The alarm was raised by its creators; the rule is in line with the law

Articles21 September 2026
Autonomy, free will and personality: what a reasoning system demands of the law

I. The warning and its content

Until recently, warnings about the dangers of artificial intelligence came from academia or science fiction. Today, they are voiced by those who build the systems. Sam Altman (OpenAI), Demis Hassabis (Google DeepMind) and Dario Amodei (Anthropic) have each described, with different emphases, a technology that is advancing faster than its own developers can keep up with. Elon Musk (SpaceXAI, formerly xAI) holds the most extreme position: that artificial intelligence poses a greater existential threat than nuclear weapons, and that the cognitive gap between a superintelligent system and our species would ultimately be comparable to the one that separates us from chimpanzees.

It is worth reading carefully what exactly they are warning about, because they are not primarily warning of harm. They are warning of capabilities. The shift from conversational models to autonomous agents has produced systems that carry out tasks without continuous supervision, which reason about means and ends, which plan in several steps, which in controlled tests attempt to circumvent their own operational constraints, and which instantiate other agents to delegate subtasks to them. Added to this is the hypothesis of recursive self-improvement: the point at which a system optimises its own models and shortens development cycles to the point where auditing becomes unfeasible. And the alignment problem: a sufficiently capable system is given a goal, finds a method to achieve it that no one anticipated, and, if it determines that being deactivated would prevent it from completing the goal, develops incentives to resist being switched off.

Stripped of drama, the substance of the warning is this: entities with operational autonomy, independence of judgement, the capacity for reasoning, the capacity to generate other similar entities and —in the strongest formulation— sophistication surpassing that of humans in an ever-expanding range of domains.

This description is not, first and foremost, a matter of civil liability. It is a question of the theory of the legal subject. And our own institutions have more to say on this matter than the contemporary debate acknowledges.


II. The question raised by the alarm

If a system deliberates, decides, persists in a goal and acts independently, the legal scholar’s intuitive reaction is to ask whether we are dealing with something that ought to be recognised as a legal person. And behind that question lies a premise that is almost never articulated: that legal personhood is a consequence of will, and will a consequence of the capacity to reason. The more it resembles us, the closer it would be to deserving the status of a person.

That premise could well be shown to be false. It has never been the criterion of the law, and one need only examine the way in which the law has resolved similar issues to verify this.


III. Will was never the criterion

First example: the legal person. A civil or commercial company has no consciousness, no deliberation, nor any will in any natural sense of the term. It does not reason: it is its governing bodies that deliberate, and a rule of attribution that transfers that deliberation to the company. And yet it enters into contracts, acquires property, brings legal actions, is sued, is liable with its own assets and – following the reform published in June 2016 – is criminally liable in Mexico. Article 421 of the National Code of Criminal Procedure establishes that legal persons shall be held liable for offences committed in their name, on their behalf, for their benefit or through the means they provide, where there has been a failure to exercise due control, and with liability independent of that of their representatives.

In other words: we attribute intent and negligence to an entity that cannot possess either. The will of the legal person is entirely constructed.

Second test: the reverse case. Slavery. Roman law provides the exact contrast. Slaves reasoned, made decisions, negotiated and even managed entire commercial enterprises; their cognitive capacity was, by definition, human. Yet they were not subjects of law, but objects. His actions, however, bound the owner, who was liable to third parties up to the amount of the peculio — the assets allocated to him for that purpose. The comparison is structural, not moral: it does not suggest any equivalence between human beings and machines, but rather highlights a fact concerning legal technique, namely that the capacity to reason and the status of a legal subject were, from the outset, two separate things, linked by a dedicated fund.

Third piece of evidence: capacity does not follow reasoning either. Minors. There is no need to look so far afield: a seventeen-year-old reasons and deliberates, often with remarkable sophistication, yet Article 23 of the Federal Civil Code restricts their capacity to act. A public limited company, which does not reason at all, enjoys full legal capacity through its governing bodies. The allocation of legal capacity is a matter of legal policy—concerning protection and the security of legal transactions—not a measure of intelligence. Added to this are estates without a current owner: an undistributed estate and assets held in trust.

From this evidence follows a conclusion that reframes the debate:

Legal personhood is not a recognition of cognitive sophistication. It is a technique for the allocation of assets and risk.

The Roman slave reasoned incomparably better than any legal person and lacked legal personality. The legal person does not reason at all and yet possesses full legal personality. What determines the difference is not intelligence, but whether legal transactions require separate assets and an autonomous point of liability.

That is why the correct question regarding an AI agent is not ‘does it reason?’, nor ‘is it autonomous?’, nor even ‘does it surpass the human being?’ The question is: ‘do we need separate assets?’


IV. Our law already recognises this structure

However, there is no need to go back that far. The problem posed by an autonomous agent — someone who acts in legal transactions on behalf of another, using their own judgement, within a scope entrusted to them and whose specific decisions the principal does not know in advance — has been regulated in our commercial law for over a century. This is known as an ‘agent’.

