AI Agent Lawyer: Liability, Registration, and Governance
Astraea Counsel advises companies building and deploying AI agents — on who is liable when an agent acts, which financial-services registration an autonomous agent triggers, and how to contract for a product built on someone else's model.
Lead attorney: Chanté Eliaszadeh, Founder & Principal
- Licensed in California · State Bar No. 335803 — verify
- Consultations scheduled directly with the attorney, not an intake desk
When companies call us
- Your agent moves money, trades, or advises — and you need to know whether that makes you a broker-dealer, an investment adviser, a commodity trading advisor, or a money transmitter
- You are papering a vendor agreement for an AI product and the IP assignment has to reach the model and the data, not just the code
- Your agent retains memory or session state, and a deletion request arrives that you cannot actually honor
- You trained on user-generated or third-party content and need the copyright and consent posture assessed before you ship
- Your board wants an AI governance framework that would hold up against a Caremark-style oversight challenge
- A protocol or product is governed in part by autonomous agents, and you need to know how that reads under the securities laws
What engagement gets you
- A registration analysis mapping what your agent actually does to the regime it answers to — the Exchange Act broker test, the Advisers Act three-part test, CFTC registration categories, and FinCEN and state money transmission — including where they stack
- Deployer liability assessed under the doctrines that already apply, rather than waiting for AI-specific legislation: agency, negligence, product liability, unfair practices, and the emerging state AI statutes
- Vendor and customer agreements for AI products, drafted around what an assignment can and cannot reach — a third-party foundation model and open-source components need carve-outs and licenses rather than a blanket assignment, and AI-generated code may carry no copyright at all
- Privacy architecture for agents that persist memory, built so a deletion obligation under the CCPA or GDPR can actually be executed against what the agent stored
- AI governance frameworks and board-level reporting structures, and a clear read on which California AI statutes actually bind you — AB 2013's training-data disclosures reach developers, and the California AI Transparency Act's provenance and watermarking duties reach "covered providers" — generative-AI systems above 1,000,000 monthly users — but AB 853 (Stats. 2025, ch. 674) extended that Act past developers, so large online platforms and GenAI system hosting platforms take on provenance duties from January 1, 2027 — plus the EU AI Act's obligations for US companies
Recognition
- Quoted throughout "AI Agents Can Move Money – Lawyers Say Nobody Knows Who's Liable," part four of Sandmark's seven-part Agentic AI series (August 6, 2026), Chanté Eliaszadeh
- Author, "Complying With Calif. Crypto License Law's 11th-Hour Rewrite," Law360 Expert Analysis (August 13, 2026) — Chanté Eliaszadeh and Brandon Orewyler
- Astraea Counsel ranked in Chambers USA: Spotlight 2026 — Fintech (Los Angeles)
- Lawdragon 500 X — The Next Generation: Crypto Regulation, Disputes, Blockchain (2026), Chanté Eliaszadeh
- 2024 Law360 Distinguished Legal Writing Award, The Burton Awards — Chanté Eliaszadeh, co-author (White & Case)
- Panelist, American Bar Association Business Law Section 2026 Spring Meeting — Financial Services Technology Joint Subcommittee, on use cases tied to agentic-AI payment flows
Common Questions
Does my AI agent need a financial license?
It depends on what the agent does, not on what it is called. An agent that effects securities transactions for others implicates the Exchange Act broker test; one that gives personalized advice about securities for compensation implicates the Advisers Act, where the personalized character is often what breaks the publisher's exclusion; one that trades futures, swaps, or leveraged retail crypto implicates CFTC registration; and one that moves customer funds implicates FinCEN and state money transmission. These regimes stack rather than substitute, so an agent can fall into more than one.
Who is liable when an autonomous agent gets it wrong?
There is no settled federal rule allocating responsibility between the operator of an AI agent and its end user, and that gap is the practical problem. Chanté Eliaszadeh told Sandmark: “While each case is necessarily going to be fact-specific under existing law, the test for liability will usually follow control.” In practice the user is usually the starting point, having chosen to let the agent act on their behalf, and the federal E-SIGN Act recognizes contracts formed by “electronic agents” so long as the agent’s action is legally attributable to the person to be bound. But that does not put a company in the clear: a deployer risks liability where the agent fails outside the course of normal operations and misfires because of a corrupted data feed, and a developer risks it where a system marketed for autonomous trading fails in a foreseeable way. The workable answer is architectural: a named human principal, a defined scope of authority, disclosure to counterparties, and an audit trail. Astraea Counsel publishes that architecture as the Know Your Agent (KYA) framework.
If someone tricks our AI agent into sending money, is that an authorized payment?
As Chanté Eliaszadeh put it to Sandmark, “No regulator or court has resolved this question, and the loss allocation for the whole agentic-payments economy rides on it.” Regulation E protects consumers against unauthorized electronic transfers, but a payment the consumer approves — even one induced by a scammer — is generally still treated as authorized. That is the gap some lawyers call the “Zelle gap.” What nobody has decided is how a standing instruction to an agent, something like “manage my portfolio” or “keep purchases under $2,000,” fits those rules. Our founding principal framed the two candidate outcomes for Sandmark: a prompt-injection attack could be treated like stolen credentials, making the payment unauthorized; or a user who deliberately hands an agent credentials has furnished the means of access, which points the other way. Until it is settled, the defensible posture is to build now the authorization record you would want to litigate from later.
What AI work has the firm actually done?
Client identities are confidential, but the questions are representative. For a client whose platform layers a personalized coaching feature over impersonal market signals, we assessed whether that personalization defeats the Advisers Act publisher's exclusion under Lowe v. SEC — the line between publishing and advising, drawn on the product's actual architecture. For a client licensing a consumer application with an AI component, we drafted the intellectual-property terms around a problem most assignment clauses miss: a developer cannot assign what he does not own, so the agreement has to address the third-party model and the open-source components separately, and cannot assume AI-generated code carries copyright at all. And for a protocol client, we analyzed how automated governance mechanisms read under Howey.
Book a Call With Chanté Eliaszadeh
Pick a time that works for you — a 15-minute introductory call, no forms, no waiting.
Pick a date and time
Prefer to send a message instead?
Get your AI deployment assessed before it ships
Schedule a consultation on agent liability, registration, or AI governance.
Talk to an AttorneyAttorney advertising. Each case result described on this page was dependent on the facts of that case, and the results will differ if based on different facts. No attorney-client relationship is formed by visiting this page or submitting the contact form.