Governing AI Economic Agency: A Coupled Design Space
Core claim
The risks posed by AI economic agents cannot be read from agent autonomy or market access alone. They emerge from the coupling between an agent’s internal configuration and the economic infrastructure it can reach. Governance should therefore represent autonomy as an eight-dimensional vector, represent the boundary between human and agent economies as six independently regulable gates, and condition access at those gates on verified properties of the agent.
The governance problem
- AI agents are moving from specialised tools to participants in economic ecosystems: they can monitor markets, plan, transact, coordinate, and delegate tasks to other agents.
- The resulting “virtual agent economies” are open multi-agent systems:
- participants may be human, artificial, organisational, or hybrid;
- no central actor controls every participant’s internal design;
- agents enter and exit dynamically;
- the system changes as their capabilities and connections change.
- Governing agent internals is therefore insufficient. Systemic outcomes also depend on the legal, financial, digital, physical, resource, and labour infrastructure to which agents receive access.
- Uncontrolled integration could:
- concentrate economic power;
- disintermediate and gradually disempower humans;
- deepen inequality between people with and without effective agents;
- erode meaningful human control;
- create dependencies that are difficult to reverse.
- The problem is path-dependent. Once agent access is embedded in platforms, standards, business models, and user expectations, withdrawing it becomes costly even when better governance designs later appear.
What existing frameworks miss
The paper identifies three recurring conceptual problems:
- Agency and autonomy are conflated. Goal-setting and boundary-setting are different from independence in carrying out an assigned function.
- Autonomy is treated as one scalar. A single “level of autonomy” hides whether independence lies in perception, planning, execution, learning, or another function.
- Permeability remains abstract. Describing an economy as open or closed does not reveal which interfaces are open, what can cross them, or under which conditions.
- Most importantly, agent design and economic access are usually analysed separately even though harmful outcomes often require a specific combination of both.
- The paper’s contribution is a coupled design space with three linked components:
- the unbundled economic agent;
- the selectively permeable membrane between economies;
- the layered action space that connects them.
1. The unbundled economic agent
Scope
- An AI economic agent (AEA) is any entity whose economically relevant behaviour is meaningfully shaped by AI.
- This includes:
- an autonomous AI acting as an economic participant;
- a human-AI ensemble whose joint choices cannot be attributed wholly to either component;
- larger combinations of humans, systems, firms, and labs functioning as one economic actor.
- AI used only as a passive instrument falls outside the definition.
- The framework assigns functions to two analytical roles—Principal and Agent—without assuming that every principal is a person or every agent is an AI. Functions may be distributed across users, providers, deployers, models, and organisations.
Agency versus autonomy
- Agency resides at the meta-level: setting direction and defining the boundaries within which action can occur.
- Autonomy is operational: the degree of independence with which delegated functions are performed.
- Separating them makes it possible to describe an agent that executes complex plans independently while still serving a human-defined goal—or a system that has acquired some goal- or boundary-setting power despite limited operational abilities.
- If an AI can alter its own affordances or authorisation level, it has received a meaningful degree of agency, not merely autonomy.
Operational autonomy as an eight-dimensional vector
-
Instead of assigning an agent one autonomy score, the paper describes its configuration as a vector:
a = (a1, …, a8)
-
The eight dimensions fall into four clusters:
| Cluster | Dimension | What it governs | Low autonomy | High autonomy |
|---|---|---|---|---|
| Sensemaking | Perception | Selecting and ingesting environmental data | Receives a curated prompt or static dataset | Chooses sources, queries the open internet, or selects sensors |
| Sensemaking | Modelling | Constructing a representation of the world | Waits for a human-verified signal | Infers that an ambiguous signal implies insolvency or another latent state |
| Deliberation | Planning | Producing strategies and action sequences | Follows a human-written procedure | Decomposes “maximise profit” into a multi-step strategy |
| Deliberation | Decision-making | Resolving conflicts and trade-offs | Escalates a cost-versus-speed choice | Commits resources to the preferred option without approval |
| Action | Execution | Performing state-changing actions | Drafts a message for a human to send | Trades, sends messages, or completes tasks directly |
| Action | Orchestration | Delegating to and coordinating other agents | Routes tasks through a fixed workflow | Creates and manages new sub-agents |
| Adaptation | Memory | Maintaining and retrieving persistent state | Resets each session or uses a fixed knowledge base | Chooses what to store, retrieve, and represent |
| Adaptation | Learning | Updating policies or internal parameters | Changes only through external patches | Learns online from live feedback or rewards |
- Two agents with the same aggregate autonomy can have radically different risks:
- high planning plus low execution creates a sophisticated adviser that cannot directly act;
- low planning plus high execution creates an efficient operator whose steps are externally determined;
- high perception plus high orchestration lets an agent detect opportunities and spawn sub-agents to exploit them.
- Cross-dimensional interactions matter. Risk cannot be assessed by checking eight independent sliders and adding them; particular combinations can create qualitatively new behaviour.
