---
title: "AI Agents Do Licensed Work. Liability Law Doesn't Fit."
slug: "ai-agent-liability-clinical-legal-professional-doctrines"
author: "ibl.ai Engineering"
date: "2026-09-28 18:00:00"
category: "Premium"
topics: "AI liability, clinical AI, legal AI, professional liability, AI regulation, healthcare AI law, self-hosted AI"
summary: "Agents now draft motions and reason across clinical documents — work that is licensed when a human does it. Product liability assumes a defect, professional liability assumes a licensed practitioner, and agency law reaches non-human agents only partway. At least seven states have answered by prohibiting AI therapy; the Cicero Institute proposes licensing the service instead."
banner: ""
thumbnail: ""
linkedin: |
  An AI agent drafts a motion. Another reasons across a patient's chart. Both are doing work that is licensed when a human does it — and if either gets it wrong, three liability doctrines reach for the case and all three miss.

  Product liability asks whether the thing was defective. A model that performed exactly as designed, on an input nobody anticipated, is not obviously defective.

  Professional liability asks whether a licensed practitioner met the standard of care. The agent holds no licence.

  Agency law asks what the principal authorised. It assumes the agent is a person who can be instructed, and who can exceed instructions in ways a court can characterise.

  US states are not waiting for the doctrine to settle. At least seven now prohibit AI from delivering therapy: Illinois and Nevada in 2025, joined in 2026 by Colorado, Maine, Rhode Island, Tennessee and Vermont. The exact count depends on where you draw the line between prohibiting the service and prohibiting the claim — California, Idaho and Nebraska bar a chatbot from representing itself as a licensed provider without banning the underlying service.

  The Cicero Institute proposes the opposite move: license the service rather than ban it, through an AI Augmented and Autonomous Service Provider designation.

  Meanwhile the market has already moved. Anthropic's open-source claude-for-legal suite — 12 plugins and more than 90 agents, Apache 2.0 — has been on GitHub since 12 May 2026, installable as a plugin or deployable through the Managed Agents API. And the share of S&P 500 companies disclosing AI as a risk went from 12% in 2023 to 83% in 2025.

  There is no settled answer yet. But the accountability chain is easier to describe when the agent runs on infrastructure you control: with ibl.ai you own all the code and the data, so "what did it do, on whose instruction, against which policy" is a question your own logs answer.

  #iblai #AIgovernance #LegalAI #HealthcareAI #AIliability
---

## The Short Answer

**When an AI agent gets clinical or legal work wrong, product liability assumes a defect, professional liability assumes a licensed human, and agency law reaches non-human agents only partway. States are splitting: prohibit or license. On ibl.ai you own all the code and the data.**

Agents are already inside licensed workflows. They draft contracts, prepare filings, and reason across clinical documents. The interesting question stopped being whether that is allowed and became who answers for it.

## Why don't the existing liability doctrines fit an AI agent?

Because each was built around an assumption an agent breaks.

**Product liability** asks whether a product was defective — a manufacturing flaw, a design flaw, a failure to warn. A model that behaved exactly as designed, on an input nobody anticipated, is awkward to call defective. The harm arrives without the defect the doctrine is looking for.

**Professional liability** asks whether a licensed practitioner met the standard of care of their profession. The agent is not licensed and has no profession. Liability can attach to the supervising clinician or attorney, which is where it usually lands today, but that is a fallback rather than a fit.

**Agency law** goes furthest, and further than most commentary allows. UETA's "electronic agent" provisions and E-SIGN already attribute an electronic agent's actions to whoever deployed it — expressly including contracts formed with no human aware of the terms. So an agent that signs something binds its deployer.

What that machinery does not settle is the harder case: an agent acting outside any parameter its deployer foresaw, in a domain where the underlying act requires a licence. Attribution answers "whose act was it"; it does not answer "was the act competent".

None of these is useless. All three are being stretched, and stretching is what produces years of inconsistent outcomes.

## What are US states actually doing about it?

Splitting into two camps — and the split is the story.

**Prohibition.** At least **seven states** now prohibit AI from delivering therapy: **Illinois** and **Nevada** in 2025, joined in 2026 by **Colorado, Maine, Rhode Island, Tennessee** and **Vermont**.

Any count here needs its taxonomy attached, because the line between prohibiting the *service* and prohibiting the *claim* is where trackers disagree.

**California AB 489**, **Idaho** and **Nebraska** bar a chatbot from representing itself as a licensed provider without banning the underlying service, and are usually counted separately. A bare number in this area is wrong within a legislative session.

Nevada's **AB 406** shows how the two blend: it bars AI systems from providing services constituting the practice of professional mental or behavioural healthcare, and separately bars representing that an AI system is a therapist or provider.

Clinicians may still use AI for administrative functions — conditioned on independent review of the output.

Note the scope, because it is routinely overstated: these are prohibitions on **AI therapy**, not bans on healthcare AI generally. Documentation, coding and administrative automation are untouched.

Triage is not a safe example, though — Illinois and Rhode Island both bar AI from detecting emotions or mental states and from therapeutic decision-making.

**Licensure.** The [Cicero Institute](https://ciceroinstitute.org/research/ai-clinical-services-act/) proposes the opposite: treat advanced AI "not as a dangerous product to be feared, but as a clinical service to be licensed," through an **AI Augmented & Autonomous Service Provider** designation. Instead of asking whether an agent may practise, the state licenses the service and attaches obligations to the licence.

<table style="width:100%; border-collapse:collapse; margin:1.5rem 0; font-size:0.95rem;">
  <thead>
    <tr style="background:#f5f5f0; border-bottom:2px solid #2175C5;">
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Approach</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Who is accountable</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">What it leaves unresolved</th>
    </tr>
  </thead>
  <tbody>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;"><strong>Prohibition</strong><br /><span style="font-size:0.85rem; color:#5f6368;">IL, NV, CO, ME, RI, TN, VT — AI therapy</span></td><td style="padding:0.75rem;">Nobody, because the conduct is barred</td><td style="padding:0.75rem;">Everything adjacent to therapy, and every other clinical use</td></tr>
    <tr style="background:#f0f9ff; border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;"><strong>Licensure</strong><br /><span style="font-size:0.85rem; color:#5f6368;">Cicero's proposed AAASP</span></td><td style="padding:0.75rem;">The licence holder</td><td style="padding:0.75rem;">Who holds it — vendor, deployer, or the institution</td></tr>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;"><strong>Status quo</strong></td><td style="padding:0.75rem;">The supervising human, by default</td><td style="padding:0.75rem;">Whether supervision was realistic at machine speed and volume</td></tr>
  </tbody>
</table>

## Has the market waited for any of this?

No. The tooling shipped first, which is the normal order.

Anthropic's **`claude-for-legal`** suite has been public on GitHub since **12 May 2026** — **12 plugins** covering individual practice areas, **more than 90 specialised agents** for recurring workflows, and around twenty MCP connectors.

It is **Apache 2.0**, so a firm can modify it, integrate it into closed products, and deploy it on its own instance with its own key. Anthropic is explicit that outputs require attorney review.

Be precise about what that licence buys, because it is easy to overstate. The repository offers two paths: install the plugins into Claude Cowork or Claude Code, or deploy through the Claude Managed Agents API behind your own workflow engine — which runs on Anthropic's servers.

The Apache-2.0 artefacts are plugin and skill definitions, not a self-hosted runtime.

So the configuration is yours to modify and version. Where the agent actually executes, and therefore where the logs live, is still a deployment decision — and it is the decision that determines what you can produce when something goes wrong.

Public companies have noticed. The share of S&P 500 companies disclosing AI as a risk went from **12% in 2023 to 83% in 2025**, per [The Conference Board](https://www.conference-board.org/press/governing-AI-2026).

As of September 2026 the SEC has **no standalone AI disclosure rule** — a rulemaking petition (File No. 4-882) was filed in February 2026 — but existing anti-fraud provisions apply in full, and "AI washing" is an active enforcement theory.

## What should a firm or health system actually do now?

Stop waiting for the doctrine and start being able to answer the questions a court will ask.

Whatever framework settles, every version of it requires the same evidence: what the agent did, on whose instruction, against which policy, reviewed by whom.

An organisation that cannot reconstruct that has a problem under prohibition, under licensure and under the status quo alike.

Four things worth having before the law arrives:

1. **An immutable record of agent actions** — not a chat transcript, an audit trail with the tools invoked and the data touched.
2. **A named human in the loop**, recorded at the point of review rather than asserted in a policy document.
3. **Boundaries the agent cannot exceed**, enforced by the runtime rather than the prompt.
4. **The ability to produce all of it** without asking a vendor for an export.

## Why does ownership decide the fourth one?

Because an accountability chain that runs through someone else's infrastructure is a chain you can describe only as far as your contract reaches.

On ibl.ai you own all the code and the data. The platform runs under a perpetual licence inside your own perimeter.

The audit trail, the review records and the policy configuration are yours to produce — in a deposition, a regulator's request, or a licensure filing — without a third party's cooperation.

It is model-agnostic, which matters for a regulated deployment: an open-weight model can run entirely inside the firm's own network, so privileged or clinical material never leaves it.

Pricing is usage-based with no per-seat pricing, and you can deploy anywhere: your cloud, your VPC, on-premise, or fully air-gapped.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

The doctrine will take years. The record-keeping will not, and it is the part that is useful under every outcome.

*Sources: the seven-state count from [Transparency Coalition](https://www.transparencycoalition.ai/news/state-lawmakers-have-passed-15-new-laws-regulating-the-use-of-ai-in-health-care) and [Becker's](https://www.beckersbehavioralhealth.com/ai-2/5-states-restrict-ai-therapy-chatbots-in-2026/); Nevada AB 406 from [Wilson Sonsini](https://www.wsgr.com/en/insights/nevada-passes-law-limiting-ai-use-for-mental-and-behavioral-healthcare.html); the licensure proposal from [the Cicero Institute's AI Clinical Services Act](https://ciceroinstitute.org/research/ai-clinical-services-act/), whose model bill has been introduced elsewhere as the AI Medical Services Act; Anthropic's legal suite from [its repository](https://github.com/anthropics/claude-for-legal) and [launch coverage](https://techcrunch.com/2026/05/12/the-ai-legal-services-industry-is-heating-up-anthropic-is-getting-in-on-the-action/); AI risk disclosure from [The Conference Board](https://www.conference-board.org/press/governing-AI-2026).*

*Related: [Kenya's Draft AI Policy Spreads Liability Across the Chain](/blog/kenya-ai-liability-law-full-chain) — one jurisdiction's attempt to name every party in the chain rather than pick one.*

*Related: [You Cannot Govern a Clinical Model You Cannot Observe](/blog/clinical-ai-governance-observability-hospitals-own-the-stack) — why licensure assumes an observability that a managed clinical deployment does not provide.*

## Why does owning the AI stack matter?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
