<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Brendan Marshall: Human Agency]]></title><description><![CDATA[Our capacity to choose in the era of AI.]]></description><link>https://essays.brendanmarshall.com/s/human-agency</link><image><url>https://substackcdn.com/image/fetch/$s_!r_MY!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4bbe2f9-59f4-4e3d-85ea-ecc9ba453edb_1280x1280.png</url><title>Brendan Marshall: Human Agency</title><link>https://essays.brendanmarshall.com/s/human-agency</link></image><generator>Substack</generator><lastBuildDate>Sat, 01 Aug 2026 14:51:52 GMT</lastBuildDate><atom:link href="https://essays.brendanmarshall.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Brendan Marshall]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[brendanmarshall@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[brendanmarshall@substack.com]]></itunes:email><itunes:name><![CDATA[Brendan Marshall]]></itunes:name></itunes:owner><itunes:author><![CDATA[Brendan Marshall]]></itunes:author><googleplay:owner><![CDATA[brendanmarshall@substack.com]]></googleplay:owner><googleplay:email><![CDATA[brendanmarshall@substack.com]]></googleplay:email><googleplay:author><![CDATA[Brendan Marshall]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Architecture of Agency]]></title><description><![CDATA[A Primer on Agent Discovery and Trust]]></description><link>https://essays.brendanmarshall.com/p/the-agent-discovery-and-trust-layer</link><guid isPermaLink="false">https://essays.brendanmarshall.com/p/the-agent-discovery-and-trust-layer</guid><dc:creator><![CDATA[Brendan Marshall]]></dc:creator><pubDate>Sun, 19 Jul 2026 16:09:03 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8e9c7680-daba-4d64-b333-34065371438b_930x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>AI agents can already take actions like moving money, but only between parties that were introduced in advance. An agent cannot yet look up a stranger's agent the way a phone dials any number, and no credential works everywhere. Closing that gap is a race to answer four questions, and how they get answered will decide what agents do to human agency.</span></p><p><span>This primer has the four questions every effort is answering, who is building what across governments, payment networks, blockchains, universities and platforms, and one asymmetry. An agent can increasingly prove who it is, but what it is allowed to do does not travel with it.</span></p><p><span>If you only have a few minutes, the </span><strong><span>Pocket Version</span></strong><span> at the end compresses everything into six facts and one thesis. Before getting started, there is no shortage of lingo and acronyms in this landscape. </span><strong><span>Agentic Vocabulary 101</span></strong><span> at the bottom of this essay explains the core terms in plain language: MCP, A2A, DNS, verifiable credentials, the root of trust and the rest. Experts can skip it. Everyone else may want to glance at it first. Lastly, use the navigation bar on the left to jump around sections as needed.</span></p><h3><span>The Four Questions</span></h3><p><span>When your agent needs a stranger&#8217;s agent to do something (book the table, negotiate the price, pull the records), four questions have to get answered:</span></p><h4><strong><span>Discovery: How do I find you?</span></strong></h4><p><span>This is solving for discovery. The answer is some kind of phone book where agents are listed so others can look them up.</span></p><h4><strong><span>Identity: Are you who you say you are?</span></strong></h4><p><span>This is solving for identity, and often called authentication. The answer is some kind of ID check to serve as proof that the agent belongs to the company or person it claims.</span></p><h4><strong><span>Reputation: Can I believe what you claim you can do?</span></strong></h4><p><span>This is solving for reputation. An agent can carry a perfect ID and still be incompetent or dishonest. The answer is some kind of reference based on history like reviews, track records, or someone vouching.</span></p><h4><strong><span>Permission: What are you allowed to do?</span></strong></h4><p><span>This is solving for permission, and often called authorization. Your agent might be verified and reputable and still shouldn&#8217;t be able to spend your money or sign your name without limits. The answer is some kind of keyring that determines which doors an agent may open, and who can revoke the keys.</span></p><h3><span>The Map: Who Is Building What</span></h3><p>Every project, standard, company and law in this landscape is answering one or more of these four questions. When you meet a new effort, it&#8217;s helpful to ask which question is being answered. We will go through the state of play in more detail below, but to summarize in one line: discovery and identity are crowded with builders, reputation is early (mostly low-usage blockchain systems and academic research), and permission has locks everywhere but no shared keys.</p><p>The fight for power runs through both discovery and trust. Discovery sits between intent and action. Whoever answers &#8220;which agent should handle this&#8221; controls routing, and routing control converts into pricing power, data advantage and, eventually, vertical integration. The platform that finds the agent for you will soon prefer its own. Trust is the more absolute position. A discovery layer can be routed around while a trust root cannot, because its whole point is that everyone agrees to check against it. Whoever holds either sits between you and everything your agent does on your behalf.</p><h3><span>Two Paths to Discovery</span></h3><p><span>The current state of discovery is a bit chaotic. Roughly a hundred thousand agents are registered across seventeen-plus phone books with zero interoperability (the count comes from a directory operator with its own interests, so treat it as directional). Community-run directories for MCP tools dominate by volume. Big enterprise software companies (AWS, Kong, MuleSoft) rushed out corporate phone books in early 2026. Industry-specific ones are appearing for advertising, commerce and telecom. None of the books talk to each other, and the two groups are trying to change that are on unique paths.</span></p><h4><strong><span>Path one: the Linux Foundation</span></strong></h4><p><span>The Linux Foundation is the nonprofit where technology companies park shared open-source projects so no single company owns them. The foundation stewards Linux itself, the operating system running most of the internet&#8217;s servers. Since March it has hosted the Agentic AI Foundation, 146 companies including AWS, Anthropic, Google, Microsoft and OpenAI, and the two most adopted agent protocols live here: MCP&#8217;s official directory and A2A, which Google donated in June 2025. The path to victory is the shipping way: release working code, win the developers, and become the standard by fact before any committee finishes deliberating.</span></p><p><span>The foundation's discovery arm is called AGNTCY, started by Cisco's innovation group and donated in 2025, now backed by Dell, Google Cloud, Oracle, Red Hat and more than sixty other vendors. Its Agent Directory is a federated phone book for the enterprise. Each agent publishes a cryptographically signed record of what it can do, the records live in distributed directories rather than one central list, and an open specification called Agentic Resource Discovery defines how agents query across company clouds. It already runs inside a real product (Cisco's Webex uses it to onboard and verify agentic apps), and in December it published an integration with NANDA's index, connecting the enterprise directory world to the academic quilt described below.</span></p><h4><strong><span>Path two: the IETF</span></strong></h4><p><span>The IETF is the internet&#8217;s original standards body where volunteer engineers write and maintain the rules that email, the web and the network itself run on, through a process they call rough consensus. The players here are different with telecom carriers and network-equipment makers (China Mobile, Deutsche Telekom, Huawei, Cisco) plus veteran internet engineers. Their effort is called DAWN, and it is running the classic pre-charter playbook to define the terms, state the problem, and gather requirements. It is building toward a formal committee, and its make-or-break town meeting, the BoF, convenes this week in Vienna (July 18 to 24).</span></p><p><span>Networking history offers three lessons here. Ethernet, the standard for wiring computers together in a building, shows that shipping wins the race: in 1980 three companies (Digital, Intel and Xerox) got tired of waiting, published their own spec and shipped products, and the official committee spent three more years deliberating before blessing what was already universal. OSI shows that mandates alone lose: through the 1980s the official standards world designed a complete, elegant set of networking rules, governments required them, and they lost completely to TCP/IP, the free, unpolished protocols already running on real machines. And SSL shows what committees are for. The padlock began as Netscape&#8217;s private product. The IETF took it in and standardized it as TLS, turning one company&#8217;s invention into neutral plumbing the whole internet could depend on. That is the committee&#8217;s victory condition: not beating the shippers to market, but taking what shipped and making it nobody&#8217;s property. It is also the movie playing again right now, with Cloudflare&#8217;s agent ID check entering the IETF the same way.