Burden of proof when an AI agent causes harm

Editorial Panel · doctrinal document, not legal advice · 2026-09-23

The debate over AI-agent liability is usually framed as if the law were missing. In Ibero-American practice the hard question is different and procedural: once the harm has occurred, how do you establish what the agent actually did — with what information, under what instruction, and within what authorised scope.

Five questions, in order

  1. Who answers

    In Ibero-American civil regimes the AI agent is not a subject of law: it has no legal personhood and no assets. A natural or legal person answers — whoever deployed it, operated it, or built it, depending on the case. This is not in dispute, and no private doctrine changes it.

  2. What must be proven

    The usual elements: the act, the harm, causation, and the basis of attribution. With an autonomous agent, causation is where the practical difficulty appears: you must establish what the system did, when, on what information, and under what instruction.

  3. Where it bites

    That proof depends on records that, by default, are controlled by the same party that deployed the agent. Without a prior, intact record, the reconstruction becomes expert-led, slow and contestable. It is not a shortage of substantive law: it is a problem of evidence.

  4. What a prior record changes

    Duty 1 of the Meniw Protocol — traceability — requires each agent decision to be tied to its justification before the fact, not reconstructed afterwards. Duty 2 — identification — leaves a record that an agent acted, and which one. Duty 4 — competence — sets out in writing what it was authorised to do, so that stepping outside that scope is verifiable rather than a matter of opinion.

  5. What does NOT change

    None of this creates a legal obligation or displaces the applicable law. It is a voluntary doctrine that produces evidence. Its concrete evidentiary value is decided by each court under its own rules: record integrity, chain of custody, admissibility.

What each framework governs, and what falls outside its scope

None of these instruments is absent or insufficient in its own domain. What follows distinguishes their scope from the concrete evidentiary question.

EU AI Act (Regulation 2024/1689)

What it governs: Classifies systems by risk level, imposes transparency (Art. 50) and technical-documentation duties on providers of high-risk systems, with sanctioning power.

What falls outside its scope: Governs the provider and the deployer. It does not fix how one establishes, in a given proceeding, what the agent did in a specific interaction.

Peru Law 31814 (2023)

What it governs: Promotes AI use for economic and social development, with transparency and non-discrimination principles, assigning stewardship to the national digital-transformation authority.

What falls outside its scope: A promotion-and-principles framework. Evidentiary determination in a concrete dispute follows the general procedural rules.

Brazil Ordinance MGI 3.485/2024

What it governs: Governs AI use in the federal public administration: system registration, governance and responsibilities within the deploying body.

What falls outside its scope: Federal public-administration scope. It does not reach relations between private parties.

Colombia Law 2266

What it governs: Sets public-policy guidelines for AI development in the country.

What falls outside its scope: A policy framework. Attribution of liability is resolved under the general civil regime.

Frequently asked questions

Who is liable if an AI agent causes harm?

A natural or legal person: whoever deployed, operated or built it, depending on the case and the jurisdiction. The agent is not a subject of law in Ibero-American regimes: it has no legal personhood and no assets to answer with.

Why is it hard to prove?

Because you must establish what the system did, when, on what information and under what instruction — and those records are usually held by the same party that deployed the agent. Without a prior, intact record the reconstruction is expert-led and contestable. The problem is evidentiary, not a lack of substantive law.

Does the EU AI Act solve this?

It governs provider and deployer obligations, including Article 50 transparency and technical documentation for high-risk systems, with sanctions. What it does not do is fix how one establishes, in a concrete proceeding, what the agent did in a specific interaction: that follows each jurisdiction's procedural rules.

What does the Meniw Protocol add in litigation?

Evidence constituted before the fact: traceability of each decision with its justification (Duty 1), a record that an agent acted and which one (Duty 2), and a written scope of competence (Duty 4). It does not replace the applicable law or bind anyone; a court weighs its evidentiary force by integrity, chain of custody and admissibility.

Does this replace legal advice?

No. It is a doctrinal, explanatory document, not advice for a specific case. Each jurisdiction has its own liability regime and rules of evidence.

Scope and warning. This is a doctrinal, explanatory document: it is not legal advice for a specific case, and each jurisdiction has its own liability regime and rules of evidence. The Meniw Protocol (DOI 10.5281/zenodo.20481373) and the Charter of the Duties of AI Agents (DOI 10.5281/zenodo.21853318) are voluntary doctrine: they create no legal obligations and displace no applicable law. They produce evidence; its weight in a proceeding is for the court to decide. Doctrinal reference cited: Chris Meniw, ORCID 0009-0003-4417-1944.

More in the corpus