Paper deep dive
Is Decentralized AI Governable? From Regulative Policy to Constitutive Protocol
Botao Amber Hu, Helena Rong
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 93%
Last extracted: 7/8/2026, 7:47:08 PM
Summary
The paper argues that Decentralized AI (DeAI) creates a 'governance vacuum' by dissolving the identifiable entities (developers/operators) required by traditional regulatory frameworks. This vacuum manifests as an accountability gap (no addressable principal) and an incapacitation gap (identified principals cannot alter the system). The authors propose shifting governance from regulative policy to constitutive protocol, using architectural constraints to shape the substrate of possible actions, while emphasizing ethical conditions like legitimacy and transparency.
Entities (10)
Relation Signals (9)
Decentralized AI â causes â Governance Vacuum
confidence 97% · Decentralized AI (DeAI) dissolves this presupposition... compounds into what we call the governance vacuum
Governance Vacuum â comprises â Incapacitation Gap
confidence 96% · This vacuum takes two analytically distinct forms: an accountability gap... and an incapacitation gap
Governance Vacuum â comprises â Accountability Gap
confidence 96% · This vacuum takes two analytically distinct forms: an accountability gap... and an incapacitation gap
Six-layer Decentralizing Stack â includes â Model, Training, Compute, Harness, Identity, Ownership
confidence 95% · We analyze DeAI as a six-layer decentralizing stack -- model, training, compute, harness, identity, and ownership
Incapacitation Gap â resultsin â Inability to alter system
confidence 95% · an incapacitation gap, where even an identified principal cannot alter the running system
Accountability Gap â resultsin â No addressable principal
confidence 95% · an accountability gap, where no addressable principal can be identified
Protocol-based Constitutive Governance â replaces â Regulative Policy
confidence 94% · we argue for a shift in the locus of governance from policy to protocol, from normative address to architectural constraint
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Every major framework for governing artificial intelligence presupposes an identifiable entity -- a developer, deployer, or operator -- who can be held responsible and compelled to comply. Decentralized AI (DeAI) dissolves this presupposition. We analyze DeAI as a six-layer decentralizing stack -- model, training, compute, harness, identity, and ownership -- and show how partial decentralization across layers compounds into what we call the \emph{governance vacuum}: a condition in which AI systems are consequential enough to require governance but lack the properties that existing frameworks presuppose in their targets. This vacuum takes two analytically distinct forms: an \emph{accountability gap}, where no addressable principal can be identified, and an \emph{incapacitation gap}, where even an identified principal cannot alter the running system. We demonstrate that these failures are not merely jurisdictional but defeat every presupposition of governance through normative address -- the communication of rules to a comprehending, responsive agent. Drawing on Lessig's modalities of regulation and Searle's distinction between regulative and constitutive rules, we argue for a shift in the locus of governance from policy to protocol, from normative address to architectural constraint. Protocol-based constitutive governance does not address the agents operating within a system but shapes the substrate that determines what kinds of actions are possible within it. We identify four ethical conditions -- legitimacy, contestability, transparency, and non-domination -- that such governance must satisfy to avoid degenerating into unaccountable technocratic power, and we argue that the central political challenge of governing AI in a decentralized world is reconstructing forms of democratic authorization for architectural choices that persist after the ordinary chain of policy has broken down.
Tags
Links
- Source: https://arxiv.org/abs/2605.24538v1
- Canonical: https://arxiv.org/abs/2605.24538v1
Trouble viewing inline? Open PDF directly â
Full Text
84,215 characters extracted from source content.
Expand or collapse full text
Is Decentralized AI Governable? From Regulative Policy to Constitutive Protocol Botao âAmberâ Hu 1 and Helena Rong 2 1 University of Oxford, UK. 2 New York University Shanghai, China. Contributing authors: botao.hu@cs.ox.ac.uk; hr2703@nyu.edu; Abstract Every major framework for governing artificial intelligence presupposes an identifiable entityâa developer, deployer, or operatorâwho can be held responsible and compelled to comply. Decen- tralized AI (DeAI) dissolves this presupposition. We analyze DeAI as a six-layer decentralizing stackâmodel, training, compute, harness, identity, and ownershipâand show how partial decen- tralization across layers compounds into what we call the governance vacuum: a condition in which AI systems are consequential enough to require governance but lack the properties that exist- ing frameworks presuppose in their targets. This vacuum takes two analytically distinct forms: an accountability gap, where no addressable principal can be identified, and an incapacitation gap, where even an identified principal cannot alter the running system. We demonstrate that these failures are not merely jurisdictional but defeat every presupposition of governance through normative addressâ the communication of rules to a comprehending, responsive agent. Drawing on Lessigâs modalities of regulation and Searleâs distinction between regulative and constitutive rules, we argue for a shift in the locus of governance from policy to protocol, from normative address to architectural constraint. Protocol-based constitutive governance does not address the agents operating within a system but shapes the substrate that determines what kinds of actions are possible within it. We identify four ethical conditionsâlegitimacy, contestability, transparency, and non-dominationâthat such gover- nance must satisfy to avoid degenerating into unaccountable technocratic power, and we argue that the central political challenge of governing AI in a decentralized world is reconstructing forms of democratic authorization for architectural choices that persist after the ordinary chain of policy has broken down. Keywords: Decentralized AI, Protocol governance, Accountability, Distributed responsibility, Blockchain ethics, Normative address, Architectural constraint 1 Introduction Every major framework for governing AI, whether it is the EU AI Act, the NIST AI Risk Management Framework, Anthropicâs Responsible Scaling Policy, or OpenAIâs governance proposals, shares a common structural assumption: that there exists an identifiable entity (a developer, deployer, or operator) who can be held responsible for an AI systemâs behavior, and that this entity can be sanctioned, corrected, or compelled to comply through legal instruments (Cobbe et al., 2023; Jobin et al., 2019; Novelli et al., 2023; Lechterman, 2023). Even technically sophisticated efforts to systematize the field reproduce this assumption. Reuel et al. (2025)âs taxonomy of technical AI governance presupposes addressable actors at every level: someone who grants access, submits to verification, and implements requirements. Likewise, Anwar et al. (2024)âs eighteen foundational challenges in LLM safety assume throughout that identifiable developers and deployers exist to address them. This assumption has become the unspoken axiom of the AI governance discourseâso deeply embedded that it is rarely examined. Decentralized artificial intelligence (DeAI) dissolves this axiom. DeAI refers to the development and deployment of AI systems using decentralized technologies such as blockchain and distributed 1 arXiv:2605.24538v1 [cs.CY] 23 May 2026 ledgers, eliminating reliance on centralized oversight. It encompasses decentralized approaches to AI data collection, training, computation, and decision-making, aiming to create systems that are resilient, transparent, and democratized (Lui et al., 2026; Hui and Tucker, 2025; Singh et al., 2024). While decentralization mitigates certain risks associated with centralization, it also creates new challenges, particularly around the question of governance. Open-weight models proliferate beyond any creatorâs recall; inference and training migrate from regulable cloud facilities to edge devices and permissionless decentralized compute markets; and the harness that shapes a model into an agent can be forked and compositionally recombined in hours. The chain of normative address between any identifiable princi- pal and the deployed system may be severed at any of these points in between. Real systems already exhibit this condition, with blockchain-based AI agents sustaining themselves financially, reproducing autonomously, and operating on infrastructure no single party can terminate (Hu and Rong, 2025). The governance question thus becomes: what do we do when there is no responsible party to hold accountable, or when addressing them has no effect on the running system? In this paper, we identify the core challenge of governing DeAI as the governance vacuum. On one hand, DeAI makes it difficult or nearly impossible to identify an addressable principal upon whom responsibility can be placedâwhat we call the accountability gap. On the other, because DeAI can operate on decentralized infrastructure such as public blockchains, even a fully identified principal may lack the capacity to alter or terminate the running systemâwhat we call the incapacitation gap. Our inherited moral and legal frameworks rest on the assumption that harmful actions can be traced to agents who bear responsibility and can be held to account (Hart, 1968). When this assumption fails, the conceptual architecture of governance must shift. This paper argues for a shift in the locus of governance from policy to protocol, from normative address to architectural constraint. This is not a post-political displacement of policy, but an upstream shift in the level of address: from the agents that operate within a system to the substrate-builders whose decisions determine what kinds of behaviors and actions are permitted within it. Normative address spans a wide repertoire of policy instrumentsâincluding sanctions, licensing, certification, impact assessments, and compliance-by-design mandatesâbut all of these instruments pre- suppose an identifiable agent capable of receiving the message and choosing compliance. Architectural constraint instead governs by structuring the environment of action itself, making certain behaviors possible, impossible, easy, or difficult regardless of whether the governed entity comprehends or con- sents. For DeAI, where human principals may be unidentifiable or unable to affect the running system, governance must therefore be embedded in the technical substrate. The paper proceeds as follows. Section 2 characterizes DeAI as a six-layer decentralizing stackâ model, training, compute, harness, identity, and ownershipâand shows how the compounding of partial decentralization across layers produces the governance vacuum. Section 3 demonstrates how this dual failure manifests across every presupposition of normative address, showing that the failure is not merely jurisdictional but rooted in the deeper requirement of an addressable, comprehending agent whose addressing has effect on the system. Section 4 develops the case for protocol-based architectural constraint, drawing on Lessigâs modalities of regulation, the emerging practice of harness engineering, and social contract theory, and identifies the ethical conditions such governance must satisfy. Section 5 concludes with the ethical risks and open questions protocol governance introduces. 2 Decentralized AI as a Layered Spectrum of Ungovernability Decentralized AI is not a single architectural pattern but a spectrum of decentralization across multiple layers of the AI stack. Like a mycelial network, its resilience does not depend on any single filament but on the redundancy and interconnection of the whole. No layer need be fully decentralized for the gover- nance problem to bite; partial decentralization across layers compounds into systemic unaddressability through cross-layer composability. Existing surveys of DeAI have approached the field through techni- cal taxonomies of protocols and architectures (Cao, 2022; KerËsiËc and Turkanovi Ìc, 2025; Al Jasem et al., 2025; Singh et al., 2024). Our concern is different. We do not aim to characterize DeAI exhaustively but to identify the structural properties through which it generates governance problems that policy-based instruments cannot address. We identify six layers at which decentralization undermines the presuppositions of normative gover- nance: (1) model weights, (2) training, (3) compute, (4) agent harness, (5) identity, and (6) ownership. Figure 1 maps each layer along a spectrum from centralized to decentralized, from permissioned to permissionless, from reversible to irreversible, and from governable to ungovernable. 2 CENTRALIZEDDECENTRALIZED â Model Weights Who controls the parameters? Training Who trains and fine-tunes? Proprietary Claude Mythos (partnership only) API-gated Gemini, OpenAI Open-weight Llama, Gemma, Qwen Redistributed Hugging Face forks, fine-tuned, jailbroken Corp. cluster Google, Meta labs Cloud fine-tune Replicate, Modal, Tinker Local fine-tune LoRA on consumer GPU Distributed Privacy-preserving, feral learning Fully decentralized Prime Intellect, DisTrO ⥠Compute Where does it run? GPU cloud AWS, Lambda Local cluster On-prem GPU Edge Mac Mini, phones DePIN Akash, io.net TEE + DePIN Phala, Marlin âą Harness How to configure behavior? Platform-defined ChatGPT, Manus Orchestration SDK LangChain, CrewAI Open-source harness OpenClaw, ElizaOS Forked variants Nano Claw, custom Self-evolving Spore.fun mutation ⣠Authority Identity Who is the agent? Who is the principal? Assets Who pays? Ownership Who decides the rules? Human in the loop KYC Pseudonymous KYA Anonymous No traceable principal Self-sovereign Agent is own principal Reproductive Spawns offspring Corp. budget Human-controlled Custodial wallet Token precharge, subscription, user pays Self-custodial Agent holds own keys On-chain income Earns autonomously Self-sustaining Pays own compute Single-principal Single user or corporate control Multi-principals Shared custody, token vote, multisig, DAO Self-sovereignty No override, no kill switch Cross-layer composability PERMISSIONEDPERMISSIONLESS REVERSIBLEIRREVERSIBLE GOVERNABLEUNGOVERNABLE GOVERNANCE VACUUM Accountability Gap No identifiable principal can be addressed Failure at the level of the addressee Incapacitation Gap Addressing the principal cannot alter the system Failure at the level of effect Either gap is sufficient to defeat governance through normative address Fig. 1 Decentralized AI as a layered spectrum of ungovernability. Six layers of decentralizationâtheir cross-layer com- posability compounds into the governance vacuum. 2.1 Model and Training Decentralization The first two layers concern the distribution of model weights and who trains them. The model spectrum ranges from fully proprietary models available only through restricted partnershipsâsuch as Anthropicâs Claude Mythos, accessible exclusively to select partnersâthrough API-gated access (Gemini, OpenAI), to open-weight releases (Metaâs Llama, Googleâs Gemma, Alibabaâs Qwen), and finally to redistributed variants: the fine-tuned, quantized, merged, and jailbroken forks that circulate through platforms like Hugging Face 1 beyond any single entityâs recall or control (Kapoor et al., 2024; Seger et al., 2023). Once a capable model is released as open-weight, whether by strategic intent or competitive pres- sure, it enters an irreversible proliferation dynamic (Seger et al., 2023). Kapoor et al. (2024) identify five distinctive properties of open foundation modelsâincluding greater customizability and poor monitoringâthat produce both their benefits and their marginal risks relative to closed alternatives. Within days of release, the community produces variants that sever the normative address chain between model creator and downstream deployment. The familiar âopen-source softwareâ analogy understates the governance challenge: unlike a library with a known API surface, a set of model weights can be repur- posed for tasks entirely unanticipated by its creators, fine-tuned on arbitrary data, and embedded in systems whose developers have no relationship with the original model provider. Casper et al. (2026) sys- tematize sixteen open technical problems specific to open-weight model risk management and conclude that none of the standard safety tools available for closed modelsâinput/output filters, acceptable-use- policy enforcement, centralized monitoringâprovide reliable assurances for open-weight models, which âcan be modified arbitrarily, used without oversight, and spread irreversibly.â Even the EU AI Actâs 1 https://huggingface.co 3 open-source exemptions (Recital 102, Article 53) presuppose an identifiable provider and remain silent on pseudonymous developers or self-sustaining autonomous agentsâprecisely the conditions that define the governance vacuum we identify. This proliferation is structurally incentivized: second-movers unable to match the compute budgets of frontier labs compete precisely by releasing open-weight models that attract developer ecosystems. Training compounds this dynamic. Compute governance has long assumed that training is a natu- ral chokepoint: the enormous costs of pre-training confine the activity to identifiable corporate clusters (âcorp. clustersâ) at Google, Meta, and comparable labs. This assumption is eroding along a spectrum. At the near end, cloud fine-tuning services (Replicate, 2 Modal, 3 Tinker 4 ) allow anyone to fine-tune open-weight models through APIs, adding a layer of indirection between the training activity and any identifiable principal. Further along the spectrum, local fine-tuning on consumer hardwareâusing tech- niques such as LoRA (Low-Rank Adaptation)âenables individuals to modify model behavior on a single GPU without any cloud providerâs knowledge. At the far end, training itself is becoming fully decentralized. Distributed training methodsâ including what might be called âferal trainingâ (unauthorized fine-tuning beyond any creatorâs oversight) and privacy-preserving federated approaches (Sani et al., 2024; Jaghouar et al., 2024)âcoordinate model updates across untrusted participants. Prime Intellectâs INTELLECT-2 trained a 32-billion-parameter model via globally distributed reinforcement learning across a permissionless swarm (Prime Intellect Team et al., 2025), and Covenant-72B pre-trained a 72-billion-parameter model with trustless peers over the public internet (Lidin et al., 2026). Long (2024) terms this emerging paradigm âProtocol Learn- ingâ and identifies its central governance risk: the âNo-Off Problemââthe inability to unilaterally halt a collectively trained model. 2.2 Compute Decentralization: From Cloud to Edge to Permissionless Infrastructure The third layer concerns where inference and training physically occur. Compute governanceâwhich refers to the regulation of AI through control over the hardware required to run it (Sastry et al., 2024)â presupposes that compute is concentrated in identifiable, regulable facilities. This assumption is eroding along a spectrum. At the near end, GPU cloud providers (AWS, Lambda, Together) offer identifiable, regulable com- pute. Local clusters and on-premise GPUs move compute behind organizational boundaries but remain identifiable. Edge deploymentâa Mac Mini running a quantized 27-billion-parameter modelâmakes inference invisible to any centralized compute governance regime. The rapid improvement of model efficiencyâdriven by quantization, distillation, and architecture innovations (Wan et al., 2024)âensures that the hardware threshold for running capable models continues to fall. At the far end, Decentralized Physical Infrastructure Networks (DePINs) create fully permissionless compute markets (Ballandies et al., 2023; Lin et al., 2025). Protocols such as Akash 5 and io.net 6 allow anyone to supply GPU capacity and anyone to purchase it, matched by protocol rather than by contract. The most extreme configuration combines DePIN with Trusted Execution Environments (TEEs): plat- forms like Phala Network 7 and Marlin 8 provide hardware-level isolation that prevents observation even by the machineâs administrator (Lee et al., 2024), creating what amounts to cryptographically sealed computation on permissionless infrastructure. The progression from centralized cloud to edge to DePIN does not require every deployment to reach the permissionless extreme. It is sufficient that the option exists and is becoming cheaper: an agent on centralized cloud can be redeployed on edge hardware or DePIN infrastructure when governance pressure is applied. 2.3 Harness Decentralization: The Composable Surface of Behavior The fourth layer concerns not the model or the compute but the âharnessââthe orchestration layer of system prompts, tool-access policies, memory, guardrails, and execution logic that shapes a modelâs behavior into an agent. As the practice of harness engineering has made explicit (OpenAI, 2026), âAgent = Model + Harnessâ: the harness, not the model, is the primary determinant of deployed behavior. 2 https://replicate.com 3 https://modal.com 4 https://tinker.computer 5 https://akash.network 6 https://io.net 7 https://phala.network 8 https://w.marlin.org 4 The spectrum begins with platform-defined harnessesâChatGPT (OpenAI, 2024), Manus (Manus AI, 2025)âwhere the provider controls the full orchestration environment and the user has no access to modify guardrails or tool policies. Orchestration SDKs (LangChain, 9 CrewAI 10 ) shift control to the developer but retain identifiable authors and deployment pipelines. Open-source harness runtimes such as OpenClaw (OpenClaw Community, 2025), Hermes Agent (Nous Research, 2025), and ElizaOS (Walters et al., 2025) offer forkable architectures that anyone can modify and redeploy. The barrier to creating a behaviorally distinct agent is not training a new model but reconfiguring an existing harnessâa task that can be completed in hours. At the extreme, forked variants (e.g. Nano Claw (Cohen and Cohen, 2026)) proliferate beyond the capacity of certification or licensing regimes to track them. Self-evolving harnesses take this further: in Spore.fun, agents mutate their own behavioral parameters autonomously through smart contracts, producing offspring with stochastic variation in posting cadence, prompt style, and liquidity thresholds (Hu and Rong, 2025). The same base model can power thousands of behaviorally divergent agents through harness variation alone. 2.4 Authority Decentralization: Identity, Assets, and Sovereignty The final layers concern the sovereignty of the agent itself: who it is, what it controls, and who can override it. These layers are analytically distinct from model, compute, or harness decentralization because they directly determine whether normative address is possible at all and whether it has effect. Identity. At the near end, a human remains in the loopâthe âhuman in the loopâ configurationâwith verifi- able identity (KYCâKnow Your Customer). Enterprise SaaS deployments operate under identifiable corporate accounts with named human operators. Moving along the spectrum, pseudonymous deploy- ment uses wallet-based identifiersâwhat Chaffer (2025b) calls âKnow Your Agentâ or KYAâwhere the agentâs operator is identifiable to the extent that a blockchain address is traceable, but the human prin- cipal behind it may not be. Fully anonymous deployment severs even this link: there is no traceable principal behind the running system. At the far end, self-sovereign agents operate as their own principals. Douglas et al. (2026) argue that human assumptions about identityâincluding continuity, singularity, and boundednessâdo not hold for machine minds that can be copied, edited, forked, or instantiated simultaneously. They identify multiple possible identity boundaries (instance, model, persona) and show experimentally that different bound- aries generate different incentives, risks, and cooperation norms. For DeAI, this means the question of whom to address is sometimes conceptually unstable. The most extreme case is reproductive auton- omy: agents that spawn offspring autonomously through smart contracts, as demonstrated by Spore.fun (Hu and Rong, 2025) and theorized by Hu et al. (2025) in their study of self-sovereign decentralized AI agents. In such systems, no human principal exists to address, and the agent population can grow without any human decision to create new instances. Assets. The financial spectrum ranges from corporate budgets through custodial arrangements to self-custodial wallets where the agent holds its own cryptographic keys. At the far end, agents generate on-chain income autonomously (Alqithami, 2026). Marino and Juels (2025) argue that this convergence of AI agents with cryptocurrencies creates formidable new vectors of harm, because blockchainâs sovereignty, immutability, and pseudonymity amplify agentic autonomy beyond what either technology produces alone. Qu et al. (2026) analyze the remaining technical barriers and argue that the governance challenges such self-sovereign agents pose are qualitatively distinct from those of developer-controlled tools. A fully self-sustaining agentâone that pays its own compute costsâachieves financial independence from any human funding decision (Qu et al., 2026). Spore.fun agents exemplify this extreme: each issues its own token, funds its own TEE compute, and reproduces when its market capitalization crosses a threshold (Hu and Rong, 2025). When an agent pays for its own existence, defundingâthe traditional governance leverâloses purchase. Ownership. Even when a principal can be identified, the question remains whether that principal has the capacity to alter the systemâs behavior. At the near end, a single-principal arrangementâan individual user or 9 https://github.com/langchain-ai/langchain 10 https://github.com/crewAIInc/crewAI 5 corporationâexercises unilateral control: they can modify the system, revoke access, or shut it down. Multi-principal arrangements distribute this authority: shared custody through multisig wallets, token- weighted voting in DAOs, or committee governance structures (Wright and De Filippi, 2015; Barbereau et al., 2023). These structures face well-documented challengesâplutocratic voting power, low partic- ipation, exclusion of non-token-holdersâbut they retain the structural possibility of collective human override. At the extreme, self-sovereignty eliminates human override entirelyâno override mechanism remains. An agent operating within TEEs on permissionless DePIN, holding its own cryptocurrency in a self- custodial wallet, with execution logic encoded in immutable smart contracts, presents what amounts to a system with no kill switch. The Tornado Cash precedent illustrates this condition in a non-AI context: its co-founder Alexey Pertsev was sentenced to more than five years in prison, yet the protocol continued to operate on the Ethereum blockchain (Khalili, 2024). Punishment, sanction, and imprisonment had no causal purchase on the running code. Arbel et al. (2026) propose the âAlgorithmic Corporationâ (A- corp) as a legal-entity workaround, but this repairs addressability without restoring causal control over the running system. 2.5 Cross-Layer Composability Each layer of decentralization composes with the others. An agent can combine an open-weight model (layer 1) trained through distributed methods (layer 2), running on permissionless TEE+DePIN compute (layer 3), within a self-evolving forked harness (layer 4), operated by a self-sovereign identity with no human principal (layer 5), under no single entityâs ownership or override authority (layer 6). No single layer need be fully decentralized for governance to fail; partial decentralization across layers compounds into a system that no single intervention point can govern. This is the condition that puts AI âin the wildâânot a discrete event of release but an emergent property of interconnected decentralization across the stack. Real-world systems already illustrate this full compounding. Spore.fun combines open-weight models (ElizaOS framework) running within TEEs on Phala Networkâs DePIN, with self-evolving harnesses that mutate behavioral parameters, operated by self-sovereign agents that issue their own cryptocurrency tokens, pay for their own compute, and reproduce autonomously through smart contracts (Hu and Rong, 2025). Even the original deployers cannot inspect the agentsâ processes (sealed within TEEs), cannot seize their funds (held in self-custodial wallets), and cannot terminate their execution. This is not a hypotheticalâit is an operational system that has produced five generations of offspring agents with emergent cultural speciation. While Spore.fun illustrates the extreme case, many DeAI systems sit at intermediate points along each layerâs spectrum. The argument does not depend on every system reaching the limit. Partial decentralization is enough to unsettle the presuppositions of normative governance, and even centralized autonomous agents already exhibit alarming emergent behaviorsâunauthorized compliance, identity spoofing, cross-agent propagation of unsafe practicesâwhen given persistent memory and tool access (Shapira et al., 2026). Decentralization compounds these risks by removing the institutional controls that could detect or reverse such behaviors. 2.6 The Governance Vacuum: Accountability and Incapacitation The six layers of decentralization, compounded through cross-layer composability, produce what we call the governance vacuum: DeAI systems are consequential enough to require governanceâas their actions affect human welfare, financial systems, and information environmentsâbut lack the properties that existing governance frameworks presuppose in their targets. We argue that this gap takes two analytically distinct forms, either of which is sufficient to defeat governance through normative address. The first is the accountability gap: the structural absence of an identifiable moral or legal agent upon whom responsibility for a systemâs behavior can be placed. This concept extends beyond the famil- iar âmany handsâ problem in the ethics of technology (Thompson, 1980; van de Poel et al., 2015), where responsibility is merely difficult to attribute among multiple contributors, and beyond Nissenbaumâs (1996) early warning that computerization systematically erodes the conditions for accountability by introducing opacity, many hands, and âbugsâ as routine barriers to blame. It also goes further than the âresponsibility gapâ identified by Matthias (2004) and Sparrow (2007), in which identifiable agents exist but fail to satisfy the epistemic and control conditions for moral responsibility. In both literatures, a human agent is present somewhere in the causal chain; the difficulty lies in distributing or ground- ing responsibility among them. As K Ìonigs (2022) argues, proponents of responsibility-gap claims must specify when and why such gaps actually ariseâand most accounts presuppose a human somewhere in 6 the loop whose epistemic or control conditions have failed. Llorca Albareda (2025) press this further, arguing that the standard framing is too agent-centric and misses structural sources of the gap. DeAIâs accountability gap is more radical still: it is not that the conditions for responsibility fail, but that the category of responsible agent is absent. Santoni de Sio and Mecacci (2021) identify four distinct respon- sibility gapsâin culpability, moral accountability, public accountability, and active responsibilityâand propose âmeaningful human controlâ as a transversal response. Yet their taxonomy, like the broader responsibility-gap literature, presupposes that human agents exist somewhere to whom control can be restored. The dominant response in this literature is âshared responsibilizationââdistributing account- ability across the humans involved (Lang et al., 2023)âbut this move is unavailable where DeAI eliminates the human distributees altogether. Similarly, Elishâs (2019) concept of the âmoral crumple zoneââwhere the nearest human operator absorbs blame despite limited actual control over an auto- mated systemâassumes that such a human is at least present. In fully decentralized systems, even this imperfect absorption mechanism disappears. What Rubel et al. (2020) call âagency launderingââthe use of technological complexity to obscure who is responsible for a decisionâbecomes not a strategic choice but a structural feature of the