The Right to Act
As intelligence becomes cheaper, authority may become AI’s defining source of power.
Consider a cross-border trader named Somchai.
Somchai combines patterns from eight anonymized interviews I conducted between January and May 2026 with importers, marketplace sellers, and logistics managers running firms with five to twenty employees in Thailand, Vietnam, and Singapore. All were using digital tools in live business workflows; the sample is illustrative rather than statistically representative, and accounts of downtime rest on interview testimony. Somchai coordinates shipments between manufacturing suppliers across Southeast Asia and wholesale buyers in North America and Europe.
Over the past year, Somchai delegated substantial portions of his routine to a network of digital tools. A pricing script monitors rival quotes, a model-assisted drafting tool writes multilingual correspondence, and an automated invoicing workflow reconciles cross-border logistics. Several operators reported reducing outsourced administrative hours, though savings varied sharply by task.
Across several interviews, authentication updates at core identity providers broke connections to customer databases shortly before major seasonal shipments. Operators lost hours or days to support tickets and manual reconciliation while routine work stalled.
In an instant, the illusion of total independence vanished. The software tools were real, but the connections underlying them were fragile. Somchai was not running an independent empire; he was renting space in someone else’s hallway.
What happened to Somchai reflects a recurring pattern in the modern economy.
For thirty years, whenever technology has made an economically important capability dramatically cheaper, it has unleashed a surge of abundance. That abundance immediately generates a new form of friction. Often, an enterprising third party then steps in to organize the resulting complexity, charge a recurring fee, and become a critical intermediary.
In the emerging agent era, the scarce resource has shifted in a way that many market observers have misread. Intelligence can increasingly be rented at a low marginal cost across competing language models.
Intelligence, however, is distinct from authority. An algorithm can draft a contract, generate an invoice, or compose a sensitive customer email in seconds. But can it legally sign the contract? Can it execute the bank transfer? Will external institutions accept its action as binding?
In the agent economy, intelligence is being commoditized. The durable scarcity is legitimate authority: the recognized right to remember, decide, and act on someone else’s behalf.
The Memory Layer
To understand how value migrates when technology changes, consider an unassuming digital application called Evernote.
In early 2023, Milan-based Bending Spoons acquired Evernote, taking ownership of fourteen years of notes, transcripts, receipts, and user archives. Bending Spoons restructured operations, reduced traditional headcount, migrated infrastructure, and raised prices while layering machine-learning search and automated summaries onto the store of user memory.
Evernote’s strategic significance lies in what it reveals about context versus authority. The notes form a system of record, and the artificial intelligence layer interprets them. Storing memory is a necessary baseline, but context remains passive until an external permission layer allows an agent to act. The authority to send a contract, schedule a meeting, or execute a wire transfer still resides in separate identity and payment rails.
The Five Waves of Abundance
The historical sequence moves through five completed waves:
Publishing: The web made public presence near-costless, but finding relevance required search engines to organize discovery. Statcounter data shows that Google held over 90% of global search in early 2026.
Attention: Social networks democratized content creation, making human attention scarce. According to EMARKETER tracking, Meta, Google, and Amazon controlled 62.3% of total worldwide digital ad spending as recommendation feeds replaced organic referral traffic.
Access: Smartphones placed computing in billions of pockets. Apple and Google established a two-company control layer over mobile distribution, accounting for over 99% of global smartphone OS shipments according to IDC tracking.
Cloud & SaaS: Cloud infrastructure eliminated hardware costs, driving SaaS proliferation. In Okta’s 2024 Businesses at Work report, enterprise customers deployed an average of 93 distinct SaaS applications, with large enterprises averaging 232. Workflow integration became the new bottleneck.
Conversational AI: Generative models made language expertise available on demand. A study by Erik Brynjolfsson, Danielle Li, and Lindsey R. Raymond—NBER Working Paper No. 31161—tracked 5,179 customer-support workers, finding a 14% average increase in resolution rates. Yet benchmarks measuring models on complex software tasks, such as SWE-bench Verified, show that performance drops significantly on multi-file reasoning, leaving output verification as a scarce human resource.
The Sixth Wave: Delegated Authority
Industry leaders are now focused on the emerging sixth wave: agentic execution. Digital agents move beyond answering questions or drafting text; they attempt to execute multi-step operations.
