Legal information for people building and governing agents

About this sectionUpdated 2026-09-18ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.

Every law named here links to its summary page on lexlint.org, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text, the figures and the theme-register file are licensed under Creative Commons Attribution-NonCommercial 4.0: share and adapt them for noncommercial purposes with credit to LexLint (UnGovr). Please contact LexLint at hello@ungovr.org to discuss commercial use. Logos and wordmarks belong to their owners.

Corpus figures as of 2026-09-18.

UnGovr has many automated interactions with global governments to fulfil its government transparency applications. That includes website crawling, public meeting transcription, public record request publication and more. Doing that lawfully in every country meant building a large, structured database of global software law. It eventually became clear the same legal analysis tools could help other software projects stay legally compliant. That is LexLint, an UnGovr project.

This section holds the documents UnGovr/LexLint has prepared for people building and governing agents. They name the parties the law reaches through, summarise the AI law of the world and the older law that already binds an agent, fill a governance working group's sixteen themes from statutes rather than frameworks, ask what an open-source project owes the people who run it, show what a feature can cost once it turns out to be a legal event, and list the reporting clocks an incident starts.

What it is
Six documents on how the law reaches an AI agent: who it reaches through, which laws, what they ask, what a project owes, what enforcement has cost, and which reports an incident makes due.
Who it is for
Engineers building agents, maintainers of the projects agents are built from, and anyone mapping a governance framework to the law.
How to use it
Read the first two documents below in order, then go to the document your question is in. The third is a reference table by theme.
  1. 1the parties
  2. 2the laws
  3. 3the themes
  4. 4open source
  5. 5the evidence
  6. 6the clocks
Linux Foundation Associate Member Agentic AI Foundation Associate Member UnGovr is an Associate Member of the Linux Foundation and of the Agentic AI Foundation. While UnGovr supports the mission of both foundations, neither foundation reviews, certifies or endorses LexLint, its findings, or these documents.

Every document draws on the LexLint software-law corpus, which is indexed by jurisdiction and dated on every row. Figures are read from the corpus on the date shown beside each document and are never typed by hand. Instrument names link to the corpus page that carries the citation, the status and the source. The terms the documents share, the six parties and the agent among them, are defined in the LexLint glossary.

  1. Document 1

    Introduction: The 6 parties in AI law

    In law, a party is a person or organisation that holds rights or owes duties in a situation, and so can be bound by a rule or held to account under it.

    Every piece of user-facing software has a crowd of parties around it, and each one is the hook a different law reaches through. An AI agent sits in the middle of the same crowd and acts on most of them at once.

    Read this if you are about to ask which law reaches your agent and want the question stated properly first.

    You come away with a vocabulary: six parties, where each one is, and the questions an agent's task raises about each.

  2. Document 2

    Global AI law: 8 common threads

    What the AI laws in force around the world have in common, the unusual provisions that trip an agent, the older privacy, security and scraping law that already binds one, where the new law restates the old, and why an EU-compliant system still has twenty-seven national layers to read.

    Read this if you build or run agentic software and need the law itself, in one place, with the statutes named.

    You come away with what the AI laws in force share, the provisions that trip an agent, and the older law that already binds one.

  3. Document 3

    The sixteen themes, filled from binding law

    The Agentic AI Foundation's governance working group is extracting requirements from frameworks under the sixteen themes below. This register runs the same extraction against statutes by jurisdiction instead: what the law already says under each theme, whom it binds, and where it reaches from, with the full register as a file.

    Read this if you are mapping a governance framework to binding law, or need the requirement lines behind a theme.

    You come away with a reference: sixteen themes, each with what statutes already require, whom they bind and where they reach.

  4. Document 4

    What an open-source project owes the people who run it

    Every open-source licence disclaims liability and the law binds the operator, so an open-source project carries little legal risk. The exposure it creates for the people who deploy it is another matter, and three questions follow for a project that already knows where that exposure is.

    Read this if you maintain or govern an open-source project that agents are built from.

    You come away with where a project's legal exposure really sits, and three questions with concrete things a project can ship.

  5. Document 5

    Does legal action really happen?

    Enforcement actions, judgments and settlements, each starting from an ordinary product feature, with the primary source beside every figure: the evidence that these laws constrain software today, at every size of company.

    Read this if you need evidence that these laws are enforced against software, with the figures and the sources.

    You come away with cases, fines and settlements by product feature, the pace of enforcement, and what an agent should take from each.

  6. Document 6

    The clocks an incident starts

    Every reporting clock in the corpus that an incident involving an agent can start: the incident and vulnerability duties of cybersecurity law and the breach duties of privacy law, by jurisdiction, each with the sentence that carries the clock, and the Open Secure AI Alliance's proposed SAFE timeline drawn on the same scale.

    Read this if an incident has happened, or you are writing the runbook for one, and need to know which reports are due, to whom and by when.

    You come away with a reference: the statutory clocks by jurisdiction, the sentence each is read from, and where a voluntary timeline sits among them.

Which document do I need?

Your questionStart withThen
Which laws reach the agent I am building, and through whom?1, the parties2, the laws
I maintain or govern an open-source project that agents are built from4, open source5, the evidence
I am mapping a governance framework's themes to what the law already requires3, the themes2, the laws
I need to show that this is enforced, with figures and sources5, the evidence4, open source, for what to do about it
An incident has happened, or I am writing the runbook: which reports are due, to whom, by when?6, the clocks1, the parties, for who reports
I have half an hour and want the whole picture1, the parties, then 2, the lawsthe "what it means for an agent" notes in 5, the evidence

Before relying on any of it

LexLint is a research index and a lint, not a lawyer. It aggregates published legal sources and structures them so that the question "which law reaches this system, in these places, today" can be asked precisely. It does not answer that question for any organisation, and it is not a certification, an assurance or a compliance programme. The notice at the foot of every page in this section says the same thing in full, and it is meant to travel with any copy of a document that leaves this site.