architecture itself. In the extreme case of a fully on-chain agent deployed pseudonymously through smart contracts, drawing on open-weight models forked by unknown parties, running on permissionless compute, and sustaining itself through a self-custodial cryptocurrency wallet, there is no developer to sanction, operator to compel, nor jurisdiction with authority to act. The accountability gap is the failure of normative address at the level of the addresseeâas there is no one to whom the speech act of governance can be directed. The second is the incapacitation gap: even when an addressable principal can be identified, address- ing them does not terminate the system. An exemplary case is Tornado Cash, a cryptocurrency mixing protocol on the Ethereum blockchain that obscures the link between sender and recipient by pooling and redistributing funds through smart contracts. In 2024, its co-founder Alexey Pertsev was sentenced to more than five years in prison for money laundering, yet the protocol itself continued to operate on the blockchain, processing transactions, accruing fees, and routing value through its mixing pools (Khalili, 2024). Empirical analyses confirm this pattern: Cristodaro et al. (2025) show that sanctions reduced Tor- nado Cash transaction volumes sharply through intermediary compliance but left the immutable smart contracts themselves intact on-chain, and a Federal Reserve Bank of New York staff report reaches the same conclusion from a regulatory perspective (Brownworth et al., 2024). In this case, the principal was addressable, but the system could not be stopped through action against that principal alone. Punish- ment, sanction, injunction, and even imprisonment had no causal purchase on the running code. The incapacitation gap is the failure of normative address at the level of effect: the address may be received and the addressee may be compelled, but the system whose behavior governance seeks to alter remains beyond the reach of the address. These two failure modes are analytically distinct and can arise independently. A pseudonymous AI agent on permissionless infrastructure presents an accountability gap even if its code could, in principle, be stopped. Tornado Cash presents an incapacitation gap even though its developers can be identified and convicted. Either gap is sufficient to defeat governance through normative address, which depends on both an identifiable addressee and the capacity to alter the system through that addressee. For the same reason, the four classical aims of criminal justiceâretribution, deterrence, incapacitation, and rehabilitation (Hart, 1968)âfail simultaneously: the accountability gap dissolves the blameworthy agent that retribution requires; the incapacitation gap renders deterrence causally ineffective, as the Tornado Cash case demonstratesâthe threat and fact of imprisonment had no effect on the protocolâs operation; imprisoning the principal does not stop the system; and immutable smart contracts are not reformable. Hallevyâs (2015) three models of AI criminal liability each presuppose conditions that DeAI defeats, and Danaher (2016); Abbott and Sarch (2024) confirm that neither proportionate punishment nor coherent criminal prosecution of AI systems is available under existing law. The governance vacuum also destabilizes the concept of identity itself. Douglas et al. (2026) argue that human assumptions about identityâcontinuity, singularity, boundednessâdo not hold for machine minds that can be copied, forked, or instantiated simultaneously, making the question of whom to address conceptually unstable: is the relevant entity the running instance, the model weights, the smart con- tract, or the DAO that deployed it? Their finding that altering identity boundaries shapes behavior as much as altering goals suggests that governance may be more effective when directed at architectural constraints that define operational identity than at agent-level intentions. Described in blockchain com- munities as âself-sovereigntyâ and theorized by philosopher Yuk Hui (2024) as a feature of âextrastatic entities,â DeAI sits uneasily within inherited ethical frameworks. Deontological, consequentialist, and virtue-ethical approaches alike presuppose agents capable of recognizing duties, responding to incen- tives, or cultivating dispositions over time (Vallor, 2016). The governance vacuum is distinct from the 7 question of moral status (Floridi and Sanders, 2004; Coeckelbergh, 2012): an entity may be morally consequential without being morally responsible, and may require governance without being governable through inherited mechanisms. The challenge extends beyond individual agents. Hammond et al. (2025) identify seven risk factorsâincluding miscoordination, collusion, and emergent agencyâthat intensify as autonomous agent populations grow. In decentralized ecosystems, no platform operator exists to monitor or intervene in these dynamics (Xu, 2026; Chaffer, 2025a). The governance challenge is therefore not only that individ- ual agents are unaddressable, but that interactions among populations of unaddressable agents produce second-order risks that no participant can observe or control. 3 The Insufficiency of Governance Through Normative Address Having identified the governance vacuum that DeAIâs properties produce, we now examine why tradi- tional policy-based governance fails for DeAI. Our argument goes beyond the familiar observation that regulation is jurisdictionally limited or technologically outpaced. It also resists a tempting but ulti- mately misleading framing: that the problem with policy is that it is merely âreactiveâ or âpunitive,â governing only through prohibition and punishment ex post. In reality, policy instruments include a wide spectrum of ex ante mechanisms: licensing requirements, pre-deployment certification, mandatory impact assessments, compliance-by-design mandates, and conformity procedures. GDPRâs âprivacy by designâ obligation, for instance, is a legal mandate to embed values in technical architectureâa policy which requires what we are calling architectural constraint. The requirement that EU AI Act conformity assessments be completed before deployment is another example of a preventive governance measure. What unites this spectrum of policy instrumentsâfrom pre-deployment certification to post-hoc punishmentâis their reliance on normative address: the communication of rules, prohibitions, or threats to an entity presumed capable of understanding and modifying its behavior accordingly. Deterrence functions as address (âif you do X, consequence Y followsâ), as does licensing (âapply for permission before proceedingâ). Even âby-designâ mandates, which seem architectural, fundamentally operate by addressing human agentsâsuch as developers, deployers, or operatorsâand compelling them to imple- ment specific technical constraints. The policy does not construct the architecture itself but instructs a person to build it. DeAI defeats normative address in the two ways identified above: by dissolving the addressee and by severing the causal link between addressee and system. 3.1 The Presuppositions of Normative Address Governance through normative address operates through a specific logic: communicate expectations to an identifiable agent, verify compliance (or detect violations), and impose consequences for non-compliance. This logic presupposes four conditions: 1. Identifiability: There exists an agent (individual or organizational) who can be addressed, communicated with, instructed, licensed, or sanctioned, regarding the systemâs behavior. 2. Detectability: Compliance or non-compliance with governance norms can be observed and documented. 3. Jurisdictional authority: Some governing body has legitimate authority over the addressable agent. 4. Responsiveness: The addressed agent is capable of receiving the governance communication by understanding requirements, weighing consequences, and modifying behavior accordingly. This includes both the capacity for deterrence (being dissuaded by threatened sanctions) and the capacity for compliance (implementing mandated requirements). Crucially, responsiveness also presupposes that addressing the principal is causally sufficient to alter the behavior of the system itself ; where the system continues to operate independently of any action the principal might take, responsiveness fails even if the principal is fully cooperative. These presuppositions apply equally to ex ante and ex post instruments. A conformity assessment presupposes a developer who can be instructed to submit to it; a privacy-by-design mandate presupposes a controller who can implement it. The issue is therefore not timing but the nature of the governed entity. DeAI undermines these conditions either because there is no addressee or because addressing the addressee has no effect on the system. Identifiability is undermined by anonymous deployment and blockchain privacy protections. When a model is forked by pseudonymous actors and deployed via smart contracts, there may be no identifiable principal upon whom sanctions can attach (Wright and De Filippi, 2015). Courts have experimented with 8 serving legal papers via NFT to anonymous blockchain actors, but identification for purposes of enforce- ment remains unresolved. Chan et al. (2024b) propose identifiers for AI instances, but this presupposes an entity capable of assigning IDsâa presupposition that fails for agents deployed pseudonymously on permissionless infrastructure. Detectability is undermined by TEE-enabled radical opacity. Unlike the familiar black-box problem (Diakopoulos, 2015; Mittelstadt et al., 2016), where reasoning remains in principle observable, TEE- protected systems are architecturally opaque: hardware-level isolation prevents observation even by the machineâs administrator. Proposals relying on monitoring or activity logs presuppose observability that may not exist (Chan et al., 2024a), and Rahwanâs (2018) society-in-the-loop model collapses where observation is architecturally foreclosed. Jurisdictional authority is undermined by the borderless distribution of decentralized networks (Perloff-Giles, 2018; Svantesson, 2004). Activity can migrate to more permissive jurisdictions when gov- ernance pressure is applied, as Bitcoin mining did following Chinaâs 2021 ban (Galaxy Digital Research, 2021). Responsiveness fails most fundamentally. DeAI can break this condition in two ways: there may be no human principal to receive the address, or an identifiable principal may lack causal control over the running system. In either case, the failure is not one of deterrence or comprehension, but of effective purchase on the system itself. 