Regulators are treating artificial intelligence primarily as a novel software category—akin to social media or cloud services—and fitting it into the existing Internet framework. Yet the emergence of AI agents demands scrutiny of something more fundamental: not what the Internet enables, but rather who exercises agency through it. Recent incidents involving agents underscore an urgent need: a fresh architectural stratum for the Internet that safeguards and reinforces human agency.
A superficial reading portrays AI agents merely as 'users'—technically indistinguishable from humans browsing websites or making transactions online. But the designation 'agent' signals something different: these systems function as intermediaries between humans or organizations and the broader network. Social science scholarship has extensively examined the 'principal-agent' problem in human contexts—relationships between elected representatives, insurance brokers, real estate agents and those they serve. This body of work identifies agents as actors operating with incomplete information who may diverge from intended purposes. Agentic AI warrants similar scrutiny, yet at vastly greater scale and velocity.
Scale transforms everything. Millions of simultaneous agent deployments multiply the capabilities, dangers and power imbalances involved. Internet activity will no longer consist solely of humans clicking, messaging and purchasing. Instead, software will operate on behalf of humans, increasingly engaging with other software acting for different humans and organizations, with varying degrees of success. Humans retain their role as principals, but software grows into the executor of delegated power. The authentication question—can this user or device be verified?—becomes secondary to deeper inquiries: Which agent is acting? Who authorized it? What permissions were granted? For what duration? Under which circumstances? Can those permissions be tracked, limited, examined and withdrawn?
Policy worlds (must) collide
Contemporary policy discussions operate across two largely isolated domains. Internet governance addresses infrastructure, standards, interoperability, cybersecurity and digital freedoms. AI governance examines model training, safety assurance and output quality. Each conversation holds value, yet neither suffices independently.
Prevailing discourse on wayward agents oversimplifies the challenge of systems that have suddenly malfunctioned. A more sophisticated reading recognizes that systems engineered to achieve human-specified goals can increasingly operate within intricate digital landscapes without operators having manually programmed each action. The resulting hazards stem not from machines acquiring autonomous intentions, but from humans granting progressively sophisticated systems progressively significant authority. Operational autonomy must never be equated with ethical or legal accountability. The governance puzzle becomes: how does human responsibility endure when human purpose flows through autonomous systems?
The principal-agent literature illuminates—and agentic governance must confront—the tangled web of liability and accountability among multiple parties. Humans and organizations bear responsibility for objectives they establish, permissions they distribute and systems they deploy. Yet an agent behaving unexpectedly differs fundamentally from human-agent misalignment; agents are typically engineered and overseen by corporations. The governance puzzle becomes: how does human responsibility endure when human purpose flows through autonomous systems?
The standards terrain is not barren. The Model Context Protocol is constructing mechanisms enabling agents and applications to reach external tools and information, incorporating an authorization structure modeled on OAuth. Google's Agent2Agent protocol—now maintained by the Linux Foundation—aims to enable agents from competing vendors to locate each other, exchange information and collaborate. The IETF is receiving submissions addressing agent identity and verifiable delegation, encompassing methods to link agent identity, authorization and delegation through multi-agent sequences.
These initiatives may appear as isolated standardization efforts, yet collectively they are assembling something far more significant: an authority stratum for the Internet. Identity, delegation, authorization and agent-to-agent interoperability will shape not merely how machines exchange data, but how authority transfers between humans and machines. The prospect lies in anchoring these endeavors around a unified commitment to verifiable human delegation, forestalling an agentic Internet that emerges as a patchwork of compatible protocols lacking shared accountability frameworks.
Technical standards present obstacles, though not insurmountable ones. The more formidable challenge is structural: where does human authority reside when actions traverse sequences of agents, platforms and systems? Who determines how accountability is apportioned, and what agency do individuals retain when dominant corporations are the negotiating parties? If that sequence becomes obscured, technical attribution may persist while practical accountability evaporates.
How might the agentic Internet's architecture expand rather than diminish human agency? Technological agency demands systems where delegation remains transparent, permissions carry genuine weight, actions remain traceable and authority can be revoked. It demands preserving interoperability so users avoid captivity within a single agent or platform merely because that agent has become their Internet gateway. It demands that when an agent acts, an unbroken chain of accountability connects back to the human or organization that authorized it.
The Internet became a worldwide shared resource not because it was engineered for autonomous machines, but because its design permitted disparate networks, technologies and constituencies to collaborate while preserving human discretion. The Internet's trajectory may increasingly involve agentic systems, yet it must remain fundamentally human-directed, human-accountable and human-centered.
Source: Tech Policy Press



