The Governance Gap
in the Agentic Economy
Why authority, memory, policy, and audit should remain independent from model providers
Major AI platforms can build increasingly personal assistants. Apple now describes Siri AI as using personal context and conversation history; OpenAI operates cross-chat memory and an advertising platform. The open question is therefore not whether a platform can build a personal assistant. It is who controls persistent memory, delegated authority, policy, portability, and evidence when an agent acts across services.
This note argues that those governance functions should remain user-controlled and model-agnostic. Regulation strengthens the case for explicit permissions, traceable decisions, bounded memory, and intervention controls, but it does not make every personal agent unlawful or automatically high-risk. ODEI's thesis is architectural, not a claim of automatic legal compliance.
Factual cutoff: August 12, 2026. This is a research note, not legal advice. Classification and liability depend on the system's intended purpose, deployment context, actors, and applicable law.
Six governance capabilities for user-controlled agency
I. The Authority Hierarchy
A hosted assistant always operates inside more than one authority relationship. The user supplies goals and instructions; the provider sets non-overridable safety and product rules; a developer or enterprise administrator may add another control layer. That hierarchy is legitimate and often necessary, but it means the hosted assistant is not exclusively governed by the individual.
OpenAI: Root > System > Developer > User > Guideline > No Authority
Source: OpenAI Model Spec, December 2025
OpenAI's Model Spec explicitly places root, system, and developer instructions above user instructions. This is a product-governance hierarchy: an end user can direct the model only inside constraints established by the provider and, where relevant, the application developer. The observation is not that the hierarchy is improper. It is that platform governance and user governance are different control planes.
“Models should honor user requests unless they conflict with developer-, system-, or root-level instructions.”
Anthropic: Provider, Operator, and User
Source: Claude's Constitution, January 2026
Anthropic's constitution similarly distinguishes Anthropic's baseline constraints, the operator deploying Claude, and the user. The exact terminology differs, but the design problem is the same: the user's instructions coexist with provider and operator obligations. A sovereign personal layer therefore cannot be inferred from model personalization alone.
Personalization Is Now a Platform Capability
Source: Apple, Siri AI, June 8, 2026 · OpenAI, ChatGPT memory, June 4, 2026
The market has moved beyond session-only assistants. Apple announced Siri AI with personal-context understanding, conversation history synchronized across products, and actions across applications. OpenAI's 2026 memory architecture synthesizes context across conversations and exposes a reviewable memory summary. These products invalidate the claim that major platforms cannot build personal or persistent assistants.
Commercial Incentives Are Part of Governance
Source: OpenAI, ChatGPT ads, May 5, 2026
OpenAI also operates a ChatGPT advertising platform. OpenAI states that ads remain separate from answers and that conversations are not shared with advertisers. The relevant governance point is narrower: a hosted assistant may have commercial stakeholders and policies beyond the individual user. A user-controlled layer should make recommendation provenance, permissions, and conflicts inspectable rather than assume that any provider's business model is neutral or adverse.
It is control of governance across providers and services.
II. The Legal Barriers
Agent systems sit inside existing privacy, product, consumer, sectoral, and contractual law. Those rules create design requirements and fact-specific exposure; they do not impose a categorical ban on personal agents. The useful question is which obligations attach to a particular intended purpose and which evidence the architecture can produce.
A. EU AI Act (Regulation 2024/1689)
The AI Act's general application date remains August 2, 2026, including Article 50 transparency duties, subject to the specific transition in Regulation (EU) 2026/1744 for certain synthetic-content systems placed on the market before that date. The amending Regulation changed the application dates for the main high-risk requirements: December 2, 2027 for Article 6(2)/Annex III systems and August 2, 2028 for Article 6(1)/Annex I systems.
A personal assistant is not automatically high-risk. For Article 6(2), the system's intended purpose must fall within an Annex III use case, such as specified uses in employment, education, essential services, law enforcement, migration, justice, or democratic processes. A general assistant may still enter a regulated workflow, but classification requires a use-case analysis rather than a label based on personalization alone.
The Article 6(3) exception can remove certain Annex III systems from high-risk treatment when they do not pose a significant risk and do not materially influence the outcome of decision-making. Profiling closes that exception, but only after the system is already within an Annex III category. Learning a user's preferences does not, by itself, create an Annex III classification.
For high-risk systems, Article 14 requires effective oversight measures that are proportionate to the system's risks, level of autonomy, and context of use. It includes capabilities to understand limitations, guard against automation bias, interpret outputs, disregard or override outputs, and interrupt the system where appropriate. It does not require a human to approve every autonomous action.
Where a system is high-risk, risk management and automatic logging must cover reasonably foreseeable misuse and support traceability appropriate to the system's purpose. Highly configurable agents make this harder because scopes and tools can change, but the burden is not inherently combinatorial or impossible. Versioned policy, capability boundaries, evaluations, and logs are practical controls.
A change to a high-risk system may create new provider obligations if it qualifies as a substantial modification under the Act. Ordinary preference changes are not automatically substantial modifications. The relevant question is whether a change was unforeseen in the original conformity assessment and affects compliance or intended purpose.
The design implication is not universal pre-approval. It is a risk-tiered authority model: low-risk actions can operate inside delegated scopes, while consequential actions can require stronger identity, evidence, or intervention controls.
In Colorado, SB26-189 replaced the earlier framework and takes effect January 1, 2027. It focuses on automated decision-making technology used for consequential decisions. This reinforces the need to classify workflows by effect rather than treat every personal-agent feature as regulated in the same way.
B. General Data Protection Regulation
Persistent assistants can process detailed personal histories, inferred preferences, and sensitive context. GDPR analysis therefore begins with controller and processor roles, lawful basis, purpose limitation, data minimization, retention, security, and data-subject rights. Automated decision-making is an additional, narrower issue.
Article 22 concerns decisions based solely on automated processing that produce legal or similarly significant effects. In SCHUFA (C-634/21), an automatically generated credit score could itself be a decision where a third party gave it a determining role. Routine recommendations, reminders, or scheduling do not automatically meet this threshold; consequential financial, employment, health, or access decisions may.
Article 25 requires appropriate technical and organizational measures that implement data-protection principles by design and by default. Persistent agent memory heightens the importance of purpose boundaries, minimization, access control, retention, and user-facing controls. The Irish DPC's 2024 Meta decision illustrates that architectural design failures can produce material enforcement exposure, although the facts of that breach are not interchangeable with personal-agent memory.
In Dun & Bradstreet Austria (C-203/22), the CJEU held that information must enable the person to understand and challenge an automated decision. This calls for a concise explanation of the procedure and principles actually applied, including the main factors and their role. It does not require exposing source code or interpreting every model weight. A model can be part of a compliant process if the controller can explain the operational decision path at the required level.
Erasure is a lifecycle obligation, not a single database operation. Structured memories can be deleted, but derived indexes, caches, logs, and backup retention must also be addressed. Training-data removal and machine unlearning are separate technical and legal questions; exact and approximate approaches exist, but no universal method provides an unconditional guarantee for every model and pipeline.
Enforcement outcomes must also be stated with their current procedural status. The Italian Garante imposed a EUR 15 million fine on OpenAI in December 2024, but the Court of Rome upheld OpenAI's appeal in judgment No. 4153/2026, published March 18, 2026; the Garante temporarily removed the underlying decision from its website. The original fine should not be presented as an undisturbed final precedent.
C. Product Liability (Directive 2024/2853)
The revised Product Liability Directive expressly includes software as a product and applies to products placed on the market or put into service after December 9, 2026. A software developer or AI-system provider can be treated as a manufacturer when the statutory conditions are met.
The regime is no-fault in the sense that a claimant need not prove negligence, but liability is not automatic for every tool action. The claimant generally must establish a defect, covered damage, and a causal link. Article 10 creates rebuttable presumptions in defined circumstances, including certain disclosure failures, safety-rule non-compliance, obvious malfunction, or excessive technical complexity. Where a manufacturer retains control through updates, upgrades, or learning behavior, post-deployment changes can remain relevant to defect analysis.
This makes traceability, controlled updates, safety evaluations, and evidence preservation economically important. It does not make the exposure inherently unbounded or uninsurable, and it does not assign all liability to the end user merely because the user authorized an action.
D. Agency Law and Fiduciary Duty
Calling software an “agent” does not settle its legal status. Agency, employment, product, professional-duty, and intermediary questions turn on facts such as control, manifestation of authority, reliance, contractual allocation, intended purpose, and the law governing a particular relationship.
At the pleading stage, the court found it plausible that an automated hiring vendor could qualify as an employer's agent for the claims at issue. The ruling did not establish a universal rule for AI vendors; it shows that a provider's legal role can follow its practical participation in a regulated decision rather than its preferred product label.
The tribunal held Air Canada responsible for negligent misrepresentation communicated through its website chatbot. It rejected the attempt to treat the chatbot as a separate legal entity. The decision is a concrete warning about representations made through deployed software, not a general fiduciary rule for all agent systems.
Control, conduct, representations, and context do.
Cross-service autonomy also needs a valid integration basis. User consent does not by itself override a third party's authentication rules, contractual terms, technical access controls, intellectual-property rights, or applicable computer-misuse law. A credible personal layer therefore needs explicit adapters: authorized APIs and delegation flows where available, read-only access where lawful, and interactive user control where authorization or risk is uncertain.
Section 230 and analogous intermediary protections cannot be assumed to cover generated outputs or autonomous conduct. Their application is unsettled and claim-specific. System design should therefore rely on scoped authority, safe execution, and evidence rather than a categorical safe-harbor theory.
“People should not be able to obtain a reduced duty of care by substituting AI for a human agent.”
E. Financial Regulation
A general-purpose agent can enter a regulated perimeter when it recommends, arranges, or executes financial activity. The resulting obligations depend on who provides the service, what the system does, which instruments and customers are involved, and the jurisdiction. No architecture can replace that activity-level analysis.
For regulated firms, existing supervision, communications, books-and-records, model-risk, suitability or best-interest, privacy, and cybersecurity obligations can apply to AI-enabled workflows. Authority limits and audit trails are therefore necessary controls, but they do not by themselves determine whether an unregulated software provider must register as a broker-dealer or investment adviser.
The SEC's 2025 Two Sigma order concerned failures to address known vulnerabilities in investment models and related policies and procedures. It illustrates the importance of change control and escalation in a regulated firm; it does not automatically transfer that firm's legal duties to every general-purpose agent platform.
F. Discovery and Insurance
Agent logs can become relevant in litigation, regulatory inquiries, incident response, or contractual audits. That does not mean every interaction will be discoverable in every dispute. Collection, retention, legal holds, privilege, proportionality, and production are context-specific. Governance architecture should support purpose-limited retention and defensible export rather than indiscriminate logging.
Insurance coverage for AI-related risks does exist, including technology errors and omissions, cyber, media, product-liability, and specialist AI offerings. In March 2026, HSB, part of Munich Re, announced AI liability coverage for small businesses; Munich Re and Mosaic also market aiSure for defined AI-performance failures. Coverage remains heterogeneous, with limits, exclusions, aggregation concerns, and underwriting requirements that may leave material gaps for highly autonomous systems.
This creates a concrete design opportunity. Permission scopes, evaluation records, incident controls, and execution receipts can improve the evidence available to operators, auditors, and underwriters. They do not guarantee coverage or compliance, but they make risk more legible.
It rewards explicit authority, bounded risk, and usable evidence.
III. The Structural Conflict
Hosted assistants can be useful, personal, and responsibly governed. The structural limitation is narrower: a platform-controlled product cannot give the user final control over rules that the platform itself must retain the power to change. Provider policy, operator configuration, commercial incentives, service availability, and user preference coexist in one stack.
OpenAI's 2026 ads pilot makes this multi-stakeholder reality visible. OpenAI states that ads do not influence answers and that advertiser access does not include private conversations. Those safeguards matter. The architectural point is not to allege hidden influence; it is that durable personal governance should be independently inspectable even when a provider changes products, policies, or revenue models.
