AI Agent Accountability: Who Is Legally Responsible When an Agent Acts?

When an AI system sends, accepts, approves, or commits, the real governance question is not what the system can do. It is who authorized it to do it.

When an AI system sends, accepts, approves, or commits, the real governance question is not what the system can do. It is who authorized it to do it.

If your company has turned on an AI agent that can send commitments, accept terms, quote prices, or approve requests, it may already have a path to binding the company before anyone in leadership decided what the agent could do. The capability ships first. The authority question comes later, if it comes at all.

That order is backwards. Since 2000, the law has let a machine help form a contract with no human reviewing the deal. The federal E-SIGN Act (15 U.S.C. 7001(h)) says a contract can't be denied legal effect "solely because its formation, creation, or delivery involved the action of one or more electronic agents so long as the action of any such electronic agent is legally attributable to the person to be bound." Maryland and DC adopted the same rule (D.C. Code 28-4913; Maryland Commercial Law 21-113).

That last clause is the whole game: the law lets the machine into the deal, it doesn't decide the deal is yours. That turns on ordinary questions, like whether your company agreed, whether the agent looked authorized, whether you blessed the action after the fact. Most companies never answer that on purpose. They answer by default.

The Capability Changed. The Liability Rules Did Not.

By "AI agent" I mean software that acts for the company without a human checking each step: it sends the email, accepts the terms, approves the request. Some also move money; set those aside, since payments pull in banking, fraud, and sanctions rules that need their own analysis.

Calling it an "electronic agent" is just a statutory label; it doesn't make the software a person or give it authority of its own. The question is never what the agent decided, but who set it up that way, and within what limits. D.C. Code 28-4908 says an electronic act "is attributable to a person if it was the act of the person," judged from your agreements and how the system was set up. Maryland's Commercial Law 21-108 uses the same language. Neither law binds you the instant an agent acts; both send the question back to your setup.

Why an Audit Log Is Not Enough

The real danger isn't the agent going rogue and doing something no one coded. It's the agent doing exactly what it was built to do, staying inside its limits, and making a commitment no one with authority ever decided it should be able to make.

That's what an audit log can't reach: it can prove the agent stayed in scope, but it cannot prove you had the authority to grant the scope. Giving an agent a power no one signed off on is a defect, not a feature. When engineering lets an agent accept a counterparty's terms just because the software can, it has quietly turned a legal decision into a product decision.

Where Does Existing Law Already Place Responsibility?

No reported U.S. enforcement action squarely decides whether a general-purpose AI agent exceeded its authority while entering an ordinary commercial commitment. Regulators have brought cases over automated hiring, algorithmic discrimination, and deceptive AI claims, though, and every one pins responsibility on the company, not the tool.

The clearest version comes from the CFPB, the federal consumer-finance regulator. Its 2022 circular told lenders they can't dodge fair-lending law because their AI is too complex to explain. A 2023 follow-up added that a rejection reason has to be specific and accurate. That binds only lenders, but it travels: you can't hide behind "the algorithm did it."

Hiring is another place regulators have moved. In EEOC v. iTutorGroup, the companies set their software to auto-reject women 55 and older and men 60 and older, screening out more than 200 qualified applicants by age. The EEOC settled in 2023 for $365,000 plus training and policy changes; the tool was a hard-coded age cutoff, not a self-directed agent, but an employer still answered for what its software did.

The FTC's cases need care. Its Operation AI Comply (September 25, 2024) reached more than "companies that lied about AI": AI-branded get-rich-quick schemes (the FTC alleged Ascend Ecom took at least $25 million and FBA Machine over $15 million) and tools built to help people deceive (Rytr's assistant could crank out fake reviews). Overstated-capability cases like DoNotPay's "robot lawyer" are one piece, not the whole, and none involve an agent acting on its own. The FTC's proposed statement on AI accuracy (comment open July 1, 2026) is about garbled outputs, not agent authority.

The sharpest losing argument is Canadian. In Moffatt v. Air Canada (February 14, 2024), an airline's chatbot gave a customer wrong information about bereavement fares; Air Canada argued it wasn't on the hook because the chatbot was its own entity. The tribunal said no and made the airline pay the difference. It's about wrong information, not an agent's authority to make deals, and a Canadian tribunal doesn't bind U.S. courts, but the point lands: you can't wave off your own chatbot as a stranger when it misinforms your customer.

Colorado spells out the pieces most directly. Its 2024 AI law (SB 24-205, signed May 17, 2024) was replaced by SB 26-189 (signed May 14, 2026), built around automated decision-making technology: software that plays a big part in a high-stakes decision about someone's education, job, housing, loan, insurance, healthcare, or government benefits. A company using it must tell people up front, which a clear public posting can satisfy, and give a plain-language explanation within 30 days when a decision goes against someone. Human review is narrower than people assume: something the person can request after a bad outcome, only as far as commercially reasonable. Duties on the builders start January 1, 2027. It binds only in Colorado, but it names what any company needs: someone accountable, notice, an explanation after a bad call, and a route to a person.

The Agent Authority Record

Put your decision framework into one document, done before the agent takes a single live action, redone whenever the model, vendor, tool, or scope changes. Call it the Agent Authority Record. Unwritten answers mean the agent runs on authority no one granted.

  1. Permitted and prohibited actions. What the agent may do, and a hard line on what it may not. For anything that could bind the company, "the agent drafts, a named person sends" is the safer default.
  2. Limits on each action. Ceilings on price, term, dollar amount, who it can deal with, and where. Any ability to go past them is a defect to close.
  3. A named owner. A real person, by name and role, accountable for what the agent does. No name, no answer when someone asks who's responsible.
  4. Sign-off before it goes live. Written approval from whoever holds that authority, before the agent can bind the company. A rule you set yourself, not something the law requires.
  5. When it has to stop and ask. The points where the agent must pause and hand off to a person, and who catches the handoff.
  6. A kill switch. Who can shut the agent down, how, and how fast, written down before go-live. A stop button living only in one engineer's head isn't a control.
  7. Logging and record retention. The log must prove the agent stayed in scope and that a named person authorized that scope, tied to how long you keep the record.
  8. What reopens the review. A new model, vendor, or tool, a version change, or a real change in scope. Name who re-checks it and against what.
  9. A path for the customer. For high-stakes decisions, the ability to give a specific, accurate reason and a clear route for a person to ask for another look.
  10. Incident response. When the agent does something it shouldn't have: who can undo it, fix it, or stand behind it, and how fast, so an out-of-bounds commitment meets a decision instead of silence.

Two of these have ready-made language worth borrowing. The EU AI Act's Article 14 says high-risk systems must be built so a person can watch over them and stop them safely: the model for items 5 and 6. The FDA's December 2024 final guidance on change-control plans for AI in medical devices requires a planned model change, and how you'll test it, to be spelled out in advance (it floated the same idea for all device types in an August 22, 2024 draft that is still just a draft). Item 8 is that lesson outside medicine: a changed model means you re-check it.

What Does This Mean for Founders, Operators, and Boards?

For founders: turning on an agent buries a legal-authority call inside a product call, made by whoever wired up the integration. Draw the line now, not mid-financing, when a buyer's lawyer is combing your incident history asking who authorized each agent to act.

For operators and general counsel: the line that matters most runs between "may draft" and "may send," and between "may recommend" and "may approve." A meaningful share of the exposure drops away once the agent prepares the action and a named person commits it. Where you need full autonomy, choose it on purpose, with an owner in place.

For investors and boards: agent authority belongs on the diligence checklist, and on the board agenda for portfolio companies running agents in high-stakes decisions. The right question isn't whether a company uses AI agents, it's who authorized each one to act, and can they show it. NIST's AI Risk Management Framework Govern function (January 26, 2023) says the same: name your owners and accountability structures before you deploy.

Frequently Asked Questions

Is my company legally bound if my AI agent signs something?

Possibly. The federal E-SIGN Act (15 U.S.C. 7001(h)) and Maryland and DC's electronic-agent rules (Maryland Commercial Law 21-113; D.C. Code 28-4913) allow a contract to form without human review, if the software's action is legally attributable to your company. Ask your team: who decided what this agent can commit to, and is it written down?

Do I need a human approving every action my AI agent takes?

Not necessarily, but the line matters more than the label. The Agent Authority Record draws the boundary between actions the agent completes on its own within a defined ceiling, and actions where a named person signs off first. Full autonomy is fine for lower-stakes actions with an owner and escalation path in place. The risk is that choice getting made by default, inside engineering, instead of on purpose.

What is an Agent Authority Record?

A single written document, built before your AI agent's first live action, answering what it may and may not do, who owns it by name, who signed off before go-live, when it must stop and hand off to a person, and how the log ties actions back to whoever authorized them.

Does this apply to my company if I am not in Colorado or subject to the EU AI Act?

Yes, in the parts that matter most. Colorado's automated decision-making law (SB 24-205, replaced by SB 26-189) and the EU AI Act's human-oversight requirement (Article 14) apply only where they're governing law, but the exposure comes from contract-formation rules that reach further, including the federal E-SIGN Act and Maryland and DC's electronic-agent statutes (Maryland Commercial Law 21-108; D.C. Code 28-4908). Wherever you operate: who authorized this agent to act, and can you show it.

Do I need to do anything about this right now, or can it wait until my AI agents get more sophisticated?

This isn't a future problem. If your company has already turned on an agent that can send, accept, quote, or approve on its own, the authority question exists today. Building the Agent Authority Record now costs far less than reconstructing it later during financing diligence, or after an agent commits to something it shouldn't have.

Closing Perspective

Companies keep treating agent deployment as an engineering milestone and accountability as something to sort out later. The law won't do that work for you. The risk isn't every move automatically binding the company; it's that whether it's really yours gets sorted out later, from your setup and conduct. Here's the line I'd put on the whiteboard: your audit log can prove the agent stayed in scope, but it cannot prove you had the authority to grant the scope. Write the authority down before the agent acts, and you own the record; skip it, and the record still gets written by whatever the agent did while no one was deciding. Authority must precede autonomy. The next thing worth watching is whether a U.S. regulator calls out an agent-specific action. Don't wait for it, the rules that will decide that day are already on your desk.


This article is for informational purposes only and does not constitute legal advice. Every company's situation is different, and you should consult with qualified legal counsel before making compliance decisions based on the developments discussed here.

Share this article and about the author

Meetesh Patel, Esq., founder of Consilium Law LLC

Meetesh Patel

Founder and Managing Attorney

I write SparkPoint myself. I built and sold a law firm, ran a clean energy company as CEO, and spent a decade advising founders before building this practice.

More about the firm
Contact

If this touches the work in front of you, start a conversation.

Send a short note about what changed, what you are building, and where legal judgment needs to sit closer to the work.

Disclaimer. This article is provided for informational purposes only and does not constitute legal advice. Readers should consult independent counsel before acting on any analysis. The views expressed are solely those of the author and do not necessarily reflect the views of Consilium Law LLC.