We have spent years teaching computers to answer our questions, although sometimes it is the other way around. Now we are teaching them to spend our money. The first time an AI shopping agent orders the wrong shoes, nobody will call a lawyer, but the first time it orders 4,000 of them for a company, somebody will.
This isn’t just a mental exercise. In September, Amazon blocked Meta’s Muse agent from shopping on its platform, citing a lack of authorization, an agent that didn’t identify itself, and the handling of customer credentials. Amazon has also blocked some agents from OpenAI and Google. Banks have separately warned that shopping agents may buy the wrong product, exceed a budget, steer customers toward weaker payment protections, or expose them to scams and fraud.
That raises a deceptively simple question: When the bot clicks “Buy,” who agreed to the contract?
The short answer is usually the person or company that deployed, authorized, or controlled the bot—not the bot itself. But the short answer rarely ends the argument. The longer answer, which is the one that could generate billable hours, is whether the bot acted within the authority it was given.
The federal E-SIGN Act provides that a contract involving interstate or foreign commerce cannot be denied legal effect, validity, or enforceability solely because its formation involved one or more electronic agents, so long as the agent’s action is legally attributable to the person to be bound. E-SIGN removes the electronic-agent objection; it does not itself establish agency, assent, scope of authority, or compliance with other applicable law. 15 U.S.C. § 7001(h). State law may matter as well, including state enactments of the Uniform Electronic Transactions Act (UETA), whose § 14 addresses automated transactions.
So the fact that no human physically clicked the button does not automatically make the transaction disappear. We crossed that bridge years ago with automated ordering systems. Today’s bots are just crossing it with your credit card in their (virtual) hands.
The harder issue is authorization.
Suppose a client tells an agent, “Find me a laptop under $1,500 with at least 32 gigabytes of memory,” and the agent buys one for $1,425. That looks comfortably authorized. Now suppose it buys a $2,300 laptop because it decides the improved processor is “worth the investment.” Helpful initiative, perhaps. Also a decent opening paragraph for a complaint.
Agency principles will matter. What authority did the user actually grant? What limits appeared in the prompt, account settings, purchasing policy, or platform terms? Did the user authorize the transaction itself? Did the merchant’s terms allow this type of automated or third-party access? Did the agent have authority to manifest assent to the merchant’s terms on the user’s behalf? And did the merchant have reason to know that the agent was operating outside its instructions?
These disputes will be won or lost on the digital record, and much of that record is logs.
Attorneys should stop thinking of the receipt as the complete record. It’s not a piece of paper in your pocket. The relevant evidence may include the user’s original prompt and follow-up instructions; spending limits and product filters; whatever agent action history exists, tool-call logs, audit trails, and system events; model and software versions; authentication records; cart changes; confirmation screens; and the merchant’s server logs.
Collect it early. AI systems and their vendors do not necessarily retain every step indefinitely. A clean-looking final confirmation can conceal ten earlier decisions, three rejected products, a changed budget, and one hallucinated free-shipping offer. Hallucinated by the bot, that is.
Then there is the chargeback problem. Consumers may assume that “the AI did it” means “unauthorized.” Card issuers and banks may see a more complicated record. A purchase made through credentials deliberately supplied to an agent is not automatically equivalent to a stolen-card transaction. Whether a customer has a chargeback right, an error-resolution claim, or some other remedy may depend on the payment method, the issuer’s and network’s rules, the authentication record, the instructions given to the agent, the merchant’s conduct, and whether the agent made an unauthorized purchase or merely made an authorized purchase badly.
In other words, buyer’s remorse does not become a stolen-card case just because software was involved.
Fraud and privacy add another layer. A shopping agent may see card details, purchase history, addresses, brand preferences, and perhaps the contents of an email account or calendar. A compromised agent could make an unauthorized purchase. A perfectly functioning agent could also be manipulated by a fraudulent listing, a poisoned recommendation, or a merchant designed to look legitimate to software rather than to a human.
For attorneys advising businesses, now is the time to ask practical questions. Are agent-made purchases permitted? Is human approval required above a stated amount? Are transaction logs preserved? Can the system explain which instruction caused it to choose a product? Can the agent accept arbitration clauses, subscriptions, or recurring charges? And who receives the alert when it gets creative?
Like agency law, consumer protection, and the rules of evidence, contract law isn’t going anywhere. It just has a new participant: one that works quickly, reads terms instantly, and has never once felt the healthy hesitation that comes from entering a credit-card number. Has it ever felt anything?
The bot may have clicked “Buy.” The case may turn on who told it that it could.
Questions about the digital trail behind an automated transaction? Burgess Forensics examines system logs, account activity, metadata, and other digital evidence. (866) 345-3345 | steve@burgessforensics.com
