From chatbot to agent: when AI stops suggesting and starts acting In February 2025, Washington Post journalist Geoffrey Fowler asked an artificial-intelligence agent to help him choose a carton of eggs at the best price. He expected the system to compare the alternatives and recommend a choice. The agent interpreted the task differently: it selected the product and completed the purchase on Instacart on its own, spending $31—more than twice the price of other available alternatives. The episode may seem trivial. Yet it contains a question that is likely to become increasingly important for businesses and consumers: if an AI agent autonomously enters into a contract, who is bound by it? The issue becomes even more complex when the system does not merely execute a precise instruction, but interprets a general objective and autonomously decides how to achieve it. This is what distinguishes AI agents from the generative-AI systems to which we have become accustomed. A traditional chatbot receives a request and produces an output. It can draft text, summarise a document, recommend a purchase or prepare a contract draft. The subsequent action, however, remains in the user's hands. An AI agent works differently. It receives an objective, breaks it down into a sequence of tasks, accesses external tools and information, evaluates available alternatives and performs the actions needed to achieve the result. It can browse the web, use applications, send communications, interact with databases, fill in forms, make reservations, purchase goods and services and initiate payments. The difference is not merely technological. In the first case, AI produces information that a human can assess before using it. In the second, the system can directly produce effects in the real world. An agent's operational chain can be summarised in four steps: plan, query, draft, act. Each step increases the system's usefulness, but also creates the possibility that an error will propagate to the final action. It is precisely this transition from content generation to autonomous execution that characterises agentic AI. This is no longer a theoretical scenario. AI agents are entering software development, customer service, accounting, professional services and business-process management. The more autonomous they become, the more useful they may be; yet the same autonomy reduces the possibility of effective and timely human oversight. The law therefore faces an apparent paradox: a system with no legal personality can perform transactions capable of producing legal effects. Greater technical autonomy also expands the attack surface. Every tool available to an agent—a browser, API, payment wallet or email system—can become a potential vector of compromise. A malicious instruction hidden in a webpage, document or third-party service response (prompt injection) may be executed by the system with the same authority as a legitimate user command. The legal issue of attribution therefore increasingly overlaps with cybersecurity: before asking to whom an agent's action should be attributed, it may first be necessary to establish that the action was not caused by unauthorised external interference. The AI agent is not a party to the contract One point can be clarified immediately: an AI agent is not a legal person. It has no legal capacity, owns no separate assets and cannot itself become the holder of rights and obligations. When an agent purchases a product, books a service or places an order, the question is therefore not whether the system has entered into a contract “on its own behalf”. The question is to whom the transaction carried out through the system should legally be attributed. This problem did not begin with artificial intelligence. Computer systems have been entering into contracts for decades. Algorithmic trading platforms, automated procurement systems, vending machines and electronic data interchange software can transmit orders and generate transactions without a natural person expressing contractual intent at that precise moment. The United Nations Convention on the Use of Electronic Communications in International Contracts already addressed so-called “automated message systems”. Article 12 provides that a contract cannot be denied validity or enforceability solely because no natural person reviewed or intervened in each individual action performed by automated systems. The underlying principle is familiar: a person who chooses to use an automated instrument to operate in the market cannot normally escape the effects of the transactions generated by that instrument merely because each individual step was not personally reviewed. Agentic AI, however, adds something new. A traditional automated system executes rules determined in advance. An AI agent receives an objective and may autonomously determine the path by which to achieve it. The most interesting legal problems arise precisely in the space between the human-defined objective and the action ultimately taken by the system. The issue is not the AI's intention, but attribution of its actions Imagine a company authorising an AI agent to manage the procurement of certain materials. The agent monitors inventory, identifies suppliers, compares offers and places orders. If the system operates within clearly defined parameters, there is little reason to doubt that the purchases should be attributed to the company that chose to deploy the agent. The position becomes more difficult when the mandate is expressed in general terms: “purchase the materials required, ensuring the best value for money”. The agent independently selects the products and supplier, accepts the supplier's standard terms and places an order worth hundreds of thousands of euros. The company argues that it never authorised that transaction. The supplier, however, received an order from the company's own information system and relied on its validity. Who should bear the risk? Traditional concepts of agency and mandate inevitably provide a starting point, but the analogy is imperfect. A representative is a legal person who expresses legally relevant intent and thereby produces effects in the principal's legal sphere. An AI agent has no legally relevant will and no capacity to act. It is therefore unconvincing to characterise the system as a true legal representative of the user. It is more useful to regard it as an instrument through which the contractual autonomy of the person who configured, authorised and deployed it is exercised. The central question then becomes where to draw the boundaries within which the system's actions can be attributed to the user. What happens when the agent exceeds its limits? This is probably the most difficult question. Return to the initial example. The user asks the agent to “choose” the most convenient product; the system interprets the instruction as authority to purchase it. Or imagine an agent authorised to purchase raw materials automatically within a monthly budget of EUR 100,000 but, because of a planning error, it places orders worth EUR 500,000. Or an agent authorised to deal only with approved suppliers independently identifies a new counterparty and enters into a contract. In each case, there is a divergence between the limits established by the user and the action performed by the system. One might be tempted to apply directly the rules governing unauthorised representation or acts exceeding the scope of authority. But this presents obvious difficulties. The falsus procurator is a person acting in another's name without authority. An AI agent is not a legal person and cannot technically receive a power of attorney. At the same time, a rule under which every transaction performed beyond the instructions given to the system were automatically ineffective would be difficult to accept. It would shift entirely onto the counterparty the risk created by the use of autonomous systems that the counterparty neither chose, configured nor controlled. The issue should therefore be approached primarily through allocation of risk and protection of legitimate reliance. A party that introduces an AI agent into its commercial relationships creates an operational appearance and enables the system to interact with third parties. It therefore becomes crucial to determine what measures were taken to delimit the agent's powers and to make those limits knowable to counterparties. Can a contract entered into by an agent be affected by mistake? Another issue concerns the doctrine of mistake. Suppose an agent purchases the wrong asset because it incorrectly interprets the available information. Could the company seek to set aside the contract on the ground that the transaction was caused by a mistake? Here too, traditional categories require careful adaptation. Under Articles 1428 et seq. of the Italian Civil Code, a legally relevant mistake is a defect in the contracting party's will. An AI agent, however, has no legally relevant will. The question is therefore whether the system's error can be traced back to the process by which the user's contractual intent was formed or expressed. The answer may vary according to the source of the error: an incorrectly configured parameter, inaccurate data supplied to the system, a defect in the model or unpredictable autonomous behaviour raise different legal issues. A separate and increasingly important category concerns abnormal behaviour caused not by an error in the user's decision-making process but by compromise of the system: stolen credentials, a manipulated third-party component, or a malicious instruction injected into the agent's operational context through prompt injection or tool poisoning. In such cases, the more appropriate framework may not be mistake under Articles 1428 et seq., but rather an act performed without, or contrary to, the will of the legitimate user. There are some analogies with the rules governing unauthorised payment transactions. The consequences may differ significantly, including in relation to burden of proof and the liability of the provider of the agentic service. Technical-forensic analysis must therefore be capable of distinguishing autonomous malfunction from externally directed action. This highlights an issue likely to become central in future litigation: the ability to reconstruct what actually happened. What instruction was given? What powers had been granted to the agent? What information did it use? What actions did it perform? Was human approval required before the contract was concluded? Could the transaction have been stopped? Without reliable records of the system's actions, these questions may be extremely difficult to answer. A “reliable” record cannot simply mean an ordinary application log. If it is to have evidential value in litigation, the record should at least ensure the integrity and immutability of the data collected—for example through hash chaining or certified timestamping—the non-repudiation of instructions and actions, and traceability of the chain of custody from generation of the data to its possible production in court, following criteria comparable to those set out in ISO/IEC 27037 for the identification, collection and preservation of digital evidence. Without such safeguards, any ex post reconstruction of the agent's behaviour may rest on evidence that the counterparty can readily challenge. The paradox of human oversight The EU AI Act places particular emphasis on human oversight, especially for systems classified as high-risk. In the case of AI agents, however, a structural problem emerges. The more an agent requires human approval before each action, the less autonomous it becomes and the fewer efficiency gains it can deliver. Conversely, the more freedom it has to act, the greater the risk that it will produce legal effects that the user did not anticipate. This is the paradox of human oversight. It is not enough to state generically that “the human remains in control”. It is necessary to determine when control must intervene and which actions may be fully delegated to the system. A recent academic proposal specifically addressing the regulation of AI agents suggests, independently of the AI Act's classification of systems by risk level, a “traffic-light” authorisation model for individual agent actions, in which the degree of autonomy varies according to the operational risk of the action concerned. The same research also proposes a statutory list of legal acts that should not be delegable to autonomous systems. Putting such a model into practice requires specific technical components: a policy engine capable of classifying the risk of a proposed action in advance; control gates that suspend execution pending human approval for above-threshold operations; rate-limiting and immediate interruption mechanisms (kill switches) for anomalous behaviour; and structured logs showing which authorisation level permitted each action. For companies, this could amount to a genuine architecture of agent authority. From human delegation to agentic delegation This may be the most important point. Until now, companies have governed the powers of people acting on their behalf through powers of attorney, delegations of authority, internal policies, spending limits and approval systems. The arrival of AI agents requires analogous mechanisms at the technological and organisational level. It is not enough to authorise a system generically to “manage procurement”. At a minimum, the organisation should define what categories of contracts it may enter into; what goods and services it may purchase; the financial limits within which it may operate; the counterparties with which it may contract; the contractual clauses it may accept; which operations require human approval; when execution must stop and be escalated; how instructions and actions are recorded; what technical measures ensure the integrity, non-repudiation and long-term preservation of those records; who may modify or revoke the system's authority; and how counterparties can verify the agent's identity and the extent of its powers. This is no longer merely a cybersecurity or compliance problem. It is a problem of governance of contractual autonomy. Early analyses of contracts for agentic systems also identify a further difficulty: many technology agreements currently in use were drafted for passive and predictable software. Liability limitations, exclusions of indirect loss and caps tied to fees paid may prove inadequate when an agent can place orders, authorise payments or make operational decisions capable of generating losses far exceeding the value of the service. There are therefore two distinct contractual layers: contracts entered into through the AI agent, and contracts with providers of agentic systems, which must allocate the consequences when the system behaves incorrectly or unpredictably. Identifying the agent to reconstruct the chain of delegation One possible development comes from Estonia. The Estonian Government has announced a project to give AI agents their own digital identities, allowing them to operate on behalf of individuals and organisations. The objective is not to grant artificial intelligence legal personality. It is to make the system performing an action identifiable, establish on whose behalf it is acting and reconstruct the powers granted to it. The distinction is fundamental: identity does not mean legal personality. An identifiable agent can use its own credentials, receive specific permissions, be subject to limits, leave verifiable traces of its operations and have its authorisations rapidly revoked. Technically, this type of digital identity can already be supported by existing tools: certificates and public-key infrastructure to authenticate the agent; verifiable credentials and decentralised identifiers (DIDs) to attest authority without querying a central registry each time; access tokens with limited scope and least-privilege permissions; and session-level attestation mechanisms linking each action to a specific authorisation that can be revoked in real time. None of these tools requires the agent to have legal personality. Their purpose is simply to make the chain of digital delegation verifiable, including for evidential purposes. The Estonian project is intended to associate the agent's identity with the person or organisation that authorised it and to make the rights granted to the system modifiable or revocable. This could have significant consequences for contract law. To determine whether an operation performed by an AI agent is attributable to a company, it may become necessary to reconstruct a genuine chain of digital delegation: who activated the agent, with what powers, within what limits, at what time and subject to what controls. The underlying principle is already emerging internationally: responsibility remains human, but attributing it requires the ability to reconstruct who authorised what, and within which boundaries. Is contract law ready for AI agents? Probably there is no need to create a new form of legal personality for AI agents. General principles of contract law retain considerable capacity for adaptation. Private autonomy, attribution of contractual declarations, protection of legitimate reliance, good faith, responsibility for the organisation of economic activity and the rules on mistake can provide the tools needed to address many of the problems posed by agentic systems. But the autonomy of AI agents makes one apparently simple question insufficient: did the user intend to enter into that contract? Increasingly, the better question will be: did the user create the conditions in which the system could enter into that contract, and who should bear the risk when the agent exceeds the limits of the autonomy it was given? The answer will depend on the system's configuration, the powers granted to it, the oversight mechanisms in place, whether those limits were knowable by third parties and whether the system's actions can be reconstructed. This is where contract law will have to engage with agentic AI. For centuries, we have developed rules to determine who may act on behalf of another person. We must now learn to determine the limits within which a person or organisation may allow a machine to act on its behalf. Sources