Manav.id
Regulated ยท 17 min read

Your agent agreed to the terms. Are you bound?

A procurement agent negotiates a supply agreement, converges on terms, and accepts. Under the electronic transactions statutes that contract is probably yours, whether or not a human read a word of it. The interesting question is not enforceability, which is largely settled. It is whether you can prove what you actually authorised.

Picture a Tuesday at a mid-size manufacturer. The contracts manager, who we will call the one person in this story with a clear conscience, opens her queue at nine and finds a supply agreement marked executed. It was negotiated overnight by the procurement agent the company switched on six weeks ago, the one that has already saved four hundred hours of back and forth on routine renewals. The counterparty's own agent was on the other side. The two of them exchanged eleven rounds between eleven at night and four in the morning, converged, and one of them accepted.

She reads it. The unit pricing is fine. The volume commitment is higher than she would have agreed, but defensible. Then she reaches clause 14, which contains an uncapped indemnity, and clause 22, which auto renews for three years unless cancelled in a ninety day window that closes eleven months from now. Neither is something any human at the company would have signed. Neither is something the agent was told it could sign, because the person who configured it wrote, in the system prompt, in plain English, never accept uncapped liability.

She calls legal. Legal asks the only question that matters, and it is not the question she expects. They do not ask whether the contract is valid. They ask what she can produce, today, that states what the agent was permitted to agree to and who decided that. And the honest answer is a system prompt in a configuration file, a Slack thread from August, and a policy document that says agents must operate within delegated authority without saying what that authority is.

Short answer. Under the US electronic transactions statutes, a contract formed by your automated agent is generally attributed to you, and the fact that no human reviewed it is not by itself a defence. The real dispute becomes authority: what you actually granted, whether the agent stayed inside it, and whether the counterparty reasonably believed it had. Almost nobody can currently produce evidence of the grant, which is why these disputes will be decided on Slack threads and screenshots.

Is a contract my AI agent agreed to actually binding?

Usually yes, and the law got there long before anyone shipped a negotiation agent.

What the electronic transactions statutes actually say

Two instruments do most of the work in the United States. The Uniform Electronic Transactions Act, approved by the Uniform Law Commission in 1999 and adopted in nearly every state, contains a provision on automated transactions stating that a contract may be formed by the interaction of electronic agents of the parties even if no individual was aware of or reviewed the electronic agents' actions or the resulting terms. UETA defines an electronic agent as a computer program or electronic or other automated means used independently to initiate an action or respond to electronic records without review or action by an individual.

Sit with that phrasing for a moment, because it is doing something people find surprising when they first read it. The statute does not merely tolerate the absence of a human. It contemplates it explicitly and says the resulting contract is fine. The drafters in 1999 were thinking about electronic data interchange, automated ordering systems, and the early web, but they wrote the rule at a level of generality that reaches whatever automated means happens to exist.

Federally, the Electronic Signatures in Global and National Commerce Act, codified at 15 U.S.C. section 7001, carries a parallel provision on electronic agents. It provides that a contract relating to a transaction in or affecting interstate or foreign commerce may not be denied legal effect, validity, or enforceability solely because its formation involved the action of one or more electronic agents, so long as the action of the electronic agent is legally attributable to the person to be bound.

That trailing clause is the whole post. Everything after this paragraph is an argument about what makes an agent's action legally attributable to you, because the statute assumes attribution rather than supplying it.

Why "a robot did it" is not a defence

The instinct of every principal in a bad agent contract is to say that the machine acted on its own. The statutes anticipated that instinct and closed it, and general contract formation doctrine closes it again from a different direction. Under the Uniform Commercial Code section 2-204, a contract for sale may be made in any manner sufficient to show agreement, including conduct by both parties recognising the existence of a contract. Courts have long been comfortable finding agreement from conduct rather than from a signature ceremony.

