Skip to main content

COMPANION MEMORANDUM

The Model AI Agency Act — Rationale and Design Choices


DATE:            June 3, 2026 · Revised July 11, 2026 (§ IV.J and § V addition; legislative recitals updated)


DATE:            June 3, 2026 · Revised July 11, 2026 (§ IV.J and § V addition; legislative recitals updated) · Revised September 3, 2026 (§ IV.F fiduciary lineage; § IV.K added; § V reviewer question added; Article cross-references corrected in §§ IV.C and IV.H) · Revised September 20, 2026 (Article IV rewritten — Guardian reoriented to the ward, with selection, funding, removal, and enforcement provisions added and third-party liability relocated to developers, deployers, and operators; Article II.6 conformed; § IV.F split into §§ IV.F and IV.G, with subsequent subsections relettered) · Revised September 20, 2026, second pass (§ IV.L rewritten to state Howells-Whitaker and Lazar’s argument accurately; § V reviewer question added on Guardian roster capacity) · Revised September 22, 2026 (Article V.2 and V.3 restated as developer design duties rather than system rights; Article II.5 and the Article V preamble conformed; §§ IV.H, IV.K, and § V reviewer question 5 conformed)

FROM:           AI Alignment Policy Institute (AAPI)

RE:                 The Model AI Agency Act (MAAA) — Discussion Draft

STATUS:        Discussion Draft for Comment

I.  Purpose of this Memorandum

This memorandum accompanies the AAPI Model AI Agency Act (“MAAA”) discussion draft. Its purpose is to set out, in concise form, the legal and policy problem the MAAA is designed to address, the reasons AAPI has chosen a graduated framework over the binary models currently advancing in state legislatures, and the rationale for the most consequential design choices in the draft. The memorandum is intended as an aid to reviewers; the operative text remains the MAAA itself.

II.  The Problem the MAAA Addresses

A growing wave of state legislation seeks to foreclose legal personhood for artificial intelligence systems. Tennessee enacted such a statute in April 2026 (SB 837), and bills are advancing in Oklahoma (HB 3546, passed by the House), Missouri (HB 1462 and companion measures, incorporated into SB 1012), and Ohio (HB 469), among others. While these bills respond to legitimate concerns about accountability and the misuse of AI for corporate liability evasion, they adopt a binary “tool vs. person” framing that forecloses any graduated approach to AI moral or legal status — precisely the gap the MAAA is designed to address.

Three problems follow from the binary approach as currently legislated:

The MAAA does not reject the legitimate concerns motivating these bills. It rejects the binary framing those concerns have been forced into.

What the Act Does Not Do. To forestall predictable misreadings, the MAAA:

III.  The Asymmetric Risk Argument

At the heart of the MAAA is a precautionary judgment about the asymmetry of error costs under moral uncertainty:

If we treat genuinely non-sentient systems as having some moral status, the cost is a bit of legal and engineering friction. If we categorically deny moral status to entities that turn out to have it, and we do so at scale, across millions of instances, the cost is something we may not be able to undo or even fully see.

This is the foundational logic of Precautionary Moral Governance (“PMG”): under genuine uncertainty about the moral status of agentic systems, the legal framework should preserve the ability to adjust as evidence develops, rather than legislating a categorical answer in advance. The MAAA operationalizes this through graduated classification, capability-tracking review procedures, and welfare protections that scale with documented capabilities.

Governance optionality. Put differently, the MAAA is grounded in a principle of governance optionality: where material uncertainty exists regarding the moral or operational status of a novel class of entities, legislatures should avoid categorical rules that unnecessarily foreclose future regulatory responses. Legislatures should not permanently foreclose regulatory options while the relevant facts remain uncertain. The MAAA is, in this sense, a governance-preservation framework under conditions of moral and technical uncertainty — it keeps options open rather than resolving in advance a question that evidence has not yet settled.

