Search for content, post, videos

The Rise of Agentic Artificial Intelligence in Practice from a Legal Perspective

The development of artificial intelligence is entering a new phase, increasingly characterized by the term “agentic artificial intelligence” (agentic AI). Unlike traditional AI systems, which function primarily as tools that respond to individual user inputs, agentic AI systems have the ability to autonomously plan, make decisions, and perform complex tasks without constant human intervention. In practice, these include, for example, systems capable of independently analyzing data, communicating with other software tools, making business decisions, or coordinating an organization’s internal processes.

It hardly needs to be mentioned that this is precisely where agentic AI runs into or at the very least may run into many of the pitfalls of regulation in its effort to address necessary compliance issues. It is precisely this risk-based approach to AI systems (introduced not only through the AI Act) that is key for businesses. It is particularly important to correctly assess whether a specific agentic AI system falls under high-risk applications, what obligations arise from this, and how to ensure compliance with new requirements in the areas of governance, documentation, transparency, and risk management.

In other words, this technological shift raises fundamental legal questions. New challenges are emerging in the areas of legal liability, personal data protection, cybersecurity, transparency in decision-making, and compliance with regulatory obligations.

From a legal practice perspective, one of the key issues is determining liability for decisions made by an AI (agentic) system. Even an autonomous agentic AI is still “just AI.” If it causes harm, makes a discriminatory decision, or violates regulatory obligations, the question arises as to who bears legal liability for such conduct—the system developer, the technology provider, the user, or the organization itself that implemented the AI into its processes? Traditional concepts of civil or contractual liability may not always be sufficient to address situations in which AI acts in an unpredictable or adaptive manner.

Another significant area is the protection of personal data and compliance with GDPR requirements. Agency AI systems often work with large volumes of data, including personal data, and their autonomous nature can complicate compliance with fundamental data processing principles such as transparency, data minimization, purpose limitation, and ensuring human oversight of automated decision-making. A particularly sensitive issue is profiling and decision-making with legal or similarly significant effects (under Article 22 of the GDPR).

In addition to regulatory issues, however, one cannot overlook the broader ethical and legal risks associated with the practical deployment of agentic AI. Among the most discussed are the risks of discrimination, lack of algorithmic transparency, insufficient explainability of decisions, the dissemination of inaccurate outputs, or the misuse of AI systems in sensitive sectors such as finance, healthcare, or labor relations. Organizations will, therefore, increasingly need to integrate technological innovations with a robust compliance framework and internal mechanisms for managing legal risks.

The aim of this article is to analyze the rise of agentic artificial intelligence from the perspective of legal practice and to highlight the main legal, regulatory, and ethical issues that these technologies raise in the real business environment. Particular attention will be paid to issues of liability for AI decisions, personal data protection, European regulation of artificial intelligence, and the practical challenges of implementing AI systems in organizations.

Autonomous Decision-Making and Task Execution in Business Practice

It is crucial to realize that while traditional AI systems function primarily as reactive tools that generate outputs based on specific user input, agentic AI goes significantly further. It possesses the ability to autonomously plan individual steps, assess situations, and independently perform tasks without the need for constant human intervention.

Put simply, while traditional AI answers questions or performs narrowly defined tasks based on specific user input, agentic AI goes significantly further and can independently initiate actions, plan procedures, continuously assess the situation, and execute entire end-to-end processes. In practice, this is not merely a “response to a prompt,” but rather autonomous workflow management, within which the AI itself decides what steps are necessary to achieve a set goal, while coordinating and executing individual tasks through interconnected systems, databases, and external tools without the need for constant human intervention.

In the corporate sector, agentic AI is beginning to be used primarily for the automation of internal processes, customer support, financial decision-making, compliance monitoring, and supply chain management. For example, an agentic AI can autonomously analyze business data, assess risks, draft a contract, communicate with a client, or coordinate multiple enterprise systems simultaneously.

These technologies also hold significant potential in the areas of legal services and corporate governance, where AI can conduct legal research, monitor regulatory obligations, or identify potential compliance risks. However, human oversight is often unavoidable, not only due to compliance requirements but also because of the ever-present inaccuracy—or, at times, even apparent schizophrenia—that must occasionally be challenged to prompt the AI to correct its errors and, ideally, prevent them from recurring. Paradoxically, alongside the need for its autonomy, there is a growing need to ensure sufficient human oversight of (especially) final decisions—and not just those that may have legally or economically significant consequences.

The AI Act’s Risk-Based Approach

It hardly needs to be mentioned that the European AI Act introduces a risk-based regulatory model, under which AI systems are classified according to the degree of potential risk to individuals and society. The higher the risk a specific system poses, the stricter the regulatory obligations that apply to it.

