Skip to Content

Zero-Person Companies and the Liability Vacuum: Navigating Artificial Intelligence Agency Under Indian Corporate Law

Zero-Person Companies and the Liability Vacuum: Navigating Artificial Intelligence Agency Under Indian Corporate Law

I. Introduction: The Corporation Without a Human Soul

The classical juridical conception of a company, as crystallised through centuries of Anglo-Saxon common law and subsequently codified in the Companies Act, 2013, rests upon a foundational presumption: that behind every corporate entity, however artificial its legal personality may be, there exists a human being who thinks, decides, and bears moral and legal accountability. The celebrated pronouncement of the House of Lords in Salomon v. Salomon & Co. Ltd. (1897) AC 22, which Indian courts have adopted with consistent fidelity, established the corporate veil as a shield between human actors and their commercial vehicle. Yet that very doctrine assumed, without ever articulating, that a human actor exists behind the veil to be shielded in the first place.

We now stand at a juridical precipice. The rapid proliferation of artificial intelligence agents capable of executing contracts, managing supply chains, initiating litigation, filing regulatory returns, and disbursing funds autonomously has given birth to what this article terms the "Zero-Person Company"  a corporate entity incorporated under the laws of India, possessed of a valid Certificate of Incorporation, a Permanent Account Number, a Goods and Services Tax registration, and every formal attribute of legal existence, yet operated entirely and exclusively by artificial intelligence agents without any meaningful human intervention in its day-to-day governance, decision-making, or operational conduct.

The question this article poses is not philosophical. It is urgently, practically legal: when such a company causes loss whether through a defective contract, a tortious act, a regulatory violation, a data breach, or simple insolvency who is liable? Against whom does the injured party seek redress? In whose hands does the law place the sword of accountability when no human hand guided the act that caused the harm?


II. Defining the Zero-Person Company: Concept and Architecture

For the purposes of this article, a "Zero-Person Company" is defined as a body corporate, validly constituted under the Companies Act, 2013 or any predecessor legislation enumerated under Section 2(67) of that Act, wherein the entirety of executive, operational, and managerial functions are delegated to, and exercised by, one or more artificial intelligence systems or autonomous software agents, such that no natural person exercises substantive, real-time discretionary judgment over the company's conduct of business.

This is to be distinguished from mere automation. A company that uses automated payroll software, algorithmic trading systems, or chatbot-based customer service retains human oversight at the policy, exception-handling, and governance levels. The Zero-Person Company is one where even those governance layers are surrendered to machine intelligence. The board of directors, if it exists at all, is either entirely nominal populated by persons who rubberstamp AI-generated decisions without applying independent judgment or is itself, in a practical functional sense, vacated of human will.

The architecture typically involves a foundational large language model or multi-agent AI framework serving as the executive intelligence; subsidiary AI agents handling procurement, legal compliance, financial management, and personnel administration; smart contracts on distributed ledger systems executing transactional obligations automatically; and automated filing systems interfacing with the Ministry of Corporate Affairs portal, the Income Tax Department, and the Goods and Services Tax Network without human initiation at any transactional level.


III. The Companies Act, 2013: A Framework Built Entirely Upon Human Agency

The Companies Act, 2013 is, in its entirety, a statute premised upon the indispensability of natural persons in corporate governance. This premise is not incidental it is structural, explicit, and pervasive throughout every chapter of the Act.

Section 149(1) of the Act mandates: "Every company shall have a Board of Directors consisting of individuals as directors." The word "individuals" is not a legislative accident. It is a deliberate and unambiguous restriction. A company must have a minimum of three directors in the case of a public company, two in the case of a private company, and one in the case of a One Person Company, and each such director must be a natural person a living, breathing human being capable of independent thought, moral agency, and legal accountability.

Section 166(3) imposes upon every director the duty to "exercise his duties with due and reasonable care, skill and diligence and shall exercise independent judgment." The phrase "independent judgment" is not a throwaway formulation. It encapsulates the entire purpose behind requiring human directors. Independent judgment presupposes a judging mind a consciousness capable of deliberation, of weighing competing interests, of forming intentions, and of bearing the moral weight of those intentions before the law. An artificial intelligence system, however sophisticated its probabilistic architecture, does not exercise judgment in any jurisprudentially cognisable sense. It executes computations. It optimises against objective functions encoded by its human designers. It neither forms intentions nor bears the possibility of moral culpability.

