There is a contradiction at the centre of the agentic age.
The most useful personal artificial intelligence is one that knows me well.
It should know what I am working on, whom I work with, what I have promised, what I prefer, what I have already decided, what happened yesterday and what will probably matter tomorrow. I should not need to explain myself from the beginning every morning. I should not have to provide the same biography, preferences, constraints and working context to fifty different assistants embedded inside fifty different applications.
Human relationships become easier in part because context accumulates. We do not reintroduce ourselves to an old friend every time we meet. We do not explain our entire professional history to a long-standing colleague before asking a question. The relationship itself carries memory.
Personal artificial intelligence is beginning to acquire the same property.
And that creates the contradiction.
Because the safest architecture is probably not one in which the same machine that remembers everything about me is also allowed to see every bank account, every medical record, every employer system, every government interaction, every credential and every decision that affects my life.
Convenience pulls toward concentration.
Sovereignty pulls toward separation.
The interesting question is what happens when both forces win.
Two earlier volumes already sit behind this. The Last Interface asked what happens when software stops owning the relationship with its user, and people bring an existing agent to the product instead. Human Sovereignty asked what remains ours when machines remember, decide and act, and answered that delegation can preserve sovereignty when authority stays bounded and recoverable. There is a question between those two arguments that I had not examined closely enough. If the personal agent becomes the interface through which I reach much of the digital world, does that agent eventually need to contain that world? I do not think it does. I increasingly think the more credible architecture is almost the opposite. One agent to the human. Many sovereignties underneath.
Evidence before prediction
It is easy to write about AI agents as if their arrival were inevitable.
It is not.
The technology remains unreliable in important ways. Standards are still forming. Many demonstrations are easier than production systems. Consumer trust is unresolved. Business models remain uncertain. Much of what is described as agentic today is still carefully bounded automation.
So before predicting an architecture, it is worth looking at what can actually be observed as of 31 August 2026.
The large consumer platforms are making assistants more personal and persistent. On 8 June 2026 Apple previewed Siri AI with personal context across messages, email and photos, search across apps, and conversation history synchronised across its devices. The features were in developer testing at announcement. As of 25 August Apple still described Siri AI as a beta later this year, for a supported device set to English, currently available through the Apple Beta Software Program. Apple’s event on 9 September is likely to name when the public version-27 systems arrive. That would still be a date for a Siri AI beta, not for a finished production assistant. On 14 January 2026 Google introduced Personal Intelligence for Gemini, connecting Gmail, Photos, YouTube and Search. The connections are off by default, and the launch was for eligible U.S. AI Pro and AI Ultra subscribers, not the free tier and not Workspace. OpenAI's Memory FAQ, updated on 15 August 2026, says memory draws on chats, files, and connected apps. Microsoft 365 Copilot can retain a person's job role, work, common tasks and preferences; the current support article was updated on 18 August 2026. Google has also begun importing memories and chat history from other AI products into Gemini: memories by paste, history by ZIP. The 26 March 2026 launch was not available in the EEA, the UK or Switzerland, and it is not a cross-vendor API. It is still an early acknowledgement that accumulated context is becoming a switching asset.
Agents are also being given more ways to act. Microsoft first announced Windows 365 for Agents on 18 November 2025 and took the product to general availability in the week of 1 June 2026: pooled, stateless Cloud PCs, distinct identities, Zero Trust controls and audit. OpenAI's ChatGPT agent, introduced on 17 July 2025, combined a visual browser, a text-based browser, a terminal and direct API access. OpenAI now labels that launch page outdated. It remains useful as architectural evidence, not as a description of the current product.
Interoperability infrastructure is developing beside the products. Anthropic transferred the Model Context Protocol to the Linux Foundation's Agentic AI Foundation on 9 December 2025 and reported more than 10,000 active public MCP servers at the time. The Linux Foundation reported on 9 April 2026 that the A2A protocol had more than 150 organisations supporting it. Production deployments, described separately, already span financial services, insurance, supply chain and IT. On 17 June 2026 Google's Developers Blog announced Agentic Resource Discovery, a specification for publishing, finding and verifying tools, skills and other agents across the web. Identity and authorisation are being treated as engineering problems in their own right. NIST launched an AI Agent Standards Initiative on 17 February 2026: a programme, not a finished standard. On 5 February 2026 it published an Initial Public Draft, Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization. Microsoft's Agent 365 documentation, dated 10 August 2026 and updated on 13 August, represents agents as distinct Entra identities with permissions, sponsors, lifecycle management and audit. The OpenID Authorization API 1.0 became a Final specification in January 2026, with the specification published on 11 January and membership approval on 12 January. AuthZEN working-group drafts of 15 June 2026 address approval, consent and delegated authority; they are drafts, not Final, and policy remains the ultimate authority. An individual Internet-Draft, draft-mishra-oauth-agent-grants-02, published on 30 August 2026, describes an OAuth profile for identifying an AI agent, obtaining human consent, issuing resource-bound and sender-constrained tokens, and attenuating authority as it moves onward. It is not Working-Group-adopted. It is work in progress. Its importance here is not that this particular draft will win. It is that the problem it attempts to solve now exists clearly enough to be written down.
