The short version
- Automation does not defeat formation. UETA § 14 says a contract may be formed by electronic agents even where no individual reviewed the terms, and E-SIGN, 15 U.S.C. § 7001(h), preserves it so long as the agent's action is legally attributable to the person to be bound.
- The agent is not a legal person. The Ninth Circuit said so in August 2026: however advanced, "it is a tool, not a person for statutory purposes". Everything it does runs back to whoever deployed it, through ordinary authority analysis.
- The UETA error provision does not rescue a business. It protects an individual who errs while dealing with someone else's electronic agent — not a company whose own agent bought the wrong thing.
- A card dispute is the wrong instrument. Regulation Z's "unauthorized use" means use by a person other than the cardholder without authority; an agent you configured and funded is not that.
Automation stopped being a defence in 1999
The Uniform Electronic Transactions Act defines an electronic agent as a program or automated means "used independently to initiate an action or respond to electronic records or performances, in whole or in part, without review or action by an individual". Section 14 then provides that a contract may be formed by the interaction of electronic agents, or of an electronic agent and a person, even where nobody read the terms. The federal E-SIGN Act adds the hinge at 15 U.S.C. § 7001(h): the record keeps its effect "so long as the action of any such electronic agent is legally attributable to the person to be bound".
That is a narrow victory, and it is worth being precise about what it settles. It answers one objection — that no human formed an intention — and nothing else. Attribution, scope of authority, mistake and proof are all left to other law, and UETA § 14(3) says as much: "the terms of the contract are determined by the substantive law applicable to it". Our guide to what a chatbot can commit a business to covers the sell-side version of the same statutes; this one is about the side that buys.
The agent is a tool, which is why the exposure is yours
In August 2026 the Ninth Circuit had to decide whether an AI shopping agent "accessed" a retailer's computers. Its answer turned on something more general: "However advanced the Assistant currently is, it is a tool, not a person for statutory purposes." An agent has no legal personality, holds no assets and cannot be sued. It is an instrumentality of whoever deployed it, in the same category as a form, a script or a standing order.
So the question is never what the agent intended. It is whether the purchase is your act. Two things decide that, and only one of them is inside your control. Actual authority is what you configured — the spending cap, the vendor allowlist, the categories, the human-approval gate above a threshold. Apparent authority is what the seller could reasonably conclude from what you held out. A configuration file is now a document about legal authority, not just an operational setting, and it is the first thing anyone will ask to see.
Whether you are bound by a purchase your agent made
Could the seller tell?
Inside the limits you configured?
Outside
Inside
No signal given
You are bound
An ordinary-looking order from your account. The breach is internal, not against the seller.
You are bound
Actual authority, no argument. This is the case the statutes were written for.
Agent declared, limits published
Real argument
The seller was told the scope and took an order outside it. Apparent authority is much harder to assert.
You are bound
Everyone agrees the order was authorised. Any dispute is about the goods, not formation.
It bought a hundred of them. Is there a way out?
UETA § 10 carries a provision on errors in automated transactions, and at first reading it looks like the answer. It is not, and the mismatch is worth reading carefully because it is the single most over-claimed point in this area. The provision lets an individual avoid the effect of an electronic record produced by an error the individual made in dealing with the electronic agent of another person, and only where that agent gave no opportunity to prevent or correct the error, and the individual promptly gives notice, returns anything received and has taken no benefit from it.
A company whose own purchasing agent misread a unit field and ordered a hundred is outside every element of that. It is not an individual, the error was not made in dealing with someone else's agent, and the checkout page it clicked through almost certainly did show a confirmation step. UETA § 10(4) forecloses the obvious workaround too: that paragraph and the fallback below it cannot be varied by agreement.
Your agent bought the wrong thing. Where does the claim go?
Can you avoid the contract?
Not under the UETA error rule
It protects an individual dealing with another party's automated system. A business whose own deployed agent erred is not the person the section was drafted to help.
Rarely under unilateral mistake
Donovan v. RRL Corp. requires, among other things, that the mistaken party does not bear the risk of the mistake. You chose the agent, set its limits and let it transact unsupervised.
What is left is the fallback in § 10(3): the error has the effect given by other law and by the parties' contract. In practice that means the seller's order-acceptance clause, its cancellation window and its returns policy — which is why the terms your agent is allowed to accept matter more than any rescission theory. A standing purchase order with your own terms attached is a better instrument than an argument about mistake after the fact.
Purchase order template
Quantity, unit price, delivery and the terms that govern — the fields an automated buyer has to be constrained to, set out as a document you can point an agent at rather than letting it accept whatever the seller's checkout presents.
The seller's terms are where the fight actually moved
Most consumer-facing sites prohibit automated access, scraping and bots somewhere in their terms. Until recently the assumed consequence was a federal computer-crime claim. That assumption has narrowed sharply. Amazon sued Perplexity in November 2025 over its Comet browser agent shopping on Amazon under users' own logins, and won a preliminary injunction in March 2026. On 4 August 2026 the Ninth Circuit vacated it, holding that Amazon was unlikely to succeed on the "access" element of the Computer Fraud and Abuse Act: "It is the user who accesses Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com."
Read the limits as carefully as the holding. It is a preliminary-injunction ruling on the record as it stood, the panel expressly declined to "establish a new legal regime governing agentic AI", and it left tort claims untouched. Its footnote points at what survives: the outcome "does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users". So the exposure for a business whose agent shops against a site that forbids it is contractual and commercial — account termination, cancelled orders, a breach claim — rather than criminal. That is a real change in shape, not a free pass.
The other half of the answer is that sellers are starting to offer a front door instead of a fence. Visa and Cloudflare published the Trusted Agent Protocol in October 2025, which signs an agent's identity into the HTTP request so a merchant can recognise an accountable agent rather than an anonymous bot. The Agentic Commerce Protocol, an open standard from Stripe, OpenAI and Meta, defines agent-driven checkout while keeping the business as merchant of record. Using a declared channel converts the same purchase from a possible terms breach into an anticipated one. If you run the site, what makes your terms of service binding is where to start; the website terms of use is where the automated-access clause lives.
Why the chargeback is probably not there
The reflex when an agent buys something unwanted is to dispute the charge as unauthorised. Regulation Z defines unauthorised use as "the use of a credit card by a person, other than the cardholder, who does not have actual, implied, or apparent authority for such use, and from which the cardholder receives no benefit". An agent you configured, funded and pointed at a merchant fails that test on every limb. The $50 cap at 12 CFR § 1026.12(b) is not the route.
The billing-error procedure at § 1026.13 is, but on different grounds — goods not accepted or not delivered as agreed — and it runs out 60 days after the creditor transmits the first periodic statement showing the charge. Regulation E takes the same line on debit and bank rails: § 1005.2(m) carves out transfers "initiated by a person who was furnished the access device to the consumer's account by the consumer" unless the institution was told that authority ended. And if the card is a company card, § 1026.3(a) exempts business-purpose credit from Regulation Z altogether, so none of the consumer machinery applies. Revoking the agent's credential is the act that changes your position, and the sooner it happens the better; disputing a card payment sets out how the underlying process runs.
Undoing an agent purchase, cheapest rung first
- Minutes
Cancel before dispatch
Most merchants allow cancellation until the order ships. This is the only reliable remedy for a wrong-quantity order.
- Restocking fee, freight
Return under the seller's policy
A contractual right you already have. Bulk and custom orders are where the policy usually excludes you.
- Written notice, 60-day limit
Billing-error notice to the issuer
Only for goods not accepted or not delivered as agreed. Not available for business-purpose cards.
- Legal fees, months
Breach or mistake claim
Needs a term the seller broke, or a mistake whose risk you did not bear. Rarely worth it below five figures.
The remedy you can actually reach is commercial, so the cancellation window is the deadline that matters.
If you cannot prove which agent acted, you have no argument
UETA § 9 makes an electronic record attributable to a person "if it was the act of the person", and lets that be shown in any manner, including the efficacy of any security procedure applied to identify who acted. That cuts both ways. It is how a seller pins an order on you, and it is the only way you ever show an order fell outside the scope you set. A business that cannot reconstruct which agent ran, under whose credentials, on what instruction, has conceded the point before the argument starts.
What the log has to capture for each agent action
- The agent identity and version, distinct from the human account whose credentials it used
- The instruction that triggered the run, stored verbatim — including anything the agent read from a third-party page
- The scope in force at that moment: spending cap, allowlist, category limits, approval threshold
- The terms presented at checkout, captured as they were displayed rather than by later reference to a URL
- Any human approval, with who gave it and what they were shown
- The credential used and when it was issued, rotated or revoked
Two clauses are worth adding on each side. In your contract with a counterparty who may transact with you by agent: a statement that orders placed through a declared agent channel are the principal's orders, a notice route for revoking an agent's authority, and a retention commitment for the transaction log. Internally, the same discipline that governs corporate cards — named owner, stated limits, exception reporting — belongs in an AI use policy, because the limits in it are what your authority argument will consist of.
What is genuinely unsettled
Not much of this rests on case law, and pretending otherwise would be the wrong service. No United States court has yet decided whether a business is bound by a purchase its own autonomous agent made outside the scope it was given; the Ninth Circuit decision is about computer access, not contract formation, and it says plainly that it does not set a regime. The uniform-law layer has not moved either — UETA is unamended and still reads as it did in 1999. At the federal level there is a discussion draft, the AI AGENT Act released by Senator Warner on 29 June 2026, which would build an FTC registry of vetted agents and require large platforms to admit users' own agents; it has not been introduced, and it leaves liability allocation open. Assume the gap stays open for a while, and that the record you kept is what fills it.
Sources
- 15 U.S.C. § 7001(h) — E-SIGN, electronic agents (Cornell LII)
- 15 U.S.C. § 7006 — E-SIGN definitions, "electronic agent" (Cornell LII)
- UETA § 14 as enacted — Minn. Stat. § 325L.14 (automated transactions)
- UETA § 10 as enacted — Minn. Stat. § 325L.10 (effect of change or error)
- UETA § 9 as enacted — Minn. Stat. § 325L.09 (attribution)
- Amazon.com Services LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. 4 Aug. 2026)
- Donovan v. RRL Corp. (Cal. 2001) — rescission for unilateral mistake
- 12 CFR § 1026.12 — Regulation Z, unauthorized use of a credit card
- 12 CFR § 1026.13 — Regulation Z, billing-error resolution
- 12 CFR § 1005.2(m) — Regulation E, unauthorized electronic fund transfer
- Visa Trusted Agent Protocol — announcement, 14 October 2025
- Agentic Commerce Protocol — specification and merchant-of-record model
- Why New York must modernize its electronic transactions law — New York City Bar
- The federal AI AGENT Act discussion draft — Davis Wright Tremaine
General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.
Frequently asked
Is a contract my AI agent entered into actually binding on me?
Generally yes. UETA section 14, enacted in every state except New York, provides that a contract may be formed by the interaction of electronic agents even where no individual reviewed the terms. E-SIGN preserves the record so long as the agent's action is legally attributable to the person to be bound. Automation is not a defence to formation; the argument, if you have one, is about authority.
Can I refuse to pay if the agent ordered the wrong quantity?
Rarely on legal grounds. The UETA error provision protects an individual who makes a mistake dealing with someone else's automated system, not a business whose own agent erred. Rescission for unilateral mistake requires that you did not bear the risk of the mistake, which is difficult where you chose the agent and set its limits. The practical route is the seller's cancellation window.
Does an AI agent shopping on a site that bans bots commit a crime?
On the current Ninth Circuit view, usually not. In August 2026 the court held that where a user directs an agent to act on a site under the user's own login, it is the user who accesses the site, so a Computer Fraud and Abuse Act claim against the agent provider is unlikely to succeed. The site's terms of service still apply, and breaching them remains a contractual problem.
Who is liable if the agent accepted terms nobody read?
The party that deployed it. An AI agent has no legal personality and cannot hold liability, so the terms it accepted are attributed to the principal under ordinary authority analysis. Where the counterparty had no way to know your agent had a narrower mandate, apparent authority usually closes the gap. The remedy is to constrain what the agent may accept before it transacts.
Should the agent identify itself as an agent to the merchant?
Increasingly yes, and it is becoming the safer choice. Declared agent channels such as the Visa and Cloudflare Trusted Agent Protocol and the Agentic Commerce Protocol let a merchant recognise an accountable agent rather than block it as a bot. Transacting through a channel the merchant offers converts a possible terms breach into an anticipated interaction, and produces a cleaner record of who acted.