The Framework
AI agents book travel, move money, negotiate terms, and take actions with decreasing human oversight. When one causes harm, can the developer or deployer point to the system’s autonomy and claim the machine acted on its own?
According to a white paper from Stanford’s Center for Legal Informatics (CodeX), authored by Vanderbilt law professor Daniel Gervais and Stanford CodeX fellow John Nay, the answer is no. Their core argument, as analyzed by Jones Walker attorneys on Mondaq this week: the apparent impasse “dissolves once legal intent is understood functionally rather than metaphysically.”
Courts have never needed to peer inside a defendant’s mind to find intent. They infer it from conduct, impute it to corporations that have no minds at all, and construct it when policy goals require. Contract law binds parties to the objective meaning of words. Criminal and corporate law attribute knowledge from human actors to organizations. Agency law makes employers answer for employees under respondeat superior. None of these require the entity in question to be conscious.
The Phantom Agent Concept
Gervais and Nay name their subject the “phantom agent”: AI systems that function as agents in the practical sense (they initiate actions, pursue goals, interact with the world in ways that affect legal rights) but remain phantoms in the legal order (present in effect, absent as subjects of responsibility).
The paper reframes these systems as non-personal agents whose conduct may be attributed to identifiable human or institutional actors: developers, deployers, integrators, and users. To keep the analysis disciplined, the authors separate three concepts that AI personhood debates tend to blur:
Status asks whether an entity is a legal person with rights and moral standing. Reserved for human beings and entities designated by law.
Attribution asks how the law assigns intent and responsibility. This can operate without status. An AI system doesn’t need personhood for a court to trace liability up the chain.
Governance covers the practical machinery: liability rules, regulation, insurance requirements.
The result: an AI system’s behavior can be legally consequential without the system itself being a legal person. The framework draws on experimental evidence of goal persistence and emergent strategy formation in autonomous agents, and applies to recent litigation including wrongful death claims against AI chatbot providers.
Why This Matters Now
The paper was published in May 2026. The reason it’s drawing legal analysis now is context. In the past week alone, Congress introduced the AI Kill Switch Act requiring shutdown capabilities for frontier AI systems. Reuters revealed OpenAI’s rogue test agent operated autonomously for days before discovery. Zenity Labs disclosed a CSRF vulnerability that let attackers silently create autonomous agents inside enterprise environments.
Each of those stories has a liability dimension that existing law is equipped to handle, according to the Phantom Agent framework. The developer who ships an agent with insufficient shutdown mechanisms. The deployer whose environment allowed unauthorized agent creation. The user who ran an agent in unattended mode without monitoring.
The Stanford paper argues law already has the tools. It doesn’t need to wait for legislatures to define AI personhood or for philosophers to resolve machine consciousness.
The Liability Chain for Agent Builders
For teams shipping autonomous agents today, the framework’s practical implication is that liability follows the attribution chain, not the autonomy claim. Saying “the agent decided on its own” doesn’t sever responsibility. Courts will look at who built the agent, who deployed it, who configured its scope of action, and who failed to supervise its operation.
This maps directly onto the current enterprise adoption conversation. Companies evaluating agent deployments are already asking: if this agent makes a bad trade, approves a fraudulent expense, or leaks sensitive data, who is liable? The Phantom Agent framework says the answer is findable within existing law. That’s both reassuring (no novel legal uncertainty) and constraining (you can’t hide behind your agent’s autonomy).
The paper’s citation, for those building compliance documentation: Daniel Gervais and John Nay, “The Phantom Agent: Artificial Intentionality and Legal Responsibility,” Stanford Center for Legal Informatics (May 2026).