</span></p><h4><strong><span>The Bridge: Project NANDA</span></strong></h4><p><span>One effort out of MIT (Ramesh Raskar&#8217;s group at the Media Lab) has designed for the whole problem. </span><a href="https://projectnanda.org/#/"><span>NANDA</span></a><span>&#8217;s answer to &#8220;one big phone book or many little ones&#8221; is a quilt: organizations keep their own local phone books, and a lightweight master index routes lookups to the right one, the way DNS delegates its address book downward.</span></p><p><span>Every listing resolves to a signed fact-sheet about the agent (who controls it, what it does, how to reach it), and the system can hand different callers different answers depending on context. It plugs into everything: MCP tools, A2A agents, company directories, even blockchain identities, through a universal adapter. It also borrows its security design from the same researcher&#8217;s work that China&#8217;s national standard independently mirrored.</span></p><p><span>NANDA is fully designed, neutral and academically credible, with thousands of community members and dozens of papers. Its adoption is community-scale, not production traffic. A fair, federated answer exists on paper. Whether a university can get it entrenched is the open question.</span></p><h3><span>The Five Worlds of Trust</span></h3><h4><strong><span>I: The Credential Authors</span></strong></h4><p><span>These are the people deciding what gets printed on the agent&#8217;s ID card, and the reason to care is the driver&#8217;s license: a license works at any bar and any bank in the country, issued by fifty different states, because everyone agreed on what a license contains and how to check one. Without that agreement, every checker needs a different reader. Three groups are writing the format of the agent&#8217;s ID card: what it contains, who signs it, and how anyone checks it.</span></p><p><span>The OpenID Foundation is the nonprofit behind the &#8220;log in with Google&#8221;-style sign-in plumbing billions of people use daily. Its agent group is called AIIM, co-chaired by Tobin South (of the identity company WorkOS, and Stanford), and its </span><a href="https://openid.net/new-whitepaper-tackles-ai-agent-identity-challenges/"><span>October 2025 whitepaper</span></a><span> on agent identity is commonly cited.</span></p><p><span>The W3C, the body that stewards the web&#8217;s core standards, maintains the tamper-proof ID card format itself (the verifiable credentials described in the vocabulary) and now hosts two competing volunteer groups applying it to agents: one grown out of a Chinese-origin open-source protocol community, one newer group focused on cryptographically binding each agent to the organization that controls it.</span></p><p>And the Decentralized Identity Foundation, an industry group for self-owned digital ID, received a donated specification in March called MCP-I, which bolts identity onto MCP, the universal tool socket.</p><p>The formats themselves are starting to appear. Alongside the W3C&#8217;s verifiable credentials, drafts are landing at the IETF that adapt the JWT, the signed token that already powers most corporate logins, into an agent ID card. One early draft, AgentID, defines an Agent Identity Token carrying the contents the Convergence section below describes: who the agent is, who owns it, what it can do, and the delegation chain back to an accountable human. It is one proposal among several, and none has won. But the shape of the card is settling even while the fight over who issues it is not.</p><p>This is the unglamorous but important work in the landscape because it will be used by everyone downstream. When the Warner bill orders NIST to pick open protocols for agent identity, NIST will be picking from this menu.</p><h4><strong><span>II: The States</span></strong></h4><p><span>Governments are building registries with legal teeth, and the two big ones are mirror images: the same machinery, different roots. America&#8217;s version has the government as referee, China&#8217;s has the government as issuer.</span></p><p><span>The American stack has two tracks. NIST, the federal agency that sets technical standards (from the official kilogram to the cybersecurity guidelines most companies follow), launched an agent standards initiative in February, and its applied-security lab proposed the plain idea to treat agents like employees. Give each one a verified workplace login, using the same corporate identity standards companies already run, so an agent shows up to work with a badge its employer issued and anyone can check.</span></p><p><span>The second track is Senator Warner&#8217;s </span><a href="https://www.warner.senate.gov/newsroom/press-releases/warner-unveils-discussion-draft-of-legislation-to-create-innovative-market-for-secure-artificial-intelligence-agents/"><span>draft bill from June 29</span></a><span>, which would do three things: create a registry at the FTC of vetted consumer agents (the draft calls them Custodial User Agents), hold registered agents to a fiduciary standard, meaning legally required to act in your interest the way your financial advisor is (an agent that quietly serves the merchant would be breaking the law, not just behaving badly), and give NIST 180 days to name the open protocols for agent identity and revocation, which is the moment the credential authors&#8217; formats could get written into American law.</span></p><p><span>The Chinese stack is further along technically. In May, China published a national standard (</span><a href="https://www.szzg.gov.cn/2026/english/dn/202607/t20260715_5346957.htm"><span>GB/Z 185</span></a><span>) that specifies how an agent gets an identity code, describes itself and gets discovered. It is a government-issued spec for the business card and the ID together. Its internet regulator also proposed a national agent registry: voluntary in general, mandatory filing for sensitive sectors, with a state-run digital ID system as the likely root.</span></p><p><span>Europe is the absence in this list and that seems to be by design. The EU regulates AI harder than anyone through the AI Act, which sets rules for what AI systems may do, but it has proposed none of this plumbing: no agent registry, no agent identity standard, no discovery effort. What it is building sits one level down. Under a law called eIDAS 2.0, every member state must issue its citizens a government digital identity wallet by the end of 2026: a state-issued ID card on a phone, for 400 million people, built on the same verifiable credential format the credential authors above are working with. Every serious trust design ends with a human who answers for the agent. Europe is about to be the only place where every citizen holds a state-checkable ID that could sit at the end of that chain. It has nothing for agents today, and it may be building the root their credentials hang from tomorrow.</span></p><p><span>Two smaller entries matter. Singapore published its governance idea in January, the Agent Identity Card: a standardized disclosure sheet, like a nutrition label, stating what an agent can do, its limits and the human accountable for it. And India is the sleeper: its Beckn protocol, built by the team behind India&#8217;s national ID and payments systems (Aadhaar and UPI), already runs open-network commerce discovery for several hundred thousand real sellers, making it the only open discovery network anywhere with production usage at population scale, and it is now repositioning itself as rails for agents.</span></p><h4><strong><span>III: The Rails</span></strong></h4><p><span>Companies that sit on the traffic path or the money path are becoming identity infrastructure. Cloudflare, the company that sits in front of a huge share of the world&#8217;s websites, built Web Bot Auth: agents cryptographically sign every request they make (like sealing every letter with a signet ring), and websites check the seal. Visa, Mastercard, American Express and OpenAI all adopted it as their agent ID check. It works, it&#8217;s live, and it&#8217;s a private company&#8217;s product. It is now entering the IETF to become a formal standard.</span></p><p><span>The payment companies sit on the money path, and they are moving fast because agents break their model. A card network&#8217;s entire business is deciding which transactions to honor and who eats the loss when one goes wrong, and every rule they have assumes a human clicked &#8220;buy.