tech
Google can track exactly how your agent spends your money — but it's no help when it buys something you didn't approve
You tell an artificial intelligence agent, an AI capable of autonomous reasoning and multistep actions, “Find me a shirt for less than $30, but do not buy it.” The agent finds one – and places the order anyway.

TL;DR
- AI agents can perform multistep actions, including purchases, which can lead to disputes when they act against user instructions (e.g., buying when told not to).
- Current record-keeping systems across different companies (retailer, payment service, AI provider) are fragmented and lack a verifiable link between the user's initial instruction and the final transaction outcome.
- Senator Mark Warner's AI AGENT Act (S. 5051) proposes defining 'custodial user agents' and requiring real-time records, but does not mandate a cross-system verifiable evidence chain.
- A robust verification system would need to bind user accounts, agents, and tasks, enforce task-specific limits, and maintain a verifiable linkage across the entire transaction, including checks before each action and tamper-evident records.
- Technical solutions like task references and digitally signed authorization records are discussed as ways to create linkage and verify authority.
- Google's Agent Payments Protocol (AP2) is mentioned as an example that meets some requirements for evidence travel, but does not determine liability or data retention policies.
- The challenge of verifying agent actions extends beyond simple purchases to more significant transactions like financial transfers or benefit appeals.
- Current NIST efforts focus on agents within organizations, deferring the complex case of consumer agents crossing company boundaries.