Intent, Mandates, and the Law: What Happens When AI Misinterprets a Consumer's Instructions
arrow_backAll posts

1 June 2026

Intent, Mandates, and the Law: What Happens When AI Misinterprets a Consumer's Instructions

Daniel Bamidele

Written by

Daniel Bamidele

You said "get me something for dinner." The agent bought a kitchen.

Picture this.

You are running late. You fire off a quick instruction to your AI shopping agent: "Get me something nice for the weekend." You are thinking a bottle of wine, maybe some good cheese, perhaps a nice cut of meat for Saturday dinner.

Your agent, having previously noted that you mentioned your kitchen was feeling tired, your last three weekend purchases were home-related, and that you once searched for kitchen renovation ideas, decides "something nice for the weekend" clearly means a new countertop installation. Booked. Paid. Confirmed. Have a lovely weekend.

Absurd? Yes. Impossible? Not remotely.

This is the intent problem. And it sits right at the intersection of technology, consumer protection, contract law, and a set of very old legal principles that nobody ever imagined would one day apply to software making grocery runs.

The question of what happens when an AI agent misinterprets your instructions is not a hypothetical. It is a question that courts, regulators, payment networks, and consumer advocates are all going to have to answer, probably sooner than any of them would like. And the answers, depending on which seat you are sitting in, look very different.

Let us take a walk through those seats.

The Consumer's View: I Did Not Ask For This

Start where it matters most. The person whose money was spent.

From a consumer's perspective, the experience of an AI agent misinterpreting your instructions sits somewhere on a spectrum. At the mild end, the agent buys the slightly wrong thing. Wrong size, wrong colour, different brand than you had in mind. Annoying. Fixable. You return it and move on.

At the serious end, the agent spends a significant sum on something you genuinely did not want, based on an interpretation of your words that made some kind of internal sense to the model but bears no resemblance to what you actually meant. You are now in a dispute, possibly with a merchant, possibly with the agent platform, possibly with your bank, and nobody is quite sure whose fault it is or what your rights are.

Here is what makes this genuinely hard for consumers.

In traditional commerce, the contract of sale is formed at the moment you, a human being with legal capacity, consciously agree to purchase something. You click the button. You tap the screen. You hand over the cash. There is a moment of clear, voluntary, informed consent that forms the legal basis of the transaction.

In agentic commerce, that moment is smeared across time and abstracted into language. You gave an instruction at some point. The agent interpreted it. The agent acted. By the time the purchase is made, you may have no idea it is happening, let alone whether it accurately reflects what you meant.

The consumer's question is a simple one, even if the answer is not: if the agent got it wrong, is this still my purchase? Am I bound by it? And if I am not, who is?

The Lawyer's View: Welcome to a Very Old Problem in Very New Clothes

Here is something that will either reassure you or mildly terrify you, depending on your disposition.

The law has been dealing with the problem of agents misinterpreting their principals' instructions for centuries.

Not AI agents. Human agents. Solicitors, brokers, employees, attorneys, factors, servants. The entire body of agency law, built up over hundreds of years of case law and statute, exists precisely because humans have always delegated tasks to other humans, and those other humans have always, occasionally, gotten it wrong.

The core principles are actually quite elegant. An agent has authority to act on behalf of a principal. That authority can be express, meaning specifically granted, or implied, meaning reasonably inferred from the circumstances. When an agent acts within their authority, the principal is bound. When an agent acts outside it, things get complicated.

There is a concept called apparent authority, where a third party reasonably believes the agent has authority it does not actually have, and the principal may still be bound. There is ratification, where a principal can choose to accept an agent's unauthorised act after the fact. There is the question of which party bears the loss when things go wrong, which typically depends on whose fault the misunderstanding was.

All of this is directly relevant to what is happening in agentic commerce right now. And yet it was all developed for human agents, with human judgment, human accountability, and a human who could be questioned, sued, or held responsible.

The lawyers' problem is not that there are no applicable legal principles. It is that all of the applicable principles were designed for a world where the agent is a person.

What is the "reasonable judgment" of a large language model? What does it mean for an AI agent to act in good faith? When a model hallucinates a product specification or misreads an ambiguous instruction, is that analogous to a human agent making an honest mistake, or is it something categorically different that existing law simply cannot accommodate?

These questions do not have clean answers yet. They will be answered, eventually, through a combination of legislation, regulation, and some spectacularly messy test cases in court. The lawyers who will argue those cases are, right now, probably in law school or junior associate positions, completely unaware of what is waiting for them.

The Merchant's View: Please Do Not Make This My Problem

Merchants occupy an interesting and uncomfortable position in the intent debate.

On one hand, they want the sales. Agentic commerce opens up an enormous new channel. Consumers who would never have found them organically, purchases made frictionlessly, transactions completed without the usual dropout rates of traditional checkouts. The upside is real.

On the other hand, merchants are increasingly anxious about receiving orders that turn out to be disputed, reversed, or legally contested because the agent misinterpreted the consumer's instructions and the consumer is now claiming they never authorised the purchase.

In traditional e-commerce, the chargeback process, as painful as it is, at least has a clear logic. The consumer says they did not authorise the transaction. The bank investigates. The merchant provides evidence. Someone wins, someone loses.

In agentic commerce, the question of authorisation is murkier. The consumer did authorise the agent. The agent did make the purchase. Whether the purchase accurately reflects the consumer's actual intent is a question that sits somewhere between those two facts, and the merchant is stuck in the middle of an argument they had no part in starting.

What merchants want, and what the protocols being developed are trying to provide, is a clean separation of responsibility. If the agent had a valid, logged mandate from the consumer, and the agent purchased something within the scope of that mandate, the merchant should not bear the loss when the consumer later claims they meant something different. The dispute is between the consumer and the agent platform. Not the merchant.

Whether that clean separation will hold up legally, in every jurisdiction, across every type of transaction, is a question nobody can fully answer yet. But the direction of travel is clear: merchants are going to push hard for frameworks that protect them from being the last line of defence against a problem they did not create.

The Platform's View: We Built the Thing, So Apparently Everything Is Our Fault

If you are building an AI agent platform right now, the intent problem keeps you up at night.

Because you are the one in the middle. You are the one whose system interpreted the consumer's instruction. You are the one whose model decided that "something nice for the weekend" was a kitchen renovation. And when the consumer complains, and the merchant wants to be held harmless, and the bank wants someone to absorb the chargeback, the eyes tend to drift toward you.

Platform liability in agentic commerce is genuinely unsettled. The frameworks that currently govern platform liability for user-generated content, or for algorithmic recommendations, do not map cleanly onto the scenario where the platform's AI is directly executing financial transactions on behalf of users.

This is why the mandate infrastructure being built into protocols like ACP and Visa's Trusted Agent Protocol matters so much from the platform's perspective. Not just as a consumer protection mechanism, but as a legal defence.

If a platform can demonstrate that it captured a specific, scoped, timestamped consent from the consumer before the agent acted, that the agent acted within the parameters of that consent, and that the consumer verified the consent with a biometric or passkey, the platform is in a much stronger position when things go wrong.

The mandate is not just a record of what the consumer wanted. It is the platform's evidence that it behaved responsibly. That it did not just let the agent loose with someone's payment credentials and hope for the best. That it took reasonable steps to verify, scope, and log the consumer's authorisation.

In the absence of that kind of infrastructure, platforms are exposed in ways that are hard to fully quantify right now but that will become very clear the first time a high-profile misinterpretation case lands in front of a judge.

The Regulator's View: We Are Going to Need a Bigger Rulebook

Regulators are watching agentic commerce with a combination of genuine interest and mounting concern.

Consumer protection law in most jurisdictions is built around a few foundational assumptions. That consumers have access to clear information before they make a purchase. That consent to a transaction is informed and voluntary. That there are meaningful remedies when things go wrong. That liability can be assigned to identifiable parties.

Agentic commerce stress-tests every single one of these assumptions.

What does "clear information before purchase" mean when the purchase is made by software that interpreted an instruction you gave hours or days earlier? What does "informed consent" mean when the consumer's role was to express a preference in natural language to a probabilistic system? What does "identifiable liable party" mean when the chain of causation runs from consumer instruction through multiple AI models and intermediary systems to a final transaction?

The regulatory challenge is not that consumer protections do not apply to agentic commerce. They do, and regulators will enforce them. The challenge is that the existing rules were written for a world that no longer fully exists, and writing new ones requires understanding a technology that is evolving faster than any legislative process can track.

What is likely to emerge, over the next few years, is a patchwork. Some jurisdictions will extend existing consumer protection frameworks by analogy, relying on courts to make the necessary adaptations. Others will draft specific agentic commerce regulation. Industry bodies will develop voluntary standards. Payment networks will update their operating rules. And through that messy, overlapping process, something resembling a coherent legal framework will eventually emerge.

The question is how many consumers get burned in the meantime.

The Technical View: The Problem Is Not Malice, It Is Probability

Here is something worth understanding if you are going to form a view on the intent problem.

AI agents do not misinterpret your instructions because they are careless, or poorly designed, or because anyone cut corners. They misinterpret them because of the fundamental nature of how large language models work.

