About this series: This is the third article in a four-part series on agentic commerce and its legal implications. This article examines who bears liability when an autonomous agent transacts on a consumer's behalf — and why existing law offers more protection, and more uncertainty, than most people assume. ← Read Part 2

When the Agent Gets It Wrong

The previous article ended with a question the payments industry cannot yet answer: if a fraudulent or incorrect transaction occurs, who is accountable — the user, the agent's developer, the merchant, the issuer, or the intermediary platform?

A transaction can fail in two ways, and the law sorts them differently. One is the unauthorized transaction: an account takeover, a hijacked agent, or money sent to a thief. The other is the transaction that the consumer genuinely set in motion: no impostor, no hijacking; the agent transacted in the consumer’s name and still got it wrong, whether by going beyond his/her instructions or misreading the fine print. This article takes up the second. The first runs on the separate rails of the chargeback and unauthorized-transfer rules, and it is part of why networks and platforms are building what the final article describes.

Return to the Amalfi Coast to see why the question is so difficult. You asked for the Amalfi Coast, but your agent booked a hotel in Taormina, on the coast of Sicily — the wrong region entirely, hundreds of miles south of the water you had in mind — or it locked in two non-refundable fares for the wrong week. You trusted that the agent had read the fine print you never opened. The reservations are confirmed, and the charge has cleared. Someone must absorb that loss. The law's task is to decide who.

Two initial considerations. First, we need to set that you cannot sue the software. As Diana Stern and Dazza Greenwood observe, a transactional agent cannot be held liable or enter into agreements itself because it is not a legal entity, it is software.

Second, two overlapping frameworks may apply to accountability here. Under the Uniform Electronic Transactions Act (UETA), it is well-settled that transactional agents can form contracts on behalf of their users (UETA § 14). But principal-agent law may also be operating in the background (and that relationship need not be written down). As Stern and Greenwood explain, a principal-agent relationship may exist even without an express agreement: it can be implied, or based on "apparent authority," when a third party reasonably believes an agent has the authority to act on the principal's behalf. See Restatement (Third) of Agency §§ 1.01, 2.03 (Am. L. Inst. 2006). We examine that below.

Agent or Instrument?

Start with the one fixed point: the consumer is the principal. The harder, fact-specific question is whether the provider behind the software counts as the consumer's agent or whether the software is merely an instrument the consumer acts through.

What decides it is a close look at the circumstances. A court, Stern and Greenwood suggest, would likely look at the customer's actions in deploying and configuring the transactional agent as well as the terms they agreed to; and as for apparent authority, it would consider how the provider's authority was communicated to third parties, including representations, disclaimers, and industry standards. The answer points in two very different directions.

If the provider is not the consumer's agent, then there is no common-law agency relationship at all: only the consumer and a tool. The software is the instrument through which the consumer acts, its actions are attributed to the consumer under UETA, and the consumer is bound by whatever it does within the scope of authority granted. This is why clear instructions, clear limits, and authority matter so much: they set the boundaries of what the consumer is responsible for.

If, on the other hand, the provider is the consumer's agent, the liability shifts, because now there is a legal person in the agent's seat, capable of bearing obligations the software never could. As Stern and Greenwood put it, that matters because an agent owes duties, not merely services. Unlike a piece of software, a common law agent owes the consumer fiduciary duties; above all, a duty of loyalty: a legal obligation to act in the consumer’s best interests, not its own. Few providers want that role. The reality is that those duties are hard to meet for a product built to move fast and transact at scale.

The Protection the Fine Print May Not Erase

Whichever way the agent-or-instrument question is resolved, the consumer is not left exposed while it is sorted out. UETA, a uniform commercial law enacted by every state except New York (which runs its own Electronic Signatures and Records Act), contains provisions written specifically for errors in automated transactions. A relevant provision permits the individual to reverse transactions if the transactional agent did not provide a means to prevent or correct the error (UETA §10). But the remedy is narrower than it sounds. It runs only to an individual, not a company, and only if that individual does three things: gives prompt notice of the error, takes reasonable steps to return what was received, and has not used or taken any benefit from it. With a non-refundable booking, that last condition is the obstacle: once the reservation is confirmed, the consumer already holds what the booking gives (the right to that room on that date), so there is nothing left to be returned.

There is a deeper problem: the UETA § 10 remedy may not help against the merchant at all. The provision was built for a familiar case: an individual who makes an error while dealing with a merchant's automated system that gave no chance to catch it. The agent scenario does not fit. The merchant's system worked, the wrong booking arrived as a clean order, and the error came from the consumer's own agent, not from the consumer's dealings with the merchant. So if the consumer invokes § 10 against the merchant to undo the booking, the merchant may argue that the consumer is bound by what its agent did, whether under § 14 or through an agency relationship. § 10 was never meant for an error that originated on the consumer's own side. The consumer's real complaint, then, is with the agent's provider, not the merchant. And what that complaint is worth turns on the agent-or-instrument question from the start: if the provider is merely the supplier of an instrument, the recourse runs into its terms of use, which will disclaim liability as far as the law allows; if the provider is the consumer's agent, it owes fiduciary duties those terms cannot simply waive away.

There is also the protection that a real consumer reaches for first. Nobody litigates UETA over a hotel booking. They call the card issuer and dispute the charge. That route runs on its own rules: the card networks' chargeback procedures, which a consumer actually invokes first, layered over the statutory rights, the Fair Credit Billing Act and Regulation Z for credit cards, the Electronic Fund Transfer Act and Regulation E for debit and other electronic transfers. Regardless, every version of the dispute runs between the cardholder and the merchant, and asks the same question: did the merchant perform? Here it did. The room that was reserved is the room that was delivered, on the dates that were booked. Its performance was conforming. The usual grounds for disputing a credit card charge (goods not as described, services not received, an unauthorized charge) are not present. And debit is narrower still: Regulation E does not reach an authorized payment that the consumer has come to regret.

The defect is between the consumer and the agent, where a card dispute does not reach. What is left is a claim against the provider of the agent, and how far it gets returns to the agent-or-instrument question that decides what such a claim is worth.

The law leaves the consumer's recourse uncertain. So the better answer is to prevent the error in the first place, through good design, and UETA § 10 rewards providers who do this. This is what makes that single approval click more important than it looks. When providers build a user interface and a process that lets customers review and correct a transaction before it is final, they do two things at once. They comply with UETA, and they also create a strong argument for ratification. The reason is simple: if a customer had the opportunity to fix an error but chose not to, it can be argued that the customer accepted the transaction as final.

Where This Leads

Consumers are not unprotected: agency law and UETA already supply meaningful safeguards, and the most important of them cannot be waived away. But as Stern and Greenwood candidly acknowledge, the legal and practical implications of these changes and errors are complex and largely untested. Almost every question of how these rules apply to autonomous agents remains open. That uncertainty is why the market is not waiting for the courts. In the final article, we turn to the infrastructure being built to resolve these questions before they ever reach a courtroom: the authentication and trust protocols emerging from Visa, Mastercard, Google, and others.

Continue reading · Part 4 of 4

Verifying the Machine: The Infrastructure of Agentic Trust
The Briefing

New essays in your inbox, roughly monthly.

Legal analysis on the AI and privacy regulations that actually affect technology businesses. No noise, no boilerplate.

This article is for informational purposes only and does not constitute legal advice. Reading this essay does not create an attorney-client relationship.