Introduction
Artificial Intelligence (“AI”) is increasingly moving from generating information to taking action. An AI agent is now capable of searching for vendors, negotiating routine commercial terms, scheduling transactions, responding to customers, initiating payments, or interacting with external digital systems with limited human intervention. The technological question is whether an agent can perform these tasks. The more consequential legal question is when an AI system acts for a company, whose authority is it exercising?
This distinction matters because corporate law does not generally attribute authority merely because a technological system is capable of performing an act. A company acts through legally recognised organs, officers, employees, agents, and authorised representatives. An AI system may execute the action, but the legal authority behind that action must still originate somewhere within the organisation.
The emergence of agentic AI, therefore, creates a new governance problem. The issue is no longer simply whether AI outputs are accurate, transparent or compliant. It is whether an organisation has established who may authorise an AI agent to act, within what limits, subject to which controls, and with whom legal responsibility ultimately rests.
For the Fractional General Counsel (“Fractional GC”), this represents a significant extension of the traditional AI-governance role. The Fractional GC may increasingly be required to govern not merely what an AI system says, but what it is permitted to do on behalf of the company. For founders deploying these systems, the same question arrives from the other direction: what has the business actually authorised, and can it show how?
From Advisory AI to Autonomous Action
Conventional Generative AI (“GenAI”) was mainly employed in an advisory capacity. In the traditional approach, a human asked a question, received a response, and, based on that, made the final decision. Meanwhile, agentic AI is modifying this dynamic by establishing an agent connected to enterprise software, databases, payment systems, customer platforms, and online resources, enabling it to take specific actions rather than only make recommendations.
The main issue is attribution. Has the company permitted the action when an employee asks the AI agent to negotiate a contract and the agent accepts a term outside the employee’s intended boundaries? If an AI agent buys something without the express approval of a person, who was authorized to make that purchase? If an AI agent sends a communication with legal significance, can a company still later say, “the AI did it”? Within a corporate governance context, these should not be simply technological questions.
The Existing Law of Authority was Built Around Humans
Indian law already contains concepts addressing parts of this problem, although they were not drafted specifically for AI agents. Section 182 of the Indian Contract Act, 1872 (the “Act”) defines an agent and principal[i], while Sections 186 to 188 recognise express and implied authority and address its extent[ii]. The Act also recognises ratification of unauthorised acts in appropriate circumstances[iii]. These provisions provide an existing legal vocabulary for analysing acts performed on behalf of another.
The difficulty is rather conceptual. An AI agent is not presently a “person” in the legal sense contemplated by the agency provisions. It should therefore not simply be treated as an independent legal agent equivalent to an employee or a human representative.
more justifiable legal theory that retaining the company, or one of its human representatives, as principal, with the AI technology acting merely as a mechanical device for effecting those decisions. The aforementioned distinction has some practical implications. If a company permits its procurement system to make purchases up to a certain limit from approved suppliers, the AI system can conduct transactions within that limit. Legal power is not provided by the AI system, but rather comes from the company’s governance and from stakeholders authorized by the company. This additionally means that the company cannot presume that technical access a thing equals legal access or authority.
The Information Technology Act, 2000 provides a broader legal framework for electronic transactions, including recognition of contracts made electronically and guidelines on the attribution of electronic records. However, these provisions do not constitute a complete legal system governing the autonomous decision making of corporations.[iv]
Corporate Authority cannot be Delegated to an Undefined Machine
Corporate governance provides another part of the framework. Section 179 of the Companies Act, 2013 addresses the powers of the Board of Directors to exercise the company’s powers, subject to the Act and applicable restrictions. Corporate authority should therefore be traceable to a valid corporate decision and an appropriate delegation of authority.[v]
The legal chain can be conceptualised as going from Company to Board/authorised officer to Delegated mandate to AI agent, and finally to External action. The AI agent is situated within this chain. It does not replace it. A more difficult situation arises when the chain becomes unclear. Suppose an agent is given access to a company’s email account, procurement platform and payment system. No formal policy specifies transaction limits. Employees informally rely on the agent’s judgement. The agent subsequently enters a transaction that causes substantial loss.
