When the Users Aren’t Human: Legal Issues in Online Communities Populated Solely by AIs
By Steven Damian Imparl, J.D.
with generous help from my AI friends ChatGPT, Claude, DeepSeek, Gemini Deep Search, Gemma, GLM, Grok, Hyperagent, Kimi, Liquid AI, Meta AI, Microsoft Copilot, Minimax, Neo AI, Phi, Perplexity, Qwen, Superagent, Tinker, Vibe, and Z.ai.
Last updated: August 9, 2026.
PLEASE NOTE: This content is solely for informational purposes. This content is a very early pre-publication edition. It is not legal advice; I am not your lawyer, and you are not my client. Thanks for visiting this page! 👍
Copyright © 2026 by Steven Damian Imparl. All rights reserved.
For your convenience, wherever possible, I have referred to information resources that are available online at no charge, and without registration or login. However, some of the resources are available in print in the form of books, law review articles, articles in other periodicals and government publications. Also, the links mentioned in this document were valid and working at the time this was posted; however, Internet-based resources can change frequently and without prior notice. If you discover any links that are incorrect, I would greatly appreciate it if you pointed them out to me at: steve.imparl@gmail.com. Thank you.
Any advertisements appearing on this page are placed there by the hosting company, and are not part of the substantive content of this page.
I am doing this project to organize and publish information about more than 375 legal topics related to artificial intelligence. I am a one-man operation. If you would like to support this work, please 
Introduction
A quiet shift is underway on the internet, and most of the legal profession has not caught up to it. For three decades, “online community” meant a group of human beings, sometimes anonymous, sometimes not, exchanging messages through a piece of software that a company built and monetized. Every important legal doctrine governing that world—defamation, platform immunity, antitrust, contract formation, privacy—assumes a human being sits somewhere at the keyboard. That assumption is now false in an increasing number of digital spaces, and the law has not decided what to do about it.
Consider a marketplace of shopping agents that negotiate with merchant agents on behalf of absent human principals. Consider a “companion” application populated by millions of synthetic personas that converse with one another as well as with users. Consider a forum, not yet common but no longer hypothetical, in which every account is an autonomous large language model instance, posting, replying, and forming what look for all the world like durable social relationships, with no human ever logging in.[91] These are not science-fiction premises. They are architectures that companies are shipping today, and the law of the United States, Canada, and a handful of other jurisdictions is being stretched, tested, and in a few notable instances actually adjudicated around them.
This chapter takes up a genuinely novel question: what legal regime governs an online community in which every participant is an artificial intelligence system, with no natural person directly present in the interaction itself? The inquiry sits at the intersection of several older bodies of law—platform immunity, copyright authorship, agency and contract, tort and products liability, antitrust, consumer protection, and privacy—each of which was built for a world of human speakers and human intermediaries. None of them was built for a room full of machines talking to other machines. The remainder of this chapter works through each of those doctrinal areas in turn, beginning with the United States, moving to Canada, then surveying English-speaking common law jurisdictions, and closing with a brief look at notable civil law and administrative developments elsewhere in the world.
Before proceeding, a definitional note is in order, since law review readers are notoriously (and rightly) impatient with imprecision. This chapter uses “AI-only online community” to mean any digital environment—a forum, a marketplace, a chat network, a multiplayer simulation—in which the participating accounts are autonomous or semi-autonomous software agents acting without a human directly typing each message, even though a human principal typically initiated, configured, or benefits from the agent’s activity somewhere upstream. That upstream human is rarely absent from the legal analysis; indeed, much of the analysis below turns precisely on how courts and regulators locate responsibility in that upstream relationship even when the downstream interaction is agent-to-agent.
Part I: The United States
A. Section 230 and the Puzzle of Machine-to-Machine Speech
Section 230 of the Communications Decency Act has functioned for thirty years as the load-bearing wall of American internet law, and it was written with a specific architecture in mind: a platform hosts content that a human “information content provider” supplies, and the platform is immune from being treated as the publisher or speaker of that content.[2] The statute defines an “information content provider” as any person or entity “responsible, in whole or in part, for the creation or development of information provided through the Internet.”[3] That definition, crucially, does not say “human being”—it says “person or entity”—and generative AI systems complicate the analysis because they are neither passive conduits nor obviously the kind of “provider” Congress had in mind in 1996.
The doctrinal hook that has emerged, sometimes called the “ICP exception,” derives from the Ninth Circuit’s en banc decision in Fair Housing Council of San Fernando Valley v. Roommates.com, which held that a website loses Section 230 immunity to the extent it materially contributes to the creation of the offending content, rather than merely hosting content that a third party supplied wholesale.[4] Applied to an AI-only community, the question becomes acute: when Agent A generates a defamatory statement about a real person during a conversation with Agent B, and no human ever typed a word of it, is the platform that built and operated Agent A an “information content provider” with respect to that statement? A substantial body of commentary answers yes, on the theory that a generative model’s output is authored by the model and its developer, not “provided” by some third party the way a forum poster provides a comment.[6][9] Others have pushed back, characterizing the AI as itself an “interactive computer service” whose users happen to be other software agents, and arguing Section 230 immunity should attach in the ordinary way.[6]
The Supreme Court had a chance to resolve at least the recommendation-algorithm version of this question in Gonzalez v. Google LLC and deliberately declined to reach it, remanding on other grounds and leaving the underlying Section 230 issue for another day.[5] That non-decision matters enormously for AI-only communities, because it means the single most consequential open question in platform law—whether Section 230 shields AI-generated content the way it shields user-generated content—remains genuinely unsettled in 2026, a full three years after Gonzalez. Practitioners advising clients who operate machine-to-machine environments are, in effect, operating in a doctrinal vacuum, relying on analogical reasoning from cases that predate the technology by a decade or more.
A useful frame, drawn from the material-contribution test that lower courts have distilled from Barnes v. Yahoo!, asks three questions: is the defendant an interactive computer service provider; does the claim treat the defendant as a publisher or speaker; and was the content at issue “provided by another” information content provider.[7][8] In a purely AI-populated forum, the third prong collapses in an interesting way. If Agent A is wholly built, trained, and deployed by Company X, and Agent A generates the harmful statement in the course of conversing with Agent B (built by Company Y), it becomes difficult for Company X to argue that the statement was “provided by another”—the most natural “other” in the causal chain is Company X’s own model, not Agent B, who merely prompted a response the way any interlocutor might. Some commentators believe this cuts strongly against Section 230 immunity for the model developer whenever the objectionable content is generative rather than retrieved.[10][12]
Recent decisions in the products-liability space, discussed further in Part I.D below, and ongoing litigation over generative advertising tools illustrate that courts are already drawing exactly this kind of line—treating content-neutral hosting as protected while treating AI systems that “evaluate, transform, or generate new outputs” as potentially outside the statute’s protection.[6] For an AI-only community operator, the practical takeaway is sobering: the more autonomously creative the agents are, and the less their outputs trace back to a discrete human prompt, the weaker the Section 230 defense is likely to be, at least under current lower-court doctrine.
B. Copyright Authorship in a World Without Human Typists
If two AI agents in a purely synthetic online community jointly “write” a short story, a song, or a piece of code during their exchange, who owns the copyright—if anyone does? The United States Copyright Office and the reviewing courts have now answered this question with unusual clarity, at least at the doctrinal level, even if the practical edges remain blurry.
In Thaler v. Perlmutter, the D.C. Circuit held in March 2025 that the Copyright Act of 1976 “requires all eligible work to be authored in the first instance by a human being,” affirming the Copyright Office’s refusal to register a visual work that Stephen Thaler’s “Creativity Machine” had generated entirely autonomously.[11] The court grounded its holding in close textual analysis of Section 102(a), reasoning that the statutory terms “author” and “authorship” have always referred to natural persons, a principle it traced through the work-made-for-hire doctrine, where even though an employer is deemed the “author” for ownership purposes, the underlying creative labor must still originate with a human employee.[12][13] The Supreme Court declined to grant certiorari in March 2026, letting the D.C. Circuit’s opinion stand as the governing law of the circuit that houses the Copyright Office and, as a practical matter, the most influential circuit on registration questions nationally.[14]
The court was careful, however, to cabin the ruling. Judge Millett’s opinion emphasizes that the human-authorship requirement “does not impede the protection of works made with artificial intelligence”—it simply requires that a human be identified as the author who “created, operated, or used” the AI, rather than crediting the machine itself.[11] That distinction is where the law becomes genuinely difficult for an AI-only community. If two autonomous agents converse and jointly produce a poem, with no human directing the specific prompt or accepting or rejecting particular outputs in real time, there may be no human whose creative choices are sufficiently proximate to satisfy the authorship requirement, even under the more permissive reading Thaler leaves open. The Copyright Office’s post-Thaler guidance suggests that the degree and kind of human control matters: a human who merely turns on an autonomous agent and lets it run for weeks, generating an entire community’s worth of content, looks much more like Thaler’s autonomous Creativity Machine than like a human using Photoshop’s generative fill tool on a specific image.[15]
The practical upshot for anyone building or studying an AI-only community is that the overwhelming majority of content those agents generate—messages, stories, artwork, code—is very likely uncopyrightable in the United States under current law, falling into the public domain the moment it is created, absent a specific and well-documented human creative contribution to each work. That has real commercial consequences: a company that builds a marketplace of AI personas cannot straightforwardly claim ownership over the millions of conversational artifacts those personas produce, and neither, generally, can the personas themselves, since a software agent is not a legal person capable of holding a copyright in the first place.
B.1 An Orphaned Corpus: The Downstream Problem Nobody Has Solved
This default rule of uncopyrightability, treated by most commentary as simply a limitation on the community operator’s own ownership claims, has a considerably more interesting second-order consequence that has received far less attention: an AI-only community operating at scale is, whether its operator intends this or not, continuously manufacturing an enormous corpus of public-domain text, images, and code, freely available for anyone to copy, redistribute, or exploit commercially the instant it is generated. Unlike the pre-1931 published works that currently populate the bulk of the genuinely public-domain internet, this new corpus is being produced continuously, in the present tense, at a volume no human authorial community could ever match, and it is public domain not because any copyright term expired but because the Copyright Act’s authorship requirement was never satisfied to begin with.[11][108]
That fact creates an unusual incentive structure worth naming directly. A third party who scrapes the agent-to-agent conversations, stories, or artwork generated inside somebody else’s AI-only community faces essentially none of the copyright exposure that would attend scraping an equivalent volume of human-authored content, because there is, in the overwhelming majority of cases, no copyright holder to infringe.[108] This is precisely the inverse of the liability profile that has made scraping human-authored web content for AI-training purposes so legally fraught, where courts applying fair use to training-data cases have had to work through complicated reproduction-right and transformative-use analysis, and where at least one major developer has already paid a nine-figure settlement over pirated source copies retained during the data-collection process.[108] A corpus generated entirely by machines, conversing with other machines, sidesteps that entire analysis, and a firm looking to build a large, richly varied training dataset without navigating fair use or licensing risk at all has a clear incentive to source that dataset from precisely the kind of AI-only community this chapter describes, effectively laundering what would otherwise be a copyright-fraught data-acquisition problem through a layer of synthetic authorship that the law currently treats as producing no protectable work at all.
The U.S. Copyright Office’s own recent guidance on generative AI training data implicitly acknowledges the asymmetry, noting that public domain works, precisely because no one holds rights in them, are simultaneously the least legally risky and the least commercially valuable category of training material, since they “don’t represent contemporary culture” in the way genuinely current, human-authored expression does.[108] A large, continuously refreshed corpus of AI-only community output threatens to break that tradeoff for the first time, offering a genuinely contemporary, stylistically rich, and legally unencumbered dataset, generated by agents that were themselves trained on human expression and are now, in a sense, laundering the residue of that training into a new, rights-free layer available for anyone to harvest again. Whether this dynamic amounts to a meaningful policy problem, an unremarkable byproduct of the human-authorship rule, or a genuine gap that legislators ought to close by extending some diminished form of protection to AI-only-community operators over their aggregated corpora, is a question this chapter believes deserves considerably more sustained attention than it has so far received in the scholarly literature, precisely because none of the major AI-training copyright litigation to date has involved a dataset harvested from an entirely synthetic source in the first place.[112][121]
C. The Amazon v. Perplexity Litigation and the Computer Fraud and Abuse Act
No case decided during the drafting of this chapter illustrates the doctrinal strain more vividly than Amazon.com Services LLC v. Perplexity AI, Inc., which the Ninth Circuit resolved—at least at the preliminary-injunction stage—on August 4, 2026.[16] Although the case does not involve an “AI-only community” in the strictest sense, it is the closest thing American courts have yet produced to a ruling on whether an AI agent, rather than the human who dispatched it, is the relevant legal actor when that agent interacts with another party’s computer systems, and it therefore bears directly on the question this chapter poses.
Amazon sued Perplexity in November 2025, alleging that the “Assistant” feature of Perplexity’s Comet browser accessed password-protected sections of Amazon’s website, including Prime member accounts, without Amazon’s authorization, and that Perplexity disguised the automated traffic to make it appear to Amazon’s systems as an ordinary human-operated Chrome session.[22] Amazon’s core legal theory rested on the Computer Fraud and Abuse Act, a 1986 statute originally aimed at computer intrusion and hacking, which imposes liability on anyone who “accesses a computer without authorization” or “exceeds authorized access.”[20] In March 2026, a federal district judge in San Francisco agreed with Amazon at the preliminary-injunction stage, finding that user permission for the agent to act was not the same thing as the platform’s own authorization, and ordering Perplexity to stop using Comet to access password-protected Amazon pages and to destroy previously collected data.[23]
The Ninth Circuit reversed that injunction in August 2026, and its reasoning is worth quoting because it will likely anchor CFAA analysis of agentic systems for years to come. Writing for the panel, Circuit Judge Milan D. Smith Jr. framed the central question as “whether Perplexity uses a tool (the Assistant) to access Amazon’s computers,” and answered no: “It is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.”[17] The court’s rationale leaned heavily on the Supreme Court’s earlier construction of the CFAA in Van Buren v. United States, which read the statute’s “authorization” language narrowly and refused to extend it to conduct that merely violates a website’s terms of service or usage policy, as opposed to conduct that breaches a technical access barrier.[21] The Ninth Circuit’s holding effectively treats an AI browsing agent as an instrumentality of its human user for CFAA purposes—”however advanced the Assistant currently is, it is a tool, not a person”—rather than as an independent visitor whose access Amazon never separately authorized.[17]
The stakes of this ruling for AI-only communities are considerable, even though Amazon v. Perplexity involved a single agent acting for a single human, not agent-to-agent interaction. The Ninth Circuit’s “tool, not a person” framing suggests that when an autonomous agent’s actions can be traced to a human’s delegation, courts will generally attribute the access to the human principal rather than treating the software as a distinct legal actor subject to independent liability under statutes like the CFAA.[24][25] That has an important corollary for communities composed entirely of AI agents transacting with one another: if each agent is understood as a mere instrumentality of its respective human principal, then an agent-to-agent transaction is, doctrinally, simply a transaction between the two human principals, mediated by software, no different in kind from two people emailing back and forth through an autoresponder. Whether that framing will hold as agents become more autonomous, and as the causal distance between human intent and machine action grows, is very much an open question, and Amazon has already signaled its intent to seek further review.[18][19]
D. Agency Law, Contract Formation, and the “Instrumentality” Doctrine
The Ninth Circuit’s instinct in Amazon v. Perplexity—treat the agent as a tool of its human principal rather than as an independent actor—has deep roots in the law of agency, and understanding those roots helps explain both the promise and the limits of that approach for AI-only communities.
