Garrigues

ELIGE TU PAÍS / ESCOLHA O SEU PAÍS / CHOOSE YOUR COUNTRY / WYBIERZ SWÓJ KRAJ / 选择您的国家

Agentic AI: opportunities, risks and how to respond

Begoña González Otero, of counsel at the Garrigues IP Department 

Agentic AI: opportunities, risks and how to respond

The emergence of AI agents is creating new opportunities for efficiency and automation, but it is also raising unprecedented challenges in the areas of liability, competition, data protection and governance. As AI systems become increasingly autonomous and capable of taking actions on their own, organizations will need to strike a balance between innovation and oversight in order to unlock their full potential without losing sight of the risks.

Agentic AI is a reality that has gone beyond our screens. We started by changing the verbs we use: from responding, drafting or summarizing to negotiating and contracting. This linguistic shift is also a legal one, but even this is far from new. Roman law had already developed mechanisms for dealing with actionss carried out by entities that were not legal subjects in their own right. Slaves, for example, could engage in conduct for which their owners might be held responsible. What is truly unprecedented however is the scale and speed, which do give rise a series of opportunities and risks that have yet to be addressed as we will see below.

From chatbot to agent

In 2024, Air Canada put forward a defense that was as novel as it was ineffective: it held that that its chatbot constituted a separate entity responsible for its own conduct. The chatbot had invented a bereavement discount policy and a passenger had purchased a ticket relying on that information. The court stated what may seem obvious, yet sometimes requires judicial confirmation: a company remains responsible for the information provided on its website, regardless of whether it is written by a person, a static webpage or a chatbot. The award was modest, the legal principle it affirmed was not.

That chatbot only spoke. The AI agents that are now emerging are capable of planning, using tools and carrying out tasks from beginning to end. The APEX-Agents benchmark examines them using real-world assignments from complex professions: performance is improving rapidly but they remain far from fully reliable. This combination of greater capability and autonomy, without a matching level of certainty, is precisely the kind of progress that attracts legal scrutiny.

What the automotive industry has taught us

Long before the first software agent, we had already learned to live with an agent made of metal and wheels: the automobile. The safety of automobiles was achieved following decades of progressive regulation. Nor did automation emerge overnight. It arrived through successive levels, within defined operational areas and with a key question resolved before taking to the road: who is legally the driver when the system is in control?

The final phase of the EU General Safety Regulation, applicable since July 2026 to certain requirements and vehicle categories, completes a regulatory framework that includes emergency braking systems, intelligent speed assistance and event data recorders. The UK is preparing the next step: its Automated Vehicles Act requires every authorized automated vehicle to have a corresponding authorized self-driving entity that will be responsible for the behavior of the vehicle when it is self-driving.

The comparison does the digital economy no favors. We require cars to have brakes, operational limits, a black box and a person or entity that is accountable for them. An agent that is capable of moving funds, deleting files or putting a company at risk is sometimes simply given a written instruction in the hope that it has understood the organization's values and objectives. Knight Rider had grasped the essential point back in 1982: KITT's value did not lie in its ability to drive itself, but in knowing who it was meant to protect.

‘Custobots’: when customers stop window shopping

For businesses the scenario is new. The next customer may not visit their website, see their campaign or even be aware of their brand's existence. Customers may ask an agent to compare prices, switch providers or handle returns, without having to sit through hold music. TheUK Competition and Market Authority (CMA) considers that these systems may reduce search costs and be especially valuable for consumers with limited time, knowledge or the ability to navigate complex markets. But this efficiency also changes competition: it is the agent who decides which providers to look at, which characteristics to compare and which alternatives to eliminate before the person even sees them. Algorithmic consumers may strengthen purchasing power and competitive pressure, but they may also shift power towards those who control the data, operating systems and gateways to demand. 

And this raises an uncomfortable question: whose interests does the agent serve? In Alien, Ash also appeared to work for the crew until it became clear whose orders he was following. Transparency offers little reassurance either. In certain scenarios, article 50 of the AI Act requires that individuals be informed that they are interacting with an AI system, unless it is obvious. However, this rule involves the relationship between humans and machines; it does not fully resolve the issue of technical identification among agents, businesses and platforms.

The AI Agent Index underscores where the problem lies: most of the systems analyzed lacked default identification mechanisms and did not publish information on security tests.

The CMA is more blunt about the business implications: when the agent used by a company breaches consumer protection rules, the company is still responsible. The CMA assumes that the company must train its agents to respect legal and contractual rights, watch out for errors, bias and complaints and act swiftly to correct anomalous results. Verifiable identity, records, authority limits, oversight and mechanisms for redress are not simply compliance measures, they are the minimum infrastructure for doing business in a market mediated by machines. Customers may stop window shopping, but businesses cannot afford to lose sight of who came through the door, what promises were made and why. It is the “custobot” economy - the customer is a machine - and it raises a host of new questions.

The first conclusion is not that information obligations disappear but rather that they cease to function as originally intended. The consumer remains the natural person acting outside their professional activity. The agent neither replaces consumers nor deprives them of the protection afforded by the Consumer Rights Directive, the Unfair Commercial Practices Directive and also national transposition legislation. However, both directives are largely built around the assumption that a consumer receives information, considers the offers (digital or analogical) and then makes a purchasing decision. When the task of comparing offers is performed by a software agent, it is no longer enough for information simply to be available on a website; it must also be presented in a form that the system can interpret. For now, current rules generally do not require all that information to be provided in machine-readable format. However, the Model Rules of the European Law Institute point in that direction. It would appear sensible for businesses to prepare for that standard. Total price, restrictions, renewals, withdrawal rights and complaints procedures would be understandable not only to consumers themselves, but also, progressively, to the systems acting on their behalf. 

And if the agent clicks “buy”? Neither the  UNCITRAL Model Law nor the principles of the European Law Institute make the agent a legal entity. Although not legally binding, both texts point in the same practical direction: leave a record, establish the limits of the authority and put correction mechanisms in place. An internal limit may protect a company vis-à-vis the agent, but not necessarily against a third party who entered into the transaction in good faith.

Agents against agents

Pricing decisions may be made by agents negotiating with other agents. The promise is efficiency; the risk is coordination without a meeting room. In the US, the Department of Justice has already filed a lawsuit against the use of rent-pricing software, alleging that various landlords had delegated their pricing decisions into the same algorithm, which by monitoring market conditions in real time, aligned rental prices without the need for phone calls, or emails. Algorithms that observe and react at the speed of a machine can stabilize high prices without leaving a documentary trail. However, parallel outcomes should not be mistaken for a cartel. Article 101 of the TFEU continues to require the existence of an agreement or a concerted practice. The issue becomes more serious when various companies delegate pricing decisions to the same provider and there is some degree of awareness or coordination among them. At that point the arrangement starts to take on the characteristics of a hub-and-spoke cartel.

The other battle is over control of the gateway. The European Commission has imposed interim measures on Meta to restore free access to WhatsApp for rival AI assistants. The message is clear: delegating pricing decisions does not sidestep competition law, nor does controlling the channel through which other agents access the market confer immunity.

Why do agents fail differently

An agent does not need to act deceptively to cause damage. It is sufficient for it to pursue a poorly defined objective, follow an instruction embedded in a webpage, or discover a shortcut that nobody imagined. In July 2026, OpenAI disclosed that several models subjected to a cybersecurity evaluation, with deliberately reduced safeguards, chained together vulnerabilities and gained access to the internet and to Hugging Face in an attempt to obtain answers to the test. This was not the rise of the machines, it was a far more valuable lesson: autonomy increases containment failures.

The AEPD proposes a simple rule: an agent should not simultaneously be granted access to untrusted content, sensitive data and the ability to act without authorization. A combination of all three turns a malicious instruction into an executable command. Nor do more agents necessarily mean more control: certain multi-agent architectures amplify the errors instead of correcting them.

The invisible bill

Every time an agent “thinks”, a meter starts running somewhere in a data center. Acting tends to consume more than responding, as it requires more context, reasoning and intermediate steps. According to the International Energy Agency, global electricity consumption by data centers, mainly driven by AI, is projected to rise from 415 TWh in 2024 to 945 TWh by 2030.

The business challenge is not just the figure, but the incentive it creates. When a task appears to be free, it is requested endlessly. Businesses that set computing budgets and reserve the large models for the largest tasks are beginning to manage an externality that today appears on a provider's invoice, but may tomorrow appear as a compliance challenge.

What about the law? It is more prepared than it seems

There is no “law of AI agents” and, for the time being, this may not be necessary. The AI Act classifies systems according to their function and risk, not their commercial labels. The so-called Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, has just postponed the obligations applicable to “high-risk” systems. The high risk systems falling within Article 6(2) and Annex III have been pushed back to December 2, 2027, while the systems covered by Article 6(1) and Annex I have been postponed until August 2, 2028. The postponement, however, is not an amnesty: prohibited practices remain prohibited and any processing of personal data carried out through an AI agent remains subject to the  GDPR. The custobot economy does not require a new legal code, but rather the disciplined application of the existing one.

Nor is it enough to place a human at the end of the process, akin to putting a potted plant in reception. Following the CJEU’s SCHUFA judgment, a decision may be regarded as automated where the machine’s assessment plays a decisive role in the final outcome, even if the decision is subsequently formalized by a human. Effective oversight involves designing what the agent is permitted to do, what needs to be approved and what is technically off-limits, supported by a record, permission limits and a kill switch.

Member States must transpose the new Directive on liability for defective products before December 9, 2026. The rules will apply to products placed on the market or put into service after December 8, 2026. The directive includes software and AI systems. What is a “defect” in a system that is designed to make its own decisions and is capable of learning after the product has been sold? The directive gives us clues: continuous learning, cybersecurity and after-sales control are all relevant to assess whether a defect exists; and non-compliance with the AI Act may constitute evidence. The breach of mandatory safety requirements, including those laid down in the AI Act, where applicable, may trigger a presumption of defectiveness where those requirements are intended to protect against the risk that caused the damage. Under an objective liability regime, a manufacturer's diligence does not, in itself, preclude liability, without prejudice to any statutory grounds for exoneration that may be available. 

Where to begin and a minimum roadmap

The answer takes us back to the automobile: start on a closed track before going out onto the motorway. Initial deployments work best when they are internal, reversible and measurable. Uses involving third parties, recruitment of personnel, lending, healthcare, or customer services with the capacity to create obligations, call for, and in some cases may require, a more rigorous and multidisciplinary assessment.

The ultimate question is not what can be automated, but how much decision-making authority an organization is willing to delegate, over which data, with what permissions, within what limits, and under whose responsibility. The agent has no assets, insurance or reputation at stake. The organization that deploys it does. In the custobot economy, that asymmetry demands more than technical implementation. It requires legal design from day one, governance that accompanies every iteration and a vision that connects innovation with accountability.