AI Agent Liability: What India Inc Wants Fixed in 2026

Harshvardhan Kothari
By
Harshvardhan Kothari
Harshvardhan kothari, Technology and Policy Correspondent at StartupFeed
Technology and Policy Correspondent
Harshvardhan Kothari is a Technology and Policy Correspondent at StartupFeed. He covers India's AI and deep-tech sector — model releases, AI safety research and the venture...
- Technology and Policy Correspondent
Companies are adding clauses for errors, hallucinations, data breaches and unintended actions as autonomous systems complicate responsibility across the AI chain.

Quick Take

  • Indian companies are rewriting vendor contracts to fix who pays when an AI agent makes a costly mistake.
  • A Shardul Amarchand Mangaldas report on February 28, 2026 found three gaps in India’s AI liability law.
  • India’s AI Governance Guidelines, released February 19, 2026, ask for human oversight of high-impact systems.

Indian companies are asking their lawyers a new question. Who is responsible when an AI agent acts on its own and gets it wrong? The Economic Times reported on September 15, 2026 that firms across India are now seeking clear legal frameworks for this exact problem.

The trigger is agentic AI. These are systems that make decisions and take actions with little or no human sign-off. That autonomy is the whole point of the technology. It is also the reason the old rules no longer fit.

The Economic Times reporting shows companies are already rewriting vendor contracts to fix liability. These contracts now try to spell out who carries the cost of errors, hallucinations, data breaches and unintended actions by AI systems.

Why does agentic AI break the old rules?

Traditional software does what it is told. An AI agent decides what to do. When a normal program fails, the fault usually traces back to a bug or a bad instruction. When an autonomous agent fails, the chain of blame is far less clear.

India’s current laws were not built for this. According to a report from law firm Shardul Amarchand Mangaldas released on February 28, 2026, existing statutes lack precise definitions for the different actors in the AI chain. The report is titled “Reforming India’s AI Liability Regime”.

The Consumer Protection Act, 2019 was written mainly for physical goods. The report notes it does not clearly cover intangible, adaptive software or algorithmic failures like statistical bias. The Information Technology Act, 2000 offers a safe harbour for platforms that merely host content. An AI agent that generates and acts on information is not a passive host.

So the safe harbour logic does not map cleanly onto systems that rank, transform or act on their own. That is the gap founders now have to navigate.

Who is liable, the developer or the deployer?

This is the heart of the debate. The company that builds a model and the company that deploys it are often different businesses. When something goes wrong, both point at each other.

The Shardul Amarchand Mangaldas report proposes a control-based framework. In plain terms, responsibility should match how much control and influence each actor had at each stage. The firm that shapes the output and sells the service carries more risk than a distant model provider.

Legal scholars writing on the same problem describe a similar split of roles across the AI value chain.

ActorRole in the AI chainWhat they control
DeveloperDesigns or trains the modelSafety testing, capability limits
DeployerIntegrates the model into a serviceSector data, approval workflows
OperatorSets the objective for the systemThe task the agent is given
UserPrompts or uses the outputIntent, and any misuse

For a startup, the practical question is simple. Are you the developer, the deployer, or both? Your answer changes where the liability lands. A founder fine-tuning someone else’s model and selling it as a service is a deployer, and deployer risk is the risk most contracts now try to price.

What do India’s AI Governance Guidelines say?

The Government of India unveiled its AI Governance Guidelines on February 19, 2026 at the India AI Summit. The framework puts trust at the centre of AI adoption. It asks that humans keep meaningful control over AI systems wherever that is feasible.

The guidelines stress that adequate human oversight should be built into high-impact systems. Technology should assist human judgment in sensitive contexts, not replace it. This is guidance, not a binding liability statute. It still signals the direction India is heading.

The message for builders is consistent across both documents. Keep a human in the loop, and keep records. The Shardul Amarchand Mangaldas report recommends that documentation support attribution: model cards, evaluation results, incident logs and tool-call records.

Those logs are not just paperwork. In a dispute, they are the evidence that shows what your system did and why. A founder who cannot produce them is arguing from a weak position.

What should founders do now?

Read your vendor contracts. If you buy an AI model from a vendor, check what the contract says about errors, downtime and liability for the agent’s actions. Many vendors offer service-level commitments on uptime while avoiding guarantees on specific outcomes.

Keep your own records. Log what your AI agent does, especially in high-stakes decisions. The Shardul Amarchand Mangaldas report treats this kind of documentation as central to sorting out fault.

Know your role in the chain. A deployer who shapes outputs and directs how a tool is sold cannot claim to be a mere conduit. That distinction, drawn out in legal commentary on Indian AI liability, decides a lot.

The law here is still forming. India has no dedicated AI liability statute yet, and both the report and the guidelines are calls for reform rather than final rules. Founders who build good habits now will be ready when the rules arrive.

What this means for you: Before you ship an AI agent, write down who is liable when it fails, and keep logs that prove what it did.

StartupFeed Insight

The rush to rewrite vendor contracts tells you where the risk really sits. Large enterprises have legal teams to shift liability onto their AI vendors. Early-stage founders selling AI agents are often on the receiving end of those clauses, and they lack the leverage to push back. That is the quiet danger in this shift. A startup that builds an autonomous agent, signs a one-sided contract and keeps no incident logs is carrying risk it never priced. Expect the first serious Indian dispute over an AI agent’s actions to reach a court or regulator within the next 18 months. The founders who logged everything will be glad they did.

— Harshvardhan Kothari, Technology and Policy Correspondent

Frequently Asked Questions

What is agentic AI?+
Agentic AI refers to systems that pursue goals and take actions on their own, with little or no human intervention. Unlike a tool that only responds to a prompt, an agent can decide steps and act. This autonomy is why questions of legal responsibility have become harder to answer.
Does India have an AI liability law?+
India has no dedicated AI liability statute as of September 2026. Existing laws like the Consumer Protection Act, 2019 and the Information Technology Act, 2000 apply in part. A Shardul Amarchand Mangaldas report in February 2026 called for a modern, control-based liability framework built for AI systems.
What is the developer versus deployer question?+
The developer builds or trains the AI model. The deployer integrates it into a service and sells it. When an AI agent causes harm, it is often unclear which party is at fault. A control-based framework assigns responsibility according to how much control each party had over the system.
Why are companies rewriting AI vendor contracts?+
Companies want to fix who pays when an AI agent makes an error. The Economic Times reported in September 2026 that firms are adding clauses covering errors, hallucinations, data breaches and unintended agent actions. The aim is to allocate risk clearly before an autonomous system causes a costly problem.
What should a startup founder do about AI liability?+
Read vendor contracts closely, keep detailed logs of what your AI agent does, and know whether you are a developer or a deployer. India’s AI Governance Guidelines ask for human oversight of high-impact systems. Good documentation is the strongest defence in any future dispute over an agent’s actions.

Have a tip? Write to us at editorial@startupfeed.in.

Liked this story? Follow StartupFeed on Google so our reporting reaches you first.

Follow StartupFeed on Google News
Harshvardhan kothari, Technology and Policy Correspondent at StartupFeed
Technology and Policy Correspondent
Follow:
Harshvardhan Kothari is a Technology and Policy Correspondent at StartupFeed. He covers India's AI and deep-tech sector — model releases, AI safety research and the venture funds backing the category — alongside the regulation shaping it, including MSME law, e-commerce export rules and cross-border trade policy. He also tracks India's IPO pipeline and startup public-market debuts.