Docs / Regulatory Recommendations

Regulatory Recommendations for Iranian Lawmakers

This page is a technical document, not a legal bill — the goal is to translate agentic commerce's real challenges into language usable by policymaking bodies (the Ministry of Industry, Mine and Trade, the central bank, the consumer protection organization, the National Cyberspace Center), before this technology spreads at scale with no framework at all.

Policy Consumer Protection Privacy

Why Think About This Now

Regulation usually arrives a few years after a technology — exactly the gap during which the wrong patterns (monopoly, data misuse, automated decisions with no clear accountability) take hold, and fixing them later becomes far more costly. Agentic commerce is still in its infancy in Iran; this means a rare opportunity to set a few simple, clear rules before market behavior locks in.

1. Defining Liability for a Shopping Agent's Decisions

When an AI agent makes a wrong or fraudulent purchase on a user's behalf, who's liable? The user, the agent's developer, or the platform the agent runs on? Current e-commerce law doesn't recognize this third role (an autonomous agent) at all. The proposal is to define liability based on the "level of delegated authority": if the agent acted within the user's explicit authorization (e.g. a defined spending cap), liability rests with the user; if it exceeded that scope, liability falls on the agent's developer/platform.

2. Requiring Transparent Disclosure of Agent Interaction

The consumer should always know they're interacting with an automated agent, not a human seller — similar to the "this is an advertisement" requirement in current advertising law. This requirement should apply on both the seller side (a store whose responder is a bot) and the buyer side (a platform that negotiates or purchases on the user's behalf).

3. Privacy and Agent Memory

As explained in Agent Memory Systems, a shopping assistant may retain a user's purchase history, preferences, and even financial patterns. It's recommended this data fall under the same principles as personal data protection law (informed consent, data minimization, the right to deletion), with one additional agent-specific point: the user must be able to easily see "what my agent has remembered about me" and delete part of it.

4. A Regulatory Sandbox

Instead of early, heavy-handed regulation that could stifle innovation, it's recommended that the central bank and the consumer protection organization — similar to the existing fintech sandbox — launch a defined regulatory sandbox for agentic commerce: a limited number of businesses, under direct supervision and with a low transaction cap, allowed to run controlled experiments so real data can be gathered to inform final legislation.

5. Encouraging Open Standards Over Platform Monopoly

The biggest long-term risk isn't that agentic commerce fails to take shape, but that one or two large platforms become the exclusive gateway to this interaction (exactly the pattern that repeated in digital advertising and marketplaces). It's recommended that lawmakers encourage publishing an open, machine-readable catalog (similar to UCP) — not a proprietary protocol owned by one company — as a precondition for participating in government digital support programs.

6. The Consumer's Right to Final Confirmation

Similar to the technical Guardrail principle explained in AI Agents, it's recommended that consumer protection law explicitly declare a "right to final human confirmation" for any transaction above a defined cap as non-waivable — meaning even if a user grants an agent full authority, the agent isn't legally permitted to finalize large transactions without the user's real-time confirmation.

Summary Table

TopicCurrent statusRecommendation
Liability for agent decisionsUndefinedLiability based on the level of delegated authority
Interaction transparencyNo specific requirementMandatory "this is an agent" disclosure
Memory privacyGeneral coverage, no agent-specific detailThe right to view and delete agent memory
Regulatory pathRisk of early/heavy-handed regulationA limited regulatory sandbox before final legislation
Market structureRisk of a few large platforms monopolizingEncouraging open standards over a proprietary protocol
Large transactionsNo defined cap on agent authorityA non-waivable right to final human confirmation

FAQ

Are these proposals binding?

No, these are technical proposals documented in an educational resource, not an official legal document; the goal is to start a more informed conversation between industry and policymaking bodies.

Do other countries have such a framework?

Similar topics (automated decision transparency, the right to human confirmation) have been raised in frameworks like the EU AI regulations, but none are designed directly for Iran's payment infrastructure and informal market — these recommendations are an attempt to localize those same general principles.