Concentration Is Not a Safety Problem
Why the verification of agent identity and authority has to belong to nobody
Analysis ·
Two very different concerns travel under the same word. One is that an AI system does something harmful. The other is that the capacity to decide what such systems may do accumulates in a small number of hands. Both are called safety, and treating them as one problem obscures the fact that only the first has an internal solution.
A laboratory can address the first. It can test, red-team, publish evaluations, withhold capabilities, build guardrails, and improve them when they fail. Its incentives are not perfectly aligned with the public's, but they are not opposed either: a harmful failure damages the laboratory that produced it. This is why so much genuine safety work happens inside firms, and why it is reasonable to expect more of it.
The second concern has no internal solution at all. The entity doing the careful work is the entity accumulating the capacity. No amount of internal practice decentralises anything, because decentralisation is not a property an organisation can have about itself. It is a property of the relations between organisations.
The distributive answer, and what it leaves out
The answer most often offered from within the industry is distributive: make intelligence cheap, abundant, and available to everyone, so that no one controls it. That is a real answer to a real part of the problem, and the part it addresses — supply — matters.
But it addresses who can build and runagents. It says nothing about how one party establishes what another party's agent did.
And that question arrives precisely as a consequence of the distributive answer succeeding. When agents are abundant and act on behalf of individuals, companies and public authorities, the operative question stops being “is this model safe” and becomes: can a party who was not present establish which agent acted, on whose authority, within what declared scope, and whether the record of that act has been altered since it was made.
That is not a question inside any system. It is a question between systems, asked by someone who has no relationship with the operator on the other side.
Why the answer cannot belong to a participant
Suppose the infrastructure for answering it were supplied by one of the large platforms — as a service, well engineered, free at the point of use, perhaps genuinely better than anything else available.
Then every act of trust in the agentic economy would route through that platform. Concentration would not have been avoided; it would have moved. It would sit at the trust layer rather than the model layer, where it is less visible and considerably harder to displace, because trust infrastructure accumulates history and switching away from it means discarding everything already attested through it.
This is the structural reason why verification is different in kind from the capabilities it verifies. Capability can be commoditised by competition. Verification cannot, because the value of a verification layer comes from its being the same one for everybody. That property makes it a natural monopoly — and the only question is whether the monopoly is owned by someone or by no one.
Infrastructure that belongs to no participant is not an ideological preference here. It is the only configuration in which the thing works.
The inclusion question
There is a further consequence, and it is the one that ought to concern anyone outside the handful of jurisdictions where these systems are built.
If the means of verifying agent identity and authority exist only inside one bloc's regulatory perimeter, or only inside one vendor's stack, then participation in the agentic economy becomes conditional on being inside. Everyone else may use agents. They may not be parties to transactions that require verification — or they may be parties only on terms set elsewhere, revisable elsewhere, and unappealable.
This is not a hypothetical asymmetry. It is the ordinary shape of infrastructure that develops privately and is adopted globally. It happened with payment rails, with certificate authorities, with app distribution. Each of these began as a private technical solution to a coordination problem, and each became a condition of participation that its users had no part in setting. In each case the technical layer was neutral in description and consequential in ownership.
The difference now is that the layer in question determines who may act on whose behalf. That is closer to the constitutional than to the commercial.
Attribution comes before status
There is an argument, increasingly heard, that what is missing is a legal invention rather than a technical one — that the decisive innovation of the industrial revolution was not any machine but the limited liability company: a status granted by the state to something that had not previously existed, with bounded liability and the capacity to be a party. On this view, autonomous agents need an equivalent construction, and the absence of one is what holds the agentic economy back.
The analogy is instructive, but it inverts the order of construction.
Limited liability works because acts can be attributed. A company can have bounded responsibility only because it is determinable which acts were the company's, performed by whom, under what authority. Remove attribution and limited liability is not a protection but an evasion. The legal form rests on an evidentiary substrate that was already there — books, signatures, registries, witnesses — and which nobody had to invent because it predated the form.
For agents that substrate does not exist yet. Which means the first thing to build is not a legal status for agents. It is the evidentiary layer any such status would have to rest on: what is recorded when an agent acts, what properties that record must have, and what a party with no relationship to the operator can verify from it.
Until that exists, proposals to grant agents standing are proposals to grant standing to something whose acts cannot be established. And in the meantime the function is being performed anyway — by private registries, platform-issued credentials, and vendor attestations, each of them a de facto answer to a question nobody has yet asked in public.
That is the case for doing this work in the open, in venues where states, universities and small organisations have standing rather than customer relationships. Not because open processes are faster or better engineered. They are usually neither. But because this particular layer only works if it belongs to no one, and the only reliable way to arrive at something that belongs to no one is to build it where no one owns the room.