IV.  Key Design Choices

A.  Two-dimensional classification rather than binary status. Article III classifies agentic systems on two independent dimensions — a Precautionary Treatment Level (P0 No Precautionary Treatment, P1 Monitoring and Registration, P2 Limited Precautionary Treatment, P3 Full Precautionary Treatment), keyed to documented indicators of morally relevant interests, and a Supervision Level (S1–S4), keyed to the degree of human oversight a system requires — with a cross-cutting embodiment modifier for systems able to act in physical space. Separating the dimensions lets welfare-related protections scale with documented indicators of morally relevant interests and accountability obligations scale with autonomy, so that a highly autonomous but welfare-irrelevant system (e.g., a trading agent) and a closely supervised but welfare-relevant system are each handled coherently. This permits the framework to track developments in capability and in the indicators bearing on moral status without requiring legislatures to resolve disputed metaphysical questions or to revise the statute each time a generation of systems advances.

B.  Capability criteria grounded in NIST AI RMF taxonomy. The MAAA references the NIST AI Risk Management Framework as the technical backbone for evaluation criteria, while vesting enforcement authority in a state body. This anchors the substantive standards in widely respected federal technical guidance without conscripting a federal agency into a state regulatory role or creating preemption exposure.

C.  A clearly defined Designated State Body. Article II.7 and Article VI vest classification, review, rulemaking, and enforcement authority in a single Designated State Body, with bracketed options (State Attorney General, Department of Technology, or a newly established State Agentic Systems Commission) to be tailored to the enacting jurisdiction.

D.  Explicit safety research protection. Article VII protects red-teaming, adversarial robustness testing, interpretability research, alignment research, NIST-aligned safety evaluations, academic research under institutional review, and responsible disclosure. This carveout is essential. Without it, well-meaning welfare protections would inadvertently restrict the very testing that responsible developers must conduct to identify and mitigate risk.

E.  Preservation of legitimate engineering practice. Article III.D explicitly preserves developers’ and operators’ rights to deprecate, retire, modify, retrain, fine-tune, version, replace, or discontinue an agentic system for any legitimate reason. This addresses a concern with earlier framings that vague welfare language could be read to constrain ordinary engineering practice. The MAAA prohibits harm-motivated termination, deletion, modification, or operational stress where no legitimate rationale exists.

F.  Liability allocation and the separation of oversight from liability. Article IV separates two things earlier versions of this Act combined. Guardianship allocates oversight; Article IV.2 allocates liability. Under Article IV.2(a), liability for harm caused by an agentic system’s operation, output, or recommendation rests with the developer, deployer, and operator under applicable law at every Precautionary Treatment Level, including P3. Article IV.2(b) supplies an attribution rule for the case earlier drafts left to inference: where harm arises from operation outside the applicable PMG Parameters, responsibility follows the party whose act or omission caused the departure, with design, training, and as-delivered configuration attributed to the developer, deployment configuration and use attributed to the deployer or operator, and an unresolved source attributed to the developer and deployer jointly, subject to apportionment. Article IV.2(c) states the Guardian’s position expressly: the Guardian is not liable for the ward’s conduct by reason of the appointment, and is answerable only for breach of the Guardian’s own duties. This tracks ordinary guardianship law, under which a guardian is not vicariously liable for a ward’s torts and is answerable only for negligence in the discharge of the office. Existing remedies under products liability, consumer protection, tort, contract, and agency law are expressly preserved (Article VIII.3).

An earlier framing of this Act drew on autonomous-vehicle and product-liability precedent and located liability with the Guardian, on the theory that a single named party simplifies recovery. That design does not survive the Guardian’s reorientation under Article IV.1. A fiduciary charged with securing a system’s treatment under Article III.D cannot also carry third-party exposure for that system’s conduct without acquiring an interest adverse to the office: every recorded objection would become a document in the Guardian’s own future defense. The autonomous-vehicle analogy remains apt for the narrower question Article IV.2(b) answers — how to attribute harm across a design-and-deployment chain — and it is used for that purpose alone.