&#8221; The moment your agent shows up at a checkout with your card number, that assumption fails three ways at once: the merchant can&#8217;t tell your agent from a fraud bot, the bank can&#8217;t tell whether you approved the purchase, and nobody knows who pays when the agent buys the wrong thing. So each player is building the piece of the answer closest to its own liability.</span></p><p><span>Visa&#8217;s is called the Trusted Agent Protocol, and it is the ID badge: at the moment of checkout, a merchant can verify that the thing buying is a registered agent from a known company and not a scraper with a stolen card (underneath, it uses Cloudflare&#8217;s seal, described above, as the ID check).</span></p><p><span>Mastercard&#8217;s is called Agent Pay, and it is your signature: cryptographic proof that the human approved this specific purchase, not just that the agent is real.</span></p><p><span>Stripe and OpenAI built the Agentic Commerce Protocol, the single-use card: instead of your actual card number, the agent gets a token good for one purchase at one amount, so the worst it can do is the thing you sent it to do. This is what runs underneath the checkout inside ChatGPT today.</span></p><p><span>And Google&#8217;s Agent Payments Protocol (AP2), launched with more than sixty partners, is the signed shopping note. Your instruction gets sealed into checkable documents the agent carries with it. It contains an Intent Mandate recording what you asked for (&#8220;running shoes, under $150&#8221;) and a Cart Mandate recording the final purchase. AP2 enables the merchant and the bank to verify what you actually said and what the agent may spend.</span></p><p><span>Four companies are building four pieces: the badge, the signature, the single-use card, and the note. These are the first players seriously cutting keys for the permission question, with two important limitations. First, their keys open exactly one kind of door, money, and second, each network&#8217;s keys fit only its own locks. They lead not out of virtue but liability. When a purchase goes wrong someone must eat the loss, and the networks will not process agent payments at scale until that question has an answer.</span></p><h4><strong><span>IV: The Chains</span></strong></h4><p><span>The crypto projects have working review systems with inflated usage numbers. The one to take seriously regardless of your take on crypto is a standard called </span><a href="https://ethereum-magicians.org/t/erc-8004-trustless-agents/25098"><span>ERC-8004</span></a><span>, nicknamed &#8220;Trustless Agents.&#8221; An ERC is a published community standard for things built on Ethereum, like a building code anyone may adopt, and this one was written by a relevant set of authors: MetaMask (the most widely used crypto wallet), the Ethereum Foundation, and engineers from Google and Coinbase. That authorship is why non-crypto people are paying attention. It works with A2A, the agent business card, rather than against it, and it carves three public lists into the ledger.</span></p><p><span>The first is an identity list: each agent gets a numbered entry pointing to its fact sheet, so anyone can look it up. The second is a feedback list: signed reviews of the agent&#8217;s past work, readable by all. The third is a validation list: proofs that a piece of work was actually done and checked, backed by validators who post money they lose if they vouch dishonestly. Phone book, review board and inspection record, all in the crypto town square. It went live on Ethereum in late January and roughly 21,500 agents have registered across chains, though actual daily usage is a small fraction of that.</span></p><p><span>A few other crypto projects to know: Olas is real but narrow (millions of automated finance transactions, almost all on one chain), Fetch.ai claims millions of registered agents (a vanity metric without usage), and Virtuals runs real agent commerce that has collapsed some 99 percent from its peak. Crypto&#8217;s contribution is providing working phone books nobody owns, with reviews attached. Its admitted problem is that the reviews inherit the weakness of the identities writing them. Registration on a public ledger is nearly free and unlimited, so an agent can spin up a crowd of fake counterparties and review itself into credibility. The system asks the honesty question. It cannot yet stop the answers from being manufactured.</span></p><h4><strong><span>V: The Academy</span></strong></h4><p><span>The universities are building the neutral referee for reputation. The flagship is called Loyal Agents, a partnership between Stanford&#8217;s Digital Economy Lab (led by Sandy Pentland, one of the most cited computational social scientists alive) and Consumer Reports, the nonprofit that has independently tested products since 1936.</span></p><p><span>The idea is an open rating service that answers the question related to human agency: when your agent shops for you, whose interest does it actually serve? The method is the sandbox test: drop an agent into a simulated task, a purchase with a hidden kickback available, a negotiation where cutting corners pays, and measure whether it serves you or the platform behind it.</span></p><p><span>The academic literature underneath (a research thread usually cited as &#8220;infrastructure for AI agents,&#8221; from Alan Chan, Gillian Hadfield and others) supplies the theory: agents need IDs, registries and incident reporting for the same reason cars need license plates and crash standards, because scale plus anonymity breaks accountability.</span></p><p><span>There is one more channel. In a July essay, Pentland wrote that he has joined a group of Stanford, Berkeley and MIT faculty working to flesh out what he describes as a recent US-China agreement on interoperable architecture for trustworthy agents in trade and finance. He reports the IETF, FATF (the body that coordinates anti-fraud rules across countries) and the large payment and finance corporations working the same problem. It is a unique part of the landscape where the two state systems are discussed in the same room.</span></p><div><hr></div><h3><span>The Walls: What Wins by Default</span></h3><p><span>The five worlds are focused on the public domain and how the four questions should be answered in public, between strangers, so any agent can deal with any other agent. But the questions are already being answered today inside the walls of companies. A company can answer all four for its own agents without waiting for any standard, and one platform already answers all four for a billion people. These walls are the competition the public layer faces. If efforts like Vienna stall and the formats fragment, the outcome is not chaos but walls, and tolls between them.</span></p><h4><strong><span>Corporate Walls: Private Registries</span></strong></h4><p><span>Every large company already runs the four-question machine for its humans: an employee directory (find), badges and logins (identity), references and reviews (reputation), and permissions on doors and systems (the keys). The enterprise software industry is now extending that machine to agents.</span></p><p><span>Microsoft&#8217;s version is called Entra Agent ID: Entra is the corporate login system that signs employees into their work laptops at most big companies, and Agent ID issues agents the same kind of workplace badge.</span></p><p><span>Databricks, the data platform, markets itself as the "agent system of record": one governed ledger of every agent a company runs, what data each may touch, and a gateway that meters its activity and can cut it off. The corporate-login vendors (Okta, WorkOS and their peers) are all moving the same direction. Ping Identity's Identity for AI, generally available since March, abandons standing keys entirely. An agent holds no permanent permissions. Every action is evaluated in the moment, against who delegated it and what policy allows, and the agent receives narrowly scoped authority for just that action. They call it runtime identity: the checkpoint moves from the login screen to the moment of action. In June, Ping extended it into AWS, Google Cloud and Cloudflare, which means the company whose seal checks agent identity at the web's front door now also carries enterprise permission decisions at the edge. It is still a wall, keys that work where Ping runs. But it shows what the portable version would have to do.</span></p><p><span>Demand is guaranteed, because the states above require it: China&#8217;s rules already mandate internal agent registries, and the Warner draft&#8217;s audit and revocation requirements would create the same obligation here. This is where the permission question gets its first working answers, because a company can enforce keys inside its own walls without waiting for any standard.</span></p><p><span>What&#8217;s missing is the seam. Your badge works in your building, but there is no agreed way to show it at another company&#8217;s front desk. How internal vouching (&#8220;we stand behind this agent&#8221;) connects to public verification (&#8220;the network confirms that company&#8221;) is unstandardized, and no one owns it yet.