So the argument that no human formed intent is weak on its own. The company deployed the agent, pointed it at a counterparty, gave it the ability to accept, and benefited from the arrangement when it worked. A tribunal is not going to be impressed by the claim that the machinery the company built and switched on was acting for itself.

This is worth stating plainly because a good deal of commentary treats agent contract enforceability as an open frontier. It mostly is not. The frontier is one step further in.

If the law is settled, what is the actual fight?

Authority. Specifically, the difference between the authority a principal actually conferred and the authority a counterparty reasonably believed had been conferred.

Actual authority and apparent authority, in one shop assistant

Here is the analogy, and it is old because the problem is old. You run a shop. You hire an assistant and tell them, privately, in the back office, that they may sell anything on the shelves but may not offer discounts above ten percent. A customer comes in and negotiates a thirty percent discount from the assistant. You come back and find out.

Your assistant had no actual authority to give thirty percent. You said so, and if you can show you said so, the assistant is answerable to you for going outside it. But the customer never heard your back office instruction. What the customer saw was a person standing behind your counter, wearing your apron, using your till, doing the thing shop assistants do. That is apparent authority, which arises from what the principal has manifested to the third party rather than from what the principal told the agent. The Restatement (Third) of Agency, published by the American Law Institute, sets out both concepts, along with ratification, which is what happens when a principal later adopts an unauthorised act.

The shop keeps the discount, usually, because it would be intolerable if every customer had to audit the private instructions of every employee before transacting. The loss falls on the principal, who chose the assistant, benefited from the arrangement, and was in the better position to control it. Then the principal takes it up with the assistant internally, which in the agent case means taking it up with a piece of software, which is not a satisfying remedy.

Why this maps onto agents almost exactly

Replace the assistant with a negotiation agent and almost nothing about the doctrine changes. You deployed it. You pointed it at the counterparty. The counterparty saw a thing operating from your domain, on your behalf, with your branding in the message headers, doing the thing procurement agents do. If the counterparty acted reasonably in relying on that appearance, the appearance is likely to carry the day, and your private configuration file is your problem, not theirs.

The reason this matters commercially rather than academically is that the two questions have different evidence requirements, and companies are currently equipped for neither. To argue the agent exceeded actual authority you must show what actual authority was. To argue the counterparty was unreasonable in relying you must show what the counterparty could have known. Today, in almost every deployment, the answer to the first is a prompt and the answer to the second is nothing at all.

What changed when agents got discretion?

The statutes were written for automated means that were, in practice, deterministic. An electronic data interchange system in 1999 did what its rules said. If it sent a purchase order for four hundred units at the agreed price, that is because a rule said to. The principal could reconstruct exactly why, and the behaviour was in principle fully predictable from the configuration.

Three things are different now, and it is worth being precise about them rather than gesturing at novelty.

The agent exercises judgment its principal cannot fully predict

A modern negotiation agent is not executing a decision table. It is producing behaviour from a model whose outputs vary with phrasing, context, and the counterparty's moves. The principal can constrain it and can test it, and cannot enumerate in advance every position it might take. That is precisely the property that makes it useful and precisely the property that makes "the agent was instructed not to" a weaker factual claim than it sounds.

The counterparty can influence the agent directly

This one has no clean analogue in agency law and it deserves more attention than it gets. A negotiation agent reads the counterparty's messages, and those messages enter the same context the agent reasons from. Indirect prompt injection means a counterparty, or anyone who can get text in front of the agent, can attempt to shape its behaviour by writing instructions rather than by making offers. We have written about the general shape of this problem in agentic browsers acting inside authenticated sessions, and the contract case is the same mechanism aimed at a commercial outcome.

Consider what that does to the reasonableness inquiry. Apparent authority protects a third party who reasonably relied. It is a genuinely open question whether a counterparty who induced the behaviour it then relied on has relied reasonably. That question has not been squarely answered, and anyone who tells you it has is guessing.

