{"id":"1998719f-00d2-4f1a-8ff7-3340885027e6","arxiv_id":"2501.10114","paper_version":3,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"The paper introduces 'agent infrastructure', a three-part framework (attribution, interaction shaping, and response) for governing ecosystems of AI agents.","lead":"This paper proposes that safely managing AI agents will require shared infrastructure, such as identity systems, communication protocols, and rollback tools, outside the agents themselves. It offers a research agenda for building that infrastructure, rather than relying only on training agents to behave better.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Agent infrastructure's 'indispensable' claim rests on an unproven premise that agent ecosystems will be open and multi-party; if platforms remain vertically integrated, shared external protocols are optional, and the paper's own adoption analysis offers no mechanism to overcome network effects.","rationale":"The reader's weakest_assumption is adoption: external infrastructure only works if others recognize and use it. I agree that this is a genuine weak point, and the paper itself acknowledges it in Section 6.1. My concern extends that line: the indispensability claim also presupposes an open, multi-party ecosystem. If agents remain inside vertically integrated platforms, the same functions could be performed by platform-internal systems, so shared external protocols would not be indispensable. This is a distinct and arguably more fundamental assumption, although closely related to adoption. The paper is a well-structured conceptual contribution, honestly flags limitations, and does not overclaim in its body relative to its position-paper genre. The taxonomy is useful and the research questions are valuable. The soft spot is specifically the abstract's 'similarly indispensable' language, which is not supported by the argument or evidence. Because the paper is explicitly a research agenda rather than an empirical study, accepting it with its caveats is reasonable. I recommend UNCHANGED, with the understanding that the headline claim should be read as a motivated hypothesis, not an established result.","tokens_in":25478,"tokens_out":8519,"duration_ms":95237,"concrete_test":"Trace two or three currently deployed agent workflows (e.g., an OpenAI Operator purchase, a Google A2A inter-agent task, and a Microsoft Copilot workflow) end-to-end, and classify each mediation point as (a) platform-internal, (b) a pre-existing internet protocol, or (c) a new agent-specific shared protocol. If the share of (c) is empty or optional for the paper's three functions, the 'similarly indispensable' claim for shared external protocols is unsupported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The abstract and Section 1 make a strong forward-looking claim: agent infrastructure will be 'similarly indispensable' to agent ecosystems as HTTPS and TCP are to the Internet. That claim requires two premises: (i) the future agent ecosystem will be open and multi-party, so that shared external protocols are necessary; and (ii) the relevant actors will coordinate to adopt those protocols. The paper does not defend (i). It asserts that 'heterogeneous agents will interact with each other and other actors,' but current deployments are platform-centric (OpenAI Operator, Google A2A, Microsoft Copilot), and a vertically integrated provider could implement every function in Table 1 internally, making shared external protocols optional. On (ii), Sections 6.1–6.3 document network effects, incompatible systems, and lock-in, citing BGP/RPKI as a cautionary tale, but they propose no incentive or governance mechanism that would actually overcome the collective-action problem. Historical analogies such as DNSSEC and RPKI show that even security-critical, technically superior protocols can remain partially adopted for decades. Thus, the strongest claim in the paper is a plausible conjecture rather than a supported conclusion: the paper does not establish that the required coordination will occur, nor that closed-platform substitutes cannot serve the same functions.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper proposes a new concept, 'agent infrastructure': technical systems and shared protocols external to AI agents that mediate and influence agents' interactions with their environments. It argues that such infrastructure will be as indispensable to future agent ecosystems as protocols like HTTPS and TCP are to the Internet, and it identifies three functions: attribution, interaction, and response. The paper catalogs nine research directions under these functions (identity binding, certification, agent IDs, agent channels, oversight layers, inter-agent communication, commitment devices, incident reporting, and rollbacks), each with use cases, adoption considerations, limitations, and open questions. It also discusses cross-cutting challenges including adoption dynamics, lack of interoperability, and lock-in. The paper is a position paper; it contains no new empirical data or formal derivation.","tokens_in":25733,"tokens_out":5737,"duration_ms":58938,"significance":"The paper's main contribution is a useful synthesis: it gathers diverse proposals for agent governance and safety into a single taxonomy and connects them to institutional and adoption concerns. If agent ecosystems become open and multi-party, this framework could genuinely structure both research and policy, and Table 1 provides a clear starting point for that agenda. The paper is careful to hedge within individual sections and to acknowledge that the catalog is incomplete, which is appropriate for a position paper. However, the central 