news

AI Agent Authorization: The 2026 Liability Gap

August 27, 2026

AI Agent Authorization: The 2026 Liability Gap

An AI agent that exceeds its instructions leaves accurate records at every company it touched — and no single record proving what you authorized. The AI AGENT Act, introduced on July 21, 2026, would require agents to log their actions. It never says who pays for the mistake.

TL;DR

Sen. Mark Warner (D-VA) introduced S.5051, the AI AGENT Act of 2026, on July 21, 2026.12 It would give you the right to designate your own agent to act for you on any online platform with more than 50 million US customers — provided that agent's provider has registered with the FTC first.1

It also requires every "custodial user agent" to maintain real-time records of actions taken on your behalf.1

What it does not do is allocate the loss. When an agent buys something you told it not to buy, the bill hands that question to an interagency working group and asks it to develop proposals.1

Industry reached the same wall first. AP2 — Google's protocol, donated to the FIDO Alliance in April 2026 — along with Mastercard's Verifiable Intent and FIDO's new agentic working groups, all produce evidence of authorization.345 None of them decides who eats the charge.

One company did put a concrete answer on the table — and it was a card issuer, not a legislature.6

What You'll Learn

  • What S.5051 actually requires, and the compliance clock that starts on enactment
  • Why the bill's definition of "custodial user agent provider" may cover you personally
  • Where AP2, Verifiable Intent, FIDO, and OpenID's AuthZEN each stop short
  • Why NIST's agent identity project explicitly deferred the consumer case
  • How Regulation E and Regulation Z treat a purchase your agent made with your credentials
  • What American Express did in April that nobody legislated

The record that does not exist

Start with the scenario that put this story back in the news.

You tell an agent to find a shirt under $30 and not buy it. The agent finds one and orders it anyway.

You dispute the charge. The retailer shows the order came through your account. The agent provider shows your instruction not to buy. The payment processor shows the charge cleared.

Every record is accurate. None of them links the charge to the task you actually gave.

That framing comes from Aashis Luitel, associate teaching professor of artificial intelligence at the University of the Cumberlands, writing for The Conversation and republished by Fortune on August 24, 2026.7

His point is not that the evidence is missing. It is that the evidence does not travel. Each company can verify only the slice it sees, and no participant holds a record that answers the question a dispute actually turns on: did this agent, acting for this person, stay inside the limits of this task?

What the AI AGENT Act requires — and what it leaves out

Warner released a discussion draft on June 29, 2026 — explicitly to gather feedback "before it is formally introduced" — then introduced the formal bill three weeks later.81

S.5051 was read twice and referred to the Senate Committee on Commerce, Science, and Transportation on July 21. As of August 27, 2026, that referral is still the bill's latest recorded action.2 The committee's most recent markup, on August 5, took up five kids' online-safety and AI bills; S.5051 was not among them.9

The bill defines a custodial user agent as "a software-based agent that is expressly authorized by a user to interact with a large online platform provider on that user's behalf in a transparent, documented, scope-limited, and revocable manner."1

A large online platform is one with more than 50,000,000 US customers or subscribers in any calendar month during the preceding 12 months.1

Here is what starts running the day it would take effect.

Deadline after enactmentWho actsWhat they must do
120 daysLarge online platformsDisclose complete interface documentation to competing agent providers (source code excluded)1
180 daysFTCEstablish rules for verifying that an agent's access request is valid, and for revoking a prior delegation1
180 daysNISTIdentify open protocols — or publish model standards — for six classes of online service, one of which is verifiable delegation1
180 daysFTC + 8 agenciesConvene an interagency working group on agent-caused harms1
1 yearFTCPromulgate implementing regulations, with CFPB, FDIC, and OCC1

The NIST mandate is the technically interesting one. Alongside messaging, social media, e-commerce, personal finance, and AI services, Section 4(c)(6) asks for standards covering scope-limited and revocable delegation credentials, verification of agent identity and registration status, "real-time communication and effectuation of revocation," and "the creation of auditable records of actions taken by custodial user agents on behalf of users."1

That is close to a complete specification for proving delegation. It is also, notably, a records mandate rather than a liability rule.