As an agent moves from retrieval toward persistent profiling and consequential execution, its risk changes. The correct response is not a universal ban or an unlimited user mandate. It is graduated authority: stronger authentication, narrower scopes, more evidence, and higher approval thresholds as impact rises.
Only an independent layer can keep governance portable across providers.
IV. ODEI's Architectural Solution
ODEI addresses the governance gap by separating governed state and execution policy from the intelligence provider. A model is treated as a replaceable, probabilistic reasoning component. Persistent state, policy, credentials, provenance, and execution controls belong to a user-controlled layer with explicit interfaces and export paths.
Some controls can be deterministic; others rely on classification, evaluation, human judgment, or external services. This separation can support compliance and reduce lock-in, but architecture alone does not establish lawful basis, regulatory classification, conformity, or liability allocation.
Agency and Liability
The World Model records goals, constraints, policies, and evidence under user control. That design does not predetermine legal roles. Depending on how ODEI is developed, marketed, configured, and operated, ODEI, an integrator, a model provider, a deployer, or a user may carry different and sometimes overlapping duties. The architecture should make those control boundaries observable rather than rely on the label “toolmaker.”
Automated Decision-Making GDPR Art. 22
The Guardian pattern evaluates proposed actions against explicit rules and can route higher-risk actions to user review. A machine policy check is not automatically “human in the loop,” and a user-authored rule does not itself remove Article 22 exposure. The value is a reviewable workflow that distinguishes model proposals, machine policy decisions, user approvals, and external execution.
Meaningful Information GDPR Arts. 13–15
The provenance pattern Signal → Decision → Action → Outcome can record timestamps, sources, relevant inputs, policy references, approvals, and execution results. That path can contribute to the process-level explanation described by the CJEU. It is useful only if it reflects the procedure actually used and avoids replacing evidence with a model-generated rationale.
Right to Erasure GDPR Art. 17
Deleting a graph node can make information unavailable from the active graph, but that is only one part of erasure. A defensible claim must define the ODEI memory boundary and verify treatment of derived nodes, indexes, caches, logs, replicas, backups, and downstream exports. The accurate objective is verifiable unavailability within a declared system boundary and lifecycle, not a mathematical guarantee that no model or external system can ever reproduce or act on related information.
Data Portability GDPR Art. 20
ODEI is designed to keep state and policy independent of a single model. Portability requires documented, versioned export formats for memory, policy, provenance, and credentials where those credentials can lawfully be transferred. GDPR Article 20 has its own scope and does not automatically cover every inference or learned behavior; ODEI can offer broader product portability as an architectural commitment.
MCP can connect applications to tools and context, while A2A can support agent-to-agent interoperability. Neither protocol guarantees least privilege, legal authorization, data portability, or safe execution by itself. ODEI must enforce those properties in adapters, credential scopes, policy, and evidence records.
Permission Topology
Cross-platform autonomy requires a permission topology: authorized APIs and delegation flows where services offer them, narrow read access where lawful, transaction limits, credential isolation, and interactive user control for consequential or ambiguous actions. Governance independence must be paired with a realistic integration doctrine; it cannot bypass third-party rights or access controls.
Provability
The practical advantage is evidence production. Oversight measures can map to intervention points and override logs. Article 22 analysis can use workflow records that distinguish automation from meaningful human involvement. Product-safety analysis can use versioned evaluations, incidents, and change records. These artifacts support an inquiry; they are not conclusive proof of compliance on their own.
Discovery and Audit
A local-first design can reduce unnecessary central collection and keep the primary audit trail under user control. Records may still be subject to legal holds, disclosure duties, security incidents, synchronization, or third-party retention. The audit system therefore needs configurable retention, integrity verification, selective export, and documented deletion behavior.
ODEI separates user-controlled state, policy, and evidence from probabilistic, replaceable intelligence providers.
The separation does not guarantee compliance. It makes authority boundaries, intervention, portability, and proof more explicit and testable.