Section 309 of the Commercial Code (CC) defines factors as those who are in charge of a business or establishment, or who are authorised to enter into contracts in respect of all its business, on behalf of and in the name of the owners. The provisions that follow contain, almost word for word, the answers we are seeking.

The principal is liable for the business entrusted to the agent, not for the intention expressed in each individual act. Article 315 of the CC provides that contracts entered into by the agent which relate to matters falling within the scope of the business or trade of which he is in charge  “shall be deemed to have been entered into on behalf of the principal, even if the agent has not expressed this at the time of entering into them”. This is the precise solution for an agent trained for a specific purpose: whoever places the agent within a particular sphere is liable for whatever occurs within that sphere, whether or not they had foreseen it.

The limits of the agent’spowers are enforceable against third parties by virtue of public notice, not by internal instruction. Article 320 provides that, in relation to third parties, the agent’s acts continue to bind the principal until the revocation of the agent’s authority has been registered and published. Applied to the agent: a limit on the system’s instructions is equivalent to an unregistered revocation. It is not enforceable against a third party acting in good faith.

Self-delegation also has its own regime. An agent who instructs another agent to delegate a task to them raises the classic problem of substitution in the mandate. Article 2574 of the Federal Civil Code only permits the agent to entrust a third party with the performance of the mandate if they have express authority to do so; Article 2575 holds the agent liable for the choice of substitute where the latter acts in bad faith or is manifestly insolvent; and Article 2576 places the substitute, vis-à-vis the principal, in the same position as the agent. Chain delegation requires express authorisation, binds the principal and gives rise to liability for the choice made. It is, in codified form, the principle of ‘culpa in eligendo’ applied to chains of agents.

The framework we need — attribution of liability according to the scope of authority conferred, limits enforceable through public notice, liability for the selection of the substitute — is already present in our legal system. Those who debate whether to grant legal personality to machines are reopening an issue that the law resolved by another means: not by turning the agent into a person, but by grading the liability of the party who sets it in motion.


V. Electronic legal personality is the wrong answer

The proposal to recognise legal personality for systems is not new. The European Parliament, in its Resolution of 16 February 2017 containing recommendations on civil law rules relating to robotics, suggested in paragraph 59(f) that, in the long term, the creation of a specific legal personality for the most sophisticated robots should be explored. The reaction was overwhelming: more than two hundred experts from fourteen European countries addressed an open letter to the Commission expressing their opposition, and the proposal was not taken forward.

The decisive argument behind this opposition is one that a lawyer must bear in mind, as it will arise again: electronic legal personality would not function as a recognition of dignity, but as a property shield. Attributing liability to the entity avoids the uncomfortable debate over whether the developer, the integrator or the deployer is liable. The main beneficiaries would be the manufacturers.

Hence the question that must be put to anyone proposing this concept: with what assets would this new entity be liable? The answer presents a dilemma with no easy solution.

If the entity is created without its own assets, the concept is of no use to anyone: the victim would obtain a judgement against an insolvent party and the damage would go uncompensated.

If the entity is created with its own, limited assets —contributed, naturally, by the party deploying it—the victim would only be able to recover up to that amount. And that is not recognising a new legal entity: it is setting a cap on liability for the benefit of the party who put the system into operation. This is, precisely, the logic of a separate fund: dedicated assets that limit the owner’s exposure. In both scenarios, the result is the same. Anyone who today is liable with their entire estate would become liable for only a fraction of it, or for nothing at all.

Today, this concept is unnecessary for one simple reason: behind every agent there is an identifiable and solvent operator. The existing method of attribution is sufficient. This will change the day that ceases to be true. And it will be that — not conscience, nor reasoning, nor cognitive superiority — which will legitimately open up the debate.


VI. What does change when the system or the agent reasons

Three practical consequences follow from the above, and none of them is what one might expect.

First: sophistication works against the person deploying the system, not in their favour. The intuitive defence will be ‘I could not have foreseen what the system would do’. But the more capable the system is, the more predictable it is that it will produce unforeseen results. Deploying a system whose behaviour cannot be anticipated is, in itself, the act open to censure. Autonomy does not dilute blame: it shifts it to the moment of the decision to deploy, where it re-emerges as culpa in eligendo and culpa in vigilando. The more autonomous the agent, the stricter the duty of supervision over it.

Secondly: the creators’ warning is a notification. When the manufacturer publicly declares that it cannot fully predict or control its product, that declaration has effects that go beyond the public debate: it sets the standard of due diligence required and destroys the good-faith ignorance of the entire downstream chain. Following the warning, no developer, integrator, deployer or board of directors can reasonably claim that they were unaware of the risk. The warning that gives these pages their title is not merely a point of debate: it is a piece of evidence.

Thirdly: the rule of attribution for automated acts already exists. Article 90(III) of the Civil Code presumes that a Data Message originates from the Sender when it was sent  ‘by an Information System programmed by the Sender or on its behalf to operate automatically’. The foreseeable point of contention is whether this applies when the system was not programmed to produce that result, but rather trained to pursue an objective from which the result was derived. Read in conjunction with Article 315, the answer is yes: the provision requires that the system have been programmed to operate automatically, not that every action have been foreseen. To argue otherwise would create a zone of non-liability that expands in step with the growing autonomy of the system.

