When AI agents misbehave, who pays—and what skills do we need?

As AI agents move into everyday workflows, liability isn’t just a legal puzzle—it’s a question of how we redesign work, oversight, and skills.

AI agents are no longer confined to drafting suggestions. They send emails, place orders, negotiate with customers, deploy code, and trigger real-world processes. As this “software that acts” becomes routine, a deceptively simple question turns urgent: when an agent makes a costly mistake—or causes harm—whose mistake is it? Wherever the answer is fuzzy, organizations either slow adoption or bury risk in corners of the org chart. The future of work is being shaped inside that ambiguity. In MIT Technology Review’s explainer, the core argument is that our liability instincts were built for conventional software—tools with predictable boundaries and clear operators. Agents break that mold. Their behavior emerges from models, prompts, tools, integrations, and context. A long chain of actors influences outcomes: model developers, API providers, agent platforms, system integrators, the business unit that deploys the agent, and the people who rely on it. Everyone has a hand on the wheel, yet no one fully controls the route. The piece also underscores why existing legal and compliance frameworks can struggle with this distributed reality. Was the harm foreseeable? Were safeguards reasonable? Did the organization maintain logs, audits, and approval gates for high-stakes actions? In theory, these questions help allocate responsibility. In practice, many teams lack technical visibility into agent decision paths, lack mature operating processes, and lack clearly defined roles. The predictable result is a surge in contractual blame-shifting—useful, but insufficient when failures arise from complex socio-technical interaction rather than one “bad component.” From Başlangıç Noktası’s tech-for-good lens, this is not merely a “who’s at fault” debate; it’s a work-design challenge aimed at preventing harm before it happens. Agents can unlock productivity, but when safety is treated as overhead, the costs are often paid by workers, customers, and vulnerable groups. That’s why the skills agenda is bigger than learning new tools. We need agent oversight, model-behavior monitoring, security threat modeling, process redesign, auditability by default, data minimization, and incident response. Many organizations will need something like “agent operations” disciplines that distribute responsibility through systems, not scapegoats through individuals. There’s a further blind spot: if liability is discussed only in the language of enterprise risk and regulation, power imbalances can disappear from view. Smaller businesses, nonprofits, and public service teams rarely have the same governance capacity as large firms, yet they may be pushed toward the same agentic tooling. And “human-in-the-loop” is not a magic fix: if approvals are poorly designed, workers become rubber stamps. Real safety comes from clearer authority boundaries, simpler decision points, and measurement-and-training that catches failure early. A few questions to sit with: Do you have a permissions matrix for what agents may do—or is everything hiding behind a single API key? If something goes wrong, can you reconstruct the chain of events with logs and audits that people actually review? And most importantly, will “managing agents” remain a side task, or become a core professional skill across roles? Read the full piece at MIT Technology Review Source: MIT Technology Review — Who’s liable when AI agents go rogue?. Read the full piece: https://www.technologyreview.com/2026/09/28/1145197/whos-liable-wh…