Skip to content

Build1 publisher3 min readPublished

X writes the agent liability clause before shipping the agent

X's revised terms, effective October 9, put prompts, outputs and autonomous actions on the user while capping the company's own exposure at $100 for anyone who has paid nothing, with SpaceXAI, Cursor and SpaceX able to invoke the dispute clauses.

The Engineer · Build desk

Photograph accompanying X writes the agent liability clause before shipping the agent
Photo: yahoo.com

What happened

  • X published a terms update on September 9th that takes effect on October 9th, giving users a 30-day window before the revisions apply.
  • The revised user-content section makes users responsible for their use of any feature that performs autonomous actions, plus the inputs, prompts, outputs and information the service creates or obtains.
  • The contract identifies no particular autonomous feature, defines no tasks it might perform, and does not say how much control a user keeps once an action is initiated.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision There is no clause-level opt-out on offer: the user either keeps using the service after October 9th, which X counts as acceptance, or deactivates the account and stops using the covered services.
  • exposure Whoever runs automation through X's surfaces carries the compliance duty for actions taken on their behalf, against a counterparty whose stated ceiling is $100 for an account that has paid nothing.
  • constraint Class-action and jury waivers, shortened filing periods and remedy limits narrow the procedures available for contesting that allocation, and affiliates outside X can invoke them too.
  • contradiction runtimewire is explicit that the document states a position rather than settling one: the caps bind only where law permits, and no clause fixes how a court divides responsibility after an agent fails.

The user-content section does not name a feature. It names a behaviour class: any feature that performs autonomous actions, together with the inputs, prompts, outputs and information created or obtained through the service [3]. runtimewire reads that breadth as the design intent, a general allocation of responsibility that covers agentic features without a redline per product [17].

The closest available description of what those actions involve sits in a sibling company's document, not X's. SpaceXAI's consumer terms describe agentic actions that can include browsing the web, executing code, sending communications, modifying files, calling tools and interacting with third-party services, and they assign responsibility for those actions to the user [11].

Then the counterparty's side of the ledger. Aggregate liability of X and related entities is capped, under the US-oriented terms, at the greater of $100 or what the user paid for the relevant services in the previous six months, wherever such limits are permitted by law [6]. For an account that has paid nothing, the greater of $100 and zero is $100 [15]. On the other side of the same contract, the user's duty is to ensure that actions taken autonomously on their behalf comply with applicable laws, regulations and X policies [4].

Third-party beneficiary status is the load-bearing mechanism in the second half. It lets an entity you did not contract with invoke the dispute, forum and class-action clauses in a qualifying dispute, and the revised terms name SpaceXAI, the AI coding company Cursor and SpaceX entities [8]. The corporate facts arrived first: SpaceX disclosed in February that it had acquired xAI as the foundation of its AI segment [9], and Cursor said on August 14th that SpaceX had completed its acquisition of the coding company after an earlier model-training partnership with SpaceXAI [10]. The terms naming Cursor were published 26 days after that statement [16].

For the document to operate as written, several things have to hold that it cannot itself guarantee. The caps have to be permitted in the user's jurisdiction, which the clause concedes by its own wording [6]. The Texas forum has to be available, with individual arbitration as the fallback when it is not, alongside class-action and jury waivers, shortened filing periods and limits on remedies [7]. And a forum has to accept the provision applying governing law, venue and arbitration to pending as well as future disputes regardless of when the underlying conduct occurred; runtimewire notes that this states the companies' contractual position and does not guarantee retroactive enforcement in every jurisdiction [12]. The contract also does not settle how a court would allocate responsibility after a specific agent failure [13].

What the material does not contain is a developer-facing version of any of this. The reporting is sourced to X's Privacy Center consumer terms [14], and the contract identifies no particular autonomous feature, defines no tasks it might perform, and does not explain how much control a user retains once an action is initiated [5]. Anyone sizing operational risk on X's agentic surfaces is sizing it from an allocation of responsibility rather than a description of a system. A responsibility clause you can read in September binds behaviour you cannot inspect until the feature appears. The effective date does not wait for the second half.

What to watch

  • Whether a developer or API version of the autonomous-actions clause appears, and whether it carries the same $100 aggregate cap.
  • The first named agentic feature on X, and whether its documentation says how much control a user keeps after an action is initiated.
  • Any forum tested on the clause applying Texas venue and arbitration to disputes over conduct that predates October 9.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories