How AI works
Does the AI advise a person, or act on its own?
Short answerAdvisory AI produces an output and a person decides before anything happens. Agentic AI acts, and nobody stands between its decision and the effect. Most real deployments sit between the two, and where a system sits decides who answers for what it does.
Advisory. The system produces an output and a person decides. A fraud score a reviewer acts on, a draft a lawyer edits, a risk flag a clinician confirms. A person sits in the causal chain, so responsibility follows familiar paths.
Agentic. The system takes the action itself. It books, executes, sends, browses, and runs code, and no person stands between its decision and the effect.
Why this is where liability changes
In an advisory system, the person who decided is the obvious place for responsibility to land. In an agentic system that link is missing. California AB 316, in force since 1 January 2026, closes one door: a defendant cannot argue that the AI acted autonomously. It leaves causation, foreseeability, and comparative fault as they were. Who answers for an agent's action beyond that is still an open legal question. More in Who is liable when AI acts?
Most deployments sit in between
Few systems are purely one or the other. The middle ground is built from four controls:
- Approval thresholds. The system acts alone below a limit and asks a person above it.
- Review after the fact. The system acts, and a person checks the record later.
- Escalation rules. Defined cases go to a person, whatever the threshold says.
- Hard limits. Some actions the system may not attempt at all.
They differ in when they work. Thresholds, escalation, and hard limits act before the effect. Review after the fact acts on the record, so at the moment of the action the system was agentic, whatever the review later finds. That is a reasonable design for low-stakes actions and a poor one for anything that cannot be reversed.
What to check
- List what each system does without approval. For every AI system in use, write down the actions it can take before a person signs off. That list is its agentic side, whatever the product calls itself.
- Make the hard limits enforced. A limit in a policy document is advice to the system. A limit checked before the action runs is a control. See Are your AI controls enforced, or just written down?
- Record which agent acted, on whose authority. Review after the fact is only as good as the record it reviews. See Can you prove afterwards who did what?
Sources
- California Assembly Bill 316 (Krell), Artificial intelligence: defenses, chaptered 13 October 2025, effective 1 January 2026. Bars the autonomy defense; leaves causation, foreseeability, and comparative fault intact.
- European Union, Artificial Intelligence Act, Articles 14 and 15, human oversight and accuracy, robustness, and cybersecurity of high-risk systems.
Reviewed