tech

Google can track exactly how your agent spends your money — but it's no help when it buys something you didn't approve

You tell an artificial intelligence agent, an AI capable of autonomous reasoning and multistep actions, “Find me a shirt for less than $30, but do not buy it.” The agent finds one – and places the order anyway.

Google can track exactly how your agent spends your money — but it's no help when it buys something you didn't approve

TL;DR

  • AI agents can perform multistep actions, including purchases, which can lead to disputes when they act against user instructions (e.g., buying when told not to).
  • Current record-keeping systems across different companies (retailer, payment service, AI provider) are fragmented and lack a verifiable link between the user's initial instruction and the final transaction outcome.
  • Senator Mark Warner's AI AGENT Act (S. 5051) proposes defining 'custodial user agents' and requiring real-time records, but does not mandate a cross-system verifiable evidence chain.
  • A robust verification system would need to bind user accounts, agents, and tasks, enforce task-specific limits, and maintain a verifiable linkage across the entire transaction, including checks before each action and tamper-evident records.
  • Technical solutions like task references and digitally signed authorization records are discussed as ways to create linkage and verify authority.
  • Google's Agent Payments Protocol (AP2) is mentioned as an example that meets some requirements for evidence travel, but does not determine liability or data retention policies.
  • The challenge of verifying agent actions extends beyond simple purchases to more significant transactions like financial transfers or benefit appeals.
  • Current NIST efforts focus on agents within organizations, deferring the complex case of consumer agents crossing company boundaries.