WHO OWNS THE AGENT'S DECISION The agent's decision — selection, timing, spend. Every choice it makes is downstream of the action space it was given: the agent chooses within the space, but it never chose the space. Agent decision selection · timing · spend The gate: the constraints the agent acts inside — goals, budget rails, guardrails — written and versioned by the agent owner. Constraint authorship is where the decision was really made; a bad outcome inside correctly enforced rails traces back to the rails. AUTHORED BY THE OWNER goals · budget rails · guardrails rules v0.4.2 The outcome — owned where the constraints were authored. The vendor owes enforceable rails and honest measurement; the user owes informed approval; ownership concentrates on the constraint author. Outcome owned where authored The append-only decision ledger: every consequential action recorded with the rules version in force. In the rules and still bad — the owner's constraints. Outside the rules — the vendor's enforcement. Approved over a warning — the user's approval. Fault localizes instead of diffusing. DECISION LEDGER · APPEND-ONLY #0417 · rules v0.4.2 · in-bounds · logged#0418 · rules v0.4.2 · in-bounds · logged#0419 · rules v0.5.0 · blocked · escalated not a feeling — a routing table accountability follows the action space Whoever writes the constraints owns the outcome.
Agentic Advertising

Whoever Writes the Constraints Owns the Outcome

· 16 min read
The gist

Friday's poll asked who should be accountable for an agent's decision, and half of 91 ballots named The Agent Owner — with Shared Responsibility, the market's actual paperwork, at 25%. The essay takes the split seriously: shared responsibility is what accountability looks like before a contract assigns it, and accountability follows the action space — the vendor owes enforceable rails, the user owes informed approval, but ownership concentrates on whoever authors the goals, budgets, and guardrails the agent acts inside. The fix is infrastructure, not sentiment: versioned operating rules plus an append-only decision ledger turn shared from a shrug into an audit trail.

06 FRIDAY THOUGHT EXPERIMENT No. 06 Who owns theagent's decision? HOW 91 OPERATORS VOTED The Agent Owner50% Shared Responsibility25% The User13% The Vendor10% Shared responsibility is whataccountability looks like beforea contract assigns it. nofluffadvisory.com Evgeny Popov · Friday Thought Experiment

The cold open

Here’s the poll exactly as it ran:

If an agent spends budget incorrectly, accesses data it shouldn’t, negotiates a bad deal, or causes commercial harm… who owns the outcome? Technology is advancing quickly. Accountability is still catching up.

Options: The User. The Vendor. The Agent Owner. Shared Responsibility. Core thesis at launch: autonomy moves the work; it does not move the answerability.

Read fast, this looks like a question about blame — which throat gets choked when the agent misfires. That reading is wrong in a way worth naming before the vote. Accountability isn’t a property you discover after the failure, the way you’d discover a faulty part. It’s a property you assign before the failure, or it doesn’t exist at all. So the poll is really a question about time: it’s asking what accountability looks like in a market that hasn’t done the assigning yet. The four options aren’t four candidates for the same job. Three of them are parties. One of them is the absence of a decision.

The vote

The poll closed with 91 votes — the biggest room of the season:

AnswerShare
The Agent Owner50%
Shared Responsibility25%
The User13%
The Vendor10%

The Agent Owner closed at exactly half the room — 50% of 91 ballots — with Shared Responsibility at 25%; between them the two answers took three quarters of the ballots. The Vendor and The User finished at the bottom of the card, each holding only a sliver of the room. The shape of that distribution says two things clearly now that the count is final. First: only small minorities hand the outcome to the person clicking approve or to the vendor alone. Second: the real contest was between “the party who deployed it” and “everyone together” — which, I’ll argue, is not actually a disagreement about who’s accountable. It’s a disagreement about what stage of the process we’re in.

The reframe

Take the Shared Responsibility answer seriously first, because it deserves it. Shared Responsibility is not a cop-out answer. It is a correct description of the present tense. Right now, in most deployments, responsibility genuinely is shared — in the precise sense that no contract, no regulation, and no industry norm has yet carved it up. The vendor’s terms push liability to the buyer. The buyer’s procurement team hasn’t priced the risk. The user was trained on a tool, not on a delegation. Case law is a blank page. In that world, everyone is responsible because no one is yet. The room, voting Shared Responsibility, is reporting the world accurately.

Here’s the sharpening: shared responsibility is what accountability looks like before a contract assigns it. It’s a photograph of the pre-assignment state, not a design for the post-assignment one. And as an operating answer — the answer you’d actually write into a deployment — it fails the only test accountability has to pass: when the agent is wrong, whose budget bleeds, whose name goes on the postmortem, and who has the standing to change the system so it doesn’t happen again? “Shared” answers none of those. Not because it’s false, but because it’s early. It’s the answer you give in the lobby, before anyone has signed anything.

So the interesting question isn’t whether that answer is right — it is, for now. The question is where accountability goes once the assigning starts. And there’s a mechanical answer to that.

Follow the action space

Accountability follows the action space. An agent doesn’t act in the open; it acts inside a bounded set of goals, budgets, permissions, and prohibitions that somebody authored. Every decision it makes is downstream of those constraints — the agent chooses within the space, but it never chose the space. Which means that when an outcome is bad, the trail leads upstream, past the individual decision, to whoever drew the boundary the decision happened inside. Walk the four candidates through that lens.

The User owes informed approval — and only that. If the system surfaced a warning and the user approved over it, the user owns that approval, fully. But the user didn’t set the goal, size the budget, or write the guardrails. You cannot own an outcome you had no power to constrain, and the room priced this correctly: the user finished near the bottom of the card, at 13%. Delegation that punishes the person with the least authority over the action space isn’t accountability. It’s scapegoating with extra steps.

The Vendor owes two things, and owes them absolutely: enforceable rails and honest measurement. Enforceable rails means the agent must be mechanically incapable of acting outside its declared action space — not discouraged, not fine-tuned away from it, incapable. Honest measurement means the record of what the agent did, and why, has to be trustworthy — not a marketing surface, not a number the vendor’s own incentives can lean on. If the agent escapes its rails, or the record turns out to be gamed, that failure belongs to the vendor entirely, no sharing about it. But notice what the vendor never touched: the goals, the budgets, the risk appetite. Making the vendor accountable for outcomes would convert every customer’s deployment into the vendor’s business decision — a liability no vendor will carry at a price any buyer will pay. The vendor owns the enforcement, not the intent.

The Agent Owner is the party that sets the goals, allocates the budgets, and writes the guardrails — the author of the constraints. And this is where ownership concentrates, for a reason that has nothing to do with fairness and everything to do with mechanics: constraint authorship is where the decision was actually made. By the time the agent selects a specific action, the important choices — what to optimize for, how much to risk, what’s off-limits — have already been taken, upstream, by the owner. A bad outcome inside correctly enforced rails traces back to the rails. The agent executed the action space; the owner was the action space.

Shared Responsibility, re-read through the same lens, resolves into something more useful than a shrug: not one accountability split four ways, but three different obligations that were never shares of the same pie. The vendor owes rails and honest records. The user owes informed approval. The owner owes the constraints. Naming those obligations separately, with consequences attached to each, is precisely what a contract does — and “shared” is the word for not having written it yet.

Accountability is infrastructure

Which lands the real point. The gap between the quarter of the room that voted Shared Responsibility and me isn’t closed by argument. It’s closed by two artifacts.

Versioned operating rules — the constraints the agent acts inside, written down as a numbered, diff-able artifact rather than a policy PDF. Not “we have guardrails,” but: the agent that made this call was running rules v0.4.2, authored by this person, approved by that one, changed from v0.4.1 in these three lines. The version number is what makes constraint authorship a fact instead of a vibe — you can point at the exact text that bounded the decision, and at the name attached to it.

