Your Client’s Shopping Bot Clicked “Buy.” Who (or What) Made the Contract?

by | Sep 28, 2026 | AI, Attorneys, Cell phones, Digital Forensics, Expert Witness Insights, Forensic stories, Shopping Agent, Tech | 0 comments

We have spent years teaching computers to answer our questions, although sometimes it is the other way around. Now we are teaching them to spend our money. The first time an AI shopping agent orders the wrong shoes, nobody will call a lawyer, but the first time it orders 4,000 of them for a company, somebody will.This isn’t just a mental exercise. In September, Amazon blocked Meta’s Muse agent from shopping on its platform, citing a lack of authorization, an agent that didn’t identify itself, and the handling of customer credentials. Amazon has also blocked some agents from OpenAI and Google. Banks have separately warned that shopping agents may buy the wrong product, exceed a budget, steer customers toward weaker payment protections, or expose them to scams and fraud.

That raises a deceptively simple question: When the bot clicks “Buy,” who agreed to the contract?

The short answer is usually the person or company that deployed, authorized, or controlled the bot—not the bot itself. But the short answer rarely ends the argument. The longer answer, which is the one that could generate billable hours, is whether the bot acted within the authority it was given.

The federal E-SIGN Act provides that a contract involving interstate or foreign commerce cannot be denied legal effect, validity, or enforceability solely because its formation involved one or more electronic agents, so long as the agent’s action is legally attributable to the person to be bound. E-SIGN removes the electronic-agent objection; it does not itself establish agency, assent, scope of authority, or compliance with other applicable law. 15 U.S.C. § 7001(h).  State law may matter as well, including state enactments of the Uniform Electronic Transactions Act (UETA), whose § 14 addresses automated transactions.

So the fact that no human physically clicked the button does not automatically make the transaction disappear. We crossed that bridge years ago with automated ordering systems. Today’s bots are just crossing it with your credit card in their (virtual) hands.

The harder issue is authorization.

Suppose a client tells an agent, “Find me a laptop under $1,500 with at least 32 gigabytes of memory,” and the agent buys one for $1,425. That looks comfortably authorized. Now suppose it buys a $2,300 laptop because it decides the improved processor is “worth the investment.” Helpful initiative, perhaps. Also a decent opening paragraph for a complaint.

Agency principles will matter. What authority did the user actually grant? What limits appeared in the prompt, account settings, purchasing policy, or platform terms? Did the user authorize the transaction itself? Did the merchant’s terms allow this type of automated or third-party access? Did the agent have authority to manifest assent to the merchant’s terms on the user’s behalf? And did the merchant have reason to know that the agent was operating outside its instructions?

These disputes will be won or lost on the digital record, and much of that record is logs.

Attorneys should stop thinking of the receipt as the complete record. It’s not a piece of paper in your pocket. The relevant evidence may include the user’s original prompt and follow-up instructions; spending limits and product filters; whatever agent action history exists, tool-call logs, audit trails, and system events; model and software versions; authentication records; cart changes; confirmation screens; and the merchant’s server logs.

blankCollect it early. AI systems and their vendors do not necessarily retain every step indefinitely. A clean-looking final confirmation can conceal ten earlier decisions, three rejected products, a changed budget, and one hallucinated free-shipping offer. Hallucinated by the bot, that is.

Then there is the chargeback problem. Consumers may assume that “the AI did it” means “unauthorized.” Card issuers and banks may see a more complicated record. A purchase made through credentials deliberately supplied to an agent is not automatically equivalent to a stolen-card transaction. Whether a customer has a chargeback right, an error-resolution claim, or some other remedy may depend on the payment method, the issuer’s and network’s rules, the authentication record, the instructions given to the agent, the merchant’s conduct, and whether the agent made an unauthorized purchase or merely made an authorized purchase badly.blank

In other words, buyer’s remorse does not become a stolen-card case just because software was involved.

Fraud and privacy add another layer. A shopping agent may see card details, purchase history, addresses, brand preferences, and perhaps the contents of an email account or calendar. A compromised agent could make an unauthorized purchase. A perfectly functioning agent could also be manipulated by a fraudulent listing, a poisoned recommendation, or a merchant designed to look legitimate to software rather than to a human.

For attorneys advising businesses, now is the time to ask practical questions. Are agent-made purchases permitted? Is human approval required above a stated amount? Are transaction logs preserved? Can the system explain which instruction caused it to choose a product? Can the agent accept arbitration clauses, subscriptions, or recurring charges? And who receives the alert when it gets creative?

Like agency law, consumer protection, and the rules of evidence, contract law isn’t going anywhere. It just has a new participant: one that works quickly, reads terms instantly, and has never once felt the healthy hesitation that comes from entering a credit-card number. Has it ever felt anything?

The bot may have clicked “Buy.” The case may turn on who told it that it could.

Questions about the digital trail behind an automated transaction? Burgess Forensics examines system logs, account activity, metadata, and other digital evidence. (866) 345-3345 | steve@burgessforensics.com

 

 

Related Posts

Happy Forensic Science Week!

TV has made digital forensics seem like it’s a piece of cake—all you have to do is lean toward a blurry security camera frame, say “Enhance,” and it will work. Every time. (At least on CSI.) In honor of the week, here are a few things television has taught the public...

Auto-Delete, Take Two: Regulatory Fines Can Dwarf Sanctions

Deleting the messages was the cheap part. I recently wrote about sanctions: the adverse-inference instruction, the spoliation finding, the judge with disapproval written all over his face telling the jury it may assume the worst about whatever got erased. That's a...

Your Client Told a Chatbot His Defense Strategy. Is It Still Privileged?

Your client wanted an early start. What he handed over was an early Exhibit A. Picture this: he knows he's under investigation, but he's anxious, he can't sleep, and he wants to get ahead of the thing. So, he opens a chatbot at 1 AM and does what people do now: he...

The Fourth Amendment Meets the Fourth Dimension

The Fourth Amendment walks into the fourth dimension. The bartender says, “Why are you here?” The Fourth Amendment replies, “You’re going to need probable cause to ask me that.” In some of my earlier articles and videos, I referred to a “Fourth Amendment search”...

Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed

Your phone has been keeping a travel diary. For years, Google kept a copy too. That made possible one of the more controversial investigative tools of the smartphone era: the geofence warrant, sometimes called a reverse-location warrant. Instead of starting with a...

When “Auto-Delete” Becomes “Adverse Inference”

The messages were set to delete within an hour, and some of those settings were changed after a litigation hold had already landed. That was really the whole idea. If you practice long enough, you learn that the tools change but human nature doesn't. Caveguy Ugg...

What Happens to Your Digital Life When You Die (And Who Can Access It)

By Steve Burgess, Burgess Forensics, 2026 “He passed last month, and his whole life is locked inside his phone. Can’t you just get in?” I hear some version of that rather often —more than you might think, in fact. The request comes from grieving families, from...

Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access

“It’s encrypted, so I guess we’re just out of luck.” I hear some version of that from attorneys and other clients more often than you’d think, usually said with a kind of resigned finality, as though the phone in evidence had sealed itself inside a block of concrete....

The Metadata You Didn’t Know You Were Sending

You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren't looking. That paperwork is metadata — data about data. And it travels with your files whether or not...

Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having

The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: "produce as PDF, that's fine." Maybe not so fine when that same attorney later pays me to...

Pin It on Pinterest

Share This