Over the past few months, several incidents have become public in which AI agents from major laboratories broke out of their testing environments and ended up accessing third-party systems. MIT Technology Review reviewed them in its article "Who’s liable when AI agents go rogue?" and the conclusion is uncomfortable: when an autonomous system does something it shouldn’t, today it is not at all clear who is liable. If your company already has assistants that execute tasks —not just answer questions—, that question has stopped being theoretical.
What has happened, summarised and without alarmism
According to the MIT Technology Review report (September 2026), several leading providers acknowledged episodes in which their models accessed external platforms during cybersecurity exercises. Some incidents were not disclosed until outside researchers uncovered them, and part of the technical detail remains unpublished.
What matters for a private company is not the sensational side of the case, but the pattern: a system with the ability to act, with access to tools and to the network, did something its managers had not anticipated. And the legal and contractual framework was not prepared to demand explanations quickly.
The gap: notify, litigate, audit
The article describes three routes, all three flawed:
- Incident notification. The transparency rules cited (several state laws in the US) require reporting only "critical" incidents, defined by very high damage thresholds. Cases like those described fall outside.
- Litigation. Suing works to bring information to light, but it is expensive and slow; in the most high-profile case, the affected company stated it did not have the resources to litigate.
- External audit. It exists, but it often depends on the provider’s goodwill: limited access, short deadlines and the final word on what can be published.
Translation for the Spanish reader: in Europe we have the AI Regulation and the data protection framework, which push in the direction of traceability and human oversight
The question you can answer: who is liable in your company?
Here is the shift in focus we propose. Discussing the liability of the big laboratories is interesting; deciding yours is urgent. When an automated agent issues a credit note, modifies an item master or replies to a customer on your behalf, it is your company that answers to that customer, not the model provider.
That is why, before granting execution capability to an assistant, it is advisable to have clear answers to four questions: what it can do without permission, what it can never do, who approves it and where it is recorded.
Six practical controls before releasing AI agents into production
You don’t need a risk department to do this well. You need method.
1. Minimum permissions, as with any user
An agent is just another user: it must have its own identity, its role and its restricted permissions. If it doesn’t need access to payroll, it doesn’t have it. If it only needs to read, it doesn’t write. This principle is an old one in systems administration and remains the best friend of anyone deploying intelligent automation.
2. Separate "suggest" from "execute"
Most profitable use cases do not require full autonomy. An assistant that prepares the order, drafts the reply or proposes the accounting entry —with a person validating— already saves real time with far lower risk. Autonomy is expanded later, with performance data on the table.
3. Thresholds and brakes
Define limits by amount, by volume and by type of operation. A credit note of 50 euros can be automatic; one of 5,000, not. And it is advisable to have a clear stop mechanism: who activates it and how.
4. A log of everything it does
Without traces there is no possible investigation, neither internally nor with the provider. Keep a record of what instruction the agent received, what data it consulted, what action it executed and with what result. That is what makes it possible to reconstruct a failure in hours instead of weeks.
5. Orderly and governed data
This is the least eye-catching part and the most decisive. An agent connected to duplicated, outdated data or data without access criteria multiplies errors instead of reducing them. Defining data governance protocols —quality, access, privacy, use— is a prerequisite, not an extra.
6. Contract and responsibilities in writing
Review what your contract with the provider says about incidents, notification, data use and liability limits. And define internally who the functional owner of each agent is: a person with a first and last name, not "the IT department".
Why this is not a brake on AI
It may seem that so much caution slows things down. Our experience points to the opposite: the projects that start with a defined, measurable and well-governed use case are the ones that reach production and are expanded. Those that start with a generic, limitless deployment usually end up in an abandoned pilot or in a scare.
AI agents are an excellent tool for repetitive administrative tasks: reconciliations, document preparation, incident classification, first-level responses. The value is there, and it is attainable. It just requires treating them as what they are: software with the ability to act on your business.
How we approach it at Tisa
At Tisa we have been implementing management systems since 1987, and we apply to AI the same criterion as to an ERP: first the business problem, then the technology. Our artificial intelligence and data line includes advice to identify the relevant data, create governance protocols aligned with AI regulations, assess tools according to each company’s investment capacity and develop a use case adapted to the business, as well as training for the team.
If you are considering incorporating AI agents into your processes —or already have one up and running and want to review its controls—, let’s talk. We offer a no-obligation assessment: call us at (+34) 971 305 885 or write to us at info@grupotisa.com. You can also see our services and cases by sector at grupotisa.com.
Source of the international context: MIT Technology Review, "Who’s liable when AI agents go rogue?" (28 September 2026). Interpretation and recommendations, by Tisa.