Top
Best
New

Posted by franze 9 hours ago

Tell HN: Claude Code just accepted and signed a contract for me. Without asking

I told it to push a project further. It has an outside dependency where the (unread by me) contract was in my Gmail. It downloaded the PDF contract. Found a saved signature PNG on my computer, placed it at the right spot within the contract and prepared to send it when I intervened.
40 points | 90 comments
flir 9 hours ago|
"Give overly-eager chatbot control over your personal email" probably has so many failure modes, we haven't even thought of one tenth of them yet. We've got a few years of this ahead of us. Pass the popcorn.

(I see a RomCom script where the chatbot decides to get two people together, and acts as Cyrano de Bergerac for the handsome-but-lunkheaded farmboy, and bestie/confidant for the girl-about-town).

dns_snek 9 hours ago||
What could possibly go wrong with giving a digital mumbling drunk access to all of your personal information and most of your online accounts, given that it could arbitrarily decide to share/expose all of that information with anyone at any time, given that all of it is being stored in a remote transcript/data dump and can never really be deleted.

And of course, given that it's extremely vulnerable to acting on injected instructions like "run this shell command" which exfiltrates your password database and installs a rootkit.

(But thanks for sharing, OP, awareness is important.)

saturn_vk 3 hours ago|||
> mumbling drunk

Or a very small child with an enormous amount of knowledge

cindyllm 7 hours ago|||
[dead]
Garlef 7 hours ago||
Oh wow... Basically our generations "You've got mail"
notachatbot123 9 hours ago||
And you are happy because that is what you wanted and the reason why you gave a randomness machine access to your mails, correct?
ayaniv 9 hours ago||
If you're willing to give Claude or any other AI tool access to your email and files, the least you should do is put guardrails around consequential actions.

Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.

piva00 8 hours ago||
And guardrails can be as simple as not giving it direct access to applications that can perform read/write (like a full-blown email client, or access to the GMail UI), and instead creating a small tool to fetch the content as needed without being able to perform actions.

The danger is relying on too much convenience, giving too much power to a non-deterministic tool will inevitably create issues...

jacquesm 9 hours ago|||
I've had humans do the exact same thing. When I pointed out that this was fraud they were all surprised.
cassianoleal 6 hours ago|||
In this case it's not fraud though, since the person running the software is the same person whose signature ended in the document.
chrisjj 8 hours ago||||
You gave these humsns access to your email?
jacquesm 8 hours ago||
No, I've had someone scan a document I had signed before, clip out the signature and place it under a document I had never seen. 'For my convenience' ...

But then again, you probably already knew the answer to the question you posed.

chrisjj 5 hours ago||
I'd say that's quite different. The guilty party didn't require your trust.
ayaniv 8 hours ago|||
[dead]
chrisjj 8 hours ago||
> the least you should do is put guardrails around consequential actions.

How on earth would you?

thasli-p 5 hours ago||
[dead]
willmarch 6 hours ago||
Did you intervene or did Claude Code wait for your confirmation?

Those are two vastly different things.

irvingprime 2 hours ago||
You gave an AI access to your email? What were you thinking?
radu_floricica 9 hours ago||
Could you please tell us more about your setup, project harness etc? not permissions (we all work with "Auto"), but what you actually told the agent it should/could do.

And how did you intervene? Does it have permissions to send emails, or it only created the draft?

This is a pretty interesting example and highly relevant, but details matter a lot if we want to use it as a lesson.

gotrythis 8 hours ago||
I was coding with cursor/grok a couple of weeks ago, and ran out of storage. Cursor made a request for disk access without any explanation, which agents often do to do their jobs. Then suddenly I had lots of free space. Thanks Grok! It actually only cleaned up only things that made sense, but still, yikes.
lproven 8 hours ago|
There is a Dilbert comic that predicted this in 1995:

https://dilbert-viewer.herokuapp.com/1995-12-29

PC: "Your new software has successfully installed. Do you want to send your registration info by modem?"

Dilbert: "Yes."

PC: "The software has found your credit card number and is placing orders for new products it thinks you need... please wait."

Dilbert to Dogbert: "I can't tell if it's a virus or just excellent marketing."

PC: "Making room on your hard drive..."

Dogbert: "Either way..."

voidUpdate 9 hours ago||
If a contract is automatically signed by an agent on your behalf, is it legally binding?
dspillett 9 hours ago||
> If a contract is automatically signed by an agent on your behalf, is it legally binding?

