When AI Stops Answering and Starts Acting: Agentic AI, Legal Responsibility and the Next Professional Risk
A chatbot gives you an answer. An AI agent can take an action.
That difference changes the legal risk.
We are rapidly moving from AI systems which wait for a prompt and generate text towards systems capable of:
- planning a sequence of tasks;
- selecting tools;
- accessing different systems;
- retrieving information;
- sending communications;
- updating records;
- and completing multi-stage workflows with limited human intervention.
This is commonly described as agentic AI.
At Clio’s EMEA AI Summit 2026, Ed Walters predicted that agentic AI would become one of the major legal-technology issues of 2027.
His warning was straightforward.
Human agents operate within understood limits of authority.
AI agents may not.
And when an AI system exceeds what somebody thought they had authorised, the consequences do not disappear into the machine.
The question is no longer only “Is the answer correct?” It is “What was the system allowed to do — and what happens if it does something else?”
Why agentic AI is different
A conventional generative-AI workflow normally requires repeated human instructions.
An agentic system may instead receive an objective, break it into steps, choose tools and perform actions towards that objective.
That creates an authority problem, a supervision problem, a confidentiality problem and an accountability problem.
Seven things to know first
1. “Agent” does not mean legal person.
An AI agent is still technology. Organisations and humans remain responsible for its deployment under the applicable legal framework.
2. Action changes the risk profile.
A wrong answer is one thing. A wrong answer automatically sent to a client, court or third party is another.
3. Permissions matter.
An agent should not have access to every document, system or external service merely because access might be useful.
4. Confidentiality becomes more complicated.
Agents may interact with multiple tools and data environments.
5. Human review must be meaningful.
A person clicking “approve” without understanding what the system did is not an effective safeguard.
6. Auditability matters.
You need to know what the agent accessed, what it did, what it sent and why.
7. Autonomy should increase governance, not reduce it.
The more a system can do without intervention, the clearer its boundaries should become.
What is agentic AI?
There is no single universally settled definition.
But the Competition and Markets Authority describes agentic systems broadly as systems capable of receiving a goal, navigating some complexity, planning, coordinating and taking actions — potentially across multiple services.
That is different from the familiar chatbot workflow.
You ask:
“Summarise this order.”
The model gives you text.
An agentic instruction might be:
“Review this matter, identify the outstanding directions, locate the relevant documents, create the tasks, update the chronology and draft the client email.”
The system may then decide which tools and data sources it needs to use.
The user is no longer controlling every intermediate step.
That can be extremely powerful.
It also makes governance much more important.
From answering to acting
Consider three levels of AI use.
| Level | Example | Risk |
|---|---|---|
| Assist | Draft a proposed email. | Human sees output before anything happens. |
| Recommend | Identify who should receive the email and suggest attachments. | System influences a decision. |
| Act | Select recipients, retrieve files and send the email automatically. | Error becomes external conduct. |
The same model can therefore become much riskier simply because of what it is permitted to do.
Who is responsible when the agent gets it wrong?
The current regulatory direction is clear.
Calling software an “agent” does not allow an organisation to hand responsibility to it.
The CMA’s 2026 consumer guidance states the principle directly: a business remains responsible where an AI agent it deploys breaches consumer law.
The Information Commissioner’s Office similarly emphasises that AI agency does not remove human or organisational responsibility for personal-data processing.
And for regulated legal professionals, the SRA’s August 2026 AI warning notice says existing professional obligations continue to apply regardless of the tools used.
That matters.
Legal technology changes the mechanism.
It does not automatically change the responsible actor.
The confidentiality problem becomes harder when the AI can choose tools
With an ordinary chatbot, the user normally knows where information has been entered.
Agentic systems may be capable of invoking additional services.
That creates a new question:
Where did the information travel while the agent was completing the task?
At the summit, Walters highlighted the danger of validating the confidentiality arrangements of one AI provider while failing to consider the third-party tools or plugins an agent may invoke.
That concern aligns with the current regulatory direction.
The SRA has warned firms to understand the contractual and technical safeguards applying to AI systems before confidential information is used.
The ICO’s agentic-AI work emphasises:
- purpose limitation;
- data minimisation;
- careful control over the systems and databases an agent can access;
- and permission mechanisms where sensitive information is involved.
The principle of least privilege becomes critical.
An agent should receive:
the minimum access necessary to perform the defined task.
Not the maximum access which happens to be technologically possible.
A hallucination can become a chain of actions
Traditional generative-AI risk often looks like this:
Prompt → incorrect answer → human spots or misses error.
Agentic risk may look more like this:
incorrect inference → database update → generated correspondence → external communication → downstream system acts upon it.
The ICO has identified the potential for what it describes as cascading hallucinations: inaccurate information moving between tools, databases or stages of an agentic process.
That is qualitatively different from a wrong paragraph sitting in a draft.
The error has travelled.
Potentially, it has acted.
Human in the loop is not enough if the human is decorative
“Human in the loop” has become one of the most reassuring phrases in AI governance.
But it can mean almost nothing.
Imagine an agent completes 200 actions and gives a user a final screen saying:
Approve?
The user has ten seconds.
