My agent signed me up for forty things
A single agent action can create an obligation that repeats every month until somebody cancels it. Every merchant will have a valid consent record, and every one of those records was generated by the agent. This is the worst possible fit between delegated autonomy and the way subscriptions work.
Say you are starting a small consulting practice. You tell your assistant agent, in the way people actually talk to these things, to get you set up with the tools you need. It is good at this. Within twenty minutes it has you on a project tracker, a scheduling tool, a transcription service, an invoicing product, a design tool, a password manager, a virtual mailbox, and a stock photo library. Nine of them offered free trials. It took all nine, because a free trial is obviously the right move when you are evaluating tools, and because nothing in its instructions said otherwise.
Six weeks later the card statement arrives. Two of the trials converted at prices you never saw. One converted at an annual rate because the annual plan was preselected on the page. One is a service you used exactly once. One you cannot identify at all from the merchant descriptor. The total is not ruinous, it is about two hundred and forty dollars a month, which is the amount that annoys people for years without ever quite justifying an afternoon of admin to fix.
So you call your card issuer and say these were not authorised. The issuer asks the merchants. Each merchant produces a consent record: a timestamp, an IP address, a session identifier, a checkbox that was checked, a button labelled Start trial that was pressed, and in the better cases a copy of the terms as displayed. It is a complete, well formed, entirely genuine record of consent.
It was produced by your agent. So was every other signal the merchant would normally use to establish that you were there.
Short answer. Under the electronic transactions statutes an agent's acceptance is generally attributed to you, so the subscription is likely binding. But the merchant still has to prove informed consent to a recurring charge, and every artifact it holds was generated by the agent. A consent receipt signed on your own device, over the actual terms, is the only evidence that distinguishes a human who agreed from software that clicked.
Is a subscription my AI agent accepted binding on me?
Probably, and for the same reason a contract your procurement agent negotiates is probably binding, which we covered in detail in the post on agent negotiated contracts. The short version is that the Uniform Electronic Transactions Act contemplates contracts formed by electronic agents without human review, and the electronic agent provision of the ESIGN Act at 15 U.S.C. section 7001 says such a contract cannot be denied effect solely because an electronic agent was involved, provided the agent's action is legally attributable to the person to be bound.
But consumer subscriptions carry a second layer that commercial contracts do not, and that layer is where this gets interesting. Recurring charges in the United States sit under the Restore Online Shoppers' Confidence Act, at 15 U.S.C. sections 8401 and following, which requires a seller using a negative option feature online to disclose the material terms clearly and conspicuously, obtain the consumer's express informed consent before charging, and provide a simple mechanism to stop recurring charges. The Federal Trade Commission has pursued negative option cases for years and finalised an updated rule in this area in 2024, whose status has been the subject of litigation, so treat the precise obligations as contested and check the current position rather than relying on a summary.
Notice what ROSCA asks for. Not consent. Express informed consent, obtained after clear and conspicuous disclosure. That is a higher bar than a checkbox, and it is a bar aimed at a state of mind. A merchant relying on a consent record generated by an agent is asserting something about a human's understanding on the basis of evidence that contains no human at all.
Why were subscriptions already broken before agents arrived?
Because the effort required to start a subscription and the effort required to end one were deliberately set at different levels, and everyone in the industry knows it.
The asymmetry is the business model
Starting is one click, often on a button that is the largest and most colourful thing on the page, frequently with the annual plan preselected. Ending has historically meant finding a settings page that is not where settings usually are, clicking through a retention flow that offers you three discounts you did not ask for, and in a number of documented enforcement actions, calling a phone number during business hours. The FTC's negative option work exists precisely because this asymmetry was widespread enough to warrant a rule.
Add the pre checked box, the trial that converts silently, the price that is displayed monthly and billed annually, and the notice email that arrives in a promotions tab. None of this is new and none of it required artificial intelligence.
