An autonomous AI agent holds no rights or obligations of its own. What it does is treated as an act of the company operating it. If the limits of its authority are not in writing, the problem is not what the agent did — it is that whether you are bound becomes arguable.
Companies are handing procurement, supplier correspondence and customer conversations to autonomous agents one process at a time. The debate usually circles the question "can an AI be held liable?". In practice that is the wrong question: the agent holds no rights or obligations of its own. What it does is an act of its operator.
The real gap sits elsewhere. Whether a transaction binds the company turns not on whether the agent "decided", but on whether the company created the appearance of authority towards the counterparty. If your agent writes from your domain, carries your corporate signature block and discusses price, it is entirely reasonable for the counterparty to treat it as authorised.
What these three share is not a limitation of the agent but the fact that the limits of authority are unwritten and undisclosed. The protocol below produces exactly that: what may be done, at what threshold it passes to a human, what the counterparty is told, and how all of it is recorded.
| Basis | Subject | What it means in practice |
|---|---|---|
| AI Act Art. 50(1) | Transparency | Telling the human they are dealing with an AI system |
| AI Act Art. 25 | Deemed provider | Offering a third party's agent under your own brand |
| AI Act Art. 14 | Human oversight | Design requirement for high-risk systems |
| AI Act Art. 12 | Logging | Automatic record-keeping over the system's lifetime |
| GDPR Art. 22 | Automated decisions | Decisions producing legal effects on a person |
| GDPR Art. 32 | Security | Measures appropriate to the risk |
| Contract law | Offer and acceptance | When the exchange forms a contract |
| Agency law | Apparent authority | What the counterparty could reasonably assume |
| Agency law | Ratification | The risk created by late notification |
Contract and agency rules differ by governing law; the position under the law applicable to your agreements must be confirmed. Regulatory provisions reflect the text as at the date this page was prepared.
Complete a separate one for each agent. Copy it or download it as markdown. No sign-up.
# AUTONOMOUS AI AGENT AUTHORISATION AND LIABILITY PROTOCOL
Document code: AIA-AGT-03 · Version 1.0 · Classification: Internal
Effective: ……/……/20…… Review: on every change of authority
ARTICLE 1 — AGENT RECORD
1.1 Agent name / version: [……]
1.2 Operating purpose: [……]
1.3 Technical provider (model / framework): [……]
1.4 Owning function and responsible person: [……]
1.5 Channel of contact with counterparties: [……]
1.6 Counterparty may itself be an agent: ( ) Yes ( ) No ( ) Unknown
1.7 Output used within the EU: ( ) Yes ( ) No
ARTICLE 2 — LIMITS OF AUTHORITY
2.1 The agent is authorised only for the EXPRESSLY LISTED transactions:
2.1.A [transaction] — cap [……] — condition [……]
2.1.B [transaction] — cap [……] — condition [……]
2.1.C [transaction] — cap [……] — condition [……]
2.2 ABSOLUTE PROHIBITIONS — the agent may never:
2.2.A Execute a binding contract or give final acceptance,
2.2.B Depart from the approved range on price, delivery time or
limitation of liability,
2.2.C Issue payment instructions or change payment details,
2.2.D Disclose information covered by an NDA,
2.2.E Alter its own authority or delegate it to another agent.
2.3 On threshold breach the transaction halts and passes to human approval
(Art. 4). The agent may not assess its own breach; the cap is enforced
technically.
ARTICLE 3 — LEGAL FRAMEWORK OF REPRESENTATION
3.1 The agent is not a bearer of rights and obligations; its transaction is
an act of the company operating it.
3.2 What matters is not whether the agent "decided" but whether the company
created the APPEARANCE OF AUTHORITY. Failing to communicate the limits
can result in the company being bound.
3.3 Engaged: AI Act Art. 50(1), Art. 25, Art. 14, Art. 12; GDPR Art. 22,
Art. 32; and the contract/agency rules of the applicable law.
ARTICLE 4 — HUMAN APPROVAL THRESHOLDS
4.1 The transaction is suspended and passed to an authorised person where:
4.1.A The value exceeds [AMOUNT],
4.1.B The counterparty is a first-time counterparty,
4.1.C A change to the standard contract text is requested,
4.1.D The agent produced output below its confidence threshold,
4.1.E The transaction requires processing personal data,
4.1.F The counterparty is understood to be an autonomous agent.
4.2 Approval is given by a person who has SEEN the substance. Bulk approval
without reviewing content is not human oversight.
4.3 Approver, date and reasoning are entered in the ANNEX 2 log.
ARTICLE 5 — DISCLOSURE TO THE COUNTERPARTY
5.1 Disclosure is made AT THE FIRST INTERACTION.
5.2 Standard text:
"This conversation is conducted on behalf of [COMPANY] by an autonomous
AI assistant. Its authority is limited to [SCOPE] and it cannot
conclude a binding contract. Final approval is given by [FUNCTION]."
5.3 This satisfies the transparency obligation and puts the counterparty on
notice of the limits, reducing the risk in 3.2. Disclosure is recorded.
ARTICLE 6 — LOGGING AND TRACEABILITY
6.1 Per transaction: timestamp, counterparty identity, input and output,
version of authority applied, threshold/approval records, model version.
6.2 Retention [PERIOD], set against the limitation period for claims.
6.3 Logs are kept in a form that cannot be altered after the fact.
ARTICLE 7 — ERROR AND ROLLBACK
7.1 Where the agent acted outside authority or in error:
1) The relevant authority is suspended IMMEDIATELY,
2) The counterparty is notified without delay,
3) Legal reversibility is assessed,
4) The event is entered in the ANNEX 3 log,
5) Limits and thresholds are reviewed.
7.2 Late notification risks the transaction being treated as tacitly
ratified. Notification deadline: [PERIOD].
ARTICLE 8 — SUPPLIER AND COUNTERPARTY
8.1 Supplier agreement: notice of model changes, liability for error,
access to logs, whether inputs are used for training.
8.2 Offering a third party's agent UNDER YOUR OWN BRAND may make you a
deemed provider under Art. 25.
8.3 Where the counterparty is also an agent, agree expressly when the
exchange becomes a binding declaration of intent.
ARTICLE 9 — ENTRY INTO FORCE
9.1 In force from [DATE].
9.2 Re-approved whenever the agent's authority is widened.
SIGNATURE: Prepared (Technical) / Reviewed (Legal) / Approved (Management)
ANNEXES: 1 Authority Matrix · 2 Human Approval Log · 3 Error and Rollback
This template is general in nature and does not constitute legal advice.
The agent holds no rights or obligations of its own; its transaction is an act of the company operating it. Whether liability is shared with the supplier depends on your agreement and on whether you offer the agent under your own brand — the latter engages Art. 25.
What matters is whether the company created the appearance of authority. Where the limits were never communicated, the conclusion may well be that you are bound. Hence the limits must both exist in writing and be disclosed.
There is no specific regime; the outcome falls under general contract law. Agree expressly, in the framework agreement, at which point the exchange becomes a binding declaration of intent.
Art. 50(1) requires it for systems interacting directly with people, at the latest at the first interaction. The same disclosure also serves to communicate the limits of authority.
The aim is not to gate every transaction but to set thresholds. The protocol leaves routine transactions with the agent and escalates only monetary caps, first-time counterparties, changes to contract text and similar cases.
In a twenty-minute preliminary call we look at what your agent actually does and work out the authority matrix and approval thresholds. If you're out of scope, we tell you that clearly too.
Reserve your spot for an online call The call is online · the protocol is yours either way