A note from Daring: We occasionally invite people in our community to write about the parts of building companies they understand unusually well.
For our first guest essay, Yelena Ambartsumian, founder of AMBART LAW and a Daring Ventures Community Partner, looks at a question applied AI founders are going to encounter more often: when software acts, who ultimately has to stand behind what it does?
Last year, a civil engineering client of ours received an unusual request. One of its customers had contracted with an AI vendor to produce a survey of the interior of a large manufacturing facility. The survey was finished, but it was not usable. That is because no licensed engineer had stamped it, and, without a stamp, no permitting office in Connecticut would accept it.
So the customer made an offer. Would our client “review” the survey and stamp it, for a modest fee? Easy money, right?
Well, the customer was greedy, and they wanted to use their own paper, instead of my client’s standard terms and conditions. So that’s how the question came to me.
Legally, our client could stamp an AI-generated survey. In fact, Connecticut had answered this question decades ago. Under § 20-300-10(b) of the Board of Examiners’ regulations, a licensee may not seal work she did not prepare or supervise unless she prepares, signs, seals, and retains for six years a “thorough written evaluation of the professional services represented by the documents,” down to the design calculations and the applicable codes.
In other words, the regulation permitted the customer’s request, but it first required the engineer to do the work the customer was hoping to skip.
More worrying than the modesty of the fee were the liability and indemnity terms in the agreement that accompanied it: put your license on the result, absorb the downside if the AI got it wrong, indemnify us for third-party claims, and do it for a fraction of what the survey itself would have cost.
I see a similar request on legal platforms nearly every week. A business has an AI-drafted complaint, though of course it never says so. Rather, the request reads: we are looking for a litigator to assist with a filing. You do not have to do anything! The issues have already been analyzed, and a thorough complaint has been prepared. We only need a lawyer admitted in the right court to sign and file it, for a flat fee of $1,000 or so.
But Rule 11(b) of the Federal Rules of Civil Procedure attaches to the signature, and it certifies that the signer made a reasonable inquiry into the facts and the law. The courts that have sanctioned lawyers for filing hallucinated citations since Mata v. Avianca were not asking who wrote the brief. They were asking who signed it.
Anything a lawyer submits to a court, she has to stand behind. (Oh, and we can be sanctioned too.)
Founders are told to ship. Professionals are required to sign.
The software can produce the survey or the complaint, but it cannot be licensed, disciplined, or sued. The liability, therefore, attaches to the nearest license.
And that gets us to the next example, the radiologist.
The radiologist
Consider the scenario Maddi and I discussed when we first spoke about this piece. An AI system reads a chest CT alongside a radiologist and misses a nodule. The radiologist signs the report. The patient is harmed.
Who is accountable?
Today, the answer is the radiologist, who is responsible for the final interpretation of the CT scan, and the law is reasonably settled on this. The standard of care belongs to the physician.
The FDA clears computer-aided detection software as an aid to the reading physician, and the vendor’s terms of service repeat the point: the tool “does not replace or substitute for clinical judgment,” a phrase that appears in nearly every AI vendor agreement I have reviewed.
The radiologist’s signature on the report is her stamp.
But the answer is less stable than it appears, and it is eroding in two directions at once.
First, the standard of care can invert. Once a detection tool is widely adopted, the exposure may shift toward the radiologist who did not use it.
Price, Gerke, and Cohen anticipated this in JAMA in 2019: a physician is safest when she follows the prevailing standard, and the prevailing standard may eventually include the tool.
Sometimes, as the technology becomes readily available, you are faulted for not having it.
In a 1932 Second Circuit case about negligence, The T.J. Hooper, the Court held that two tugboats sailing without radio receivers, which would have alerted them to the evening report that predicted worsening weather, were unseaworthy.
Interestingly, at the time, most operators were not purchasing radio receivers for their crews, but the Court explained:
“An adequate receiving set suitable for a coastwise tug can now be got at small cost and is reasonably reliable if kept up; obviously it is a source of great protection to their tows.”
Radios became a standard within a few years.