So the consent model was already thin
Here is the uncomfortable observation that makes this post more than a complaint about agents. The consent artifact merchants have relied on for two decades was always weak. A checkbox proves a checkbox was checked. An IP address proves a network path. A timestamp proves time passed. None of them proves a person read the price after the trial. The industry accepted this because the alternative was friction, and because disputes were rare enough to absorb.
Agents did not break the consent model. They removed the one assumption that was quietly holding it together, which is that a human was somewhere in the vicinity.
What is actually different when an agent clicks accept?
People push back on this reasonably. Humans click accept without reading all the time. What is the difference?
The difference is that the human was present, and presence has evidentiary value even when attention does not. A human who clicked without reading can still say, later and truthfully, what they thought they were signing up for. A court or an ombudsman can weigh that. There was a mind in the room with intentions about the outcome, however poorly informed.
When an agent accepts a trial, nobody formed an intent about that trial. Not a badly informed intent. Not a careless one. None. The human formed an intent about a category of outcome, which was roughly get me set up with tools, and the agent converted that into forty specific commitments that nobody evaluated. There is no state of mind to inquire into, which means express informed consent, as a concept, has nothing to attach to.
The second difference is that the evidence is circular. In an ordinary dispute the merchant's records and the consumer's account of events are two independent sources, and a decision maker weighs them. Here the merchant's records describe the behaviour of software the consumer deployed, so both sides are arguing about the same artifact. We made this point about one off purchases in the post on agent chargeback liability, and recurring charges are the version where the problem compounds monthly.
Why does a recurring charge deserve its own consent?
This is the technical heart of the post and it is a point about scope design rather than about fraud.
A spending cap is not a commitment cap
Every agent commerce design starts with a spending limit, because that is the obvious control. You tell the agent it may spend up to five hundred dollars a month, and you feel you have bounded the risk. You have not, and the reason is arithmetic.
A one off purchase of nineteen dollars costs you nineteen dollars. A subscription of nineteen dollars a month costs you nineteen dollars this month and creates a liability with no defined end. Against a five hundred dollar monthly cap, the agent can add roughly twenty six such subscriptions in a single month without ever exceeding its limit. In month two it can add twenty six more, and now the recurring load is over a thousand dollars a month, at which point the cap is being breached by obligations that were individually compliant when created.
A cap on flow does not bound a stock. Any engineer who has thought about rate limits and resource leaks will recognise the shape immediately: you have limited the rate of allocation and never implemented free.
Reversibility is the axis that matters
The right way to classify what an agent may do is not by price. It is by how hard the thing is to undo.
| Obligation | How reversible | Liability window | Consent it warrants |
|---|---|---|---|
| Metered usage, pay as you go | High, stop using it | Ends when usage ends | Delegation with a cap |
| One off digital purchase with refund window | High, within the window | Days | Delegation with a cap |
| One off physical purchase | Moderate, returns policy | Weeks | Delegation with a cap |
| Monthly subscription, cancel any time | Moderate, but requires action | Indefinite until acted on | Human signature over terms |
| Free trial that converts | Moderate, if you remember | Indefinite, starts silently | Human signature over terms |
| Annual plan paid upfront | Low | Twelve months | Human signature over terms |
| Auto renewing annual with a notice window | Very low, window is easy to miss | Rolling years | Human signature, and arguably a reminder signature |
| Multi year contract with early termination fee | Very low, costs money to exit | Years | Human signature, no delegation |
Read down the consent column and the design writes itself. Delegated authority is appropriate for the top three rows, where a mistake costs a bounded amount and can be undone. Everything below the line creates an obligation that outlives the decision, and those should require the human to be present at the moment of commitment.
What would a signed terms receipt actually look like?
Two objects. The first is the delegation, which is what the agent carries, and the important field is the one that is usually missing.
"scope": {
"actions": ["purchase.one_time"],
"constraints": {
"max_single_purchase_usd": 200,
"max_total_usd_per_month": 500,
"recurring_commitments": "deny"
}
}
That last line is the whole design. Recurring commitments are denied by default, not capped, because a cap is the wrong instrument for an unbounded obligation. If the agent encounters a subscription it hands the decision back rather than deciding.
The second object is the consent receipt, produced when the human decides to accept.
{
"merchant": "did:web:toolco.example",
"subject_key": "ed25519:c41f8b...", // the human, not the agent
"terms": {
"price_now_usd": 0.00,
"price_after_trial_usd": 49.00,
"cadence": "monthly",
"trial_ends": "2026-10-19",
"first_charge_date": "2026-10-19",
"cancellation_method": "in_app_single_step",
"notice_before_charge_days": 7
},
"terms_hash": "sha256:9b21e0c7...",
"signed_at": "2026-09-21T14:02:11Z",
"signature": "ed25519:..."
}
Three properties make this different from a consent log. It is signed by a key held by the human on their own device, so the agent cannot produce it. It commits to a specific terms hash, so the merchant cannot later present different terms and claim these were the ones displayed. And it verifies offline against a published key, so the issuer assessing a dispute does not have to take the merchant's word for the record's integrity, which is the situation today.
Note what the receipt deliberately contains: the price after the trial, the date of the first charge, and how to cancel. Those are the three facts consumers most often say they did not know, and putting them inside the signed object means the merchant is attesting that they were shown.
Why can I not simply list my subscriptions?
Because nothing in the system was built to answer that question, and it is a genuinely hard one even before agents.
Your subscriptions live in as many places as there are merchants. Some appear on a card statement under a descriptor that resembles the product name and some do not. Some are billed through an app store, which at least gives you one list for that subset. Some run through a payment processor whose name appears instead of the merchant's. There is no authoritative register, which is why an entire category of applications exists solely to read your bank feed and guess.
Add an agent and the position gets worse, because now there are commitments you did not personally create and cannot recall. This is the same failure we described as authority opacity in the piece on the agent authority graph: a human cannot enumerate what has been committed on their behalf, so they cannot review it, and cannot revoke what they cannot see.
If consent is a signed receipt held by the human rather than a log held by each merchant, enumeration becomes trivial, because the receipts are in one place by construction. That is a pleasant side effect rather than the main argument, and it happens to be the feature most consumers would actually want.
What does a signed consent receipt not fix?
Quite a lot, and pretending otherwise would repeat the industry's mistake of overselling consent artifacts.
It does not make anyone read the terms. A human can sign the receipt in two seconds without absorbing the price after trial. What changes is that the specific material facts are inside the signed object rather than in a paragraph below the fold, and that the human, not their software, performed the act. That is a meaningful improvement in evidence and an unproven one in comprehension.
It does nothing about obligations created before adoption. The forty subscriptions in the opening scene are already running. This is a control for new commitments, not a remedy for existing ones.
It requires merchants and billing platforms to adopt it. A receipt no merchant requests and no issuer accepts is a consumer keeping a diary. The realistic path runs through billing platforms and issuers who want fewer disputes, and it is early. Manav has shipped no subscription or billing integrations, and the per action signature and delegation constraints described here are the general primitives rather than a subscription product.
It adds a step at the worst moment for conversion. Merchants will resist, and their objection is legitimate. The honest counterargument is that a signed receipt is worth more to a merchant in a dispute than the conversion it costs, and that argument gets stronger as agent originated disputes grow. It is an argument, not a proof.
It does not address cancellation. Making signup provable while leaving cancellation in a retention maze would be a poor trade for consumers. If cancellation is not symmetric with signup, this becomes another obstacle dressed as a protection. Consumer advocates should hold anyone deploying this, including us, to that standard.
Consumers may not want it. Survey work in this area, including consumer trust research published by fraud vendors, suggests a substantial share of people are uncomfortable with agents managing purchases at all. Survey figures about brand new behaviours are directional at best, so treat them as a signal rather than a measurement.
What should you do this week?