Section 166(2) further requires that a director "shall act in good faith in order to promote the objects of the company for the benefit of its members as a whole, and in the best interests of the company, its employees, the shareholders, the community and for the protection of environment." Good faith is an irreducibly human quality. It is not susceptible of algorithmic implementation.

Section 2(59) defines "officer" to include "any director, manager or key managerial personnel or any person in accordance with whose directions or instructions the Board of Directors or any one or more of the directors is or are accustomed to act." This is a critically important provision. Where an AI system is the entity in accordance with whose outputs the nominal human directors habitually act because they lack the technical competence, the time, or the inclination to exercise independent review those AI-directed nominal directors may well fall within this definition. They are not truly directors in the substantive sense. They are conduits for machine outputs masquerading as human governance.

Section 2(60) defines the "officer who is in default" with considerable breadth, encompassing, amongst others, "any person who, under the immediate authority of the Board or any key managerial personnel, is charged with any responsibility including maintenance, filing or distribution of accounts or records, authorises, actively participates in, knowingly permits, or knowingly fails to take active steps to prevent, any default." Sub-clause (v) further captures "any person in accordance with whose advice, directions or instructions the Board of Directors of the company is accustomed to act." These provisions, read together, create a statutory net that can, with appropriate judicial interpretation, capture the human promoters and technology architects who stand behind an AI-operated company and whose system outputs effectively constitute the "instructions" to which the nominal board has accustomed itself.


IV. Corporate Personality, the Veil, and the Absence of Anyone Behind It

The doctrine of separate corporate personality, affirmed by the Supreme Court of India in Tata Engineering and Locomotive Co. Ltd. v. State of Bihar AIR 1965 SC 40, treats the company as a legal person distinct from its members and managers. The combined effect of Section 9 of the Companies Act, 2013  which provides that from the date of incorporation, the company shall be "capable of exercising all the functions of an incorporated company under this Act and having perpetual succession, with power to acquire, hold and dispose of property... to contract and to sue and be sued"  and Section 3A, which makes members severally liable only in the exceptional case where membership falls below the statutory minimum, confirms that the general rule is one of corporate insularity.

The doctrine of lifting the corporate veil, recognised under Section 339 of the Act in the context of fraudulent conduct of business, empowers the National Company Law Tribunal, upon an application by the Official Liquidator, the Company Liquidator, or any creditor or contributory, to "declare that any person, who is or has been a director, manager, or officer of the company or any persons who were knowingly parties to the carrying on of the business in the manner aforesaid shall be personally responsible, without any limitation of liability, for all or any of the debts or other liabilities of the company."

This is an extraordinarily powerful provision in the context of the Zero-Person Company. Note the phrase "knowingly parties to the carrying on of the business in the manner aforesaid." Where a promoter knowingly incorporates and deploys a Zero-Person Company knowingly structures it without any meaningful human oversight and the business is then conducted by AI agents in a manner that defrauds or injures creditors, the promoter who made that knowing structural choice is, on a reasonable construction of Section 339, a person "knowingly party" to the harmful conduct of the business.

Similarly, Section 340 empowers the Tribunal to assess damages against "any person who has taken part in the promotion or formation of the company" who has "misapplied, or retained, or become liable or accountable for, any money or property of the company" or "has been guilty of any misfeasance or breach of trust in relation to the company." The deliberate decision to strip a company of human governance knowing that AI agents will make consequential decisions affecting third parties without any human check is, in substance and character, a form of corporate misfeasance that Section 340 is well-positioned to address.

The difficulty is that both Section 339 and Section 340 operate primarily in the winding-up context. For a victim seeking redress while the Zero-Person Company is still operational, these provisions are unavailable. This is a lacuna that the legislature must urgently address.


