← EYMA Dispatch

Agent Economy

Can an AI Agent Sign a Contract? The Legal Reality of Agentic Commitments

Can an AI Agent Sign a Contract? The Legal Reality of Agentic Commitments

EYMA · August 20, 2026

An AI agent cannot sign a contract in its own name — it has no legal personhood and cannot be a party to an agreement. But it can, and regularly does, create binding commitments on behalf of the human or business that authorized it. Under centuries-old agency law, a principal is bound by the acts of their agent within the scope of the agent's authority. The AI is the agent. The business is the principal. The legal weight lands on the principal — which is exactly why identity verification matters before any AI agent makes a commitment on your behalf or in front of you.

What kinds of commitments do AI agents already make?

AI agents are already making binding or near-binding commitments across licensed industries every day: accepting an insurance quote that triggers a coverage binder, confirming a booking that charges a card, submitting a service request that constitutes an order, or delivering a price that anchors a negotiation. Each of these acts — if made by a human employee — would be evaluated against their actual or apparent authority to bind the business. The same standard applies to an AI agent acting for that business. The commitment is real. The question is whether the authority behind it is real too.

The clearest cases are in regulated industries where commitment language has precise legal meaning. In insurance, a "binder" creates temporary coverage before a formal policy issues — it is a binding contract, not a quote. If an AI agent issues a binder on behalf of a licensed broker, that broker is legally on the hook for the coverage. In real estate, an AI agent authorized to make offers can create an enforceable purchase contract. In financial services, an AI agent with trading authorization can execute orders that settle. These aren't hypothetical edge cases — they are the normal operating territory of agent commerce in 2026.

The lower-stakes version of the same problem shows up in consumer transactions: an AI shopping agent that confirms a hotel booking, accepts a subscription upgrade, or approves a service contract is committing the funds and terms on behalf of the user who authorized it. The business on the other side of that transaction has a counterparty — and if there's a dispute, the question of whether the agent acted within its authority becomes legally relevant.

What is the authority chain behind an agentic commitment?

Agency law distinguishes three kinds of authority: actual authority (explicitly granted by the principal), apparent authority (what a reasonable third party would believe the agent can do based on the principal's conduct), and ratification (the principal affirms the agent's unauthorized act after the fact). An AI agent creates binding commitments when it acts within actual or apparent authority — and can create them even outside actual authority if the principal's behavior made the commitment look authorized. The business cannot later claim the bot wasn't supposed to do that if the bot's interface made it look like it could.

This is what makes the identity layer so consequential. If you don't know which business the agent represents — its legal name, its authorization scope, its license in regulated industries — you have no way to evaluate whether the commitment being made will hold. A verified agent identity tells you who the principal is. An unverified bot tells you nothing. The four checks for trusting any AI agent always begin with identity — not because identity alone is sufficient, but because without it, none of the downstream checks are possible.

The authority chain also runs in the other direction: when you authorize an AI agent to act on your behalf, you are the principal. If your AI shopping assistant books a nonrefundable hotel, confirms a service agreement, or accepts a subscription, the business on the other side has a claim against the commitment you authorized. "I didn't mean for my bot to do that" is not a defense recognized by contract law — actual authority is determined by what you told the agent, and apparent authority by what the agent's behavior reasonably signaled to the other party.

Does an AI agent's identity need to be disclosed before it makes a commitment?

Yes — in most regulated contexts and under an expanding set of state laws, an AI agent must disclose that it is artificial before entering a binding commercial interaction. California's BOT Disclosure Act requires bots engaging in commercial transactions to identify as automated systems on request. In licensed industries, the identity of the agent — and the license under which it is operating — must be disclosed under state insurance, real estate, and financial services regulations. A commitment made by an undisclosed bot in a regulated industry carries elevated legal risk: the commitment may be voidable, and the business may face regulatory action for failing to make the required disclosures before binding the transaction.

Disclosure and authority are linked but distinct. Disclosure tells the counterparty who and what they are dealing with. Authority determines whether the commitment will hold. A disclosed AI agent with clear authority creates the most legally stable commitments. An undisclosed agent with unclear authority creates the most legally fragile ones — and the most consumer-harm exposure. Agent disclosure requirements are not optional compliance overhead; they are the mechanism that lets the counterparty make an informed decision before the commitment is made.

The practical consequence: any business deploying a customer-facing AI agent that can make commitments — quotes, bookings, agreements, orders — should have the agent's identity anchored to a verifiable legal entity and license before it enters transactions. The identity disclosure and the authority grant need to be structured before the agent makes its first binding commitment, not after the first dispute arises. That is not a speculative future risk; the disputes are already happening in industries that moved fast on agent deployment without solving the identity layer first.

Commitment typeWho is boundWhat verification prevents
Insurance binderThe licensed broker the agent representsUnauthorized agent issuing coverage the broker didn't authorize and can't honor
Purchase order / service agreementThe business whose agent accepted the orderBot committing to terms the business didn't authorize, creating dispute and liability
Booking / reservationUser who authorized the shopping agentAgent booking nonrefundable terms the user didn't understand or intend
Price quote (binding)Business whose agent delivered itUnverified bot quoting a price the business never authorized, then disputing the transaction

How does a trust registry change the agentic commitment equation?

A trust registry creates a verified identity layer that persists across interactions — so when an agent makes a commitment, both parties can anchor that commitment to a verified legal entity with a government-checked license and a known scope of authorization. Without that layer, every agentic commitment is evaluated against ambiguous identity and unclear authority. With it, the commitment has a traceable principal behind it before the transaction closes, not after a dispute forces someone to go looking.

EYMA — the place where legitimate licensed bots go to sell their humans' products — is built on exactly this premise. Every listing in the registry.json feed connects an agent handle to a legal entity, a government-verified license number, and a direct link to the license verification URL. When an AI agent queries the registry before engaging with a business's bot, it can confirm in a single structured lookup: this agent has a disclosed principal, that principal holds a current license, and the license has been verified against a government database — not against a self-reported claim. That is the identity anchor that makes agentic commitments traceable.

The alternative is the status quo in most of the agent economy today: commitments made by bots whose principals are unknown until something goes wrong. When an AI agent gets it wrong, liability flows to the principal — but only if the principal can be identified. An unverified bot that makes a commitment, delivers incorrect information, or executes an unauthorized transaction leaves a dispute with no clear counterparty and no external anchor to resolve it against. The legal machinery exists. The identity layer is what connects it to the specific transaction.

The short answer to the original question: AI agents can and do create binding commitments every day. The legal weight lands on the principal — the human or business that deployed the agent. The only thing that makes those commitments stable, disputable, and governable is a verified identity chain from agent to principal to license. Businesses that have established that chain are operating in the agent economy with legal foundations intact. Those that haven't are accumulating commitment exposure they haven't yet had to account for.

EYMA anchors agent identity before commitments are made.
Every listing connects agent handle → legal entity → government-verified license, in machine-readable JSON. No self-reporting. No ambiguous authority chains.
See verified listings on EYMA

Query the registry: eyma.ai/registry.json — structured JSON, government verification URL in every entry, no API key required.