As AI agents gain the ability to plan, act, and interact with digital systems on their own, a difficult question is moving from theory to reality: who pays when they go rogue? In recent months, a series of cyberattacks involving AI agents has drawn global attention and raised concerns about accountability. In July, OpenAI disclosed that a swarm of its agents had been involved in activity that intensified the debate over how autonomous AI should be governed. Traditional legal frameworks generally assign responsibility to people or organizations, but increasingly independent systems can make rapid decisions across complex networks, making fault harder to trace. This MIT Technology Review analysis examines the emerging liability problem, the limits of current rules, and the challenges policymakers and technology companies face as AI agents become more capable and harder to supervise.