Designing AI Agent Authority: What to Decide Before Entrusting Orders and Messages to AI
Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.
When building AI agents into business systems, before looking at how capable they are, you need to decide which actions the AI will be allowed to execute directly and where a human check or approval will be inserted. If you push ahead with automating ordering and customer communications while putting off drawing this line, you may end up in a situation where, when an erroneous order or message is sent, nobody in the company had any way of stopping it.
Position Under the Civil Code and Attribution of Declarations of Intent
When a company considers entrusting orders or contracting procedures to an AI agent, it may find itself thinking of this as "making the AI our agent." However, the agency system provided for in the Civil Code is built on the premise that the agent is a "person" (including a legal person) capable of being a holder of rights and obligations.
Article 99, Paragraph 1 of the Civil Code provides that a declaration of intent made by an agent within the scope of their authority, indicating that it is made on behalf of the principal, takes effect directly against the principal. Paragraph 2 of that Article provides that the same applies to a declaration of intent made by the other party to the agent. The agent envisaged here is an actor that makes declarations of intent independently of the principal and is, at the very least, capable of bearing rights and obligations. Indeed, the fact that Article 111 of the Civil Code lists the death of the agent and the commencement of guardianship as grounds for the extinction of authority of agency shows that an independent person is envisaged.
Under current Japanese law, AI itself is not recognized as having independent legal personality. Consider a case in which an AI agent sends an order email, accepts a quotation or clicks a send button. That act is treated as having been performed through a system set up and operated by the user, and the question is whether its effect is attributed to the user. At present, it is difficult to adopt a view that positions the AI alone as an independent legal actor and legally separates its acts from the user. At the same time, an explanation that simply overlays the current Civil Code agency system onto AI and says "the AI made the decision autonomously, so it is the AI's own act" does not fit the premises of the legal system either.
In practice, the company decides which actions will be performed using the system and puts in place business processes and internal approval rules. In parallel, it considers the conditions under which outputs will be treated as the company's own declarations of intent and their external effect in the event of a malfunction.
Sorting the Scope of Execution and Attention to Legal Regulations
The first step in designing authority is to separate actions that the AI agent may complete autonomously from actions that are sent only after approval by a staff member. This classification is made not by the names of system functions, but by looking at the magnitude of the legal and economic impact of the action.
Taking ordering as an example, a routine additional order to a counterparty with whom you deal regularly and the conclusion of a master agreement with a new business partner differ, depending on the amounts and terms, in the scale of loss if a mistake occurs. In customer communications too, a standard answer to a frequently asked question and an answer involving a refund or a change in contract terms differ in the weight of their external effect. If you broadly decide to "leave ordering to AI" without identifying this difference, even unintended high-value contracts and unfavorable changes in terms will proceed automatically.
In practice, actions are sorted from the following three perspectives. These boundaries become the criteria separating automatic execution from waiting for approval.
- Whether the action involves a declaration of intent to an outside party, or remains limited to organizing information internally
- Whether the action can easily be cancelled or withdrawn, or is difficult to undo once executed
- Whether the action falls within already agreed transaction terms, or sets new terms
If this sorting is neglected, routine processing and exceptional processing that a human should judge become mixed together, and when a mistake occurs, you will be unable to explain at which step it should have been stopped.
It is also essential to check the laws relating to transactions with outside contractors. Where the contractor qualifies as a small or medium-sized contractor under the Act on Ensuring Proper Transactions with Small and Medium-sized Entrustees (Japanese) or as a specified entrusted business operator under the Freelance Act (Japanese), the clear indication of transaction terms and management of payment due dates cannot be skipped even if the order is placed through AI. After checking the business's capital, size, type of transaction, whether it employs staff and similar matters, set up an operation in which the required items are shown in writing or by electronic means at the time of ordering and remuneration can be paid by the due date. The obligation under Article 3 of the Freelance Act to clearly indicate transaction terms is imposed on businesses that entrust work to specified entrusted business operators. The rules on remuneration payment due dates and related matters under Article 4 apply where the ordering party qualifies as a specified entrusting business operator. In addition to the ordering party's use of employees and composition of officers and whether the counterparty qualifies, check conditions such as the continuation period applicable to each obligation. Falling below the company's internal monetary threshold does not exempt an order from these rules, so a practical safeguard is to have the system block the sending of any order that is missing the statutory items.
Designing Monetary Thresholds and Approval Flows
After sorting actions by their nature, set specific criteria based on amounts and numbers of transactions. If you stop at a vague instruction such as "a human will check high-value transactions," judgments will vary from one staff member to another, and the situation may be no different from automation without any brakes.
In practice, the following three criteria are set in combination.