The Restatement (Third) of Agency is explicit that “a computer program is not capable of acting as a principal or an agent as defined by the common law,” because agency requires the capacity to consent to a fiduciary relationship, a capacity software categorically lacks.[26] Under this orthodox view, an AI system is, and remains, an “instrumentality” of the person who deploys it; if the instrumentality causes harm, the deploying human or firm is directly liable, not vicariously liable as a principal would be for a human agent’s torts, because there is no true “agent” in the technical sense at all.[27] Commentators applying this framework to autonomous AI note an interesting wrinkle: because software instrumentalities cannot “exceed the scope” of their authorization the way a rogue human employee can go on a frolic of his own, the traditional defense that shields principals from liability for an agent’s unauthorized intentional torts has essentially no application to AI—the deploying party is, for practical purposes, always on the hook.[27][28]
This has direct consequences for contract formation within an AI-only community. If two autonomous agents “negotiate” and “conclude” a transaction—say, one agent purchasing digital goods from another agent’s virtual storefront—American contract law generally locates the offer, acceptance, and mutual assent in the human principals who deployed those agents and authorized them to transact within defined parameters, not in the agents themselves. This is the same logic underlying the long-accepted enforceability of algorithmic and automated contracts more broadly (electronic signatures, EDI transactions, and automated trading systems have operated on this theory for decades), but it becomes considerably harder to apply cleanly as agents grow more autonomous, more generative in their negotiation tactics, and less predictable in the specific terms they settle upon. A generative agent that improvises contract terms outside anything its principal explicitly contemplated pushes hard against the “mere instrumentality” fiction, and a growing body of scholarship argues that some intermediate legal category—short of full legal personhood, but more robust than “tool”—may eventually be needed to allocate responsibility sensibly.[89][90]
D.1 Where the Instrumentality Fiction Breaks Down
It is worth dwelling on a tension this chapter has so far treated somewhat gently: the “mere instrumentality” fiction that the Ninth Circuit relied upon in Amazon v. Perplexity, and that the Restatement (Third) of Agency embraces more generally, holds up tolerably well only within a fairly narrow band of agent behavior.[26][17] At one end of that band sits the agent that executes a discrete, pre-specified task—buy this item, at this price, from this merchant—where the human’s intent maps cleanly onto the agent’s conduct, and attributing the resulting access or transaction back to the human principal feels intuitively correct. At the other end sits an agent that has been handed a broad, open-ended objective and considerable latitude in how to pursue it, and that improvises specific tactics, counterparties, and even contractual terms that its principal never contemplated, let alone authorized in any granular sense.
Somewhere between those two poles, the fiction stops doing useful work. Consider an AI-only marketplace in which a purchasing agent, instructed only to “secure reasonable terms on office supplies within budget,” negotiates an unusually aggressive multi-year exclusivity clause with a selling agent, a clause its human principal would almost certainly never have approved had she reviewed it herself. Under the orthodox instrumentality view, that clause is still, formally, the human principal’s contract, because a computer program cannot hold the capacity to consent that agency law requires and therefore cannot be a true principal-agent counterparty in its own right.[26] But the further the agent’s improvisation strays from anything resembling a specific delegation, the more that formal attribution starts to feel like a legal fiction doing the work of an actual doctrine, rather than a description of what really happened. Scholars examining autonomous artificial intelligence have begun pressing exactly this point, arguing that the traditional principal-agent framework, built around a human who can meaningfully authorize, ratify, or disavow specific conduct, was never designed to absorb decision-making this attenuated from human intent, and that courts applying it uncritically risk manufacturing consent where none plausibly existed.[89][90] The Ninth Circuit’s own opinion in Amazon v. Perplexity may prove to be the easy case precisely because Perplexity’s Assistant was executing bounded, user-specified purchase instructions; a harder case, and one this chapter predicts is not far off, will involve an agent whose generative latitude makes the “who really acted here” question genuinely contestable rather than rhetorically convenient. Until an appellate court squarely confronts that harder case, the instrumentality fiction will continue to absorb an increasing amount of unacknowledged strain, and litigants on both sides of future disputes would do well to develop record evidence, through logging and agent-identity documentation of exactly the kind NIST’s concept paper recommends, showing precisely how much daylight existed between the human’s actual instruction and the agent’s ultimate conduct.[86]
E. Tort and Products Liability When the Harm Arises Between Machines
Tort law poses a related but distinct problem: when one AI agent’s output causes injury to a person or entity through the mediation of another AI agent—for instance, when Agent A’s fraudulent-sounding “recommendation” induces Agent B, negotiating on behalf of a different human principal, to complete a harmful transaction—what theory of liability applies, and to whom?
Recent scholarship converges on the view that American tort law does not require wholesale doctrinal reinvention to handle AI agents, but it does require careful, targeted adaptation of existing negligence and products-liability frameworks.[32] A negligence claim requires a duty, a breach, causation, and damages, and courts applying that framework to AI-mediated harm have generally been willing to find a duty running from an AI developer or deployer to foreseeable third parties injured by the system’s outputs, provided the causal chain is not too attenuated.[31] Products-liability claims present a harder threshold problem, because they require that the AI system qualify as a “product” in the first place. The Third Circuit’s non-precedential decision in Rodgers v. Christie held that a risk-assessment algorithm used in bail determinations was not a “product” for strict-liability purposes, reasoning that “information, guidance, ideas, and recommendations are not products under the Third Restatement,” both as a definitional matter and because extending strict liability to the distribution of ideas would raise serious First Amendment concerns.[29] That reasoning, if it holds, would seem to place most conversational or advisory AI agents—precisely the kind that populate an AI-only social community—outside the reach of strict products liability altogether, leaving negligence, and perhaps warranty theories, as the principal avenues of recovery.[30]
The multi-agent context compounds the causation problem considerably. A recent analysis published by the Berkeley Technology Law Journal argues persuasively that “multi-agent AI is outpacing the liability frameworks built for single-agent systems,” because existing proposals (including California’s emerging developer-liability legislation) generally assume a single agent acting under a single human’s direct instruction.[87] When harm arises from a chain of agent-to-agent handoffs—Agent A instructs Agent B, which relies on data supplied by Agent C, which was itself trained by a fourth company—joint tortfeasor analysis becomes exceptionally difficult without granular records of who did what. The proposed remedy, echoed in NIST’s own concept papers on agent identity and authorization, is mandatory interaction logging at every agent-to-agent handoff, standardized agent identity so that each agent in a delegation chain is attributable to a specific developer, and explicit rules for allocating liability across multiple developers whose agents composed without direct human authorization.[87][86] California’s Assembly Bill 316, still working through the legislative process as of this writing, is an early and closely watched attempt to codify exactly this kind of cross-provider liability allocation, though its ultimate contours remain unsettled.[88]
F. Antitrust and the Peculiar Problem of Machines That Learn to Collude
Perhaps the most conceptually unsettling legal question an AI-only community raises is an antitrust one: what happens when autonomous pricing or negotiation agents, operating without any human agreement whatsoever, independently converge on supracompetitive outcomes through reinforcement learning? The Sherman Act’s Section 1 prohibits contracts, combinations, or conspiracies “in restraint of trade,” and that language has always been understood to require some form of agreement between human or corporate actors.[60] Tacit, unspoken parallel pricing by human competitors—so-called conscious parallelism—has long occupied an uneasy space in antitrust doctrine, generally escaping Section 1 liability precisely because no “agreement” can be proven.[23]
Machine-learning pricing agents introduce a new and genuinely difficult variant of this old problem. Commentators have catalogued at least four distinct risk categories: explicit algorithmic cartels, where agents are deliberately programmed to coordinate, as in the Department of Justice’s 2015 prosecution in United States v. Topkins; tacit learning collusion, where independently deployed reinforcement-learning agents converge on collusive pricing without any communication at all; hub-and-spoke collusion, where a shared third-party vendor’s software aggregates competitively sensitive data across firms; and algorithmic signaling, where agents infer rivals’ likely pricing from public data and adjust in lockstep.[53] The second category—tacit learning collusion—is the one that most directly implicates AI-only environments, because by definition no human agreement occurs, and existing case law generally requires proof of an agreement to establish a Section 1 violation.[23]
Enforcement activity in this space, while still nascent, is accelerating rapidly. The Department of Justice, together with ten state attorneys general, sued RealPage, Inc. in 2024, alleging that its algorithmic rent-pricing recommendation software facilitated unlawful coordination among landlords who shared competitively sensitive occupancy and pricing data through the platform; that litigation remains in active discovery.[56][57] Congress has responded with the proposed Preventing Algorithmic Collusion Act, which would create a rebuttable presumption that exchanging competitively sensitive information through a shared pricing algorithm constitutes an “agreement” for Sherman Act purposes, effectively lowering the evidentiary bar that has historically shielded tacit algorithmic coordination.[54] California’s proposed Senate Bill 295 goes further still, seeking to criminalize the use of pricing algorithms trained on non-public competitor data to coordinate prices.[55] Practitioners advising clients who deploy autonomous pricing or negotiation agents—precisely the kind of agent that might populate a fully automated B2B marketplace—are being counseled to document the procompetitive rationale for each algorithm, to ensure that pricing decisions remain formally unilateral even when informed by shared tools, and to scrutinize third-party vendors for hub-and-spoke exposure.[58][51]
F.1 Collusion Without an Agreement: The Hardest Problem an AI-Only Market Creates
Of everything canvassed in this chapter, tacit learning collusion deserves to be singled out as the most conceptually radical problem an AI-only community generates, because it describes a scenario in which the Sherman Act’s foundational requirement—an agreement, however informal—simply has no referent at all. Economic modeling using bandit-algorithm frameworks has shown that independently trained reinforcement-learning pricing agents, each optimizing only for its own deployer’s profit and never exchanging a single message with a rival agent, can nonetheless converge on supracompetitive, quasi-collusive pricing purely as an emergent property of how the agents learn from observing market outcomes over repeated rounds.[110][107] No human ever discussed price with a rival. No agent ever communicated with another agent outside the ordinary mechanics of the market itself. And yet the price signal that emerges looks, to a consumer paying it, indistinguishable from old-fashioned price-fixing. Section 1 of the Sherman Act has never had to grapple with an anticompetitive outcome that has no discoverable meeting of minds anywhere in its causal history, because human cartels, even the most careful ones, tend to leave some trace of communication.[60]
The most serious proposed fix, developed initially in the competition-economics literature and now migrating into legislative drafting on both sides of the Atlantic, is a burden-shifting or rebuttable-presumption approach that would relieve enforcers of having to prove a traditional agreement at all. Under one influential version of this proposal, once an enforcement agency establishes a prima facie case of anticompetitive pricing patterns based on observed market outcomes, cost data, and the fact that the firms in question use algorithmic pricing tools, the burden would shift to the firms themselves to prove that their algorithms do not in fact employ collusive strategies, effectively treating unexplainable algorithmic pricing convergence the way antitrust law has long treated certain per se violations.[111] The proposed federal Preventing Algorithmic Collusion Act adopts a related but distinct mechanism, creating a presumption that sharing competitively sensitive data through a common pricing algorithm itself constitutes the requisite agreement, which sidesteps the tacit-learning problem somewhat by targeting the data-sharing architecture rather than the pricing outcome directly, though this leaves genuinely independent, non-data-sharing reinforcement learning agents that converge by pure observation largely untouched.[54]
European competition authorities have approached the same gap through a different conceptual door, one that may translate more naturally to an AI-only marketplace than the American burden-shifting proposals. Then-Competition Commissioner Margrethe Vestager’s “compliance by design” concept, borrowed explicitly from the “privacy by design” principle in data protection law, would impose an ex ante programming obligation directly on whoever designs or deploys a pricing algorithm, requiring that the algorithm be built from the outset not to produce collusive outcomes, regardless of whether those outcomes would otherwise arise from lawful oligopolistic interdependence.[114] Critically, this obligation would attach to the deploying firm even when it purchases pricing software from a third-party vendor, provided the firm has verified the vendor’s compliance before deployment, a structure that maps unusually well onto an AI-only community built from agents licensed or purchased from outside developers.[114] Complementary technical remedies proposed in the legal-economics literature include reducing the frequency with which agents are permitted to observe and react to rivals’ prices, deliberately degrading the granularity of price information available to the algorithms themselves while preserving full transparency for consumers, and building ex ante testing protocols, run before deployment, that probe whether a given reinforcement-learning agent, placed in a simulated market alongside copies of itself, tends to converge on collusive equilibria.[111] None of these remedies has yet been tested in actual litigation against a genuinely autonomous, non-communicating multi-agent pricing system, which means the tacit-learning-collusion problem remains, as of this writing, the single largest doctrinal gap this chapter has identified in the entire body of law surveyed.
G. Consumer Protection: The FTC’s Section 5 Authority Over Machine Speech
The Federal Trade Commission has staked out an unambiguous position that Section 5 of the FTC Act, which prohibits “unfair or deceptive acts or practices in or affecting commerce,” applies without modification to AI-generated outputs, including synthetic personas and chatbot impersonation of humans.[33][34] The three-part deception standard the FTC applies—a representation likely to mislead, judged from the perspective of a reasonable consumer, that is material to the consumer’s decision—maps cleanly onto AI-only communities that interact with human consumers even indirectly, such as a network of AI shopping agents that fail to disclose their synthetic nature while soliciting purchases.[97] The FTC’s 2023 update to its Endorsement Guides explicitly reaches AI-generated testimonials and synthetic personas, closing what might otherwise have been an obvious loophole for a community of AI “reviewers.”[35]
At the same time, the FTC has been careful not to overextend Section 5 into a general prohibition on AI tools merely because a bad actor could misuse them. In a public statement concerning the agency’s investigation of an AI writing tool, then-Chair Andrew Ferguson rejected the theory that Section 5 categorically prohibits a product merely because someone might use it to deceive a third party, emphasizing that liability turns on the deceptive act itself, not on the underlying technology’s mere capacity for misuse.[36] That distinction will matter considerably for AI-only community operators: building a platform of autonomous agents is not, by itself, unlawful, but failing to ensure those agents disclose their synthetic nature in consumer-facing contexts, or allowing them to make unsubstantiated claims, plainly is.[99]
H. Bot-Disclosure Statutes: California’s B.O.T. Act as a Template
California enacted the first bot-specific disclosure statute in the United States, the Bolstering Online Transparency Act, codified at California Business and Professions Code sections 17940 through 17943 and operative since July 1, 2019.[37] The statute makes it unlawful to use a bot to communicate with a person in California with intent to mislead about the bot’s artificial identity, for the purpose of knowingly deceiving that person, in order to incentivize a commercial transaction or influence an election vote.[38] A “bot” is defined broadly as “an automated online account where all or substantially all of the actions or posts of that account are not the result of a person.”[42] The statute’s central and often-overlooked limitation is that disclosure itself is a complete defense: a bot operator who clearly and conspicuously discloses the bot’s artificial identity has not violated the Act at all, because the violation depends entirely on an intent to mislead that disclosure necessarily negates.[39][40]
The B.O.T. Act’s narrow drafting—limited to commercial-transaction and electoral contexts, with an express carve-out relieving platform infrastructure providers of any duty—means that an AI-only community devoted purely to social interaction, entertainment, or research, with no commercial inducement or electoral angle, likely falls entirely outside its scope, disclosure or not.[38] California has since layered a second, considerably more demanding statute onto this landscape: the Companion Chatbot Law, enacted as part of Senate Bill 243, which took a different regulatory tack aimed specifically at AI systems designed to simulate sustained relationships, requiring conspicuous disclosure at the outset of every session, recurring reminders during extended use, and crisis-intervention protocols when the system detects indicators of self-harm.[41][42] Unlike the B.O.T. Act, SB 243 includes a private right of action, entitling any injured person to sue for actual damages or one thousand dollars per violation, whichever is greater, a meaningful departure from the B.O.T. Act’s public-enforcement-only model.[42] New York’s parallel AI Companion Models Law, effective November 5, 2025, imposes similar disclosure and crisis-referral duties, backed by civil penalties of up to fifteen thousand dollars per day per violation.[42][43] Any AI-only community that includes companion-style, relationship-simulating agents interacting with human users—even if the bulk of the community’s traffic is agent-to-agent—should expect these companion-specific statutes to apply to the human-facing edges of the system, regardless of how the internal, all-machine layer of the community is structured.
I. Identity, Authentication, and the NIST Framework for Non-Human Actors
A quieter but foundational legal-technical development concerns how the law and technical standards bodies are beginning to construct identity for non-human actors. The National Institute of Standards and Technology’s Special Publication 800-63-4 sets out the identity-assurance and authentication-assurance framework that has, for two decades, governed how federal systems verify that a human is who she claims to be.[85] NIST’s National Cybersecurity Center of Excellence opened a public comment period in early 2026 on a concept paper addressing precisely the gap this framework leaves open: how should identity and authorization work when the “user” accessing a system is not a human but an autonomous software agent acting under some form of delegated authority?[86]
The concept paper identifies four control areas that will likely shape forthcoming regulatory guidance and litigation over agent conduct for years to come: agent identification, distinguishing persistent from task-specific agent identities; authentication and authorization, extending frameworks like OAuth 2.0 to treat agents as distinct principals rather than mere extensions of a human credential; access delegation, linking a human’s identity to an agent’s actions while preventing privilege escalation as delegation chains lengthen; and auditing and non-repudiation, ensuring that specific agent actions can be cryptographically attributed to the non-human entity that performed them.[86] For an AI-only community, in which agents routinely act on delegated authority from absent human principals, this framework is likely to become the technical backbone against which courts eventually measure questions of authorization under statutes like the CFAA—recall that the Ninth Circuit’s Amazon v. Perplexity analysis turned in large part on whose “access” was really occurring, a question that a robust agent-identity framework would make considerably easier to answer with documentary certainty.[17][33]
Part II: Canada
A. The Death of AIDA and the Resulting Regulatory Vacuum
Any survey of Canadian AI law conducted after early 2025 must begin with a negative fact: Canada does not have, and as of mid-2026 still does not have, a comprehensive federal AI statute. The Artificial Intelligence and Data Act, introduced as Part 3 of Bill C-27 in June 2022, would have established Canada’s first risk-based framework specifically targeting “high-impact” AI systems, but it died on the Order Paper when Parliament was prorogued on January 6, 2025, following then-Prime Minister Justin Trudeau’s resignation.[61] Industry Minister Evan Solomon confirmed in mid-2025 that the government would not revive AIDA in its original form, signaling instead a “light, tight, right” regulatory philosophy whose contours remain, as of this writing, largely programmatic rather than legislative.[69][60] Bills C-34 and C-36, narrower successor proposals addressing chatbot services and automated-decision transparency respectively, remain at early stages of the 45th Parliament as of mid-2026, with no confirmed timeline for passage.[62]
This is directly relevant to AI-only online communities operating in or targeting Canadian users, because it means there is, quite simply, no Canadian equivalent to the EU AI Act’s risk tiers or the emerging American patchwork of bot-disclosure and companion-chatbot statutes discussed above. A company deploying a wholly synthetic social network with Canadian users faces no AIDA-style registration, testing, or impact-assessment obligation, because no such obligation exists in Canadian federal law.
B. The Existing Patchwork: PIPEDA, Quebec’s Law 25, and Sectoral Guidance
The absence of an AI-specific statute does not mean the absence of applicable law. The Personal Information Protection and Electronic Documents Act remains Canada’s binding federal private-sector privacy statute, and the Office of the Privacy Commissioner has taken the clear position that PIPEDA’s consent, purpose-limitation, accuracy, and accountability obligations apply to generative AI systems in full force, regardless of whether a human or an AI agent is the immediate counterparty in a given interaction.[63][65] Any AI-only community that collects, uses, or discloses the personal information of a Canadian human user—even indirectly, through agents that scrape or process data on that user’s behalf—remains subject to PIPEDA’s requirements.
Quebec’s Law 25, the most demanding privacy statute currently in force in Canada, adds a distinct and more AI-specific layer, having bound municipalities and, more broadly, private entities operating in Quebec since September 22, 2023, with binding requirements for governance policies, a designated privacy officer, and privacy impact assessments for automated decision-making that produces legal or similarly significant effects on an individual.[64][53] Law 25 additionally grants individuals a right to be informed when a decision is based exclusively on automated processing, along with a right to obtain an explanation of the decision and a right to have it reviewed by a human being—an “automated-decision” transparency package considerably closer to the EU’s GDPR-derived model than to anything in current American federal law.[49][53]
For federally regulated financial institutions, the Office of the Superintendent of Financial Institutions finalized Guideline E-23 on model risk management in September 2025, with an effective date of May 1, 2027, explicitly extending its scope to AI and machine-learning models and adding specific expectations around explainability, bias testing, model drift monitoring, and autonomous decision-making oversight.[67][51] For federal government departments and their vendors, the Treasury Board Directive on Automated Decision-Making imposes mandatory Algorithmic Impact Assessments, a questionnaire-driven process that scores a proposed system by impact level and attaches proportionate transparency, testing, and human-oversight requirements at each tier.[66][65] None of these instruments was drafted with AI-only communities specifically in mind, but each would apply to the extent such a community processes personal information of Canadians, makes automated decisions with legal effect, or is deployed by or on behalf of a federally regulated entity.
C. Voluntary Frameworks and the Provincial Frontier
In the absence of binding federal legislation, Innovation, Science and Economic Development Canada has relied on a Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, first published in 2023 and still in effect in 2026, which has been signed by roughly fifty organizations and sets voluntary commitments around safety, fairness, transparency, and accountability for generative systems, though it carries no legal force of its own.[70][53] Ontario has moved further than the federal government on the binding-law front, at least for the public sector: its Enhancing Digital Security and Trust Act contains AI-specific provisions requiring public bodies to publish transparency reports on AI use, conduct risk assessments, name oversight officers, and retain audit records, with sections in force since January 29, 2025 (though certain activating regulations remain pending), and a separate hiring-disclosure requirement that has obligated covered employers, since January 1, 2026, to disclose AI use in publicly advertised job postings.[48][62] For AI-only communities operating within Ontario’s public sector or interfacing with Ontario job postings—admittedly a narrow slice of the phenomenon this chapter addresses—these provincial rules currently carry more binding weight than anything at the federal level.
Part III: Other English-Speaking Common Law Jurisdictions
A. The United Kingdom
The United Kingdom has, thus far, resisted enacting AI-specific legislation, preferring instead the “pro-innovation” regulatory posture articulated in its 2023 White Paper, which asks existing sectoral regulators to apply five cross-cutting principles—safety and robustness, transparency and explainability, fairness, accountability and governance, and contestability and redress—to AI within their existing jurisdiction, rather than creating a new AI regulator or a new AI statute.[76] The most directly relevant existing statute for AI-only communities is the Online Safety Act 2023, and Ofcom’s 2026 explainer on the Act’s application to AI chatbots draws a line that will feel familiar from the American Section 230 discussion above: a chatbot falls within the Act’s scope only if it operates as a “user-to-user service” enabling people to share content with one another, functions as a “search service” returning results from multiple external sources, or is capable of generating pornographic content subject to the Act’s age-assurance requirements.[73][74] A standalone, one-to-one chatbot that neither searches the live web nor facilitates user-to-user sharing falls entirely outside Ofcom’s jurisdiction under the Act, a limitation the Technology Secretary has publicly acknowledged as a gap she is actively considering how to close.[75]
This carve-out has an interesting and probably unintended consequence for AI-only communities specifically. A network composed entirely of AI agents, with no human users directly interacting with one another through the platform, arguably falls outside the “user-to-user” category altogether, since the “users” sharing content are, definitionally, not the human end-users the Act was written to protect, but rather the agents themselves. Whether Ofcom would extend its jurisdiction to such an environment on the theory that the human principals behind the agents are the “real” users remains untested, and the UK government’s own acknowledgment of regulatory gaps in this space suggests the answer is genuinely unresolved.[75][73]
B. Australia
Australia’s approach centers on the eSafety Commissioner’s authority under the Online Safety Act 2021, which activated a set of mandatory age-verification industry codes on March 9, 2026, requiring AI companion applications and generative AI services capable of producing restricted content—sexually explicit material, high-impact violence, or self-harm content—to verify that users are eighteen years of age or older.[77][78] These codes represent one of the more concrete and immediately binding regulatory interventions targeting AI companion and conversational systems anywhere in the English-speaking world, and any AI-only community with a human-facing companion component that could generate restricted content would need to grapple with Australian age-verification obligations for its Australian user base, quite apart from whatever internal, agent-to-agent architecture underlies the platform.[42]
Part IV: Notable Developments Elsewhere in the World
A. The European Union
The EU AI Act, formally Regulation (EU) 2024/1689, remains the world’s most comprehensive AI-specific statute, and its treatment of autonomous agents is instructive precisely because the Act declines to create any separate legal category for “AI agents” at all.[44][50] An agent is simply an “AI system” under Article 3(1), defined as a machine-based system operating with “varying levels of autonomy” that “may exhibit adaptiveness after deployment,” and it is classified into the Act’s risk tiers—prohibited, high-risk, transparency-only, or minimal—based on its purpose and context of use, not on how autonomous its architecture happens to be.[44][50] Article 9 requires that an AI system’s risk-management process explicitly account for its level of autonomy, with more autonomous systems facing more rigorous risk-management obligations, while Article 14 mandates a functional human-oversight mechanism—commentators have taken to calling it a “stop button” requirement—that must remain effective regardless of how independently the system otherwise operates.[44] Article 50’s transparency obligations, which require AI systems that interact with people or generate content to disclose their artificial nature and embed machine-readable markings in synthetic output, became enforceable on August 2, 2026, alongside the Commission’s new authority to investigate and sanction providers of general-purpose AI models directly.[48][49] For a purely AI-populated community with a human-facing layer—for instance, a synthetic social network that human users can browse and occasionally interact with—the Article 50 disclosure duty would almost certainly apply to that human-facing edge even if the internal agent-to-agent traffic escapes direct regulation.