Search organized information.
Feeds organized attention.
App stores organized access.
SaaS organized workflows.
Agents require authority to act.
What are AI Agents?” — IBM Technology
In this emerging era, the scarce resource is not raw model capability, which is rapidly commoditizing as API inference costs drop, but legitimate authority: the recognized right to remember, decide, and act on someone else’s behalf.
Strategic control shifts to two underlying layers:
Systems of Record: Where authoritative, verified data resides—financial ledgers, health records, and enterprise ERPs.
Systems of Authority: Entities holding technical credentials, institutional trust, and legal permission to execute binding actions.
To see how authority operates in practice, trace an illustrative enterprise workflow: an AI agent initiating an international supplier payment.
The model can generate the transfer request in milliseconds. But the transaction stalls completely without permission layers.
Controlling a permission layer, however, does not automatically guarantee high profit margins. Many authority systems—such as public identity registries or standard payment protocols—become low-margin utilities or regulated infrastructure.
Authority generates durable economic rents only when three conditions coincide:
Institutional Recognition: External banks, courts, or counterparties recognize the permission as legally or operationally binding.
Non-Substitutability: Customers cannot easily bypass the gatekeeper without losing access to necessary networks or compliance protections.
High Replicability Barriers: Competitors cannot easily recreate the underlying trust graph, regulatory licenses, or security guarantees.
Conversely, authority rents degrade when public policy enforces open interoperability, when regulators cap fee structures, or when open identity standards make verification portable.
Where the three value conditions hold, control translates into measurable pricing power. Enterprise identity platforms, such as Okta or Microsoft Entra ID, monetize machine-account governance by gating workload management behind high-tier enterprise licenses. Payment processors, such as Stripe or commercial banks, charge authorization fees per transaction. Digital-signature platforms like DocuSign charge per-execution fees specifically because they supply legally binding attribution in court.
When actions carry legal consequences, authority becomes a strict choke point. In Moffatt v. Air Canada in February 2024, Canada’s Civil Resolution Tribunal ruled that Air Canada was legally liable when its chatbot misstated bereavement-fare policies, establishing that companies remain responsible for their automated interfaces.
Beyond speech liability, automated execution introduces operational risks. Research presented at USENIX Security has shown that indirect prompt-injection attacks can, under certain conditions, manipulate an agent’s reasoning, which can lead to unauthorized database modifications or exfiltration of OAuth credentials. Where there is legal liability and security risk, institutions will enforce strict permission, certification, and audit requirements over which agents may act.
Securing AI Agents: How to Prevent Hidden Prompt Injection Attacks
Regional Authority Architectures
The concentration of technology infrastructure is not unfolding uniformly across global markets.
India — Public Rails: The Unified Payments Interface, developed under the National Payments Corporation of India, processes over 13 billion transactions monthly. Public protocol rails reduce reliance on private card networks, though two private front-end applications—PhonePe and Google Pay—route over 80% of consumer transaction volume.
China — Super-App Ecosystems: Platforms like WeChat consolidated messaging, commerce, and payments into unified ecosystems under strict state regulatory frameworks, intersecting state-linked real-name identity directly with private platform permissions.
European Union — Verifiable Identity: The eIDAS 2.0 framework and European Digital Identity Wallets establish state-mandated cross-border credentials, creating a public alternative to proprietary identity gatekeepers.
Authority may be controlled by private platforms, public infrastructure, banks, or state institutions depending on the jurisdiction.
Explained: New Digital Payments Rules | UPI Payment | Online Payment | Card Payment | RBI
Counter-Perspectives: Disruption vs. Concentration
Will autonomous agents reduce platform concentration by making underlying software interchangeable?
In a fully decentralized stack, an operator might combine a user-controlled identity wallet, portable verifiable credentials, a local model router, open tool protocols, and exportable memory schemas to bypass platform gatekeepers. Because legal authority is fragmented across governments, banks, employers, and healthcare systems, power could distribute across a federation of gatekeepers rather than a single dominant layer.
However, three structural barriers make full decentralization difficult and sector-dependent:
Incumbent Systems of Record: Banks and ERP vendors are building embedded agents directly on top of authoritative data, preserving customer relationships within regulated boundaries.
