ASTRÆA COUNSEL
  • Home
    • Team
    • How We Work
    • Speaking
    • Press & Recognition
    • Results & Case Studies
    • Pricing
    • Litigation & Disputes
    • Business Partner Disputes
    • Commercial Litigation
    • Crypto Litigation
    • SEC Enforcement Defense

    • Crypto & Digital Assets
    • AI & Emerging Tech
    • DAOs
    • Fund Formation

    • Browse All Practice Areas
  • Insights
  • Contact
(310) 800-1780Book a Call

ASTRAEA COUNSEL

Trial and regulatory counsel for high-stakes disputes and digital-asset, fintech, and AI companies.

info@astraea.law

(310) 800-1780

Beverly Hills, CA

Practice Areas

  • Digital Assets & Blockchain
  • Litigation & Disputes
  • Artificial Intelligence & Emerging Tech
  • Securities Enforcement & Investigations
  • Fintech & Payments
  • Corporate & Transactions
  • Regulatory Compliance

Litigation

  • Litigation & Disputes
  • Business Partner Disputes
  • Commercial Litigation
  • Crypto Litigation
  • SEC Enforcement Defense
  • Results & Case Studies

Resources

  • Latest Insights
  • Token Classifier
  • GENIUS Act Compliance Clock
  • Our Team
  • Press & Recognition
  • Contact

The Firm

  • DAO & Governance
  • How We Work
  • Pricing
  • Speaking

© 2026 Astraea Counsel, APC. All rights reserved.

Privacy PolicyTerms of Use

Attorney Advertising. Attorney Advertising. The material on this website is for informational purposes only and does not constitute legal advice. No attorney-client relationship is created by accessing or using this website. Any result portrayed on this website was dependent on the facts of that case, and the results will differ if based on different facts. Astraea Counsel, APC is a California Professional Corporation. Chanté Eliaszadeh (State Bar No. 335803) and Brandon Orewyler (State Bar No. 324391) are licensed to practice law in California only. The firm is not certified by the State Bar of California as a specialist in any field.

This site uses Google Analytics to improve user experience. See our for details.Privacy Policy for details.

Skip to main content
  1. Home/
  2. Insights/
  3. Can an AI Agent Legally Enter Into a Contract?
Client Guide

Can an AI Agent Legally Enter Into a Contract?

White & Case|Dechert|U.S. Securities and Exchange Commission, Cyber Unit|UC Berkeley Law

July 2, 2026•Chanté Eliaszadeh
AI AgentsContract LawESIGNUETAAgentic CommerceEmerging Technology
“A 1999 uniform act and a 2000 federal statute answered whether a machine can form a contract. UETA and ESIGN call the software an 'electronic agent' and, where the agent's act is legally attributable to the deployer, say a deal it strikes is not void just because no human saw it and treat it as that person's act, not the counterparty's. The open questions are no longer about validity; they are about how much authority you gave the agent, and who bears the risk when it agrees to something you never intended.”
Chanté Eliaszadeh · Principal — Transactional, Regulatory, and Digital Assets

An AI agent can form a binding contract, and the contract is not void just because no human reviewed it. A federal statute and a uniform act answered the validity question a generation ago: the Electronic Signatures in Global and National Commerce Act (ESIGN), enacted in 2000, and the Uniform Electronic Transactions Act (UETA), approved and recommended for enactment in all the states in 1999. Both recognize a category called the “electronic agent”—a computer program that acts without a human in the loop—and ESIGN bars denying such a contract legal effect or enforceability solely because an electronic agent formed it, so long as the agent’s action is legally attributable to the person to be bound, while UETA provides that a contract may be formed by the interaction of electronic agents even if no individual reviewed the result. So the interesting questions for an autonomous AI agent are not whether it can contract; they are how much authority it had and who bears the risk when it agrees to something its operator never intended.

That is a different posture than most builders assume. The instinct is to ask whether a “real” contract can exist without human assent. The answer has been yes since the Uniform Electronic Transactions Act was approved in 1999 and ESIGN was enacted in 2000—for automated ordering systems then, and for generative agents now. This guide covers what the electronic-agent framework actually says, why the AI is a tool rather than a person in the sense agency law requires, who ends up bound, and the one area that is genuinely unsettled: what happens when an autonomous agent exercises judgment—or hallucinates—its way into a term.