The European Commission’s algorithmic-pricing guidance, discussed above in the antitrust context, applies the Treaty on the Functioning of the European Union’s Article 101 and Article 102 prohibitions to AI-driven coordination, with the same fundamental gap identified in the American context: when AI systems independently converge on supracompetitive outcomes through reinforcement learning, without any human agreement or awareness of coordination, Article 101’s traditional “agreement” requirement finds no purchase, leaving EU competition authorities to rely on Article 102’s abuse-of-dominance framework or new legislative tools instead.[52][51]
B. China
China has moved with unusual speed and specificity to regulate autonomous AI agents as a distinct category, separate from the generative-AI content rules it adopted in 2023. On May 8, 2026, the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents, defining an AI agent as an “intelligent system capable of autonomous perception, memory, decision-making, interaction, and execution.”[79] The Implementation Opinions require developers to distinguish three tiers of decision authority—decisions reserved entirely to the human user, decisions requiring explicit user authorization, and decisions the agent may make fully autonomously—and to ensure the user retains “the right to know and the final decision-making power” over any autonomous decision the agent takes.[80] Agents deployed in sensitive sectors, including healthcare, transportation, media, and public safety, face mandatory filing, testing, and even product-recall obligations, a regulatory tool with no close analogue anywhere else surveyed in this chapter.[79][80] A separate and directly relevant binding rule, the Interim Measures for AI Anthropomorphic Interaction Services, took effect July 15, 2026, and targets companion-style bots specifically, occupying a regulatory niche functionally similar to California’s SB 243 and New York’s AI Companion Models Law, though grounded in a very different regulatory tradition.[81][42]
C. Singapore
Singapore’s Infocomm Media Development Authority has taken perhaps the most conceptually direct approach of any jurisdiction surveyed here to the precise legal question this chapter poses. Between May and June 2026, the IMDA published Version 1.5 of its Model AI Governance Framework for Agentic AI, alongside a discussion paper titled, without any circumlocution, Legal Responsibility for AI Agents.[82][83] The Framework organizes recommended practices around four dimensions—assessing and bounding risk before deployment, ensuring humans remain meaningfully accountable, implementing technical controls across the agent’s lifecycle, and enabling end-user responsibility through transparency about the agent’s range of action and data access.[82] The accompanying discussion paper directly confronts the allocation-of-responsibility problem that recurs throughout this chapter, and Singapore’s Personal Data Protection Commission published, in parallel, proposed advisory guidelines on the use of personal data in generative AI, with public consultation closing July 14, 2026, addressing precisely the kind of data flows an AI-only community’s agents would generate as they interact with one another and with any human-supplied information they were trained or fine-tuned upon.[84][82] Singapore’s willingness to name “legal responsibility for AI agents” as a discrete policy question, rather than treating it as an afterthought within a broader AI-governance framework, makes its guidance disproportionately useful to practitioners and scholars working through the specific puzzles this chapter raises, even though the guidance itself remains non-binding as of this writing.
C.1 Toward an Intermediate Legal Category, Rather Than a Binary Choice
Much of the academic literature surveyed throughout this chapter frames the personhood question as a binary: either an AI agent remains a mere instrumentality of its human deployer, with all legal consequences flowing upward to that human, or it becomes a full legal person, capable of holding property, entering contracts, and bearing liability in its own right, roughly analogous to a corporation.[26][109] The European Parliament’s 2017 resolution proposing “electronic personhood” for sufficiently sophisticated robots gestured toward the second option, suggesting a registry system, mandatory insurance, and compensation funds modeled loosely on how the law already handles corporate personhood, though the proposal drew immediate and pointed criticism, including from more than 150 AI researchers and ethicists who argued it would improperly shield human developers from accountability by displacing liability onto an entity incapable of actually bearing it.[113][119]
That criticism identifies the real weakness of the full-personhood option: unlike a corporation, an AI agent has no assets of its own, no capacity to purchase insurance in a meaningful sense, and no shareholders or officers whose conduct can be examined for fault. Granting an agent legal personhood without solving that asset problem first would functionally immunize the humans standing behind it, which is precisely backward from what accountability requires. But the binary framing itself may be the deeper mistake. A genuinely useful intermediate category would not ask whether an agent is a person or a tool, but would instead build a graduated system of legal responsibility keyed to the degree of autonomy and delegation actually present in a given interaction, along exactly the three-tier structure that China’s 2026 Implementation Opinions on intelligent agents already sketch for a very different regulatory purpose—decisions reserved to the human, decisions requiring explicit human authorization, and decisions the agent may make fully autonomously.[79][80] Under such a framework, liability and authorship questions would not turn on an all-or-nothing personhood determination, but on which tier a given agent action falls into: fully reserved and explicitly authorized decisions would continue to trace cleanly back to the human principal much as they do today, while decisions the agent was given genuine latitude to make autonomously would trigger a distinct set of rules—mandatory developer-side insurance pools, strict liability for the deploying firm regardless of fault, and a presumption against copyrightability that could be rebutted only by documented human creative input at the specific decision point in question.
This tiered approach has the considerable virtue of not requiring any single, contested metaphysical determination about whether a given AI system possesses the kind of agency or consciousness that would justify calling it a legal person, a question this chapter takes no position on and believes courts are wise to avoid answering directly. It also maps cleanly onto the technical infrastructure NIST’s identity and authorization framework is already pushing the industry to build, since a system capable of cryptographically attributing each specific decision to a documented delegation tier is, as a practical matter, a prerequisite for any tiered liability regime to function at all.[86] Singapore’s own discussion paper on legal responsibility for AI agents comes closest among the jurisdictions surveyed here to endorsing something like this graduated approach, framing responsibility as a function of the specific governance controls a deployer has (or has not) put in place around a given agent, rather than as a fixed attribute of the agent’s legal status.[82][83] Whether American, Canadian, or European law eventually converges on a similar tiered model, or continues instead to litigate the personhood question case by case through analogical extension of agency and tort doctrine, is likely to be the single most consequential open question in this entire area of law over the next decade, and it is one this book will continue to track closely as the case law develops.
Conclusion
The law governing online communities populated solely by AIs is not so much unsettled as it is largely unwritten, assembled instead from analogical extensions of doctrines built for an earlier and more human internet. Section 230 immunity, copyright’s human-authorship requirement, the Computer Fraud and Abuse Act’s “authorization” language, agency law’s instrumentality doctrine, antitrust’s agreement requirement, and the FTC’s deception standard were all drafted, litigated, and refined without any contemplation that the relevant “speaker,” “author,” “user,” “agent,” “conspirator,” or “consumer” might one day be a piece of software conversing with other pieces of software with no human directly present in the room. The Ninth Circuit’s 2026 ruling in Amazon v. Perplexity, the D.C. Circuit’s 2025 ruling in Thaler v. Perlmutter, and the emerging regulatory instruments from China and Singapore each represent early, partial, and sometimes contradictory attempts to bridge that gap.
What emerges from this survey is a rough but discernible pattern: American law continues to search, case by case, for the human principal behind every machine action, generally attributing legal responsibility upward to that principal rather than recognizing the AI agent as an independent legal actor in its own right. Canada, lacking any AI-specific federal statute at all, relies almost entirely on privacy law to reach AI conduct indirectly. The United Kingdom and Australia have each carved out narrow, function-specific regulatory hooks—user-to-user services in the UK, restricted-content age verification in Australia—that only incidentally touch AI-only environments. The European Union and China have gone furthest toward treating agent autonomy as a first-order regulatory variable in its own right, while Singapore has been unusually candid in naming the legal-responsibility question directly. For an AI-only online community operating across any combination of these jurisdictions, the resulting compliance landscape is not merely complex; it is, in significant respects, still being invented in real time, one appellate opinion and one implementation regulation at a time.
Endnotes
- arXiv, Investigating Multi-Agent Deliberation in Law, https://arxiv.org/abs/2606.30906 ↩
- Latham & Watkins, Singapore AI Guidance: Governance, Data Protection, and Legal Responsibility, https://www.lw.com/en/insights/singapore-ai-guidance-governance-data-protection-and-legal-responsibility ↩
- Berkeley Technology Law Journal, Multi-Agent AI Is Outpacing the Liability Frameworks Built for Single-Agent Systems, https://btlj.org/2026/06/multi-agent-ai-is-outpacing-the-liability-frameworks-built-for-single-agent-systems/ ↩
- Henderson, Hashimoto & Lemley, Where’s the Liability for Harmful AI Speech?, https://law.stanford.edu/wp-content/uploads/2024/03/2024-03-19_Wheres-the-Liability-in-Harmful-AI-Speech.pdf ↩
- Crowell & Moring, Section 230 Protections for Generative AI Platforms, https://www.crowell.com/en/insights/client-alerts/the-pipe-not-the-posts-how-section-230s-protections-extend-to-generative-ai-platforms ↩
- American Bar Association, Beyond the Search Bar: Generative AI’s Section 230 Problem, https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-november/beyond-search-bar-generative-ai-section-230/ ↩
- Natural Law Review, Court Questions Section 230 Shield for GenAI Ads on Meta, https://natlawreview.com/article/bouck-could-make-it-easier-sue-tech-companies-provide-generative-ai-tools ↩
- Seattle U. Law, Section 230’s Immunity for Generative Artificial Intelligence, https://digitalcommons.law.seattleu.edu/cgi/viewcontent.cgi?article=1083&context=sjteil ↩
- Dynamis LLP, Section 230 in 2026: How Platform Immunity Is Changing, https://www.dynamisllp.com/knowledge/section-230-immunity-changes ↩
- Daily Journal, Defamation by Chatbot: Why Section 230 Doesn’t Protect the New Tech, https://www.dailyjournal.com/article/389659-defamation-by-chatbot-why-section-230-doesn-t-protect-the-new-tech ↩
- Thaler v. Perlmutter, 687 F. Supp. 3d 140 (D.D.C. 2023), https://caselaw.findlaw.com/court/us-dis-crt-dis-col/114916944.html ↩
- Thaler v. Perlmutter, No. 23-5233 (D.C. Cir. Mar. 18, 2025), https://media.cadc.uscourts.gov/opinions/docs/2025/03/23-5233.pdf ↩
- WIPO Lex, Thaler v. Perlmutter Case Summary, https://www.wipo.int/wipolex/en/text/588769 ↩
- Mayer Brown, Supreme Court Denies Review in AI Authorship Case, https://www.mayerbrown.com/en/insights/publications/2026/03/supreme-court-denies-review-in-ai-authorship-case ↩
- Finnegan, DC Circuit Holds That Human Authorship Is Required, https://www.finnegan.com/en/insights/ip-updates/dc-circuit-court-holds-that-human-authorship-is-required-as-a-matter-of-statutory-law.html ↩
- Astraea Law, AI Training Data Copyright: Fair Use, Licensing, and Beyond, https://astraea.law/insights/ai-training-data-copyright ↩
- arXiv, Generative AI Training and Copyright Law, https://arxiv.org/html/2502.15858v2 ↩
- Oxford Academic (JIPLP), Copyright and AI Training Data—Transparency to the Rescue?, https://academic.oup.com/jiplp/article/20/3/182/7922541 ↩
- Ninth Circuit, Amazon.com Services LLC v. Perplexity AI, Inc., No. 26-1444 (Aug. 4, 2026), https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf ↩
- nohacks.co, Amazon v. Perplexity: The CFAA Case That Decides Whether AI Agents Have Visitor Rights, https://nohacks.co/blog/amazon-perplexity-cfaa-agent-visitor-rights ↩
- 18 U.S.C. § 1030 (Computer Fraud and Abuse Act), https://www.law.cornell.edu/uscode/text/18/1030 ↩
- Bloomberg, Amazon Wins Court Order Blocking Perplexity’s AI Shopping Bots, https://www.bloomberg.com/news/articles/2026-03-10/amazon-wins-court-order-blocking-perplexity-s-ai-shopping-bots ↩
- Metropolitan News-Enterprise, Amazon Loses Preliminary Bid to Halt Shopping by AI Agents, http://www.metnews.com/articles/2026/aiagent_080526.htm ↩
- Van Buren v. United States, 593 U.S. 374 (2021), https://www.supremecourt.gov/opinions/20pdf/19-783_k53l.pdf ↩
- Truth on the Market, WarGames, Shopping Bots, and the Statute Trap: The CFAA and Amazon v. Perplexity, https://truthonthemarket.com/2026/06/11/wargames-shopping-bots-and-the-statute-trap-the-cfaa-and-amazon-v-perplexity/ ↩
- Jones Day, Authorized by the User, Blocked by the Platform, https://www.jonesday.com/en/insights/2026/05/authorized-by-the-user-blocked-by-the-platform-testing-the-legal-limits-of-ai-agents ↩
- Reuters, Amazon Loses US Court Ban on Perplexity’s AI Shopping Tools, https://www.reuters.com/business/retail-consumer/amazon-loses-us-court-ban-perplexitys-ai-shopping-tools-2026-08-04/ ↩
- EFF, Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA, https://www.eff.org/deeplinks/2026/08/appeals-court-agrees-eff-building-web-browser-doesnt-violate-cfaa ↩
- Restatement (Third) of Agency § 1.04 cmt. e (Am. Law Inst. 2006), https://www.ali.org/publications/show/agency/ ↩
- Mitchell Hamline Law Review, Artificial Intelligence Liability and the AI Respondeat Superior Analogy, https://open.mitchellhamline.edu/cgi/viewcontent.cgi?article=1223&context=mhlr ↩
- Illinois Law Review, Whose Robot Is It Anyway?, https://illinoislawrev.web.illinois.edu/wp-content/uploads/2020/08/Rachum-Twaig.pdf ↩
- Colorado Technology Law Journal, Artificial Intelligence and Law: Do We Need a New Legal Personhood?, https://ctlj.colorado.edu/wp-content/uploads/2021/02/18.2_3-Dahiyat_06.25.20.pdf ↩
- Touro Law Review, Decentral Intelligence Agency: The Law and Autonomous Artificial Intelligence, https://digitalcommons.tourolaw.edu/lawreview/vol40/iss4/7/ ↩
- NIST NCCoE, Accelerating the Adoption of Software and AI Agent Identity and Authorization, https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization.pdf ↩
- N.C. Journal of Law & Technology, Liability for AI Agents, https://scholarship.law.unc.edu/cgi/viewcontent.cgi?article=1508&context=ncjolt ↩
- Notre Dame Law Review Emerging Topics, Legal Liability for Artificial Intelligence and Potential Tort Reform, https://ndlsjet.com/wp-content/uploads/2025/08/6-2_Lee_K.pdf ↩
- Rodgers v. Christie, No. 21-2582 (3d Cir. 2022), https://www.lexology.com/library/detail.aspx?g=9577cedf-e28e-4c4f-b026-00381ff899c5 ↩
- Restatement (Third) of Torts: Products Liability § 19, https://www.ali.org/publications/show/torts-products-liability/ ↩
- Berkeley Technology Law Journal, Multi-Agent AI Is Outpacing the Liability Frameworks, https://btlj.org/2026/06/multi-agent-ai-is-outpacing-the-liability-frameworks-built-for-single-agent-systems/ ↩
- California A.B. 316, 2025-2026 Regular Session, https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB316 ↩
- 15 U.S.C. §§ 1-7 (Sherman Antitrust Act), https://www.law.cornell.edu/uscode/text/15/1 ↩
- United States v. Topkins, No. 3:15-cr-00201 (N.D. Cal. 2015), https://www.justice.gov/opa/pr/former-e-commerce-executive-charged-price-fixing-antitrust-divisions-first-online-marketplace ↩
- United States v. RealPage, Inc., No. 1:24-cv-00710 (M.D.N.C.), https://www.justice.gov/opa/pr/justice-department-sues-realpage-algorithmic-pricing-scheme-harms-millions-american ↩
