When AI Gets the Authority to Act, Is Indian Law Ready?
With AI agents moving from assistance to autonomous action, experts offer views on AI liability, existing laws, human oversight and State accountability.
As AI agents move from assistance to autonomous action, the transition raises new questions about legal responsibility.
An Artificial Intelligence (AI) agent may soon make a UPI payment on your behalf. The National Payments Corporation of India (NPCI) is working on a registry to authenticate and monitor AI agents that conduct UPI transactions, initially for routine payments and potentially, over time, for conditional purchases and investments. The proposed framework is expected to allow such agents to transact within defined limits, marking another step towards integrating autonomous AI systems into everyday financial activity.
That possibility points to a larger shift underway: AI is moving from tools that assist human decisions to systems capable of acting on their own. This raises questions that existing legal frameworks may not have been designed to answer. If an AI agent exceeds the authority given to it, misreads an instruction, or acts without the user's approval, where does legal responsibility lie? More fundamentally, when an AI system acts autonomously, whose act is it in the eyes of the law?
Two lawyers who have closely followed India’s technology regulation debate approach the question from different starting points.
Alok Prasanna Kumar, co-founder of Vidhi Centre for Legal Policy, argues that an AI agent is ultimately “a piece of code” and that its actions are “the act of the person who used it”. At the same time, he notes that, where an AI system causes damage, liability could also extend to “the company which created the AI model”.
Nikhil Narendran, a partner at Trilegal, takes a similar starting point but places greater emphasis on the circumstances in which the agent was deployed. “An AI agent does not have a separate legal personality,” he says. Responsibility, therefore, “must be assessed by reference to the people or entities behind its deployment and use”, depending on “who configured or deployed the agent, who authorised the relevant action, and the context in which it was used".
But the legal difficulty becomes clearer when agentic AI is compared with conventional software.
With conventional software, a human generally determines the action and uses software to execute it. An AI agent works differently. A user may specify an objective, while the system determines the steps required to achieve it. The problem for law is therefore not merely that the machine has made a mistake. It is that the person who authorised the objective may not have specifically authorised the action that ultimately caused the harm.
The question, then, is whether existing legal doctrine can locate responsibility for an AI agent's actions.
Prasanna Kumar argues that existing laws may apply to AI, but are not sufficient to address the particular difficulties posed by autonomous systems. “An AI-specific liability regime should be there in India,” he says, suggesting that it should preferably follow the “absolute liability model” applied to nuclear technology and other hazardous substances. His concern is rooted in the opacity of AI systems: “Because AI functions in a black box and it is simply impossible to explain why an AI Agent did something in a particular way,” he says, “the person who is using it or the creator should be held absolutely liable for damage that it causes".
Narendran takes a more incremental approach. He argues that existing Indian laws can address liability arising from AI, including agentic AI, with responsibility turning on the role and conduct of the person or entity deploying or using the system. Developers, he says, could also bear responsibility in particular circumstances. “If there was gross negligence in developing or releasing an agent [that] causes harm, then the developer could have responsibility,” he says. But “the use of AI does not, by itself, require an entirely separate liability regime", he says.
India isn't alone in circling this. The UK Jurisdiction Taskforce's 2026 statement on liability for AI harms concluded that existing principles of contract and negligence can address many AI-related harms in England and Wales, while identifying areas of uncertainty, including cases involving standalone AI software and situations where harm occurs but negligence cannot readily be established.
The European Union has taken a more prescriptive approach in certain high-risk areas. Under the EU AI Act, AI systems intended to assist judicial authorities in researching and interpreting facts and law are classified as high-risk, while the framework makes clear that AI should support, rather than replace, human judicial decision-making.
India's 2026 AI Governance Guidelines recognise many of the same difficulties. They describe AI systems as probabilistic, generative, agentic and adaptive, identify “loss of control” as a risk and call for accountability to be assigned across developers, deployers and end-users.
The question of liability also raises a more fundamental issue: where should the law draw the line between AI assistance and autonomous decision-making?
Prasanna Kumar takes a clear position. “Autonomous decision-making should be prohibited,” he says, arguing that “a human must always sign off on a decision”. AI assistance, he says, should be permitted where it adds value to human decision-making, but “a human must always be the one taking responsibility for a decision”.
Narendran does not see autonomy, by itself, as requiring a change in the law. Much of the existing legal framework, he says, assumes that “a human or legal entity stands behind a machine”, whether through its design, deployment or use. Even when an AI system makes decisions autonomously, “the central question remains who should be held responsible for its actions”. The legal framework, he argues, would need to identify the person or entity responsible within the particular workflow and apply the relevant legal obligations.
The question becomes particularly consequential when autonomous AI is used by the State, where an automated decision can affect a person’s fundamental rights, livelihood or access to public services. Here, Narendran argues that the threshold for safeguards must be higher. Decisions involving “life and personal liberty, equality, freedom of speech, or the freedom to practise a profession or carry on a trade” require especially close scrutiny, he says.
The safeguards, he suggests, should include meaningful human oversight, checks for discriminatory outcomes, clear reasons for adverse decisions, and accessible mechanisms for review and redress. Even where AI is used in the decision-making process, “The State must remain accountable for decisions made through AI systems,” he says.
Prasanna Kumar takes a categorical position on the issue. “The state must never use autonomous AI in decisions affecting citizens. Period,” he says.
The emerging debate, therefore, is not simply about whether AI should be permitted to act autonomously. It is about whether the law can continue to assign responsibility through frameworks built around human decision-making when the immediate decision may be made by a system that neither has legal personality nor bears legal responsibility.
Therefore, as AI moves from recommending what a user should do to deciding how to do it, the law will have to keep pace with that shift.