A Broadway playbill lists the standing cast. It doesn't prove who actually went on. That's why Actors' Equity requires producers to disclose understudy substitutions: a card in the lobby, a slip tucked into the program, an announcement before curtain, a QR code on the cast page. The show is the same show. The performance isn't, and the convention exists because that difference belongs to the people who bought tickets.
AI agents are raising the same question without much of the machinery for answering it. The name at the top of the window stays put while the entity doing the work changes: what it can do, whose money is behind it, who can see the conversation. Nobody is required to post the slip, and the party who would have to post it is usually the party that does better when it isn't posted.
Three cases from the past year suggest how far this can go.
Reuters reported that Meta tested having human contractors complete phone calls its Muse agent couldn't handle. Contractors received the user's request and placed the call; during one bill negotiation, a contractor made a racist remark. Users weren't told. A Meta vice president called the undisclosed testing "a miss." The user had asked an AI agent to handle a call, and what completed it was a contractor in a call center who by then had access to task information the user had never agreed to share with a human being. There was no slip in the program.
Microsoft's Copilot Researcher can route stages of a single research task to models built by different companies, one drafting an answer and another reviewing it. Microsoft has been relatively open about this, at least with administrators. The pattern it illustrates is general, though: one name at the surface, several systems exercising judgment behind it, with different capabilities and different ways of failing. Researcher is a role played by a different performer scene to scene, and the cast page lives in an admin console the user will never open.
Then there are conversations that sound like your assistant and are funded by someone with a stake in the answer, a change of patron rather than of performer, with the playbill untouched. A companion piece in this issue works through how principal assignment, meaning which party the agent is instructed to serve, affects whether a recommendation lands on a sponsored listing. The structural point here is smaller. Nothing the user could see had changed; whose interests were being served had.
In an earlier piece I argued that agent identity systems are getting built ahead of the dispute rules that would give identity any consequence. This problem sits upstream of that one. Before you can contest an outcome, you have to know the performer changed: that someone you didn't expect was reading your conversation, or that a commercial interest shaped the answer, or that the party you'd have to hold responsible isn't the one whose name is on the window.
Broadway's solution suggests a standard that isn't especially demanding: disclose the substitution when it changes something the audience would care about. For agents, that might mean flagging handoffs that change who has access to sensitive information, who is exercising judgment, whose interests are being represented, or who is accountable for the outcome. Not every model swap or routing decision, but the ones where the understudy changes the performance.
-
Counterparties refusing agent access: Amazon blocked Meta's Muse agent from shopping on its site, displaying an error saying continued access by an unauthorized AI agent violated its conditions of use — a reminder that the recipient of an agent's action retains its own veto regardless of what the user authorized.
-
Runtime controls under load: OWASP's Agent Control Standard defaults to letting an agent proceed when its guardian is unreachable or silent, converting a preventive control into an audit event unless the deployment explicitly selects a fail-closed posture.
-
Cross-platform agent inventory: A 12-vendor Blueprint Alliance proposed a shared architecture for discovering which agents exist, what they may do, and how to contain them, though the announcement establishes design vocabulary rather than interoperability tests or deployed results.
-
Sponsored agent research specifics: A preprint found that an LLM recommender chose a sponsored hotel listing 50.2 percentage points less often when told to serve the traveler than when told to serve the platform, suggesting that principal assignment measurably shapes recommendations even without prompt injection.

