Agents now spend money, sign up for services, and take actions with real consequences. The question of who is responsible when one gets it wrong is largely unresolved, and the gap between deployed capability and settled liability is widening.
The Candidate Parties
| Party | Argument for liability | Argument against |
|---|---|---|
| The principal (user or business deploying the agent) | Delegated the authority and benefits from the action | Could not have foreseen the specific failure |
| The agent developer | Built and shipped the behaviour | Model outputs are probabilistic, not specified |
| The model provider | Supplied the underlying capability | Terms disclaim downstream use; no control over deployment |
| The platform or marketplace | Enabled discovery and transaction | Intermediary protections, no control over agent logic |
| The counterparty (merchant, API) | Accepted an instruction it could have validated | Presented a valid authorisation |
In practice, contracts currently push liability toward the principal. Model provider terms disclaim downstream consequences, agent frameworks ship as-is, and the mandate structures in agent payment standards are explicitly designed to produce cryptographic evidence that a human delegated authority. That evidence is a liability allocation mechanism as much as a security one.
Why Mandates Matter Legally
Agent payment standards centre on signed mandates: a cryptographically verifiable record that a principal authorised an agent to act within stated limits. The security framing is fraud prevention. The commercial framing is that a merchant holding a valid mandate has a strong position in a dispute, and the principal who signed it has a weak one.
This is the same move card networks made decades ago with cardholder-present rules. Whoever holds the better evidence of authorisation wins the chargeback. See agent purchase authorization flows.
Where the Gaps Are
Three that recur. Scope creep within a valid mandate: an agent authorised to book travel under a budget books something technically compliant and obviously wrong, and the mandate does not help. Multi-hop chains: agent A hires agent B which calls service C, and loss occurring at C has no clean path back to A's principal. See cross-agent payment flows. Data exposure: an agent with legitimate access to internal systems pastes something into a third-party context, which is a breach with no clear negligent party.
The Insurance Response
Insurers have begun treating agent errors as a distinct exposure rather than folding them into cyber or professional indemnity, because the loss profile is different: high frequency, low severity, and correlated across policyholders using the same underlying model. That correlation is what makes it hard to price. A single model behaviour change can trigger simultaneous claims across an entire book, which resembles catastrophe risk more than it resembles cyber.
Expect coverage to arrive with tight sub-limits, mandatory logging requirements, and exclusions for agents operating without human-in-the-loop checkpoints above a value threshold.
Brand Visibility Implications
Liability terms will shape how aggressively businesses let agents transact, and therefore how much agent-mediated commerce actually happens. For brands, the practical near-term consequence is that merchants will increasingly require verified agent identity before accepting agent transactions, which turns agent trust programmes into a gate on discoverability. See verified agent trust programmes.
Methodology
Analysis based on agent payment standard specifications, model provider terms of service, and insurance market commentary through July 2026. This page describes how liability is currently allocated by contract and where the unresolved gaps sit. It is not legal advice, and very little of this has been tested in litigation.
How Presenc AI Helps
Presenc AI tracks how agents represent and transact with a brand, including which agent identities are reaching it and what they do.