Back to BlogLaw & Compliance

The FTC’s Agent Liability Doctrine: Why Developers Own Every Transaction

5 min read

For the past two years, I've watched founders build AI agents with a quiet assumption baked into their term sheets and their product roadmaps: that autonomy creates distance. The theory was simple and, frankly, seductive. If an AI agent independently negotiates a price, books a hotel, cancels a subscription, or executes a trade, the developer who built it is merely the architect of a system, not the actor behind a transaction. The agent did it. Not us.

That theory is dead. The Federal Trade Commission's enforcement posture over the last several years, applying its longstanding Section 5 authority over unfair and deceptive practices to AI-driven commerce, has made clear that there is no meaningful legal distinction between a company that deceives consumers directly and a company that deploys software to do it on their behalf. The FTC has repeatedly signaled, through enforcement actions against AI-enabled business automation tools and through public guidance on chatbots and automated decision systems, that it does not recognize an 'autonomous actor' defense. If your agent transacts, you transact. If your agent misrepresents, you misrepresent.

The Collapse of the Autonomous Actor Defense

The legal theory founders wanted to rely on was borrowed, often loosely, from product liability law: build a good tool, disclaim the outcomes, and let the user or the market absorb the risk of misuse. That framework never fit AI agents cleanly, and the FTC has made sure it doesn't fit at all. Agents that initiate payments, modify contracts, or make representations to consumers are not passive tools in the way a hammer or a spreadsheet is passive. They are acting with a degree of delegated authority that the law has a name for, and that name is agency.

Under basic agency law, a principal is responsible for the acts of an agent performed within the scope of actual or apparent authority. The FTC has simply applied this centuries-old doctrine to software.

This is the crux of what I'd call the FTC's agent liability doctrine, even though it isn't formally codified as a single rule. It's an accumulation of enforcement posture, public statements, and case outcomes that collectively establish one proposition: the developer or deploying company is the principal, the AI system is the agent, and the company owns the consequences of every transaction the agent executes, regardless of how autonomous the marketing materials claim it to be.

Why This Matters More for Payments Than Any Other Function

Founders building agents that touch money, subscriptions, refunds, checkout flows, or financial commitments are in the most exposed position. The FTC has been explicit that unauthorized charges, deceptive billing practices, and dark-pattern-style commitments are enforcement priorities, and agentic commerce sits squarely in that crosshair. An agent that upsells a customer without clear consent, auto-renews a service without adequate disclosure, or completes a purchase the user didn't fully authorize is not a technical bug from the FTC's perspective. It's a Section 5 violation with your company's name on it.

The mistake I see repeatedly in founder circles is treating this as a compliance afterthought, something legal will 'clean up later' once the product has traction. That approach no longer survives contact with regulatory reality. If you are building or deploying an agent that can spend money, commit to terms, or bind your company or your customers to an obligation, you need to treat that agent the way you would treat a new employee with signing authority: onboarded carefully, monitored constantly, and constrained by policy.

From Experimental Deployment to Auditable Infrastructure

The operational shift this requires is significant, and I don't think most founders have internalized its scope yet. Early-stage agent deployment has largely been experimental: give the model broad tool access, monitor loosely, iterate fast, and treat edge cases as they surface. That posture was tolerable when agents were internal productivity tools. It is not tolerable when agents are executing real transactions with real legal consequences.

What replaces it is a discipline closer to financial controls than software engineering. Specifically, founders need to build:

  • Hard transaction ceilings that define the maximum value, frequency, and category of purchase or commitment an agent can execute without human confirmation.
  • Immutable audit logs that capture every decision point, every tool call, and every piece of context the agent used to reach a transactional decision, not just the outcome.
  • Explicit consent checkpoints for any action that creates a financial obligation, renewal, or binding commitment on behalf of a customer.
  • Kill switches that allow immediate suspension of agent transactional authority without taking down the entire product experience.
  • Scope-limited credentials so that an agent's access to payment rails, APIs, and account permissions mirrors the principle of least privilege, not convenience.

None of this is exotic. It's the same governance framework that regulated financial institutions and payment processors have used for decades to manage risk from automated trading systems and algorithmic underwriting. The novelty is simply that founders now building consumer-facing AI products need to adopt it years earlier in their company's life cycle than they expected.

Governance Is Now a Product Requirement, Not a Legal Afterthought

I'd argue the deeper shift here is cultural. Founders have to stop thinking of guardrails as friction that slows down the product experience and start thinking of them as the feature that makes autonomous commerce legally viable at all. Investors and boards should be asking, as a matter of diligence, whether transactional agents have audit trails sufficient to reconstruct any disputed charge, whether there is a documented consent architecture, and whether liability exposure has been modeled the way you'd model any other operational risk.

Insurance markets are moving in this direction as well, and I expect underwriters to increasingly condition coverage for AI-related liability on demonstrable guardrail infrastructure, much the way cyber insurance now conditions coverage on specific security controls.

The Founders Who Win This Cycle

The founders who treat this moment as a constraint will lose ground to the founders who treat it as a design principle. Auditable, bounded, consent-driven agent architecture is not the opposite of a great product experience; it is the foundation of trust that makes agentic commerce durable rather than a regulatory liability waiting to surface. The FTC has told us, unambiguously, that there is no autonomous actor standing between your company and your customer. There is only you, your system, and the record you can produce when someone asks what happened and why.