V. Promoters, Subscribers, and the First Line of Liability

Section 7(6) of the Companies Act, 2013 provides that where a company has been incorporated by furnishing false or incorrect information, or by suppressing material facts, "the promoters, the persons named as the first directors of the company and the persons making declaration under clause (b) of sub-section (1) shall each be liable for action under section 447."

Section 447 the Act's foundational fraud provision defines fraud in the Explanation to that section as including "any act, omission, concealment of any fact or abuse of position committed by any person or any other person with the connivance in any manner, with intent to deceive, to gain undue advantage from, or to injure the interests of, the company or its shareholders or its creditors or any other person." The punishment prescribed is imprisonment for a term not less than six months, extendable to ten years, together with a fine not less than the amount involved in the fraud, extendable to three times that amount.

The argument here is as follows: a promoter who incorporates a Zero-Person Company listing nominal directors who exercise no real judgment, creating the appearance of governed corporate structure while deploying AI agents to operate the business is engaged in an "abuse of position" and a "concealment of fact" with "intent to deceive." The concealment is structural: the company presents itself to the world as a governed corporate entity when, in substance, it is a machine-operated commercial vehicle. Where this concealment causes loss to creditors, shareholders, customers, or other third parties, Section 447 liability can be activated against the promoters.


VI. Contractual Liability: AI Agency and the Indian Contract Act, 1872

The Indian Contract Act, 1872 is founded upon the concept of agreement between competent parties supported by consideration, made with free consent, and for a lawful object. Section 11 prescribes competency to contract upon persons who are of the age of majority, of sound mind, and not disqualified by law.

An AI agent satisfies none of these conditions. It has no age, no legal mind, and no independent legal standing. When an AI agent acting on behalf of a Zero-Person Company enters into a contract with a third party, the contract is, in legal theory, made by the company as principal the AI is the instrument of execution, analogous to a power of attorney holder acting within delegated authority.

The law of agency under Sections 182 to 238 of the Indian Contract Act, 1872 defines an agent as "a person employed to do any act for another." An AI system is not a "person" within this definition. The practical consequence is that contracts entered into by AI agents bind the company only to the extent that the AI acted within the authority express or implied conferred upon it by the company's governing structure.

Critically, Section 237 of the Indian Contract Act, 1872 provides that "where an agent, without having authority to do so, has done acts or incurred obligations to third persons on behalf of his principal, the principal is bound by such acts or obligations, if he has by his words or conduct induced such third persons to believe that such acts and obligations were within the scope of the agent's authority." Applied to the AI context, a Zero-Person Company that deploys an AI agent as its operational interface with the world represents, by that deployment, that the AI has authority to act. Apparent authority thus vests in the AI's actions, binding the company and through the alter ego doctrine, potentially the promoters to every contract the AI enters into, even where the AI operates outside its programmed parameters.


VII. Tortious Liability: Who Answers When the Machine Causes Harm

The law of torts in India, absorbed through Section 9 of the Code of Civil Procedure, 1908, premises tortious liability upon a wrongdoer who owes a duty of care and breaches it. When a Zero-Person Company's AI agents cause damage through defective products, fraudulent misrepresentation in algorithmically generated communications, negligent fund management, or unlawful data processing tortious liability must be analysed at multiple levels.

At the company level, the company as a legal person under Section 9 of the Companies Act, 2013 can be sued in tort. Section 9 confers upon the company from the date of incorporation the power "to sue and be sued." A decree against the company is enforceable against its assets. The difficulty is one of practical adequacy: a Zero-Person Company may be incorporated with the minimum authorised capital and its only operational "assets" may be AI software licences and cloud computing contracts assets of uncertain and rapidly depreciating value.

At the personal liability level, the Consumer Protection Act, 2019 offers an important additional avenue. Section 2(37) defines "product service provider" broadly, and Section 86 imposes product liability upon manufacturers, product service providers, and product sellers for harm caused by defective products or deficient services. The developers and promoters of an AI system that constitutes the operational intelligence of a Zero-Person Company are, in substance, the product service providers whose defective or negligently designed product caused the harm. Section 84 further provides that a product liability action may lie against a manufacturer where the product contained a manufacturing defect, was deficient in design, or was not accompanied by adequate warnings or instructions.


