Field Notes · daily AI intelligence for Australian business
← Field Notes

AI Compliance & Regulation

When Your AI Agent Gets It Wrong, You're the One Liable

AI agents now act on their own — placing orders, making calls. In Australia the business that deploys one owns the outcome. Where to keep a human in the loop.

Six in ten Australian workers have caught AI getting it wrong

Six in ten Australian workers have already caught an AI tool making a mistake at work. That's from research the automation firm Appian released on 8 October. The figure that should hold a business owner's attention isn't the error rate, though — it's the timing. AI is shifting from a tool that drafts and answers to one that acts: placing orders, booking jobs, approving transactions, routing work. When an AI that only drafts gets it wrong, someone catches it before it leaves the building. When an AI that acts gets it wrong, the first you hear of it is the consequence.

The same survey — 500 Australian workers, conducted by Zoho Research — found only 14 per cent fully trust what AI produces, and 94 per cent think AI should not make decisions affecting employees or customers without human oversight. Appian sells automation software, so read the enthusiasm with that in mind. But the unease is the part worth keeping: workers want a human between the machine and the decision. On this, the law agrees with them.

60%

Have caught AI making an error at work

Australian workers (Appian, Oct 2026)

94%

Say AI shouldn't decide about people unchecked

Without limits or human oversight

14%

Fully trust AI-generated outputs

Zoho Research, 500 AU workers

In Australia, you own what your AI agent does

Australia has no AI Act, and that is exactly why the exposure sits with you. There is no special regime that quarantines an AI's mistakes from the business running it. Australian governance and legal commentators — among them the Governance Institute and law firm Mallesons — make the point plainly: the law treats an AI agent as part of your IT systems, not as a separate actor you can hold at arm's length the way you might a rogue employee. And it reaches the top of the business. Directors and officers can be personally exposed under the Corporations Act duty to act with reasonable care and diligence, and ASIC's stated view is that the duty now requires officers to know what AI their business uses and what it can get wrong.

"The algorithm did it" is not a defence, and the Federal Court has already said so. In ACCC v Trivago, it ordered the company to pay $44.7 million for conduct driven by its ranking algorithm — a system that quietly favoured the booking sites paying the highest fees over the cheapest rooms the consumer was promised. The dollar figure belongs to a big company; the principle belongs to every business. If your AI misquotes a customer, leaks their data, or makes a biased call in hiring, it is the Australian Consumer Law, the Privacy Act and anti-discrimination law that reach you — not the vendor whose logo is on the tool. Overseas the point is already concrete: a Canadian tribunal rejected Air Canada's argument that its own chatbot was responsible for the fare advice it gave a customer.

The fix is deciding where a human stays on the loop

None of this is an argument against AI agents. It's an argument for deploying them on purpose. The useful question isn't "do we trust the AI" — it's "which decisions can it make alone, and which need a name attached before they happen". Draw the line at consequence and reversibility. An agent drafting a quote, triaging the overnight inbox, reconciling the ledger or summarising a long file is low-risk and easily checked — let it run, with a person approving what goes out. An agent that sends money, commits you to a client, changes a customer's data or makes a call about a person is a different category. That one needs a human signing off, every time.

This is where most businesses are exposed without knowing it. In global research sponsored by Appian, 92 per cent agreed AI agents need rules-based guardrails — and only about half had actually defined them. The gap between buying the capability and governing it is where the liability lives. If you can't say which of your workflows an AI already touches, map where it sits before you hand over another decision. And before you buy the next "agent", check it's a real agent and not a chatbot in costume — you can't govern a capability the vendor can't actually deliver.

The pattern that works is the one Australia's Fair Work Commission used when it let AI draft and a human sign off: the machine does the grunt work, the person keeps the judgement and the accountability. You get the productivity. You don't get the 2am surprise. Write the rule down — which decisions are the agent's, which are a human's — and you've done more for your risk position than any vendor warranty will.

Key takeaways

01Six in ten Australian workers have caught an AI tool making a mistake at work, and as AI shifts from drafting to acting, those mistakes become actions the business has to answer for (Appian, October 2026).
02In Australia the business that deploys an AI agent owns what it does — commentators note the law treats the agent as part of your IT systems, and directors can be personally exposed under the Corporations Act.
03"The algorithm did it" is no defence: the Federal Court fined Trivago $44.7 million over conduct driven by its ranking algorithm.
04The fix isn't avoiding agents — it's keeping a human on the loop for any decision that moves money, commits you to a client or affects a person.

Common questions

Who is liable if an AI agent makes a mistake in Australia?

The business that deploys it. Australia has no separate AI law, and legal commentators note the law treats an AI agent as part of your IT systems rather than a separate actor — so the Australian Consumer Law, Privacy Act and anti-discrimination law reach the business, and directors can be personally exposed under the Corporations Act.

Can I blame the AI vendor if the agent gets it wrong?

Generally no. Vendor terms rarely shift liability back to the supplier, and the Federal Court has already held a company liable for conduct driven by its own algorithm — the $44.7 million Trivago penalty. The obligation to your customer stays with you.

Do I have to stop using AI agents to stay safe?

No. The practical control is keeping a human on the loop for any decision that moves money, commits you to a client or affects a person, while letting the agent run low-risk, reversible tasks like drafting, triage and reconciliation.

Sources

Assumptions & methodology
  1. The worker-survey figures — 60% of Australian workers having personally identified an AI error at work, 94% saying AI should not make decisions affecting employees or customers without limits or human oversight, 66% wanting human review and approval (or always a person) for such decisions, and 14% fully trusting AI outputs — are from research commissioned by Appian and conducted by Zoho Research, surveying 500 Australian workers in Q3 2026, released 8 October 2026 (via PR Newswire APAC). Appian sells AI automation software; the findings are read with that commercial interest in mind.
  2. The figure that 92% agree AI agents need rules-based guardrails while only about half (48%) have defined them is from global Harvard Business Review Analytic Services research sponsored by Appian — it is a global figure, not Australian-specific, and is presented as such.
  3. ACCC v Trivago: the Federal Court ordered Trivago to pay $44.7 million in penalties (April 2022) for breaches of the Australian Consumer Law (ss 29(1)(i) and 34) relating to its hotel-rate ranking algorithm and strike-through pricing, following a January 2020 liability finding — per the ACCC's media release. The Air Canada matter was decided by the British Columbia Civil Resolution Tribunal (2024); it is a Canadian decision cited here as an overseas analogy, not Australian authority.
  4. The characterisation that Australian law is likely to treat an AI agent as part of a business's IT systems, that directors may be personally exposed under the Corporations Act duty of care and diligence, and that ASIC expects officers to be aware of their organisation's AI use and risks, reflects Australian governance and legal commentary (the Governance Institute of Australia and Mallesons). Liability for autonomous-agent outcomes has not yet been directly tested in an Australian court.
  5. Last reviewed 10 October 2026. General information, not legal advice — confirm your obligations with a qualified Australian adviser before relying on them.
ShareLinkedInEmail

Field Notes are general commentary on AI trends for Australian businesses. They don’t constitute professional advice. Talk to your accountant, lawyer, or IT adviser before acting on anything specific to your situation.

If this applies to you

Not sure where your AI should stop and a human should start?

Agentic AI is worth adopting — the risk is handing it decisions no one checks. A short conversation will map where to keep a human on the loop, so the productivity is yours and the liability isn't a surprise. Book a call.

Don't miss the next one

Get each new Field Note in your inbox as it publishes — short, practical AI intelligence for business owners.