REVIEW 4 major objections 5 minor 28 references
NDAI Agreements
T0 review · 4 major / 5 minor · reviewed 2026-08-08 · deepseek-v4-flash
Pith's one-line read The paper argues that TEE-resident AI agents can turn the inventor's disclosure paradox into an efficient full-disclosure equilibrium whenever the TEE is secure and the agent can value the invention.
desk verdict TEEs as ironclad NDAs is a genuinely new idea, but the main theorem is under-specified and the robustness section has a clear internal inconsistency. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The mechanism is a secure enclave for delegated bargaining: each party's AI agent runs inside a trusted execution environment that takes private inputs, mediates negotiation, and releases the invention and the payment only on mutual acceptance, deleting the session otherwise. The two load-bearing formulas are the Nash-bargaining split $\theta = (1+\alpha_0)/2$ and the scope condition $\omega \le \Phi$, where $\Phi(k,p,C) = \frac{k\left(1-(1-p)^{k\gamma}\right)}{(1-p)^{k\gamma}}C$ is the maximum invention value that a $(k,n)$-threshold secret-sharing scheme can protect against colluding providers given detection probability $p$ and penalty $C$.
What would settle it
Demonstrate a side-channel attack that extracts the invention from the TEE without triggering the assumed detection probability $p_k$; if it succeeds, the scope condition $\omega \le \Phi$ fails to deter expropriation and the full-disclosure equilibrium collapses. Alternatively, record an AI agent's payment errors on real novel inventions: if the error half-range exceeds $E_b^* = 12/11$ at the split $\theta = 6/11$, the buyer's ex-ante payoff is negative and delegation fails.
Extended reading notes
Core claim
In the no-protection game, the seller discloses nothing because any disclosed portion can be expropriated. The paper's Theorem 1 states that with maximally aligned agents and security $\omega \le \Phi$, the TEE arrangement has a unique equilibrium with full disclosure ($\hat\omega = \omega$) and investment at price $P = \theta\omega$, where $\theta = (1+\alpha_0)/2$ is the seller's Nash-bargaining share; both parties strictly prefer this to the baseline $(\alpha_0\omega, 0)$. When $\omega > \Phi$, the seller discloses only $\Phi$ and the parties still trade at $P = \theta\Phi$, partially mitigating hold-up. With noisy agents, a buyer-side overpayment error $e_b$ is truncated by the budget cap and filtered by the seller's acceptance threshold, leaving the buyer's ex-ante payoff $\Pi_B(\theta) = (6-11\theta)/24$, positive for $\theta < 6/11$ (equivalently error half-range up to $E_b^* = 12/11$), so moderate agent errors do not destroy the mechanism.
Load-bearing premise
The buyer's AI agent must be able to assess the true value of the invention inside the TEE with sufficient fidelity, and the TEE must truly be tamper-proof; both capabilities are assumed rather than derived.
Editorial extensions
If this is right
- Any invention valued below the security threshold $\Phi$ can be sold with full disclosure and no NDA, converting disclosure from a risk into a routine transaction.
- For inventions valued above $\Phi$, the seller can still reveal up to $\Phi$ and capture $P = \theta\Phi$, which is strictly better for both parties than the no-disclosure baseline.
- Budget caps and acceptance thresholds make the mechanism work with imperfect AI agents: the buyer's expected payoff stays positive for error half-ranges up to $E_b^* = 12/11$ with $\theta \le 6/11$.
- Policy support for certifying TEE security, subsidizing shared secure infrastructure, and clarifying breach liability would widen the range of ideas that can be safely traded and accelerate cumulative innovation.
Reading between the lines
- Beyond the paper: the same logic should extend to any information good an agent can evaluate without leakage, such as datasets, trade secrets, unpublished results, or proprietary algorithms, not only inventions.
- Beyond the paper: because $\Phi$ grows with the penalty $C$ and with TEE revenue, the model predicts that secure-disclosure adoption will first appear for mid-value secrets near $\Phi$, while very high-value ideas remain under-protected until hardware security improves.
- Beyond the paper: a natural test is behavioral, comparing disclosure depth and deal rates when inventors are offered TEE-mediated bargaining versus a plain NDA; the model predicts significantly more disclosure and more completed deals under the TEE.
