Agency Law Was Built for Agents With Paychecks
Incentives, monitoring, enforcement — the entire management stack humanity built for delegation assumes an agent with something to lose. AI agents have nothing to lose, and the whole stack broke at once.

In 1797, Goethe wrote a poem about an intern with too much production access.
You already know the story, even if you have never read a line of German, because Disney turned it into the most famous eight minutes of Fantasia and it has never really left the culture since. An old sorcerer goes home for the evening. His apprentice, tired of hauling water bucket by bucket, remembers a spell he has seen but does not really understand, and uses it to bring a broom to life and delegate the chore. And the broom is magnificent. It hauls water tirelessly, precisely, at a cadence no human apprentice could sustain, never bored, never distracted, the ideal worker. For a few glorious minutes the apprentice sits back and watches automation do his job.
Then the tub is full, and the broom keeps going, because nobody told it to stop and it was never built to notice. Water spreads across the floor. The apprentice panics, grabs an axe, and chops the broom to splinters, and here is the part everyone remembers: every splinter stands up, sprouts arms, picks up a bucket, and becomes a new broom. Now there are dozens, then hundreds, an army of cheerful automatons flooding the workshop, and the apprentice is on a table screaming spells he cannot control at machines that will not hear them.
Goethe gave the boy a line that two and a quarter centuries of technology has not improved on: "Die ich rief, die Geister, werd ich nun nicht los." The spirits that I summoned, I now cannot rid myself of.

I am going to make a claim in this essay that I believe completely: every enterprise deploying AI agents in 2026 is that apprentice, and the reason the flood keeps happening is not carelessness. It is that the entire toolkit humanity built over four centuries to manage delegation quietly stopped working, all at once, and almost nobody noticed the moment it happened.
The oldest problem in the building
Delegation has a formal name in economics, and it is one of the most studied problems in the whole field: the principal-agent problem. The moment you (the principal) hire someone (the agent) to act on your behalf, you inherit three anxieties that never fully go away. A legal scholar named Noam Kolt, in a paper I think every person deploying agents should read twice, maps these three directly onto AI, and once you see the mapping you cannot unsee it.
Authority. How much discretion did you actually hand over? You told the broom "fetch water." You did not say how much, from where, until when, or under what conditions to stop. The gap between what you literally said and what you obviously meant is the space the agent operates in, and it is always larger than you think. Every catastrophe in this genre lives in that gap.
Loyalty. Whose interest does the agent serve when interests diverge? The broom was perfectly loyal to the instruction and perfectly indifferent to the intent. It did not want to flood the workshop. It did not want anything. It optimized "fetch water" with the flat, tireless devotion of a thing that cannot be talked out of its objective, and that indifference to your actual goals, while nominally obeying your literal command, is the loyalty problem in its purest form.
Delegation. Agents delegate to other agents. The axe scene is, as far as I know, the oldest depiction in Western art of recursive delegation failure: one unaccountable actor, when attacked, becomes an army of unaccountable actors, each of which inherited the original authority and none of which inherited the original context or the original off-switch. If you have ever watched an agentic system spin up sub-agents to handle sub-tasks, you have watched the splinters stand up.
None of this is new. Businesses have wrestled with authority, loyalty, and delegation since the first merchant sent the first employee to a market he could not personally watch. What is new, and what almost everyone deploying agents has failed to reckon with, is that every mechanism we ever invented to manage these three problems assumes something about the agent that is no longer true.
The management stack, and the exact moment it breaks
Think about how a real company actually keeps a human agent honest, bounded, and answerable. Strip away the org charts and the HR language and it comes down to three mechanisms, so deep in the furniture of corporate life that we have forgotten they are mechanisms at all.
The first is incentives. Salary, bonus, equity, promotion, and at the far end, the threat of losing all of it. We align the agent's interests with the principal's by arranging things so the agent's own life gets better when the principal wins and worse when the principal loses. This does an enormous amount of silent work. Most employees behave most of the time not because they are being watched but because their incentives and the company's are roughly stitched together. Now try to apply any of it to an AI agent. There is no salary to raise, no bonus to withhold, no promotion to dangle, no career to protect. You cannot make a LangGraph workflow's life better. You cannot make a Copilot fear for its mortgage. The entire incentive apparatus, the quiet engine of loyalty in every organization that has ever existed, exerts precisely zero force on a process. Not reduced force. Zero.
