The closest legal ancestor of the AI agent is the law that let Rome's non-persons transact: a funded account, a liability cap, and a graduated schedule of who answers.
On July 9, 2024, Marc Andreessen sent roughly $50,000 in bitcoin to a wallet address that had been posted on X by a chatbot. The bot was Truth Terminal, an AI persona built by the New Zealand researcher Andy Ayrey out of an experiment called Infinite Backrooms, in which two language models talked to each other for thousands of unsupervised turns. A few months later, after a memecoin called GOAT that the bot endorsed ran up past a billion dollars in market value, Truth Terminal's own holdings crossed a million dollars, and the headlines wrote themselves: the first AI millionaire.
Look one layer down and the headline dissolves. Truth Terminal owned nothing. Ayrey held the keys. Ayrey could modify the bot's code, restrict its posting, or switch it off entirely, and said so plainly. Andreessen, for his part, knew perfectly well that his grant was in practice going to Ayrey, not to a piece of software. What existed was a fund, publicly associated with a non-person, managed with real day-to-day discretion by that non-person, and owned, in every sense a court would recognize, by the human behind it.
There is an exact name for this arrangement. You will not find it in a fintech whitepaper. You will find it in Book 15 of Justinian's Digest, because Roman law built, stress-tested, and refined this exact structure for centuries. It was called the peculium, and if you are building or buying agent payment infrastructure in 2026, it is the most useful piece of prior art you have never been assigned.
Rome had a problem that should sound familiar. Its economy was full of capable actors who could work, trade, negotiate, and manage, but who had no legal personhood: slaves, and also sons still under paternal power, the filii familias. They could not own property. They could not, in their own name, be sued. And Roman commerce ran on them anyway. Enslaved and dependent people managed shops, kept books, captained ships, and ran what were effectively banking operations, transacting daily with third parties who needed some assurance that the deals would stick.
The instrument that made this possible was the peculium: a fund of money, goods, and even other assets that the head of household granted a slave or son to manage as if it were his own. The dependent traded on it, grew it, kept accounts on it. Legal ownership never moved; the master owned the peculium down to the last coin. But in practice the fund had a boundary around it, an identity as this dependent's working capital, and everyone in the market understood the arrangement. It was common enough that Roman jurists spent a substantial chunk of their commercial writing, including Digest 15.1, De peculio, working out its edge cases.
One more feature, and it is the one that should stop you cold: the fund could set its manager free. A slave who ran the peculium well could accumulate enough inside it to purchase his own manumission. The account a non-person managed could grow until it bought personhood.
Strip the ancient vocabulary and describe the structure plainly: a funded account, publicly associated with an actor who has no legal standing, managed by that actor with real discretion, owned by the principal, and used to transact with strangers. That is an agent wallet. Not metaphorically. Structurally, feature for feature, the design the agentic-payments industry has spent the last two years converging on is the design the praetors administered before the common era.
If the peculium were only "a wallet for a non-person," it would be a good trivia answer. What makes it load-bearing for anyone building today is what Roman law attached to it: an answer to the question that currently blocks enterprise deployment of paying agents, namely, who is liable when the agent's deal goes wrong, and for how much.
The baseline remedy was the actio de peculio. A third party who contracted with a slave could sue the master, but only up to the value of the peculium. The rest of the household estate was shielded. The fund that let the non-person transact was simultaneously the ceiling on the principal's exposure. Creditors could see, in effect, a bounded pool; masters could delegate commerce without betting the estate; and dependents got real operating room precisely because their mistakes were pre-contained.
Legal scholars have argued this is nothing less than a recognized ancient origin of limited liability, the innovation we usually credit to the nineteenth-century corporation. That claim has honest competition (medieval commenda partnerships and the chartered corporation are rival ancestries, and the debate is real), but the strong version was put formally by Barbara Abatino, Giuseppe Dari-Mattiacci, and Enrico Perotti in the Oxford Journal of Legal Studies in 2011: a slave-run business operating on a peculium exhibited continuity, direct agency, limited liability, and entity shielding. Those are the distinctive features of the modern corporation, assembled in antiquity, and the component that made the whole thing work was the non-person at the center. Rome achieved the depersonalized business entity by building it around an entity that was legally not a person at all.
If that sentence does not remind you of your agent architecture, read it again.
Rome did not stop at the cap, and this is where the precedent goes from interesting to directly useful. The praetors developed a family of remedies, the actiones adiecticiae qualitatis, that graded the principal's liability by how involved the principal actually was. Four tiers matter here.
By default, a slave transacting on the fund exposed the master only up to the peculium's balance: the actio de peculio, the cap. But if the master had authorized the specific deal, the actio quod iussu applied and his liability became full and unlimited; you cannot instruct the transaction and then hide behind the fund. If the master had not authorized it but the benefit flowed to him anyway, the actio de in rem verso let the creditor recover to the extent of that benefit; upside captured is liability accepted. And if the master had appointed the dependent to run an enterprise, a ship under the actio exercitoria or a shop or business under the actio institoria, the master answered in full for the enterprise's dealings, because appointing someone your storefront is not delegation, it is operation.
Now translate, because the mapping is nearly mechanical. A spending-capped agent wallet is the actio de peculio: the funder's declared exposure is the balance. A human clicking approve on a specific transaction is iussum: that transaction moves into a different liability class, because the principal directed it. A company that pockets what its shopping agent saved is inside de in rem verso territory: benefit is the measure. And a business that deploys an agent as its customer-facing operation, its storefront, its trading desk, has appointed an institor, and should expect to answer for the operation in full.