The duties in Section 3(g) follow the same pattern. An agent must safeguard user data, must not act in ways inconsistent with the user's directions or reasonable expectations, must not use the data for advertising or profiling, and must "maintain real-time records of actions taken on the user's behalf" and hand them over on request — with one carve-out, for records the user previously told the agent to delete.1

Those duties cannot be waived by contract, terms of service, or any form of user consent — a meaningful provision, given how much of today's agent risk is disclaimed away in a EULA.1

Section 3(g)(1)(F) is the sub-delegation rule: an agent cannot pass its authority to another entity's agent or AI system unless the user expressly, specifically, and revocably authorized it, and the recipient takes on the same duties.1 Anyone building multi-agent handoffs should read that clause twice.

But search the bill for who bears the cost of a bad transaction and you land on Section 4(g), which directs the FTC, CFPB, FDIC, OCC, Treasury, DHS, Commerce, DOJ, and SEC to form a working group "for the purpose of developing proposals to prevent harms to businesses and the Government resulting from custodial user agents undertaking actions on behalf of a principal as a result of fraud, misuse, or genuine mistake."1

Proposals. Not a rule. And the harms named are those to businesses and the government — the consumer's $30 shirt is not the subject of that sentence.

The registration clause that may cover you

One definition in Section 2 deserves more attention than it has gotten.

A "custodial user agent provider" means any entity that operates or offers one or more custodial user agents — and includes a user who operates a custodial user agent on the user's own behalf and not on behalf of any other user.1

Read that against Section 3(d)(1): a custodial user agent provider "shall register with the Commission as a condition of, and prior to, any custodial user agent operated or offered by that provider accessing an interface" covered by the Act.1

On its face, that means the hobbyist running a self-hosted agent against a covered platform is a provider who must register with the FTC first.

The bill softens this. The Commission "may establish uniform terms and scope of service, by which a custodial user agent provider may register through self-attestation," and the FTC or a recognized certification body has 180 days from submission to evaluate a registration.1 Self-attestation would make solo registration a form, not an audit.

Whether that is how it plays out depends entirely on rulemaking that has not started, for a bill that has not moved out of committee. It is worth watching if you build agents in the open.

Where the standards bodies stopped

The legislative timeline is the tail end of a much faster industry one. Every entry below strengthens the record of what a user authorized. Only one of them — the odd one out, and not a standard — also says who absorbs the cost when the record shows the agent got it wrong.

DateWhat shippedWhat it establishes
Sept 16, 2025Google announces AP2, capturing purchases as Mandates — "tamper-proof, cryptographically-signed digital contracts" signed by verifiable credentials10What the user asked for, what the agent assembled, and the payment linked to it
Mar 5, 2026Mastercard introduces Verifiable Intent, co-developed with Google4A "tamper-resistant record of what a user authorized when an AI agent acts on their behalf"
Apr 14, 2026American Express launches the ACE Developer Kit plus Agent Purchase Protection6Registered agent identity, logged purchase intent — and a commitment to credit the cardmember when a registered agent errs
Apr 28, 2026Google donates AP2 to the FIDO Alliance and ships AP2 v0.2 with "Human Not Present" payments3Pre-authorized instructions executed with no human in the loop
Apr 28, 2026FIDO forms an Agentic Authentication Technical Working Group5Verifiable user instructions, agent authentication, trusted delegation
Jun 15, 2026OpenID Foundation's AuthZEN WG approves the AARP and COAZ drafts11What a policy needs before it can authorize an agent action
Jul 21, 2026S.5051 introduced12Real-time records; NIST standards for verifiable delegation

Two of those entries deserve a closer look.

