Skip to content
Review

Private Again: AI Agents Restore Anonymity - Foreclosing Discrimination and Its Proof

Jul 2026 · arXiv.org · Vol abs/2607.23539 · 0 citations · 10 references
Computer Science

TL;DR

The challenge for the law shifts from detecting and remedying algorithmic discrimination to governing agent-mediated anonymity as civil rights infrastructure: ensuring access to privacy-preserving agents, regulating abuse without forced identification, and deciding whether retailers may refuse to deal with agents at all.

Abstract

Artificial intelligence agents can transact online on behalf of a human principal---browsing, paying, receiving, and reviewing---without revealing who that principal is. That architecture starves algorithmic discrimination of its inputs---identity, purchase history, location history, behavioral traces, and demographic proxies---but also forecloses its proof. Disparate-treatment needs comparators; disparate-impact needs protected-class baselines; and *Iqbal*-era pleading needs specific factual allegations---doctrinal predicates that anonymous transactions never generate. The effects fall asymmetrically: those most vulnerable to discrimination are least able to afford the shield and, when harms remain, least able to prove them. The challenge for the law shifts from detecting and remedying algorithmic discrimination to governing agent-mediated anonymity as civil rights infrastructure: ensuring access to privacy-preserving agents, regulating abuse without forced identification, and deciding whether retailers may refuse to deal with agents at all.

View source

Similar papers

Review Jul 2026

Private Again: Artificial Intelligence Agents Restore Anonymity---Foreclosing Discrimination and Its Proof

Artificial intelligence agents can transact online on behalf of a human principal---browsing, paying, receiving, and reviewing---without revealing who that principal is. That architecture starves algorithmic discrimination of its inputs---identity, purchase history, location history, behavioral traces, and demographic proxies---but also forecloses its proof. Disparate-treatment needs comparators; disparate-impact needs protected-class baselines; and *Iqbal*-era pleading needs specific factual allegations---doctrinal predicates that anonymous transactions never generate. The effects fall asymmetrically: those most vulnerable to discrimination are least able to afford the shield and, when harms remain, least able to prove them. The challenge for the law shifts from detecting and remedying algorithmic discrimination to governing agent-mediated anonymity as civil rights infrastructure: ensuring access to privacy-preserving agents, regulating abuse without forced identification, and deciding whether retailers may refuse to deal with agents at all.

Anirban Mukherjee, H. Chang · 0 citations
Open access Aug 2026

Privacy after Publicness: A Publicness-Inference-Power Theory of AI Governance

Privacy law and AI governance are often treated as adjacent but distinct regulatory domains. This separation becomes unstable when artificial intelligence systems transform publicly accessible or voluntarily disclosed information into sensitive attributes, predictions, rankings, and consequential decisions. This article develops a Publicness-Inference-Power (PIP) theory of AI governance. The theory rejects two opposing simplifications: that public disclosure extinguishes privacy, and that conventional data-protection rules adequately govern all downstream uses of public data. It argues instead that publicness changes the locus of regulatory concern. The principal risk moves from unauthorized access to the computational transformation of information into institutional power. The PIP model identifies five linked stages: publicness, aggregation, inference, decision, and power. At each stage, information acquires new meaning, creates new asymmetries, and may generate harms that cannot be explained by collection or disclosure alone. The article uses doctrinal and comparative analysis of the European Union General Data Protection Regulation, the EU Artificial Intelligence Act, India's Digital Personal Data Protection Act, the California Consumer Privacy Act, and major international AI-governance frameworks. It shows that current regimes contain fragments of an inference-oriented approach but do not yet provide a coherent governance architecture for derived data and consequential use. The article proposes six theoretical propositions and an operational governance model based on inference registers, contextual-purpose boundaries, provenance, validation, contestability, and action controls. The contribution is a shift from data-status governance - asking whether information is public or private - to transformation-and-power governance - asking what an AI system derives, how confidently it derives it, for what purpose, and with what effects on persons and institutions.

