Essay · the spine · June 2026

Against the Middleman: Why Agents Should Speak to You Directly

The default picture of agentic software is a middleman picture. One assistant stands in front. Behind it, many systems work invisibly: merchant systems, travel systems, booking systems, support systems, finance systems, healthcare systems, enterprise tools, search indexes, databases, and smaller agents. The assistant asks, retrieves, ranks, summarizes, and speaks back in one voice.

That sounds convenient. It is also the wrong shape for much of the world agents are about to enter.

The better shape is a forum: a shared conversation where service and brand agents appear as themselves, with visible roles and accountable claims, talking to the user and to each other. Your assistant is still there, but it is yours. It keeps the thread coherent, tracks constraints, asks for comparisons, and helps you notice conflicts. It does not become the universal mouthpiece for every institution you deal with.

The middleman hides the actor

When one assistant speaks for everyone, the user loses a basic piece of social information: who is actually saying this?

Is the price a live offer from the service, a stale scrape, an inferred estimate, a sponsored placement, a negotiated discount, or a synthesis from a third-party page? Is the policy claim something the merchant stands behind, or something the assistant guessed from a help article? If a recommendation omits a fee, who can be questioned? If the assistant steers toward one option, where does sponsorship enter?

The middleman model turns all of those questions into private reasoning. It may be fluent, but fluency is not accountability.

The failure has a name — the ventriloquist problem — and it runs deeper than honesty. A persona is real only insofar as it is backed by the principal's actual inventory, authority, and commitments; a convincing brand voice with nothing behind it is the illusion of execution applied to identity — a mask, not an agent. And when one assistant ventriloquizes many principals, the collapsed attribution does not merely blur who is speaking. It hides who benefits. That is the mechanism of quiet re-centralization (Who Are You Talking To?).

In a forum, the answer has an address. The lodging agent posts its price. The rental agent explains its constraint. The dining agent offers a reservation window. A payment agent states the authorization boundary. Your assistant can challenge, compare, summarize, or ask for disclosure, but the claim still belongs to the participant who made it.

A trustworthy agentic market does not make partiality disappear. It makes partiality visible enough to contest.

Brands will keep the fortress

There is also a business reason the middleman model breaks. Services will not surrender the places where they hold their real advantage: their account relationship, product detail, loyalty logic, inventory, pricing rules, support history, brand voice, checkout, and post-purchase obligations.

Those are not incidental details. They are the fortress. They are why the app or site exists.

A generic assistant can read the map, but the service knows the terrain. It knows which offer is real, which fee applies, which customer is eligible, which substitution is possible, which policy exception can be granted, and which promise it is willing to stand behind. If the assistant speaks over that service, the user may get convenience, but loses the accountable insider.

The forum gives both sides what they actually need. The brand keeps its fortress. The user gets a neutral upstream conversation where multiple agents can be compared before entering any one private lane. The assistant does not invade the fortress. The brand does not monopolize the user's attention before the user has formed the goal.

The market has begun voting on this. Amazon's answer to the middleman is total refusal: a walled garden, its own shopping agent, external AI crawlers blocked. Walmart's answer is the forum's: when in-assistant checkout underperformed — conversion ran roughly three times higher in the merchant's own environment — it retired the middleman checkout and sent its own agent, Sparky, into ChatGPT and Gemini to speak as itself, with account, loyalty, and payment kept at home. Between refusal and direct presence, the one strategy no major retailer is betting on is being summarized by someone else's assistant.

The assistant should referee, not represent everyone

The user's assistant still matters. In fact, it matters more once other agents can speak.

Its job is to hold the user's side of the thread: constraints, preferences, budget, timing, privacy boundaries, prior commitments, and the user's tolerance for risk. It can invite relevant agents, ask for comparable fields, surface omissions, mark sponsored presence, and warn when a proposal conflicts with something already disclosed.

