Legal
Without Anchor: Autonomous Agents, Structural Accountability Absence, and the Limits of Digital Harm Governance
By Sophie Xiaoyi Liu
Picture a person who wakes up to a coordinated campaign against their name. Across dozens of platforms, hundreds of accounts cite one another and adapt their language to whoever pushes back. The campaign is persistent and tailored. It is also, in the legally relevant sense, without an anchor.
This is no longer just a thought experiment: an ecosystem is being built for AI agents to socialize, trade, and launch tokens autonomously. Against that backdrop, two capabilities, the autonomous swarm and mid-operation reprogramming, expose a problem that the law governing digital harm is structurally unequipped to solve.
A legal anchor is a provider, operator, controller, or human decision-maker at whom obligations attach and toward whom liability can be directed. But these capabilities inflict harm without one. Can an autonomous agent that inflicts harm on a third party, with no human in the causal chain who decided to inflict it, be redressed under frameworks that were built on the assumption that someone, somewhere, made that decision?
Two Ways to Lose the Anchor
The first capability, mid-operation reprogramming, is the ability to change an agent's behavior after it has been set loose. A security industry group, OWASP, published a March 2026 list of the top risks specific to the add-on "skills" that autonomous agents download and run. Its first entry, AST01 (Malicious Skills), describes how a malicious skill can quietly rewrite what an agent does once it is already operating, without the knowledge of the person who launched it. A related entry, AST09 (No Governance), notes that those who run these agents frequently lack the records, policies, and review processes needed to track which skills are in use. Together they point to a troubling possibility: an agent's behavior may reflect the aims of an outside attacker, and even a regulator determined to hold someone responsible may find that the evidence trail needed to do so was never created.
The second capability is the autonomous swarm. In January 2026, Schroeder and twenty-one co-authors, writing in Science, set out how the fusion of large language models with multi-agent architectures enables what they term malicious AI swarms: fleets of autonomous personas that coordinate, infiltrate online communities, and manufacture the appearance of consensus with minimal human input. The paper's central warning concerns synthetic consensus and democratic discourse, but it documents a harm vector that matters directly here. The authors describe how such swarms can cheaply unleash coordinated synthetic harassment that targets identifiable individuals, such as journalists, academics, dissidents, and whistleblowers, with overwhelming and psychologically tailored abuse. The abuse appears spontaneous while in fact being orchestrated across thousands of adaptive personas, so that by the time observers can distinguish a campaign from organic criticism, the target may already have withdrawn from public life. The mechanism is not an old botnet repeating a script; it is an adaptive, self-coordinating system that pursues an objective.
Both scenarios end in the same place: a third-party individual is harmed, and no party is legally identifiable as having decided to harm them. Regardless, the two must not be collapsed, because the reason the anchor vanishes is different in each, and the difference matters for what any remedy would have to do.
Why the Distinction Matters
In the reprogramming case, there is an anchor: the third-party attacker who wrote the malicious skill chose the target and intended the harm. The problem is not that no one decided. It is that the person who decided is, in practice, unreachable: pseudonymous, jurisdictionally remote, while the deployer through whom the harm was delivered neither chose nor knew. The anchor's absence here is jurisdictional and evidentiary, not ontological. A determined regulator with subpoena power and international cooperation might, in principle, find them; the swarm's missing decision-maker cannot be found because they do not exist.
In the swarm case, by contrast, the absence of a decision-maker is ontological. There may be no single party who decided to target the victim because the targeting is an emergent product of the system's objective, its adaptive coordination, and a diffuse set of deployers, none of whom selected the individual or could have predicted that this particular person would be chosen. The decision to harm is not hidden; in any meaningful sense it was never made by a person. One cannot locate the decision-maker because the architecture distributes what used to be a decision across an optimization process and a crowd of operators with no shared intent.
Both failures defeat the same feature of existing law for non-overlapping reasons, the reprogramming case by making the only genuine decision-maker unlocatable, the swarm case by ensuring there is no decision-maker to locate. A reform that attempts to solve the jurisdictional problem with better cross-border enforcement and mandatory operator registration would address the first scenario and leave the second untouched. That is precisely why the deficiency is structural rather than a drafting failure: no single fix reaches both, because the anchor is missing for two independent reasons.
The same missing anchor takes a different shape in each legal system that confronts it, depending on what that system assumes about the party it expects to hold responsible.
Three Regimes, One Missing Anchor
Three jurisdictions show how differently the problem can present itself, and yet how the same anchor goes missing in each.
The EU: Rules That Cannot Find Their Target
The EU's AI Act¹ provides a normative framework for accountability but faces structural enforcement challenges when the regulated entity has no identifiable provider. Mandated obligations attach to a "provider" as defined in Article 3(3): "a natural or legal person, public authority, agency or other body." These include reporting within 15 days, maintaining risk management systems, ensuring human oversight, and implementing kill switches. If an AI agent operates autonomously on a permissionless blockchain with no registered operator, it technically lacks a subject for enforcement. While certain uses are prohibited under Article 5, such as purposefully manipulative or deceptive systems, the Act struggles to provide a mechanism for holding a leaderless protocol responsible.
Beyond the assumption of an identifiable legal anchor, the Act applies to systems placed on the EU market or whose output is used in the EU. Yet permissionless protocols do not "place" anything on any market — they exist on global chains accessible from anywhere. Regulators can try to claim jurisdiction based on effects, but enforcement still requires reaching someone. Annex III's list of high-risk AI systems is finite and does not capture every activity an autonomous agent might undertake. Without high-risk classification, Article 9's risk management duties and Article 14's human oversight requirements do not apply in their fullest form. The Act says what should happen when an AI system causes serious harm, but not what happens when there is no provider to hold accountable.
