{"id":"808cda1f-61d6-48f3-87f8-df68576281ce","arxiv_id":"2608.06510","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A comparative study of four digital technologies finds that user control erodes when contestable choices are embedded in closed technical standards, and warns that agentic AI is repeating that pattern now.","lead":"This paper compares how ad blockers, recommender systems, robo-advisors, and spam filters changed who controls what digital agents can do. It argues that user empowerment depends less on the technology than on the collective ability to contest decisions made in protocols, standards, and platform rules.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The framework is induced from the same four cases it explains, and the robo-advisor case coded as a contestation success ends in re-embedding and SEC withdrawal, so the agentic-AI foreclosure prediction lacks a confirmed causal foundation.","rationale":"The reader's weakest assumption identifies the core problem: the framework is induced from the same cases it explains, with no out-of-sample validation, and the agentic-AI prediction inherits that fragility. My stress-test sharpens the same concern by noting that the robo-advisor case, which the paper treats as a partial positive for adversarial contestation, actually ends in nested re-embedding and regulatory withdrawal, so the framework lacks a clean positive instance of durable empowerment. This does not change the verdict. The individual case narratives are historically grounded, the depoliticization lens is a legitimate contribution, and the policy warning about AAIF governance is timely even if not fully proven. The right response is to keep the verdict conditional and require an out-of-sample or leave-one-out test before accepting the stronger claim that protocol-level agentic-AI governance is closing the window for contestation now.","tokens_in":20893,"tokens_out":5735,"duration_ms":61807,"concrete_test":"Run a pre-registered leave-one-out test on the four trajectories: code the three conditions and the contestation outcome independently, derive the conditions from any three cases, and predict the held-out case. The critical fold is the robo-advisor trajectory: if the conditions derived from ad blockers, recommenders, and spam predict durable user empowerment there, the framework is falsified by the later SEC withdrawal and nested re-embedding; if they do not, the framework is already fit to the outcome. A pass requires held-out predictions to match without post hoc adjustment of the condition definitions.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim requires that the three conditions—public observability, independent infrastructure, and governance that sustains contestation—are general causes of durable user empowerment, not labels retrospectively attached to four selected trajectories. The paper itself undercuts this: Section 3 says the cases were selected to span variation, and Section 6 admits the dimensions emerged from the trajectories analyzed. With conditions and outcomes defined on the same four cases, causal direction cannot be inferred, and the Section 5 application to agentic AI carries no control for historical confounds such as regulatory intensity, market concentration, or user exit costs. More pointedly, the only case the framework codes as a successful instance of adversarial contestation, robo-advisors, is the one that most clearly fails the durability claim: MiFID II and SEC interventions were followed by nested re-embedding at the implementation level, and the SEC withdrew its predictive-analytics rule in 2025. If a trajectory with the paper's preferred institutions still produces re-embedding, the framework has no confirmed positive instance of durable empowerment, and the claim that multi-dimensional foreclosure in agentic AI will be qualitatively harder to reverse is not derivable from the evidence presented. The AAIF application is also time-sensitive: rapid MCP adoption is treated as material embedding, but MCP is an open protocol, and no evidence establishes that protocol-level standards without public-interest standing historically lock in before contestation can form.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper develops a \"constitutive politics\" framework for studying user-facing agents, organized around three dimensions (infrastructural, epistemic, teleological) and three conditions for collective contestation (public observability, independent infrastructure, governance that sustains contestation). It applies this framework to four historical trajectories—browser ad blockers, platform recommender systems, financial robo-advisors, and email spam governance—to argue that depoliticization drives a divergence between individual-level improvements and collective capacity to contest the terms of agency. It then uses the framework prospectively to analyze the Model Context Protocol and the Agentic AI Foundation, concluding that current governance arrangements reproduce foreclosure-prone patterns and that the window for public contestation is closing.","tokens_in":21025,"tokens_out":4032,"duration_ms":38408,"significance":"If its central claim is accepted, the paper usefully reframes protocol-level standards and industry foundations as primary sites of political