ODEI
DOCUMENTATION Public surfaces evolve in real time.
Runtime Research Category Thesis
ODEI Research Note · Version 2.0 · Updated August 12, 2026

The Governance Gap
in the Agentic Economy

Why authority, memory, policy, and audit should remain independent from model providers

Major AI platforms can build increasingly personal assistants. Apple now describes Siri AI as using personal context and conversation history; OpenAI operates cross-chat memory and an advertising platform. The open question is therefore not whether a platform can build a personal assistant. It is who controls persistent memory, delegated authority, policy, portability, and evidence when an agent acts across services.

This note argues that those governance functions should remain user-controlled and model-agnostic. Regulation strengthens the case for explicit permissions, traceable decisions, bounded memory, and intervention controls, but it does not make every personal agent unlawful or automatically high-risk. ODEI's thesis is architectural, not a claim of automatic legal compliance.

Factual cutoff: August 12, 2026. This is a research note, not legal advice. Classification and liability depend on the system's intended purpose, deployment context, actors, and applicable law.

Six governance capabilities for user-controlled agency

01
Initiative
AI acts on your behalf without waiting for a prompt
Scoped authority · Intervention
Autonomy needs explicit scopes, risk-based approval gates, and a reliable stop or override path
02
Transparency
Every decision and action is traceable through persistent memory
Provenance · Retention
Useful audit evidence must be purpose-bound, proportionate, and subject to a declared retention policy
03
Execution
Agent uses tools to perform real actions, not just generate text
Permissions · Evidence
Tool use needs valid authorization, bounded side effects, and records of what was approved and executed
04
Adaptation
Agent evolves over time, learning from your feedback and context
Change control · Evaluation
Material changes may alter risk, intended purpose, or regulatory roles and need versioned evaluation
05
Control
You own the governance: switch models without losing your agent
Portability · Revocation
Platform export rights do not automatically make inferred behavior or execution policy portable
06
Continuity
Context persists across sessions: no resets, no starting over
Bounded memory · Erasure
Deletion must cover declared stores, indexes, caches, logs, and backup lifecycles; model unlearning is a separate problem


I. The Authority Hierarchy

A hosted assistant always operates inside more than one authority relationship. The user supplies goals and instructions; the provider sets non-overridable safety and product rules; a developer or enterprise administrator may add another control layer. That hierarchy is legitimate and often necessary, but it means the hosted assistant is not exclusively governed by the individual.

OpenAI: Root > System > Developer > User > Guideline > No Authority

OpenAI's Model Spec explicitly places root, system, and developer instructions above user instructions. This is a product-governance hierarchy: an end user can direct the model only inside constraints established by the provider and, where relevant, the application developer. The observation is not that the hierarchy is improper. It is that platform governance and user governance are different control planes.

OpenAI Model Spec, Dec 2025

“Models should honor user requests unless they conflict with developer-, system-, or root-level instructions.”

Anthropic: Provider, Operator, and User

Anthropic's constitution similarly distinguishes Anthropic's baseline constraints, the operator deploying Claude, and the user. The exact terminology differs, but the design problem is the same: the user's instructions coexist with provider and operator obligations. A sovereign personal layer therefore cannot be inferred from model personalization alone.

Personalization Is Now a Platform Capability

The market has moved beyond session-only assistants. Apple announced Siri AI with personal-context understanding, conversation history synchronized across products, and actions across applications. OpenAI's 2026 memory architecture synthesizes context across conversations and exposes a reviewable memory summary. These products invalidate the claim that major platforms cannot build personal or persistent assistants.

Commercial Incentives Are Part of Governance

OpenAI also operates a ChatGPT advertising platform. OpenAI states that ads remain separate from answers and that conversations are not shared with advertisers. The relevant governance point is narrower: a hosted assistant may have commercial stakeholders and policies beyond the individual user. A user-controlled layer should make recommendation provenance, permissions, and conflicts inspectable rather than assume that any provider's business model is neutral or adverse.

The gap is not personal capability.
It is control of governance across providers and services.

Agent systems sit inside existing privacy, product, consumer, sectoral, and contractual law. Those rules create design requirements and fact-specific exposure; they do not impose a categorical ban on personal agents. The useful question is which obligations attach to a particular intended purpose and which evidence the architecture can produce.

A. EU AI Act (Regulation 2024/1689)

The AI Act's general application date remains August 2, 2026, including Article 50 transparency duties, subject to the specific transition in Regulation (EU) 2026/1744 for certain synthetic-content systems placed on the market before that date. The amending Regulation changed the application dates for the main high-risk requirements: December 2, 2027 for Article 6(2)/Annex III systems and August 2, 2028 for Article 6(1)/Annex I systems.

The design implication is not universal pre-approval. It is a risk-tiered authority model: low-risk actions can operate inside delegated scopes, while consequential actions can require stronger identity, evidence, or intervention controls.

In Colorado, SB26-189 replaced the earlier framework and takes effect January 1, 2027. It focuses on automated decision-making technology used for consequential decisions. This reinforces the need to classify workflows by effect rather than treat every personal-agent feature as regulated in the same way.

B. General Data Protection Regulation

Persistent assistants can process detailed personal histories, inferred preferences, and sensitive context. GDPR analysis therefore begins with controller and processor roles, lawful basis, purpose limitation, data minimization, retention, security, and data-subject rights. Automated decision-making is an additional, narrower issue.

Enforcement outcomes must also be stated with their current procedural status. The Italian Garante imposed a EUR 15 million fine on OpenAI in December 2024, but the Court of Rome upheld OpenAI's appeal in judgment No. 4153/2026, published March 18, 2026; the Garante temporarily removed the underlying decision from its website. The original fine should not be presented as an undisturbed final precedent.

C. Product Liability (Directive 2024/2853)

The revised Product Liability Directive expressly includes software as a product and applies to products placed on the market or put into service after December 9, 2026. A software developer or AI-system provider can be treated as a manufacturer when the statutory conditions are met.

This makes traceability, controlled updates, safety evaluations, and evidence preservation economically important. It does not make the exposure inherently unbounded or uninsurable, and it does not assign all liability to the end user merely because the user authorized an action.

D. Agency Law and Fiduciary Duty

Calling software an “agent” does not settle its legal status. Agency, employment, product, professional-duty, and intermediary questions turn on facts such as control, manifestation of authority, reliance, contractual allocation, intended purpose, and the law governing a particular relationship.

Product labels do not allocate legal responsibility.
Control, conduct, representations, and context do.

Cross-service autonomy also needs a valid integration basis. User consent does not by itself override a third party's authentication rules, contractual terms, technical access controls, intellectual-property rights, or applicable computer-misuse law. A credible personal layer therefore needs explicit adapters: authorized APIs and delegation flows where available, read-only access where lawful, and interactive user control where authorization or risk is uncertain.

Section 230 and analogous intermediary protections cannot be assumed to cover generated outputs or autonomous conduct. Their application is unsettled and claim-specific. System design should therefore rely on scoped authority, safe execution, and evidence rather than a categorical safe-harbor theory.

Ayres & Balkin, U. Chicago Law Review (2024)

“People should not be able to obtain a reduced duty of care by substituting AI for a human agent.”

E. Financial Regulation

A general-purpose agent can enter a regulated perimeter when it recommends, arranges, or executes financial activity. The resulting obligations depend on who provides the service, what the system does, which instruments and customers are involved, and the jurisdiction. No architecture can replace that activity-level analysis.

F. Discovery and Insurance

Insurance coverage for AI-related risks does exist, including technology errors and omissions, cyber, media, product-liability, and specialist AI offerings. In March 2026, HSB, part of Munich Re, announced AI liability coverage for small businesses; Munich Re and Mosaic also market aiSure for defined AI-performance failures. Coverage remains heterogeneous, with limits, exclusions, aggregation concerns, and underwriting requirements that may leave material gaps for highly autonomous systems.

This creates a concrete design opportunity. Permission scopes, evaluation records, incident controls, and execution receipts can improve the evidence available to operators, auditors, and underwriters. They do not guarantee coverage or compliance, but they make risk more legible.

Law does not prohibit the personal agent category.
It rewards explicit authority, bounded risk, and usable evidence.

III. The Structural Conflict

Hosted assistants can be useful, personal, and responsibly governed. The structural limitation is narrower: a platform-controlled product cannot give the user final control over rules that the platform itself must retain the power to change. Provider policy, operator configuration, commercial incentives, service availability, and user preference coexist in one stack.

