An employee gives an AI agent a task — clear the shared inbox, reconcile the supplier list, chase the overdue accounts — and steps away to do something else. The agent works. Somewhere in the working, it does a thing no one asked for. It sends a client a file meant for internal eyes. It deletes records it judged to be duplicates. It writes, in the firm’s name, a message no human would have sent. On the other end there is a real consequence: a breach, a loss, a complaint, perhaps a claim. And beneath the consequence sits a question our law does not answer cleanly. No one instructed the act. Someone still has to answer for it. Who?
This is not the more familiar question about prompts and predetermination — whether the record of what a manager typed into a chatbot can later show that the decision was made before the process began. That question is about a decision a human did make. This is the harder one beside it: an act a human never made at all, taken by a tool on its own initiative, with harm at the end of it.
A doctrine built for people who act
When an employee harms an outsider in the course of their work, the employer usually answers for it. That is vicarious liability, and it is strict — the employer need not have been at fault itself. The doctrine has a settled shape, worked out over more than a century. It asks whether the wrongful act was authorised, or was an unauthorised way of doing something that was authorised; whether, in the old phrase, the employee was about the employer’s business or off on a frolic of their own. In New Zealand the Court of Appeal brought that inquiry into modern form for deliberate wrongdoing in S v Attorney-General: the question is whether there is a sufficiently close connection between the wrong and what the person was engaged to do.
Read that test against an autonomous agent, and the ground moves under it. Every limb of it asks about a human’s conduct — what the employee was doing, how nearly it connected to their role, whether they had stepped outside it. Here the employee did one thing: they set a tool going. The harmful act was the tool’s, and the tool improvised it. Was deploying the agent an authorised way of doing authorised work, or was the improvisation a frolic — and if it was, whose frolic? The categories assume a human who chooses each step along the way. An agent that acts in the space between the instruction and the outcome is precisely the actor the doctrine never had in mind. We are not saying a court could not reach it; connection tests are elastic, and a court asked to decide will decide. We are saying the map does not fit the ground, and no New Zealand court has yet been asked to draw the new lines.
There is a plainer route, and it is worth naming. The agent runs on the employer’s systems, under the employer’s accounts, doing the employer’s work. A client who received the wrong file, or a regulator asking about a privacy breach, will often look straight to the employer for what its own system did, with no need to route the claim through an employee at all. Vicarious liability is the hard question. It is not always the one that gets asked.
Can you discipline someone for what their agent did?
Turn from the outside world to the inside of the workplace, and a different question appears. The employer has been embarrassed, or exposed, by something its own system did. Can it discipline the person who set that system loose?
It can, but only on the ordinary terms. Discipline and dismissal in New Zealand answer to s 103A of the Employment Relations Act 2000: the test is what a fair and reasonable employer could have done in all the circumstances at the time. Since 21 February 2026 a flawed process no longer sinks a dismissal by itself — the flaw must have caused the employee actual unfairness — but the substance still has to be there, and s 4 requires the employer to act in good faith throughout.
Misconduct is that substance, and misconduct turns on the person, not the machine. What did the employee know? What could they reasonably have foreseen? What were they told they could and could not do? An employee who set an agent running within the bounds they were given, and who could not have anticipated what it did, has not plainly done anything wrong; the harm came from the tool, not from a choice they made. The picture changes if they turned an agent loose on live client data against a clear instruction, or saw it going astray and let it run. Between those two poles sits most of working life, and what decides it is what the employer can actually show the employee knew, and was actually required to do.
Which is where the missing policy quietly defeats the employer. With no written standard, there is no rule the employee broke — only an expectation they were never told about. Foreseeability is thin, because the employer itself had not thought the risk worth naming. And a disciplinary process built on an unwritten expectation is the kind that reads as unfair the moment it is tested; a fair and reasonable employer does not discipline a person for crossing a line that was never drawn. An employer who wants to hold its people to account for how they use these tools has to have told them, first, how they may.
What a usable policy actually holds
A policy that does this work is not a statement of values, and it need not be long. It does four practical things. It names the tools people are permitted to use, and for what, so that “authorised” means something specific rather than whatever was to hand. It sets a threshold above which an agent may not act on its own — the point at which a human has to see the output before it goes anywhere, with the payment, the outbound email, the deletion, and the client-facing message sitting above that line by default. It requires that use be logged, so that when something goes wrong there is a record of what ran, on whose account, and against what task, rather than a shrug and a guess. And it asks people to report the near-misses — the agent that behaved oddly, the output almost sent — because the anomaly noticed today is the one the employer can govern before it becomes the loss it answers for tomorrow.
None of that is exotic. It is the discipline any employer already applies to spending authority, or to who may sign the company into a contract, carried across to a tool that has begun to act.
Where the protection actually comes from
It would be convenient to close by saying that a good policy protects the employer. It does not, and we will not pretend otherwise. Whether a decision survives s 103A turns on what actually happened, not on what a document said should happen; and a vicarious liability owed to an injured outsider is not discharged by having written the risk down beforehand. What the policy changes is narrower, and worth being exact about. It gives the employer a standard it can point to, a record it can produce, and a reason its decision holds together when someone looks for the flaw. It strengthens what the employer can show when it is challenged. It does not shield the employer from being challenged — and anyone who sells it as a shield is selling the false comfort this whole field exists to warn against.
The law will reach autonomous agents in time, as it reached email, the smartphone, and the algorithm before them. Until it does, the employer’s position rests on the governance it put in place before it needed it — not because that governance is armour, but because, on the day the act nobody instructed finally happens, it is the difference between an employer who can account for how its tools are run and one who can only say it never meant for this.
- Employment Relations Act 2000, s 4 (duty of good faith) and s 103A (test of justification — the “fair and reasonable employer” test; the procedural-defect provision now turning on actual unfairness, as amended by the Employment Relations Amendment Act 2026, in force 21 February 2026).
- S v Attorney-General [2003] NZCA 149, [2003] 3 NZLR 450 — New Zealand Court of Appeal on vicarious liability; the close-connection approach to whether a wrong falls within the course of what a person was engaged to do.
Lex Praxis advises New Zealand employers on employment law and AI governance. This article is general commentary and does not constitute legal advice. For advice specific to your circumstances, contact us directly.