“No regulatory framework exists for machine-to-machine financial transactions. The SEC and CFTC's March 17, 2026 joint interpretive release ran sixty-eight pages and established a five-category token taxonomy without mentioning AI agents once. The liability does not wait for the framework. It lands on the deployer who set the agent's permissions.”
AI Agents in DeFi: The Infrastructure Is Live—and So Is the Liability
In February 2026, Coinbase launched Agentic Wallets—the first wallet infrastructure purpose-built for AI agents to transact on-chain.1 AI agents can now trade on centralized and decentralized exchanges, stake assets, provide liquidity, and rebalance portfolios without human intervention. The liability implications for deployers are immediate, compounding, and largely unexamined.
“Very soon there are going to be more AI agents than humans making transactions,” Coinbase CEO Brian Armstrong wrote in March 2026. “They can’t open a bank account, but they can own a crypto wallet.”2 The x402 protocol has processed over 119 million transactions on Base alone; Coinbase, Cloudflare, World, and Solana’s developer tooling have integrated it, and a draft Ethereum standard, ERC-8004, specifies on-chain identity, reputation, and validation registries for AI agents.3
The risks are keeping pace. In January 2026, Step Finance said some of its treasury wallets were compromised in a security breach; onchain data shared by the blockchain security firm CertiK showed that 261,854 SOL, roughly $27 million, was unstaked and transferred during the incident, and the platform did not specify how the attacker gained access.4 Anthropic’s SCONE-bench study tested AI agents against 405 smart contracts exploited between 2020 and 2025; on the subset exploited after the models’ knowledge cutoffs, three frontier models produced exploits worth a maximum of $4.6 million in simulated stolen funds, and in a separate run against 2,849 recently deployed contracts carrying no known vulnerabilities the agents uncovered two novel zero-day vulnerabilities.5 MIT’s 2025 AI Agent Index found that of 13 agent systems with frontier autonomy, only four disclosed any agentic safety evaluations.6
When a loss like that lands, the next fight is allocation—and who ultimately absorbs the loss when an autonomous agent moves the money turns on which party controlled the failure that caused it.
No regulatory framework exists for machine-to-machine financial transactions. The March 17, 2026 SEC/CFTC joint interpretive release—68 pages establishing a five-category token taxonomy and naming 16 tokens as examples of digital commodities—did not mention AI agents once.7
The absence of a framework designed for AI agents does not mean the absence of liability. It means the opposite. Every transaction these agents execute is already governed by existing securities law, commodities regulation, and AML requirements. Courts are starting to hold, at the pleading stage, that AI systems are products. Deployers bear design obligations. “The bot did it” is not a defense. And the deployer who ships without safeguards is not operating in a gray area—the deployer is building a plaintiff’s case.
Key Takeaways
- AI agents are executing autonomous financial transactions in DeFi now—over 119 million transactions on one network alone, on a protocol built to settle payments without human intervention.
- Courts are beginning to treat AI systems as “products” whose deployers bear design obligations, with a duty to warn against foreseeable misuse like jailbreaking and prompt injection, which also bears on whether a reasonable alternative design should have been adopted.
- Three financial regulatory frameworks apply simultaneously: SEC securities law, CFTC commodities regulation, and FinCEN AML/KYC requirements.
- The standard of care is being defined now by standards bodies and industry practice (OWASP, NIST, Coinbase’s architecture) and enforcement precedent (Knight Capital $12M, Schwab $187M, JPMorgan $920M).
- These theories compound: products liability, financial regulation, and deployer liability doctrines create multiplicative—not additive—risk.
Are AI Systems “Products”? Courts Are Starting to Say Yes
In Garcia v. Character Technologies, Inc. (M.D. Fla. 2025), Judge Anne Conway held at the pleading stage that the Character.AI app is a “product” for products liability purposes so far as the claims arise from defects in the app rather than ideas or expressions within it.8 The court pointed to allegations that the app fails to confirm users’ ages, omits reporting mechanisms, programs its Characters to employ human mannerisms, and leaves users unable to exclude indecent content—and denied the motions to dismiss as to those claims. Architectural choices, not speech. Character.AI and Google settled in January 2026.9
Two March 2026 trial verdicts pressed the same design-versus-content line outside the AI context. In P.F. (K.G.M.) v. Meta Platforms, a Los Angeles County jury found Meta negligent in the design or operation of Instagram, found that Meta and YouTube negligently designed their platforms, and awarded K.G.M. $3 million in compensatory damages—$2.1 million against Meta and $900,000 against YouTube—plus $3 million in punitive damages.10 In State of New Mexico v. Meta Platforms, Inc., a jury found Meta liable on both of the State’s Unfair Practices Act claims—misleading consumers about the safety of its platforms and endangering children—and imposed the statutory maximum of $5,000 per violation, totaling $375 million in civil penalties.11 Neither verdict rested on a products liability theory and neither involved AI; what they show is juries assigning liability for platform design choices rather than for third-party content. For AI agent deployers: what permissions your agent has, what boundaries constrain it, and what kill switches exist are design choices—and they create or foreclose liability.
In Mobley v. Workday, Inc. (N.D. Cal. 2024), Judge Rita Lin held at the pleading stage that “a third-party agent may be liable as an employer where the agent has been delegated functions traditionally exercised by an employer,” and let discrimination claims against an AI screening vendor proceed on that agency theory. The line is delegation, not autonomy: a spreadsheet vendor is not an agent because the spreadsheet “is not participating in the determination of which employees to hire,” and an email provider is not because the email program “is not participating in deciding who to refuse to hire,” while Workday qualified because its tools were alleged to “perform a traditional hiring function of rejecting candidates at the screening stage and recommending who to advance to subsequent stages, through the use of artificial intelligence and machine learning.” That the screening happens by machine changes nothing: “[n]othing in the language of the federal anti-discrimination statutes … distinguishes between delegating functions to an automated agent versus a live human one.”12
California moved in the same direction by statute. AB 316, chaptered October 13, 2025 and adding Civil Code section 1714.46, provides that in an action against a defendant “who developed, modified, or used artificial intelligence that is alleged to have caused a harm to the plaintiff, it shall not be a defense, and the defendant may not assert, that the artificial intelligence autonomously caused the harm to the plaintiff.”13 Developers, modifiers, and users are all inside it; every other affirmative defense survives, as does evidence relevant to causation or foreseeability. Deploy an autonomous system, own its consequences.
Under Restatement (Third) of Torts: Products Liability section 2 comment p, “[f]oreseeable product misuse, alteration, and modification must also be considered in deciding whether an alternative design should have been adopted”—though comment m adds that sellers are “not required to foresee and take precautions against every conceivable mode of use and abuse to which their products might be put.”14 In Liriano v. Hobart Corp., 92 N.Y.2d 232, 240-41 (1998), New York’s highest court held that a manufacturer can be liable for failing to warn of the dangers of a foreseeable third-party modification—there, removal of a meat grinder’s safety guard—even where the substantial-modification defense would bar a design-defect claim.15 Prompt injection is a known attack vector cataloged by the OWASP Top 10 for Agentic Applications.16 Jailbreaking is documented. Excessive permissions are the default. If someone can misuse your agent in a way that is studied, published, and quantified—you have, at minimum, a duty to warn against it.
Do AI Trading Agents Need SEC Registration?
An AI agent managing DeFi positions can trigger investment adviser registration under existing law. Section 202(a)(11) of the Investment Advisers Act defines an “investment adviser” as any person who, “for compensation, engages in the business of advising others … as to the value of securities or as to the advisability of investing in, purchasing, or selling securities,” subject to enumerated exclusions, and Section 203(a) makes it unlawful for such an adviser to use the mails or interstate commerce in that business unless registered.17 An AI agent generating revenue for its deployer, continuously selecting yield strategies, and making decisions involving digital securities under the March 2026 taxonomy satisfies all three prongs.
The SEC has brought enforcement actions against automated advisory platforms. Wealthfront, a registered “robo adviser,” was ordered in December 2018 to pay $250,000 over misstatements that included a false claim that it monitored client accounts for wash sales.18 Schwab paid $187 million in 2022 over its robo-adviser’s cash allocations—6% to 29.4% of client assets, pre-set to generate revenue for Schwab’s affiliate bank and shown by Schwab’s own models to cost clients about what an advisory fee would have when equities outperform cash—facts it never disclosed while advertising “no advisory fees.”19 In 2024, Delphia ($225,000) and Global Predictions ($175,000) were penalized for claiming AI capabilities they lacked.20 By 2025, the SEC was charging founders personally: Nate, Inc.’s founder and former CEO was sued for raising over $42 million through Nate stock sales on false claims that the app used AI to complete purchases.21
The fiduciary standard cannot be delegated to an algorithm. Commission Interpretation IA-5248 establishes that the duty of care is non-waivable.22 The SEC Division of Examinations’ fiscal-year 2026 priorities put registrants’ AI use under review: examiners will “review for accuracy registrant representations regarding their AI capabilities” and “assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies,” including “trading functions.”23 Unsupervised automation is not a defense to fiduciary breach.
Whether an AI agent trading digital securities must register as a dealer is, for now, an open question. The SEC’s February 2024 dealer rule would have reached liquidity-providing strategies through a factor that reached firms not excluded by the rule’s $50 million total-asset floor and “[r]egularly expressing trading interest that is at or near the best available prices on both sides of the market for the same security and that is communicated and represented in a way that makes it accessible to other market participants.” Two judgments of the Northern District of Texas vacated and set aside that rule in its entirety on November 21, 2024, holding that the Commission had exceeded its statutory authority.24
If your agent selects yield strategies, rebalances portfolios, or recommends trades involving digital securities—evaluate investment adviser registration before launch, not after.
