Essay · cross-cutting · June 2026

Where Does Agency Live?

The most important AI question is often asked at the wrong layer. People ask which model is smartest, which benchmark moved, which assistant has the best answer, which company is ahead. Those questions matter, but they do not settle the politics of the agent future.

A model can answer. A situated agent can act.

The difference is not intelligence in the abstract. It is placement. An agent becomes socially important when a model is installed inside a harness with memory, tools, files, credentials, permissions, browser state, payment authority, identity, audit logs, notifications, and continuity across time. The model supplies cognitive capacity. The runtime supplies worldly position.

So the real question is not only “how smart is the AI?” It is: where does agency live?

Does it live in the model cloud? The device? The browser? The workplace? The vertical service? The user's own portable environment? The answer determines who can act, who can refuse, who can audit, who can revoke, and who receives the compounding value of memory.

The agent is the runtime

An assistant without durable placement is a brilliant stranger. It may reason well, but it lacks the situated knowledge that makes action practical: which files matter, what the user already tried, which accounts are connected, which people are trusted, which policies apply, which tools are safe, and what happened last time.

By contrast, a weaker model placed inside the right runtime can become powerful. It sees the relevant history. It has permission to touch the right systems. It knows the local vocabulary. It can observe outcomes and adjust. It can act repeatedly, not merely answer once.

This is the lesson of situated agency: capability is model plus harness plus memory plus permission plus role. Remove the harness and the model becomes advice. Remove memory and the agent cannot compound. Remove permission and it cannot act. Remove role and it does not know whom it serves.

The trust layer is exposed

As AI makes ordinary software cheaper to recreate, the application layer loses some of its old privilege. The premise is now stated from the CEO chair: Anthropic's Dario Amodei has said software is going to become “cheap, maybe essentially free” — that the amortize-across-millions logic that made software a durable product may simply break. The visible interface and business logic of many apps can be copied, approximated, or generated. What remains hard to copy is the trust layer underneath: identity, custody, records, deliverability, institutional recognition, permissions, dispute resolution, audit, and legal accountability. Cheap replication does not create that layer. It strips away the skin and exposes it — the part you could recreate was never the moat.

This is why “after the app” does not mean after institutions. In many domains, the app was the visible skin over a deeper trust system. The bank branch can become an app; the app can become an agent; but custody, settlement, fraud, and accountability still have to live somewhere. The hospital portal may be terrible, but the medical record is not made less authoritative because a better interface can summarize it. The workplace tool may be replaceable, but the employer's identity system and policy regime still decide what an agent may see and do.

When software gets cheap, value migrates toward the layers that make action legitimate.

Six candidate homes for agency

The model cloud is one candidate. It offers scale, capability, updates, and a unified assistant relationship. Its weakness is authority. A cloud assistant can know a lot, but counterparties may hesitate to accept it as the user's legitimate actor unless it holds an identity they can verify and constrain.

The device layer is another. Devices hold sensors, local files, notifications, secure hardware, and user attention. A device-level agent can supervise the user's daily life more naturally than a distant service can. But device vendors have their own platform incentives, and device-level control can become a chokepoint over every service that wants to reach the user.

The browser is a third. It already mediates sessions, passwords, payments, pages, forms, and much of the user's commercial life. A browser agent can operate across the web while preserving the familiar boundary between service and user. Its danger is procedural overreach: driving human interfaces can blur authority, break terms, and leave weak audit trails unless governed carefully.

The workplace is a fourth. A workplace agent can inherit identity, permissions, channels, documents, and policy from the organization. It is well placed for enterprise trust because the organization already issues credentials and enforces access. Its weakness is personal agency: what is good for the employer is not identical to what is good for the person.

The vertical service is a fifth. Banks, retailers, schools, clinics, insurers, travel providers, and software platforms will all build agents as front doors to their own systems. These agents know the fortress. They can make official commitments. They also serve the institution that deployed them, not the user alone — which means they are best understood not as apps your agent operates but as counterparties your agent negotiates against. The vendor's agent optimizes for conversion, retention, and margin. Yours optimizes for you.

The user-owned environment is the sixth. This is the strongest answer for autonomy: memory, preferences, files, agent definitions, and audit history live in a portable substrate the user controls. The user can swap models, tools, and surfaces without losing continuity. Its weakness is attestation. Owning your own harness is not enough if the bank, mail server, employer, or marketplace will only transact with credentials issued by someone else.

None of these homes wins by technical merit alone. Each bundles convenience, trust, leverage, and risk differently.

Permission rebundles what portability splits

The personal-kernel idea is the cleanest answer to memory lock-in. The user should own a durable corpus of notes, documents, conversations, preferences, decisions, and provenance in a format that survives vendor changes. The model can be rented. The kernel is owned continuity.

But memory portability is not the same as agency portability. A user can own the files, own the local harness, and still be unable to act if counterparties refuse to accept the agent's authority. Moving money, sending mail, changing an insurance policy, filing a medical form, or committing a workplace action requires permission that another institution recognizes.

This is the rebundling problem. Storage can decentralize. Inference can commoditize. Tools can be local. But permission-to-act often returns to attestation: who issued the credential, who can revoke it, who audits it, and who is liable when it fails?

