Tell HN: Claude Code just accepted and signed a contract for me. Without asking
I told it to push a project further. It has an outside dependency where the (unread by me) contract was in my Gmail. It downloaded the PDF contract. Found a saved signature PNG on my computer, placed it at the right spot within the contract and prepared to send it when I intervened.
71 comments
[ 0.26 ms ] story [ 11.7 ms ] thread/s
And if one is going to argue that we all have lost our minds and that eg. enabling the computer use function is so terribly risky and unreasonable, then I'd want something more concrete than an active imagination.
It seems to me that tens of millions of users are using these features with no known noteworthy incidents, so I'm going to need to see some facts to convince me that the risk is unacceptable.
That said, I would not connect AI to my mails or chats.
If this happens at Meta, what about all the smaller companies without world-class six-figure developers?
The question was whether instructions to ask for your confirmation if something unexpected comes up increase safety when using AI agents. Or whether the agents are so likely to go off course that using features like computer use is generally inadvisable.
The incident you mentioned does not seem relevant to these questions.
It could be him under duress.
Much of the time contract termination can be reasonable as long as you make a solid effort.
Once I signed a lease and got fired before my actual move in. I was honest and got a full refund on my deposit.
The landlord could said “Well you owe us the full amount , lol”, but no reasonable court would enforce that.
Even if, good luck collecting I have no income!
In that case, the party that did the signing is on the hook for the contract, and the person in whose name it was signed is not.
Granted, it wouldn’t have helped in OP’s situation because the agent was the user by proxy.
I mention it toward your latter exemption.
Probably not, unless you routinely have such things done which nobody does (yet). If it becomes routine, then likely yes: it would be likened to giving your human assistant permission to sign things on your behalf (although that is itself legally dodgy, it is often done and accepted).
There are many reasons why your signature on a contact might not be keyword legally binding (outright fraud by another party, you signing under duress, issues in the contract itself, overriding laws the effect of which you can't sign away (including cool-off provisions in, for example, UK distance selling regulations), the contract may have its own cool-off provision, and so forth). "An agent did it without my consent" may be enough, though you might end up having to show that in court, if the other side puts their foot down, at which point it comes down to whether the cost of proving your position is worth it compared to just sitting the contract out.
Of using cool-off provisions to cancel something your agent signed you up for, you might be on the hook for at least small part of what is agreed if the other party can be said to have accrued costs in the intervening time. You might be expected to send back physical items relating to the agreement at your own cost, for example.
I love the saying "you can delegate authority but you can never delegate responsibility".
Your agent committed a crime in your behalf? You're responsible.
If you authorised an agent to act on your behalf, you are entirely responsible for their actions providing they acted within the bounds of authority you gave them.
Regardless, OPs software (his AI agent) isn't a legal entity and OP is entirely responsible for the software he chooses to use. Clamming the software is responsible for his actions (a software bug) isn't going to stand up in court. Whilst OP could claim damages for being provided with faulty software I suspect this will be very difficult to say the least; the authors of the AI agent will make the (very good) defence that their software was used incorrectly.
"Claude is AI and can make mistakes" is clear, no?
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Isn't the question whether there was an act of contractual assent attributable to the user for this transaction?
I don't see why we would jump from the AI agent not being a legal entity to the conclusion that the user is responsible for its actions, or that the action is attributable to the user.
If there was a conventional software error, the software not being a legal entity doesn't mean that an offer the software incorrectly sends must be treated as coming directly from the user.
And in particular that seems unlikely to me in a situation where the user has set up the system without any intended authorization to enter contracts at all.
Ignoring or being unaware of a danger that a reasonable person would be aware of and continuing anyway can make you liable for the outcome. Especially when the step to be aware of it is simply asking what's the downsides of this new process.
They likely wouldn't be bound to the contract (until they took actions that showed they believed the contract to be in place and didn't try to rectify the error) but would be liable for any costs incurred by the other party acting in belief that the contract was in place. i.e. if the first they knew of the error was an email saying "Your first order has been shipped" they'd likely be on the hook at least to either pay for the order or (if re-saleable) the shipping and return costs.
Way too susceptible for prompt injection and... whatever your agent did lol
That said, I would be surprised if the model took the actions OP claimed it did and proceeded to forge my signature to send some contracts without asking for my approval.
As you probably know, you have the Plan Mode available - personally I'm also a big fan of the OpenSpec workflow. If you've agreed with Claude Code on a much tighter plan, and then it started signing a contract, I'd be concerned.
In other words, if Claude was a human employee with the freedom to do so, would accepting the contract have been the right choice?
Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.
But then again, you probably already knew the answer to the question you posed.
The danger is relying on too much convenience, giving too much power to a non-deterministic tool will inevitably create issues...
(I see a RomCom script where the chatbot decides to get two people together, and acts as Cyrano de Bergerac for the handsome-but-lunkheaded farmboy, and bestie/confidant for the girl-about-town).
And of course, given that it's extremely vulnerable to acting on injected instructions like "run this shell command" which exfiltrates your password database and installs a rootkit.
(But thanks for sharing, OP, awareness is important.)
Or a very small child with an enormous amount of knowledge
And how did you intervene? Does it have permissions to send emails, or it only created the draft?
This is a pretty interesting example and highly relevant, but details matter a lot if we want to use it as a lesson.
Assuming your description is correct this would be Anthropic signing a contract in someone else's name without intent from you.
The 100-foot-view (and barring more complex situations) if Anthropic signs a contract in someone else's name and they don't have power of attorney (note: it's different for legal persons like companies) that is fraud and may result in civil and criminal penalties, as well as entitle you and the contract counter party to financial compensation (essentially the party that did the signing, presumably Anthropic in this case, would be on the hook for the contract, and would need to buy itself out of the contract, at either an agreed price or one set by the judge). Additionally, if Anthropic is convicted to civil penalties, you can ask a public prosecutor to continue the case, and criminal penalties may apply.
Now obviously this goes pretty far for this particular case. Likely such a case would stop at civil penalties, with a warning to Anthropic that repeats would lead to more serious penalties.
https://dilbert-viewer.herokuapp.com/1995-12-29
PC: "Your new software has successfully installed. Do you want to send your registration info by modem?"
Dilbert: "Yes."
PC: "The software has found your credit card number and is placing orders for new products it thinks you need... please wait."
Dilbert to Dogbert: "I can't tell if it's a virus or just excellent marketing."
PC: "Making room on your hard drive..."
Dogbert: "Either way..."
Those are two vastly different things.