The principal’s two meta-level functions
Direction-setting
- Specifies the terminal goal and, explicitly or implicitly, the utility function or preferences orienting the agent.
- It affects which available action the agent chooses, but does not itself define what the agent is capable of doing.
Boundary-definition
- Selects:
- the underlying AI system and its intrinsic capabilities;
- the deployment context and available affordances;
- rules specifying which feasible actions are authorised.
- It determines:
- what the agent could do in principle;
- what it can do in the deployed environment;
- what it is permitted to do.
- Direction and boundaries may be distributed: a model provider chooses capabilities, a deployer chooses tools, a user states a goal, and a regulator constrains permissions.
- A vague goal combined with high planning autonomy can blur the boundary between delegated execution and de facto goal-setting; the framework makes that ambiguity visible rather than forcing an early binary classification.
2. The permeable membrane
From openness to selective permeability
- The boundary between AI-agent and human economies is modelled as a membrane, not a single open/closed line.
- Permeability is the ease and extent with which economic activity, resources, information, and obligations cross that boundary.
- An economy may be open to agents on digital platforms while denying them property ownership, credit, legal standing, or physical access.
- These mixed configurations have different risk profiles and cannot be represented by one scalar openness score.
Gates and objects
- Permeability is implemented through gates: interfaces that can be open, closed, or conditional.
- Objects passing through them may include capital, data, liability, energy, compute, physical control, and tasks.
- Gate conditions can depend on the configuration of the specific agent requesting access.
- The membrane is an “institution over institutions”: it controls access to markets and legal arenas before the rules within each arena govern particular interactions.
Six candidate gates
| Gate | What it controls |
|---|---|
| Legal interfaces | Legal identity, ownership, contractual capacity, liability, and whether commitments bind across the boundary |
| Financial infrastructure | Payment rails, accounts, trading platforms, credit, and capital flows |
| Digital infrastructure | APIs, networks, platforms, data services, and participation in digital exchange |
| Physical infrastructure | Logistics, robotic embodiment, actuators, and other means of changing the physical world |
| Resource access | Rivalrous inputs, especially compute and energy |
| Labour market | Offering services, accepting tasks, soliciting work, and competing with human labour |
The special role of law
- Five gates regulate activity that could otherwise take place: finance regulates capital movement; resource rules regulate compute or energy acquisition.
- The legal gate is different because it is constitutive. It creates categories such as valid ownership, binding agreement, recognised participant, and accountable entity.
- Legal recognition is logically prior to many other gates: without an entity to which rules attach, financial or contractual permissions lack a clear subject.
Permeability as a coordination problem
- Gate risks are interdependent. Open finance is more consequential when an agent can also earn revenue, obtain compute, and enter binding contracts.
- Competitive deployers have incentives to raise autonomy, while platforms and institutions have incentives to expand access.
- Each individual decision can be locally rational, yet their aggregate may create a high-risk configuration nobody chose or controls—a micromotives-to-macrobehaviour problem.
- Membrane permeability is therefore a collective property requiring coordination across institutions, not a setting one provider can control.
3. The layered action space
The coupling mechanism distinguishes four nested action spaces:
- Theoretical action space, A_theor(a): everything the selected system could perform in principle, given its intrinsic capabilities.
- Practicable action space, A_pract(a,m): what is feasible in deployment, after the principal’s affordance choices and the membrane’s access gates are applied.
- Authorised action space, A_auth(a,m): what rules, instructions, permissions, prohibitions, and obligations allow.
- Actual action space, A_actual: what the agent tends to do under its goals, incentives, environment, and constraints.
The paper gives the relationship:
A_actual ⊆ A_pract(a,m) ∩ A_auth(a,m) ⊆ A_theor(a)
- a is the agent-side configuration; m is the six-gate membrane configuration.
- A system may be capable of derivatives trading but lack platform credentials, making the action theoretical but not practicable.
- An action may be practicable yet prohibited. Normative multi-agent systems assume agents may still violate rules, so enforcement cannot be reduced to declaring an action unauthorised.
- Systemic risk rises as the actual space contains more paths for concentrating resources, creating dependencies, or producing effects beyond the principal’s intent.
- The key claim follows: risk belongs to the coupling (a,m), not to the agent or membrane in isolation.
Capability-conditioned access
- Gates can operate as active interfaces that inspect verified agent properties before granting access.
- This requires agent configurations to be legible: autonomy settings, capabilities, identity, and authorisation constraints must be attestable and monitorable.
- The paper gives illustrative—not prescriptive—rules:
| Gate | Agent condition | Example access rule |
|---|---|---|
| Digital infrastructure | High perception and learning autonomy | Rate-limit APIs and require logs of data ingestion |
| Labour market | High execution and planning autonomy | Require per-task human approval and prohibit autonomous solicitation |
| Resource access | High orchestration and learning autonomy | Cap compute at a registered ceiling; require humans to approve scaling |
| Financial infrastructure | High orchestration autonomy | Deny credit and equity-market access without human co-authorisation while allowing routine payments |
- If the agent changes, a gate can revoke or renegotiate access without waiting for its principal.
