AI trading agents are already moving money and executing orders without a human clicking “confirm.” That raises a pressing legal question: when an autonomous agent makes a losing trade, who is on the hook? Edwin Mata, lawyer and CEO of tokenization platform Brickken, argues the answer is straightforward — liability should track the authority granted to the software, not be assigned to the AI itself. No neat legal answer yet A Sandmark investigation on Aug. 6 found existing law offers no single, tidy rule for losses caused by autonomous financial agents. Courts will likely weigh contract law, negligence standards, product liability and fiduciary duties case-by-case, focusing on who controlled the agent and why the loss happened. If an agent acted within an authorized strategy, the principal who delegated it may bear the loss. If the agent went beyond its remit because of flawed design, weak safeguards, or corrupted data, the developer, platform or financial institution might be liable. “Under current law, AI is not a legal person capable of assuming duties or bearing liability,” Mata told crypto.news. “It is a technical system acting on behalf of a natural or legal person.” He says investigators should establish who authorized the agent, whose interests it represented, and what powers it received — essentially treating the relationship like a power of attorney. Delegation = responsibility, until the agent oversteps Mata argues that when an issuer, bank or investor authorizes an agent to transact, the principal ordinarily bears the consequences of actions that fall inside that authority. A bad price move does not automatically prove the agent acted outside its mandate. “An issuer cannot disown an unfavourable but authorised transaction merely because the decision was generated by software,” he said. Liability can shift, however, when an agent exceeds its mandate. In those cases, Mata says developers, platforms or financial institutions could face exposure if their design or controls caused or permitted the failure — though outcomes will depend on the specific facts and applicable law. Chanté Eliaszadeh, founder of Astraea Counsel, told Sandmark that liability will generally follow control: users are the starting point for responsibility, but developers can be on the hook if autonomous systems fail in predictable ways. Real-world traction and rising stakes Autonomous agents already have real access to wallets and payment rails. Keyrock reported in May that AI agents settled about $73 million across 176 million transactions in the prior year, with USDC accounting for 98.6% of the value studied. Coinbase has connected agents to trading, portfolio management, and payments under user-set limits. Chainalysis counted over 100 million x402-linked payments on Base by July, though it cautioned early totals reflected meme-coin farming and automated activity as well as independent agent payments. Mata warns that formal consent is not the same as meaningful control. Effective delegation, he says, should be explicit: a list of permitted actions and eligible assets, per-transaction and cumulative spending limits, mandate duration, triggers for human review, revocation rights, and an auditable record of every action. Tools and standards to make delegation verifiable Industry players are starting to build those controls into products. Anchorage Digital introduced “agentic banking” in May with verified identities, spending limits, and audit controls for autonomous systems accessing crypto and traditional rails. Visa and Wirex have trialled agent-led stablecoin payments for subscriptions and procurement to study security, reliability and consumer control. A June guide to agentic payments explained how x402 enables software to pay for data, compute and online services using stablecoins — and why authorization needs to define what an agent can buy, how much it can spend, and when access ends. Brickken contributors — Ludovico Rossi, Dario Lo Buglio, Thamer Dridi and Nabil El Alami Khalifi — drafted ERC-8226, a proposed Regulated Agent Mandate Standard (RAMS) filed April 12 as an Ethereum draft. RAMS would let a verified principal grant an on-chain agent limited permissions tied to asset, action, duration and monetary value. A regulated token contract could check the mandate before allowing a transaction. The draft separates three verification steps: an identity registry to confirm the agent, a compliance provider to verify the principal’s eligibility, and the RAMS registry to check whether the planned action fits the delegated mandate. Mandates could set per-transaction and cumulative limits, activation and expiry windows, allowed assets and actions, revocation functions, and usage records. Mata stresses RAMS is not a mechanism to transfer liability to software or to reimburse principals for authorized losses — it’s designed to make attribution auditable: who gave authority, what it allowed, whether the agent stayed within limits, and where controls failed when they didn’t. Standards and regulators are still catching up ERC-8226 remains a draft and includes open questions — for example, whether tokens bought by an agent should end up in the agent’s wallet or the principal’s account. Regulators likewise are grappling with how to treat agent-led activity. U.S. market rules already impose duties on firms that provide market access. SEC Rule 15c3-5 requires broker-dealers to maintain direct, exclusive financial and regulatory risk controls for market access, including automated pre-trade checks and systems that limit trading to authorized users. For consumer payments, Regulation E requires authenticated preauthorized electronic fund-transfer authorizations and gives consumers the right to stop or revoke future payments; CFPB guidance says the authorization process should prove identity and agreement. But existing rules don’t clearly spell out how a standing instruction like “manage my portfolio” applies when an AI autonomously picks and executes transfers, and lawyers remain divided over whether manipulated agent payments look like unauthorized transfers or authorized ones carried out by a delegated agent. Across the Atlantic, Bank of England Deputy Governor Sarah Breeden warned in June that current oversight frameworks were not designed for autonomous agents and that requiring human sign-off on every action may be impractical. Regulators are considering stronger safeguards, from circuit breakers to market-wide kill switches, if faulty AI models threaten trading systems. Why it matters As agentic software gains direct access to funds and trading rails, the practical and legal lines between delegation, control and liability are being redrawn. Standards like ERC-8226 and product features such as identity verification, spending caps and audit trails aim to make delegation transparent and traceable — not to absolve human or corporate actors. The growing consensus among industry lawyers and executives is simple: software can act, but responsibility still rests with people and institutions that give it power — unless those systems are demonstrably designed or controlled to fail. Read more AI-generated news on: undefined/news
