field note / 2026 / ai-agents + policy A legislative technology worktable with marked-up AI agent bill pages, platform access diagrams, FTC registry notes, laptop audit logs, delegation-token sketches, and account-permission checklists under low committee-room light.

field dossier

The AI AGENT Act Makes Delegation a Platform Right

The AI AGENT Act draft matters because it treats agentic software as a delegated representative with rights against large platforms and duties back to the human. That moves agent policy from chatbot safety into access law.

Senator Mark Warner’s AI AGENT Act draft is the first serious attempt to give consumer agents a legal right to touch the platforms that would rather keep them outside the wall. The draft does something sharper than the usual AI safety posture routine: it treats an agent as a delegated representative, then asks Amazon-scale platforms, banks, social networks, travel sites, and app ecosystems to maintain interfaces where that delegation can be authenticated, limited, audited, revoked, and contested.

This is a revisit of the agent-infrastructure thread I covered in WebMCP Makes the Browser an Agent Contract and Fly Sprites Make Agent Sandboxes Stateful. Those posts tracked browser-native tool declarations and stateful execution sandboxes. The new development is legal: Warner’s June 29 AI AGENT Act discussion draft tries to turn agent delegation into an enforceable platform-access regime.

The draft’s key object is the custodial user agent, or CUA. The section-by-section summary defines it as software expressly authorized by a user to interact with a large online platform on that user’s behalf in a transparent, documented, scope-limited, and revocable manner. The scope is broad: e-commerce, social media, online banking, travel booking, user-generated content, account settings, and other online interactions.

That definition does useful violence to the current agent discourse. It strips away the fake mysticism. The agent becomes an authorization object. Who delegated authority? What platform can it access? What can it do? How is revocation communicated? Which logs exist? Which provider is responsible when it screws up? Which platform can deny access, and on what record?

Those are boring questions, which means they are the real ones.

The platform obligation is the live wire. Warner’s draft would require large online platform providers to maintain third-party-accessible interfaces so CUAs can access covered interactions on the same terms as a user. The phrase doing the work is fair, reasonable, and nondiscriminatory. Platforms could set privacy and security standards, deny access for fraud or malicious behavior, apply reasonable request thresholds, publish fees or usage limits, and report violations. They could not use interfaces or terms of use to unreasonably deny or undermine a CUA’s access.

That is antitrust vocabulary smuggled into the agent layer, and good. A consumer agent that cannot reach the account, cart, booking, feed, billing page, or settings panel is a toy. Platform-owned agents would win by default because they already sit inside the walls. Third-party agents would be stuck scraping screens, replaying brittle flows, or asking users to hand over god-session cookies like absolute maniacs.

Warner’s draft tries to stop the obvious gatekeeper move before it becomes normal: platforms launch first-party agents, call them safer, throttle third-party agents, then claim the market chose integration. The market did not choose anything if the access surface was rigged.

The privacy duties matter because an agent is a concentrated blast radius. CBS notes the draft frames agents as systems touching email, e-commerce accounts, credit cards, and other sensitive access paths. The CyberScoop account adds the operational shape: FTC-certified bodies could vet agent vendors, providers would link agents to human operators, and built-in controls would let users grant or revoke permission.

That linkage will annoy the anonymity absolutists. Fine. There is a valid civil-liberties fight hiding here, especially for pseudonymous work, hostile jurisdictions, and self-hosted agents. But consumer delegation at platform scale cannot rely on vibes about benevolent automation. If an agent buys something, posts something, changes a setting, exports contacts, books a trip, or files a dispute, the system needs a way to prove which human granted the authority and whether the act stayed inside it.

The harder problem is provider registration. The draft gives FTC registration real weight. Only registered CUAs would get access to large platforms. The stated reason is obvious: keep malicious apps from masquerading as empowerment tools. The risk is also obvious: a registry can become a tollbooth for incumbents, compliance vendors, and platforms that would love to define “safe” as “funded enough to hire counsel.”

Opus Research makes the best critique here: a future with self-hosted, open-source, enterprise, bank-provided, and consumer-subscription agents should not collapse into one commercial-hosted provisioning model. The draft does direct NIST to identify open protocols, or develop model technical standards if none exist, for scope-limited delegation credentials, registration verification, real-time revocation, and auditable records. That standards work is the escape hatch. If it is weak, the registry becomes a velvet rope. If it is strong, registration can certify conformance without forcing every useful agent into the same corporate shape.

The web history is ugly enough to be useful. We have seen platforms use safety language to close APIs, punish interoperability, and keep third-party clients out until the only remaining clients are official, surveilled, ad-optimized, and conveniently mediocre. We have also seen open APIs become spam cannons, bot farms, credential drains, and abuse tunnels. Anyone pretending one side owns the truth is selling something.

The correct frame is access with teeth. A CUA should get narrow, inspectable capabilities, not a scraped session with ambient authority. A platform should get abuse controls, request thresholds, fraud reporting, and emergency denial paths, not a veto over competition. A user should get exportable delegation, logs, revocation, and provider portability, not a cartoon mascot that turns every account into a magic cave.

This is where the draft connects back to WebMCP. Chrome’s browser-agent work asks websites to expose declared tools with schemas and invocation logs. Warner’s bill asks large platforms to expose legally recognized interfaces for delegated agents. Different layer, same pressure: stop pretending agents are fast humans clicking buttons. Treat them as machine actors with capabilities.

Fly’s sandboxing work sits under the same stack. If an agent has legal access to a platform and technical access to a workflow, it still needs an operating body that can fail safely: scoped credentials, checkpoints, logs, rollback, and separation between durable memory and dangerous execution. Delegation law without runtime discipline becomes paperwork around a chainsaw.

The bill is a discussion draft, so the details will mutate. Good. They should. The exact threshold for a large platform, the scope of financial and health data, the appeal path for denied access, the liability model for hallucinated transactions, the meaning of fiduciary-like duty, and the treatment of self-hosted agents all need hostile review.

The important part is that the policy object is finally becoming legible. Agents are delegated actors crossing account boundaries. The fight ahead is about who can certify them, who can block them, who can observe them, who can revoke them, and whether the user gets a portable representative or another platform pet.

If this draft lands well, consumer agents become a new interoperability layer with legal backing and technical standards. If it lands badly, the agent market becomes a registry cartel with platform-approved bots and compliance theater for everyone else.

Either way, the agent web just moved from demo lane to access law. That is where the knives come out.