When Software Acts: Contracting for the Agentic AI Era

Legal Alert
Agentic AI systems create risks that traditional software agreements may not fully address because they can take actions with limited human intervention—not just generate content or recommendations. Organizations should consider how their agreements define authority, oversight, data governance, accountability, liability, and protections against unauthorized actions.

Artificial intelligence is rapidly evolving from a tool that assists users to a technology capable of acting on their behalf. While generative AI systems typically produce content in response to user prompts, agentic AI systems can plan tasks, access tools, interact with connected systems, and execute workflows with limited human intervention.

That distinction matters because an AI-generated recommendation and an AI-performed action present very different risks. A mistaken summary may create an accuracy problem. An autonomous agent that sends a communication, changes permissions, deletes records, initiates a purchase, or accesses an external system may create an operational, legal, security, or regulatory event.

Why Agentic AI Changes Licensing Assumptions

Recent news reports involving rogue autonomous AI agents have focused attention on the challenges of governing systems capable of acting independently. Agentic AI breaks many assumptions embedded in conventional software agreements. Historically, software users made decisions and software executed. Agentic systems blur that distinction by pursuing objectives, selecting methods, and performing actions over time.

Autonomous systems may identify unexpected pathways, tools, or sources of information while attempting to achieve assigned goals. When software can take actions instead of merely generating outputs, agreements should expressly address the scope of permissible conduct, oversight requirements (e.g., logging, monitoring, audit trails), and responsibility for autonomous decisions (e.g., escalation procedures and suspension rights).

The lesson for organizations is not that agentic AI should be avoided. Rather, it is that companies should evaluate and contract for agentic AI differently than they would traditional SaaS offerings.

Define Authority, Not Just Authorized Users

Traditional SaaS licenses focus on named users, access rights, uptime, and restrictions on copying or redistribution. Agentic AI agreements must also define what the system may access, decide, communicate, change, and execute. Agents may interact with CRM platforms, email systems, cloud storage, procurement tools, financial applications, HR systems, databases, and third-party APIs, often with little or no real-time human involvement.

A general requirement for “human oversight” is rarely enough. Instead, companies should consider implementing a structured authorization framework that distinguishes between:

  • Autonomous actions, such as knowledge retrieval, content drafting, data classification, workflow initiation, and ticket creation;
  • Human-approval actions, such as external communications, customer-facing decisions, security changes, access provisioning, and financial approvals; and
  • Prohibited actions, such as executing contracts, transferring funds, making employment decisions, filing regulatory reports, or waiving legal rights.

The agreement should also establish spending thresholds, approval workflows, escalation rights, data-access classifications, and the requirement for the creation and maintenance of a detailed (granular) log of all actions and decisions taken by the AI agent that is immutable, meaning the log may not be altered by any AI agent. Clearly defined authorization boundaries reduce ambiguity and provide a stronger foundation for allocating risk if an agent acts outside its intended parameters.

Responsibility Should Follow Control

One of the most important questions in any agentic AI agreement is deceptively simple: when an AI agent takes an action, who is responsible?

The answer should generally depend on control. Customers may appropriately assume responsibility for their data, instructions, configurations, and business decisions. Vendors may appropriately bear responsibility for system design, security controls, authorization mechanisms, and failures that permit agents to exceed agreed limitations. Some organizations use a case-specific approach that allocates responsibility differently depending on whether the agent is recommending, drafting, executing, or transacting. In many deployments, a shared-responsibility model may provide the most balanced approach and is likely to become the preferred framework because both parties typically influence outcomes.

This allocation of responsibility should be reflected throughout the agreement, including warranties, indemnities, audit rights, and limitation-of-liability provisions. Traditional software contracting concepts remain relevant, but they may not fully address risks arising from autonomous actions, particularly when agents can communicate externally, alter records, trigger workflows, or access sensitive information.

Data Governance and Change Management Are Critical

Data governance remains a central concern in any AI deployment, but agentic systems introduce additional complexity. Agents may access multiple data sources, combine information across systems, generate inferences, and interact with third-party tools and services.

Organizations should pay particular attention to provisions governing:

  • Data ownership and usage rights;
  • Model training restrictions;
  • Retention and deletion obligations;
  • Audit and monitoring rights; and
  • Third-party model providers and subprocessors.

Equally important is change management. Agentic systems may evolve through model updates, new integrations, workflow changes, or modifications to underlying tools. Agreements should address how material changes will be communicated and what rights customers have when changes affect system behavior, security controls, compliance obligations, or the degree of autonomy exercised by the agent.

Key Contract Provisions to Review

As organizations evaluate agentic AI solutions, several provisions deserve heightened attention:

  • Clear definitions of the agent, solution, and authorized use case;
  • Delegation-of-authority provisions and approval requirements;
  • Data ownership and training restrictions;
  • Governance, audit, and logging requirements;
  • Warranties addressing autonomous conduct;
  • Indemnification for harms arising from unauthorized agent actions;
  • Liability frameworks calibrated to autonomous-action risks; and
  • Transition and wind-down procedures for long-running agents.

These are no longer merely technology issues. They are business risk, governance, and legal risk allocation issues that should be addressed at the contracting stage.

Looking Ahead

Agentic AI offers significant opportunities to increase efficiency, automate workflows, and improve decision support. At the same time, the technology challenges traditional assumptions about who is acting, who is in control, and who bears responsibility when something goes wrong.

Organizations should resist the temptation to treat agentic AI as simply another SaaS product. Instead, agreements should establish clear authority boundaries, define accountability, implement meaningful governance controls, and align risk allocation with the realities of autonomous action. As AI systems continue to evolve, thoughtful contracting will remain one of the most effective tools for managing both innovation and risk.

About the Author

  • Tanya A. Huertas-Langevin practices in the areas of technology transactions, data privacy, and AI governance, representing companies that develop, license, acquire, and deploy technology and data-driven products. She advises on software, SaaS, cloud services, and technology licensing agreements, AI compliance programs, data-sharing and data protection arrangements, and privacy compliance under domestic and international frameworks, including the GDPR, CCPA, and cross-border data transfer requirements.

Related Professionals

Related Practices & Industries

Practices

Industries

Media Contact

Jamie Moss (newsPRos)
Media Relations
w. 201.493.1027 c. 201.788.0142
Email

Bree Metherall
Chief Marketing and Business Development Director
503.294.9435
Email

Jump to Page
Stay Informed Arrow

Subscribe to Our Updates