Agentic AI

When we first wrote about drafting AI clauses in early 2025, the dominant concern was how to handle generative AI tools that produce content in response to prompts.  While that is still an important concern, the AI landscape has, in a short space of time, evolved considerably.  We're finding that the uptake of agentic AI in particular is proving to be challenging and raises new issues that need to be carefully considered.

Agentic AI refers to systems that can plan, make decisions, and take actions autonomously towards a defined objective without constant human input at each step.  Unlike a generative AI tool that waits to be prompted, an AI agent can be given a goal and work out how to achieve it.  This might mean that agentic AI is browsing websites, sending communications, or entering into transactions on the organisation's behalf.  A 2025 Accenture study predicts that by 2030, AI agents will be the primary users of most enterprises' internal digital systems, and major vendors including Google, Microsoft, and Salesforce have already released agentic AI solutions.

This raises a practical question about whether existing contractual clauses created with generative AI in mind will be fit for purpose when AI systems can act, not just generate.  The short answer is no.  Most technology contracts (even those with AI-specific clauses) were designed for AI that produces an output and a human deciding what to do with that output.  With agentic AI, the system takes action, and the human may only find out afterwards.  That gap between contract design and how agentic AI actually operates can create legal and commercial risk.

Unfortunately, there is no single standard clause that can be used to address that risk for every agentic AI tool.  An agent that drafts internal communications poses very different risks from one authorised to execute financial transactions.  A tailored, risk-based approach is needed.

What makes agentic AI different?  Why does it matter for contracts?

The key difference between generative AI and agentic AI is autonomy.  Agentic systems pursue objectives through a sequence of actions (using APIs, databases, and websites), making decisions at each step without a human reviewing each action.

This creates several risks that standard AI clauses are not designed to address:

  • Unauthorised action: agentic AI can take an action (eg send a communication or execute a transaction) that the human or organisation did not intend or authorise, even if it was within the broad parameters set for the agentic AI.

  • Layered liability: agentic AI often relies on a variety of sources (eg APIs, and websites).  If an agent causes harm because a third-party data feed provided the agentic AI with incorrect information, who is liable?  Should it be the customer, the AI tool provider, or the third party data owner (who may not even be aware of how or where their data is used)?

  • Invisibility: agentic AI acts autonomously and at speed.  This can mean that harmful or erroneous actions may not be readily apparent and can take time to be uncovered.

  • Contracting authority: if an AI agent is given authority to interact with third parties, questions of authority and contract formation can arise.  For example, can an agent bind the organisation?

So what should contracts for agentic AI address?

In relation to agentic AI in particular, the following issues will require careful consideration (in addition to the standard AI contracting questions summarised in our earlier article):

  • Scope and authority of the agent: as with any agent, it is critical to be clear in any contract with a vendor providing an AI agent tool about what an AI agent's authority is.  Contracts should define clearly the scope of actions the agent is permitted to take, the systems and data it may access, and the circumstances in which it may interact with third parties. Where the agent may take actions that bind the customer (eg placing orders or sending communications), the contract should address how that authority is conferred, how it can be withdrawn, and what happens if the agent acts outside its authorised scope (including clearly setting out the vendor's liability for unauthorised action).  This is an area where technology controls (ie limiting what the agent can access or do at a system level) and contractual controls need to work together.

  • Transparency and explainability: with generative AI, transparency typically means understanding how the model produces outputs.  With agentic AI, the question is harder: can the supplier explain the sequence of decisions and actions the agent took to reach an outcome?  Contracts should require that the supplier maintain sufficient logging of agent actions to enable post hoc review (in a form that can be readily accessed and understood), and that the system be capable of producing a comprehensible audit trail.  Where AI agents interact with third-party tools or APIs, the contract should address how the supplier provides visibility regarding those interactions.

  • Human oversight and escalation: the key risk of agentic AI is that it can take actions faster than a human can intervene. Contracts should address what human oversight mechanisms are built into the agent's operation: are there checkpoints at which a human must approve an action before it is taken?  What triggers an escalation?  How does the system behave if it encounters a situation outside its training or parameters?  If agentic AI is used as part of critical systems, customers may expect human-in-the-loop checkpoints.

  • Logging, audit, and incident response: as agentic AI acts autonomously, robust logging is essential for accountability and for investigating things that go wrong.  The contract should also specify what the customer's rights are in relation to those records, what responsibility the AI agent vendor has for monitoring and identifying erroneous or harmful actions and what the vendor must do if such action is discovered (eg notification and remediation obligations).

  • Accuracy, bias, and security: for generative AI, an inaccurate output is a problem the human reader must catch.  For agentic AI, an inaccurate output at one step can become embedded into further actions by the agent before a human is involved.  Contracts should address accuracy standards for agentic AI outputs, and testing obligations (including for bias).  Security can also be more complex for agentic AI.  AI agents that access external systems and APIs can be exposed to prompt injection attacks (where malicious inputs are disguised as legitimate prompts to manipulate the AI agent's behaviour), as well as the security risks associated with any third-party integration.  Security requirements should be carefully considered.

Organisations procuring agentic AI tools should not assume that AI clauses drafted for generative AI are sufficient.  The autonomous, multi-step, and often opaque nature of agentic AI systems requires careful thought.  If you would like to discuss how to approach agentic AI contracting for your organisation, please contact a member of our technology, media and telecommunications team.