Skip to content
Legal Analysis

Autonomous AI Agents: Who Is Criminally Liable? (2026)

21 May 2026Updated: 

Key Takeaways

  • AI is not a subject of criminal law
  • The individual is liable: intent or negligence
  • The legal person may be liable via Art. 31 bis
  • Compliance delineates liability

When an autonomous AI agent is involved in an offence, people are liable, not the machine: AI is not a subject of criminal law. The individual who designed, configured, deployed or instructed it is liable for intent or, in offences that punish it, negligence; and the legal person (Art. 31 bis CP) only for offences in its catalogue, committed for its benefit by managers or poorly supervised employees.

Need help with your case? Talk to a criminal defence lawyer at Alonso Sala.

Autonomous artificial intelligence agents — systems able to make decisions and carry out actions without direct human intervention — raise a major criminal-law question: if an agent causes harm, who is liable? As criminal lawyers, we set out the current framework.

The Problem

Unlike software that merely executes instructions, an autonomous agent plans, decides and acts to meet an objective. If, in doing so, it carries out operations that cause harm or fit a criminal type, the question arises as to whom the act is attributed.

AI Is Not a Subject of Criminal Law

Spanish criminal law rests on the principle of culpability: only those who act with intent or negligence are liable (negligence only where the law expressly punishes it: Art. 12 CP). An artificial intelligence is not a subject of criminal law: it cannot be sentenced or held criminally liable. Liability must necessarily be sought in the people behind the agent.

Who May Be Liable

  • The individual who designed, configured, deployed or instructed the agent, if they acted with intent or, in offences that have a negligent form, with negligence (for example, omitting due controls).
  • The legal person, under the regime of corporate criminal liability of Art. 31 bis of the Criminal Code, if the offence is one that allows such liability and is committed, through the agent and for its benefit, by a manager or by an employee over whom the duty of control was seriously breached.
  • In cases of an unforeseeable and unavoidable outcome, criminal liability might not be found, without prejudice to civil liability.

Compliance is key

For companies using AI agents, documenting the controls, limits and supervision of the system is essential: it is the basis for proving diligence and delineating liability.

A Framework Under Construction

The question is open and will evolve with European AI regulation and emerging case law. What is certain today is the starting point: criminal liability falls on people, individuals or legal persons, not on the machine.

Does your company use AI agents?

We advise on criminal risk and the controls needed to delineate liability.

📞 Call us: +34 91 078 65 74

⚖️ Need a criminal lawyer?

Advice on the criminal risk of new technologies and artificial intelligence.

→ Criminal law: full legal information

Official text: article 31 bis of the Spanish Criminal Code (BOE)

Frequently asked questions

If an autonomous AI agent commits an offence, who is liable?

The people behind the agent are liable, not the machine. Spanish criminal law rests on the principle of culpability: only those who act with intent or negligence are liable (negligence only where the law expressly punishes it: Art. 12 CP). Artificial intelligence is not a subject of criminal law, so it cannot be sentenced or held criminally liable.

Can artificial intelligence be held criminally liable?

No. An AI is not a subject of criminal law: it cannot be sentenced or held criminally liable. Liability must necessarily be sought in the individuals or legal persons behind the agent.

When is the company using the AI agent liable?

The legal person can be liable under the regime of Art. 31 bis CP if the offence is one that allows such liability and is committed, through the agent and for its benefit, by a manager or by an employee over whom the duty of control was seriously breached. That is why documenting the controls, limits and supervision of the system is essential to prove diligence and delineate liability.

What if the harm was unforeseeable and unavoidable?

In cases of an unforeseeable and unavoidable outcome, criminal liability might not be found, without prejudice to any civil liability that may arise from the harm caused.

Is the legal framework for AI criminal liability settled?

No. The question is open and will evolve with European AI regulation and emerging case law. What is certain today is the starting point: criminal liability falls on people, individuals or legal persons, not on the machine.

Do you need criminal defence in this area?

We are criminal defence lawyers specialising in corporate ai criminal risk. We act urgently to protect your rights.

View expertise

This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.

Related Articles

View all

Before you act, speak to a criminal defence lawyer.

What you read here is just the beginning. Transform information into active defence by contacting our team of experts.