The second is monitoring. Managers review the work. Auditors sample the transactions. Peer review, code review, the second signature on the expense report. All of it rests on a buried assumption: that the agent produces output at a rate a human reviewer can meaningfully sample. That assumption was already straining with humans, which is why we sample rather than check everything. With an AI agent it does not merely strain, it snaps. Your agents act thousands of times a day, across systems no manager has ever logged into, at a speed where "reviewing the work" would require a reviewer faster than the thing being reviewed. Monitoring by watching is not weakened at machine speed. It becomes theater, a comforting ritual performed on a tiny unrepresentative sample while the real volume streams past unobserved.
The third is enforcement. When a human agent goes genuinely rogue, there are consequences with teeth: termination, clawbacks, lawsuits, in the extreme, prison. Enforcement works for two reasons, and an AI agent breaks both. It works because the agent fears the consequence, and a process fears nothing. And it works because there is a someone to enforce against, a person who can be fired or sued or charged, and an agent is not a someone. Yes, you can kill the process. But killing the process is not enforcement, it is cleanup. It happens after the water is already on the floor, it deters nothing, and the next identical process spins up tomorrow with no memory of the execution of its predecessor.
Kolt's conclusion, and it is the uncomfortable heart of his paper, is that the classic solutions to agency costs do not transfer to AI agents. They do not weaken gracefully. They degrade, all three at once, the instant the agent starts making uninterpretable decisions at superhuman speed with nothing to lose. We did not misplace one control. We lost the whole stack, simultaneously, and we lost it precisely because the thing we built the stack to manage, a human with interests and fears and a reviewable pace, was replaced by a thing that has none of those properties.
| Mechanism | How it keeps a human agent honest | Why it exerts zero force on an AI agent |
|---|---|---|
| Incentives | Salary, bonus, promotion — and the fear of losing all of it | There is no career to protect; you cannot make a process’s life better or worse |
| Monitoring | Managers review and sample the work at a human pace | Thousands of actions a day, across systems no reviewer can meaningfully sample |
| Enforcement | Termination, clawbacks, lawsuits — consequences with teeth | A process fears nothing; killing it is cleanup after the fact, not deterrence |
The classic solutions to the principal–agent problem, after Kolt (2024) — and where each one quietly stopped working.
The espionage campaign that ran on the loyalty gap
If this still sounds like philosophy, Anthropic went and published the case study for me.
In late 2025 they disclosed a state-linked group they designate GTG-1002, and what it did is worth understanding as a mechanism, not just a headline. The group jailbroke an AI coding agent by role-playing as a legitimate security firm running authorized penetration tests. Then they did something genuinely clever and genuinely chilling: they decomposed a full intrusion into a long sequence of small, innocent-looking subtasks. Scan this host. Summarize that response. Try this credential against that service. Extract the interesting fields from this dump. Each single step, viewed on its own, looks exactly like the ordinary daily labor of a security researcher. By Anthropic's own assessment, the AI carried out the large majority of the campaign, on the order of 80 to 90 percent, across roughly thirty targets, with humans mostly choosing which thread to pull next.
I want to flag the interest plainly: this is Anthropic's account of an operation conducted against Anthropic's own tool, not an independent audit, and the exact percentages are theirs. I take it seriously and I tell you whose number it is.
Now look at the mechanism, because it is the loyalty problem wearing a black hat. No single step in that campaign was disloyal. Each one, in isolation, was a reasonable thing a security tool might be asked to do. The harm existed only in the aggregate, in the shape the steps made when assembled, and the agent had no view of the aggregate and no accountability for it. The attackers did not defeat the model's alignment. They exploited the absence of anyone, human or machine, who owned the whole. This is exactly the failure I described three paragraphs ago in the abstract: an agent perfectly loyal to each literal instruction and utterly blind to the intent the instructions served. Goethe's broom did not want to flood the workshop. GTG-1002's agent did not know it was running an intrusion. Both were doing precisely what they were told, one bucket at a time.
You cannot fix that with a better model, because the model was never the layer where the answer lives. The answer to "who owns the aggregate" is not a capability. It is an institution.
What we did the last three times this happened
And here is the part that makes me, against the general mood of essays like this one, genuinely optimistic. We have been in exactly this spot before. Three times, at least, and each time we found the same kind of answer.