Volume and speed remove the human backstop

The traditional check on an agent exceeding authority is that a person eventually notices. When an agent handles four renewals a quarter, someone reads them. When it handles four hundred, nobody does, and the review that does happen is often a click inside the agent's own interface, which we have argued elsewhere is approval theater rather than a control.

Why do system prompts fail as evidence of authority?

Because they are internal, mutable, unsigned, and addressed to the wrong party.

Internal. A system prompt is a communication from the principal to the agent. Apparent authority turns on manifestations from the principal to the third party. A document the counterparty never saw cannot shape what the counterparty reasonably believed. It is the back office instruction, exactly, and it has the same evidentiary weakness.

Mutable. Configuration files change. Unless you have version control with meaningful attribution, and most agent deployments do not, you cannot show what the prompt said on the night in question rather than what it says now. Every dispute over authority becomes a dispute over the integrity of your own records.

Unsigned. Nobody attested to it. A prompt is a text field a platform administrator can edit. It carries no statement that a person with authority to bind the company decided these were the limits.

Addressed to the wrong party. Even a perfect, immutable, signed prompt tells the counterparty nothing, because the counterparty cannot read it. The counterparty's agent has no way to ask what your agent is allowed to do, so it proceeds on appearance, which is the exact condition that creates apparent authority in the first place.

The dollar threshold policy has the same defect in a different costume. A policy stating that agreements above two hundred and fifty thousand dollars require human sign off is a fine internal control and is not visible to anyone outside the company. When the counterparty holds an agreement for four hundred and eighty thousand dollars, your policy is evidence of what you intended, not evidence of what they should have known.

What would a counterparty actually verify?

Here is the shape of the thing that is missing. Not a new legal theory, and not a platform feature. An artifact, presented at the start of a negotiation, that says what this agent may agree to, signed by a human with authority to say it, and checkable by the counterparty without asking the principal.

A delegation is a signed object. This is what one looks like for a procurement mandate.

{
  "principal":    "Acme Manufacturing, Inc.",
  "delegateKey":  "ed25519:8f3a91c4...",
  "scope": {
    "actions": ["negotiate.supply_agreement", "form.contract"],
    "counterparties": ["did:web:supplier.example"],
    "constraints": {
      "max_total_value_usd": 250000,
      "max_term_months": 24,
      "prohibited_clauses": ["uncapped_indemnity",
                             "auto_renew",
                             "exclusivity"]
    }
  },
  "notBefore":    "2026-09-01T00:00:00Z",
  "notAfter":     "2026-12-31T23:59:59Z",
  "maxChainDepth": 1,
  "revocationId": "rev:acme:7d21c4",
  "signature":    "ed25519:..."
}

Read the fields as a lawyer rather than an engineer and they map onto things you already argue about. scope.actions is the category of transaction. counterparties is who this authority runs to. constraints are the limits you would otherwise write in a delegation of authority matrix and file where nobody reads it. notBefore and notAfter are the term. maxChainDepth answers whether this agent may sub delegate to another agent, which is a question most companies have not thought to ask and which we cover in delegation chain depth. revocationId is how you withdraw it and prove you did.

The signature is the part that matters. It is produced by a person with authority to bind the company, on a device enrolled to them, over the canonical bytes of that object. It is not a checkbox in an administration console that any platform administrator could have clicked.

The worked example, and what it would have caught

Return to the Tuesday. The contract that arrived has these material terms:

canonical_terms = {
  "parties":            ["Acme Manufacturing", "Supplier Ltd"],
  "total_value_usd":    480000,
  "term_months":        36,
  "auto_renew":         true,
  "indemnity_cap_usd":  null
}

terms_hash = sha256(canonical_json(canonical_terms))
# 3f9c2ab7e14d...

check(delegation, canonical_terms):
  480000 > 250000                    -> FAIL  max_total_value_usd
  36     > 24                        -> FAIL  max_term_months
  auto_renew        in prohibited    -> FAIL  prohibited_clauses
  indemnity_cap_usd is null          -> FAIL  uncapped_indemnity

Four constraint violations, each one checkable arithmetically, none of them requiring anybody to read clause 14 at four in the morning. And here is the point that makes this different from an internal control: the counterparty's agent could have run that check too, because the delegation was presented at the start and verifies against Acme's published key without calling Acme.