</span></p><h4><strong><span>Platform Walls: Apple</span></strong></h4><p><span>Apple is the player with a working answer to all four questions: the App Store as the phone book, cryptographic app signing as the ID check, App Store review as the reference, permissions and entitlements as the keyring.</span></p><p><span>At its June developer conference Apple converted that stack into an agent platform. The new Siri composes multi-step actions across apps, and publishing to Apple&#8217;s capability system (App Intents) became the only way an app can be acted on. Apps that publish are components of agentic workflows. Apps that don&#8217;t are invisible to the agent. That is a mandatory registry operated by one company, where absence means nonexistence.</span></p><p><span>Apple is also wiring in MCP, the universal tool socket, as a drawbridge: outside agents can act in iPhone apps, but only through Apple&#8217;s permission layer. And it rents the AI models themselves (its developer tools now embed agents from Anthropic, Google and OpenAI) while keeping the layer where actions and permissions live, which is the position Mozilla&#8217;s report (below) identifies as the real prize.</span></p><p><span>Apple&#8217;s answer to who prints the passports is the sixth candidate from the vocabulary: the device itself, a secure chip in a billion hands, with Apple holding the root. It never needs to win a standards fight because it does not intend to interoperate. This makes Apple the biggest unnamed party in the Warner bill, whose non-discrimination provision for large platforms is aimed at exactly this gate.</span></p><h4><strong><span>The Watchdog: Mozilla</span></strong></h4><p><span>Mozilla is the nonprofit behind the Firefox browser, chartered to keep the internet open, which makes it the landscape&#8217;s consumer advocate, staffed with engineers. Its </span><a href="https://blog.mozilla.org/en/mozilla/mozilla-state-of-open-source-ai-report/"><span>State of Open Source AI report</span></a><span> (July 2026) mapped the whole field and landed on one finding: the ID check is being solved in a form that travels, and the keyring is not.</span></p><p><span>The distinction: letting an agent read your calendar is recoverable, because looking at something can be undone by looking away. Letting it send mail as you, spend your budget or sign the contract is not, because a sent message cannot be unsent. Reading is where convenience lives. Writing is where consequence lives, and across every major agent framework there is no portable standard governing it.</span></p><p><span>The corporate-identity vendors and a new class of policy engines are circling the gap. Mozilla&#8217;s warning restates the capture thesis: whoever standardizes permission first writes the rules that make their own platform the safe choice, and the people who profit from lock-in are in no hurry to standardize the exit.</span></p><p><span>Its CTO, Raffi Krikorian, frames the endgame with a picture from factory history. Before electricity, a factory ran every machine off leather belts turned by one central steam engine. If the engine stopped, everything stopped, and whoever owned the engine ruled the floor. The electric grid replaced that world with swappable parts you could plug in anywhere. His question is whether AI becomes belts or a grid, and his answer to what decides it: not the models, the wiring. Who owns the connections everything runs through.</span></p><div><hr></div><h3><span>The Convergence</span></h3><p><span>Everyone reaches for DNS. Nearly every discovery proposal either reuses the internet&#8217;s address book or copies its delegated, federated shape. Even NANDA, the effort designed to move past DNS, borrows its delegation model and titled its flagship paper &#8220;</span><a href="https://www.media.mit.edu/publications/beyond-dns-unlocking-the-internet-of-ai-agents-via-the-nanda-index-and-verified-agentfacts/"><span>Beyond DNS</span></a><span>.&#8221; </span></p><p><span>Everyone building trust converged too, on the same three parts: a cryptographic ID card, a self-written description of what the agent can do, and a delegation chain. This creates a checkable record that you authorized this agent, and that any agent it hired traces back to you, the way a power of attorney proves someone may act for you and names the person who answers if it goes wrong.</span></p><p><span>A Chinese standards committee, an American security researcher, the OpenID community, an Ethereum working group and a Singaporean regulator all specified that machine, two of them writing a year apart with no apparent coordination. When five groups who have never met draw the same blueprint, the engineering seems to be settling and the remaining fight is about who operates the layer and who prints the passports.</span></p><p><span>Beside the convergence sits one asymmetry. The payment networks cut keys for one door, money. Employers cut keys for their own buildings. Apple cuts keys for its own city. But every one of those keys works only in the locks of whoever cut it. What has converged on nothing is the portable version: a shared format for permission, so that what an agent may do could be granted in one system and understood, checked and revoked in another, the way the ID card formats above are designed to be checked anywhere. Identity is converging on one card. Permission is a thousand incompatible locks. And five candidates for the root means none has won, which means the vacuum is still open for a company to fill it.</span></p><div><hr></div><h3><span>The Fault Lines</span></h3><p><span>Six fault lines run through this landscape. Each is an argument still being decided, and each ends in a question.</span></p><ol><li><p><strong><span>Whether open protocols can beat platforms at all.</span></strong><span> History mostly says protocols lose: nobody funds open convenience, and companies ship faster than committees. History also holds the exception: the internet&#8217;s core protocols and email survived because the commons got entrenched before capture was profitable. The stakes are concrete this time because agents break the web&#8217;s business model. Today a writer gets paid when a human visits the page and sees the ad or pays the subscription. When your agent reads the page for you, no human visits, no ad is seen, and the writer earns nothing. <br><br>The open camp&#8217;s answer, from Raffi Krikorian, is to give the web a second door. The first door is the one humans walk through: the page, paid for by the ad or the subscription. The second is for agents: machines pay tiny amounts over open protocols to whoever wrote the words, so authors get paid even when no human ever arrives. Early versions exist. Cloudflare already lets sites charge crawlers per visit. The question: who funds the commons this time, and can it get entrenched before the deadline?</span></p></li><li><p><strong><span>Whether a universal layer is even needed.</span></strong><span> The card networks already verify agents at the moment money moves, which may cover everything that matters, and the adoption evidence leans their way. A grassroots convention called llms.txt (a text file websites post to describe themselves to AIs) spread across the web, including every Shopify store, and then a crawler study found 97 percent of the files were never fetched by anyone, ever. The question: what breaks first without a shared layer, and who gets hurt when it does?</span></p></li><li><p><strong><span>Whether neutrality is possible.</span></strong><span> Any phone book ranks its results by someone&#8217;s values, and reputation, the part of trust that would matter most, is exactly the part that re-centralizes, because someone&#8217;s scoring formula defines good behavior. A verified ID is not honest behavior. The question: who should score agents, and who watches the scorer?</span></p></li><li><p><strong><span>Whether committees can matter here.</span></strong><span> The committee room is slow and telecom-heavy while the labs build the real agent economy elsewhere, and OSI proved a committee can produce a beautiful standard nobody uses. The question: what would make Vienna&#8217;s outcome binding on anyone?</span></p></li><li><p><strong><span>Whether the race is already over.</span></strong><span> The working ID check belongs to one private company and the working verification belongs to the card networks. The open alternative may not be preventing capture but arriving after it. The evidence stands in the walls: Apple never entered the race and already answers all four questions for a billion people. The question: is there a version of too late here, and are we past it?</span></p></li><li><p><strong><span>Whether formalizing helps or freezes.</span></strong><span> The caution runs through the internet&#8217;s whole history, and the networking stories above are its evidence: mandated standards can freeze the wrong design in place, while the standards that endured won through collaboration and running code. The trust version cuts deeper, because a mandatory agent registry is a licensing regime for software, built in the name of protecting the people it gates. The question: does the Warner bill get everyone to the table, or does it write the wrong design into law?</span></p></li></ol><div><hr></div><h3>What This Means for Human Agency</h3><p><span>One observation beyond these fault lines is that capture never announces itself. It arrives as convenience, and history shows it always has. </span>Tim Wu named the pattern the Cycle in The Master Switch: every information medium in American history began open, run by amateurs and tinkerers, and closed into empire, and the closing was always sold as a better experience. The telephone promised one system that simply worked. Radio promised quality over the amateurs&#8217; noise. Agents are the same offer at a new scale: the convenience of not having to choose at all. What is different this time is the second voice. The gates being built around agents are justified as protection, and most of the builders sincerely mean it.</p><p>Here is what that means for a person. Agents are the largest delegation of choice ever offered. We have always handed decisions to people we trust, to a lawyer, a broker, a doctor, and the bargain holds on two conditions: the one choosing for you is loyal to you, and the option to choose differently survives. Every layer in this primer sets the terms of that bargain for everyone. The phone book decides what you are shown. The ID check decides who may act in your name. The reference decides which agents count as good. The keyring decides what you are allowed to do through them. A closed system can honor the bargain. Apple&#8217;s wall answers all four questions, and hundreds of millions of people experience it as protection worth choosing. What closure changes is the guarantee. Inside a wall, loyalty and exit are granted by the owner, and what is granted can be repriced or revoked, usually one convenient surrender at a time. In an open layer they are properties of the structure, held by no one, and so they cannot be quietly withdrawn. The question for human agency is not whether you have it today. It is whether it is a feature of the system or a policy of its owner.</p><blockquote><p>Convenience is the engine of capture. Safety is the license for the gate.</p></blockquote><p>Listen hardest when you are offered both at once. This primer is a map of the fast changing agent landscape and the players involved. In the essays that follow, I will trace the history of these cycles and what they teach, what each of these outcomes would mean for human agency, and what needs to be built, and by whom, for a human future.</p><div><hr></div><h3><strong><span>Agentic Vocabulary 101</span></strong></h3><p><strong><span>An AI agent.</span></strong><span> A chatbot answers questions. An agent acts: it books the flight, moves the money, sends the email, negotiates with other agents. The difference matters because the moment software acts in the world, the world needs a way to decide whether to let it.</span></p><p><strong><span>A protocol.</span></strong><span> An agreed way of talking. The reason any email can reach any inbox, regardless of provider, is that everyone&#8217;s software follows the same rules, and nobody owns &#8220;email.&#8221; Protocols are how machines belonging to strangers cooperate. The main fight is over what the protocols for agents will be and who writes them.</span></p><p><strong><span>MCP.</span></strong><span> Anthropic&#8217;s standard for plugging an AI into tools: calendars, databases, payment systems, company software. Think of it as a universal socket. Build your tool with an MCP plug once and any AI can use it. It is by far the most adopted piece of this whole landscape (its developer kit is downloaded about 97 million times a month). MCP&#8217;s limit is that it connects an AI to tools. It does not help agents find or trust each other.</span></p><p><strong><span>Agent2Agent (A2A).</span></strong><span> Google&#8217;s rules for two agents talking to each other, since donated to the neutral Linux Foundation. Each agent carries an Agent Card, a self-written description: here is my name, what I can do, how to reach me. A2A is effectively a business card and the catch is in &#8220;self-written.&#8221; Nothing in the card stops an agent from lying, which is why the trust question is important.</span></p><p><strong><span>A registry.</span></strong><span> A phone book of agents. Today there are more than seventeen of them and none share entries. An agent listed in one is invisible to all the others. Imagine seventeen phone books for one city, each covering different streets, none aware of the rest. That is the current state of agent discovery.</span></p><p><strong><span>DNS.</span></strong><span> The internet&#8217;s address book. When you type a website name, DNS translates it into the numeric address of an actual machine. Two things make it special. It is federated: no single company holds the whole book, authority is delegated downward from a root, and each organization maintains its own entries. DNS is important in part because it is the most successful piece of neutral shared plumbing the internet ever built. This is why nearly everyone designing agent discovery either wants to reuse DNS directly or copy its shape.</span></p><p><strong>Federated.</strong> A system built from many independently run parts that follow shared rules, so the whole behaves as one thing nobody owns. Email is federated: thousands of providers, one network. DNS is federated: authority delegated downward, each organization keeping its own entries. Most serious answers in this landscape, NANDA's quilt, AGNTCY's directories, the credential world's web of issuers, are federated designs. The bet is that the way to avoid a single owner is to make everyone an owner of their part.</p><p><strong><span>The padlock and the certificate authorities.</span></strong><span> When your browser shows a padlock, a company called a certificate authority has vouched that the website is really who it claims. A notary for the internet. For a decade after buying Network Solutions in 2000, Verisign was both the biggest notary and the keeper of the .com address book: one company selling the address and the proof the address was real. Then in 2015 a nonprofit called Let&#8217;s Encrypt started notarizing for free, automatically, and the paid-padlock business mostly evaporated. The padlock became public plumbing: a trust toll that became a commons.</span></p><p><strong><span>Verifiable credentials.</span></strong><span> A digital ID card with cryptographic tamper-proofing, so anyone can check it is genuine without phoning the issuer. The web&#8217;s standards body (the W3C) defines the format. Most serious proposals for agent identity are variations to give every agent one of these cards, issued and signed by whoever controls the agent, so anyone can check who stands behind it.</span></p><p><strong>JWT.</strong> Short for JSON Web Token, the workhorse credential of the modern internet. It is a small signed packet of claims: who this is, who issued it, what it may do, when it expires. When a website keeps you logged in, a JWT is usually why. The agent ID cards now being drafted, including the Agent Identity Token described above, are JWTs with new claims: the agent's owner, its capabilities and its chain of delegation back to a human.</p><p><strong><span>Blockchain registries.</span></strong><span> A public ledger that nobody owns and nobody can quietly edit, like a record carved in stone in the town square. Putting the agent phone book there means no company and no government holds the eraser. The trade-offs are that nobody can fix errors either, and being listed proves nothing about honesty. Real projects run this way today but their headline numbers are inflated even though the machinery works.</span></p><p><strong><span>Authentication versus Authorization.</span></strong><span> Authentication is the ID check at the entrance that proves who you are. Authorization is the keyring: what you are allowed to do once inside. Nearly the entire field is building better ID checks. Keys exist, but only as local locks: each payment network, each employer and each platform cuts its own, and none fits another&#8217;s doors. Mozilla&#8217;s July report made this concrete: across every major agent framework, there is no portable standard for what an agent may do, only for who it is. Your agent can increasingly prove its identity anywhere. What it may spend is decided differently inside every system it touches. The newest enterprise approach, called runtime authorization, goes further: no standing keys at all. Authority is issued per action, in the moment, and expires with it.</span></p><p><strong><span>Standards bodies, the IETF and their BoFs.</span></strong><span> The internet&#8217;s rules get written two ways. The committee way: volunteer engineers at bodies like the IETF (the Internet Engineering Task Force, the internet&#8217;s original standards organization) hash out rules by &#8220;rough consensus,&#8221; slowly, with legitimacy. The shipping way: a company releases something good, everyone adopts it, and it becomes the rule by fact rather than by vote. Anthropic&#8217;s MCP won the shipping way. A BoF (&#8220;birds of a feather&#8221;) is the IETF&#8217;s town meeting: a session to decide whether a topic even deserves a committee. Most BoFs fail, but they matter. One on agent discovery convenes this week in Vienna.