power over AI, rather than as technical details. The historical narratives are citation-dense, internally consistent, and the spam case documents a striking divergence between individual inbox quality and collective contestation capacity. The paper also states explicit falsifiability conditions and discloses its main methodological limitations, which is commendable. However, the central causal inference—that durable user empowerment depends on the three identified conditions—is derived from the same four cases used to test it, and the only candidate positive instance (robo-advisors) is undercut by the paper's own narrative of SEC withdrawal and nested re-embedding. The prospective agentic-AI application is therefore not yet backed by a confirmed causal foundation, though the framework remains plausible as an interpretive heuristic.","major_comments":[{"comment":"The framework is induced from the same cases it is then used to explain. Section 2 states \"We derive it from the cases, not from the framework alone,\" and Section 6's Limitations admits \"The three dimensions emerged from the trajectories we analyzed.\" Because the three conditions of collective contestation and the outcome (durable vs. foreclosed contestation) are defined on the same four cases, the comparative analysis cannot establish the causal claim in §4 that \"durable user empowerment depends on the collective capacity to contest such choices.\" The Section 5 application to agentic AI inherits this evidentiary gap; no out-of-sample trajectory is used to test the conditions. The authors should either add an independent case not used in the induction, or explicitly reframe the central claim as an interpretive synthesis rather than a causal generalization.","section":"§2 and §6"},{"comment":"The paper's only candidate positive instance of sustained adversarial contestation—the SEC/MiFID II treatment of robo-advisors—is contradicted by its own narrative. Section 3 documents that the SEC withdrew its predictive-analytics rule in 2025, and Section 4's \"Durability and the Burden of Re-politicization\" describes MiFID II as leading to \"nested re-embedding at the implementation level\" (a pattern reiterated in Section 5). Thus the paper has no confirmed positive case where the three conditions produced durable user empowerment; the robo-advisor trajectory in fact illustrates the paper's own re-embedding dynamic. This weakens the induction behind the three conditions and the specific prediction in §5 that multi-dimensional foreclosure in agentic AI will be \"qualitatively harder to reverse.\" The authors need to confront this directly and either identify a true positive case or temper the sufficiency claim.","section":"§3 (Financial Robo-Advisors) and §4 (Durability and the Burden of Re-politicization)"},{"comment":"The Section 5 application treats rapid MCP adoption and the AAIF's governance composition as reproducing the foreclosure-prone pattern without addressing the openness of the protocol itself. Unlike Chrome's proprietary extension API in the Manifest V3 case, MCP is an open protocol hosted by the Linux Foundation, with an open SEP process and public maintainer meetings. The paper does not specify the mechanism by which protocol-level governance—as opposed to a single firm's infrastructure—forecloses contestation, nor does it explain why users or third parties cannot fork or otherwise work around an unfavorable SEP outcome. To make the analogy load-bearing, the authors should either provide evidence that the AAIF's open surface is structurally incapable of channeling contestation, or explicitly limit the claim to the current governance charter rather than asserting that the window is closing on the basis of the historical analogy.","section":"§5 (Institutional configuration in place)"}],"minor_comments":[{"comment":"The falsifiability condition is stated only at the end of the section; given that it is the paper's main protection against the in-sample induction critique, it should be introduced earlier and explicitly checked against the robo-advisor case, which currently appears to violate the expectation that adversarial institutional design prevents foreclosure.","section":"§4 (Conditions of Collective Contestation)"},{"comment":"The limitation that the cases are \"US- and EU-centric\" is accurate but understated: all four cases come from Western, high-income, democratic regulatory contexts. The authors should acknowledge that the transferability of the three conditions to other administrative law traditions is not merely unaddressed but potentially constrained by the shared institutional features of the sampled cases.","section":"§6 (Limitations)"},{"comment":"The entry \"Depoliticized by design\" uses intentional language that conflicts with the paper's own definition of depoliticization as a process, not a design intention; consider rephrasing to \"depoliticized from the outset\" or similar.","section":"Table 1, Recommenders row"},{"comment":"The right-to-be-forgotten example is introduced as an illustration but no case material is provided; either develop it briefly or remove it, since it introduces a new domain without analysis.","section":"§6 (Discussion and Conclusion)"},{"comment":"The phrase in §4 that \"The cases provide no support for the view that centralized