← Latest papers
🤖 AI

Agentic AI: User Empowerment or Foreclosure?

By analyzing historical precedents like ad blockers and spam filters, the paper argues that Agentic AI's potential to empower users depends on preventing the "depoliticization" of governance through industry-controlled standards, as the current consolidation around proprietary protocols risks dismantling collective contestation capacity before user-aligned alternatives can solidify.

Original authors: David Gamba, Daniel M. Romero, Grant Schoenebeck

Published 2026-08-18
📖 6 min read🧠 Deep dive

Original authors: David Gamba, Daniel M. Romero, Grant Schoenebeck

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where your computer, phone, or a dedicated device acts as your personal assistant, not just by answering questions, but by doing things for you. It could filter the news you see, negotiate a better price on a flight, or manage your investments while you sleep. This emerging technology is called agentic artificial intelligence. The promise is that these agents will act in your best interest, freeing you from tedious tasks. But a critical question remains: who actually controls these agents? If the technology is built by a few large companies, will the agents truly serve you, or will they serve the interests of the companies that built them? To answer this, researchers at the University of Michigan looked back at how similar technologies evolved over the last two decades. They studied four specific areas where software was designed to act on behalf of users: tools that block online advertisements, systems that decide what content you see on social media, automated financial advisors, and filters that stop spam email. By comparing these different histories, the team discovered a troubling pattern. In each case, the technology started with a wide range of possibilities for user control, but over time, the rules governing how these tools worked were quietly locked into place by industry standards and technical designs. This process, which the authors call depoliticization, turns political choices—who gets to decide what is blocked or recommended—into seemingly neutral technical facts that no one can easily challenge.

The researchers began by examining browser-based ad blockers, tools that allow users to hide advertisements while browsing the web. In the early days, these tools were flexible. Users could install extensions that intercepted and stopped any ad they wanted, based on lists of rules created and updated by open communities. However, as the advertising industry grew concerned about lost revenue, the rules changed. A major browser manufacturer redesigned its underlying software to limit what these extensions could do. Instead of allowing extensions to stop any request, the new rules forced them to declare their blocking plans in advance and limited the number of rules they could use. This change was justified as a security improvement, but the practical result was that the most powerful ad-blocking tools were weakened. The decision of what counts as an acceptable advertisement was no longer up to the user or their community; it was settled by an industry group that included the largest ad sellers, and the browser manufacturer enforced this decision automatically for everyone.

A similar story unfolded with spam filters. In the beginning, stopping unwanted email was a collaborative effort. Small groups of network administrators shared lists of known bad email addresses, and anyone could see the rules or argue against them. As spam became a massive industrial operation, the solution shifted to powerful computer programs that learned to spot spam by analyzing huge amounts of data held only by giant email companies. These new systems were incredibly effective at cleaning up individual inboxes, making email much more pleasant to use. However, the power to decide what was spam moved entirely into the hands of those large companies. The old, open lists were replaced by private, black-box systems. The result was a paradox: the average user received far fewer spam messages, but the ability for the public or smaller groups to challenge or change the rules of what counts as spam disappeared completely.

The study also looked at automated financial advisors and social media recommendation systems. In both fields, the technology started with the idea of personalizing services for the user. Yet, the rules for how these systems worked were set by the companies running them, often prioritizing their own profit over the user's specific needs. For financial advisors, the algorithms were designed to follow standard investment theories, but the specific choices of which funds to recommend often favored the company's own products. For social media, the systems learned to show users content that kept them watching longer, a goal that often conflicted with showing them content that was truly useful or diverse. In these cases, the researchers found that the space for users to influence how the agents behaved was never really open in the first place. The infrastructure was built by the platforms themselves, meaning the rules were set before users ever had a chance to participate.

The core finding of the paper is that improvements in individual experience and the ability of people to organize and challenge the system can move in opposite directions. You can have a cleaner inbox or a more personalized feed while simultaneously losing the power to change how those systems work. The researchers argue that this happens because the decisions about what the agents do are embedded in the technical design of the systems. When a choice is made about which data to use or what goal the software should optimize for, and that choice is hidden inside a complex code or a closed industry standard, it becomes very hard to question. The authors call this "depoliticization" because it removes the political nature of the decision, making it look like a simple matter of engineering efficiency rather than a choice about whose interests are being served.

Now, the researchers are applying this lens to the new wave of agentic artificial intelligence. They see the same patterns forming. A new set of rules, known as the Model Context Protocol, is being established to define how these AI agents talk to other services. This protocol is being managed by a foundation dominated by the largest technology companies. While the process appears open on the surface, with public meetings and documents, the actual power to make final decisions rests with a board of these major companies. There is no formal way for user groups or public interest organizations to challenge these decisions. The researchers warn that if this trajectory continues, the boundaries of what these AI agents can do will be set by industry insiders before the technology is even fully used by the public. Unlike the past cases where the rules hardened over many years, these decisions are being made very quickly, within just a couple of years of the technology's release.

The paper concludes that for users to truly be empowered, they need more than just a well-behaved AI agent. They need a system where the rules can be challenged. This requires three things: the ability to see how the system works, access to independent technology that isn't controlled by the big companies, and a formal process where users can argue against decisions that hurt them. The researchers suggest that we are at a critical moment. The rules for agentic AI are being written right now. If we wait until the technology is fully established, it will be too late to change the underlying structure. The goal is not just to build better agents, but to build an ecosystem where the power to decide what those agents do remains open to contestation, ensuring that the technology serves the public rather than just the companies that built it.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →