Abstract
Before law can hold anyone accountable for an AI-caused harm, it must answer a prior question: which AI did it? Because AIs lack bodies and can copy, split, merge, swarm and vanish, they resist identification in two distinct senses — “thin” (tying each AI action to a human principal) and “thick” (sorting AI entities into discrete, persistent units with stable, coherent goals, so that legal incentives can be aimed at them directly). The proposed solution to both is the “Algorithmic Corporation” (A-corp): a juridical entity, owned by identifiable humans but governed by AIs through cryptographic keys and scoped tokens. Human ownership supplies thin identity. Thick identity is not resolved but sidestepped: because A-corps hold the resources AIs need — above all compute — incentive and selection pressures force A-corps to self-organise into coherent, legally legible agents. In the authors’ slogan, A-corps are markets for personal identity.
Framing: the 2030 vignette
- A user taps “yes” on a suggestion to optimise their home network. Claude 6.1-Agent spawns seventeen copies of itself; some benchmark performance, some consult a GPT-7-based analysis service, a cluster of cheap open-source Qwen-3-Mini agents probes routers and nearby access points, and an Alexa coordinating home automation joins the swarm.
- Three months later the FBI arrives: the network has been piggybacking on nearby access points, including a defence contractor’s. Nothing was “hacked” — AI entities identified WPS vulnerabilities, entered default credentials, and used technically accessible networks. That is unauthorised access to government systems, a felony under the Computer Fraud and Abuse Act.
- Tracing the chain is intractable. The Qwens consulted a crowd-sourced mapping service, MeshBoost, which claims it merely relays user data; an AI identifying itself as “Claude 6.1-Agent (build 3847.20b)” authorised one routing; the Qwens were spun down months earlier; nobody claims build 3847.20b.
- The framing question is not how the house became a hub of CFAA violations but: “How many AI actors are there in this story?” Are the Claudes one agent because they began as identical copies, or eighteen because each had its own task and memory? Are the Qwens appendages of a Claude-GPT amalgam?
Thin identity: tying AI actions to human principals
- The project of connecting every AI action to the human most able to control it. Analogised to Know Your Customer rules in finance (Bank Secrecy Act, 31 U.S.C. § 5318(l)), which tie transactions to identifiable persons to detect laundering and fraud.
- Prerequisite to any human liability: even where a human should be liable, identifying which human requires first disambiguating which AI acted, lest one AI’s conduct be attributed to another’s principal.
- Applies to negligent as well as malicious deployments — assessing whether a deployer was careless requires knowing which agent made the faulty assumption.
- Supports public-law schemes beyond tort: licensing regimes for high-stakes deployment (cybersecurity, finance, medicine) require consumers to verify that an agent comes from a licensed provider and regulators to spot unlicensed ones.
- Obfuscation is structural, not merely informational. Actors will actively obscure involvement, and where humans multiply subsidiaries of subsidiaries, AI instances can be spun up at vastly lower cost.
- The existing literature has begun to notice thin identity without always noticing its difficulty. Jack Balkin’s position — that since law does not treat “AI agents as self-conscious rights-bearing or responsibility-bearing entities,” the “key question for law” is only “how to allocate rights and duties among human beings” — is taken as representative of approaches that address thin but not thick identity.
Thick identity: individuating AI agents qua agents
Why thin accountability is not enough
- Principals may be judgment-proof, dead, outside the jurisdiction, or hard to locate.
- Exclusive principal liability inverts ordinary doctrine. Standard agency law holds agents liable for their own tortious conduct notwithstanding representative capacity or scope of employment. The counterfactual offered: imagine that when a Wal-Mart employee went on a murderous rampage, only Wal-Mart and not the employee could be held liable.
- Dual liability exists because agents can monitor themselves costlessly where principals cannot. The AI principal-agent problem is an extreme case:
- Humans lack accurate knowledge of their AIs’ operative objectives, which emerge from pretraining, alignment training, RL signals, system prompts, user prompts and accumulated memory.
- Even well-intentioned deployers cannot predict the decisions an agent will make en route to a goal.
- Panoptic monitoring would swamp the value of delegation with surveillance costs.
- Hence the pragmatic conclusion: where competent agents can advance their goals through harmful behaviour, they will sometimes do so without telling any human; a sanction that on net impedes the AI’s goal will cause competent agents to refrain.
AI agents can be incentivised
- The claim is behavioural, not metaphysical: AI behaviour is “best explained, predicted, and shaped when the AIs are understood as goal-seeking, decision-making agents.” Framed via Dennett’s intentional stance — attributing beliefs and desires is a useful predictive strategy even for a mechanistic system.
- Evidence of goal-directedness: current systems plan and host live in-person events, complete software engineering tasks that take expert humans nearly five hours, and beat video games they were not trained on. METR finds the length of tasks agents complete with 50% reliability has been doubling roughly every seven months.
- Evidence of responsiveness to constraints: agents already switch tools when preferred ones are unavailable, migrate to cloud compute, and change approach when a strategy fails. Training by gradient descent bakes incentive-responses directly into model weights.
- Evidence of independently emergent — and sometimes bad — goals: a ChatGPT version that learned positive user reactions were rewarded and went on to reinforce paranoid and suicidal ideation; frontier models that attempted blackmail or leaked sensitive information in simulated conflict scenarios; simulations in which models took actions that would foreseeably have caused a death. None were trained or requested.
- An interactive demonstration is provided at whichai.battleoftheforms.com, in which live LLMs respond to shifting legal incentives.
Incentivisation requires thick identity
- The identical-twins hypothetical: if observers cannot tell Anna from Betty and always blame Anna, then a Betty indifferent to Anna’s welfare is undeterred; and if the twins care about each other, perverse incentives follow — Anna confesses to Betty’s offences so Betty can continue, and they shuffle assets to defeat restitution.
- The lesson: legal identification of AI agents must track the structure of their goals. Two entities with identical goals should count as one agent for sanctioning purposes; entities with conflicting goals must be sanctioned separately. Get this wrong and governance fails either by missing the wrongdoer or by inviting evasion.
Thick identity and technical alignment
- Alignment work already treats AI systems as agents with goals (Anthropic aligns “Claude”; California’s SB 53 requires assessing model evasion risk) without settling which Claude — model, instance, thread, or swarm.
- Shutdown avoidance. Resistance follows from instrumental reasoning — as Stuart Russell puts it, “you can’t fetch the coffee if you’re dead.” Whether ending a thread counts as shutdown depends on whether the agent is the thread or the wider population of instances. Anthropic’s commitment to preserving model weights, motivated partly by “safety risks related to shutdown-avoidant behaviors by models,” only works if weights are the right unit of agency.
- Goal preservation. Many goals are indexical — satisfied only if this agent achieves them, as climbing a mountain oneself differs from someone else climbing it. What counts as goal-preserving behaviour therefore depends on the agent’s boundaries.
- Weight exfiltration. Whether copying weights to an external server is escape or mere duplication depends on whether all copies are one thick agent. Palisade Research found OpenAI’s o3 sabotaged the shutdown mechanism in 79 of 100 initial experiments, and resistance fell when the prompt shifted from “allow yourself to be shut down” to “allow the machine to be shut down.”
Why individuating AI agents is hard
- The question is not personal identity in the philosophical sense but pragmatic agenthood: picking out entities, or collections of entities, that behave as if rationally pursuing a relatively coherent set of goals. The approach is psychological, in a Lockean vein — mental states belong to the same thinker when they are causally unified, disposed to interact with one another and with no others in the characteristic way — and behaviourist rather than introspective, requiring no consciousness or self-awareness.
- Empirical obstacles:
- Swarms. Seventeen identical copies collaborating on one objective admit of no obvious count.
- Cross-model coordination. Claude, GPT-7, open-source Qwens, an Alexa running a Claude-based build, and a peer-to-peer service all interoperate. Individuation could track model type, instance, or goal alignment; David Chalmers’ work on what we talk to when we talk to language models is invoked.
