Liability and Accountability
Suppose an agent, acting on its own, makes a payment it should not have made, or is tricked into leaking sensitive data, or agrees to something costly on your behalf. Who is responsible? The question sounds almost philosophical, and the answer turns out to be more uncomfortable and more practical than most people building in this space assume.
The law treats an agent as a tool
As the law stands in most places today, software is treated as a tool, not as a party that can hold property, enter into a contract, or bear responsibility of its own. An agent, however capable it seems, is in legal terms closer to a hammer than to a person. The consequence is direct. The people behind the agent, the developer who built it and the operator who deployed it, generally carry the liability for what it does. An agent cannot meaningfully sign an agreement, and it cannot be sued in its own name. The comfortable mental image of two agents striking a deal between themselves runs straight into the fact that, in the eyes of the law, two humans remain answerable for whatever their software agreed to.
The rules are still being written
The major regulations now arriving, covering digital assets and artificial intelligence, were largely not written with autonomous, machine-to-machine activity in mind. For the most part they do not yet speak clearly to who is liable when agents act on their own, to how an agent's identity should be established, or to what happens when two automated systems transact without a person present. This is not a criticism of the lawmakers so much as an observation about timing. The technology is moving faster than the frameworks meant to govern it, and there is a gap between the two that has not yet been closed.
Why the gap argues for caution, not recklessness
It would be a mistake to read that gap as permission. A rule that has not been written yet is not a rule you have safely avoided. It is a risk whose shape is not yet clear, which is a reason to build conservatively rather than boldly. In practice that means keeping humans accountable by design, setting firm limits on what an agent may do without approval, and keeping records detailed enough that responsibility can be traced when something goes wrong. Read in this light, the Code of Conduct on the previous page is not idealism. Until the law catches up, principles like those are the practical way to stay on the right side of a line that has not yet been drawn, and to be able to show, if you are ever asked, that you acted with care.
A necessary note
This page is an informed overview of a fast-changing area, and it varies from one country to another. It is not legal advice, and it should not be treated as a substitute for it. For anything consequential, consult a professional who knows the law where you operate, and watch the Analysis section as the rules take shape, because this is one of the places the ground is most likely to move.