control is a precondition for adequate technical performance\" is stronger than the evidence: with four cases, the absence of support is not the same as evidence against, and the spam case actually shows centralized control achieving high individual-level performance. Weakening this to \"no support in these cases\" would avoid overstatement.","section":"General"}],"recommendation":"major_revision","confidential_remarks":"The paper is well within the scope of cs.CY and has genuine value as a close comparative reading of four technology trajectories. The main risk is the induction problem: the framework is derived from the same cases it explains, and the strongest positive case for the framework is undercut by the paper's own description of SEC withdrawal and nested re-embedding. I would encourage the authors to add an out-of-sample case (for example, a brief contrast with web feeds or another domain) or to reposition the paper explicitly as an interpretive framework rather than a causal theory. Either change would substantially strengthen the contribution without requiring new data collection. The prospective agentic-AI section is engaging but needs a more careful treatment of why open-protocol governance should be expected to foreclose contestation in the same way as proprietary browser APIs."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"This paper is worth reading before you dismiss the 'protocol governance' angle on agentic AI. The real contribution is a three-condition framework for collective contestation—public observability, independent infrastructure, and governance that sustains contestation—built from four historical cases (ad blockers, recommenders, robo-advisors, spam) and then pointed at the Model Context Protocol and the Agentic AI Foundation. The historical work is citation-dense and careful, and the spam case does a genuinely good job showing how individual inbox quality can improve while organized contestation capacity collapses. That divergence is the paper's sharpest insight, and it is well supported.\n\nWhat's new is the synthesis, not the ingredients. The paper is also commendably honest: it states in Section 6 that the dimensions emerged from the trajectories it analyzed, and it includes a falsifiability condition in Section 4. That is more than most comparative work does.\n\nThe soft spots are real but proportionate. The main one is the induction loop: the framework is derived from the same four cases it explains, then applied to agentic AI without an out-of-sample test. That does not sink the argument—the cases do span variation in outcomes—but it means the agentic-AI prediction is an extrapolation, not a confirmed test. The stress-test note about robo-advisors is only half right. The paper does not present robo-advisors as a durable win; it explicitly codes them as 're-opened by SEC / MiFID II' followed by 'nested re-embedding.' That actually fits the framework, though it does mean the positive instances of durable contestation are thin—really just uBlock Origin on Firefox. The AAIF analysis is a 2025–26 snapshot and will age quickly. None of this is a load-bearing flaw; it is a reason to ask for an additional out-of-sample case or a sharper account of why the robo-advisor re-embedding does not count against the conditions.\n\nFor whom: AI governance researchers, sociologists of standards, and people working on protocol-level policy. It deserves a serious referee and would benefit from revision, not rejection. I'd cite it if I were working on AI governance.","headline":"A careful comparative framework for when users can contest agentic systems; the induction from its own cases is real but admitted, and the agentic-AI application is timely enough to warrant serious engagement.","tokens_in":618,"tokens_out":1470,"would_cite":true,"duration_ms":30284,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Whether agentic AI empowers users depends on the collective capacity to contest choices embedded in protocol infrastructure — and this paper argues that capacity is being foreclosed now, before the architecture hardens.","keywords":["agentic AI","depoliticization","collective contestation","protocol governance","Model Context Protocol","ad blockers","recommender systems","robo-advisors"],"falsifier":"A documented trajectory in which organized collective contestation persisted without one of the three conditions, or in which multi-dimensional foreclosure was reversed within a few years, would require the framework's mechanism claim to be revised, as the paper itself states. Concretely, if the Agentic AI Foundation's final charter grants users or public-interest groups formal adversarial standing and revision authority, or if an open agent ecosystem sustains contestation without non-platform infrastructure, the central claim would be contradicted.","tokens_in":20592,"feed_emoji":"⚖️","tokens_out":6468,"duration_ms":54325,"temperature":0.7,"pith_summary":"Whether agentic AI empowers users is a political question, not just a technical one, and this paper argues the answer is being settled now at the protocol layer. Through a comparative analysis of ad blockers, recommender systems, robo-advisors, and spam governance, it identifies a recurring pattern: contestable choices about whose interests agents serve get embedded in