November 2025. The Reserve Bank of India publishes updated guidance on algorithmic trading systems. The circular is narrow: risk controls, audit trail requirements, kill switches for automated systems executing trades. Nobody calls it an “agent regulation.” It is not. But read the requirements list — unique system identification, tamper-resistant logs, a designated human accountable for every automated action — and you are reading the draft of every agent-accountability law that will exist by 2029.
The first real agent law will not come from an AI regulator. It will come from a finance regulator. And it will look like an RBI circular, not an AI act.
PRED-015 — By December 2029, at least three major economies — from the US, EU, India, UK, China, Japan, Australia, Canada — will enact legislation specifically addressing autonomous AI agents. Requirements will include: agent identity (unique, traceable), audit trails (tamper-resistant logs), and accountability assignment (a human or legal entity legally liable for every agent’s actions).
Confidence: 4 out of 5.
The chapter uses historical pacing. Drones went from consumer availability to FAA regulation in one year. Ride-sharing went from mass adoption to city and state regulation in two to three years. Cryptocurrency took five to six years from mass awareness to the EU’s MiCA regulation. Autonomous agents are higher-risk than all three — they take real-world actions with financial, safety, and legal consequences. Mass adoption is 2025–2027. Regulation follows in 2028–2029.
The regulatory infrastructure is forming. The EU AI Act classifies high-risk AI systems and includes delegated-act mechanisms for adding agent-specific provisions without new legislation. The US Executive Order on AI and NIST frameworks signal regulatory intent. India’s Digital Personal Data Protection Act establishes a framework that will need agent-specific extensions. India’s sector regulators — RBI for financial services, SEBI for markets — are already scrutinising algorithmic systems.
What the chapter does not say — and what this issue argues — is where the first enforceable law actually comes from. The conventional assumption is that it comes from an AI-specific body: the EU AI Office, or a new US agency, or India’s proposed Digital India Act. I think that assumption is wrong.
The first enforceable agent law will come from a finance regulator. Three reasons.
Statutory authority already exists. The RBI, the SEC, SEBI, and the FCA already have the legal authority to regulate automated systems acting in financial markets. They do not need new legislation. They need a circular, a guidance update, or a rule amendment. The EU AI Office needs a delegated act. The US needs a congressional vote or an executive order with uncertain legal standing. Finance regulators can move in months. AI regulators need years.
The audit-trail infrastructure already exists. Financial regulators have spent decades building audit-trail requirements for automated trading, payment processing, and risk management. The infrastructure for tamper-resistant logs, unique system identification, and human accountability assignment is not new for finance. It is an extension of what already exists. For a tech regulator starting from scratch, every requirement is a design problem. For a finance regulator, it is a parameter update.
The political cover already exists. An agent moves money. An agent executes a trade. An agent processes a payment. When that agent makes an error — and it will — the political pressure to regulate lands on the finance regulator’s desk, not the AI regulator’s desk. The finance regulator has constituents who lost money. The AI regulator has a whitepaper. Political pressure creates regulatory velocity. Whitepapers do not.
The RBI’s 2025 algorithmic trading guidance is the template. Read the three requirements: unique identification, tamper-resistant logs, human accountability. Now replace “algorithmic trading system” with “autonomous AI agent.” The extension is obvious. The RBI or the SEC will make it before any AI-specific body publishes its first binding rule.
This is the jurisdictional arbitrage that matters for builders. The first agent law will not arrive as a grand AI Act debated for three years. It will arrive as an amendment to an existing financial regulation, published on a Tuesday, effective in 90 days. If you are building agents that touch financial transactions, the 2027 conversation is with the RBI or the SEC — not with an AI policy office that does not yet exist.
The published falsification trigger:
If by December 2029, fewer than two major economies enact agent-specific legislation — not just general AI regulation that happens to cover agents — this prediction is wrong.
The realistic failure mode is jurisdictional paralysis. If the finance regulators defer to the AI regulators, and the AI regulators defer to the legislature, and the legislature defers to the next election cycle, the three-economy threshold is not met by 2029. The direction is clear. Whether three jurisdictions act within the window, rather than starting the process within the window, is the genuine uncertainty. Regulation that is proposed but not enacted does not count.
If you work inside a finance or securities regulator — or in the compliance function of a financial institution — I want to know one thing: does your institution have a 2026–2027 working group, task force, or consultation paper on autonomous agent action in regulated transactions? Yes or no. Anonymised. Named institution optional.
I will publish a cumulative count on the public PRED-015 tracking page at atin-agarwal.com/predictions/pred-015-agent-accountability-legislation/, updated as responses come in. The count itself is a leading indicator. If multiple regulators have active working groups by Q2 2027, the finance-regulator-first thesis is on track. If none do, the timeline pushes right.
If you are a fintech founder deploying agents: your agent deployment has a 2027 RBI or SEC conversation coming. Not a 2029 AI-act conversation. Build the audit trail now. Agent identity, tamper-resistant logs, human accountability assignment — these are not optional features for post-launch compliance. They are launch requirements for any agent touching regulated transactions.
If you are in legal or compliance: your 2026 watch-list is finance regulator circulars, not AI-act delegated acts. The RBI, the SEC, SEBI, the FCA — monitor their consultation papers and guidance updates. The agent-specific provisions will arrive as amendments to existing frameworks, not as headline legislation.
If you are an investor: jurisdictional arbitrage is real, but the window is 18 months, not five years. The startups that build compliant agent infrastructure before the regulation arrives have a distribution advantage over those that scramble to retrofit after. The compliance-first agent company is the defensible bet.
This issue is drawn from Chapter 9 of The AI Agent Economy — 15 falsifiable predictions with dates, numbers, and explicit triggers for being proven wrong. Read it on Kindle — $9.99. atin-agarwal.com/books
Read the full PRED-015 entry on the public tracking page → atin-agarwal.com/predictions/pred-015-agent-accountability-legislation/
Previous issue: Issue 14 — The first 18 months of being displaced — and what the dharma lens says the deploying company owes → SUBSTACK-014 Next issue: Annual verification post, first issue Jan 2027 (subscribe to stay on the list).
This is the fifteenth and final issue in this series. Over fifteen weeks, I have published fifteen falsifiable predictions — each with a date, a number, and an explicit trigger for being proven wrong.
To everyone who replied with data, counter-cases, and challenges: thank you. Your numbers made these predictions sharper. Several of you submitted evidence that made me less confident in specific claims. That is exactly what this project is for.
The predictions are now public. The annual verification post begins in January 2027. Every prediction will be assessed against its measurable criteria — on the same platforms where these issues were published, with the same specificity as the original claims. The first four predictions (PRED-002, PRED-005, PRED-007, PRED-013) become checkable in 2028. The first full scorecard review publishes in January 2029.
If a prediction is wrong, the review will say so. Willingness to be specifically, publicly wrong is the rarest quality in technology prediction. That is the bet this series made.
Hold me accountable. I will be back in January 2027 with the first annual review.
— Atin

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.