An AI purchasing workflow should separate recommendation, approval and execution. Define the legal entity, authorised users, transaction limits, permitted suppliers and actions requiring human approval. Internal limits must be supported by technical controls and appropriate external arrangements; an internal policy alone may not resolve a dispute about an agent's apparent authority.
The business situation
An agent compares suppliers and accepts a discounted annual subscription. Procurement expected a recommendation, but the workflow used a stored account with purchasing privileges. The supplier sees an accepted order; the business sees an unapproved experiment.
AI governance starts with a use case and a responsible legal entity. A model is not itself a Data Fiduciary. The organisation determining the purpose and means of personal-data processing may be one. Contract, intellectual-property, consumer, employment and sector rules can apply alongside data-protection law; the relevant obligations depend on the deployment.
What needs examining
01. Translate delegated authority into permitted actions
List the actions the agent can perform, including apparently minor steps such as clicking acceptance boxes, renewing subscriptions or agreeing amendments. Separate spend limits from legal-risk limits. A low-value order may contain an unusual indemnity, data licence or foreign jurisdiction clause. The approval matrix should reflect both the commercial exposure and the legal commitment.
02. Put the approval boundary in the system
Require approval before the external action, not merely notification afterwards. Restrict credentials, destinations and tools; capture the exact terms and version reviewed. A model instruction to ask permission is a weak control if the execution tool still accepts an unapproved command. Test failure cases such as retries, duplicated orders and stale approvals.
03. Plan for a disputed commitment
Retain the user instruction, proposed transaction, approval and execution receipt in an intelligible record. Determine who can suspend access, contact the supplier and assess ratification or challenge if something goes wrong. Questions of authority and contractual formation remain fact-specific; describing the system as autonomous does not settle liability.
Law, contract and recommended practice
Applicable Indian statutes and sector directions are mandatory where their scope is met. NIST AI RMF is a voluntary governance framework, unless particular commitments become binding through a contract or another applicable requirement. Its GOVERN, MAP, MEASURE and MANAGE functions can organise evidence without creating a new Indian legal obligation.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Law, where applicable Establish contractual authority and formation | Review entity, delegated powers and external terms | Authority record and accepted terms |
| Recommended practice Prevent unauthorised execution | Approval gate and least-privilege tool access | Approval token and execution log |
| Contractual control Manage supplier-side assumptions | Document accepted ordering channels and limits | Supplier acknowledgement and order trail |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Can a prompt create a legally reliable approval process?
A prompt can describe the process, but technical enforcement and an auditable decision record are also needed. A prompt does not replace the applicable rules on authority, contract formation or internal approvals.
Should every agent action require human approval?
The appropriate boundary depends on the action and exposure. Low-risk preparation can often be automated. Commitments, sensitive disclosures and material changes should be assessed separately and assigned explicit approval rules.
Start with one proposed purchasing workflow. Mark the precise point where preparation becomes an external commitment, and put the authority check immediately before it.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- NIST AI Risk Management FrameworkNational Institute of Standards and Technology · Voluntary governance framework. It does not, by itself, create an Indian statutory duty.
- Indian Contract Act, 1872Government of Uttar Pradesh · Commercial Tax Department · Government-hosted statutory reference. Read with applicable amendments, special law and judicial interpretation.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS ai governance practice