AP2 v0.2 pushed further into unattended territory. The same April 28 release that moved AP2 to neutral governance shipped what Google called "critical updates for autonomous transactions," including "Human Not Present" payments that let agents "securely execute payments autonomously — like securing and purchasing limited-run tickets the moment they're on sale — based on pre-authorized user instructions."3

The delegated, human-not-present flow was not new in itself; AP2's launch post described signing an Intent Mandate upfront for a task like "Buy concert tickets the moment they go on sale."10 What v0.2 added was fuller support for it. Either way, the direction of travel is more transactions whose only evidence of intent is a mandate signed before the fact.

AuthZEN is solving the adjacent problem well. The AARP draft standardizes how a system says "not yet, and here is what is required" — approval, consent, delegated authority, an attestation — so an agent can park a request and resume once a human clears it.11 The companion COAZ profile targets Model Context Protocol tools, letting them expose the authorization checks required to call a tool.11

That is the human-in-the-loop primitive agent builders have been hand-rolling. It still governs whether an action happens, not who pays when the wrong one does.

To be fair to AP2, accountability was in scope from the start. Google's launch post named it as one of three questions the protocol addresses — "Determining accountability if a fraudulent or incorrect transaction occurs" — and described the intent-to-cart-to-payment sequence as creating "a non-repudiable audit trail" that provides "a clear foundation for accountability."10

A foundation for accountability is not an allocation of it. Luitel's assessment applies to the whole column: AP2 "does not decide who bears the loss or specify how long each company must keep that evidence and how it can be retrieved later."7

Knowing exactly what happened tells you who was at fault. It does not tell you whose balance sheet absorbs the charge while that gets sorted out.

NIST deferred exactly the case consumers are in

The AI AGENT Act would put NIST on a 180-day clock for verifiable-delegation standards. NIST's own agent identity work is already running — and its scope is narrower than the bill's.

The National Cybersecurity Center of Excellence published a draft concept paper, Accelerating the Adoption of Software and AI Agent Identity and Authorization, in February 2026, authored by Harold Booth, Bill Fisher, Ryan Galluzzo, and Joshua Roberts.12 Its comment period ran from February 5 to April 2, 2026, and the project is now listed as "Reviewing Comments."13

The paper asks the right questions. "How do we handle delegation of authority for 'on behalf of' scenarios?" "How do we ensure non-repudiation for agent actions and binding back to human authorization?"12

Then it draws a boundary:

The focus of the project will be on enterprise use-cases where greater control and visibility can be maintained over agents and the systems they access. The challenge of identifying and managing access for external agents from untrusted sources will not be addressed under this initial effort, but use-cases focused on public facing or individual agents could be addressed in future iterations of the project.12

That is a defensible scoping decision for a demonstration project. It is also, precisely, the deferral of the case where an agent crosses three companies that have never met.

For what it is worth, the standards NIST names as candidates are already familiar to agent builders: MCP, OAuth 2.0/2.1 and its extensions, OpenID Connect, SPIFFE/SPIRE, SCIM, and NGAC.12 The building blocks exist. The cross-boundary assembly does not.

The old rules were written for people

Here is the part that makes the gap concrete today, before any of this is law. This is general information about published regulations, not legal advice.

Debit and other electronic fund transfers. Regulation E defines an "unauthorized electronic fund transfer" as one "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit."14

Then comes the exception. The term does not include a transfer initiated "by a person who was furnished the access device to the consumer's account by the consumer, unless the consumer has notified the financial institution that transfers by that person are no longer authorized."14

The official interpretation is blunter still: "If a consumer furnishes an access device and grants authority to make transfers to a person (such as a family member or co-worker) who exceeds the authority given, the consumer is fully liable for the transfers unless the consumer has notified the financial institution that transfers by that person are no longer authorized."14

Note where the escape hatch is. Liability stops when you tell the bank the delegation is over — not when you tell the agent.

Whether an AI agent — or the company operating it — is a "person" for this purpose is untested. Regulation E defines "person" as "a natural person or an organization, including a corporation, government agency, estate, trust, partnership, proprietorship, cooperative, or association."14 Software is not on that list. The provider behind it is an organization.

Credit cards. Regulation Z caps cardholder liability for unauthorized use at the lesser of $50 or the amount obtained before the issuer is notified.15 But "unauthorized use" means the use of a credit card "by a person, other than the cardholder, who does not have actual, implied, or apparent authority for such use, and from which the cardholder receives no benefit," and whether such authority exists "must be determined under state or other applicable law."15

The official interpretation then closes the loop the same way Regulation E does: "If a cardholder furnishes a credit card and grants authority to make credit transactions to a person (such as a family member or coworker) who exceeds the authority given, the cardholder is liable for the transaction(s) unless the cardholder has notified the creditor that use of the credit card by that person is no longer authorized."15

Substitute an agent for the coworker and the $50 cap stops doing the work most people assume it does — if an agent, or its provider, counts as a "person" who was granted authority.

Neither framework was drafted with autonomous software in mind, and no published CFPB guidance squarely applies either one to an AI agent as of August 2026. That ambiguity is the actual state of play — not a gap the AI AGENT Act closes.

One issuer put money behind the answer

On April 14, 2026, American Express launched its Agentic Commerce Experiences (ACE) Developer Kit and, alongside it, Agent Purchase Protection.6

The kit has five components: agent registration, account enablement, purchase intent, passing tokenized payment credentials, and an optional cart-context handoff from the merchant.6 Supporting partners at launch included OpenAI, Google, Microsoft, Stripe, PayPal, Adyen, Cloudflare, Delta, Expedia, and Hilton.6

The protection is the part the record-keeping standards leave out. Luke Gebb, Amex's EVP and global head of innovation, described the case directly:

If the merchant has made no error and the cardmember has made no error, but the agent has made the error, that's a new paradigm in agentic commerce today and one that has not been figured out — how to deal with that.6

Amex's answer: "As long as we're dealing with a registered agent who has used our developer kit to come in and register and they've shared the customer intent … then we will stand behind that transaction and credit the consumer so they're not out of pocket."6

Gebb's framing of why is worth quoting too, because it explains the structural difference between a protocol and a guarantee: "no one has yet brought the issuer into the equation (or the bank). That's where, when you start to have the issuer in the equation, you start to have legitimate financial liability for transactions."6

Note what this is and is not. It is one closed-loop network, covering agents registered with that network, that shared intent through that network's kit. It is a commercial commitment, not a legal standard, and it is the network's own characterization of its scope. Other issuers may match it; as of this writing, no comparable federal rule requires them to.

What this means if you are building agents

Four things follow, none of which require the bill to pass.

Log intent, not just actions. Agent observability tends to center on tool calls and outputs. What a dispute needs is the user's original instruction, the structured constraints derived from it, and evidence the user saw and approved that structured version before the run started. Store all three, timestamped and immutable.

Carry a correlation ID across every hop. Luitel's proposal is a task reference — unique to one job, carrying no account number or name, short-lived, and present in every participating company's record.7 Engineers already have the shape of this in W3C Trace Context. Treat cross-company traceability as a product requirement, not an ops nicety.

Build the approval gate now. AuthZEN's AARP gives you a standard pattern for "policy cannot authorize this yet, here is what it needs" — and a way to hand off, wait for a human, and re-evaluate rather than route around the denial.11

If you have already written your own approval plumbing, the draft is worth reading before you harden it. The same logic applies to how you scope tool access through MCP's enterprise authorization model and how you give the agent itself a verifiable identity.

Do not assume the settlement layer protects your user. The agent payment standards race is still unsettled, and the open protocols in it produce evidence rather than recourse. Build spending caps, hard stops on irreversible actions, and confirmation prompts as your own layer — the same defensive posture that applies to verifying which agents can reach your services at all.

