Elvin Garcia · ORGANISMIC
The first in a series on delegated action and what it asks of a business.
For most of the Internet’s life, intent has had to travel in a human body.
You needed something. You opened tabs. You translated a need into search terms, then translated the results back into the shape of your actual problem. You learned which prices were real and which were invitations to call. You found the form that ended in a dead link, and the number that ended in a queue, and the exception that could only be reached by explaining yourself to a person who had the authority to make it.
The Internet did not remove that work. It made it possible to perform it at a distance, in your own time, without a counter or an appointment. That was an enormous change and it is easy to forget how much of it was carried by you.
Something different is starting now, and it is quieter than the usual accounts of it suggest.
A portion of that work is becoming delegable. Not your judgment. Not your responsibility. But the movement of your intent through the world: the finding, the comparing, the asking, the preparing, and — within bounds that somebody sets — the acting.
I want to describe that carefully, because it is being described badly almost everywhere. This is not an argument that people will stop using the Internet, or that businesses will soon transact only with software, or that any particular company’s product is about to reorganise commerce. It is a narrower observation, and I think a more useful one.
The Internet is beginning to carry delegated intent in operational form. That has consequences for any business that receives intent, or sends it, which is all of them.
What the interface always assumed
To see what is changing, it helps to notice something businesses have been able to rely on for thirty years without ever writing it down.
The person at the other end will compensate.
A price page that says from £40 does not specify what conditions produce £40. A policy that says within a reasonable period does not say how long. A service description that omits the case you are actually in leaves you to work out whether you are close enough to it. None of this is negligence. It is how commercial language has always worked, and it works because a human reader absorbs the ambiguity — infers, waits, asks a follow-up question, recognises when a rule probably has an exception, and decides whether an unclear answer is good enough to act on.
The firm published an approximation. The person completed it. That division of labour has been so reliable that almost nobody has examined it.
It is worth examining, because the work involved is substantial and almost entirely invisible.
Consider what you actually do when you take a commercial question through the Internet. You read a published rule and simultaneously estimate how firm it is — whether no refunds after thirty days is a policy or an opening position, and whether the exception you need is the sort a supervisor grants. You translate your particular circumstance into whichever generic category the form allows, knowing that none of the options quite describes you, and you pick the nearest one and hope the person reading it understands. You look at a price and decide whether it is a price or a starting point. You carry context across surfaces that do not talk to each other, repeating your account number, your problem, and your history to a website, then a chatbot, then a queue, then a person, each of whom knows nothing of what you told the last.
And you absorb the gaps. When the page does not cover your case, you infer. When two pages disagree, you pick the one that seems more current. When an answer is unclear, you decide whether it is close enough to act on, and you carry the risk of being wrong about that.
None of this appears on any org chart or in any process document. It is not a service the business provides; it is a service the customer performs on the business’s behalf, unpaid and unacknowledged, every time the business publishes something less than complete. Which is always, because complete would be impossible and nobody has ever needed it.
The arrangement worked because the interpreter was always human.
There is a small legal case from 2024 that shows what happens when it fails, and I keep returning to it because it is so much more precise than the anecdotes that circulate about this subject.
Jake Moffatt’s grandmother died, and he went to Air Canada’s website to book travel. He used the chatbot on the site. It told him he could apply for a bereavement fare reduction within ninety days of the ticket being issued. He booked on that basis. Air Canada’s actual policy did not allow retroactive applications, and it refused the refund.
Air Canada’s defence, in front of the Civil Resolution Tribunal of British Columbia, included the argument that the chatbot was a separate legal entity responsible for its own actions. The tribunal did not accept it. “While a chatbot has an interactive component, it is still just a part of Air Canada’s website.” Air Canada had conceded the bot used “misleading words.” The tribunal found negligent misrepresentation and ordered C$812.02.
I am not going to overstate what that case establishes. The chatbot did not book anything. It did not act. Moffatt did the booking and Moffatt sought the refund. This is a firm’s automated surface giving a wrong answer to a human being who then acted on it — which is an old problem in a new medium, not a new problem.
But it marks something. A firm learned, in a way it could be made to pay for, that what its software said to a customer was what the firm said. The old arrangement, where publishing an approximation was safe because a person would complete it correctly, does not survive contact with software that answers it confidently and wrongly.
That is the first crack. The rest of this essay is about what arrives through it.
Assistance and delegation are not the same thing
The word agent has been applied to so many things in the past two years that it has stopped discriminating. A model that drafts an email is called an agent. So is a workflow with three automated steps. So is a system that books a flight.
There is a distinction underneath that vocabulary and it is worth holding onto.
Assistance leaves you carrying the action. The system produces something — a summary, a draft, a comparison, a recommendation — and you take it from there. You do the clicking, the submitting, the confirming, the following up. However good the output, the work of moving your intent through the world is still yours.
