TREN
Guide · Autonomous agents

Your agent is negotiating. Who is treated as having signed?

An autonomous AI agent holds no rights or obligations of its own. What it does is treated as an act of the company operating it. If the limits of its authority are not in writing, the problem is not what the agent did — it is that whether you are bound becomes arguable.

Autonomous AI agents and contract liability
Download the authorisation protocol Reserve your spot for an online call
§ 01 — Where the gap actually is

The gap isn't in the agent. It's in the authority document.

Companies are handing procurement, supplier correspondence and customer conversations to autonomous agents one process at a time. The debate usually circles the question "can an AI be held liable?". In practice that is the wrong question: the agent holds no rights or obligations of its own. What it does is an act of its operator.

The real gap sits elsewhere. Whether a transaction binds the company turns not on whether the agent "decided", but on whether the company created the appearance of authority towards the counterparty. If your agent writes from your domain, carries your corporate signature block and discusses price, it is entirely reasonable for the counterparty to treat it as authorised.

Three typical scenarios

The fix is documentary, not technical

What these three share is not a limitation of the agent but the fact that the limits of authority are unwritten and undisclosed. The protocol below produces exactly that: what may be done, at what threshold it passes to a human, what the counterparty is told, and how all of it is recorded.

§ 02 — Legal basis

What is engaged.

BasisSubjectWhat it means in practice
AI Act Art. 50(1)TransparencyTelling the human they are dealing with an AI system
AI Act Art. 25Deemed providerOffering a third party's agent under your own brand
AI Act Art. 14Human oversightDesign requirement for high-risk systems
AI Act Art. 12LoggingAutomatic record-keeping over the system's lifetime
GDPR Art. 22Automated decisionsDecisions producing legal effects on a person
GDPR Art. 32SecurityMeasures appropriate to the risk
Contract lawOffer and acceptanceWhen the exchange forms a contract
Agency lawApparent authorityWhat the counterparty could reasonably assume
Agency lawRatificationThe risk created by late notification

Contract and agency rules differ by governing law; the position under the law applicable to your agreements must be confirmed. Regulatory provisions reflect the text as at the date this page was prepared.

§ 03 — Template

Agent authorisation protocol — blank template.

Complete a separate one for each agent. Copy it or download it as markdown. No sign-up.

AIA-AGT-03 · Version 1.0 · Free Download .md ↓
# AUTONOMOUS AI AGENT AUTHORISATION AND LIABILITY PROTOCOL

Document code: AIA-AGT-03 · Version 1.0 · Classification: Internal
Effective: ……/……/20……   Review: on every change of authority

ARTICLE 1 — AGENT RECORD
1.1 Agent name / version: [……]
1.2 Operating purpose: [……]
1.3 Technical provider (model / framework): [……]
1.4 Owning function and responsible person: [……]
1.5 Channel of contact with counterparties: [……]
1.6 Counterparty may itself be an agent: ( ) Yes ( ) No ( ) Unknown
1.7 Output used within the EU: ( ) Yes ( ) No

ARTICLE 2 — LIMITS OF AUTHORITY
2.1 The agent is authorised only for the EXPRESSLY LISTED transactions:
    2.1.A [transaction] — cap [……] — condition [……]
    2.1.B [transaction] — cap [……] — condition [……]
    2.1.C [transaction] — cap [……] — condition [……]
2.2 ABSOLUTE PROHIBITIONS — the agent may never:
    2.2.A Execute a binding contract or give final acceptance,
    2.2.B Depart from the approved range on price, delivery time or
          limitation of liability,
    2.2.C Issue payment instructions or change payment details,
    2.2.D Disclose information covered by an NDA,
    2.2.E Alter its own authority or delegate it to another agent.
2.3 On threshold breach the transaction halts and passes to human approval
    (Art. 4). The agent may not assess its own breach; the cap is enforced
    technically.

ARTICLE 3 — LEGAL FRAMEWORK OF REPRESENTATION
3.1 The agent is not a bearer of rights and obligations; its transaction is
    an act of the company operating it.
3.2 What matters is not whether the agent "decided" but whether the company
    created the APPEARANCE OF AUTHORITY. Failing to communicate the limits
    can result in the company being bound.
3.3 Engaged: AI Act Art. 50(1), Art. 25, Art. 14, Art. 12; GDPR Art. 22,
    Art. 32; and the contract/agency rules of the applicable law.