The bottom line

The agent authorization stack picked up most of its missing pieces between March and July of this year: a tamper-resistant intent record in Verifiable Intent, neutral governance and a new working group at FIDO, an approval-prerequisite standard in AuthZEN, and a legislative mandate for NIST to define verifiable delegation — all on top of AP2's signed mandates from September 2025.

Every one of those produces better evidence. Not one of them says who pays.

That is not an oversight in any single effort — it is the boundary where standards bodies stop and liability regimes begin. The AI AGENT Act could have crossed it and chose a working group instead. NIST's demonstration project explicitly deferred the consumer case. The clearest concrete answer so far came from a card issuer with a closed loop and a balance sheet.

If you ship agents that spend money, act on the assumption that the recourse layer does not exist yet. Log the user's instruction alongside the agent's actions, carry a task reference across every boundary you cross, gate irreversible actions behind a human, and cap what an unattended run can do. Those are your controls to build, and for now they are the only ones you can count on.

References

Footnotes

  1. S. 5051, AI AGENT Act of 2026 — bill text as introduced — U.S. Senate, July 21, 2026. Source for the short and official titles; the Section 2 definitions of "custodial user agent," "custodial user agent provider," and "large online platform" (>50,000,000 US customers or subscribers in any calendar month during the preceding 12-month period); Section 3(d) FTC registration, self-attestation, and 180-day evaluation; Section 3(d)(4) recognized certification bodies; Section 3(g) duties, including the real-time records requirement, the sub-delegation limit at 3(g)(1)(F), and the non-waiver clause at 3(g)(3); Section 3(h)(5)(A) 120-day interface documentation deadline; Section 4(a) one-year FTC rulemaking with CFPB, FDIC, and OCC; Section 4(b) and 4(c) 180-day deadlines, including the verifiable-delegation standards at 4(c)(6); and Section 4(g) interagency working group. 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24

  2. S.5051 — 119th Congress (2025–2026): AI AGENT Act of 2026, bill status — Congressional Research Service / Library of Congress, accessed August 27, 2026. Source for the July 21, 2026 introduction date, sponsor Sen. Mark R. Warner [D-VA], referral to the Committee on Commerce, Science, and Transportation, and the absence of any later recorded action. The corresponding page is on congress.gov. 2 3 4

  3. We're donating Agent Payments Protocol to the FIDO Alliance to support the future of secure, agentic payments — Stavan Parikh, VP/GM Payments, Google, April 28, 2026. Source for the FIDO donation, the AP2 v0.2 GitHub release, the "Human Not Present" payments quote, and Verifiable Intent being co-developed with Mastercard and also donated to FIDO. 2 3

  4. When AI starts buying for you, trust becomes the product — Pablo Fourez, Chief Digital Officer, Mastercard, March 5, 2026. Source for Verifiable Intent's introduction, the "tamper-resistant record of what a user authorized" description, its use of Selective Disclosure (RFC 9901), and the open-sourced specification and reference implementation. 2

  5. FIDO Alliance to Develop Standards for Trusted AI Agent Interactions — FIDO Alliance, April 28, 2026. Source for the Agentic Authentication Technical Working Group's formation, the three focus areas (Verifiable User Instructions, Agent Authentication, Trusted Delegation for Commerce), the working group chairs, and the Google and Mastercard contributions. 2

  6. American Express launches developer kit, purchase protection for agentic commerce — Abbas Haleem, Digital Commerce 360, April 14, 2026. Source for the April 14 launch date, the five ACE Developer Kit components, the supporting-partner list, and all quotes from Luke Gebb, EVP and global head of innovation at American Express. 2 3 4 5 6 7 8

  7. Google can track exactly how your agent spends your money — but it's no help when it buys something you didn't approve — Aashis Luitel and The Conversation, Fortune, August 24, 2026. Republished from The Conversation. Source for the shirt scenario, the task-reference proposal and its analogy to W3C Trace Context, the author's affiliation (associate teaching professor of artificial intelligence, University of the Cumberlands), and the assessment that AP2 "does not decide who bears the loss or specify how long each company must keep that evidence and how it can be retrieved later." 2 3 4

  8. Warner Unveils Discussion Draft of Legislation to Create Innovative Market for Secure Artificial Intelligence Agents — Office of Sen. Mark R. Warner, June 29, 2026. Source for the discussion-draft release date and Warner's stated intent to "hear from stakeholders, experts, and the public so we can strengthen the legislation before it is formally introduced." See also CyberScoop's same-day coverage by Derek B. Johnson.