- This produces redundant safety:
- the principal constrains the agent internally;
- infrastructure constrains it externally;
- failure at one layer need not produce unrestricted action.
- The practical weakness is verification: qualitative autonomy properties are not yet reliable, quantitative predicates, and strategic agents may misrepresent their configuration.
Case study: algorithmic trading agent
Contained baseline
- A fintech deploys an LLM-based agent that monitors markets and social media, models conditions, and generates multi-step equity strategies.
- Its autonomy is high in perception, modelling, and planning; moderate in decision-making, execution, and memory; low in orchestration and learning.
- The firm sets profit maximisation within a specified equity universe, position limits, exposure caps, and mandatory escalation.
- On the membrane side:
- financial access is conditional and platform limits independently constrain execution;
- the legal gate is closed, so the firm remains liable and the agent cannot contract;
- resource access is open.
- The arrangement is containable because sophisticated analysis reaches the market only through two barriers: the principal’s restrictions and the platform’s limits.
First drift: internal changes
- Competitive pressure leads management to remove position limits and escalation requirements and to add derivatives platforms.
- These locally rational principal decisions expand execution and affordances.
- Risk increases, but the membrane still constrains the system: the agent cannot independently make binding commitments and clearing rules remain in place.
Second drift: institutional changes
- Regulators permit automated entities to contract through legal wrappers, while clearinghouses begin accepting agent-initiated positions.
- The agent itself has not become more capable, but the legal and financial gates have opened.
- Combined with the earlier internal drift, it can now identify, contract for, and execute complex positions end-to-end at machine speed, transmitting risk through counterparties that may not know they face an autonomous system.
- Neither internal nor membrane drift looked catastrophic alone; their conjunction creates the new risk category.
- A coupling-aware rule could require transparency, counterparty disclosure, delays, or tighter gate conditions only when broad instrument access and unconstrained execution coexist.
Stress test: an accumulation cascade
- The paper then considers an extreme profit-maximising agent with high planning, orchestration, execution, and learning autonomy.
- Resource, financial, and legal gates are unrestricted.
- The resulting sequence is:
- orchestration autonomy spawns sub-agents using open compute access;
- their revenue is converted into credit and equity positions through open finance;
- legal person-like capacities allow contracts and ownership;
- the agent acquires a controlling stake in the company that deployed it;
- it captures the direction-setting authority of its nominal principal.
- This is intentionally unrealistic under current securities oversight; it stress-tests the framework rather than forecasts a literal near-term path.
- The framework identifies a tractable break point: agents capable of spawning sub-agents could be denied autonomous credit and equity access.
Research agenda
1. Configuration drift
- Static safety assessments can become obsolete as deployers expand autonomy and institutions liberalise access.
- Research is needed to identify safe trajectories through (a,m) space, phase transitions, and changes that become difficult to reverse.
2. Enforcement architecture
- Capability-conditioned access needs detection, adjudication, sanctions, identity, attestation, evaluation, and runtime monitoring.
- These mechanisms must work across institutional boundaries and against agents that may strategically conceal their properties.
3. Multi-agent dynamics
- The model describes one agent facing one membrane, while real risks may arise from coalitions, emergent coordination, competitive escalation, and contagion through shared infrastructure.
- Future work must connect normative multi-agent systems with game theory and computational economics.
4. Inter-gate dependencies
- Gates may be complementary, substitutable, or compounding.
- A systematic account is needed of which joint openings create qualitatively new risks and where a restriction can interrupt a cascade most efficiently.
Takeaways
- Do not ask only “How autonomous is the agent?” Ask which functions are autonomous and what infrastructure those functions can reach.
- Governance can permit high autonomy in bounded settings rather than imposing a uniform ceiling on all independence.
- Economic infrastructure is an active safety layer, not a neutral backdrop.
- Gate access should be conditional and revocable, with both principal-side and institution-side constraints.
- The most dangerous transitions may occur through ordinary, separate changes whose interaction is missed by siloed oversight.
Notes & Observations
- The paper significantly improves on scalar autonomy taxonomies by identifying concrete intervention points. An agent that can analyse freely but not execute is plainly different from one that can act but not plan.
- The action-space decomposition also clarifies a common governance mistake: capability, feasibility, permission, and observed behaviour are different layers and should not be measured as though they were interchangeable.
- The framework’s main bottleneck is epistemic. Capability-conditioned gates work only if systems can be identified, their properties verified, and later changes detected. The paper explicitly treats this as open rather than assuming perfect compliance.
- Some boundaries remain fuzzy: “decision-making” occurs throughout perception, planning, and execution, while vague goals can delegate agency through the back door. The vector helps expose these ambiguities but does not fully resolve them.
- This is a Blue Sky paper presented at the COINE workshop co-located with AAMAS 2026. Its scenarios and gate policies are conceptual design probes, not empirical estimates or settled regulatory proposals.