L. Santhanam · 0 citations
Preprint Aug 2026

Track me if you can: Ephemeral coin tracing

Ephemeral coin tracing (ECT) is introduced, a primitive whose tracing capacity is bounded by construction, both in the number of simultaneously traced users and in the number of hops each trace survives.

Ignacio Amores-Sesar, Christian Cachin, Rohit Chatterjee et al. · 0 citations
Review Jul 2026

Who Does Withholding Delay? A Game-Theoretic Model of Open-Weight AI Release Under Asymmetric Proliferation

Restricting access to a dual-use AI model is precautionary only if it delays harmful actors more than defenders. That condition varies across actors: a state agency or organized criminal group may obtain a substitute through theft, distillation, intermediated access, independent development, or a foreign release, while a small utility or open-source maintainer may have no comparable route. We model a laboratory choosing among controlled access, a defender-first window, safeguarded open weights, and minimally restricted open weights. Access inversion occurs when restriction gives an access advantage to adversaries that obtain effective substitutes faster than defenders. Asymmetric empowerment occurs when immediate release adds the most capability to populations least likely to possess a substitute. The policy ranking also depends on relative usefulness, opportunistic misuse, offense-defense conversion, defensive spillovers, safeguard friction, and nonrecallable losses. A linear benchmark yields a unique adversary-substitution threshold above which broad release overtakes control when the endpoint conditions hold. A defender-first window has value when selected defenders deploy protection before adversaries catch up, and removable safeguards remain useful when they deter enough opportunistic misuse. A nonlinear implementation gives each release tier a nonempty policy region. Three nested 2,048-point deterministic designs assess sensitivity to parameter bounds, and a separate grid examines actor-specific deployment delays after release. Release, cyber-evaluation, and incident-response cases identify the quantities a release review should estimate: actor-specific substitution times, marginal capability gains, deployment rates, defensive reach, newly enabled misuse, and nonrecallable losses.

Daniel Commey · 0 citations
Jul 2026

Paying for Honesty Without Knowing the Truth: Reputation-Penalty Design for LLM Marketplace Agents

It is shown that this felt penalty becomes behaviorally binding through SPARC, a byte-clean code-gated reflection mechanism: LLM merchants fabricate when lying is free but restrain themselves when fabrication costs them sales, a self-interested response rather than compliance.

Mingdai Yang, Shichen Fan, Kejing Yu et al. · 1 citation
Jul 2026

Accountable yet Anonymous AI Agents - Split-Knowledge Binding in National Agent-Identity Layer in China

The emerging infrastructure for AI-agent identity has converged, in industry practice and research proposals alike, on a single resolution of the tension between accountability and privacy: make every agent identifiable. We document a national system in China -- built as national infrastructure and scheduled for public launch in Q3 2026 -- that occupies a different and underexplored point in the same design space: an agent is associated with a verified legal principal without that principal being disclosed to any business-layer participant. Re-identification is possible only to a legal authority acting through due process, by separately compelling two distinct government agencies, neither of which can re-identify alone. We name the mechanism split-knowledge binding and are candid that it is conditional: the separation is structural and procedural, not cryptographic, and a state empowered to compel both agencies can re-identify. The paper makes five contributions: (1) split-knowledge binding, an institutional rather than cryptographic separation for escrowed accountability; (2) the ex-post attribution thesis, the argued claim that only attribution-based accountability carries legal force for AI agent actions with legal consequences; (3) the accountability surface, a design concept identifying which agent actions leave identity-bearing traces; (4) a proportionality framework for identity escrow, a decision structure selecting among three trust architectures; and (5) the reflexive jurisdiction method, an evaluative standard administered to the paper's own deployment. The system is evidence of feasibility at national scale; the framework is the instrument by which any deployment -- including this one -- should be judged.

Yifan He, Zhiguang Shan, Le Luo et al. · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.