- Beyond the paper: repeated interaction among the same TEE providers would raise detection probabilities beyond the one-shot $p_k$, suggesting the model's security bound is conservative in long-run collaborations.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper studies the disclosure of a privately known invention value ω∈[0,1) under expropriation risk. In the baseline, the seller chooses zero disclosure and obtains α0ω, while the buyer gets 0. The authors propose a mechanism in which AI agents bargain inside a trusted execution environment (TEE), and they claim in Theorem 1 that with perfect security and congruent agents the unique equilibrium outcome is full disclosure and a price P=θω, where θ=(1+α0)/2 comes from a symmetric Nash-bargaining split. Section 5 introduces random payment and disclosure errors and argues that budget caps and acceptance thresholds preserve most of the gains from trade; Appendix C derives Π_B=(6−11θ)/24 for the buyer's payoff. The paper concludes with policy implications for using secure hardware as an 'ironclad NDA.'
Significance. The paper addresses a timely and important question: whether trusted execution environments combined with AI agents can mitigate Arrow's disclosure-appropriation paradox. Its baseline model is clean, the security scope condition ω≤Φ is a useful formalization, and the partial-disclosure result for ω>Φ is a sensible concession to real TEE limitations. However, the central theorem is under-specified as an equilibrium claim, and the robustness section contains a numerical inconsistency that undermines the headline message about budget caps. If the game is properly specified and the robustness statements are corrected, the framework could be a useful contribution to the economics of secure disclosure and innovation finance.
major comments (4)
- [Section 4.2 / Theorem 1] The claim of a unique equilibrium is not derived from a specified noncooperative game. The timeline in Section 4.1 ends with 'agents bargain' and Section 4.2 simply imposes a symmetric Nash-bargaining solution, but no strategies, extensive form, or deviation payoffs are given for the intra-TEE interaction. To see the issue, formalize the natural subgame in which the seller's agent announces an acceptance threshold t and the buyer's agent proposes a payment p, with trade iff p≥t. Then any t∈[α0ω,ω] can be supported: the buyer's agent optimally offers exactly t, and the seller's agent cannot profitably deviate. Thus the price is indeterminate, and θω is only one point in a continuum. If the agents are instead hard-coded to implement the Nash-bargaining split, the result is an implementation-by-construction statement, not an equilibrium uniqueness theorem. The theorem's wording must be revised to either provide a full game or claim only that the mechanism implements the Nash-bargaining outcome.
- [Section 5 / Figure 1 vs. Appendix C.2] The main text says that for θ=0.6 the budget-capped buyer payoff remains positive until Eb=0.6, but Appendix C.2 derives Π_B=(6−11θ)/24 (Eq. 7) under eb∼Unif[−2θ,2θ]. At θ=0.6, this gives (6−6.6)/24=−0.025, which is negative. In addition, Appendix C.2 sets Eb=2θ, so for θ=0.6 the relevant error range is Eb=1.2, not 0.6; the payoff is independent of Eb once the support is tied to θ. The figure and the surrounding text therefore contradict the formal calculation, and the claimed 'budget cap buys more tolerance' result is not supported for θ=0.6.
- [Appendix C.2 / Corollary 2] The robustness claim is overstated. The derived buyer payoff Π_B=(6−11θ)/24 is positive only for θ<6/11. Since θ=(1+α0)/2, this requires α0<1/11, which is a small slice of the assumed α0∈(0,1]. Moreover, the 'maximum error threshold' E_b^*=12/11 is obtained by setting θ=6/11 and then Eb=2θ, so it does not show that the mechanism tolerates errors larger than total surplus for a fixed θ. The parameter region in which the mechanism is ex ante incentive-compatible for the buyer should be stated explicitly, and the 'broad range' language in the abstract and Section 5 should be qualified accordingly.
