Whitepapers

Long-form papers from LexLint on what current law asks of agentic software, written for the people who maintain it.

  1. Paper 1 · · Sean McDermott, Co-Founder and CEO, UnGovr

    Whose law was that?

    Agents are not yet built to follow the law they act under

    Abstract. When an AI agent causes an incident, reporting deadlines start in every jurisdiction whose systems or people it touched, and the shortest are counted in hours. Which deadlines run, and for whom, depends on two facts: who the parties to the task were, and which jurisdiction each party was in. The gateways, frameworks and logs that agents run through record the connection, not the parties or their jurisdictions. Logging more does not fix that, because what may be kept is itself set jurisdiction by jurisdiction. This paper sets out that gap, works one invented incident through it, and lists what each kind of maintainer would change.

    Read paper 1

  2. Paper 2 · · Sean McDermott, Co-Founder and CEO, UnGovr

    Declared, checked, held

    An agent's legal exposure, from the first line of code to production

    Abstract. No law requires an organisation to limit where its software operates. Many limit it anyway, for the reason companies decline to sell in some countries: a narrower legal exposure is one that counsel can read, verify and enforce. This paper describes that practice for agentic software. An organisation declares what an agent does and in which jurisdictions, has the declaration checked against the law, records a decision on each finding, and holds the software to the declaration while it is written, in continuous integration and in production. One sample application is followed throughout.

    Read paper 2