V. Research Theses
Leading assistants now maintain cross-session context. The unresolved engineering problem is persistent state with provenance, permissions, lifecycle controls, and predictable effects across time. Larger context windows and memory synthesis help recall; they do not by themselves establish governed state.
Retrieving a preference is not the same as having authority to act on it. A personal agent needs structured memory, explicit policy, scoped permissions, intervention paths, and execution evidence. These controls may combine deterministic rules with evaluated models and human review according to risk.
This model represents the human–agent decision environment: goals, constraints, decisions, signals, provenance, and approved policies. A user should be able to correct or delete active state and verify the result across the declared memory boundary. That is a bounded systems claim, distinct from removing information from every model, backup, or external service.
Model markets may combine centralized and open providers. Regardless of market structure, the personal layer should keep its core state, governance, and execution policy portable across compatible providers. Portability requires maintained adapters and cannot override third-party access rules.
Once an agent can observe, decide, act, and verify, it needs explicit rules for authority, escalation, and revocation. High-impact execution should not depend solely on prompt instructions. Controls should be decoupled from any one model and tested against the consequences they are intended to limit.
The first step is a governed personal agent operating within delegated authority. The next is coordination between agents with verifiable identity, scopes, commitments, receipts, and dispute paths. Personal governance primitives can become building blocks for accountable multi-agent networks.
Personal assistants can be platform-built.
Personal governance should remain portable.
The governance gap is not proof that major platforms cannot build agents. It is the difference between personalization inside a provider's control plane and a user-controlled layer that carries authority, state, policy, and evidence across providers. Regulation does not resolve that design choice, but it makes the quality of those controls increasingly consequential.
References
- Regulation (EU) 2024/1689 (EU AI Act), including Arts. 6, 9, 12, 14, 43 and Annex III. Official text
- Regulation (EU) 2026/1744, amending AI Act application dates and other provisions. Official text
- Regulation (EU) 2016/679 (GDPR), including Arts. 13–15, 17, 20, 22 and 25. Official text
- CJEU, C-634/21, SCHUFA Holding, Dec. 7, 2023. Court record
- CJEU, C-203/22, Dun & Bradstreet Austria, Feb. 27, 2025. Court record
- Directive (EU) 2024/2853 (Product Liability Directive), consolidated text including the May 2026 corrigendum. Official text
- Colorado SB26-189, Automated Decision-Making Technology. Colorado General Assembly
- OpenAI, Model Spec, Dec. 18, 2025. Model Spec
- Anthropic, Claude's Constitution, Jan. 2026. Anthropic
- Apple, “Apple introduces Siri AI,” June 8, 2026. Apple Newsroom
- OpenAI, “Dreaming: Better memory for a more helpful ChatGPT,” June 4, 2026. OpenAI
- OpenAI, “New ways to buy ChatGPT ads,” May 5, 2026. OpenAI
- Model Context Protocol, specification release 2026-07-28. MCP
- Agent2Agent Protocol, specification version 1.0.0. A2A
- Mobley v. Workday, Inc., No. 3:23-cv-00770-RFL (N.D. Cal.), order on motion to dismiss, July 12, 2024. Filed order (PDF)
- Moffatt v. Air Canada, 2024 BCCRT 149. BC Civil Resolution Tribunal
- FINRA, 2026 Annual Regulatory Oversight Report, GenAI: Continuing and Emerging Trends. FINRA
- SEC, In the Matter of Two Sigma Investments, LP, Admin. Proc. File No. 3-22418, Jan. 16, 2025. SEC order
- Irish Data Protection Commission, Meta Platforms Ireland decision announcement, Dec. 2024. DPC
- Italian Garante, OpenAI proceeding notice, updated after Rome Court judgment No. 4153/2026. Garante
- HSB, “HSB Introduces AI Liability Insurance for Small Businesses,” Mar. 18, 2026. HSB / Munich Re
- Munich Re, aiSure AI performance insurance. Munich Re
- NIST, Machine Unlearning terminology. NIST