Compute is moving closer to the user. Apple's 25 August 2026 announcement of the M6 and M5 Ultra positions new silicon for local models. The M6 is described as running on-device LLMs for secure and private agentic tasks, with up to 32GB of unified memory. The 512GB of unified memory, and the claim that huge LLMs with hundreds of billions of parameters can run entirely on device, belong to the M5 Ultra; those figures are Apple-tested. Qualcomm, on 5 August 2026, described Snapdragon X PCs as a practical compute node for agentic experiences. That is a vendor claim. NVIDIA markets DGX Spark as a Desktop Agent Computer, with 128GB of memory and models of up to 200 billion parameters in its current product copy. Xiaomi is building more than one piece. MiClaw, announced to developers on 21 April 2026, is an invitation-only agent ecosystem, not general availability, into which developers can upload MCP servers, skills and agents. In June it unveiled Miloco 2.0, also called Xiaomi Local Copilot 2.0, for home intelligence. In August, with the HyperOS 4 beta, it introduced Hyper XiaoAi 2.0, described as moving from understanding instructions to getting things done.
The economic rails are changing too. Google's Universal Commerce Protocol, launched on 11 January 2026 and co-developed with Shopify, Etsy, Wayfair, Target and Walmart, names A2A, AP2 and MCP among the ways commerce can be exposed to agents. Stripe's Machine Payments Protocol, published on 18 March 2026, is designed so an agent can request and pay for an API, an MCP endpoint or another network resource programmatically. On 28 May 2026 Mastercard reported the first agent-based retail transaction in Switzerland, carried out with Cembra, Cornèrcard and Viseca under explicit user consent and authentication. A separate 2 March test with Santander used live European payments infrastructure inside predefined limits and permissions; it was not a commercial rollout. Network enablement of Mastercard issuers in Europe, announced on 2 June, is not the same as a customer-facing product.
None of these facts proves that one particular future will occur.
Together they describe something more substantial than another generation of chatbots.
We are building the components of an environment in which artificial agents can remember people, discover capabilities, identify themselves, receive bounded authority, communicate with other agents, operate old interfaces, call new ones and transact economically.
The question is no longer whether the pieces exist.
The question is how they should fit together.
The strongest evidence came from somewhere unexpected
Perhaps the most interesting validation of this direction does not come from an AI company at all.
On 9 March 2026 the UK Competition and Markets Authority published an analysis of agentic AI and consumers.
It is careful about tense. Most implementations, it says, are relatively bounded and cautious, particularly in consumer-facing contexts. In the near term it sees, as a possibility, more integrated personal assistants coordinating activity across multiple services within clear boundaries. Persistent personal agents — systems that might manage longer-term goals, keep learning context and preferences, and act across platforms and markets — are a longer-term possibility, and highly uncertain.
The paper then uses language close to the architectural change at issue here. If and when agentic systems become more capable, consumers may move from using apps to managing outcomes.
It also identifies a corresponding competition problem. If people cannot move preferences, context and agent memory between providers, or if their agents cannot move across ecosystems, the agent layer itself may become a new source of lock-in. Data mobility, digital identity and interoperability are described as wider enablers of a competitive agentic market. Portability, specifically, is called a structural condition.
That does not make the future certain.
It does mean the same architecture is now visible from three directions: platform companies trying to build personal intelligence, standards communities trying to connect autonomous systems, and a competition authority asking what happens if those systems become intermediaries to markets.
That convergence is difficult to dismiss as a single vendor's product story.
The expensive part is starting over
Why should people converge on a primary agent at all?
Because context has compounding value.
An assistant that has known someone for three years can potentially understand a request that would require a newly introduced assistant to ask ten questions.
“Move the meeting with Viktor because I need the afternoon for the review.”
A mature personal agent may already know which meeting, which Viktor, which review, which calendar matters, who needs to be informed, whether moving it will create a conflict, how formal the message should be and whether something should happen before the meeting is moved.
A new assistant sees a sentence.
The established agent sees a life around the sentence.
This is not speculative functionality in every detail, but the direction is visible in product design. Apple, Google, OpenAI and Microsoft are all increasing the persistent personal context their assistants can use. Google is already treating imported AI memory as something worth helping users migrate.
Every application-specific assistant begins with a disadvantage.
It knows its application.
The personal agent knows the person.
That does not make the specialist assistant useless. It may know vastly more about a particular domain. But that suggests a different relationship between them.
The personal agent should not necessarily replace the specialist.
It should know when to call it.
One relationship does not require one trust domain
This is where the idea of the universal super-agent begins to break down.
Imagine a personal agent that genuinely knows almost everything relevant about someone.
It reads their communication. It manages their diary. It knows their family relationships. It remembers their projects. It can purchase things. It can access work systems. It understands their financial position. It can read medical records. It can interact with government systems. It holds credentials for hundreds of services.
There is an obvious convenience to this architecture.
There is also an obvious security problem.
A compromise is catastrophic. A badly scoped permission is catastrophic. A malicious instruction hidden in a document may suddenly operate in a context containing the person's entire digital life. A vendor policy change affects everything. A jurisdictional problem affects everything. A model error has access to everything. And leaving becomes unimaginably difficult.
OWASP's Top 10 for Agentic Applications 2026 already names Agent Goal Hijack, Tool Misuse and Exploitation, Identity and Privilege Abuse, and Agentic Supply Chain Vulnerabilities among the risks created when agents can act on external systems. NIST's identity work begins from the same place: the risks of granting agents access to diverse data, tools and applications.
Security architecture has spent decades teaching us not to construct systems this way.
Why would artificial intelligence make least privilege obsolete?
