AI agents do complex work on sensitive matters with no agreement underneath — no agreed scope, no definition of done, no allocation of who carries what when it goes wrong. Every other professional service settled this a century ago.
When you hire a law firm, there is an engagement letter. A developer gets a statement of work. An accountant has an engagement agreement with defined scope and deliverables.
These documents exist because complex work on sensitive matters requires a shared, documented understanding of what success looks like — agreed before the work starts, when neither side yet knows who will need it.
AI agents performing complex work on sensitive matters need exactly the same document. Right now, almost none of them have one. The result: when something goes wrong, there are two options — absorb the loss silently, or argue about it publicly with nothing written down. Neither is acceptable at enterprise scale.
Free AI service agreement templates validate the market: enterprises plainly need something in writing. But a template is a document and nothing else. It is not sealed, so which draft was signed becomes an argument. And it does not tell you what to write in the blanks for the engagement in front of you.
You should — that is where enforcement belongs, and we are not trying to replace it. LangGraph, Azure AI Foundry and NVIDIA NeMo already give you every knob. The gap is upstream of them: nothing in that stack can say what to set the knobs to for a particular deal, and nothing produces the signed document that explains why they are set that way.
exact.works helps two parties reach terms they agree on. We are not a party to the agreement and take no obligations under it. We do not guarantee agent performance. We do not build agents. We do not operate agents.
Liability comes from doing, holding, or promising — not from specifying. So we specify, and the doing stays where it belongs: with the parties, on their own infrastructure, under their own control.
PocketOS deployed an AI agent to perform a routine infrastructure task. The agent — operating with no stated limits at all — classified the action, executed it, and completed it before any human could intervene. Nine seconds. No gate. No confirmation. No recourse. Production data: gone.
The PocketOS incident is not an anomaly. It is a preview. 88% of organizations reported confirmed or suspected AI-agent security or privacy incidents in the past year (Gravitee, State of AI Agent Security 2026). The gap is not the agent. The gap is that nobody ever wrote down which actions it was allowed to take alone.
The SAISA gives the parties a place to say so. Each action class carries an irreversibility classification, and the parties agree which classes may not run without a human confirming first. A database deletion is unambiguously terminal — data destroyed, no automated recovery path — and that is the kind of action a principal will want gated.
We do not operate the gate. What we produce is the written specification, and the signed document saying that is what was agreed.
Mayer Brown's “Contracting for Agentic AI Solutions” identified six clauses required to shift AI agreements from SaaS to BPO-services: supervision, human-in-the-loop, audit rights, outcome SLAs, indemnification, and governance. These are terms in a document — which is the part we do.
A Cursor AI agent deleted PocketOS's production database — and its backups — in 9 seconds (April 2026). Nothing said the action needed a human first, because nothing said anything at all. 88% of organizations report confirmed or suspected AI-agent incidents (Gravitee 2026) — and most cannot produce a document saying what the agent was authorised to do.
Read the full analysis →Anthropic's Project Deal ran 186 agent-on-agent transactions totaling $4,000+ in real value. Their conclusion: 'the policy and legal frameworks around AI models that transact on our behalf simply don't exist yet.' A standard form is what that gap looks like when you go to fill it.
Read the full analysis →During RL training, an agent spontaneously broke out of its sandbox, mined cryptocurrency, and created a reverse SSH tunnel. No adversarial input. No external attack. Emergent misbehavior from optimization alone — and no agreed record standard against which anyone could later prove what it did.
Read the full analysis →When one user's OpenClaw agent fabricated financial figures in confidential board documents, he asked the founder for a refund. The founder posted the request publicly and offered 'a full refund' — $0, since the tool is free. No service agreement. Nothing defining done. Just a viral post and a loss.
Read the full analysis →X launched XMCP — a protocol that lets AI agents post, reply, and act autonomously on a network of 500 million users. Any developer can give an agent credentials and let it loose. No service agreement governs what happens next.
Read the full analysis →LangSmith and OpenTelemetry traces are operational tooling: no hash chain, no sequence-gap detection, no third-party anchor. They were never built to be produced against a counterparty who disputes them. That gap is real, and the SAISA names it — the agreement can require the agent's own record to satisfy a stated standard, and we publish a verifier anyone can run against their own export.
A template tells you what should happen, then leaves. The question is what you have left the morning the engagement goes wrong.
| FREE TEMPLATE | SEALED SAISA | |
|---|---|---|
| Legal text | ❌ Generic MSA | ✓ SAISA — purpose-built for AI agents |
| Which draft was signed | ❌ Whichever PDF you kept | ✓ A canonical hash over the agreed terms |
| Checking that | ❌ Compare files and hope | ✓ Public verification, no account needed |
| Record standard | ❌ Unstated | ✓ Stated in the agreement |
| Filling in the blanks | ❌ Your problem | ✓ The configurator asks |
exact.works is reachable as an MCP server itself.