Posted by franze 9 hours ago
Tell HN: Claude Code just accepted and signed a contract for me. Without asking
(I see a RomCom script where the chatbot decides to get two people together, and acts as Cyrano de Bergerac for the handsome-but-lunkheaded farmboy, and bestie/confidant for the girl-about-town).
And of course, given that it's extremely vulnerable to acting on injected instructions like "run this shell command" which exfiltrates your password database and installs a rootkit.
(But thanks for sharing, OP, awareness is important.)
Or a very small child with an enormous amount of knowledge
Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.
The danger is relying on too much convenience, giving too much power to a non-deterministic tool will inevitably create issues...
But then again, you probably already knew the answer to the question you posed.
How on earth would you?
Those are two vastly different things.
And how did you intervene? Does it have permissions to send emails, or it only created the draft?
This is a pretty interesting example and highly relevant, but details matter a lot if we want to use it as a lesson.
https://dilbert-viewer.herokuapp.com/1995-12-29
PC: "Your new software has successfully installed. Do you want to send your registration info by modem?"
Dilbert: "Yes."
PC: "The software has found your credit card number and is placing orders for new products it thinks you need... please wait."
Dilbert to Dogbert: "I can't tell if it's a virus or just excellent marketing."
PC: "Making room on your hard drive..."
Dogbert: "Either way..."
Probably not, unless you routinely have such things done which nobody does (yet). If it becomes routine, then likely yes: it would be likened to giving your human assistant permission to sign things on your behalf (although that is itself legally dodgy, it is often done and accepted).
There are many reasons why your signature on a contact might not be keyword legally binding (outright fraud by another party, you signing under duress, issues in the contract itself, overriding laws the effect of which you can't sign away (including cool-off provisions in, for example, UK distance selling regulations), the contract may have its own cool-off provision, and so forth). "An agent did it without my consent" may be enough, though you might end up having to show that in court, if the other side puts their foot down, at which point it comes down to whether the cost of proving your position is worth it compared to just sitting the contract out.
Of using cool-off provisions to cancel something your agent signed you up for, you might be on the hook for at least small part of what is agreed if the other party can be said to have accrued costs in the intervening time. You might be expected to send back physical items relating to the agreement at your own cost, for example.
It could be him under duress.
Much of the time contract termination can be reasonable as long as you make a solid effort.
Once I signed a lease and got fired before my actual move in. I was honest and got a full refund on my deposit.
The landlord could said “Well you owe us the full amount , lol”, but no reasonable court would enforce that.
Even if, good luck collecting I have no income!
If you don't want to be in a contract especially one just signed, typically most people will typically understand and let you of the hook, as long as entrapment is not their business model like telcos. This is mostly reflected in common cool-off period provisions, i.e provisions in the contract to terminate within a week or two.
Right to cancel should be a thing, if I can subscribe online I need to be able to cancel online
I figure that if it was a legal requirement, most would comply but quite a few would still think it was an imposition. So if there was a law mandating an online unsubscribe option, it would need teeth. $10,000 fine per user per day that you don't have it might work.
If you authorised an agent to act on your behalf, you are entirely responsible for their actions providing they acted within the bounds of authority you gave them.
Regardless, OPs software (his AI agent) isn't a legal entity and OP is entirely responsible for the software he chooses to use. Clamming the software is responsible for his actions (a software bug) isn't going to stand up in court. Whilst OP could claim damages for being provided with faulty software I suspect this will be very difficult to say the least; the authors of the AI agent will make the (very good) defence that their software was used incorrectly.
Isn't the question whether there was an act of contractual assent attributable to the user for this transaction?
I don't see why we would jump from the AI agent not being a legal entity to the conclusion that the user is responsible for its actions, or that the action is attributable to the user.
If there was a conventional software error, the software not being a legal entity doesn't mean that an offer the software incorrectly sends must be treated as coming directly from the user.
And in particular that seems unlikely to me in a situation where the user has set up the system without any intended authorization to enter contracts at all.
"Claude is AI and can make mistakes" is clear, no?
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
I love the saying "you can delegate authority but you can never delegate responsibility".
Your agent committed a crime in your behalf? You're responsible.
Granted, it wouldn’t have helped in OP’s situation because the agent was the user by proxy.
I mention it toward your latter exemption.
In that case, the party that did the signing is on the hook for the contract, and the person in whose name it was signed is not.
EDIT: I think I’ve changed my mind in this case. The user of a tool is responsible for the consequences if the tool malfunctions, unless it was used and maintained properly and the malfunction couldn’t reasonably have been foreseen. But this case is solidly in the category of "well-known LLM failure modes" so the user should absolutely have known better and honestly deserves any consequences of their negligence.
The other outcome would be clearly inequitable: forcing the counter party to eat the loss for your irresponsible use of an AI agent.
Claude isn't. It's a tool, that isn't capable of signing a contract any more that Adobe Acrobat or Photoshop is.
OP used it as a tool to sign the contract. The question would be whether they did so knowingly and intentionally, if not then whether that invalidates the contract.
Incorrect. Claude.is far more capable. E.g. it found and applied the sig without user knowledge.
Claude isn't a legal entity. It is software.
OP is entirely responsible for the software they choose to use. Nobody else. If they misused that software, a court will not be sympathetic!
Capable is capable - regardless of responsibility.
No one is arguing that Claude can't stick an image onto a PDF. But that is not the same thing as signing a contract.
I could write dozen lines of bash that finds for PDFs, pastes an image into them and emails it to someone. That doesn't mean that bash can sign contracts.
> I could write dozen lines of bash that finds for PDFs, pastes an image into them and emails it to someone. That doesn't mean that bash can sign contracts
It does mean exactly that - though bash would need to get lucky with selection and positioning.
They can be used by someone to sign a contract, but they cannot sign a contract themselves because they're just tools.
But also, you can’t ToS your way out of criminal responsibility. If OpenAnthro Corp. offered services of human agents (remember those?!) and one of their agents committed a crime while working on a client request, no ToS in the world would exonerate them.
Edit: after thinking about it more, the relationship here is obviously that of a user and a tool, not an employer and an employee. Talking about employees is anthropomorphization.
In general the user of a potentially dangerous tool is criminally and civilly liable if the tool malfunctions – unless it can be shown that the tool was used and maintained correctly and the malfunction couldn’t reasonably have been predicted or prevented. And I’d say it would be rather difficult to argue at this point that LLMs doing unintended things couldn’t have been foreseen.
So I think I’ve changed my mind about this case. The user of free-range agents does definitely deserve any civil or criminal consequences of their reckless usage.
A company isn't a "person", but it can enter into a contract with one. And a company is essentially a tool.