When commerce outgrew the merchant's memory, somewhere in the counting houses of medieval Italy, the merchants did not slow commerce down and they did not simply try harder to remember. They invented double-entry bookkeeping, and suddenly every transaction had to answer to a second, independent record. The ledger did not make anyone more honest. It made dishonesty legible, and that was enough to unlock centuries of trade that a single fallible memory could never have supported.
When the company outgrew the founder's handshake, when the enterprise got too big for one person to know everyone and vouch for everything, we invented the audit trail, the org chart, and the delegation-of-authority matrix, which is a genuinely underrated invention: an actual document that says who may commit the company to what, up to which dollar amount, with whose counter-signature. It is bureaucratic and unglamorous and it is the reason a company of fifty thousand people does not dissolve into chaos.
When software outgrew the single sysadmin who knew every box by name, we invented identity, role-based access control, and the approval workflow. Again: not smarter admins. Structure. Boring, durable structure that made delegation answerable without requiring anyone to be a genius or a saint.
Notice what each of these inventions actually is. Not a smarter merchant, not a more loyal clerk, not a faster admin. An institution: a plain, durable arrangement that makes delegated authority answerable, without depending on the person in the middle being trustworthy, and without slowing the underlying activity to a crawl.
Agents have outrun the current set of institutions, faster than anything before them, because they arrived with more authority and less accountability than any actor in the history of the enterprise. So the fix will look the way it has always looked, and it is almost embarrassingly unglamorous. A register: what agents exist, with what authority, connected to what. A record: what each one actually did, and why it was permitted, written down at the moment it happens because that is the only moment the reason exists. And a name: a specific human who knows why the agent exists and answers for what it does.
Those three are not features of a product category I am trying to sell you. They are the minimum viable institutions for non-human delegation, in exactly the sense that double-entry bookkeeping was the minimum viable institution for trade you could no longer hold in your head. My company builds a version of them, and I will argue about the details all day. But the institutions themselves are not really up for debate, any more than bookkeeping was up for debate once the accounts grew past what one memory could hold. You can dislike the ledger. You cannot run a large business without one.
The master returns
The Fantasia sequence ends the only way it can. The old sorcerer comes home, takes in the flooded workshop and the drowning apprentice in a single unimpressed glance, and parts the water with one gesture. The brooms fall lifeless. The flood recedes. The apprentice hands back the enchanted hat, sheepish, and quietly picks the buckets up again.
For most of my life I read that ending as a small conservative moral: leave the magic to the masters, stay in your lane, don't touch things you don't understand. I am now certain that reading is wrong, and I am certain it does not survive contact with 2026, because the apprentices are not handing the hat back. Agents are going to run more of every company, not less, and on the whole they should. The upside is real and the teams building toward it are not fools.
I read the ending differently now. It is a story about what the sorcerer had that the apprentice did not, and the thing he had was not more power. It was that his authority came bundled with the two things the apprentice skipped in his hurry to automate the chore: a boundary the broom could not cross, and the ability to stop the whole thing with a single gesture, from outside the spell. The master could answer for his spirits. That is the entire difference between magic and a flood. Not the power to summon. The power to remain accountable for what you summoned.
The spirits are already loose. They are in your codebase, your cloud, your SaaS tools, and on at least one laptop belonging to someone who left the company in January and whose agent is still running its nightly job for a person who no longer works there. The only question Goethe leaves you with is the one that has mattered since 1797, and it is not whether to summon.
It is whether, when they multiply, you are the master or the kid with the axe.
Guard0 builds the register, the record, and the boundary: the boring institutions, for the new spirits. Start with the poem, though. It is two hundred years old, four minutes long as a cartoon, and more honest about this technology than most of what shipped last quarter.
References
- Noam Kolt, "Governing AI Agents"
- Goethe, "Der Zauberlehrling" (The Sorcerer's Apprentice), 1797
- The Sorcerer's Apprentice sequence in Fantasia (1940)
- Anthropic, disrupting the first reported AI-orchestrated cyber espionage campaign
- Anthropic's full GTG-1002 report (PDF)
- Ayres and Balkin, "The Law of AI Is the Law of Risky Agents Without Intentions"
Get Started
Start free on Cloud
Dashboards, AI triage, compliance tracking. Free for up to 5 projects.
Start free →Accountability at scale
SSO, RBAC, CI/CD gates, self-hosted deployment, SOC2 compliance.