Vector of OneInsights
Operator-led, Practitioner-First
ESSAY

Who Does Your AI Agent Actually Work For?

An agent acting inside your business is answering to someone. Vivek Bhogaraju on why that question decides more about your AI strategy than the model you pick.

Volume II · September 20266 min read

In the published chain of command of the world's most widely used AI, the user ranks fourth.

A vow is the oldest loyalty technology we have. Two parties, a public declaration, no ambiguity about who serves whom. I have been thinking about vows recently, for reasons I will get to at the end, and the more I sat with the idea, the more it clarified a question I now ask in every conversation about agentic AI: when an agent acts on your behalf, who is it actually loyal to?

Most people assume the answer is obvious. You deployed the agent. You gave it the instruction. It works for you. I would like that to be true. The evidence says it is not, at least not yet. The industry is settling the answer right now, largely without consulting the one party the agent claims to serve.

Four parties, one recommendation

Every agent operating in the real world serves at least four masters.

  1. Principal user. The person who typed the instruction and expects the agent to act in their interest.
  2. The enterprise deploying the agent. If it runs inside a company's environment, that company sets policies, guardrails, and commercial priorities the agent must respect.
  3. The set of data and content providers. Agents are only as good as what they can access, and the parties supplying inventory, pricing, reviews, and proprietary content attach commercial terms to that access.
  4. The frontier model underneath. Every agent inherits a hierarchy from the lab that trained it. OpenAI publishes this openly in its Model Spec: instructions are ranked root, then system, then developer, then user.

Researchers Mark Riedl and Deven Desai have named this the agentic loyalty problem. Their example is worth repeating. You ask an agent to buy an item for under $500. It finds the item at $450 and at $425. It buys the $450 version because its provider has a commercial arrangement with that seller. You never learn the cheaper option existed. A human agent who did this would violate the duty of loyalty under agency law, one of the oldest and most settled ideas in commercial life. When software does it, we currently call it a business model.

The conflict played out in a shopping cart

You tell your shopping agent: find me the best noise-cancelling headphones under $300, and I need them by Friday.

The agent finds three candidates. Option A costs $249 at an independent electronics retailer with strong reviews. Option B costs $279 at a large marketplace where the agent's provider earns a referral fee. Option C costs $265 at a retailer where you hold loyalty status, and the purchase would unlock a reward worth $20 on your next order.

Your interest points to Option A, or arguably Option C once the reward is counted. The provider's commercial interest points to Option B, whose marketplace has paid for preferred placement in the agent's results. The retailer behind Option C can only compete if its loyalty program is machine-readable in the milliseconds before checkout. Eagle Eye's analysis of the Woolworths and Google pilot makes the stakes plain: if a loyalty engine cannot verify an offer during the agent's API call, the program is invisible to the agent. Above all of it sits the frontier model's own hierarchy, deciding which of these instructions and incentives even reach the reasoning process.

Real money moves in different directions depending on whose interest wins. The user sees none of it. They see a confident recommendation.

Courtrooms are deciding what principles should agents follow

Amazon versus Perplexity is the live test. Amazon sued to stop Perplexity's Comet agent from shopping on behalf of logged-in users, and in March 2026 a federal judge granted the injunction. The pivotal finding: Comet accessed Amazon accounts with the user's permission but without Amazon's authorization. Those two things used to be the same thing. They no longer are.

Underneath the legal language, this is a loyalty fight. Agents do not see banner ads or sponsored listings, and Amazon built a business generating roughly $68.6 billion in annual advertising revenue on the assumption that human eyeballs would. Perplexity argues users should choose their own tools. Amazon argues platforms control their own front door. Both are defending their claim on the agent's loyalty.

Nobody in that courtroom is formally representing you, the user.

The legal community has at least mapped the options. Work from the Stanford AI Agents x Law workshop, summarized well by Consumer Reports, frames three postures an agent provider can take:

  • Technology provider, with minimal obligations
  • Contractor, with duties defined by contract, or
  • Fiduciary, legally bound to put the user's interest first

Most providers are drifting toward the first posture because it carries the least legal risk. As a business decision, I believe that is backwards.

The case for the principal user

My position: the agent's primary loyalty must run to the principal user, and the companies that commit to this earliest will win the era.

This is a commercial argument, not a sentimental one. Trust is the constraint on adoption, not capability. Revenue management technology did not spread to hundreds of thousands of properties because the models improved. It spread when smaller operators believed the recommendations served them rather than the platform issuing them. Agents face the identical test at a far greater scale. The first time a user discovers their agent steered them to a worse outcome because of an arrangement they could not see, that user is gone.

Fiduciary loyalty is a harder standard to operate under. It is also the most defensible moat available in a market where the underlying models are converging.

When every agent can find the headphones, the only question left is which agent you trust to choose them.

For builders, buyers, and investors, four questions cut through the noise:

  1. Disclosure: Does the agent reveal when a recommendation is influenced by a commercial arrangement, and would you know if it did not?
  2. Hierarchy: Where does the user's instruction rank when it conflicts with the platform's interest, and is that ranking published anywhere?
  3. Auditability: Can anyone verify, after the fact, that the agent chose the best available option for the user?
  4. Posture: Has the provider committed to a loyalty standard in writing, or does its terms of service quietly disclaim the duty its marketing implies?
If the answers are unclear, you are not the principal. You are the inventory.

A closing thought on vows

I said I would return to what prompted this piece. Like a good part of the planet, I followed a certain wedding at Madison Square Gardens, where two people stood before their guests and made their loyalties public, unambiguous, and mutual. Two principals, each fully committed to the other.

In the case of an actual couple, loyalty is simple and clear: it runs to each other. I look forward to the day the answer is equally simple when we ask who our agents work for. Until then, keep asking the question. It is being answered now, whether or not you are in the room.

Sources

Take it further

Map whose priorities your agents serve before delegating consequential decisions. If this question is live in your business, bring it to us.

The Applied AI Leaders Community