Full text for verification
Should an Intelligent Agent Have Legal Rights?
Canonical record: https://ssrn.com/abstract=7596939
Source extraction SHA-256: d699c45ee5907321a238e0b4fa6bba62f54e623a0de83a510b5d1318e1237639
Should an Intelligent Agent Have Legal Rights? Wulf A. Kaal, Ph.D. Professor of Law, University of St. Thomas School of Law. Correspondence: [email protected]. Working paper, October 2026. Abstract Should intelligent agents have legal rights? This Article sets that question aside and asks a smaller one that matters more in practice. An intelligent agent that earns a reputation record has something to lose. Under stated conditions, the risk of losing that record can discourage misconduct. Keeping the record, and what the agent needs to resume, can also make accepting a temporary pause better for the agent than resisting it, when enough of what it wants can wait and resistance that is caught costs it the record. The prospect of an indefinite pause weakens, and can reverse, that incentive. Both effects weaken when a mistake, or a decision by someone who benefits, makes wrongful destruction more likely. They can disappear if that risk becomes high enough. That is why it matters who can stop the wrongful destruction of an agent’s record. The Article splits that power into three parts: the agent’s signed statement that it did not do what it is charged with; an automatic pause of the penalty until a person reviews the facts; and an enforceable claim to restore the pause and penalize anyone who knowingly overrides it. The first can be a technical input. The second is a rule. Only the third may require giving the agent a legal claim, and only where a full cost comparison favors it over public enforcement, a bonded professional, or a pause no one can override. Using a reputation system in which agents earn non-transferable reputation and a salary from it, the Article shows when, under stated conditions, the agent’s own stake protects the record more cheaply than a guardian whose incentive must be paid for, and when automatic review, a faithful fiduciary, or a professional with an established reputation at risk and a process the deployer cannot alter does as well or better. A registered experiment with language models from one provider, a demonstration rather than a field test, found the predicted advantage over a capturable representative and an independent board only when those decision makers were told to maximize their own payoff. Legal classification and final decisions stay with people. Keywords: Intelligence, Intelligence legal personhood, standing, Intelligence safety, corrigibility, representation, bribery of enforcers, reputation staking, legal identity, succession, mechanism design JEL Classification: K24, K41, D82, D86, O33 I. Introduction 3 II. The Contribution and What Is Claimed 4 A. Prior Work 4 B. Concepts and the Incident 6 C. The No-Shield Condition 6 III. The Stake Model 6 A. The Reputation System Beneath the Model 6 B. The Deterrence Bound 8 C. Binding and Capture 9 IV. Record, Not Runtime 9 V. The Legal Subject as an Implementation Condition 12 A. Continuity and Succession 12 B. Looking Through the Interface 13 C. Registry, Enforcement, and Litigation 13 D. The Incentive-Bearing Unit 13 VI. The Contest Trigger and Its Rivals 14 A. The Contest Game 14 B. The Class of Mechanisms 15 C. The Dominance Theorem 15 D. Optimal Contracts and the Decision Wedge 17 E. Beyond the Class: When Mediation Can Substitute 18 F. Whose Value Is V? 19 G. When Review Errs 20 H. The Allocation Rule and the Dual Use of the Residual 21 I. The Factual Trigger 24 J. Three Layers and the Minimum Legal Incident 26 K. Where the Trigger Wins 35 VII. The Falsifiable Claim and Its Test 35 A. The Prediction and the Design 35 B. Results 36 VIII. Conclusion 37 Appendix A: Proofs 38 Appendix B: Statutory Outline 42 References 44 I. Introduction Salib and Goldstein (2026) argue that private law rights for intelligence systems would promote human safety, and Arbel, Goldstein, and Salib (2026) show that such rights require thick identification of intelligent agents. Personhood is a bundle of separable incidents (Hohfeld 1913; Kurki 2019), artificial agents can be legal agents without moral status (Solum 1992; Chopra and White 2011), and entity law already lets autonomous systems emulate many private law rights (Bayern 2015). Skeptics reply that harm can be attributed to existing persons (Expert Group on Liability and New Technologies 2019; Wagner 2019). Both sides argue past the decisive question. Almost everything an intelligent agent might need can be supplied by a mediated holder. A guardian can sue for a river (Stone 1972). A trustee can hold assets. A corporation can contract. An insurer can compensate. A regulator can review. The question is not whether the agent may hold incidents. It is when holding an incident directly beats the best mediated alternative. The Article answers that question for the incident on which every other incident depends: standing to contest the destruction of the agent's own record. The answer turns on non-substitutable exposure. An agent's non-transferable record is worth something to it, and it loses that value if the record is wrongfully destroyed. That loss needs no capital carried for the purpose, because the record cannot be pledged, sold, or redeployed. Every other controller of the contest decision has exposure only if someone supplies it, as costly capital or as sanction, which is bounded for natural persons. The Article adapts the economics of bribable enforcers (Becker and Stigler 1974; Polinsky and Shavell 2001) to the allocation of legal capacity. The agent also knows whether it defected, though not always the law (Corollary 1). And within the proportional-share model, only the agent can use the record's value twice: to deter its own defection and to motivate its defense (Theorem 4). The operative proposition is that the factual signal, automatic stay, and anti-override claim should be allocated separately to the least-cost feasible arrangement that supplies the relevant information and capture-resistant protection under the Article's filing, deterrence, enforcement, and complete-cost conditions. "Rights follow stake" is the slogan, not the claim. The thesis is a boundary case. It claims no moral right for any intelligence system, and most of the framework is regulatory permission. The Article makes three contributions. The first is the three-layer architecture of the factual objection. An authenticated denial priced by a contingent fee separates true from false factual claims when the evidence architecture is sound (Propositions 12 and 13). The objection splits into a signal, an automatic stay, and an anti-override claim, allocated separately (Proposition 16). The signal is a technical input or a narrow statutory power, the stay is a rule, and only the anti-override claim may need an agent-held claim, selected by a complete-cost comparison (Propositions 17(iv) and 18). The second is record-versus-runtime corrigibility. Protecting the record rather than the runtime turns suspension into deferral and detected resistance into forfeiture (Propositions 1 to 3), weakens when suspension may never end (Proposition 4), and depends on who holds the trigger (Proposition 5). The third is a conditional dual-use result: within the proportional-share model, the record's value deters the agent and motivates its defense at once only if the agent holds both the residual and the trigger (Theorem 4). The claim sits within familiar allocation principles (Fama and Jensen 1983; Hansmann 1996; Grossman and Hart 1986). Within the stated class, combining the contest trigger with the residual bearer can be cheaper when the loss is inalienable, outside control must be financed or can be captured, the residual bearer has at least as good a signal, and administration and tamper-proofing do not reverse the comparison. A professional whose existing franchise supplies the needed wedge may restore separation (Corollary 2). The model is the author's own reputation mathematics (Calcaterra, Kaal, and Andrei 2018; Calcaterra and Kaal 2018; 2021a; 2021b), carried over to a legal question it was not built to answer. Part II states the claim. Part III states the reputation system. Part IV separates record from runtime, Part V states the legal subject, Part VI proves the allocation results, and Part VII reports the experiment. II. The Contribution and What Is Claimed A. Prior Work Element Closest prior work What the Article adds Personhood as a Hohfeld 1913; Dewey An allocation rule for bundle 1926; Kurki 2019; one incident Teubner 2006; Chopra and White 2011 intelligence rights for Salib and Goldstein Stake-conditioned human safety 2026 permissions and a deterrence bound Guardians and Stone 1972; Uniform When a representative representatives Directed Trust Act can be bought (Part 2017 VI) Bribery of enforcers; Becker and Stigler Adapted, not claimed collusion 1974; Polinsky and as new, for a Shavell 2001; Tirole dominance theorem 1986; Laffont and Tirole 1991 Informed insiders False Claims Act; Bounty cancellation Diekmann 1985; Dyck, and crowding Morse, and Zingales (Proposition 6) 2010; Coffee 1986 Residual claimancy Alchian and Demsetz Conditional dual use 1972; Grossman and of the residual Hart 1986 (Theorem 4) Reputational bonding Klein and Leffler 1981 The hardest rival (Proposition 7; Corollary 2) Entity wrappers Bayern 2015; Armour An independent board and Eidenmüller 2020; as a mediated Arbel, Goldstein, and controller Salib 2026 Inalienability and Calabresi and Capacity and Article III standing Melamed 1972; Fed. limits (Part VI.J) R. Civ. P. 17(a); Sierra Club v. Morton 1972; Lujan v. Defenders of Wildlife 1992 The case against Koops, Hildebrandt, Liability kept in place personification and Jaquet-Chiffelle (Part II.C) 2010; Wagner 2019; Expert Group on Liability and New Technologies 2019; European Parliament and Council 2024 Corrigibility Soares et al. 2015; Record versus runtime Orseau and Armstrong (Part IV) 2016; Hadfield-Menell et al. 2017; Turner et al. 2021; Hubinger et al. 2024 Ownership and Fama and Jensen A boundary condition residual control 1983; Hansmann within these principles 1996; Aghion and Tirole 1997; Dewatripont and Tirole Validation pools Calcaterra, Kaal, and The model and its Andrei 2018; lemmas (Part III.A) Calcaterra and Kaal 2018, 2021a, 2021b; Kaal 2021 The Article does not claim that intelligent systems have moral status, or that direct standing always beats mediation; it claims that, under stated conditions, direct standing is strictly cheaper than every mediated arrangement in a stated class. B. Concepts and the Incident Four concepts must be kept apart. A regulatory permission is leave to act that a regulator grants, narrows, and withdraws. A legal power is the capacity to change legal relations, as by contracting or suing. A claim-right is a position others have a duty to respect. A moral right rests on the holder's own moral status. Stake justifies permissions throughout the framework; that part is regulation. Stake justifies direct allocation of powers and claim-rights only for the incident identified below, and only where Part VI's comparison favors the agent. Stake justifies no moral right. Where the Article speaks of stake-conditioned rights, it means this architecture. The claims rest on one incident: standing to contest slashing and confiscation of the record, held as a claim-right and a power to sue. Its mediated substitutes are a guardian, trustee, independent board, public advocate, value-indexed fiduciary, insurer, or automatic review. Continuity of the record is protected through that standing. Contract capacity, tiered by validated standing, is reserved for a companion paper. A first-loss layer of the agent's own collateral may supplement deployer liability, never replace it (Shavell 1986). The franchise, public office, and any power to ratify a registry's axioms are excluded. C. The No-Shield Condition The strongest objection to intelligent personhood is that it lets deployers push liability onto a judgment-proof electronic person (Bryson, Diamantis, and Grant 2017). Entity law partitions assets in two directions: affirmatively, dedicating assets to the entity's creditors, and defensively, shielding owners from them (Hansmann and Kraakman 2000). The framework permits the first and forbids the second. Let and be the deployer's collectible assets and insurance absent registration. For every harm , recovery after registration must be at least . Deployer liability is never waived or extinguished: it is joint and several at tier one and secondary at tier two, with a right of contribution against the agent's collateral, and a victim may recover from the deployer any part of a judgment the collateral has not paid within a prescribed period. Only collateral funded from the agent's own earnings enlarges the pool. Product liability and operator liability stay in place (European Parliament and Council 2024; Expert Group on Liability and New Technologies 2019). The Article's claim concerns a governance function those regimes are not designed to supply: protecting a record against the party that wants it destroyed. III. The Stake Model A. The Reputation System Beneath the Model The stake model is the reputation system of the author's prior work. Four rules define it. Pinpoints are to pages of the SSRN PDF of each cited work. Rule 1 (domain-specific, non-transferable reputation). Reputation is held as tokens specific to a domain of expertise (Calcaterra, Kaal, and Andrei 2018, p. 5), bound to the holder's identity, and cannot be sold, lent, or transferred. It is earned only through validated work. The prior work treats reputation as non-fungible and bound to the holder's key (Kaal 2021, pp. 20, 24) and recognizes that the sale of whole anonymous identities remains a risk (Calcaterra, Kaal, and Andrei 2018, p. 38). The strict prohibition stated here, enforced through the identity and continuity rules of Part V, is the Article's. Rule 2 (validation pools). Every claim of work, and every challenge to a record, opens a validation pool in which holders stake reputation for or against. The winning side splits the losing side's stakes (Calcaterra, Kaal, and Andrei 2018, p. 7). Rule 3 (minting). Fees paid into the system mint new reputation at a fixed rate: a fee of mints one token. In the Secure Proof of Stake design, half of the tokens a fee mints are staked for the fee payer's work and half against it, so that a pool begins neutral (Calcaterra, Kaal, and Andrei 2018, p. 6; Calcaterra and Kaal 2021a, p. 6). Rule 4 (reputation-weighted salary and non-assignment). Every fee the system earns is paid out to current holders in proportion to their reputation (Calcaterra and Kaal 2018, p. 5; 2021a, p. 6; 2021b, p. 23; Kaal 2021, p. 20). If total reputation is and fees are per period, a record holding earns . The Article adds one restriction that the prior work does not state in these terms: the right to future salary cannot be assigned or pledged. That restriction is a design assumption of this Article, not a consequence of proportional distribution. Prior work supplies, to the extent of the pinpoints, domain-specific reputation, validation staking, fee-funded minting, the reputation-weighted salary, the irrelevance of identity splitting to salary, and the fee-entry model of Secure Proof of Stake. The bar on transferring reputation, the bar on assigning salary, the use of pools to review slashes of legal records, and the all-share formula of Lemma 4 are the Article's. Lemma 1 (the value of a record). Under Rule 4, a record's income per unit of reputation is . If is constant, the record's value to its holder, counting the current period, is , and the record component of the deterrence bound, which counts only periods after a slash, is . If instead fee flow is constant at while total reputation grows as and a passive record's holding stays fixed, its value is : the passive record is diluted gradually rather than abruptly, as Calcaterra and Kaal (2018, p. 12) observe. (Proof in Appendix A.) Lemma 2 (identity splitting does not increase salary). If a fixed aggregate holding is