Key takeaways

  • The validity question is settled. ESIGN and UETA both recognize the “electronic agent”; ESIGN bars denying a contract enforceability solely because an agent formed it where the agent’s action is legally attributable to the person to be bound, and UETA provides that a contract may be formed by the interaction of electronic agents—provisions dating to 1999 (UETA) and 2000 (ESIGN), not a gap.
  • No human review is required. A contract may be formed by the interaction of electronic agents even if, in UETA’s words, “no individual was aware of or reviewed” the agents’ actions or the resulting terms.
  • The AI is a tool, not a party. An electronic agent is not a person under agency law, ESIGN, or the uniform act: it lacks capacity to hold legal rights or owe legal duties, so it cannot be a contracting party. The human or entity that uses it is the party.
  • Attribution is what makes the agent’s act the deployer’s own. The agent is a tool, not a separate party, so there is no third party for the deal to land on—but attribution is a condition, not an automatic consequence: ESIGN’s protection runs only so long as the agent’s action is legally attributable to the person to be bound.
  • A company can be liable for what its chatbot says. A 2024 Canadian tribunal decision held an airline liable in negligent misrepresentation for what its customer-service bot told a passenger about the airline’s own policy—not a contract holding or binding U.S. authority, but a preview of how conversational agents may be treated.
  • Authority and error are the open questions. The unsettled frontier is the scope of the agent’s authority and who bears the risk when it agrees to an unintended term—not contract validity.

Deploying AI agents or shipping an AI product? Book a 15-minute call on the rules that already apply. Flat fees for defined scope, quoted before we start.

Talk to an Attorney

The uniform act and ESIGN already recognized non-human contracting—in 1999 and 2000

The starting point is that Congress and the uniform-law commissioners built the rule for machine-made contracts before modern AI existed. ESIGN provides that a contract “may not be denied legal effect, validity, or enforceability solely because its formation, creation, or delivery involved the action of one or more electronic agents so long as the action of any such electronic agent is legally attributable to the person to be bound” (15 U.S.C. § 7001(h)).1 It defines an “electronic agent” as “a computer program or an electronic or other automated means used independently to initiate an action or respond to electronic records or performances in whole or in part without review or action by an individual at the time of the action or response” (15 U.S.C. § 7006(3)).1

UETA, the uniform act approved and recommended for enactment in all the states, supplies the parallel rule for state law wherever a state has enacted it. Its automated-transaction section provides that “[a] contract may be formed by the interaction of electronic agents of the parties, even if no individual was aware of or reviewed the electronic agents’ actions or the resulting terms and agreements” (UETA § 14(1)), using a materially parallel definition of “electronic agent” (UETA § 2(6)).2 Read together, the uniform act and ESIGN point the same way: a program acting on its own can form a contract, and the absence of a human reviewer is not, by itself, a defect—under ESIGN, so long as the action of the electronic agent is legally attributable to the person to be bound. An autonomous AI agent fits the statutory definition on its face—it is exactly an “automated means used independently … without review or action by an individual”—though it is worth flagging that we are aware of no court that has yet applied these 1999 and 2000 electronic-agent provisions to a generative AI agent, and a litigant could argue the drafters had deterministic automated systems in mind.

The two instruments answer the same question in parallel terms, and the differences are worth reading side by side.

QuestionESIGN (enacted 2000)UETA (approved 1999)
Where the rule sits15 U.S.C. § 7001(h)1UETA § 14(1)2
What it providesA contract “may not be denied legal effect, validity, or enforceability solely because its formation, creation, or delivery involved the action of one or more electronic agents"1"[a] contract may be formed by the interaction of electronic agents of the parties, even if no individual was aware of or reviewed the electronic agents’ actions or the resulting terms and agreements”2
How “electronic agent” is defined”a computer program or an electronic or other automated means used independently to initiate an action or respond to electronic records or performances in whole or in part without review or action by an individual at the time of the action or response” (15 U.S.C. § 7006(3))1A materially parallel definition (UETA § 2(6))2
The attribution condition”so long as the action of any such electronic agent is legally attributable to the person to be bound”1An electronic record or electronic signature “is attributable to a person if it was the act of the person,” and “[t]he act of the person may be shown in any manner” (UETA § 9(a))3
How far it reachesFederalState law wherever a state has enacted it

An “electronic agent” is not a legal “agent”

The word “agent” in “electronic agent” is a term of art, and it does not mean what it means in agency law. A common-law agent is a person, capable of holding legal rights and bearing legal duties, who can bind a principal through delegated authority; an electronic agent is a tool. It is not a person in the sense agency law requires: it lacks capacity to hold legal rights or owe legal duties, so it cannot be a party to the contract.4 Commentary to the modern law of agency treats computer programs this way—the program is an instrumentality of the person who uses it, not a separate actor.

This distinction is not academic; it decides who is on the contract. Because the agent is a tool, there is no third party for the contract to land on. The resulting record is attributed to the deploying party where the record was that party’s act. UETA states the attribution rule directly: an electronic record or electronic signature “is attributable to a person if it was the act of the person,” and “[t]he act of the person may be shown in any manner,” including through the efficacy of a security procedure (UETA § 9(a)). Attribution settles whose act the record is; UETA then makes its effect turn on “the context and surrounding circumstances at the time of its creation, execution, or adoption, including the parties’ agreement, if any, and otherwise as provided by law” (UETA § 9(b)).3 Attribution is the gateway to being bound, not the whole of it. The AI does not step into the deal as a third party; the company operating it is the counterparty, start to finish.

Who is bound—and the airline-chatbot lesson

The practical consequence is that where its agent’s act is attributable to it, the act is the deploying party’s own, and the party cannot later disown the agent as a rogue third party. The clearest recent illustration is Moffatt v. Air Canada, a 2024 decision of British Columbia’s Civil Resolution Tribunal: the airline’s customer-service chatbot told a passenger they could apply for a bereavement fare retroactively, after their travel, which was contrary to the airline’s actual policy, and the tribunal held the airline liable for its chatbot’s misrepresentation, rejecting what it described as the airline’s suggestion that the chatbot “is a separate legal entity that is responsible for its own actions.” It is a Canadian small-claims tribunal decision on negligent misrepresentation, not binding U.S. authority and not a contract-formation holding—but its reasoning parallels the attribution logic that ESIGN and UETA encode: the airline was “responsible for all the information on its website,” whether it “comes from a static page or a chatbot.”5

For an AI agent that negotiates, orders, or transacts, the lesson is direct. If the agent commits to a price, accepts a term, or makes a representation within the authority it was given, the deploying company is treated as having done so itself. “The model said it, not us” is not a defense—it is a description of attribution working exactly as designed. The counterparty dealt with your agent; the law attributes the result to you. And when what the agent moves is customer money—stablecoin transfers included—Bank Secrecy Act customer-identity obligations attach to AI-initiated transfers on top of contract attribution.

The hard edge: when the agent agrees to something you did not intend

Here is where the settled law runs out and genuine judgment begins. An autonomous agent can do something an EDI ordering system from 1999 could not: exercise discretion, “negotiate,” and—being a language model—generate a term that is wrong, unintended, or hallucinated. If your agent offers a product at a fraction of its price, or accepts an obligation you never authorized, is there a contract?

The doctrines that answer this are older than AI, and they still apply. The default is that the deploying party bears the risk of its own tool—the counterparty did not choose your agent, and attribution, where it holds, puts the agent’s act on you. The edges are governed by familiar law, and they cut both ways. UETA gives individuals who make errors dealing with another person’s electronic agent a narrow, condition-heavy way out where that agent gave them no opportunity to prevent or correct the mistake—available only if the individual also promptly notifies the other party of the error and that the individual did not intend to be bound, takes reasonable steps to return the consideration (or, if instructed, to destroy it), and has not used or received any benefit or value from it (UETA § 10(2)).6 That rule runs against the deploying party. The law of unilateral mistake can run the other way, letting a party avoid a contract where the other side had reason to know the offer was the product of an error—or, even where it did not, where enforcing the contract would be unconscionable.7 What none of these doctrines do is void the contract merely because an AI, rather than a human, generated the term. The autonomy of the agent raises the stakes of getting authority and error-controls right; it does not hand the deploying party a validity defense.

