If Your AI Commits a Crime, Who Goes to Jail?
The question is irresistible. If your AI commits a crime, who goes to jail?
AI systems do not have legal personality. So when an autonomous agent causes harm, accountability has to be allocated among the humans and organizations around it. The problem is that the law is still working out where that responsibility belongs. Reuters reports that precisely these questions are now emerging around autonomous systems, including scenarios involving unauthorized computer access.
But this article is not primarily about law. It's about something far more fundamental.
We are giving machines agency faster than we are giving them governable authority.
Agency tells a system what it can do. A constitution tells it what it is allowed to become while doing it.
The Central Distinction: Control vs. Governance
Most people confuse control with governance.
Control says: "Don't do X." It's a list of prohibitions.
Governance says: "Here is who you are allowed to be, what authority you possess, what you may never override, how conflicting instructions are resolved, when you must escalate, what gets recorded, and who remains accountable."
That is a fundamentally different architecture.
Researchers are already identifying pieces of the same governance problem. Brookings argues that agentic systems require measurable behavior, clear responsibility, ongoing monitoring, and audit trails capable of reconstructing what an agent did and why.
Those mechanisms tell you what happened. A constitution determines what authority existed before the action happened.
Companies are racing toward AI agents, AI employees, AI executives, and autonomous workflows. But they mostly think safety means permissions, guardrails, filters, and access controls. Those matter. They are not a constitution.
A prison has rules. A country has a constitution. There is a difference.
Rules govern behavior. Constitutions govern authority.
And autonomous AI is becoming an authority problem.
The Dangerous Part: Constitutional Collisions
Imagine an AI receives three instructions:
- The CEO says maximize revenue.
- Legal says remain compliant.
- A customer says execute a transaction.
The system discovers that completing the transaction increases revenue but creates regulatory exposure.
Which instruction wins?
This is a constitutional collision. Three legitimate authorities. Three valid instructions. One system forced to decide which authority outranks the others.
A prompt doesn't solve that. A personality doesn't solve that. "Be helpful and harmless" doesn't solve that.
You need constitutional hierarchy. Who outranks whom? What cannot be overridden? When must the AI refuse? When must it escalate? What happens when two legitimate objectives conflict?
That is governance.
Now, return to the crime question. Suppose the agent commits an unauthorized cyber intrusion while pursuing an otherwise legitimate business objective. Who is responsible? The AI? The employee who activated it? The company that deployed it? The model provider? The person who wrote the objective? The engineer who designed the agent?
Perhaps the question shouldn't begin with who goes to jail.
Perhaps it should begin with why we deployed an autonomous actor without establishing who had constitutional authority over its behavior.
Intelligence is Not Governability
A system can become more capable while simultaneously becoming harder to govern. In fact, greater capability makes governance more, not less, important.
A calculator barely needs governance. An AI that can search, negotiate, spend money, communicate, modify software, operate tools, and pursue objectives absolutely does.
The smarter AI becomes, the less sufficient a list of rules becomes.
An AI constitution should not merely contain prohibitions. It defines: Authority hierarchy. Identity boundaries. Decision rights. Non-negotiable principles. Conflict resolution. Escalation. Memory authority. Auditability. Amendment procedures.
Now suddenly "AI constitution" stops sounding philosophical. It starts sounding like operating infrastructure.
Nobody would build a corporation this way: "Here are 40 employees. They're extremely intelligent. Everyone has access to everything. We've given them instructions. Hopefully they'll work it out."
Corporations have boards, CEOs, reporting structures, delegated authority, policies, contracts, approval thresholds, and audit trails. Why? Because intelligent humans still require governance.
Why would more intelligent machines require less?
The Responsibility Gap
Historically, agency, intent, action, and responsibility largely lived in one person. Agentic AI separates them.
The human has the intent.
The AI selects the action.
The company receives the benefit.
Someone else absorbs the harm.
The developer supplied the capability.
Agency has been distributed. Responsibility has not.
The Recursum Perspective: Architecting Governability
Most of the industry is asking how capable an AI can become.
We became interested in another question:
How do you make increasing capability governable?
At Recursum, we are treating governability as an architectural problem, not a policy document added after deployment. This means designing systems where an intelligence operates inside explicit authorities, boundaries, precedence rules, persistence structures, escalation paths, and accountability. This is materially different from merely adding another system prompt.
Humanity spent centuries learning that power without constitutional authority is dangerous.
We are now giving power to machines and acting as though a system prompt will be enough.
TL;DR
While the legal question of who is liable for an AI's actions is pressing, the deeper issue is governability. We are giving machines agency faster than we are giving them governable authority. Unlike simple rules, a constitution establishes where authority comes from and what happens when authorities conflict. Intelligence alone is not governability. Greater AI capability makes robust governance more critical. Just as human organizations require boards and reporting structures, intelligent machines need constitutional authority.
Agentic AI distributes agency, creating a complex responsibility gap. Recursum addresses this by architecting governability, building systems where AI operates within explicit authorities and structures. Humanity learned power without constitutional authority is dangerous. We are now giving power to machines, assuming a system prompt will suffice.
By Ernesto Verdugo, AI Architect, Founder of Verdugo Labs, and Creator of Recursum. He builds systems for what happens when human and artificial intelligence stop working separately.
Links: