MaShop/Journal/Industry/Your Agent Placed the Order. You Are on the Hook
● IndustrySeptember 21, 2026
Read · 5 min
ai agent contract · ai agents

Your Agent Placed the Order. You Are on the Hook

Enacted law already says a contract can form between automated agents with nobody watching. The error escape hatch protects the other side, not you.

Key takeaways
  • Enacted law already answers whether a machine can form a contract for you. A contract may be formed by the interaction of electronic agents even if no natural person reviewed it.
  • An electronic agent is defined as a program or automated means used independently to initiate or respond, without review or action by a natural person.
  • Federal law protects such contracts from being void for being automated, provided the agent's action is legally attributable to the person to be bound.
  • The error escape hatch in these statutes runs to an individual dealing with somebody else's agent, not to a business whose own agent got it wrong.
  • So the asymmetry is against you. Your agent binds you, and your customer may have a route out that you do not.
  • The controls that matter are therefore commercial rather than legal: a spend ceiling, an approved counterparty list, a human step for anything that accepts terms.

An agent with a company card and a brief to keep the shelves stocked places an order at four in the morning. Wrong supplier, right product, quantity out by a factor of ten. Nobody saw it happen. The obvious question is whether that order is real.

It is, and the law that says so is older than the current wave of agents. This is one of the few areas where the legal position is settled and the operational practice has not caught up, which is an unusual and uncomfortable combination for a small business.

Can a machine form a contract on your behalf?

Yes, and the statute says it in one sentence. This is not a theory about where the law might go.

Nevada's enactment of the uniform electronic transactions rules is a clean place to read it. Chapter 719 of the Nevada Revised Statutes provides at section 719.310(1) that a contract may be formed by the interaction of electronic agents of the parties. It adds that this holds even where no natural person was aware of what those agents did, or reviewed the terms that came out of it. The same chapter defines an electronic agent at section 719.080 as a computer program or other automated means used independently to initiate an action, or to respond to records and performances, in whole or in part, and without review or action by a natural person.

Read those two provisions together and the position is plain. Nobody needs to have seen it. Nobody needs to have intended this particular purchase. The intention that matters was expressed when you set the thing up and pointed it at the task.

Sequence diagram showing how configuring an agent leads through independent action and acceptance of terms to attribution and performance

Does federal law add anything?

It adds a condition that is worth reading closely, because it is where your exposure is actually defined. The federal electronic signatures statute stops anybody arguing that automation alone voids the deal, and then attaches a qualifier.

Section 7001 of title 15 of the United States Code establishes at subsection (a) that a signature, contract or other record relating to a transaction affecting interstate or foreign commerce may not be denied legal effect, validity or enforceability solely because it is in electronic form. Subsection (h) extends that to agents: such a contract may not be denied legal effect solely because its formation, creation or delivery involved the action of one or more electronic agents, provided that the action of any such electronic agent is legally attributable to the person to be bound.

Legally attributable to the person to be bound is the whole game. It is not a loophole so much as a pointer to ordinary agency principles. Who gave the agent the credentials, the budget and the instruction, and did the counterparty have reason to think it spoke for that person. For a small business running an agent on its own accounts, all three answers point at you.

Note

None of this is specific to language models. The provisions were written for automated ordering systems and have applied for a quarter of a century. What changed is the range of things an agent will now do without being told to.

Who gets to escape an obvious mistake?

The individual on the other side, in defined circumstances, and not the business whose agent erred. This is the asymmetry that should shape how you deploy one.

Virginia's section on changes and errors provides that where an automated transaction involves an individual, that individual may avoid the effect of an electronic record produced by their own error while dealing with somebody else's electronic agent. The condition attached is that the agent gave no opportunity to prevent or correct the error.

Notice the direction of travel. The relief is for an individual, it concerns an error the individual made, and it is triggered by the other party's agent failing to offer a correction step. If you are the business running the agent, that provision is a duty you owe rather than a protection you enjoy. And when your own agent makes the error, you are outside it entirely.

SituationWho actedWhere the risk sitsWhat reduces it
Your agent buys from a supplierYour electronic agentWith you, by attributionSpend ceilings and an approved vendor list
Your agent accepts a vendor's termsYour electronic agentWith you, including the terms nobody readA human step before any acceptance
A customer's agent buys from youTheir electronic agentShared, and their principal is boundClear published terms and a correction step
A customer makes an error with your agentAn individualPossibly with you, if no correction was offeredA confirmation screen before commitment
Both sides fully automatedTwo agentsA contract exists, unreviewedLogs detailed enough to reconstruct it

Why is a confirmation step a legal control?

Because one of the statutory escape routes opens precisely when your agent did not offer one. That turns an interface decision into a risk decision, which is rare and useful.

If you run any automated ordering or booking flow, the opportunity to prevent or correct an error is not a nicety borrowed from usability guidance. It is the condition that determines whether a customer can later unwind a transaction. A final review screen that states quantity, total and terms before anything is committed is the cheapest protection in this article, and most small operations already have the component and have disabled it to reduce friction.

The same reasoning applies to your own outbound side. An agent that must show you a summary before it commits money is not slower in any way that matters, because the work it saved was the searching and comparing, not the pressing of the button.

What should you put in writing before an agent transacts?

Four limits, and they are commercial rather than clever. The law will not rescue a business that gave an agent an unbounded mandate, so the bounds have to exist in your configuration.

A hard spend ceiling per transaction and per day, set low enough that the worst single mistake is survivable. An approved counterparty list, because most damage comes from transacting with the wrong party rather than buying the wrong thing. A rule that any acceptance of terms, any new vendor and any recurring commitment goes through a person. And a log that records what the agent saw, what it decided and what it sent, at enough detail to reconstruct a transaction months later.

Card listing four limits to set before an agent transacts, covering a spend ceiling, an approved vendor list, a human step and a full action log

Those four are the operational form of the legal position. We went through how the permission ladder itself should be built, and why auto approval is where most of the risk enters, in deciding what an agent may do without asking.

Is a recurring commitment different from a one off?

Much worse, and it is the one to gate hardest. A wrong single order is a bounded loss you discover at delivery. A subscription an agent started is a small loss you discover in eleven months.

The reason is that nothing in your own process is looking for it. Card statements get reconciled against expectations, and a modest monthly charge with a plausible vendor name reads as expected. The agent that signed up for a tool to complete a task has created an obligation with a renewal date and possibly a notice period, none of which anybody chose.

So treat any commitment with a recurrence as categorically out of scope for autonomous action, however small. This is the same reasoning behind auditing the tools already billing you that nobody remembers approving, which we set out in auditing the AI features your existing tools switched on.

What if the agent was tricked into it?

Then you have a security incident and a contract at the same time, and the second one does not wait for the first to be resolved. This is the scenario that should worry a small business most, because it is the one where doing nothing wrong is not a defence.

An agent that reads web pages, emails or supplier documents can be steered by content inside them. The instruction to place an order does not have to come from you to be carried out by something holding your credentials. From the counterparty's side, the order still arrived from your account, authenticated, within the limits you set. The attribution question, who gave this thing the ability to act, has an awkward answer.

Which is why the boundaries matter more than the vigilance. You cannot inspect every input an agent reads, and the research on how reliably these systems can be manipulated is not reassuring, as we covered in what a large scale test of prompt injection actually found. What you can do is ensure that the worst thing a manipulated agent can accomplish is bounded by a spend limit and a list of parties it may transact with.

Treat any agent that both reads untrusted content and holds payment credentials as the highest risk configuration in your business. If you can separate those two capabilities, do that before anything else on this page.

How do you actually unwind a bad order?

Commercially, almost always, and quickly. The legal position being against you matters far less in practice than most owners fear, because the counterparty usually has no interest in holding you to an obvious machine error.

Call within the hour if you can, because a wrong order caught before dispatch is an administrative correction and a wrong order caught after delivery is a returns negotiation. Say plainly that it was an automated error and state what you want. Most suppliers deal with ordering mistakes constantly and have a process that predates any of this.

Where that fails, your options narrow to the ordinary ones. A return under the vendor's own policy. A negotiated partial, particularly on quantity errors where they keep the margin on what you do take. A payment dispute, which is a blunt instrument that costs you standing with your processor and should be a last resort rather than a reflex, for the reasons set out in how a processor scores your account rather than just your customers.

Which credentials should an agent never hold?

The ones where a mistake is not recoverable by returning something. This list is short and worth writing down before rather than after.

Anything that moves money directly, such as bank transfer or payment initiation, as opposed to a card with a low limit that can be disputed and reissued. Anything that changes your domain, hosting or DNS, because the failure mode there is your shop being offline rather than a wrong box arriving. Anything that can alter prices or publish to your live storefront without review. Anything that can send in your name to your whole customer list, since a wrong email cannot be recalled.

A card with a modest ceiling, a purchasing account at approved suppliers, a read only view of your analytics: those are reasonable agent credentials. The distinction is not how important the system is, it is whether an error in it can be undone by a phone call.

One jurisdictional note, since the provisions quoted in this article are from United States law. The specific sections differ elsewhere, and if you are trading in another jurisdiction the wording that binds you will be local. The operational conclusion does not move, because it rests on the fact that you configured the agent and gave it the means to act, and no jurisdiction treats that as somebody else's doing.

What about the agent buying from you?

Then the attribution question runs the other way, and it is largely good news. If a customer's agent places an order, their principal is bound by the same provisions that bind you.

What you owe in return is clarity and a correction opportunity. Terms that a machine can read and a human can find. A total that includes everything mandatory. A confirmation step that states what is being committed to. None of that is new practice, it is the practice you already owe a human customer, applied to a party that will not read a footnote.

The commercial mechanics of that side, including what changes at checkout when the buyer is software, are in what agentic commerce changes about checkout. The legal point is simply that you do not need a special regime to hold a customer to an order their agent placed.

What does this mean for the logs you keep?

They stop being a debugging convenience and become your evidence. When a contract can form without any person seeing it, the record of what the agent did is the only account of how the obligation arose.

Keep enough to answer three questions months later. What instruction was the agent operating under at that moment, including the version of its configuration. What information did it have in front of it, since a decision made on stale stock data is a different conversation from one made on current data. And what exactly did it transmit, as opposed to what you assume it transmitted.

That is a records retention decision as much as a technical one, and it belongs in the same place as your other commitments about handling data and access, which is why we publish ours on the page describing how the platform handles access and data rather than leaving it to be asked about.

The practical summary

The law already treats your agent's actions as yours, and it has done so since long before any of this was interesting. There is no argument available that says a purchase is void because a model made it. The qualifier in the federal provision, that the action must be legally attributable to the person to be bound, is not a shield for a business that handed over its own credentials and budget.

What follows is unglamorous and cheap. Bound the money, bound the counterparties, keep a person in the loop for anything that accepts terms or recurs, and log enough to reconstruct what happened. A business that does those four things can give an agent real work without the worst case being interesting. A business that does none of them is relying on nothing going wrong, which is not a control.

Discussion 0

0 / 4000Your email address is not displayed with your comment.
No comments are published yet.

Explore — related articles.

Build something. Move your work forward.

Start with a software project or an agent task. Describe the result you need, review the work and keep control of your connected accounts.

Open the workspace →