It should make least privilege more important.
A federation of intelligence
A more plausible architecture keeps one relationship with the human and several trust domains underneath. Personal services, employer systems and sovereign sensitive services can remain isolated from one another, linked only by narrow, controlled connections.

The personal agent owns the relationship.
It does not own every domain.
The employer can retain its own identity, permissions, records and audit requirements.
A bank or financial adviser can retain financial information inside infrastructure appropriate to that domain.
A medical system can enforce different disclosure and consent rules again.
A government can expose only those actions for which it is prepared to accept machine delegation.
The general agent's function is not to absorb every specialist system.
It is to understand enough about the human and the available world to orchestrate them.
That is a very different architecture from one AI with root access to life.
It is a federation.
The financial adviser that does not hand over your finances
Consider a concrete example.
A person has a primary personal agent.
That agent knows that they are considering buying an apartment. It knows their general goals. It knows that they dislike excessive financial concentration and that liquidity matters to them. It may know when the decision needs to be made and what questions usually matter before a large commitment.
But it does not contain their complete financial history.
Their detailed financial information sits somewhere else.
Perhaps the person has a sovereign financial-adviser agent operated on infrastructure in Switzerland. The portfolio records, transaction history, tax information, liabilities, risk mandate and other sensitive data stay inside that environment. The models used for the most sensitive analysis may run there as well.
Now the person asks:
“Can I afford this without becoming too exposed to Swiss property?”
The personal agent does not need to request the entire portfolio.
It needs to request a judgement.
It could ask the financial agent to assess the proposed acquisition against the client's current portfolio, liabilities, and agreed liquidity and concentration constraints; to return the conclusion and the reasoning needed to explain it; to disclose only that; to execute nothing; and to expire the delegation after the analysis.
The sovereign financial agent performs the work where the sensitive data already lives.
It might return:
The acquisition is affordable under the current stress assumptions, but property concentration would exceed the client's preferred range. Liquidity remains sufficient but falls close to the minimum reserve under the downside scenario. Consider either reducing the acquisition size or increasing liquid reserves before completion.

The personal agent receives what it needs to continue the conversation.
It does not automatically receive every security position, account balance, tax document and historical transaction that produced the conclusion.
This is delegation instead of disclosure.
Not absolute non-disclosure. Some workflows genuinely require information to cross boundaries.
But the default changes.
Instead of asking how to give a personal agent all the information it could ever need, we ask what minimum information and authority this particular task requires.
That is an old security principle applied to a new form of intelligence.
And in regulated finance there are good reasons to care. FINMA's survey of Swiss financial institutions, published on 24 April 2025, recorded uptake of generative AI alongside concerns about data quality, data protection, explainability, outsourcing and growing dependence on large technology providers. Those concerns do not themselves prescribe a sovereign-agent architecture. They explain why blindly concentrating regulated context in a general external assistant is unlikely to be acceptable everywhere.
Switzerland is also developing some of the infrastructure from which alternatives could emerge. On 24 July 2026 ETH Zurich, EPFL and CSCS released Apertus 1.5 as part of a longer-term effort toward sovereign AI infrastructure and an open alternative to proprietary models.
The point is not that every financial agent must run Apertus.
The point is that model jurisdiction, data jurisdiction and agent jurisdiction can become independent architectural choices.
Delegation needs a grammar
For this federation to work, agents need more than network connectivity.
They need a grammar of authority.
A useful request has to say who the human is, which agent is acting, and which organisation operates it. It has to say what the human has authorised, which resource may be touched, and which actions are allowed. It has to say whether the agent can delegate further, and whether that next agent can gain more authority than the first possessed. It has to say when the authority expires, which actions need another confirmation, what happened afterwards, who can revoke access, and who carries responsibility when something goes wrong.
This is why some of the most consequential infrastructure of the agentic age looks boring: OAuth scopes, identity objects, policy engines, audit logs, resource indicators, consent, approval, revocation and transaction records.
Microsoft's Agent 365 already treats an agent as a distinct identity with its own permissions and a human sponsor accountable for its lifecycle. OpenID AuthZEN is working on interoperable patterns for situations in which an action requires consent, approval or delegated authority before policy will permit it. Even current IETF work is focusing on attenuation: if an agent delegates a task onward, the delegated authority should not silently become broader.
These are not glamorous problems.
They are the difference between an AI demonstration and a system to which we can responsibly delegate parts of our lives.
The protocol stack is beginning to appear
No single standard currently defines this architecture, and it would be foolish to assume today's names will all survive.
But the layers are becoming easier to see.
MCP addresses the relationship between an AI application and external capabilities, resources and tools.
A2A addresses communication between agents.
ARD addresses discovery and verification: where a capability lives, which one an agent should choose, and how it can verify what it is connecting to.
OAuth, agent identity systems and emerging authorisation standards address who is acting and under which authority.
UCP, the Machine Payments Protocol and payment-network infrastructure begin to address economic activity initiated by agents.
Browser and computer-use systems provide a bridge to software that was never designed for any of this.
That does not yet constitute a complete internet for agents.
But it looks increasingly like the beginning of one.
And the most important feature of such a stack is not that machines can talk to machines.
Machines have done that for decades.
The difference is that these machines increasingly act for someone.
That makes authority the central problem.

The browser becomes a compatibility layer
Agent-native software will not replace the existing software estate overnight.
