Personal AI will soon handle our privacy choices for us. It should; nobody reads forty pages of terms. But an agent that makes consent easy can also make it meaningless. Delegated Digital Identity is an agent for your digital self that is paid by you, liable to you, and leaves a receipt for every decision made in your name.
The ledger shows the same six requests answered by two agents. Change who pays the agent and watch the answers change.
We think of an assistant's memory as storage. It is closer to power.
When an assistant remembers your friend's birthday, it keeps a fact you gave it. When it writes down that a colleague "is an obstacle to your goals," it keeps a conclusion it reached on its own. That conclusion becomes a standing premise for next week's advice, next month's reminder, and the message it drafts in your name.
Every stored inference is a small grant of authority the system gave itself. We have built careful controls around what agents can do. We have barely started on what they are allowed to conclude and keep.
Agents execute authority. They never author it, including in their own memory.
A yes at one tier is never a yes at the next. These are the defaults a DDI agent starts from; your standing orders can only make them stricter.
Reading a source to do a task
Keeping anything past the task
Drawing conclusions you never stated
Sending, buying, booking, changing
Passing data to another party
Loyalty is easy to claim. A buyer's agent is only truly yours if the seller isn't paying them. The same clarity applies here, and each test has to be checkable by someone other than the agent's builder.
| Test | What it requires | How you'd verify it |
|---|---|---|
| Who pays | Revenue from you, never from providers or data sales | Disclosed revenue sources; no provider revenue share |
| Duty | A contractual duty of loyalty with liability attached | Terms that name the duty and the remedy |
| Receipts | A record of every request, decision and the rule applied | A ledger you, or an auditor, can inspect |
| Portability | Your standing orders move with you if you leave | Export in an open, machine-readable format |
| Minimal memory | The agent keeps your rules, not your life story | Published retention limits; an inspectable store |
| Floors | Protections for other people that no instruction can waive | Hard-coded limits, tested and disclosed |
Your coworker, your sister and your neighbor never agreed to be interpreted. Your permission to share your inbox is not permission to profile everyone in it, and your agent cannot consent on their behalf. These rules sit below every negotiation. Neither you nor your agent can switch them off.
An argument, a specification, and the framework underneath both. All open, all in personal capacity.
From "memory is latent authority" to a fiduciary agent for your digital self: why AI-assisted consent only works if the assistant answers to you, and how adoption could happen.
Read the essayLoyalty as an OpenWarrant profile: eight warrant fields, five permission tiers, the third-party floor, a receipt format, and nine conformance tests.
Read the specThe warrant, gate and evidence structure this spec is a profile of. Agents execute warrants; they never author them.
OpenWarrant on ZenodoInstitutions that already owe their members loyalty are the natural home for a DDI agent. If that's you, I'd like to compare notes.
Start a conversationKnowing more about a person should never mean having more power over them.
I'm Andrew D. Plummer, MD, MPH. Physician, public health officer, and the author of OpenWarrant and the Encoded Governance stack. I write about AI governance as a runtime property rather than a compliance overlay.
Comments on the spec, challenges to the argument, and partner conversations are all welcome: drplummer@gmail.com.
Views my own. Nothing here represents any employer or agency.