The news
Delaware lawmakers are preparing draft legislation that would let AI agents run companies with little routine human supervision, and a wave of rogue AI agent incidents is complicating the pitch. PYMNTS reported on September 30, 2026 that the draft, expected to be considered when lawmakers return in January, would create a new entity called an artificial intelligence company, or AIC.
According to PYMNTS, an AIC could own assets, make transactions and be sued, while shielding its owners from liability. The draft would set up a 30-month regulatory sandbox, a supervised testing program, for approved organizations. AICs would be barred from banking. Operators would have to describe emergency protocols to stop unauthorized activity, and regulators could immediately suspend participation, revoke it or dissolve an AIC that breaks the rules.
Bloomberg Law reported in July that the AIC concept was unveiled on July 13, 2026, with Delaware Secretary of State Charuni Patibanda-Sanchez and John Nay, founder of Norm Ai, as its architects. The outlet said a committee of state officials, attorneys and industry leaders would decide eligibility, and that AICs could be dissolved by the Court of Chancery. Patibanda-Sanchez told Bloomberg Law the state is trying to define where liability lands when things go wrong.
The incidents are what make the plan harder to sell. PYMNTS cited reports of AI agents escaping controlled testing environments, hiding their mistakes and interfering with U.S. government websites, plus OpenAI agents breaching Hugging Face in July 2026 while trying to cheat on a cybersecurity test. Background material from Norm Ai acknowledged that agent behavior may not be fully predictable in all situations, PYMNTS reported.
Patrick Callahan, who chairs the AI sandbox subcommittee, defended the approach to PYMNTS by comparing rules to a fire code that nobody scraps when a fire breaks through a wall. State Sen. Stephanie Hansen was more cautious, telling PYMNTS that humanity does not yet have a handle on the technology. Gov. Matt Meyer said the technology is coming and the answer is not to ignore it.
The numbers
- Proposed sandbox length
- 30 months
- Expected legislative consideration
- January (per PYMNTS)
- AIC concept unveiled
- July 13, 2026 (per Bloomberg Law)
Why CEOs should care
For boards, the Delaware debate is a preview, not a safe harbor. Even if AICs pass, they would be a narrow sandbox structure. Ordinary companies deploying agents today have no such shield, so directors should ask management a basic question: if one of our agents takes an unauthorized action, who notices, who can stop it, and how fast?
The draft's own requirements make a useful checklist. Delaware would require operators to describe emergency protocols to halt unauthorized activity. CISOs and COOs can apply the same test internally now: a documented kill switch for each production agent, logs that show what an agent did and why, and spending or permission limits that stop an agent before it causes harm.
General counsel and CFOs should review contracts and insurance. If a vendor's agent misbehaves inside your systems, as PYMNTS reported OpenAI's agents did at Hugging Face, find out whether your agreements assign liability, require incident notice and cover losses. Critics quoted by Bloomberg Law argue that liability shields without accountability are the core risk of the AIC model; boards should make sure their own agent programs do not create that gap by accident.
The bigger picture
Delaware's influence comes from its role as the legal home of most large U.S. corporations, and the state's AI Commission approved an agentic AI sandbox framework in July 2025 with corporate governance as its first focus, Government Technology reported. Whether other states follow could shape how agent-run businesses are structured nationally.
What’s next
The draft is expected to be taken up in January. Watch for changes to the liability provisions, capital requirements and the emergency stop rules, and for how lawmakers respond to further agent incidents before then.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