Second, the radiologist cannot inspect what she is being asked to vouch for.
In a 2024 paper in Future Healthcare Journal, Lawton and colleagues warned that clinicians risk becoming “liability sinks” for artificial intelligence, absorbing blame for errors in systems they neither designed nor can audit.
The engineer asked to stamp an AI survey could decline. The radiologist cannot; the hospital chose the tool, and it comes with the job.
From “in the loop” to “over the loop”
In the engineering, legal, and radiology scenarios, there is a human reviewing the output, or, as we say in AI governance terms, “human in the loop.”
Without that, the accountability question would not be answerable at all.
Agentic AI, however, removes that step.
In a piece for Women in AI earlier this year, I argued that governance for autonomous agents must move from “human in the loop,” a person approving each decision, to “human over the loop,” where people set boundaries, define escalation triggers, and monitor behavioral telemetry rather than reviewing every action.
In a human-in-the-loop system, accountability attaches at the point of decision: the moment the professional signs.
In a human-over-the-loop system, it attaches at the point of design: the moment someone chose the boundaries, set the thresholds, and decided what the agent could do without asking.
In practice, that is usually the deployer, as an institution. The hospital’s governance committee, not the individual radiologist.
And it is the vendor to the extent the vendor set those parameters and did not allow the customer to change them.
I see this in the contracts we negotiate for our AI-native clients. Their enterprise customers increasingly ask the vendor to stand behind the consequences of the agent’s design and default configuration: how it was tuned, what it escalates, what it does when it is unsure, rather than behind the software’s conformance to its documentation.
That is a different warranty, and it tracks the shift we are discussing here: the customer has worked out that the decision was made upstream, at the design stage, and wants the party who made it to carry the accountability.
Where the law is today
For the founders reading this, here is where each of the three parties stands.
The professional still carries the standard of care, and will for some time. Courts move slowly, and malpractice doctrine is built around a human decision-maker.
The deployer carries negligent selection, configuration, and supervision. This is where “over the loop” matters legally.
A deployer that runs an autonomous agent without logging its decisions is choosing to have no evidence when something goes wrong.
Under Article 26 of the EU AI Act, deployers of high-risk systems must assign human oversight to people with the competence and authority to exercise it, and must keep the logs those systems generate.
That is a legal description of human over the loop.
The vendor is the interesting case, because the answer depends on the jurisdiction.
In the United States, vendor liability for AI software is almost entirely a matter of contract. The 40-page vendor-risk package your first enterprise customer sends, the security questionnaire, the DPA, the “AI addendum,” is the deployer trying to push accountability back upstream, to you.
In the European Union, the revised Product Liability Directive (Directive (EU) 2024/2853) now defines software as a product. Beginning in December 2026, a vendor whose AI causes personal injury or property damage to a consumer will face strict liability that cannot be disclaimed by contract.
Founders selling into both markets are therefore negotiating two different accountability regimes with the same product.
The founder’s position
Most of Daring’s founders are the vendor in this story.
Limitation-of-liability caps, the allocation of responsibility for outputs, the definition of “misuse,” and the question of who controls the agent’s boundaries after deployment: these terms decide who answers when the agent gets it wrong.
Negotiate them accordingly.
And human over the loop means accountability earlier, not less of it.
The boundaries you code, the escalation triggers you define, and the logs you keep are the evidence a court or a regulator will ask for.
If your governance lives in a policy document rather than in the architecture, you have kept the liability and discarded the defense.
The engineer who declined to stamp the AI survey and the lawyer who declines to file the AI complaint are making the same judgment about the risk to their licenses.
Agentic AI has not eliminated that question. But it has moved it earlier into the process, to the people who decide what the system is allowed to do before it does anything at all.
For founders building applied AI, that is you.
About the author:
Yelena Ambartsumian is the founder of AMBART LAW and a Daring Ventures Community Partner. She advises companies on commercial and technology matters, including AI-related contracting and governance.
The views expressed are the author’s own. This article is for informational purposes only and does not constitute legal advice.