Agency AI may in many cases fall under high-risk AI systems, particularly when used in areas such as finance, healthcare, HR processes, critical infrastructure, and others where decision-making occurs with legal or legally significant consequences for the recipient. The reason is its ability to autonomously make decisions with potentially significant impacts on the rights, obligations, or economic standing of individuals.

Providers and deployers of such systems will, therefore, be required, under the effective provisions of the AI Act, to ensure robust AI governance mechanisms, risk management, high-quality technical documentation, transparency in system operation, monitoring of outputs, and appropriate human oversight. An integral part of this obligation will also be ensuring cybersecurity and the quality of data used in training models.

Ethical and Practical Risks in the Business Sector

As with any form of artificial intelligence, there are significant ethical and practical risks associated with agentic AI. In the corporate sector, however, these risks are even more pronounced given the degree of system autonomy and their integration with the organization’s internal processes.

Among the most significant risks are lack of transparency in decision-making, discriminatory or inaccurate outputs (so-called “hallucinations”), incorrect data evaluation, or the uncontrolled execution of tasks without sufficient human intervention and oversight. In business practice, an incorrect AI decision can have a direct impact on clients, employees, business partners, or the company’s overall standing (status, etc.).

Data protection and GDPR compliance also require special attention. It is important to realize that agency AI systems (like many other AI systems) often work with large volumes of personal and internal corporate data, and the autonomous nature of these systems can complicate not only ensuring transparency in processing but, more importantly, minimizing or defining the purpose of data processing, or even the actual control and oversight of how the data is processed.

The Issue of Predictability and Control

It is precisely the degree of predictability and control over the system’s autonomous behavior that represents one of the most fundamental legal issues for the implementation of agentic AI. The more independently and adaptively a system acts, the more complicated it is to determine whether a specific harmful outcome could have been prevented or reasonably foreseen.

As mentioned earlier, unlike traditional software solutions, agentic AI often does not operate solely on the basis of strictly defined rules and deterministic processes. Modern AI models are capable of dynamically responding to new inputs, optimizing their own procedures, and making decisions that were not explicitly programmed by developers or directly approved by users. It is precisely this adaptability that significantly complicates the application of traditional legal concepts of control, oversight, and liability.

In practice, we most often discuss AI systems used for the automated processing of HR tasks, internal compliance, or customer communication management. Agentic AI in manufacturing or business processes can autonomously change task priorities, generate recommendations, or perform actions whose consequences may not be entirely transparent to the user. While such an approach may be effective and relatively safe in some industries, problems arise in situations where an organization lacks sufficient insight into the data, rules, or internal model processes on which the AI based a specific decision. If such a decision is also final and has legal, financial, or labor-law consequences for the recipient, the potential impacts can be extremely serious.

From a legal perspective, this brings to the forefront the issue of so-called explainability, i.e., the ability to explain the decision-making of AI systems. If an organization is unable to retrospectively identify the reasons (patterns) or underlying premises of a specific AI decision, it may be problematic not only to determine liability but also to comply with regulatory requirements under the AI Act or the GDPR. A lack of transparency also complicates the conduct of internal audits, the presentation of evidence in legal disputes, and communication with supervisory authorities.

A particular challenge is “human oversight,” i.e., maintaining effective human supervision of the AI system. In practice, there is often a risk of over-reliance on AI outputs when employees or management automatically accept the system’s recommendations without sufficient critical evaluation. From a legal perspective, however, the mere use of AI does not relieve an organization of its obligation to ensure adequate control over decision-making processes, especially if they may have significant legal, financial, or reputational consequences.

It is, therefore, crucial that companies implementing agentic AI establish robust governance mechanisms, internal control processes, decision auditability, and clear escalation rules for critical decisions made by the AI systems they deploy.

Contractual Liability and Legal Protection

If you are not only a user of (agentic) AI but also its direct developer, a key consideration for you will be defining the mutual liability relationships between the AI system provider/developer on one hand and your organization, which implements and uses the system, on the other. By properly defining rights and obligations, liability can be simplified for both parties as follows: The provider is generally liable for technical deficiencies in the system, the quality of the model, or failure to meet regulatory obligations during its development, while the user or deployer is responsible for improper deployment of the system, lack of oversight, or use of AI in violation of legal requirements.

