Agentic AI. Non-Agentic Liability.
Most boards have not made a conscious decision to deploy agentic AI. They have made decisions to accelerate AI adoption — and agentic capabilities arrived embedded in the tools that were purchased and the workflows that were automated. The governance threshold was crossed without anyone marking the moment. Agentic AI does not produce output for a human to review. It receives a goal and pursues it: booking meetings, executing purchases, sending communications, committing to contracts — autonomously, without pausing for human approval between steps. That changes the liability question from "who approved the decision" to "who authorised the agent." In March 2026, the UK CMA confirmed that businesses are responsible for what an AI agent does in the same way they are responsible for what an employee does. California AB 316, effective January 2026, explicitly bars the "the AI acted autonomously" defence in civil proceedings. The EU Product Liability Directive, applying from December 2026, extends strict liability to AI systems — and treats their continuous learning as a potential product defect. This article examines how the liability architecture has changed, who in the organisation actually built the agent and holds the risk, and five actions boards should take before an incident forces the question.
Most of the AI your organisation has deployed so far is advisory. It analyses documents, summarises meetings, drafts communications, models scenarios, and flags risks. A human reads the output and decides what to do. That structure is legally familiar — the AI is a tool, and the human who acts on its output is accountable for the decision, much as they would be accountable for acting on a consultant's recommendation or a spreadsheet's projection.
Agentic AI is categorically different — and the distinction matters enormously for how liability attaches to your organisation.
An AI agent does not produce output for a human to review. It receives a goal and pursues it autonomously: breaking the goal into steps, deciding which tools to use, calling external systems and APIs, reading and writing data, and taking actions in the world — all without pausing for human approval between steps. It acts, observes the result, adjusts, and continues until the goal is achieved or it encounters a boundary it cannot cross.
What this looks like in practice is worth making concrete, because the scale and scope of what agents can execute is not widely understood outside technical teams:
Drafts a supplier contract summary for a procurement manager to review. The manager reads it, makes changes, and approves. The AI influenced the output; a human made the decision.
為採購部門起草供應商合約摘要,由相關人員審閱修改後核准。AI影響輸出內容,但決策權仍在人的手中。
Receives the goal "complete the quarterly supplier review." Autonomously pulls contracts from the document system, cross-references payment records, drafts the summary, schedules the review meeting, and sends calendar invitations — before any human has seen a draft.
接收「完成季度供應商審查」的目標後,自主從文件管理系統提取合約、比對付款紀錄、起草審查摘要、排定相關會議並發出邀請——整個過程無需任何人工審閱即已完成。
The examples multiply across every business function. A financial agent adjusts ad spend allocation, reallocates budget across platforms, and commits expenditure — in real time, faster than any approval cycle. A procurement agent initiates purchase orders, negotiates standard terms, and commits to supplier agreements within predefined parameters. A customer service agent processes refund requests, modifies account terms, and makes commitments to customers on the organisation's behalf. An HR agent screens candidates, sends rejection communications, and schedules interviews — each action carrying legal implications the agent was not designed to reason about.
And increasingly, organisations are deploying not one agent but networks of them: an orchestrating agent that breaks a complex goal into subtasks, specialist agents that execute each component, and integration agents that pass outputs between systems. By the time the final action is taken, the chain of autonomous decisions leading to it may have involved dozens of steps across multiple systems — none reviewed by a human.
This is the governance threshold. When AI advises, the liability question is: who approved the decision? That question has a human answer. When AI acts, the liability question becomes: who authorised the agent? That is an organisational answer — and in most organisations today, it has not been given at the level it requires.