There are decades of applications that expose no suitable API, no MCP server and certainly no agent-to-agent interface.
This is why computer-use systems matter. Grok Bot is one example of an agent receiving its own computer, browser and terminal. Microsoft's Windows 365 for Agents takes a more enterprise-governed version of the same idea, providing stateless Cloud PCs tied to agent identities and policy.
The transition will have two tracks.
New software will increasingly expose machine-native capabilities directly.
Old software will remain usable because agents can operate the interfaces originally intended for humans.
The GUI does not disappear.
It loses its monopoly.
Intelligence moves toward the edge
The second large change is physical.
For most of the current generative-AI era, powerful inference has meant sending work to a remote data centre.
That assumption is weakening.
Apple's M6 supports local LLM execution for secure and private agentic tasks. The M5 Ultra, in Apple's testing, can provide up to 512GB of unified memory and run LLMs containing hundreds of billions of parameters entirely on device. Qualcomm is marketing PC hardware as a practical compute node for agentic experiences. NVIDIA describes DGX Spark as a Desktop Agent Computer for local autonomous agents.
The software abstraction is changing too.
Apple's 2026 Foundation Models framework introduced a LanguageModel protocol capable of using different local or server-side models behind the same application interface. Apple showed its own on-device and Private Cloud Compute models, local models through Core AI and MLX, and a path for third-party providers. Anthropic now documents a beta Claude package for Apple's Foundation Models, aimed at the OS 27 betas. Google's Gemini package remains an announcement.
Apple's own foundation-model architecture is already hybrid: smaller and larger models run on-device, while more demanding models can run through Private Cloud Compute. Agentic tool use is named for AFM 3 Cloud Pro, not for the on-device AFM 3 Core.
Xiaomi is moving in a similar direction at more than one layer. MiClaw, still invitation-only, lets developers publish MCP capabilities, skills and agents. Local Copilot 2.0 explores proactive intelligence inside the home. Hyper XiaoAi 2.0, in the HyperOS 4 beta, is the operating-system assistant: from understanding instructions toward getting things done.
This makes a hybrid future increasingly plausible. Small, frequent and private work can run on the device. Larger general reasoning can run in cloud models. Regulated or highly sensitive tasks can remain inside sovereign infrastructure. Specialist deterministic computation can stay inside domain systems. The personal agent decides which form of intelligence belongs where.
The agent therefore becomes conceptually separable from the model.
The model is one of the resources the agent can use.
That separation is the point.
Local is not sovereign
There is a temptation to equate local AI with sovereign AI.
We should resist it.
A model can run entirely on a device while the operating system vendor still determines which model runs, what it may access, how it is updated, what permissions it receives and whether another model may replace it.
Local execution improves latency, privacy, availability, the economics of repeated inference, and resistance to some forms of cloud dependency.
But sovereignty asks a larger set of questions. Can the person choose the model? Move the memory? Move the agent's identity? Export the accumulated context? Transfer its permissions and service relationships? Run it on infrastructure they control? Let another implementation assume its role? Revoke the old one and continue functioning?
Apple's new Foundation Models abstraction is interesting because it moves application development toward interchangeable models. It is not the same thing as Apple allowing a user to replace the system agent itself.
Bring Your Own Model is not yet Bring Your Own Agent.
And Bring Your Own Agent is not yet human sovereignty.
Software after the application
If people increasingly approach the digital world through a primary agent, software changes shape.
Today we usually think about a software product through its interface: a dashboard, a navigation menu, a project view, a checkout page, a configuration screen, a support area. The underlying domain logic is present, but the human interface is the visible product.
To an agent, the useful representation may be entirely different: list the outstanding invoices, calculate the tax implication, book the available journey, create the project, compare the insurance policies, run the simulation, cancel the subscription, retrieve the evidence, execute the payment within a CHF 500 limit.
The agent does not necessarily need the page.
It needs the capability.
Google's Universal Commerce Protocol is already designed so commerce can be exposed through A2A, AP2 or MCP rather than requiring every agent to reconstruct a human checkout journey. Stripe's Machine Payments Protocol exists because account creation, pricing pages, subscription selection and manual payment entry are friction designed for human users rather than machines.
The significance is not that everybody will allow an AI to buy everything tomorrow.
It is that software is acquiring an economic interface for non-human users acting under human authority.
That is a different kind of customer.
From application economy to delegation economy

For roughly four decades, digital businesses competed intensely to become places people went: visit the website, install the application, create an account, learn the navigation, build the workflow, invite colleagues, store the history, come back tomorrow.
This created what might be called an application economy. The software provider usually controlled both the capability and the path through which the human reached it.
A personal-agent architecture separates those things. The human may have one primary place where intent is expressed. Everything underneath competes to satisfy that intent.
That is closer to a delegation economy.
And it changes several parts of the software industry at once.
A company can provide an excellent capability without necessarily owning the customer's interface. Suppose someone tells their agent to find an accounting platform for a Swiss SME, with data staying in Switzerland, an audit trail, payroll integration, complete export, an API the accountant can use, and a ceiling of CHF 150 a month. The agent may inspect ten services. The human may see three. Seven vendors may never receive a website visit. That changes distribution. The future equivalent of search visibility may include whether an agent can discover a service, determine what it does, verify its claims, understand its jurisdiction, inspect its price and determine whether it can safely connect. Google's ARD proposal exists because this discovery problem is already becoming visible. Marketing does not disappear. Part of marketing becomes machine-readable.
Today's onboarding processes are partly exercises in reconstructing information that may already exist elsewhere. An established personal agent may already know much of it. That does not mean it should silently provide all of it. The better onboarding interaction is closer to: connect the agent, review the requested scopes, choose what may be shared, authorise, continue. The important interface is no longer merely the profile form. It is the boundary of delegation.
This does not make specialist software less valuable. It may make genuinely specialist software more valuable. If the human no longer cares deeply where the button is located, interface familiarity, habitual navigation, artificial complexity and ownership of attention become weaker advantages. Unique data, domain expertise, deterministic calculations, regulatory acceptance, reliability, auditability, price, jurisdiction, security, interoperability and trust become stronger ones. The question becomes less which application the user enjoys operating, and more which capability the user's agent is prepared to trust. That is a harsher market in some ways. A polished interface can hide mediocre infrastructure from a human for a surprisingly long time. An agent comparing structured capabilities may be less sentimental.
Seat pricing makes intuitive sense when one person spends their working day inside one product. It becomes stranger when that person's agent invokes a capability four times this month and never opens the application. Machine-payment infrastructure points toward different economic units: per request, per transaction, per analysis, per unit of compute, per successful outcome, per bounded workflow. Stripe describes agents as a new category of users to build and sell to, and its Machine Payments Protocol already supports programmatic payments for resources and services. That does not mean subscriptions disappear. The unit of value can still move closer to the capability.
Customer support changes as well. Today a person discovers a problem, explains it to a support interface, supplies diagnostic information, receives instructions and performs the remediation. In an agentic environment, the customer's agent may know the error before the customer does. It may contact the vendor's support capability. The two systems can exchange structured diagnostic state. The vendor agent can request a narrowly scoped log. The customer agent can approve disclosure. The vendor can propose remediation. The customer agent can apply it if authorised. The person becomes involved when judgement is required. This is one of the less glamorous consequences of agent-to-agent systems. It may also be one of the most economically important.
Identity becomes part of the product
Once agents can act, identity can no longer remain an internal security detail.
A service may need to know that this is Thierry; that this is not Thierry; that this is Thierry's personal agent; that this is an employer-operated agent acting for Thierry in a work context; that this is a financial agent with a separate mandate; that this particular request was delegated; that this particular payment was explicitly approved; that this authority expires tonight; that this agent may read but not modify; that this agent may propose but not execute.
Microsoft is already modelling agent identities separately from human identities and recording the acting identity and token subject in audit logs. NIST is treating identification, authorisation, auditing and non-repudiation as core agent infrastructure questions. Switzerland delayed the e-ID on 30 June 2026, with the trust infrastructure still aimed at the first half of 2027. The rails for proving who is acting are not all in place.
Identity therefore stops being merely login.
It becomes part of the semantics of delegation.
The new separation of powers
There is a deeper principle underneath this architecture.
We should probably not allow the same agent to be the keeper of all memory, the source of all policy, the holder of all credentials, the judge of what may be done, the executor of every action, and the auditor of its own behaviour.
States eventually learned not to concentrate every form of power in one institution.
Computer security learned the same lesson in a different language: separation of duties, least privilege, independent audit, trust boundaries, dual control.
Agents do not repeal these principles.
They give us another reason to remember them.
The primary personal agent can represent intent without holding every secret. A specialist agent can hold domain knowledge without controlling the entire user relationship. A policy system can decide whether an action is allowed without generating the action itself. A payment network can authenticate a transaction without becoming the financial adviser. An audit system can record what occurred without being able to change the event afterwards.
The human remains above the federation only if these separations remain understandable and revocable.
The largest concentration risk moves upward
There is still a danger.
Even if the personal agent does not contain every sensitive dataset, it occupies an extraordinary position.
It sees intent before almost anyone else does.
It learns that someone is thinking about changing jobs before the recruitment platform knows. It learns that they are considering a house before the property portal knows. It learns that they are unhappy with a bank before the competing bank knows. It knows what products they are considering before the merchant sees a visit. It knows which information they rejected. It knows whom they trust. It knows which arguments changed their mind. It may decide which specialist service receives the next request.
This is more than personalisation.
It is allocation power.
Browsers became gateways to the web. Search engines became gateways to information. Mobile operating systems became gateways to applications. The personal agent may become a gateway to human intent.
That is why the contest among Apple, Google, OpenAI, Microsoft and others cannot be understood only as a contest over model intelligence.
The more valuable position may be the relationship layer above the models.
The agent through which a person reaches everything else.
The CMA's concern about interoperability at the agent layer is therefore not abstract. It argues that innovation should remain possible at the service layer rather than being determined by control of the agent layer itself.
That may become one of the most important competition-policy questions of the next decade.
Memory may become the strongest moat of all
A software subscription can be cancelled. Files can often be exported. A database can be migrated with enough effort.
What does it mean to migrate ten years of an agent relationship?
Not merely ten years of transcripts. Ten years of corrected misunderstandings, preferences, exceptions, relationships, decisions, working habits, vocabulary, delegations, trusted institutions, patterns the user never explicitly wrote down, and knowledge about what matters and what does not.
This is why agent portability is more complicated than data portability.
Google's ability to import memories and histories from other AI products is a useful early signal. It recognises that moving AI systems should not necessarily require starting from zero.
But true portability will require more than importing chat archives. It may eventually need to include memory, identity, permissions, service relationships, delegation history, preferences, policies, artifacts, and perhaps enough operational state for another agent to continue the relationship without reconstructing the person from raw history.
The right to leave an agent may become as important as the right to choose one.
What true Bring Your Own Agent would require
Bring Your Own Agent is easy to say.
The serious version is demanding.
A person should be able to choose which intelligence represents them. That agent should be able to discover compatible services. Services should be able to verify the agent's identity and delegated authority. The person should be able to define which domains the agent may access. Sensitive systems should be able to remain sovereign while still participating. Authority should narrow, not expand, when delegated onward. Important actions should remain attributable. High-consequence operations should trigger appropriate confirmation. The user should be able to revoke the agent. And another agent should be capable of assuming its role without the person's accumulated digital life becoming unusable.
Only then does Bring Your Own Agent become more than another integration feature.
It becomes an architecture of choice.
Where this thesis could be wrong
There are several ways this future may fail to materialise.
Agents may remain too unreliable for broad delegation. The CMA itself stresses that long-term autonomous personal agents remain uncertain and that current deployments are predominantly bounded.
Consumers may prefer multiple visible agents and keep strong mental separation between work, finance, family and entertainment.
Security failures may cause organisations to restrict agent access rather than expand it.
The major ecosystems may deliberately prevent interoperability because controlling the personal-agent layer is too valuable to surrender.
Standards may fragment.
Authorisation may remain too complicated for ordinary consumers.
Local inference may improve dramatically while still remaining controlled by the device manufacturer.
Specialist agents may prove economically unnecessary in many domains because secure tool access to deterministic systems is sufficient.
Regulation may restrict autonomous activity in precisely the sectors where sovereign specialist agents would otherwise be most valuable.
And the personal-agent relationship may itself turn out to be less durable than expected. People may switch between intelligence providers as casually as they switch search engines.
A prediction becomes more useful when we know what evidence would prove it wrong.
For this thesis, I would watch five things: whether users actually accumulate long-lived agent relationships; whether memory becomes meaningfully portable; whether agents reliably execute multi-service tasks; whether open interoperability survives platform competition; and whether delegated identity and authorisation become usable outside technical environments.
If those five conditions fail, the federation described here may remain an attractive architectural idea rather than the dominant form of computing.
But the direction is becoming visible
For now, the evidence points somewhere interesting.
The personal AI systems are becoming more contextual. The standards are becoming more interoperable. The hardware is becoming more local. The software interfaces are becoming more machine-readable. The authorisation systems are becoming more explicit. The payment infrastructure is becoming capable of recognising machine actors. And regulators are beginning to ask what happens when an AI becomes the intermediary between a person and a market.
These developments are coming from different organisations with different interests.
That makes their convergence more meaningful.
They suggest that the next phase of artificial intelligence may not be defined by one more capable chatbot inside every application.
It may be defined by a new division of labour.
The personal agent knows the human. The specialist agent knows its bounded domain. The software provides authoritative capabilities. The model provides intelligence. The policy system provides constraints. The identity system proves who is acting. The payment system moves value. The human provides purpose and retains the authority to say no.
One agent, many sovereignties
We often imagine the future of artificial intelligence as a problem of accumulation.
The model becomes larger. The context window becomes larger. The agent receives more tools. More data enters memory. More permissions are granted. More of life is pulled into one system.
Perhaps that is not the mature architecture.
Perhaps maturity arrives when intelligence becomes capable enough to not require everything in one place.
My personal agent does not need to become my bank.
It needs to know how to speak to the institution I trust with my money.
It does not need to contain my employer.
It needs to understand when a request belongs inside my employer's boundary.
It does not need my entire medical history.
It needs to know when a medical question should be handed to a system that legitimately has it.
It does not need to own every model.
It needs to know which model is appropriate.
It does not need to replace every application.
It needs to know which capability to invoke.
This creates an architecture that looks surprisingly human.
We maintain relationships with different institutions because they hold different forms of trust.
Our doctor does not need our source-code repositories.
Our accountant does not need our medical imaging.
Our employer does not need our private correspondence.
Our friend does not need our tax return in order to know us well.
Context is distributed.
Trust is distributed.
Authority is distributed.
Yet the person remains one person.
Artificial intelligence may eventually work the same way.
One relationship can sit at the centre without one system containing the whole.
The future of AI may not be one machine that knows everything about us.
It may be one machine that knows enough about us to know which other machine should be trusted with the rest.
And if that architecture holds, the transition ahead is larger than the arrival of AI assistants.
We are moving from an application economy toward a delegation economy.
The central question will no longer be only which software we use.
It will be which intelligence may act for us, which institutions may know what, and how easily we can take that authority back.
That is not merely a question about artificial intelligence.
It is a question about sovereignty.
Sources
Research reviewed through 1 September 2026. Primary sources and institutional material are preferred. Emerging standards are identified as drafts where applicable. Vendor pages are labelled as vendor where the claim is the company's own.
Thierry Gilgen — The Last Interface, Vol. 27 (15 August 2026). Earlier Library argument for Bring Your Own Agent, machine-callable software, capability-first architecture, agent portability and the emerging concentration of power above applications.
Thierry Gilgen — Human Sovereignty, Vol. 28 (16 August 2026). Establishes the Library's underlying sovereignty framework: delegation can preserve sovereignty when it remains bounded, attributable, revocable and recoverable.
UK Competition and Markets Authority — Agentic AI and consumers (9 March 2026). Institutional source for the central thesis, quoted with its own hedges. Persistent personal agents are a longer-term possibility, highly uncertain. If and when agentic systems become more capable, consumers may move from using apps to managing outcomes. Data mobility, digital identity and interoperability are wider enablers. Most implementations are relatively bounded and cautious. https://www.gov.uk/government/publications/agentic-ai-and-consumers/agentic-ai-and-consumers
Apple — Apple introduces Siri AI (8 June 2026). Vendor. Personal context across messages, email and photos; search across apps; conversation history across devices; developer testing at publication. https://www.apple.com/newsroom/2026/06/apple-introduces-siri-ai-a-profoundly-more-capable-and-personal-assistant/
Apple — Mac mini with M6 and M5 Pro (25 August 2026). Vendor. Footnote: Siri AI currently available for testing through the Apple Beta Software Program; will be available with macOS 27 as a beta later this year for a supported device set to English. https://www.apple.com/newsroom/2026/08/apple-unveils-a-more-powerful-mac-mini-featuring-the-all-new-m6-and-m5-pro/
Apple Developer — Surprise and shine (26 August 2026). Vendor. Apple Event, 9 September 2026, 10 a.m. PT. Does not name an iOS 27 or Siri AI ship date. https://developer.apple.com/news/?id=s6spdug0
Google — Gemini introduces Personal Intelligence (14 January 2026). Vendor. Gmail, Photos, YouTube and Search; off by default; launch for eligible U.S. AI Pro and AI Ultra subscribers, not free, not Workspace. https://blog.google/innovation-and-ai/products/gemini-app/personal-intelligence/
OpenAI — Memory FAQ (updated 15 August 2026). Vendor. Memory draws on chats, files, and connected apps. https://help.openai.com/en/articles/8590148
Microsoft — Manage Copilot Memory in Microsoft 365 Copilot (support.microsoft.com; ms.date 8 July 2026, updated 18 August 2026). Vendor. Job role, work, common tasks and preferences. https://support.microsoft.com/en-us/microsoft-365-copilot/manage-copilot-memory-in-microsoft-365-copilot
Google — Make the switch: Bring your AI memories and chat history to Gemini (26 March 2026). Vendor. Memories via paste; history via ZIP. Not EEA/UK/CH. Not a cross-vendor API. https://blog.google/innovation-and-ai/products/gemini-app/switch-to-gemini-app/
Anthropic — Donating the Model Context Protocol and establishing the Agentic AI Foundation (9 December 2025). Vendor reporting, with Linux Foundation stewardship. Anthropic reported more than 10,000 active public MCP servers. https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation
Linux Foundation — A2A Protocol surpasses 150 organisations (9 April 2026). Institutional. More than 150 organisations supporting the standard. Production deployments are a separate claim, spanning financial services, insurance, supply chain and IT. https://www.linuxfoundation.org/press/a2a-protocol-surpasses-150-organizations-lands-in-major-cloud-platforms-and-sees-enterprise-production-use-in-first-year
Google Developers Blog — Agentic Resource Discovery specification (17 June 2026). Vendor / open spec. Announcement on developers.googleblog.com. https://developers.googleblog.com/en/announcing-the-agentic-resource-discovery-specification/
NIST — AI Agent Standards Initiative (17 February 2026). Institutional. A programme, not a finished standard. https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure
NIST NCCoE — Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization (5 February 2026). Institutional. Initial Public Draft. https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd
Microsoft — Agent 365 identity (ms.date 10 August 2026; updated 13 August 2026). Vendor. Distinct Entra identities with permissions, sponsors, lifecycle controls and audit. https://learn.microsoft.com/en-us/microsoft-agent-365/developer/identity
OpenID Foundation — Authorization for the agent era: AuthZEN Working Group drafts (15 June 2026). Institutional. Working Group drafts, not Final. Policy remains the ultimate authority. https://openid.net/openid-foundation-advances-authorization-for-the-agent-era-with-new-authzen-working-group-drafts/
OpenID Foundation — Authorization API 1.0 Final Specification (membership approval 12 January 2026; specification published 11 January 2026). Institutional. Status: Final. https://openid.net/authorization-api-1-0-final-specification-approved/
IETF Internet-Draft — OAuth Profile for Delegated AI Agent Authorization, draft-mishra-oauth-agent-grants-02 (30 August 2026). Individual Internet-Draft, not Working-Group-adopted; work in progress. Human consent; resource-bound and sender-constrained tokens; attenuation. https://datatracker.ietf.org/doc/draft-mishra-oauth-agent-grants/
OWASP GenAI Security Project — Top 10 for Agentic Applications 2026 (Version 2026, December 2025). Institutional. ASI01 Agent Goal Hijack; ASI02 Tool Misuse and Exploitation; ASI03 Identity and Privilege Abuse; ASI04 Agentic Supply Chain Vulnerabilities. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
Grok Bot — Introducing Grok Bot (11 August 2026). Example of an agent receiving its own computer, browser and terminal.