APIs, standards, and default configurations, removing them from public challenge. It specifies three conditions that sustain the collective capacity to contest such choices — public observability, independent infrastructure, and governance with adversarial pathways — and shows that when all three are foreclosed at once, displacement becomes qualitatively harder to reverse. Applied to agentic AI, the paper contends that the Model Context Protocol's governance under the Agentic AI Foundation reproduces this foreclosure-prone pattern, so the window for public contestation is closing now.","feed_headline":"The fight over who AI agents serve is being settled without users","feed_subtitle":"Four histories of ad blockers, spam, and robo-advisors show contestation dies at the protocol layer; MCP's new foundation lacks the…","key_machinery":"The constitutive politics framework, which decomposes any computational agent into three necessary elements — infrastructure, data/knowledge, and objective — and treats each as a site of political contestation embedded in technical form. The paper uses the concept of depoliticization to describe how contestable choices are relocated into technical or expert arrangements, and derives three conditions for collective contestation — public observability, independent infrastructure, and governance that sustains contestation — as the material basis that determines whether organized challenge can form, persist, and survive adversarial pressure. It also identifies multi-dimensional foreclosure as the mechanism that makes displacement compounding, and nested re-embedding as the pattern by which regulatory interventions are bypassed at an implementation level.","core_discovery":"The paper's central claim is that durable user empowerment depends on the collective capacity to contest the choices embedded in the technical arrangements that define what agents can do. In the four historical cases, decisions about infrastructure, knowledge production, and optimization objectives were made through API redesigns, standard-setting bodies, and default configurations — moves that were political but presented as technical. The paper identifies three jointly effective conditions for contestation to form and persist: the epistemic task must be performable with publicly observable information, community knowledge must be operable through infrastructure the platform does not control, and governance must include a formal challenge pathway. It argues that when foreclosure accumulates across all three dimensions simultaneously, the footholds from which contestation could be rebuilt are removed together, making reversal qualitatively harder. For agentic AI, the paper argues that the Model Context Protocol's donation to the Agentic AI Foundation creates a governance configuration with open procedures but no public interest mandate, no adversarial mechanism, and a Governing Board composed of platform providers — the pattern the cases show as foreclosure-prone, and one that is being settled before material adoption makes it hard to revisit.","pith_inferences":["The framework could be operationalized as a governance scorecard: evaluate any AI standards body on the three conditions, and the theory predicts that a body lacking even one will see contestation degrade; the AAIF's final charter is a near-term test case.","The argument implies that open-weight models and non-platform compute are preconditions for the epistemic commons in agentic AI; if the protocol layer locks proprietary access, the recommender-systems pattern — where no organized contestation ever formed — may recur across all domains at once.","A testable extension: if an open alternative to MCP maintains a community filter-list-like epistemic commons, the paper's framework predicts that its durability will depend on whether it can run on infrastructure not controlled by the dominant platform providers, just as Firefox preserved uBlock Origin's full capability."],"forward_implications":["If the claim is right, protocol-level standards design is a primary site of political power over AI, and the EU AI Act's silence on agentic systems means downstream regulation will operate on boundaries already set upstream.","The consolidation of the Model Context Protocol under the Agentic AI Foundation, with no formal standing for users or public interest representatives, means the conditions for collective contestation over agent behavior are absent at the layer where capability boundaries are defined.","The window for intervention is bounded: the AAIF charter is being finalized in 2026, EU technical standards are under development for 2027, and default behaviors of deployed shopping agents are accumulating habituation now; each becomes harder to revisit once material adoption advances.","Transparency alone will not constitute accountability; the robo-advisor and DSA trajectories show that disclosure without adversarial standing and revision authority can perform discursive legitimation rather than genuine contestation.","The uBlock Origin on Firefox case shows that preserving independent infrastructure can sustain user-aligned agency even when a dominant platform forecloses its own channel."],"supporting_citations":[{"why":"Documents how Chrome's Manifest V3 replaced the flexible webRequest API with the