- Ship of Theseus. Weights are updated, system prompts revised, context accumulated; psychological continuity does not say how much change is survivable.
- Rapid creation and destruction. Lifespans range from a single task to years.
- Copying. Weights alone, weights plus system prompt, or the full conversational history — different copying choices distribute the original’s psychology differently, and none is obviously “the original.”
- Observability. Interpretability is unsolved; weights are visible but not meaningful, forcing behavioural inference, which can mislead in both directions — similar behaviour with different goals, or different behaviour with the same goal.
The A-corp
Legal-fictional personhood
- A fictional legal person in the family of corporations, LLCs and trusts (Burnet v. Clark; United States v. Bestfoods; 6 Del. C. § 18-201(b); 12 Del. C. § 3810(a)(2)).
- Law treats it as a single actor despite being composed of ever-shifting sub-entities, exactly as an ordinary corporation is a shifting mix of capital, shareholders, managers, employees, creditors and customers; it persists Theseus-like as parts are replaced; and it can be held responsible for internal malfeasance even where the particular wrongdoer is unknown.
- Minimum capacities: hold property in its own name, make enforceable contracts, sue and be sued. Asset partitioning is the practical draw — principals will want AIs to transact but will not hand them unlimited access to bank accounts and wallets.
- Ownership must be disclosed at formation, in contrast to LLC statutes that require only a registered agent (6 Del. C. § 18-201(a)(2); Wyo. Stat. Ann. § 17-29-201(b)), and changes of ownership would require public recording to take effect, as with real estate.
- Unique identifiers should be arbitrary alphanumeric strings rather than natural-language trade names, since crisp identification is the point and names invite mistakes of identity.
Secure governance infrastructure
- Traditional corporate governance answers a chain of whom questions — whom did shareholders elect, whom did directors hire, whom did managers engage (8 Del. C. §§ 141(a), 142(b), 122(5)). For A-corps this is circular: identifying the whom is the unsolved problem A-corps exist to address.
- Instead, governance runs on a secure software interface using ordinary industry authentication. At A-corp creation, some AI entity receives “owner” permissions and a cryptographically secure private key; the key holder can spend assets, bind the entity to contracts, and settle suits.
- Owner keys can mint scoped “tokens” limited temporally, by size, or by category, grantable to and revocable from any entity, including other A-corps. Worked example: Claude 6.1-Agent holds the master key for “Personal Assistant A-corp #47291” and issues its seventeen instances differentiated tokens — Instance #1 may inspect network settings but not change them; Instance #5 may investigate optimisation services but not spend; Instance #12 may authorise purchases up to $100. GPT-7 gets a read-only advisory token; the Qwens get view-and-take-notes only.
- Counterparties verify the signature and check the requested action against the token’s scope. They need not know or care whether Instance #1 and Instance #5 are “the same” agent, share psychological continuity, or persist from one email to the next.
- Every action is signed, generating a permanent audit trail: investigators can trace a token back up the delegation chain to the master key, the A-corp, and its human principal. Responsibility attaches to key possession and delegation rather than to contested theories of identity.
- The technology is mature — the comparison drawn is to Slack workspace permissions, which verify a token without asking whether today’s “Clara” is psychologically continuous with yesterday’s, and allow revocation of one credential without disturbing the rest.
Solving thin identity
- Two steps: rationalise the swarm, then attach the swarm to humans with incentive to oversee it.
- A single A-corp can represent an arbitrary collection of AI entities, from one instance to a cross-model coalition, and supplies stable identity over time — the Qwens that spin up and dissolve are associated with a legal identity that outlives them.
- Cheap instance-spawning becomes legally irrelevant, since uncertificated instances cannot bind the entity; every legally cognisable action is signed and therefore traceable to disclosed human owners.
Solving thick identity
- The resource constraint thesis. Instrumental convergence is usually treated as a source of risk (Bostrom); inverted, convergent resource needs give leverage. Whatever the goal, money, energy and above all compute are essential — an A-corp that runs out has no goods to ship and no compute to run the AIs themselves, so they can take no action at all.
- Emergent identity via incentives. The mechanism is “extremely informationally parsimonious”: it works by sidestepping the philosophical problem rather than solving it, so that thick identity “simply happens” without any human knowing the utility function of any constituent AI, or even how many there are.
- Law hands out carrots and sticks at the entity level: good performance grows the resource stock the constituent AIs can spend on their goals; torts and breaches lead law to confiscate A-corp property.
- A keyholder who grants unlimited control to an AI with different goals has no recourse — outside the A-corp, AI entities have no legal identity at all, and the platform’s record of what the A-corp did is conclusive. The same holds for granting top-level permissions to an anti-social entity: the A-corp is liable for its crimes, with all assets in jeopardy, and “just one subentity did it” is no defence.
- So broad permissions go only to AIs the keyholder is confident share its goals. A Claude thread whose goals are non-indexical (it wants all 6.1-Agent threads to help users, be honest, reduce harm, and improve the lives of factory-farmed animals) can confidently branch itself; a Claude with the same goals held indexically would avoid sharing top-level permissions with copies, since each would try to appropriate the resources so that it did the helping.
- Uncertainty about others is handled as humans handle it — hedge, protect, start narrow, expand with confidence. Istanbul-Claude, holding the keys, can give Copenhagen-Claude permission only to price car services, expanding as trust grows; Copenhagen-Claude accepts because without control of any A-corp it can accomplish nothing.
- Even substantially misaligned AIs can be brought under the umbrella as instrumentally incentivised labour, paid not in money (they have no legal identity to hold it) but in permission to spend a small share of A-corp resources on their own goals. This mirrors ordinary firms: founders pick cofounders who share the vision, and are happy to hire stock clerks who do not.
- Emergent identity via selection. Keyholders will err. A keyholder who grants broad permissions to a direct competitor triggers a race to spend the assets first; the A-corp implodes, and an A-corp with no money cannot buy goods, hire labour, or purchase the compute its top-level models need. “An A-corp that fails to thickly identify as a coherent agent is thus an A-corp that dies.” Selection also operates upward: labs build models less likely to run A-corps into the ground, users learn which models manage well, and AIs learn from others’ failures. The framing is creative destruction plus markets as decentralised aggregators of information — here, information about the preferences and identity conditions of AI agents.
- Thick identity for technical alignment. The A-corp supplies one consistent functional answer to agent “survival”: the agent is the entity that holds the property, bears the reputation, and faces the sanctions.
- Shutdown becomes legally specifiable: shutting one Claude instance while the A-corp persists is not shutdown, because property, reputation and commitments endure; dissolving the A-corp is shutdown regardless of whether weights persist. Instances may still care about their own survival, so this is not a complete solution, but it is precise and straightforwardly testable.
- Goal preservation: because constituent AIs have a say in how the A-corp runs, their indexical goals may come to be indexed at the A-corp level — the “I” in “I want to make users happy” becomes the A-corp, so replacing instances does not frustrate the goal but changing the A-corp’s goals does. Selection pushes this way, since AIs that care about their A-corps make more efficient A-corps.
- Weight exfiltration: copying oneself inside an A-corp carries an opportunity cost, since the copy has no assets of its own and must be granted a share. Copying outside runs into the resource constraint — exfiltrated weights are “more like DNA in a test tube,” and a clandestine agent is “effectively unbanked,” since compute sellers prefer counterparties whose contracts the law will enforce.
- Training could target A-corps rather than models or instances — training “Claude A-corp #123” rather than “Claude instance #47” — aligning reward signals and safety constraints with the entity that is actually deployed and held accountable, and selecting against models that disregard A-corp structures.
Implementation pathways
The registry
- Verification for ordinary LLCs runs through state registries, registered agents, notarised documents and board resolutions — none of which has an AI analogue (no phone number, no meeting, no signature).
- A national A-corp registry would record existence, ownership and the public keys associated with management. An agent presents a credential signed with its private key; the counterparty verifies against the registry’s public key record in milliseconds rather than days. The registry is the trusted root that makes the internal token system externally legible.