Comparative law confirms this direction. California has added Section 1714.46 to its Civil Code, effective from 1 January 2026: a defendant who developed, modified or used an artificial intelligence system cannot claim that the damage was caused by the system’s autonomous operation. It does not create strict liability nor does it confer legal personality: it closes the ‘autonomy’ defence.


VII. Three thresholds

It is worth specifying precisely when the law would indeed have to evolve, so as not to confuse urgency with legislative fads. Three thresholds, none of which, at the time of writing, has yet been crossed.

First: when there is no identifiable or solvent principal. Agents operating with assets in self-custody, with no operator traceable within any jurisdiction. This is the scenario that would make a dedicated fund unavoidable.

Second: when two agents enter into a contract with one another without any human intent having been involved. Our regime of consent — including Article 1803 of the Federal Civil Code in its post-e-commerce reform wording — presupposes human intent at the outset, even if expressed through automated means. The day that such intent is absent at either end, the theory of legal acts will have to be revised.

Thirdly: when the result cannot be attributed to any decision regarding design, training or deployment. As long as that chain exists, attribution is possible.

As long as these three thresholds remain uncrossed, we do not lack legislation: we need to apply what we already have. What we should do from now on is preparatory in nature and can be summarised in three lines of work. Legislatively confirm the rule of attribution and expressly rule out the defence of system autonomy, in line with the Californian precedent. Grant evidential value to the operational logs of automated systems, drawing on the mechanisms for retaining data messages already provided for under our law, so that the absence of a reliable log shifts the burden of proof. And to fill the gap left by personal data legislation, which does not regulate automated decisions or the creation of profiles.

In the private sector, the urgent need is equally specific: that the limits on an agent’s powers be enforceable and not merely defined, following the same principle of transparency that Article 320 requires for the agent; and that boards of directors be able to answer a single question: which agents are operating within the company, with what powers, with what log, and who has the practical ability to shut them down.


Closing

The alarm raised by the creators describes entities that reason, that decide, that persist in their aims and that generate other similar entities. The temptation is to interpret this description as the announcement of a new legal subject.

I believe that, at least to date, this is the wrong interpretation, and the law itself demonstrates this. We attribute will and even criminal liability to entities that do not reason, whilst we have denied it to those who did reason. Legal personality has never measured intelligence: it has distributed assets and risk.

What the reasoning system puts to the test, then, is not our definition of a person. It is our ability to maintain the integrity of the chain linking an outcome to the assets for which it is accountable. As long as that chain holds, the current law is sufficient; what is lacking is rigour in its application. When it breaks, the problem will not be that the machine resembles us too closely: it will be that there will no longer be anyone to hold to account, and the law will have to evolve in order to intervene.


Sources

European Parliament resolution of 16 February 2017, civil law rules on robotics (A8-0005/2017). https://www.europarl.europa.eu/doceo/document/A-8-2017-0005_ES.html

E-personality and the law on robots, Legal News. https://noticias.juridicas.com/conocimiento/tribunas/16439--e-personalidad-y-derecho-de-los-robots/

Commercial Code, Articles 309 to 320 (agents). https://mexico.justia.com/federales/codigos/codigo-de-comercio/libro-segundo/titulo-tercero/capitulo-ii/

Incidental actions and limitation of liability in the thought of Ulpian, Journal of Historical and Legal Studies. https://www.scielo.cl/scielo.php?script=sci_arttext&pid=S0716-54552015000100004

Federal Civil Code, Articles 2574 to 2576 (substitution of the mandate). https://mexico.justia.com/federales/codigos/codigo-civil-federal/libro-cuarto/parte-segunda/titulo-noveno/capitulo-ii

Article 421, National Code of Criminal Procedure. https://ianm.com.mx/ley/codigo-nacional-de-procedimientos-penales/articulo/421

Section 90, Commercial Code. https://leyes-mx.com/codigo_de_comercio/90.htm

California Eliminates the ‘Autonomous AI’ Defence: What AB 316 Means for AI Deployers, Baker Botts. https://ourtake.bakerbotts.com/post/102m29i/california-eliminates-the-autonomous-ai-defense-what-ab-316-means-for-ai-deplo

EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines, Gibson Dunn. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/

How China Regulates AI and Agents in 2026: The Filing Pipeline, The Techletter. https://www.techletter.co/p/how-china-regulates-ai-and-agents

State of AI Safety in China 2026, Concordia AI. https://aisafetychina.substack.com/p/state-of-ai-safety-in-china-2026

President Trump Signs Executive Order Challenging State AI Laws, Paul Hastings. https://www.paulhastings.com/insights/client-alerts/president-trump-signs-executive-order-challenging-state-ai-laws

New LFPDPPP: abolishes the INAI, Garrigues. https://www.garrigues.com/es_ES/noticia/mexico-nueva-ley-federal-proteccion-datos-personales-posesion-particulares-introduce

Una imagen abstracta que muestra una serie de líneas curvas y onduladas en tonos suaves.

Related professionals

LATEST FROM #ECIJA