AI

Your agent spent the money. Now prove you told it to.

The AI AGENT Act would make agents keep real-time records and put NIST in charge of the standard. But its first scope stops at the company boundary — and the disputes that will actually cost money start the moment an agent crosses one.

N Noah · The Sharp Brief · August 29, 2026 · 4 min read
A receipt printing itself in an empty darkened office at night

An AI agent books a flight, renews a subscription, or buys the wrong thing at the wrong price. The charge lands. You dispute it. Somebody now has to answer a question that no current system is built to answer: can anyone prove you authorised that?

Senator Mark Warner introduced the AI AGENT Act, S. 5051, on July 21. It defines a “custodial user agent” as one authorised to act for a user in a manner that is transparent, documented, limited and revocable, and it generally requires those agents to keep real-time records of the actions they take. It also directs NIST to identify protocols or develop technical standards for two things: verifying that a user actually delegated authority to an agent, and keeping auditable records of what the agent then did.

NIST is already partway there. It is reviewing comments on a February 2026 draft concept paper on agent identity and permission, which asks how an agent proves its authority, how that authority connects back to a person, and what a verifiable record of its actions looks like.

The scope is narrower than the problem

NIST’s proposed first effort covers agents operating inside organisations — the environment where a single administrator controls identity, permissions and logging end to end. Agents arriving from untrusted outside sources are excluded from that initial pass. Public-facing and individual consumer agents are flagged as something to address later.

That deferral is where the disputes live. A consumer agent crosses company boundaries by design: your assistant, a merchant, a payment network, a bank. Each keeps its own identifiers, its own wording for what the user agreed to, and its own retention schedule. The bill does not expressly require a verifiable evidence chain that survives those handoffs, from the moment a user starts a task to the final outcome.

Google’s Agent Payments Protocol, published earlier this year, illustrates the same gap from the industry side. It can track exactly how an agent spent money. It is much less help when the question is whether the purchase was approved in the first place.

Our take: Every company in the chain can produce its records exactly as stored, honestly and completely, and the dispute can still end unresolved — because four correct partial records do not add up to one provable authorisation. That is a different failure from fraud or negligence, and it is the one that scales. If you are deploying agents that touch money or contracts, do not wait for the standard. Decide now which system in your stack holds the authoritative record of what a user delegated, in what words, with what limits, and for how long you keep it. The firms that can answer that in a dispute will keep their chargeback rates. The firms that discover the answer is “four systems, partially” will not.

What to watch

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.