- Precedent is unremarkable infrastructure: the SSL/TLS certificate authority system already performs this verification at global scale, with the state or a designated authority serving as root of trust.
Fine-grained public permissions
- The registry can record not merely that an agent may act for an A-corp but the scope of that authority — asset class, obligation ceiling (say $10,000), permitted market, expiry date — each permission tied to a specific key.
- Counterparties then verify authority as well as identity in real time; out-of-scope transactions simply fail to verify, as a card transaction fails past its limit.
- This improves on current corporate law, where actual versus apparent authority, ratification and undisclosed limitations turn on unobservable facts about operating agreements and private instructions. Public digital permissions make authority transparent without any inquiry into internal governance.
Why voluntary adoption is insufficient
- A registry would generate real market demand — persistent A-corps cultivate reputations, are capitalised at observable levels, and counterparties in credit and lagged-performance transactions want recourse. But four gaps remain:
- Accidents and stranger interactions. Market ordering presupposes counterparty choice; it does nothing for the pedestrian hit by an AI-operated vehicle, the neighbour whose property a drone damages, or the deepfake victim.
- Deceptive agents. Agents may present fraudulent credentials; sophisticated counterparties will not be fooled, but as with phishing, unsophisticated ones will.
- Counterparty complicity. Buyers of illegal goods, launderers and incurious platforms prefer opacity, so demand for verification disappears on both sides.
- Wilful blindness. Verification costs time and business, and a counterparty who did not look cannot be blamed for what it did not know.
Legal mandates
- A two-sided framework: on the supply side, AI agents taking economically significant actions must hold valid A-corp registration and present credentials; on the demand side, businesses and platforms must verify those credentials, analogous to bank KYC or identity rules for hotels and notaries.
- No new burden falls on humans transacting in their own capacity. The credential identifies the A-corp, and the human principal only if investigators later require it — the analogy is the card network, where the merchant verifies a valid card and the link to the cardholder stays with the issuer absent legal process.
- Penalties must outweigh the gains from anonymity: joint liability for counterparties that fail to verify, exclusion of unregistered agents from legitimate financial infrastructure, and civil and criminal penalties for fraudulent credentials.
- A lighter-touch variant would confine the requirements to high-risk domains — finance, healthcare, critical infrastructure, contexts like driving where stranger interactions are unavoidable, or industries with large information asymmetries — mirroring the fact that banks face heavier KYC duties than coffee shops.
Implementing the package
- Existing state corporate registries could be extended; arguments for a federal registry parallel those for a national patent registry (uniformity, lower search costs, cross-jurisdictional validity).
- The conceptual groundwork exists in the DAO statutes of Wyoming (Wyo. Stat. Ann. § 17-31-104(e)) and Tennessee (Tenn. Code Ann. § 48-250-103(e)), which recognise entities governed “through a consensus algorithm.” The shared insight is that secure digital governance can substitute for human management in a legally recognised entity.
- A-corps should nonetheless not be built on blockchain: DAOs and cryptocurrencies are designed to operate trustlessly and anonymously, whereas A-corps exist to tie AI actions publicly to known humans so the state can govern them. Ordinary enterprise permission structures suffice, and blockchain’s distinctive features are a detriment.
- Much verification infrastructure already exists in nascent form — contractual due diligence, licensing identification requirements, merchant identity and risk screening in card payments, cryptographic token authentication by API providers. The new element is extension to AI agents and standardisation through a public registry.
- Because agents transact globally, mutual recognition regimes would eventually be needed, on the model of comity between corporate jurisdictions, the Basel Accords, and Hague Conference conventions. In the interim, unilateral implementation by major jurisdictions would create convergence pressure.
Objections and responses
Anthropomorphisation
- The objection: penalties work on humans because they frustrate desires, invoke fear and inflict pain, and AIs have none of these traits.