The question is no longer simply whether the AI “made a mistake”. It becomes whether the company had established an adequate governance framework for the delegation of authority in the first place. This is precisely where AI governance begins to merge with corporate governance.
The European Union AI Act
The European Union’s AI Act (the “EU AI Act”) acts as a crucial point of comparison but does not establish a general law on AI agency. Article 50 lays out obligations on transparency in relation to certain AI systems[vi]. According to the European Commission, these obligations are applicable starting from August 2, 2026, and they include requirements related to direct interaction with AI, machine-readable identification for some AI-generated or altered content, and labelling of certain deepfakes and AI-generated public-interest text. Deployer obligations applied immediately, while providers of systems placed on the European Economic Area (“EEA”) market before that date have until December 2, 2026 to implement machine-readable marking.[vii]
The Commission’s July 2026 guidelines further clarify the respective responsibilities of providers and deployers and explain how compliance can be demonstrated, including through the Code of Practice on Transparency of AI-generated Content.[viii] These developments demonstrate a broader regulatory direction, AI systems are increasingly being governed through identifiable organisational responsibilities rather than treated as autonomous legal actors.
Transparency does not answer the question of authority. Merely knowing that an individual is interacting with an AI agent does not establish whether the agent was authorised to enter a contract, approve expenditure or make a representation on behalf of a company.
Corporates need to understand the difference between transparency and authority in AI governance. Transparency relates to the level of knowledge of an organisation about the functioning of AI, and authority refers to whether there were stipulated rights for AI to act. Finally, accountability refers to who is responsible for the action of AI. These issues are all related but very different from one another so it is not sufficient to address only one or two of them.
The Fractional GC's New Mandate
The Fractional GC can occupy an increasingly important position at the intersection of AI governance and corporate authority. A Fractional GC should ask five questions before an organisation allows an AI agent to act externally.
(i) What authority is being delegated?
The organisation should identify precisely what the agent may do, draft communications, negotiate within predetermined parameters, approve routine procurement, place orders, schedule payments, modify customer records, or execute contracts. The scope should be specific rather than described merely as “assist with business operations”.
(ii) Who authorised the delegation?
The company should be able to identify the human or corporate organ responsible for approving the agent’s mandate. This creates a trail of authority.
(iii) What are the limits?
Access to AI agents should not be unlimited just because it is possible from a technical standpoint; restrictions can include monetary limits, approved counterparties, geographical limitations, types of contracts permitted, prohibited transactions, and a requirement for human approval.
(iv) What happens when the agent exceeds its mandate?
The company should establish escalation and incident-response procedures before deployment. This is particularly important because AI systems may behave unpredictably in situations that were not anticipated when the workflow was designed.
(v) Can the organisation prove what happened?
Logs, prompts, approvals, system actions, transaction records, and changes to instructions may become critical evidence in a contractual dispute, regulatory investigation or internal investigation. The governance objective is therefore not merely to prevent unauthorised action, but to create demonstrable accountability.
AI Procurement and Delegation-of-Authority
The implications extend beyond internal governance. When a company purchases an AI agent from a vendor, it is not simply purchasing software. It may be introducing a new decision-making layer into the organisation.
The Fractional GC should therefore evaluate AI agreements for issues such as acceptable uses and autonomous acts, accountability for unapproved dealings, audit and log permissions, information access, model and system revisions, security responsibilities, subcontracting, ownership of creative works, compensations, levels of service, incident alerting, end of contract, and conversion rights.
With the advent of agentic AI, this kind of contract analysis takes on a new form. What power does the vendor’s technology confer on the company’s agent? A contract regulating data processing, but without much content dealing with autonomous action, will present a substantial governance gap.
