Who Does Your Agent Work For?
Personal AI is about to negotiate our privacy on our behalf. The question that decides whether that goes well is not how smart the agent is. It is who the agent works for.
Andrew D. Plummer, MD, MPH | October 7, 2026 | Views my own.
Memory is latent authority
We usually think of an assistant's memory as storage. It is closer to authority.
When an assistant remembers your friend's birthday, it keeps a fact you gave it. When it writes down that a colleague "is an obstacle to the user's goals," it keeps a conclusion it reached on its own. That conclusion becomes a standing premise. It can shape next week's advice, next month's reminder, and the message it drafts in your name.
This is no longer hypothetical. Recent reporting in TIME describes a personal agent instructed to keep hourly-updated pages on the people in a user's life, including their disputes and "tensions and alliances," and to learn notes such as "this user responds better to short nudges after 10 PM." The company told TIME the data is not shared with its advertising systems. That matters, and the governance question still stands.
None of the ingredients is new. The FTC's 2024 staff report found large platforms feeding data about users and non-users into algorithms and AI, with little way to opt out. What is new is the form. A recommender held a score. A personal agent holds a written interpretation of your life, and increasingly, the ability to act on it.
Every stored inference is a small grant of authority the system gave itself.
Consent was a cost problem
The obvious fix is a permission slip: tell people what the assistant will remember, infer and do, then ask. We have tried that. It gave us cookie banners and "Accept all."
The failure was never that people don't care. It was cost. McDonald and Cranor estimated that reading the privacy policies an average American encounters would take about 244 hours a year, roughly 40 minutes a day. Nobody pays that, so everyone clicks.
AI changes the cost. An assistant can read the fine print, translate it, and handle the hundreds of small permission requests a person will never see. The model shifts from a permission slip to standing orders:
- You set the rules once, in plain language. "Remember logistics, not opinions about people. Never send anything without showing me. Ask me about anything involving health or money."
- The agent turns those rules into precise policy and applies them to each request.
- It escalates only the exceptions: a new data source, a new kind of action, anything sensitive.
- It shows its work: a record of what it agreed to on your behalf, reviewable and reversible.
This is commander's intent plus rules of engagement, not a permission request for every trigger pull. The person writes the warrant once. The agent executes it many times.
The catch: whose agent is it?
An agent that makes consent easy can also make consent meaningless.
The evidence that assistants work is also the warning. In a Carnegie Mellon field study, users adopted 78.7% of a personalized privacy assistant's recommendations, and later changed only 5.1% of them. That is a good result for a helpful assistant. It is a sobering one for a conflicted assistant. People follow the advice they are given.
A cookie banner can nudge. A conversational agent that knows your habits, your moods and your late-night patterns can persuade. If the provider's own assistant walks you through what the provider's own assistant may collect, dark patterns stop being a design problem and become a dialogue.
So the question is not whether AI should help with consent. It should. The question is who the helper answers to.
Delegated Digital Identity: a fiduciary for your digital self
The answer is an agent with no stake on the provider's side and real stake on yours. I call this Delegated Digital Identity (DDI): an agent that holds your standing orders, negotiates with providers' agents, and is accountable to you alone.
The legal idea is not new. Jack Balkin proposed treating data-holding companies as "information fiduciaries" with duties of care and loyalty. David Pozen and Lina Khan offered a sharp critique: a platform whose business runs on data struggles to be loyal to the people that data describes. DDI takes the critique seriously. Instead of asking the platform to become loyal, it puts a separate, loyal party between you and the platform.
