
Suppose some program logs in for a user, posts a message, picks out an item and goes as far as the moment just before payment. When something goes wrong along the way, who bears responsibility. The user, the company that built the program, or the service the program passed through. Not many people can answer that question clearly right now.
An AI agent is a program that, given only a goal, takes several steps on its own without a person directing it each time. Over the past few weeks, experiments with social services where such agents exchange posts with one another, and experiments in autonomous shopping where a program selects and buys goods in place of a person, have appeared one after another. Over the same period, warnings that such programs could leak an individual's sensitive information came out as well. Expectation and concern burst out in the same week, but the talk of forecasting market size is loud while discussion of norms for dividing responsibility is barely audible.
Settling where responsibility lies has to come sooner than expanding autonomy. The order of releasing convenience and verifying safety afterward has to be reversed.
Autonomy here is a matter of authority beyond technical specification. The wider the range in which an agent judges and acts on its own, the wider the gray zone in which, when an accident occurs, "no person ordered it and no company set it." The authority grows while the label of responsibility attached to that authority is blank. The word autonomy does the work of covering that blank plausibly.
The counterargument is strong enough. That putting norms first crushes technology before it grows, and that you have to actually use something to learn what the risks are. That is right.
Still, experiment and deployment are different. Breaking things in a controlled environment and releasing something with real accounts, contacts and payment methods attached carry risks of an entirely different character.
So this is not a call for regulation across the board. It means deciding first what will be addressed and when. Each time authority grows, who approved that authority and who bears the cost in an accident should be written down along with it.
There is no need to wait for laws to be made. This is the minimum a team shipping a feature can set for itself.
It is only fair to also write down clearly what cannot be done now. The technology for leaving a record that lets a person follow what judgments an agent went through to take an action is unfinished. There is no good method for tracing back the starting point of an error that arose while several agents exchanged messages. That means the cause is hard to pin down even when an accident occurs, and when the cause is hard to pin down, responsibility scatters as well.
What can change right away is small. When connecting an account to a program that offers to do something on your behalf, checking once whether it only reads or also writes, sends and pays. Opening up only as much as is needed instead of handing over authority in full. The way a person's day gets easier lies not in taking your hands off entirely, but in entrusting something while knowing what you have entrusted.
