Am I personally liable for my AI agent's mistakes?
Founders ask this question the moment they picture the worst case: their AI agent makes a promise it should not have made, a customer is harmed, and a claim lands. The question underneath is rarely "will my business be sued." It is "can they come after my house." The honest answer depends far more on how your business is structured and how you behave than on anything the AI agent itself did. This article separates the sole trader baseline, where there is no shield at all, from the limited company protection most operators assume they have, explains precisely when that protection stops working for a director, and sets out what to check before an AI agent is given the authority to commit your business to anything.
Key takeaways
- If you trade through a limited company, the company, not you personally, is normally the party liable for your AI agent's mistakes. Your personal exposure is generally limited to the capital you put into the business.
- If you are a sole trader or in an ordinary partnership, there is no separate legal person to absorb the claim. You are personally liable for your AI agent's mistakes to the same extent you would be for your own, because in law there is no distinction between you and the business.
- A limited company's protection can be pierced in narrow circumstances, most clearly where the company was used as a device to evade an existing legal obligation, a doctrine the UK Supreme Court confirmed in Prest v Petrodel Resources Ltd [2013] UKSC 34.
- Wrongful trading under section 214 of the UK Insolvency Act 1986 is the specific mechanism that can reach a director's personal assets if they kept the business, and an AI agent's autonomous financial commitments, running after they knew or ought to have known the company could not meet its debts.
- Directors and officers insurance covers claims against you personally for an alleged breach of your duties as a director. It is not a substitute for the company's own liability cover, and the two policies answer different questions about the same incident.
The short answer: structure first, conduct second
Two variables decide whether an AI agent's mistake can reach you personally, and neither of them is how sophisticated the agent was or how the failure happened. The first variable is your business structure. The second is your own conduct once something starts to go wrong. Get the structure question right and the conduct question rarely arises. Get the structure question wrong, by assuming a protection you do not actually have, and the conduct question can become expensive fast.
This article works through both variables in order, because most of the anxious version of this question, "can I be sued personally," collapses into a much narrower and more answerable one once you know which category you are in.
If you are a sole trader or in an ordinary partnership: there is no shield
Start here, because it is the case most operators researching this question are actually in, and it is the one with the least good news. A sole trader is not a separate legal entity from the person running the business. There is no corporate structure standing between the customer and you. If your AI agent quotes a client the wrong price, gives advice a client relies on to their detriment, or commits you to a service you cannot deliver, the resulting claim is against you personally, in exactly the way it would be if you had made the same mistake yourself with no AI involved. Your personal assets, not a company's balance sheet, are what a judgment or a settlement is paid from.
The same is true, with only modest variation by jurisdiction, for partners in an ordinary (non-limited liability) partnership. Each partner is typically liable for partnership obligations, and in many jurisdictions each partner can be pursued for the full amount of a joint liability, leaving that partner to seek contribution from the others separately. If you operate this way and you are deploying an AI agent that can make representations to customers or commit the business financially, the personal liability question is not a hypothetical edge case: it is your default legal position, before you consider AI at all.
This is also the group of operators for whom the underlying liability analysis, who is responsible when an AI agent gets something wrong, matters least as a separate legal puzzle. The answer is you, subject to the ordinary rules of negligence, contract, and professional duty that would apply to a human employee's mistake. For the full mapping of those legal theories, see our decision tree on who is liable when an AI agent makes a mistake. For a sole trader, that decision tree resolves quickly: the deployer is you, and you are the only deployer there is.
If you trade through a limited company: the shield generally holds
Incorporating a limited company creates a separate legal person. The company, not its directors or shareholders, enters into contracts with customers, owes the duties those contracts create, and is the party sued when a customer alleges the AI agent it deployed caused harm. This is the entire commercial purpose of limited liability, and for the overwhelming majority of AI agent mistakes, ordinary errors, bad recommendations, incorrect quotes, mishandled requests, it works exactly as intended. Your personal exposure is capped at what you have invested in the company. This is true whether the mistake originated in a human employee's judgment or an AI agent's autonomous output; the company's liability structure does not change based on which one acted.
This is the point at which many operators stop thinking about the question, and for most day-to-day AI agent risk, that is a reasonable place to stop. But "generally holds" is doing real work in that sentence, and a founder who has read this far is usually the kind of person who wants to know exactly where the exceptions sit rather than take the general rule on faith.
When the corporate shield stops protecting a director personally
Courts do not lightly set aside the separate legal personality of a company. The doctrine that allows them to do so, often called piercing or lifting the corporate veil, is narrow by design, and the leading modern statement of its limits comes from the UK Supreme Court in Prest v Petrodel Resources Ltd [2013] UKSC 34. The Court held that the veil can be pierced only where a company is being used to evade an existing legal obligation the individual already owes, not simply because a company was involved in causing harm or because piercing the veil would be convenient for a claimant. An AI agent's ordinary operational mistake, on its own, does not come close to this threshold. Piercing the veil is not the mechanism that usually puts a director's personal assets at risk from an AI-related claim.
The more practically important mechanisms are director's duties and wrongful trading, both of which attach personal consequences directly to a director's own conduct rather than requiring a claimant to unpick the corporate structure at all.
Breach of director's duties. Under the UK Companies Act 2006, directors owe the company specific statutory duties, including the duty to act within their powers (section 171), the duty to promote the success of the company (section 172), and the duty to exercise reasonable care, skill, and diligence (section 174). A director who deploys an AI agent recklessly, for example giving it authority to make financial commitments with no oversight, no logging, and no defined limits, despite being warned this created unacceptable risk, could face a claim that they personally breached the duty of care. This is a claim brought against the director in their capacity as director, separate from any claim a customer brings against the company itself.
Wrongful trading. Section 214 of the UK Insolvency Act 1986 is the sharpest personal exposure a director can face. If a company enters insolvent liquidation, and a court finds that a director knew, or ought to have concluded, that the company had no reasonable prospect of avoiding insolvent liquidation, and the director continued trading regardless, the court can order that director to personally contribute to the company's assets. The relevant fact pattern for AI operators is specific: a director who lets an agent keep committing the company to refunds, discounts, or contracts after becoming aware the company cannot meet its existing liabilities is continuing to trade in exactly the sense section 214 addresses. The AI agent does not create this exposure. The director's knowledge, and their decision to keep the agent running regardless, does.
Similar principles, personal liability for a director's own wrongdoing rather than for the company's ordinary business risk, exist under different names and different statutory thresholds across most jurisdictions with a limited liability company structure, including fraudulent trading provisions and general fiduciary duty doctrines in common law jurisdictions and comparable insolvency-law duties across EU member states. The specific statute changes; the underlying principle, that limited liability protects you from the business's ordinary risks but not from your own knowing misconduct, does not.
Fraud and personal misrepresentation are never shielded
One category of exposure sits outside the corporate structure question entirely: your own fraud or deliberate misrepresentation. If a director personally directs an AI agent to make claims known to be false, or personally makes a fraudulent representation using AI-generated content as the vehicle, the company's separate legal personality does not protect that individual. Fraud is treated in law as the director's own act, not an act of the company, regardless of the corporate wrapper around the business. This is a narrow category and rarely the fact pattern in a genuine AI agent error, where the failure is typically a hallucination, a scope failure, or inadequate oversight rather than deliberate deception. It is worth naming precisely because it is the one scenario where "the company is liable, not me" is never a valid response, structure or no structure.
What Mata v. Avianca shows about personal professional responsibility
Mata v. Avianca (SDNY, 2023) is usually discussed as a lesson about verifying AI output before relying on it, and it is that. It is also directly relevant to the personal liability question, because the sanctions in that case fell on the individual lawyers who submitted the AI-generated brief, not on their law firm as an abstract entity. Judge Kevin Castel sanctioned Steven Schwartz and the supervising partner personally for failing to verify the fabricated case citations before filing them with the court. Where a professional's own duty of care runs personally, as it does for lawyers, doctors, accountants, and other regulated professionals acting in their professional capacity, deploying AI to produce the work does not transfer that personal duty to the AI or shield the professional behind their firm's corporate structure. An operator in a regulated profession should treat this as the clearest available precedent that "the AI got it wrong" is not a defence that reaches past the individual's own professional obligation.
What D&O insurance actually covers, and what it does not
Directors and officers insurance is built to respond to exactly the category of claim this article has been describing: an allegation that a director personally breached a duty owed to the company, its shareholders, or a regulator. A wrongful trading claim under section 214, a shareholder derivative claim alleging breach of section 174, or a regulatory investigation into a director's conduct following an AI-related failure are the kinds of claims D&O policies are designed to defend and indemnify against.
What D&O insurance does not typically do is stand in for the company's own liability cover. The underlying claim a harmed customer brings against your company, for the AI agent's incorrect advice, the bad refund decision, or the broken promise, is ordinarily a matter for the company's general liability, professional indemnity, or a dedicated AI liability policy, not the D&O policy. Treating D&O cover as a general AI liability backstop is a common and costly misunderstanding. The two policies exist to answer two different questions about the same incident: what does the company owe the customer, and did a director personally breach their duty. Read your D&O policy's specific exclusions for technology or AI-related carve-outs, and confirm with your broker that you are not relying on one policy to do the other's job. For the company-level coverage question specifically, see our guide to whether your business insurance covers AI mistakes.
