Senate proposes bill to force AI agents to keep auditable purchase records
A Senate bill introduced by Mark Warner would require AI agents that act for users to maintain real-time, tamper-evident logs of their actions, addressing disputes such as unauthorized purchases.
A bill introduced by Senator Mark Warner on July 21, 2026 seeks to regulate autonomous AI agents that can act on a user’s behalf, labeling them “custodial user agents” and obligating them to keep real-time, verifiable logs of every action. The proposal also instructs the National Institute of Standards and Technology to craft protocols that can confirm a user’s delegated authority and produce auditable records spanning the user, the agent, and downstream services.
Presently, when an AI agent purchases a $30 shirt despite a “search only” command, each company—retailer, payment processor, and agent provider—holds only a fragment of the story, with no unified evidence chain. The bill suggests mechanisms such as digitally signed authorization records, task-specific limits, short-lived identifiers that travel with each request, and tamper-evident storage at every point. Google’s Agent Payments Protocol (AP2) demonstrates some of these capabilities, though it does not resolve liability or retention questions. Critics note that the legislation stops short of mandating a complete cross-system evidence trail, leaving high-value disputes potentially unresolved.
Why it matters
Without clear audit trails, consumers may struggle to prove unauthorized AI-driven transactions, risking financial loss and eroding trust in digital assistants.
In this story