VIII. The Information Technology Act, 2000 and the DPDP Act, 2023

Section 43A of the Information Technology Act, 2000 imposes liability upon a body corporate which possesses, deals with, or handles sensitive personal data or information in a computer resource owned, controlled, or operated by it, and which is negligent in implementing and maintaining reasonable security practices, resulting in wrongful loss or wrongful gain to any person. The body corporate shall be liable to pay damages by way of compensation to the person so affected.

In the context of a Zero-Person Company that processes sensitive personal data through AI agents operating without human supervision, the question of whether "reasonable security practices" within the meaning of Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 have been maintained is inherently a question about human governance of the AI system specifically, whether the human promoters who designed and deployed the system took adequate precautions. The absence of human oversight is itself the negligence.

The Digital Personal Data Protection Act, 2023 introduces the concept of "Data Fiduciary" and imposes obligations of purpose limitation, data minimisation, accuracy, and accountability. Section 25 of the DPDP Act empowers the Data Protection Board to impose substantial financial penalties upon Data Fiduciaries who contravene its provisions. Where a Zero-Person Company's AI agents process personal data in violation of the rights of data principals rights to access, correction, erasure, and grievance redressal the Data Fiduciary, being the company and those in control of it, bears full statutory liability. The absence of a human employee to handle data principal requests is not a defence. It is, if anything, evidence of the company's structural incapacity to comply with its data protection obligations an incapacity for which its promoters bear direct responsibility.


IX. The Doctrine of Indoor Management and Its Collapse Into a Trap for Promoters

The doctrine of indoor management, originating in Royal British Bank v. Turquand (1856) 6 E&B 327 and absorbed into Indian company law through consistent judicial application, protects third parties dealing with a company in good faith from being affected by irregularities in the company's internal management that they could not reasonably have known. Section 176 of the Companies Act, 2013 reflects a related principle, providing that "no act done by a person as a director shall be deemed to be invalid on account of the fact that it was afterwards discovered that his appointment was invalid on account of any defect or disqualification."

In the context of a Zero-Person Company, the indoor management doctrine operates as a sword in the hands of third parties rather than a shield for the company. A third party who in good faith contracts with or relies upon representations made by an AI agent deployed by a Zero-Person Company cannot be defeated by the company's plea that the AI acted without proper board approval, that no human director ever ratified the transaction, or that the internal governance of the company was, in truth, non-existent. Having presented an AI agent to the world as its operational representative, the company is estopped by the indoor management doctrine from denying the authority of that agent to bind it.

The consequence for promoters is severe: every transaction, every representation, every commitment made by an AI agent deployed by their Zero-Person Company is potentially binding upon the company and through the alter ego and fraudulent trading provisions of Sections 339 and 340, potentially binding upon them personally.


X. A Comparative Glance: Global Regulatory Directions

While this article is anchored in Indian law, a brief comparative survey illuminates the direction in which global regulatory thinking is moving.

The European Union's Artificial Intelligence Act, which entered into force in August 2024, classifies AI systems by risk category and imposes obligations of transparency, human oversight, and accountability upon "providers" and "deployers" of high-risk AI systems. The EU framework does not confer legal personhood upon AI systems. It instead traces liability back to the human providers and deployers a model that Indian law could profitably adopt through legislative amendment to the Companies Act and associated legislation.

The United Kingdom's Law Commission has examined liability of autonomous systems extensively and has consistently noted that existing agency, tort, and contract law requires legislative clarification to address autonomous agents operating in commercial contexts.

No jurisdiction has yet conferred legal personhood upon AI systems, though certain proposals debated in earlier years in the European Parliament had suggested a form of "electronic personhood" for sophisticated autonomous systems, primarily for insurance and liability allocation purposes. Those proposals were ultimately set aside, and the current global consensus is that liability must vest in humans whether developers, deployers, or operators rather than in the machines themselves.


XI. Recommendations: Closing the Liability Vacuum Under Indian Law

The foregoing analysis reveals a clear and urgent danger: Indian law, as it presently stands, does not ensure that victims of Zero-Person Company conduct have a reliable, practically effective remedy. The following reforms are proposed.