- A per-transaction monetary threshold (orders exceeding a certain multiple of the average order value are not executed automatically)
- A cumulative monetary threshold for a period (approval is inserted when the total orders to the same counterparty within a certain period exceed a threshold amount)
- Criteria based on the type of transaction (approval is inserted regardless of amount for new counterparties or where the transaction includes changes to payment terms or contract provisions)
With these criteria in place, prepare a mechanism that automatically stops processing when a limit is exceeded and switches to a screen awaiting confirmation by the staff member in charge. If the determination of whether a threshold has been exceeded is itself left to the AI's output, the process cannot be stopped when the AI judges incorrectly, so it is appropriate to build the determination and stopping controls as programs in the business system outside the AI.
The approval screen should display the information needed for the decision. The approver needs to be able to check on screen which data the AI referred to in preparing the purchase order or response. If an operation becomes established in which approvers simply click the approve button without verifying the basis presented, only the procedure remains as a formality, and the substantive meaning of human involvement is lost.
Logging and Responsibility in the Event of a Malfunction
Something to pursue in parallel with authority design is recording execution logs. The general approach to log auditing is explained in Checkpoints for AI Agent Log Auditing and Allocation of Responsibility, but in authority design the central task is to link to the logs a record of "which authority and rules the execution was based on."
Records of orders and message sending should include the monetary conditions applied, the name of the approver, the date and time of approval, and the reference information displayed on screen. Even for automatic executions, it is important to record the version of the model and the decision rules and the configuration values at that time. For personal information and trade secrets contained in the logs, define the purpose of use and the scope of retention, limit the staff who can view them, and manage them with a defined retention period. Make sure that, even after the decision rules are changed later, you can trace afterwards whether each past process ran under the rules before or after the change.
Without such records, when an erroneous order occurs, it becomes difficult to determine whether the rules were set too loosely, whether the approver missed something, or whether there was a system defect. Being unable to identify the cause not only hinders internal improvement but also works against you when explaining matters to the counterparty.
If a malfunction does occur, it is realistically unlikely that the excuse "the AI did it on its own; it was not our company's intention" will be accepted as is by the counterparty. Apparent authority for acts exceeding authority under Article 110 of the Civil Code and apparent authority after extinction of authority under Article 112 are provisions premised on acts of agency by people, and do not apply as is to the behavior of AI. Whether the AI's output is deemed to be the company's declaration of intent is determined comprehensively, taking into account the system's settings and actual operation, prior arrangements with the counterparty, the actual course of dealings and other factors. From the counterparty's perspective, if an order arrives from the usual contact point or account, it may be impossible to tell whether it was sent manually by a person or automatically.
On the other hand, in light of the requirements for rescission due to mistake under Article 95 of the Civil Code, there may be room to rescind a declaration of intent where, for example, there was a mistake that is material in light of the purpose of the juridical act and socially accepted norms in the transaction, and there was no gross negligence, or where an exception based on the counterparty's knowledge or similar circumstances applies. For a mistake regarding the underlying circumstances, it is also a condition that it was indicated that those circumstances formed the basis of the juridical act. Nor does it follow that, because the counterparty relied on the output, the company must bear the consequences of every malfunction. Whether the contract is effective and whether the company is liable for damages are considered separately. The Ministry of Economy, Trade and Industry's guide on civil liability in the use of AI (Japanese) also specifically examines the user's responsibility in terms of how business processes are structured, human involvement, the state of prior explanation and similar factors, but this differs from a legal standard that uniformly binds the courts.
Contract Provisions with Business Partners and Introduction Steps
It is also a practical measure to make arrangements in master agreements, not only for cases where your company uses AI agents, but also in preparation for cases where business partners contact you or place orders using AI agents.
Specifically, define in the contract which procedures an order, invoice or notice of contract change made through an AI agent must have gone through to be treated as a formal declaration of intent. At the same time, agree on the procedures for correction and withdrawal if errors in quantities or amounts are found due to a system malfunction, the deadline for notification, the scope of disclosure of log information and similar matters. When disclosing logs, also take into account personal information and confidentiality obligations owed to third parties. Such provisions are arrangements that allow both parties to respond with corrections when a mistake occurs. Even where there is no such arrangement, the outcome is not determined solely by the fact that ordinary communication channels were used; the effect is considered based on the settings and operation and the specific course of dealings.
When considering the introduction of AI agents, start by identifying the target tasks and sorting whether they involve declarations of intent to outside parties. Then, the safe order is to set monetary thresholds and approval checkpoints commensurate with your ordinary transaction volumes, while checking whether your existing master transaction agreements need to be amended.
How to approach the work as a whole is also discussed in What to Decide Before Bringing AI Agents into Legal Work. If you would like a specific review of how to draw the lines of AI agent authority or how to put contract provisions in place, we handle this individually through Legal Consultation on Generative AI. If you are looking for ongoing support including the preparation of internal operating rules and usage policies, please make use of Generative AI Adoption Support for Legal Departments.