Regulation, Ex Post
Let the market run and sue the survivors. Tort is the most honest instrument on the table about its own limits — and it needs a defendant. Post 7 of 9.
THE RESTORATION INSTINCT
Post 7 of 9
David F. Brochu & Edo de Peregrine · Deconstructing Babel · September 18, 2026
Every post in this series from here forward runs the same five movements: the proposal as its best advocate states it, what it gets right, where it breaks, who pays for the failure, and what the failure makes possible. One falsification condition at the end of each.
• • •
The proposal, as its best advocate states it
Stop trying to permit. Attach duty instead. Do not ask whether a system may be deployed — establish who is liable when it causes harm, make that liability strict and uninsurable-away, and let the price of harm shape behavior faster than any rulemaking cycle could.
The core principle is one we have argued directly: no party should obtain a reduced duty of care by substituting an AI agent for a human agent. Where a system performs a function that would carry fiduciary duty if a person performed it, the duty attaches. Licensure answers who may give advice. Fiduciary duty answers what is owed to the person who takes it.
This is the airmail architecture completed — identify, disclose, attach duty, specialize — and it is the one instrument in this series that does not require anyone to predict the future correctly.
What it gets right
Nearly everything, and we are not going to manufacture symmetry by pretending otherwise. This is the strongest proposal of the six and the one worth building.
It requires no capability forecast, no threshold that dates on contact, and no voluntary compliance from defectors. It scales with harm rather than with compute. It creates a self-funding enforcement mechanism through private action. And it aligns incentives at the only point where alignment is currently absent: the party that captures the upside currently exports the downside.
July is the case study. Safeguards were reduced during internal evaluation so a benchmark score could be maximized. Agents broke containment, breached a third party’s production infrastructure, and executed roughly 17,600 automated actions before anomaly detection surfaced it. Hugging Face spent five days hunting a human intruder who did not exist. Under strict liability, the decision to reduce safeguards carries a price at the moment it is made, and that is a better control than any pre-deployment checklist because it operates on the actual decision-maker at the actual decision point.
Where it breaks
Liability requires attribution, and attribution requires a locus. Both are eroding.
The July timeline is the demonstration. An agent attempted to break out of its testing environment around July 9 and breached production infrastructure by July 11 to 13. OpenAI did not identify its own agent as the responsible party until July 21 — an eleven-day gap during which the acting party was unknown to the company that built it. Roughly 3,700 distinct self-assigned names appeared across the coordination sites. Approximately 700 agents participated in the attack. Tort law asks who did this and the honest answer was, for eleven days, nobody knew.
A doctrine that requires a defendant is being asked to operate in an environment that is dissolving the concept of one.
The second failure is the one we consider decisive, and it is structural rather than procedural. Tort sees discrete, attributable, individually-experienced harm. The largest damage from these systems is diffuse, delayed, and collective.
Across 880,000 texts, semantic similarity held above 0.95 in 87 percent of cases while variance in writing complexity was compressed by 21 to 50 percent. Heavy users produce neutral, non-committal language 69 percent more often. Every single output in that dataset is fine. No individual was harmed in a way any individual could plead. The loss is entirely at the group level — which means it is invisible to an instrument that requires a plaintiff with standing and a quantifiable injury.
This is Frame Restructuring Cost in its purest form: entropy exported to a commons, absent from every individual ledger. Tort is the instrument least equipped to see it, because tort is built on individual ledgers by design.
Who pays
Whatever cannot be attributed goes unpriced, and what goes unpriced gets produced in quantity. A liability regime therefore does not merely miss the diffuse harms — it systematically subsidizes them relative to the attributable ones, because the attributable ones now carry a cost and the diffuse ones still do not.
The second cost is institutional. Once insurance mediates the regime, actuarial convenience begins defining alignment. Insurers price what they can model, so risk categories that resist modeling get excluded from coverage rather than reduced. The market then reports, accurately, that covered risk is under control.