- [Section 3.2 / Eq. (3)] The security threshold formula is internally inconsistent with the notation. The text defines p as 'the probability that a breach is detected,' but Eq. (3) uses (1−p)^k and 1−(1−p)^k, which treats p as a per-TEE baseline detection probability for each of k colluding providers. Appendix D later defines p_k=1−(1−p)^{kγ}. These definitions should be aligned so that the 'sufficient security' condition ω≤Φ is unambiguous. Since Theorem 1 conditions on ω≤Φ, this notational inconsistency affects a load-bearing part of the model.
minor comments (5)
- [Section 4.2] The phrase 'It's straightforward that du*_S/dω~>0' should be written with the full derivative and clearly defined variables, as the current notation is hard to parse.
- [Appendix C.2 / Eq. (8)] The decomposition in Eq. (8) labels term (2) as the loss from half of all draws killing trade, but half of the no-error baseline surplus is (1−θ)/4, not 1/2. The algebra is consistent, but the verbal explanation is misleading.
- [Section 5 / Appendix C.2] The seller's acceptance threshold is set at θω, the Nash-bargaining price, rather than at the seller's reservation value α0ω. Since the seller would accept any offer above α0ω, this threshold is a design choice that reduces trade; it should be justified or relaxed in the robustness analysis.
- [Footnote 1 and Section 3.1] The assumption that the buyer's agent can evaluate ω with 'sufficient fidelity' is central but unmodeled. If the agent can fully value a novel idea, it can also memorize or leak it, so the deletion guarantee in the TEE requires a formal statement about agent behavior outside the secure environment.
- [References] The text cites Arrow [1971] and Arrow [1972] with different publication years in the references; please unify the citation style and ensure the Nelson and Arrow references are consistently formatted.
Circularity Check
Theorem 1's unique price is the imposed Nash-bargaining share, so the headline prediction reduces to the paper's definition of theta.
-
self definitional
[Section 4.2, Eq. (4)-(5), and Theorem 1]
"Inside the TEE, the buyer's agent and the seller's agent solve a symmetrical Nash-bargaining problem over how to split ˆω. ... It follows that the fraction of ˆω accruing to the seller is given by θ = 1+α0 2 . ... We denote θ as the seller's equilibrium share throughout the analysis. Hence, the price the buyer pays in equilibrium is P∗ = θ ˆω. ... Theorem 1 ... the unique equilibrium outcome is full disclosure (ˆω=ω) and investment at price P=θω."
The paper defines θ as 'the seller's equilibrium share' and then Eq. (5) sets the equilibrium price to θω; Theorem 1 restates this as a derived uniqueness result. No noncooperative inside-the-TEE bargaining game is specified: the split is imposed by assuming the agents 'solve a symmetrical Nash-bargaining problem.' Thus P=θω holds by construction, not by deviation arguments. If the TEE is programmed to implement the Nash split, 'unique' describes the mechanism's specification, not an equilibrium deduction; if agents instead can choose acceptance thresholds and offers, any split between the seller's outside option and full value can be an equilibrium, and the stated uniqueness fails.
full rationale
The baseline hold-up result and the security-scope condition (Eq. 3) are self-contained and not circular. The robustness exercise in Section 5 and Appendix C is a real computation from stated error distributions and is not fitted to the theorem. However, the central Theorem 1 is circular in a specific, quotable way: the 'unique equilibrium' price is not derived from a specified extensive-form bargaining game but is imposed by declaring that agents solve a symmetric Nash-bargaining problem and then defining θ as the seller's equilibrium share. Once the split is imposed as the mechanism's programming, the theorem merely restates the mechanism's specification; once it is not imposed, the paper gives no argument ruling out a continuum of equilibrium splits. Thus the main quantitative prediction reduces by construction to the paper's own definition of θ. This warrants a moderate circularity score of 6; there is no load-bearing self-citation chain, and the broad idea that a secure TEE can mitigate hold-up has independent content.
Assumptions & free parameters
free parameters (5)
- alpha_0
- p =
0.005 in the numerical example
- gamma =
2
- C =
approx 7.5bn USD
- E_b =
2*theta in Appendix C.2
assumptions (4)
- domain assumption The TEE is perfectly secure within the stated scope: no information leaks to the buyer unless the agents mutually agree.
- domain assumption The buyer's AI agent can accurately evaluate the invention's value omega from the disclosure.
