Skip to main content
Welcome to Deloitte

If we have selected the wrong experience for you, please change it above.

No human, no contract

The legal risks behind agentic commerce

Current laws governing online transactions are built on the foundational principles of human intent, notice and consent—concepts that are not easily applied to autonomous artificial intelligence (AI) and the rise of agentic commerce. For business leaders, not addressing this misalignment introduces significant agentic commerce legal risk. It invites the risk of unenforceable sales contracts, regulatory action from bodies like the Federal Trade Commission (FTC) and significant liability exposure. Explore how you can anticipate and adapt your legal strategies to help shield your business from unnecessary liability.

Key Takeaways:

  • Are your online contracts valid if a bot clicks “I agree”? Because traditional laws require human intent, autonomous transactions create a significant agentic commerce legal risk where sales may be deemed legally unenforceable and revenue is lost.
  • Is your marketing budget actually reaching the buyer? As AI in e-commerce scales, advertising budgets optimized for human visual and emotional triggers will yield diminishing returns, requiring a shift toward machine-led discovery channels.
  • Can your operational systems handle a surge in automated disputes? When e-commerce AI agents make unapproved purchases, it multiplies the risk of unauthorized chargebacks, testing the limits of traditional fraud models built for human patterns.

The challenge: A legal framework built for humans, not bots

The legal structure of e-commerce, from the Uniform Electronic Transactions Act (UETA) to the Electronic Signatures in Global and National Commerce (ESIGN) Act, is predicated on the idea that a “person” must assent to a contract through human action. As the use of AI in e-commerce expands and an AI agent autonomously clicks “I agree” on a terms of service page, can a bot lacking legal intent bind a human user to unseen terms?

Courts consistently reinforced this idea. As established in Nguyen v. Barnes & Noble Inc., valid contracts require actual or constructive knowledge of the terms. An AI agent’s actions obscure this, making it difficult, if not impossible, to prove the human consumer was aware of your terms of sale. This creates a serious agentic commerce legal risk where AI-facilitated transactions may be deemed legally unenforceable.

Key risk areas for your business

As agentic commerce scales, businesses could face a widening set of risks, including the following:

  1. Unenforceable sales and revenue loss
    Because online agreements require conspicuous notice and unambiguous assent, it is highly questionable whether a bot’s pre-programmed action on behalf of an unaware user creates a legally binding contract, putting your sales and revenue at risk.
  2. FTC scrutiny and “unfair practices”
    Since the FTC targets bots, operating your platform for autonomous agents without guardrails could be deemed an unfair practice, inviting regulatory investigation, fines and damage to your brand’s reputation.
  3. Liability for unauthorized access and system misuse
    Circumventing security measures like CAPTCHAs can violate terms of use and the Computer Fraud and Abuse Act (CFAA), while permitting third-party AI agents to conduct illegal activities on your platform can trigger vicarious liability under the precedent set in Mohon v. Agentra LLC.
  4. A growing patchwork of state-level AI regulations
    As states like California, Maine, Utah, and Colorado mandate commerce-related AI disclosures, businesses failing to anticipate this legislative trend will fall into reactive agentic commerce compliance rather than leading from a position of strength.

A proactive strategy to help mitigate risk and embrace the future

Companies that take proactive steps to bridge the gap between agentic commerce and current legal doctrines can not only help protect themselves from liability but also build the trust necessary to lead the future of AI in e-commerce. Here are the five important steps to consider:

  • Update your terms and conditions (T&Cs). Explicitly address the use of e-commerce AI agents. Work with your legal team to evaluate whether your current T&Cs adequately account for bot-mediated transactions and to identify gaps that may require revision.
  • Ensure user control at the final step. As emphasized by the FTC and financial regulations (such as Regulation E), authorization is narrowly construed. Implement a final, human-in-the-loop confirmation step for high-value transactions or for the initial setup of an AI agent’s purchasing authority to solidify customer authorization.
  • Implement AI-ready consent mechanisms. Establish a one-time user verification and authorization process for enabling an AI agent to make purchases, with a clear record of the customer’s informed approval, scope of authority, and applicable limits.
  • Align security controls with approved AI interactions. Assess whether traditional anti-bot measures—such as CAPTCHA—could conflict with authorized agentic commerce. For designated AI interaction points, consider controlled alternatives that preserve security while preventing legitimate AI agents from being treated as unauthorized bots.
  • Provide clear, upfront disclosure. Clearly explain whether and how AI agents may interact with the organization’s commerce channels, including the authorization process, transaction limits, user controls, and responsibilities. This supports transparency, customer trust, and consistent implementation as regulatory expectations evolve.

Beyond legal risk: Revenue exposure and operational vulnerability

The risks of agentic commerce extend beyond contract enforceability and regulatory exposure. As AI-driven purchasing scales, two additional areas deserve the same level of scrutiny: the impact on marketing-driven revenue and the operational risk of agent-initiated chargebacks.

Revenue exposure: Marketing in an agent-driven world
As agent-driven purchases grow, marketing budgets optimized for human browsing may yield diminishing returns. The immediate questions are how much of your marketing budget is reaching the buyer that converted and is there an emerging channel optimized for machine-led discovery? 

Operational risk: The chargeback problem
When e-commerce AI agents buy on behalf of a consumer without explicit approval, the transaction may be disputed as unauthorized under existing chargeback frameworks. With scenarios compounding quickly—from duplicate orders to fraudulent disputes at scale—evaluating whether your systems are prepared for agent-driven volume, velocity and dispute complexity is an urgent operational necessity.

Final Summary

Agentic commerce is not on the horizon; it is at our doorstep. While layered with legal ambiguity and risk, it also offers a pathway to innovation and enhanced consumer experience. Success will likely belong to those that confront risks head-on. By proactively updating your legal frameworks, embracing transparency and reengineering consent, you can help shield your organization from unnecessary liability.

Download our “Agentic commerce legality” report to explore the legal, governance and trust challenges reshaping digital transactions.

Did you find this useful?

Thanks for your feedback