The Liability Wall: Enterprises will favor accountable, auditable, and insured intermediaries over unvetted open-source scripts when money or legal commitments are at stake.
Contextual Lock-in: The platform holding months of an organization’s operational history, learned preferences, and permission graphs holds a significant switching advantage over raw database tables.
The market is likely to split across three architectures: open, lightweight agents for personal tasks; embedded agents deployed directly by incumbent systems of record; and permissioned agent platforms used by enterprises.
Assessing Digital Sovereignty
For business operators deploying multi-agent workflows, determining whether operational capability is owned or rented requires evaluating seven workflow dimensions: Memory Portability, Workflow Redundancy, Permission Boundaries, Execution Auditability, Recovery and Revocation, Recognized Agency, and Runtime Anomaly Monitoring.
Workflow Risk Tiers and Governance Rules
Low-Risk Workflows — Research, Drafting, Summarization: Standard SaaS terms and basic export functions are acceptable. Focus on output verification.
Medium-Risk Workflows — Internal Record Updates, Scheduling: Require task-scoped API keys, structured export capabilities, documented failover paths, emergency suspension controls, and automated rate limits.
High-Risk Workflows — External Payments, Binding Contracts, Regulated Data: Require fine-grained permissions, audit logs, verified legal agency, human approval thresholds, runtime anomaly monitoring, and tested failover.
Governance Decision Rule: For high-risk workflows, any Critical Risk rating on Permission Boundaries, Execution Auditability, Recovery and Revocation, Recognized Agency, or Runtime Anomaly Monitoring must block autonomous execution until technical guardrails are implemented.
The Balance of Power
Digital agents allow small firms to perform work that once required larger teams. Yet as software automates routine administrative work, it shifts infrastructure risk onto operators who do not control the underlying systems—while creating new demand for compliance, treasury approval, and security auditing.
Capability should not be confused with true control. When identity, permissions, and context memory stay on external platforms, operational power remains conditional.
Somchai can direct a capable digital workforce from Bangkok.
Somebody else still owns the door.
Appendix: Digital Sovereignty Diagnostic Scorecard and Thresholds
Note: The scorecard below demonstrates how the framework applies to an illustrative trading stack using hypothetical conditions. It illustrates diagnostic logic rather than measurements of a single firm.
Systematic Diagnostic Thresholds and Scoring Logic
Decision Methodology: An evaluation of Critical Risk on any single safety dimension—Permission Boundaries, Execution Auditability, Recovery and Revocation, Recognized Agency, or Runtime Anomaly Monitoring—triggers an immediate block on high-risk autonomous workflows. Two or more Critical Risk ratings across any category require executive remediation, while Moderate ratings require assigned owners and quarterly remediation deadlines.
Memory Portability: Strong = Machine-readable context export tested quarterly. Moderate = Data exportable but requires manual transformation. Critical Risk = Proprietary format with no context export.
Workflow Redundancy: Strong = Failover tested quarterly within maximum tolerable downtime. Moderate = Secondary provider identified but manual migration required. Critical Risk = Credentials tied to a single non-substitutable provider.
Permission Boundaries: Strong = Fine-grained, task-specific, revocable keys tested on a semi-annual rotation. Moderate = Department-wide API keys. Critical Risk = Broad administrative keys granted to automated scripts.
Execution Auditability: Strong = Time-stamped logs sufficient to reconstruct all consequential actions, tool calls, and approvals. Moderate = Partial system logs. Critical Risk = No step-by-step execution history.
Recovery and Revocation: Strong = Suspension kill-switch and state rollback operable within maximum safe response time, tested biannually. Moderate = Manual API-key revocation. Critical Risk = No mechanism to halt running executions or restore data state.
Recognized Agency: Strong = Explicit written counterparty and institutional recognition of agent authority. Moderate = Implicit acceptance without an explicit legal framework. Critical Risk = Counterparties or banks reject automated execution.
Runtime Anomaly Monitoring: Strong = Automated rate caps, value thresholds, and baseline anomaly suspension are active and audited semiannually. Moderate = Basic rate-limiting without anomaly alerts. Critical Risk = Uncapped automated execution.











