ReadExplain It Simply30 Aug 20263:125 min readAI on the factory floor

Is a Bot a User? A 2017 Court Case Already Answered That.

Business software is sold by the login. You pay for every person allowed in.

A turnstile gate at the entrance of a bright office, one small friendly robot standing in the lane holding up a plain blank membership card to the reader, three more identical robots queued behind it, a single human-sized coat hook empty on the wall
The picture for this piece. Made for it: no people, no brands.

In plain words

Business software is sold by the login. What happens when the thing logging in is not a person?

Business software is sold per person who may log in. An AI agent does not replace the plant's systems. It logs into them, like a person, and often.

To answer one question about a slow line it may open three systems: production, quality and the schedule. Three logins, one question.

Palo Alto Networks, a security firm, asked 2,930 security leaders in 2026. For each human account they found 109 machine accounts, up from 82 a year before.

In February 2017 the software firm SAP won a court case in London against the drinks maker Diageo. Using SAP through another system still counted as use.

Gartner, a research firm, expects the cost of core factory software to rise 40 percent by 2029, partly from fees for machine accounts.

Picture it. Think of a gym that sells membership per person. When a robot vacuum starts using the treadmill every night, is it a member? The gym decides, in its own favour.

Why it matters to you. Open the terms of one tool your team uses and find the word user. If it says individual and says nothing about machines, your AI agent's login has no price yet.

Mechanism diagram: Is a Bot a User? A 2017 Court Case Already Answered That.
The mechanism, in one picture.Open full size

The number

2017

a court already decided this

What to do Monday

Pick any software your team runs and open the terms and conditions page on the vendor's website — the standard one anyone can read. Paste that page into whatever AI assistant you have and ask it one thing: find every definition of "user", and say whether a service account, an automated script or an AI agent counts as one. Ask it to quote the exact wording. Running this on Atlassian's Customer Agreement returns "any individual that Customer authorizes to use the Products" — an individual, and then nothing about machines at all. It doesn't allow them and it doesn't rule them out, and that silence is the point. Public document, ten minutes, none of your own data involved. It is the same discipline a factory already applies: everything automated that can touch a batch has its own identity, and gets counted.

The honest caveat

The money could move the other way. Gartner also says $234 billion of business software spend is at risk, because an agent that does the work means fewer human seats. And the SAP case turned on one contract's wording; a different licence could read differently. The bill moves. It does not vanish.

Your turn

So what happens when the thing logging in isn't a person?

Argue with me on LinkedIn

Sources

  1. AnalystPalo Alto Networks, "2026 Identity Security Landscape" report (May 2026; survey of 2,930 cybersecurity decision-makers) [primary]: 109 machine identities per human identity, up from 82:1; AI agent identities expected to grow 85% over the next 12 months — https://www.paloaltonetworks.com/idira/identity-security-landscape-report · Help Net Security summary (14 May 2026) — https://www.helpnetsecurity.com/2026/05/14/2026-identity-security-landscape-report/ link
  2. AnalystSAP UK Ltd v Diageo Great Britain Ltd [2017] EWHC 189 (TCC), High Court of Justice, 16 February 2017 [primary]: direct and indirect access under a Named User licence; SAP's claim of about £55m — https://www.bailii.org/ew/cases/EWHC/TCC/2017/189.html · Kemp IT Law, "SAP v Diageo – the UK's first software over-deployment case" [analyst] — https://www.kempitlaw.com/sap-v-diageo-the-uks-first-software-over-deployment-case-takeaways-for-business/ link
  3. AnalystGartner, "Manufacturing Predicts 2026: Digital Twins, AI Agents and the Race to Autonomous Operations" (December 2025) [analyst]: core manufacturing systems cost +40% by 2029; semiautonomous agents to orchestrate 10% of key production, quality and maintenance operations by 2030, from 2% today — https://www.gartner.com/en/webinar/797437/1795012-manufacturing-predicts-2026-digital-twins-ai-agents-and-the-race-to-autonomous-operations link
  4. PrimaryGartner press release, 1 July 2026 [analyst]: "$234 Billion in Enterprise Application Software Spend Is at Risk from Agentic AI" — https://www.gartner.com/en/newsroom link
  5. PrimaryProskauer, New Media and Technology Law Blog, 24 August 2026 [analyst]: "Does Your AI Agent Need Its Own Software License?" — legacy definitions of authorized user, access, use, device and instance were drafted before autonomous agents — https://newmedialaw.proskauer.com/ link
  6. PrimaryMicrosoft Learn, Microsoft Entra Agent ID [primary]: agents treated as first-class identities with their own identity object — https://learn.microsoft.com/en-us/entra/identity/ link
  7. As citedAtlassian Customer Agreement [primary]: "User" means "any individual that Customer authorizes to use the Products" — https://www.atlassian.com/legal/customer-agreement link
  8. PressThe Register, 12 December 2025 [press]: Salesforce moves AI agent pricing to a seat-based model after customers asked for predictability — https://www.theregister.com/ link
Read the full script (438 words)
Everyone is working out what an AI agent will save you. Almost nobody has worked out what it adds to your software bill — not the agent, but the software it logs into. An agent doesn't replace the systems your plant runs on. It signs into them, the same way a person does. To answer one question about a slow line, it might open your production system, then your quality records, then the scheduler. Three logins, one question. And you pay for every login. So do those three count? Nobody is sure yet — and how many are we actually talking about? Palo Alto Networks asked three thousand security leaders how many non-human accounts they run — scripts, service accounts, automated connections. For every one human being, they counted a hundred and nine. So is this a new problem? Not really. A court settled it nine years ago. In twenty-seventeen the software giant SAP took one of its own customers to court in London: the drinks maker Diageo. Diageo had built its own app for its sales team, and behind the scenes that app pulled data out of SAP. Diageo's argument was simple — our salespeople never opened SAP, so they are not SAP users. The court disagreed. Reach the software and you are using it, whichever door you come through. SAP had sued for fifty-five million pounds. That was decided long before anyone said the word agent — what's changed is the volume. So what does that do to your bill? Gartner expects the software that runs factories to cost forty percent more by twenty-twenty-nine — partly because vendors are starting to charge for accounts that aren't people. It might go the other way, mind — fewer humans, fewer seats. Your factory worked this out decades ago. Everything automated that can touch a batch already has an identity, and gets counted. Your contract was written as though only people log in. So what do your own contracts call a user? Here's this week's tip, and it takes ten minutes. Pick any software your team runs and open its terms and conditions page. Paste it into any AI assistant and ask one thing: find every definition of "user", and say whether a service account or an AI agent counts as one. I did this on Atlassian's. Their contract says a user is any individual that Customer authorizes to use the Products. An individual. It says nothing about machines at all — it doesn't allow them, and doesn't rule them out. Public document, ten minutes, none of your own data. The question isn't new. Only the scale is. Go and count yours — I'll see you next week.