Delegation is when the system carries a bounded portion of that work toward a result, under somebody’s authority. Not all of it. Not without limits. But a real segment of the path from wanting a thing to having it, performed by something that is not you, on your behalf.
That second condition is what has begun to appear in the primary record, and it is worth being specific about what has and has not.
OpenAI’s current documentation describes an agent mode available to paid ChatGPT plans in supported countries. It can use a browser-like interface: navigate sites, click buttons, fill forms, and — once signed in — perform actions on a user’s account. The documentation describes confirmation prompts for high-impact actions, a watch mode on certain sites, and the ability for a user to take over or interrupt. The launch material names the sort of tasks intended: research, bookings, building a slide deck, submitting an expense claim.
Notice what that is and what it is not. It is not a system that decides what you want. It is a system that, having been told what you want, does some of the moving. And it is bounded in every direction that matters: by plan, by geography, by which sites permit it, by confirmations, and by a person who can stop it.
Amazon shipped something narrower and, for this argument, more interesting. Buy for Me appears in the Amazon shopping app for a subset of US customers, across a limited set of brands. You find a product Amazon does not sell. You confirm the address, the tax, the shipping, and the payment method on an Amazon screen. Then Amazon uses your encrypted details to complete the checkout on the brand’s own website. The brand sends the confirmation. The brand handles fulfilment, returns and service.
I would ask you to sit with that arrangement for a moment, because it is the whole of this essay in one product.
A customer’s intent reached a brand’s own transaction surface through software the brand did not operate, on behalf of a customer the brand may never have directly interacted with — while the brand retained the delivery, the returns, the service, and the relationship that follows.
The brand had chosen to participate. Amazon says brands opt in, and the programme is a limited beta across a subset of US customers and a limited set of stores. That does not make the arrangement ordinary. It makes it an early, bounded instance of a firm being approached through another principal’s software, on terms the firm agreed to in advance.
That is not a firm deploying an agent. It is a firm receiving one, by arrangement, and finding out what that is like.
Two directions, unevenly arrived
Which brings me to the turn this essay exists to make.
The change has two directions, and almost everything written about it addresses only one.
Outward: firms are beginning to act through software. This is the direction with budget, attention, and vendors. A business deploys something that answers a routine enquiry, prepares a customer response, checks a condition, routes a task, or assists an operator in a workflow that matters. That is the version most executives have encountered, and it is the version most of the market is selling.
Inward: firms are beginning to be approached by software acting for someone else. A customer’s system, a supplier’s system, a marketplace’s system, arriving at a surface built for a person, carrying a request that a person authorised.
I want to be honest about the evidence, because the two are not equally documented and the difference matters.
The outward direction is visible in the record. Visa — which sits on the receiving side of the payments network rather than selling an agent — reported in December that it and its partners had completed hundreds of controlled, real-world, agent-initiated transactions, with more than twenty agents and agent-enablers integrating directly. The named instances are specific: headphones bought through a recommendation agent, checkout completed via API between two named companies, business bill-payment operations at Ramp. Visa is careful, and the essay should be too: these are controlled transactions in closed beta, not a consumer service, and Visa has published no audited volumes.
But notice what has happened to the firm in each of those cases, because it is easy to read the word payments and file the whole thing under a different department. When a system is permitted to prepare or complete a payment, a purchase, a request, a booking, a record change, or a commitment, the business has not adopted a productivity tool. It has allowed a bounded delegation to cross into a process that produces outcomes — money leaving, an obligation forming, a record becoming the version of events everyone downstream will rely on. That is a different category of decision from buying a licence, and it is not obvious that every firm currently making it knows which category it is in.
The infrastructure is visible too, and this is the part that tells you the direction is not one company’s bet. In December, Anthropic donated the Model Context Protocol — an open protocol by which models can connect with external systems — to a new Agentic AI Foundation under the Linux Foundation, co-founded with Block and OpenAI, with support from Google, Microsoft, AWS, Cloudflare and Bloomberg. MCP has been adopted across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot and Visual Studio Code, with more than ten thousand active public servers.
Set aside the acronyms. Competing firms who agree on almost nothing have placed part of the connective layer under neutral stewardship. That is a meaningful signal that interoperability is becoming a shared problem rather than a private feature.
The inward direction is thinner, and I will say so plainly rather than paper over it. Almost everything in the public record describes firms opting in — merchants wiring themselves into a marketplace, brands joining a pilot, platforms enabling a checkout. I could not find a documented case of a business that did not opt in, and then had to handle software acting for a customer at a surface it had built for people.
That absence is itself information, and it should be read precisely. It does not show that the condition will not develop. It shows that the public record is earlier, and more voluntary, than the surrounding rhetoric suggests — even as firms build the tools, the payment arrangements, and the interoperability layers that make such delegation more practicable.
