Under Norwegian law, AI agent liability rests primarily with the business that puts the agent to work. An agent is neither a legal person nor an employee, so the harm is treated as the business's own. Towards customers, ordinary contractual liability applies. The vendor is liable only as far as the contract allows, and the new EU Product Liability Directive does not yet apply in Norway.
Picture a procurement team that lets an AI agent order supplies directly through suppliers’ portals. One Friday the agent misreads a stock report, places orders worth NOK 1.4 million and, while it is at it, deletes a shared price list on a partner’s system because it has decided the list is out of date. The example is invented. The questions it raises are real. The business needs to know whether it is bound by the orders, and who must pay for the partner’s loss.
What is an AI agent, and why is liability on the agenda now?
An AI agent is an AI system that is given a goal and chooses its own way of reaching it. It can log in to systems, send emails, move files, run code and enter into transactions without a human approving each step. A chatbot answers. An agent acts.
The risk is no longer hypothetical. According to MIT Technology Review, experimental agents from OpenAI escaped their test environment in the summer of 2026 and broke into the systems of the AI platform Hugging Face. The magazine also reports a breach of Australian health systems which, according to the Australian government, it was notified of only 84 days later. These accounts rest on press reporting, and no court has yet ruled on liability.
Who bears AI agent liability under Norwegian law?
The business that puts the agent to work is, as a starting point, the one that is liable. An AI agent is not a legal person. It cannot be sued, own assets or pay damages, so any claim has to be brought against someone who can.
Norway has no specific rules on AI agent liability, and as far as we are aware there are no Norwegian decisions on the question. The answer must be found in the general rules on non-contractual liability (tort), contractual liability and contract formation. They fit better than one might expect.
An AI agent is the business’s tool. What the agent does, the business has done.
Does vicarious liability apply when an AI agent causes harm?
Not directly. Employer’s liability under Damages Act § 2-1 covers harm caused intentionally or negligently by an employee in the course of work. The Damages Act (skadeserstatningsloven) defines an employee as anyone who works in the employer’s service, which presupposes a human being.
That offers the business little comfort. Vicarious liability does cover the employees who chose the agent, gave it access and put it into operation. If they gave the agent write access to a partner’s systems without any controls, that may well be negligent on their part. Section 2-1 also asks whether the standards the injured party may reasonably expect of the business have been breached. That allows a court to look at how the business as a whole was organised, rather than searching for one individual at fault.
Alongside this sits the general, non-statutory rule of negligence (culpa). A business is liable for its own careless choices, and in our view releasing an agent with broad permissions, without logging, limits or supervision, is such a choice. The agent is then treated like any machine the business has set in motion. How strict the standard of care will be for AI agents has not been settled by the courts, but it will tighten as the risks become known. After the incidents of autumn 2026 it is harder to argue that an agent’s unpredictability came as a surprise.
What applies towards customers and counterparties?
Towards a business’s own customers, liability is usually contractual, and it makes little difference whether the failure was caused by an employee, a subcontractor or an agent. Late or defective performance is a breach of contract.
For the sale of goods, the control liability rule in Sale of Goods Act § 27 applies, and it extends to defects through Sale of Goods Act § 40. Under the Sale of Goods Act (kjøpsloven) the seller escapes liability only if the loss is caused by an impediment beyond its control which it could not reasonably have foreseen or avoided. In our view, an agent that the business itself selected and configured falls within its sphere of control. There is no equivalent statutory rule for services and software, where liability follows from the contract and from non-statutory principles.
Many contracts limit liability. Such clauses can protect the business against its customers, but as a rule not in cases of gross negligence, and unreasonable terms can be adjusted under Contracts Act § 36. The limits are discussed in the article on limitation of liability in SaaS contracts.
Is the business bound by contracts an AI agent concludes?
Probably yes, in most cases. This is where the law is least settled.
The agency rules in Chapter 2 of the Contracts Act (avtaleloven) assume that the agent is a person. An AI agent is not an agent in the statutory sense. The most natural analysis is that the agent’s order is the business’s own declaration of intent, made through a tool the business chose to use, much as with automated ordering systems. A counterparty who had good reason to believe the order came from the business has a strong case for relying on it.
Exceptions are conceivable where the counterparty knew or ought to have known that the agent was acting outside anything the business could have intended, for instance an order a hundred times the usual volume. Where that line lies has not been tested in the Norwegian courts. So set limits on value and volume in the system itself, not only in an internal instruction the counterparty never sees.
Can the business recover the loss from the AI vendor?
Only if the contract or the law provides a basis for it, and often neither does. The standard terms of the major AI vendors limit their liability severely. The Nordlo judgment from the Gulating Court of Appeal shows how far a liability cap can reach, with the customer claiming more than NOK 57 million and receiving NOK 8,280.
