Agent-Based Corporate Systems And Decision Fragmentation Risks .
Agent-Based Corporate Systems and Decision Fragmentation Risks in Europe
1. Meaning
Agent-based corporate systems are corporate structures in which software agents, AI systems, automated decision tools, or semi-autonomous digital systems perform tasks that were traditionally carried out by human employees or managers.
Examples include AI agents that:
negotiate contracts;
purchase goods;
set prices;
approve credit;
recruit employees;
allocate inventory;
manage advertising;
communicate with customers;
trade securities;
detect fraud;
approve payments;
manage supply chains;
generate corporate documents;
make procurement decisions.
Decision fragmentation occurs when an important corporate decision is divided among several agents, departments, algorithms and human supervisors, so that no single actor appears to have made the complete decision.
Example:
Agent A selects supplier → Agent B negotiates price → Agent C approves payment → Agent D assesses risk → Human manager accepts the final output.
If the transaction causes harm, a difficult question arises:
Who is legally responsible for the final decision?
European civil law generally does not allow a company to avoid responsibility merely because its decision-making has been technologically fragmented.
2. The Basic Legal Problem
Traditional corporate decision-making looks approximately like:
Board → Manager → Employee → Action
An agent-based corporation may look like:
Board
↓
AI procurement agent
↓
Pricing agent
↓
Risk agent
↓
Contract agent
↓
External software
↓
Supplier
↓
Customer
Responsibility can therefore become dispersed.
This creates five principal legal risks:
attribution risk — who made the decision?
causation risk — which agent caused the damage?
supervision risk — who should have detected the error?
evidence risk — can the decision process be reconstructed?
corporate-liability risk — can the company be liable even though no individual intended the result?
3. European Legal Principle: Technology Does Not Automatically Become a Separate Legal Person
An AI agent normally operates as a technological instrument or system deployed by a natural or legal person.
The fact that:
"the algorithm decided"
does not ordinarily mean:
"the company did not decide."
The legal analysis instead asks:
Who deployed the system?
Who defined its objectives?
Who supplied its data?
Who authorised its operation?
Who benefited from it?
Who had control over it?
Who had a duty to supervise it?
Was the resulting conduct foreseeable?
Was there a contractual, statutory or tortious duty?
This is especially important for corporate civil liability.
4. Corporate Personality and Agent-Based Systems
A company is a separate legal person.
Its acts may be performed through:
directors;
officers;
employees;
authorised representatives;
contractors;
automated systems.
The use of an automated system does not normally destroy the company's legal personality.
The central problem becomes one of attribution.
For example:
Company X deploys an AI purchasing agent with authority to buy inventory up to €10 million.
The agent purchases €8 million of defective goods.
Company X generally cannot simply argue:
"The AI did it."
The legal analysis will instead examine:
the agent's authority;
the company's instructions;
system design;
contractual allocation of risk;
supervision;
negligence;
product/service defects;
causation.
5. Decision Fragmentation
Decision fragmentation can occur in several ways.
A. Functional fragmentation
Different agents perform different tasks.
Agent A = pricing
Agent B = risk
Agent C = contracting
B. Hierarchical fragmentation
One AI agent supervises other agents.
Master agent → sub-agents → external systems
C. Temporal fragmentation
A decision evolves over time.
Day 1: Agent A recommends
Day 2: Agent B modifies
Day 3: Agent C executes
D. Organisational fragmentation
Different corporate departments use different AI systems.
E. Cross-company fragmentation
Company A's agent interacts with Company B's agent.
This creates particularly difficult attribution questions.
6. European Legal Framework
Several legal regimes may apply.
Civil law
Depending on the jurisdiction:
contract;
tort/delict;
agency;
negligence;
unjust enrichment;
product liability.
Corporate law
Relevant issues include:
directors' duties;
corporate authority;
delegation;
supervision;
shareholder protection.
AI Act
The EU AI Act creates risk-management and governance obligations for certain AI systems and establishes requirements concerning human oversight, technical documentation, monitoring and accountability.
Product Liability
The revised EU Product Liability Directive expands product-liability concepts to modern digital products, including software.
GDPR
Where agents process personal data:
controller/processor obligations;
automated decision-making;
transparency;
security;
data protection rights
may become relevant.
7. Case Law
Direct European case law specifically concerning multi-agent corporate AI systems remains limited. Therefore, the following authorities establish the closest principles concerning attribution, automated decision-making, corporate responsibility, technology and delegated decision-making.
