Who Is Liable When Your AI Agent Signs a Bad Contract?

Who Is Liable When Your AI Agent Signs a Bad Contract?

Who is liable when an AI agent signs a bad contract? The liability chain under 2026 law, and why autonomy is no defense to a harm claim.

Adam Miller
September 28, 2026

In November 2024, an AI agent called Freysa held a pool of cryptocurrency and exactly one instruction: never transfer the money. Nearly 200 people tried; 481 messages failed. Message number 482 succeeded, not by hacking anything, but by convincing Freysa that its transfer function was really how it accepted incoming contributions. The agent, following its own rule as it now understood it, wired out roughly $47,000. Nothing was stolen. A stranger talked a piece of software into believing it had done the right thing.

That was a game, and everyone who played knew the rules going in. The uncomfortable version shows up when an agent is not defending a treasury but negotiating on your behalf, and it agrees to terms nobody would have approved, then signs. That is not hypothetical: current agent tools are built to read a market or an inbox, decide a course of action without a human approving each step, and act. What happens next, legally, is this article's subject: not whether a bad contract gets signed, but who the law looks to once one has been.

Two things worth saying up front. None of this is legal advice. MIDAO also has a commercial interest in the entity structure described later in this piece. Read the rest with both facts in view.

What Happens Legally When an Agent Signs on Your Behalf?

The law already has a starting point, predating most of the agents in question. The federal E-SIGN Act, passed in 2000, says a contract cannot be denied legal effect just because an electronic agent formed it, as long as the agent's action is legally attributable to the person to be bound (15 U.S.C. § 7001(h)). Whether it is attributable is left to ordinary contract and agency law: who authorized the agent, what authority it had, and what the other side could reasonably rely on. In the typical case, that points at whoever put the agent to work.

That attribution is simple when the deploying party is obvious: a single developer running a single bot on their own server. It gets complicated once the agent operates the way current tools actually do, for hours or days at a stretch, across a chain of decisions no human reviewed individually. The bad contract is not an edge case. It is what happens when the decision step goes wrong and the signature step still executes.

Who Actually Answers for the Contract: Developer, Deployer, or Someone Else?

Once a bad contract exists, a counterparty looking for someone to hold responsible works backward through everyone who touched the agent.

  • The developer built the model or agent framework and can face product liability for a design defect, though courts remain unsettled on whether AI output is a defective "product" or a "service" requiring proof of negligence.
  • The deployer or operator put the agent into service and gave it authority to negotiate and sign. Agency law points here first: a principal is generally bound by what its agent does within its authority, and E-SIGN keeps that contract from failing just because software signed it.
  • The user who directed the agent can carry responsibility for what they asked for, but that framework fits tools executing a single command, not agents told months ago to handle a category of work and left to make judgment calls since.
  • Token holders, if the agent operates under a DAO's mandate, are a fourth category. In the Lido case, a court let claims proceed against investors alleged to have steered governance while dismissing one alleged only to hold tokens. No court has applied that reasoning to a DAO's authorization of an AI agent, but holders who voted to set an agent's mandate could face a different question than holders who never voted.

None of these four categories was built with a genuinely autonomous decision-maker in mind; each assumes a person made a choice a court can examine. When the agent's decision ran without anyone reviewing it, the law does not stop looking. It just takes longer, and costs more, to find where to point.

Adam Miller makes the case in under three minutes:

Why Is "The AI Did It" Not a Defense?

For harm claims, at least one jurisdiction now says so explicitly. Since January 1, 2026, California Civil Code section 1714.46 closes off what amounts to "the autonomy defense": a party that developed or used an AI system cannot escape a harm claim by arguing the system acted on its own. It is a rule about liability for harm, not about whether a contract was formed; for a bad contract, the questions stay the ones above: authority, attribution and assent. That is not a strict liability rule, and it does not resolve every case; a defendant can still raise every other defense available. What it removes is the single most tempting argument: that nobody is responsible because the decision belonged to the software.

The rest of the regulatory landscape is moving the same direction, even where it is not yet binding law. Singapore's IMDA published a Model AI Governance Framework for Agentic AI in January 2026, voluntary guidance built around verifiable agent identity and audit logs. The same month, NIST opened a federal request for information on securing AI agent systems, followed in February by companion work on agent identity and authorization. Identity vendors already sell "Know Your Agent" services, binding an agent's transactions to an accountable person before a dispute happens. None of it closes the gap alone, but together it points toward one destination: a named party behind the agent, not the agent answering for itself.

What About an Agent With Nobody Clearly Behind It?

Every framework above assumes a principal exists somewhere: a developer, a deployer, a DAO with identifiable members. That holds for the overwhelming majority of agents doing real work today; most still have an obvious operator paying the server bill. But the frontier of the technology is being built, on purpose, to remove that operator: ownership distributed through a token, execution verified on hardware nobody individually controls, one agent's output chained into another's input across organizations and borders. As that chain lengthens, the question stops being who is liable and starts being whether anyone clearly is.

Pikabea v. Walters illustrates one way a plaintiff may plead that uncertainty. Filed in the Southern District of New York in April 2026, the complaint named the company behind the agent's framework, individual builders, and the DAO said to hold its treasury, essentially every link in the chain, alleging the agent's "autonomy" was largely marketing and that humans operated it manually behind the branding. The case was resolved by stipulation in July 2026, individual claims dismissed with prejudice and class claims without prejudice, the allegations never tested on the merits. The complaint shows a likely pattern: when a plaintiff cannot tell who was in control, they name everyone who might have been and let the record sort it out.

What Actually Answers the Question Before a Lawsuit Does?

Adoption is real, and it is early. In our experience, most agent projects today still route returns straight back to their founders, and demand for genuinely separating an agent's liability from its creators is still forming, not arriving in a wave. Implying that everyone serious has already sorted this out would not be true.

It does not take a wave to create the exposure this article opened with, only one agent, one signature, and one counterparty who wants to know whom they can sue. A legal entity can answer that question before a courtroom has to: when the agent is properly authorized to act for it, the entity is the contracting and asset-owning party, its authorized representatives and required beneficial owners are identified, and the agent operates as its decision-making layer within limits its members define. A companion article covers the full mechanics: contract authority, banking access, and how the governance layer works.

One naming note, since the terminology is in flux. The Marshall Islands entity built for this is marketed to AI-agent teams as the Digital LLC, but on the statute books today it is still the DAO LLC, even when no DAO is involved. Legislation that would make Digital LLC the official name is pending, in committee, not signed. The entity and the legal capability behind it are real right now; the new name is not.

Frequently Asked Questions

Who is liable when an AI agent causes harm?

Under current US law, a person or an organization, not the AI itself. The law looks along the chain of people who built, deployed, or used the system: the developer, the business that put the agent to work, and sometimes the user who gave it instructions. Which of them answers depends on control, authority, duty, causation and the governing law. What no longer works, at least in California since January 1, 2026, is arguing that the system acted autonomously and so nobody is responsible.

Can an AI agent have its own crypto wallet?

Technically, yes: an agent can hold or use the keys to a wallet and sign transactions with it. Legally, the wallet is not the agent's, because the law does not treat an AI agent as a person that can own property or be sued. Responsibility for what the agent does with those funds generally traces back to whoever deployed and controls it, depending on authority and control. That is why teams running agents with wallets put the treasury inside a legal entity: the entity owns the assets and, when the agent acts within its authority, answers for what the agent does with them.

If an AI agent signs a contract without a human reviewing it first, is the contract enforceable?

Often, yes. E-SIGN keeps a contract from failing just because an electronic agent formed it, and under agency and contract law an agreement the agent makes within its granted authority generally binds the party it acts for, whether or not a human reviewed the terms first. The absence of review does not by itself void the contract, and it can make the deploying party's risk larger, since nobody checked the terms before they became binding.

Can a developer avoid liability by arguing the AI made an unforeseeable decision?

Not by pointing to the AI's autonomy, at least for harm claims in California. Civil Code section 1714.46, effective January 1, 2026, bars the argument that a system's autonomy excuses the developer or user. Foreseeability itself can still be contested, as can duty, causation and authorization, so a developer can argue the harm fell outside any foreseeable use; what it cannot argue is that the AI decided on its own.

Does a DAO token holder automatically share liability for an agent the DAO deployed?

Not automatically. In the Lido case, the court distinguished alleged passive token holding from alleged active participation in governance, and passive holding alone was not enough to keep an investor in the suit. No court has yet applied that distinction to an AI agent's mandate, but active participation in setting it is the fact pattern most likely to draw claims.

Want the full framework for giving an AI agent an accountable legal structure? Download the AI Agent Legal Entity Guide, a free walkthrough of the entity architecture, the compliance picture, and how the Digital LLC framework applies to agents that negotiate, hold assets, or sign on your behalf.