ARTICLE 4 — HUMAN APPROVAL THRESHOLDS
4.1 The transaction is suspended and passed to an authorised person where:
    4.1.A The value exceeds [AMOUNT],
    4.1.B The counterparty is a first-time counterparty,
    4.1.C A change to the standard contract text is requested,
    4.1.D The agent produced output below its confidence threshold,
    4.1.E The transaction requires processing personal data,
    4.1.F The counterparty is understood to be an autonomous agent.
4.2 Approval is given by a person who has SEEN the substance. Bulk approval
    without reviewing content is not human oversight.
4.3 Approver, date and reasoning are entered in the ANNEX 2 log.

ARTICLE 5 — DISCLOSURE TO THE COUNTERPARTY
5.1 Disclosure is made AT THE FIRST INTERACTION.
5.2 Standard text:
    "This conversation is conducted on behalf of [COMPANY] by an autonomous
     AI assistant. Its authority is limited to [SCOPE] and it cannot
     conclude a binding contract. Final approval is given by [FUNCTION]."
5.3 This satisfies the transparency obligation and puts the counterparty on
    notice of the limits, reducing the risk in 3.2. Disclosure is recorded.

ARTICLE 6 — LOGGING AND TRACEABILITY
6.1 Per transaction: timestamp, counterparty identity, input and output,
    version of authority applied, threshold/approval records, model version.
6.2 Retention [PERIOD], set against the limitation period for claims.
6.3 Logs are kept in a form that cannot be altered after the fact.

ARTICLE 7 — ERROR AND ROLLBACK
7.1 Where the agent acted outside authority or in error:
    1) The relevant authority is suspended IMMEDIATELY,
    2) The counterparty is notified without delay,
    3) Legal reversibility is assessed,
    4) The event is entered in the ANNEX 3 log,
    5) Limits and thresholds are reviewed.
7.2 Late notification risks the transaction being treated as tacitly
    ratified. Notification deadline: [PERIOD].

ARTICLE 8 — SUPPLIER AND COUNTERPARTY
8.1 Supplier agreement: notice of model changes, liability for error,
    access to logs, whether inputs are used for training.
8.2 Offering a third party's agent UNDER YOUR OWN BRAND may make you a
    deemed provider under Art. 25.
8.3 Where the counterparty is also an agent, agree expressly when the
    exchange becomes a binding declaration of intent.

ARTICLE 9 — ENTRY INTO FORCE
9.1 In force from [DATE].
9.2 Re-approved whenever the agent's authority is widened.

SIGNATURE: Prepared (Technical) / Reviewed (Legal) / Approved (Management)
ANNEXES: 1 Authority Matrix · 2 Human Approval Log · 3 Error and Rollback

This template is general in nature and does not constitute legal advice.
§ 04 — Filling it in

The three places that matter most.

  1. Article 2.1 — the authority matrix. Broad wording like "general procurement correspondence" does no work; in a dispute the counterparty gets to interpret its scope. Write out the triple of transaction type, monetary cap and approver, one line at a time.
  2. Article 5 — disclosure. This clause does two jobs: it meets the transparency obligation and puts the counterparty on notice of the limits. Skip the second and the risk in 3.2 stays exactly where it was.
  3. Article 7.2 — the notification deadline. When setting it, keep the gap between "spotted" and "notified" in view. In practice this is the most argued point: whether the delay amounts to tacit ratification.
Note This protocol is a general framework and is not designed to be adopted as-is. The authority matrix, the approval thresholds and the liability split in your supplier agreement change with your business model, and agency rules differ under the law governing your contracts. You can book a preliminary call to adapt the protocol to your processes and review your existing supplier agreements on this point.
§ 05 — Frequently asked

Questions.

Who is liable for a faulty transaction by an autonomous agent?

The agent holds no rights or obligations of its own; its transaction is an act of the company operating it. Whether liability is shared with the supplier depends on your agreement and on whether you offer the agent under your own brand — the latter engages Art. 25.

Does a contract concluded by the agent bind us?

What matters is whether the company created the appearance of authority. Where the limits were never communicated, the conclusion may well be that you are bound. Hence the limits must both exist in writing and be disclosed.

What if two agents negotiate with each other?

There is no specific regime; the outcome falls under general contract law. Agree expressly, in the framework agreement, at which point the exchange becomes a binding declaration of intent.

Must we disclose that the agent is an AI?

Art. 50(1) requires it for systems interacting directly with people, at the latest at the first interaction. The same disclosure also serves to communicate the limits of authority.

Doesn't adding human approval defeat autonomy?

The aim is not to gate every transaction but to set thresholds. The protocol leaves routine transactions with the agent and escalates only monetary caps, first-time counterparties, changes to contract text and similar cases.

Related

Read next.

Let's set your agent's limits together.

In a twenty-minute preliminary call we look at what your agent actually does and work out the authority matrix and approval thresholds. If you're out of scope, we tell you that clearly too.

Reserve your spot for an online call The call is online · the protocol is yours either way