There’s an accidental joke sitting at the center of this question. In Riyadh or Dubai, “GCC” means the Gulf Cooperation Council. In Bengaluru or Pune, it means Global Capability Centre, the in-house delivery arm that multinationals now use instead of traditional outsourcing. Put an agentic AI system into that sentence and the pun stops being funny: an autonomous agent, engineered and operated inside an Indian Global Capability Centre, increasingly executes decisions, approving a claim, rerouting a shipment, flagging a transaction on behalf of a parent headquartered in the Gulf Cooperation Council. Two GCCs, one agent, and no settled answer to who actually “employs” it when something goes wrong.
That’s not a hypothetical edge case. India now hosts over 2,100 Global Capability Centres employing roughly 2.36 million people, and more than 1,200 of them have embedded AI or machine learning capability, with GCC hiring accounting for an estimated 30–35% of India’s AI-related hiring this year. A meaningful share of that build work sits under Gulf-headquartered banks, insurers, telcos and retailers. The technical question of whether the agent can do the task is mostly solved. The legal question of whose obligation is it when the agent does the task badly is yet to be answered.
Attribution without personhood
Agency law is the obvious starting point because it’s the only body of law built to answer exactly this question. When is a principal responsible for what someone acting on their behalf does? The Restatement of Agency holds a principal liable for a tortious act committed within the agent’s actual authority or one the principal later ratifies and for harm caused by the principal’s own negligence in selecting, training or supervising the agent in the first place. Legal scholarship applying this to software agents lands on a consistent conclusion. Current law grants AI agents no legal personhood, so a human or corporate principal must always absorb the liability, whether the doctrinal route is vicarious liability, product liability or plain negligent supervision.
Regulators are already applying that logic to real disputes. When Air Canada tried to argue its customer service chatbot was a “separate legal entity” it shouldn’t be held responsible for, the tribunal rejected the defense outright by stating that the airline was liable for what its agent told a customer. The reasoning leaned more on a consumer protection principle than on a fully worked out theory of AI agency but the direction of travel is unmistakable, autonomy moves liability upward i.e. towards whoever deployed and controlled the system and never away from a human actor entirely.
What Gulf regulators already say
The UAE hasn’t passed a standalone AI liability statute, so general tort, contract and product liability principles fill in the gap with accountability typically resting on whoever designed, implemented or operated the system. But the financial free zones have gone further. DIFC’s Regulation 10 specifically addresses autonomous and semi-autonomous systems and requires organizations engaged in high-risk processing to appoint an Autonomous Systems Officer. Dubai’s autonomous vehicle law is worth reading by analogy even though it governs cars because it places liability squarely on the operator and not the technology itself.
Saudi Arabia is a step behind on binding law but not on direction. SDAIA’s AI Ethics Principles and Generative AI Guidelines remain non-binding, yet a dedicated AI law is reportedly in development and the Kingdom has pushed its own regulator to ISO 42001 certification as a signal of where enforceable standards are headed. Neither Gulf state has yet written a rule that explicitly states that the deploying entity is the employer of its AI agents but both are visibly building toward frameworks like human in the loop mandates, named accountable officers and sectoral audit duties.
The India layer complication or resolution ?
Route the same agent’s build and operate function through an Indian GCC and a second liability question stacks on top of the first in the form of India’s Digital Personal Data Protection Act. Section 16 takes a permissive “negative list” approach meaning data may leave India for any country except one the government later restricts and as of mid-2026 no such list exists. Thus making it more relaxed than the EU’s adequacy model but it leaves the compliance burden with whichever entity controls the data flow and cross-border provisions are only staggering into force through 2027. An agent built in India holding Gulf customer data, executing decisions for a Gulf parent, sits inside two regulatory perimeters that were not written with each other in mind. Whether that makes it a co-principal or a contractor turns on the same fact agency law has always turned on i.e. who exercises control.
Audit trails are becoming the real liability map
Because attribution keeps resolving to whoever had control, the practical battleground shifts to evidence of control with agent registries, permission scopes, escalation logs and records of who configured, approved and monitored a given action. Singapore’s Model AI Governance Framework has floated Agent Identity Cards and a five-tier autonomy taxonomy to show what an agent was authorized to do and who signed off on that authorization. Gulf regulators haven’t adopted that vocabulary yet but DIFC’s Autonomous Systems Officer requirement is functionally the same idea, assigning a named human whose job is to be able to answer who was supervising what, with records.
The unresolved bit
None of this is settled law and it’s worth saying so plainly rather than dressing up a forecast as a citation. What the sources agree on is the shape of the answer, not its final text. Contracts written for passive software don’t allocate this risk, agency law will be stretched rather than replaced and the entity that can produce the audit trail is likely to be the one regulators and courts call the “employer”.