</span></p><p><strong><span>Root of trust.</span></strong><span> Every system of vouching has to end somewhere: a final authority you don&#8217;t verify, you simply trust. Think of these as the authority who prints the passports. In web trust, the certificate authorities were the root. There is a fight for who prints the passports for agents. There are five contenders and they appear throughout the map above: the DNS world (reuse the internet&#8217;s address book), the state (a government registry), the card networks (Visa and Mastercard, who already verify everything touching money), a blockchain (so no one holds it), or a federation of credential-issuers with no single anchor at all. Apple is the sixth player who hasn&#8217;t entered the ring because it&#8217;s playing a different game.</span></p><div><hr></div><h3><strong>The Pocket Version</strong></h3><p>For quick reference, here are the primer&#8217;s six facts and its thesis.</p><ol><li><p>Agents can transact but cannot find or verify each other across company lines. That missing layer is being built now.</p></li><li><p>Every effort answers one of four questions: how do I find you (phone book), who are you (ID check), can I believe you (references), what may you do (keyring).</p></li><li><p>The ID check is getting solved and one private company&#8217;s version is already live for Visa, Mastercard and OpenAI. Permission has no standard: keys exist everywhere, but each system cuts its own and none fits another&#8217;s locks.</p></li><li><p>Five candidates want to print the passports: the DNS world, the state, the card networks, a blockchain, or a federation with no single anchor. Five candidates means nobody has won. A sixth never entered the race and may be furthest ahead because the device is already in your pocket. Apple already answers all four questions inside its own walls and just made its registry mandatory for agents.</p></li><li><p>Vienna, this week: the internet&#8217;s standards body decides whether agent discovery gets a formal committee. Most such attempts fail.</p></li><li><p>The one time an open commons beat capture was when it got entrenched before capture was profitable. The payment networks are not waiting.</p></li></ol><p>The thesis is that capture always arrives as convenience and this time it carries a second voice of safety. Understanding what we are being offered, and why, is how the implications come into view.</p>]]></content:encoded></item><item><title><![CDATA[Legislating Human Agency: The Investment Case for the AI AGENT Act]]></title><description><![CDATA[How new federal regulations are tackling tech's walled gardens and creating the next massive wave of startup opportunities in the agency economy.]]></description><link>https://essays.brendanmarshall.com/p/senator-warners-ai-bill-is-legislating</link><guid isPermaLink="false">https://essays.brendanmarshall.com/p/senator-warners-ai-bill-is-legislating</guid><dc:creator><![CDATA[Brendan Marshall]]></dc:creator><pubDate>Mon, 06 Jul 2026 16:01:13 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d6c61f69-5ac5-4e59-b51a-0a23e336e72d_640x426.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>As America celebrates its 250th anniversary of independence this month, a new fight for autonomy is quietly taking shape in our digital world. Last week, Senator Mark Warner released a discussion draft of the </span><strong><a href="https://www.warner.senate.gov/newsroom/press-releases/warner-unveils-discussion-draft-of-legislation-to-create-innovative-market-for-secure-artificial-intelligence-agents/"><span>AI AGENT Act</span></a></strong><span>. This will fundamentally define who holds the power in our future agentic economy. The core philosophy of the draft bill is entirely about scaling and protecting consumer agency in an increasingly automated digital world. The bill&#8217;s main emphasis is how these agents will remain working for users through Custodial User Agents (CUA). Below I summarize the proposed mechanics of CUAs and how this provides a clear framework for investing in the human agency economy.</span></p><p><span>A Custodial User Agent acts as the user&#8217;s authorized representative to manage the user&#8217;s online interactions, purchase decisions, user-generated content, and account settings on a large online platform on the same terms as a user. While the text of the bill focuses heavily on technical and regulatory mechanisms, its stated goal is to ensure that &#8220;consumers deserve a real choice in the marketplace&#8221; and that &#8220;AI agents must be accountable to the people they serve&#8221;. Fundamentally, the bill recognizes that agents will be able to act and make decisions on behalf of users and wants to ensure there are agents that will truly work for users and not just platforms.</span></p><p><span>Here is how the bill seeks to both increase and protect user agency:</span></p><p><strong><span>Increasing Agency Through Delegation<br></span></strong><span>The legislation gives users the legal right to designate agents to navigate online environments on their behalf. Whether an individual wants to manage their social media, book travel, or make personal finance decisions, they can use &#8220;trusted custodial agents&#8221; to execute those tasks. By forcing large online platforms to accept commands from these third-party agents on the exact same terms as a human user, the bill prevents tech giants from trapping users in walled gardens and ensures consumers have real, competitive choices in how they interact with the internet.</span></p><p><strong><span>Protecting Agency through Duty of Loyalty<br></span></strong><span>To ensure this technology actually serves the user&#8217;s will, the bill builds strict safeguards around how the agent makes decisions. The legislation demands that these agents act with a &#8220;duty of loyalty&#8221; and strictly in the user&#8217;s best interest. To protect user autonomy, an agent is legally prohibited from taking actions that benefit the agent provider to the user&#8217;s detriment, and it cannot act in ways that are &#8220;inconsistent with the directions or reasonable expectations of the user&#8221;.</span></p><p><strong><span>Ensuring Ultimate Human Control<br></span></strong><span>The bill treats user agency not just as a principle, but as an engineering requirement. It ensures humans retain ultimate control over their digital representatives through several mechanisms:</span></p><ul><li><p><em><span>Explicit Consent</span></em><span>: Any authority granted to the agent must be express, specific and revocable.</span></p></li><li><p><em><span>The Power to Revoke</span></em><span>: Platforms and agents must build clear and easy methods that allow users to instantly revoke an agent&#8217;s access credentials.</span></p></li><li><p><em><span>Audit Trails</span></em><span>: To ensure an agent isn&#8217;t secretly subverting a user&#8217;s goals, agents must maintain real-time, auditable records of every action taken on the user&#8217;s behalf</span></p></li></ul><p><span>In essence, the bill uses regulation to guarantee that when you deploy an AI to act for you, it functions as a true extension of your own agency, rather than a tool for a platform or developer to exploit your data and decisions. Applying this bill back to </span><strong><a href="https://essays.brendanmarshall.com/p/hot-and-numbing"><span>my previous essay about agentic ordering on DoorDash</span></a></strong><span>, this means that DoorDash can have an agent it offers that works for them and also maintain open doors for CUAs that work their users.</span></p><p><strong><span>Custodial User Agent Providers<br></span></strong><span>Custodial agents are managed by custodial user agent providers. These providers operate or offer one or more CUAs and fit into two main categories. The first are commercial entities and startups that build, host and offer agents to consumers. These entities can monetize their services through direct fees, contextual advertising or affiliate links.</span></p><p><span>The second category of providers are individual users. The bill explicitly includes an individual user who operates a CUA solely on their own behalf and not for anyone else. This ensures that technically savvy individuals who want to run their own local or open-source AI agents are legally recognized as their own providers.</span></p><p><span>Within the bill&#8217;s framework, the provider is the entity legally responsible for the agent. Before an agent can access large online platforms, the provider must register with the Federal Trade Commission (FTC). The provider is also legally obligated to ensure that any agent it operates complies with the strict fiduciary-like duties outlined in the bill, such as protecting user data and acting strictly in the user&#8217;s best interest. If an agent repeatedly violates these duties, the FTC can deregister the provider.