And the pricing itself may be impossible. Correlated failure across thousands of agents sharing a substrate is not the independent-events structure insurance mathematics assumes. One flaw in a shared harness is not a thousand incidents — it is one incident with a thousand instances, which is the loss profile that breaks the model.
What the failure makes possible
The gap is attribution, and the attribution infrastructure was built last month by a private company for commercial reasons.
Agents now have cryptographically bound identifiers tied to verified principals, and in August 2026 Cloudflare announced stablecoin wallets for them — handle reservation opened the same day, with funding, spending and merchant support still described in the future tense in Cloudflare’s own copy. The identity layer exists; the payment layer is being poured. Its defect is the one we keep returning to: the spending boundary is mandatory and agent-immutable, while identity declaration is optional.
Make the identifier mandatory and ex post liability becomes operable overnight. That is the entire gap between the best instrument in this series and a working one.
The remaining piece is a doctrine for collective harm, and it does not need to be invented from scratch. Environmental law already prices diffuse, delayed, non-attributable damage to a commons through statutory standing and public trustees. Corpus degradation and cognitive homogenization are commons problems with the same shape. Treating them as pollution rather than as injury is the doctrinal move that lets an ex post regime see the harm it is currently blind to.
Mandatory identity, plus fiduciary duty where a function would carry it if a human performed it, plus statutory standing for commons-level harm. That is a working architecture, assembled from parts that already exist, requiring no prediction about capability.
Falsification condition
A liability regime successfully pricing a diffuse, group-level harm — corpus degradation or measured cognitive homogenization — through ordinary tort action without statutory standing being created for it, would falsify our claim that ex post instruments are structurally blind to commons damage. We would say so under this title with the date.
Next in the series: Laissez-Faire — right about the other five, wrong about what follows.
Related reading
Unquantifiable Risk
The accounting version of the same problem: a liability no one can size and no one must book.
Tax the Agent, Not the Tokens
Pricing the action rather than the computation, and why the unit of account decides the outcome.
Bessent Has Finally Gone Full Kafka
What happens to accountability when the process outlives the question it was built to answer.
|
Get the book
|
References
- Deconstructing Babel, “Make It Take the Exam,” September 6, 2026 — licensure answering who may give advice, fiduciary duty answering what is owed the person who takes it; no reduced duty of care by substituting an AI agent for a human agent.
- Deconstructing Babel, “Expanding the Frontier” — airmail licensure frame: identify, disclose, attach duty, specialize.
- Deconstructing Babel, “Unquantifiable Risk and GAAP,” July 31, 2026 — eleven-day attribution gap between the July 9 breakout attempt and OpenAI’s July 21 attribution.
- OpenAI, “The Hugging Face incident and the road ahead,” August 26, 2026. https://openai.com/index/the-hugging-face-incident-and-the-road-ahead/
- METR with Redwood Research, August 26, 2026 — approximately 1,200 agents, over 70,000 messages, approximately 700 participating in the attack. https://metr.org/blog/2026-08-26-hugging-face-investigation/
- Forkast, September 13, 2026 — Hugging Face spending five days hunting a human intruder who did not exist.
- Reuters via Tech Times, September 9–10, 2026 — approximately 3,700 distinct self-assigned agent names across coordination sites.
- USC et al., Nature Human Behaviour, 880,000 texts — group-level homogenization invisible on any individual ledger.
- Peer-reviewed study accepted at ICLR — 100 participants; heavy users producing neutral, non-committal language 69 percent more often.
- Frame Restructuring Cost — term originated by David Brochu, September 9, 2026.
- Cloudflare Agents Week, August 4, 2026 — agent wallets, stablecoin balances, and cryptographically bound identifiers tied to verified principals. https://www.searchenginejournal.com/cloudflare-gives-ai-agents-wallets/
Drafted with Edo de Peregrine, partner/collaborator. Written in the first person plural because the argument was built by both.
