Delegus

ReceiptsEssay

When Machines Act for Us

Inam HaqFounder, Delegus

  • 13 min read
A timeline of authority: the seal (rulers), the letter (merchants), the signature (people), the resolution (companies), and now the agent (machines).

For millennia, we authorized other people to carry out our wishes. Now we are beginning to authorize machines to carry out our wishes. How do we respond when the entity acting for us can execute at speeds and scales we cannot?

There is something odd about authority that we tend to ignore. I can authorize another individual to act in my behalf without the individual becoming me.

Although the individual does not gain my identity or unlimited access to all of my capabilities, the individual’s actions can possess the weight of my intent when operating within limits I impose.

A lawyer can speak for me. An employee can spend a company’s resources. A corporate officer can sign an agreement that obligates the corporation. For centuries, merchants authorized agents to travel to locations they could not reach themselves. Rulers authorized emissaries to bear their authority. Shipowners authorized captains to make decisions regarding thousands of miles of ocean that they could not oversee.

None of these individuals were principals. They carried authority.

We have been so accustomed to using this abstraction for so long that it has become commonplace; however, it is amazing. Humans learned how to allow intention to extend beyond the physical presence of the individual who formed the intention. I do not have to accompany each action performed on my behalf. I can grant someone else a limited portion of my ability to perform actions in the world.

I can grant them a degree of agency.

The term “agent” has long been applied to such individuals for a good reason. An agent is not a principal; an agent performs actions for a principal.

In addition, agency has never implied total freedom in this context. I may grant you authorization to purchase an item for me; however, I will limit the amount you may spend. I may grant you authorization to negotiate a contract; however, I will not authorize you to sign the contract. You may represent me until Friday; however, I reserve the right to modify your authority at any time prior to Friday. The boundary is not irrelevant to agency. It is a necessary element of delegation.

In essence, civilization learned how to separate the person performing the action from the authorization to perform the action.

This separation facilitated tremendous accomplishments. Trade occurred across oceans. Businesses grew larger than the number of individuals capable of meeting together at a single location. Banks moved capital on behalf of clients. Modern civilization would likely collapse if every significant action required the ultimate principal to personally execute the action.

Delegation facilitated another challenge: when an individual asserts that he/she is performing actions on behalf of another individual, why should other individuals accept that assertion?

Over centuries, we developed responses to this question through mechanisms such as seals, witnesses, signatures, mandates, agency law, corporate resolutions and powers-of-attorney.

While mechanisms evolved, the underlying question continued to be remarkably consistent: who authorized you to perform that action? For much of this history, there existed one presumption that required little discussion: the agent was an individual. That is beginning to change.

We are creating agents again#

The term “agent” has reappeared in a new context. We are now applying the term to software that can pursue objectives, select among alternatives, utilize tools and communicate with other systems on our behalf.

Although technology may seem new, the relationship is surprisingly similar. We are once again creating agents. This time they are machines. For the majority of the computing era, software has served as a tool that we utilize. We click buttons, complete forms, authorize purchases and send messages. Computers can execute complex processes below the surface; however, human intention typically lies near the surface of the final action. Agents expand upon this relationship. I can increasingly state to a machine what I desire rather than specifically how to achieve my desire. A machine can research alternatives, operate software, access Application Programming Interfaces (APIs) and make intermediate decisions without requesting approval from me after each step. That is agency in a functional sense, and as we grant machines additional agency, an older distinction will become increasingly significant: agency and authority are not identical concepts.

Agency refers to an entity's capacity to perform actions. Authority refers to which actions an entity is permitted to perform. An artificial intelligence (AI) agent may be technically capable of executing actions far beyond those I authorized it to perform. Let's look at an example.

A purchasing agent at a business can use an authorized supplier to purchase manufacturing supplies for up to twenty-five thousand dollars on each purchase order. The agent places an $18,400 order with one of those suppliers via API. The supplier has the ability to see which agent made the order and which organization he/she/it represents.

However, what the supplier cannot do on its own is confirm that the organization approved this specific action – this money, these components, from this supplier, at this time. The supplier also doesn’t necessarily know that the finance manager took away the agent’s authorization to place orders two minutes earlier. No matter how well the agent follows instructions, nothing has to actually happen for this issue to arise. The agent may be following all the rules. To the supplier, a valid order will look exactly like an order placed after the agent lost his/her/its authorization to place orders, or for an amount greater than the agent was allowed to spend, or for an item that the agent was never authorized to purchase. The only way the supplier might find out about the difference between a valid order and an invalid one would be by disputing the invoice – once the merchandise is delivered.