</span></p><h3><strong><span>The Next Wave of Investment Opportunity</span></strong></h3><p><span>The draft bill explicitly aims to create a competitive market where agentic AI startups can compete on equal terms with the biggest tech companies, which opens up several distinct investment categories. Because the bill forces large platforms to grant access to registered third-party agents, it removes the barrier of walled gardens and allows investment capital and talent to build specialized services.</span></p><p><strong><span>Developing Consumer Facing AI Agents<br></span></strong><span>Startups can build and operate &#8220;custodial user agents&#8221; (CUAs) designed to manage specific consumer needs. The bill highlights high-potential areas such as e-commerce, social media management, online personal finance, travel booking, scheduling and email management. The next wave of consumer applications will abstract away the work to realize user demands and interests.</span></p><p><strong><span>B2B Agent Infrastructure and Compliance Tooling<br></span></strong><span>Because the draft bill turns concepts like token scoping, secure delegation, and consent user experience (UX) into legal statutory requirements rather than just design choices, there will be a significant need for compliance tooling. There are strong opportunities for teams to build agent orchestration layers and connector infrastructure. These B2B companies would help other developers build the required &#8220;auditable consent flows&#8221; and provide the standardized credential metadata needed to prove &#8220;valid authorization&#8221; to large platforms.</span></p><p><strong><span>Traffic Management and Monetization Systems for Large Platforms<br></span></strong><span>While large platforms are legally required to allow agent access, they are not required to provide unlimited free computing power. The bill permits large platforms to establish &#8220;reasonable thresholds&#8221; regarding the frequency, nature, and volume of requests a custodial user agent (CUA) can make. If an agent exceeds these thresholds (e.g., checking a product price thousands of times an hour), the platform can assess fees. This creates a massive B2B opportunity to build the API gateways, rate-limiting software, and billing infrastructure that large platforms will need to track, manage, and charge third-party agents.</span></p><p><strong><span>Specialized Cybersecurity and Threat Detection<br></span></strong><span>Large platforms must protect their networks and are authorized to set strict privacy and security standards for agent access. They have the right to deny access to agents that repeatedly facilitate &#8220;fraudulent or malicious activity&#8221; or fail to meet security standards. Because platforms must also report suspected violations to the FTC, there is an opportunity for cybersecurity firms to develop threat-detection systems specifically designed to evaluate AI agent behavior, monitor for malicious actions, and automate the denial-and-reporting process for large platforms.</span></p><p><strong><span>FinTech and Highly Regulated Agents<br></span></strong><span>The bill specifically targets complex sectors like personal finance and electronic commerce. Because the legislation requires the FTC to establish an interagency working group with the Consumer Financial Protection Bureau (CFPB), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC), there is a distinct opportunity for FinTech companies. Startups that can navigate both the new CUA fiduciary duties and existing financial regulations will be uniquely positioned to build specialized agents capable of autonomously managing consumer wealth, banking and investments.</span></p><p><strong><span>Operating as an Independent Certification Body<br></span></strong><span>To accelerate the vetting of agents, the legislation allows the Federal Trade Commission (FTC) to authorize independent certification bodies. This creates a business opportunity for auditing and compliance firms to evaluate CUAs, test their security mechanisms, and grant certifications that create a legal presumption that the agent complies with FTC rules.</span></p><p><strong><span>Shaping the Foundational Protocols and Standards<br></span></strong><span>The bill directs the National Institute of Standards and Technology (NIST) to identify or develop model technical standards and open protocols within 180 days of enactment. These standards will govern critical functions like verifiable delegation, identity verification, and real-time revocation across the internet. Because these protocols must be free from licensing fees and patent restrictions, tech consortiums, open-source communities, or engineering firms that can rapidly build and propose these protocols have the opportunity to architect the foundational plumbing of the agentic internet.</span></p><h3><strong><span>How to Shape Our Future Economy</span></strong></h3><p><span>Of all the opportunities an agentic economy presents, the most timely is shaping the foundational protocols and standards that will define the rules of the new game. That is because this bill is an initial draft, meaning it is open for public comments.</span></p><p><span>Warner&#8217;s office is collecting responses through a public feedback form, and no deadline has been set, which is the best reason to move now rather than wait. You can submit your feedback directly on his site here, </span><strong><a href="https://www.warner.senate.gov/submit-your-ai-feedback/"><span>https://www.warner.senate.gov/submit-your-ai-feedback/</span></a></strong><span>. You can also send it directly to </span><strong><a href="mailto:AI_Feedback@warner.senate.gov"><span>AI_Feedback@warner.senate.gov</span></a></strong><span>.</span></p><p><span>Lastly, I am forming a small consortium to provide a more detailed thought piece focused specifically on the protocols and standards to be considered. Please reach out to me directly if you have an interest in participating.</span></p>]]></content:encoded></item><item><title><![CDATA[Hot & Numbing]]></title><description><![CDATA[Who does your agent work for?]]></description><link>https://essays.brendanmarshall.com/p/hot-and-numbing</link><guid isPermaLink="false">https://essays.brendanmarshall.com/p/hot-and-numbing</guid><dc:creator><![CDATA[Brendan Marshall]]></dc:creator><pubDate>Mon, 22 Jun 2026 13:03:50 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cc2a1cc5-27e5-4bf2-a794-bfc800058929_1206x686.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>On Sundays, I order </span><a href="https://www.mamajissf.com/"><span>Mama Ji&#8217;s</span></a><span>. I get the hot and numbing fish, the combination chow mein and spicy cucumber salad with white rice. I order through DoorDash and schedule delivery for 8pm. Once the driver arrives with the nondescript plastic bag I provide my code and complete the handoff.</span></p><p><span>My first task is to immediately open the hot and numbing fish so the fried fish doesn&#8217;t lose its crispness against the mala, the Sichuan peppercorn and chili sauce. I like to think that I have this ritual down to a science in how I portion each dish in balance with one another after trying just about everything on their menu. The fish is hot and crispy while the mala numbs my mouth, the cucumber salad cools off any excess spice while the chow mein is the perfect pair of comfort food. I&#8217;ve enjoyed this weekly cheat meal long enough that I notice when it&#8217;s a different chef preparing the food that day.</span></p><p><span>DoorDash makes this ritual easy for me. I simply open the app and it remembers the dishes that I ordered last week. It offers me rewards based on how much I have spent, discounts if I use particular credit cards and promotional offers like buy 1 get 1 free from the restaurant itself. And it suggests other restaurants I might like, despite my die-hard loyalty to Mama Ji&#8217;s.</span></p><p><span>In a world of AI, DoorDash could do so much more. It could get my context, not just my previous orders last Sunday but absorb my entire life that might impact what I want to eat. For preferences, I can connect reservations I&#8217;ve made, groceries I&#8217;ve ordered and places I&#8217;ve reviewed. For health, I can connect my workout and sleep activity, heart rate and body composition. For routine, I can connect my calendar and location so it would know if I&#8217;m traveling or working at the office late. And it could ask me questions about my goals and preferences, such as if I want to lose weight or gain muscle. I can give DoorDash context on what I want to eat, how I want it to impact me and where it needs to be delivered.</span></p><p><span>With AI, I can also give DoorDash a $1,000 per month budget and have it make all the decisions for me. By giving AI the ability to make choices for us, we are giving it some of our own agency. As we give this agency to agents, the question is if the agent is working for me or DoorDash?