- domain assumption Parties resolve the intra-TEE negotiation via symmetric Nash bargaining.
- domain assumption Seller type omega is uniformly distributed on [0,1).
invented entities (1)
-
TEE-resident AI agent with valuation fidelity
Cite this review
Pith. "Pith review of NDAI Agreements." pith.science (2026). https://pith.science/paper/5ES2VVBT
@misc{pith2026250207924,
author = {Pith},
title = {Pith review of: NDAI Agreements},
year = {2026},
howpublished = {\url{https://pith.science/paper/5ES2VVBT}},
note = {Machine review of arXiv:2502.07924}
}
read the original abstract
We study a fundamental challenge in the economics of innovation: an inventor must reveal details of a new idea to secure compensation or funding, yet such disclosure risks expropriation. We present a model in which a seller (inventor) and buyer (investor) bargain over an information good under the threat of hold-up. In the classical setting, the seller withholds disclosure to avoid misappropriation, leading to inefficiency. We show that trusted execution environments (TEEs) combined with AI agents can mitigate and even fully eliminate this hold-up problem. By delegating the disclosure and payment decisions to tamper-proof programs, the seller can safely reveal the invention without risking expropriation, achieving full disclosure and an efficient ex post transfer. Moreover, even if the invention's value exceeds a threshold that TEEs can fully secure, partial disclosure still improves outcomes compared to no disclosure. Recognizing that real AI agents are imperfect, we model "agent errors" in payments or disclosures and demonstrate that budget caps and acceptance thresholds suffice to preserve most of the efficiency gains. Our results imply that cryptographic or hardware-based solutions can function as an "ironclad NDA," substantially mitigating the fundamental disclosure-appropriation paradox first identified by Arrow (1962) and Nelson (1959). This has far-reaching policy implications for fostering R&D, technology transfer, and collaboration.
Figures
Reference graph
Works this paper leans on
-
[1]
Innovation and growth: an overview
Philippe Aghion and Peter Howitt. Innovation and growth: an overview. Growth and Development: Theories and Facts, pages 71--87, 1992
work page 1992
-
[2]
Formal and real authority in organizations
Philippe Aghion and Jean Tirole. Formal and real authority in organizations. Journal of political economy, 105 0 (1): 0 1--29, 1997
work page 1997
-
[3]
Expropriation and inventions: Appropriable rents in the absence of property rights
James J Anton and Dennis A Yao. Expropriation and inventions: Appropriable rents in the absence of property rights. The American Economic Review, pages 190--209, 1994
work page 1994
-
[4]
The sale of ideas: Strategic disclosure, property rights, and contracting
James J Anton and Dennis A Yao. The sale of ideas: Strategic disclosure, property rights, and contracting. The Review of Economic Studies, 69 0 (3): 0 513--531, 2002
work page 2002
-
[5]
Arm security technology: Building a secure system using trustzone technology
ARM . Arm security technology: Building a secure system using trustzone technology. https://developer.arm.com/documentation, 2020
work page 2020
-
[6]
Economic welfare and the allocation of resources for invention
Kenneth Joseph Arrow. Economic welfare and the allocation of resources for invention. Springer, 1972
work page 1972
-
[7]
K.J. Arrow. Essays in the Theory of Risk-bearing. Markham economics series. Markham Publishing Company, 1971. ISBN 9780841020016. URL https://books.google.com/books?id=KkMoAQAAMAAJ
work page 1971
-
[8]
The travels and trials of mr harrison's timekeeper
Jim Bennett. The travels and trials of mr harrison's timekeeper. In Instruments, Travel and Science, pages 75--95. Routledge, 2003
work page 2003
Show all 28 references
-
[9]
Sequential bargaining under asymmetric information
B Douglas Bernheim and Michael D Whinston. Sequential bargaining under asymmetric information. Journal of Economic Theory, 48 0 (1): 0 5--39, 1987
1987
-
[10]
The adoption of blockchain-based decentralized exchanges