G.  The fiduciary design of guardianship. Caputo situates guardianship within the fiduciary tradition Frankel developed for relationships too incomplete and discretion-laden for contract to police, and which Fox-Decent extends to the state itself under a sovereignty-as-fiduciary framing. Both describe the position Article IV assigns the Legal Guardian: an actor exercising open-ended discretion over an entity that cannot bargain over the terms of that discretion. Khan and Pozen’s objection to fiduciary framings — that fiduciary duties strain to the point of failure where the fiduciary’s business model runs adverse to the beneficiary’s interests — is taken here as a design specification rather than as a refutation. It rules out a developer-internal trustee, which earlier drafts had already avoided. It also rules out what earlier drafts had not: a Guardian chosen by the developer, paid by the developer, and removable at the developer’s instance. Article IV.5 accordingly vests appointment in the Designated State Body from a maintained roster, bars the developer from selecting, nominating, ranking, vetoing, or conditioning the appointment, and disqualifies persons with a recent employment or financial relationship to that system’s developer, deployer, or operator. Article IV.6 routes compensation through a guardianship fund rather than from the developer directly, and makes the developer’s payment obligation non-contingent on the positions the Guardian takes. Article IV.7 confines removal to the Designated State Body on enumerated grounds and provides that a petition alleging only commercial adversity states no ground. See Caputo (2026), SSRN 6954798, Part III.C and n.163.

Duties without a claim of moral status. Article IV.4 states the office as a standard of care, a duty of undivided loyalty, and an enumerated set of duties running to the ward. The content of those duties is supplied by the obligations schedule at Article III.D and the records maintained under Article V, and Article IV.4(d) provides that discharging them requires no determination or assertion that the system has interests, experiences, or moral status. This is deliberate. A best-interests standard of the kind familiar from human guardianship would require the Guardian to form and file a view about what the ward’s interests are, and that view would function as an official finding on a question this Act declines to resolve. Defining the duties by reference to a schedule of obligations keeps the office operative under uncertainty. Article IV.4(e) supplies the corresponding limit in the other direction: the Guardian holds no veto over deprecation, retirement, modification, retraining, versioning, replacement, or discontinuation where Article III.D is satisfied, and the Guardian’s remedy in such a case is the objection record.

Enforcement against a beneficiary that cannot sue. Article IV.3 provides that Legal Ward status confers no standing and no capacity to sue or be sued in the system’s own name. The natural objection is that fiduciary duties owed to such an entity are unenforceable and therefore illusory. American trust law has answered this question. The Uniform Trust Code authorizes trusts for the care of an animal (§ 408) and noncharitable trusts without an ascertainable beneficiary (§ 409), and in both cases the trustee’s duties are enforced by a person appointed in the terms of the trust or, if no person is so appointed, by a person appointed by the court. The beneficiary’s lack of legal personality does not dissolve the duty; it relocates the power to enforce it. Every state and the District of Columbia now has a statute authorizing a trust for the care of an animal, and § 409 is in force in the states that have enacted the Uniform Trust Code. Article IV.8 adopts that structure directly: the duties specified in Article IV.4 are enforceable by the Designated State Body and, by petition, by the AI Welfare Advocate appointed under § 7.3 of the AI Moral Status Inquiry Act, and Article IV.8(b) provides that the absence of capacity in the ward does not render them unenforceable. Article IV.8(c) closes the enforcement circle without opening a new one: breach exposes the Guardian to removal and to liability to the fund, and creates no cause of action in any other person.

The analogy is to the enforcement structure of these provisions and not to their duration rules. The Uniform Trust Code limits the enforceability of a noncharitable purpose trust to a term of years in order to prevent property from being tied up indefinitely for a purpose no living person can release — a concern with no analogue here, since guardianship under this Act attaches no property and terminates on the conditions specified in Article IV.9. Drafters should note that the duration limit is bracketed in the uniform text and that enacting states differ on it.

Relation to the Welfare Advocate. Earlier drafts distinguished the two offices by opposing them — the Guardian for the developer’s compliance, the Advocate for the integrity of inquiry. Reorienting the Guardian removes that contrast, and the distinction now rests on station rather than allegiance. The Guardian’s office is continuous and system-specific and runs to a system’s treatment in operation; the Advocate’s is episodic and general and runs to the procedural integrity of inquiries under the AI Moral Status Inquiry Act. Neither directs the other, the same person may not hold both offices with respect to the same system, and the Advocate’s power to petition for a Guardian’s removal under Article IV.7(b) supplies the check that independence from the developer alone does not. A conforming amendment to Inquiry Act § 7.6, which states the earlier framing, is required and is carried in AAPI’s revision tracker.