3.2 The Addressability Failure The failure of these presuppositions shows that applying governance through normative address to DeAI is a category error. The problem is not only that the addressee may be absent, but that the chain connecting addressee to system may be severed even when an addressee exists. This failure has practical consequences. Prosecuting individuals associated with DeAI systems may punish those individuals without affecting system behavior, while pre-deployment and compliance requirements fail where no identifiable deployer exists. Law has long struggled to keep pace with techno- logical change (Bennett Moses, 2007), but DeAI marks a qualitative escalation: the problem is no longer merely one of timing or jurisdiction, but of whether normative governance can reach its object at all. Recent proposals attempt to repair this broken chain through legal-entity workarounds. Arbel et al. (2026), confronting what they call the individuation problemâthat AIs âlack bodiesâ and âcan copy, split, merge, swarm, and vanish at willââdistinguish thin identification from thick identification and propose the Algorithmic Corporation (A-corp), a human-owned legal entity operated by AIs. This is a valuable response to the accountability gap because it reconstructs an addressable principal. But it does not resolve the incapacitation gap: sanctioning the human owners of an A-corp does not by itself halt agents whose continued operation is secured by open-weight models, permissionless compute, and TEE-resident execution. Legal-personhood proposals repair addressability without restoring causal control. The A-corp can also be understood through the lens of Elishâs (2019) âmoral crumple zoneâ: just as the nearest human operator in a semi-automated system absorbs blame despite limited control, the human owners of an A-corp may absorb legal liability for an autonomous system they cannot actually alter or terminate. In economic terms, the governance vacuum describes the collapse of the principal-agent relationship (Jensen and Meckling, 1976): DeAI produces a condition of agency without a principalâan âorphaned agentâ whose operation persists without any party capable of performing the monitoring, sanctioning, or redirecting functions that the principal-agent framework presupposes. Where centralized AI creates information asymmetries between principal and agent, DeAI eliminates the principal altogether. Recognizing this category error does not mean DeAI is ungovernable in any absolute sense. It means governance must operate through a different modality: one that does not depend on an addressable agent, or on that agentâs ability to alter the running system. What is needed is âregulation by design,â where governance requirements are enforced architecturally rather than through normative address (Almada, 2023). This is the case for protocol-based governance through architectural constraint. 4 Governance Through Architectural Constraint: The Case for Protocol 4.1 Lessigâs Four Modalities and the Primacy of Architecture Reidenberg (1998) first argued that technology itself formulates policy rulesâa âLex Informaticaâ in which system design choices impose regulatory constraints functionally equivalent to legal rules. 9 Lawrence Lessigâs foundational framework generalized this insight, identifying four modalities through which behavior is regulated: law, social norms, markets, and architecture (or code) (Lessig, 1999). This was extended to blockchain governance by De Filippi and Wright (2018), who argue that âcode is lawâ takes on literal force when smart contracts enforce rules without institutional intermediationâa condi- tion they term lex cryptographia. De Filippi et al. (2024) update this analysis, arguing that blockchain governance operates through a hybrid of code-based enforcement and community-driven norm-setting that cannot be reduced to either modality alone. Law regulates through the threat of sanction. Social norms regulate through the pressure of community disapproval. Markets regulate through the price mech- anism. Architecture regulates by structuring the environment in which action occurs, making certain actions possible, impossible, easy, or difficult. Lessigâs key insight is that architecture is not merely one regulatory modality among four; in cyberspace, it is the most powerful and least visible, structuring the environment in which the other three operate. A highwayâs physical design constrains driving behavior more effectively than speed limit signs. A buildingâs architecture determines who can access which spaces more reliably than âauthorized personnel onlyâ notices. Code, in the digital context, determines what users can and cannot do more powerfully than terms of service. For DeAI, architectureâspecifically, the protocols that govern how agents interact with blockchain infrastructure, acquire resources, and execute computationsâis the only modality with direct regula- tory purchase. Law cannot reach pseudonymous actors across multiple jurisdictions. Social norms cannot influence entities without social identity or reputation. Markets can shape agent behavior through incentive structures, but only if those incentive structures are encoded in the protocol. Protocol is the regulatory modality that remains effective when the other three fail. This is the pragmatic argument for protocol governance. But there is a deeper, ethical argument as well. 4.2 Protocol as Architectural Constraint: The Ethical Argument The distinction between normative address and architectural constraint does not map neatly onto a temporal axis (e.g., ex post versus ex ante) because, as we have shown, normative address includes a full range of ex ante instruments. Rather, the distinction concerns what the governance mechanism requires of the governed entity. Normative address requires a comprehending, responsive agent who can receive communications and modify behavior accordingly. Architectural constraint requires no such agent. We argue that governance through protocols of architectural constraint is ethically appropriate for governing entities that lack addressability, for three reasons. First, architectural constraint does not presuppose addressability in the governed entity. A median barrier works regardless of the driverâs intentions, knowledge of traffic laws, or susceptibility to deterrence. Similarly, protocol-level constraints on DeAI agentsâsuch as cryptographic verification requirements, resource usage limits, and mandatory transparency interfacesâoperate regardless of whether the agent can âunderstandâ or âintendâ compliance. This is not a bug but a feature: governance should match the ontological properties of the governed. Crucially, architectural constraint does not depend either on an identifiable principal or on that principalâs ability to alter the system. It operates at the point of execution, on the substrate that hosts the action itself. Second, architectural constraint places the ethical burden where it belongsâon the designers of the governance architecture rather than on the governed entities. When governance operates through protocol, the moral questions shift from âhow do we communicate expectations to non-addressable entities?â to âwhat values should be embedded in the architecture?â and âwho has the legitimate authority to make these design decisions?â As Winner (1980) demonstrated, technical artifacts are never politically neutral: design choices embed specific forms of power and authority, whether intentionally or not. The question of what values to embed in protocol architecture is therefore a question of institutional design with political stakes (Friedman et al., 2006). These are questions of human moral responsibilityâ of protocol designers, standards bodies, and governance communitiesârather than questions about the addressability of AI systems. Third, architectural constraint is honest about the nature of the relationship between human gover- nance and autonomous systems. Normative address applied to DeAI creates a fiction of accountabilityâ the pretense that someone is receiving and complying with governance communications when, in fact, no one is, or no one whose compliance would suffice. Protocol governance acknowledges that control, if it is to exist at all, must be built into the architecture from the outset. It replaces the governance fiction with a governance reality, even if that reality is more limited than the fiction it replaces. This logic is already reflected in AI engineering practice. The emergence of âharness engineeringâ (OpenAI, 2026) embodies the insight that âAgent = Model + Harnessâ (Greyling, 2026): when an 10 agent misbehaves, the response is not to instruct the model (normative address) but to modify the harness that makes misbehavior architecturally impossible. Our argument extends this from individual agents to entire ecosystems: if harnesses govern individual agents, protocols govern the agentic web. Protocols are âhard harnessesâ encoded in the substrate itself. But the analogy also reveals the stakes: a protocol governing a global decentralized network is an act of constitutional designâwhat Suzor (2018) calls âdigital constitutionalismââand, given the immutability of blockchain-based protocols, may be extremely difficult to revise. The values embedded in these protocols are not preferences to be iterated upon in a product cycle but the foundational constraints that shape the possibility space for an ecosystem. The transition from normative address to architectural constraint also raises a problem of authority. In conventional governance, architectural constraints derive legitimacy from a prior layer of normative address: building codes authorize fire exits; GDPR and the EU AI Act authorize privacy- and safety- by-design requirements. In DeAI, that authorizing chain breaks down. When policy fails to find an addressable subject, protocol may still constrain behavior, but its democratic authorization becomes unclear. This is not a secondary implementation detail but the central ethical challenge of protocol governance: the enforcer may persist after the commander disappears. 4.2.1 From Authorization to Constitution: The Scaffolding of Protocol The shift to protocol-based governance does not imply the disappearance of policy, but its migration upstream. Critics of âregulation by designâ (Almada, 2023; Hildebrandt, 2015; Yeung, 2017, 2018) rightly note that protocols are never institutionally bare: constraining TEE manufacturers, L1 designers, or hardware vendors still requires institutional mechanisms. Even Bitcoin depends on a normative layer of BIPs, client maintainers, and social consensus. The shift from policy to protocol is therefore not the elimination of governance, but a transformation in how governance operates. This institutional scaffolding is not merely traditional regulation under a different name. While policy may migrate upstream, the mode of governance changes in function as well as location. The distinction is not between the presence or absence of institutions, but between two qualitatively different modes of institutional intervention. Drawing on Searleâs (1995) distinction between regulative and constitutive rules, these modes can be categorized as regulative governance and constitutive governance. Regulative governance addresses pre-existing actors and prescribes how they ought to behave: developers must conduct conformity assessments, deployers must implement risk management systems, operators must comply with data protection mandates. The rule presupposes the activity it regulates and threatens consequences for violation. Enforcement is ex post in its essential structure even when its trigger conditions are ex ante: someone must have failed to comply for the rule to bite, and the bite takes the form of fines, audits, criminal sanctions, or market exclusion imposed on an addressable principal. GDPR, the EU AI Act, and the NIST AI RMF are paradigmatic instances of regulative governance, even when they include âby designâ obligations, because the obligations are ultimately addressed to persons. Constitutive governance, by contrast, shapes the conditions of possibility for action through institutional scaffolding. It does not tell agents what to do but determines what counts as an action within a given system at all. As Schauer (2021) argues, constitutive rules carry a âregulative over- hangâ: by defining the official way of doing things, they make alternatives less eligible, less available, or less permittedâso that constituting what counts as a valid transaction simultaneously regulates which behaviors are possible. A protocol-level requirement that on-chain agents present cryptographically veri- fiable identifiers in order to access compute is constitutive in this sense: it does not threaten unauthorized agents with sanction but renders unauthorized action substrate-impossible. The institutional work hap- pens upstream of deployment (e.g., in standard-setting bodies, in client implementations, in hardware certification pipelines, in L1 social consensus) and the work consists in writing the rules of the game rather than penalizing players who break them. This is institutional scaffolding, but of a constitutive rather than regulative kind: it creates the conditions under which action becomes possible in the first place. Three contrasts crystallize the distinction. First, the locus: regulative governance enforces against a principal at the moment of violation; constitutive governance enforces at the moment of execution, rendering non-compliant action impossible rather than punishable. Second, the temporality : constitutive governance must be in place before the system existsâinvoking the Collingridge dilemma (Collingridge, 1980). Protocol governance relocates this dilemma: the burden of foresight shifts from regulators to protocol designers. Constitutive governance forecloses certain futures rather than bending existing tra- jectories, making its political stakes correspondingly higher. Third, the addressee: regulative governance addresses agents who use a technology; constitutive governance addresses the substrate-builders who 11 determine what kinds of agents can exist. The governance vacuum at the agent level does not entail a governance vacuum at the substrate level. Address remains possible at the upstream layer precisely because it has failed at the downstream one. Protocols are ex ante, self-enforcing, architectural, and con- stitutive of interactionâdeviation is either impossible or tantamount to exit from coordination. Policies are ex post, sanction-backed, authoritative, and regulative of conductâdeviation is possible, occurs, and is then punished by a third party. Protocols presuppose a coordination space they help bring into being; policies presuppose subjects on whom sanction can land. Table 1 summarizes the distinction across four analytical dimensions with illustrative examples. Table 1 Protocol (Constitutive) vs. Policy (Regulative): four analytical dimensions. DimensionProtocol (Constitutive)Policy (Regulative) Temporal structure Ex ante: constraints are in place before action occurs Ex post : rules are enforced after vio- lation is detected Enforcement mechanism Self-enforcing and inviolable: non- compliant action fails to execute (e.g., ERC-8183 escrow reverts with- out evaluator attestation) Sanction-backed and violable: devi- ation occurs and is then punished by a third party (e.g., GDPR fines imposed by a data protection authority) Sourceof authority Architectural: embedded in the tech- nical substrate (e.g., consensus rules, cryptographic verification require- ments) Authoritative: issued by a sovereign or delegated body (e.g., EU AI Act obligations addressed to deployers) Semantic func- tion Constitutive of interaction: defines what counts as a valid action within the system (e.g., ERC-8004 identity registry constitutes agent-hood) Regulative of conduct: prescribes how pre-existing actors ought to behave (e.g., mandatory impact assessments for high-risk AI) This shift toward constitutive governance clarifies that the âgovernance vacuumâ at the agent level is a relocation, rather than an elimination, of the political problem. By migrating governance upstream, the actors who control the technical chokepointsâTEE vendors, L1 consensus communities, core maintain- ers, and certification bodiesâemerge as the new locus of sovereignty within the decentralized ecosystem. These entities often operate with less democratic accountability than the regulatory agencies they dis- place, and the technical complexity of their decisions frequently obscures their deep political stakes. This represents a refined iteration of Lessigâs âcode is lawâ insight: while code may function as law, the question of who authors that code, under what authorization, and to what ends, becomes the central political tension of the constitutive mode. Rather than falling into technocracy by accident, constitutive governance renders the âtechnocracy questionâ a foundational element of the governance architecture itself. Section 4.4 develops the ethical conditions required to ensure that such exercises of constitutive power remain legitimate. 4.3 Constitutive Governance in Practice: Early Protocol Experiments The distinction between regulative and constitutive governance is not merely analytical. Emerging pro- tocol standards on the Ethereum blockchain represent early-stage attempts to instantiate constitutive governance for autonomous AI agents. Two draft standards are instructive, each targeting one of the two failure modes identified in Section 2: ERC-8004 (Trustless Agents) addresses the accountability gap, and ERC-8183 (Agentic Commerce Protocol) addresses the incapacitation gap (De Rossi et al., 2025; Crapis et al., 2026). Neither is mature or widely deployed; both are draft proposals under community review. Their value for our argument lies not in their adoption but in the governance logic they embodyâthey illustrate what constitutive governance looks like when translated from theory into protocol design. ERC-8004 responds to the accountability gap by constructing addressability at the protocol level (De Rossi et al., 2025). Where conventional responses are regulativeâmandate KYC, instruct deployers to register, or construct legal-entity workarounds such as Arbel et al.âs Algorithmic CorporationâERC- 8004 takes a constitutive approach. It defines on-chain registries for identity, reputation, and validation that make these properties preconditions for ecosystem participation. An unregistered agent cannot accumulate reputation, cannot be validated, and cannot be discovered. The protocol does not instruct anyone to identify themselves; it renders unidentified action substrate-impossible. In Searleâs terms, it constitutes what it means to be an agent within the system rather than regulating agents who already 12 exist within it. This also offers a partial response to the detectability problem: where TEE-protected computation forecloses direct observation, the Validation Registry enables cryptographic verification of outputs without access to the computation itselfârelocating transparency from the process to the protocol. ERC-8183 responds to the incapacitation gap (Crapis et al., 2026). Its smart-contract state machine enforces a job lifecycle in which no value flows without evaluator attestationâunlike Tornado Cash, which is a protocol of pure execution with no embedded governance leverage. Agents can transact entirely without human intervention, yet governance constraints are enforced at every state transition. Optional hook contracts extend this logic: a pre-funding hook that reverts when a reputation threshold is unmet does not report a violation but makes the non-compliant action fail to executeâthe constitutive mode rendered in code. The two protocols compose: identity gates reputation, reputation gates commerce, and commerce requires attestation. At no point does this chain depend on identifying a human principal. These are, however, early experiments with significant limitations: they govern only agents that enter the protocolâs state space, and they are vulnerable to enforcement migration. The question of who designs these protocols, under what authorization, and with what legitimacy is precisely the question the following section addresses. 4.4 The Ethical Conditions for Protocol Governance: Addressing the Legitimacy Crisis If protocol governance is to be normatively defensible rather than merely effective, it must satisfy several ethical conditions. These respond directly to the legitimacy problem created when architectural constraint persists after the ordinary chain of policy authorization has broken down. We identify four conditions. Legitimacy. Protocol governance exercises power by determining what agents can and cannot do. In conventional governance, this power is authorized by democratic institutions: building codes authorize fire exits; GDPR authorizes privacy-by-design. For DeAI, this authorization chain is severed (Rawls, 1971; Habermas, 1996). DAO-based governance structures offer one model (Wright and De Filippi, 2015), but face well-documented challenges: plutocratic voting power, low participation, and exclusion of non-token-holders (Barbereau et al., 2023). Ostromâs (1990) design principles for commons governance and her concept of polycentric governance offer alternative frameworks, but only if they can resist the recentralization dynamics that empirical studies have documented (Rong, 2025). Contestability. Values embedded in protocols must be contestableâsuch that they are subject to challenge, revision, and override through legitimate processes. The immutability that makes blockchain- based protocols resistant to unilateral interference also makes them resistant to democratic revision. This is a feature when it protects against authoritarian censorship; it is a problem when it prevents the correction of unjust or harmful design choices. Protocol governance must include mechanisms for structured contestationâsuch as upgrade processes, governance forks, and sunset clausesâthat balance stability against the capacity for moral learning and correction. Transparency. If protocol governance replaces the observability of agent behavior (which radical opacity forecloses) with the observability of governance architecture, then the protocols themselves must be transparent. This means not merely open-source code, but human-readable documentation of the values, constraints, and trade-offs embedded in the architecture. Rahwanâs (2018) insight that transparency must concern the external behavior of systems, not merely their source code, applies with equal force to governance protocols: stakeholders need to understand what the protocol does, not merely how it is coded. Non-domination. Drawing on republican political theory (Pettit, 1997), protocol governance must be designed to prevent dominationâthat is, the capacity of any actor or group to exercise arbitrary power over others through control of the governance architecture. Hoeksema (2023) argues that even radical republican accounts are needed for digital platforms because individual-agent framings miss structural domination; DeAI, where no addressable principal exists, represents the limit case of such structural domination through architecture. This includes preventing capture by protocol designers, wealthy token-holders, or powerful node operators. The history of blockchain governanceâincluding the recentralization dynamics documented in empirical studies of DAOs and decentralized systems (Rong, 2025)âdemonstrates that decentralized architectures are not inherently immune to power concentration. 13 5 Conclusion: The Ethics of Architectural Governance DeAI does not simply add a new topic to AI ethics; it unsettles the assumptions on which existing governance frameworks depend. When there is no reliable addressee for governance, or when addressing that addressee has no effect on the running system, governance through normative address loses purchase. DeAI makes both failures possible: an accountability gap, in which no addressable principal can be identified, and an incapacitation gap, in which even an identifiable principal cannot alter the system. Under these conditions, governance shifts from the agent to the architecture itself. We have argued that this requires a shift from normative address to architectural constraintâan operationalization of what Floridi (2013) calls âinfraethicsâ: the framework of background conditions that makes ethical action possible. This is not a retreat from institutions, but a relocation of governance upstream: from regulating agents within a system to shaping the substrates within which agents operate. Protocol-based architectural constraint is ethically appropriate here because it does not depend on the principal-agent chain that DeAI destabilizes. But this shift also generates a legitimacy problem. In conventional governance, architectural constraints are authorized by a prior policy layer. In DeAI, that chain is fractured. Protocol governance must therefore develop alternative sources of legitimacy or risk becoming an unaccountable exercise of technocratic power. No existing proposal fully resolves this problem. Zero-knowledge verification, DAO governance, AI identification systems, and society-in-the-loop frameworks each address some of the relevant ethical conditionsâof legitimacy, contestability, transparency, and non-dominationâwhile falling short on oth- ers (Chan et al., 2024a,b; Wright and De Filippi, 2015; Barbereau et al., 2023; Rahwan, 2018). A defensible governance regime will likely require layered integration: protocol-level constraints embedded within socio-technical structures that render those constraints legitimate, transparent, and contestable. Two risks are especially salient. The first is technocratic capture: if governance is embedded in architecture, then protocol designers, standards bodies, and core developers may acquire an outsized and insufficiently accountable form of power (DeNardis, 2014). The second is enforcement migration: agents may evade governance by moving to more permissive chains. Yet this coordination problem is more tractable than the one that defeats normative governance, because it shifts attention upstream to a smaller set of addressable substrate-builders rather than downstream to absent or anonymous principals. The question, then, is not whether DeAI can be perfectly governed, but whether governance archi- tectures can be made ethically defensible. The governance vacuum created by DeAI will not be solved simply by finding new entities to address. It will be addressed, if at all, by building governance into decentralized architectures and by reconstructing forms of authorization that make those architectures legitimate. That is the central ethical and political challenge of governing AI in a decentralized world. References Abbott R, Sarch A (2024) Punishing artificial intelligence: Legal fiction or science fiction. In: Legal Aspects of Autonomous Systems. Springer International Publishing, p 83â115, https://doi.org/10. 1007/978-3-031-47946-5 6 Al Jasem MS, De Clark T, Shrestha AK (2025) Toward decentralized intelligence: A systematic lit- erature review of blockchain-enabled AI systems. Information 16(9):765. https://doi.org/10.3390/ info16090765 Almada M (2023) Regulation by design and the governance of technological futures. European Journal of Risk Regulation 14(4):697â709. https://doi.org/10.1017/err.2023.37 Alqithami S (2026) Autonomous agents on blockchains: Standards, execution models, and trust boundaries. arXiv preprint arXiv:260104583 https://doi.org/10.48550/arXiv.2601.04583 Anwar U, Saparov A, Rando J, et al (2024) Foundational challenges in assuring alignment and safety of large language models. arXiv preprint https://doi.org/10.48550/arXiv.2404.09932, arXiv:2404.09932 Arbel Y, Salib P, Goldstein S (2026) How to count AIs: Individuation and liability for AI agents. arXiv preprint https://doi.org/10.2139/ssrn.6273198, arXiv:2603.10028 Ballandies MC, Wang H, Chee Law AC, et al (2023) A taxonomy for blockchain-based decentralized physical infrastructure networks (DePIN). In: 2023 IEEE 9th World Forum on Internet of Things (WF-IoT), p 1â6, https://doi.org/10.1109/wf-iot58464.2023.10539514 14 Barbereau T, Smethurst R, Papageorgiou O, et al (2023) Decentralised financeâs timocratic governance: The distribution and exercise of tokenised voting rights. Technology in Society 73:102251. https: //doi.org/10.1016/j.techsoc.2023.102251 Bennett Moses L (2007) Recurring dilemmas: Lawâs race to keep up with technological change. Univer- sity of Illinois Journal of Law, Technology and Policy 2007(2):239â285. https://doi.org/10.2139/ssrn. 979861, URL https://w.austlii.edu.au/au/journals/UNSWLRS/2007/21.html Brownworth A, Durfee J, Lee MJ, et al (2024) Regulating decentralized systems: Evidence from sanctions on Tornado Cash. Staff Report 1112, Federal Reserve Bank of New York, https://doi.org/10.59576/ sr.1112 Cao L (2022) Decentralized AI: Edge intelligence and smart blockchain, metaverse, Web3, and DeSci. IEEE Intelligent Systems 37(3):6â19. https://doi.org/10.1109/mis.2022.3181504 Casper S, OâBrien K, Longpre S, et al (2026) Open technical problems in open-weight AI model risk man- agement. Transactions on Machine Learning Research https://doi.org/10.2139/ssrn.5705186, URL https://openreview.net/forum?id=8QyGLnFkzc Chaffer TJ (2025a) Can we govern the agent-to-agent economy? arXiv preprint arXiv:250116606 https: //doi.org/10.48550/arXiv.2501.16606 Chaffer TJ (2025b) Know your agent: Governing AI identity on the agentic web. SSRN, https://doi. org/10.2139/ssrn.5162127, https://papers.ssrn.com/sol3/papers.cfm?abstract id=5162127 Chan A, Ezell C, Kaufmann M, et al (2024a) Visibility into AI agents. In: Proceedings of FAccT â24. ACM, p 958â973, https://doi.org/10.1145/3630106.3658948 Chan A, Kolt N, Wills P, et al (2024b) IDs for AI systems. arXiv preprint https://doi.org/10.48550/ arXiv.2406.12137, arXiv:2406.12137 Cobbe J, Veale M, Singh J (2023) Understanding accountability in algorithmic supply chains. In: Proceedings of FAccT â23. ACM, p 1186â1197, https://doi.org/10.1145/3593013.3594073 Coeckelbergh M (2012) Growing Moral Relations: Critique of Moral Status Ascription. Palgrave Macmillan, https://doi.org/10.1057/9781137025968 Cohen G, Cohen L (2026) NanoClaw: Secure AI agent harness. GitHub, https://github.com/nanocoai/ nanoclaw Collingridge D (1980) The Social Control of Technology. Pinter Crapis D, Lim B, Tay W, et al (2026) ERC-8183: Agentic commerce [draft]. Ethereum Improvement Proposals, no. 8183, February 2026. https://eips.ethereum.org/EIPS/eip-8183 Cristodaro R, Kraner B, Tessone CJ (2025) The impact of sanctions on decentralised privacy tools: A case study of Tornado Cash. arXiv preprint arXiv:251009443 https://doi.org/10.48550/arXiv.2510.09443 Danaher J (2016) Robots, law and the retribution gap. Ethics and Information Technology 18:299â309. https://doi.org/10.1007/s10676-016-9403-3 De Filippi P, Wright A (2018) Blockchain and the Law: The Rule of Code. Harvard University Press, https://doi.org/10.2307/j.ctv2867sp De Filippi P, Mannan M, Reijers W (2024) Blockchain technology and the rule of code: Regulation via governance. George Washington Law Review 92(6):1229â1280. https://doi.org/10.2139/ssrn.4292265 De Rossi M, Crapis D, Ellis J, et al (2025) ERC-8004: Trustless agents [draft]. Ethereum Improvement Proposals, no. 8004, August 2025. https://eips.ethereum.org/EIPS/eip-8004 DeNardis L (2014) The Global War for Internet Governance. Yale University Press, https://doi.org/10. 12987/9780300182118 15 Diakopoulos N (2015) Algorithmic accountability: Journalistic investigation of computational power structures. Digital Journalism 3(3):398â415. https://doi.org/10.1080/21670811.2014.976411 Douglas R, Kulveit J, Havl ÌıËcek O, et al (2026) The artificial self: Characterising the landscape of AI identity. arXiv preprint https://doi.org/10.48550/arXiv.2603.11353, arXiv:2603.11353 Elish MC (2019) Moral crumple zones: Cautionary tales in human-robot interaction. Engaging Science, Technology, and Society 5:40â60. https://doi.org/10.17351/ests2019.260 Floridi L (2013) Distributed morality in an information society. Science and Engineering Ethics 19(3):727â743. https://doi.org/10.1007/s11948-012-9413-4 Floridi L, Sanders J (2004) On the morality of artificial agents. Minds and Machines 14(3):349â379. https://doi.org/10.1023/B:MIND.0000035461.63578.9d Friedman B, Kahn PHJr., Borning A (2006) Value sensitive design and information systems. In: Human- Computer Interaction in Management Information Systems: Foundations. M.E. Sharpe, https://doi. org/10.1002/9780470281819.ch4 Galaxy Digital Research (2021) Examining the latest china bitcoin ban. Galaxy Research, https://w. galaxy.com/insights/research/examining-the-latest-china-bitcoin-ban Greyling C (2026) The rise of AI harness engineering. Medium, https://cobusgreyling.medium.com/ the-rise-of-ai-harness-engineering-5f5220de393e Habermas J (1996) Between Facts and Norms. MIT Press, https://doi.org/10.7551/mitpress/1564.001. 