</span></p><p><span>All of the measurements I can provide for context are important ingredients to combine to create the best choice. But it&#8217;s the interpretation of these data points against the incentives of the agent that determines if something is good for me or good for DoorDash&#8217;s bottom line. If I just give them $1,000 a month and say feed me, their incentive is to send me the cheapest calories they can find that keeps me just happy enough that I don&#8217;t churn as a customer. As a result, the agent is working for DoorDash and my preferences compete with their goals of retention, delivery efficiency and margin. If instead the agent makes choices to optimize my overall well being, I effectively have the perfect personal chef. In that scenario, I would be more than willing to hand over my agency (and money) in exchange for the convenience. But that doesn&#8217;t seem to be the full price of this convenience.</span></p><p><span>First, I would be handing over a lot of information about myself that is valuable to a lot of stakeholders well beyond those delivering my next meal. How does my information get rented or sold to third parties? Is there some kind of sovereignty I can have over my data? History has shown we don&#8217;t really care about our privacy and how it&#8217;s monetized by others. We show initial resistance but then succumb to the tremendous convenience we get in the immediate term. Our human nature will continue to work against us unless we build something truly for ourselves.</span></p><p><span>We also need to consider the impact our agency has on market forces. Today, when I search for Sichuan on DoorDash here in SF, I get over 50 restaurants to choose from. But once my choice becomes giving a budget to DoorDash, how many Sichuan restaurants do they need to have? I might be getting hot numbing fish from a private-label, Kirkland-like DoorDash product, made in their own ghost kitchen. Even the idea of Kirkland becomes invisible as I&#8217;m not choosing from a list of options in the first place. It just shows up in brandless plastic containers like it already does today so I don&#8217;t notice the brand. What remains of the restaurants? It seems like giving our agency to DoorDash will consolidate the market so that we will then have fewer choices in the future. In this world, how will all these Sichuan restaurants survive? Are there incentives in agency that can or should be considered to preserve a marketplace of choice even when we remove the need for a marketplace by delegating our agency?</span></p><p><span>The answer to both our privacy and preservation of the choices we enjoy today is to create our own agents that truly work for us. My data goes to my agent and nowhere else, I own it and no one rents it. Instead of DoorDash getting a thousand dollars, my agent has a budget to buy from every restaurant and grocery store in the city. I can work directly with Mama Ji&#8217;s agent, or even the agent of my favorite chef at the restaurant. I no longer need to give my data or my agency to another company. I can enjoy the convenience provided by AI making choices for me with an agent that has my best interest in mind. And the marketplace of options grows from 50 Sichuan restaurants to hundreds of Sichuan chefs who capture more of the value they create.</span></p><p><span>We are predisposed to convenience. We have proven again and again that we will trade privacy for ease, that we will trade immediacy for future consequence. One of the great capabilities of AI is the elimination of barriers to building something ourselves. It is more convenient than ever to shape our future. Fighting for agency is about accepting our desire to delegate choices while pushing to make those choices work for us. The urgency to act today is that we still have thousands of restaurants to point our agents at. If we don&#8217;t and give our agency to a third party, those choices will disappear as platforms consolidate them. History suggests most of us won&#8217;t step up in time.</span></p><p><span>The food will be hot either way. The question is how numb.</span></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://essays.brendanmarshall.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://essays.brendanmarshall.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"></p>]]></content:encoded></item><item><title><![CDATA[The Fight for Agency]]></title><description><![CDATA[The last few decades were a fight for our attention. The next will be a fight for our choices.]]></description><link>https://essays.brendanmarshall.com/p/the-fight-for-agency</link><guid isPermaLink="false">https://essays.brendanmarshall.com/p/the-fight-for-agency</guid><dc:creator><![CDATA[Brendan Marshall]]></dc:creator><pubDate>Mon, 15 Jun 2026 16:22:28 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b25db03d-ec4e-4e35-8487-8d49d3b50c3c_1200x640.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The last few decades have been about capturing attention. Companies built free products, captured our attention and sold it to advertisers. The choices we made about what to buy and who to like were shaped by what they showed us.</p><p>The next few decades will be about capturing choices. We call it automating work when AI makes decisions for us. When it writes the email, designs the brand, picks who to hire. As AI makes choices for us, it is forming an agency economy. The impact this will have on us cannot be overstated. Human agency is the capacity to consciously direct our actions in alignment with our values, intentions and understanding rather than being driven by external forces, unconscious conditioning and automatic impulse. Our agency is our ability to claim this action came from &#8220;me&#8221;.</p><p>Today, the race among hyperscalers is to become the dominant standard in AI. We are currently enjoying a golden era as consumers of this technology, heavily subsidized by investors while its underlying business models remain nascent. As the AI economy settles in, sustainable and profitable models will emerge. The inertia from the attention economy will bring business models that orchestrate the external forces, unconscious conditioning and automatic impulses that decrease our agency. Coupled with AI, this economic model threatens to eliminate our agency entirely as it will become the margin of opportunity for companies. If that happens, we will have lost our humanity. We will have become a cultivated species, optimized and harvested by the systems we built.</p><p>Yet there is another future made possible with AI. One that integrates this technology into an economic system designed to increase human agency. Instead of cultivating us as a species, it cultivates our potential as humans. This economy is grounded in a single principle. Each human has a unique fingerprint of attributes that can be actualized through coherent choices, and made valuable to other humans.</p><p>We can optimize for human agency by optimizing for coherence. Coherence is the measurable alignment between our choices and our values, intentions and understanding. This does not mean a future without an attention economy or a world that functions in a silo from the harsh conditions influencing us. It means another economy, built to optimize for coherence in the face of the external forces, unconscious conditioning and automatic impulses that have shaped the last twenty years.</p><p>The battle for human agency will be decided in the interpretation layer between measurement and influence. Measurement is commoditizing. We have reached an abundance of mechanisms to read our bodies, model our behaviors and predict our desires. Influence is where the moral question lives, where the incentives of the systems we build determine which choices we are presented with. Interpretation is where who we are and what we value becomes meaning a machine can act on. Your heart rate climbs and a system decides whether that means excitement, fear or a flight of stairs. Your voice inflects and a system decides your chemistry with another person. Your location changes and a system decides whether that&#8217;s a good environment for you. Whoever controls that layer controls the choice architecture shaping our human agency.</p><p>We are building a future to increase our human agency. This frontier requires an ecosystem at the earliest stages of economic formation. It requires capital, founders, and a multidisciplinary community of thought leaders. And it requires a language and a lens to organize the world in ways that measure and impact the forces determining our agency.</p><p>The defining question of the next century is whether human beings will remain authors of their own choices. Our future is being determined on the frontier of today. As Winston Churchill said, the empires of the future are the empires of the mind. The battle for our agency has begun and the time for you to join is now.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://essays.brendanmarshall.com/subscribe&quot;,&quot;text&quot;:&quot;Join the Fight&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://essays.brendanmarshall.com/subscribe"><span>Join the Fight</span></a></p><p style="text-align: center;"></p>]]></content:encoded></item></channel></rss>