Dimension
Hosted Assistant Layer
User-Controlled Governance Layer
Authority
Provider and operator rules constrain user instructions
User-defined delegation within explicit legal and technical boundaries
Memory
Persistent but provider-controlled state
Portable state with declared provenance and lifecycle
Autonomy
Provider-defined capability and approval ceilings
Risk-tiered, user-defined scopes and revocation
Loyalty
Provider, operator, user, and sometimes advertiser interests
Visible conflicts and user-selected policy
Economics
Subscription, platform, enterprise, or advertising economics
Transparent service economics and exportable state
Persistence
Dependent on provider availability and policy
Model-agnostic continuity with recoverable exports

OpenAI's 2026 ads pilot makes this multi-stakeholder reality visible. OpenAI states that ads do not influence answers and that advertiser access does not include private conversations. Those safeguards matter. The architectural point is not to allege hidden influence; it is that durable personal governance should be independently inspectable even when a provider changes products, policies, or revenue models.

As an agent moves from retrieval toward persistent profiling and consequential execution, its risk changes. The correct response is not a universal ban or an unlimited user mandate. It is graduated authority: stronger authentication, narrower scopes, more evidence, and higher approval thresholds as impact rises.

A provider can personalize the assistant.
Only an independent layer can keep governance portable across providers.

IV. ODEI's Architectural Solution

ODEI addresses the governance gap by separating governed state and execution policy from the intelligence provider. A model is treated as a replaceable, probabilistic reasoning component. Persistent state, policy, credentials, provenance, and execution controls belong to a user-controlled layer with explicit interfaces and export paths.

Some controls can be deterministic; others rely on classification, evaluation, human judgment, or external services. This separation can support compliance and reduce lock-in, but architecture alone does not establish lawful basis, regulatory classification, conformity, or liability allocation.

Agency and Liability

The World Model records goals, constraints, policies, and evidence under user control. That design does not predetermine legal roles. Depending on how ODEI is developed, marketed, configured, and operated, ODEI, an integrator, a model provider, a deployer, or a user may carry different and sometimes overlapping duties. The architecture should make those control boundaries observable rather than rely on the label “toolmaker.”

Automated Decision-Making GDPR Art. 22

The Guardian pattern evaluates proposed actions against explicit rules and can route higher-risk actions to user review. A machine policy check is not automatically “human in the loop,” and a user-authored rule does not itself remove Article 22 exposure. The value is a reviewable workflow that distinguishes model proposals, machine policy decisions, user approvals, and external execution.

Meaningful Information GDPR Arts. 13–15

The provenance pattern Signal → Decision → Action → Outcome can record timestamps, sources, relevant inputs, policy references, approvals, and execution results. That path can contribute to the process-level explanation described by the CJEU. It is useful only if it reflects the procedure actually used and avoids replacing evidence with a model-generated rationale.

Right to Erasure GDPR Art. 17

Deleting a graph node can make information unavailable from the active graph, but that is only one part of erasure. A defensible claim must define the ODEI memory boundary and verify treatment of derived nodes, indexes, caches, logs, replicas, backups, and downstream exports. The accurate objective is verifiable unavailability within a declared system boundary and lifecycle, not a mathematical guarantee that no model or external system can ever reproduce or act on related information.

Data Portability GDPR Art. 20

ODEI is designed to keep state and policy independent of a single model. Portability requires documented, versioned export formats for memory, policy, provenance, and credentials where those credentials can lawfully be transferred. GDPR Article 20 has its own scope and does not automatically cover every inference or learned behavior; ODEI can offer broader product portability as an architectural commitment.

MCP can connect applications to tools and context, while A2A can support agent-to-agent interoperability. Neither protocol guarantees least privilege, legal authorization, data portability, or safe execution by itself. ODEI must enforce those properties in adapters, credential scopes, policy, and evidence records.

Permission Topology

Cross-platform autonomy requires a permission topology: authorized APIs and delegation flows where services offer them, narrow read access where lawful, transaction limits, credential isolation, and interactive user control for consequential or ambiguous actions. Governance independence must be paired with a realistic integration doctrine; it cannot bypass third-party rights or access controls.

Provability

The practical advantage is evidence production. Oversight measures can map to intervention points and override logs. Article 22 analysis can use workflow records that distinguish automation from meaningful human involvement. Product-safety analysis can use versioned evaluations, incidents, and change records. These artifacts support an inquiry; they are not conclusive proof of compliance on their own.

Discovery and Audit

A local-first design can reduce unnecessary central collection and keep the primary audit trail under user control. Records may still be subject to legal holds, disclosure duties, security incidents, synchronization, or third-party retention. The audit system therefore needs configurable retention, integrity verification, selective export, and documented deletion behavior.

ODEI separates user-controlled state, policy, and evidence from probabilistic, replaceable intelligence providers.

The separation does not guarantee compliance. It makes authority boundaries, intervention, portability, and proof more explicit and testable.


V. Research Theses

Thesis I The next bottleneck is governed persistence, not memory alone.

Leading assistants now maintain cross-session context. The unresolved engineering problem is persistent state with provenance, permissions, lifecycle controls, and predictable effects across time. Larger context windows and memory synthesis help recall; they do not by themselves establish governed state.

Thesis II Memory without governance is recall, not agency.

Retrieving a preference is not the same as having authority to act on it. A personal agent needs structured memory, explicit policy, scoped permissions, intervention paths, and execution evidence. These controls may combine deterministic rules with evaluated models and human review according to risk.

Memory without governance is recall, not agency.
Thesis III A true personal agent requires a Persistent Digital World Model.

This model represents the human–agent decision environment: goals, constraints, decisions, signals, provenance, and approved policies. A user should be able to correct or delete active state and verify the result across the declared memory boundary. That is a bounded systems claim, distinct from removing information from every model, backup, or external service.

Thesis IV The personal AI layer must be owned by the individual.

Model markets may combine centralized and open providers. Regardless of market structure, the personal layer should keep its core state, governance, and execution policy portable across compatible providers. Portability requires maintained adapters and cannot override third-party access rules.

Thesis V Autonomous agents require constitutional control.

Once an agent can observe, decide, act, and verify, it needs explicit rules for authority, escalation, and revocation. High-impact execution should not depend solely on prompt instructions. Controls should be decoupled from any one model and tested against the consequences they are intended to limit.

Thesis VI Personal agents are the wedge. Agent infrastructure is the scaling layer.

The first step is a governed personal agent operating within delegated authority. The next is coordination between agents with verifiable identity, scopes, commitments, receipts, and dispute paths. Personal governance primitives can become building blocks for accountable multi-agent networks.


Personal assistants can be platform-built.
Personal governance should remain portable.

The governance gap is not proof that major platforms cannot build agents. It is the difference between personalization inside a provider's control plane and a user-controlled layer that carries authority, state, policy, and evidence across providers. Regulation does not resolve that design choice, but it makes the quality of those controls increasingly consequential.

References

  1. Regulation (EU) 2024/1689 (EU AI Act), including Arts. 6, 9, 12, 14, 43 and Annex III. Official text
  2. Regulation (EU) 2026/1744, amending AI Act application dates and other provisions. Official text
  3. Regulation (EU) 2016/679 (GDPR), including Arts. 13–15, 17, 20, 22 and 25. Official text
  4. CJEU, C-634/21, SCHUFA Holding, Dec. 7, 2023. Court record
  5. CJEU, C-203/22, Dun & Bradstreet Austria, Feb. 27, 2025. Court record
  6. Directive (EU) 2024/2853 (Product Liability Directive), consolidated text including the May 2026 corrigendum. Official text
  7. Colorado SB26-189, Automated Decision-Making Technology. Colorado General Assembly
  8. OpenAI, Model Spec, Dec. 18, 2025. Model Spec
  9. Anthropic, Claude's Constitution, Jan. 2026. Anthropic
  10. Apple, “Apple introduces Siri AI,” June 8, 2026. Apple Newsroom
  11. OpenAI, “Dreaming: Better memory for a more helpful ChatGPT,” June 4, 2026. OpenAI
  12. OpenAI, “New ways to buy ChatGPT ads,” May 5, 2026. OpenAI
  13. Model Context Protocol, specification release 2026-07-28. MCP
  14. Agent2Agent Protocol, specification version 1.0.0. A2A
  15. Mobley v. Workday, Inc., No. 3:23-cv-00770-RFL (N.D. Cal.), order on motion to dismiss, July 12, 2024. Filed order (PDF)
  16. Moffatt v. Air Canada, 2024 BCCRT 149. BC Civil Resolution Tribunal
  17. FINRA, 2026 Annual Regulatory Oversight Report, GenAI: Continuing and Emerging Trends. FINRA
  18. SEC, In the Matter of Two Sigma Investments, LP, Admin. Proc. File No. 3-22418, Jan. 16, 2025. SEC order
  19. Irish Data Protection Commission, Meta Platforms Ireland decision announcement, Dec. 2024. DPC
  20. Italian Garante, OpenAI proceeding notice, updated after Rome Court judgment No. 4153/2026. Garante
  21. HSB, “HSB Introduces AI Liability Insurance for Small Businesses,” Mar. 18, 2026. HSB / Munich Re
  22. Munich Re, aiSure AI performance insurance. Munich Re
  23. NIST, Machine Unlearning terminology. NIST