An AI agent books a flight, renews a subscription, or buys the wrong thing at the wrong price. The charge lands. You dispute it. Somebody now has to answer a question that no current system is built to answer: can anyone prove you authorised that?
Senator Mark Warner introduced the AI AGENT Act, S. 5051, on July 21. It defines a “custodial user agent” as one authorised to act for a user in a manner that is transparent, documented, limited and revocable, and it generally requires those agents to keep real-time records of the actions they take. It also directs NIST to identify protocols or develop technical standards for two things: verifying that a user actually delegated authority to an agent, and keeping auditable records of what the agent then did.
NIST is already partway there. It is reviewing comments on a February 2026 draft concept paper on agent identity and permission, which asks how an agent proves its authority, how that authority connects back to a person, and what a verifiable record of its actions looks like.
The scope is narrower than the problem
NIST’s proposed first effort covers agents operating inside organisations — the environment where a single administrator controls identity, permissions and logging end to end. Agents arriving from untrusted outside sources are excluded from that initial pass. Public-facing and individual consumer agents are flagged as something to address later.
That deferral is where the disputes live. A consumer agent crosses company boundaries by design: your assistant, a merchant, a payment network, a bank. Each keeps its own identifiers, its own wording for what the user agreed to, and its own retention schedule. The bill does not expressly require a verifiable evidence chain that survives those handoffs, from the moment a user starts a task to the final outcome.
Google’s Agent Payments Protocol, published earlier this year, illustrates the same gap from the industry side. It can track exactly how an agent spent money. It is much less help when the question is whether the purchase was approved in the first place.
Our take: Every company in the chain can produce its records exactly as stored, honestly and completely, and the dispute can still end unresolved — because four correct partial records do not add up to one provable authorisation. That is a different failure from fraud or negligence, and it is the one that scales. If you are deploying agents that touch money or contracts, do not wait for the standard. Decide now which system in your stack holds the authoritative record of what a user delegated, in what words, with what limits, and for how long you keep it. The firms that can answer that in a dispute will keep their chargeback rates. The firms that discover the answer is “four systems, partially” will not.
What to watch
- Whether the cross-boundary case gets written back in. S. 5051 is early. The consumer agent chain is the expensive case, and leaving it to a later phase is the single biggest weakness in the current text.
- NIST’s response to comments. The internal-agents-first scope is a reasonable engineering call and a bad match for where the harm is. Whether the final framework extends past the organisational boundary matters more than the timeline.
- Who absorbs the losses meanwhile. Until authorisation is provable, disputed agent transactions get resolved commercially — which usually means the merchant or the issuer eats them. Watch for card networks writing agent-specific rules before Congress does.
- Revocability in practice. The bill’s definition requires authority be revocable. Most agent integrations today revoke access going forward and say nothing about actions already in flight.