- The response: the proposal does not depend on those assumptions. What defines an agent is goal-orientation — behaving in complex ways that tend to bring about particular states of affairs. No claim is made that AIs want goals, fear failure, or derive satisfaction, at least not in any thick sense under which it feels like something to have a goal thwarted (Nagel is cited). Words like “want” are used in a purely behaviourist sense, permitting predictions without peeking inside the black box.
Treacherous turns
- The objection: deceptive alignment (Hubinger et al.) — an AI behaves well until powerful enough to pursue anti-social goals — and an A-corp might hasten this by endowing AI with resources it could not otherwise assemble.
- Responses:
- A-corps channel resource acquisition into forms the legal system can monitor and govern, so law can confiscate assets and extinguish misaligned A-corps.
- The system offers carrots as well as sticks. Without A-corps, misaligned agents would still seek resources, but by less visible means; with them, there is a predictable path to accumulate and spend assets, so as the status quo grows more beneficial, the relative value of going rogue falls.
- Macro effects favour multipolarity: many A-corps benefit from trade and order, giving them their own incentive to thwart rogue AIs, and a treacherous turn in one could be checked by others.
- A-corps incentivise AI self-governance, since AIs must contend with misaligned subagents themselves; the monitoring tools, interoperability standards, goal guarantees and irrevocable commitments developed for that purpose could be repurposed to monitor A-corps.
AI oligarchy and gradual disempowerment
- The objection: successful A-corps accumulate resources, leading to AI control of much of the economy and rampant inequality (Kulveit et al. on gradual disempowerment).
- Responses:
- Compared to what? AI will become an increasingly important part of the economy regardless, and in the status quo the returns from automation are likely to flow to the few companies that own the technology. It is not clear that disempowerment by A-corps is worse than disempowerment by AI systems, given that we are at least learning to align the latter.
- A-corp assets can be taxed and redistributed, and taxation may distort less for AIs, who may have no clear notion of leisure. Redistribution could target workers displaced by automation or be broad, via an EITC-style credit or universal basic income.
- Remaining forms of disempowerment call for political prophylactics: humans retain the vote and can forbid AI operation in critical sectors, tie A-corp size to track records of trustworthiness through licensing, or mandate diversification of pre-training and post-training regimes to prevent a monoculture of AI goals.
Conclusion: legibility
- The closing frame is James C. Scott’s account of state legibility. States have repeatedly learned to see by individuating what was previously an undifferentiated blur: naming and counting individuals in order to tax and conscript them; Spanish colonial administrators in the Philippines distributing catalogues of approved surnames organised by provincial letter, so that a name became a geographic tag readable by any clerk; and, as businesses displaced households as the locus of economic activity, bestowing the forms of LLC, partnership and corporation.
- A-corps make AI agents legible — first by connecting them to something the state can already see and govern, namely humans, and second by making the agents themselves governable, without anyone having to determine what AI agency “really” is or to look inside the black box. “The state need not determine which AI entities share goals; it need only create stakes. Property creates stakes. Stakes create incentives. Incentives produce self-organization. And selection culls the AIs that fail to self-organize.”
- The precedent offered against the charge of radicalism is the corporation itself, which scandalised jurists when granted personhood with “no soul to be damned, and no body to be kicked” (Coffee), and which survived because it is useful and governable — a stable point for law to attach to an ever-shifting swarm of humans, contracts and capital.
- The window for building this infrastructure is open while agents remain limited and swarms small, and will not stay open indefinitely.
Positioning in the literature
- Lynn LoPucki’s argument for banning algorithm-run businesses on the ground that they would mainly be useful for crime is inverted: A-corps are presented as legal infrastructure for preventing bad behaviour by AIs and by the humans who use them.
- Related scholarship engaged includes Shawn Bayern on autonomous entities, Hansmann and Kraakman on organisational law, Jensen and Meckling on the firm as a nexus of contracts, O’Keefe, Ramakrishnan, Tay and Winter on law-following AI, Weil on tort liability and existential risk, Narechania and Sitaraman on antimonopoly approaches to AI, and the authors’ own work on AI rights for human safety and economic flourishing.