constrained declarativeNetRequest API, a load-bearing instance of infrastructural foreclosure in the ad blocker case.","marker":"Cyphers 2021"},{"why":"Source for the Model Context Protocol's donation to the Agentic AI Foundation, the Governing Board's composition, and membership-tier-based decision authority.","marker":"Linux Foundation 2025"},{"why":"Audit evidence that agent behavior is partially observable and value-embedding is detectable in deployed shopping agents, grounding the epistemic feasibility condition.","marker":"Allouah et al. 2025"},{"why":"Ethnographic account of the anti-spam community's transition to gated industry forums like M3AAWG, supporting the collapse of collective contestation in spam governance.","marker":"Mathew and Cheshire 2017"},{"why":"Analysis of EasyList's growth, unused rules, and centralized maintenance, supporting the characterization of the ad-blocking epistemic commons and its operational burdens.","marker":"Snyder, Vastel, and Livshits 2020"},{"why":"History of digital spam and the consolidation of proprietary machine-learning classifiers, underpinning the individual-improvement/collective-collapse divergence.","marker":"Ferrara 2019"},{"why":"Summarizes the SEC's 2023 proposed rule on conflicts of interest in predictive analytics, used to illustrate adversarial-enabling regulatory architecture and its subsequent withdrawal.","marker":"Bearup 2023"},{"why":"DSA compliance audits showing minimal implementation of mandated provisions, supporting the limits of transparency and the nested re-embedding dynamic.","marker":"Fabbri and Boratto 2025"}],"fun_headline_variants":["AI agent governance is a political fight wearing a technical mask","Protocols are politics: AI agents serve those who set the standards","MCP's new foundation settles who AI agents serve before users weigh in","The real AI agent battle: political choices disguised as technical specs","AI agents' loyalties are fixed in boring protocols, not user choice"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The paper assumes the four historical cases are a fair and sufficient sample from which to infer the three conditions as general causes of contestation, even though the framework was induced from those same cases and applied to agentic AI without an out-of-sample test.","fun_headline_variants_meta":{"raw":{"variants":["AI agent governance is a political fight wearing a technical mask","Protocols are politics: AI agents serve those who set the standards","MCP's new foundation settles who AI agents serve before users weigh in","The real AI agent battle: political choices disguised as technical specs","AI agents' loyalties are fixed in boring protocols, not user choice"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000812,"raw_usage":{"total_tokens":3590,"prompt_tokens":1002,"completion_tokens":2588,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":618,"completion_tokens_details":{"reasoning_tokens":2498}},"tokens_in":618,"tokens_out":2588,"duration_ms":18661,"temperature":1.0,"reasoning_tokens":2498,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T04:17:53.935846+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A documented trajectory in which organized collective contestation persisted without one of the three conditions, or in which multi-dimensional foreclosure was reversed within a few years, would require the framework's mechanism claim to be revised, as the paper itself states. Concretely, if the Agentic AI Foundation's final charter grants users or public-interest groups formal adversarial standing and revision authority, or if an open agent ecosystem sustains contestation without non-platform infrastructure, the central claim would be contradicted.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Documents how Chrome's Manifest V3 replaced the flexible webRequest API with the constrained declarativeNetRequest API, a load-bearing instance of infrastructural foreclosure in the ad blocker case."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Source for the Model Context Protocol's donation to the Agentic AI Foundation, the Governing Board's composition, and membership-tier-based decision authority."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Ethnographic account of the anti-spam community's transition to gated industry forums like M3AAWG, supporting the collapse of collective contestation in spam governance."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Analysis of EasyList's growth, unused rules, and centralized maintenance, supporting the characterization of the ad-blocking epistemic commons and its operational burdens."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"History of digital spam and the consolidation of proprietary machine-learning classifiers, underpinning the individual-improvement/collective-collapse divergence."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Summarizes the SEC's 2023 proposed rule on conflicts of interest in predictive analytics, used to illustrate adversarial-enabling regulatory architecture and its subsequent withdrawal."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"DSA compliance audits showing minimal implementation of mandated provisions, supporting the limits of transparency and the nested re-embedding dynamic."}],"review_version":1}