← Latest papers
💻 computer science

The Agentic Web Requires New Normative Infrastructure

This paper argues that realizing the potential of the agentic web requires establishing a new normative infrastructure of laws, norms, and practices to distinguish authorized AI agents from malicious bots and prevent platforms from unjustly blocking them.

Original authors: Cameron Pattison, Matthew Boulos, Noam Kolt, Changbai Li, Tiziano Piccardi, Seth Lazar

Published 2026-07-16
📖 7 min read🧠 Deep dive

Original authors: Cameron Pattison, Matthew Boulos, Noam Kolt, Changbai Li, Tiziano Piccardi, Seth Lazar

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a giant, bustling city. For a long time, this city was built with open streets where anyone could walk, look around, and chat. But recently, the city has been divided into thousands of private, gated neighborhoods called "walled gardens." Inside these gardens, powerful landlords (the big tech platforms) control the gates. They decide who gets in, what you can see, and how you can move around. Usually, if you want to enter, you have to walk through the gate yourself, following their strict rules.

Now, imagine a new kind of helper: a super-smart digital assistant, or "agent." Think of it like a personal robot butler that you can send out to do your chores. Instead of you walking to the grocery store to compare prices, your robot butler can run there, check the shelves, and bring you the best deal. In the world of the internet, these agents are powered by advanced AI. They can read websites, fill out forms, and even negotiate deals on your behalf. The big question is: If you have the right to walk into a digital neighborhood yourself, shouldn't your robot butler be allowed to walk in with you? Currently, the landlords are often slamming the gates shut on these robots, treating them like sneaky thieves, even when they are just doing your homework. This paper explores how we can fix the rules so these helpful robots can do their jobs without getting kicked out of the city.


The Paper: "The Agentic Web Requires New Normative Infrastructure"

This paper argues that we are standing on the edge of a massive shift in how we use the internet. For years, the only way to get things done online was to do it yourself, clicking and typing. But now, AI agents are ready to take over those tasks. However, the rules of the road haven't caught up. The authors suggest that we need a brand new set of laws and social norms—what they call "normative infrastructure"—to make sure these agents can work for us without being blocked by the platforms that host the websites.

The Problem: A Cold War of Gates and Locks
Right now, there is a tense standoff between the people building these AI agents and the companies that own the websites. The website owners are terrified. They see automated traffic and think, "That's a malicious bot stealing our data or crashing our servers!" So, they build high-tech fences and write strict rules in their "Terms of Service" that say, "No robots allowed."

The AI developers, meanwhile, are like ninjas trying to sneak past those fences. They use clever tricks to hide their robots' identities so the websites think they are just regular humans. This has turned into a "cold war" where both sides are burning money and energy trying to outsmart each other. The paper points out that this is a waste. It's like a store owner yelling at a customer's authorized shopping assistant, thinking it's a thief, while the customer is just trying to buy groceries.

The Solution: A Three-Part Rulebook
The authors propose a new "Normative Triad"—a three-part rulebook to fix this mess. They believe these rules should be the foundation for how the internet works in the age of AI.

  1. Delegation (The "Proxy" Rule):
    Imagine you have a key to your own house. If you hire a friend to water your plants while you are away, you are "delegating" your authority to them. The paper argues that if you have the right to access a website, you should have the right to send an AI agent to do it for you. The agent is just your tool, like a browser or a pair of glasses. If the website lets you in, it should let your authorized agent in too. The authors say we shouldn't treat a user's robot as a stranger; it's just the user, wearing a digital mask.

  2. Transparency (The "Name Tag" Rule):
    The problem with the current system is that websites can't tell the difference between a helpful robot and a bad one. The authors suggest a two-way transparency rule.

    • The Agent's Job: The AI agent must wear a digital name tag. It must say, "Hi, I am an agent, and I am working for [User's Name]." It can't sneak in disguised as a human.
    • The Website's Job: The website must be honest about its rules. It can't secretly block robots or slow them down without telling anyone. If a website says, "We block all bots," it needs to say that clearly, not hide it in fine print.
      This way, users know if their agent is being treated fairly, and websites know exactly who is knocking at the door.
  3. Proportional Restriction (The "Less is More" Rule):
    Sometimes, a website does need to say "No." Maybe the server is overloaded, or the agent is trying to do something illegal. The paper argues that if a website wants to block an agent, it must have a very good, specific reason. It can't just ban all robots because it's scared. It has to use the "least restrictive means" possible.
    Think of it like a bouncer at a club. If a group is causing trouble, the bouncer can kick them out. But the bouncer shouldn't kick out the whole group just because one person is wearing a weird hat. The restriction must match the actual problem. If the only issue is that the agent is using too much data, the website should just limit the data, not ban the agent entirely.

What This Paper Does NOT Say
The authors are careful to say they are not solving every problem in the world.

  • They are not saying that every bot is good. They explicitly distinguish between "malicious bots" (like those stealing data to train AI models without permission) and "user-authorized agents" (robots working for a specific person). Their rules are for the good guys, not the thieves.
  • They are not saying that platforms must give up all control. They admit that websites have legitimate concerns about security, privacy, and server costs. Their "Proportional Restriction" rule is designed to let websites protect themselves, just not in a way that hurts regular users.
  • They are not claiming that this is a solved problem. They are suggesting these principles as a starting point for a big conversation. They admit that there are risks, like agents getting too powerful or creating new inequalities, but they believe the benefits of letting users control their own digital assistants are too big to ignore.

Why This Matters
The paper suggests that if we don't fix these rules, the internet will become a place where only the big companies win. If users can't send their agents to compare prices, negotiate bills, or manage their lives, they will remain trapped in the "walled gardens," forced to accept whatever terms the platforms offer. By building this new infrastructure, we could shift the power back to the users, letting them use their AI helpers to navigate the digital world freely, just as they would in the real world.

The authors conclude that the technology is ready. The robots are built. The only thing missing is the agreement on how to let them in. They are calling for a society-wide conversation to write these new rules before the internet gets locked down forever.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →