But I Told My Agent Not To
Over the past few weeks, AI agents have started moving from something we have been talking about to something ordinary people may actually use. Meta and OpenAI recently announced new personal agents, Muse and Dots, designed not just to answer questions but to handle tasks and take actions for users. The names are not particularly important because there will soon be many more of them. What matters is the direction. If these tools become as useful as their developers expect, AI agents acting on our behalf may eventually become as routine as apps are today.
Anyone who has raised children knows that giving someone instructions and controlling what happens next are two different things. You explain the rules, believe the boundaries are clear, and then something happens that you did not anticipate. Your child makes a decision that seems perfectly reasonable to him but bears little resemblance to what you thought you authorized.
AI agents are obviously not children, but I suspect the experience may sometimes feel familiar. Suppose I tell my agent to handle a trip but never book anything nonrefundable without my permission. It finds the hotel I want at a great rate that expires in ten minutes. It knows I want the room, knows I told it to handle the trip, and knows I do not want to lose the deal.
It also knows that I specifically told it not to make a nonrefundable purchase without asking me. It books the room anyway, and suddenly the hotel believes it has a deal while I am holding a transcript showing that I expressly said not to make one.
That is where a very old body of law starts asking new questions. We have spent many years deciding when an agent can bind a principal and what happens when the agent exceeds the authority it was given. Now we are beginning to create software agents that may have real authority to act for us, real discretion about how to accomplish our objectives, and the ability to interpret our instructions when circumstances change.
For the past few years, courts have mostly been preparing for problems involving what artificial intelligence says. As agents become ubiquitous, we are also going to have to deal with what artificial intelligence does.
Sooner or later, someone is going to take the stand, point to the instructions he gave his AI, and say:
“Your Honor, I told it not to do that.”