Amazon’s Buy for Me is what the early version looks like: a real encounter, on agreed terms, at a surface the brand had built for a person.
The two directions are one condition seen from opposite sides, and a firm will eventually meet both. What is being delegated is not the same in each case — outward, the firm delegates its own action; inward, someone else’s principal delegates theirs — but the question underneath is identical. Something is acting on someone’s behalf, and somebody remains answerable for what it does.
The condition arrived before the rules
If you want to know how early this is, look at where the institutions are.
In February, the US National Institute of Standards and Technology created an AI Agent Standards Initiative. Its stated concern is agents capable of autonomous actions, and its stated aim is that they should be able to operate securely on behalf of users and interoperate across systems. Its three pillars are industry-led standards, community-led protocols, and research into agent authentication and identity. It links to a request for information on agent security and a draft concept paper on identity and authorisation.
That is a standards body opening a file. It is not a rule. Nothing in it is in force, nothing in it has settled the relevant standards, and no firm can outsource its present responsibility to a future rulebook.
But notice what it means that the file is open. The question NIST has posed is not should agents exist. It is: when a system acts for a principal, how is that authority identified, granted, bounded, and checked? A standards institution does not convene on a question that has not yet become operational.
So the honest summary of where we are is this. The condition has changed before its settled rules have arrived. Software can now carry bounded portions of intent. Money has moved on the strength of it. Competing vendors have agreed on the plumbing. And the questions of who authorised what, how far the authority extended, and who answers when it goes wrong are open — being worked on, unresolved, and arriving after the capability rather than before it.
That is not unusual. It is how most consequential technologies arrive. It is worth naming because it locates the responsibility precisely: for the foreseeable period, the boundary is whatever each firm has actually built and can actually defend — not what a settled, general agentic standard requires, because no such rulebook yet governs the whole condition.
What this leaves on the table
I have deliberately not answered the operational question, and I want to name it clearly so that it is obvious what has been left open.
When the next thing to arrive at your business is not a person reading a page but a system carrying someone’s delegated intent — what does it find? Not what does your website say. What is true, in a form that something which cannot infer, wait, or ask a clarifying question is able to rely on?
And when your own systems begin carrying your intent outward — into commitments, quotes, bookings, records, and money — what have they actually been permitted to do? Not what did you intend. What is enforced?
Both questions have the same shape and neither is answered by being more available. A business does not meet this condition by publishing more, connecting more, or automating more. It meets it by knowing what it is prepared to receive, what it is prepared to send, and what remains answerable when either goes wrong.
Air Canada found out what its chatbot had caused a customer to rely upon after the fact, in front of a tribunal, for eight hundred dollars. That is a small number and an early one. The systems now arriving are considerably more capable than that chatbot, and the things they can do on a principal’s behalf go well past giving a wrong answer.
A business is more than the information it publishes.
The next question is what it must become when the Internet begins asking it to act.
Elvin Garcia is the founder of ORGANISMIC, a publishing house for capability you own rather than rent — governed architectures published as plain text, which you load into whatever AI you already use, read end to end, run, and keep. The catalogue and a free complete capability are at organismic.org.
This is the first essay in When Intent Moves, a series on delegated action and what it asks of a business.
Sources
Civil Resolution Tribunal of British Columbia, Moffatt v. Air Canada, (14 February 2024). A public chatbot gave inaccurate information; the tribunal treated it as part of the company’s website. Moffatt booked and sought the refund himself — no autonomous action is claimed.
OpenAI, ChatGPT agent (Help Center, updated 15 August 2026) and Introducing ChatGPT agent (17 July 2025). Cited as a documented current capability under stated plan, geography, site, confirmation and supervision limits. Product naming is in transition at the time of writing; the capability is the durable fact, not the label.
Amazon, Buy for Me button on Amazon Shopping app (3 April 2025). A limited beta: a subset of US customers, a limited set of participating brand stores, customer confirmation at an Amazon checkout screen, Amazon-mediated checkout on the brand site, brand-managed delivery, returns and service. Brands choose whether to participate.
Visa, Visa and Partners Complete Secure AI Transactions (18 December 2025). Hundreds of controlled real-world agent-initiated transactions in closed beta, with more than twenty direct integrations. No audited volumes and no claim of mainstream availability.
Anthropic, Donating the Model Context Protocol and establishing the Agentic AI Foundation (9 December 2025); Linux Foundation, Formation of the Agentic AI Foundation (9 December 2025). Cited as a governance and interoperability signal. No claim that one protocol will prevail.
US National Institute of Standards and Technology, AI Agent Standards Initiative (created 17 February 2026, updated 14 August 2026). An initiative, a request for information, and draft-oriented work. Not a standard, not a regulation, not in force.