8. Case 1 — SCHUFA
SCHUFA Holding (Scoring), C-634/21
CJEU, 7 December 2023
The case concerned automated credit scoring.
SCHUFA generated a score used by third parties in making credit decisions.
The CJEU considered Article 22 GDPR and the circumstances in which automated processing constitutes a decision producing legal or similarly significant effects.
Importance
The case demonstrates that an organisation cannot necessarily avoid regulatory responsibility by saying:
"The score is only an automated recommendation."
If the automated output effectively determines the decision, the legal significance of the system may be substantial.
Relevance to corporate agents
Consider:
AI risk agent → credit score → loan agent → automatic approval/rejection.
Responsibility cannot necessarily be fragmented by placing multiple automated stages between the data and the final outcome.
The legal analysis must examine the substantive effect of the automated process.
9. Case 2 — Dun & Bradstreet Austria
Dun & Bradstreet Austria, C-203/22
CJEU, 27 February 2025
The case concerned information relating to automated scoring and the information necessary for individuals to understand the operation of automated decision-making.
The judgment is significant for the transparency and explainability of automated decision systems.
Relevance
In an agent-based corporate system, a final decision may depend on:
Agent A's data;
Agent B's risk score;
Agent C's recommendation;
Agent D's ranking.
If nobody can explain how the final result was produced, the company may face serious problems concerning:
transparency;
accountability;
evidence;
regulatory compliance.
The lesson is:
Fragmentation cannot be allowed to make the decision legally inexplicable.
10. Case 3 — Österreichische Post
Österreichische Post, C-300/21
CJEU, 4 May 2023
The case concerned GDPR compensation and unlawful processing of personal data.
The CJEU addressed the conditions for compensation for non-material damage resulting from GDPR infringements.
Relevance
Corporate AI agents can process enormous quantities of personal information.
Suppose:
Customer-data agent → profiling agent → marketing agent → automated decision.
If unlawful processing occurs, the corporation may face GDPR consequences even though no single employee personally made the problematic decision.
The case therefore supports an important principle:
Distributed technological processing does not eliminate organisational responsibility.
11. Case 4 — Meta Platforms
Meta Platforms and Others, C-252/21
CJEU, 4 July 2023
The case concerned Meta's processing and combination of personal data for its services.
The CJEU addressed the interaction between competition law and GDPR requirements.
Relevance
Agent-based corporations may combine information across multiple systems:
CRM agent
advertising agent
customer-support agent
analytics agent.
A fragmented architecture can therefore produce a single corporate data-processing ecosystem even when individual agents perform separate functions.
The case demonstrates why regulators may need to examine the overall data-processing architecture, rather than treating each technological component in isolation.
12. Case 5 — Google Spain
Google Spain SL, Google Inc. v AEPD and Mario Costeja González
C-131/12, CJEU, 13 May 2014
The CJEU held that search-engine operators could have responsibilities under EU data-protection law concerning personal information appearing in search results.
Relevance
The importance of the case for agent-based corporate systems lies in functional responsibility.
The company did not necessarily create the underlying information.
Nevertheless, its technological system played a significant role in:
processing;
indexing;
organising;
displaying information.
Similarly, an AI agent may not create the original information but may:
aggregate it;
rank it;
analyse it;
make decisions from it.
Corporate responsibility may therefore depend on the organisation's actual role in the processing or decision-making chain.
13. Case 6 — Google LLC v CNIL
Google LLC v Commission nationale de l'informatique et des libertés
C-507/17, CJEU, 24 September 2019
The case concerned the territorial scope of delisting obligations imposed on search engines.
Relevance
It demonstrates that a technological platform may have responsibilities arising from the manner in which it operates its system even where the underlying content originated elsewhere.
For agent-based systems, this supports a broader analytical principle:
Legal responsibility may attach to the organisation controlling the technological process, not merely to the person who originally generated the underlying information.
14. Case 7 — Uber
Asociación Profesional Elite Taxi v Uber Systems Spain
C-434/15, CJEU, 20 December 2017
The CJEU considered Uber's platform and concluded that, in the circumstances of the case, its intermediation service formed an integral part of an overall service in the field of transport.
Relevance
Uber is important for agent-based corporate systems because it illustrates that a company cannot always characterise itself merely as a neutral technology provider.
The legal analysis examines:
What does the technological system actually do?
This is highly relevant to AI agents.
An organisation may say:
"The AI merely connects the parties."
But if the system actually:
determines prices;
allocates work;
controls access;
sets conditions;
manages transactions,
the substantive economic and legal function of the system may be more important than its technological label.
