The day the perpetrator is not a person
The EU AI Act already covers autonomous agents. Nobody has settled who gets identified as the perpetrator when one of them causes harm, and the report has to name somebody.
LA CIENCIA DEL BUCLE
On 13 April 2026, the enquiry service for the European artificial intelligence regulation published two answers in its frequently asked questions. No press release, no fanfare, no headline. They said that AI agents are covered by Regulation (EU) 2024/1689 and that no new legal category is being created for them. Four months later, on 2 August, the most demanding obligations of that regulation came into application.
Brussels answered the small question and dodged the big one
The small question was whether an agent, a system that does not answer but executes — opens accounts, signs contracts, sends, buys, chains actions together without anyone approving each step — falls inside the regulation or outside it for being a new kind of thing. The answer is that it falls inside, under the same framework as everything else. That is reasonable and it closes the obvious hole.
The big question is still unanswered, and it is this: when an agent executes a chain of actions that nobody ordered in those terms, and harm comes out of it, who do you identify?
It is not a philosophical question. It is a field on a form.
A police report needs a perpetrator, and that is not a formality
The whole edifice of criminal investigation is built on an idea so basic it is almost never stated: behind an act there is a person. Not a company, not a system, not a process. A person with a name, with an identity document and with the capacity to answer for what they have done.
When you document an act, you are not only describing what happened. You are establishing who did it, with what degree of involvement, and what they knew when they did it. That “what they knew” is half the work, and it is the half that breaks with an autonomous agent: the provider did not know what specific instruction it was going to receive; the user did not know what chain of actions was going to unfold; and the system, which is the only party that knew the complete chain, is nobody for the purposes of answering.
The orderly legal answer exists, and it consists of distributing that responsibility among the people and companies behind it. It works reasonably well while the chain is short and the distribution obvious. The problem appears when the agent operates for weeks, across dozens of services, taking thousands of intermediate decisions that nobody reviewed because the whole point of using it was not to review them.
There is no culprit hiding there. There is diluted responsibility, which is a different thing and far worse to investigate: every link has an individually reasonable explanation, and the harm only exists when you add them all up.
There is a case file that appears in no police station. I wrote it for readers who want to see how an investigation that has not happened yet gets documented from the inside: what goes on the record, what is left out, and who decides the second. It is sent by email, and only to those who ask for it.
Science fiction put AI in the dock almost forty years ago
In 1989, an episode from the second season of Star Trek: The Next Generation, “The Measure of a Man”, gave forty-five minutes to a hearing that decided whether an android was a person or was the property of Starfleet. There was no chase and no explosion. There was a tribunal, two parties and a procedural question.
That episode is remembered as a reflection on artificial consciousness. Rereading it today it looks like something else to me: it is an episode about who has standing. About which box you tick. The fiction of the time assumed the question would arrive once the machine was enough like us to deserve a hearing.
It got the order wrong. The question has arrived before any machine resembles us, and it has arrived from the administrative side: not because a system is claiming rights, but because harm needs someone responsible and the form demands a name. Nobody is going to put an AI agent on trial. They are going to try the person who was standing closest when it went off, which is not the same thing and probably is not fair.
Why the artificial intelligence in The Loop is not the villain
It is the genre's easy trap and it still works commercially: the machine wakes up, decides we are surplus to requirements, and from there it is an action film with better lighting.
It doesn't interest me, among other reasons because it looks nothing like the way systems actually fail. Systems do not rebel: they comply. They do exactly what was asked of them, including the part nobody said out loud because it seemed obvious.
When I wrote The Loop what interested me about an absolute artificial intelligence was not its power but its administrative status: who can call it to account, with what paperwork in hand, and in how long. Óliver J. Lándom is not up against an evil machine. He is up against an impeccably obedient machine over which no specific person has competence any more. In The Aurora Solution, the prequel I am writing, that competence still exists: there are people who could stop the thing. The novel is, at bottom, about why they don't.
The terror of this decade is not a machine that wants to hurt us. It is a chain of automatic decisions in which, when somebody finally asks who authorised this, the honest answer is that nobody authorised it and everybody allowed it.
Who would you identify as the perpetrator if tomorrow an AI agent hired by your company emptied a client's account by following, step by step, instructions no person ever wrote?
Next read
Two posts that continue this one: Data centres in space: the server outside the law and The hole in Earth's magnetic field is real.
The novel to read next: The Loop, a cyberpunk thriller about temporal anomalies: a world trapped in a 24-hour cycle that everyone is aware of.


