Skip to main content Scroll Top

The Contract Nobody Signed: AI Agents and the Limits of Agency Law

Heckelai_July_Marina D_The Contract Nobody Signed_Image
I. A Market Reality with No Legal Infrastructure

Contract law is built on a simple premise: somewhere behind every agreement, there is a person who meant to make it. AI contracting systems are dismantling that premise transaction by transaction, while the legal framework looks the other way.

Walmart is among the companies that have deployed AI systems to conduct supplier negotiations with limited human sign-off on individual transactions.¹ “AI agent” is used here as a technical term, a system authorized to negotiate or conclude transactions on a deploying party’s behalf, and implies no legal personality or formal agency status. The doctrinal tools we would normally reach for were not built for this. Agency law and the objective theory of contract formation can carry the analysis a long way, but they carry it to a threshold, and beyond that threshold, the analysis stops being doctrine and starts being fiction. This article compares common-law agency doctrine, European contract principles, the UNCITRAL Model Law, and EU consumer law to locate that threshold and ask what follows from it.

II. What Existing Doctrine Can Accommodate

Most AI contracting systems currently in commercial use operate within defined parameters: price bands, standard term structures, and escalation rules that trigger human review above certain thresholds. A supplier negotiation agent authorised to agree payment terms within a 30- to 60-day window, at a price within five per cent of a reference figure, is doing something tractable under existing law. The deploying party has authorised a range of outcomes in advance; the agent’s actions fall within that range; the contract binds the principal under conventional actual authority principles.

The objective theory of contract formation reinforces this picture.² Contract law has never demanded that subjective mental states be directly readable. It asks whether the external conduct (offer, acceptance, certainty of terms) is present. When an AI agent produces that conduct within a pre-authorised scope, the intention element can be located in the principal’s decision to deploy the system in the first place. This is the “prior intent” move.³ Within guardrails, AI-concluded contracts are enforceable under existing doctrine, strained at the edges but not broken.

The temptation is to conclude that the problem is therefore overstated, a conclusion with a long and undistinguished history in technology law. The edge cases are already arriving, and the doctrine is not ready for them.

III. The Threshold: Where the Analysis Breaks Down

The picture changes when the agent operates beyond its guardrails, or when no guardrails were meaningfully set. Noam Kolt identifies the structural difficulty with precision: as agent autonomy increases, the gap between what the principal authorised and what the agent executes can move from merely difficult to monitor toward effectively unmonitorable in practice.⁴ The distinction matters: a monitoring difficulty is a governance problem, addressable through better contractual design or audit rights; a gap that is effectively unmonitorable is something else. In such cases, the principal often cannot know in advance what the agent will do, because the agent’s outputs emerge from processes not fully transparent even to its own developers. The principal has not authorised a range of outcomes; they have authorised a process, and the process has its own logic.

Xiaoshui Zhai has argued that existing contract law principles are sufficiently flexible to handle this through judicial adaptation of established doctrines.⁵ That argument deserves to be taken seriously, but flexibility has a structural ceiling. Agency doctrine requires, at minimum, a principal whose will the agent is representing.⁶ When an AI agent concludes a contract based on emergent behaviour that neither the principal anticipated nor could reasonably have constrained, the prior intent analysis produces a fiction. The contract is attributed to the principal not because they intended it but because the law has no one else to attribute it to. That is attribution by elimination, not by principle.

The problem sharpens in the agent-to-agent scenario: two autonomous systems negotiating with each other without human involvement on either side. Here, agency doctrine is not being stretched. It is being asked to perform a function it was never designed for. The doctrine assumes a human principal behind each agent, whose authority delimits the agent’s actions.⁷ Where both counterparties are AI systems operating beyond their principals’ real-time knowledge or control, there is no conduct on either side traceable to an authorising decision, and no authority relationship that maps onto the transaction that results. The objective theory can identify offer and acceptance in the systems’ outputs; it cannot locate, on either side, the authorising will those outputs are supposed to express.

IV. The UNCITRAL Model Law and the Politics of Avoidance

The UNCITRAL Model Law on Automated Contracting, adopted in July 2024, is the most significant international legislative response to date.⁸ It establishes that automated contracting is legally valid and that, as a general rule, an automated system’s actions are attributable to the deploying party, a sensible and necessary baseline, treated by the Model Law as a matter of practical necessity rather than doctrinal resolution. It does not articulate a doctrinal basis for that attribution, does not squarely address inconsistent agent actions, and does not engage with the agent-to-agent scenario, where there is no single deploying party to attribute the transaction to. Questions of consent and intention are left to national law.