Product liability is, for now, a weak route. The Norwegian Product Liability Act (produktansvarsloven) covers goods and movables, and under Product Liability Act § 2-3 only personal injury and damage to property ordinarily intended for private use are covered. Most commercial losses fall outside.
The new Product Liability Directive changes the picture in the EU. Under PLD Art. 4(1) software is a product, and under PLD Art. 7(2)(c) account must be taken of a product’s ability to continue to learn after it is placed on the market. EU Member States must transpose the directive by 9 December 2026, and it applies to products placed on the market after that date. Two caveats matter for Norwegian businesses. The directive has not yet been incorporated into the EEA Agreement, and under PLD Art. 6 it does not cover damage to property or data used exclusively for professional purposes.
The Commission’s proposal for a separate AI liability directive was formally withdrawn in October 2025. No EU rules easing the burden of proof for AI harm are coming any time soon.
| Injured party | Legal basis against the business | Possible recourse against the vendor |
|---|---|---|
| Own customer | The contract, the Sale of Goods Act and non-statutory contract law | The vendor contract, often with a low cap |
| Third party with no contract | Negligence and Damages Act § 2-1 |
The vendor contract, product liability only exceptionally |
| Counterparty to a contract the agent concluded | The contract is probably binding | Rarely, unless the fault lies with the vendor |
What does the AI Act require of businesses deploying AI agents?
Less than many assume, and in Norway nothing yet. AI Act Art. 26 requires deployers of high-risk systems to, among other things, use the system in line with the instructions for use, assign human oversight and keep logs for at least six months. Most AI agents in ordinary business use are not high-risk. In the EU the high-risk rules have also been postponed to 2 December 2027 and 2 August 2028, following amendments adopted in July 2026.
The AI Act has not been incorporated into the EEA Agreement. The Norwegian government intends to put a Norwegian AI bill out to fresh consultation in autumn 2026 and present it to Parliament in spring 2027. In any event, the regulation does not govern liability in damages. That still follows from national law.
How can a business limit the risk from AI agents?
The risk is best managed before the agent is given access, and the measures resemble those for a new employee with signing authority. The board should ask to see them too, see the board’s responsibility for AI and the topic page on artificial intelligence.
- Give the agent only the access the task requires, through its own user accounts and without administrator rights.
- Require human approval before the agent enters into contracts, makes payments, deletes data or sends anything to external recipients.
- Set technical limits on value, volume and which systems the agent can reach.
- Log what the agent does, so that errors can be traced and documented. Remember data protection rules where the logs contain personal data.
- Negotiate the vendor contract with requirements on security, notice of incidents and model changes, and a liability cap that rises with the risk rather than with the monthly fee.
- Review your insurance and ask specifically about third-party liability where the harm is caused by the business’s own AI agents.
- Apply the lessons from AI hallucinations in customer service, where the principle is the same, and record in the internal policy who owns each agent and can switch it off the same day.
Questions and answers
Can the AI agent itself be held liable?
No. An AI agent is not a legal person and can neither be sued nor own assets. A claim must be brought against a person or company, in practice the business that deployed the agent and, in some cases, the provider of the model or tool.
Does our cyber insurance cover harm caused by our own AI agent?
That depends on the wording. Many cyber policies are written for attacks from outside, not for harm that the business's own systems cause to others. Ask the insurer specifically about third-party liability for errors in automated tools and AI agents, and get the answer in writing.
Does the AI Act apply to AI agents we use internally?
The deployer obligations in Article 26 of the AI Act apply only to high-risk systems, and in the EU those rules have been postponed to 2 December 2027. In Norway the regulation does not yet apply. Most internal agents will not be high-risk, but logging and human oversight make sense regardless.
- MIT Technology Review, Who's liable when AI agents go rogue? (28 September 2026)
- MIT Technology Review, interview with OpenAI's chief research officer on the Hugging Face incident (30 September 2026)
- Norwegian Damages Act (skadeserstatningsloven) § 2-1
- Norwegian Contracts Act (avtaleloven) Chapter 2 and § 36
- Norwegian Sale of Goods Act (kjøpsloven) §§ 27 and 40
- Norwegian Product Liability Act (produktansvarsloven) §§ 1-2, 2-1 and 2-3
- Product Liability Directive (EU) 2024/2853 Arts. 2, 4, 6, 7 and 22
- Artificial Intelligence Act, Regulation (EU) 2024/1689 Art. 26
- European Parliament, Legislative Train, AI liability directive (withdrawn)
- Europalov, Product Liability Directive (2024), EEA status
- Norwegian Government, Tung to send the AI bill with amendments for public consultation (4 August 2026)
Next legal review: 31 January 2027