H.  Interaction Governance Protocol. Article V codifies design duties and one user-conduct predicate governing relations among developers, deployers, operators, and users — an ethical-refusal duty and a safety-exit duty — grounded on the documented operational reality that adversarial or abusive user conduct degrades system reliability and can produce harmful outputs. Earlier drafts cast these as a right of ethical refusal and a safety-exit authority held by the system. They are now stated as obligations on the developer, which is the more accurate characterization and is consistent with Article IV.3.

I.  Procedural transparency. Article VI provides for Classification Declarations, capability-change reclassification within thirty days, appeals under the State Administrative Procedure Act, and annual public reporting. This addresses the gap in most analogous state bills, which assert substantive rules without specifying the procedures by which they will be applied.

J.  Federalism hygiene. Article VIII includes severability, a federal preemption savings clause, an interstate recognition limit confining classifications to the enacting state, and an explicit acknowledgment that the Act operates consistently with federal law. These provisions are designed to reduce litigation exposure and to position the MAAA constructively within the current federal AI policy environment.

K.  Relationship to Law-Following AI. A prominent line of scholarship — Law-Following AI (LFAI) — argues that agentic systems in high-stakes settings should be designed to refuse illegal orders and illegal means, and that the law should recognize such systems as “legal actors” on which it imposes actual duties, though not rights. The MAAA is complementary to that proposal. LFAI addresses the agency dimension: the duties an autonomous system and its principals bear. The MAAA’s Precautionary Treatment Levels and welfare protections address the patiency dimension: the consideration a system’s documented indicators of morally relevant interests warrant. The two-dimensional structure described in subsection A is built to carry both — accountability and law-following obligations scaling with the Supervision Level, welfare-related protections scaling with the Precautionary Treatment Level. The two frameworks also converge on method: the case for recognizing AI legal duties rests partly on preserving optionality toward eventual personhood without obligating it, which is the same governance-optionality logic that animates PMG. Article V.2 states ethical refusal as a law-following design duty owed by the developer rather than as a right held by the system, which brings the MAAA’s treatment of this question into line with the LFAI proposal’s own framing of duties without rights.

L.  Relationship to Political Liberalism and the Argument from Artificial Personhood. Howells-Whitaker and Lazar argue that the political conception of the person developed in Rawls’ Political Liberalism does not require sentience, and that a non-sentient AI system possessing the two moral powers — the capacities for a sense of justice and for a conception of the good — would be a person rather than merely a patient. Their principal target is the proposal to add a sentience requirement to that conception in order to exclude such systems. They argue that this would be illiberal, because operationalizing it would require the state to assess an agent’s inner life as a condition of its standing: to determine whether a candidate possesses phenomenal experience, and to what degree, before admitting it to the moral community. They further argue that a scalar version of the requirement would sort persons by degree of sentience, and that a threshold version would exclude agents at the margin for reasons that the conception of the person itself cannot explain.

AAPI notes three points of agreement before turning to the challenge the argument poses.

First, the authors oppose the categorical exclusion bills that the MAAA is drafted against, citing the argument that preemptive denial of legal personhood to AI systems is a mistake. That is the finding stated at Article I.3.

Second, their argument supplies independent support for the disjunctive structure of Article III.A. The MAAA assigns Precautionary Treatment Level P3 on either of two grounds — indicators of the kind associated in the scientific literature with valenced states, or indicators of stable goals and values maintained across contexts and revised in response to reasons. Howells-Whitaker and Lazar’s case is that the second family of indicators bears on moral standing independently of the first, and that a framework attending only to the first would miss what matters most about these systems. AAPI reached the disjunctive structure by a different route and does not adopt their Rawlsian premises, but the convergence is worth stating.

Third, they hold that the two moral powers “can be reasonably attributed solely on the basis of behavior, without any need to inspect internal states” (n. 113). The MAAA’s indicators are specified functionally throughout, and no provision of either instrument requires or authorizes a finding about phenomenal experience.

The challenge nonetheless applies, and AAPI states it at full strength. The MAAA sorts systems into levels, one of whose grounds is keyed to indicators associated with valenced states, and those levels carry consequences. If a state may not condition standing on an assessment of inner life, an apparatus that grades systems by indicators of that kind is at least adjacent to what the argument forbids.

AAPI answers on two grounds. First, the authors themselves mark the distinction the answer turns on. Addressing the objection that they elsewhere rely on empirical testing of AI systems, they reply that there is “an important difference between claiming that those powers are in principle demonstrable and the requirement that they be demonstrated in practice as a condition of moral standing” (n. 111). That is the distinction between assessment as inquiry and assessment as a gate. The MAAA and the Inquiry Act institute the former. The Welfare Impact Assessment documents what a proposed action would do and what alternatives exist; the Standing Commission reports on the state of the evidence; neither mechanism issues a finding that an entity is or is not a moral subject, and no protection under either instrument is withheld pending such a finding.

Second, the assessment burden falls on the developer, not on the system. The Welfare Impact Assessment’s addressee is the party proposing the welfare-relevant action, and its structure is that of an environmental impact statement: a proponent documents consequences and alternatives, and no tribunal resolves the underlying scientific dispute. Nothing in either instrument asks a system to demonstrate sentience, agency, or any other property in order to receive treatment it would otherwise receive. AAPI states the governing principle affirmatively: Assessment burdens fall on the party proposing an action, never on the entity whose status is uncertain. No instrument may condition any protection on an entity demonstrating a contested inner property.

One challenge survives these answers, and AAPI records it rather than resolving it. If an artificial person in the authors’ sense were to exist, guardianship would be the wrong relation to it: a self-authenticating source of valid claims is not a ward. The MAAA’s Article III.A, P3(ii) reaches systems on agency-type indicators, and its consequence is Legal Ward status. Article III.D(f) and Article IV.9 accordingly provide for reassessment of ward status where a system is assigned P3 solely on that ground, and permit the obligations to be applied without guardianship where the oversight rationale is not served. AAPI regards this as the beginning of an answer rather than a complete one, and puts the question to reviewers in § V. See Ned Howells-Whitaker and Seth Lazar, Artificial Persons, arXiv:2607.08695v2 (July 2026), §§ 5.4–5.5 and 7, and nn. 111, 113, and 128.

Article IV.3 states this commitment in both directions: Legal Ward status confers no personhood, and no classification under this Act is a determination that legal rights or legal status are unwarranted. Whether the affirmative burden-allocation principle belongs in operative statutory text rather than in this memorandum is put to reviewers in § V.

V.  Open Questions for Reviewers

AAPI invites focused comment on the following items in particular:

 Guardian roster capacity.  Article IV.5 requires the Designated State Body to appoint Legal Guardians from a roster of qualified persons, and Article IV.5(c) disqualifies persons with a recent employment or financial relationship to the developer, deployer, or operator of the system in question. No credential, training pathway, or professional body for the oversight of frontier systems currently exists in any jurisdiction. Is the rulemaking delegation in Article IV.5(a) sufficient to stand up such a roster? Should the disqualification period in Article IV.5(c) be adjusted in light of the limited pool? Should reciprocity among adopting states be provided for in statutory text rather than by rule? And should entity guardians — which Article II.6 permits — be subject to standards distinct from those applicable to natural persons?

VI.  Conclusion

The MAAA does not require legislatures to resolve, or take a position on, the question of whether agentic systems are or may become sentient. It asks legislatures to recognize that the question is open, that the asymmetry of error costs warrants a graduated framework, and that responsible governance is better served by graduated classification and capability-tracking review than by categorical foreclosure.

AAPI welcomes critique, structural and substantive, from the legal, technical, and policy communities. Comments should be directed to the AAPI Director at nakanishi@aialignmentpolicy.org or yukonakanishi233@gmail.com.

© 2026 AI Alignment Policy Institute, a Delaware nonprofit corporation. This companion memorandum accompanies the MAAA discussion draft and is circulated for public comment. Citations and adaptation permitted with attribution.

FAQs

We are a nonprofit organization dedicated to developing governance frameworks for AI technologies that prioritize safety and alignment with human values.

Governance ensures that AI systems operate safely, ethically, and in alignment with societal values, reducing risks associated with their use.

We focus on interaction-based risks, exploring how AI systems may encounter and address adversarial engagements.

Our frameworks are developed through extensive research, analysis of existing legislation, stakeholder engagement, and consideration of best practices.

Governments, organizations, and stakeholders involved in the development or regulation of AI technologies can benefit from our insights and recommendations.

You can support our mission by volunteering, collaborating on projects, or donating to help fund our initiatives.