AI agents are moving from “to give recommendations” to “to implement on behalf”, but once it completes the order over the user's instructions, existing payments and platform records do not necessarily restore the chain of responsibility. It was pointed out that the difficulty of such disputes was not whether payment had occurred, but whether it could be proved that the agent had acted within the authority of the user.

The controversy is that the records are not connected to each other.

In the case of shopping grounds, for example, the user asked AI agents to look for a shirt below $30, but made it clear not to buy it. If the agent finally completes the order, the retailer can prove that the order came from the user's account, the agent can issue the original “no purchase”, and the payer can confirm that the deduction has taken place.

The question is whether all three types of records may be true, but there is no verifiable chain of evidence between them, sufficient to indicate whether the transaction originated from that particular task and whether the agent exceeded the mandate.

The bill caused problems, but it didn't add up the whole link.

The article mentions that US Senator Mark Warner presented AI AGENT Act in July 2026. The Act defines “host-user agency” as an AI agent that can act on behalf of the user and that the authorization process should be transparent, recordable, limited in scope and revocable, and requires that such agent normally keep a real-time operating record.

The Act also requires the National Institute of Standards and Technology (NIST) of the United States to identify or develop technical standards to verify whether the user has delegated authority to the agent and what the agent has done. However, according to the article, this direction still does not explicitly require the establishment of a cross-system, verifiable chain of evidence.

Existing delegation mechanisms are difficult to cover mission-level limitations

According to the article, many of the current online services rely on enabling mechanisms such as OAuth. It allows for access to protected services to be applied without disclosing the user password and for follow-up through access to tokens.

However, such mandates are often consistent and effective. Users may have approved the application access accounts a few weeks ago, so the agent can still file the accounts today with a valid token. For retailers, the transaction can continue as long as the token is valid; as for the restriction that “the mission only permits search and no purchases”, it is often confined to the agent service provider.

Google AP2 only partially completed

In the opinion of the external media, at least a few things are required to make AI proxy transactions accountable: binding user accounts, specific agents and specific tasks; preciseing the restriction to a single task; making the same task relevant in the records of the various participants; re-approving restrictions before critical actions; and keeping a record that can be identified for tampering.

  • Google's AP2 can record user-approved limitations
  • The agreement can also show what the parties saw in the dispute.
  • However, the burden of loss and the duration of the preservation of evidence were not specified

NIST is reviewing the feedback from its February 2026 proxy identity and authority concept paper, but the current initial scope is mainly for internal agents of the organization. The article argues that what is really complex is a consumer-oriented agent that operates across company boundaries. In the future, the costs of similar disputes can be significantly magnified if they involve large transfers, benefit claims or requests for medical records.