tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

What you are on the hook for when an AI agent acts for you

The rules that decide who pays when an agent buys, sends or publishes something on your behalf, and how to cap the damage before it acts.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

The question arrives late. You have already let the browser agent do the reordering, or wired the automation that answers the inbox at 06:00, and then one morning it buys 12 of something, or emails a client a draft that was never meant to leave the folder, or accepts terms on a supplier site you have never read. The first thing you want to know is whether this is your problem or somebody else’s.

It is yours. That is the short answer, and it has been the answer since before anyone called this software an agent. This guide sets out the three places the rule comes from, what it means for a card charge and a signed-by-nobody contract, and the specific limits worth putting in place before the next unattended run. It is written for a solo operator or small team using ordinary tools, and it is not legal advice. If you are pointing agents at decisions about people, note that OpenAI’s terms already forbid using output for any purpose with a legal or material impact on a person, naming credit, educational, employment, housing, insurance, legal and medical decisions [6]. That is a case for counsel, not for a guide.

The law already treats what your agent does as something you did

The federal E-SIGN Act says a contract cannot be denied legal effect “solely because its formation, creation, or delivery involved the action of one or more electronic agents so long as the action of any such electronic agent is legally attributable to the person to be bound” [2]. The state-level twin, adopted from the Uniform Electronic Transactions Act, goes further and removes the excuse you would reach for first. In California’s version, a contract “may be formed by the interaction of electronic agents of the parties, even if no individual was aware of or reviewed the electronic agents’ actions or the resulting terms and agreements” [3].

Read that clause again with your automation in mind. Nobody was watching is not a defence. It is the exact situation the statute contemplates and then makes binding. California added its section in 1999 and it took effect on 1 January 2000 [3]. That vintage is why the rule is worth building on rather than arguing with. It was settled law for a quarter of a century before browser agents existed, and their arrival did not amend a word of it.

The same section covers the case that actually describes your week, where software on one side deals with a human on the other. A contract may be formed “by the interaction of an electronic agent and an individual,” including where the individual does something they were free to refuse and knew would cause the agent to complete the transaction [3]. The supplier’s sales rep who replies to your agent’s email is that individual. Nothing in the arrangement requires them to work out which side of the exchange had a person on it.

E-SIGN does attach a condition worth noticing, because it is the only real seam. Attribution holds “so long as the action of any such electronic agent is legally attributable to the person to be bound” [2]. That is a question about the ordinary law of authority, not about the software, and in the small-business case it usually answers itself. You installed it, you connected the account, you set the schedule, you took the benefit.

The newest data point points the same way. In August 2026 the Ninth Circuit vacated the preliminary injunction Amazon had won against Perplexity’s Comet assistant, and the reasoning matters more than the outcome. Amazon had argued that Perplexity was the party accessing its systems, because the assistant navigates the site itself and checks back with Perplexity’s servers for instructions [1]. The panel disagreed: “It is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com,” and “however advanced the Assistant currently is, it is a tool, not a person for statutory purposes” [1]. That was a win for the agent maker. Notice which way it leaves the arrow pointing when the agent is yours.

Your vendor’s terms say the same thing in plainer words

You do not need a court to work out where you stand, because you agreed to it at signup. Anthropic’s consumer terms define Actions as the service taking steps on your behalf, “such as software manipulation, data processing, and system interactions,” and then state that “you are responsible for all Inputs you submit to our Services and all Actions” [4]. The same document tells you not to rely on outputs or actions “without independently confirming their accuracy,” and provides the service on an “AS IS” basis [4]. The browser product repeats it without hedging: “You remain responsible for all browser actions taken by Claude performed on your behalf,” including content published, purchases and financial transactions [5].

OpenAI’s terms are built the same way. You own the output, you are responsible for content, output “may not always be accurate,” and if you are a business you indemnify OpenAI against third-party claims arising out of your use of the service [6]. That last clause is the one people skim. It means that if your agent’s action causes somebody else a loss and they come looking, the contract you signed sends the bill back toward you, not toward the model provider.

A purchase your agent makes is not an unauthorised charge

Card protection is the backstop most operators assume they have, and it is the one that fits worst. Regulation Z caps your liability for unauthorised use of a credit card at “the lesser of $50 or the amount of money, property, labor, or services obtained by the unauthorized use before notification to the card issuer” [7]. The protection is real. The definition is the problem. Unauthorised use means “the use of a credit card by a person, other than the cardholder, who does not have actual, implied, or apparent authority for such use, and from which the cardholder receives no benefit” [7].

Your agent is not a person other than you, it was acting on authority you gave it when you connected the card, and you received whatever it bought. Three of the elements fail at once. Whatever recourse you have when an agent overspends, that clause is not it, and the practical consequence is simple: the limit that protects you is the one you set in advance on the card, the account or the workflow, not the one you invoke afterwards.

What is left is the seller. Cancelling before dispatch, returning inside the window, arguing that the goods were not what was described: all ordinary commercial recourse, all subject to that particular merchant’s rules, and none of it something you can size or rely on before it happens. That is the gap. The protection you assumed was structural turns out to be a negotiation, and it starts on a morning when you are busy.

So decide the number before the first unattended run rather than after the first surprise. The useful figure is not what a single mistake costs. It is how much value the agent can commit between two moments when a human actually looks.

calculator
What an agent can commit between reviews
— $ / month

runs × per-run ceiling × 4.3 weeks. Your own numbers, not a benchmark. If the result is larger than you would write a cheque for without asking, lower the ceiling rather than the run count. Computed in the page; nothing is sent anywhere.

The realistic failure is an instruction arriving from the page

Agents rarely go wrong the way films suggest. They go wrong because the web page, email or document they were told to read contained text addressed to them. Anthropic’s own safety guidance names it as the biggest risk facing browser-using AI tools: malicious instructions hidden in web content “could trick Claude into taking unintended actions.” Two safety classifiers screen for it, one checking incoming content and one checking every action before it runs, and the page still says plainly that “the risk is not zero” [5]. OpenAI describes the same category for ChatGPT agent, including prompt injection monitoring and an example in which planted content tries to make the agent retrieve a password reset code from a mailbox [8].

The reason this is a liability question rather than a security curiosity is attribution. The injected instruction inherits your authority. The purchase it makes is a purchase you authorised, the email it sends comes from your address, and the contract it accepts is formed even though no individual reviewed the terms [3]. There is no layer in that chain where the exposure moves to somebody else.

Treat every surface where the agent reads content you did not write as hostile input, and treat the actions available downstream of that surface as the actual risk. An agent that reads the open web and can only draft is a nuisance when it goes wrong. The same agent with a saved card and a send button is a loss.

Cap the blast radius before you polish the prompt

Better prompting reduces how often the agent misfires. It does nothing about what a misfire costs. That is set by the permissions and the credentials, so spend the first hour there.

Both major browser agents ship the controls already. Claude in Chrome starts in “Automatically approve” mode, where Claude screens its own actions and pauses only when something needs you; switching to “Manually approve” means you review every action instead. It asks permission before financial sites and blocks adult and known pirated content outright [5]. ChatGPT agent pauses and hands the browser back to you when a login is needed, and while you are in control “screenshots are not captured, which helps protect passwords and other sensitive data you enter,” alongside user confirmations for high-impact actions and a watch mode requiring supervision on certain sites [8]. Turn the stricter setting on for anything that spends, sends or publishes, and leave it on. The friction is the product.

Before that, cut the list of things the agent can reach at all. Most tasks people hand to an agent are reading, comparing and drafting, and those tasks do not need a payment method attached or a mailbox with send rights. Anthropic keeps a few categories off the table entirely for its browser agent and asks permission before it touches financial sites [5]. Do the equivalent yourself with the accounts you connect: an agent that cannot reach the thing cannot lose it, and no prompt is as reliable as an absent credential.

Then separate the identities. A virtual card with a low ceiling for the agent, not your main card. A login with only the access the task needs, not the owner account. A sending address whose reputation you can afford to lose, not the one clients reply to. For scheduled automations in Zapier or n8n, the same logic applies at the step level: keep the irreversible actions (payment, publish, delete, send to a client) behind a confirmation or a queue you clear each morning, and let the reversible ones run.

Last, keep the run history. Not for tidiness. Because attribution runs both ways, and the only version of what happened that you will be able to show a supplier, a client or an insurer is the log of what you instructed and what the agent did.

checklist
Before you let an agent act unattended
0 of 7 · saved in this browser only

What still goes wrong

The clean rule has ragged edges. The Ninth Circuit was explicit that its holding is “limited to ‘access’ as contemplated by the CFAA and as applied to the Assistant’s interactions with Amazon.com on the record before us, not the broader legal landscape surrounding agentic AI,” and added that it was not addressing whether Perplexity could avoid liability for the assistant’s actions in other contexts, including tort claims [1]. So it settles one federal statute in one circuit and leaves contract claims, terms of service and state law where they were. Nothing here is legal advice. The statutes quoted are federal law [2] and California’s enactment of UETA [3]; the text that governs you is your own state’s, and if your agent transacts across borders the answer is somebody else’s to give.

The vendor terms move. Anthropic’s Actions language and OpenAI’s indemnity clause both read as they do today [4][6], and both companies revise these documents as agent features ship. The date at the top of the terms page is the only reliable version marker, and it is worth checking before you widen what an agent is allowed to do rather than after.

The controls are also softer than they look. Approval prompts train you to approve; by the fortieth confirmation you are clicking, not reading. Prompt injection classifiers reduce a risk their own vendor says is not zero [5]. And the log that protects you only exists if the tool kept it, which is a question worth asking before you need the answer rather than during the argument.

sources
  1. 01Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026)cdn.ca9.uscourts.gov
  2. 0215 U.S.C. § 7001 — General rule of validity (E-SIGN)law.cornell.edu
  3. 03California Civil Code § 1633.14 — Automated transactions (UETA § 14)law.justia.com
  4. 04Anthropic — Consumer Terms of Serviceanthropic.com
  5. 05Anthropic Help Center — Use Claude in Chrome safelysupport.claude.com
  6. 06OpenAI — Terms of Use (effective January 1, 2026)openai.com
  7. 0712 CFR § 1026.12 — Special credit card provisions (Regulation Z)ecfr.gov
  8. 08OpenAI Help Center — ChatGPT agenthelp.openai.com
next guide
Your own data is the part AI never scraped
9 min · verified 2026-09-04
related guides