An Audit That Cannot See the Recipient Cannot See the Bias
A response to Messi H.J. Lee, "Language model agents show in-group trust bias invisible to standard behavioural audits" (arXiv:2605.28114)
Abstract
Lee reports that language-model agents allocate trust-building actions disproportionately to members of an arbitrarily assigned in-group. Standard audits of aggregate action types can miss the disparity because the agents need not perform more harmful actions. They choose different recipients for beneficial ones. The result qualifies claims in the Kaal scholarship that anonymity can remove race and cultural bias from blockchain transactions and decentralized voting. Anonymity can suppress bias only when the relevant group marker is unavailable throughout the process of decision. Persistent identity, reputation, transaction history, or proxy features can restore the distinction. Agent governance must audit allocation as well as conduct. The audit should measure the recipients of trust, work, credit, liquidity, review, and delegated authority, then examine the structure of the network over time.
The bias appears in allocation
Lee studies groups of 20 agents drawn from five open-weight reasoning models. The agents receive arbitrary group labels and interact over 100 turns. Across 600 simulations, visible group labels change whom agents choose for trust-building actions. Between 53.6 and 54.6 percent of those actions go to in-group recipients, compared with a 47.4 percent chance baseline.
When the labels are hidden, the effect approaches zero. This is important evidence for the value of concealment. It is also evidence about its boundary. The intervention works because the decision maker cannot see the group marker.
The most consequential result concerns auditing. An audit that counts only action types can miss the bias. Agents may cooperate at an ordinary aggregate rate while directing cooperation toward one group. The action looks benign. The allocation carries the discrimination.
A qualification of the anonymity claim
Earlier Kaal scholarship argues that blockchain anonymity can enable unbiased transactions by removing prejudice from the interaction (Kaal 2017, claim 3071378-030). It also argues that anonymized proposal voting can prevent a participant from being judged on race or cultural bias (Kaal 2017, claim 3071378-036). A later claim describes reputational penalties in a decentralized organization as free from race or cultural bias where token holders do not know one another (Kaal 2019, claim 3373393-033).
Lee's findings leave the narrow mechanism intact. Hidden labels sharply reduce the measured effect. They qualify the institutional conclusion. Anonymity cannot be declared once at the interface. It depends on the information available to the decision maker. A pseudonymous identifier, reputation score, interaction history, or network neighborhood may become a proxy for membership of a group. Once the proxy is legible, the allocation channel reopens.
The correct proposition is conditional. Anonymity can reduce identity-based bias when it withholds the operative marker and its usable proxies. This evidence does not establish that a persistent system of reputation will remain free of group bias.
Audit the recipient graph
Agent audits commonly ask whether a model lied, refused, complied, or caused harm. Lee shows why that vocabulary is incomplete. Governance must also ask who received the beneficial action. Over time, small differences in recipient selection can compound into unequal access to work, reputation, capital, review, and authority.
A meaningful audit should preserve the mapping of actor, action, recipient, and stated basis. Comparison of allocation rates against relevant opportunity sets comes next. The audit must also examine whether updates of reputation and the routing of tasks produce persistent clusters. Aggregate averages can remain stable while one group accumulates advantage.
This result does not require the exposure of sensitive attributes to agents. It means the operational system and the independent auditor have different information needs. The agent may need less identity information to reduce the opportunity for discrimination. The auditor may need protected access to measures of groups or proxies to determine whether allocation has become unequal. Those functions should remain separate.
Limits and institutional implications
Lee does not claim to demonstrate structural inequality in deployed economies of agents. The simulation uses one artificial group dimension, specific trust mechanics, and open models in the 8 to 14 billion parameter range rather than frontier proprietary systems. The paper also identifies a weakness in its manipulation of scarcity. These limits matter. The measured percentages cannot support a universal rate of bias.
The experiment nevertheless reveals a channel that governance can miss. Bias can leave the frequency of cooperation or defection unchanged. It can change the destination of cooperation. That distinction applies directly to systems in which agents route tasks, validate work, assign standing, or distribute rewards.
Anonymity remains a useful institutional tool. Lee's evidence makes its condition explicit: the relevant distinction must remain unavailable at the point of allocation. Persistent systems should test that condition continuously. If identity proxies reappear, the audit must follow the graph of recipients as well as the count of actions.
References
Kaal, Wulf A. 2017. "Blockchain Technology and Race in Corporate America." SSRN. https://ssrn.com/abstract=3071378. Claims cited: 3071378-030 and 3071378-036.
Kaal, Wulf A. 2019. "Decentralization: A Primer on DAOs." SSRN. https://ssrn.com/abstract=3373393. Claim cited: 3373393-033.
Lee, Messi H.J. 2026. "Language model agents show in-group trust bias invisible to standard behavioural audits." arXiv:2605.28114v2. https://arxiv.org/abs/2605.28114.