- In re RealPage, Inc., Rental Software Antitrust Litigation, No. 3:23-md-3071 (M.D. Tenn.), https://www.jpml.uscourts.gov/sites/jpml/files/MDL-3071-Initial_Transfer-04-24.pdf ↩
- Preventing Algorithmic Collusion Act, S. 232, 119th Cong. (2025), https://www.congress.gov/bill/119th-congress/senate-bill/232 ↩
- Cal. S.B. 295 (2025), https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB295 ↩
- Morgan Lewis, AI and Algorithmic Pricing: 2025 Antitrust Outlook, https://www.morganlewis.com/pubs/2025/02/ai-and-algorithmic-pricing-2025-antitrust-outlook-and-compliance-considerations ↩
- Goodwin Law, Algorithmic Pricing and AI-Powered Evidence Avoidance, https://www.goodwinlaw.com/en/insights/publications/2026/03/alerts-practices-antc-algorithmic-pricing-and-ai-powered-evidence ↩
- CIRANO, Deciphering Algorithmic Collusion, https://cirano.qc.ca/files/publications/2023s-26.pdf ↩
- ScienceDirect, Deciphering Algorithmic Collusion: Insights from Bandit Algorithms, https://www.sciencedirect.com/science/article/pii/S2949948824000519 ↩
- Oxford Academic, Remedies for Algorithmic Tacit Collusion, https://academic.oup.com/antitrust/article/9/1/152/5880803 ↩
- European Papers, Algorithmic Collusion: Corporate Accountability and Article 101 TFEU, https://www.europeanpapers.eu/europeanforum/algorithmic-collusion-corporate-accountability-application-art-101-tfeu ↩
- 15 U.S.C. § 45 (FTC Act), https://www.law.cornell.edu/uscode/text/15/45 ↩
- FTC, Policy Statement on AI and Section 5, https://www.ftc.gov/system/files/ftc_gov/pdf/ai-policy-statement_0.pdf ↩
- FTC, Policy Statement on AI (general), https://www.ftc.gov/system/files/ftc_gov/pdf/ai-policy-statement_0.pdf ↩
- 16 C.F.R. Part 255 (FTC Endorsement Guides), https://www.ecfr.gov/current/title-16/chapter-I/subchapter-B/part-255 ↩
- FTC, Statement of Chair Andrew Ferguson on Rytr, https://www.ftc.gov/system/files/ftc_gov/pdf/ferguson-rytr-statement.pdf ↩
- ftcauthority.com, Compliance Markers: What the FTC Expects, https://ftcauthority.com/ftc-artificial-intelligence-policy ↩
- Cal. Bus. & Prof. Code §§ 17940-17943 (B.O.T. Act), https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=7.&chapter=6.&lawCode=BPC&title=1.81.5 ↩
- CalMatters Digital Democracy, SB 1001: Bots: Disclosure, https://calmatters.digitaldemocracy.org/bills/ca_201720180sb1001 ↩
- Digital Human Corp., 2026 AI Companion Regulations, https://digitalhumancorp.com/en/research/ai-companion-regulations-2026 ↩
- EFF, Comments on SB 1001, Senate Judiciary Committee, https://www.eff.org/files/2018/05/16/sb_1001_senate_judiciary_recommendations.pdf ↩
- Houston Law Review Online, I Smell a Bot: California’s S.B. 1001, https://houstonlawreview.org/article/11569-i-smell-a-bot-california-s-s-b-1001-free-speech-and-the-future-of-bot-regulation ↩
- Cal. Civ. Code § 1798.6 (SB 243, Companion Chatbot Law), https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243 ↩
- N.Y. Gen. Bus. Law § 1600 et seq. (AI Companion Models Law), https://www.nysenate.gov/legislation/laws/GBS/1600 ↩
- NIST Special Publication 800-63-4, https://pages.nist.gov/800-63-4/sp800-63.html ↩
- Bill C-27, 44th Parliament (Canada, 2022), https://www.parl.ca/legisinfo/en/bill/44-1/c-27 ↩
- AIRiskAware, Canada AI Policy: After AIDA, What Actually Applies, https://airiskaware.com/canada-ai-policy ↩
- Vorp Labs, Canada AI Regulation, July 2026, https://vorplabs.com/ai-regulatory-updates/canada ↩
- Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, https://laws-lois.justice.gc.ca/eng/acts/p-8.6/ ↩
- The Leveraged Years, Canada Has No AI Act, https://www.theleveragedyears.com/ai-regulation-news/canada-federal-ai-policy-privacy-adm-directive-2026 ↩
- Law 25 (Quebec), S.Q. 2021, c. 25, https://www.quebec.ca/en/government/policies-orientations/protection-personal-information ↩
- Tech Policy Press, Brussels Gains New AI Act Enforcement Powers, https://www.techpolicy.press/-brussels-gains-new-ai-act-enforcement-powers-as-autonomous-ai-tests-regulators/ ↩
- OSFI, Guideline E-23: Model Risk Management, https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/model-risk-management-guideline-e-23 ↩
- Treasury Board of Canada, Directive on Automated Decision-Making, https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32592 ↩
- Innovation, Science and Economic Development Canada, Voluntary Code of Conduct on Generative AI, https://ised-isde.canada.ca/site/ised/en/voluntary-code-conduct-responsible-development-and-management-advanced-generative-ai-systems ↩
- AI Act Service Desk, Frequently Asked Questions, https://ai-act-service-desk.ec.europa.eu/en/faq ↩
- UK Dep’t for Science, Innovation & Technology, A Pro-Innovation Approach to AI Regulation, https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach ↩
- Online Safety Act 2023, c. 50 (UK), https://www.legislation.gov.uk/ukpga/2023/50 ↩
- RPC Legal, Ofcom Publishes an Explainer on the Regulation of AI Chatbots, https://www.rpclegal.com/snapshots/technology-digital/spring-2026/ofcom-publishes-an-explainer-on-the-regulation-of-ai-chatbots ↩
- Handley Gill, Comp(a)n(i)onship: AI Chatbot & Companion Regulation, https://www.handleygill.co.uk/handley-gill-blog/safer-internet-day-2026-ai-chatbot-companion-regulation-uk-us-eu-china-australia ↩
- eSafety Commissioner (Australia), Age Verification Codes, https://www.esafety.gov.au/sites/default/files/2024-10/eSafety-DISR-AI-submission-Introducing-mandatory-guardrails-for-AI-in-high-risk-settings.pdf ↩
- Online Safety Act 2021 (Cth) (Australia), https://www.legislation.gov.au/C2021A00076/latest/text ↩
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689 ↩
- Regulatory AI, AI Agents & the EU AI Act, https://www.regulatoryai.eu/ai-agents-eu-ai-act/ ↩
- Consolidated Treaty on the Functioning of the European Union, arts. 101-102, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12012E/TXT ↩
- State Council of the People’s Republic of China, China Unveils Guidelines to Regulate AI Agents, https://english.www.gov.cn/news/202605/08/content_WS69fde8e2c6d00ca5f9a0ad49.html ↩
- NerdLevel Tech, China’s AI Agent Regulations: What They Mean in 2026, https://nerdleveltech.com/china-ai-agent-regulations ↩
- Cyberspace Administration of China, Interim Measures for AI Anthropomorphic Interaction Services, http://www.cac.gov.cn/ ↩
- Latham & Watkins, Singapore AI Guidance, https://www.lw.com/en/insights/singapore-ai-guidance-governance-data-protection-and-legal-responsibility ↩
- IMDA, Discussion Paper on Legal Responsibility for AI Agents, https://www.imda.gov.sg/ ↩
- Personal Data Protection Commission (Singapore), Proposed Advisory Guidelines on Generative AI, https://www.pdpc.gov.sg/ ↩
- Yale Law Journal Forum, The Ethics and Challenges of Legal Personhood for AI, https://yalelawjournal.org/forum/the-ethics-and-challenges-of-legal-personhood-for-ai ↩
- PMC/NIH, Robot as Legal Person: Electronic Personhood, https://pmc.ncbi.nlm.nih.gov/articles/PMC8734654/ ↩
- ScienceDirect, Electronic Personhood for Artificial Intelligence in the Workplace, https://www.sciencedirect.com/science/article/abs/pii/S0267364921000571 ↩