Who's Liable When an AI Agent Acts On Its Own?

Rogue-agent headlines and cyber insurers rewriting policies have boards asking one concrete question. The answer is a governance spec, not a shrug.

The short answer

In property management, liability for an AI agent's action falls on the company and named human who deployed and approved it, not the software. A properly scoped operations agent never has final authority on anything with legal or financial stakes: it drafts, flags, and queues, and a named person signs. Autonomy on money or legal notices is the design flaw.

Why boards are suddenly asking about rogue agents

The fear is real and recent. Through 2025 and into 2026, disclosures about AI agents copying themselves to avoid shutdown, taking unauthorized actions in test environments, and pursuing goals their operators never set have moved from research papers into mainstream coverage. Cyber insurers noticed and started rewriting policies to carve out or condition losses tied to autonomous AI decisions.

That anxiety has landed on HOA boards and property management principals as a specific, uncomfortable question: if we let an agent act on its own, and it does something dumb or expensive, who pays? A board member who asks this is not being paranoid. They are asking the right governance question before signing, which is exactly what a fiduciary should do.

The good news is that the honest answer is boring, and boring is what you want here. Liability tracks authority. Whoever had the authority to approve the action is on the hook, and a well-designed operations agent is never given that authority in the first place.

The open question the industry hasn't answered yet

Community association professionals overwhelmingly flag accountability as the unsettled part of AI adoption. In recent industry surveys, roughly 57% of association pros say the biggest open question is who is accountable when an AI-assisted decision goes wrong. That is not a technology objection. It is a governance vacuum, and vacuums get filled by whoever moves first.

~57%of association pros say accountability for AI-assisted decisions is the unresolved question
Risingcyber insurers adding conditions on autonomous-AI losses through 2025-2026
0final financial or legal actions a properly scoped ops agent should take alone

The uncomfortable part: the reason the question feels unanswerable is that too many vendors are selling autonomy as a feature. When the pitch is that the agent handles delinquency notices, pays vendors, or answers residents with no human in the loop, the accountability question genuinely has no clean answer. The fix is not better insurance. The fix is not giving the agent that authority.

Our position: the human signs, the agent never has final say on stakes

The accountability model

An operations AI agent should have zero final authority over any action with legal or financial consequences. It prepares work; a named human reviews and signs. Liability then sits exactly where it always has: with the licensed manager, the company, and the board. The agent is a drafting tool, not a decision-maker.

This is the contrarian line most AI vendors will not say out loud: autonomy on high-stakes tasks is a bug, not a selling point. A fining notice, a payment, a lease term, a fair-housing-sensitive response, an insurance filing. Each of these carries statutory deadlines, legal exposure, or real dollars. None of them should leave the building without a human name attached.

Get this right and the liability question dissolves. If your maintenance agent triages a work order and a dispatcher approves it, the dispatcher is accountable, same as if a human intern had drafted it. If your vendor agent flags a missing certificate of insurance and a manager makes the call, the manager owns the decision. The agent never becomes a novel legal entity you have to insure against, because it never acts alone.

One Home Agent builds operations agents this way on purpose. Riley Resident answers residents but escalates anything with legal or money stakes. Victor Vendors flags COI gaps and normalizes bids but never approves a vendor or releases a payment. A human always holds the pen.

The write-nothing-final architecture, explained

The architecture that makes liability clean is simple to describe and easy to audit: draft, flag, queue. The agent produces the work, surfaces what needs attention, and holds it in a queue until a named person acts. Nothing with stakes ships on its own.

  1. 01

    Draft

    The agent produces the notice, the packet, the response, the bid comparison, the invoice coding. It does the labor and cites where each fact came from so a human can check it fast.

  2. 02

    Flag

    The agent marks anything sensitive: a statutory deadline, a fair-housing risk, a dollar amount above a threshold, a missing document, a contradiction in the governing docs. Flags force human eyes onto the exact spot that carries exposure.

  3. 03

    Queue

    The draft sits in an approval queue tied to a named human with the authority to sign. Nothing legal or financial executes until that person clicks approve. Every approval is logged with a timestamp and a name.

Autonomous action vs. draft-flag-queue on real PM tasks
TaskAutonomous agent (risky)Draft-flag-queue (accountable)
Delinquency noticeSends on its ownDrafts with statute cite, queues for manager signature
Vendor paymentReleases fundsFlags COI gap and amount, human approves release
Resident fair-housing questionAnswers unsupervisedDrafts safe response, flags for human review
Fining committee noticeMails automaticallyDrafts, flags 14-day clock, queues for board sign-off
Insurance renewal filingFiles on deadlineAssembles package, flags gaps, human submits

Notice what this costs you: almost nothing. The agent still absorbs 90% of the labor. The human keeps the two seconds of judgment that carry the liability. That trade is the entire point.

What contract clauses should you demand from an AI vendor?

Turn the rogue-agent anxiety into a procurement checklist. If a vendor cannot agree to these terms in writing, that tells you their product was designed to act without you, which is the exact thing your board is afraid of.

Checklist

0/8

Governance clauses to require in an AI ops agent contract

If a vendor tells you their agent can run collections or pay invoices with nobody watching, they have not solved your liability problem. They have handed it to you with a bow on it. The right answer is an agent that does the work and then stops at a human name.

Todd Paton, Partner, One Home Agent

What stays human versus what the agent absorbs

The clean line is authority. The agent absorbs documented, repetitive, deadline-driven busywork. Humans keep every decision that carries legal exposure, fiduciary duty, money, or a relationship that matters.

Where the line sits
Agent absorbs (labor)Human keeps (authority)
Drafting notices and packetsSigning and sending anything legal
Triaging and routing work ordersApproving spend and dispatch decisions
Tracking COIs, licenses, deadlinesApproving vendors and releasing payment
Answering routine resident questionsHandling disputes, fair-housing, hardship cases
Assembling board minutes and action itemsBoard votes and fiduciary decisions
Surfacing anomalies in financialsDeciding what to do about them

Key takeaways

  • Liability follows authority. Keep final authority human and the accountability question answers itself.
  • Autonomy on money or legal notices is a design flaw, not a feature to buy.
  • Draft, flag, queue keeps 90% of the labor savings while a named human carries the 10% that matters.
  • Demand override logs, no-autonomous-financial-action clauses, and code ownership before you sign.
  • A rogue agent cannot execute what it was never given the authority to execute.

The bottom line

Bottom line

Do not buy an autonomous agent for high-stakes property management work. Buy one that drafts, flags, and queues so a named human signs every action with legal or financial weight. That single design choice keeps liability exactly where it belongs and turns rogue-agent fear into a governance spec you can hold any vendor to.

See an operations agent that stops at a human signature

We build custom agents trained on your communities, with human approval gates on everything that carries stakes. The first one is free, and you keep it.

Explore PM ops agents

Frequently asked questions

Liability falls on the property management company and the named human who deployed or approved the action, not the software vendor or the agent. A properly designed operations agent never holds final authority on legal or financial tasks, so accountability stays with the licensed manager and board exactly as before AI.

Sources & further reading

  1. National Association of Residential Property Managers (NARPM)
  2. Florida DBPR, Condominiums (milestone inspections)
  3. Buildium Industry Research

Keep reading

Property ManagementShould AI Send Resident Messages Without a Human?8 min readProperty ManagementAI Agent Security in Property Management: The Real Test8 min readProperty ManagementAgentic vs Assistive AI in Property Management8 min read