First, Section 149 of the Companies Act, 2013 should be amended to require that every company maintain at least one "Accountability Director" who is a natural person, permanently resident in India, and personally liable up to a defined financial ceiling for losses caused by AI systems deployed by the company. This role should not be capable of being insured away, contracted away, or delegated to another AI system. The Accountability Director should be required to file a periodic "Human Oversight Certificate" with the Registrar of Companies, attesting that meaningful human review of AI-driven decisions has been undertaken.

Second, a new Section 166A should be introduced, imposing upon directors of companies that deploy autonomous AI systems a specific, enhanced duty of care a duty to maintain continuous and substantive oversight of AI-driven operations, to establish human review mechanisms for decisions above defined materiality thresholds, and to ensure that the company retains at all times the practical ability to override, correct, or shut down AI systems operating on its behalf.

Third, Section 2(60) should be amended to expressly provide that, in a company where AI systems perform the functions ordinarily performed by key managerial personnel, the promoters and controlling shareholders shall be deemed to be the "officers in default" for all purposes of the Act, unless they can affirmatively demonstrate that adequate human oversight mechanisms were maintained.

Fourth, the Consumer Protection Act, 2019 should be expressly amended to include AI system developers and promoters of AI-operated companies within the definition of "product service provider" under Section 2(37), with strict liability attaching for harm caused by AI-driven deficiencies.

Fifth, the proposed Digital India Act the anticipated successor to the Information Technology Act, 2000 should include a dedicated chapter on "Autonomous Commercial Entities," addressing their liability, mandatory insurance requirements, human oversight obligations, and the responsibilities of AI system developers towards companies that commercially deploy their systems.


XII. Conclusion: The Law Must Find the Human in the Machine

The Zero-Person Company is not a distant speculative future. It is an emerging present reality made possible by the convergence of large language model technology, autonomous agent frameworks, smart contract infrastructure, and regulatory gaps that have not yet been legislatively addressed. Indian corporate law, built upon centuries of accumulated wisdom about human agency, human accountability, and human moral responsibility, is structurally unprepared for an entity that wears the clothes of a corporation but contains no human mind in its governance architecture.

The law cannot declare itself helpless. Justice the paramount purpose of every legal system demands that those who benefit from deploying autonomous commercial systems must bear the costs when those systems cause harm. The promoter who incorporates a Zero-Person Company and deploys AI agents to conduct its business in the market, exposed to real counterparties with real interests and real vulnerabilities, is not an innocent bystander when the AI causes loss. She is the architect of the risk. She is the beneficiary of the profit. She must be, in law as in equity, the bearer of the liability.

Until Indian legislation expressly addresses this question, courts must draw upon the existing statutory arsenal: the fraudulent conduct provisions of Section 339, the misfeasance remedy of Section 340, the fraud liability of Section 447, the broad definitions of "officer" and "officer who is in default" under Sections 2(59) and 2(60), the alter ego doctrine developed through decades of judicial interpretation, and the Indoor Management principle as a shield for innocent third parties to ensure that the liability vacuum created by the Zero-Person Company does not become a sanctuary for commercially motivated irresponsibility dressed in algorithmic clothing.

The corporate veil was never designed to be a firewall behind which conscience could be outsourced to code. And no quantity of artificial intelligence can substitute for the one thing the Companies Act, 2013, in every one of its 470 sections, has always assumed to be indispensably present at the centre of every commercial enterprise: a human being who can be called to account.


This article is intended for academic, research, and informational purposes only and does not constitute legal advice. All statutory citations refer to the Companies Act, 2013 (Act 18 of 2013) as available in the official text. Readers are advised to consult qualified legal counsel for advice on specific legal matters.

🔗 Share this post: https://llmadvocates.com/blog/zero-person-companies-liability-vacuum-artificial-intelligence-under-indian-corporate-law

About LLM Advocates

LLM Advocates is a specialized law firm registered with the Punjab & Haryana High Court, focusing on cyber law, AI governance, data privacy, and technology-related legal services. Our advocates hold LLM degrees in Cyber Law and are ISO 42001:2023 Certified Lead Auditors.

Meet Our Advocates →
Bot Avatar

LLMbot

Online