Who does your agent work for?

Personal AI will soon handle our privacy choices for us. It should; nobody reads forty pages of terms. But an agent that makes consent easy can also make it meaningless. Delegated Digital Identity is an agent for your digital self that is paid by you, liable to you, and leaves a receipt for every decision made in your name.

The ledger shows the same six requests answered by two agents. Change who pays the agent and watch the answers change.

Six requests, one afternoon
This agent is paid by

    Memory is latent authority

    We think of an assistant's memory as storage. It is closer to power.

    When an assistant remembers your friend's birthday, it keeps a fact you gave it. When it writes down that a colleague "is an obstacle to your goals," it keeps a conclusion it reached on its own. That conclusion becomes a standing premise for next week's advice, next month's reminder, and the message it drafts in your name.

    Every stored inference is a small grant of authority the system gave itself. We have built careful controls around what agents can do. We have barely started on what they are allowed to conclude and keep.

    Agents execute authority. They never author it, including in their own memory.

    Five permissions, not one

    A yes at one tier is never a yes at the next. These are the defaults a DDI agent starts from; your standing orders can only make them stricter.

    Access

    Reading a source to do a task

    Default: the sources you named, for that task

    Remember

    Keeping anything past the task

    Default: session only

    Infer

    Drawing conclusions you never stated

    Default: nothing sensitive is kept; every guess stays labeled a guess

    Act

    Sending, buying, booking, changing

    Default: draft only; you see the exact action first

    Share

    Passing data to another party

    Default: denied

    Six tests of believable loyalty

    Loyalty is easy to claim. A buyer's agent is only truly yours if the seller isn't paying them. The same clarity applies here, and each test has to be checkable by someone other than the agent's builder.

    TestWhat it requiresHow you'd verify it
    Who paysRevenue from you, never from providers or data salesDisclosed revenue sources; no provider revenue share
    DutyA contractual duty of loyalty with liability attachedTerms that name the duty and the remedy
    ReceiptsA record of every request, decision and the rule appliedA ledger you, or an auditor, can inspect
    PortabilityYour standing orders move with you if you leaveExport in an open, machine-readable format
    Minimal memoryThe agent keeps your rules, not your life storyPublished retention limits; an inspectable store
    FloorsProtections for other people that no instruction can waiveHard-coded limits, tested and disclosed

    The people in your messages

    Your coworker, your sister and your neighbor never agreed to be interpreted. Your permission to share your inbox is not permission to profile everyone in it, and your agent cannot consent on their behalf. These rules sit below every negotiation. Neither you nor your agent can switch them off.

    1. Task-boundDetails about another person are kept only while a task you authorized needs them.
    2. No interpretive profilesNo standing judgments about anyone's motives, loyalties, mood or character.
    3. No sensitive inferenceNothing about another person's health, beliefs, sexuality, finances or legal status.
    4. No reuseWhat was gathered for one purpose is never mined for another.
    5. No onward sharingNothing about another person passes to a provider beyond what the task strictly requires.
    6. Reconstruction checkA deleted inference must not be regenerated from the material that produced it.

    What exists today

    An argument, a specification, and the framework underneath both. All open, all in personal capacity.

    Who Does Your Agent Work For?

    Essay, October 2026

    From "memory is latent authority" to a fiduciary agent for your digital self: why AI-assisted consent only works if the assistant answers to you, and how adoption could happen.

    Read the essay

    DDI Loyalty Spec v0.1

    Draft for comment, CC BY 4.0, DOI pending

    Loyalty as an OpenWarrant profile: eight warrant fields, five permission tiers, the third-party floor, a receipt format, and nine conformance tests.

    Read the spec

    OpenWarrant

    Framework, DOI 10.5281/zenodo.18666989

    The warrant, gate and evidence structure this spec is a profile of. Agents execute warrants; they never author them.

    OpenWarrant on Zenodo

    Design partners

    Credit unions, fee-only advisors, benefits platforms, patient apps

    Institutions that already owe their members loyalty are the natural home for a DDI agent. If that's you, I'd like to compare notes.

    Start a conversation

    Knowing more about a person should never mean having more power over them.

    I'm Andrew D. Plummer, MD, MPH. Physician, public health officer, and the author of OpenWarrant and the Encoded Governance stack. I write about AI governance as a runtime property rather than a compliance overlay.

    Comments on the spec, challenges to the argument, and partner conversations are all welcome: drplummer@gmail.com.

    Views my own. Nothing here represents any employer or agency.