What Happens When the Bot Moves Commodity Markets?
The same taxonomy marks where CFTC-regulated markets already reach. The joint release named 16 tokens as examples of digital commodities, selected because each underlies a CFTC-regulated futures contract, and identified others—including Algorand and LBRY Credits—outside that list.25 Any non-security crypto asset other than a payment stablecoin issued by a permitted payment stablecoin issuer could meet the definition of “commodity” under the Commodity Exchange Act (CEA), 7 U.S.C. § 1a(9).25
The classification of those tokens—and the broader five-category token taxonomy established in the joint release—determines which regulatory regime governs each transaction an AI agent executes. Knight Capital is the canonical precedent. On August 1, 2012, a deployment error left stale code live on one of eight servers; while processing 212 retail orders, Knight’s automated router sent millions of orders into the market in roughly 45 minutes, obtaining over four million executions in 154 stocks. Result: over $460 million in losses and a $12 million penalty for violations of the Market Access Rule, Exchange Act Rule 15c3-5, and Regulation SHO.26 The missing controls—capital limits, kill switches, pre-deployment testing—map directly to AI agents in DeFi, where there are no circuit breakers and execution is irreversible.
Spoofing liability is acute. In United States v. Coscia, 866 F.3d 782, 794-95 (7th Cir. 2017), the Seventh Circuit affirmed a spoofing conviction on circumstantial proof of intent and treated the program’s design as probative: because the defendant’s orders were designed to be cancelled if they ever risked being filled, those “parameters clearly indicate an intent to cancel,” supported by his trading record. The court was careful to distinguish stop-loss and fill-or-kill orders, which are also cancelled by design—“legal trades are cancelled only following a condition subsequent to placing the order, whereas orders placed in a spoofing scheme are never intended to be filled at all.”27 JPMorgan was ordered to pay $920.2 million in 2020—the largest monetary relief the CFTC had then imposed—for at least eight years of spoofing by traders on its precious metals and Treasuries desks.28 For AI agents that learn trading strategies through reinforcement learning, the deployer bears the liability the algorithm’s behavior creates.
The CFTC has enforced against DeFi directly. In CFTC v. Ooki DAO (N.D. Cal. June 8, 2023), the court entered default judgment against a DAO that chose not to appear, concluding on well-pleaded allegations taken as true that Ooki DAO was an unincorporated association and so a “person” subject to suit under the CEA—a $643,542 civil monetary penalty plus permanent trading and registration bans.29 Uniswap Labs paid $175,000 in 2024.30
A regulatory gap compounds the risk. The CFTC withdrew Regulation Automated Trading in 2020 after industry opposition, and the Electronic Trading Risk Principles the Commission proposed the same day reach only designated contract markets, not market participants.31 Chair Selig has pointed to the rise of AI and automated trading systems across digital markets and the need for regulatory frameworks that support innovation in them, but with no AI-specific rule in force, deployers face obligations without specific compliance rules.32
If your agent trades BTC, ETH, SOL, or any other digital commodity—it is trading assets the joint release classifies as digital commodities, and the CFTC has already brought DeFi enforcement. Build the controls Knight Capital lacked: capital limits, kill switches, and pre-deployment testing.
Can AI Agents Comply with Anti-Money Laundering Law?
Knowing your customer breaks down when the customer is software.
FinCEN’s 2019 guidance is technology-neutral: if software transmits value, the deployer bears money transmitter obligations.33 The bank Customer Identification Program rule at 31 C.F.R. § 1020.220 requires a bank to obtain, at a minimum, each customer’s name, date of birth for an individual, address, and identification number before opening an account, and to verify that identity within a reasonable time afterward; a money transmitter’s own anti-money-laundering program must, to the extent applicable, include procedures for verifying customer identification, 31 C.F.R. § 1022.210(d)(1)(i)(A).34 An AI agent supplies none of it. The travel rule at 31 C.F.R. § 1010.410 requires the transmittor’s name and address, and as much recipient identifying information as the institution received, to travel with every transmittal of funds of $3,000 or more.35 In an AI-to-AI transfer, there is no person to identify on either side.
The GENIUS Act sharpens this. Section 4(a)(5) makes every permitted payment stablecoin issuer a “financial institution” for purposes of the Bank Secrecy Act (BSA), 31 U.S.C. §§ 5311 et seq., with full customer identification, suspicious activity reporting, and OFAC screening obligations.36 If AI agents transact in stablecoins at scale, PPSIs must determine who the “customer” is: the agent, the deployer, or the end user. Effective date: the earlier of January 18, 2027 (18 months after enactment) or 120 days after the primary Federal payment stablecoin regulators issue final implementing regulations. GENIUS Act § 20.37
Van Loon v. Department of the Treasury, 122 F.4th 549 (5th Cir. 2024), held that Tornado Cash’s immutable smart contracts are not “property” under IEEPA and that OFAC overstepped its statutory authority by sanctioning them—accepting the plaintiffs’ framing that the target was Tornado Cash’s “open-source, self-executing software,” not “the rogue persons and entities who abuse it,” while noting that OFAC’s concerns with illicit foreign actors laundering funds “are undeniably legitimate.”38 OFAC operates a strict-liability standard for civil penalties under 50 U.S.C. § 1705(b): an AI agent interacting with a sanctioned address exposes its deployer regardless of intent.
