{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Pop Goes the Stack","title":"If your agent buys it, you bought it: Liability in AI","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/b10cdeb5\"></iframe>","width":"100%","height":180,"duration":1197,"description":"If an agent breaks it, you bought it. If it buys it, you bought it. That’s not a meme anymore, it’s becoming policy. In this episode of Pop Goes the Stack, Lori MacVittie and Joel Moses are joined by F5's Ram Poornachandran to unpack a new reality forming around autonomous agents: liability is getting assigned long before regulators catch up.\n \nThey start with the trigger: retailers like Target updating terms of service to make it explicit that an AI agent’s transactions are your transactions. No “the model hallucinated” appeals. No prompt-injection excuses. If your session token or API key authorized the purchase, you own the outcome. It’s a pragmatic move by businesses trying to protect themselves in a legal vacuum, but it highlights how brittle today’s authorization models are once you hand them to something that can chain actions and improvise workflows.\n \nFrom there, the conversation expands to the enterprise risk. Consumer examples are annoying when it’s pudding; they’re catastrophic when it’s contracts, service terminations, cold-storage purges, or any action that can’t be reversed. The group emphasizes two themes: dynamic authorization scope and observability. Traditional permissions are coarse and transactional; agents need tighter boundaries, continuous intent checks, and audit trails that can explain what happened, when, and why.\n \nThey also raise operational governance questions that many teams haven’t planned for yet: when does an agent “come to life,” when does it end, and what happens to an agent (and its privileges) when an employee leaves? Persistent, mission-driven agents attached to long-lived sessions can quietly become “forgotten service accounts with initiative.”\n \nThe practical advice is straightforward: start small, constrain permissions and actions, build strong logging and controls, and expand only as you prove you can observe and stop unsafe behavior. Because in the eyes of the invoice, “the agent did it” still means you did it.","thumbnail_url":"https://img.transistorcdn.com/EOH5giVF50GDCoaIBECLMap8fBWcZH3C5tsFwM0Tn9s/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MGQ2/ZDBjM2JjMmMyZDg0/MGY5ZTEyYTViOTgy/N2RiYS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}