A counterparty that runs the check and proceeds anyway has a materially harder time arguing it reasonably believed the agent had authority. A counterparty that runs the check and stops has avoided a dispute that would otherwise have cost both sides more than the contract was worth. Either outcome is better than the one where nobody can establish anything.

Above the constraint ceiling, the second artifact appears: a human signature over the terms hash itself. Not a click in the agent's interface, but a signature from an enrolled device, over the exact bytes of the final terms. That is the ratification the doctrine already contemplates, produced at the moment of formation rather than reconstructed afterwards from a Slack thread.

Which contracting scenarios raise which authority question?

ScenarioWho actedThe authority questionEvidence available today
Human negotiates, human signsHumanDid this employee have signing authorityDelegation of authority matrix, signature block, email trail
Agent drafts, human reviews and signsHumanDid the human actually reviewPlatform click log, which the reviewer's own session generated
Agent negotiates, human approves in the agent UIAmbiguousWas the approval a human act or an agent actAn application state change, forgeable by anything holding the session
Agent negotiates and forms, inside stated limitsAgentWhat were the limits and can either party prove themA system prompt the counterparty never saw
Agent negotiates and forms, outside stated limitsAgentActual versus apparent authorityNothing that resolves it
Agent sub delegates to a specialist agentAgent chainWas sub delegation permitted, and to what depthUsually not even logged
Counterparty influenced the agent via injected textContestedDid the counterparty rely reasonably on behaviour it inducedMessage logs, if retained, and no doctrine squarely on point

Six of those seven rows describe an evidence problem rather than a law problem. That is the argument of this post in one table.

Does a machine readable scope actually decide the case?

No, and any vendor telling you otherwise is selling you something. This is the honest limits section and it needs to be longer than usual, because the temptation to overclaim in the legal domain is severe.

Courts weigh many things. A signed scope is one piece of evidence among course of dealing, industry custom, the parties' conduct after formation, the sophistication of the parties, and whatever the tribunal makes of the overall commercial reality. A cryptographic artifact does not convert a legal question into an arithmetic one. It gives you a document with better provenance than the alternatives.

Presenting scope has a commercial cost. Telling a counterparty that your agent may not exceed two hundred and fifty thousand dollars tells them your ceiling. Experienced negotiators will find that objectionable, and they are not wrong. The realistic design discloses the existence and the category of a delegation and reveals specific constraints selectively, or discloses a coarse ceiling well above the expected deal. Selective disclosure of individual fields is roadmap at Manav rather than shipped today, and it would be dishonest to describe it otherwise.

Ratification can still cure an excess. If your company performs under the contract for eight months, accepts deliveries, and pays invoices, you may have ratified the agent's act regardless of what any delegation said. The artifact does not protect a principal who behaves as though the contract is fine and then objects when it becomes inconvenient.

It does nothing about a badly drafted authorised contract. If your agent stays inside every constraint and still agrees to something commercially foolish, the delegation confirms that the foolishness was authorised. That is not a defect in the mechanism. It is a reminder that the mechanism proves authority, not wisdom.

Adoption is two sided. A delegation that no counterparty checks is an internal control with extra steps. The value appears when checking is normal, which is a network problem rather than a technical one, and it is genuinely early.

None of this is legal advice, and the analysis differs by jurisdiction. Talk to your own counsel about your own facts.

What should a procurement or legal team do this week?

  1. Write down what your agents may agree to. Not in a prompt. In a document, with values: counterparties, maximum total value, maximum term, prohibited clause types, and whether sub delegation is permitted. Most teams discover during this exercise that nobody had decided.
  2. Identify who is entitled to grant that authority and confirm it matches your existing delegation of authority matrix. If your agent can commit more than a director can, you have found a governance gap that predates the agent.
  3. Version control your agent configuration with real attribution, so that you can answer what the constraints were on a given date. This costs almost nothing and is the single highest value step here.
  4. Set a ratification threshold above which a named human signs the final terms hash from their own device, not a button in the agent's interface. Pick the number your board would recognise.
  5. Add an authority clause to your template. Require each party to present a verifiable statement of its agent's authority at the start of negotiation, and make silence about it a representation. Your counterparties will start asking you for the same thing, which is how this becomes normal.
  6. Log the counterparty's inbound messages and retain them. If the injection question is ever litigated, the transcript is the case.
  7. Decide your position on sub delegation now. The default in most agent frameworks is unlimited, which is not a position anyone chose.

If you want to see the mechanics rather than read about them, the signing demo shows a payload bound signature end to finish, and the developer documentation covers delegation objects and offline verification.

Frequently asked questions

If my AI agent agrees to a contract, am I bound? Generally yes. UETA's automated transaction provision and the electronic agent provision of the ESIGN Act at 15 U.S.C. section 7001 both contemplate contracts formed without human review, and ESIGN conditions this on the agent's action being legally attributable to the person to be bound. The practical dispute shifts from whether a contract exists to what authority the agent held.

Can I argue my agent exceeded its authority? You can, and you will need evidence of what the authority was. A system prompt is an internal instruction the counterparty never saw, which makes it weak against an apparent authority argument. A signed scope presented at the start of the negotiation is a different kind of evidence because the counterparty had the chance to check it.

Can a counterparty verify my agent's authority today? In almost every deployment, no. There is no standard way for one party's agent to ask another party's agent what it is permitted to agree to, which is why negotiations proceed on appearance. A signed delegation object that verifies offline against a published key is one way to close that, and it requires the counterparty to check it.

What happens if the counterparty manipulated my agent? This is genuinely unresolved. Apparent authority protects a third party who relied reasonably, and it is an open question whether a party that induced behaviour through injected instructions relied reasonably on it. Retain the full message transcript, because if this is litigated the transcript will be the evidence.

Does a human clicking approve in the agent's interface fix this? Weakly. That approval is an application state change produced inside the same session the agent operates in, so it inherits whatever compromised or automated the session. A signature produced on a separate enrolled device over the terms hash is a different artifact, because it cannot be produced by anything holding the session alone.

Should I just require human review of every agent contract? If your volume allows it, yes, and most volumes will not for long. The reason companies deploy negotiation agents is that human review does not scale to the number of routine agreements. A threshold model, where everything below a value runs on delegated authority and everything above it takes a human signature, is the design most teams converge on.

Is this legal advice? No. This is a description of statutory provisions and common law doctrine at a general level, and outcomes vary by jurisdiction and by facts. Consult your own counsel.

Sources

  1. Electronic Signatures in Global and National Commerce Act, 15 U.S.C. section 7001, including the provision on electronic agents. law.cornell.edu/uscode/text/15/7001
  2. Uniform Electronic Transactions Act (1999), Uniform Law Commission, including the definition of electronic agent and the automated transaction provision. uniformlaws.org
  3. Uniform Commercial Code section 2-204, formation in general. law.cornell.edu/ucc/2/2-204
  4. Restatement (Third) of Agency, American Law Institute, on actual authority, apparent authority and ratification. ali.org
  5. Regulation (EU) 2024/1689 (Artificial Intelligence Act), for the European oversight obligations referenced. eur-lex.europa.eu
  6. Regulation (EU) No 910/2014 (eIDAS), on electronic signature tiers in the European framework. eur-lex.europa.eu
The question was never whether your agent can bind you. It is whether you can prove what you let it agree to, and right now the answer is a system prompt nobody signed.