MICKAI®ArticlesCan an AI agent sign a contract o…
Article · 21 July 2026

Can an AI agent sign a contract on behalf of your company?

The company can be bound but the agent cannot be responsible, so authority and evidence become the questions that matter.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aiagentic aicontract lawai governanceai agents

No, not in the sense the question usually intends, and the distinction carries the whole risk. Under English law a company contracts through humans who hold actual or apparent authority. An AI system has no legal personality, so it cannot itself be responsible for anything. When an agentic system places an order or accepts terms, the company can be bound, but the legal analysis runs through the humans who deployed the agent and the authority they gave it.

The question matters in 2026 because agentic AI has moved from demonstration to deployment. Systems now negotiate renewals, place orders, accept standard terms and commit resources without a human touching each transaction. The contracts they make are generally valid. The unresolved question inside most organisations is what happens when a counterparty holds the company to a commitment the board never intended.

Is a contract made by an AI agent legally valid?

Generally yes, and this is not new. Automated contracting has been commonplace for years: online checkouts, algorithmic ordering and automated supply chain replenishment all form contracts without a human reviewing each one. English law accommodates this by treating the machine as the instrument of the humans who deployed it: the company manifests its intention to be bound by putting the system into service. An agentic AI system is a far more capable instrument, but the same analysis applies. Validity is rarely the problem. Authority is.

Who is responsible when the agent commits the company?

The humans, always. An AI agent cannot own property, hold rights, be sued or be held responsible, so responsibility lands on the organisation that deployed it and the people who authorised its mandate. If an agent accepts terms nobody read, the company accepted them. If it orders stock on ruinous terms, the company ordered it. The counterparty deals with the company, not the software, and the company answers for its instrument. The real legal event is therefore the deployment decision, not the individual transaction.

What is a bounded mandate and why does it matter?

A bounded mandate defines what an agent may commit before it acts, and it needs at least three dimensions:

  • Value limits: the most an agent may commit in one transaction and in one period.
  • Counterparty limits: whom the agent may deal with, and which counterparties always require human approval.
  • Subject limits: which goods, services and terms the agent may accept, and which clause types, such as indemnities, exclusivity and automatic renewal, are always escalated.

The mandate matters because authority decides disputes. A counterparty facing a repudiated commitment will argue the agent had apparent authority. The organisation will argue the agent exceeded its mandate. Whether the organisation can show what the mandate actually said, at the moment the agent acted, may decide the case.

What happens when an agent exceeds its authority?

The company may still be bound. Where an organisation has held its agent out as able to transact, a counterparty acting in good faith may hold the company to the deal even though an internal limit was breached. That mirrors the position with human employees, and so does the practical lesson: limits that exist only in a policy document protect nobody. Limits must be enforced at the moment of action, before commitment, and the enforcement must leave evidence. A pre-commitment check, where every proposed commitment is tested against the mandate before it can leave the perimeter, converts a policy into a control.

What evidence do you need when a dispute arrives?

Three records, and they must hang together: the mandate in force at the moment of the action, the action itself with its full context, and the approval chain through which humans conferred that mandate. Reconstructing this from scattered logs and emails months later is where organisations fail. On Mickai, a Sovereign Intelligence Operating System, every agent action is sealed to a post-quantum signed audit ledger bound to hardware-attested identity, and the record verifies offline, so what the organisation shows a court or a counterparty does not depend on anyone taking its word.

What should a board put in place before agents transact?

A short list, applied before the first live transaction:

  • A written mandate for each agent, versioned, with a named owner.
  • Pre-commitment checks enforced by the system, not by the policy.
  • A defined escalation route for anything outside mandate.
  • A sealed, verifiable record of mandates, actions and approvals.
  • Periodic review of agent behaviour against the mandate it was given.

For firms subject to senior manager accountability regimes there is a further regulatory dimension, which we examine separately; the contract and authority analysis here applies to every company. The principles above reflect English law, and while the broad direction is similar elsewhere, organisations trading across borders should take advice on each jurisdiction.

An AI agent can commit the company but can never answer for it, so the record of its authority must.

How mandates, pre-commitment checks and the sealed record fit into the wider architecture is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Is a contract my AI agent accepted enforceable against my company?

Generally yes. English law treats an automated system as the instrument of the company that deployed it, so a commitment within the agent's apparent authority will usually bind the company. The productive question is not whether the contract is valid but whether the organisation can evidence the authority it gave.

Can I let an AI agent make purchases for my business?

Companies already do, and the safe structure is a bounded mandate: value limits, counterparty limits and subject limits, enforced by pre-commitment checks rather than a policy document, with every proposed and completed commitment written to a sealed record. The agent then operates inside a perimeter the board actually defined.

What if my AI agent agrees to terms nobody in the company ever read?

The company is likely bound, exactly as it is when an employee clicks through standard terms. The mitigation is architectural: clause classes that matter, such as indemnities, exclusivity and automatic renewal, are escalated to a human before acceptance, and the escalation itself is recorded.

Does an AI agent need its own legal identity to trade?

No. Under English law an AI system has no legal personality, and no proposal to grant one has been adopted. Commitments run through the deploying company, which is why the mandate and the evidence of it, rather than any notion of machine personhood, carry the legal weight.

How do I prove what my agent was authorised to do six months ago?

Only with a versioned, tamper-evident record. The mandate, its approval and every action taken under it need to be sealed at the time, not reconstructed afterwards. A post-quantum signed audit ledger that verifies offline gives the organisation an account of its agent's authority that stands up without relying on memory or goodwill.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/can-an-ai-agent-sign-a-contract-on-behalf-of-your-company. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles