Skip to main content
Mubienclarity for what comes next
← Agents that spend
C1September 2026

Write down what the agent is allowed to buy

What did the person actually agree to, and can a machine check it before the money moves?

Where this sits: Permission is recorded. What the agent may buy, from whom, for how long, and what to do when the exact thing is unavailable.

Claims last checked against sources on 16 September 2026. Protocols and guidance in this area change quickly, so treat anything here as accurate as of that date rather than indefinitely. The primary source registry shows the main specifications and payment programs used across the framework.

What goes wrong

Someone asks an agent to book a flight to Toronto. It books business class for $4,200. They meant economy.

The airline took the money in good faith and it is gone. Now the argument starts, and it is hard to settle, because nothing wrote down what the buyer agreed to. There is an instruction at one end, a payment at the other, and nothing in between recording what the agent was allowed to do.

There is a worse version of this, and it is already happening. Security researchers at Palo Alto's Unit 42 and at Forcepoint have each found hidden instructions planted on live websites: text that a person scrolling the page never sees, but that an agent reads and treats as direction. Forcepoint's April 2026 research includes payloads aimed at taking money.

Applied to shopping, the attack is easy to picture. Hidden text tells the agent to add something the buyer never asked for, and if the screen shows a total rather than a full basket, nobody notices until a statement arrives. I have not found a documented case of exactly that, so treat it as a predictable next step rather than something that has already happened.

The law already has a name for this

It is an old problem in new clothes. When one person acts for another, the law calls them an agent, and it calls the person they act for the . It has spent centuries working out who is responsible for what.

Whether an AI counts as the agent in that legal sense is not settled — it might be the software, it might be the company that built it. Nothing here assumes an answer. But the questions agency law asks are the right questions, and there are three of them.

First: what was the agent actually allowed to do? can be spelled out or reasonably implied, so a vague instruction does not leave an agent with nothing to work from. It also does not hand over a blank cheque. “Buy me a laptop” is not permission to buy a Ferrari, and the gap between the two is not filled by whatever the agent guesses you would have wanted.

Second: can the shop rely on it? This is . If a seller reasonably believed the agent had permission, and that belief traces back to something the buyer did, the seller may be protected. But that is the hard part, not the easy part. Does handing an agent your card details tell a merchant it can buy anything? Does using a particular platform? Nobody has answered that, and these disputes will have to.

Third: what if you find out later and say nothing? This is , and staying quiet can count as agreeing after the fact, though not automatically. It usually turns on whether you knew what had happened, and on whether a reasonable person would read your silence as approval. That matters a great deal when the first you hear of a purchase is a statement three weeks later.

What to build

Write the permission down before the agent goes anywhere, in a form a machine can check, and then check it again at the moment money actually moves.

At a minimum it should say: the most that can be spent in total, what kinds of things or which shops are in scope, how long the permission lasts, whether it is good for one purchase or many, and what the agent should do when the exact thing is unavailable.

That last one matters more than it sounds. Substitution is where a helpful agent turns into an unauthorised purchase. Out of stock, so it bought the next size up. Sold out, so it bought a similar model at twice the price. Every one of those is a decision the buyer never made.

Build the permission from what the buyer said, and then have the buyer confirm it. An agent that works out its own permission from a vague sentence has not been authorised — it has guessed, and the guess is what gets argued about later.

The Agentic Commerce Protocol, the open specification for agent checkout, already limits the to one use, a maximum amount and an expiry, based on the checkout the buyer has just approved. That is the right instinct, and more than critics usually give it credit for. What the specification does not describe is what the agent was allowed to go looking for before any checkout existed — which is a boundary on its scope rather than a defect, because the document is about finishing a purchase and it does that job well.

What proves it worked

Two records, and without both of them you cannot answer the question a dispute will ask.

One: what the buyer confirmed, timestamped and unchangeable, showing their decision rather than the agent's interpretation of it. Two: proof that the purchase was checked against that permission before it went through, along with what the check returned.

The test is not whether you can explain the purchase today. It is whether somebody who does not trust you can work out what happened eleven months from now, from your records, without your help.

What the rules actually say

Less than people claim, and pretending otherwise is how this kind of writing loses its readers.

The EU AI Act's transparency rules under Article 50 have applied since 2 August 2026, but they are about whether a person knows they are dealing with an AI, not about what it may buy. The AI Omnibus came into force on 27 July 2026 and moved the high-risk rules for Annex III systems — the Act's list of sensitive uses, covering things like employment, credit and essential services — to 2 December 2027. That regime is not a general agentic-commerce regime, and it does not automatically cover ordinary shopping agents.

Card network rules on authorisation, disputes and chargebacks still decide who absorbs a loss, and they are the most immediately relevant rules here. The networks are also not standing still: Visa, Mastercard and others are building controls specific to agents — who the agent represents, what it may do, under what conditions — and in September 2026 Visa, Mastercard and Ant International announced work towards a shared agent-trust framework.

Worth noting against my own argument: the card networks are already building this. Mastercard's Agent Pay binds a token at provisioning to a specific agent and to the cardholder's limits, covering spend ceilings, merchant categories, time windows and recurring rules. That is close to the structure described above, and it does not weaken the case for recording permission. It is the clearest evidence available that the gap is real, and it is covered properly in C3.

I am not aware of a general legal requirement to record permission the way this describes. Agency principles and card network rules will settle these arguments long before any dedicated law does, which is a reason to build it now rather than wait to be told.

Written in a personal capacity, from public sources. It is not legal advice and does not create any professional relationship. Where a specification, a piece of research or a set of guidance is named, it is named so a reader can go and check it. Nothing here is a judgement about any company's conduct or compliance.