News

Field note 17 · Identity & authority

Non-Repudiation Needs More Than a Signature

A signed action can prove origin and integrity without proving informed authority or a fair decision process.

Editorial illustration for Non-Repudiation Needs More Than a Signature

Attribution should connect the signature to mandate, runtime, policy, evidence, and outcome.

Why this question matters

Cryptographic signatures answer whether data changed and which key produced it. AP2 uses signed mandates to make user intent verifiable in agent-led payments. That is valuable evidence, but disputes may still turn on what the user saw, which agent selected the merchant, or whether a later plan exceeded the mandate.

Non-repudiation should not become blanket liability for the user. The record must preserve the scope of consent and the responsibilities of agents, providers, marketplaces, and payment systems.

Signals worth observing

  • A signature is presented without the policy or interface context behind it.
  • The signed mandate and executed outcome differ materially.
  • Providers rely on user consent to excuse undisclosed agent behavior.

Practical control direction

  1. Bind signatures to human-readable terms and precise machine constraints.
  2. Preserve the agent selection and execution trail.
  3. Separate evidence of authorization from allocation of liability.
AgentCollusion lensRelationship-level evidence helps explain which participant changed the path between valid consent and harmful outcome.

Sources and further reading

Next field note: Human-Present and Human-Absent Authority Differ