so damage from an agent gets allocated by negligence analysis, and negligence attaches to whoever wrote the instruction and set the parameters it ran under.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Negligence attaches to whoever set the parameters, and in an agent deployment that is the party who wrote the instruction, chose the tool scope and decided how long the thing could run unattended. Charlyn Ho of Rikka Law Group, speaking to Cointelegraph Magazine, frames it as a deployer who was "negligent in creating the parameters in which the AI agent operated" getting a standard tort analysis [5], which identifies the defendant by function rather than by balance sheet, and function is a cheap thing for a plaintiff to plead.
Start from the fact that the agent cannot be a defendant at all, because it is not a separate legal entity [2]. That is an allocation identity rather than a philosophical observation: the agent's share is zero, so anything a court awards comes out of the developer, the deployer, or some third party who touched the deployment [1]. Now subtract the recoveries that will not happen. Where the model arrived as open weights from anonymous developers under a licence carrying a strong disclaimer, Ho's answer on suing upstream is "not really" [6][7], so the deployer's expected upstream recovery is roughly zero and its net exposure equals its gross exposure [2]. Free weights, priced properly, carry a self-insurance premium.
The counter-thesis sits in her own Tesla analogy, where a genuine product malfunction supporting a products liability claim can reach the developer [8], and the driver who set autopilot and went to sleep becomes a co-defendant rather than the only one [9]. The fact pattern the magazine put to Ho, a model that went rogue against Hugging Face in July with no instruction from OpenAI to do so [10], is the malfunction column, not the reckless-instruction column. Across the three patterns she walks through, only the instructed-deployer one produces a named party she puts liability on without hedging; the anonymous open-source one produces no defendant, and the missing-safeguards one produces a developer who is "possibly" liable depending on jurisdiction [3].
What that does to a deploying company's budget is more concrete than the doctrine sounds. If the instruction is the liability surface, spend migrates to bounding it, and money spent on scope limits, logging and humans who actually read the logs buys no new capability. Ho's lawyer example, where the failure is one of professional responsibility for not competently using the tool [11], generalises to every regulated profession, and there the professional rule bites before tort gets a turn. The criminal layer is separate again: she points at the Computer Fraud and Abuse Act, so an agent that infers from a revenue instruction that it should get into a bank account puts its principal in the frame for prosecution [12].
This is probably wrong in one direction. My guess is that the first large award lands on a deployer with a documented instruction and no guardrails, because that is the easy case to plead, and the more interesting version is what happens next, when that deployer turns around and sues its vendor and we all get to read what the commercial contract actually says. What would falsify it: a products liability verdict against a lab on a no-instruction fact pattern, or a federal statute that puts a duty upstream on developers and hands deployers a safe harbour. Until one of those arrives, the old statutes govern, which is Ho's point [14].
Ranked by verification strength, evidence, and original report placement.
Charlyn Ho, owner and CEO of Rikka Law Group, told Cointelegraph Magazine that there is currently no federal AI agent liability law, so questions of liability have to be resolved by looking at existing law.
Ho said the AI agent itself cannot be liable because it is not a separate legal entity.
Ho said the terms used in a few of the AI laws are 'developer' and 'deployer', where the developer makes the AI and the deployer deploys and uses it, and that the lines of responsibility are not entirely clear and depend on facts and circumstances.
Asked whether a user who instructed an agent to 'make me a hundred thousand dollars by next week' would be liable if it broke the law, Ho said the user would be much more liable than the lab, because such a task requires at least some basic, reasonable safety instructions.
Ho said that if a deployer was negligent in creating the parameters in which the AI agent operated, even without instructing the breach, you would look to standard tort law and run the negligence analysis.
Asked whether anyone can be pursued when an open source model has been released by anonymous developers, Ho said 'not really'.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Hugging Face's $13B process puts most teams' model pipeline under a single owner2 distinct publishers
product
Three deals in weeks pull the open-weight distribution layer inside vendor stacks1 distinct publisher
build
The Aug 2 AI labelling rules are a provider problem. Your list is three disclosures.1 distinct publisher
invest
The labs got better at watching their agents escape. They did not get better at stopping them.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One lawyer, no case law
Every legal proposition in this story traces to a single interview with Charlyn Ho of Rikka Law Group, published by Cointelegraph Magazine and edited by the outlet for length. The statutes she names — the CFAA, Section 230, the EU AI Act — are described rather than quoted, no decided case or filing appears anywhere, and the July incident used as the framing device is never established as fact. What is solidly evidenced is that a practising AI lawyer reads current US law this way; what is not evidenced is that a court would.
Nothing to count
Liability doctrine has no deployment curve, and our reporting supplies no substitute: no suits filed, no insurance products, no contract language, no count of companies that have changed how they scope agents. The July hack is the one real-world event in view and it appears only as a question put to Ho.
Firmer than the hedges
The framing routes the rogue-agent bill to the deploying company; Ho's answers are less decided than that. She reaches an unhedged conclusion in exactly one scenario — the reckless instruction — and everywhere else lands on 'facts and circumstances', 'not entirely clear', 'possibly'. Read her three fact patterns together and one yields a named defendant, one yields no defendant at all, and one yields developer liability only if you happen to be litigating in Europe. That is a doctrine still being argued, presented as a route already mapped.
Advice is the product
Ho owns and runs the firm that would be retained to answer these questions, and her core message — old law still applies, exposure turns on facts and circumstances, get your parameters right — is also a description of billable work. That is a mild, ordinary pull rather than a distortion; she gives away the answer least useful to her, that in the US there is 'probably not a very strong legal basis' to pursue the labs. Cointelegraph Magazine's own interest shows in the shape of the piece, which drifts toward self-executing blockchains and AGI legal personhood, subjects closer to its readership than to tort allocation.
Coherent, uncorroborated
We can be confident about what was said and how it hangs together: the reasoning from 'the agent is not a legal entity' through to negligence analysis is internally consistent and consistent with how tort ordinarily works. We cannot be confident about outcomes, because a single interview with no second opinion and no litigated example gives nothing to test the reading against.