techpolicy.press web signal

Komaitis, Chowdhury urge 'authority layer' for agentic web

TL;DR

  • Chowdhury and Komaitis argue AI agents break the internet's assumption of human requesters and need a new 'authority layer' for delegated action.
  • They point to three live efforts: Model Context Protocol on OAuth, Google's Agent2Agent under the Linux Foundation, and IETF proposals for agent identity.
  • Their warning: if delegation chains go opaque, attribution may survive technically while accountability disappears in practice.

Two internet policy veterans argue in a TechPolicy.Press essay that regulators keep treating AI agents as ordinary software when they in fact break the internet's founding assumption: that a human sits at the other end of every request.

Rumman Chowdhury, described in the piece as a pioneer in applied AI ethics and governance, and Konstantinos Komaitis, a veteran of developing and analyzing internet policy, dust off the 'principal-agent' framework from social science and apply it to a network never built with delegated software in mind.

"Internet traffic will not simply represent humans clicking links, sending messages or making purchases," they write. "It will represent software acting on behalf of humans."

The essay maps three efforts already underway. The Model Context Protocol is developing an authorization framework based on OAuth. Google's Agent2Agent protocol, now hosted under the Linux Foundation, is intended to let agents built by different vendors discover one another, communicate and coordinate. The IETF is seeing proposals for agent identity and verifiable delegation. Together, the authors argue, these efforts begin to "construct something more consequential: an authority layer for the Internet."

Their sharpest worry is what happens to the audit trail. "Where does human authority sit when actions can pass through chains of agents, platforms and tools?" they ask. "If that chain becomes opaque, attribution may survive technically while accountability disappears in practice." The agentic internet, they conclude, "should remain, at its core, human-directed, human-accountable and human-centered."

Three researchers on our Who's Who radar shared the essay the day it ran.

Shared on Bluesky by 3 AI experts