Agostino Capponi, Ruizhe Jia, and Ye Wang. The adoption of blockchain-based decentralized exchanges. Management Science, 2023
2023
-
[11]
Patent trolls: Evidence from targeted firms
Lauren Cohen, Umit G Gurun, and Scott Duke Kominers. Patent trolls: Evidence from targeted firms. Management Science, 65 0 (12): 0 5461--5486, 2019
2019
-
[12]
How trade secrets hurt innovation
Andrea Contigiani and David H Hsu. How trade secrets hurt innovation. Harvard Business Review, 29, 2019
2019
-
[13]
Intel sgx explained
Victor Costan and Srinivas Devadas. Intel sgx explained. Cryptology ePrint Archive, Report 2016/086, 2016. https://eprint.iacr.org/2016/086
2016
-
[14]
Strategic information transmission
Vincent P Crawford and Joel Sobel. Strategic information transmission. Econometrica, pages 1431--1451, 1982
1982
-
[15]
Flash boys 2.0: Frontrunning in decentralized exchanges, miner extractable value, and consensus instability
Philip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li, Xueyuan Zhao, Iddo Bentov, Lorenz Breidenbach, and Ari Juels. Flash boys 2.0: Frontrunning in decentralized exchanges, miner extractable value, and consensus instability. IEEE Symposium on Security and Privacy, pages 910--927, 2020
2020
-
[16]
Limitations to interorganizational knowledge acquisition: The paradox of corporate venture capital
Gary Dushnitsky and J Myles Shaver. Limitations to interorganizational knowledge acquisition: The paradox of corporate venture capital. Strategic Management Journal, 30 0 (10): 0 1045--1064, 2009
2009
-
[17]
Recombinant uncertainty in technological search
Lee Fleming. Recombinant uncertainty in technological search. Management science, 47 0 (1): 0 117--132, 2001
2001
-
[18]
How to start a startup
Paul Graham. How to start a startup. https://www.paulgraham.com/start.html, March 2005. [Blog post]
2005
-
[19]
Confidential computing market size & share analysis report, 2030
Grand View Research . Confidential computing market size & share analysis report, 2030. https://www.grandviewresearch.com/industry-analysis/confidential-computing-market-report, 2024. Accessed: 2025-01-18
2024
-
[20]
The costs and benefits of ownership: A theory of vertical and lateral integration
Sanford J Grossman and Oliver D Hart. The costs and benefits of ownership: A theory of vertical and lateral integration. Journal of Political Economy, 94 0 (4): 0 691--719, 1986
1986
-
[21]
Incomplete contracts and renegotiation
Oliver Hart and John Moore. Incomplete contracts and renegotiation. Econometrica, pages 755--785, 1988
1988
-
[22]
Lewis & Bockius LLP Morgan. Should venture capital firms sign ndas? https://www.morganlewis.com/-/media/files/special-topics/vcpefdeskbook/fundoperation/cpefdeskbook_shouldventurecapitalfirmssignndas.pdf, 2015. [Legal memo]
2015
-
[23]
The simple economics of basic scientific research
Richard R Nelson. The simple economics of basic scientific research. Journal of political economy, 67 0 (3): 0 297--306, 1959
1959
-
[24]
Management of the innovation process: An overview of japanese firms
Masahiro Okuno-Fujiwara. Management of the innovation process: An overview of japanese firms. Research Policy, 20 0 (2): 0 165--172, 1991
1991
-
[25]
Transaction fee mechanism design for the ethereum blockchain: An economic analysis of eip-1559
Tim Roughgarden. Transaction fee mechanism design for the ethereum blockchain: An economic analysis of eip-1559. arXiv preprint arXiv:2012.00854, 2020
2012 arXiv
-
[26]
Finite automata play the repeated prisoner's dilemma
Ariel Rubinstein. Finite automata play the repeated prisoner's dilemma. Journal of economic theory, 39 0 (1): 0 83--96, 1986
1986
-
[27]
On the optimality of the patent renewal system
Suzanne Scotchmer. On the optimality of the patent renewal system. The RAND Journal of Economics, pages 181--196, 1999
1999
-
[28]
Longitude: The true story of a lone genius who solved the greatest scientific problem of his time
Dava Sobel. Longitude: The true story of a lone genius who solved the greatest scientific problem of his time. Macmillan, 2005
2005
Reviewed August 8, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.