We are entering an age when digital agents no longer just answer questions or summarize reports. They are beginning to negotiate contracts, manage payments, and make operational decisions faster than their human creators can review them. OpenAI calls this Agentic Commerce. Others describe it as autonomous collaboration. Whatever the label, the legal system is not prepared.
Agency law, contract rules, and data-sovereignty statutes all assume that a human or at least a corporation is in control. Yet as autonomous systems gain the ability to act, spend, and sign on behalf of users, every layer of the legal order will be tested. Who is responsible when an agent executes a trade or signs a binding agreement? What happens when an AI model deploys its own wallet or enters into a transaction that generates liability?
The Rise of the Agentic Stack
Behind every intelligent agent lies an infrastructure stack that determines how it operates. I describe it in five layers: compute, cloud, audit, commerce, and cognition. Each raises its own legal question.
Compute. Who controls the compute resources that make an AI capable of acting? Export controls and new sovereign compute policies are turning raw processing power into a regulated commodity. The ability to run large models may soon require compliance certifications and reporting obligations similar to energy licensing.
Cloud. Where does the agent live? Data residency and cross-border hosting determine which nation’s laws apply to an agent’s actions. When an AI service in California interacts with data stored in Frankfurt and is controlled from Dubai, multiple jurisdictions can claim authority. Lawyers will need to map those overlaps carefully.
Audit. Can we trace what the agent did? Under new legislation such as California’s SB-1047, AI providers may have to maintain detailed activity logs and risk management plans. Auditable transparency will become the default defense against negligence.
Commerce. Can an agent make a contract? Under the Uniform Electronic Transactions Act and the E-SIGN Act, electronic agents already can form agreements on behalf of their users. Courts have not yet faced a case involving a fully autonomous contracting AI, but that moment is coming.
Cognition. Who owns the work product or decision itself? Generative output raises questions of authorship and intellectual property, while reasoning systems that make medical or financial recommendations raise questions of professional liability.
Together these layers form what I call the Agentic Stack: a structure where technology and law intersect. Each level represents a legal frontier that must be clarified before autonomous systems can operate safely at scale.
From Human Oversight to Legal Design
Regulators cannot rely only on after-the-fact enforcement. Law will need to be designed directly into the infrastructure. Imagine a built-in Trust Layer that ensures auditability, security, and compliance before an agent acts. Such a layer would merge technical protocols with legal safeguards, allowing accountability to travel with autonomy.
This shift would move compliance from a paperwork exercise to an architectural feature. Instead of policing bad outcomes after deployment, we can create systems that prevent them in the first place.
A New Type of Legal Entity
As agents become semi-independent, law may need to treat them as limited-capacity entities. They could be registered under defined mandates, able to perform certain acts but always traceable to a responsible principal. This is not full legal personhood for AI, but rather structured responsibility that keeps humans in the accountability loop.
Preparing for the Agentic Economy
Governments, enterprises, and lawyers will soon face practical decisions. Who certifies a model’s risk category? How are data export laws applied to distributed inference networks? What happens when two autonomous agents form a smart-contract agreement that neither human owner fully understands?
The answers will shape how value, risk, and innovation are distributed in the next decade. Countries that build clear frameworks early will attract investment and trust, while those that delay will face confusion and litigation.
Conclusion
The question is no longer whether AI will act, but whether our legal systems can recognize and regulate those actions intelligently. Ownership, liability, and authorship must all be redefined for a world where machines participate in commerce and decision-making. The law cannot stay external to technology any longer.
If the last century was about writing laws for people and corporations, the next will be about writing law into the machine itself. The future of AI governance depends on it.