If you use a purchasing agent:
- Set an explicit rule that the agent may not accept trials or recurring plans, and check whether your agent platform actually supports that distinction rather than only a spending cap. Most support only the cap.
- Use a dedicated payment instrument for agent purchases, ideally one with per merchant virtual cards, so a recurring charge you did not authorise can be stopped at the instrument.
- Reconcile the card statement line by line once, now, and write down every recurring charge you find. This is the boring step everyone skips and it is the one that finds the two hundred and forty dollars.
- Set a calendar reminder for every trial end date before you let the agent start one.
If you build a subscription product:
- Decide today whether agent originated signups are something you want, and make it a deliberate policy rather than an accident of your checkout flow.
- Put the price after the trial, the first charge date, and the cancellation method into whatever consent artifact you retain, because those are the three facts every dispute turns on.
- Make cancellation symmetric with signup. If starting takes one click, ending should take one click. Do this before a regulator asks you to.
- Ask your billing platform what evidence it can produce for an agent originated dispute, and notice how the answer sounds when you say it out loud.
The widget demo shows the shape of a single signature bound to a specific payload, and the developer documentation covers delegation constraints and offline receipt verification.
Frequently asked questions
Is a subscription my AI agent accepted binding on me? Likely yes. Under UETA and the electronic agent provision of the ESIGN Act, an act by an automated agent is generally attributed to the person who deployed it. Separately, though, a merchant charging on a negative option basis must be able to show express informed consent under ROSCA, and a consent record generated entirely by your agent is thin evidence of a human's informed state of mind.
How do I stop my agent from accepting free trials? Look for a control that distinguishes recurring commitments from one off purchases rather than only setting a spending cap. A cap does not bound recurring obligations, because many small subscriptions can each be individually compliant while the accumulated monthly load grows without limit. If your platform offers only a cap, the practical control is a dedicated payment instrument.
Does Regulation E cover purchases my agent made? Regulation E governs electronic fund transfers and unauthorised transfers from consumer accounts, and how it applies when a consumer's own agent initiated the transaction is not settled. That ambiguity is precisely why an artifact showing whether a human authorised the specific recurring commitment is valuable to consumers, merchants and issuers alike.
Why is a subscription worse than a one off agent purchase? Because a one off purchase has a known cost and a refund window, while a recurring commitment creates an open ended liability from a single unreviewed decision. The consent problem is identical; the consequence compounds every billing cycle until somebody notices and acts.
Cannot the merchant just send a confirmation email? It can, and the email arrives in a mailbox the agent may also be reading and triaging. Any confirmation delivered into the same environment the agent controls inherits the agent's reach, which is the general failure we describe as mailbox grade approval.
Would a signed consent receipt hurt conversion? It adds a step, so probably yes at the margin. The offsetting argument is that a merchant holding a device signed receipt over specific terms is in a far stronger position in a dispute than one holding a click log, and that the value of that evidence rises as agent originated disputes become more common.
Is this legal advice? No. This describes statutes and regulatory activity at a general level, and the position varies by jurisdiction and is subject to ongoing litigation. Consult your own counsel.
Sources
- Restore Online Shoppers' Confidence Act, 15 U.S.C. sections 8401 and following, on negative option marketing, clear disclosure, express informed consent and simple cancellation. law.cornell.edu/uscode/text/15/chapter-110
- Federal Trade Commission, negative option and subscription enforcement materials and rulemaking record. ftc.gov
- Electronic Signatures in Global and National Commerce Act, 15 U.S.C. section 7001, electronic agent provision. law.cornell.edu/uscode/text/15/7001
- Uniform Electronic Transactions Act (1999), Uniform Law Commission, automated transaction provision. uniformlaws.org
- Regulation E, Electronic Fund Transfers, 12 CFR Part 1005, Consumer Financial Protection Bureau. consumerfinance.gov
A spending cap bounds what your agent can spend this month. Nothing in it bounds what your agent can commit you to paying forever.