'indispensable' claim is a forward-looking conjecture that rests on assumptions about open, decentralized agent ecosystems that are not defended; the paper's own adoption analysis highlights how fragile such assumptions are. The most defensible version of the claim is conditional: if agents operate across many organizations and actors, then external infrastructure will be needed for accountability, coordination, and incident response. As a piece of agenda-setting conceptual work, the paper is strong; as a proof of inevitability, it is not.","major_comments":[{"comment":"The central claim that agent infrastructure 'will be similarly indispensable' is stronger than the evidence presented in the paper. In Section 1 the authors say only that infrastructure 'will likely be crucial,' and Sections 6.1-6.3 document network effects, lack of interoperability, and lock-in without proposing a concrete governance or incentive mechanism that would overcome the collective-action problem. The claim also presupposes an open, multi-party agent ecosystem; if agents remain mostly on vertically integrated platforms (as current deployments from major vendors suggest), a single provider could implement the Table 1 functions internally and shared external protocols would be optional. The paper should either weaken the abstract to a conditional claim or supply a substantive argument and evidence that open, multi-party adoption will actually occur; its own BGP/RPKI example in Section 6.3 shows that even security-critical protocols can remain partially adopted for decades.","section":"Abstract; Section 1; Section 6"},{"comment":"The definition of agent infrastructure as 'external to agents' and explicitly 'not system-level interventions' is not applied consistently. Oversight layers (Section 4.2) are described as a monitoring system plus an interface for intervention, which could be embedded in the agent's own control loop; rollbacks (Section 5.2) are illustrated with Patil et al.'s LM runtime, which operates on the agent's internal state and could reverse the agent's actions. If these count as infrastructure, then 'external' cannot mean outside the agent's software; if they do not count, then Table 1 includes non-infrastructure items. The authors should clarify whether 'external' is defined relative to the model weights, relative to the agent's scaffolding/runtime, or relative to the agent's decision-making process, and adjust the examples and the definition accordingly.","section":"Section 2.1; Section 4.2; Section 5.2"}],"minor_comments":[{"comment":"The sentence 'agents could soon become capable of interacting with with human interfaces' contains a duplicated 'with' and should be corrected.","section":"Section 4.1"},{"comment":"'Google is collaborating with the number of large enterprises' should read 'with a number of large enterprises'.","section":"Section 4.3"},{"comment":"The statement 'Adoption of the Border Gateway Protocol (BGP) ... ran into similar problems' is imprecise: BGP itself is almost universally deployed, whereas the slow-adoption example is RPKI, the verifiable variant. Please rephrase to avoid conflating the protocol with its security extension.","section":"Section 6.3"},{"comment":"The name 'TrustARC (formerly TRUSTe)' appears as 'TrustARC' throughout the discussion; this should be consistent, and 'Analagously' should be 'Analogously'.","section":"Section 3.2"},{"comment":"The phrase 'existing incident report systems in other countries' appears to be a leftover or misphrasing; the surrounding discussion is about different domains and reporting mechanisms, not countries.","section":"Section 5.1"},{"comment":"The abstract's 'similarly indispensable' is stronger than the body's 'will likely be crucial'; unless the claim is defended, these should be harmonized.","section":"Abstract; Section 1"}],"recommendation":"major_revision","confidential_remarks":"The paper is a position piece with no testable hypotheses or formal results, so its fit depends on whether the venue values forward-looking conceptual taxonomies in AI governance. There is substantial overlap with the authors' earlier work, especially Chan et al. (2024a,b) for agent IDs and visibility, and Hammond et al. (2025) for multi-agent risks; Section 7 and Section 3.3 draw directly on these. I do not see a circularity problem because the framework is defined independently, but the authors should ensure the new taxonomy is sufficiently distinct from these prior papers and add a sentence explaining the incremental contribution. The two major comments above are fixable through precise reframing and definitional clarification; the central idea is worth publishing once these are addressed."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper is worth a serious read. It does something useful: it names a class of interventions—technical systems and protocols external to agents that shape how agents interact with the world—and organizes them under three functions: attribution, interaction, and response. The taxonomy is new as a synthesis, even though the components (agent IDs, certification, agent channels, rollbacks) each come from somewhere else. The authors map those components into a coherent agenda, with per-item analysis of use cases, adoption, limitations, and open questions. That is real value for governance researchers and for builders who want a checklist of where to intervene outside the model itself.\n\nThe paper is also honest. Sections 6.1–6.3 flag adoption, interoperability, and lock-in as serious barriers, and the BGP/RPKI example is well chosen. The body is appropriately hedged: it says infrastructure will likely be important, that it can help, that the catalog is incomplete. I give credit for that.\n\nThe soft spot is the abstract and Section 1. \"Similarly indispensable to ecosystems of agents\" is stronger than anything the body establishes. The stress-test note is right: the claim depends on the future agent ecosystem being open and multi-party, so that shared external protocols are necessary. But a vertically integrated provider (OpenAI, Google, Microsoft) could implement every function in Table 1 internally—IDs, oversight, communication between its own agents—without any shared protocol. The paper documents network effects and lock-in but offers no mechanism that would overcome them; it gives examples of coordination failures, not successes. So the indispensable claim is a plausible conjecture, not a supported conclusion. That is a mismatch between abstract and body, and it should be fixed. It is not a load-bearing flaw in the taxonomy itself. The framework is still useful if adoption is partial, contested, and uneven—which is the more likely world.\n\nThe citation pattern is fine. There is heavy self-citation, but the cited papers are genuinely prior work on IDs and visibility, and the new framework is not defined in terms of them. The paper is a position piece, so no data or formal proof is expected; the internal argument is coherent.\n\nWho should read it: AI governance folks, standards people, and anyone thinking about how to influence agents after deployment. It would make a good reading-group discussion. It deserves peer review—a journal with a governance or FAccT-style audience should send it out. My recommendation: accept after the authors align the abstract with the body and give a paragraph to the closed-platform alternative.","headline":"Useful conceptual synthesis and research agenda for external agent infrastructure, with an abstract that overstates the inevitability of adoption; the framework survives the overreach.","tokens_in":679,"tokens_out":2611,"would_cite":true,"duration_ms":34272,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"External protocols and identity systems, not just model training, will be what makes AI agents safe and useful, this paper argues.","keywords":["AI agents","agent infrastructure","identity binding","agent certification","inter-agent communication","rollback mechanisms","AI governance","protocols"],"falsifier":"A concrete falsifier: if a large ecosystem of heterogeneous, independently deployed agents provably coordinates and stays safe without any shared identity, communication, or rollback protocol—relying only on model-level training—then the paper's central claim fails. A more modest check: after several years, if no inter-agent communication protocol has reached meaningful adoption across independent developers while agent use grows, the 'indispensable' claim is undercut.","tokens_in":25304,"feed_emoji":"🏗️","tokens_out":5810,"duration_ms":56090,"temperature":0.7,"pith_summary":"This paper tries to establish that safe, useful AI agents will require external infrastructure, not just better models. It defines agent infrastructure as technical systems and shared protocols outside agents that shape how agents interact with the world, and argues these systems will be as central to agent ecosystems as HTTPS and TCP are to the Internet. The paper identifies three functions for such infrastructure—attribution, interaction, and response—and catalogs concrete research directions for each, from identity binding and agent IDs to communication protocols and rollback tools. A sympathetic reader would care because the claim redirects attention from model-level training alone toward the protocols, standards, and institutions that surround agents.","feed_headline":"AI agent safety hinges on external protocols, paper argues","feed_subtitle":"Identity, communication, and rollback systems around agents could decide whether AI helpers help or harm.","key_machinery":"The central object is the concept of agent infrastructure itself, defined as technical systems and shared protocols external to agents that are designed to mediate and influence agents' interactions with and impacts on their environments. The paper's analytic machinery is a three-function taxonomy—attribution, interaction, response—paired with an analogy: just as HTTPS, TCP, and BGP enable the Internet, external protocols and systems will enable agent ecosystems. A companion unit is the agent instance, an instantiation of a model with a user, interaction history, and tools, which gives IDs and certification something to attach to. The taxonomy does the work of turning a broad intuition into eight concrete research directions, each with a use case, an adoption path, and stated limitations.","core_discovery":"The paper's central claim is that making AI agents useful and safe will require more than directly training or prompting the models: it will require agent infrastructure—technical systems and shared protocols external to agents that mediate and influence how agents interact with their environments. The paper argues this infrastructure will be as indispensable to ecosystems of agents as HTTPS and TCP are to the Internet, and organizes it under three functions: attribution, which binds actions and properties to agents or legal actors; interaction, which shapes how agents encounter services and one another; and response, which detects and remedies harm. It then catalogs eight research directions, from identity binding, certification, and agent IDs to agent channels, oversight layers, inter-agent communication, commitment devices, incident reporting, and rollbacks. Alongside each direction the paper analyzes use cases, adoption dynamics, limitations, and open questions, and it takes no stance on which pieces should be prioritized.","pith_inferences":["Beyond the paper, the taxonomy suggests a market-failure prediction: because most agent infrastructure is a coordination good, purely private provision will likely underproduce it, and agent ecosystems may fragment into incompatible standards unless a public body or a dominant platform coordinates.","A testable extension would compare agent marketplaces that require identity binding or IDs against those that do not, measuring rates of fraud, spam, and contested transactions.","The paper's rollback and oversight ideas imply a natural experiment: platforms offering reversible agent transactions versus irreversible ones, and whether reversibility changes user willingness to delegate consequential actions.","If private actors build the infrastructure, design choices around identity could concentrate power in identity providers; the paper notes the privacy risks but does not develop this political-economy implication."],"forward_implications":["If agent infrastructure is indispensable, safety work on agents must include protocols and systems that surround agents, not just training, fine-tuning, and prompting.","Attribution tools such as identity binding and agent IDs would give counterparties a way to seek recourse, which could make agents more widely trusted in commerce and services.","Agent channels and oversight layers would give operators a way to contain incidents, for example by suspending agent traffic during a worm outbreak.","Because communication protocols and IDs depend on network effects, early choices by large platforms could lock in standards that are hard to revise, as happened with BGP.","Governments and standards bodies would need to participate early if agent infrastructure is to be interoperable and updatable."],"supporting_citations":[{"why":"TCP is cited as foundational Internet infrastructure whose indispensability the paper wants to replicate for agents.","marker":"Eddy, 2022"},{"why":"HTTPS is the central analogy for how external protocols unlock trusted e-commerce, the model for agent infrastructure.","marker":"Fielding et al., 2022"},{"why":"BGP provides the key analogy for indispensable infrastructure and supplies the lock-in example in Section 6.3.","marker":"Rekhter et al., 2006"},{"why":"Source of the agent ID concept and its cryptographic requirements, a load-bearing piece of the attribution function.","marker":"Chan et al., 2024b"},{"why":"Existing inter-agent communication protocol that grounds the interaction function and adoption analysis.","marker":"Marro et al., 2024"},{"why":"Defines adaptation interventions, the broader class that agent infrastructure is claimed to be a subset of.","marker":"Bernardi et al., 2024"},{"why":"Real-world inter-agent protocol adoption example used to discuss network effects and coordination barriers.","marker":"Surapaneni et al., 2025"},{"why":"Runtime allowing state reversal, the concrete example behind the rollback function.","marker":"Patil et al., 2024"}],"fun_headline_variants":["Agent infrastructure: the missing layer for safe AI agents","AI agents need HTTPS-style protocols to stay safe","Attribution, shaping, response: three pillars of agent infrastructure","External systems, not just training, will make agents reliable","Agent safety hinges on shared protocols, not model tweaks"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The argument rests on enough independent parties choosing to adopt the same external identity, communication, and response systems; the paper itself notes that without such coordination, individual tools remain useful but the 'indispensable' claim does not follow.","fun_headline_variants_meta":{"raw":{"variants":["Agent infrastructure: the missing layer for safe AI agents","AI agents need HTTPS-style protocols to stay safe","Attribution, shaping, response: three pillars of agent infrastructure","External systems, not just training, will make agents reliable","Agent safety hinges on shared protocols, not model tweaks"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000177,"raw_usage":{"total_tokens":1318,"prompt_tokens":992,"completion_tokens":326,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":608,"completion_tokens_details":{"reasoning_tokens":247}},"tokens_in":608,"tokens_out":326,"duration_ms":3475,"temperature":1.0,"reasoning_tokens":247,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T19:22:27.477884+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete falsifier: if a large ecosystem of heterogeneous, independently deployed agents provably coordinates and stays safe without any shared identity, communication, or rollback protocol—relying only on model-level training—then the paper's central claim fails. A more modest check: after several years, if no inter-agent communication protocol has reached meaningful adoption across independent developers while agent use grows, the 'indispensable' claim is undercut.","supporting_citations":[{"cited_title":"RFC 4271: A border gateway protocol 4 ( BGP -4), 2006","cited_arxiv_id":null,"evidence_quote":"BGP provides the key analogy for indispensable infrastructure and supplies the lock-in example in Section 6.3."},{"cited_title":"A Scalable Communication Protocol for Networks of Large Language Models , October 2024","cited_arxiv_id":null,"evidence_quote":"Existing inter-agent communication protocol that grounds the interaction function and adoption analysis."},{"cited_title":"Announcing the Agent2Agent Protocol ( A2A ) - Google Developers Blog , April 2025","cited_arxiv_id":null,"evidence_quote":"Real-world inter-agent protocol adoption example used to discuss network effects and coordination barriers."}],"review_version":1}