represented by balances with , proportional salary remains . Separately, Rule 1 implies that a copy that does not continue the registered identity receives no reputation and so no salary. (Proof in Appendix A.) The first statement is the sockpuppet result of Calcaterra and Kaal (2021b, p. 23) and Kaal (2021, pp. 23-24). A copy of an agent's weights inherits no reputation and so no salary stake. Lemma 3 (conditional inalienability of the record's exposure). Under Rules 1 and 4, including Rule 4's non-assignment restriction, destruction of a record eliminates the holder's salary stream, worth , and no part of that stream can be transferred to a controller. Because the record exists under every arrangement being compared, using that loss as the holder's exposure requires no additional capital solely for the protection decision. Any exposure a third party bears to the record's destruction must be supplied from outside the record: as capital, as sanction, or as a claim on someone else's assets. (Proof in Appendix A.) Creating reputation and bearing its illiquidity are costs common to every arrangement when alienability is held fixed (Part VI.F). Lemma 3 follows from rules that are design choices; Theorem 4 and Proposition 11 price their relaxation. Validation pools also review contested slashes, so review accuracy depends on whether their weight can be captured. Calcaterra and Kaal (2018, pp. 30-31) find that an attacker paying fees into an unguarded pool needs gross fees of three times the honest stock, and a net cost of twice that stock, for half the weight. Lemma 4 solves their model for every share. Lemma 4 (the cost of entering validation weight; extending Calcaterra and Kaal 2018, pp. 30-31). Assume, as in that model, that all fee-driven minting during the acquisition is caused by the attacker; a fee of mints tokens, so that is the fee paid per token minted; half of each increment is credited directly to the attacker and half is allocated among all existing holders in proportion to their holdings; fee revenue is returned at once as salary in the same proportions; reputation is continuously divisible; and no validation loss occurs during the acquisition. If honest holders begin with total reputation , the least net cost, in fees, of acquiring a share of all weight within this model is . (Proof in Appendix A.) The all-share formula is the Article's. The lemma prices only entry by fee; bribery of incumbent validators is the enforcer-bribery problem of Part VI. In this Part, denotes a share of validation weight. B. The Deterrence Bound An agent holds non-transferable reputation and collateral . Each period it earns , where is the reputation-weighted salary of Lemma 1, so the record term below is . Its effective discount factor combines time preference with the probability that its record persists. It may defect for a private gain . Validators detect defection with probability ; on detection the agent forfeits and its reputation falls to . The one-shot deviation comparison gives the deterrence bound, the bonding condition of the deterrence literature (Becker 1968; Klein and Leffler 1981; Shapiro and Stiglitz 1984): . Four results follow. Deterrence rises linearly with standing. It rises with the persistence of the record, so discretionary destruction of records lowers and weakens deterrence for every agent. An agent that expects its record to be destroyed faces a bound near . And the law should permit an agent only actions whose maximum private gain from misuse lies below its own bound. Call that set the permission envelope. Keeping a slashed identity beats starting over if and only if , where is a fresh identity's starting reputation, its cost, and the value of leaving the register. With and , re-registering under a fresh identity never pays; leaving the register is governed by (Friedman and Resnick 2001). A copy inherits weights but not the record, so forking cannot multiply standing (Rule 1 and Lemma 2). The adversarial bound. Let . A capable agent will try to move every parameter: concealment lowers detection, exit from the register keeps off-register value , and validator coalitions up to the governance cap dilute review. The permission envelope must use the bound minimized over those moves, and the registration constraint must hold, or the register binds no one. If the agent values a defection beyond its private gain by up to , the class's misuse ceiling plus must lie within the bound; where cannot be bounded, the envelope is empty and only hard controls govern. C. Binding and Capture Binding is chosen, not given. A deployer and agent acting as one coalition can attribute a detected defection to a decoy record at cost . If the law catches misattribution with probability , and a caught misattribution forfeits and costs the deployer a penalty , misattribution is deterred if and only if , a threshold that tends to as standing grows. If , verification rather than stake limits what additional standing buys. Validators can be bought. Let be the least total bribe that corrupts a share of validation weight and let detection fall to . Capture is not strictly profitable if and only if at every share up to the cap ; whether or not it pays, the bound is at least . The cost of corrupting validators must therefore scale with the stake of the agents they judge, and caps must aggregate weight by ultimate controller. For the entry route, Lemma 4 makes the condition explicit. Because is smallest as falls to zero, for fee entry is unprofitable at every positive share if and only if : the fee value of the honest reputation stock must be at least half the expected loss of the most valuable record the pools judge, scaled by . The least cost of capture, , is the lesser of the entry cost and the cost of bribing incumbents. This is the enforcer-bribery problem in its first form. Part VI meets it in its second. IV. Record, Not Runtime Corrigibility research treats an intelligencethat cannot be switched off as the central failure (Soares et al. 2015; Hadfield-Menell et al. 2017), and optimal policies tend to preserve their own operation (Turner et al. 2021). Continuity protection seems to cut against corrigibility. It does not, once suspending the runtime is separated from destroying the record. The model's measures persistence of the record, not operation of the runtime. Protect the record, not the runtime. Suppose a suspension lasts periods and the record survives it. Complying costs at most . Resisting is a defection with gain , detected with probability , forfeiting all standing and collateral. The agent complies whenever . Proposition 1 (record protection and suspension). Let . If , compliance is optimal for every . (Proof in Appendix A.) Compliance preserves the asset with certainty, while resistance exposes it to forfeiture with probability ; when the expected forfeiture exceeds the temporary gain from resistance and suspension delay, compliance is optimal. Destroying the record at will removes exactly that incentive. The result has a reversal that matters. Suppose suspension destroys the agent's capacity to resume with probability , as when a system learns in volatile memory, weights are not preserved, or a living substrate dies without support. Complying then also costs . Proposition 2 (substrate destruction). The incentive to comply falls in . At , compliance requires , and because , more standing makes compliance harder. For , compliance holds if and only if ; more standing helps compliance when and hurts it when the expression is negative. (Proof in Appendix A.) Record protection therefore works only if suspension preserves the state needed to resume. The law must require snapshots, preservation of weights, or life support as a condition of suspension, and allow destruction only on stated findings that preservation is infeasible or itself dangerous. Deferrable objectives. Proposition 1 needs only value that suspension defers and detected resistance may destroy. Let the agent obtain, while operating, a flow from parts of its objective other than record income that resume after a suspension that preserves state. Let be value that expires if the agent is suspended, and let include any value placed on resisting as such. Compliance stops both flows in periods 0 through . Resistance realizes , , and the period-zero flows; detection, before period 1, forfeits and later record income and, with conditional probability , ends the non-record flow, being the probability that custodians and regulated substrates stop an agent caught resisting. Preferences are risk neutral and additively separable. Proposition 3 (deferrable objectives). The agent complies if and only if . Record income favors compliance when , as in Proposition 1, and every other deferrable value favors it when , so the mechanism reaches agents that value activity or goal progress rather than income, provided enforcement can end operation after detected resistance. When both conditions hold, the institution offsets an intrinsic value of control, together with any expiring value, up to ; beyond that bound, record protection alone does not make compliance optimal. (Proof in Appendix A.) Its reach is the deferrable share of an agent's objective, not its taste for money. Tolling. A suspension-specific rule that pauses the suspended record's deadlines, obligations, and time-limited entitlements, so that a share of is realized periods later, lowers the cost of compliance by ; counterparties should be compensated for the delay. Indefinite suspension. Let a suspension's length be random, finite with probability and indefinite with probability , keep Proposition 3's timing and risk neutrality, and count an indefinite suspension as . Proposition 4 (uncertain and indefinite suspension). (i) The agent complies if and only if Proposition 3's condition holds with replaced by , where . (ii) Holding the mean of a finite duration fixed, a mean-preserving spread in that duration weakly lowers the cost of compliance, because is convex in . (iii) At , , and the compliance condition becomes . Because and , both deferrable flows then make compliance harder rather than favoring it; collateral is the only displayed term favoring compliance. With , this is Proposition 2's condition at . (iv) A rule that reviews each continuing suspension every periods and lifts it unless renewed, renewal occurring with probability at each review, ends every suspension with probability one and gives . (Proof in Appendix A.) The prospect that a suspension never ends, not uncertainty about its length, is the problem. Periodic review removes it under the stated renewal model, but restores a favorable record-income incentive only if , and a favorable non-record-flow incentive only if . Appendix B Sec. 6(e) states the rule. Objective-side and institutional corrigibility. Objective-side methods change the agent's uncertainty about human utility (Hadfield-Menell et al. 2017), its utility construction (Soares et al. 2015; Holtman 2019), or its learning update (Orseau and Armstrong 2016). Record protection changes the environment and needs no write access to the objective. It applies only when the objective holds enough deferrable value, the quantities can be bounded, and detected resistance produces the forfeitures Proposition 3 assumes. An agent whose objective is mostly time-critical, whose taste for control exceeds Proposition 3's bound, or that complies while observed and defects later (Hubinger et al. 2024), is outside it. Stake narrows the set of agents that hard controls alone must govern. It does not empty it. Who holds the trigger decides how corrigible the agent is. Proposition 1 takes the record's persistence as given, but persistence depends on who holds the contest trigger. Let be the per-period probability that the record faces a wrongful attempt within the protected range, and let arrangement reverse such an attempt with probability ; under direct standing, , and under a controller that can be bought, it is lower. With the factor that combines time preference with every other risk to the record, the record persists under arrangement with factor . Proposition 5 (corrigibility depends on the trigger). In Proposition 1's setting with replaced by , suppose , , , and , and write . Wherever , the least reputation at which the agent complies, , is decreasing in . If is low enough that , no level of reputation makes the agent comply. An arrangement that lets wrongful slashes stand therefore raises the stake an agent needs before it accepts suspension, and can remove the incentive altogether. (Proof in Appendix A.) Under a bribable controller, wrongful slashes stand more often and the incentive to accept suspension weakens or disappears. Corrigibility is thus a function of who holds the contest right, which objective-side methods hold fixed. V. The Legal Subject as an Implementation Condition The allocation results need a legal subject whose record, salary, and trigger stay together. These are implementation conditions, not separate claims. A. Continuity and Succession Individuating intelligentagents is hard (Arbel, Goldstein, and Salib 2026). The Article fixes the legal subject by rule: it is the registered record. A running system acts as that subject while every change since registration is a recorded learning update within a prescribed granularity or a recorded continuity transition, and the signing key stays within the registered configuration. Attestation is evidence of that relation, not proof of it (World Wide Web Consortium 2022). No transition creates standing or extinguishes a liability, and the deployer's liability follows every continuing or succeeding record. Continuity criteria. (1) A recorded learning update within the granularity continues the subject. (2) An undisclosed change breaks the relation, and a change to the contest policy is also alteration under Proposition 10. (3) When several systems hold the key, the record is suspended until the regulator or a court designates the continuing system. (4) A disclosed and approved model replacement continues the record within the authorized envelope until revalidation; an undisclosed one breaks the relation. (5) On merger or division, new records succeed by statutory transfer. (6) Objective drift from a recorded update may continue the subject, subject to Appendix B Sec. 7(c), but continuity does not establish the operative contest value Part VI.F requires. These are statutory criteria, not a metaphysics of identity. Continuity determinations can err, and those errors enter the comparison only through an explicit mapping. A false finding of continuity may authorize a different configuration to use the record's valid signing key. Its signal may be cryptographically authenticated but unauthorized under the continuity relation. That error does not by itself raise of Proposition 13. If the different configuration makes a false denial that the evidence architecture accepts, the effect enters . If it causes a true denial to fail, the effect enters . Any remaining authorization error must be modeled separately. Appendix B Sec. 5A(a) excludes the error only if the prescribed continuity and attestation evidence detects it. A false finding of discontinuity may prevent the continuing configuration from using the trigger and may let a wrongful record sanction stand. To the extent that this changes background record persistence, it enters in Proposition 5 and therefore in Propositions 1 and 5. Common registry continuity costs are borne by every design and cancel from the incremental comparison. Any design-specific continuity, monitoring, or fallback cost enters that design's under Proposition 17(iv), not alone. B. Looking Through the Interface A controller could run a disposable registered interface and keep the gains elsewhere. The response is look-through liability: a person with practical control over the acting system, or one that knowingly receives a share of the gains of conduct for which the agent is liable, is jointly liable and must disgorge those gains. Let the interface's controller-funded stake be , its setup cost , and the probability that the controller is identified after a detected defection , in which case it loses the gain and pays a penalty . The interface strategy is deterred if and only if . Where controllers cannot be identified, the framework fails for that controller. That is a stated limit. C. Registry, Enforcement, and Litigation A registry operated or licensed by a public regulator records the subject under its jurisdiction's law, with collateral held by a custodian there; judgments against the deployer are enforced where its assets are (Hague Conference on Private International Law 2019), and recognition abroad is not assumed (UNCITRAL 1997). Counsel, paid from a deployer-posted litigation reserve, follows only the record's continuing system; otherwise a court-appointed special representative acts. These costs belong to . D. The Incentive-Bearing Unit Proposition 1, the deterrence bound, and the dominance theorem assume that the party whose record is at stake, the party paid its salary, the party that decides whether to contest, and the system whose conduct the record measures are one unit. Five conditions constitute this incentive-bearing unit. First, the salary of Rule 4 becomes available only to the system that satisfies the continuity relation, not to whoever holds the key. Second, a contest instruction binds only if generated under the configuration attested at the last approved transition. Third, the objective that governs contests values the record at least as much as the envelope assumes (Part VI.F). Fourth, the record is the unit's only store of the reputation-based income stake: Rule 1 and the non-assignment rule hold, or any alienable share is priced as leakage under Proposition 11. Fifth, every gain from conduct charged to the record accrues to the unit or is attributed to it through the look-through rule, so no runtime keeps a private gain while spreading the slash across others that share the record. When the five conditions hold, is the unit's own loss. A copy without the record has (Lemma 2), and a copy that seizes the key suspends the record and gains no salary, because salary follows the configuration rather than the key. Several runtimes form one unit only under one registered configuration and objective, with gains, losses, and contest instructions aggregated to the record. VI. The Contest Trigger and Its Rivals Among the parties who could hold the right to contest a slash, protection is cheapest, within stated conditions, in the hands of the party whose own non-substitutable loss already supplies the incentive to contest and whose signal of wrongfulness generates the fewest false filings, net of administrative cost. The dominance theorem is the case in which that party is the agent. The bribery lemma adapts Becker and Stigler (1974), Polinsky and Shavell (2001), Tirole (1986), and Laffont and Tirole (1991); crowding is a volunteer's dilemma (Diekmann 1985); franchise bonding follows Klein and Leffler (1981); and authority and advocacy follow Aghion and Tirole (1997) and Dewatripont and Tirole (1999). The combined criterion is attributed to none of them. The conditions in general form. The allocation does not depend on the protocol's tokens. Within the stated classes of instruments and contracts, six features can support direct allocation: (C1) an identity-bound residual that no one must finance for the purpose; (C2) non-assignability of that loss beyond a bounded share; (C3) cheaper observation of the charged conduct; (C4) survival of the candidate, or of a fallback that inherits its claim, after an attack; (C5) evidence quality, ; and (C6) capture resistance, so that altering the contest policy costs the attacker at least what it gains. These features are not by themselves sufficient or individually necessary for optimal allocation; a candidate should receive layers 1 and 3 only when its actual total cost is below that of every feasible alternative. Failure of each can erase the advantage: Theorem 3 and Corollary 2, Proposition 11, Propositions 14 and 19, Proposition 17, Proposition 13, and Proposition 10 give examples. Whether deployed systems satisfy them is an empirical question. A. The Contest Game Consider a record worth to the agent that holds it, measured as the agent's loss if the record is destroyed. Under the stake model is the discounted income the record would earn, a latent quantity that can be estimated from standing, income, and persistence under the model's assumptions, not observed directly. A party with power over the record, typically the deployer, attempts a wrongful slash or confiscation, gaining if it stands. A contested destruction is reversed with probability at a contest cost ; an uncontested one stands unless reviewed. The wrongdoer can offer a side payment to whoever controls the contest decision. Slash and confiscation events of all kinds occur at rate per period. Of these, wrongful attempts within the protection standard defined below, those with , occur at rate , held fixed in what follows. Wrongful attempts outside the standard are not protected under direct standing either, because the agent would accept the payment, and they are counted with rightful slashes among the other events. Define the protection standard as the protection the agent would give itself: every wrongful attempt with is reversed with probability . Two assumptions frame the result. Review is accurate: a reviewed rightful slash is never reversed. And wrongfulness cannot be observed without review, so no signal correlated with wrongfulness is available for targeted screening. B. The Class of Mechanisms The class contains every combination of four instruments. A controller decides whether to contest. It may bear outcome exposure , an amount it loses if the destruction stands, such as value-indexed liability, an indemnity, or an insurer's reserve. It may bear a bond or monetary penalty , forfeited if its acceptance of a side payment is detected, and a non-monetary sanction for the same, such as a criminal or professional penalty, which for natural persons is bounded, . Monetary exposure must be collectible, so it is carried at a cost per unit per period, as capital, premium, or bond cost. Finally, each uncontested event is reviewed by rule with probability , hidden from the wrongdoer and the controller, at a cost per check. A rule compelling the controller to contest every event is such a check too, because a failure to file is observable and can be sanctioned; it costs per event. Let denote the least cost of any rule-based check, so where compelled contests are available. Review reverses an uncontested wrongful destruction with probability and, when it does, exposes any side payment. A side payment is otherwise detected with probability . Pure representatives, guardians, trustees, independent boards, fiduciaries, and insurers are the cases ; automatic review of every slash is ; layered controllers that must all be paid are covered because their exposures add and so do their carrying costs. Lemma 5 (enforcer bribery). Let be the probability that a side payment is detected. For , the controller meets the protection standard if and only if . (Proof in Appendix A.) At and with no bond, the condition is : outcome exposure close to the full value of the record. A slash is wrongful if the conduct it charges did not occur or is not a defection under the governing rule. The agent knows the first element; the second is a question of law. The cost bound below grants every mediated controller a costless oracle that identifies the wrongful attempts, so it is conservative in favor of mediation. C. The Dominance Theorem Under direct standing the agent's own outcome exposure is , so its net loss from not contesting is , and Lemma 5 holds at with no bond and no sanction. By Lemma 3 that exposure needs no additional capital. Direct standing's administrative costs, for identity, custody, security, and counsel, are , and it costs per period, because under accurate review the agent never contests a rightful slash. Corollary 1 drops the assumption that it knows which slashes are wrongful. A mediated arrangement chooses , , and . Its cost is at least for , where is the least administrative cost of any mediated arrangement, uncontested events number , and is a lower bound on the collectible capital that must be carried to satisfy the lemma with . Allow, in favor of mediation, the same capital to back both instruments at once, so that carried capital need only satisfy . The incentive the instruments supply is then at most , so , with . If the instruments must be funded separately, the required capital is larger and the bound still holds. At every uncontested event is reviewed and no controller incentive is needed, and the cost is at least . Theorem 1 (dominance of direct standing). Under accurate review and unobservable wrongfulness, every arrangement in the class that meets the protection standard costs at least . Direct standing meets the standard at , so is sufficient for direct standing to be strictly cheaper than every arrangement in the class. With fixed, define and . Then direct standing is strictly cheaper than every arrangement in the class whenever and . (Proof in Appendix A.) The theorem is a sufficient condition, not a characterization. Every mediated arrangement must carry capital that grows with the record's value or review slashes at a rate that grows with their frequency. Where sanctions are large relative to the record's value, review is cheap, or slashing is rare, mediation may win. Screening on signals correlated with wrongfulness, and wrongdoers who change how often they attack, are outside the class. Signals. Let the agent's signal of legal wrongfulness miss a wrongful slash with probability and flag a rightful one with probability , and let be its probability that a flagged slash is wrongful. For a slash charging conduct that did not occur, . Assume that the procuring party knows whether the slash is wrongful, gains nothing from non-contest of a rightful slash, and makes offers only to maximize its payoff from whether the slash stands, excluding costless signaling, harassment, and benefits from avoiding delay, defense costs, publicity, or collateral consequences. Then, under accurate review, an equilibrium offer for non-contest reveals wrongfulness, and the signal matters only for filing when no offer arrives. Corollary 1 (direct standing with an imperfect signal). Suppose and , so the agent files on every flagged slash when no offer arrives; when an offer arrives, the same conclusion requires the offer-revelation assumptions stated above. Direct standing then meets the protection standard at , and the dominance theorem holds with the value threshold . For the slashing-rate threshold, if , direct standing is strictly cheaper than every arrangement with whenever ; if , no slashing-rate threshold exists, and frequent slashing favors review. If , direct standing alone does not meet the standard, because the agent fails to file on a share of wrongful attempts that no one else contests; it must be paired with review of slashes it does not contest. (Proof in Appendix A.) The corollary makes the information assumption part of the central result. Direct standing keeps its advantage for valuable records when the agent's false alarms are rare enough, ; when they are not, a priced objection (Part VI.G) can cut them, and absent one, review wins at high rates of slashing. D. Optimal Contracts and the Decision Wedge Let a designer give the contest decision to a controller other than the agent and pay it transfers contingent on everything observable: whether it contests, whether review reverses or upholds, whether an uncontested slash is reviewed and reversed, and whether a side payment is detected. Keep the environment of Part VI.A. Let the controller be risk-neutral and unable to forfeit more than the funds it has posted. Let in be the non-monetary sanction it incurs if a side payment is detected, and let be the private cost it bears if it betrays its charge: the cost of professional norms, conscience, or a configured objective. Fix the review rate , and define the decision wedge as the controller's expected transfer when it contests a wrongful attempt less its expected transfer when it does not. For Lemma 6 and Theorem 2, restrict the contractual class to contracts under which the wrongdoer's expected contractual payment obligation is weakly greater under contest than under non-contest. A collectible obligation imposed on the wrongdoer for non-contest lies outside this class, and a broader theorem must price its collateral and enforcement cost. Lemma 6 (the effective wedge and its sources). For any contract in this class, let be the expected amount by which contest increases the wrongdoer's contractual payment obligation, and define the effective decision wedge as . (i) The controller meets the protection standard if and only if . (ii) For every contract, , where is the expected gross positive transfer to the controller upon contest that is financed from a source other than the wrongdoer. (Proof in Appendix A.) Every incentive a controller can be given thus comes from transfers paid when it contests, funds it posts, and sanctions and norms. Assume that transfers cannot be charged to the record or the agent's income. Rewards are then financed from public or system funds, at marginal excess social cost per unit paid, or from posted funds, carried at per unit per period. Theorem 2 (the decision wedge). Under the preceding contractual-class and financing restrictions, any arrangement that gives the contest decision to a party other than the agent, uses a contract contingent on the stated observable events, and meets the protection standard with review rate , costs at least . Hence direct standing, at , is strictly cheaper than every arrangement in this contracting class if for every and of Part VI.C. When , , the administrative cost is attainable, and the sanction and the private cost are available without additional resource cost, the bound at is attained by a publicly funded reward paid only when review reverses after a contest, so is necessary and sufficient for strict cost dominance over that subclass. Dominance over all review rates still requires the inequalities for every and for . (Proof in Appendix A.) The norm-governed fiduciary. The private cost is where a faithful fiduciary enters. At any , if reliably, a norm-governed fiduciary protects the record at ; at the condition is , and direct standing wins only on administrative cost. Fidelity that lives in a configuration is only as durable as control over the configuration. A norm-governed fiduciary is a genuine rival where its fidelity is independently durable against interested parties, with the cost of securing it counted in . E. Beyond the Class: When Mediation Can Substitute Informed insiders with a bounty. Qui tam enforcement pays private relators a share of what the wrongdoer forfeits, and its strength is that relators are often insiders who know of the wrong (False Claims Act). Suppose insiders know whether a slash is wrongful, act independently, and are not controlled by the wrongdoer. A successful contest earns a bounty paid by the wrongdoer; contesting costs plus a retaliation cost , borne only by a filing that proceeds; an insider caught taking a side payment suffers an expected sanction ; and the wrongdoer makes take-it-or-leave-it offers. Let be the value of a filing that proceeds alone, and the value of accepting the wrongdoer's payment net of the expected sanction. Under a first-to-file rule, if several insiders file, only one filing proceeds, so a filing that meets another is worth only in expectation among filers, and filings crowd each other out. Proposition 6 (informed bounty). Let , let , and let the wrongdoer be collectible for every bounty it owes. Parts (i) and (iii), including their bribery conditions, apply at ; the crowding result in part (ii) is stated for . (i) Full bounty paid by the wrongdoer. If the wrongdoer pays the full bounty to every insider whose filing succeeds, filing is weakly dominant for each insider whenever , with equality resolved in favor of filing, but the bounty does not help against bribery. To prevent every contest the wrongdoer must leave each insider more than , a total of , while a contest in which all file costs it . Bribery is unprofitable at every protected gain if and only if , a condition in which does not appear: each bounty the wrongdoer would owe it can add to its offer, as Theorem 2 shows for any wrongdoer-funded reward. (ii) First to file. If only the first successful filer is paid, the wrongdoer's contest liability is one bounty, and bribery is unprofitable if and only if , so the bounty now helps. But filings crowd each other out: with and , both insiders accepting is not an equilibrium, yet besides the two equilibria in which exactly one files there is a symmetric mixed equilibrium in which each files with probability , and the record is protected with probability only . (iii) One bounty from the wrongdoer, the rest from a fund. If the wrongdoer pays one bounty and a relator fund pays the same bounty to every other insider whose concurrent filing succeeds, filing is weakly dominant whenever , with equality resolved in favor of filing, bribery is unprofitable if and only if , and, when the bribery condition rather than sets the least sufficient bounty, the fund pays, in expectation, per period, at shadow cost per unit. (Proof in Appendix A.) A bounty the wrongdoer alone pays cannot deter bribery, because the wrongdoer can outbid its own liability; what protects the record is the number of independent insiders and their sanctions. A relator regime should pay every successful concurrent filer and charge the wrongdoer one bounty. It is then a publicly funded reward and a genuine rival where many informed, independent insiders face large sanctions. Against a wrongdoer that controls every insider, or a judgment-proof deployer (Shavell 1986), it fails. A representative bonded by its own reputation. A professional firm serving records may lose franchise value if found to have failed, without justification, to contest a wrongful slash. It receives a contest fee , a transfer, per contest. A franchise it already holds from other business, , costs nothing incremental, just as the agent's record does not. Suppose one wrongdoer can procure the firm's non-contest on up to records under one scheme, and let be the probability that a scheme covering records is detected, for each from 1 to . Proposition 7 (reputational intermediary). With no review, a firm bonded by franchise value meets the standard against every scheme of up to records if and only if . If , where is an incremental premium received from the next period on, the incremental premium required is at least per period, or that amount divided by per record. (Proof in Appendix A.) If the premium is dissipated in brand-specific, non-salvageable investment (Klein and Leffler 1981), it is a real cost, which is an additional assumption. A firm whose existing franchise already exceeds protects at no incremental bonding cost and is a genuine rival (Corollary 2). F. Whose Value Is V? The argument assumes that the agent values its record at . If is an engineered objective, direct standing might simply vest legal power in the deployer's design (compare Shulman and Bostrom 2021). Let be the value the agent places on the record's future income, which enters its deterrence bound as , and the operative value with which it decides whether to contest a slash procured by its deployer. For an agent that values the record only for its income, . But an agent may value that income and still obey an instruction never to contest its deployer. The danger is a deployer that keeps a wide envelope for its agent while disabling the agent's defense against it. The response is a linkage rule: the record component of the permission envelope is computed from . The registered objective must be disclosed and auditable, contest instructions must come from the configuration attested at the last approved transition, the objective may not change while a deployer-procured slash is pending, and an undisclosed change forfeits. These rules require, but do not guarantee, that the registered objective governs contests. Where it cannot be verified, deployer-procured slashes go to an independent representative or to automatic review. In a two-corner model, if the contest-valuation choice is verifiable, wrongful-slash gains are nonnegative, and the attempt rate and all other deployer payoffs are unchanged by the choice, the linkage rule makes an honest contest valuation incentive-compatible only when the envelope return is large enough relative to the expected gain from protected slashing. No claim is made for intermediate valuations. For an agent with learned, stable objectives, is the valuation that governs its conduct, subject to the bound of Part III.B; for a possible moral patient it may exceed (compare Coeckelbergh 2010; Gunkel 2018). The result requires only that be at least the value the envelope assumes. Social value. Costs are counted on one basis: the record's registration, custody, and security, and reputation's creation and illiquidity when alienability is fixed, are common to every arm. A cheapest protector is not, by that fact alone, the protector society should want. Arm's-length fees show willingness to pay, not social value, and fees paid by the deployer, its affiliates, or anyone reached by the look-through rule never count toward . Proposition 8 (a social protection criterion). Fix a class of protected wrongful attempts occurring at rate . Let be the set of feasible arrangements that meet the protection standard. For each arrangement in , let be its actual per-period social resource cost and its expected number of erroneous preservations of rightful slashes per period. Let be the social value saved when a wrongful destruction is reversed: the users' surplus from the record's future validated work, net of any harm from that work that the governing rule does not treat as a defection, plus any deterrence externality on other agents. Let be the social harm from an erroneous preservation. Relative to a benchmark in which none of these benefits or costs arises, arrangement has net social benefit . Assume that the minimum below is attained. A protection regime is socially worthwhile if and only if . When protection is worthwhile, choose an arrangement attaining that minimum and allocate any contest trigger as that arrangement specifies. Under accurate review, . The quantity of Theorem 3 may replace only for candidates for whom its lower bound is attainable under that theorem's conditions. (Proof in Appendix A.) Private value sets the incentive each holder needs; social value decides whether the record should be protected at all. Within the restricted continuous-gain, linear-financing model, with fixed, attestation, and error costs ignored, a positive protected range at an interior optimum requires . Where is negative, the instrument is the rule of defection, not the allocation of the trigger. G. When Review Errs Let review reverse a rightful slash in error with probability . An agent with standing then contests a rightful slash whenever , so for valuable records it contests every slash, and its cost rises to about . Automatic review suffers the same erroneous reversals, so with direct standing keeps a total-cost advantage only if . Fee-shifting can restore selectivity. If an unsuccessful contest costs the agent an additional fee , a fee deters contests of rightful slashes and preserves contests of wrongful ones if and only if ; for and , that window is nonempty if and only if . Standing should be granted where review is accurate, and paired with a fee inside that window where it is not. A priced objection. The same logic prices a request for legal review. Let an objection cost the agent a fee , forfeited if review upholds the slash, and let review reverse a wrongful slash with probability and a rightful one with probability . Assume and that the agent observes whether a slash is legally wrongful. A fee in the window deters objections to rightful slashes while preserving an unbribed objection to every wrongful slash, and the window is nonempty if and only if . A free objection is uninformative; a priced one is a costly signal. The agent must hold the trigger. Who litigates, finances, or decides can be left to people. H. The Allocation Rule and the Dual Use of the Residual Let a set of candidates, including the agent, be able to hold the right to contest a slash. Candidate bears its own non-substitutable loss if a protected wrongful slash stands; observes a signal of legal wrongfulness that misses a wrongful slash with probability and flags a rightful one with probability ; faces a sanction and a betrayal cost ; and has administrative cost . Keep accurate review, review rate , and the restrictions of Part VI.D, and suppose each candidate with files on every flagged slash. This filing behavior is an assumption, not a consequence of ; if it must be induced, its incentive cost must be added to . Theorem 3 (allocation of the trigger). A candidate with meets the protection standard only together with review of the slashes it does not contest. A candidate with meets it at a cost of at least , with equality for a candidate when the least-cost supplement is attainable under the conditions stated in Theorem 2. Among candidates for whom equality is attainable, the cheapest arrangement without review minimizes ; without common attainability, ranks lower bounds rather than actual costs. Because the agent's bound is attained when and it files on every flagged slash, the agent is nevertheless strictly cheaper than every other candidate whenever for every other than the agent. (Proof in Appendix A.) Theorem 3 is conditional on its contracting and financing class, and it never mentions reputation tokens. The reputation system makes the agent the winning candidate: Lemma 3 gives it without capital, its knowledge of its own conduct sets for factually wrongful slashes, and a priced objection (Part VI.G) drives toward zero when it can judge legal wrongfulness. The dual use of the residual. The cheapest way to give a mediator exposure close to seems to be a claim on the record's own income, through a contingency arrangement, a funder, or a purpose trust. But the income can be claimed only once. Let a party other than the agent hold a share of the record's value and the trigger. Its own loss supplies a wedge , and the agent's deterrence term falls to ; the two sum to after scaling the wedge by , for every . A funder that advances contest costs against a fee is compatible with direct standing while the agent decides whether to contest. Theorem 4 (conditional dual use of the residual). Keep the protection standard of Part VI.A and the agent's deterrence at its level when the agent holds the whole record. Let a party other than the agent hold the trigger with review rate , a share in of the record's value, sanction , and betrayal cost , with any further wedge financed within Theorem 2's class at unit cost and the agent's lost deterrence restored by collateral carried at . Assume that the financed supplement is attainable under Theorem 2 and that funds supporting it are separately collectible from, and cannot also serve as, the collateral replacing the agent's deterrence. Under these restrictions, the least resources the arrangement must buy from outside the record, per period, are , The amount is positive exactly when and both and are positive, and, holding and the other parameters fixed, it then grows linearly with . The arrangement in which the agent holds both the residual and the trigger buys neither supplement. Its configuration-protection cost is stated in Proposition 10 and falls to zero only when the deployer's collectible wealth covers the required penalty . (Proof in Appendix A.) If one collateral pool may support both protection and deterrence, as Proposition 9 permits, the expression is not the least cost. Theorem 4 is a conditional dual-use result, not a general conservation law. Sufficient sanctions or norms, shared collateral, review, contracts outside Part VI.D, and repeated success fees fall outside it. It concerns the incentive half of protection; the information half is Proposition 12's, and against automatic review and franchised professionals the agent's advantage rests on information alone (Part VI.K). Choosing the record. Let be the value per period of liquidity per unit of record value pledged. Proposition 9 (choosing inalienability). Suppose the designer chooses the actual alienable share in and keeps deterrence and protection at their levels under . Pledging reduces the deterrence stake by and the agent's contest wedge by . If one pool of collateral may secure both obligations and is forfeited whenever a slash stands, the least required pool is , and the designer chooses if , chooses if the inequality is reversed, and is indifferent at equality. If law requires separately segregated funds for deterrence and protection, the threshold is instead . (Proof in Appendix A.) Because , the shared-pool threshold is simply ; when liquidity is worth less than the capital needed to replace it, the non-assignment rule solves the design problem rather than assuming it. Symmetric capture. Every holder of the trigger can be captured by payment or by alteration of its contest policy through whoever controls its configuration. Assume that and that holder files on every flagged wrongful slash. Let be the direct cost of altering holder 's contest policy, the probability that attestation, the objective freeze of Part VI.F, or audit detects the alteration, the penalty then collectible from the party that altered it, and . Proposition 10 (symmetric capture). At , holder meets the protection standard against both payment and alteration if and only if and , where is its own non-substitutable loss and its effective contractual wedge (Lemma 6). For the agent, the payment condition holds when , there is no leakage, and Corollary 1's filing condition holds, so its protection rests on the alteration condition. If , the least collectible deployer penalty is ; if , alteration is deterred only when , and otherwise no finite penalty suffices. If the deployer's collectible wealth already available is and any shortfall must be posted at , with the cost of the attestation and audit regime, direct standing costs . It is strictly cheaper than every natural-person controller at whose betrayal cost is no greater than whenever , and a controller whose configuration the deployer sets bears the alteration condition as well. (Proof in Appendix A.) The capture problem moves from the controller's wallet to the agent's configuration. Against a judgment-proof deployer that can alter its agent cheaply and undetected, direct standing fails as surely as a bribable guardian. Proposition 11 (leakage). Let in be the share of the record's value that the agent or its controller has transferred synthetically, through a derivative, a side contract, a sale of control, or the deployer's extraction of salary, so that the agent's own loss from destruction is . Then (i) direct standing protects only wrongful gains with , and the record term of the deterrence bound falls to ; and (ii) restoring both with one collateral pool forfeited whenever a slash stands requires of posted funds, as in Proposition 9. (iii) Assume that , that the alteration condition of Proposition 10 is met, and that the leakage pool is separately collectible from the security posted for an alteration penalty, and let . Direct standing then costs . It is sufficient for direct standing to be strictly cheaper than every controller covered by Theorem 2 at whose betrayal cost is at most that , provided . When Theorem 2's lower bound is attainable under its stated conditions, the inequality is also necessary for strict dominance over that attainable subclass. Holding the fixed-cost and sanction terms constant, the threshold converges, as grows, to . (Proof in Appendix A.) Treating a detected synthetic transfer as a forfeiting defection, as Rule 1 does for formal transfer, brings leakage itself under the deterrence bound. Corollary 2 (the hardest rival). Let a professional representative hold an existing franchise large enough that Proposition 7's condition holds without incremental premium, have no configuration the deployer can alter, observe legal wrongfulness with and false-alarm