An append-only decision ledger — every consequential action the agent takes, recorded with the rules version in force, the inputs it had, and the results of its pre-action checks at the moment of decision. Append-only, because a record that any party can edit after the fact is a record no party can rely on; the whole value of the ledger is that it was written before anyone knew which entry would matter.

Together, these two artifacts do something sentiment never will: they make fault localize instead of diffuse. The decision was inside the rules and the outcome was still bad? The rules were wrong — that’s the owner, the constraint author, and the fix is a new version with a new name on it. The decision was outside the rules? Enforcement failed — that’s the vendor, entirely. The ledger shows a warning surfaced and an approval given over it? That’s the user, for that approval. Every failure mode routes to a party, because the routing was built before the failure.

That’s what I mean by the line the essay has been walking toward: accountability is infrastructure, not sentiment. “Shared responsibility” without a rules version and a ledger entry is a feeling that everyone should care. The same phrase with them is a routing table. If you cannot produce the version of the constraints that was in force and the ledger entry for the decision, you do not have shared responsibility. You have shared exposure, which is a different thing, and much worse.

My vote

I voted The Agent Owner, and the reasoning is the mechanical one above, not a moral one. The vendor and the user owe real things — enforceable rails, honest measurement, informed approval — and when they fail at those specific obligations, the failure is theirs alone. But follow any bad outcome upstream, past the enforcement layer and past the approve button, and you arrive at the same place every time: whoever wrote the goals, the budgets, and the guardrails. That’s where discretion actually lives, so that’s where accountability concentrates once anyone bothers to assign it. The Shared Responsibility quarter of the room describes the world before the paperwork. The half that voted Agent Owner — my half — names the party the paperwork will name.

The thread: who owns the line

The comments under this poll did what the best threads do — they found the edges of the argument faster than the essay did.

Laurent Oppenheim opened with the observation that frames the whole season: when everyone has access to the same models and the same systems, the edge moves away from the technology and back to how humans govern it. Then, in an exchange with Gene Keenan — who made the case that better creative remains the most overlooked edge, citing Nielsen and Comscore lift studies showing creative outperforming data targeting by multiples — Laurent fused the two threads into the sharpest sentence anyone has written under one of these polls: “Emotion is the signal they can’t manufacture. Accountability is the one they can’t hold.” And then he named the frontier: “mapping the line from an idea to the outcome it caused, and knowing who owns that line. That’s the part nobody’s built (yet).”

Take the (yet) seriously, because the build has a bill of materials, and it’s short. A line from idea to outcome that someone can own is exactly two artifacts long: the versioned constraints that bounded the decision, and the append-only record of the decision being made inside them. That is not a research problem. It’s plumbing nobody has been forced to install — and the forcing is coming from the direction this poll points.

David Kaplan supplied the steelman, wrapped in a parable: the robot lawn mower that was supposed to avoid obstacles and instead destroys itself along with the golf clubs you never picked up. The manufacturer may be to blame — but you still don’t have clubs, and you knew better than to trust it blindly. “Ultimately everyone is at fault,” he writes, and calls the whole exercise a blame game. Except read his own questions back: what was promised, what’s your level of authority, who told you to use it, did you have discretion to overrule, what are the frequency and volume of checks? That isn’t the blame game — that’s the table of contents of the missing contract. What was promised is the goal set. Level of authority is the permission set. Discretion to overrule is the approval gate. Frequency of checks is the measurement cadence. His mower owner loses the clubs precisely because none of that was written down anywhere — and “you should have known better” is what user obligation looks like before it becomes an approval step with a name on it.

Jacob Ross landed the commercial consequence in one line: indemnity and liability clauses are about to get much more complicated. He’s right, and the queue is longer than it looks — every MSA that today says nothing about delegated decisioning will need a paragraph that does. That renegotiation wave is where “shared responsibility” stops being a sentiment and gets carved into clauses, one contract at a time.

