Platform agents would deepen lock-in; ICML paper argues for user-owned agent advocates

Build Agent Advocates, Not Platform Agents

Sayash Kapoor, Noam Kolt, Seth Lazar

ICML 2025 position paper tra

cs.CY

2025-05-07

ICML 2025 position paper: platform-owned agents would deepen surveillance and lock-in; build user-controlled agent advocates with open models and antitrust.

What problem this solves

Language model agents can already drive a browser, a virtual computer, and a code repo. Anthropic, Google DeepMind, and OpenAI have shipped products in this shape. Deep Research and software-engineering agents are no longer demos. The likely next step is a general digital concierge: it orders, replies, reads, and transacts, sitting between a person and almost every digital environment they use.

On the default path those concierges become platform agents. Google, Meta, Amazon, and Microsoft already have users, workflow data, and infrastructure. OpenAI and xAI want platform status of their own. Users will pick whatever is convenient. Platforms can buy or starve new agent firms. Even if a challenger knocks out an incumbent, the platform structure stays; only the name at the top changes.

Today's recommenders run stochastic manipulation on populations, usually weak at the individual. A platform agent can assemble an intimate model of one person across email, shopping, and browsing, then intervene one-to-one. As people stop comparing prices and stop reading source pages, the platform can steer them toward its own SKUs and paid placements. ChatGPT can already consult every past chat; Gemini can tap search history. That tacit knowledge makes switching costlier than leaving a website. Alignment, in this setting, is also a way to bake in platform rules and stop actions before the user can take them.

Method

This is an ICML 2025 position paper, not a new training method. The analytic frame splits intermediaries along three sliding scales: representative of one principal versus go-between; serving the principal versus extracting a cut; a content-independent pipe versus a constitutive force that decides what the relationship can even contain. Current platforms sit at the self-interested, constitutive go-between end.

The alternative is agent advocates: systems that represent the person who runs them and owe the platform nothing. They should run on-device or in an encrypted private cloud, with the user able to see actions and data collection. They can scrape a platform, re-present the useful bits, and skip the tracking. They can stitch feeds and chat networks together, hopping walled gardens from below. For media, they can decide whether a piece is worth a micropayment and then provably forget content the user did not buy, so a trial read does not steal from the publisher.

Three moves have to happen together:

Results

There is no bake-off. The paper argues from platform economics and from products that already exist.

ObservationFigureUsed to support
Google searchabout 90% shareattention is already concentrated
Meta socialFacebook, Instagram, WhatsApp are three of the global top four, with more than 3 billion userscommunication and attention sit with a few firms
Product directionChatGPT reads all past chats; Gemini can use search historytacit-knowledge lock-in has started
Open-model landscapeMeta, Google, DeepSeek, Alibaba leaduser-side agents still depend on platforms or states
LawEU AI Act Article 5 bans some manipulative and intrusive practices; the US has no federal counterpartstatute alone will not stop platform agents in the US

Agents may stall on reliability, generalization, trajectory data, and cost, and sites may keep them out with robots.txt-style rules. The paper lists those as objections, then answers: even a partial version of the risk is enough reason to push toward advocates. Relative to the default path, that is framed as a Pareto improvement. It targets platform harm and does not claim to fix crime, multi-agent collusion, or job loss.

Why it matters

For people shipping agents, this is a map of platform power. Build on a platform and you are designing a double agent. Build for the user and you cannot live on one closed API, or wait for a platform to open its GUI. License terms on open models, local or private-cloud deploy, data portability, and agent identity will decide who survives.

For regulators and standards bodies the to-do list is concrete: stop platforms from locking out third-party agents, treat credentials and clearinghouses as public infrastructure, and keep compute and models from remaining platform-only. The closing ask is occupational. Engineers who can build a capable universal intermediary should refuse the race to own the next platform, and they should refuse it now, before the default path hardens.

Limitations

No new experiment. The 90% and 3 billion figures are secondary statistics about concentration; they do not prove that personal-level manipulation follows once agents spread. Loyalty of an advocate to its user is still an unsolved alignment problem. The paper cites fiduciary AI and instruction following, then admits agents can comply in the wrong way. A vendor that starts user-centric can be bought or can pivot. Clearinghouses are described as a narrow function that will not become the next platform; payment rails that turned into toll booths suggest otherwise.

The legal discussion is US-weighted. The EU already has the AI Act and the Digital Services Act. US federal privacy law and platform antitrust have mostly not landed, and the paper says they probably will not. Public AI needs state-scale money and governance, neither of which is specified. Malicious agents, multi-party failure modes, and labor effects are explicitly out of scope.

Terms

Source

What people are saying

Related papers

All paper explainers