15. Case 8 — Bărbulescu v Romania
Bărbulescu v Romania
ECtHR Grand Chamber, 5 September 2017
The case concerned workplace monitoring and the balance between employer interests and employee privacy.
Relevance
Agent-based corporate systems may monitor:
employee performance;
emails;
keystrokes;
communications;
productivity;
location;
behavioural patterns.
If multiple monitoring agents collectively determine employment consequences, the corporation may face questions concerning:
proportionality;
transparency;
privacy;
employee rights;
human oversight.
The case illustrates the broader principle that technological monitoring does not eliminate the employer's legal responsibilities.
16. Case 9 — Bărbulescu and Decision Fragmentation
Suppose:
Monitoring Agent → productivity score → HR Agent → disciplinary recommendation → manager approval.
The employer cannot necessarily argue that:
"No human actually monitored the employee."
The real question becomes:
Was the technological monitoring system lawfully designed, disclosed and proportionate?
This demonstrates why fragmented corporate decision-making requires an audit trail.
17. Case 10 — Google Shopping
Google and Alphabet v Commission
C-48/22 P, CJEU, 10 September 2024
Google's search-ranking system favoured its own comparison-shopping service.
Relevance
The case demonstrates that algorithms can become part of the substantive competitive conduct of a corporation.
An agent-based corporate system could similarly:
rank suppliers;
rank customers;
allocate resources;
prioritise transactions;
select competitors;
determine advertising exposure.
The legal analysis should therefore examine the actual economic effects of the system, not merely its technical architecture.
18. Corporate Decision Fragmentation and Agency Law
Traditional agency law asks:
Did the agent act within authority?
An AI agent creates a technological variation:
Did the software agent act within the authority granted by the corporation?
For example:
Company authorises:
Purchases up to €1 million.
AI agent purchases:
€1.8 million.
Potential questions include:
Was the transaction authorised?
Could the counterparty reasonably rely on the agent's apparent authority?
Was the AI configured incorrectly?
Was the counterparty aware of the limitation?
Who bears the loss?
National civil and commercial law will determine many of these questions.
19. Apparent Authority
An especially difficult situation arises when the AI system appears to have authority.
Imagine:
Company website → AI purchasing agent → supplier.
The supplier reasonably believes:
"This agent represents the company."
If the company publicly presents the system as authorised to negotiate and conclude contracts, the company may face contractual or agency-law arguments even if an internal configuration limited the agent's authority.
The precise result depends upon applicable national law.
20. Contract Formation
Agent-based systems can also create automated contracts.
Example:
Buyer agent sends offer
↓
Seller agent accepts
↓
contract automatically generated.
Questions include:
Was there offer and acceptance?
Who is the contracting party?
Was the AI authorised?
What happens if the algorithm makes an obvious error?
Can the company revoke the contract?
Which version of the algorithm controlled?
Which terms were incorporated?
EU electronic-commerce and electronic-identification law can become relevant, alongside national contract law.
21. Decision Fragmentation and Negligence
Consider:
Agent A incorrectly forecasts demand.
Agent B relies on A's forecast.
Agent C approves procurement.
Agent D negotiates delivery.
Agent E releases payment.
The company suffers €5 million loss.
Who was negligent?
A fragmented system can make traditional single-actor causation difficult.
The court may instead examine:
system design;
foreseeable failure modes;
monitoring obligations;
human oversight;
corporate governance;
software defects;
supplier responsibilities.
22. The "Responsibility Gap"
A responsibility gap exists when:
Everyone participated in the decision, but nobody appears legally responsible.
For example:
| Actor | Function |
|---|---|
| Board | General strategy |
| AI Agent A | Recommendation |
| AI Agent B | Risk assessment |
| AI Agent C | Negotiation |
| Manager | Final click |
| Software vendor | Technology |
Each actor might say:
"The final decision was made somewhere else."
Civil law must therefore reconstruct the chain of causation and responsibility.
23. Corporate Governance Risk
Boards cannot necessarily delegate all substantive responsibility to AI.
Important governance questions include:
Who supervises autonomous agents?
Who sets risk limits?
Who approves major transactions?
Who monitors system drift?
Who can stop the system?
Who investigates errors?
Who maintains audit logs?
Who reviews unexpected decisions?
For important corporate decisions, a human escalation mechanism is particularly important.
24. AI Agent Cascades
The most complex model is:
Master AI
↓
Finance Agent
↓
Procurement Agent
↓
Negotiation Agent
↓
Payment Agent
Each agent receives instructions from another agent.
