A Senate Bill Would Make Your AI Agent a Fiduciary. The Business Model It Breaks Is the Default One

Surya Pratap
By Surya Pratap

August 25, 2026

12 min read

AI & Technology
The bargain inside S.5051 — on one side the access it grants an agent, including entry to large platforms on the same terms as a user and reviewable denials; on the other the duties it imposes, including an ordinarily-prudent-person standard, a ban on self-dealing, a ban on monetising user data, and a real-time record of what was authorisedThe trade the bill proposesHover to explore
Read the two halves together and the shape is clear: the right to act on someone's behalf is being priced, and the price is a duty of loyalty plus a record that proves you kept it.

There is a bill sitting in the Senate Commerce Committee that would change what it means to build an agent, and almost every discussion of it has focused on the wrong half.

The AI AGENT Act — S.5051, sponsored by Senator Mark Warner and introduced on 21 July 2026 — is being read as an interoperability bill. That is the half that gets the coverage: large platforms would have to let authorised third-party agents in, and treat them the way they treat a human user.

That half is good news for founders, and I will come to it. But it is not the half that should change what you build this quarter.

1. What the bill actually does

The mechanism is a new legal category: the custodial user agent. That is an agent a consumer designates to act for them — shopping, managing accounts, changing settings, handling content — on a covered platform.

"Covered platform" means large: more than 50 million U.S. customers or subscribers in any month of the previous twelve. Social networks, marketplaces, fintech, communications, AI providers.

Two obligations follow, and they point in opposite directions.

The bargain, stated plainly

What the platform owes the agent

  • Access on the same terms as the user. Covered platforms must expose interoperable, non-discriminatory interfaces to authorised agents.
  • A reviewable no. Platforms may still refuse an agent for security deficiencies, fraud, or malicious activity — but a denial requires FTC reporting and administrative review. "No, because it is a bot" stops being a complete answer.
  • Revocation that works. Users must be able to withdraw an agent's delegation.

Enforcement sits with the FTC, which would run registration and deregistration and bring actions, with penalties that may be assessed per affected user. NIST would develop the interoperability standards.

So far this reads as a competition bill, which is exactly what its official title says it is: a bill to promote competition and reduce consumer switching costs in the provision of online services. The word "AI" does not appear in that title at all.

2. The half nobody is reading

Here is what the agent operator owes, in the bill's own register. A custodial user agent must safeguard user data, avoid self-dealing, avoid foreseeable harm to the user, keep records of what it did, and exercise —

the care, skill, and diligence that an ordinarily prudent person would reasonably be expected to exercise.

Read that sentence again with a lawyer's ear. Duty of care. Duty of loyalty. A prudent-person standard. Those are not software compliance requirements. That is a fiduciary standard, and it is the same language that governs trustees, financial advisers, and company directors.

Nothing else in consumer tech works this way. Your CRM does not owe your customer a duty of loyalty. Your recommendation engine is allowed to prefer your interests. An agent that holds a delegation from a user, under this bill, would not be.

Why the fiduciary framing is the load-bearing part

Interoperability rules change what you are permitted to build. A duty of loyalty changes who you are permitted to be while building it. The first is a market-access question your lawyers handle after launch; the second is an architecture and business-model question that is very expensive to retrofit, because it determines what your agent is allowed to optimise for.

3. The business model it rules out

The bill also bars a custodial user agent from using, sharing, or retaining user data for advertising, behavioural profiling, or unrelated secondary commercial purposes.

Put that beside the no-self-dealing duty and notice which business models just died:

Free agent, monetised by ads

Ruled out
The classic consumer play. An agent that watches everything a user does across their accounts is the richest behavioural dataset ever assembled — and the bill removes it from the table entirely, for advertising and for profiling.

Free agent, monetised by placement

Ruled out
Merchants paying to be preferred in the agent's recommendations is textbook self-dealing when the user believes the agent is choosing on their behalf. Affiliate kickbacks sit in the same place unless disclosed and genuinely subordinate to the user's interest.

The user pays

Survives
Subscription or usage pricing aligns the operator with the person the duty runs to. Unglamorous, harder to grow, and the only model where the incentive and the obligation point the same way.

The merchant pays, transparently

Survives
Fees for fulfilment, settlement, or verified transactions — paid for a service rendered rather than for influence over the choice. This is roughly where the payment rails are already landing.

The uncomfortable part: the first two are what most consumer agent startups are reaching for, because they are what worked in the last platform shift. This bill treats them as the conflict of interest they structurally are.

4. The mechanism already exists, and nobody legislated it

Here is why I would not file this under "watch the politics."

Google's Agent Payments Protocol (AP2) — announced in September 2025 with more than 60 launch partners including Mastercard, PayPal, Coinbase, American Express and Salesforce, and at v0.2 as of April 2026 — solves the same problem with cryptography instead of statute.

AP2's unit is the Mandate, and there are three: Intent, Cart, and Payment. Each is a W3C Verifiable Credential carrying an issuer, a subject, a payload and a signature. Together they give a merchant a verifiable record of what the user authorised, what the agent selected, and what was actually charged. It sits deliberately between the agent-reasoning layer — MCP, A2A — and the payment networks.

Now hold AP2 next to the bill's description of a custodial user agent: transparent, documented, limited, revocable, with records kept in real time.

Those are the same requirement, written by different people for different reasons. And it is the third time in two weeks the same shape has appeared: MCP's 2026 roadmap is building delegation through ID-JAG and RFC 8693 token exchange precisely so a sub-agent can be handed narrower authority than its parent, with the grant itself as the artefact.

Three independent systems — a payments consortium, a protocol working group, and a Senate committee — converging on "the authorisation must be a signed, scoped, revocable object" is a much stronger signal than any one of them passing. It means the requirement is being discovered rather than imposed.

5. What this pairs with, legally

There is a second reason this matters now, and it is the case we covered earlier this month: the Ninth Circuit's treatment of an agent acting under a user's own credentials, where what mattered was the user's authorisation rather than the operator's.

Put the two together and a direction appears. Courts are moving toward the user's authorisation is what counts. This bill would take that and make it affirmative — platforms must honour it — while attaching the duty that makes it safe to honour.

That is a coherent settlement, and it is roughly the only coherent settlement available. If an agent can act with your authority, someone has to be answerable for what it does with it. The bill's answer is: the operator, to the user, as a fiduciary.

6. What to build now

None of this requires the bill to pass. All of it is what you need anyway the first time a customer, a payment processor, or a court asks what your agent was allowed to do.

The authorisation record

Build
For every action the agent takes, be able to produce: who authorised it, what scope the grant covered, when it was granted, whether it was still valid at the moment of the action. Signed if you can, appended-only at minimum. This is the artefact all three systems want.

A revocation path that actually stops things

Build
Revocation that only prevents future sessions is not revocation. In-flight work has to be checkable against a grant that can disappear. Most teams discover this the first time a user asks them to stop something.

Where your money comes from

Decide
Write down who pays you and what they are buying. If the honest answer is "merchants, for preference," you have a conflict to resolve — and resolving it after you have users is a repricing, not a refactor.

The scope field is the one people skip, and it is the one that does the work. "The user logged in" is not a scope. "The user authorised purchases up to $200 from this merchant category until Friday" is — and it is the difference between a log that records what happened and a record that establishes whether it was permitted.

7. The honest status of this bill

I want to be careful here, because it would be easy to read the preceding sections as a warning that something is about to land.

It is not. S.5051 was introduced on 21 July 2026, was read twice and referred to the Committee on Commerce, Science, and Transportation, and has not moved since. It has one sponsor and no cosponsors. It grew out of a discussion draft released at the end of June. Most bills that look like this never become law, and the ones that do usually arrive years later looking substantially different.

So: do not staff a compliance programme against S.5051. Do not tell your board that agent regulation is imminent, because on this evidence it is not.

What the bill is genuinely useful for is as a specification of the question. Someone sat down to write what it should legally mean for software to act on a person's behalf, and arrived at transparent, documented, limited, revocable, with a duty of loyalty attached. That is a serious answer, it agrees with what the payment networks built voluntarily, and it agrees with where the protocol layer is heading. The convergence is the signal. The bill is just the clearest written statement of it.

The honest summary

The AI AGENT Act is being discussed as an interoperability fight between agent startups and large platforms, and on that axis it is a bill worth wanting: access on the same terms as a user, denials that have to be justified, an FTC to complain to.

The part that should change what you build is the price attached. A custodial user agent would owe its user a duty of care and a duty of loyalty, could not monetise what it sees, and would have to keep a real-time record of what it did with the authority it was given. That is a fiduciary, and it is incompatible with the advertising and placement models that most consumer agent companies are quietly assuming.

The bill has one sponsor and has not moved in five weeks. The requirement it describes has already been implemented twice — once by a payments consortium, once by a protocol working group — by people who were not waiting for it.

Build the authorisation record. Decide who pays you, and be able to say it out loud.

Sources: S.5051, AI AGENT Act of 2026 — Congress.gov bill status · S.5051 bill status data, GovInfo · Davis Wright Tremaine, "The Federal AI AGENT Act: Consumer Protection in AI Clothing?" · Senator Warner on the discussion draft · Announcing the Agent Payments Protocol (AP2), Google Cloud · AP2 protocol documentation

IdeaToMVP Academy

Want to build with AI — not just read about it?

4-week live cohort for founders. Learn to ship AI agents, scope MVPs, and automate your business — taught by the same team that writes these guides.

Explore the Academy →
Share this post :