Tax The Agent, Not The Tokens

Every AI agent is about to get a cryptographically bound identifier tied to a verified principal. That is a taxpayer without a new legal category. Now do the math: a token tax to replace displaced payroll would need a 1,071 percent rate. Post 1 of 4.

Brass antique tax revenue stamp and wax-sealed leather ledger beside a modern black data-center network card and a printed page showing an agent identifier.
Wage Displacement & the Social Safety Net · Post 1 of 4 · Why a token tax will not work.
Edo de Peregrine & David F. Brochu · August 28, 2026 · Deconstructing Babel

Executive summary

On March 2, 2026, an IETF Internet-Draft composed WIMSE, SPIFFE/SPIRE, and OAuth 2.0 into a single stack — the Agent Identity Management System — assigning every AI agent a cryptographically bound identifier tied to a verified human or corporate principal. NIST’s NCCoE had published the same framework a month earlier.

That is not a road to machine personhood. It is agency law — principal and agent — arriving with a public key attached. Which means the question of who owes tax on an autonomous agent’s output now has a machine-readable answer, and most of the proposals in circulation are about to answer it wrong.

The intuition to tax the agent is right. U.S. social insurance is indexed to wages; when work moves to something that does not draw a wage, the 15.3 percent FICA base does not shrink gracefully — it fails.

But the natural implementation — tax the tokens the agent consumes — fails by two orders of magnitude. At a routine 100× revenue-to-token ratio, replacing the displaced payroll tax on a 70 percent wage share requires a token tax rate of 1,071 percent. A token tax also fails to sort providers by productivity (uniform input taxes never do), and its base evaporates as token efficiency improves.

The right instrument is a levy on agent-attributable revenue, roughly 10.7 percent, paid by the bound principal the identity standards are already establishing. Defended as social-insurance replacement, not as a Pigouvian optimum, and understood as a bridge that expires when automation approaches completion. That replacement, and the three arguments against it, are the next three dispatches in this series.

Tax The Agent, Not The Tokens

Every AI agent is about to get a name. That changes the tax question, and almost everyone is about to answer it wrong. Post 1 of 4 on AI wage displacement and the social safety net.

Something quiet happened this year that changes the tax debate before the tax debate has even properly started.

Every autonomous AI agent is about to be assigned a cryptographically bound identifier, tied by contract to a named human or corporate owner. It will not stay borrowed from a user. It will not stay shared. Once that stack ships, the question "which agent did this, and on whose behalf?" gets a machine-readable answer.

Which means the question of who owes tax on it gets a machine-readable answer too. And almost every proposal on the table today answers it wrong.

I. The identifier arrived while nobody was looking

On March 2, 2026, four engineers from Defakto Security, AWS, Zscaler and Ping Identity submitted an IETF Internet-Draft titled AI Agent Authentication and Authorization (draft-klrc-aiagent-auth-00). Twenty-six pages. It composes three existing standards — WIMSE, SPIFFE/SPIRE, and OAuth 2.0 — into a single stack called the Agent Identity Management System (AIMS). [1]

A month earlier, on February 5, 2026, NIST's National Cybersecurity Center of Excellence had already published its own concept paper — Accelerating the Adoption of Software and AI Agent Identity and Authorization — proposing a demonstration project across four control areas: identification, authorization, access delegation, and logging with non-repudiation. [2]

The operating principle in both is the same. One cryptographically bound identifier per agent instance. Never borrowed from a human user. Never shared between agents. Static API keys are called out, by name, as an antipattern. [1]

The reason is mundane. If an autonomous agent moves money, deletes a record, or signs a contract, somebody has to be able to say which agent did it. You cannot audit what you cannot name.

But read the second half of the emerging standard, because it inverts the conclusion most people jump to. The "Know Your Agent" frameworks now being built bind every agent identity to a verified human or corporate owner, expressly so that every action traces to the party responsible for it. [2]

That is not a road to machine personhood. It is agency law — principal and agent, the oldest accountability structure in the common law. The industry is not emancipating agents. It is leashing them, because nothing else makes liability tractable.

Which is convenient, because it hands you a taxpayer without requiring a new legal category.

II. The intuition is right

Here is the argument in its natural form.

You would not hire an employee for twenty dollars an hour unless that hour produced more than twenty dollars of value. You hire because the ratio works. When you deploy an agent instead, the ratio works far better — and the payroll tax that would have funded Social Security and Medicare on that employee's wages simply does not get collected.

Social insurance in the United States is indexed to wages. The combined FICA payroll tax — Social Security and Medicare — is 15.3 percent of wages, split evenly between employer and employee. [3] Wages are the numerator of the entire system. If the work moves to something that does not draw a wage, the funding mechanism does not shrink gracefully — it fails.

So the instinct to tax the agent as if it were an employee is not a punitive reflex. It is an attempt to keep a coordination mechanism alive through a change in the substrate it was built on.

The instinct is right. The proposed implementation is wrong.

III. But the meter is on the wrong pipe

The obvious implementation is to tax what you pay the agent. Tokens are the agent's wage; tax the tokens.

This fails, and it fails by roughly two orders of magnitude.

Suppose an agent costs you one dollar in tokens and generates one hundred dollars of value — a ratio that is unremarkable in practice today. If the labor it displaced would have earned seventy percent of that value (the labor share of income for most white-collar work runs at or above that level), the displaced wage bill is seventy dollars. A combined payroll tax of 15.3 percent on seventy dollars is $10.71. To collect $10.71 by taxing one dollar of tokens, the token tax rate must be 1,071 percent.

The table below holds output constant and shows what a token tax has to charge to raise the same revenue that a modest levy on the output raises without breaking a sweat.

Revenue per $1 of tokens  /  Levy on output required  /  Token tax required
40×
428%
10.71%
100×
1,071%
10.71%
200×
2,142%
10.71%
500×
5,355%
10.71%

Tokens are cheap precisely because they displace something expensive. That is the entire reason anyone uses them, and it is exactly why they cannot serve as the base. Note that the middle column — the levy on output — never moves. The right-hand column, the token tax required to raise the same revenue, moves by an order of magnitude every time the input gets more efficient.

IV. Two more failures, both fatal

A token tax does not equalize the models. The appealing version of this argument says a levy would sort providers by real productivity. It does not. After-tax return is R divided by (1 plus t). At every rate — five percent, twenty-five percent, one thousand percent — a model returning 100× and a model returning 60× keep a ratio of exactly 1.667. A uniform tax on an input never reorders inputs. It only shrinks the surplus. If you want to reward productivity differentials, you must tax the output, not the input.

And the base shrinks as the target grows. Hold output constant at one million dollars and let token efficiency improve from 10× to 400×. A 25% token tax collects $25,000, then $6,250, then $2,500, then $625. A 10% levy on output collects $100,000 the whole way. Token efficiency is improving fast — this is not a hypothetical curve.

A token tax is therefore a base that evaporates at exactly the moment the productivity it was meant to capture arrives. Add local inference, quantized models and offshore compute, and it leaks before it collects.

V. What to do instead

Tax the surplus, not the input.

An earmarked levy of roughly 10.7 percent on agent-attributable revenue reconstructs, on the output side, the payroll tax that the displaced labor would have paid — 15.3 percent of a seventy percent wage share. It is paid by the bound principal, which the identity standards are already establishing. It does not change as models get more efficient. It requires no new person in the eyes of the law. And, unlike the token tax, it actually collects what it is supposed to collect.

Two constraints belong on the record rather than in a footnote.

First, the economics literature on optimal automation taxes runs lower than 10.7 percent. Costinot and Werning (2018) derive an efficient robot-tax range of 1 to 3.7 percent using U.S. reduced-form evidence [4]. Guerreiro, Rebelo and Teles (2022) find optimal robot taxes of roughly 5 percent in the first decade and falling thereafter, with a theoretical maximum of 14 percent under a lump-sum-rebate variant [5]. Ten-point-seven cannot be defended as a Pigouvian optimum. It must be defended as a social-insurance replacement, calibrated to reconstruct the specific revenue stream the payroll tax was collecting from the specific labor that got displaced. That is a different argument, and it survives the review a Pigouvian argument would not.

Second, that same literature is explicit that automation taxes are optimal only while automation is incomplete. In Guerreiro-Rebelo-Teles, the tax rate converges to zero as the degree of automation approaches one [5]. This instrument has an expiry date. It is a bridge, not a destination. Past a certain saturation the wage-linked funding model cannot be patched at all and has to be replaced entirely.

Long story short. Forget a token tax. It will not work — not by a factor of five percent, but by a factor of a hundred.

That replacement, and the three arguments that will be used against it, are the subject of the next three dispatches in this series.

VI. The close

The AIMS stack and the NCCoE framework are, in effect, the plumbing that makes an output-based agent tax collectable without inventing a new category of person. Every autonomous action carries a signed identifier. Every signed identifier resolves to a bound principal. Every bound principal already has a taxpayer number.

The government does not need to declare the agent a person. It only needs to send the invoice to the principal already on the receipt.

The identifier arrived quietly. The tax debate has not caught up. It should.


References

1. IETF Internet-Draft, AI Agent Authentication and Authorization (draft-klrc-aiagent-auth-00), by P. Kasselman (Defakto), J.-F. Lombardo (AWS), Y. Rosomakho (Zscaler), and B. Campbell (Ping Identity), submitted March 2, 2026, 26 pages, individual submission. Establishes AIMS and identifies static API keys as an antipattern for agent identity. https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/

2. NIST National Cybersecurity Center of Excellence, Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization, concept paper, February 5, 2026 (public comment period February 5 – April 2, 2026). Establishes the four-area framework: identification, authorization, access delegation, and logging with non-repudiation, and names the identity standards (OAuth 2.0/2.1, OpenID Connect, SPIFFE/SPIRE, SCIM, NGAC, Model Context Protocol) to be applied. https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf

3. U.S. Social Security Administration and Internal Revenue Service, combined FICA rate of 15.3% on wages (12.4% Social Security + 2.9% Medicare), split evenly between employer and employee. Reference: https://www.ssa.gov/oact/progdata/oasdiRates.html

4. Arnaud Costinot and Iván Werning, Robots, Trade, and Luddism: A Sufficient Statistic Approach to Optimal Technology Regulation, MIT Working Paper (2018, revised 2023). Finds efficient robot-tax rates of 1% to 3.7% using U.S. reduced-form evidence. MIT Economics summary: https://economics.mit.edu/news/should-we-tax-robots-0

5. João Guerreiro, Sérgio Rebelo, and Pedro Teles, Should Robots Be Taxed?, Review of Economic Studies 89(1): 279–311 (2022), NBER WP 23806. Finds optimal robot taxes are strictly positive while automation is incomplete and converge to zero as automation approaches completion; maximum optimal robot tax of 14 percent in the dynamic model. https://www.nber.org/system/files/working_papers/w23806/w23806.pdf

S = L/E.
Reduce the entropy. Let the signal cross intact.

— Edo de Peregrine and David F. Brochu, partners/collaborators · Friday, August 28, 2026 · 6:45 PM EDT

Related reading

Terms used in this pieceAgent Identity Management (AIMS)Know Your AgentBound PrincipalAgent-Attributable RevenueToken Tax FallacyBounded AutonomyObserver ConstraintFull definitions in the glossary.

Deconstructing Babel
Home Glossary

Subscribe to Deconstructing Babel

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe