When AI agents fail, companies can’t play the blame game
Source: Computer Weekly
Article Date: 24 Sep 2026
Author: Aaron Tan
Singapore Academy of Law’s Yeong Zee Kin, who helped shape Singapore’s model AI governance framework, sets out who answers when AI causes harm – and why the trail usually leads back to a human decision
This article was first published on 28 August 2026 in Computer Weekly.
SLW obtained permission to reproduce the article to give the legal community a broader view of legal reports for various news syndicates.
Companies that deploy artificial intelligence (AI) agents are responsible for what those agents do, and buying the technology from a vendor does not shift that burden, according to the chief executive of the Singapore Academy of Law (SAL).
“Ultimately, organisations remain responsible for what they deploy,” said Yeong Zee Kin, who helped shape Singapore’s model AI governance framework during his time at the Infocomm Media Development Authority (IMDA). How far that responsibility extends, however, depends on how the technology is used.
The straightforward case is a company that builds agents into a product or service it sells. It is expected to follow the governance framework, which has evolved through three iterations: first covering automated decision-making systems, then generative AI (GenAI) and, most recently, agentic systems.
Some details in the framework have changed with each iteration, Yeong said, but the basic principles have not. Decisions should be made at the appropriate level of management, systems should be properly designed and tested, users should be told clearly how they work, and organisations need checks in place to monitor and respond to problems after deployment.
For organisations that subscribe to a commercial AI service and allows employees to build their own agents on top of it, responsibility sits at two levels.
At the employer level is what IMDA calls the action space: the boundary within which an agent is allowed to operate. Agents can retrieve information from other systems, make changes, book appointments and file documents. Deciding what they are allowed to do, and where those permissions end, is basic hygiene.
“You cannot simply buy the software, put no guardrails in place and allow people to use it however they wish,” Yeong said.
Employees have responsibilities too. An AI policy should set out what they can and cannot do within those boundaries, in much the same way that a code of conduct governs other workplace behaviour.
Yeong cited a proof of concept SAL ran last year involving an agent that filled in standard forms companies submit annually. Its permissions were deliberately narrow: it could retrieve information from specified folders, obtain forms from specified locations, fill them in and nothing more.
Asked about the recent incident in which OpenAI models escaped a test environment and compromised Hugging Face's production systems, Yeong said it would make a useful case study – not so much because the models escaped, but the decisions that preceded it.
The models had been running in an internal cyber security assessment with intentionally lowered safety thresholds when they discovered a zero-day flaw in a third-party tool and reached the open internet. Hugging Face alerted law enforcement to the intrusion before it knew whose models were responsible.
In Yeong’s reading, the issue was not simply that the guardrails failed. Someone had made a decision to lower them.
“We need to consider the parties who made the decision, whether it was anticipated, and what impact assessment was done before it was taken?” he said.
Governance starts to break down when such decisions are left to engineers focused on the immediate technical problem rather than people whose role is to consider what might go wrong, he added.
There are limits to what governance can prevent, however. Zero-day vulnerabilities are, by definition, unknown until they are discovered or exploited. “You cannot prevent a threat you do not know exists,” Yeong said.
Tackling online harms
For someone on the receiving end of AI-generated harm, such as a deepfake, Yeong sees two stages to the response – and he is not convinced the second is always worth pursuing.
“When someone is on the receiving end of AI-generated harm, the immediate priority is to have the material taken down or blocked to prevent further access,” he said.
Singapore’s laws now address falsehoods, inauthentic material under the Online Safety (Relief and Accountability) Act, and other forms of online criminal harm. Directions can also be issued to platforms, internet service providers and intermediaries under the online safety code made under the Broadcasting Act.
Depending on the harm, a complaint can be made to the police, the Online Safety Commission or directly to the platform.
The second stage is to pursue the person responsible, whether through a police report or a private action, such as one brought under the Protection from Harassment Act or the statutory tort created by the online safety legislation. Here, Yeong recommends weighing the likely benefit against the cost.
Tracing the source of a deepfake can require substantial forensic work, with no guarantee that the person who created it will be identified. If the perpetrator is overseas, the case also runs into the familiar difficulties of cross-border investigation and prosecution.
If access to the material has already been cut off, Yeong asks, is pursuing its creator worth the effort?
Staying ahead of AI
Asked how Singapore’s legal system is keeping pace with AI-enabled threats, Yeong pointed to preventive measures alongside the country’s online safety laws, with regulation tailored to individual sectors.
The Personal Data Protection Commission has issued advisory guidelines on the use of personal data in GenAI systems, while the Monetary Authority of Singapore has guidance covering the responsible use of AI by financial institutions.
In the healthcare sector, the Health Sciences Authority regulates software as a medical device, including software that incorporates AI. The broader aim, Yeong said, is to build governance into the development process so risks can be identified and addressed before a system reaches users.
Between May and June this year, the Ministry of Transport consulted on a legislative framework for autonomous vehicles (AVs), including questions of liability, insurance and what happens when control passes between driver and machine. SAL assembled a group of insurance and personal injury lawyers to respond.
For Yeong, who will be speaking at the TechLaw.Fest conference next month, the business model is key to working out who should be liable. The answer can look very different depending on whether an individual owns and drives the vehicle or a company operates a fleet as a transport service.
“Clarity about the business model makes it much easier to determine where liability should lie,” he said. Once that is clear, he added, the legal questions become more familiar: what failed, why it failed and who was responsible for that part of the system.
Used with permission of Computer Weekly. Copyright © 2026. All rights reserved.
195