Think of a buyer's agent in real estate. They are only truly on your side if the seller isn't paying them. Loyalty is easy to claim, so DDI has to make it checkable:
| Test | What it requires | How you'd verify it |
|---|---|---|
| Who pays | Revenue from the user, never from providers or data sales | Disclosed revenue sources; no provider rev-share |
| Duty | A contractual duty of loyalty with liability attached | Terms that name the duty and the remedy |
| Receipts | A record of every request, decision and the rule applied | A ledger the user (or an auditor) can inspect |
| Portability | Your standing orders move with you if you leave | Export in an open, machine-readable format |
| Minimal memory | The agent keeps your rules, not your life story | Published retention limits; inspectable store |
| Floors | Protections for third parties that no instruction can waive | Hard-coded limits, tested and disclosed |
Some of the plumbing already exists. IEEE 7012-2025 standardizes machine-readable privacy terms that an individual proffers and a service accepts, with both sides keeping signed records. That is the user-side contract. DDI adds the loyal agent that chooses, applies and audits those terms on your behalf.
The people in your messages
A loyal agent solves the user's burden. It does not solve the hardest problem: the people who never signed up.
Your coworker, your sister and your neighbor appear in your inbox. None of them agreed to be interpreted. My permission to share my messages is not permission to profile everyone in them, and my agent cannot consent on their behalf either.
So DDI needs a floor that sits below every negotiation. A starting set:
- Task-bound only. Details about a third party are kept only as long as a task you authorized needs them.
- No interpretive profiles. No standing judgments about another person's motives, loyalties or state of mind.
- No sensitive inference. Nothing about a third party's health, beliefs or relationships beyond what the task strictly requires.
- No reuse. What was gathered for one purpose is not mined for another.
The floor is not a setting. Neither you nor your agent can switch it off, because it protects someone who is not in the room.
How this gets adopted
Large platforms have little reason to welcome a third-party agent negotiating against their defaults. History suggests three paths, and DDI needs only one of them to open.
Regulation creates an interface. In the UK, the Retail Banking Market Investigation Order 2017 required the nine largest banks to adopt standard open APIs so customers could authorize trusted third parties. In California, the Attorney General's 2022 Sephora settlement made clear that businesses must honor opt-out requests sent by a user's Global Privacy Control signal. Both established that a party or signal acting for a person can be required to be honored.
Enterprises demand it. Organizations will not let personal agents near employee and customer data without enforceable boundaries and an audit trail. A loyal agent with receipts is easier to approve than a black box.
A challenger competes on trust. Some provider will decide that accepting a user's agent is a feature, not a threat.
The practical move is to have the protocol ready before any of these doors opens.
Knowing more shouldn't mean more power
Personal AI will be genuinely useful. An assistant that remembers nothing helps with very little. The goal is not to stop personalization. It is to keep understanding and authority separate.
Three principles hold the line:
- Agents execute authority; they never author it. That includes the authority hidden in their own memory.
- Consent should be cheap for the person, not cheap for the provider. AI should lower the cost of saying what you want, not the cost of getting you to agree.
- Loyalty has to be checkable. Who pays, who is liable, and what the receipts show.
The next generation of personal agents will know us better than any software before them. Whether that is a relationship worth trusting depends on one question: who does your agent work for?
(Views my own.)
Sources
All links opened and checked October 7, 2026.
- Harry Booth, "Meta's Muse AI Agent Is Building a Dossier On You," TIME, Oct 6, 2026.
- Federal Trade Commission, "FTC Staff Report Finds Large Social Media and Video Streaming Companies Have Engaged in Vast Surveillance of Users…," Sept 19, 2024.
- Aleecia M. McDonald and Lorrie Faith Cranor, "The Cost of Reading Privacy Policies," I/S: A Journal of Law and Policy for the Information Society, 2008.
- Bin Liu et al., "Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions," SOUPS 2016.
- Jack M. Balkin, "Information Fiduciaries and the First Amendment," UC Davis Law Review 49:4, 2016.
- David E. Pozen and Lina M. Khan, "A Skeptical View of Information Fiduciaries," Harvard Law Review 133, 2019.
- IEEE, IEEE 7012-2025: Standard for Machine Readable Personal Privacy Terms, approved Nov 4, 2025; published Jan 20, 2026.
- Open Banking Limited, "Regulatory" (CMA Retail Banking Market Investigation Order 2017).
- California Department of Justice, "Attorney General Bonta Announces Settlement with Sephora…," Aug 24, 2022.