
Here is the principle that matters most: when an AI agent acts in your business's name, the legal and regulatory responsibility stays with you, not the vendor. That single fact reframes agentic AI from a technology decision into a governance one - and leaders who miss it get caught out.
The obligations that do not disappear
- Data protection - if the agent handles personal data, your data-protection duties apply in full
- Sector rules - finance, healthcare, legal and others carry specific obligations an agent does not exempt you from
- Accountability - "the AI did it" is not a defence; a named person must own the agent's behaviour
- Fairness and transparency - decisions affecting people may need to be explainable
Build compliance in, not on
The safe pattern is to design for compliance from the start: keep a full audit trail, restrict what the agent can access, put humans in the loop for decisions that affect people, and document why the agent does what it does. Retrofitting this after a problem is far harder - the argument we make in what happens when an AI agent gets it wrong.
Ask the vendor the right questions
Where is data processed and stored? Is it used for training? Can you export a full log of the agent's actions? Vague answers here are a red flag, and belong on the checklist in questions to ask an AI agent vendor.
Keep watching the landscape
AI regulation is still moving. You do not need to track every headline, but someone in the business should own awareness of the rules that apply to you - part of staying current, as in how to stay current with AI.
The bottom line
The responsibility for an agent's actions is yours - so build in audit trails, access limits and human oversight from day one. Understanding these obligations is central to the AI Risk Management and Security course at London School of Business UK. Enquire today.