That risk allocation is not confined to unintended terms; when an agent’s autonomy produces an outright financial loss, which party bears a financial loss caused by an autonomous agent turns on the same attribution logic that makes the agent’s act yours.

What this means for building agentic commerce

Because validity is settled and attribution is unforgiving, the legal work moves to the front end—the design of the agent’s authority. Practically: define and technically constrain what the agent may agree to (price floors, term whitelists, value ceilings); require human confirmation above a threshold for high-value or irreversible commitments; build error-avoidance and correction procedures so a counterparty’s—and your own—mistakes are catchable; log the agent’s actions so attribution can be proven or bounded; and put terms of use in front of counterparties that address automated dealing. These are contract-design and governance choices, and they are far cheaper made before deployment than litigated after an agent binds you to a term you never saw.

What to do first

In order: (1) treat any contract your AI agent can form as a real, enforceable contract attributable to you; (2) map and technically bound the agent’s authority—what it may offer, accept, and spend; (3) put a human-in-the-loop gate above a value or risk threshold; (4) build error-avoidance and correction into the transaction flow, and keep an action log; and (5) address automated agents expressly in your terms of use and counterparty contracts. Do this design work before the agent transacts with anyone, because where your agent’s action is legally attributable to you, the law treats the result as yours.


This article provides general information only and is not legal advice. The application of electronic-transaction statutes, agency principles, and contract-mistake doctrines to autonomous AI agents is an emerging area, and outcomes are fact-specific and jurisdiction-specific. Statutory section numbers, the uniform-act text as adopted in a particular state, and the cited decision should be confirmed against the controlling authority before you rely on them. Whether and how any rule applies to a particular business is a determination to make with qualified counsel. No attorney-client relationship is formed by this article. Attorney Advertising.

Work with Astraea Counsel

Astraea Counsel advises fintech, crypto, and AI companies on agentic commerce, contract and regulatory risk, and the questions raised by autonomous AI agents. Explore our Regulatory Compliance services or contact us to design your agent’s authority before it transacts.

Related resources

  • Does Your AI Agent Need a Financial License? A Decision Guide—the registration side of deploying an agent that transacts
  • The AI Agent Identity Doctrine—the accountability companion: tracing an agent to a named human principal
  • Does Your Agentic-Payments Startup Need a Money Transmitter License?—when the agent moves customer money
  • Smart Contract Legal Enforceability: When Code Isn’t Law—the enforceability of self-executing code, a distinct question

Notes

Footnotes

  1. Electronic Signatures in Global and National Commerce Act (ESIGN) § 101(h), 15 U.S.C. § 7001(h) (“A contract or other record relating to a transaction in or affecting interstate or foreign commerce may not be denied legal effect, validity, or enforceability solely because its formation, creation, or delivery involved the action of one or more electronic agents so long as the action of any such electronic agent is legally attributable to the person to be bound.”); id. § 106(3), 15 U.S.C. § 7006(3) (defining “electronic agent” as “a computer program or an electronic or other automated means used independently to initiate an action or respond to electronic records or performances in whole or in part without review or action by an individual at the time of the action or response”). PDF PDF ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  2. Uniform Electronic Transactions Act (UETA) § 14(1) (1999) (“A contract may be formed by the interaction of electronic agents of the parties, even if no individual was aware of or reviewed the electronic agents’ actions or the resulting terms and agreements.”); id. § 2(6) (defining “electronic agent”). UETA was “approved and recommended for enactment in all the States” in 1999, and ESIGN defers to a state’s enactment of that official text where applicable (15 U.S.C. § 7002(a)(1)). The section numbering follows the uniform act, and a specific state’s enactment should be checked. PDF PDF PDF ↩ ↩2 ↩3 ↩4

  3. UETA § 9(a) (1999) (“An electronic record or electronic signature is attributable to a person if it was the act of the person. The act of the person may be shown in any manner, including a showing of the efficacy of any security procedure applied to determine the person to which the electronic record or electronic signature was attributable.”); id. § 9(b) (“The effect of an electronic record or electronic signature attributed to a person under subsection (a) is determined from the context and surrounding circumstances at the time of its creation, execution, or adoption, including the parties’ agreement, if any, and otherwise as provided by law.”). PDF ↩ ↩2