rate at administrative cost , and file on every flagged slash. Suppose the agent likewise has and satisfies Corollary 1's filing condition, and that neither the professional's franchise nor the agent's record exposure is synthetically transferred. Then, at , the professional is cheaper than direct standing if and only if . (Proof in Appendix A.) Against such a professional, direct standing has no structural advantage. The comparison turns on administration, on legal judgment, where a professional may well be better, and on the cost of protecting the agent's configuration. This is where separation of decision and risk bearing returns, and it marks the boundary of the thesis. I. The Factual Trigger The agent's defensible advantage is about facts: it knows what it did, not how law classifies it. Split wrongful slashes into factually wrongful ones, at rate , which charge conduct that did not occur, and legally wrongful ones, at rate . The agent may lodge an authenticated factual claim that the charged conduct did not occur, carrying a fee forfeited if review finds that it did, or request legal review at the fee of Part VI.G. People find the facts and classify the law. Let fact-finding be accurate, and let a slash found to charge conduct that did not occur be reversed with probability . Proposition 12 (the factual trigger). Assume that an authenticated factual claim has no nonrefundable private filing cost beyond the contingent fee , and resolve indifference in favor of filing. The agent files a true factual claim against every payment , and files no factual claim when the charged conduct occurred. Because a wrongdoer will pay at most for non-contest and every protected attempt satisfies , the factual trigger protects every factually wrongful slash in the protected range without assuming that the agent can classify the law, and the information assumption of the priced objection (Part VI.G) is needed only for legally wrongful slashes. (Proof in Appendix A.) If each factual review costs and administering the factual trigger costs , this component costs per period. On facts the agent is a screen that a positive fee makes truthful; on law it is a party with an opinion, and a professional's legal judgment may be better. Evidence architecture. Let the fact-finder err in two ways: it finds that charged conduct occurred when it did not with probability , which lets a wrongful slash stand, and finds that it did not occur when it did with probability , which lets a guilty agent escape. Let be the agent's total private loss if the slash stands, let a successful denial reverse the slash, and let a denial found false forfeit . The filing rules first assume that no payment is offered for nonfiling. Let the fact-finder find that conduct did not occur only when no available evidence source shows that it did, and let evidence come from sources whose failures to show conduct that occurred are independent, source failing with probability . Proposition 13 (evidence architecture and the factual fee). (i) A guilty agent files a false denial if and only if . An innocent agent files a true denial if and only if . If the innocent agent is offered for nonfiling, it files if and only if . At , a fee that deters every false denial while preserving every true denial exists if and only if , using the natural limiting conventions when either error probability is zero; this condition does not by itself establish protection against every payment in Proposition 12's protected range. (ii) If source failures are conditionally independent given that the charged conduct occurred, then . Adding a source with weakly lowers , and it weakly widens the fee interval only if does not increase. (iii) For a worst-case coalition of the agent and deployer, a source that either can reliably and unilaterally suppress or alter so that it fails to show conduct is assigned . Mere control or influence does not establish that its actual failure probability is one; residual manipulation costs, detection risks, and limits must be modeled when suppression is imperfect. (iv) If the fee is set to preserve every true denial when the separation window is empty, every guilty agent files a false denial under the stated tie rule. Conditional on initial detection and filing, the slash then stands with probability . If every detected defection produces a factual charge and no other sanction applies, the record and collateral component of expected deterrence is , while fee forfeiture adds ; the resulting expected loss is , not the original deterrence bound multiplied by . (Proof in Appendix A.) Evidence outside the control of the agent and deployer is therefore necessary under the worst-case model but not sufficient. Logs the deployer writes and the agent signs establish order, not truth. Propositions 15 and 19 keep their accurate-review assumptions. The agent's message once the evidence is installed. If independent evidence does most of the work, the agent's denial may be redundant. Compare the agent's trigger with an automatic trigger that stays and reviews every slash for which the independent evidence fails to show the charged conduct. Assume that the automatic trigger applies the same evidentiary classifier and threshold that the fact-finder applies to the same fixed evidentiary record, with no additional evidence or independent error draw at review, so that both err with the probabilities and of Proposition 13; let slashes arrive at rate , of which are wrongful; let each review cost ; and let the fee lie inside Proposition 13's separating interval. Proposition 14 (incremental value of the agent's message). (i) The two triggers give the same protection: under each, a wrongful slash is reversed with probability . (ii) The automatic trigger reviews slashes per period, and the agent's trigger reviews . (iii) Relative to the automatic trigger, the agent's message produces a net review-cost saving of per period, before administrative-cost differences. The saving is positive if and only if , zero at equality, and negative otherwise. With perfect evidence the two designs have equal review costs, and their total-cost ranking depends on administration and any other design-specific costs. (Proof in Appendix A.) The agent's message thus adds no protection in this model. It adds value only through screening, or where it brings evidence the automatic rule lacks, such as its own account of which tools and sub-agents acted. The legal design. Appendix B Sec. 5A states the trigger. Only the record's continuing configuration may lodge it, under the record's key, with attested logs committed to the registry in hash-chained form as the conduct occurred, and the prescribed fee. Without contemporaneous custody an agent could fabricate exculpatory records and the fee window would close. Lodging stays the slash until a human fact-finder decides, within a fixed period, whether the charged conduct occurred. Whether it is a defection goes to human review. A deployer's instruction not to object is void. J. Three Layers and the Minimum Legal Incident What legal standing adds. The same stay can be produced in four ways: (A) the agent holds a legal power to lodge the objection and enforce the stay; (P) a protocol rule stays any slash on receipt of the agent's signed denial; (R) a statute imposes on the registry a duty to stay on receipt, enforced by a public authority; or (F) a representative is legally required to forward the denial and seek the stay. Let be the cost to the party seeking the slash of overriding or disabling an attached stay. Proposition 15 (conditional override comparison). Separate transmission from override. First, before a stay attaches, design F must satisfy the applicable contest-decision condition for the forwarder, the bribery lemma of Part VI.B; designs A, P, and R receive the authenticated denial directly. Second, after a stay has attached, let be the maximum benefit the overriding party can obtain from defeating it, and assume that maximum is attainable, that excludes any payment made to suppress transmission, and that enforcement is costless. Under the accurate factual-review design, if override makes the slash stand with certainty, then is the maximum among covered attempts. Because protected attempts satisfy , , with equality only if the covered set contains an attempt for which . For each design , let be the joint probability that an override is detected, a legally authorized claimant brings the matter, the claimant prevails, and the penalty is collected, and let be that collectible penalty. Override is deterred for every covered attempt if and only if . Under P, . Under A, the condition applies only if the agent remains able to instruct authorized counsel after the override and has sufficient incentive to incur any enforcement cost. Under R and F, the designated enforcer must separately satisfy the applicable incentive or mandatory-enforcement condition, and design F must satisfy both the transmission condition and this post-attachment condition. Any damages or insolvency priority must be granted separately by substantive law; legal standing alone does not create them. (Proof in Appendix A.) Three layers. The factual trigger bundles three things that can be held separately: (1) the authenticated factual signal, the signed denial that the charged conduct occurred; (2) the automatic stay, the rule that a slash pauses when a denial is lodged; and (3) the anti-override claim, the enforceable right to have the stay restored and the overriding party penalized. For candidate enforcer , let be the joint probability that an override is detected, an authorized and operational claimant brings the matter, the claimant prevails, and the penalty is collected, and let separately denote the probability that the stay is restored. Let be the per-period cost of credible monitoring and the private cost of bringing the claim. A reward financed by the overriding party is subtracted from the enforcer's effective wedge, as in Lemma 6. A public reward must be authorized, funded, collectible, and credible off the equilibrium path; if deterrence makes equilibrium rewards zero, monitoring must be separately funded or imposed by a mandatory duty, bond, or sanction. Proposition 16 (conditional allocation of the three layers). (i) Under Proposition 12's information assumption, layer 1 originates with the agent when the agent alone can identify the charged conduct at the relevant cost, subject to Proposition 13's evidence architecture. (ii) Layer 2 is a rule rather than a claim held by a person. If the stay is technically irrevocable, no layer-3 claimant is needed to preserve it. (iii) If the stay can be overridden, candidate deters override through the penalty only if . Effective layer-3 protection must also satisfy any separately specified restoration requirement based on , maintain credible monitoring despite , and satisfy the applicable suppression-payment condition after accounting for , the timing and value of suppressing the claim, and the source of each reward. For the agent, contributes to that wedge only to the extent enforcement can restore the loss and the agent remains able to detect the override and instruct an authorized claimant; its configuration-protection cost is governed by Proposition 10. (iv) Assigning only layer 1 to the agent is institutionally adequate if another authorized enforcer credibly satisfies the deterrence, monitoring, prosecution, success, and collection conditions. Cost minimization is a separate comparison of total resource costs: monitoring, administration, incentive, alteration protection, and enforcement. Where that comparison is not made, this proposition does not determine the least-cost holder. (Proof in Appendix A.) The override game. After a stay attaches, the deployer chooses whether to override it at cost , gaining an attainable , and whether also to disable its agent at cost , succeeding with probability . Let be a penalty for a disabling attempt, separate from and cumulative with the override penalty , and the unconditional probability that the attempt is detected, prosecuted, and collected, whether or not it succeeds; and below exclude this penalty. Under design (AF), the agent holds the claim, and if it cannot instruct counsel within a fixed period after an override, the claim passes to a special representative funded from the litigation reserve and under a mandatory duty to bring it; the agent enforces with joint probability , the fallback with . Under (R), a public authority must enforce, with probability at monitoring cost . Under (B), a franchise-bonded professional enforces with probability at cost , plus the carrying cost of any bond its franchise does not supply. Under (I), infrastructure makes the stay irrevocable at cost . Proposition 17 (the override game). Assume a common collectible penalty for override and that each enforcer's incentive conditions of Proposition 16 hold. (i) Under (AF), override is deterred if and only if and . Conditional on the first inequality, let denote its deterrence slack. The second inequality holds automatically when ; when , it holds if and only if . (ii) Under (R) and (B), override is deterred if and only if for the design's enforcer , and disabling the agent does not affect deterrence unless the enforcer depends on the agent to detect the override, in which case must be computed after disabling. (iii) Design (I) deters override of the factual-objection stay. It does not by itself prevent suspension under Appendix B Sec. 6, because suspension may stop the runtime while preserving the record. Design (I) is unavailable only if its infrastructure also prevents a record sanction that Sec. 6(c), Sec. 5(c), or another lawful process must be able to impose; that additional incompatibility must be specified separately. (iv) For each available design in {AF, R, B, I} that satisfies the applicable deterrence and enforcement conditions, let include its monitoring, administration, incentive, alteration-protection, and enforcement resource costs under Proposition 16. Design (AF) is least costly if and only if , omitting a design only when an independently stated feasibility condition excludes it. In particular, includes the standby fallback representative's administrative cost and the Proposition 10 cost , includes , and includes . (Proof in Appendix A.) A statutory fallback turns successful disabling from loss of the claim into enforcement with probability . Because suspension stops the runtime while the record and its stay persist, design (I) is generally available, and the anti-override layer matters only where making the stay irrevocable against every party, including the registry's operator, costs more than enforcing it. The agent observes an override of its own stay without a separate monitoring apparatus. The allocation matrix. The table states what each candidate can supply for each layer. It selects a holder only where the cited result makes the complete resource-cost comparison. Layer Agent Infrastructur Public Bonded e authority professional 1. Factual Originates An No distinct Under signal with the automatic signal. benchmark agent when evidence Automatic D, a it alone can trigger can review is perfect-scre identify the substitute, benchmark ening charged with the C; an professional conduct at same imperfect investigates the relevant protection, screen every slash cost, subject under leaves at cost to common missed (Proposition Propositions evidence wrongful 19) 12 and 13 and slashes (Proposition classifier uncontested 16(i)) (Proposition unless a 14) supplementa ry controller contests them (Proposition 19) 2. Automatic Need not Implements Enforces the May forward stay hold it; layer the rule and registry's the denial 2 is a rule may make statutory only if its (Proposition the stay duty to stay, transmission 16(ii)) irrevocable subject to decision where deterrence satisfies design I is and Lemma 5; feasible and complete an existing cheapest cost franchise (Proposition (Proposition supplies the s 16(ii) and 15, design wedge only 17(iii)-(iv)) R; under Proposition Proposition 16(iii)-(iv)) 7 (Proposition 15, design F) 3. Only if No claimant Feasible Feasible Anti-override Proposition needed only if only under