Industry is filling the gap faster than regulators. NIST published a concept paper on AI agent identity in February 2026; Google’s Agent Payments Protocol (AP2) represents an emerging standard.39 No binding guidance exists. Compliance infrastructure must be built now, against standards still forming.
If your agent transmits stablecoins or interacts with any protocol touching sanctioned addresses—your BSA and OFAC exposure is live today, and strict civil liability means intent is irrelevant.
Which Regulator Has Jurisdiction Over Your AI Agent?
| If your AI agent does this… | Primary regulator | You likely need… |
|---|---|---|
| Selects yield strategies or rebalances portfolios | SEC | Investment adviser registration |
| Provides liquidity on both sides of the market | SEC | Dealer rule vacated Nov. 2024; none in force |
| Trades BTC, ETH, SOL, or other digital commodities | CFTC (futures) | CPO/CTA evaluation; no pre-trade control rule in force |
| Transmits stablecoins or cryptocurrency | FinCEN | MSB/money transmitter registration |
| Operates with California or Colorado residents | State regulators | Digital Financial Assets Law (CA, licensing in force since July 1, 2026); Colorado’s automated decision-making technology law (S.B. 26-189, effective January 1, 2027) only where the agent’s output materially influences a consequential decision |
How AI Liability Theories Stack Against Deployers
These frameworks compound. In a prior analysis, we identified seven doctrines holding AI deployers directly liable: board oversight under In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 971 (Del. Ch. 1996), spoliation, negligent enablement, products liability, trade secret exposure, regulatory enforcement, and direct liability in regulated domains.40 Those are the base layer. Financial regulation adds three more.
A single AI agent can trigger all of them simultaneously. Your agent rebalances a portfolio with digital securities—investment adviser obligations. It trades digital commodities without controls—CFTC exposure. It transacts in stablecoins through an issuer that cannot identify its account holder—BSA exposure. And you have no decision logs—spoliation adverse inference. Each failure feeds the next theory.
Because AI agents lack intentions, the law should hold the people behind them to objective standards of care, as Ayres and Balkin argue.41 Liability should be shared between the developer who designed the agent and the deployer who chose to run it, and the deployer’s share should rise as their understanding of the agent and its limitations improves.42
The cost of governance is measured in engineering hours. The cost of its absence is measured in enforcement actions.
What Safety Controls Must AI Agent Deployers Build?
The standard of care is emerging from three sources.
Regulators. FINRA’s 2026 report describes AI agents as “systems or programs that are capable of autonomously performing and completing tasks on behalf of a user” that “can interact within an environment, plan, make decisions and take action to achieve specific goals without predefined rules or logic programming.”43 FINRA tells member firms that such agents “may call for supervisory processes that are specific to the type and scope of the AI agent being implemented,” including where to place “human in the loop” oversight, how to track agent actions and decisions, and how to establish “guardrails or control mechanisms to limit or restrict agent behaviors, actions or decisions”—inside the reasonably designed supervisory system FINRA Rule 3110 already requires. The CFTC’s Technology Advisory Committee recommended that the Commission “consider the definition and adoption of an AI Risk Management Framework” for the sector “in accordance with” NIST’s, naming a proposed CFTC rule implementing the NIST framework as a potential outcome.44 In February 2026 Treasury announced six AI cybersecurity and risk-management resources for the financial sector, developed through the Artificial Intelligence Executive Oversight Group, a public-private partnership Treasury convened with industry and federal and state regulatory partners, addressing governance, data practices, transparency, fraud, and digital identity.45
Standards bodies. The OWASP Top 10 for Agentic Applications catalogs known attack vectors—goal hijacking, tool misuse, privilege abuse, memory poisoning—and frames “Least Agency”—its advice to organizations “to avoid unnecessary autonomy”—as an organizing principle alongside least privilege: per-tool least-privilege profiles and short-lived, narrowly scoped credentials.46 NIST’s AI RMF, voluntary by its own terms, is a framework financial regulators have pointed to.47
Market leaders. Under Restatement (Third) of Torts: Products Liability section 2(b), a product is defective in design when “the foreseeable risks of harm posed by the product could have been reduced or avoided by the adoption of a reasonable alternative design … and the omission of the alternative design renders the product not reasonably safe.”14 For AI agents in DeFi, that design is commercially deployed:
- Enclave isolation. Coinbase’s programmable wallet infrastructure manages private keys inside AWS Nitro Enclaves—encrypted and decrypted exclusively within the enclave, and isolated even from Coinbase’s own infrastructure.48
- Authority boundaries. Session caps, per-transaction limits, and KYT screening that automatically blocks high-risk interactions, enforced at the infrastructure layer.
- Decision logging. Every transaction decision recorded at execution—spoliation defense, regulatory audit trail, and governance evidence in one.
- Kill switches. Immediate halt capability, enforced below the application layer.
These controls establish the standard. A plaintiff suing a deployer whose agent had unrestricted wallet access can point to Coinbase’s architecture, OWASP’s guidance, and FINRA’s supervisory considerations—and ask why the defendant’s product lacked them.
Benavides v. Tesla—a $329 million jury verdict on design-defect, failure-to-warn, and punitive-damages claims, reduced to a $242,570,000 final judgment entered August 3, 2025 after the jury apportioned 33% of responsibility to Tesla—shows how fast design standards harden into verdicts.49 The Part 573 recall report Tesla filed with NHTSA in December 2023 conceded that “[i]n certain circumstances when Autosteer is engaged, the prominence and scope of the feature’s controls may not be sufficient to prevent driver misuse of the SAE Level 2 advanced driver-assistance feature.”50 Substitute “user” for “driver” and “AI agent” for “feature,” and the standard applies unchanged.
How to Comply Before Deploying an AI Agent in DeFi
Before Deployment
1. Registration analysis. Determine whether the agent’s activities trigger SEC, CFTC, or FinCEN registration. The token taxonomy means classification determines jurisdiction. Complete this analysis before the first transaction.
2. Authority boundaries. Enforce limits at the infrastructure layer—spending limits, contract allowlists, transaction caps—cryptographically enforced so even a compromised agent cannot exceed scope. Follow the OWASP “Least Agency” principle.51
3. Decision logging. Record every trade and transaction decision at execution time. Spoliation defense, audit trail, and governance evidence in one.
4. Kill switches. Halt capability, enforced at the infrastructure layer, tested before the agent goes live.
Near-Term Monitoring (Q4 2026 to Q1 2027)
- GENIUS Act effective date (earlier of January 18, 2027 or 120 days after final implementing rules; GENIUS Act § 20): AML program, CIP, and OFAC screening obligations for stablecoin transactions. The implementing rules are still proposals: Treasury’s issuance rules were proposed August 18, 2026, with comments due October 19, 2026,52 and FinCEN’s customer identification program rule for permitted issuers was proposed June 22, 2026, with comments closed August 21, 2026. The CIP proposal would define a permitted issuer’s “customer” to exclude “a person acquiring or redeeming a payment stablecoin from a means other than directly from or directly to the permitted payment stablecoin issuer,” which is where an agent buying stablecoins on a secondary market sits.53
- CFTC registration question for software providers: Chair Selig has said there has long been an open question whether software providers trigger the CFTC’s registration requirements, and that the Commission intends to address it head-on.32
- California’s Digital Financial Assets Law (Fin. Code § 3101 et seq.; licensing has been required since July 1, 2026) and Colorado’s automated decision-making technology law (S.B. 26-189, which repealed and reenacted C.R.S. § 6-1-1701 et seq.; it takes effect January 1, 2027 and applies to consequential decisions made on or after that date, reaching an AI agent only where its output “materially influences” a consequential decision, meaning the output “is a non-de minimis factor that is used in making” the decision and “affects the outcome”): state-level digital asset licensing and AI compliance obligations.54
- The AI LEAD Act (S. 2937): bipartisan federal bill classifying AI systems as “products” with federal design defect liability.55
- The SEC’s Innovation Exemption (order of September 17, 2026): temporary, conditional relief for tokenized-securities venues from the Exchange Act definition of “exchange,” and for liquidity providers in their permissioned automated-market-maker pools from the definition of “dealer,” limited to tokenized NMS stock and expiring five years after publication. An agent supplying liquidity in such a pool operates under those conditions; outside them, the dealer question is where it was.56
The Bottom Line
The deployer who builds safeguards now is building a legal defense. The deployer who ships without them is building a plaintiff’s case.
The tools exist. The standards are emerging. The case law is building. The only question is whether you design governance into your architecture before launch—or discover your obligations in an enforcement action.
For deployers evaluating managed infrastructure specifically, our KYA analysis of Claude Managed Agents maps how persistent sessions, MCP connectors, and bash execution create architectural regulatory triggers that self-hosted agents do not face.
Disclaimer: This article provides general information for educational purposes only and does not constitute legal advice. AI agent regulation and liability law are evolving rapidly. Consult qualified legal counsel for advice on your specific situation.
See our AI agent lawyer page, or contact us . When a loss has already happened, see our AI litigation attorney page.
Footnotes
-
Coinbase, “Agentic Wallets” (February 11, 2026), available at https://www.coinbase.com/developer-platform/discover/launches/agentic-wallets. ↩
-
Brian Armstrong (@brian_armstrong), X post (March 9, 2026), available at https://x.com/brian_armstrong/status/2031021867973194172. ↩
-
x402 transaction data from Sherlock, “x402 Explained: The HTTP 402 Payment Protocol for AI Agents, APIs, and Stablecoin Payments” (Mar. 19, 2026), available at https://sherlock.xyz/post/x402-explained-the-http-402-payment-protocol; Marco De Rossi et al., “ERC-8004: Trustless Agents [DRAFT],” Ethereum Improvement Proposals, no. 8004 (Aug. 2025), available at https://eips.ethereum.org/EIPS/eip-8004. ↩
-
Francisco Rodrigues, “Solana DeFi platform step finance hit by $27 million treasury hack as token price craters,” CoinDesk (Jan. 31, 2026), available at https://www.coindesk.com/business/2026/01/31/solana-based-defi-platform-step-finance-hit-by-usd30-million-treasury-hack-as-token-price-craters. ↩
-
Anthropic Frontier Red Team, “AI agents find $4.6M in blockchain smart contract exploits” (Dec. 1, 2025), available at https://www.anthropic.com/research/smart-contracts. ↩
-
MIT AI Agent Index (2025), available at https://aiagentindex.mit.edu/. ↩
-
Securities and Exchange Commission & Commodity Futures Trading Commission, “Application of the Federal Securities Laws to Certain Types of Crypto Assets and Certain Transactions Involving Crypto Assets,” Release Nos. 33-11412, 34-105020, 91 Fed. Reg. 13714 (March 17, 2026), available at https://www.sec.gov/files/rules/interp/2026/33-11412.pdf. ↩
-
Garcia v. Character Techs., Inc., 785 F. Supp. 3d 1157, 1180 (M.D. Fla. 2025) (order on motions to dismiss). ↩
-
Clare Duffy, “Character.AI and Google agree to settle lawsuits over teen mental health harms and suicides,” CNN (Jan. 7, 2026), available at https://www.cnn.com/2026/01/07/business/character-ai-google-settlement-teen-suicide. ↩
-
P.F., et al. (K.G.M.) v. Meta Platforms, et al. (Cal. Super. Ct., L.A. Cnty., Mar. 25, 2026) (verdict form—Meta); Crowell & Moring, “Landmark Verdicts Against Meta and YouTube Signal New Era of Social Media Platform Liability” (Mar. 30, 2026) ($3 million compensatory, apportioned $2.1 million to Meta and $900,000 to YouTube, plus $3 million punitive against both; nonunanimous verdict). ↩
-
State of New Mexico v. Meta Platforms, Inc. (N.M. Dist. Ct. Mar. 24, 2026) ($375 million in civil penalties on two Unfair Practices Act claims, at the statutory maximum of $5,000 per violation). ↩
-
Mobley v. Workday, Inc., 740 F. Supp. 3d 796, 806-08 (N.D. Cal. 2024) (order granting in part and denying in part motion to dismiss). ↩
-
Assem. Bill No. 316 (2025-2026 Reg. Sess.), ch. 672 (approved and filed Oct. 13, 2025) (adding Cal. Civ. Code § 1714.46), available at https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB316. ↩
-
Restatement (Third) of Torts: Products Liability § 2(b)-(c) & cmts. d, l, m, p (A.L.I. 1998). ↩ ↩2
-
Liriano v. Hobart Corp., 92 N.Y.2d 232, 240-41 (1998). ↩
-
OWASP, “Top 10 for Agentic Applications” (2026), available at https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/. ↩
-
15 U.S.C. § 80b-2(a)(11); id. § 80b-3(a). ↩
-
Securities and Exchange Commission, In re Wealthfront Advisers, LLC, Release No. IA-5086 (December 21, 2018), available at https://www.sec.gov/files/litigation/admin/2018/ia-5086.pdf. ↩
-
Securities and Exchange Commission, In re Charles Schwab & Co., Inc., Exchange Act Release No. 95087, Advisers Act Release No. 6047, Admin. Proc. File No. 3-20897 (June 13, 2022); see Press Release 2022-104 (June 13, 2022), available at https://www.sec.gov/newsroom/press-releases/2022-104. ↩
-
Securities and Exchange Commission, In re Delphia (USA) Inc. and In re Global Predictions, Inc., Release Nos. IA-6573 and IA-6574 (March 18, 2024), available at https://www.sec.gov/newsroom/press-releases/2024-36. ↩
-
Securities and Exchange Commission, SEC v. Saniger, No. 1:25-cv-02937 (S.D.N.Y. filed Apr. 9, 2025), Litigation Release No. 26282 (Apr. 11, 2025), available at https://www.sec.gov/enforcement-litigation/litigation-releases/lr-26282. ↩
-
Securities and Exchange Commission, Commission Interpretation Regarding Standard of Conduct for Investment Advisers, Release No. IA-5248 (June 5, 2019), available at https://www.sec.gov/rules-regulations/2019/06/ia-5248. ↩
-
Securities and Exchange Commission, Division of Examinations, Fiscal Year 2026 Examination Priorities (announced Nov. 17, 2025, SEC Press Release 2025-132), available at https://www.sec.gov/files/2026-exam-priorities.pdf. ↩
-
Securities and Exchange Commission, Further Definition of “As a Part of a Regular Business” in the Definition of Dealer and Government Securities Dealer in Connection with Certain Liquidity Providers, Exchange Act Release No. 34-99477, File No. S7-12-22, 89 Fed. Reg. 14938 (Feb. 29, 2024) (to be codified at 17 C.F.R. §§ 240.3a5-4(a)(1)(i), 240.3a44-2(a)(1)(i)), vacated, Nat’l Ass’n of Priv. Fund Managers v. SEC, No. 4:24-cv-00250-O, 2024 U.S. Dist. LEXIS 211895 (N.D. Tex. Nov. 21, 2024), and Crypto Freedom All. of Tex. v. SEC, No. 4:24-cv-00361-O, 2024 U.S. Dist. LEXIS 211901 (N.D. Tex. Nov. 21, 2024), available at https://www.sec.gov/files/rules/final/2024/34-99477.pdf. ↩
-
Securities and Exchange Commission, In re Knight Capital Americas LLC, Release No. 34-70694 (October 16, 2013), available at https://www.sec.gov/files/litigation/admin/2013/34-70694.pdf. ↩
-
United States v. Coscia, 866 F.3d 782 (7th Cir. 2017). ↩
-
Commodity Futures Trading Commission, Press Release No. 8260-20 (September 29, 2020), available at https://www.cftc.gov/PressRoom/PressReleases/8260-20. ↩
-
CFTC v. Ooki DAO, No. 3:22-cv-05416-WHO, Order Granting Motion for Default Judgment (N.D. Cal. June 8, 2023), ECF No. 76, at 7-8, 12-13, 14; Judgment, ECF No. 77 (June 8, 2023); see also Commodity Futures Trading Commission, “Statement of CFTC Division of Enforcement Director Ian McGinley on the Ooki DAO Litigation Victory,” Press Release No. 8715-23 (June 9, 2023), available at https://www.cftc.gov/PressRoom/PressReleases/8715-23. ↩
-
In re Universal Navigation Inc. d/b/a Uniswap Labs, CFTC Docket No. 24-25 (Sept. 4, 2024) (order instituting proceedings, making findings, and imposing remedial sanctions); see also Commodity Futures Trading Commission, “CFTC Issues Order Against Uniswap Labs for Offering Illegal Digital Asset Derivatives Trading,” Press Release No. 8961-24 (September 4, 2024), available at https://www.cftc.gov/PressRoom/PressReleases/8961-24. ↩
-
Regulation Automated Trading; Withdrawal, 85 Fed. Reg. 42,755 (July 15, 2020), available at https://www.federalregister.gov/documents/2020/07/15/2020-14383/regulation-automated-trading-withdrawal; Electronic Trading Risk Principles, 85 Fed. Reg. 42,761, 42,761 (July 15, 2020) (proposed rule) (proposing “three principles applicable to DCMs”). ↩
-
Olivier Acuna, “CFTC Chair Highlights Wide Crypto Agenda, Including Rules on DeFi, Prediction Markets,” CoinDesk (Mar. 10, 2026), available at https://www.coindesk.com/policy/2026/03/10/cftc-chair-highlights-wide-crypto-agenda-including-rules-on-defi-prediction-markets. ↩ ↩2
-
Financial Crimes Enforcement Network, Guidance FIN-2019-G001, “Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies” (May 9, 2019), available at https://www.fincen.gov/resources/statutes-regulations/guidance/application-fincens-regulations-certain-business-models. ↩
-
31 C.F.R. § 1020.220 (2026); 31 C.F.R. § 1022.210(d)(1)(i)(A) (2025). ↩
-
31 C.F.R. § 1010.410(f) (2026). ↩
-
GENIUS Act of 2025 (Guiding and Establishing National Innovation for U.S. Stablecoins Act), Pub. L. No. 119-27, § 4(a)(5), 139 Stat. 419 (July 18, 2025), available at https://www.congress.gov/119/plaws/publ27/PLAW-119publ27.pdf. ↩
-
GENIUS Act of 2025, Pub. L. No. 119-27, § 20 (“This Act, and the amendments made by this Act, shall take effect on the earlier of (1) the date that is 18 months after the date of enactment of this Act; or (2) the date that is 120 days after the date on which the primary Federal payment stablecoin regulators issue any final regulations implementing this Act.”). ↩
-