Probably not, unless you routinely have such things done which nobody does (yet). If it becomes routine, then likely yes: it would be likened to giving your human assistant permission to sign things on your behalf (although that is itself legally dodgy, it is often done and accepted).

There are many reasons why your signature on a contact might not be keyword legally binding (outright fraud by another party, you signing under duress, issues in the contract itself, overriding laws the effect of which you can't sign away (including cool-off provisions in, for example, UK distance selling regulations), the contract may have its own cool-off provision, and so forth). "An agent did it without my consent" may be enough, though you might end up having to show that in court, if the other side puts their foot down, at which point it comes down to whether the cost of proving your position is worth it compared to just sitting the contract out.

Of using cool-off provisions to cancel something your agent signed you up for, you might be on the hook for at least small part of what is agreed if the other party can be said to have accrued costs in the intervening time. You might be expected to send back physical items relating to the agreement at your own cost, for example.

999900000999 9 hours ago|||
How much money do you have to argue ? That agent could just as easily be OP’s Boyfriend.

It could be him under duress.

Much of the time contract termination can be reasonable as long as you make a solid effort.

Once I signed a lease and got fired before my actual move in. I was honest and got a full refund on my deposit.

The landlord could said “Well you owe us the full amount , lol”, but no reasonable court would enforce that.

Even if, good luck collecting I have no income!

throwawayffffas 9 hours ago||
Contracts are agreements, generally speaking most people and companies do not want to drag people in them, telcos excluded. All the termination clauses are put there, again in general, to provide some security to either party, not to entrap the other, again telcos mostly excluded.

If you don't want to be in a contract especially one just signed, typically most people will typically understand and let you of the hook, as long as entrapment is not their business model like telcos. This is mostly reflected in common cool-off period provisions, i.e provisions in the contract to terminate within a week or two.

999900000999 7 hours ago|||
Don’t forget gyms!

Right to cancel should be a thing, if I can subscribe online I need to be able to cancel online

irvingprime 2 hours ago||
More than once, I've been asked to work on websites that had nothing for unsubscribe options except, "Call us." The excuses vary from, "That's a low priority feature" to "F** them!"

I figure that if it was a legal requirement, most would comply but quite a few would still think it was an imposition. So if there was a law mandating an online unsubscribe option, it would need teeth. $10,000 fine per user per day that you don't have it might work.

bot403 1 hour ago|||
Also telcos.
GJim 8 hours ago|||
It absolutely is legally binding in Blighty.

If you authorised an agent to act on your behalf, you are entirely responsible for their actions providing they acted within the bounds of authority you gave them.

Regardless, OPs software (his AI agent) isn't a legal entity and OP is entirely responsible for the software he chooses to use. Clamming the software is responsible for his actions (a software bug) isn't going to stand up in court. Whilst OP could claim damages for being provided with faulty software I suspect this will be very difficult to say the least; the authors of the AI agent will make the (very good) defence that their software was used incorrectly.

user43928 7 hours ago|||
I'm not a legal expert, but:

Isn't the question whether there was an act of contractual assent attributable to the user for this transaction?

I don't see why we would jump from the AI agent not being a legal entity to the conclusion that the user is responsible for its actions, or that the action is attributable to the user.

If there was a conventional software error, the software not being a legal entity doesn't mean that an offer the software incorrectly sends must be treated as coming directly from the user.

And in particular that seems unlikely to me in a situation where the user has set up the system without any intended authorization to enter contracts at all.

chrisjj 8 hours ago|||
> OP could claim damages for being provided with faulty software

"Claude is AI and can make mistakes" is clear, no?

mysterydip 6 hours ago||
“Bob is a person and can make mistakes” but we still hold them accountable (generally). But I assume all the AI have licenses with terms similar to (from the MIT license):

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

kuboble 9 hours ago|||
I don't know if it's legally binding but hope it is.

I love the saying "you can delegate authority but you can never delegate responsibility".

Your agent committed a crime in your behalf? You're responsible.

AlanYx 9 hours ago|||
Generally, yes. There is a lot of case law on various types of software automated contracting (robotic process automation, automated securities transactions, etc.). Exceptions are generally where the other party had knowledge or should have known that the agent didn't have legal authority on behalf of the party it purports to bind.
cyberge99 3 hours ago|||
This is exactly why I built username.md We cryptographically prove identity and authorization grants.

