Have you ever handed someone the keys to your car and then watched them drive it into a ditch? That sinking feeling of responsibility is exactly what more investors are starting to feel as autonomous software begins executing trades and moving funds without a human clicking “confirm” every single time. The software itself cannot be sued. It cannot pay damages. It cannot sit in a courtroom and explain its decisions. So when the numbers turn red, who actually carries the loss?
Who Pays When An AI Agent Loses Money In Crypto
I have been watching this shift closely for months. What used to be a theoretical discussion among lawyers has become a practical problem for anyone running capital through automated systems. Recent industry figures show AI agents settling tens of millions of dollars across hundreds of millions of transactions in a single year, with stablecoins dominating the flow. That volume is no longer experimental. It is real money moving in real time.
The core legal reality is straightforward yet uncomfortable. Current law does not recognize artificial intelligence as a legal person. An AI system cannot assume duties or bear liability the way a human or a company can. It remains a technical tool acting on behalf of a natural or legal person. Responsibility therefore travels with the authority that was granted, not with the code that executed the order.
Liability Follows The Mandate, Not The Algorithm
Think of it the same way courts treat a power of attorney. When you authorize another party to act inside a defined scope, you generally live with the results of actions taken within that scope. An unfavorable outcome alone does not erase the authorization. The same logic applies when an investor, issuer or institution gives an AI agent permission to trade or transfer assets.
In my view this is the cleanest way to analyze these situations. The first questions any investigation should ask are simple: Who authorized the agent? Whose interests was it meant to serve? What exact powers did it receive? Once those answers are clear, it becomes far easier to separate a legitimate but losing decision from a transaction that stepped outside the original mandate.
An issuer cannot disown an unfavourable but authorised transaction merely because the decision was generated by software.
That statement captures the practical reality better than most formal legal language. Price declines and missed opportunities do not automatically transfer blame to the developer or the platform. Only when the agent exceeds its granted authority, or when design flaws and weak controls enable the breach, does the liability picture change.
Where Responsibility Can Shift
There are clear scenarios in which the principal is no longer the only party exposed. If a developer markets a system as ready for autonomous trading and the system fails in a foreseeable way, claims can arise. The same holds for platforms that provide inadequate safeguards or financial institutions that fail to maintain effective risk controls. Courts will look at control, design decisions and the quality of information the agent received.
I have seen similar patterns in traditional finance when algorithmic trading systems went wrong. The entity that retained final control usually carried the heavier burden. Crypto is following the same path, only faster and with less established case law. That uncertainty is precisely why clear documentation of authority has become so important.
Why Consent Alone Is Not Enough
Many users tick a box that says they authorize an agent to manage a portfolio or make payments. On paper that looks like consent. In practice it often provides almost no meaningful control. Effective delegation requires more than a general statement of permission. It needs specific boundaries.
A workable mandate should list the exact actions the agent may take and the assets it may touch. It should set hard limits on single-transaction size and cumulative spending. Duration matters. Conditions that trigger mandatory human review matter. The right to revoke access at any moment matters. And a complete, verifiable record of every action the agent takes matters most of all.
Without those elements, the so-called authorization is closer to a blank check than a controlled delegation. I have found that investors who treat AI agents like junior employees with clear job descriptions fare far better than those who treat them like magic black boxes.
Practical Controls Already Appearing In The Market
Some institutional platforms have begun embedding these safeguards directly into their products. Verified identities for agents, spending ceilings, real-time audit trails and the ability to cut access instantly are no longer theoretical features. Payment networks have run limited trials allowing software to settle stablecoin invoices for subscriptions and procurement while keeping the human principal firmly in the loop on limits and revocation.
These experiments are valuable because they surface the operational friction early. How does an agent prove it is still within its mandate when it tries to move funds? How does the receiving system verify that claim without slowing the transaction to a crawl? Those questions are being answered in live environments right now.
An Onchain Standard For Regulated Mandates
One technical proposal aims to make the entire chain of authority visible and enforceable on a public ledger. The draft standard known as ERC-8226, or the Regulated Agent Mandate Standard, would allow a verified principal to grant an onchain agent permission limited by asset type, permitted action, time window and monetary value. When the agent attempts a transaction, the token contract itself can check the mandate before allowing the transfer.
The design deliberately separates three distinct checks. An identity registry confirms the agent exists and is recognized. A compliance layer confirms the principal is eligible to hold or trade the asset in question. The mandate registry confirms the specific action falls inside the delegated authority. Only when all three align does the transaction proceed.
A mandate under this model can include a maximum amount for any single trade, a cumulative ceiling across multiple trades, activation and expiry timestamps, lists of allowed assets and actions, revocation functions, and a running tally of how much of the original authority has already been used. None of this transfers legal liability onto the agent. The purpose is purely evidentiary: to create a clear, immutable record of who granted what power and whether the agent stayed inside those boundaries.
I consider this approach promising because it turns abstract legal principles into machine-readable constraints. Courts and regulators still decide ultimate responsibility, but they would have far better evidence to work with. At the same time the standard remains a draft. Several practical questions are still open, including whether assets acquired by the agent should settle into the agent’s own wallet or move directly into the principal’s.
Existing Rules Already Place Duties On Regulated Firms
In the United States, securities regulations have long required broker-dealers that provide market access to maintain financial and regulatory risk controls under their direct and exclusive control. Those controls must include automated pre-trade checks that reject orders exceeding preset credit or capital thresholds. They must also restrict access to authorized users, block prohibited transactions and deliver immediate reports to surveillance staff. Importantly, the broker-dealer remains responsible for the effectiveness of the controls even when the technology comes from a third-party vendor.
Consumer payment rules add another layer. Preauthorized electronic transfers generally require a written or similarly authenticated authorization from the account holder. The process must demonstrate the consumer’s identity and agreement, and the consumer must retain the ability to stop future payments under defined procedures. What remains unsettled is how a broad standing instruction such as “manage my portfolio” should be interpreted when an AI agent independently selects and executes individual transfers. Lawyers continue to debate whether a manipulated agent payment looks more like an unauthorized transfer caused by stolen credentials or an authorized action carried out under previously granted access.
Outside the United States, senior central bank officials have openly acknowledged that existing oversight frameworks were not designed for autonomous agents. Requiring a human to approve every single action may prove unrealistic at scale. Some regulators are therefore examining stronger circuit breakers and market-wide kill switches that could halt activity if faulty models threaten system stability.
The Human Element Still Matters Most
Technology can enforce limits, but only humans can set sensible ones. I have spoken with portfolio managers who give agents extremely wide latitude and then express surprise when the results diverge from their unspoken expectations. The gap between what the human intended and what the software was actually authorized to do is where most disputes begin.
Perhaps the most useful mental model is to treat the AI agent the way a careful principal treats a human attorney-in-fact. You would never hand over unrestricted power of attorney without defining the purpose, the duration, the monetary ceilings and the reporting obligations. The same discipline belongs in the digital realm. Vague instructions produce vague accountability.
There is also a cultural dimension. Many early adopters of autonomous systems come from a software background where rapid iteration is prized. Legal and compliance teams move more slowly by design. Bridging that difference requires deliberate conversation rather than assumptions. The firms that manage the tension well are the ones writing detailed mandates and reviewing them regularly rather than treating authorization as a one-time event.
What Happens When Things Go Wrong
When an agent produces a loss that stays inside its mandate, the principal absorbs the economic result. That outcome can feel unfair, especially if the strategy looked sound on paper and the market simply moved against it. Yet the alternative—allowing principals to walk away from every authorized decision that turns negative—would make autonomous systems commercially unworkable.
When the agent exceeds its mandate, the analysis becomes fact-specific. Did the developer ship software that ignored its own stated limits? Did the platform fail to enforce the revocation mechanism? Did a third-party data feed corrupt the agent’s decision-making? Each of those paths can shift exposure. Product liability, negligence and contractual claims all remain available depending on the jurisdiction and the precise facts.
I expect the first wave of litigation to focus less on novel legal theories and more on ordinary principles applied to new technology. Courts already know how to examine scope of authority, foreseeability and control. The novelty lies mainly in the speed and opacity of the systems involved.
Building Better Mandates From Day One
Anyone deploying an AI agent with access to real funds should treat the mandate as a living document rather than a set-and-forget checkbox. Start with the narrowest permissions that still allow the agent to perform its intended function. Expand only after observing real behavior under controlled conditions. Record every change to the mandate and the reason for the change.
- Define permitted actions with precision rather than broad categories
- Set both per-transaction and cumulative financial ceilings
- Include clear activation and expiry timestamps
- Require human review for any action that approaches the limits
- Maintain an immutable log of every instruction the agent receives and every action it takes
- Test the revocation process under realistic conditions before relying on it in production
These steps sound basic, yet they are frequently skipped in the rush to automate. The cost of that haste appears only later, when a loss has already occurred and the documentation proves incomplete.
The Broader Market Implications
As more capital flows through autonomous systems, the quality of mandate design will become a competitive differentiator. Platforms that make authority transparent and enforceable will attract institutional users who cannot afford ambiguity. Those that treat authorization as a mere interface feature will find themselves on the wrong side of both regulators and litigants.
There is also a systemic dimension. If many agents operate under poorly defined mandates and share similar model architectures, correlated failures become more likely. Circuit breakers and market-wide safeguards under discussion at senior regulatory levels are responses to exactly that risk. Individual principals still control their own exposure, but collective behavior can create market-level problems that no single mandate can solve.
I remain optimistic about the technology itself. Properly constrained agents can execute strategies with speed and consistency that pure human teams cannot match. The danger lies not in the capability but in the casual way authority is sometimes handed over. Treating the grant of power with the same seriousness we apply to human agents is the simplest and most effective protection available today.
Looking Ahead Without Wishful Thinking
No one expects AI systems to acquire legal personality overnight. The more realistic path is continued refinement of the tools that make human authority visible and enforceable. Onchain standards, clearer regulatory guidance and better commercial practice around mandate design will gradually reduce the gray areas that currently exist.
Until that process matures, the safest posture is conservative. Assume that any loss occurring inside the granted authority will land on the principal. Assume that only clear evidence of excess or design failure will shift responsibility elsewhere. And assume that the quality of the original mandate will be the first document examined when something goes wrong.
That approach may feel cautious, yet it aligns with how law has always treated delegated power. The software is new. The underlying principles of authority and accountability are not. Investors and institutions that remember this distinction will navigate the coming years with far less drama than those who treat autonomy as a free pass from consequence.
In the end the question is not whether AI agents can trade. They already do. The question is whether the humans who deploy them are prepared to own the results of the authority they freely grant. That preparation starts with precise mandates, real limits and an honest recognition that the algorithm itself will never be the party writing the check when things go sideways.
The conversation around autonomous financial agents is still young. Every new deployment and every unexpected loss will add practical detail to the legal and operational frameworks that are only now taking shape. Those who treat the subject with clear eyes rather than hype will be better positioned when the next wave of volume arrives. And volume is coming. The only remaining question is how carefully the accompanying authority will be defined.