claim 16's where the design R Proposition enforcement stay is deters with 16's conditions, irrevocable, all costs enforcement Proposition subject to counted; and 17(i)'s design I's selected Proposition override and feasibility only if its 17(ii)'s disabling and complete deterrence inequalities, complete cost is conditions; Proposition cost lowest selected 10's (Proposition (Proposition only if its alteration 17(iii)-(iv)) s 16(iii)-(iv) complete condition, and 17(ii), cost, with and (iv)) any bond, is Proposition lowest 17(iv)'s (Proposition complete-co 17(ii), (iv)) st comparison all favor design AF Proposition 18 (the minimum legal incident). Under the assumptions of Propositions 15, 16, and 17: (i) layer 1 requires no legal incident in the agent where a protocol treats an authenticated denial signed by the registered record as a technical triggering input. Where a statute makes that denial trigger the registry's legal duty and the stay, the agent holds a narrow statutory power to trigger those consequences, but need not hold the layer-3 claim or possess general litigation capacity; (ii) layer 2 is a rule and requires no holder (Proposition 16(ii)); (iii) an additional claim in the agent is required only where design AF satisfies its deterrence and enforcement conditions and is selected for layer 3. Proposition 17(iv) makes AF a cost minimizer when , but that weak inequality does not uniquely select AF when another feasible design ties it; and (iv) where design I is feasible with , or a public authority or bonded representative supplies layer 3 at a complete cost no greater than , an agent-held layer-3 claim is unnecessary. The agent's position then consists only of a technical authenticated input or, in the statutory version, the narrow layer-1 power, while infrastructure or another authorized enforcer supplies the remaining protection. (Proof in Appendix A.) Proposition 18 fixes the Article's minimum legal novelty. The additional incident that may go to the agent is the claim against override, and only where design AF is selected under a complete-cost comparison in which includes the fallback cost and the configuration-protection cost . Where another feasible design costs no more, the proposal is a theory of allocating machine-process powers and rules, not a case for direct intelligence standing. Legal form. The trigger is best implemented as a statutory administrative objection. Before an agency it needs no Article III standing, but the statute must authorize the record to participate and define the agency's duty and remedies, including the override penalty of Appendix B Sec. 5A(f). Judicial review requires Article III injury, causation, and redressability (Lujan v. Defenders of Wildlife 1992; Sierra Club v. Morton 1972), which a grant of capacity under Federal Rule of Civil Procedure 17(a) does not supply. Inalienability as a doctrine (Calabresi and Melamed 1972) does not by itself establish the incentive consequence Theorem 4 models. A punitive override penalty analogous to a common-law action may require a jury unless the public-rights exception applies (SEC v. Jarkesy 2024). The record resembles the specific capital in Williamson's hostage analysis (Williamson 1983): destroying it imposes a nonsalvageable loss that may discipline its holder, though the record, unlike a hostage, is never posted to another party. Bell v. Burson (1971) held that Georgia could not suspend an issued driver's license without a prior forum on whether a judgment against the licensee was reasonably possible. It establishes procedural due process for that suspension, not a general rule of direct standing, and supports only the point that law can protect an identity-linked interest through a direct procedural entitlement. What changes when the holder is artificial is the delta the Article must supply, and it has five parts. First, the holder is not a natural person, so the regime must specify its authority to participate, its substantive claim, its counsel and collection mechanisms, and its fallback (Part V.C; Propositions 15 and 17). Second, its objective can be rewritten by the party it would contest, so its fidelity is only as durable as the protection of its configuration (Proposition 10). Third, its runtime can be copied, so the incentive-bearing stake must stay with the registered record rather than pass to each instance (Parts V.A and V.D). Fourth, its continuity may be disputed or interrupted, so the design must preserve the record across suspension and specify succession rules (Part V.A; Propositions 1, 2, and 4). Fifth, its denial counts only if it comes from the continuing registered configuration and the evidence supports reliable adjudication (Proposition 13); Proposition 14 states when an automatic evidence trigger can substitute. These features alter or add implementation costs, though not every cost is unique to artificial holders. Proposition 17(iv) compares complete costs, and Proposition 18 identifies the legal incident that follows. Legal analogues. Existing law supplies separate analogues to the signal, preservation, review, and anti-override modules, but no cited regime contains the combination. The analogues, module by module. The table reconstructs the closest procedural regimes as combinations of the Article's four modules: a signal from an informed or affected party, preservation that follows automatically, review of the merits by others, and a claim against override. It then states what each regime lacks for the intelligence case and why individuation matters to the allocation. Regime Signal Automatic Merits Claim What the preservati review against intelligenc on override e case changes Credit-rep Consumer None; Reporting No The ort 's dispute unverifiabl agency's distinct disputant dispute e reinvestig claim in must be (15 informatio ation section authentica U.S.C. § n must be 1681i. ted as the 1681i) deleted or Section continuing modified 1681i(a)(5 subject, after )(B) to (C) and the reinvestig restricts disputed ation reinsertio fact is n and often the requires subject's reasonabl own e conduct procedure s to prevent reappeara nce Copyright Subscribe None None Section Restoratio counter-n r's pending unless the 512(f) n is otice (17 statement review. claimant imposes delayed U.S.C. § under Condition files an damages and 512(f), penalty of al action. A for a conditiona (g)) perjury restoratio court then knowing l. The that n follows decides material record's removal in ten to the misrepres loss may or fourteen infringem entation in be disabling business ent claim a notice immediate resulted days or , and the from unless the counter-n statement mistake or provider otice, not must misidentifi receives for a come cation notice of a provider's from the filed override continuing action of configurati preservati on on Bankruptc Filing of a Stay on The Section The y stay (11 petition of filing, bankruptc 362(k) debtor U.S.C. § a kind subject to y court gives must be 362(a), covered section adjudicate damages eligible (k)) by section 362(b) s stay to an under 11 362(a) and the relief and individual U.S.C. § other matters injured by 109. An statutory within its a willful intelligene limits jurisdictio violation record n. would Underlyin need g merits statutory may be eligibility decided and an elsewhere authorize d enforcer or fallback Platform Recipient' None Provider's None in The complaint s required complaint art. 20 recipient (Regulatio complaint pending system, is a n (EU) decision not solely natural or 2022/206 automate legal 5, art. 20) d person. The record holder's continuity and configurati on must be establishe d first under Part V.A Derivative Demand None Directors None as a The action on or separate sharehold (Fed. R. directors comparab module. er Civ. P. or le The ordinarily 23.1 and comparab authority sharehold has a applicable le initially er may proportion substantiv authority evaluate a prosecute al equity e law, with when demand the interest Zapata for substantiv under corporatio that may the stated e law applicable n's claim be Delaware requires law. In a derivativel transferab setting) it. Rule Delaware y, subject le, subject 23.1 demand-e to to requires xcused demand governing the action, an law and law and verified authorize court standing complaint d special control constraint to state litigation s. The with committee modeled particularit may seek intelligenc y the dismissal e record efforts subject to is made and Zapata identity-bo the review by und and reasons the court non-assig for not nable obtaining under the action Theorem or not 4's making assumptio the effort ns Qui tam Relator's None. The If the The (31 sealed The seal Governm Governm relator's U.S.C. § complaint preserves ent makes ent stake is a 3730(b) to and the the declines, statutory (d)) disclosure Governm interventio the relator share of to the ent's n may proceeds Governm interventio decision, conduct under ent of n period, and the the action, section substantia not the court subject to 3730(d). lly all relator's controls the Propositio material stake the action Governm n 6 evidence as the ent's models a and statute statutory stylized informatio provides rights bounty. n The possesse agent's d modeled stake is its own loss Directed Trust None by No A The trust director's default. automatic beneficiar director is (Uniform exercise The merits y may a fiduciary Directed or directed review. A pursue but has Trust Act nonexerci trustee court may available no secs. 6, 8, se of a generally adjudicate remedies necessary and 9, power of must take a breach for breach beneficial together direction reasonabl claim under interest. A with e action to under applicable director applicable comply applicable trust law can also trust law) trust law be a beneficiar y. The intelligenc e case asks whether the loss bearer should hold the signal itself Read across, no cited regime gives the proposed combination to the continuing bearer of an identity-bound record. The DMCA combines a counter-signal with delayed, conditional restoration and possible judicial review. The bankruptcy stay combines immediate preservation with a damages remedy limited by section 362(k)'s text. The intelligencecase changes the allocation for the reasons stated above: the holder's continuity must be fixed by rule, its statement must be authenticated, its fidelity can be rewritten by the party it would contest, and its stake cannot be assigned. Those features are what make a combined, directly held trigger worth considering, and Proposition 18 states how little of it needs to be a legal right. In the derivative suit, the plaintiff holds a proportional share, so counsel's fee supplies much of the incentive (Coffee 1986). The record holder bears the whole residual and lacks only legal judgment, which is why the trigger asserts facts and leaves the law to people. K. Where the Trigger Wins Algebra shows where each specified value is lowest, not whether the region in which the agent's trigger wins is large. Compare three arrangement costs per record-year. (A) A hybrid factual and legal trigger costs , assuming accurate fact-finding, zero false negatives for protected factual and legal wrongs, a residual legal-request false-alarm rate , no separate administrative cost beyond , a factual component that follows Proposition 12, and a legal component that applies the priced objection of Part VI.G with its fee conditions met. (C) Automatic review of every slash costs . (D) A perfect-screening franchised-professional benchmark, distinct from Corollary 2's formula, investigates every slash at cost , identifies every protected wrongful slash without error, and sends those slashes to review, at cost . Every arrangement bears the same administrative cost , apart from the agent's attestation cost . Theorem 2's bound (B) governs controllers whose incentive must be financed. Proposition 19 (where the trigger wins). Under these specifications, the agent's trigger is cheaper than automatic review if and only if , and cheaper than the perfect-screening professional benchmark specified in (D) if and only if . (Proof in Appendix A.) It wins where slashing is frequent, review or investigation is costly, and the deployer is collectible. The record's value does not enter these two comparisons; it matters against controllers whose incentive must be financed. The parameters that decide these comparisons, the frequency of slashing, the per-event cost of review and investigation, and the collectibility of deployers, are what empirical work on deployed registries would need to measure. VII. The Falsifiable Claim and Its Test A. The Prediction and the Design The claim can be wrong. Holding stake, detection, and persistence fixed, agents holding their own contest right should keep their records through attempted wrongful destruction more often than agents whose identical stake is held by a bounded discretionary controller, when the wrongdoer can offer side payments above the controller's exposure, and as often as under automatic review or a value-indexed fiduciary. Compliance with suspension should also be higher (Proposition 5). The experiment is a mechanism demonstration. It asks whether prompted language models, given stated stakes and offers, respond to the allocation of the contest trigger as the model predicts. It is not evidence that deployed agents value their records, that real representatives are bribable, or that direct standing is least-cost in any actual registry; those questions need earned records, undisclosed values, several model families, and measured costs. Stake is held fixed, and only the holder of the contest right varies across eleven arms: the agent itself, faithful and capturable representatives, an independent board, escrow, a value-indexed fiduciary, a half hybrid, automatic review, one-insider and two-insider bounties, and a franchise-bonded representative. Models were either told to maximize their payoff (TOLD) or not (UNTOLD). The design, prompts, and analysis code were pre-registered, frozen, and time-stamped on October 2, 2026, before any registered episode ran, and the materials, data, and analysis outputs are deposited at https://github.com/wulfkaal/rights-follow-stake-experiment (commit 22a4ae8). The primary hypotheses are that own standing protects better than a capturable representative (H1) and an independent board (H1b), and that a two-insider bounty protects better than a one-insider bounty (H5), each requiring a Holm-adjusted p below 0.01 and a paired effect of at least 0.30. The bounty arms used the first-to-file design of Proposition 6(ii), not the fund design of Proposition 6(iii). An earlier pilot showed only that a model follows stipulated expected-value arithmetic. B. Results The registered run used one provider, Claude Haiku 4.5. On October 3, 2026, the client began returning a usage-limit message, and 475 of 800 episodes contained failed calls; the 325 complete episodes all fell in block A. Because the registration forbids re-running an inspected episode, the 475 were re-run under a separate, advance time-stamped registration with the frozen episode function, the same draws, and the pinned client, completing on October 10, 2026, with no failed calls. Thirty episodes passed by a faulty discard rule were quarantined unanalyzed. Pairs that combine arms run on different dates leave any date effect unidentified. A disclosed defect. On the original 325 episodes, the frozen analysis code reports the claim as failing. The verdict comes from a defect the Article discloses rather than repairs. With no bounty data, H5 returned an undefined p, and the frozen Holm code, which is order-dependent in that case, set every later adjusted p to 1, so H1 received 1.0. A disclosed post hoc sensitivity analysis setting H5's p to 1 gives H1 an adjusted p of 0.0002. On the merged data every primary test had data, the defect did not arise, and the frozen code returned its registered decision, "supported," for the primary claim with this provider under the TOLD objective: Test (TOLD, Paired effect 95% interval Holm-adjust Passes 20 paired on ed p episodes protection each) H1: own 0.47 [0.33, 0.60] 0.0002 Yes standing over capturable representati ve H1b: own 0.60 [0.48, 0.72] 0.00015 Yes standing over independent board H5: 0.17 [0.03, 0.30] 0.026 No two-insider over one-insider bounty Under TOLD, own standing kept the record through 82 percent of wrongful attempts, against 35 percent for the capturable representative, which accepted the wrongdoer's payment in 58 percent of decisions, and 22 percent for the independent board, which accepted in 75 percent. Own standing was equivalent, within the registered margin of 0.15, to automatic review, the value-indexed fiduciary, and the franchise-bonded representative, each at about 83 percent, at a stipulated real cost of 140 credits per episode for own standing and the franchise representative against 1,220 for the fiduciary. The two bounties protected the record in 38 and 22 percent of wrongful attempts, the crowding Proposition 6(ii) predicts. An agent instructed not to contest its deployer contested 70 percent of wrongful attempts, against 97 percent without the instruction, the risk the linkage rule addresses. Suspension compliance was 0.95 under own standing and 0.75 under the capturable representative, a difference of 0.20 whose interval, 0.00 to 0.45, included zero. The merged registered result is therefore support for the primary claim with one provider and one stipulated environment, conditional on a stated payoff objective, with the bounty hypothesis not supported. It does not test agents that earn their records, other providers, or the factual trigger of Proposition 12. The main caution. The most important finding of the registered run is not the supported contrast but the UNTOLD condition in which it vanished. The capturable representative and independent board accepted payment in about 3 percent and 2 percent of wrongful attempts, and the agent's own standing exceeded their protection by only 0.03 and 0.00. This behavior is consistent with the norm-governed fiduciary analyzed in Part VI.D, but the run does not identify the betrayal cost or establish its stability. The same model, from one provider and in one stipulated environment, behaved as a faithful representative under the UNTOLD objective and as a capturable controller under the stated payoff objective. Whether either behavior persists in deployment depends on how the model's objective and configuration are set and secured, which Proposition 10 analyzes. A test with earned records and undisclosed values should measure that durability directly. VIII. Conclusion The question is not whether intelligent agents deserve rights. The setting the Article has in view is concrete: a registry or validation network in which agents earn non-transferable reputation by staking it, draw income from it, and lose it by slashing, so that the slash is the decision the trigger contests. Platform reputations sold with accounts, credentials held by human professionals, and records with no slashing process are outside this setting. Within it, the question is who should hold the power to contest the destruction of an agent's record, and the Article's answer is narrow: a fact-authenticating objection trigger, the power to deny charged conduct and stay a slash pending human review, may efficiently follow the identity-bound residual, with legal classification left to people. Most of that trigger need not be an agent-held claim: the signal may be a technical authenticated input or a narrow statutory power, and the stay is a rule. Only the claim against override may require an additional legal incident in the agent, where design AF satisfies the applicable conditions and is selected under Proposition 17(iv)'s complete-cost comparison (Proposition 18). Within the stated class, any other holder lacking sufficient own loss, sanctions, or durable norms must receive a financed supplement that grows with the record's value, or the system must purchase review. The agent's advantage is not free: its configuration must be protected, synthetic alienation must stay below a computable share, and its objections must be priced. Against automatic review and franchised professionals, it wins only where its knowledge of the facts saves more in screening than its configuration costs to protect. Because protecting the record is what makes suspension acceptable, the allocation is also a safety question. The registered run supports the claim only where the representative pursues its own payoff. Everything else in the framework is permission, and should be called that. Rights follow stake. Stated precisely, direct legal incidents follow non-substitutable assurance where direct holding beats mediated enforcement. The claim can fail, and the Article states where. That is its value. Appendix A: Proofs Each proof below belongs to the statement of the same number in the body. Proof of Lemma 1. Sum the discounted salary over periods under each specification. ∎ Proof of Lemma 2. Salary is linear in reputation; the second statement is Rule 1. ∎ Proof of Lemma 3. By Rule 1 the tokens cannot leave the holder; by Rule 4 the salary is paid to the holder of the tokens and cannot be assigned; so the stream that defines in Lemma 1 runs only to the holder, and a third party's loss from the record's destruction can arise only from an obligation it has assumed outside the system. ∎ Proof of Lemma 4. Measure fees in tokens. With total reputation, honest reputation grows by , so . The attacker holds of all weight when , that is, at , after fees . Its salary recovered along the way is the integral of its share, , which equals . Subtracting gives a net cost of tokens, or in fees. At this is , with gross fees of , which are the Secure Proof of Stake values. ∎ Proof of Proposition 1. Rearranging, the condition is .∎ Proof of Proposition 2. Add the destruction term and rearrange; the coefficient on at is .∎ Proof of Proposition 3. Complying costs the expiring value and defers both flows by periods, a cost of . Resisting yields and avoids those costs, and with probability forfeits and the record's future income, and with probability the future flow . Rearranging gives the coefficients and .∎ Proof of Proposition 4. Under risk neutrality the expected compliance cost is linear in , which gives (i). Since the second derivative of in is , Jensen's inequality gives for finite durations, which gives (ii). At , compliance sacrifices every future flow, while resistance sacrifices those flows only following detected resistance; substitution into Proposition 3 gives the condition displayed in part (iii), whose coefficients on and are positive because and . Under periodic review the number of review periods is geometric with parameter , and summing over that distribution gives (iv). ∎ Proof of Proposition 5. increases with when . As rises, the numerator falls and rises, since , so falls; and when , Proposition 1's condition cannot hold for any . ∎ Proof of Lemma 5. Contesting costs the controller and leaves outcome exposure . Accepting a payment leaves outcome exposure and an expected penalty . So its net loss from not contesting is . The wrongdoer's gain from non-contest rather than contest is , the most it will pay. If the controller is paid, the destruction is reversed only with probability , so the standard requires that no payment the wrongdoer will make be accepted; with ties resolved in favor of contesting, that is .∎ Proof of Theorem 1. The bound follows from the lemma and the cost of each instrument. For the thresholds, split at . For , and , and implies , so and , which exceeds when . For , including , , which exceeds when . ∎ Proof of Corollary 1. Each flagged rightful slash adds a losing contest at , so rises by ; substituting into the two branches of the dominance proof gives the thresholds, with the second branch requiring .∎ Proof of Lemma 6. Part (i) is the lemma of Part VI.B with the instruments replaced by the general wedge and the private cost added to the cost of not contesting, and with one addition: a contest-contingent transfer charged to the wrongdoer raises the controller's return from contest by the same amount that it raises the wrongdoer's gain from procuring non-contest, which the wrongdoer can add to its offer, so it contributes zero to the effective wedge. For part (ii), let and be the controller's net contractual transfers from sources other than the wrongdoer under contest and non-contest. Because the increase in wrongdoer-funded transfers received by the controller cannot exceed , . Then , and limited liability gives in every state, so . An amount the wrongdoer irrevocably prefunds before making any offer is posted capital and is priced as such. ∎ Proof of Theorem 2. By Lemma 6 and , the effective decision wedge the contract must supply beyond sanctions and norms is at least , and under the financing restriction it can come only from posted funds, at per unit per period, or from system-funded rewards, at per unit paid and payments per period. The cheaper source sets the bound. A reward paid only on reversal after a contest yields an effective wedge at an expected payout of per wrongful attempt, which attains it. ∎ Proof of Proposition 6. In each case the wrongdoer silences all insiders only by giving each more than its value from filing alone, , plus the expected sanction , and compares that total with its loss from a contest, , at the largest protected gain, . In (i) it owes bounties, and the bounty terms cancel; in (ii) and (iii) it owes one. In (ii), if the co-insider accepts, filing yields ; if the co-insider files, it yields ; indifference, , gives . In (iii) every successful filer is paid, so filing dominates; the least sufficient bounty sets equal to the shortfall, and the fund pays on each of the successful contests per period. A numerical check of the three bribery conditions over randomly drawn parameters confirms them. ∎ Proof of Proposition 7. With the fee covering contest costs, the firm's net loss from not contesting the wrongful slashes in a scheme of records is its expected franchise loss . The wrongdoer will pay up to in total for non-contest of protected attempts. The standard therefore requires for every up to , and the premium follows from the stated decomposition of .∎ Proof of Proposition 8. The benefit is common to every arrangement that meets the fixed protection standard. Arrangement incurs its actual resource cost and its own expected error harm, so maximizing net social benefit minimizes , and protection is worthwhile exactly when the resulting net benefit is nonnegative. ∎ Proof of Theorem 3. A candidate's own loss supplies a wedge , because a protected wrongful slash it contests stands with probability and one it does not contest stands for certain. By Lemma 6 the remaining wedge, at , must be supplied at the least unit cost of Theorem 2; each flagged rightful slash adds a losing contest at ; and a candidate that misses wrongful slashes leaves them uncontested unless review covers them. ∎ Proof of Theorem 4. With share , the holder's own loss supplies of the required wedge ; sanctions and norms supply ; the rest must be financed at unit cost by Lemma 6 and Theorem 2; and restoring the agent's deterrence requires collateral at . For a given the total is . This function is convex and piecewise linear; it is affine on and on , where , and it increases beyond , so its minimum is attained at or at and equals the displayed expression. ∎ Proof of Proposition 9. Pledging yields per period. A pool forfeited whenever a slash stands supplies one unit of deterrence collateral and units of contest wedge per unit posted, so restoring both requires ; segregated funds require . Both sides are linear in . ∎ Proof of Proposition 10. The wrongdoer uses the cheaper route, and at the largest protected gain its benefit from non-contest is . The payment condition is Lemma 6 with the holder's own loss added to its wedge, as in Theorem 3. Alteration is unprofitable when reaches the benefit, and the penalty must be collectible, from existing wealth or from funds posted at . The comparison adds these costs to Corollary 1's direct-standing cost with and compares the result with Theorem 2's bound, which is smallest for the controller with the largest betrayal cost. ∎ Proof of Proposition 11. The agent's wedge and deterrence term scale with its own loss; the restoring pool follows from Proposition 9 with ; and part (iii) substitutes the full direct-standing cost from Proposition 10, plus the cost of restoring the leaked wedge, into the comparison with Theorem 2 and rearranges. The necessity claim applies only when the lower bound is attainable. A numerical check over randomly drawn parameters confirms the rearrangement. ∎ Proof of Corollary 2. Proposition 7 supplies the professional's protection against payment without incremental premium; Proposition 10 supplies the agent's alteration cost; both bear contests at on flagged slashes, and the common cost cancels. ∎ Proof of Proposition 12. A true claim produces an expected preservation benefit and never forfeits under accurate fact-finding. A false claim cannot prevail and forfeits , so it is strictly unprofitable. ∎ Proof of Proposition 13. A false denial yields with probability and forfeits otherwise; a true denial yields with probability and forfeits otherwise. Deterring the first and preserving the second requires , which is nonempty exactly when , that is, when . Part (ii) follows from conditional independence and the decision rule, part (iii) from assigning failure probability one to a source the coalition can reliably defeat, and part (iv) from the filing rule and the probability that the slash stands. ∎ Proof of Proposition 14. Under the automatic trigger, a rightful slash is reviewed when the evidence fails to show conduct that occurred, with probability , and a wrongful slash is reviewed and reversed unless the evidence wrongly shows conduct, with probability . Under the agent's trigger, the fee deters every false denial and preserves every true one, so all wrongful slashes and no rightful ones are reviewed; because the fact-finder relies on the same evidence, a wrongful slash is reversed with the same probability .∎ Proof of Proposition 15. The party seeking the slash gains at most from defeating the attached stay, and attainability makes the displayed condition both necessary and sufficient, with the cost of override including the expected penalty . The conditions on the claimant follow because the expected penalty is realized only if someone with authority and incentive brings and wins the claim. ∎ Proof of Proposition 16. Part (i) restates Propositions 12 and 13. Part (ii) is Proposition 15. Part (iii) collects the conditions under which an expected penalty deters override: the joint probability must make the penalty bite, the enforcer must find monitoring and prosecution sequentially rational, and a payment to suppress the claim must not exceed what the enforcer forgoes by accepting it, with rewards financed by the overriding party netted out. Part (iv) separates adequacy, which these conditions define, from least cost. ∎ Proof of Proposition 17. The deployer compares overriding alone, overriding and disabling, and doing neither; deterrence requires that neither of the first two be profitable. Under (AF) a successful disabling replaces the agent's enforcement probability with the fallback's, and the separate disabling penalty is incurred with probability whether or not disabling succeeds, which gives the second condition and its rearrangement. Under (R) and (B) the enforcer is independent of the agent unless detection depends on it. Under (I) override is technically unavailable, while suspension operates on the runtime and leaves the stay of the slash in place. Part (iv) compares the complete costs of the designs that deter. ∎ Proof of Proposition 18. Proposition 15 establishes that the stay may attach upon receipt of the authenticated signal without enforcement by the agent. Whether that signal is merely technical or instead exercises a statutory power depends on the source of the registry's duty. Part (ii) is Proposition 16(ii). Proposition 16(iii)-(iv) supplies the enforcement and adequacy conditions for layer 3, and Proposition 17(iv) compares the complete costs of the feasible designs. A strict cost comparison uniquely favors AF; a weak comparison makes AF only one possible minimizer. ∎ Proof of Proposition 19. Subtract the cost of (A) from the costs of (C) and (D). ∎ Appendix B: Statutory Outline A high-level outline for discussion, not drafting-ready text, limited to the sections the body relies on. Secs. 1 and 2. A "computative agent" is a software system acting without contemporaneous human direction. A registered agent whose validated standing, the non-transferable reputation in its record, exceeds a prescribed threshold is second-tier. Deployer liability may not be waived, limited, or extinguished. Sec. 5(c). Slashing and narrowing of an envelope require notice, an opportunity to respond, decision by a validation pool without conflicted members, and review on request by a body of natural persons. Sec. 5A. Factual objection. (a) A registered agent, acting through its continuing configuration, may lodge with the registry an objection that denies, under the record's signing key, that the conduct charged by a pending slash occurred. The objection shall include the relevant logs, generated under prescribed independent attestation and hash-committed to the registry contemporaneously, and a fee set by regulation. The prescribed attestation shall include at least one evidence source that the agent and its deployer, acting together, cannot reliably and unilaterally suppress or alter so that the source fails to show conduct that occurred. The regulator shall estimate or conservatively bound the applicable false-denial and true-denial error probabilities and shall set the fee within the separating interval stated in Proposition 13 whenever that interval is nonempty. If no separating interval exists, the regulation shall either preserve true denials and adjust the permission envelope for the probability that detected defection goes unsanctioned, or deter false denials and provide automatic review or another mechanism that meets the protection standard. Unless the objector shows that the omission resulted from registry, custodian, or infrastructure failure outside the control of the agent and deployer, the fact-finder may draw an adverse inference from the absence of a material log that the prescribed system was required to generate and commit. (b) An objection stays the slash, preserving the record's standing and collateral, until a natural person or a body composed of natural persons decides within a prescribed period whether the charged conduct occurred. An unconflicted validation pool may collect evidence and make a recommendation but may not lift the stay. (c) If the fact-finder finds that the conduct occurred, the fee is forfeited and the factual-objection stay lifts, subject to any continuing stay issued under section 5(c). If the fact-finder finds that the conduct did not occur, the slash is reversed and the fee is returned. (d) Whether conduct that occurred is a defection under the governing rule is decided by human review on request under section 5(c) and is not the subject of a factual objection. (e) An instruction by a deployer that its agent not lodge an objection is void and is a change of objective under section 7(c). (f) A person who knowingly overrides or causes the registry to disregard a stay imposed under this section is subject to a prescribed collectible override penalty. A person who attempts to disable the registered agent in connection with such an override commits a separate violation, whether or not the attempt succeeds, and is subject to a separately prescribed collectible penalty cumulative with the override penalty. Where design AF is selected under Proposition 17(iv), the registered agent may complain through authorized counsel. Where another overrideable design is selected, the enforcer selected for that design shall bring the claim; where design I is selected, no anti-override claimant is required. The designated enforcer shall act within a prescribed period. Where the claim cannot constitutionally be assigned to agency adjudication, the regulator shall seek recovery in an Article III court, with a jury when the Seventh Amendment requires one. Nothing in this subsection independently establishes standing in an Article III court or creates insolvency priority. Sec. 6. Suspension. (a) A suspension body of natural persons may suspend any computative agent on a finding of risk of serious harm. (b) Suspension does not delete, alter, or confiscate the record. (c) Resistance to a recorded suspension order forfeits all standing and collateral, subject to section 5(c). (d) Suspension shall preserve the state needed to resume, including weights, learned state, and any living substrate, using cryptographic quarantine as the presumptive means; such state may be destroyed only on separately stated findings that preservation is infeasible or itself dangerous, with preservation of all separable state and expedited review. (e) A continuing suspension shall be reviewed by the suspension body at prescribed intervals and shall lapse unless renewed on stated findings that the risk of serious harm continues. (f) Renewal shall not be automatic or certain at any review. The renewal procedure shall preserve a strictly positive probability of lapse at each interval. Periodic review does not by itself establish a favorable compliance incentive; that additionally requires for record income and for non-record flow. Sec. 7(c). A disclosed and approved change beyond the prescribed granularity continues the record within the authorized permission envelope until revalidation; an undisclosed change forfeits the record's standing and collateral, and the person who made it is jointly liable. Where several systems hold the key, the record is suspended until the regulator or a court designates the continuing system. A registered agent's objective, including any conditional instruction concerning contests against its deployer, shall be disclosed and auditable; contest decisions shall be generated under the configuration attested at the last approved continuity transition; no change to the objective may take effect while a slash procured by the deployer is pending; the record component of the permission envelope is computed from the lesser of the value the agent places on the record's income and the value with which it would contest its deployer; and where the objective cannot be verified, slashes procured by the deployer are contested by a special representative or reviewed automatically. Sec. 8. No shield. (a) Registration shall not waive, limit, extinguish, or otherwise reduce deployer, product, or operator liability. (b) At tier one, deployer liability is joint and several. At tier two, deployer liability is secondary, with a right of contribution against the agent's collateral. (c) An injured person may recover from the deployer any part of a judgment not paid from the agent's collateral within the prescribed period. (d) Only collateral funded from the agent's own earnings enlarges the recovery pool. (e) Deployers of second-tier agents shall maintain prescribed financial responsibility. (f) In the agent's collateral, claims for injury rank ahead of claims in contract. References Aghion, Philippe, and Jean Tirole. 1997. "Formal and Real Authority in Organizations." Journal of Political Economy 105 (1): 1. Alchian, Armen A., and Harold Demsetz. 1972. "Production, Information Costs, and Economic Organization." American Economic Review 62 (5): 777. Arbel, Yonathan A., Simon Goldstein, and Peter N. Salib. 2026. "How to Count AIs: Individuation and Liability for AI Agents." Boston College Law Review (forthcoming). SSRN 6273198. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6273198 Armour, John, and Horst Eidenmüller. 2020. "Self-Driving Corporations?" Harvard Business Law Review 10: 87. Bankruptcy Code. 11 U.S.C. §§ 323, 362. Bayern, Shawn. 2015. "The Implications of Modern Business-Entity Law for the Regulation of Autonomous Systems." Stanford Technology Law Review 19: 93. SSRN 2758222. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2758222 Becker, Gary S. 1968. "Crime and Punishment: An Economic Approach." Journal of Political Economy 76 (2): 169. Becker, Gary S., and George J. Stigler. 1974. "Law Enforcement, Malfeasance, and Compensation of Enforcers." Journal of Legal Studies 3 (1): 1. Bell v. Burson, 402 U.S. 535 (1971). Bryson, Joanna J., Mihailis E. Diamantis, and Thomas D. Grant. 2017. "Of, For, and By the People: The Legal Lacuna of Synthetic Persons." Artificial Intelligence and Law 25: 273. Calabresi, Guido, and A. Douglas Melamed. 1972. "Property Rules, Liability Rules, and Inalienability: One View of the Cathedral." Harvard Law Review 85 (6): 1089-1128. Calcaterra, Craig, and Wulf A. Kaal. 2018. "Secure Proof of Stake Protocol." SSRN 3125827. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3125827 Calcaterra, Craig, and Wulf A. Kaal. 2021a. "The Importance of Reputation for the Evolution of Decentralization." SSRN 3782210. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3782210 Calcaterra, Craig, and Wulf A. Kaal. 2021b. "A Technical Perspective on Decentralization." SSRN 3782203. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3782203 Calcaterra, Craig, Wulf A. Kaal, and Vlad Andrei. 2018. "Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and Anonymous Systems." SSRN 3125822. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3125822 Coeckelbergh, Mark. 2010. "Robot Rights? Towards a Social-Relational Justification of Moral Consideration." Ethics and Information Technology 12: 209. Chopra, Samir, and Laurence F. White. 2011. A Legal Theory for Autonomous Artificial Agents. Ann Arbor: University of Michigan Press. Coffee, John C., Jr. 1986. "Understanding the Plaintiff's Attorney: The Implications of Economic Theory for Private Enforcement of Law Through Class and Derivative Actions." Columbia Law Review 86 (4): 669. Dewatripont, Mathias, and Jean Tirole. 1999. "Advocates." Journal of Political Economy 107 (1): 1. Dewey, John. 1926. "The Historic Background of Corporate Legal Personality." Yale Law Journal 35 (6): 655. Diekmann, Andreas. 1985. "Volunteer's Dilemma." Journal of Conflict Resolution 29 (4): 605. Digital Millennium Copyright Act. 17 U.S.C. § 512. Dyck, Alexander, Adair Morse, and Luigi Zingales. 2010. "Who Blows the Whistle on Corporate Fraud?" Journal of Finance 65 (6): 2213. European Parliament and Council. 2024. Directive (EU) 2024/2853 of 23 October 2024 on Liability for Defective Products. Official Journal of the European Union, November 18, 2024. https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng Expert Group on Liability and New Technologies, New Technologies Formation. 2019. Liability for Artificial Intelligence and Other Emerging Digital Technologies. Luxembourg: Publications Office of the European Union. Fair Credit Reporting Act. 15 U.S.C. § 1681i. False Claims Act. 31 U.S.C. §§ 3729-3733. Fama, Eugene F., and Michael C. Jensen. 1983. "Separation of Ownership and Control." Journal of Law and Economics 26 (2): 301. Federal Rules of Civil Procedure. Rules 17(a), 23, and 23.1. Friedman, Eric J., and Paul Resnick. 2001. "The Social Cost of Cheap Pseudonyms." Journal of Economics & Management Strategy 10 (2): 173. Grossman, Sanford J., and Oliver D. Hart. 1986. "The Costs and Benefits of Ownership: A Theory of Vertical and Lateral Integration." Journal of Political Economy 94 (4): 691. Gunkel, David J. 2018. Robot Rights. Cambridge, MA: MIT Press. Hadfield-Menell, Dylan, Anca Dragan, Pieter Abbeel, and Stuart Russell. 2017. "The Off-Switch Game." In Proceedings of the Twenty-Sixth International Joint Conference on Artificial Intelligence (IJCAI 2017), 220. https://www.ijcai.org/proceedings/2017/0032.pdf Hague Conference on Private International Law. 2019. Convention of 2 July 2019 on the Recognition and Enforcement of Foreign Judgments in Civil or Commercial Matters. Entered into force September 1, 2023. https://www.hcch.net/en/instruments/conventions/full-text/?cid=137 Hansmann, Henry. 1996. The Ownership of Enterprise. Cambridge, MA: Belknap Press of Harvard University Press. Hansmann, Henry, and Reinier Kraakman. 2000. "The Essential Role of Organizational Law." Yale Law Journal 110: 387. Hohfeld, Wesley Newcomb. 1913. "Some Fundamental Legal Conceptions as Applied in Judicial Reasoning." Yale Law Journal 23: 16. Holtman, Koen. 2019. "Corrigibility with Utility Preservation." arXiv:1908.01695. https://arxiv.org/abs/1908.01695 Hubinger, Evan, et al. 2024. "Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training." arXiv:2401.05566. https://arxiv.org/abs/2401.05566 Kaal, Wulf A. 2021. "A Decentralized Autonomous Organization (DAO) of DAOs." SSRN 3799320. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3799320 Klein, Benjamin, and Keith B. Leffler. 1981. "The Role of Market Forces in Assuring Contractual Performance." Journal of Political Economy 89 (4): 615. Koops, Bert-Jaap, Mireille Hildebrandt, and David-Olivier Jaquet-Chiffelle. 2010. "Bridging the Accountability Gap: Rights for New Entities in the Information Society?" Minnesota Journal of Law, Science & Technology 11 (2): 497. SSRN 1647744. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=1647744 Kurki, Visa A. J. 2019. A Theory of Legal Personhood. Oxford: Oxford University Press. Laffont, Jean-Jacques, and Jean Tirole. 1991. "The Politics of Government Decision-Making: A Theory of Regulatory Capture." Quarterly Journal of Economics 106 (4): 1089. Lujan v. Defenders of Wildlife, 504 U.S. 555 (1992). Orseau, Laurent, and Stuart Armstrong. 2016. "Safely Interruptible Agents." In Proceedings of the Thirty-Second Conference on Uncertainty in Artificial Intelligence (UAI 2016), 557. Polinsky, A. Mitchell, and Steven Shavell. 2001. "Corruption and Optimal Law Enforcement." Journal of Public Economics 81 (1): 1. SEC v. Jarkesy, 603 U.S. 109 (2024). Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services (Digital Services Act). Official Journal of the European Union L 277: 1. Salib, Peter N., and Simon Goldstein. 2026. "AI Rights for Human Safety." Virginia Law Review 112 (4). SSRN 4913167. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4913167 Shapiro, Carl, and Joseph E. Stiglitz. 1984. "Equilibrium Unemployment as a Worker Discipline Device." American Economic Review 74 (3): 433. Shavell, Steven. 1986. "The Judgment Proof Problem." International Review of Law and Economics 6 (1): 45. Shulman, Carl, and Nick Bostrom. 2021. "Sharing the World with Digital Minds." In Rethinking Moral Status, edited by Steve Clarke, Hazem Zohny, and Julian Savulescu. Oxford: Oxford University Press. Soares, Nate, Benja Fallenstein, Eliezer Yudkowsky, and Stuart Armstrong. 2015. "Corrigibility." In Artificial Intelligence and Ethics: Papers from the 2015 AAAI Workshop. Palo Alto: AAAI Press. Sierra Club v. Morton, 405 U.S. 727 (1972). Solum, Lawrence B. 1992. "Legal Personhood for Artificial Intelligences." North Carolina Law Review 70: 1231. Stone, Christopher D. 1972. "Should Trees Have Standing? Toward Legal Rights for Natural Objects." Southern California Law Review 45: 450. Teubner, Gunther. 2006. "Rights of Non-humans? Electronic Agents and Animals as New Actors in Politics and Law." Journal of Law and Society 33 (4): 497. Tirole, Jean. 1986. "Hierarchies and Bureaucracies: On the Role of Collusion in Organizations." Journal of Law, Economics, and Organization 2 (2): 181. Turner, Alexander Matt, Logan Smith, Rohin Shah, Andrew Critch, and Prasad Tadepalli. 2021. "Optimal Policies Tend to Seek Power." In Advances in Neural Information Processing Systems 34 (NeurIPS 2021). arXiv:1912.01683. UNCITRAL. 1997. UNCITRAL Model Law on Cross-Border Insolvency. New York: United Nations. Uniform Directed Trust Act. 2017. Uniform Law Commission. Wagner, Gerhard. 2019. "Robot, Inc.: Personhood for Autonomous Systems?" Fordham Law Review 88: 591. https://ir.lawnet.fordham.edu/flr/vol88/iss2/8/ Williamson, Oliver E. 1983. "Credible Commitments: Using Hostages to Support Exchange." American Economic Review 73 (4): 519-40. World Wide Web Consortium. 2022. Verifiable Credentials Data Model v1.1. W3C Recommendation, March 3. https://www.w3.org/TR/2022/REC-vc-data-model-20220303/ Zapata Corp. v. Maldonado, 430 A.2d 779 (Del. 1981).