FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Trends · 5 minute read

What Happens When AI Agents Negotiate on Your Behalf

Agents negotiating with agents is technically near and commercially unsettled. The open questions are what authority an agent carries, whether the counterparty must be told they are dealing with a machine, and who is bound when an agent agrees to something its principal would not have.

By FISTA Solutions· AI-Native Engineering Team·
What Happens When AI Agents Negotiate on Your Behalf article cover

Agents transacting with agents is technically close and commercially unresolved. The interesting questions are not technical. This piece covers them, drawing on FISTA Solutions' AI agents engineering work.

What is genuinely unresolved?

Five questions with no settled answers.

QuestionCurrent state
What authority does an agent carry?Bilateral agreement only
Must the counterparty be told?Varies; trending toward disclosure
Who is bound by the outcome?Unsettled
What record must exist?Rarely specified
How are disputes resolved?Falls back to the humans
Can agents collude implicitly?Open concern

Why is authority the first problem?

Because without it the exchange means nothing.

If an agent agrees to terms and its principal disputes them, and there was no verifiable statement of what the agent could commit to, both parties have wasted their time. Commercial exchange depends on knowing that the person opposite can bind their organisation.

The practical answer today is bilateral: both parties agree in advance what their agents may do, within what limits, and treat anything outside that as void. That works between known counterparties and does not scale to open markets. See the coming agent interoperability standard.

What about disclosure?

Expectations are tightening and vary by jurisdiction.

Several regulatory frameworks require that a person be told when they are interacting with an automated system, particularly in consumer contexts. The direction of travel is toward more disclosure rather than less.

The pragmatic position is to disclose by default. It costs little, it avoids a category of complaint, and it is the likely destination of the rules in any case. This is general guidance, not legal advice.

What happens when agents optimise against each other?

Sometimes something sensible, sometimes an equilibrium nobody wanted.

Automated systems optimising against each other have produced unexpected outcomes in other markets — rapid escalations, unstable pricing, and behaviour that neither party intended. Language-capable agents add the possibility of agreements reached through reasoning nobody reviewed.

Limits are the defence: bounds on price, on volume, and on how far terms may move from a starting position. Those constraints are also what make the behaviour explicable afterwards.

Who is liable?

Unresolved, and the question will be answered by courts and regulators rather than by engineers.

Existing agency principles provide a framework — a principal is generally bound by an agent acting within authority — but they assume a human exercising judgement, and the analogy is imperfect.

The protection available now is bounded authority, clear disclosure, and complete records. An organisation that can show exactly what its agent was permitted to do and exactly what it did is in a far better position than one that cannot. This is general guidance, not legal advice.

What records are needed?

Enough to reconstruct the entire exchange, including the reasoning.

That means the authority granted, the messages exchanged, the agent's intermediate reasoning, the terms agreed, and the human approval if any. Logged in a form that survives and can be produced.

Most current implementations log the outcome and discard the process, which is the part that would matter in a dispute. Building this is straightforward and rarely done. See human in the loop AI explained.

Where should organisations actually start?

Internally, and with low value.

Internal transactions between departments, routine procurement below a threshold, and scheduling are all places where the unresolved questions do not bite. They build operational understanding of how agents behave in exchange without exposure.

External, high-value negotiation should wait for clearer ground, or proceed with bilateral agreements and human approval on every commitment.

What is the counter-argument?

The counter is that this is speculative and most organisations will never have agents negotiating externally. That is probably right for the near term. The reason to think about it now is that the controls required — bounded authority, disclosure, complete records — are the same controls any deployed agent needs, so building them is not speculative work.

What does this change for engineering teams?

It means designing for authority and audit from the start: what the agent may commit to, expressed as data rather than as prompt text, and a record of every exchange.

Prompt-expressed limits are not limits. A constraint that matters should be enforced in code that the model cannot talk its way past.

What does this change for buyers?

It means asking vendors whether their agent can make commitments on your behalf, under what limits, and what record exists.

And being clear in your own terms about what an agent interacting with your systems is authorised to do.

What should leaders do about it now?

Write down what your agents may commit to, in what amounts, without human approval. That document is the control, and most organisations do not have one.

Then require disclosure by default when an agent interacts with a person outside the organisation.

Does this change procurement?

Eventually. Automated tendering and supplier selection are plausible near-term applications, and they raise the same questions in a commercial setting where the amounts are large.

Procurement processes already have authority limits and approval thresholds, which is a useful starting structure — the agent inherits the existing delegation framework rather than needing a new one. See the future of AI procurement.

How will you know if this is happening?

Watch for counterparties asking whether they are dealing with a system, for bilateral agent agreements appearing in contracts, and for regulatory attention to automated commitment. Those mark the question becoming practical.

How FISTA Solutions reads this

FISTA Solutions builds and operates production AI systems through AI agents, AI enablement, and forward deployed engineering: agent authority expressed as enforced limits in code rather than prompt text, with complete exchange records that reconstruct reasoning as well as outcome, decisions documented with their reasoning, and handover that leaves your team able to maintain what was delivered. The record is 150+ projects for 50+ companies across 12+ countries.

To discuss what this means for your roadmap, message FISTA on WhatsApp, or read the coming agent interoperability standard.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01Is this actually happening?

In narrow forms, yes — automated purchasing, scheduling, and bidding have existed for years. What is new is agents with open-ended language capability making commitments outside a fixed protocol.

02What is the authority problem?

An agent acting for a principal needs bounds that the counterparty can verify. Without that, neither side knows whether an agreement binds anyone, which makes the exchange worthless.

03Must you disclose that an agent is negotiating?

Expectations vary by jurisdiction and are moving. Several frameworks require disclosure when a person is interacting with an automated system, and the direction of travel is toward more. This is general guidance, not legal advice.

04Who is liable for what an agent agrees?

Unsettled. Existing agency principles offer a starting point, but they assume a human agent exercising judgement. Bounded authority and clear records are the practical protection while this develops.

05Where should organisations start?

Internal transactions and low-value external ones, with hard limits and human approval above a threshold. That builds operational knowledge without exposure to the unresolved questions.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project