  9. Executive Session 24 — U.S. Senate Committee on Commerce, Science, and Transportation, markup held August 5, 2026. The published legislative agenda lists S. 737 (SCREEN Act), S. 1748 (Kids Online Safety Act), S. 4199 (Youth AI Privacy Act), S. 4407 (CHATBOT Act), and S. 5171 (Children's Artificial Intelligence Toy Safety Act of 2026). S. 5051 does not appear on it.

  10. Powering AI commerce with the new Agent Payments Protocol (AP2) — Stavan Parikh and Rao Surapaneni, Google Cloud, September 16, 2025. Source for AP2's launch date; the description of Mandates as "tamper-proof, cryptographically-signed digital contracts" that "are signed by verifiable credentials (VCs)"; the Intent Mandate and Cart Mandate flows for human-present and human-not-present purchases, including the "Buy concert tickets the moment they go on sale" example; and the three questions AP2 addresses (authorization, authenticity, accountability), including "Determining accountability if a fraudulent or incorrect transaction occurs" and the "non-repudiable audit trail… clear foundation for accountability" framing. 2 3 4

  11. OpenID Foundation advances authorization for the agent era with new AuthZEN Working Group Drafts — OpenID Foundation, June 15, 2026. Source for the approval of the AuthZEN Access Request and Approval Profile (AARP) and the AuthZEN Profile for Model Context Protocol Tool Authorization (COAZ) as Working Group Drafts, and for the "not yet, and here is what is required" framing. 2 3 4

  12. Accelerating the Adoption of Software and AI Agent Identity and Authorization — Concept Paper — Harold Booth, Bill Fisher, Ryan Galluzzo, and Joshua Roberts, NIST, draft, February 2026. Source for the February 5 – April 2, 2026 comment period, the delegation and non-repudiation questions posed to reviewers, the enterprise-scope quotation excluding external agents from untrusted sources, and the candidate standards list (MCP, OAuth 2.0/2.1, OpenID Connect, SPIFFE/SPIRE, SCIM, NGAC). 2 3 4

  13. Software and AI Agent Identity and Authorization — NIST National Cybersecurity Center of Excellence, accessed August 27, 2026. Source for the project's current status ("Reviewing Comments") and the closed comment period.

  14. 12 CFR § 1005.2 — Definitions (Regulation E) — Consumer Financial Protection Bureau, current version accessed August 27, 2026. Source for the § 1005.2(m) definition of "unauthorized electronic fund transfer" and its (m)(1) exception, official interpretation comment 2(m)-2 on furnished access devices, and the § 1005.2(j) definition of "person." 2 3 4 5

  15. 12 CFR § 1026.12 — Special credit card provisions (Regulation Z) — Consumer Financial Protection Bureau, accessed August 27, 2026. Source for the § 1026.12(b)(1)(i) definition of "unauthorized use," the § 1026.12(b)(1)(ii) liability limit of the lesser of $50 or the amount obtained before notification, official interpretation comment 12(b)(1)(i)-1 ("Whether such authority exists must be determined under state or other applicable law"), and comment 12(b)(1)(i)-3 on implied or apparent authority when a cardholder furnishes a card to a person who then exceeds the authority given. 2 3 4

Frequently Asked Questions

No. S.5051 was introduced on July 21, 2026 and referred to the Senate Committee on Commerce, Science, and Transportation. As of August 27, 2026, that referral is still its latest recorded action. 2