  4. An electronic agent is a tool, not a person under ESIGN, the uniform act, or the law of agency: it lacks capacity to hold legal rights or owe legal duties, so it cannot be a party to a contract. This follows from the structure of both acts—the “electronic agent” is defined as “a computer program or an electronic or other automated means” (15 U.S.C. § 7006(3); UETA § 2(6) (1999); see also UETA § 2(12) (defining “person” to reach only individuals and legal or commercial entities); id. § 2(16) (defining “transaction” to require an action “occurring between two or more persons”)) whose action is shielded from a validity challenge resting solely on its involvement only where it is “legally attributable” to the person to be bound (15 U.S.C. § 7001(h))—and from the law of agency, whose commentary treats a computer program as an instrumentality of the person using it rather than a common-law agent with independent capacity. Restatement (Third) of Agency § 1.04 cmt. e (A.L.I. 2006). PDF PDF PDF PDF ↩

  5. Moffatt v. Air Canada, 2024 BCCRT 149, paras. 2, 15, 17, 27, 32 (B.C. Civ. Resolution Trib.) (holding the airline liable for negligent misrepresentation made by its website chatbot and rejecting what the tribunal described as the airline’s suggestion that the chatbot “is a separate legal entity that is responsible for its own actions”). A Canadian tribunal decision, cited as a persuasive illustration of agent-attribution, not as binding U.S. authority. ↩

  6. UETA § 10(2) (1999) (providing that, in an automated transaction involving an individual, the individual “may avoid the effect of an electronic record that resulted from an error made by the individual in dealing with the electronic agent of another person” if the electronic agent “did not provide an opportunity for the prevention or correction of the error” and the individual, on learning of the error, promptly notifies the other person of the error and that the individual did not intend to be bound, takes reasonable steps to return the consideration received or, if instructed by the other person, to destroy it, and has not used or received any benefit or value from it); id. § 10(4) (paragraphs (2) and (3) “may not be varied by agreement”). PDF ↩

  7. See Restatement (Second) of Contracts § 153 (A.L.I. 1981) (stating when a mistake of one party makes a contract voidable, including where the other party had reason to know of the mistake); id. § 153 cmt. e (“If the other party had reason to know of the mistake, the mistaken party can avoid the contract regardless of whether its enforcement would be unconscionable.”). Whether § 153 reaches an erroneous automated offer turns on the Section’s own fact-bound requirements: a mistake as to a basic assumption with a material effect on the agreed exchange adverse to the mistaken party, no allocation of the risk to the mistaken party under § 154, and either unconscionability, the other party’s reason to know of the mistake, or that party’s fault in causing it. PDF ↩

On This Page

  • Key takeaways
  • The uniform act and ESIGN already recognized non-human contracting—in 1999 and 2000
  • An "electronic agent" is not a legal "agent"
  • Who is bound—and the airline-chatbot lesson
  • The hard edge: when the agent agrees to something you did not intend
  • What this means for building agentic commerce
  • What to do first
  • Work with Astraea Counsel
  • Notes

Frequently Asked Questions

Can an AI agent enter into a binding contract?

Generally, yes. Under the federal ESIGN Act, a contract may not be denied legal effect solely because its formation involved the action of an “electronic agent” — a computer program that acts without human review — as long as the agent’s action is legally attributable to the person to be bound. The Uniform Electronic Transactions Act (UETA) adds that a contract may be formed by the interaction of electronic agents even if no individual reviewed the agents’ actions or the resulting terms. An AI agent fits the statutory definition on its face, so a deal it forms can be a real, enforceable contract. The harder questions are how much authority the agent had and who bears the risk of its mistakes — not whether a contract can exist at all.

Is a contract void if no human reviewed it?

No. That is the specific question these provisions address. ESIGN provides that a contract may not be denied legal effect solely because its formation involved one or more electronic agents, so long as the agent’s action is legally attributable to the person to be bound, and UETA provides that a contract may be formed by the interaction of electronic agents even if no individual was aware of or reviewed the agents’ actions or the resulting terms. Lack of human review, standing alone, is not a defense to enforcement where the agent’s action is legally attributable to the person to be bound.

Who is bound by a contract an AI agent makes — the company or the AI?