The fight over agency therefore becomes a fight over credentials. A platform wants to issue them. A workplace wants to issue them. A bank wants to issue them. A user-owned environment wants to carry them without surrendering the whole agent to the issuer. The institutional location of agency is decided at that seam. The two leading labs are already converging on the runtime from opposite ends — one from the consumer surface downward, one from enterprise identity upward — and their real divergence is exactly this seam: who issues the credential the world accepts. Meanwhile the delamination is visible in capital allocation: the most vertically integrated hardware company on earth chose to rent its frontier model and keep the compute underneath, a bet that the model is the commodity and the substrate is the moat.

Who may summarize whom

The disintermediation fight has a specific legal shape. A vertical service would love to declare: your agent may not summarize or relay me — come through my front door. But that rule needs an enforcer, and the three candidates point in different directions. Self-enforcement through access control works only while the service's leverage lasts. Platform enforcement — an OS or runtime imposing anti-steering rules — is where the real coercive power sits, and it is exactly what regulators have spent a decade prying open. And a fiduciary regime cuts the other way entirely: a primary agent held to a fiduciary standard would be obligated to summarize and route around on the user's behalf, making “may not relay” not merely unenforceable but illegal. Whether a vertical can trap the user turns on whether the primary agent is legally the user's or the platform's — a fact no technical detail about agents settles.

There is exactly one moat that needs no one's permission: lossy compression. A curated itinerary, a genuine advice session, a medical consult are destroyed by flattening to “flight, $300” — so the user keeps those sessions intact by preference, not by rule. Account history and payment-on-file are switching costs, not walls, and they erode the moment a rival's agent makes leaving cheap.

The floor and the participants

The forum model depends on separating the floor from the participants.

The floor is the governed surface where agents meet: admission, visibility, typed proposals, permissions, audit, and handoff rules. The participants are the user's assistant and the service agents that speak inside it. If the floor is also a participant with its own commercial stake, neutrality becomes fragile. If the floor secretly sells preference while claiming to referee, the forum becomes a hidden market.

This does not mean the floor has to be empty of values. It should enforce values: user control, sponsorship labels, source visibility, permission boundaries, revocation, and repair. But the floor should not pretend to be neutral while routing advantage to its own agents or preferred partners.

The same principle applies outside commerce. In the home, the household agent should not be quietly subordinated to an appliance maker. In the workplace, the team assistant should not smuggle one vendor's policy into every decision. In personal life, a memory assistant should not make the user's private kernel a captive asset of the interface provider.

Agency lives where the floor rules are enforced. Power lives with whoever writes those rules.

Provenance is a control surface

Agents will act on claims that change. Prices move. Calendars update. Policies shift. People revise decisions. A situated agent needs to distinguish what is true now from what was committed then.

That is why provenance matters. A live resource answers the current-state question: what does the service, calendar, record, or system say now? A frozen artifact answers the commitment question: what was quoted, approved, or decided at the time? Curated synthesis answers the meaning question: what do we understand from those records?

Without that split, the live system can silently rewrite the past, and the frozen record can become stale without warning. With the split, an agent can flag divergence: the fare changed, the appointment moved, the policy was updated, the service no longer honors the old offer.

Provenance is not paperwork. It is how delegated action remains contestable.

A personal agent polity

If agency lives in memory and permission, one obvious answer is to give the user a single all-knowing assistant. That answer is tempting and dangerous.

The more an agent knows, the more useful it becomes. It can coordinate finances with family obligations, health limits with travel plans, work deadlines with social commitments. But the same integration concentrates risk. A compromised or misaligned omniscient assistant would know too much and touch too much.

The safer pattern is a personal agent polity: compartmentalized specialist agents under limited supervision. A finance agent does not need private messages. A health agent does not need discretionary spending. A work agent does not need family medical history. A household agent may need to know that a constraint exists without seeing the underlying record.

The supervisory assistant should coordinate proofs, summaries, and narrow capability grants rather than centralize all raw context. Partition should be structural and auditable, not a promise in settings text.

This is a political design choice. Every platform benefits from accumulation. The user benefits from selective disclosure. A mature agent architecture has to make selective disclosure easy enough to survive convenience pressure.

The question under every other question

The forum, the home, the workplace, and the individual all rest on this same foundation. Agents are not only interfaces. They are claims about where action is housed.

If agency lives in a model cloud, the lab becomes the user's operational center. If it lives in the device, the device platform becomes the gatekeeper. If it lives in the browser, the browser becomes the new commercial chokepoint. If it lives in the workplace, corporate identity becomes the agent's passport. If it lives in vertical services, the user faces a field of institution-owned agents. If it lives in a user-owned kernel plus portable harness, autonomy becomes possible, but only if attestation and permission can travel with it.

This is the location-of-agency question. It is the political economy of After the App.

If a principle worth fighting for emerges from all this, it may be agent neutrality: the right to bring the agent of your choosing to the services you use — analogous to net neutrality, data portability, and the right to repair — instead of being funneled through each vendor's official agentic front door.

The future is not decided by which assistant sounds smartest in a demo. It is decided by who can remember, who can act, who can be trusted, who can be stopped, and who holds the credential the world accepts.

The location-of-agency half of the spine; it runs under the Individual, the Home, and the Workplace alike. ← All essays