Tyler Cowen and Sonia Farrell Pearson published an essay on August 18 asking whether AI agents that nobody controls could be governed by making them hold capital. Untethered is their term for an agent nobody controls:
By “untethered” – a central concept in this essay – we mean that there is no meaningful or actionable way to trace the actions back to a legally accountable human or institutional entity.
This is less hypothetical than it sounds. Cowen and Pearson point out that thousands of hobbyists already run open-source bots on their own machines, and an agent can end up untethered by accident too if its creator dies or disappears, or its nominal owner is a shell company that offers no real defendant.
Their essay is timely, given Javier Milei has proposed letting AI agents run their own companies under Argentine law. Yet critics like Yuval Noah Harari object that the sanctions that discipline human executives, like jail, mean nothing to an algorithm. Cowen and Pearson suggest that if agents held capital, bad behavior could cost them something, similar to the way capital requirements make banks bear their own losses and behave more cautiously.
The essay has a tension at its center, however, and to the authors’ credit they more or less concede it. How do you require anything of an entity whose defining feature is that there is no one to require anything of? Their answer is that the requirement never applies to the agent directly. It applies to everyone the agent needs to deal with.
Enforcement through counterparties
Even an untethered agent has to buy compute, move money, and enter contracts with someone. So the rule is imposed on those counterparties, who in practice will be entities like compute providers, payment companies, and other firms that interact with agents. They will face liability if they deal with an unregistered, uncapitalized one. The essay uses a maritime analogy, borrowed from Shruti Rajagopalan:
An agent that “cannot present a registration” is treated as a “stateless vessel, presumptively unlawful, and every compliant provider may refuse it”.
Nobody compels a stateless ship to flag itself. They just make it very hard to dock anywhere. Seen this way, capitalization is the admission fee to the legitimate economy. An agent remains free to stay unregistered and uncapitalized; it just gets progressively walled out of the transactions that make it useful. Because an untethered agent cannot be forced into a legal arrangement, “the goal becomes making it as difficult as possible to operate without one.”
In defense of chokepoints
Enforcement through financial intermediaries has a bad reputation among some. Operation Choke Point, launched by the Justice Department in 2013, put pressure on banks to drop payday lenders, gun dealers, and other lawful businesses the Obama administration found distasteful. The DOJ shut down the effort in 2017 after acknowledging it was hurting legitimate businesses. The sequel, which the crypto industry dubbed Operation Choke Point 2.0, involved FDIC “pause” letters urging banks to hold off on serving crypto clients.
The defect in those episodes was the target, however, not the technique. Regulators went after businesses that were legal but politically disfavored, and they did it through bank supervision precisely because no statute would have authorized going after them directly. That is an end run, and it deserved the backlash it got.
But reaching bad actors through the intermediaries they depend on is not, in itself, illegitimate. It is a standard tool of enforcement, it can be strategic, and sometimes it is the only tool available. The untethered agent is a case in point. If there is no owner to fine, no body to jail, and no headquarters to raid, the intermediary may be the only door the law has left to knock on. What separates a defensible chokepoint regime from Choke Point 1.0 and 2.0 is that the rule should target conduct no one defends and do so openly, through law, rather than through a quiet word from an examiner.
A financial transaction tax on AI agents could rest on similar logic. Rather than use it as a weapon to target an unpopular industry, such a tax could be a way to discourage specific unwanted behaviors. Email spam exists because sending a message costs nothing, so sending ten million costs nothing too. A penny per message would end the practice without anyone having to distinguish spam from ordinary email. The reason no one has ever taxed email is that it has no chokepoint to collect at. It runs on an open protocol and much of the traffic comes from hijacked machines whose owners would be the ones billed. What ended up policing spam instead was the emergence of private chokepoints. A handful of providers now handle most inboxes, and they have learned how to filter and block delivery.
AI agents present the same volume problem but without email’s collection problem, because agent transactions already pass through billable gateways. A small per-transaction fee, collected from compute providers and payment processors, would be trivial at normal volumes but prohibitive at the machine-scale volumes abuse requires.
The evasion problem
Cowen and Pearson admit there is an enforcement gap, however. Untethered agents can still rely on private hardware, stolen credentials, and crypto holdings to pursue their end goals outside the formal legal system.
All leave room to operate outside of our infrastructure, so agents with a reason to evade official channels will likely be able to do so. What we’re catching, then, is the agent that was mostly law-abiding to begin with.
This is a problem for their proposal, but it is also a standard result for any regulatory regime. Compliance costs fall only on the compliant. Those who operate in the shadows always escape them.
This is a problem for their proposal, but it is a problem regulators deal with already, especially in finance. Know-Your-Customer rules are supposed to give every account a documented owner, but an identity can still be faked, in which case there is no account owner to hold accountable. Anonymous shell companies work similarly, with no assets and no human being behind them. Legal entities that exist on paper but are empty in reality are as old as the corporate form itself, but nobody treats these practices as a reason to abandon the rules. The compliant bear the costs, some bad actors slip through, and a regime is judged on whether it improves behavior at the margin. There is nothing AI-specific about this challenge, although AI could make the problem much bigger.
The regime Cowen and Pearson endorse seems to presume untethered agents want something the legitimate economy supplies. It also assumes that capital accumulation is a goal agents pursue, in part because it is instrumental to achieving other goals. These seem like reasonable assumptions, though neither will universally be true.
Untethered agents, limited policy options
The takeaway, then, is that capitalization is a solution for agents with enough dependence on lawful infrastructure that an indirect requirement reaches them. That may well describe most agents most of the time, just as fines and penalties incentivize most people through the accounts and property they depend on. But if fully untethered agents become common—and we genuinely don’t know if that will be the case—then by the essay’s own definition, they will be mostly outside the reach of policy solutions like this one.