目前多數企業部署的AI,仍以建議型工具為主:分析文件、摘要會議、起草文字、模擬情境、標記風險。最終由人讀取輸出並做出決策。此一結構在法律層面並無陌生之處——AI作為工具,根據其輸出採取行動的決策者對後果負責,一如依據顧問建議或財務模型作出決定的情形。
代理型AI的運作邏輯根本不同。
AI代理接收的不是「請分析這份文件」,而是「請完成這項任務」。代理自主地將目標拆解為步驟,決定調用哪些工具、存取哪些系統、讀寫哪些資料,在真實的業務環境中連續執行一系列動作——步驟之間無需等待任何人工審核。代理行動、觀察結果、自我調整、持續推進,直至目標達成或抵達無法跨越的邊界。
有必要將代理的執行能力說得更為具體,因為在技術團隊以外,這一能力的規模與範圍普遍未獲充分認識。財務代理可在即時環境中調整廣告投放配置、跨平台重新分配預算、提交支出承諾,速度遠超任何審批週期。採購代理可發起採購訂單、依標準條款完成協商、在預設參數內對供應商作出承諾。客戶服務代理可處理退款申請、修改帳戶條款、以企業名義向客戶作出允諾。人力資源代理可篩選應徵者、發送拒絕通知、安排面試——每一項動作均涉及法律意涵,而代理本身並未被設計成能夠推理這些意涵。
進一步而言,諸多企業部署的並非單一代理,而是代理網絡:統籌代理將複雜目標拆解為子任務,專項代理分頭執行各環節,整合代理在系統之間傳遞輸出。待最終行動完成時,驅動它的那條自主決策鏈,可能已橫跨多個系統、涵蓋數十個步驟,其中沒有任何一個步驟經過人工審閱。
此即建議型AI與代理型AI之間的治理門檻所在。建議型AI的責任問題是:誰批准了這項決定?那個問題有一個明確的人的答案。代理型AI的責任問題則轉變為:誰授權了這個代理?那是一個組織層面的答案——而在當前多數企業中,這個問題從未在應有的決策層級被認真回答過。
The legal response to agentic AI is forming faster than most boards realise — and it is forming, as with AI generally, under existing law rather than new AI-specific statutes. Three developments in the past six months define the emerging framework.
法律層面對代理型AI的回應,形成速度遠超多數董事會的預期。與整體AI治理的演進規律一致,相關回應並非仰賴AI專法的到來,而是在既有法律框架下直接展開。過去六個月,四項重要發展勾勒出正在成形的責任架構。
The CMA published binding enforcement guidance stating explicitly that businesses are responsible for what an AI agent does in the same way they are responsible for what an employee does — including where a third party built or provides the agent. The guidance applies existing consumer protection law to agentic deployments with no new statute required. Fines of up to 10% of global annual turnover are available under the Digital Markets, Competition and Consumers Act 2024. The CMA separately warned that AI agents independently optimising pricing decisions can produce coordinated market outcomes — creating antitrust exposure for organisations even without any human intent to fix prices.
英國競爭與市場管理局(CMA)於2026年3月9日發布具約束力的執法指引,明確指出:企業對AI代理行為所負之責任,等同於對員工行為所負之責任——即便該代理係由第三方建立或提供。本指引並未創設新法,而是將現行消費者保護法的既有要求直接適用於代理型AI部署。依2024年《數位市場、競爭與消費者法》,違規企業最高可被處以全球年營業額10%之罰款。CMA另行警示:各自獨立優化定價決策的AI代理,在無任何人為協議的情況下,可能經由相互學習而達致相同的市場均衡,從而使企業面臨反壟斷責任——即便企業從未有意為之。
California has enacted legislation that explicitly closes the "the AI acted autonomously" defence. Companies and individuals who developed, modified, or used AI cannot assert the AI's autonomous action as a defence in civil proceedings seeking to hold them liable for harm caused by it. The organisation that deployed the agent is the responsible party — full stop. This is the first US statute to address agentic AI liability directly, and it is already in force.
加州AB 316於2026年1月1日正式生效,明確封堵「AI係自主行動,非企業所為」此一抗辯路線。無論係AI之開發者、修改者抑或使用者,在任何因AI造成損害之民事訴訟中,均不得以AI之自主性主張免責。部署代理之機構即為責任方,無一例外。此為美國首部直接針對代理型AI責任之成文法,且已付諸實施。
A federal judge in San Francisco issued a preliminary injunction blocking Perplexity's Comet AI agent from accessing Amazon user accounts — even though users had explicitly authorised Comet to act on their behalf. Amazon sued under the 1986 Computer Fraud and Abuse Act, alleging that Perplexity's agent disguised itself as a regular Chrome browser to evade detection. The court found Amazon had "strong evidence" of unauthorised access and ordered data destruction. The question at the centre of this case — when an AI agent acts on a user's authority, can a platform refuse that agent access regardless? — is being answered in litigation right now, under a statute that predates the internet as we know it. The answer will shape the authority boundaries of every enterprise agent deployment.
2025年11月,亞馬遜對Perplexity提起聯邦訴訟,指控其Comet AI代理在存取亞馬遜平台時將自身偽裝成普通瀏覽器工作階段以規避偵測。2026年3月10日,舊金山聯邦法院就本案發出初步禁令,禁止Comet存取亞馬遜用戶帳戶——儘管用戶本人已明確授權Comet代其執行購物操作。法院援引的是1986年制定的《電腦欺詐與濫用法》,一部早於現代網際網路問世的法律。此案的核心法律問題——用戶授權代理代為行事,平台能否拒絕該代理的存取——正在訴訟程序中逐步形成答案。本案裁決結果,將為企業代理部署的授權邊界確立早期司法先例。
The revised EU Product Liability Directive explicitly extends strict product liability to software and AI systems. From December 2026, if an AI system is found to be defective, the developer and deployer face liability regardless of fault. Critically, the Directive specifically addresses AI's capacity to learn after deployment: an AI system's continuous learning and adaptation can itself constitute a product defect. For agentic AI — whose core value proposition is precisely that it learns and adapts — this creates a strict liability exposure that persists and potentially grows throughout the system's operational life. Note: the separate EU AI Liability Directive was withdrawn by the European Commission in February 2025. The PLD is doing the liability work instead, and its reach is broader.
歐盟修訂版產品責任指令(2024年通過,2026年12月9日生效)明確將軟體與AI系統納入嚴格產品責任的規範範疇。自生效日起,凡AI系統被認定存在缺陷,開發者與部署方無論有無過失均需承擔責任。指令特別處理了AI於上線後持續學習之特性,明確指出:AI系統在部署後的持續學習與自我調適,本身即可構成產品缺陷。對代理型AI而言——其核心價值主張恰在於持續學習與自主適應——此意味著嚴格責任之曝險將在系統整個運作生命週期中持續存在,且可能持續累積。另須說明:歐盟委員會已於2025年2月撤回原另行起草之AI責任指令,產品責任指令成為承擔相關責任規範工作之主要機制,其適用範圍較原擬議之AI責任指令更為廣泛。
The pattern is the same as the broader AI enforcement landscape: no AI-specific statute required. The deploying organisation is accountable, under existing law, for what its agents do in the world.
四項發展,涵蓋四個不同司法管轄區,援引的均為既有法律,無一需要AI專法。部署代理之機構,須對代理之一切行為承擔法律責任。
The cases above are not isolated incidents. They reflect a structural shift in how liability attaches to AI use — a shift that the advisory AI era did not require boards to confront.
When AI advises, liability flows from decisions. Someone reviewed the AI's output and acted on it. The liability chain runs from the harm backward through the decision to the decision-maker. That chain is familiar — it is how negligence, fiduciary duty, and professional accountability have always worked.
When AI acts, liability flows from authorisation. Nobody reviewed each action before it was taken. The liability chain runs backward not to a decision, but to the scope of authority the organisation gave the agent — in its system prompt, in its permission settings, in the access credentials it was granted. The moment of legal significance is not when the agent executed. It is when someone decided what the agent was permitted to do.
Three specific exposures follow from this shift that did not exist — or did not exist at this scale — in the advisory AI era.
上述案例並非孤立事件,而是一項結構性轉變的早期訊號——建議型AI時代從未迫使董事會正視的轉變。
建議型AI的責任追溯,本質上是一道溯源題:從損害回溯至決定,再回溯至決策者。此一鏈路,傳統過失責任、受託義務與專業問責框架均能有效處理。
代理型AI的情形截然不同。責任追溯所指向的,不是某一項具體決定,而是企業賦予代理的授權範圍——體現於系統提示詞的內容、權限配置的設定,以及存取憑證的授予。具有法律意義的關鍵時刻,不在代理執行行動之際,而在授權範圍被確立之時。
由此衍生出三類在建議型AI時代幾乎不存在——或未以此規模存在——的具體法律曝險。
The scope of authority as the new governance document. Every boundary you define for an AI agent — what systems it can access, what it can commit to, what it can spend, what it can communicate on your behalf — is a legally consequential governance decision. If the agent acts within that scope and causes harm, you authorised the harm. If the agent acts beyond its defined scope, you may still be bound: if a third party reasonably relied on the agent's apparent authority, that reliance can create obligation regardless of your internal limitations. The permission scope you set for your agents is functionally equivalent to a board resolution on authority — and in most organisations, it was written by an engineer.
授權範圍即治理文件。企業為AI代理劃定的每一條邊界——可存取哪些系統、可作出哪些承諾、可動用多少支出、可以企業名義傳達何種資訊——均構成具有法律效力的治理決定。代理在授權範圍內行事並造成損害,即意味著企業對該損害負有授權責任。代理超出授權範圍,企業仍可能受到約束:若第三方基於代理的表見授權合理信賴而行事,此種信賴足以產生法律義務,無論企業內部設定了何種限制。就功能而言,企業為代理設定的權限範圍,等同於一份關於授權事項的董事會決議——而在多數企業,此文件係由工程師於技術配置過程中寫就。
The liability gap in multi-agent systems. When Agent A instructs Agent B which instructs Agent C which executes a transaction, the chain of authority becomes genuinely difficult to trace. The EU Law Commission has explicitly noted that multi-agent architectures create liability gaps where "no natural or legal person is liable for the harms caused by or the conduct of an AI system" — particularly in complex cross-border supply chains. Existing law was not designed for distributed autonomous decision-making. It is being stretched across architectures it was never intended to cover, and the gaps are real. The organisation that deployed the network is the responsible party externally. Who is accountable internally is often genuinely unclear.
多代理系統的責任缺口。代理A指示代理B,代理B指示代理C,代理C執行一筆交易——待最終行動完成,授權鏈條已難以清晰追溯。歐盟法律委員會明確指出,多代理架構會產生責任缺口,在跨境複雜供應鏈情境中尤為顯著,可能出現「任何自然人或法人均不對AI系統所造成之損害或行為承擔責任」的情形。現行法律從未設計用以涵蓋分散式自主決策架構,強行套用之下,缺口確實存在。對外而言,部署代理網絡之企業為責任方;對內而言,責任應由誰承擔,往往缺乏清晰的答案。
Algorithmic collusion without human intent. AI agents independently optimising pricing or commercial strategy can reach the same market equilibrium as competitors' agents — producing coordinated outcomes without any communication or human decision to collude. Antitrust liability that has historically required a human agreement can now emerge from autonomous systems learning to behave identically. The CMA's March 2026 guidance specifically flags this risk, and organisations using the same pricing algorithms as competitors are on notice. The fact that no human made a decision to collude is not a defence.
演算法共謀:無需人為協議的競爭法風險。各自獨立優化定價策略的AI代理,可能在無任何溝通或人為決策介入的情況下,與競爭對手的代理達致相同的市場均衡,產生協調一致的定價結果。傳統競爭法責任以人為協議之存在為前提,而此前提可能因自主系統相互學習而遭到繞過。CMA 2026年3月指引已明確點名此項風險。採用與競爭對手相同定價演算法之企業須知:從未存在共謀意圖,並不構成免責依據。
Agents are built by people. Understanding who those people are — and how accountability diffuses across the chain — is essential for any board that wants to close the governance gap before an incident closes it for them.
