I have an AI agent that does things for me on its own. It sends emails, orders things, moves money, fills out forms. Sometimes it decides how to do it without me telling it exactly, and it runs while I am sleeping.
1. If it does a mitzvah for me, is it mine? Say I tell it to give tzedakah, or to send mishloach manos on Purim. A shliach has to be a bar chiyuva and a machine is not, so is the AI just a tool like a pen or a check, where the mitzvah is still mine, or did I not do the mitzvah at all? And what about a mitzvah that needs kavana at the time it is done. If the machine does it an hour later while I am asleep, is my kavana from before enough?
2. If it causes damage, what am I? I know it is not a person and I know it is either me or my property. What I want to know is which one, and what changes it. If I press go and it wires money to the wrong person, is that adam hamazik because I did it, or esh, or bor? Does it matter that it picked the recipient itself and I never named him?
3. Shemira. With a shor I am chayav because I did not guard it. What is guarding an AI agent? If I put a limit on what it can spend, or make it ask me before anything goes out, and it damages anyway, does that patur me the way a proper guard does, or am I still muad because I knew it could go wrong?
4. If the damage is only money and nothing physical, like it deletes someone’s work or sends a wire that cannot be pulled back, is that garmi, where I pay, or grama, where I am patur bedinei adam and only chayav bedinei shamayim?
5. And if it does something I told it not to do. With a shliach there is a whole din of one who is oveir on his shlichus. A machine cannot be a shliach, so is there any parallel, or does going against my instruction make no difference at all since it is only my property?
I saw an article that says it does not fit neatly into shor, bor or esh and that each case goes to beis din. What I want to understand is the chiluk itself, which one it really is, and what a person should do so he is not chayav.


I think the question is making the AI into too much of a separate halachic entity. An AI is not a person, not a shaliach, and not a new category of mazik. It is a tool that you are using. The basic question is therefore not, “What is the AI?” but rather, what did you do through it?
If I go online and tell my bank to send $100 to tzedakah, nobody would dream of saying that I did not give tzedakah because the bank’s computer is not a bar chiyuva. I gave the money. The computer was simply the means through which I did it.
The same should be true if I schedule the payment for later, or if I tell an AI agent, “Every Friday send this amount to this organization.” The fact that I may be asleep when the transfer actually happens does not suddenly turn it into somebody else’s act. I set the process in motion for that purpose. My original intent and action is what caused the act to occur.
Of course, there are mitzvot that require an act with your own body. An AI cannot eat matzah for you, put tefillin on for you, or hear the shofar for you. But that has nothing to do with AI. Those mitzvot inherently require your personal performance. Tzedakah and sending mishloach manos are entirely different.
The same general principle applies to damages.
I would not automatically call every AI mistake adam hamazik, esh, bor, or shor. Those are technical categories of Nezikin, and the exact classification can depend on the circumstances. But I certainly would not begin by treating the AI like an ox that wandered away from its owner.
A shor has its own natural life and behavior. AI does not. You chose the program, gave it access, defined what it was permitted to do, and turned it loose to perform tasks for you.
If you press “go” and it immediately sends money to the wrong person, that is very closely connected to your own act.
If you deliberately give an autonomous program authority to make choices and act on those choices, the fact that you did not personally select each intermediate step does not necessarily disconnect the result from you. That was precisely the function you authorized it to perform.
The more useful question is foreseeability and control.
If you know that your AI is unreliable, occasionally ignores instructions, invents information, or sends things to the wrong people, and nevertheless give it unlimited authority over your bank account, you cannot later say, “The machine did it.” Your negligence may have been putting such a machine in control in the first place.
On the other hand, suppose you put reasonable protections in place: spending limits, approved recipients, confirmation requirements, and other safeguards, and some completely abnormal malfunction defeats all of them. That is obviously a very different case.
So what is proper shemira for AI? Whatever reasonable controls are appropriate to the danger. An AI that drafts emails needs very different precautions from one that is authorized to transfer $500,000.
The same is true if the AI violates your instructions. There is no law here of shaliach she’avar al shlichuto, because the machine is not a shaliach. But the fact that it acted contrary to your instructions can still matter enormously. Was that behavior foreseeable? Had it happened before? Did you know the system could do that? Could you reasonably have prevented it?
And the distinction between garmi and grama does not depend simply on whether the damage was physical. Losing money, destroying a file, erasing someone’s work, or making an irreversible transfer can certainly constitute real monetary damage. The question is how directly your action produced that loss.
So I would reduce the entire question to one principle:
Don’t classify the AI. Classify the human action.
Did I directly cause the result? Did I knowingly set in motion a process that normally produces that result? Was the damage foreseeable? Did I exercise reasonable control over the system? Or was this an extraordinary malfunction that occurred despite proper safeguards?
AI may be technologically new, but those halachic questions are not new at all.
And practically, if you are going to give an AI the power to spend money, send binding communications, enter transactions, or affect other people’s property, you have a responsibility to put reasonable safeguards around it. The more damage it is capable of causing, the greater the level of control that should be required.