This creates a cascade problem.
If the first agent makes an error:
A → B → C → D → E
the original error may become increasingly difficult to detect.
This is sometimes described as decision propagation.
25. Causation in Agent-Based Systems
Traditional causation asks:
Did X cause Y?
Agent-based systems require:
Which combination of agents, instructions and system conditions caused Y?
A useful conceptual model is:
Input
→ Agent decision
→ Inter-agent communication
→ Human oversight
→ Execution
→ Harm.
The court may need to identify:
factual causation;
legal causation;
foreseeability;
intervening events;
contributory negligence.
26. Product Liability
Software and AI systems can potentially fall within the modern EU product-liability framework.
Suppose:
Company purchases an AI procurement system.
The software contains a serious defect.
The system automatically purchases unsafe equipment.
Potential defendants could include:
software producer;
AI developer;
integrator;
hardware manufacturer;
corporate operator.
The revised EU Product Liability Directive is particularly relevant because modern software and digital products can fall within the updated product-liability framework.
27. Cybersecurity and Agent Manipulation
Agent-based systems can also be manipulated externally.
Example:
Attacker → prompt injection → procurement agent → fraudulent supplier → payment agent → money transfer.
Potential liability questions include:
Was the system adequately secured?
Was the attack foreseeable?
Did the company implement appropriate safeguards?
Did the software provider fail to patch a vulnerability?
Did an employee ignore warnings?
This creates interaction between:
cybersecurity + corporate governance + contract + tort + product liability.
28. Decision Logs as Evidence
Agent-based corporations should preserve:
prompts;
instructions;
system versions;
model versions;
decision outputs;
tool calls;
approval records;
human interventions;
timestamps;
data sources;
exception reports.
Without such records, litigation may become extremely difficult.
A corporation may be unable to demonstrate:
why a particular decision occurred.
This creates both substantive liability risk and evidentiary risk.
29. Black-Box Decision Making
Suppose the corporation's system produces:
"Reject supplier."
But no employee can explain why.
This creates several problems:
contract disputes;
discrimination claims;
regulatory investigations;
shareholder disputes;
employee claims;
data-protection complaints.
The SCHUFA and Dun & Bradstreet Austria cases show the increasing importance of transparency and explanation where automated processing significantly affects individuals.
30. Human-in-the-Loop
A human-in-the-loop system can be represented as:
AI recommendation
↓
Human review
↓
Approval/rejection
This is safer from an accountability perspective than:
AI recommendation
↓
Automatic execution
But merely inserting a human click does not necessarily create meaningful human oversight.
If the human simply approves every AI decision without reviewing it, the human role may be largely formal.
Therefore:
Human involvement should be meaningful rather than merely symbolic.
31. Agent-Based Corporate Contracts
Contracts should ideally address:
Authority
What may the AI agent do?
Financial limits
Maximum transaction value.
Geographic limits
Where may the agent operate?
Counterparty limits
Which counterparties may it contract with?
Data limits
What data may it access?
Escalation
When must a human intervene?
Audit
Who may inspect decision logs?
Liability
Who bears losses caused by system errors?
Cybersecurity
What security standards apply?
Termination
How is the AI system disabled?
32. Multiple-Agent Liability Matrix
| Failure | Potential responsible party |
|---|---|
| Incorrect corporate instruction | Company |
| Faulty software | Developer/vendor |
| Incorrect integration | Integrator/company |
| Failure to supervise | Company/management |
| Unauthorized transaction | Company/agent/vendor depending on authority |
| Defective hardware | Manufacturer |
| Cyberattack | Depends on circumstances and security duties |
| Wrong data | Data provider/company depending on responsibility |
| Human override failure | Responsible human/company |
| Algorithmic discrimination | Company and/or relevant service provider |
This is not an automatic liability allocation; the governing national law and facts determine responsibility.
33. Competition-Law Dimension
Agent-based systems can also create competition risks.
Suppose several competing companies deploy autonomous pricing agents.
The agents observe:
Competitor price = €100.
They automatically set:
€105.
The agents continuously observe each other.
Potential questions include:
Is this merely intelligent unilateral pricing?
Was there human communication?
Was the algorithm designed to coordinate?
Did companies intentionally configure agents to follow competitors?
Does the conduct amount to concerted practice?
The fact that AI agents communicate indirectly does not automatically resolve the Article 101 analysis.
34. Data Protection Dimension
Agent-based systems may process:
employee data;
customer data;
supplier data;
behavioural data;
biometric data;
financial data.
Potential issues include:
lawful basis;
purpose limitation;
transparency;
automated decision-making;
data minimisation;
security;
profiling.
Meta Platforms, Österreichische Post, SCHUFA and Dun & Bradstreet Austria provide important European guidance for different parts of this problem.
35. AI Governance Principle
A useful corporate governance rule is:
The more autonomous the system and the greater the consequences of its decisions, the stronger the need for human oversight, auditability, access controls and escalation mechanisms.
This is particularly important where decisions involve:
large financial commitments;
employment;
credit;
safety;
personal data;
regulatory compliance;
major corporate transactions.
36. Practical Legal Test
A useful analytical framework is:
A-A-C-E-L
A — Authority
Who authorised the agent?
A — Architecture
How was the decision divided between agents?
C — Control
Who could supervise, modify or stop the system?
E — Effect
What legal or economic consequence resulted?
L — Liability
Which person or entity bears responsibility under the applicable law?
This is an analytical framework rather than a statutory European test.
37. Example
Facts
Company X deploys five AI agents.
Agent 1: selects supplier.
Agent 2: negotiates price.
Agent 3: checks compliance.
Agent 4: approves payment.
Agent 5: manages delivery.
Agent 1 incorrectly selects a fraudulent supplier.
Agent 3 incorrectly classifies the supplier as compliant.
Agent 4 releases €2 million.
The supplier disappears.
Legal questions
The court may investigate:
Who designed Agent 1?
Who configured the supplier-selection criteria?
Was fraud detection adequate?
Did Agent 3 receive sufficient data?
Was Agent 4 authorised to release €2 million?
Was human approval required?
Were warning signals ignored?
Was the software defective?
Did the supplier exploit a system vulnerability?
What contractual allocation of liability existed?
The existence of five AI agents does not itself determine liability.
38. Evidence Checklist
For litigation involving agent-based corporate decisions, important evidence may include:
Corporate
board resolutions;
delegation documents;
internal policies;
risk limits.
Technical
model architecture;
agent instructions;
system versions;
API logs;
prompts;
outputs.
Operational
human approvals;
exception reports;
alerts;
audit logs.
Contractual
software agreements;
warranties;
indemnities;
limitation clauses;
service-level agreements.
Financial
transaction records;
payment approvals;
losses.
39. Key Case Comparison
| Case | Core principle | Agent-system relevance |
|---|---|---|
| SCHUFA, C-634/21 | Automated decision-making | AI outputs can have direct legal significance |
| Dun & Bradstreet Austria, C-203/22 | Explanation/transparency | Fragmented AI decisions must remain sufficiently understandable |
| Österreichische Post, C-300/21 | GDPR compensation | Automated processing can generate corporate liability |
| Meta Platforms, C-252/21 | Data + competition | Multiple agents may create integrated data processing |
| Google Spain, C-131/12 | Platform responsibility | Responsibility can arise from technological processing |
| Google v CNIL, C-507/17 | Search-engine obligations | System operator can bear legal responsibilities |
| Uber, C-434/15 | Substance over technological label | "Technology platform" label does not determine legal status |
| Bărbulescu v Romania | Employee monitoring | Automated corporate monitoring remains subject to legal constraints |
| Google Shopping, C-48/22 P | Algorithmic self-preferencing | Automated ranking can form part of unlawful conduct |
40. Exam-Ready Conclusion
Agent-based corporate systems and decision fragmentation create a new form of corporate legal risk because decisions that were previously made by one manager can now be distributed across multiple AI agents, software systems, human supervisors and external vendors.
European law generally requires the analysis to move beyond the simplistic question:
"Which AI made the decision?"
The more important questions are:
Who designed the system? Who authorised it? Who controlled it? Who benefited from it? Who had a duty to supervise it? What did the system actually do? And what harm resulted?
The SCHUFA and Dun & Bradstreet Austria judgments demonstrate the significance of automated decision-making and transparency. Österreichische Post and Meta Platforms illustrate the importance of data-processing responsibility. Google Spain, Google v CNIL and Google Shopping demonstrate that technological systems can themselves become legally significant components of corporate conduct. Uber shows why legal analysis should examine the substantive function of a platform rather than merely its technological description.
Ultra-basic rule
A corporation should not be able to escape legal responsibility merely by dividing one corporate decision among several AI agents. The decisive issues are authority, control, supervision, causation, transparency and the legal duties applicable to the company and the technology providers involved.

comments