By the end of 2022 it felt like the direction of travel was obvious: an intelligent personal agent that would travel with you across apps, devices, and organisations. Your memory. Your preferences. Your context. Your work. One agent that knew you and could act on your behalf.

That vision arrived in pieces. Siri got rebuilt as a systemwide assistant. Copilot sits at OS level. Gemini runs service-side agents that follow you around the cloud. The capability is there. The protocols are there. The autonomy is there.

What is missing is the ownership layer.

When you live inside one vendor's ecosystem, your agent belongs to that ecosystem. The context is not really yours. It is a product asset. The model is a service. The memory is a controlled environment. The user is not the owner. The user is the tenant.

That is not the personal agent I thought we were building. It is agent feudalism. You are not in charge of your agent. You are living inside someone else's castle, and the rent is your data.

The demand was never the fantasy

If anyone doubted that people actually wanted user-owned agents, the open-source rush this year should have laid that to rest.

OpenClaw and similar projects showed the appetite plainly: a self-hosted, persistent agent that could follow a person across files, messages, browser sessions, and calendar events without handing the whole digital life to a platform vendor.

It spread fast. Not because of hype. Because it was the thing people had been promised and that the mainstream platforms kept keeping for themselves.

The security problem was not a surprise

The first big agent security crisis of 2026 was also the clearest demonstration of why ownership matters.

Vulnerabilities appeared quickly. Instances were exposed. Malicious plugins circulated. Prompt injection turned a user's own agent into an attacker’s tool. The project documentation was honest about the fact that there is no perfect secure setup.

That is not a criticism of the builders. It is a useful warning. The capability was never the hard part. The hard part was always the contract around it: what it may do, what it may read, what is logged, what is denied, and what happens if it fails.

Everyone built the agent. Nobody built the contract.

Give an agent persistence, memory, and authority to act, and it becomes capable of moving fast with your credentials and a very confident sense of certainty.

That is a serious issue. It is not abstract. It is a design risk with real consequences. Systems fail. Models are manipulated. Agents are poisoned. Sometimes they are simply wrong in a way that looks plausible enough to fool a human.

The platforms solved this by keeping the agent inside their own walls. That is not governance. It is containment.

It helps their liability story. It does not solve the user's ownership problem. It merely shifts the power to the operator of the platform.

The open-source answer skipped the problem altogether. It demonstrated the need for a durable system contract, but it did not provide one.

What is missing is the layer that matters: the runtime contract that decides what an agent may touch, what it must log, what it must ask for, and when it must refuse. Not a wrapper around the model. Not a PDF policy document. A real operational boundary.

Who owns the agent?

That is the underlying question. The models are converging. The agents are converging. The moat is not in the model and it is not in the agent itself anymore.

The durable layer is the contract. Whoever owns that contract is the one that decides who the agent really serves.

And right now the honest answer is still too often “not you.”

That is a weak foundation for a system that has to act on your behalf. Whether you are a company deploying internal agents or a person giving one access to your digital life, that is not a position you should be comfortable with.

The vendors will tell you this is the year of the agent. It may be. But the more important question is: whose agent is it, and who governs it?