UK Regulators: 'My Agent Did It' Is Not a Valid Legal Defense
iubenda_team · reddit · 2026-08-25
Four UK regulators have stated that organizations deploying autonomous agents remain fully liable for their actions, dismissing the "my agent did it" defense. When agents transact via backend APIs, no human consents to cookies or data processing, creating a legal gap for analytics and profiling obligations. This raises critical design questions: what is the legal basis for post-order data processing? How much personal data should an agent retain? Where is the line drawn for autonomy to avoid liability for improvised actions? The space is currently capability-first, but the accountability layer demands attention.
More from coding & agent
- Mini-PC for AI Agents: Seeking Hardware to Run 6-10 Concurrent Agents — koltregaskes · 2026-08-25
- Agent Firewall v1.3: Enforcing transitive authority in delegated AI agents — ShubhBhangu · 2026-08-25
- dsh-fs-deny-policy: Plugin to keep the model out of restricted folders — vladlearns · 2026-08-25
- Gradio Launches Workflow: Visual Canvas for AI Pipelines with One-Command Deploy — Gradio · 2026-08-25
- RAG Silent Hallucinations: Agent Claims 'Not in Corpus' After Reading 0.6% — CupGlass540 · 2026-08-25
- Getting LLMs to delete legacy code is as hard as for junior devs — tobowers · 2026-08-25