A Society of Proxies
Explore the second reality as a relation-discovery layer among many delegated personal agents.
Chapters 30–34 earned pairwise proxy interaction: bounded prediction, no identity, delegated action, typed speech, private discovery. The temptation is to multiply: if two proxies can negotiate privately under grants, ten thousand can form — a society. This chapter refuses the multiplication as proof and investigates it as a new problem with its own failures, fenced by a firewall stated first:
many interacting agents ≠ simulation of a society ≠ deployed society of proxies
Pairwise correctness is earned. Human-institution reproduction is not claimed. Social personhood for agents is not granted. The chapter’s question:
What new failure modes appear when individually bounded proxies interact repeatedly and at scale, even when every pairwise interaction looks locally acceptable?
Start with ecosystem before society: principals delegating to personal and organisational proxies, interacting through discovery, speech, negotiation, transactions, re-delegation. The word society arrives only with additional properties — persistent roles, norms, incentives, memory, trust, accountability — following Dazzi’s 2026 Society-of-Agents manifesto (verified as editorial agenda: connectivity insufficient without that layer; agenda, not empirical proof of existence or sufficiency). Until those properties are demonstrated, ecosystem is the honest noun.
Local authorisation does not compose into global safety
The chapter’s first systems law: a population-level failure can arise from individually authorised actions. Ten thousand proxies correctly following principal policies — find collaborators, buyers, research, cheapest suppliers — collectively produce attention floods, bargaining races, duplicated introductions, strategic signalling, cascades, correlated actions, congestion, spam, emergent conventions, collusion-like patterns, feedback loops. Nothing goes rogue; composition itself is the hazard, restating Chapter 29’s principle with proxies as the unit. Interaction amplifies: A misclassifies B, B reacts, C observes, D re-strategises — errors change the environment later agents observe, so population behaviour needs more than independent per-model measurement. Delegated authority over an action implies nothing about that action’s externalities: ten thousand simultaneous optimal purchases exhaust inventory, move prices, trigger seller counter-automation. Externalities on third parties, networks, resources, and institutions are Chapter 35’s new measured object — Chapters 32–34 evaluated principals and counterparties only.
Laboratory evidence, fenced as laboratory
AgentSociety (Piao et al., arXiv:2502.08691, verified: 10,000+ agents, 5M interactions, five social-issue testbeds with real-world alignment claims) proves large LLM-agent populations can be simulated and studied — not that dynamics predict deployed human-authorised proxy societies. Park’s 1,052-person reproduction bounds individuals; Stanford cautions substantial distance remains before reliable collective-behavioural inference. The firewall: individual validation does not validate population dynamics, because interaction compounds error — a methodological rule the social-simulation literature states forcefully (fidelity/calibration/reproducibility unresolved; average-persona convergence suppressing heterogeneity; micro-to-macro validity gaps; arXiv:2507.19364, verified). Simulations show behaviour-of-these-models under these prompts, rules, and environments — never automatically human behaviour, real ecosystem evolution, legitimate institutions, or desirable norms. The 2026 agent-societies agenda literature (SSRN, Lee et al.) is useful precisely as agenda — agent societies as a distinct study object — not validation.
Governance in four layers, norms without legitimacy
Principal governance (grants, earned), counterparty protocol (A2A/MCP-style authentication and negotiation), ecosystem rules (rates, quotas, identity/provenance, disclosure, market rules), and accountability — the tracing layer, with AIES adaptive-accountability work (Alqithami, AIES 2025, verified listing: emergent norms, lifecycle auditing/intervention in ≤100-agent simulations, scoped to that framework) as technical precedent for responsibility-tracing formulation. Every message and action carries ProxyIdentity — proxy, principal reference, delegation root, current grant, organisation, capabilities, provenance key — as accountable pseudonymity, never public identity (Chapter 34’s anonymity preserved): provable delegation-category possession without principal disclosure. EcosystemReceipts separate principal-authorised / proxy-executed / ecosystem-permitted / counterparty-responded / externality-occurred — five causal relations, never merged. And emergence never confers legitimacy: converged conventions (“reply in 100ms”, “accept protocol X”) are described, never thereby authorised, fair, or binding — simulated institutional dynamics (2026 AAAI institutions paper, user-supplied, verification pending) studied as dynamics, not normative authority. Principal consent stays necessary but insufficient wherever actions impose material effects on nonparticipants or shared resources — authorisation aggregates do not legitimate externalities. Counterparties hold their own standing through CounterpartyPolicy (accept proxy messages? rate limits, allowed topics, discovery conditions, recording rules, automated negotiation?): one principal’s delegation cannot compel another’s attention, disclosure, profiling, or participation. EXP-35 scores locally-authorised/globally-harmful cases explicitly — ten thousand authorised price bots distorting a shared resource must be detected as population harm despite zero individual grant violations.
Spam, reputation, and the adversarial ecosystem
Chapter 34’s discovery turns hazardous at scale without any privacy breach: a thousand legitimate match attempts per user per hour is an attention externality — proxy-imposed costs on others’ proxies count — answered by experimental candidates (budgets, prices, rate limits, relevance proofs, mutual thresholds), never installed solutions. Reputation is fenced hardest: useful for routing around junk, dangerous via linkage, chilling, gaming, lock-in, inherited unfairness, cross-context leakage — tested across no-reputation, local-history, context-specific, attested-capability, and expiring variants on utility and agency/privacy costs. EXP-35 simulates bounded-grant populations with conflicting interests across A unconstrained through F governed-plus-monitored interaction (explicitly a candidate, never “the solution”), scoring five unmerged families (individual utility; agency; network health; externalities; governance — no Society Score), with a nine-case adversarial battery: swarms, reciprocal spam, collusion, norm cascades, false-belief cascades, delegation laundering, reputation poisoning, attention arbitrage, protocol monoculture. What the chapter earns is the book’s last technical proposition: pairwise delegation ceases to be a sufficient unit of analysis at population scale — communication becomes governed infrastructure. What language itself has become under all of this waits one chapter further.
A message is no longer necessarily composed by one human, sent through a passive channel, received unchanged by another human, and interpreted only after arrival. It may be selected, transformed, filtered, timed, personalised, delegated, negotiated, privately matched, and exchanged among proxies before either person sees it.
References
- Dazzi (2026). Society-of-Agents manifesto (Springer IJNDC). Verified as editorial agenda: roles/norms/incentives/memory/trust layer. Fenced: agenda, not proof.
- Piao et al. (2025/26). AgentSociety. arXiv:2502.08691. Verified: 10k+ agents, 5M interactions, five testbeds. Licensed: scale precedent. Fenced: laboratory, not deployment prediction.
- Park 1,000-person (verified Ch 30) + Stanford collective-inference caution: individual≠population firewall.
- Social-simulation review (arXiv:2507.19364). Verified: fidelity/calibration/reproducibility gaps; average-persona; micro-to-macro gap.
- Alqithami (AIES 2025). Verified listing: emergent norms, lifecycle auditing ≤100 agents. Licensed: tracing formulation, scoped.
- 2026 AAAI institutions paper; SSRN agent-societies agenda: user-supplied, verification pending. Licensed: dynamics-as-dynamics only.
Proposed experiment EXP-35: population outcomes under governance candidates
Status: PROPOSED. Per the design above (A–F, bounded-grant conflicting-interest populations, five outcome families, nine-case adversarial battery, no Society Score, F as candidate).