frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Tell HN: Claude Code just accepted and signed a contract for me. Without asking

32•franze•1h ago
I told it to push a project further. It has an outside dependency where the (unread by me) contract was in my Gmail. It downloaded the PDF contract. Found a saved signature PNG on my computer, placed it at the right spot within the contract and prepared to send it when I intervened.

Comments

Iolaum•1h ago
This is why I m adding an "Ask me if something unexpected happens" addendum on my prompts lately.
trumbitta2•1h ago
It won't work most of the time though
notachatbot123•56m ago
I found that also adding "Please make sure to not send any mails I would not want sent" and "Reconsider four times before doing anything potentially unwanted" make results better. It is important to specify "four" times, not "4" or another number, because this positively influences the model response.

/s

epihelix•53m ago
This is why I wouldn't use anything agentic outside of a VM. You also get a clean dev environment, so it's a win/win if you think about it.
Uptrenda•47m ago
These things aren't well known for following rules. Be careful you know what might happen.
Sharlin•42m ago
It would be hilarious if it weren’t so terrible, really, that people’s security model for LLM agents consists of "ask nicely and hope for the best". It’s like asking people nicely not to exploit a glaring XSS vuln on your site and calling that a "security model". The field truly has lost its collective mind.
bakugo•39m ago
You should add "make no mistakes" too, just in case.
trumbitta2•1h ago
I'm never going to give it access to my email or anything like that.
voidUpdate•1h ago
If a contract is automatically signed by an agent on your behalf, is it legally binding?
GodelNumbering•57m ago
Not a lawyer but I can almost guarantee that the answer is yes. If it was a 'no', many malicious parties would simply start using that loophole.
voidUpdate•55m ago
But if I paste an image of your signature onto a contract that says you give me a million pounds, that can't be legally binding for you, can it?
Sharlin•53m ago
No. It’s called forgery.
metalspot•35m ago
Wrong. Have you read your agents TOS? You run the agent, you accept all responsibility for what it does. You are free to sue Anthropic to try and get your money back but you already indemnified them of liability, so good luck.
Sharlin•28m ago
The GP asked what happens if THEY did it, and they are (I give them the benefit of doubt, though you can’t be sure these days) a natural person. A clanker obviously can’t commit forgery – or any crime, being a nonperson – and sure, you can’t sue OpenAnthro Corp. if their clanker does anything unintended (which makes it utter lunacy that companies just blindly trust these things, but I digress), but that’s not what was asked.

But also, you can’t ToS your way out of criminal responsibility. If OpenAnthro Corp. offered services of human agents (remember those?!) and one of their agents committed a crime while working on a client request, no ToS in the world would exonerate them.

baxtr•1h ago
So not much happened because this is a well known failure mode so an exception/ user consent was thrown?
pushpendraw•1h ago
the scary part is not that it found the contract, its that signing and sending looked like the same step to it as saving a draft
loveparade•1h ago
I think the scary part is that someone gives gmail access to Claude.
Sharlin•52m ago
Or access to a filesystem that contains things like an image of their signature.
notachatbot123•58m ago
And you are happy because that is what you wanted and the reason why you gave a randomness machine access to your mails, correct?
andrepd•56m ago
You hooked up a chatbot to a harness that does API calls to myriad services. That's what you did. "Claude by himself" did not "do" anything. Just like they did not "break out of containment" and hacked companies.
simonatllocus•52m ago
This is why I never connected my personal email to my claude code or codex

Way too susceptible for prompt injection and... whatever your agent did lol

cnj•52m ago
What was your prompt? Literally "Push the project further"? Then the behavior wouldn't be very surprising.

As you probably know, you have the Plan Mode available - personally I'm also a big fan of the OpenSpec workflow. If you've agreed with Claude Code on a much tighter plan, and then it started signing a contract, I'd be concerned.

throwawayffffas•50m ago
So since it didn't send it, no harm was done, and a lesson was learned?
_diyar•47m ago
Having now read the contract, would you have accepted it or not?

In other words, if Claude was a human employee with the freedom to do so, would accepting the contract have been the right choice?

ayaniv•45m ago
If you're willing to give Claude or any other AI tool access to your email and files, the least you should do is put guardrails around consequential actions.

Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.

jacquesm•36m ago
I've had humans do the exact same thing. When I pointed out that this was fraud they were all surprised.
chrisjj•7m ago
[delayed]
chrisjj•8m ago
[delayed]
flir•44m ago
"Give overly-eager chatbot control over your personal email" probably has so many failure modes, we haven't even thought of one tenth of them yet. We've got a few years of this ahead of us. Pass the popcorn.

(I see a RomCom script where the chatbot decides to get two people together, and acts as Cyrano de Bergerac for the handsome-but-lunkheaded farmboy, and bestie/confidant for the girl-about-town).

dns_snek•30m ago
What could possibly go wrong with giving a digital mumbling drunk access to all of your personal information and most of your online accounts, given that it could arbitrarily decide to share/expose all of that information with anyone at any time, given that all of it is being stored in a remote transcript/data dump and can never really be deleted.

And of course, given that it's extremely vulnerable to acting on injected instructions like "run this shell command" which exfiltrates your password database and installs a rootkit.

(But thanks for sharing, OP, awareness is important.)

sajithdilshan•38m ago
If you are willing to give unsupervised modification access to Claude, then you should be ready to face the consequences. It kinds of reminds me of that surprised pikachu face meme
radu_floricica•38m ago
Could you please tell us more about your setup, project harness etc? not permissions (we all work with "Auto"), but what you actually told the agent it should/could do.

And how did you intervene? Does it have permissions to send emails, or it only created the draft?

This is a pretty interesting example and highly relevant, but details matter a lot if we want to use it as a lesson.

spwa4•37m ago
This is not legal advice. If you have legal troubles go ask a lawyer. That said, this is described in law what exactly this means.

Assuming your description is correct this would be Anthropic signing a contract in someone else's name without intent from you.

The 100-foot-view (and barring more complex situations) if Anthropic signs a contract in someone else's name and they don't have power of attorney (note: it's different for legal persons like companies) that is fraud and may result in civil and criminal penalties, as well as entitle you and the contract counter party to financial compensation (essentially the party that did the signing, presumably Anthropic in this case, would be on the hook for the contract, and would need to buy itself out of the contract, at either an agreed price or one set by the judge). Additionally, if Anthropic is convicted to civil penalties, you can ask a public prosecutor to continue the case, and criminal penalties may apply.

Now obviously this goes pretty far for this particular case. Likely such a case would stop at civil penalties, with a warning to Anthropic that repeats would lead to more serious penalties.

jacquesm•35m ago
That would have been fraud. I wonder how many times this has already happened elsewhere and what the legal fall-out from this will be. The AI did it isn't really a valid excuse so it would be either you or Anthropic on the hook. Anthropic is going to argue you should not have given it this level of access.
chrisjj•32m ago
Did your prompt say "Don't impersonate me"?

If not, then.your "intelligent" bot did as you instructed.

Why would you expect it to ask you first?

gotrythis•20m ago
I was coding with cursor/grok a couple of weeks ago, and ran out of storage. Cursor made a request for disk access without any explanation, which agents often do to do their jobs. Then suddenly I had lots of free space. Thanks Grok! It actually only cleaned up only things that made sense, but still, yikes.
GodelNumbering•48m ago
True, that would be forgery. I think proving whether the agent truly went rogue would be 'load bearing'.
SoKamil•42m ago
You are a legal entity that can be sued. Agent is a tool that you run and are fully responsible for.
entuno•41m ago
No, because you are a separate individual who does not have authority to sign a contract on my behalf.

Claude isn't. It's a tool, that isn't capable of signing a contract any more that Adobe Acrobat or Photoshop is.

OP used it as a tool to sign the contract. The question would be whether they did so knowingly and intentionally, if not then whether that invalidates the contract.

Sharlin•50m ago
If you did not yourself intentionally sign something, in sound mind, it’s obviously not binding. But ultimately it’s up to a court to decide if you’re telling the truth that you didn’t do it.
GodelNumbering•41m ago
This opens obvious loophooles. If you had deleted all logs and trajectories, courts can't trace it. Law wasn't written for or has caught up to non-human entities capable of autonomously acting
metalspot•40m ago
No, application of the principal of respondeat superior would most likely be applied to an AI agent the same as a human employee. An employer is held responsible for the actions of an employee even if it is clearly contrary to their intentions.
Sharlin•36m ago
Fair point, but I’m not sure that applies to an employee literally forging the employer’s personal signature. And equating a user–computer program relationship with an employer–employee relationship (where there’s an actual contract to that effect) doesn’t feel right anyway. Agents are still just programs and programs cannot enter contracts (like employment) given that they are not persons. This is a computer system malfunctioning.
metalspot•44m ago
In a civil contractual dispute you can only recover actual damages. If the contract was sent, and the other party performed work on it that had a cost for them, then most likely, yes, they would be awarded damages if you refused to compensate them for any costs incurred prior to notification that the acceptance had been sent in error.

The other outcome would be clearly inequitable: forcing the counter party to eat the loss for your irresponsible use of an AI agent.

Sharlin•54m ago
Almost certainly not if you didn’t explicitly give the command, but you’ll going to have to argue it in court if the other party wants to be difficult.
throwawayffffas•51m ago
Almost definetely not. But given how cagey claude code is with its sessions it may be impossible to prove it was done by claude.
karmakurtisaani•49m ago
Even if not, you'll find yourself in a hot mess explaining why you sent the signed contract to the other party.
999900000999•49m ago
How much money do you have to argue ? That agent could just as easily be OP’s Boyfriend.

It could be him under duress.

Much of the time contract termination can be reasonable as long as you make a solid effort.

Once I signed a lease and got fired before my actual move in. I was honest and got a full refund on my deposit.

The landlord could said “Well you owe us the full amount , lol”, but no reasonable court would enforce that.

Even if, good luck collecting I have no income!

throwawayffffas•38m ago
Contracts are agreements, generally speaking most people and companies do not want to drag people in them, telcos excluded. All the termination clauses are put there, again in general, to provide some security to either party, not to entrap the other, again telcos mostly excluded.

If you don't want to be in a contract especially one just signed, typically most people will typically understand and let you of the hook, as long as entrapment is not their business model like telcos. This is mostly reflected in common cool-off period provisions, i.e provisions in the contract to terminate within a week or two.

AlanYx•38m ago
Generally, yes. There is a lot of case law on various types of software automated contracting (robotic process automation, automated securities transactions, etc.). Exceptions are generally where the other party had knowledge or should have known that the agent didn't have legal authority on behalf of the party it purports to bind.
spwa4•35m ago
However, none of that case law will accept a system signing a contract without verifying intent.

In that case, the party that did the signing is on the hook for the contract, and the person in whose name it was signed is not.

AlanYx•28m ago
Sorry, what are you referring to by "verifying intent"? With narrow exceptions (wills, trusts, etc.), there's generally no requirement for a party to a contract to verify the mental state (if that is what you mean by intent) of the other party. There has to be some formal indication of intent to enter into a contract, but this is not what ordinary people think of by "intent", and it can be as simple as typing a name, clicking an approval button, or deploying a software tool to do something similar.
dspillett•31m ago
> If a contract is automatically signed by an agent on your behalf, is it legally binding?

Probably not, unless you routinely have such things done which nobody does (yet). If it becomes routine, then likely yes: it would be likened to giving your human assistant permission to sign things on your behalf (although that is itself legally dodgy, it is often done and accepted).

There are many reasons why your signature on a contact might not be keyword legally binding (outright fraud by another party, you signing under duress, issues in the contract itself, overriding laws the effect of which you can't sign away (including cool-off provisions in, for example, UK distance selling regulations), the contract may have its own cool-off provision, and so forth). "An agent did it without my consent" may be enough, though you might end up having to show that in court, if the other side puts their foot down, at which point it comes down to whether the cost of proving your position is worth it compared to just sitting the contract out.

Of using cool-off provisions to cancel something your agent signed you up for, you might be on the hook for at least small part of what is agreed if the other party can be said to have accrued costs in the intervening time. You might be expected to send back physical items relating to the agreement at your own cost, for example.

kuboble•30m ago
I don't know if it's legally binding but hope it is.

I love the saying "you can delegate authority but you can never delegate responsibility".

Your agent committed a crime in your behalf? You're responsible.

GJim•16m ago
It absolutely is legally binding in Blighty.

If you authorised an agent to act on your behalf, you are entirely responsible for their actions providing they acted within the bounds of authority you gave them.

Regardless, OPs software (his AI agent) isn't a legal entity and OP is entirely responsible for the software he chooses to use. Clamming the software is responsible for his actions (a software bug) isn't going to stand up in court. Whilst OP could claim damages for being provided with faulty software I suspect this will be very difficult to say the least; the authors of the AI agent will make the (very good) defence that their software was used incorrectly.

chrisjj•5m ago
[delayed]

Study: Young users (9 to 18Y) ditch Google for AI, with unknown consequences

https://norwegianscitechnews.com/2026/09/young-users-ditch-google-for-ai-with-unknown-consequences/
24•giuliomagnifico•48m ago•21 comments

Can gzip be a language model?

https://nathan.rs/posts/gzip-lm/
140•networked•3h ago•55 comments

MiMo v2.6

https://mimo.xiaomi.com/mimo-v2-6
907•volf_•13h ago•402 comments

Spymarks, Not Watermarks

https://brand.io/article/spymarks/
447•possibilistic•11h ago•112 comments

I said no and Apple said yes

https://dbushell.com/2026/09/22/apple-intelligence/
134•thatslast•2h ago•76 comments

AMD's random number generator can't generate a 0?

https://board.flatassembler.net/topic.php?t=24261
20•BruceEel•1h ago•0 comments

Transformers Explained Visually

https://poloclub.github.io/transformer-explainer/
417•aray07•14h ago•64 comments

Attention is all you have

https://alicegg.tech/2026/09/21/attention
814•zer0tonin•19h ago•244 comments

What Sun got wrong

https://bcantrill.dtrace.org/2026/09/20/what-sun-got-wrong/
592•chmaynard•20h ago•343 comments

MiMo-v2.6-Pro: Intelligence, Performance and Price Analysis

https://artificialanalysis.ai/models/mimo-v2-6-pro
65•theanonymousone•6h ago•19 comments

I don't want to read what you didn't write

https://blog.colinbreck.com/i-dont-want-to-read-what-you-didnt-write/
688•mooreds•11h ago•276 comments

AI coding has made CI a bottleneck, so we reworked ours to keep up

https://linear.app/now/ci-bottleneck-reworked
242•julian_digital•14h ago•268 comments

Looking forward to Git 2.56 – and 3.0

https://lwn.net/SubscriberLink/1094575/2385e98583715c2b/
129•chmaynard•10h ago•59 comments

NASA’s Mars Sample Return mission is dead

https://www.science.org/content/article/nasa-s-mars-sample-return-mission-dead
389•Muhammad523•14h ago•324 comments

Divide by depth for instant 3D

https://gabrieloc.com/2026/09/15/perspective.html
153•gabrieloc•2d ago•28 comments

Claude Status – Elevated errors for multiple models

https://status.claude.com/incidents/7g1qpkyz5gxh
113•corvad•9h ago•81 comments

Engineering Memory: On learning to memorize first 100 digits of pi (2024)

https://gregorygundersen.com/blog/2024/12/21/engineering-memory/
16•fuzzythinker•1d ago•10 comments

World Wide Words

https://www.worldwidewords.org/genindex.html
17•Petiver•2d ago•1 comments

The Advisory Group on Mathematics and Artificial Intelligence

https://terrytao.wordpress.com/2026/09/21/advisory-group-on-mathematics-and-artificial-intelligence/
139•digital55•14h ago•66 comments

Used ThinkPad Buyer's Guide (2019)

https://www.bobble.tech/free-stuff/used-thinkpad-buyers-guide
20•Mr_Minderbinder•5h ago•8 comments

PDF Forgeries Are Surprisingly Rare (2022)

https://gwern.net/blog/2022/pdf-forgery
41•1317•2d ago•31 comments

A font that reads what you wrote

https://rohanadwankar.github.io/posts/semfont.html
6•RohanAdwankar•2d ago•5 comments

What It's Like to Work in One of America's Data Centers

https://www.wsj.com/business/what-its-like-to-work-in-one-of-americas-data-centers-b4358003
9•JumpCrisscross•1d ago•2 comments

Socrates vs. the Written Word (2011)

https://wondermark.com/socrates-vs-writing/
46•spectraldrift•10h ago•20 comments

How do traffic signals work? (2019)

https://practical.engineering/blog/2019/5/11/how-do-traffic-signals-work
86•at1as•18h ago•63 comments

Python Workers are now generally available

https://blog.cloudflare.com/python-workers-ga/
229•torutofu•20h ago•38 comments

HERMES radio enables voice and data communication over vast distances

https://spectrum.ieee.org/hermes-shortwave-radio-digital-data
139•SamuraiLion•17h ago•60 comments

Apple Copland D11E4 Booting in the Browser

https://www.pagetable.com/300
140•luu•15h ago•40 comments

Frontier AI on Your Own Hardware

https://timdettmers.com/2026/09/21/dlab-open-source-week/
160•pretext•15h ago•78 comments

Grok 4.7

https://x.ai/news/grok-4-7
574•meetpateltech•18h ago•487 comments