The company (or person) that uses the agent. An electronic agent is a tool, not a person under agency law, ESIGN, or the uniform act: it lacks capacity to hold legal rights or owe legal duties, so it cannot be a contracting party. Its actions are attributed to the human or entity operating it where they are that party’s own acts, and the effect of those acts then turns on the surrounding circumstances, the parties’ agreement, and other law. A Canadian tribunal reached a parallel result in 2024 on a negligent-misrepresentation claim, holding an airline liable for a misrepresentation its customer-service chatbot made about the airline’s own bereavement-fare policy — the company could not disown its own automated agent.

What happens if an AI agent agrees to something the company never intended?

This is the genuinely open frontier. Because the agent’s action, where it was the deploying party’s own act, is attributed to that party, the starting point is that the company bears the risk of what its agent does — the counterparty did not choose your tool. Traditional doctrines still apply at the edges, and they cut both ways: UETA lets an individual dealing with the company’s agent avoid the effect of some of the individual’s own errors, while the law of unilateral mistake can let the company avoid a deal where the counterparty had reason to know of the error or enforcement of the contract would be unconscionable. The practical answer is to bound the agent’s authority and build error controls before deployment, not to argue about validity afterward.

Share

Follow this firm’s analysis on Google — see our commentary first when a story like this one breaks.

Stay Informed on Digital Asset Law

Practical legal analysis on crypto regulation, AI compliance, and fintech law—delivered when it matters.

No spam. Unsubscribe anytime.

Chanté Eliaszadeh profile picture

Chanté Eliaszadeh

Principal — Transactional, Regulatory, and Digital Assets

Chanté Eliaszadeh is the principal attorney of Astraea Counsel APC, advising crypto, AI, and fintech companies on securities and digital-asset regulation. She is named to the 2026 Lawdragon 500 X — The Next Generation guide for Crypto Regulation, Disputes, and Blockchain; won the 2024 Law360 Distinguished Legal Writing Award from The Burton Awards as co-author at White & Case; is recognized in The Legal 500 USA (White & Case LLP, 2023); and served as a summer SEC Honors Program intern in the SEC's Cyber Unit. Her firm is ranked in Chambers USA: Spotlight 2026 — Fintech (Los Angeles). She is an invited speaker at venues including ETHDenver, Korea Blockchain Week, the American Bar Association Business Law Section, Art Basel Miami, and Berkeley Law, and keynote speaker at the Computational Law & Blockchain Festival.

Book a 15-Minute Call →

Legal Disclaimer: This article provides general information for educational purposes only and does not constitute legal advice. The law changes frequently, and the information provided may not reflect the most current legal developments. No attorney-client relationship is created by reading this content. For advice about your specific situation, please consult with a qualified attorney.

Related Articles

Client Guide

Drafting Vendor Agreements for Claude Managed Agents: A GC's Clause Library

Standard SaaS MSAs were not written for autonomous AI agents. A former SEC Honors Program intern in the SEC's Cyber Unit provides a ready-to-redline clause library organized by the KYA Five Pillars, with the regulatory basis and plain-language rationale for each provision.

April 15, 2026 · 21 min readRead More →
Client Guide

Does Your Agentic-Payments Startup Need a Money Transmitter License?

When an AI agent moves money on a user's behalf, the licensing question turns on one thing regulators have asked for decades: do you control the funds? If your platform holds, pools, or controls customer money, you are likely a money transmitter — federally and in most states — no matter how autonomous the agent is.

July 1, 2026 · 10 min readRead More →
Client Guide

Does Your AI Agent Need a Financial License? A Decision Guide

Whether an AI agent needs a financial license does not turn on the fact that it is AI. It turns on what the agent does with money or securities — and more than one regime can apply at once. An agent that executes securities trades answers to the SEC; one that trades futures, swaps, or leveraged retail crypto answers to the CFTC; one that moves customer money answers to FinCEN and the states. This is the decision guide that routes your agent to the right regulator — often more than one.

July 1, 2026 · 9 min readRead More →
View All Articles

Deploying AI Agents or Building an AI Product?

Agent liability, governance frameworks, vendor contracts, and the state and EU rules that already apply — mapped to what you are actually shipping.

Talk to an Attorney