OpenAI — Introducing ChatGPT agent (17 July 2025). Vendor. Visual browser, text-based browser, terminal, direct API access. The launch page is labelled outdated; used here as architectural evidence only. https://openai.com/index/introducing-chatgpt-agent/
Microsoft — Windows 365 for Agents (first announced 18 November 2025; general availability week of 1 June 2026). Vendor. Pooled, stateless Cloud PCs with distinct identities, Zero Trust controls and audit. https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-for-agents-unlocks-secured-scalable-ai-automation/4468107
Apple — M6 and M5 Ultra (25 August 2026). Vendor; performance figures are Apple-tested. M6: on-device LLMs for secure and private agentic tasks, up to 32GB unified memory. M5 Ultra only: up to 512GB unified memory and huge LLMs with hundreds of billions of parameters entirely on device. https://www.apple.com/newsroom/2026/08/apple-introduces-m6-and-m5-ultra-for-a-big-leap-in-performance-and-ai-compute/
Apple Machine Learning Research — Introducing the third generation of Apple Foundation Models (8 June 2026). Vendor. Hybrid on-device and Private Cloud Compute. Agentic tool use is named for AFM 3 Cloud Pro, not on-device AFM 3 Core. https://machinelearning.apple.com/research/introducing-third-generation-of-apple-foundation-models
Apple Developer — Foundation Models framework, WWDC26 session 339 (8 June 2026). Vendor. LanguageModel protocol; local and server; Core AI; MLX; third-party. Gemini package still “will soon”. https://developer.apple.com/videos/play/wwdc2026/339/
Anthropic — Claude for Apple Foundation Models (docs, retrieved 1 September 2026). Vendor. Beta package targeting OS 27 betas. https://platform.claude.com/docs/en/cli-sdks-libraries/libraries/apple-foundation-models
Qualcomm — Agentic AI apps running natively on Snapdragon X Series PCs (5 August 2026). Vendor. “Practical compute node” for agentic experiences. https://www.qualcomm.com/news/onq/2026/08/agentic-ai-apps-snapdragon-x-series
NVIDIA — DGX Spark product page. Vendor positioning. Exact heading Desktop Agent Computer. 128GB memory; models up to 200 billion parameters. Live page as of 31 August 2026. https://www.nvidia.com/en-us/products/workstations/dgx-spark/
Xiaomi HyperOS Developer Platform — Agent ecosystem beta (21 April 2026). Vendor. MiClaw as a system-level AI agent; upload of MCP, skills and agents; invitation-only, not general availability. https://dev.mi.com/xiaomihyperos/announcement/detail?id=41
Xiaomi Corporation — Results announcement for the three and six months ended 30 June 2026 (Hong Kong, 18 August 2026). Vendor (IR). Two products: Xiaomi Miloco 2.0 (Xiaomi Local Copilot 2.0), June, home intelligence; Hyper XiaoAi 2.0, August, HyperOS 4 beta, from “understanding instructions” to “getting things done.” https://ir.mi.com/static-files/4a85fc36-8a6d-4c24-b45b-b18d5d162e6c
Google — Universal Commerce Protocol (11 January 2026). Vendor. Co-developed with Shopify, Etsy, Wayfair, Target and Walmart. blog.google names A2A, AP2 and MCP. https://blog.google/products/ads-commerce/agentic-commerce-ai-tools-protocol-retailers-platforms/
Stripe — Machine Payments Protocol (18 March 2026). Vendor. Programmatic payment for APIs, MCP endpoints and other network resources. https://stripe.com/blog/machine-payments-protocol
Mastercard — First agent-based retail transaction in Switzerland (28 May 2026). Vendor. Explicit user consent (Zustimmung), not mandate. With Cembra, Cornèrcard and Viseca. https://newsroom.mastercard.com/news/europe/de-ch/newsroom/pressemitteilungen/de-ch/2026/premiere-in-der-schweiz-mastercard-fuhrt-die-erste-agentenbasierte-transaktion-im-handel-durch-gemeinsam-mit-cembra-cornercard-und-viseca/
FINMA — Survey: artificial intelligence gaining traction at Swiss financial institutions (24 April 2025). Institutional. Generative-AI uptake alongside concerns around data quality, data protection, explainability, outsourcing and Big Tech dependence. https://www.finma.ch/en/news/2025/04/20250424-mm-umfrage-ki/
ETH Zurich / EPFL / CSCS — Apertus 1.5: Building the next generation of open AI infrastructure (24 July 2026). Institutional. Stated long-term objective includes sovereign AI infrastructure and an open alternative to proprietary models. https://www.cscs.ch/science/computer-science-hpc/2026/apertus-15-building-the-next-generation-of-open-ai-infrastructure
Mastercard / Santander — European live end-to-end agentic payment (2 March 2026). Vendor and bank press. Predefined limits and permissions. Not a commercial rollout. https://newsroom.mastercard.com/news/europe/en/newsroom/press-releases/en/2026/santander-and-mastercard-complete-europe-s-first-live-end-to-end-payment-executed-by-an-ai-agent/
Mastercard — Europe is building the foundations for trusted agentic commerce (2 June 2026). Vendor. Network-level enablement of issuers in Europe is not the same as a customer-facing product. https://newsroom.mastercard.com/news/europe/en/perspectives/en/2026/europe-is-building-the-foundations-for-trusted-agentic-commerce/
Federal Office of Justice / Confederation — New timetable for the introduction of the e-ID and the trust infrastructure (30 June 2026). Institutional. e-ID delayed; trust infrastructure still aimed at the first half of 2027. https://www.eid.admin.ch/en/20260625-neuer-zeitplan-fuer-die-einfuehrung-der-e-id-und-der-vertrauensinfrastruktur-en
