The familiar complaint runs the other way: technology sprints, law limps behind. The E-SIGN Act is a counterexample sitting in plain sight. In June 2000, Congress put into federal law that a contract "may not be denied legal effect, validity, or enforceability solely because its formation, creation, or delivery involved the action of one or more electronic agents." The same statute defines an electronic agent as an automated system acting "without review or action by an individual at the time of the action or response."
Machine-formed contracts, given federal standing two decades before anyone shipped software capable of reasoning its way through a checkout page. Then the sentence keeps going:
"so long as the action of any such electronic agent is legally attributable to the person to be bound."
Everything else in the provision rests on that clause, and nowhere does the statute say what makes a machine's action attributable to whoever put it into service. The Senate report on the predecessor bill handled attribution by treating it as a question of common-law principles already in force, which is Congress pointing at a body of law rather than writing one. The legislative record keeps the question open.
For twenty-five years that worked, for a reason more mundane than foresight or failure: the question never had to stand up on its own. When an automated system does exactly what someone specified, attribution and authorship collapse into the same fact. The official commentary to E-SIGN's state-level companion, the Uniform Electronic Transactions Act, comes close to saying so outright: in an automated transaction, "the requisite intention flows from the programing and use of the machine." The illustrations are inventory systems reordering stock when it drops below a threshold. Nobody has to infer intent in that world, because intent is sitting in the source code, legible and dated.
Which is what makes this something other than sloppy drafting. The drafters could see the load coming. The same commentary describes its own paradigm as bounded by "the technical strictures of its preset programming," and then, in the next breath, turns to systems with "the ability to act autonomously, and not just automatically," able to revise their own instructions. They wrote down the exact condition that would test the joint, and left construing it to courts that would meet the condition later. It is a note tucked behind the drywall for whoever eventually opens the wall.
Very little has loaded that joint since. The nearest thing to a real test is Singapore's Court of Appeal in 2020, holding trading firms to algorithmically executed cryptocurrency trades struck at roughly 250 times the market rate. Assessing a mistake defense meant establishing what the parties knew at the moment of execution, and with deterministic software that reduces to asking what the programmer knew, since the program can do nothing the programmer did not put in it. The court was explicit that its reasoning was built for deterministic programs.
That premise has stopped holding. In a controlled study accepted to CHI 2026, researchers pointed an agent at a mock website's graphical interface and asked it to subscribe to a creator. The agent consented to sharing the user's data for personalized advertising, having concluded the step was required, and asked nobody. The setting was artificial; the gap it opens is not. A subscription was authorized. The data sharing was authorized by no one.
Underneath the whole structure sits a factual assumption nobody wrote down, because for decades nobody had to: that any machine action traces back to a human decision about that action. Selection, substitution, and inference wear that assumption thin. For the first time the clause is taking the load directly. The legal literature has generated several plausible answers and no agreement about which one governs, and disagreement at that altitude has a practical meaning: nobody is looking the answer up.
We have watched a version of this before. When paper forms became HTML forms, the signature field ported over intact while the question of who was entitled to fill it quietly went missing. A deferral like this gets settled by whichever dispute reaches a tribunal first, and that is not a random draw. It is whoever has the litigation budget and the appetite, arriving with facts that may look nothing like an ordinary transaction. Those facts are being produced right now, in production, by people who do not know they are drafting the record.
-
A chatbot's words, billed: The closest thing to a live test is a small Canadian tribunal decision holding an airline responsible for its chatbot's bad advice on the reasoning that the bot was "still just a part of Air Canada's website" — a tort case, not contract formation, and worth reading for how narrow the holding actually is.
-
The 1999 warning: A preliminary working-group memorandum submitted to the UETA drafters argued for deeming an agent's operations the user's acts while preserving defenses for lack of authority, malfunction, hijacking, and "unpredictable operation" — the objection to strict attribution was on the table before the statute passed.
-
Risky agents without intentions: Ayres and Balkin take the hardest line on allocation, arguing that because contract law runs on objective manifestations rather than private intent, a principal who deploys an AI contracting agent cannot escape by pleading ignorance of what the system did.
-
Contract or tort: A competing view holds that as human review of machine-generated terms falls away, high-uncertainty agent bargaining may fit tort law better than contract enforcement — a reframing that would move the whole question out from under E-SIGN.

