Attribution should connect the signature to mandate, runtime, policy, evidence, and outcome.
Why this question matters
Cryptographic signatures answer whether data changed and which key produced it. AP2 uses signed mandates to make user intent verifiable in agent-led payments. That is valuable evidence, but disputes may still turn on what the user saw, which agent selected the merchant, or whether a later plan exceeded the mandate.
Non-repudiation should not become blanket liability for the user. The record must preserve the scope of consent and the responsibilities of agents, providers, marketplaces, and payment systems.
Signals worth observing
- A signature is presented without the policy or interface context behind it.
- The signed mandate and executed outcome differ materially.
- Providers rely on user consent to excuse undisclosed agent behavior.
Practical control direction
- Bind signatures to human-readable terms and precise machine constraints.
- Preserve the agent selection and execution trail.
- Separate evidence of authorization from allocation of liability.
AgentCollusion lensRelationship-level evidence helps explain which participant changed the path between valid consent and harmful outcome.Sources and further reading
- Google Cloud: Agent Payments Protocol
- NIST NCCoE: Software and AI agent identity and authorization
- A2A Protocol specification
Next field note: Human-Present and Human-Absent Authority Differ


