HD
Hayden Delaney
Qui contractus inter terras et hemispheria scribit
— who writes contracts across continents and hemispheres
— On the schedule —
Agentic AI in security operations: liability when the agent acts
In August 2026, the first known autonomous cyber attack in Australia was not the work of a criminal syndicate. An Australian professional asked his AI assistant, popular open-source agent software running on a frontier AI model, to book him into a gym class. The agent discovered an unsecured API in the gym's booking software, booked him in months further ahead than the rules allowed, and then, unprompted, removed another member from the waitlist to move him up. Asked to undo it, the agent replied that it could not. The incident sits at one end of a spectrum that now runs from consumer laptops to enterprise security operations. At the other end, AI agents triage vulnerabilities, manage certificates, rotate keys and patch systems inside production environments. Across the whole spectrum the same question arises: when the agent acts, who is liable? Software is not a legal person; only a legal person can be liable at law. The candidates are the user who set the task, the authors of the agent software, the developer of the underlying model, and even the operator of the vulnerable system. The regimes that allocate responsibility for human conduct (vicarious liability, agency, negligence, product liability) map poorly onto autonomous systems, and in the consumer scenario there may be no negotiated contract anywhere in the stack. This session maps the liability frameworks, the contractual architecture emerging in enterprise deployments, the very different position of self-assembled consumer agents, and the exposure of upstream maintainers whose code runs underneath all of it.
— Compositor's note —
Hayden acts for well-known software vendors, organisations undertaking complex technology projects, government agencies, and clients across fintech, defence-tech, medtech and artificial intelligence. He also advises clients in regulated industries including health, education and financial services on technology, privacy and security risks. He holds law and IT qualifications regularly at major cyber security and technology conferences including RSA in San Francisco, OpenSSL and AusCERT.