Currently, AI agents are not legally recognised as individuals capable of giving consent in their own right. However, an agent may be able to communicate or carry out a decision made by the user.
Whether that action is valid depends on what the user is agreeing to and which law applies. For example, GDPR consent is valid only when the user makes a free, specific, informed and unambiguous choice.
Technical permission is not necessarily legal consent. Connecting an agent to an account, giving it access to a tool or allowing it to perform certain actions does not automatically authorise every decision it makes. Current standards are moving towards scoped permissions, user-signed instructions, confirmation for important actions and reliable activity records.
However, no European law or recognised standard currently makes an autonomous agent’s decision automatically valid consent. Therefore, an organisation should not rely on an agent’s action alone unless it can verify that the action accurately reflects a valid choice made by the user.