AI agents have begun executing transactions and transferring funds without continued human approval, prompting Brickken CEO Edwin Mata to argue that responsibility should shift with the rights granted to the software, rather than the AI itself.
Abstract
AI agents cannot assume legal obligations because current law does not recognize them as legal subjects. Mata said that when an agent acts within the scope of authorization, the principal usually has to bear the corresponding consequences. The ERC-8226 standard sets time limits, financial ceilings, revocation controls, and verifiable records for AI agents. U.S. securities rules already require brokers to control automated systems that access regulated markets.
It is reported that the current law does not have a unified answer to the losses caused by autonomous financial agencies, and courts need to examine the users, developers, platforms and institutions involved in each transaction. The report noted that contract law, negligence rules, product liability and fiduciary liability may all apply, depending on who controlled the agency and the cause of the loss. Users may face consequences for authorization transactions, and developers or platforms may face claims if agents exceed their authority due to design flaws, weak safeguards, or information errors.
Commenting on the matter, Edwin Mata, a lawyer and CEO of tokenization platform Brickken, said the responsibility should never be directly attributed to the software. "Under current law, AI is not a legal subject capable of assuming obligations or responsibilities. It is a system that acts on behalf of natural or legal persons." Mata believes that the investigation should first determine who authorized the agent, whose interests the agent represented, and what authority was obtained. Such investigations can help distinguish between loss decisions made within approval strategies and transactions that violate agency authority.
AI agency liability depends on the scope of authorization
Mata compares this legal relationship to a power of attorney: one party is allowed to act on behalf of the other party within a limited scope. He said that when an issuer, bank or investor authorizes an agent to conduct a transaction, the principal usually has to bear the consequences of his actions within the scope of authorization. In the same way, investors cannot refuse to trade simply because the software produces unfavorable results. Loss of price does not in itself indicate that the agent acted without permission or that the other party failed to perform its duties. "Issuers cannot deny an unfavorable but authorized transaction just because the decision was generated by software," Mata said.
Responsibilities may change when an agent exceeds the scope of authorization. Mata said there may be risks if the design or control of a developer, platform or financial institution caused or allowed a failure, but the final assessment depends on the facts and applicable law. The above-mentioned report also cited similar legal distinctions. Some lawyers pointed out that liability usually depends on control. Users are often the starting point when agents act on their behalf, but developers can also be at risk if the system fails in a foreseeable way using autonomous transactions as a selling point.
This issue has become increasingly urgent as agents gain direct access to wallets and payment systems. A report shows that AI agents settled $73 million through 176 million transactions in the past 12 months, with USDC accounting for 98.6% of the payments reviewed. Coinbase has also connected agents to trading, portfolio management and payments under user-set limits. As of July, there were more than 100 million x402-related payments recorded, but analysts pointed out that memin mining and automation activities contributed to the total amount of early transactions, so these numbers do not represent the purchase of goods or services by independent agents.
Clear and enforceable upper limit for human approval
Mata believes that while a person can formally approve an agent's activities, consent alone does not provide meaningful control if a person cannot understand the authority granted. Effective authorization requires a listing of allowed operations and eligible assets, as well as individual transactions and total expenditure limits. The authorization should also clarify its validity period, the conditions requiring manual review, the client's revocation authority, and the record of each operation. Such controls have appeared in commercial products. Agencies launched agent banking in May, which includes authentication, spending limits, and audit controls for autonomous system access encryption and traditional payment tracks. Visa and Wirex tested agent-led stablecoin payments for software subscriptions, marketing budgets and purchases respectively. The trials aim to explore issues such as security, reliability, transparency and user control when software initiates payments on behalf of users or businesses.
A guide on proxy payments explains how x402 allows autonomous software to use stablecoin payment data, computing services and online resources. Because these payments do not require manual approval on a case-by-case basis, the authorization system must clarify what the agent can purchase, the amount that can be spent, and when access rights will expire.
ERC-8226 will record AI agent authorization on the chain
Mata pointed out that ERC-8226 (the proposed standard for authorization of regulated agents) is a model to make delegated authorization verifiable. The standard was submitted as a draft Ethereum standard on April 12 and is intended to be used to operate AI agents that tokenize regulated assets. The proposal was co-written by Brickken contributors and is called RAMS. This standard allows verified principals to grant rights to on-chain agents, with rights limited by assets, operations, duration, and monetary value. When an agent attempts to execute a transaction, regulated token contracts can check authorization. The proposal separates three issues that may arise in agent-led transactions: the identity registry confirms whether an agent exists; the compliance provider determines whether the principal is qualified to trade the asset; and the RAMS registry verifies whether the plan operation is within the scope of the delegated authority.
According to the draft specifications, the authorization can set the maximum amount for a single transaction and the cumulative amount for multiple transactions. It can also include activation and expiration times, allowed assets, approved actions, revocation functions, and a record showing the rights the agent has used. Mata said RAMS will not transfer liability to the agent and will not compensate the principal for loss of authorization. Instead, the standard will provide evidence of who granted the authority, what the agent can do, whether the transaction is within limits, and which links or controls fail when limits are exceeded. "The purpose is to make accountability verifiable: who granted the authority, what the agent was allowed to do, whether it remained within limits, and which individual or control failed when limits were exceeded." ERC-8226 is still in draft form and has not yet become an Ethereum standard or legal requirement. Its discussion page also lists unresolved issues, including whether tokens purchased by agents should remain in the agent's wallet or be settled directly into the principal's wallet.
U.S. rules leave responsibility to regulated companies
For the U.S. market, existing securities rules already place obligations on companies that provide access to exchanges and alternative trading systems. Under SEC Rule 15c3 -5, brokers providing market access must maintain financial and risk controls under their direct and exclusive control, unless there are limited exceptions. The SEC guidance states that even if a broker uses technology provided by an independent third party, it remains responsible for the effectiveness of the control. The rule requires automated pre-trade inspections to block orders that exceed preset credit or capital thresholds. It also requires controls to restrict the use of trading systems only by authorized personnel, prohibit trading in restricted securities, and provide immediate execution reports to monitors.
For consumer payments, Regulation E requires pre-authorized electronic funds transfers to be authorized in writing or similarly authenticated by the account holder. The Consumer Financial Protection Bureau (CFPB) guidance also states that the authorization process should prove the consumer's identity and consent, while allowing consumers to stop or revoke future payments in accordance with specific procedures. Current CFPB rules do not directly state how continuing instructions such as "manage my portfolio" should apply when an AI agent independently selects and executes a single transfer. Lawyers are reportedly still divided over whether the manipulated proxy payments are similar to unauthorized transfers resulting from stolen vouchers or authorized transactions based on previously granted authority.
Outside the United States, Bank of England Deputy Governor Sarah Breeden said in June that the financial regulatory framework was not designed for autonomous agencies and requiring manual approval for every action might be impractical. She said regulators are considering stronger safeguards, including setting circuit breakers or market-level emergency shutdown switches when AI models fail and threaten trading systems.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following