Four steps that materially reduce your personal exposure
First, confirm which category you are actually in. If you are a sole trader or in an ordinary partnership, treat every AI agent deployment as if you personally were the one speaking to the customer, because in law, you are. Second, if you are a director, document the oversight you put in place before giving an agent authority to commit the company financially or make representations to customers: defined scope, defined thresholds for human sign-off, and a record that you asked whether the risk was acceptable before switching it on. This documentation is what separates ordinary business risk, which the company absorbs, from a director's own failure of care, which does not necessarily stay with the company. Third, if your company's financial position becomes uncertain, review what your AI agent is authorised to commit the business to immediately, not after the fact; this is precisely the moment wrongful trading exposure begins to accrue. Fourth, review your D&O policy and your company's general or professional liability policy together, with your broker, so you know which one responds to which version of a claim before you need either of them. For the practical week-by-week version of getting this right before go-live, see the 90-day AI agent insurance and compliance playbook, and for the regulatory dimension of what an AI agent should and should not be allowed to commit you to, see the Article 26 deployer obligations guide on agentliability.eu.
Frequently asked questions
Am I personally liable if my AI agent makes a mistake?
Usually not, if you trade through a limited company and the mistake was ordinary business error rather than fraud, deliberate wrongdoing, or a breach of your specific duties as a director. The company is a separate legal person and normally absorbs the liability. Personal liability attaches in narrower circumstances: if you traded through the company knowing it could not meet its debts, if you gave a personal guarantee, if you were personally negligent in a way the law recognises as your own act rather than the company's, or if you operate as a sole trader or in an ordinary partnership, where there is no separate legal person to absorb the loss in the first place.
Does a limited company protect me from my AI agent's mistakes?
In most cases, yes. Limited liability means the company, not you personally, is the party that contracted with the customer, owes the duty of care, and is sued when something goes wrong. A customer harmed by your AI agent's output generally has a claim against the company, and your personal exposure is limited to the money you invested in it. This protection is not absolute. Courts can disregard the company structure and reach a director personally where the company was used as a device to evade an existing legal obligation, a doctrine confirmed by the UK Supreme Court in Prest v Petrodel Resources Ltd [2013] UKSC 34, though the circumstances in which this applies are narrow and rarely turn on ordinary operational mistakes.
What is wrongful trading and how could deploying an AI agent trigger it?
Wrongful trading, under section 214 of the UK Insolvency Act 1986, allows a court to require a director to personally contribute to a company's assets if the director knew, or ought to have concluded, that the company had no reasonable prospect of avoiding insolvent liquidation, and continued trading regardless. Deploying an AI agent does not itself create this exposure. The risk arises if a director continues to let an agent commit the business to financial obligations, refunds, or contracts after becoming aware the company cannot meet its existing liabilities, or ignores clear warning signs that the agent's autonomous actions are generating losses the company cannot absorb. The trigger is the director's knowledge and continued conduct, not the technology.
Am I personally liable for my AI agent's mistakes if I am a sole trader?
Yes, in full, and this is the most important distinction in this entire question. A sole trader and their business are the same legal person. There is no company to absorb a claim. If your AI agent gives a customer wrong advice, commits you to a bad price, or breaches a duty you owe a client, the claim is against you personally and your personal assets, not shielded by any corporate structure, are exposed in the same way they would be if you had made the mistake yourself without any AI involved. The same is true for partners in an ordinary partnership, where each partner can typically be pursued for the full liability.
Does directors and officers insurance cover claims arising from an AI agent's actions?
It can, but only for the specific thing D&O insurance is built to cover: claims made against you personally for an alleged breach of your duties as a director, such as a wrongful trading claim, a breach of the duty of care under section 174 of the Companies Act 2006, or a shareholder or regulator action following an AI-related failure. D&O insurance does not typically respond to the underlying claim a customer brings against your company for the AI agent's output itself; that is usually a matter for the company's general liability, professional indemnity, or a dedicated AI liability product. Read your D&O policy's exclusions specifically for technology or AI-related carve-outs before assuming either policy picks up the other's gap.
Related reading
Run the Coverage Audit
Before you talk to a broker or a lawyer, use the Coverage Audit tool to map what your AI agent is authorised to do against your current business and D&O policies. It takes ten minutes and produces the document your broker needs to review your position.
Start the Coverage AuditReferences
- Prest v Petrodel Resources Ltd [2013] UKSC 34. UK Supreme Court decision on the limits of piercing the corporate veil, confirming the doctrine applies only where a company is used to evade an existing legal obligation.
- Insolvency Act 1986 (UK), section 214, wrongful trading. Permits a court to order a director to personally contribute to a company's assets where the director knew or ought to have concluded there was no reasonable prospect of avoiding insolvent liquidation and continued trading.
- Companies Act 2006 (UK), section 171 (duty to act within powers), section 172 (duty to promote the success of the company), and section 174 (duty to exercise reasonable care, skill, and diligence).
- Mata v. Avianca Inc., Case No. 22-cv-01461 (PKC) (SDNY). Order re: sanctions, June 22, 2023 (Judge Kevin P. Castel). Individual sanctions imposed on the lawyers who submitted an AI-generated brief containing fabricated case citations.
- Moffatt v. Air Canada, 2024 BCCRT 149 (BC Civil Resolution Tribunal, February 14, 2024). Company-level liability for an AI chatbot's representations, cited here for contrast with the personal-liability analysis above.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act), Article 26, deployer obligations for high-risk AI systems.