Skip to main content

Artificial intelligence is rapidly moving from a tool that recommends actions to a system that takes them. Businesses are beginning to deploy AI agents capable of communicating with vendors, requesting quotes, negotiating prices, placing orders, scheduling services, accepting online terms, processing transactions, and responding to commercial communications without waiting for a human employee to approve every step. That development creates an increasingly important legal question: when an AI agent tells another company “we agree,” places an order, accepts contractual terms, or otherwise behaves as though it has authority to act, has the company itself become legally bound?

Please note this blog post should be used for learning and illustrative purposes. It is not a substitute for consultation with an attorney with expertise in this area. If you have questions about a specific legal issue, we always recommend that you consult an attorney to discuss the particulars of your case.

The answer may be yes. The fact that no employee personally clicked “accept,” signed a purchase order, or reviewed the final transaction does not necessarily prevent contract formation. American law has accommodated automated transactions for decades, long before generative AI and modern autonomous agents became commercially practical. At the same time, traditional principles of agency law, particularly apparent authority, create an additional source of risk when a company places a representative—human or technological—in a position where third parties reasonably believe that representative is authorized to act.¹ ²

The difficult legal issue therefore may not be whether an artificial intelligence system itself possesses legal personality or can independently become a contracting party. In most circumstances, it does not. The more consequential question is whether the conduct of the business that deployed the system, together with the electronic transactions generated by that system, is sufficient to bind the business behind it.

The distinction between traditional generative AI and autonomous AI agents is significant. A conventional chatbot may generate a draft email that a human reviews before sending. An autonomous agent may instead receive a broader instruction such as “keep our warehouse stocked,” “schedule maintenance, when necessary,” or “negotiate renewal pricing with our software vendors.” The agent may then independently determine what communications to send, which vendors to contact, what information to request, and what actions are necessary to accomplish the assigned objective.

At that point, the AI is no longer merely producing information. It is participating in the company’s commercial relationships.

Consider a purchasing agent that monitors inventory and automatically orders replacement materials whenever supplies fall below a designated level. Imagine that the agent has access to the company’s purchasing account, communicates from an address associated with the company’s domain, receives vendor quotations, negotiates delivery dates, and issues electronic purchase orders. To the vendor, the communications may look substantially like communications from an authorized employee.

Similar issues arise when an AI agent negotiates professional services, accepts a software provider’s online terms, schedules contractors to perform work at company facilities, renews subscriptions, modifies existing orders, approves change orders, or negotiates pricing with existing vendors. The greater the agent’s operational independence, the more difficult it becomes for the company to characterize the system as merely a passive communication tool.

That does not mean every statement generated by an AI system creates a contract. Ordinary contract principles still matter. There must generally be sufficient objective evidence of agreement, and questions involving offer, acceptance, definiteness, conditions, and other requirements remain relevant. But the absence of contemporaneous human involvement is not, standing alone, a reliable
 defense. ² ³ ⁴

Traditional agency law distinguishes between actual authority and apparent authority. Actual authority generally concerns what authority the principal has granted to an agent. Apparent authority examines a different relationship: what
a third party reasonably understands the agent’s authority to be based on manifestations attributable to the principal. ¹

This distinction becomes critical when companies deploy autonomous AI.

Suppose a company internally programs an AI purchasing agent not to enter transactions exceeding $25,000. That restriction may establish an important internal limit. But imagine that the company allows the AI to communicate directly with vendors using the company’s name, access the company’s procurement system, negotiate commercial terms, place previous orders, and send confirmations that appear indistinguishable from ordinary company purchase orders. A vendor may have no knowledge of the internal $25,000 limitation.

If the AI then accepts a $30,000 transaction, the legal dispute may not end with the company’s assertion that the software exceeded its internal instructions. A court examining apparent authority would ordinarily focus on the manifestations attributable to the company and whether those manifestations reasonably caused the vendor to believe that the actor was authorized. ¹

The Supreme Court has recognized the importance of apparent authority in determining when organizations may be held responsible for the actions of representatives who appear to possess authority even when organizational leadership did not specifically authorize the disputed conduct. In American Society of Mechanical Engineers, Inc. v. Hydrolevel Corp., the Court addressed organizational responsibility for conduct undertaken with apparent authority and emphasized the significance of the principal’s placement of an actor in a position that allows the actor to appear authoritative.⁵ Although that case did not involve artificial intelligence or contract formation, the underlying principle has obvious significance for organizations that intentionally place autonomous systems in outward-facing positions of commercial responsibility.

Apparent authority ordinarily must be traceable to the principal’s manifestations. An actor cannot simply announce, without more, “I represent Company X” and thereby create authority to bind Company X. ¹ The principal must have done something that reasonably contributes to the third party’s understanding that the actor is authorized.

That rule provides both protection and risk in the AI context.

A fraudulent chatbot operating on an unrelated website cannot ordinarily create authority merely by claiming to represent a company. But the analysis may change when the company itself places the AI agent on its website, provides it access to a company email address, connects it to a procurement portal, permits it to communicate through an authenticated vendor account, authorizes it to issue purchase-order numbers, or allows it repeatedly to transact with the same counterparties.

The decision in CSX Transportation, Inc. v. Recovery Express, Inc. illustrates the importance of identifying a manifestation attributable to the alleged principal rather than relying exclusively on the supposed agent’s representations.⁶ In an AI dispute, that inquiry may focus on technological facts that traditional agency cases rarely encountered: Who created the account? Who authenticated the AI? What company systems could it access? What communications did the company send to vendors concerning the agent? How had the system behaved in prior transactions? Did company employees previously honor agreements the system made?

These facts can collectively become the twenty-first-century equivalent of placing an employee behind the purchasing desk with a company title, telephone number, business card, and authority to interact with vendors.

One of the most important misconceptions concerning AI contracting is that the legal system has no framework for transactions conducted by software. In reality, electronic transaction statutes expressly contemplated automated contracting years before today’s AI agents existed.

The Uniform Electronic Transactions Act defines an “electronic agent” broadly enough to encompass a computer program or other automated means used independently to initiate an action or respond to electronic records or performances without human review or action at the relevant time. ² The federal Electronic Signatures in Global and National Commerce Act, commonly known as E-SIGN, similarly defines an electronic agent as a computer program or electronic or automated means used independently to initiate an action or respond to electronic records or performances without contemporaneous review or action by an individual. ³

Most importantly, UETA expressly addresses automated transactions. It provides that a contract may be formed through the interaction of electronic agents even when no individual was aware of or reviewed the agents’ actions or the resulting terms and agreements. ²

That statutory language is remarkably well suited to today’s agentic AI environment despite having been written before modern large language models existed.

The legal significance is substantial. A company disputing an unfavorable automated transaction may naturally argue that no executive, lawyer, purchasing officer, or employee actually reviewed the agreement. UETA demonstrates why that fact alone may not resolve the dispute. Automated transactions are designed precisely to permit electronic systems to act without contemporaneous individual review. ²

E-SIGN reinforces the same general policy at the federal level. Subject to statutory requirements and exceptions, electronic records and electronic signatures cannot be denied legal effect solely because they are electronic. ³ UETA contains comparable provisions at the state level. ²

This matters because an AI agent does not need to reproduce the traditional image of a handwritten signature to create contractual risk. Contract formation frequently depends on objective manifestations of assent rather than ceremonial signatures.

For the sale of goods, for example, UCC Article 2 recognizes that a contract may be made in any manner sufficient to show agreement, including conduct by the parties recognizing the existence of a contract. The agreement may exist even when the precise moment of formation cannot be identified. The UCC also generally permits acceptance by any reasonable manner or medium unless the circumstances or offer provide otherwise.⁴

An AI system that requests a shipment, approves a price, provides delivery information, generates a purchase order, and causes the company’s receiving department to accept the goods therefore creates more than a philosophical question about whether a machine can “intend” to contract. A court may instead examine the objective conduct of the companies participating in the transaction.

Online contract cases already demonstrate how courts analyze assent in technology-mediated transactions. The focus typically rests on notice and objective conduct rather than whether the user subjectively read every contractual term.

In Register.com, Inc. v. Verio, Inc., the Second Circuit examined repeated automated interactions with an online service after the user had received notice of contractual restrictions.⁷ The case is particularly instructive for autonomous systems because software was conducting repeated automated queries. The court did not treat automation as a barrier insulating the user from legal consequences. Continued automated conduct after notice could have contractual significance.

Similarly, Meyer v. Uber Technologies, Inc. demonstrates the importance of reasonably conspicuous notice and an unambiguous manifestation of assent in electronic contracting.⁸ Although the case involved an individual registering through a digital interface rather than an autonomous AI agent, its broader lesson applies directly to agentic transactions. Contract formation in digital environments depends heavily on what terms were presented, how they were presented, and what conduct objectively communicated agreement.

An AI agent that navigates a purchasing website receives conspicuous notice that proceeding constitutes acceptance of terms, and then completes the transaction may therefore create a significantly different risk profile from an agent that receives no meaningful notice of contractual terms.

Companies focusing exclusively on whether their AI can “sign contracts” may be asking too narrow a question. Commercial contracts are often formed through communications and conduct without a formal signature ceremony.

A vendor may send an email stating that it can provide 2,000 units at a specified price with delivery on a particular date. An AI procurement agent may respond, “Approved. Please proceed and invoice us under Purchase Order 45821.” The company may later receive the shipment and use the products.

In that scenario, the legal issue is not simply whether the AI produced a legally recognized electronic signature. The communication itself may constitute acceptance, or the parties’ subsequent conduct may establish an agreement.⁴ The vendor could also argue that the company placed the AI in a position where it reasonably appeared authorized to approve ordinary purchases. ¹

The same problem can arise with service providers. Suppose an AI facilities-management system communicates with an HVAC contractor that has worked with the company for several years. The AI requests repairs, approves an estimate, schedules technicians, provides building-access instructions, and later confirms completion. Even if the company intended the AI merely to coordinate scheduling, its outward conduct may communicate broader authority.

This is why autonomous scheduling, ordering, negotiation, and vendor communication should not be analyzed as separate from contracting authority. In commercial practice, these activities frequently constitute the conduct through which contracts are formed.

Repeated transactions can make the apparent-authority question more difficult for the deploying company.

Imagine an AI agent has placed twenty orders with a particular supplier during the previous year. The company paid every invoice. Employees received every shipment. Nobody told the supplier that the AI lacked contracting authority. The supplier therefore developed a reasonable understanding that orders generated through that channel were authorized company purchases.

If the company disputes order number twenty-one because the AI exceeded an internal budget, the historical pattern becomes significant. The company may argue that the AI violated its internal controls. The supplier may respond that the company’s own prior conduct established the opposite appearance.

Agency law’s focus on manifestations and reasonable belief makes this history relevant. ¹ Commercial law likewise gives considerable importance to the parties’ conduct and recognizes contracts through behavior demonstrating agreement.⁴

Autonomous agents therefore create cumulative legal risk. Every successful automated transaction may become evidence affecting how counterparties reasonably interpret the next transaction.

A company may also face problems if it discovers an unauthorized AI transaction but continues to accept its benefits.

Agency law recognizes the concept of ratification, under which a principal may become bound by previously unauthorized conduct if the principal later affirms the act under circumstances satisfying the applicable legal requirements. ¹ Ratification can occur through express approval, but conduct may also matter.

Suppose an AI agent orders equipment outside its approved authority. Management learns of the transaction when the equipment arrives. Rather than immediately rejecting the shipment and disputing the order, employees install the equipment and use it for three months. If a dispute later arises over payment, the company’s continued acceptance and use may materially weaken the argument that the transaction should be treated as entirely unauthorized.

The practical lesson is that AI-contract governance cannot end when the agent acts. Businesses need escalation procedures for detecting questionable transactions and responding to them promptly. A delayed response may alter the legal landscape.

Generative AI introduces an additional complication because its errors may not resemble traditional software errors.

Conventional automated systems generally execute predetermined logic. A modern AI agent may misunderstand instructions, infer an incorrect business objective, hallucinate a factual premise, misinterpret vendor communications, or pursue a goal using a strategy that management never anticipated.

A company might therefore argue that the AI’s agreement resulted from mistake. Traditional doctrines involving mistake, misrepresentation, impossibility, unconscionability, or other defenses may sometimes apply depending on the circumstances. But there is no general rule that a contract becomes unenforceable simply because software made a poor decision.

UETA does contain provisions addressing certain electronic errors, including limited protections for particular errors occurring in automated transactions. ² Those rules, however, should not be mistaken for a universal right to rescind any unfavorable agreement generated by artificial intelligence.

Michigan’s version of UETA illustrates the distinction. Michigan expressly recognizes contracts formed through interactions of electronic agents even when no individual reviewed the agents’ actions or resulting terms. ¹⁰ Michigan also contains specific rules addressing changes or errors in electronic records, including particular circumstances in which the effect of an erroneous electronic record may be avoided. ¹⁰ The existence of carefully defined error rules reinforces an important point: “our system made an error” does not automatically eliminate contractual consequences.

Contract authority is only part of the risk presented by autonomous systems. AI communications may expose a company to liability even when no contract is ultimately formed.

A notable example comes from Canada. In Moffatt v. Air Canada, the British Columbia Civil Resolution Tribunal considered inaccurate information supplied to a customer through Air Canada’s website chatbot. The tribunal rejected the notion that the company could separate itself from information presented through its own chatbot and held Air Canada responsible for the negligent misrepresentation.⁹

The decision is Canadian and is not binding authority on U.S. courts. It nevertheless provides a useful preview of the practical problem. Businesses generally choose which automated systems to place in front of customers and counterparties. When a company creates a channel that appears to speak for the organization, decision-makers may be skeptical of arguments that the company should have no responsibility for statements delivered through that channel.

The lesson for autonomous contracting is straightforward. A company should assume that counterparties will attribute official-looking AI communications to the business unless the surrounding circumstances clearly indicate otherwise.

Businesses may attempt to solve the problem by adding a disclaimer stating that an AI agent lacks authority to enter contracts. That can be useful because apparent authority depends heavily on what the counterparty reasonably believes. ¹ A clear and conspicuous limitation communicated before a transaction may substantially affect whether reliance on the AI’s purported authority is reasonable.

But a disclaimer can be undermined by inconsistent conduct.

Imagine that every AI-generated email states, “This system has no authority to bind the company,” but the company routinely pays invoices resulting from those emails, accepts goods the AI orders, and allows the AI to negotiate final pricing without human intervention. A court may have to reconcile the disclaimer with the company’s broader behavior.

Authority should therefore be designed into the technological system, not merely described in fine print.

If an AI is authorized only to solicit quotations, the system should ideally be technically incapable of issuing purchase orders. If it can negotiate but cannot accept, acceptance should require an independent human authorization step. If transactions above a particular value require executive approval, the procurement platform should prevent the agent from completing those transactions rather than relying exclusively on a natural-language instruction telling the model not to exceed the limit.

Requiring human approval for every AI-generated message may eliminate much of the operational value of autonomous agents. Effective governance therefore does not necessarily mean eliminating autonomy. It means defining where autonomy stops.

An AI agent may safely possess broad authority to research vendors, request proposals, identify scheduling availability, obtain pricing, compare alternatives, and draft proposed terms while remaining unable to make legally consequential commitments. At a higher level of authority, a business might permit autonomous purchases of standardized goods under existing master agreements within predetermined financial thresholds. Transactions involving new vendors, indemnification obligations, intellectual-property licenses, automatic renewals, limitations of liability, arbitration provisions, exclusivity commitments, material data-processing obligations, or substantial expenditures may require human approval.

The relevant governance principle is consequence-based authority. The system’s ability to take action should correspond to the legal and financial risk associated with that action.

When a human employee signs a contract, the relevant evidence may include emails, negotiation drafts, corporate resolutions, and testimony. AI transactions generate a different evidentiary record.

A future dispute may require reconstruction of the agent’s instructions, system permissions, model version, account credentials, vendor communications, contractual terms presented to the system, previous transactions, approval thresholds, escalation events, and subsequent company conduct.

That information may determine whether the agent possessed actual authority, whether the counterparty reasonably perceived apparent authority, whether electronic records are attributable to the company, whether an error occurred, and whether the company later ratified the transaction. ¹ ²

Businesses deploying autonomous agents should therefore treat logging and auditability as components of contract governance rather than merely technical administration. A company that cannot reconstruct why an agent acted may face substantial difficulty proving that the transaction exceeded the authority communicated to the outside world.

The problem runs in both directions. Companies receiving communications from autonomous agents must decide when reliance is reasonable.

A vendor receiving a million-dollar purchase request from an unfamiliar chatbot should not necessarily assume that the system has unrestricted authority simply because it uses a company’s name. By contrast, a vendor receiving routine replenishment orders through the same authenticated procurement channel the customer has used for two years may have a much stronger basis for believing the order is authorized.

Commercial agreements can reduce uncertainty by defining which electronic channels are authorized, what types of automated communications may create obligations, what transaction limits apply, when human approval is required, what authentication procedures must be used, and how errors are reported. Such provisions can transform uncertain questions of apparent authority into express contractual rules governing automated interactions.

This may become particularly important as companies deploy AI agents that negotiate directly with other companies’ AI agents. UETA already contemplates contracts formed by interactions between electronic agents. ² Businesses therefore should expect “machine-to-machine” contracting to become a governance issue rather than treating it as a speculative future problem.

The most useful way to manage autonomous agents may be to think of each system as operating within an authority envelope. That envelope defines not merely what employees intend the AI to do, but what the AI can technically do and what outsiders are told it can do.

Those three concepts should align.

If internal policy says that an agent cannot purchase goods exceeding $10,000, the procurement platform should enforce the same limit, and vendors interacting with the system should receive consistent information concerning the scope of its authority. If the system can communicate only proposed terms, its communications should be labeled and structured accordingly. If transactions require human confirmation, the workflow should create an identifiable approval event before the commitment is transmitted.

The danger arises when internal policy, technological capability, and external appearance diverge. A company may believe it has created a narrow AI assistant while providing the system with credentials, communications channels, and transactional powers that make it look like a fully empowered company representative.

Apparent authority has always been concerned with appearances created by the principal.¹ Autonomous AI makes those appearances programmable.

The debate over whether an AI agent can “enter into a contract” can therefore be misleading. The AI is not ordinarily the commercial principal. The business deploying it is.

The real issue is delegation.

Companies have always delegated authority to employees, purchasing departments, brokers, sales representatives, contractors, and other intermediaries. The law developed doctrines of actual authority, apparent authority, estoppel, and ratification because internal authority and external appearances do not always match. ¹

AI changes the mechanism of delegation, but it does not eliminate the underlying problem. In fact, autonomous software may magnify it. A human employee normally handles a limited number of transactions during working hours. An AI agent may communicate simultaneously with hundreds of counterparties, generate commitments in seconds, and repeat an erroneous interpretation across an entire vendor network before management becomes aware of what happened.

The speed and scale of autonomous action make advanced governance more important, not less important.

An AI agent does not need to become a legal person before it can create legally significant consequences for the company that deploys it. Existing electronic-transactions law already recognizes automated contracting mechanisms, including transactions formed without contemporaneous human review. ² ³ Traditional contract law recognizes agreements manifested through electronic communications and conduct.⁴ Agency law adds another layer of exposure when a company creates circumstances in which a third party reasonably believes that a representative has authority to act on the company’s behalf. ¹ ⁵

The practical question for businesses is therefore no longer simply whether employees are permitted to use artificial intelligence. It is whether particular AI systems are being given access to the tools of corporate authority.

A system that can send messages is one thing. A system that can negotiate prices, access authenticated vendor accounts, issue purchase orders, accept terms, schedule performance, authorize payments, and repeatedly transact in the company’s name is something very different.

Businesses deploying those capabilities should identify the agent’s authority before deployment, enforce that authority technologically, communicate material limitations to counterparties, preserve transaction records, monitor automated commitments, and create prompt procedures for rejecting unauthorized transactions. The more autonomy a company gives its AI, the more carefully it should define the legal boundaries surrounding that autonomy.

The key principle is simple: a company may not be able to avoid a contract merely by explaining afterward that the computer was not supposed to make it. When the company gives an AI agent the credentials, access, history, and outward appearance of authority, the law may ultimately focus less on what the company privately intended and more on what the company allowed the world reasonably to believe.

Contact Tishkoff

Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).

Footnoted Sources:

1- American Law Institute, Restatement (Third) of Agency §§ 1.01, 2.01, 2.03, 3.01, 3.03, and 4.01 (2006). https://www.fiduciarylawblog.com/wp-content/uploads/2014/11/Restatement-101.pdf

2- Uniform Law Commission, Uniform Electronic Transactions Act §§ 2, 5, 7, 9, 10, and 14 (1999). https://www.uniformlaws.org/committees/community-home?CommunityKey=2c04b76c-2b7d-4399-977e-d5876ba7e034

3- Electronic Signatures in Global and National Commerce Act, 15 U.S.C. §§ 7001 and 7006. https://uscode.house.gov/view.xhtml?path=/prelim@title15/chapter96&edition=prelim

4- Uniform Commercial Code §§ 1-103, 2-204, 2-206, and 2-207. https://www.uniformlaws.org/acts/ucc

5- American Society of Mechanical Engineers, Inc. v. Hydrolevel Corp., 456 U.S. 556 (1982). https://www.oyez.org/cases/1981/80-1765

6- CSX Transportation, Inc. v. Recovery Express, Inc., 415 F. Supp. 2d 6 (D. Mass. 2006).  https://www.casemine.com/judgement/us/5914b595add7b04934773903

7- Register.com, Inc. v. Verio, Inc., 356 F.3d 393 (2d Cir. 2004). https://www.casebriefs.com/blog/law/contracts/contracts-keyed-to-fuller/acceptance-contracts-keyed-to-fuller/register-com-inc-v-verio-inc/

8- Meyer v. Uber Technologies, Inc., 868 F.3d 66 (2d Cir. 2017). https://law.justia.com/cases/federal/appellate-courts/ca2/16-2750/16-2750-2017-08-17.html

9- Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal 2024). https://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot

10- Michigan Uniform Electronic Transactions Act, Mich. Comp. Laws §§ 450.832, 450.839, 450.840, and 450.844.
https://law.justia.com/codes/michigan/chapter-450/statute-act-305-of-2000/


This article is intended for general informational purposes and does not constitute legal advice. The application of agency, contract, electronic-transactions, and other laws depends on the governing jurisdiction and the particular circumstances of each transaction.