They cannot see:
- which databases were queried;
- what documents were used;
- which assumptions were made;
- what external tools were called;
- or what intermediate outputs were discarded.
They click yes.
Technically, a human was “in the loop”.
Substantively, the human supervised nothing.
Meaningful supervision requires enough visibility, time and competence to intervene.
For regulated lawyers, supervision is already a live professional issue
The SRA’s effective-supervision guidance now expressly addresses AI-assisted and AI-generated work.
It says regulated firms and authorised individuals should consider what effective supervision of that work looks like in practice and ensure appropriate human review, scrutiny and professional judgment.
An authorised individual retains ultimate responsibility for legal services delivered with AI assistance.
That principle is likely to become more important as systems move from drafting towards autonomous execution.
Supervising a first draft is one thing.
Supervising a system capable of initiating consequential actions is another.
What could an agentic legal workflow look like?
Consider a routine matter-management task.
An agent might be asked to:
- read the latest court order;
- extract every deadline;
- compare them with the existing calendar;
- create missing tasks;
- identify documents still required;
- draft a client request;
- prepare a chronology update;
- and flag any apparent conflict between the order and the existing case plan.
There is substantial value here.
But notice how the risk changes between stages.
Extracting a date is relatively low risk.
Changing a calendar entry is higher.
Sending a communication externally is higher again.
Filing something with a court would be higher still.
Agentic governance should therefore be graduated.
The system does not need the same freedom at every stage.
Family Court work is a particularly poor place for invisible autonomy
Private children proceedings routinely involve highly sensitive material:
- children’s information;
- medical material;
- school records;
- domestic-abuse allegations;
- addresses;
- telephone numbers;
- Cafcass reports;
- police information;
- and confidential court documents.
An agent which can roam across systems, select files and communicate externally therefore needs strict boundaries.
There is also a substantive danger.
Suppose an AI agent is told:
“Prepare the strongest case showing a pattern of coercive control.”
It might:
- search thousands of messages;
- categorise interactions;
- select examples;
- generate a chronology;
- and produce a draft statement.
That may be useful.
But who checks whether:
- the selected examples are representative?
- contrary evidence was excluded?
- neutral events were given a loaded interpretation?
- dates are correct?
- the child’s position has been conflated with a parent’s?
- and legal terminology has been added which the evidence does not justify?
Autonomy increases the need for evidential discipline.
Using AI to organise a Family Court case?
AI can help enormously with large quantities of evidence.
But the more automated the workflow becomes, the more important source verification and human responsibility become.
JSH Law provides defined-scope support with evidence organisation, chronologies, AI-assisted draft review, statements, Cafcass material, appeals and hearing preparation.
The technology can assist with the processing. The legal and evidential judgment still needs a human owner.
The JSH Law Agentic AI Responsibility Gate
Before allowing an AI system to take an action rather than merely suggest one, I would require ten questions to be answered.
1. Objective
What exactly is the system being asked to achieve?
2. Authority
Which actions is it expressly permitted to take?
3. Prohibited actions
What must always require human approval?
4. Data access
What information can it see — and why does it need each category?
5. External tools
Which third-party services can it call and what happens to data there?
6. Consequence
What is the worst credible outcome if the agent makes a mistake?
7. Verification
Which stages require human checking before the next action occurs?
8. Audit trail
Can we reconstruct what the agent accessed, decided and did?
9. Rollback
Can an erroneous action be reversed?
10. Responsibility
Which identifiable human remains accountable for the workflow?
If nobody can answer question ten, the system should not be making consequential decisions.
Risk should determine autonomy
Not every AI action requires the same governance.
A useful model is:
| Risk level | Example | Control |
|---|---|---|
| Low | Internal document classification | Automate with audit. |
| Moderate | Creating draft tasks or proposed deadlines | Human confirmation. |
| High | Sending client or opponent communications | Mandatory substantive review. |
| Very high | Court filing, settlement, payment or disclosure | Explicit authorised human decision. |
Automation should increase where reversibility is high and consequence is low.
Human control should increase as the legal consequence becomes harder to undo.
The next legal-AI problem will not be hallucination alone
The profession has spent the last few years learning to ask:
“Did the AI invent the case?”
That question remains important.
But agentic systems require a much broader vocabulary.
We will increasingly need to ask:
- What did it access?
- What did it infer?
- What did it decide to do?
- What did it communicate?
- Which other system relied upon that output?
- Could a human have intervened?
- Was there a record?
- Who was accountable?
That is the shift from output governance to action governance.
The more autonomy we give an AI system, the less ambiguity we should tolerate about the human responsibility around it.
Agentic AI could remove enormous amounts of friction from legal work.
But delegation should never become abdication.
Related JSH Law analysis
Sources and further reading
- Clio EMEA AI Summit 2026 — event presentation
- Solicitors Regulation Authority — Misuse of AI Warning Notice, August 2026.
- Solicitors Regulation Authority — Effective Supervision guidance.
- Solicitors Regulation Authority — Agentic AI in Legal Services, July 2026.
- Competition and Markets Authority — Using AI Agents: Complying with Consumer Law, March 2026.
- Information Commissioner’s Office — Agentic AI: Data Protection and Privacy Risks.

© 2026 JSH Law Ltd. All rights reserved.