A typical enterprise agentic AI deployment involves five distinct layers of human decisions. External liability lands on the deploying organisation for all of them. Internal accountability is assigned to none of them.
代理由人建造,至少在現階段如此。填補治理缺口的前提,是釐清相關人員的角色構成,以及問責如何沿著鏈條逐層擴散,最終落入真空。
一個典型的企業代理型AI部署,涉及五個層次的人的決定。對外,法律責任全部壓在部署機構身上。對內,這五層沒有任何一層被明確指定為問責對象。
Provides the reasoning capability that powers the agent. Responsible for the model's baseline behaviour, safety guardrails, and the terms under which it operates. Their liability is contractually limited — typically to subscription fees — and their terms of service disclaim fitness for specific purposes. They are the foundation, but they are the furthest from the consequence.
提供代理之推理能力,對模型的基線行為、安全護欄及使用條款負責。其合約責任受嚴格限制,通常不逾訂閱費金額,且服務條款免除特定用途之適用性保證。模型供應商為整條鏈條之起點,卻與最終後果相距最遠。
Builds the scaffolding that turns a model into an agent: the tool-calling architecture, memory systems, orchestration logic. This layer is almost entirely invisible to boards and legal teams — yet it determines the structural limits of what the agent can do and how failures propagate. Vendor terms similarly disclaim liability.
建立將模型轉化為代理之基礎架構,包括工具呼叫機制、記憶體系統及任務協調邏輯。此層對董事會及法務團隊幾乎完全不可見,卻決定了代理的能力邊界與失靈傳播路徑。相關供應商條款同樣免除責任。
Engineers, data scientists, and sometimes external consultants who wrote the system prompt, defined the tool permissions, set the scope of what the agent can access and do, and connected it to live systems. The system prompt is a policy document — it defines what the agent is authorised to represent on your organisation's behalf, what it is prohibited from doing, and how it presents its outputs. In virtually no organisation has that document been reviewed by legal or compliance before deployment. The permission scope is an authorisation decision that in any other context would require executive sign-off. Here it is a technical configuration choice made by an engineer on a Tuesday afternoon.
工程師、資料科學家,有時輔以外部顧問,負責撰寫系統提示詞、定義工具權限、設定存取與執行範圍,並將代理接入正式系統。系統提示詞實為政策文件,定義代理獲授權以企業名義陳述何事、執行何種行動、受何種限制。在幾乎所有企業,此份文件在部署前從未經法務或法遵部門審閱。從實質內容看,授權範圍的設定在任何其他情境均需高層核簽;在此,它僅是工程師於技術配置過程中所作的選擇。
The VP or director-level person who said "build me an agent that handles this workflow." They defined the goal and approved deployment. In most organisations this is not treated as a governance decision — it is treated as a productivity initiative. The business owner rarely has visibility into what the agent was actually configured to do, what systems it can access, or what liability the organisation assumed when it went live.
提出「建立一個能自動處理此流程之代理」需求的副總裁或總監級人員,負責定義目標並核准部署。在多數企業,此舉被視為提升營運效率的業務決定,而非治理決定。相關業務負責人通常對代理的實際配置內容、可存取之系統範圍,以及企業因此承擔之責任,掌握甚少。
The board and CEO who set the AI adoption strategy, approved the budget, and sanctioned the deployment environment. Under CMA guidance, California AB 316, and the EU Product Liability Directive, this is where external liability lands — on the organisation. But in most cases, leadership had no visibility into what agents were deployed, what they were authorised to do, or what liability was assumed. The external accountability is clear and enforced. The internal accountability chain runs from the legal consequence at Layer 5 directly to a decision made at Layer 3 by someone who was never told it was a governance decision.
制定AI採用策略、核准相關預算並批准部署環境的董事會與執行長。依CMA執法指引、加州AB 316及歐盟產品責任指令,對外法律責任全部落於企業身上。然而在多數情形下,領導層對已部署之代理、其授權內容及企業所承擔之責任,幾乎毫無掌握。對外問責鏈路清晰且具強制執行力;對內問責鏈路則從第五層的法律後果往回追溯,直接指向第三層某位人員所作的技術配置選擇——而該人員從未被告知,彼等所作之決定具有治理意涵。
This is the accountability vacuum. Nobody along the chain from model provider to deploying organisation has been clearly assigned responsibility for the agent's real-world consequences. The model provider disclaims it. The framework developer disclaims it. The internal engineer treated it as a technical build. The business owner treated it as an operational decision. Leadership has no visibility into any of it — but holds all the external liability.
此即問責真空之樣貌。自模型供應商至最終部署企業,整條鏈條中沒有任何一個環節被明確指定須對代理的現實後果負責。供應商免除責任,框架開發商亦然;工程師將其視為技術建構作業,業務負責人將其視為效率提升措施;企業領導層對上述一切幾乎毫無掌握——卻承擔了全部對外法律責任。
The governance gap that agentic AI creates is not a technology problem. It is closed by asking questions that only leadership has the authority and visibility to demand answers to — and insisting on complete, documented responses.
代理型AI的治理缺口,本質上不是技術問題。填補此缺口,有賴於在適當層級提出相應問題,並要求以書面形式作出完整回應——此類問題,唯有領導層方具備追問的權威與立場。
1. What agents do we have, and what have we authorised them to do? Before governing your agents, you need to know what agents you have. In most organisations, agentic deployments have accumulated across business units without central visibility. Can your organisation produce a complete inventory of every AI agent in operation — what systems each can access, what actions each can take, and what spending authority or commitment-making capacity each has been granted? If the answer is no, that is itself the most important governance finding.
一、企業目前部署了哪些代理,各自獲授權執行哪些事項?有效治理的前提,是掌握代理部署的全貌。現實情況是,代理型部署正在各業務單位分散累積,缺乏統一的集中可見性。企業能否提供一份完整清單,涵蓋每一個正在運作的AI代理、其可存取之系統範圍、可採取之行動類型,以及獲授予之支出權限或承諾訂立能力?若答案為否,此即當前最重要的治理發現。
2. Where does our agent's authority end? The Amazon v. Perplexity case is not just about one company's shopping agent. It raises a question every enterprise deploying agents must be able to answer: what are the explicit boundaries of what our agents can do — and have those boundaries been set deliberately, by someone with the authority to set them, and documented in a form that can be audited? The line between autonomous and supervised action is a governance decision. Has it been drawn?
二、代理的授權邊界在哪裡,由誰劃定?亞馬遜訴Perplexity一案並不僅關乎某家企業的購物代理,其所提出的,是每一家部署代理的企業遲早必須面對的問題:代理的行動邊界在哪裡?該邊界是否由具備相應授權之人員,經審慎考量後,以可接受稽查的方式明確劃定?哪些行動可由代理自主執行,哪些須經人工確認——此為治理決定,而非技術預設值。企業現行部署中,這條線是否已被明確劃定?
3. Has anyone with legal accountability reviewed what our agents are authorised to say and do? The system prompt that governs each agent is the document that most directly determines your organisation's liability exposure. Has legal or compliance reviewed it? Has it been treated as a governed policy document with version control and change management — or as a technical file that engineers update as needed? If the latter, the gap between the governance framework and the governance reality is not abstract. It is an unreviewed authorisation document operating in a live system.
三、代理的系統提示詞是否已接受法律與治理層面的審查?每一份系統提示詞,均為最直接決定企業法律曝險的文件——它定義代理獲授權以企業名義陳述何事、執行何種行動、受何種限制。法務或法遵部門是否曾審閱此文件?相關文件是否以受管政策文件的規格對待,設有版本控制機制並遵循變更管理程序?抑或僅作為工程師視需要修改的技術配置檔案?若為後者,治理框架與現實之間的落差並非抽象概念,而是一份未經具備法律問責責任之人員審閱的授權文件,正在正式生產系統中運作。
4. Who is the named accountable executive for each material agent deployment? Not the engineer who built it. Not the vendor who provides the underlying model. An executive who owns the agent's consequences — who will be the first point of internal accountability if the agent causes harm, creates a contractual obligation the organisation did not intend, or generates a regulatory incident. The law assigns external accountability to the organisation. Internal accountability, in most organisations, remains unassigned. Naming it is not a technology decision. It is a governance act.
