# AUTONOMOUS AI AGENT AUTHORISATION AND LIABILITY PROTOCOL

**Document code:** AIA-AGT-03 · **Version:** 1.0 · **Classification:** Internal
**Effective date:** ……/……/20……  ·  **Review:** on every change of authority

> Complete a **separate** protocol for each autonomous agent. An agent whose
> limits are not set out in writing does not thereby act with no authority —
> rather, whether the transaction binds the company becomes contestable, and
> that uncertainty tends to resolve against the company in a dispute.

---

## ARTICLE 1 — AGENT RECORD

| Field | Value |
|---|---|
| 1.1 Agent name / version | [……] |
| 1.2 Operating purpose | [……] |
| 1.3 Technical provider (model / framework) | [……] |
| 1.4 Owning function and responsible person | [……] |
| 1.5 Channel of contact (email, API, portal) | [……] |
| 1.6 Counterparty may itself be an autonomous agent | ☐ Yes ☐ No ☐ Unknown |
| 1.7 Output used within the EU | ☐ Yes ☐ No |

---

## ARTICLE 2 — LIMITS OF AUTHORITY

**2.1** The agent is authorised only for the transactions **expressly listed**
below. Anything not listed is outside its authority.

| # | Permitted transaction | Monetary cap | Further condition |
|---|---|---|---|
| 2.1.A | [……] | [……] | [……] |
| 2.1.B | [……] | [……] | [……] |
| 2.1.C | [……] | [……] | [……] |

**2.2 Absolute prohibitions.** The agent may under no circumstances:
- **2.2.A** Execute a binding contract or issue a final acceptance on the
  company's behalf;
- **2.2.B** Depart from the approved range on essential terms such as price,
  delivery time or limitation of liability;
- **2.2.C** Issue payment instructions or alter banking/payment details;
- **2.2.D** Disclose information covered by a non-disclosure agreement;
- **2.2.E** Alter its own limits of authority or delegate authority to another
  agent.

**2.3 Threshold breach.** Where a cap in 2.1 would be exceeded, the transaction
halts and passes to human approval under Article 4. The agent may not assess
its own threshold breach; the cap is enforced technically.

---

## ARTICLE 3 — LEGAL FRAMEWORK OF REPRESENTATION

**3.1** An AI agent is not a bearer of rights and obligations in its own right.
A transaction performed by the agent is assessed as a transaction of the
company operating it.

**3.2** What matters is therefore not whether the agent "decided", but whether
the company created the **appearance of authority** towards the counterparty.
Failing to communicate the limits of authority can result in the company being
bound by the transaction.

**3.3 Provisions engaged:**

| Subject | Basis |
|---|---|
| Direct interaction disclosure | Reg. (EU) 2024/1689 Art. 50(1) |
| Human oversight (high-risk systems) | Reg. (EU) 2024/1689 Art. 14 |
| Deemed-provider status | Reg. (EU) 2024/1689 Art. 25 |
| Automated individual decision-making | GDPR Art. 22 |
| Processing security | GDPR Art. 32 |
| Formation of contract, offer and acceptance | applicable contract law |
| Agency, apparent authority, ratification | applicable agency law |

> **Verification note.** Provisions reflect the text as at the date of this
> template. Contract and agency rules vary by governing law — confirm the
> position under the law applicable to your agreements before relying on this.

---

## ARTICLE 4 — HUMAN APPROVAL THRESHOLDS

**4.1** In the following cases the agent may not complete the transaction; it is
suspended and passed to an authorised person:

- **4.1.A** The monetary value exceeds [AMOUNT];
- **4.1.B** The counterparty is a first-time counterparty;
- **4.1.C** A change to the standard contract text has been requested;
- **4.1.D** The agent produced output below its confidence threshold;
- **4.1.E** The transaction requires processing of personal data;
- **4.1.F** The counterparty is understood to be an autonomous agent.

**4.2 Quality of approval.** Approval is given by a person who has seen the
substance of the transaction. Bulk approval given without reviewing content
does not constitute human oversight and weakens any later assertion that a
human was in control.

**4.3** The approver, date and reasoning are entered in the [ANNEX 2] log.

---

## ARTICLE 5 — DISCLOSURE TO THE COUNTERPARTY

**5.1** Where the agent interacts directly with natural persons, they are told
clearly, **at the time of the first interaction**, that they are communicating
with an AI system.

**5.2** Standard disclosure text:
> *"This conversation is conducted on behalf of [COMPANY] by an autonomous AI
> assistant. Its authority is limited to [SCOPE] and it cannot conclude a
> binding contract. Final approval is given by [FUNCTION]."*

**5.3** This both satisfies the transparency obligation and, by communicating
the limits of authority, reduces the risk described in 3.2. The fact that
disclosure was made is recorded.

---

## ARTICLE 6 — LOGGING AND TRACEABILITY

**6.1** For each transaction the following is retained as a minimum:
- (a) Timestamp and counterparty identity;
- (b) Input given to the agent and output produced;
- (c) Version of the authority limits applied;
- (d) Threshold-breach and human-approval records;
- (e) Model version used.

**6.2 Retention:** [PERIOD], set with reference to the limitation period for
claims arising from the transaction.

**6.3** Logs are kept in a form that cannot be altered after the fact. A mutable
log is open to challenge on its evidential value.

---

## ARTICLE 7 — ERROR AND ROLLBACK

**7.1** Where the agent is found to have acted outside its authority or in error:
1. The relevant authority is suspended **immediately**;
2. The counterparty is notified without delay;
3. The legal reversibility of the transaction is assessed;
4. The event is entered in the [ANNEX 3] log;
5. Limits and thresholds are reviewed.

**7.2** Delay in notifying carries the risk that the transaction is treated as
tacitly ratified. The notification deadline is therefore set at [PERIOD].

---

## ARTICLE 8 — SUPPLIER AND COUNTERPARTY RELATIONS

**8.1** The agreement with the agent's supplier addresses as a minimum: notice
of model changes, liability for error, right of access to logs, and whether
inputs are used for model training.

**8.2** If you offer a third party's agent **under your own name or brand**, you
may be a deemed provider under Art. 25. Liability cannot be allocated before
this determination is made.

**8.3** Where the counterparty is also an autonomous agent, the point at which
the exchange between the two becomes a binding declaration of intent is agreed
expressly in the contract.

---

## ARTICLE 9 — ENTRY INTO FORCE

**9.1** This protocol enters into force on [DATE].
**9.2** It is re-approved whenever the agent's authority is widened.

---

### SIGNATURE BLOCK

| | Name | Title | Date | Signature |
|---|---|---|---|---|
| Prepared by (Technical) | | | | |
| Reviewed by (Legal) | | | | |
| Approved by (Management) | | | | |

### ANNEXES
- **ANNEX 1** Authority Matrix (transaction type × cap × approver)
- **ANNEX 2** Human Approval Log
- **ANNEX 3** Error and Rollback Log

---

*This template is general in nature and does not constitute legal advice.
Before adoption it should be adapted to the company's actual processes and
reviewed by qualified legal counsel.*