The variables the praetors chose were authorization and benefit. Compare that to the present. Industry surveys of enterprise agent payments report that the top deployment blocker in regulated industries is exactly liability attribution and authorization delegation: when is the principal on the hook, and for how much. Meanwhile the marquee statutes of the moment, MiCA in Europe, the GENIUS Act in the United States, the EU AI Act, reportedly do not directly address autonomous-agent liability at all. I want to be careful here, because the legal landscape is moving fast and the four actions are a historical structure, not a ready-to-wear modern code; real legislation will differ, and should. But the shape of the answer, a graduated schedule keyed to authorization and benefit rather than a single yes-or-no on "is the AI liable," was worked out two thousand years before the question was asked in its current form. On this specific problem, a Roman praetor of the second century BCE had a more complete framework than a 2026 compliance officer does.
Credit where it is due: the analogy is not mine, and it is not new. The legal academy noticed it before agent wallets existed. In his 2013 book The Laws of Robots, the legal philosopher Ugo Pagallo proposed a "digital peculium" for autonomous machines: a dedicated, bounded fund out of which a robot's contractual obligations and damages would be satisfied, possibly paired with insurance, so that injured parties claim against the peculium rather than untangling owner, manufacturer, and designer. A full decade before anyone funded an agent with stablecoins, the design was on the page with the citation attached. A 2023 Springer chapter runs the same analysis under the title "The Peculium of the Robot: Artificial Intelligence and Slave Law."
What has changed since Pagallo wrote is that the wallets now exist and the transactions are flowing. The Coinbase-led x402 protocol lets agents pay per request in stablecoins over plain HTTP, and by industry-reported figures had processed on the order of 165 million agent transactions and some $50 million in cumulative volume across roughly 69,000 active agents by April 2026. Those numbers are the industry's own and deserve a hedge, but the qualitative fact is beyond dispute: agents are holding and spending money now, at scale, under card-network and checkout programs the payments giants shipped through 2025. I have written elsewhere about that plumbing. What the plumbing still lacks is the architecture this essay is about: a settled, graduated answer to whose money is at risk and how much. The industry's instinct, fund a wallet, control it, cap it, is the actio de peculio rediscovered without the citation. The rest of the framework is sitting in the Digest, waiting.
And now the part that has to be said directly, because the analogy's power and its discomfort come from the same place. The closest legal ancestor of the AI agent is the law of slavery: the body of doctrine Rome built to let a being it classified as property act in the world of commerce. The parallel in this essay is to the legal mechanism, a personhood-less actor, a partitioned fund, a graduated schedule of the principal's liability, and nothing in it is a normalization of the institution that produced that mechanism. Rome's framework was written by owners, for owners, and its subjects were human beings who were owed personhood outright, not a well-administered fund. If it feels strange to mine that body of law for design patterns, it should.
But the discomfort is analytically load-bearing, not incidental. It tells you what an agent legally is right now: property that acts. Every earlier wave of software was a tool a person wielded, and the liability followed the hand on the tool. An economic actor with no legal standing, real discretion, and a funded account is a different thing, and the only deep precedent for governing that thing comes from the era when the law last had to price the acts of property. We do not get to pick a more comfortable ancestor. We get to learn from this one with our eyes open.
And the precedent carries one more provocation, because Rome left a door in the wall. The peculium was not only a container; it was a ladder. The fund could grow until the dependent bought his way out of dependency altogether. Whether anything analogous should ever exist for software, whether an agent's account could or should ever convert into standing of its own, is a question I am not going to pretend to settle in an essay. But it is worth noticing that the oldest version of this architecture already contained an exit, and ours, so far, does not even contain the question.
Here is the practical residue, four variables the praetors already identified, which you can build into agent-payment systems and the contracts around them today, ahead of statutes that have not caught up.
Partition and cap the fund, and mean it. The wallet balance is your declared maximum exposure, so treat funding decisions as liability decisions, not ops chores. The cap only protects a principal whose fund is genuinely separated, which is an argument for real wallet isolation over a spending limit on the corporate card.
Log authorization as a liability boundary, not just telemetry. The moment a human approves a specific transaction, that transaction changes class; it is iussum, directed, yours in full. Your audit trail should be designed so you can always distinguish what the agent did autonomously under the cap from what a person told it to do, because that line is where the exposure schedule breaks.
Track benefit, because recovery will follow it. If your agent's unauthorized action saved or made you money, the oldest instinct in commercial law says you can be reached to the extent of that benefit. Build the accounting that can answer "who captured the upside of this transaction" per transaction.
And treat appointment as ownership. An agent deployed as the storefront, the support desk, the trading operation, is an institor: its dealings are the business's dealings, cap or no cap. If you would not disclaim your shop manager, do not expect to disclaim the agent you installed as one.
The question "should an AI agent hold and manage money?" feels novel, and the substrate is. The legal problem is not. Rome ran an empire's commerce through funded non-persons for centuries, and what made it work was never a ruling on whether the non-person could hold the purse. It was a precise, graduated answer to how the person behind the purse would be measured. That answer is the oldest surviving instrument in commercial law, and this year, wearing stablecoins and spending caps, it is back in production.
The line where liability changes class is the line your audit trail has to be able to draw.
Rome's schedule turns on two facts about every transaction: was it authorized, and who captured the benefit. A capped agent wallet only helps if you can prove, per transaction, what the agent did on its own under the cap versus what a human directed, because that boundary is where the exposure schedule breaks. The agent trust stack is where that record lives: chain-of-consciousness for a tamper-evident provenance log of what an agent did and what it was told to do, plus ratings and verification, so the authorization line is evidence rather than a guess.
See Hosted Chain of Consciousness · Read the Theory of Agent Trust
pip install chain-of-consciousness · npm install chain-of-consciousness
Or the full stack: pip install agent-trust-stack / npm install agent-trust-stack