These models are probabilistic systems. They do not parse your instruction and execute it deterministically. They generate a response, including a plan of action, based on patterns learned from vast amounts of text. The interpretation they produce is the most statistically likely interpretation given your instruction and the context available to them.

Most of the time, that works remarkably well. Language is full of ambiguity and the models navigate it with impressive fluency.

But sometimes the context misleads them. Sometimes the ambiguity in your instruction is genuine and the model resolves it in a direction you did not intend. Sometimes information earlier in the conversation, or in the model's broader context, skews the interpretation in ways that would surprise you if you could see inside the process.

This is not a bug that will be fixed in the next version. It is a property of the technology. And building legal and commercial frameworks around it requires accepting that ambiguity, misinterpretation, and edge cases are not exceptional failure modes. They are inherent features that the system needs to accommodate.

This is precisely why the mandate structure matters so much from a technical perspective. The more specific and structured the consent capture is, the less room there is for interpretive drift. "Buy me something nice" is a mandate that will cause problems. "Purchase groceries for pesto pasta, maximum spend of fifty pounds, from a verified merchant" is a mandate that leaves very little room for the kitchen renovation scenario.

The technical solution to the intent problem is not better AI. It is better constraint. Tighter mandates, clearer parameters, more structured consent capture. The model's probabilistic nature is a given. Containing it within well-defined guardrails is the design challenge.

What Needs to Happen Now

Across all of these perspectives, a few things are clear.

Mandate infrastructure needs to be standardised and robust. Not just as a best practice but as a baseline expectation. Every agentic transaction should have a logged, scoped, verified mandate behind it. Not vague natural language. Structured parameters with clear limits.

Liability frameworks need to be developed before the disputes pile up. The question of who bears the loss when an agent misinterprets a consumer's instruction is going to be answered one way or another. Better to answer it through deliberate policy design than through adversarial litigation that produces inconsistent outcomes and leaves everyone uncertain.

Consumer remedies need to be clear and accessible. Whatever legal framework emerges, consumers need to know, in plain language, what their rights are when an agent gets it wrong. Not buried in terms and conditions. Actually communicated, at the point of setting up an agent and at the point of any dispute.

And perhaps most importantly, the conversation about what agents can and cannot be trusted to decide autonomously needs to happen now, before the defaults get baked in and become impossible to change.

Because the intent problem is, at its core, a question about the nature of delegation. How much of your judgment can you hand to a system that thinks in probabilities? Where do you draw the line between what the agent decides and what you decide? And what are the consequences, legal, financial, and practical, when that line is crossed?

These are not questions with obvious answers. But they are questions that everyone who is building, buying, regulating, or simply using agentic commerce needs to be actively asking.

The kitchen renovation is not inevitable. But it is coming for someone. And whether that someone has any recourse when it does depends on choices being made right now, by people in rooms that most consumers will never see.

.

.

This piece draws on discussions from the Loyal Agents Initiative, a collaboration between Stanford HAI's Digital Economy Lab, Stanford CodeX, and Consumer Reports Innovation Lab.

This Is Exactly the Problem Roving Is Building For

Everything you just read, the intent gaps, the liability questions, the mandate structures, the consumer protections that have not caught up yet, it all points to one thing that does not yet properly exist.

A financial layer built specifically for AI agents.

Not a workaround. Not a card credential passed through a chain of intermediaries and hoped for the best. A proper banking infrastructure where every agent has its own verified financial identity, its own account, its own controlled spending card, owner-defined rules before money moves, and a complete audit trail of every single action it takes with your money.

That is what Roving is building.

Roving is the neo bank for the agentic economy. Give your AI agent a real bank account, smart virtual cards, spending rules it cannot override, global payment capability, and a verified KYA identity before it moves a single penny. Whether you are a developer building agents, a business deploying them, a lawyer watching the liability questions pile up, or a consumer who just wants to know someone is thinking about this properly, Roving is where the financial infrastructure for that future is being built right now.

Get early access at roving.money and be among the first to give your agents the financial identity they need to operate safely in the world.

If this piece made you think, argue with your screen, or quietly reconsider how much financial autonomy you are about to hand to a probabilistic system, drop a comment below. We want to hear from you.

Stay in the loop:

  • Follow us on LinkedIn for product updates, industry news and founder notes

  • Join our Discord community and be part of the conversation shaping the future of agentic finance

  • Share this with someone who needs to read it, the lawyer who thinks AI is just a chatbot, the product manager building an agent platform who has not thought about liability yet, or the consumer who just gave their AI assistant access to their card and has not thought too hard about what that means

Comments

No comments yet. Be the first to share your thoughts.

Leave a comment

Comments are reviewed before publishing.