Friday evening, you ask your assistant to book a table for four, on Saturday, at a good Italian restaurant.
Saturday morning, you discover it has booked twelve. Across twelve different restaurants. With a thirty-euro deposit each time, paid with your card.
Three hundred and sixty euros. Who pays?
There is nothing far-fetched about this scenario. AI agents — those assistants that no longer merely answer, but act on your behalf — are starting to book, buy and fill in forms. And nobody yet really knows who answers for their mistakes.
This week, someone started to give an answer.
"An agent is not someone"
The FTC, the American authority responsible for protecting consumers, has let it be known through its leadership that it refuses to treat AI agents as independent actors.
Put like that, it seems obvious. But it closes a door that some were quite happy to leave ajar.
The idea was this: an agent makes its own decisions, so it is the one that answers for them. Convenient for everyone... except you. Because if it is "the agent's fault", then it is nobody's fault. Software has no bank account. You cannot send it the bill.
The FTC's position is clear: behind an agent, there are always humans and companies. And they are the ones who answer.
So who, then?
Let us return to our twelve restaurants. Responsibility is shared between three parties, and each has its share.
You, for what you asked for and for what you authorised. If you gave the agent the right to pay without limit and without asking you, you left the door wide open.
The company that builds the agent, for the way it is designed. An agent that books twelve tables instead of one has a defect. And a manufacturing defect can be fixed — and sometimes refunded.
The service that took the payment, for what it accepted. A site that receives twelve identical bookings in thirty seconds from the same account might want to ask itself a question.
None of the three can simply say "it's the AI". That is exactly what the FTC has just reminded us.
An agent is a bit like an intern working at breakneck speed, to whom you have handed your bank card. If it does something silly, nobody will say it is solely to blame. We will look at who gave it the card, with what instructions, and who trained it. With one sizeable difference: a real intern would hesitate before spending three hundred and sixty euros. An agent will not. It does what it believes it has been asked to do, without the slightest doubt.
What you can do right now
While waiting for the rules to be written, three simple protections work very well.
Require confirmation for every payment. It is a little less smooth, but it is the best insurance there is. An agent that has to ask you "I'm paying 30 euros, all right?" cannot do it twelve times without you noticing.
Set a cap. Most services let you limit what an agent can spend. We explain how in our guide to giving access to your accounts without giving everything away.
Keep your messages. If a dispute arises, the question will always be the same: did the error come from your request, or from the way the agent understood it? Your original message will be your best evidence.
What remains to be settled
The FTC's position is a principle, not yet a law. And the details are numerous: how to prove what an agent was entitled to do, what to do when it has been trapped by a malicious site, who refunds when everyone is a little bit right. This work has been moving fast since the summer.
But the starting point has been set, and it is reassuring: the agent will not be a convenient scapegoat. When it gets things wrong, someone will have to answer for it.
And that someone, more often than not, will be whoever designed it badly. Not necessarily you.