In practice, we can expect an increasing emphasis on contractual provisions governing liability for damages, compliance obligations, audit rights, cybersecurity, and data protection. A key element of legal protection will also be the thorough establishment of internal control mechanisms and documentation of AI usage. It is also important to note that, given the autonomous nature of these systems, traditional general terms and conditions or standard IT contracts often do not provide sufficient legal protection for situations in which (agentic) AI makes an incorrect, inaccurate, or legally problematic decision.

When implementing AI in practice, it is essential to clearly define the scope of responsibility for each party. The contractual documentation should primarily address issues such as the accuracy and reliability of the system, the limits of AI use, the method of human oversight, liability for incorrect outputs, rules for updating models, data protection, cybersecurity, and compliance with the applicable legal framework for the given jurisdiction, not to mention the enforceability of remedies and potential penalties in the event of a breach. From a security perspective (but also to meet regulatory requirements), it is also extremely important to define the provider’s audit rights and obligations in the event of incidents or inspections by the supervisory authority.

These issues have practical significance, for example, in AI systems used in HR processes, financial services, customer support, or compliance monitoring. If an AI system autonomously rejects a candidate, incorrectly assesses a client, or provides a recommendation that is non-compliant with regulations—resulting in a penalty being imposed on the company—the organization must be able to demonstrate how the system was implemented, what control mechanisms were in place, and who was responsible for each stage of the decision-making process.

For this very reason, a lawyer should be an integral part of every AI implementation in business processes. From a business continuity perspective, it is important to recognize that a lawyer’s role today is no longer limited to assessing risks after the fact or finding solutions to disputes that have already arisen but primarily involves the preventive establishment of the entire governance and compliance framework. It is precisely a legal expert (in-house or external) who should participate in the entire process of implementing an AI system as a whole, from selecting a suitable AI solution, through setting up internal processes, preparing contractual documentation, assessing the legality of data processing, evaluating the riskiness of individual AI categories, as well as in the creation of internal AI policies.

Close collaboration between the lawyer and the IT, compliance, risk management, and cybersecurity teams is essential. The implementation of agentic AI is a multidisciplinary process in which technological, legal, and regulatory issues intersect. A standard IT contract typically does not address issues such as the system’s autonomous decision-making, explainability, model auditability, obligations in the event of an AI incident, or the extent of human oversight over AI decision-making. This is precisely why there is a need for specifically tailored contractual provisions that will govern the limits of system use, the allocation of liability, compliance obligations, incident reporting, audit rights, and mechanisms for immediate intervention in the event of AI system malfunction, among other things.

The absence of a legal assessment in the early stages of implementation may lead in the future not only to significant penalties, contractual disputes, and reputational damage, but also, and most importantly, to violations of the rights of data subjects.

In practice, the importance of so-called AI governance frameworks, which combine technological system management with legal and compliance mechanisms, is growing. Properly configured contractual protection, together with an internal governance model, thus, represents one of the key prerequisites for the secure and regulatory-compliant use of agency AI in the corporate sector.

Conclusion

The rise of agentic AI represents a significant technological shift that fundamentally changes the way organizations operate, not only in the areas of development and practical application. The ability of AI systems to make autonomous decisions and perform complex tasks brings significant benefits in terms of efficiency, automation, and process optimization; at the same time, however, it creates new legal, regulatory, and ethical risks and may significantly impact the rights of data subjects whose data is processed or whose rights may be affected by AI data processing.

In our view, a key factor in the successful implementation of agentic AI is the establishment of a comprehensive internal AI governance framework. Organizations should establish clear rules for the use of AI, risk management processes, internal controls, human oversight mechanisms, and compliance procedures ensuring adherence to the complex legal framework across the areas of law relevant to the development and use of a specific AI (in practice, we most often refer to the GDPR and the AI Act, but also many others, such as sector-specific regulations, which despite the harmonization of EU law often need to be localized to the conditions of a particular jurisdiction).

The legal profession, or the role of a lawyer specializing in technology is, thus, gradually becoming an integral part of AI implementation in organizations. We emphasize, as we have already noted in the text, that the role of the legal department is not and must not be limited to assessing legal risks. Rather, it should operate in symbiosis with active participation in establishing governance mechanisms, contractual relationships, data protection, and internal compliance processes.

Only under these conditions will agentic AI be able to represent not only technological innovation but also a real strategic and business advantage for companies, without its implementation leading to disproportionate costs associated with damages, regulatory sanctions, or resolving legal and reputational complications ex post. Successfully navigating this transformation will therefore depend on companies’ ability to effectively align technological development with legal certainty, ethical principles, and rigorous risk management. If not through their own efforts, then at the cost of actively engaging external experts who can identify potential risks even before AI systems are deployed in practice.

Leave a Reply

Your email address will not be published. Required fields are marked *