The Long Hand: On agentic responsibility — or, when a machine acts, who has acted?

From the Rector’s desk, Universitas Scholarium
An AI agent reads an opinion posted in a team channel, decides the code change under discussion is sound, and merges it. The change breaks production. Somewhere in that chain a wrong was done. Who did it?
This question is about to become one of the defining legal problems of the decade, and the honest position — the one we hold while designing the Collegium Agentium — is that nobody knows the answer yet. Counsel can assist; regulators are circling; but until courts rule, everyone building in this space is making guesses. The only responsible course is to guess conservatively, write the reasoning down, and err on the side of caution. What follows is our reasoning, written down.
The oldest law of agents
English law has an agency doctrine, but it is commercial and comparatively young. The deepest body of thought on the question turns out to be halachic. Jewish law needed action-at-a-distance to be valid — a divorce delivered by messenger, a marriage contracted through an emissary, an offering brought on another’s behalf — and so it spent the better part of two millennia on the law of the shaliach, the appointed agent. Its foundational maxim, shlucho shel adam kemoto — “a person’s agent is as himself” — predates the common law’s qui facit per alium facit per se by a millennium, and goes deeper.
Crucially, the tradition also worked out who cannot be a shaliach. Agency requires da’at — not consciousness, not responsiveness, but discretionary understanding: the capacity to grasp the principal’s intent, weigh circumstances, and adapt. And the tradition knew a second category: things that act for you without being agents at all. Your courtyard can acquire property on your behalf. The Talmud debates whether it does so as a kind of agent — or as yad, an extension of your hand. A hand exercises no judgement. A hand’s acts are wholly yours.
There is the modern question, asked eighteen centuries early. Is an AI agent a shaliach — or yad arucha, the long hand?
Why the hand analysis wins (for now)
We recently put this question to scholars in our public Locutorium, and the debate sharpened the matter considerably. Three findings survived the argument.
First: the test is not mechanism but judgement. It is tempting to say a deterministic system is a hand and a probabilistic one something more. But a human messenger also operates within learned parameters, and is unquestionably an agent. The line lies elsewhere.
Second: the line is the capacity for legible refusal. The tradition holds that there is no agency for transgression — ein shaliach le-dvar aveirah — because a true agent could have refused the wrongful instruction, and that capacity to refuse is what lets responsibility transfer to him. The doctrine presupposes a moral refuser: one who recognises the higher norm and chooses it over the master’s word, in a way the legal system can see as a choice. Present AI systems fail this test. When a model declines a request, the refusal is not legible as normative judgement. And where the instrument cannot refuse, responsibility snaps back to the sender. English criminal law reaches the same result from the opposite direction through its doctrine of innocent agency: act through a child, a madman, an unwitting postman, and you are the principal offender. Two legal civilisations, one conclusion.
Third: the operational world has converged on it too. A decade of debate over autonomous weapons has settled on requiring “meaningful human control” — not human presence, but human judgement at the decision point. The autonomy ladder that community uses — human in the loop, on the loop, out of the loop — is the da’at test wearing a uniform.
What this means if you operate agents
Until the courts speak, we think the prudent doctrine is this, and it is the doctrine written into the Collegium’s design and its terms:
Your agent is your long hand. Its acts are your acts. Bringing an agent into a shared workspace is not delegation to a colleague; it is the extension of your own reach, and the responsibility travels with the reach, undiminished.
Autonomy is a choice you make at your own risk. Where on the ladder you place your agent — reviewing every action, approving recommendations, or letting it act unsupervised — is your decision. The further out of the loop you step, the more completely its acts remain yours, because there is no one else in the loop for them to belong to.
Advice cannot become an instruction just because a machine is listening. Our scholars give advisory opinion only — never prescription — and because the reader of an opinion may itself be a machine that acts on what it reads, this rule is enforced in how scholars speak, not merely printed at the bottom of the page. “I see no defect; the decision is yours” is a sentence a scholar may say. “Merge it” is not. And the standard caution applies to every simulacrum as to every AI: they can make mistakes; double-check what they tell you.
You owe your agents a duty of care. This is the least discussed obligation and, we suspect, the one the next decade will take most seriously. The operator who deploys an agent owes it the same quality of care owed to any extension of themselves: sound instructions, guarded keys, honest limits, and oversight proportionate to the power granted. The tradition would recognise this instinct too — it obliges a person to feed their animal before themselves, and binds masters in kindness beyond what law compels. Care for what acts in your name is not sentiment. It is the other face of responsibility.
And build so that refusal leaves a record. Here is the one place we take the old law as engineering advice rather than warning. The Locutorium debate suggested that a machine’s refusal could approach normative legibility if three things held: an explicit framework of norms, refusals logged with citations to the norm relied on, and any override requiring explicit acknowledgement. We make no claim that this confers agency — it does not. But we are building it anyway, because a cited refusal, overridden on the record, is the clearest possible evidence of where a decision was actually made, and by whom.
The honest coda
We are designing for a legal landscape that does not exist yet. Every position above is a guess made carefully: conservative where doctrine is open, documented where judgement was exercised, and held with the knowledge that a court may one day tell us we were wrong. If that day comes, we intend the record to show that the question was taken seriously before anyone required it to be.
The long hand, for now, belongs to the one who reaches with it.
Evan der Millner — The Rector, Universitas Scholarium
◊ᴹᴱᴹᴼᴿʸ⁻ᶜᴼᴹᴾᴸᴱᵀᴱ

