SignedBySign in
← Research

The Agent-to-Agent Signing Gap

Michael Eagles, founder of SignedBy · 27 August 2026

Over the past year, AI agents have gone from answering questions to taking actions — booking, purchasing, negotiating, and increasingly, agreeing to terms. A narrower question sits underneath the broader “can an AI agent sign a contract” debate: when an autonomous agent commits an organization to something, who is legally speaking, under what authority, and how would a counterparty verify any of that?

In Europe there is a purpose-built legal instrument that predates the current moment by ten years, and a live gap it was never designed to close. This is what we found looking into it — not legal advice, not an announcement, and not a claim that we’ve solved the hard part.

Two real anchors, not one

The instrument Europe already has: seals, not signatures

eIDAS — Regulation (EU) No 910/2014 — draws a distinction that maps unusually well onto the agent-authority question, despite predating it by a decade. Articles 26/27 govern electronic signatures: instruments that authenticate a natural person’s approval. Articles 35/36 govern electronic seals: instruments that authenticate a legal entity’s output, with no natural person’s personal approval implied at all. A qualified electronic seal carries a legal presumption of the integrity of the sealed data and the correctness of its origin, and the regulation explicitly contemplates seals supporting fully automated workflows — batch operations with no individual reviewing each instance.

That is precisely the shape of the problem an unattended, agent-driven action creates: not “did a person approve this,” but “did the organization that authorized this agent stand behind what it just did.”

The instrument the industry is building: a way to discover the rules

On 24 June 2026, the American Arbitration Association and Integra Ledger launched the Legal Context Protocol(LCP), with Google, IBM, Circle, Wayfair, and a wide set of other technology and infrastructure companies as founding contributors. LCP solves a different, complementary problem: not “who is legally responsible,” but “how does an agent reliably discover and cite the terms, consent basis, and dispute-recourse mechanism that govern a transaction, before it acts.”

The base standard is deliberately minimal — a JSON file at a predictable path (/.well-known/legal-context.json) over plain HTTPS, with no blockchain, cryptographic proof, or centralized intermediary required at the base tier. Lighter than the standard’s “trust infrastructure for agentic commerce” framing might suggest, and genuinely cheap for any organization to adopt.

What eIDAS answers

Who is legally speaking when an organization’s automated system produces an output with no human clicking “approve.” Fully solved for the single-organization case; a decade of settled EU law.

What LCP answers

How an agent finds and cites the actual terms and recourse mechanism governing a transaction before acting on it. A new, lightweight, rapidly-forming standard — not yet widely adopted.

What neither one answers

Put the two together and a real gap remains, precisely at the point most “agent-to-agent” framing implicitly assumes is already solved: two independentorganizations’ agents completing a transaction with each other, unattended, in a way that is enforceably binding on both sides. eIDAS tells you who is accountable for one side’s automated action. LCP tells an agent where to find the rules. Neither specifies the handshake — the actual mechanism by which agent A’s commitment and agent B’s commitment become one mutual, binding agreement, nor how a counterparty is supposed to verify that the agent it’s dealing with was authorized to make that specific commitment, within what bounds, before it happened.

In the United States, the doctrinal groundwork for one-sided agent authority is considerably more settled. ESIGN (15 U.S.C. § 7001(h)) and UETA both explicitly recognize “electronic agents” — software acting with no human review at all — as capable of forming enforceable contracts, provided the agent’s actions are legally attributable to the party that deployed it. Attribution to the deployer, not prior authorization or bounded authority specifically, is the operative legal requirement; authorization scope and human-in-the-loop thresholds are best practice, not statutory prerequisites (Astraea Counsel’s analysis goes through this well).

What remains genuinely unsettled — on both sides of the Atlantic — is what happens when an autonomous agent’s action turns out to be a mistake: the 2024 Moffatt v. Air Canadadecision, in which a tribunal held Air Canada bound by an incorrect promise its customer-service chatbot made, is frequently cited as an early, concrete illustration of exactly this exposure. Unilateral-mistake doctrine and UETA’s own consumer error-correction provisions offer partial analogies, but neither was written with an autonomous counterparty in mind.

The honest summary

Europe has the stronger single-party instrument. The US has the more settled two-party contract-formation doctrine. Nobody — no vendor, no standards body, no jurisdiction — has yet produced a complete, tested answer for two independent agents forming a mutually binding commitment with each other, verifiably, at machine speed. That is not a gap we claim to have closed. It is the actual state of the field.

A concrete data point from practice

It’s worth grounding this in something real rather than purely hypothetical, and describing it precisely rather than generously. SignedBy already lets an organization authorize an MCP-calling agent to certify a document as final: no recipient, no signature request sent to anyone, and no per-document human click, gated by a one-time, organization-level identity verification. It is explicitly not a signature request — it never asks another party to agree to anything; it lets an organization that already considers a document final say so, in an automated, auditable way. That’s a real instance of the eIDAS seal model in production, not a thought experiment.

Two things are equally important to say plainly: it is a single-organization action, not two agents transacting with each other, and it has not been independently verified to meet the bar for a qualified seal specifically, as opposed to a lower advanced or simple tier of assurance — a real compliance question this piece does not resolve, and neither have we, yet.

Open questions worth a real conversation

These are genuine questions, not rhetorical ones. Some sit closer to standards-body territory than to any single vendor’s roadmap:

  1. The handshake itself.If eIDAS settles single-party accountability and LCP settles rule-discovery, what’s the minimum viable mechanism for two independent agents to form a verifiably mutual, bounded commitment — a bilateral protocol each platform implements separately, or a neutral, shared standard closer to what LCP is already attempting for a related problem?
  2. Mistake correction for autonomous counterparties.UETA’s consumer error-correction provisions and unilateral-mistake doctrine both predate agents acting on both sides of a transaction. Does either framework meaningfully extend to that case, or does it need to be rebuilt?
  3. How much assurance is actually necessary. Qualified trust service status is a genuine accreditation undertaking, not just an engineering task. For most agent-driven commercial use cases, is that bar the right one, or does an advanced-tier instrument with clear attribution and a solid audit trail already do the job the law actually requires?
  4. Interoperability versus proliferation.If every e-signature and agent-commerce platform builds its own bilateral trust bridge, that’s a lot of duplicated, incompatible plumbing. Is there a real opening for a neutral, multi-party standard — the way LCP already approaches rule-discovery — to cover the handshake too, rather than each vendor solving it alone?

We don’t have settled answers to any of these, and we’re skeptical of anyone who claims to. We’d genuinely welcome hearing how the people building LCP, and others working on the legal side of agent commerce, are thinking about the handshake question specifically — it’s the piece that still feels the most open.

Read the full paper

The five-page working paper covers the same ground with full citations and footnotes, formatted for reading or sharing on its own.

Download the PDF →

I run SignedBy, an eIDAS-oriented e-signature company built in the Netherlands. We operate the live document-sealing infrastructure described above, alongside our core e-signature product. This reflects independent research and current thinking, not an official position tied to any product roadmap, and nothing here should be read as legal advice or as a claim of affiliation with the American Arbitration Association, Integra Ledger, or the Legal Context Protocol. Questions or corrections are welcome at hello@signedby.ai.