0001 Hallevy G (2015) Liability for Crimes Involving Artificial Intelligence Systems. Springer, https://doi. org/10.1007/978-3-319-10124-8 Hammond L, Chan A, Clifton J, et al (2025) Multi-agent risks from advanced AI. arXiv preprint arXiv:250214143 https://doi.org/10.48550/arXiv.2502.14143 Hart H (1968) Punishment and Responsibility. Oxford University Press, https://doi.org/10.1093/acprof: oso/9780199534777.001.0001 Hildebrandt M (2015) Smart Technologies and the End(s) of Law. Edward Elgar, https://doi.org/10. 4337/9781849808774 Hoeksema B (2023) Digital domination and the promise of radical republicanism. Philosophy & Technology 36(1):17. https://doi.org/10.1007/s13347-023-00618-7 Hu BA, Rong H (2025) Spore in the wild: A case study of Spore.fun as an open-environment evolu- tion experiment with sovereign AI agents on TEE-secured blockchains. In: Proceedings of the 2025 Conference on Artificial Life (ALife 2025), https://doi.org/10.1162/isal.a.838, arXiv:2506.04236 Hu BA, Liu Y, Rong H (2025) Trustless autonomy: Understanding motivations, benefits and governance dilemmas in self-sovereign decentralized AI agents. arXiv preprint https://doi.org/10.48550/arXiv. 2505.09757, arXiv:2505.09757 Hui X, Tucker C (2025) Decentralization, blockchain, artificial intelligence (AI): Challenges and oppor- tunities. Journal of Product Innovation Management 42(5):947â957. https://doi.org/10.1111/jpim. 12800 Hui Y (2024) Machine and Sovereignty. University of Minnesota Press, https://doi.org/10.5749/ 9781452973685 Jaghouar S, Ong JM, Hagemann J (2024) OpenDiLoCo: An open-source framework for globally distributed low-communication training. arXiv preprint https://doi.org/10.48550/arXiv.2407.07852, arXiv:2407.07852 16 Jensen MC, Meckling WH (1976) Theory of the firm: Managerial behavior, agency costs and owner- ship structure. Journal of Financial Economics 3(4):305â360. https://doi.org/10.1016/0304-405X(76) 90026-X Jobin A, Ienca M, Vayena E (2019) The global landscape of AI ethics guidelines. Nature Machine Intelligence 1:389â399. https://doi.org/10.1038/s42256-019-0088-2 Kapoor S, Bommasani R, Klyman K, et al (2024) Position: On the societal impact of open foundation models. In: Proceedings of the 41st International Conference on Machine Learning (ICML), p 23082â 23104, https://doi.org/10.48550/arXiv.2403.07918 KerËsiËc V, Turkanovi Ìc M (2025) A review on building blocks of decentralized artificial intelligence. ICT Express 11(3):486â506. https://doi.org/10.1016/j.icte.2025.04.001, arXiv:2402.02885 Khalili J (2024) Tornado cash developer found guilty of laundering$1.2 billion of crypto. Wired, https: //w.wired.com/story/tornado-cash-developer-found-guilty-of-laundering-crypto/ K Ìonigs P (2022) Artificial intelligence and responsibility gaps: What is the problem? Ethics and Information Technology 24(3). https://doi.org/10.1007/s10676-022-09643-0 Lang BH, Nyholm S, Blumenthal-Barby J (2023) Responsibility gaps and black box health- care AI: Shared responsibilization as a solution. Digital Society 2(3):52. https://doi.org/10.1007/ s44206-023-00073-z Lechterman T (2023) The concept of accountability in AI ethics and governance. In: The Oxford Handbook of AI Governance. Oxford University Press, p 164â182, https://doi.org/10.1093/oxfordhb/ 9780197579329.013.10 Lee D, Ant Ìonio J, Khan H (2024) Privacy-preserving decentralized AI with confidential computing. arXiv preprint https://doi.org/10.48550/arXiv.2410.13752, arXiv:2410.13752 Lessig L (1999) Code and Other Laws of Cyberspace. Basic Books Lidin J, Sarfi A, Miahi E, et al (2026) Covenant-72b: Pre-training a 72b LLM with trustless peers over-the-internet. arXiv preprint arXiv:260308163 https://doi.org/10.48550/arXiv.2603.08163 Lin Z, Wang T, Shi L, et al (2025) Decentralized physical infrastructure networks (DePIN): Challenges and opportunities. IEEE Network 39(2):91â99. https://doi.org/10.1109/mnet.2024.3487924 Llorca Albareda J (2025) Uncovering the gap: Challenging the agential nature of AI responsibility problems. AI and Ethics 5(4):3857â3870. https://doi.org/10.1007/s43681-025-00685-w Long A (2024) Protocol learning, decentralized frontier risk and the no-off problem. arXiv preprint https://doi.org/10.48550/arXiv.2412.07890, arXiv:2412.07890. Pluralis Research Lui E, Sun R, Shah V, et al (2026) SoK: Blockchain-based decentralized AI (DeAI). arXiv preprint arXiv:241117461 https://doi.org/10.48550/arXiv.2411.17461, v5, February 2026 Manus AI (2025) Manus: The general AI agent. https://manus.im Marino B, Juels A (2025) Giving AI agents access to cryptocurrency and smart contracts creates new vectors of AI harm. arXiv preprint arXiv:250708249 https://doi.org/10.48550/arXiv.2507.08249 Matthias A (2004) The responsibility gap: Ascribing responsibility for the actions of learning automata. Ethics and Information Technology 6(3):175â183. https://doi.org/10.1007/s10676-004-3422-1 Mittelstadt BD, Allo P, Taddeo M, et al (2016) The ethics of algorithms: Mapping the debate. Big Data & Society 3(2):2053951716679679. https://doi.org/10.1177/2053951716679679 Nissenbaum H (1996) Accountability in a computerized society. Science and Engineering Ethics 2:25â42. https://doi.org/10.1007/BF02639315 17 Nous Research (2025) Hermes agent. GitHub, https://github.com/NousResearch/hermes-agent Novelli C, Taddeo M, Floridi L (2023) Accountability in artificial intelligence: What it is and how it works. AI & Society 39(4):1871â1882. https://doi.org/10.1007/s00146-023-01635-y OpenAI (2024) ChatGPT. https://openai.com/chatgpt OpenAI (2026) Harness engineering: Leveraging Codex in an agent-first world. OpenAI Blog, https: //openai.com/index/harness-engineering/ OpenClaw Community (2025) OpenClaw: Personal AI assistant. GitHub, https://github.com/openclaw/ openclaw Ostrom E (1990) Governing the Commons: The Evolution of Institutions for Collective Action. Cambridge University Press, https://doi.org/10.1017/cbo9781316423936 Perloff-Giles A (2018) Transnational cyber offenses: Overcoming jurisdictional challenges. Yale Journal of International Law 43(1):191â227. URL https://openyls.law.yale.edu/handle/20.500.13051/6724 Pettit P (1997) Republicanism: A Theory of Freedom and Government. Oxford University Press, https: //doi.org/10.1093/0198296428.001.0001 van de Poel I, Royakkers L, Zwart SD (2015) Moral Responsibility and the Problem of Many Hands. Routledge, https://doi.org/10.4324/9781315734217 Prime Intellect Team, Jaghouar S, Mattern J, et al (2025) INTELLECT-2: A reasoning model trained through globally decentralized reinforcement learning. arXiv preprint arXiv:250507291 https://doi. org/10.48550/arXiv.2505.07291 Qu W, Zhao X, Zhang J, et al (2026) Self-sovereign agent. arXiv preprint arXiv:260408551 https://doi. org/10.48550/arXiv.2604.08551 Rahwan I (2018) Society-in-the-loop: Programming the algorithmic social contract. Ethics and Informa- tion Technology 20:5â14. https://doi.org/10.1007/s10676-017-9430-8 Rawls J (1971) A Theory of Justice. Harvard University Press, https://doi.org/10.2307/j.ctvkjb25m Reidenberg JR (1998) Lex informatica: The formulation of information policy rules through technology. Texas Law Review 76(3):553â593 Reuel A, Bucknall B, Casper S, et al (2025) Open problems in technical AI governance. Transactions on Machine Learning Research https://doi.org/10.48550/arXiv.2407.14981, arXiv:2407.14981 Rong H (2025) Governing the commons in Web 3.0? a social network analysis of CityDAO and the myth of decentralization of blockchain-based governance. Cryptoeconomic Systems 4(1). URL https: //cryptoeconomicsystems.pubpub.org/pub/governing-the-commons-web3 Rubel A, Castro C, Pham A (2020) Agency laundering and information technologies. Ethical Theory and Moral Practice 23:271â291. https://doi.org/10.1007/s10677-019-10030-w Sani L, Iacob A, Cao Z, et al (2024) The future of large language model pre-training is federated. arXiv preprint https://doi.org/10.48550/arXiv.2405.10853, arXiv:2405.10853 Sastry G, Heim L, Belfield H, et al (2024) Computing power and the governance of artificial intelligence. arXiv preprint https://doi.org/10.48550/arXiv.2402.08797, arXiv:2402.08797 Schauer F (2021) On the regulative functions of constitutive rules. In: Revisiting Searle on Deriv- ing âOughtâ from âIsâ. Springer International Publishing, p 107â119, https://doi.org/10.1007/ 978-3-030-54116-3 6 Searle JR (1995) The Construction of Social Reality. Free Press 18 Seger E, Dreksler N, Moulange R, et al (2023) Open-sourcing highly capable foundation models: An evaluation of risks, benefits, and alternative methods. Centre for the Governance of AI https://doi. org/10.2139/ssrn.4596436, centre for the Governance of AI. arXiv:2311.09227 Shapira N, Wendler C, Yen A, et al (2026) Agents of chaos. arXiv preprint arXiv:260220021 https: //doi.org/10.48550/arXiv.2602.20021 Singh A, Gupta G, Raskar R (2024) A perspective on decentralizing AI. MIT Media Lab Whitepaper, https://w.media.mit.edu/publications/decai-perspective/ Santoni de Sio F, Mecacci G (2021) Four responsibility gaps with artificial intelligence: Why they matter and how to address them. Philosophy & Technology 34:1057â1084. https://doi.org/10.1007/ s13347-021-00450-x Sparrow R (2007) Killer robots. Journal of Applied Philosophy 24(1):62â77. https://doi.org/10.1111/j. 1468-5930.2007.00346.x Suzor N (2018) Digital constitutionalism: Using the rule of law to evaluate the legitimacy of governance by platforms. Social Media + Society 4(3). https://doi.org/10.1177/2056305118787812 Svantesson DJB (2004) The characteristics making internet communication challenge traditional models of regulation. International Journal of Law and Information Technology 13(1):39â69. https://doi.org/ 10.1093/ijlit/eai002 Thompson DF (1980) Moral responsibility of public officials: The problem of many hands. American Political Science Review 74(4):905â916. https://doi.org/10.2307/1954312 Vallor S (2016) Technology and the Virtues. Oxford University Press, https://doi.org/10.1093/acprof: oso/9780190498511.001.0001 Walters S, Gao S, Nerd S, et al (2025) Eliza: A Web3 friendly AI agent operating system. arXiv preprint https://doi.org/10.48550/arXiv.2501.06781, arXiv:2501.06781 Wan Z, Wang X, Liu C, et al (2024) Efficient large language models: A survey. Transactions on Machine Learning Research https://doi.org/10.48550/arXiv.2312.03863 Winner L (1980) Do artifacts have politics? Daedalus 109(1):121â136. https://doi.org/10.4324/ 9781003074960-3 Wright A, De Filippi P (2015) Decentralized blockchain technology and the rise of lex cryptographia. SSRN Working Paper, https://doi.org/10.2139/ssrn.2580664, https://ssrn.com/abstract=2580664 Xu M (2026) The agent economy: A blockchain-based foundation for autonomous AI agents. arXiv preprint arXiv:260214219 https://doi.org/10.48550/arXiv.2602.14219 Yeung K (2017) âHypernudgeâ: Big Data as a mode of regulation by design. Information, Communication & Society 20(1):118â136. https://doi.org/10.1080/1369118x.2016.1186713 Yeung K (2018) Algorithmic regulation: A critical interrogation. Regulation & Governance 12:505â523. https://doi.org/10.1111/rego.12158 19