Quick Take
- Indian companies are rewriting vendor contracts to fix who pays when an AI agent makes a costly mistake.
- A Shardul Amarchand Mangaldas report on February 28, 2026 found three gaps in India’s AI liability law.
- India’s AI Governance Guidelines, released February 19, 2026, ask for human oversight of high-impact systems.
Indian companies are asking their lawyers a new question. Who is responsible when an AI agent acts on its own and gets it wrong? The Economic Times reported on September 15, 2026 that firms across India are now seeking clear legal frameworks for this exact problem.
The trigger is agentic AI. These are systems that make decisions and take actions with little or no human sign-off. That autonomy is the whole point of the technology. It is also the reason the old rules no longer fit.
The Economic Times reporting shows companies are already rewriting vendor contracts to fix liability. These contracts now try to spell out who carries the cost of errors, hallucinations, data breaches and unintended actions by AI systems.
Why does agentic AI break the old rules?
Traditional software does what it is told. An AI agent decides what to do. When a normal program fails, the fault usually traces back to a bug or a bad instruction. When an autonomous agent fails, the chain of blame is far less clear.
India’s current laws were not built for this. According to a report from law firm Shardul Amarchand Mangaldas released on February 28, 2026, existing statutes lack precise definitions for the different actors in the AI chain. The report is titled “Reforming India’s AI Liability Regime”.
The Consumer Protection Act, 2019 was written mainly for physical goods. The report notes it does not clearly cover intangible, adaptive software or algorithmic failures like statistical bias. The Information Technology Act, 2000 offers a safe harbour for platforms that merely host content. An AI agent that generates and acts on information is not a passive host.
So the safe harbour logic does not map cleanly onto systems that rank, transform or act on their own. That is the gap founders now have to navigate.
Who is liable, the developer or the deployer?
This is the heart of the debate. The company that builds a model and the company that deploys it are often different businesses. When something goes wrong, both point at each other.
The Shardul Amarchand Mangaldas report proposes a control-based framework. In plain terms, responsibility should match how much control and influence each actor had at each stage. The firm that shapes the output and sells the service carries more risk than a distant model provider.
Legal scholars writing on the same problem describe a similar split of roles across the AI value chain.
| Actor | Role in the AI chain | What they control |
|---|---|---|
| Developer | Designs or trains the model | Safety testing, capability limits |
| Deployer | Integrates the model into a service | Sector data, approval workflows |
| Operator | Sets the objective for the system | The task the agent is given |
| User | Prompts or uses the output | Intent, and any misuse |
For a startup, the practical question is simple. Are you the developer, the deployer, or both? Your answer changes where the liability lands. A founder fine-tuning someone else’s model and selling it as a service is a deployer, and deployer risk is the risk most contracts now try to price.
What do India’s AI Governance Guidelines say?
The Government of India unveiled its AI Governance Guidelines on February 19, 2026 at the India AI Summit. The framework puts trust at the centre of AI adoption. It asks that humans keep meaningful control over AI systems wherever that is feasible.
The guidelines stress that adequate human oversight should be built into high-impact systems. Technology should assist human judgment in sensitive contexts, not replace it. This is guidance, not a binding liability statute. It still signals the direction India is heading.
The message for builders is consistent across both documents. Keep a human in the loop, and keep records. The Shardul Amarchand Mangaldas report recommends that documentation support attribution: model cards, evaluation results, incident logs and tool-call records.
Those logs are not just paperwork. In a dispute, they are the evidence that shows what your system did and why. A founder who cannot produce them is arguing from a weak position.
What should founders do now?
Read your vendor contracts. If you buy an AI model from a vendor, check what the contract says about errors, downtime and liability for the agent’s actions. Many vendors offer service-level commitments on uptime while avoiding guarantees on specific outcomes.
Keep your own records. Log what your AI agent does, especially in high-stakes decisions. The Shardul Amarchand Mangaldas report treats this kind of documentation as central to sorting out fault.
Know your role in the chain. A deployer who shapes outputs and directs how a tool is sold cannot claim to be a mere conduit. That distinction, drawn out in legal commentary on Indian AI liability, decides a lot.
The law here is still forming. India has no dedicated AI liability statute yet, and both the report and the guidelines are calls for reform rather than final rules. Founders who build good habits now will be ready when the rules arrive.
What this means for you: Before you ship an AI agent, write down who is liable when it fails, and keep logs that prove what it did.
StartupFeed Insight
The rush to rewrite vendor contracts tells you where the risk really sits. Large enterprises have legal teams to shift liability onto their AI vendors. Early-stage founders selling AI agents are often on the receiving end of those clauses, and they lack the leverage to push back. That is the quiet danger in this shift. A startup that builds an autonomous agent, signs a one-sided contract and keeps no incident logs is carrying risk it never priced. Expect the first serious Indian dispute over an AI agent’s actions to reach a court or regulator within the next 18 months. The founders who logged everything will be glad they did.
— Harshvardhan Kothari, Technology and Policy Correspondent
Frequently Asked Questions
Have a tip? Write to us at editorial@startupfeed.in.