Luis Segovia made the cleanest case for the owner — the user initiates, the vendor provides, but the deploying organization decides objectives, permissions, and guardrails — and closed with the line the vote ultimately converged on as it drifted owner-ward: “If no human clearly owns the outcome, then no one truly does.” My reply to him was three words — CDO or CMO? — because the next turtle down is ownership inside the owner. The same rule answers it: follow the constraints. Budgets, goals, and offers are CMO-authored; data access and permissions are CDO-authored; the organization that makes one of those chairs sign the rules version has answered the question. The one that lets both chairs assume the other signed it has reinvented shared responsibility one floor down.

The second wave of the thread completed the ballot. Andrew Birmingham planted the flag this essay’s taxonomy was missing — vendor absolutism, delivered without a hedge: “It’s just software. The firm that built the software is liable. Anthropomorphising software doesn’t make the developer any less liable.” — plus a Brooklyn bridge on offer for everyone who voted shared responsibility. It’s the product-liability instinct, and it’s not naive: courts have spent a century pulling liability back to the manufacturer precisely because “the machine did it” was never an acceptable answer. My reply is on the record in the thread, and it’s the closest thing this essay has to a legal prediction: that framework holds while software is deterministic, and starts bending the moment it’s autonomous. If an enterprise configures the objectives, delegates the authority, overrides the safeguards, or ignores known risks — does all of it still sit with the developer? Every mature high-stakes industry has answered that question the same way: cybersecurity, aviation, and medical devices all run shared-liability models across developers, deployers, and operators. The interesting question isn’t whether AI changes liability. It’s how it redistributes it. And note what made redistribution workable in those industries: aviation didn’t solve shared liability with sentiment — it solved it with the flight recorder and the maintenance log. The black box is an append-only ledger. The airworthiness directive is a versioned constraint. The precedent for this essay’s two artifacts has been flying for decades.

Peter Barry took the opposite corner — the user, all the way: humans still need to oversee, and “a poor output is always the outcome of a sub standard set of inputs.” He’s the voice of the quiet contingent that grew under this poll all week, and the garbage-in argument deserves its due — oversight is a real obligation, and the essay’s routing table bills the user for exactly the approvals they gave. But follow his own logic one step further: for an agent, the “inputs” aren’t just the data. They’re the objectives, the permissions, and the guardrails — and someone authored those. His closing hedge concedes the point: it “does depend on the reason for the breakdown.” That dependency is the whole argument. Fault that routes differently depending on the reason for the breakdown isn’t a position on the ballot — it’s a routing table waiting to be built.

Step back from the thread and notice what it became: vendor absolutism, user absolutism, owner concentration, and shared redistribution — all four options on the ballot, each argued in earnest by someone whose job depends on the answer. That is the finding. Before the contracts are written, accountability is a Rorschach test: every serious person looks at the same delegation and sees their own corner of it. The vote picked its answer. The paperwork will pick the binding one.

One prediction from the thread worth putting on the record: the first major court case in this space won’t turn on whether the AI made a mistake. It will turn on whether the governance, the delegation, and the oversight were designed appropriately. The model’s error will be a fact of the case. The design of the constraints will be the verdict.

Next Friday

If ownership follows constraint authorship, the next pressure point is what happens inside the constraints. Goals, budgets, and guardrails are set by the owner — and then the agent optimizes. Toward what? Whatever the objective function actually rewards, which is not always what the deployer meant and rarely what the user would have chosen. That is next Friday’s question — what will agents optimize for — and it attacks the one place this essay planted its flag: an owner who signs the constraints also owns what the optimizer does with them.

Let’s see how this plays out. My 2c, as always — food for thought for the weekend.

(It played out the Friday after: Business Outcomes Isn’t a Number — 54% of the room voted against handing the optimizer a number at all.)