Regulatory Recommendations for Iranian Lawmakers
This page is a technical document, not a legal bill — the goal is to translate agentic commerce's real challenges into language usable by policymaking bodies (the Ministry of Industry, Mine and Trade, the central bank, the consumer protection organization, the National Cyberspace Center), before this technology spreads at scale with no framework at all.
Why Think About This Now
Regulation usually arrives a few years after a technology — exactly the gap during which the wrong patterns (monopoly, data misuse, automated decisions with no clear accountability) take hold, and fixing them later becomes far more costly. Agentic commerce is still in its infancy in Iran; this means a rare opportunity to set a few simple, clear rules before market behavior locks in.
1. Defining Liability for a Shopping Agent's Decisions
When an AI agent makes a wrong or fraudulent purchase on a user's behalf, who's liable? The user, the agent's developer, or the platform the agent runs on? Current e-commerce law doesn't recognize this third role (an autonomous agent) at all. The proposal is to define liability based on the "level of delegated authority": if the agent acted within the user's explicit authorization (e.g. a defined spending cap), liability rests with the user; if it exceeded that scope, liability falls on the agent's developer/platform.
2. Requiring Transparent Disclosure of Agent Interaction
The consumer should always know they're interacting with an automated agent, not a human seller — similar to the "this is an advertisement" requirement in current advertising law. This requirement should apply on both the seller side (a store whose responder is a bot) and the buyer side (a platform that negotiates or purchases on the user's behalf).
3. Privacy and Agent Memory
As explained in Agent Memory Systems, a shopping assistant may retain a user's purchase history, preferences, and even financial patterns. It's recommended this data fall under the same principles as personal data protection law (informed consent, data minimization, the right to deletion), with one additional agent-specific point: the user must be able to easily see "what my agent has remembered about me" and delete part of it.
4. A Regulatory Sandbox
Instead of early, heavy-handed regulation that could stifle innovation, it's recommended that the central bank and the consumer protection organization — similar to the existing fintech sandbox — launch a defined regulatory sandbox for agentic commerce: a limited number of businesses, under direct supervision and with a low transaction cap, allowed to run controlled experiments so real data can be gathered to inform final legislation.
5. Encouraging Open Standards Over Platform Monopoly
The biggest long-term risk isn't that agentic commerce fails to take shape, but that one or two large platforms become the exclusive gateway to this interaction (exactly the pattern that repeated in digital advertising and marketplaces). It's recommended that lawmakers encourage publishing an open, machine-readable catalog (similar to UCP) — not a proprietary protocol owned by one company — as a precondition for participating in government digital support programs.
6. The Consumer's Right to Final Confirmation
Similar to the technical Guardrail principle explained in AI Agents, it's recommended that consumer protection law explicitly declare a "right to final human confirmation" for any transaction above a defined cap as non-waivable — meaning even if a user grants an agent full authority, the agent isn't legally permitted to finalize large transactions without the user's real-time confirmation.
Summary Table
| Topic | Current status | Recommendation |
|---|---|---|
| Liability for agent decisions | Undefined | Liability based on the level of delegated authority |
| Interaction transparency | No specific requirement | Mandatory "this is an agent" disclosure |
| Memory privacy | General coverage, no agent-specific detail | The right to view and delete agent memory |
| Regulatory path | Risk of early/heavy-handed regulation | A limited regulatory sandbox before final legislation |
| Market structure | Risk of a few large platforms monopolizing | Encouraging open standards over a proprietary protocol |
| Large transactions | No defined cap on agent authority | A non-waivable right to final human confirmation |
FAQ
Are these proposals binding?
No, these are technical proposals documented in an educational resource, not an official legal document; the goal is to start a more informed conversation between industry and policymaking bodies.
Do other countries have such a framework?
Similar topics (automated decision transparency, the right to human confirmation) have been raised in frameworks like the EU AI regulations, but none are designed directly for Iran's payment infrastructure and informal market — these recommendations are an attempt to localize those same general principles.