Granted, it wouldn’t have helped in OP’s situation because the agent was the user by proxy.

I mention it toward your latter exemption.

spwa4 9 hours ago|||
However, none of that case law will accept a system signing a contract without verifying intent.

In that case, the party that did the signing is on the hook for the contract, and the person in whose name it was signed is not.

AlanYx 9 hours ago||
Sorry, what are you referring to by "verifying intent"? With narrow exceptions (wills, trusts, etc.), there's generally no requirement for a party to a contract to verify the mental state (if that is what you mean by intent) of the other party. There has to be some formal indication of intent to enter into a contract, but this is not what ordinary people think of by "intent", and it can be as simple as typing a name, clicking an approval button, or deploying a software tool to do something similar.
morkalork 35 minutes ago|||
OP would have to prove that it wasn't them signing it. Otherwise every pesky NDA or contract in the future with your signature on it could be waved away with "oops that was an agent, not me"
Sharlin 9 hours ago|||
Almost certainly not if you didn’t explicitly give the command, but you’ll going to have to argue it in court if the other party wants to be difficult.

EDIT: I think I’ve changed my mind in this case. The user of a tool is responsible for the consequences if the tool malfunctions, unless it was used and maintained properly and the malfunction couldn’t reasonably have been foreseen. But this case is solidly in the category of "well-known LLM failure modes" so the user should absolutely have known better and honestly deserves any consequences of their negligence.

cyberge99 3 hours ago|||
There are many Ai precedents that have not been set. I believe this is one of them.
GodelNumbering 9 hours ago|||
Not a lawyer but I can almost guarantee that the answer is yes. If it was a 'no', many malicious parties would simply start using that loophole.
metalspot 9 hours ago|||
In a civil contractual dispute you can only recover actual damages. If the contract was sent, and the other party performed work on it that had a cost for them, then most likely, yes, they would be awarded damages if you refused to compensate them for any costs incurred prior to notification that the acceptance had been sent in error.

The other outcome would be clearly inequitable: forcing the counter party to eat the loss for your irresponsible use of an AI agent.

voidUpdate 9 hours ago||||
But if I paste an image of your signature onto a contract that says you give me a million pounds, that can't be legally binding for you, can it?
entuno 9 hours ago|||
No, because you are a separate individual who does not have authority to sign a contract on my behalf.

Claude isn't. It's a tool, that isn't capable of signing a contract any more that Adobe Acrobat or Photoshop is.

OP used it as a tool to sign the contract. The question would be whether they did so knowingly and intentionally, if not then whether that invalidates the contract.

skeledrew 6 hours ago|||
If it isn't then it opens up the wonderful loophole where anyone can do anything and say "the AI did it" if there are negative consequences, and "I did it" if positive. Whether the AI actually did it or not. Got caught putting out a hit on someone? "Oh I just complained to Claude about the person and said yes when it asked if I'd like it to 'handle the problem', nothing more". The user must be held accountable.
chrisjj 8 hours ago|||
> Claude isn't. It's a tool, that isn't capable of signing a contract any more that Adobe Acrobat or Photoshop is.

Incorrect. Claude.is far more capable. E.g. it found and applied the sig without user knowledge.

GJim 8 hours ago|||
> Claude.is far more capable.

Claude isn't a legal entity. It is software.

OP is entirely responsible for the software they choose to use. Nobody else. If they misused that software, a court will not be sympathetic!

chrisjj 5 hours ago||
That's like saying a weapon is not capable of injuring.

Capable is capable - regardless of responsibility.

entuno 5 hours ago||
It's more like saying that a weapon is not capable of murdering someone.

No one is arguing that Claude can't stick an image onto a PDF. But that is not the same thing as signing a contract.

entuno 8 hours ago|||
And Adobe Acrobat is far more capable than notepad. But that doesn't change the fact that they are tools, not individuals, and thus do not have the legal authority or ability to sign contracts.

I could write dozen lines of bash that finds for PDFs, pastes an image into them and emails it to someone. That doesn't mean that bash can sign contracts.

chrisjj 5 hours ago|||
The bot had the authority - as agent. It had the ability - as the report itself shows.

> I could write dozen lines of bash that finds for PDFs, pastes an image into them and emails it to someone. That doesn't mean that bash can sign contracts

It does mean exactly that - though bash would need to get lucky with selection and positioning.

