01
Define the principal-agent relationship
Document who the recognized principal is, which subject acts as delegate, and whether the delegate may create sub-delegates. Ambiguous ownership and authority chains create avoidable disputes.
02
Bound the blast radius
Use purpose, scope, value, expiry, counterparty, resource, and revocation limits. A useful delegation should make unauthorized expansion detectable rather than merely trusting the agent to self-limit.
03
Plan for compromise
Keys, runtimes, models, and infrastructure can fail. Recovery and succession procedures should preserve identity continuity while allowing compromised credentials and authority to be replaced or restricted.
04
Preserve contestability
Emergency controls should be time-bounded and reviewable. Records should make it possible to reconstruct why an action occurred, who authorized it, and what evidence existed at the time.
05
Map data roles independently from agent delegation
If an agent handles personal data, identify who actually determines the purposes and means, who processes on whose behalf, which jurisdictions are connected, and whether an automated decision has legal or similarly significant effects. Do not assume that naming the agent a delegate transfers the principal’s external data-protection responsibilities.
06
Do not treat product-liability exposure as one universal AI rule
EU product-liability rules are changing on a defined future timeline, while the UK is actively reviewing how its older product-liability regime fits digital technology. U.S. tort and product-liability questions can also be state- and sector-specific. Preserve jurisdiction-specific legal review rather than advertising one global liability wrapper.