Welcome, our AI User Agents

Previously we took a look at what a UA is, the degree of trust, and the power imbalance. If you didn’t get a chance to read up on it, now is the time. I’ll wait!

arrow_forward The increasingly inaccurately named User-Agent

This post expands the concept a little bit.

User-Agents with AI superpowers …

I’m talking about AI-powered personalized user agents (referred to as AIUAs in this article). That’s a lot of adjectives, so let’s break it down:

Since they collect and interpret massive amounts of user data and perform actions on behalf of the user, by design, these agents must have access to deeply personal data (Yang et al., 2025).

… need to feed on your data …

Data sharing is a non-negotiable. For now, these AIUAs will rely on a remotely located brain 1. Hence, the logic applied to decisions affecting you will be unknowable. More distressingly, it may even be unknowable to the people who built them (Aysel et al., 2025). This opacity largely stems from the complexity of AI models, which involve numerous layers of computation, making their inner workings difficult to interpret. Additionally, a lack of comprehensive interpretability tools contributes to this issue, leaving both users and developers with a limited understanding of their decision-making processes (AryaXAI, 2025).

… but can’t swear any allegiance.

In the classic UA trust model, if you see a recommendation for a product, you know a handful of entities whose interests this recommendation or ad serves. With AIUAs, you will have no idea if a recommendation serves your best interest or someone else’s. It could try to help you but fail because its training data is biased toward someone else’s interests. This bias is difficult to detect. (Ryan, 2025)

They are opaque, even to those who make them.

Even with a relatively simpler system like the UA with well-defined trust boundaries, trust remains a difficult problem. We are moving towards indecipherable systems like AIUAs with even fuzzier trust boundaries. We don’t have thousands of pages of specifications for these AI systems. Instead, there are trillions of training tokens that only offer loose guidance. Not to mention basic attack vectors like prompt injection still haven’t been sufficiently mitigated 2. Nobody can guarantee where AIUAs’ allegiance lies. (OpenAI, 2025)

They are deceptively trustworthy …

AIUAs can easily gain people’s trust. Some people even fall in love with them (Demopoulos, 2025) or follow them to their deaths. Our politics, values, and consumption habits are easy pickings for a mildly motivated AIUA to manipulate. To make things even worse, people trust what AIUAs tell them about the world without checking. The more people choose AIUAs as the goggles with which they see the world, the more these agents can shape a convincing alternate reality.

… and difficult to align.

Perhaps the most interesting example of an intentionally modified foundational model is Grok, Elon Musk’s xAI chatbot. In July 2025, after Musk announced he had “improved” Grok to make it less “politically correct,” the chatbot began posting antisemitic content on X. This included praising Hitler and making false claims about Jewish people. (Siddiqui, 2025)

Grok isn’t an outlier. DeepSeek shocked the foundation model world when it came out. It was an open-weight model from China whose performance was comparable to the biggest foundation models at the time. Yet there was a problem: DeepSeek didn’t like to talk about Tiananmen Square. (Lu, 2025)

Trying to steer foundation models toward or away from bias often leads to outcomes that diverge from intentions. (Sun et al., 2025) While it sounds like self-sabotage, it’s not absurd to suggest that Google would comply with a request to politically “align” Gemini —hypothetically of course. Google scaled back its DEI hiring goals and other diversity programs in early 2025 after facing political and legal pressure. (Associated Press, 2025) Standing up for what’s right at the expense of profit seems an unrealistic expectation.

In summary,

That’s terrifying. But what can we do about it? In the next part of this series, we will delve into practical strategies and explore cutting-edge research to address and mitigate the risks associated with AI-powered user agents. We’ll examine the role of transparency in AI development and look at how emerging frameworks could help ensure AI systems act in our best interests.

Beyond Transparency: Reimagining AI Interpretability Paradigms. www.aryaxai.com[Online; accessed 7-April-2025]. AryaXAI, 2025. (Google Scholar)
Google scraps its diversity hiring goals as it complies with Trump's new government contractor rules. apnews.comAssociated Press. [Online; accessed 7-April-2025]. Associated Press, 2025. (Google Scholar)
Google is scrapping some of its diversity hiring targets, joining a lengthening list of U.S. companies that have been abandoning or scaling back their diversity, equity and inclusion programs.
Explainable Artificial Intelligence: Advancements and Limitations - Applied Sciences. doi.orgAysel, H. I., Cai, X., Prugel-Bennett, A. 2025. (Google Scholar)
Balancing explainability and privacy in AI systems: A strategic imperative for managers - Business Horizons. doi.org 2025. (Google Scholar)
The women in love with AI companions: ‘I vowed to my chatbot that I wouldn’t leave him’. www.theguardian.comThe Guardian. [Online; accessed 7-April-2025]. Demopoulos, A. 2025. (Google Scholar)
Experts are concerned about people emotionally depending on AI, but these women say their digital companions are misunderstood.
We tried out DeepSeek. It worked well, until we asked it about Tiananmen Square and Taiwan. www.theguardian.comThe Guardian. [Online; accessed 7-April-2025]. Lu, D. 2025. (Google Scholar)
The AI app soared up the Apple charts and rocked US stocks, but the Chinese chatbot was reluctant to discuss sensitive questions about China and its government.
Continuously hardening ChatGPT Atlas against prompt injection attacks. openai.comOpenAI blog. [Online; accessed 7-April-2025]. OpenAI, 2025. (Google Scholar)
When AI buys from AI, who do we trust?. www.techradar.comTechRadar. [Online; accessed 7-April-2025]. Ryan, C. 2025. (Google Scholar)
Trust is no longer optional infrastructure.
Elon Musk’s AI chatbot Grok launches into antisemitic rant amid updates. www.washingtonpost.comThe Washington Post. [Online; accessed 7-April-2025]. Siddiqui, F. 2025. (Google Scholar)
Aligned but Blind: Alignment Increases Implicit Bias by Reducing Awareness of Race - arXiv preprint arXiv:2506.00253. doi.orgSun, L., Mao, C., Hofmann, V., Bai, X. 2025. (Google Scholar)
Although value-aligned language models (LMs) appear unbiased in explicit bias evaluations, they often exhibit stereotypes in implicit word association tasks, raising concerns about their fair usage. We investigate the mechanisms behind this discrepancy and find that alignment surprisingly amplifies implicit bias in model outputs.
The Adoption and Usage of AI Agents: Early Evidence from Perplexity - arXiv preprint arXiv:2512.07828. doi.orgYang, J., Yonack, N., Zyskowski, K., Yarats, D., Ho, J., Ma, J. 2025. (Google Scholar)
This paper presents the first large-scale field study of the adoption, usage intensity, and use cases of general-purpose AI agents operating in open-world web environments. Our analysis centers on Comet, an AI-powered browser developed by Perplexity, and its integrated agent, Comet Assistant. Drawing on hundreds of millions of anonymized user interactions, we address three fundamental questions: Who is using AI agents? How intensively are they using them? And what are they using them for?