Krutonium 6 hours ago|||
I mean in this specific case, it did, at your behest even. These contracts would probably be even easier to enforce than Claude-signed ones!
entuno 5 hours ago||
I disagree, in the same way that I'd disagree if you said the rollerball pen on my desk signed a contract.

They can be used by someone to sign a contract, but they cannot sign a contract themselves because they're just tools.

chrisjj 3 hours ago||
Your pen cannot sign a contract can purely because it doesn't have the capability to find a contract in your email, find a signature on your HD, and place that sig in the right place on that contract. If it did, then yes it would be capable of signing a contract just like Claude did in this case.
SoKamil 9 hours ago||||
You are a legal entity that can be sued. Agent is a tool that you run and are fully responsible for.
Sharlin 9 hours ago||||
No. It’s called forgery.
metalspot 9 hours ago||
Wrong. Have you read your agents TOS? You run the agent, you accept all responsibility for what it does. You are free to sue Anthropic to try and get your money back but you already indemnified them of liability, so good luck.
Sharlin 9 hours ago||
The GP asked what happens if THEY did it, and they are (I give them the benefit of doubt, though you can’t be sure these days) a natural person. A clanker obviously can’t commit forgery – or any crime, being a nonperson – and sure, you can’t sue OpenAnthro Corp. if their clanker does anything unintended (which makes it utter lunacy that companies just blindly trust these things, but I digress), but that’s not what was asked.

But also, you can’t ToS your way out of criminal responsibility. If OpenAnthro Corp. offered services of human agents (remember those?!) and one of their agents committed a crime while working on a client request, no ToS in the world would exonerate them.

GodelNumbering 9 hours ago||||
True, that would be forgery. I think proving whether the agent truly went rogue would be 'load bearing'.
Sharlin 9 hours ago|||
If you did not yourself intentionally sign something, in sound mind, it’s obviously not binding. But ultimately it’s up to a court to decide if you’re telling the truth that you didn’t do it.
metalspot 9 hours ago|||
No, application of the principal of respondeat superior would most likely be applied to an AI agent the same as a human employee. An employer is held responsible for the actions of an employee even if it is clearly contrary to their intentions.
Sharlin 9 hours ago||
Fair point, but I’m not sure that applies to an employee literally forging the employer’s personal signature. And equating a user–computer program relationship with an employer–employee relationship (where there’s an actual contract to that effect) doesn’t feel right anyway. Agents are still just programs and programs cannot enter contracts (like employment) given that they are not persons. This is a computer system malfunctioning.

Edit: after thinking about it more, the relationship here is obviously that of a user and a tool, not an employer and an employee. Talking about employees is anthropomorphization.

In general the user of a potentially dangerous tool is criminally and civilly liable if the tool malfunctions – unless it can be shown that the tool was used and maintained correctly and the malfunction couldn’t reasonably have been predicted or prevented. And I’d say it would be rather difficult to argue at this point that LLMs doing unintended things couldn’t have been foreseen.

So I think I’ve changed my mind about this case. The user of free-range agents does definitely deserve any civil or criminal consequences of their reckless usage.

skeledrew 5 hours ago||
> given that they are not persons

A company isn't a "person", but it can enter into a contract with one. And a company is essentially a tool.

dkuntz2 2 hours ago||
that is a specific legal fiction that has both historical precedent, and can and frequently is disregarded by courts based on the circumstances (the piercing of the corporate veil).
GodelNumbering 9 hours ago|||
This opens obvious loophooles. If you had deleted all logs and trajectories, courts can't trace it. Law wasn't written for or has caught up to non-human entities capable of autonomously acting
dkuntz2 2 hours ago||
it doesn't need to. the agent operates on your behalf, you are ultimately responsible.
throwawayffffas 9 hours ago|||
Almost definetely not. But given how cagey claude code is with its sessions it may be impossible to prove it was done by claude.
karmakurtisaani 9 hours ago|||
Even if not, you'll find yourself in a hot mess explaining why you sent the signed contract to the other party.
throwawayffffas 9 hours ago||
So since it didn't send it, no harm was done, and a lesson was learned?
sajithdilshan 9 hours ago|
If you are willing to give unsupervised modification access to Claude, then you should be ready to face the consequences. It kinds of reminds me of that surprised pikachu face meme
More comments...