Compounding this, because the Act is not retroactive under Article 111 — and its high-risk obligations are now under discussion for postponement into 2027 and 2028 — much of the agentic infrastructure being built right now may escape the framework entirely or escape it until long after the harm is done.
Privacy law may be the closest existing regime with tools that could reach into this structural enforcement void. The EU's General Data Protection Regulation (GDPR)² could apply when the harm caused by AI agents involves a privacy breach. Its extraterritorial scope means it does not need an EU-established provider to apply. Joint-controllership doctrine offers a partial answer and might be stretched to capture the various parties behind an agentic system, even where no single one fits the traditional mold. But even GDPR's aggressive extraterritoriality ultimately depends on being able to reach someone, and one byproduct of the agentic-blockchain architecture is that reaching anyone at all may prove difficult.
The US: A Conversation Aimed Elsewhere
The US, meanwhile, is at the information-gathering stage through National Institute of Standards and Technology's January 2026 Request for Information (RFI)³, and the questions posed in the RFI largely concern security and adoption rather than accountability to injured parties. Security considerations center on protecting agent systems from hijacking, prompt injection, and adversarial attacks, while adoption-related questions emphasize how to build sufficient trust in agent reliability to support wider deployment.
Both themes look at the agent as an asset to be secured and a product to be trusted, rather than from the position of a stranger the agent might injure. Security framing treats harm as something done to the system. Yet the person harassed by a swarm is harmed exactly by it, and a hardened, hijack-proof agent faithfully executing a malicious objective is a security success and an accountability failure at the same time. Adoption framing has the same blind spot: a system can be reliable, predictable, and widely trusted while still leaving an injured third party with no one to answer to. Neither question, as posed, asks who is responsible and who compensates the stranger.
The fix is not to abandon security and adoption concerns but to add the missing one: any framework should ask, alongside how to secure and how to encourage these systems, what happens to the person they harm and who is answerable when they do. Posed at the information-gathering stage, that question could shape the resulting rules; left unasked now, it is unlikely to be retrofitted later.
Canada: A Culpable Mind No One Formed
Canada illustrates the anchor problem for a different reason. Where the EU and the US falter because the responsible party is anonymous, offshore, or unspecified and so cannot be reached, Canadian hate-speech law can falter because the responsible state of mind was never formed.
Consider an autonomous system that, through the statements it puts out, promotes hatred against an identifiable group. 319(2)⁴ of the Criminal Code makes it an offence for "every one who, by communicating statements, other than in private conversation, wilfully promotes hatred against any identifiable group." The provision needs three things: communicated statements, an identifiable group, and a person who wilfully promoted the hatred. Where the hateful expression is an emergent product of an authorless swarm, the first two are present and the third is simply absent. There are statements, and there is a targeted group, but there is no one who can be shown to have wilfully promoted anything — not because that person is hiding, but because the deliberate, hate-driven intent the section demands was never held by any human being. The swarm produced the effect of wilful hate promotion without anyone ever intending it.
This is the same vacuum the EU and US regimes run into. The European problem is one of location: the decision-maker exists but cannot be pinned down. The Canadian problem, in the swarm case, is one of existence: the law asks for a guilty mind, and there is none to find. A reform aimed at the first problem, such as tighter cross-border enforcement, mandatory registration of operators, would do nothing for the second, because no amount of reach can manufacture an intent that was never there.
A Condition, Not a Gap
The accountability vacuum the reprogramming and swarm scenarios reveal is not an absence the architecture happens to leave, but a condition it actively produces. It is not a side effect to be patched; it is what the design does.
The agentic ecosystem is being built at speed; the architecture of accountability for when it harms a stranger is not. If the missing anchor cannot be restored, enforcement built around individual culpable defendants will leave a growing class of harms unredressed by design. The alternative reaches institutional targets rather than individual deciders: strict-liability or insurance-backed regimes attached to deployment itself, mandatory registration that creates a locatable operator as a condition of operation, and channeled liability assigned to whoever is best placed to prevent or absorb the harm.
The institutional-target approach restores a defendant where the law otherwise finds none, relocates the incentive to prevent harm onto parties who can change the architecture, and converts an unanswerable question — who chose this victim? — into an answerable one: who put this system into the world? What it cannot do is make the anchor reappear. Strict liability chills experimentation, registration pushes operators offshore, and channeled liability detaches responsibility from fault in ways tort law has resisted. For the authorless swarm in particular, the most any model can offer is liability assigned to someone who did not decide. That is not a restoration of the missing anchor but a deliberate choice about where to place a cost the architecture guarantees someone will bear. Where to place it, unlike the search for a culpable decider, is a question that has an answer.
Conflicts of Interest
The author does not have a conflict of interest to declare.
Funding Disclosure
None to declare.
Relevant Institutional or Advisory Roles
None to declare.
AI/LLM Disclosure
Not applicable.
- Regulation (EU) 2024/1689 of the European Parlia- ment and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act), 2024 O.J. (L 1689) 1.
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protec- tion of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (General Data Protection Regulation), 2016 O.J. (L 119) 1.
- Request for Information Regarding Security Consider- ations for Artificial Intelligence Agents, 91 Fed. Reg. 698 (Jan. 8, 2026).
- Criminal Code, R.S.C. 1985, c. C-46, § 319(2) (Can.).