The sidestep is understandable: reopening foundational questions of contract formation across civil law and common law traditions would have faced insuperable drafting difficulties. But the practical consequence is telling: the Model Law answers “are these contracts valid?” while leaving unaddressed “on what basis, and within what limits?” That is the question courts will face when something goes wrong. The European Commission services’ preliminary, non-binding discussion paper on automated contracting, circulated in October 2025, reflects the same posture.⁹ It identifies the gap and acknowledges the inadequacy of existing Member State frameworks for fully autonomous contracting, but proposes only further consultation; no legislative proposal has followed. Both instruments lower legal uncertainty without raising doctrinal clarity: progress, not resolution.

V. Three Questions the Literature Has Not Settled

The threshold argument generates three open questions that deserve more sustained attention than they have received.

The first concerns the unit of consent. The prior intent approach locates consent in the decision to deploy. For narrow-parameter systems, that is coherent: the deploying party has pre-signed a limited range of contracts and authorised a mechanism to select among them. For general-purpose agents pursuing open-ended strategies, the same logic produces a different result: the deploying party has consented to a process, not to any particular outcome. Process-level and outcome-level consent are not the same thing, and contract law has historically cared about the latter.¹⁰

The second concerns unexpected outputs. The instinctive response is to reach for mistake or misrepresentation, the path Zhai follows, and it works for one category: an obviously absurd result the counterparty knew or should have known was an error already voids the contract for unilateral mistake, on grounds that predate AI contracting entirely. The harder case is different: some unexpected outputs are not obvious errors but outputs the system was designed to produce, just not ones the principal anticipated. There, the result is neither a mistake, since the system performed as designed, nor a misrepresentation, since no false statement was made. Unilateral mistake narrows this problem without eliminating it; adapting doctrine to what remains is possible in principle, but the conceptual work has not yet been done.

The third concerns consumer protection. The Unfair Contract Terms Directive’s fairness assessment turns on whether a term was individually negotiated and whether it creates a significant imbalance to the consumer’s detriment, assessed in good faith and by reference to transparency.¹¹ That framework strains when terms are generated by AI systems without human drafting decisions at the individual transaction level. Such terms are, almost by definition, not individually negotiated, which should bring them within the Directive’s scope; the harder question is what “significant imbalance” and “good faith” mean absent a human drafter, when a term’s effects can only be reconstructed through the system’s own audit trail, if one exists. Transparency and auditability, not draft intent, become the load-bearing concepts, and the downstream implications become urgent.

None of these questions resolves itself through doctrinal elaboration alone. Agency law, stretched by judicial creativity, can accommodate a great deal and deserves the chance to do so before being displaced by legislation that may not understand the technology it regulates. But there is a point at which the fiction of prior intent becomes an acknowledgement that the law does not know what to do. Identifying that point clearly is a precondition for deciding what comes next. The UNCITRAL Model Law deferred the question. EU private law has not yet reached it. The systems generating the question are already deployed.

References

¹ Mary Lacity and Remko Van Hoek, “How Walmart Automated Supplier Negotiations,” Harvard Business Review, November 3, 2022, https://hbr.org/2022/11/how-walmart-automated-supplier-negotiations.

² Ole Lando and Hugh Beale, eds., Principles of European Contract Law, Parts I and II (The Hague: Kluwer Law International, 2000), Arts. 2:201–2:204.

³ Xiaoshui Zhai, “Autonomous Systems: How Should Contract Law Treat Such Autonomy?” Information and Communications Technology Law, published online February 12, 2026, https://doi.org/10.1080/13600834.2026.2624924.

Noam Kolt, “Governing AI Agents,” Notre Dame Law Review 101 (forthcoming 2025), https://ssrn.com/abstract=4772956.

Zhai, “Autonomous Systems.”

Simon Chesterman, We, the Robots? Regulating Artificial Intelligence and the Limits of the Law (Cambridge: Cambridge University Press, 2021), ch. 4.

Samir Chopra and Laurence F. White, A Legal Theory for Autonomous Artificial Agents (Ann Arbor: University of Michigan Press, 2011), ch. 2.

UNCITRAL Model Law on Automated Contracting (adopted July 11, 2024), Art. 7, https://uncitral.un.org/sites/uncitral.un.org/files/mlac_en.pdf.

European Commission, High-Level Forum on Justice for Growth, “Discussion Paper on Automated Contracting” (October 2025), https://commission.europa.eu/document/download/6b8c3d6e-ef3e-4cb9-8b3f-ad20f518e585_en.

¹⁰ Kolt, “Governing AI Agents.”

¹¹ Council Directive 93/13/EEC of April 5, 1993 on Unfair Terms in Consumer Contracts, 1993 O.J. (L 95) 29, Art. 3(1).