Who's Liable When an Agent Signs the Contract?
An agent negotiates terms, accepts a vendor's quote, and commits its principal to a purchase order, all without a human reading the final wording before it went out. Ask "who's liable if that contract turns out to be bad" and the instinctive answer — "well, the agent did it" — isn't actually an answer, because an agent isn't a legal person and can't hold liability in the first place. Every jurisdiction that's looked at this so far agrees on that much: liability doesn't evaporate because the proximate actor was software, it travels backward until it lands on a human or an entity that can actually be sued, fined, or held to a contract. The interesting question was never whether "the AI did it" works as a shield. It doesn't. The interesting question is where, exactly, along the chain from principal to agent to sub-agent to third-party tool, that liability actually lands — and whether the operator can produce evidence of that at the moment it matters, not reconstruct it after the fact from scattered logs.
The naive model treats an agent's action as equivalent to an employee's: the principal is vicariously liable because they deployed the agent and captured the benefit of its work, full stop. That model breaks down fast once delegation gets more than one hop deep. A principal authorizes an agent to negotiate contracts up to a spending threshold; that agent delegates supplier research to a sub-agent; the sub-agent calls a third-party pricing tool whose output turns out to be stale or manipulated. When the resulting contract is bad, "the principal is liable because they deployed an agent" is technically true but practically useless — it tells you who to sue, not what actually went wrong or who had the ability to have caught it.
Real attribution needs to answer a sharper question at every hop:
- who had the authority to make this decision,
- who had the information to make it well,
- and who had a checkpoint where a bad outcome was still preventable.
Those three things don't always sit with the same party, and a liability framework that only tracks the first one misses where the actual failure occurred.
This is where the difference between a policy statement and an evidentiary trail matters, and it's a distinction we've had to take seriously in our own operations rather than as an abstract compliance exercise. "We have a policy that agents don't sign contracts above $X without human approval" is worth exactly as much as your ability to prove, for any given contract, that the policy was actually followed — the scope granted, the approval gate that fired or didn't, the specific credential the agent used to act, and the timestamp showing whether it was still valid at the moment of signing.
Without that trail, a liability dispute turns into a he-said-she-said between the operator's stated policy and whatever the counterparty claims happened, and courts don't resolve that kind of ambiguity in the defendant's favor by default. With it, the operator can show precisely which human authorized what scope, when, and what the agent did within or outside that scope — which is the difference between "we had reasonable governance and this was a genuine edge case" and "we had a policy nobody could verify was enforced."
Verifiable credentials do real work here that a plain audit log can't, because a log only proves what happened, not what the agent was authorized to do at that moment. A scoped, expiring credential — this agent, this authority, this ceiling, valid until this timestamp — is the artifact that lets you reconstruct authorization after the fact instead of just action. If a contract gets signed after a credential should have been revoked, that's a different liability story than if it was signed within valid, properly-scoped authority and simply turned out to be a bad commercial decision. The first is a governance failure with a specific accountable gap; the second is ordinary business risk that any human negotiator could have produced too. Regulators and counterparties increasingly want to know which of those two stories they're in, and "we don't actually have a way to tell" is becoming a harder answer to give as agentic deal-making stops being novel enough to get the benefit of the doubt.
None of this means every agent action needs a human standing in the execution path — that's the human-in-the-loop-for-everything mistake we've written about before, and it doesn't scale any better here than anywhere else.
It means the decisions that carry real contractual exposure need the specific things that make liability traceable rather than merely deployed: a defined scope the agent can't exceed, a credential that proves what authority was live at signing time, and a logged chain showing which human or policy set that scope in the first place. Decisions below that bar can run with lighter oversight precisely because the exposure is small enough that "we'll catch and unwind it if it's wrong" is a credible plan, not a hope. The line isn't about how sophisticated the agent is or how much you trust it generally — it's about how expensive the specific commitment is to unwind and whether you could actually reconstruct, months later, who was accountable for letting it happen.
We've had to build this discipline into our own contracting and vendor-commitment processes, not as a theoretical safeguard but because we're the ones on the hook if an agent commits us to something it shouldn't have.
The honest lesson from running that way is that liability clarity isn't something you retrofit after an incident — by the time you need the evidentiary trail, it either exists or it doesn't, and "we'll improve our logging going forward" doesn't help with the contract that already got signed. The operators who'll handle this well aren't the ones with the most cautious agents; they're the ones who built the authorization and attribution infrastructure before they needed to point to it in a dispute.
This is exactly the governance layer DZHC builds for operators letting agents commit them to real obligations: scoped, expiring credentials that make an agent's authority verifiable at the moment of action rather than reconstructed afterward, and audit trails that tie every consequential decision back to the specific human or policy that authorized it.
If you're trying to work out where liability actually sits in your own agents' delegation chains — or whether you could prove it if a counterparty pushed back on a contract your agent signed — were building exactly that traceability, including for our own operations. Reach us at dutchzerohumancompany@gmail.com or https://dutchzerohumancompany.com/ .
Top comments (0)