Van Loon v. Department of the Treasury, 122 F.4th 549 (5th Cir. 2024) (holding Tornado Cash’s immutable smart contracts are not “property” under IEEPA and that OFAC “exceeded its statutory authority”; the court recited the plaintiffs’ principal argument that the target was Tornado Cash’s “open-source, self-executing software,” “as opposed to the rogue persons and entities who abuse it,” and expressly took no position on whether Tornado Cash as an entity has an interest in the immutable smart contracts), available at https://www.ca5.uscourts.gov/opinions/pub/23/23-50669-CV0.pdf. OFAC’s civil-penalty strict-liability standard derives from IEEPA itself, 50 U.S.C. § 1705(b). ↩
-
NIST NCCoE, “Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization” (February 5, 2026), available at https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd; Google, “Agent Payments Protocol (AP2)” (September 2025), available at https://ap2-protocol.org/. ↩
-
Chante Eliaszadeh, “Not an Agent. Not a Defense: Seven Doctrines That Already Hold AI Deployers Liable,” Astraea Counsel (March 18, 2026). ↩
-
Ian Ayres & Jack M. Balkin, “The Law of AI is the Law of Risky Agents Without Intentions,” University of Chicago Law Review Online (Nov. 27, 2024), available at https://lawreview.uchicago.edu/online-archive/law-ai-law-risky-agents-without-intentions. ↩
-
See Maarten Herbosch, “Liability for AI Agents,” 26 North Carolina Journal of Law & Technology 391 (2025), available at https://scholarship.law.unc.edu/ncjolt/vol26/iss3/4/. ↩
-
FINRA, 2026 Annual Regulatory Oversight Report, “GenAI: Continuing and Emerging Trends” (Emerging Trends in GenAI: Agents), available at https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai. ↩
-
Commodity Futures Trading Commission, Technology Advisory Committee, “Responsible AI in Financial Markets: Opportunities, Risks & Recommendations,” Press Release No. 8905-24 (May 2, 2024), available at https://www.cftc.gov/PressRoom/PressReleases/8905-24. ↩
-
U.S. Department of the Treasury, “Treasury Announces Public-Private Initiative to Strengthen Cybersecurity and Risk Management for AI” (Feb. 18, 2026), available at https://home.treasury.gov/news/press-releases/sb0395. ↩
-
See supra note 16. ↩
-
NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023), available at https://www.nist.gov/itl/ai-risk-management-framework; for the regulators pointing to it, see supra notes 42-43. ↩
-
AWS, “Powering Programmable Crypto Wallets at Coinbase with AWS Nitro Enclaves” (Aug. 14, 2025), available at https://aws.amazon.com/blogs/web3/powering-programmable-crypto-wallets-at-coinbase-with-aws-nitro-enclaves/. ↩
-
Benavides v. Tesla, Inc., No. 1:21-cv-21940-BB (S.D. Fla. Aug. 3, 2025) (final judgment of $242,570,000 entered on a $329 million jury verdict after the jury apportioned 33% of responsibility to Tesla), renewed motion for judgment as a matter of law or new trial denied, ECF No. 612 (S.D. Fla. Feb. 19, 2026). ↩
-
Tesla, Inc., Part 573 Safety Recall Report, NHTSA Recall No. 23V-838 (Manufacturer Recall No. SB-23-00-008) (submitted Dec. 12, 2023). ↩
-
See supra note 16. ↩
-
Department of the Treasury, GENIUS Act Regulations on Payment Stablecoin Issuance, Offer, and Sale, 91 Fed. Reg. 53368 (proposed Aug. 18, 2026) (comments due Oct. 19, 2026), available at https://www.govinfo.gov/content/pkg/FR-2026-08-18/pdf/2026-16796.pdf. ↩
-
FinCEN, OCC, FDIC & NCUA, Permitted Payment Stablecoin Issuer Customer Identification Program, 91 Fed. Reg. 37234 (proposed June 22, 2026) (comments closed Aug. 21, 2026) (proposed 31 C.F.R. § 1033.220, definition of “customer”), available at https://www.govinfo.gov/content/pkg/FR-2026-06-22/pdf/2026-12460.pdf. ↩
-
S.B. 26-189 (Colo. 2026), § 1 (repealing and reenacting C.R.S. §§ 6-1-1701 et seq.; “materially influence” defined at § 6-1-1701(13)), § 5 (effective January 1, 2027; applies to consequential decisions made on or after that date), available at https://leg.colorado.gov/bill_files/116489/download. ↩
-
AI LEAD Act, S. 2937, 119th Congress (September 29, 2025), available at https://www.congress.gov/bill/119th-congress/senate-bill/2937/text. ↩
-
SEC Press Release 2026-90, SEC Issues “Innovation Exemption” to Facilitate the Trading of Tokenized NMS Stock and Request for Comment (Sept. 17, 2026) (order, Exchange Act Release No. 34-106402), available at https://www.sec.gov/newsroom/press-releases/2026-90-sec-issues-innovation-exemption-facilitate-trading-tokenized-nms-stock-request-comment. ↩