0 cumulative citations
View corpus contextEU, UK and Pakistan law leave a gap in who pays when autonomous AI agents mishandle crypto-assets; the paper proposes a five-step attribution framework to allocate responsibility across developers, deployers, custodians and service providers rather than creating AI legal persons.
Citation observations
Cumulative provider counts captured on specific dates; providers are never combined.
0 cumulative citations
View corpus contextAutonomous artificial intelligence agents in the crypto-asset markets present a distinct attribution of legal liability issue. An autonomous agent can approve, arrange and conduct transactions without special user case consent and the relevant legal relationship is spread among various participants such as developers, AI providers, deployers, users, custodians, crypto-asset service providers and other infrastructure operators. Traditional legal systems usually do not recognize autonomous AI agents as independent legal entities and traditional private-law rules and specialized regimes do not offer a consistent process for determining the legal subject who is held liable for financial damage resulting from autonomous execution. This article has made a comparison of European Union with England and Wales and Pakistan. It takes into account the EU AI Act, Markets in Crypto-Assets Regulation, revised Product Liability Directive, and the proposed AI Liability Directive, as well as the Property ( Digital Assets etc) Act 2025, the Financial Services and Markets Act 2000 (Crypto assets) Regulations 2026 in England and Wales and the National AI Policy 2025, the Regulation of Artificial Intelligence Bill 2024 and the Virtual Assets Act 2026 in Pakistan. The analysis shows that every jurisdiction has rules that potentially apply to AI governance, crypto-asset activity, custody, product liability and property rights/institutional responsibility, but no rules providing a methodology to assign legal responsibility when autonomous agents operate across various technical and institutional layers. The article is not a substantive cause of action but a normative attribution model that is the Control-Authorization-Duty-Causation-Rule framework. The framework provides guidance to adjudicators with respect to: determination of the technically and operationally competent actors; scope of authorization; identification of duties; breach or defect and causation; selection and application of the governing liability rule, including allocation of liability among multiple actors and available remedies. The framework distinguishes technical autonomy from legal responsibility: autonomy alone does not create or end liability and the AI system does not need to have legal personality for responsibility to be attributed to an existing legal person. The analysis also identifies “double opacity” – the interaction of algorithmic opacity and transactional opacity – as a distinctive evidentiary problem in autonomous crypto-asset disputes. A worked hypothetical illustrates the framework thru VASP-mediated self-custodied hybrid DeFi and institutional multi-agent architectures. The article argues that reforms to targeted attribution, evidence preservation and risk allocation are preferable to granting autonomous AI agents independent legal personality.
Summary
Main Finding
No analyzed jurisdiction (EU, England & Wales, Pakistan) currently provides a clear, consistent method to attribute civil legal liability for financial losses caused by autonomous AI agents in crypto-asset transactions. The article proposes a normative attribution methodology — the Control‑Authorization‑Duty‑Causation‑Rule (CADCR) framework — to guide adjudicators in identifying technically and operationally competent actors, defining scope of authorization and duties, assessing breach/causation under double opacity, and selecting/applying liability rules and remedies. The author argues targeted attribution, evidence‑preservation and risk‑allocation reforms are preferable to granting legal personality to AI agents.
Key Points
-
Scope and focus
- Civil liability for financial harm from autonomous AI agents in crypto transactions; criminal liability excluded.
- Comparative analysis of three jurisdictions chosen for contrast: EU (regulatory-intensive), England & Wales (common-law adaptability), Pakistan (emerging-market, sectoral regulation).
-
Core problem
- Technical autonomy of AI agents (decision/execution/economic autonomy) separates decision-making, signature/execution, custody and economic benefit across multiple actors, creating attribution gaps.
- “Double opacity” — interaction of algorithmic opacity (black box decision processes) and transactional opacity (pseudonymity, fragmented distributed records) — creates a distinctive evidentiary problem for proving causation and fault.
-
Four AI‑crypto transaction architectures (distinct attribution challenges)
- A. AI agent acting through a regulated VASP/CASP (custody/execution under a regulated intermediary).
- B. AI agent controlling a self‑custodied wallet (no intermediary; hardest for attribution).
- C. Hybrid custody/DeFi execution (custody by a regulated actor, execution on DeFi protocols).
- D. Multi‑agent institutional systems (multiple interacting autonomous agents across organizations).
-
Actor ecosystem (potentially liable parties)
- Data providers/curators, model developers, AI model/API providers, testers, software integrators, wallet/infrastructure providers, custodians, VASPs/CASPs, oracles, DEX/protocol operators, DAOs/governance participants, sellers/distributors, deployers/operators, end users. Liability relevance depends on architecture and jurisdiction.
-
Doctrinal tools and limits
- Existing doctrines that may be applied: agency concepts, vicarious/enterprise liability, contractual obligations, negligence (duty of care, breach, causation), statutory/product liability, fiduciary duties, restitution/proprietary remedies.
- EU revised Product Liability Directive (2024) explicitly covers software (including AI) but does not create a general strict-liability cause of action for pure economic loss from financial transactions.
- None of the three jurisdictions confer legal personality on autonomous AI agents; autonomy ≠ legal autonomy.
-
Proposed attribution model (CADCR)
- Control: identify who had technical and operational control/competence over the system or transaction path.
- Authorization: determine whether the actor had authority (express/implied/contractual) to act or to permit actions.
- Duty: identify legal duties owed (contractual, statutory, fiduciary, professional).
- Causation: assess breach/defect and causation in light of algorithmic and transactional opacity; consider evidentiary burdens and preservation.
- Rule: select and apply the appropriate liability regime; allocate liability among multiple actors; determine remedies (compensation, restitution, injunctive relief).
-
Policy conclusion
- Recommend targeted reforms: clarified attribution rules, mandatory evidence‑preservation/auditability, clearer contractual risk allocation, regulatory duties for VASPs/custodians, insurance/market mechanisms — rather than creating AI legal personality.
Data & Methods
- Methodology: doctrinal and comparative legal analysis drawing primarily on primary legal sources, supplemented by policy documents, law‑reform materials, academic literature and select industry reporting for factual context.
- Primary sources reviewed: EU AI Act (Regulation (EU) 2024/1689), Markets in Crypto‑Assets Regulation (MiCAR), revised EU Product Liability Directive (Directive (EU) 2024/2853), proposed EU AI Liability Directive; England & Wales statutes/regulations including Property (Digital Assets etc) Act 2025 and Financial Services and Markets Act 2000 (Crypto assets) Regulations 2026; Pakistan’s National AI Policy 2025, Regulation of Artificial Intelligence Bill 2024, Virtual Assets Act 2026.
- Comparative framing: functional comparison across differences in constitutional/regulatory/private‑law systems, focusing on how each addresses legal status, legal relationship, duties, attribution, causation, liability standards and remedies.
- Evidence/examples: uses recent industry incidents (e.g., Lobstar token transfer, AI wallet prompt‑injection hacks) to illustrate practical issues; contains a worked hypothetical involving VASP‑mediated self‑custody hybrid DeFi and institutional multi‑agent architectures to demonstrate the CADCR framework in practice.
Implications for AI Economics
-
Risk allocation and contracting
- Unclear liability increases transaction and contracting costs: parties will seek detailed contractual allocation of risks, stricter terms with VASPs/custodians, and bespoke indemnities—raising negotiation and compliance costs.
- Self‑custody architectures (B) may see higher private bargaining/insurance costs or reduced uptake due to attribution difficulty; intermediated models (A/C) may be preferred despite fees.
-
Market design and adoption
- Providers may internalize higher compliance and liability‑mitigation costs (testing, logging, attestations), which raises prices or reduces marginal innovation.
- Enterprises may prefer architectures that reduce attribution uncertainty (use regulated VASPs, on‑chain attestations, stronger identity linkage), influencing the evolution of product offerings and DeFi integration choices.
-
Insurance and capital
- Demand for tailored cyber/financial/AI‑errors insurance will rise; insurers will price for double‑opacity risks, possibly requiring minimum technical controls (logging, explainability, transaction caps) for coverage.
- Systemic risk considerations: multi‑agent institutional systems and large‑scale autonomous trading agents can create correlated failure modes; incomplete liability rules may leave socialized losses or underpriced tail risk.
-
Evidence, auditability and information economics
- Double opacity creates asymmetric information and adverse selection problems; mandates for evidence preservation, standardized logs and cryptographic attestations would reduce informational frictions and lower the cost of claims and monitoring.
- Regulatory requirements for provenance/audit trails and model reporting would improve market confidence but increase compliance costs.
-
Regulatory competition and cross‑border frictions
- Differing attribution regimes across jurisdictions will generate regulatory arbitrage opportunities and friction in enforcement for cross‑border transactions, impacting capital flows and where firms choose to deploy AI‑crypto services.
-
Innovation incentives and policy tradeoffs
- The paper’s recommendation for targeted attribution and evidence reforms (rather than AI personhood) aims to balance innovation with accountability: clearer liability channels reduce moral hazard without chilling development as much as rigid strict‑liability regimes or novel personhood constructs might.
- Implementation choices (e.g., strict liability for certain actors vs. negligence‑based duties) will affect where costs fall (developers, deployers, intermediaries) and therefore shape incentives for safer design, testing, and monitoring.
Overall, the article signals that in the emerging AI‑crypto market, legal uncertainty about who bears loss will materially affect market structure, product design, insurance markets, compliance costs and incentives for safe AI deployment. Concrete reforms—especially on evidence preservation, minimum operational controls, and clearer duties for intermediaries—are likely to have the largest beneficial impact on reducing transaction costs and systemic risk while preserving innovation.
Assessment
Claims (9)
| Claim | Direction | Outcome | Confidence & Evidence | Details |
|---|---|---|---|---|
| The EU, England and Wales, and Pakistan each have rules that may apply to AI governance, crypto-asset activity, custody, product liability, property rights, or institutional responsibility, but none provides a methodology for assigning legal responsibility when autonomous agents operate across multiple technical and institutional layers. Governance And Regulation | negative | Availability and adequacy of legal mechanisms for attributing liability for autonomous AI-agent crypto transactions |
Reading fidelity
high
Study strength
medium
|
n=3
|
| The paper proposes the Control-Authorization-Duty-Causation-Rule framework as a normative methodology for attributing legal responsibility among actors involved in autonomous crypto-asset transactions. Governance And Regulation | positive | Methodological guidance for legal liability attribution |
Reading fidelity
high
Study strength
low
|
n=3
|
| The proposed framework directs adjudicators to identify technically and operationally competent actors, determine the scope of authorization, identify applicable duties, assess breach or defect and causation, select the governing liability rule, and allocate liability and remedies among multiple actors. Governance And Regulation | positive | Completeness of the proposed legal attribution process |
Reading fidelity
high
Study strength
low
|
n=1
|
| Technical autonomy by an AI agent does not itself create or terminate legal liability, and an AI system need not have legal personality for responsibility to be attributed to an existing natural or legal person. Governance And Regulation | null_result | Legal effect of AI autonomy and legal personality on liability attribution |
Reading fidelity
high
Study strength
medium
|
n=3
|
| None of the three legal frameworks analyzed currently establishes a general legal-personality regime under which autonomous AI agents are independent legal persons capable of being held civilly liable. Governance And Regulation | negative | Recognition of autonomous AI agents as independently liable legal persons |
Reading fidelity
high
Study strength
medium
|
n=3
|
| The interaction of algorithmic opacity and transactional opacity creates a distinctive evidentiary problem for establishing legal causation and attribution in autonomous crypto-asset disputes. Governance And Regulation | negative | Ability of claimants to establish the causal chain and prove liability |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Direct negligence in deploying or supervising an autonomous AI agent may provide a more straightforward liability basis than vicarious liability, including where a business installs an insufficiently tested system, fails to establish transaction caps, or fails to supervise the agent. Governance And Regulation | positive | Availability of negligence-based liability for unsafe deployment or supervision |
Reading fidelity
high
Study strength
low
|
not reported
|
| The revised EU Product Liability Directive expressly includes software, including AI systems, within its product-liability framework, but its compensable-damage provisions do not create a general strict-liability action for pure economic loss arising solely from a financial transaction. Governance And Regulation | mixed | Availability and scope of product-liability remedies for AI-related crypto-asset financial losses |
Reading fidelity
high
Study strength
medium
|
n=1
|
| The paper argues that targeted attribution reforms, evidence preservation, and risk allocation are preferable to granting autonomous AI agents independent legal personality. Governance And Regulation | positive | Preferred regulatory and liability-reform approach for autonomous AI-agent transactions |
Reading fidelity
high
Study strength
low
|
n=3
|