The missing piece of information is “authorization.” This is where identity no longer provides sufficient verification. The supplier should not have to rely upon the agent’s statement that he/she/it has been given authorization; nor should the supplier have to build a custom-built integration into the organization’s internal permissions system. Instead, the supplier should be able to independently verify the delegation of authority – who granted the authority, what kind of authority it included, the limitations of that authority, if it has expired, and if it has been withdrawn.

The procurement example is not particularly compelling as an argument against agents if you consider only the case where one agent is making one purchase. When you increase the scale of this example by several orders of magnitude (to millions/billions of agents continuously working for people/organizations), then the argument becomes significantly larger. Agents will be communicating with other agents, buying resources, processing money, provisioning computing power, executing contracts, calling API's, and operating machinery. Many of the same decisions that were previously made on a daily basis within organizations may now be occurring at millions of times per second across multiple organizational boundaries. Human oversight cannot reside in the middle of this type of system because human oversight removes many of the advantages of having agents in the first place.

However, every service cannot rely upon an agent stating "I'm authorized." Delegated authorization will begin to resemble an infrastructure component rather than a capability of individual services. Each consequential action will require a machine-speed response to the age-old question: Does the principal truly authorize this action under these constraints at this moment? To me, this is what makes the problem interesting. AI will not only enhance the intelligence within an organization; it will exponentially increase the rate at which an organization can employ agents. Organizations that previously employed thousands of individuals who performed a limited amount of actions each day will eventually employ thousands/millions of agents performing actions continuously. The volume of decisions will likely grow exponentially faster than the volume of human supervision.

The internet made information move at machine speed. Payments made value move at machine speed. AI will likely make agency move at machine speed. If and when that happens, authority will have to move at machine speed with it.

Therefore, at some point in the very near future, reliance on human processes for establishing trust will no longer be feasible. Consequently, authorization will need to become computationally-driven.

The issue in this scenario is that identity and authority represent two distinct facts. Identity provides the supplier with knowledge of who arrived. Authority provides the supplier with knowledge of whether the company supports the procurement agent's actions.

Therefore, I continually refer back to a simple phrase: identity is a badge. Authority is dynamic.

Authority evolves based upon circumstances. Authority has scope, limitations, purpose and duration. Authority may rely upon prior events occurring. Authority can be narrowed or withdrawn. What is relevant is not whether an AI agent has general authority; rather, whether an AI agent has authority for a specific action under a specific set of circumstances at a specific point in time. We intuitively understand this concept with humans.

Awareness that someone serves as my lawyer does not imply that he/she can sell my home. Awareness that someone is employed by a company does not imply that he/she can execute a $10 million contract. Identity, capability, agency and authority are distinct concepts. Human organizations have developed methods over centuries to maintain separation among these concepts. Machines will require similar distinctions.

Authority at machine speed#

There is one problem, however. The organizations we established to facilitate delegated authority presuppose that humans exist on both sides of the delegation. Someone reads a document. A manager authorizes a purchase. A lawyer examines a contract. Finance initiates a telephone call. These processes can consume minutes, hours or days because the people involved operate at approximately equal speeds. Artificial Intelligence alters the time-frame. Eventually an AI agent may execute thousands of decisions across hundreds of applications in less time than it takes an individual to read one contract. An individual will not obtain a PDF power-of-attorney before each API call; nor can a lawyer position himself/herself between two machines executing thousands of trivial transactions.

If machines are to execute at machine speed, then authority must ultimately operate at machine speed. At this point, I started pondering about some form of machine-verifiable power-of-attorney. I am not referring to converting the legal instrument we call a power-of-attorney into software. The analogy has apparent deficiencies. What fascinates me is the structure underlying it: one entity authorizes another entity to perform actions on its behalf with defined limitations; subsequently a third-party can independently verify that authority prior to accepting the authorization to perform the action.

Return to the procurement agent. Instead of just proving to be who they say they are to the supplier, what if they were able to show that their employer had given them explicit permission to act on behalf of their employer? This permission could state that the agent is allowed to buy manufacturing components from authorized suppliers for up to $25,000 per purchase through the end of the current quarter. There may also be other limitations included in this permission and the employer could limit or remove their authorization at any point. When the agent sends an order for $18,400, the supplier doesn't have to rely on the agent saying "I have permission." The supplier will be able to check whether the employer really authorized the agent; if the items being ordered and the supplier are within the scope of the authorization; if the dollar value of the order is within the maximum allowed amount; and — most importantly — if the authorization is still valid at the moment the order is made. If the finance manager removed the agent's ability to buy things only two minutes prior to placing the same order with the same agent and identity, the agent would receive a different response. The main difference here is that the supplier does not need to access the employer's internal systems, nor does the supplier require an individual from the employer to approve each order. The authority itself becomes something the supplier can check. The decision process can take place at the same rate as the transaction.

Proof-of-permission#

There is another aspect of this issue that is equally important. Following an autonomous system's execution of a consequential action; someone will ultimately inquire why it was allowed. Perhaps tomorrow; perhaps during an audit six months later; or perhaps after something went amiss. "The API responded 200 OK" is not a satisfactory response as to why an AI agent was authorized to expend funds; modify infrastructure; or enter into an agreement. We should be able to reconstruct the authority existing at the time a decision was rendered.

  • Who authorized it?
  • To which AI agent?
  • What were its parameters?
  • What were its limitations?
  • Was the authority still valid?
  • Had it been terminated?
  • What did the AI agent request; and why was that request authorized?

The authorization decision should leave behind evidence. Not simply a log entry indicating that something occurred; rather a receipt demonstrating why the system believed it was authorized to permit it to occur. An environment populated by autonomous AI agents will necessitate more than permission; it will necessitate proof-of-permission.

What a machine can do is not what it may do#

This also impacts my perception of increasingly sophisticated AI. We devote considerable time inquiring about what machines will ultimately be able to achieve: whether they can produce superior software than we; conduct scientific investigations; negotiate; manage enterprises; or control machines in the physical realm. These inquiries pertain to capability; they do not pertain to authority. If an AI agent becomes twice as intelligent tomorrow; then it should not automatically receive twice as much authorization. If it develops an innovative approach to achieving a goal; that does not provide it authorization to achieve that goal.

Human organizations recognized this principle long ago. An exceptionally proficient employee does not automatically receive access to his/her employer's bank account. An exceptionally competent lawyer does not automatically receive permission to represent any client he/she chooses. Competency does not establish authority. Machines should inherit this distinction; perhaps even more emphatically than we do. An employee is constrained by temporal factors; attention deficits; geographical constraints; and physical limitations. An AI agent can potentially operate continuously across multiple platforms at speeds and scales no employee could ever approach.

This distinction can be expressed simply: intelligence determines what an AI agent can ascertain; agency enables it to execute actions; authority determines which actions it may execute on our behalf.

Or possibly even more fundamentally:

intelligence provides an AI agent with opportunities; agency converts opportunities into actions; and authority determines which actions belong to us.

That final aspect is crucial. If an AI agent executes actions on my behalf; the relevant inquiry is not merely whether the action occurred; rather whether I can truthfully declare: yes; that action was executed with my authority.

Maybe trust is the bottleneck#

There exists an economic implication here as well. Soon AI may perform certain categories of work in seconds that currently require hours for individuals to perform.

However; if every consequential action concludes with "let me consult my manager," "finance requires approval for this," or "can someone verify that the customer authorized the AI agent?"; then intelligence operates at machine speed whereas trust operates at human speed. We may observe that phenomenon and conclude that humans are the bottleneck. I increasingly doubt that conclusion is accurate. Maybe trust is the bottleneck. Perhaps one of the next significant productivity gains derived from AI will not be achieved by significantly increasing model sophistication; rather by establishing infrastructure that enables us to safely allow our existing intelligence to execute actions. We desire AI agents specifically because we do not wish to individually approve every intermediate action they execute. The greater their ability to operate independently; the more critical it becomes to precisely delineate where that agency terminates.

That is the issue we have been addressing with Delegus. The simplest explanation I have identified for Delegus (today) is machine-verifiable power-of-attorney for AI agents. An AI agent arrives at a destination stating that it represents an individual or organization. The destination party can independently verify what authority was granted; what its parameters are; whether it continues to exist; and whether it has been terminated. Prior to executing an action; verify the authority. Subsequent to executing an action; establish proof-of-authority for why the decision was rendered. The objective is not to establish inherent trustworthiness for an AI agent; rather to establish explicit authority sufficient enough that machines do not have to rely upon each other's representations concerning what they are permitted to execute.

Perhaps this is merely another chapter in an ongoing human narrative. For thousands of years; we have conceived methods for allowing our intentions to extend further than our physical bodies. A seal denoted a ruler's authority. A letter denoted a merchant's authority. A signature denoted an individual's authority. A corporate resolution denoted an organization's authority. All were methods for granting an individual a portion of our agency while retaining boundaries around the authority accompanying that agency. Now we are starting to apply this same concept to machines. The technology is new. The speed is new. The scope is unquestionably new.

However; perhaps the relationship is not as new as it appears initially. We have principals. We have agents. We delegate agency. We establish authority. And on the other side of this world; there still remains an inquiry that humans have been posing for centuries:

Who authorized you to execute that action?