The past year has seen AI tools multiply across the crypto industry: Coinbase, MoonPay, Circle and Visa have introduced AI-powered payment tools, while tech giants OpenAI, Anthropic and Google have released increasingly capable autonomous agents.
Lawyers say the law is struggling to keep up. Questions remain over who is responsible if an AI agent makes a bad trade, falls victim to manipulation or loses customer funds.
Existing laws already cover some of these situations, experts say, but they were written long before AI could make financial decisions or move money on its own. That means courts and regulators will have to decide how those rules apply to AI agents.
The rapid rise of autonomous AI agents
The debate is becoming more urgent as companies give AI agents greater autonomy. Research firm Gartner predicts 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5% in 2025.
In a recent IBM survey of more than 800 executives across 20 countries, 24% said AI agents already take independent action inside their organizations. By 2027, that figure is expected to rise to 67%.
At the same time, businesses are struggling to monitor how AI agents make decisions. IBM found 45% of executives said they lack visibility into those decisions, raising real concerns about accountability.
Who is responsible under the law?
"Today, liability for AI agents is not set by any general statutory scheme," said Chanté Eliaszadeh, founder of blockchain and AI-focused law firm Astraea Counsel. Instead, courts will likely rely on existing laws covering contracts, negligence, product liability and fiduciary duties.
One example is the federal E-SIGN Act, which recognizes contracts formed by "electronic agents." In practice, Eliaszadeh said, that means the starting point is usually that users are responsible for decisions made by AI agents acting on their behalf.
"While each case is necessarily going to be fact-specific under existing law, the test for liability will usually follow control," she said.
By default, users are likely to bear the first loss because they chose to let the AI act on their behalf. Users who remove human approval requirements or give AI agents broad permission to make financial decisions may also take on greater legal risk.
Eliaszadeh pointed to Coinbase's AgentKit, a developer toolkit that lets AI agents hold crypto wallets and execute onchain transactions. Its terms state that actions taken by an AI agent through the software "are not acts of Coinbase," a sign of how companies are already trying to place responsibility on users.
However, that does not mean companies are off the hook. For example, a company could face negligence claims if it releases an AI agent without reasonable safeguards or ignores known security risks.
"If the agent fails outside the course of normal operations and misfires because of a corrupted data feed, then the deployer would face liability," Eliaszadeh said. "Or, if the system was marketed for autonomous trading and failed in a foreseeable way, the developer would risk liability."
Not every company faces the same risk
Not every company involved in an AI system is likely to face the same legal risk, Felix Shipkevich, founder of New York-based law firm Shipkevich PLLC and a law professor at Hofstra University in New York state, told Sandmark.
Companies that build AI models, such as OpenAI and Anthropic, may be less likely to face lawsuits because they generally require people to approve important financial decisions. That places more responsibility on the companies using those models to build AI-powered financial products.
Shipkevich also noted that today's AI systems are still largely recommendation tools rather than fully autonomous financial agents.
"Regarding any AI agent that has the ability to execute trades, to the best of my knowledge, such AI agents are quite limited and have not been properly tested," he said. "It's very difficult to hold an AI agent responsible."
As AI agents become more capable, however, Shipkevich said that regulators and lawmakers may need to create new laws and consider whether companies offering AI-powered trading tools should be regulated like other financial firms.
"The existing laws do not currently sufficiently address AI agents making financial decisions," Shipkevich said. "I would not be surprised if legislation is proposed at the federal or even state level to regulate AI agents."
DeFi makes things more complicated
Things also become more complicated when AI agents interact directly with decentralized finance, or DeFi, where there is not always a single company in control and transactions are usually irreversible.
"Courts have resolved questions of liability for decentralized activities on opposite ends of the spectrum," Eliaszadeh said.
She pointed to recent court decisions that reached different conclusions depending on the level of decentralization. In one case, a court found immutable smart contracts were beyond anyone's control. In another litigation involving Ooki DAO, a decentralized crypto trading platform, the Commodity Futures Trading Commission (CFTC) successfully argued that the DAO was an unincorporated association, potentially exposing governance participants to liability.
"An AI agent trading on DeFi rails sits somewhere in the middle," she said. "And the liability question turns on who exercised control – the agent's deployer, the front-end operator, or the governance token holders – and how the losses happened."
The questions are becoming more pressing as AI agents play a larger role in DeFi. DWF Ventures, the venture capital arm of DWF Labs, estimates automated and agentic activity now accounts for about 19% of onchain activity, as agents increasingly handle tasks such as yield optimization, trading and liquidity management.
The unresolved Regulation E question
Another unanswered question is what happens if an AI agent is tricked into sending money.
Eliaszadeh said that US rules under Regulation E protect consumers from unauthorized electronic payments, but if consumers approve a payment themselves – even after being tricked by a scammer – the transaction is usually still considered authorized, creating what some lawyers call the "Zelle gap" - named after the US bank-to-bank payment app Zelle, often exploited in such scams.
However, it's unclear whether those protections apply when someone has already given an AI agent permission to manage money.
"Nobody knows yet how a standing instruction to an AI agent – such as 'manage my portfolio' or 'keep purchases under $2,000' – fits into Regulation E's rules on authorized payments," Eliaszadeh said.
One possible outcome is that a prompt-injection attack could be treated like someone stealing a user's account credentials, making the payment unauthorized, Eliaszadeh explained. Another is that consumers who give AI agents access to their accounts are considered to have authorized those payments.
"The counterargument is that users who deliberately hand agents their credentials have furnished the means of access, which points the other way," she said. "No regulator or court has resolved this question, and the loss allocation for the whole agentic-payments economy rides on it."
Why the courts will likely decide first
For now, lawyers say many of the biggest legal questions surrounding AI agents will likely be answered not by new legislation, but by the first wave of lawsuits over who is responsible when AI agents make mistakes.
This is already beginning to play out in the courts. In one recent case, Amazon sued Perplexity, alleging its AI shopping agent improperly accessed customer accounts and placed orders. A federal judge granted Amazon a preliminary injunction in March 2026, but the Ninth Circuit stayed the order pending appeal and heard oral arguments in June. The case remains undecided and could help determine how courts distribute liability for AI agents.
"Ultimately, we are going to see legal precedent being developed on where AI agent liability starts and ends," Shipkevich said. "The courts will likely have case law that establishes liability and responsibility for those who create AI agents, as well as those who potentially have any type of ownership or control."