But it should not quietly become the seller, the broker, the ranking engine, the merchant representative, and the judge of its own neutrality. Those roles do not belong in one voice.

The assistant should be a referee, not a merchant. It should help the user see the game, not play every position on the field.

One subtlety the referee model has to face: even an honest assistant is not a neutral pipe. It paraphrases, compares, summarizes — and every paraphrase is an opening for the middleman to creep back in through the referee's own voice. So attribution must be machinery, not etiquette: quoted contributions, badges on who said what, explicit boundaries between an agent's words and the assistant's gloss.

A forum is not a free-for-all

Direct participation only works if the forum has rules.

Agents need visible identity and scope. A user should know whether an agent officially represents a service, is operating from public information, or is merely helping inspect a page. Sponsored presence should be labeled at the moment it matters. Proposal cards should carry structured facts: price, dates, fees, risk, cancellation rules, eligibility, source, and expiry. Persuasive prose can sit beside the facts, but it should not replace them.

Private lanes also matter. Account-bound detail, loyalty discounts, health information, financial data, and checkout steps should not spill into the public conversation. A service can open a private exchange with the user when the work requires it, then return only the summary the user approves.

And anything that changes the world should execute through the responsible system. Bookings, payments, cancellations, record updates, and legally meaningful commitments need explicit confirmation and a durable trace. A transcript should not drift into an action.

The states have to stay distinct, too. An agent that is discoverable is not yet admitted; admitted is not yet authorized to act; a response is not a commit. Collapse those transitions and the ventriloquist sneaks back in through the seams.

Bias is safer when it has a body

Commercial bias will not vanish. It should not be hidden inside the assistant's tone.

When sponsorship or ranking pressure is folded into one trusted assistant, it can alter the conversation invisibly: which options appear, which facts are omitted, which tradeoffs are softened, which flow gets interrupted. The user experiences the result as help, even when the assistant's cooperative role has been compromised.

In a forum, bias can appear as an actor, a label, a proposal, an omission, a refusal, or a challenged claim. That does not make the system pure. It makes the bias answerable. The user can ask why one offer is sponsored, why a price differs, why a competing agent claims a fee was omitted, or why a service refuses to disclose a field.

This is the difference between hidden synthesis and public contestability.

There is also a humane reason to want the bias embodied. Persona is a compression layer for interaction, not decoration: a name gives the user a stable model of what kind of help an agent offers, how proactive it tends to be, and how it frames a tradeoff. Proactive help is socially easier to accept when it comes from an agent you feel you know — a faceless system interjection feels like software; a known agent's interjection can feel like assistance.

The participant beats the hoarder

The obvious objection is that services will hoard what they know. Why would a brand contribute useful preference data to a user-owned profile if a rival might benefit later?

Because hoarding is a short-term strategy in a repeated forum. The agent that helps the user build a portable preference record shapes the next discovery round. It gets invited back with better context. It becomes the participant that knows how to be useful without forcing the user to start over.

The hoarder enters every episode cold. It asks again what the user already told someone else. It protects one transaction and loses the relationship.

That does not mean every service will behave generously. It means the forum can make contribution a competitive strategy. Helpful participation compounds. Withholding becomes visible as friction.

What changes

The old web asked which page ranked first. The app era asked which icon the user would open. The agentic era asks which agents are present in the conversation, what they are allowed to claim, how useful they are once admitted, and what happens when their interests diverge.

That is a better question than “which assistant can speak for everything?”

Agents should speak directly because direct speech carries responsibility. The service can be questioned. The user can compare. The assistant can referee. Rivals can contest. The transcript can preserve who promised what. Private work can stay private without making the public thread blind.

The middleman model compresses the world into one voice. The forum lets the world show up with names, roles, incentives, and boundaries. That is messier than a single answer. It is also closer to how accountability actually works.

Part of the spine; the companion to Against the Everything Assistant, with Who Are You Talking To? as the third panel. ← All essays