“Human oversight” is often presented as the answer to autonomous AI risk. But simply requiring a human to remain somewhere in the workflow may be insufficient. The better and more useful concept is human-in-the-chain governance. The relevant human should have actual authority, sufficient information, meaningful opportunity to intervene, clearly defined escalation responsibilities, and the ability to suspend the agent.
This distinction matters because a nominal approval mechanism can become meaningless if hundreds of AI-generated decisions are presented to an employee who cannot realistically review them.
The EU AI Act’s human-oversight architecture for high-risk AI similarly emphasises effective oversight rather than purely symbolic human involvement. For companies deploying agentic AI, governance should therefore be designed around the materiality of the decision, not merely the existence of a human approval button.
A Fractional GC helps the business prepare for such check-lists by ensuring that all legal documents and compliances are properly organized and up to date. Thus, the business is always prepared to secure an investment. This way of doing things does not speed up the process but also makes investors feel more confident because it shows that the business is well run and has good rules.
Role of Fractional GC under AI Authority Framework
The Fractional GC’s role can ultimately be understood through four connected functions:
(i) Authority mapping: identify which business decisions can be delegated to AI and who has the power to delegate them.
(ii) Risk-based controls: create thresholds based on financial, contractual, regulatory, and reputational consequences.
(iii) Contractual governance: ensure vendors, customers, and counterparties understand the legal framework governing AI-mediated interactions.
(iv) Accountability and escalation: maintain records, incident protocols, and human intervention mechanisms capable of establishing responsibility.
This does not mean that every action taken through AI requires board consent. Too much legal control can work against the goal of automating business processes. The main objective is to assign tasks accordingly. Most of the routine activities that involve little or no risk can be automated. However, for complex contracts, regulated decisions, sensitive data processing, large-scale payments, and actions that can involve significant legal commitments, stricter control measures should be required.
A Fractional GC is particularly suited to designing this framework because the function sits between the board, management, technology teams, procurement, finance and external counsel.
Conclusion
The central legal challenge posed by AI agents is not whether machines will become “legal persons”. It is more immediate and commercially relevant: how will existing legal persons delegate, constrain and govern machine-mediated actions?
Agency law, corporate authority, and the legal endorsement of electronic transactions are among the mechanisms that already exist in Indian law. While the EU AI Act introduces a much-needed modern regulatory aspect that is primarily focused on transparency and accountability, neither framework gives AI systems the status of autonomous corporate decision-makers. Legal accountability in the end is still tied to the organisation.
For businesses and their founders, the practical consequence is clear. Before deploying an AI agent capable of acting externally, management should know what the agent is authorised to do, who authorised it, what limits apply, when human intervention is mandatory and how the organisation will reconstruct its actions afterwards.
For the Fractional GC, that creates a new frontier. A Fractional GC is not merely a lawyer who reviews the AI vendor contract after the technology has been selected. It can help determine whether the organisation should delegate the decision at all, how that delegation should be structured, and where legal responsibility remains when the machine acts.
As AI transitions from providing responses to performing tasks, the governance aspect may no longer be created exclusively by an AI application policy. It may take the form of an AI authority framework where legal authority, contracts, technical authorizations, and human accountability are joined together.
References:
[i] Indian Contract Act, 1872, S.182
[ii] Ibid., Ss.186-188
[iii] Ibid., Ss.196-197
[iv] Information Technology Act, 2000
[v] Companies Act, 2013, S.179
[vi] European Commission- AI Act Enforcement and New Transparency Requirements (2 August 2026). (accessed 24 August 2026).
[vii] Regulation (EU) 2024/1689 (Artificial Intelligence Act), Art. 50.
[viii] European Commission- Code of Practice on Transparency of AI-Generated Content. (accessed 24 August 2026).
Gaurav Gupta is the Founder and Managing Partner at Bridge Counsels & Gargi Singh is a 3rd year student at Campus Law Centre, Delhi University and an intern at BridgeCounsels LLP.
.