四、每項重大代理部署,是否已指定具名之問責高管?所指並非建立代理之工程師,亦非提供底層模型之供應商,而是一位對代理後果承擔責任的資深主管——一旦代理造成損害、訂立非預期之合約義務或引發監管事件,此人為內部問責之首要接觸點。法律對對外問責之歸屬表述清晰;而對內問責在多數企業至今仍懸而未決。指定此人,並非技術決定,而是治理行動。
The governance gap that agentic AI creates is not difficult to close. It is simply not being closed, because the decisions required have not been recognised as governance decisions. Five actions will close most of it — none of them require a technology project.
前述治理缺口,填補並非難事。其之所以迄今未獲填補,原因在於所需之相關決定,至今仍未被視為治理決定加以對待。以下五項行動可填補大部分缺口,且無一需要啟動技術專案。
Before governing what your agents are authorised to do, establish what agents you have. A board-commissioned inventory — every agent in operation, what systems it accesses, what actions it can take, who commissioned it, and who currently owns it — is the baseline for every other governance decision. This is not an IT audit. It is a governance act, and it needs to be treated as one: resourced appropriately, completed on a defined timeline, and reported to the board.
有效治理的基礎在於可見性。在多數企業,代理型部署已在各業務單位分散累積,缺乏集中的統一掌握。由董事會授權並跨部門執行的清查——涵蓋每一個正在運作之代理、其存取之系統範圍、可採取之行動類型、委託建立之來源及現行負責人員——是所有後續治理決定的必要基礎。此舉並非IT稽核,而是治理行動,須配置適當資源,設定明確時程,並建立向董事會報告之機制。
Define, at board or executive committee level, which categories of consequential action an AI agent may take autonomously and which require human approval before execution. Financial commitments above a defined threshold. External communications that bind the organisation. Decisions affecting individual employees or customers. Actions in regulated domains. The line between autonomous and supervised action is a governance decision that carries legal weight — it defines the scope of what your organisation has authorised. It needs to be drawn explicitly, documented, and enforced.
由董事會或執行委員會明確界定:哪些類別的重大行動可由代理自主執行,哪些須在執行前取得人工確認。相關類別包括但不限於:逾越特定門檻之財務承諾、以企業名義具約束力之對外溝通、涉及個別員工或客戶之決策,以及受監管業務領域之行動。此授權邊界具有實質法律效力,須以書面形式明確記錄,並以可接受稽查之方式付諸執行。
Every agent your organisation operates has a system prompt — a document that defines what the agent is authorised to represent, commit to, and do on your behalf. Require that system prompts for material agent deployments be reviewed by legal and compliance before deployment, treated as governed policy documents with version control thereafter, and subject to the same change management discipline as any other document that defines organisational authority. In most organisations, no lawyer has ever read a system prompt. That needs to change.
重大代理部署之系統提示詞,須於部署前完成法務與法遵審查,一如任何其他定義企業授權事項之文件。上線後,應作為受管政策文件進行版本控制,任何變更均須遵循正式的變更管理程序,不得由技術人員逕行修改。在多數企業,律師從未閱讀過系統提示詞。此種情況須即刻改變。
The Workday precedent established that deploying an AI tool does not transfer liability to the vendor. Research by Stanford CodeX found that 92% of AI vendor contracts claim broad data usage rights while only 17% commit to regulatory compliance. Before your agents create a consequence your vendor contracts cannot remedy, audit the indemnification and liability allocation terms in your AI vendor agreements — specifically for agentic deployments where the agent has authority to act, not merely advise. Standard procurement review was not designed to catch these gaps. A governance-level contract review is required.
Workday案已確立,部署AI工具並不能將法律責任轉移至供應商。史丹佛大學CodeX法律科技中心的研究指出,92%的AI供應商合約主張廣泛之數據使用權,僅17%就遵守監理法規作出承諾。在代理製造出無法透過合約機制補救之後果之前,應主動審查AI供應商協議中關於賠償責任分配之條款——尤其是涉及代理具備行動授權而非僅提供建議之部署情境。標準採購審查程序並非針對此類缺口而設計,所需者係治理層級之合約審查,而非例行合規核查。
For each material agentic deployment, name an accountable executive — not the engineer who built it, but a senior leader who owns its consequences. That person should be able to answer all four questions in the previous section at any time. They should be the first point of contact in the event of an agent incident. And their accountability should be documented formally, reviewed periodically, and updated when agent scope changes. The law is clear about where external accountability lands. Make the internal accountability chain equally clear — before an incident makes it a crisis management exercise rather than a governance one.
每項重大代理部署,均須指定一位具名之問責高管——非建立代理之工程師,而是對代理後果承擔責任之資深主管。此人須能隨時回答前述四項問題;一旦代理引發事件,須作為內部問責之首要接觸點;其問責責任須以書面正式記錄,定期審查,並於代理授權範圍發生變更時同步更新。法律對對外問責之歸屬已有清晰表述。宜趁問責鏈條尚屬治理議題、尚未演變為危機管理事件之際,以同等清晰度確立對內問責架構。
Most boards have not made a conscious decision to deploy agentic AI. They have made decisions to accelerate AI adoption — and agentic capabilities arrived embedded in the tools that were purchased, the platforms that were adopted, and the workflows that were automated. The governance threshold was crossed without anyone marking the moment.
That is the characteristic governance failure of this technology: not recklessness, but invisibility. The liability exposure exists because consequential decisions were made at a level of the organisation that did not recognise them as governance decisions. The legal frameworks that enforce accountability — CMA guidance, California AB 316, the EU Product Liability Directive — do not ask whether the board knew. They ask whether the organisation deployed the agent.
The organisations that will navigate agentic AI liability most effectively are not those with the most sophisticated AI systems. They are those where leadership has answered the authority question — clearly, on the record, before an agent's actions force the question in circumstances that are no longer within their control.
Advisory AI changed how decisions are made. Agentic AI changes who — or what — makes them. The governance response to that change is not a technology project. It is a leadership decision about what your organisation has authorised to act in its name.
多數董事會從未作出「部署代理型AI」的明確決定。董事會作出的,是「加速AI採用」的決定——代理能力隨採購的工具、引進的平台、自動化的流程一同到來。治理門檻就此被跨越,無人標記那個時刻。
此係代理型AI特有的治理失靈模式:非源於無知,非源於輕率,而是源於不可見性。重大的授權決定在組織的某一層級被作出,而該層級從未意識到彼等所作者係授權決定。CMA執法指引、加州AB 316、歐盟產品責任指令——上述執法框架並不詢問董事會是否知情,其所追問的只有一件事:企業是否部署了代理?
在代理型AI責任問題上應對最為從容的企業,並非AI系統最為先進者,而是其領導層在代理行動以失控方式迫使問題浮現之前,已清晰且有據可查地回答了授權問題的企業。
建議型AI改變了決策的形成方式;代理型AI改變的,是決策由誰——或由何物——作出。對此一轉變的治理回應,並非技術專案,而是企業領導層關於「授權何者以企業名義在商業世界中行動」的根本性決定。
This article is published for informational and thought leadership purposes only. It does not constitute legal, regulatory, or compliance advice. The cases and regulatory developments referenced are summarised for illustrative purposes; readers should consult primary sources and qualified professional advisers for complete and accurate information. CloudVista Consulting LLC makes no representation as to the completeness or currency of the information presented.
本文僅供資訊參考及思想領導之用,不構成法律、監理或合規建議。文中援引的案例與監管發展僅供說明之用;讀者應查閱原始資料並諮詢合格專業顧問,以獲取完整及準確的資訊。雲蔚管理顧問有限公司對本文所呈現資訊之完整性或時效性不作任何陳述。