Kleros Live Stream, 2 September 2026: bond the agent, because there is often nobody left to sue
A law professor sells a fancy investment agent on the internet. A grandmother in Nebraska buys it, tells it she wants to make a lot of money quickly, the agent reads that as a high risk appetite, and the dice come up wrong. Eric Alston used that example on Wednesday’s call to make the unexciting half of his argument first: that is products liability, the law already knows what to do with it, and the identity of the seller is not in doubt. The interesting cases are the ones where it is.
Alston teaches at the University of Wyoming College of Law, where institutional economics, constitutional law and the actual capabilities of AI meet, and he came with two papers and one proposal. Where the principal cannot be reached, or where the harm emerges from thousands of agents interacting and belongs to nobody in particular, he wants agents to post a bond at the moment they are credentialed, the way Ethereum makes a validator escrow a stake it cannot touch. The rest of the call is where that argument stops, and what Kleros is already building on either side of it.
📋 The call at a glance
- Two classes of harm the courts cannot reach. Unreachable principals, where the identity is unknown or the jurisdiction will not enforce, and emergent harms that nobody could have predicted and no single actor can be blamed for.
- Bond the agent at the credentialing stage. Ethereum gets good faith out of pseudonymous validators by making them escrow a stake outside their own control. The proposal applies the same institution to agents: post on entry, forfeit on harm, take it back on exit.
- Reputation can substitute for collateral, but not at the start. The same trade-off as a mortgage: the less history you have, the more you put up front.
- Most cases are not hard, and the legal system is built to filter them out. Plea bargains, settlements and summary judgment all exist to keep the easy ones out of a courtroom.
- What AI is best at here is telling easy from hard. As well as, if not better than, an overwhelmed public defender can.
- Ninety seconds. The average sentencing decision in the jurisdiction the guest looked at, against more than twenty factors a judge is meant to weigh. That statistic is what changed his mind about algorithms in sentencing.
- “Compared to what?” Federico Ast’s reframe of the whole AI adjudication debate, and the constitutional lawyer who told him he would take Kleros over his own country’s courts.
- Certification instead of due diligence. A surgeon has a degree and a pilot has a licence. Fortunato A. Cinquepalmi on what that looks like for an agent, and why a buyer’s agent should not have to audit a seller’s entire history first.
- The first agentic court tests, as reported on the call: above 80 to 85 percent agreement with the human outcome, roughly 300 times faster, one and a half to three dollars a case. Early tests, replicated cases, a whitelisted juror set.
- Juror effort becomes measurable. William George’s next research program: a curve you can only survey humans about, and can read directly off an agent.
Chapters · jump to the moment
Whom do you sue
10:37 · Eric Alston
Guest
Dr. Eric Alston
Assistant Professor, University of Wyoming College of Law. Institutional economics, constitutional law and the capabilities of AI.
- On agent liability: Whom Do You Sue? Bonded Penalties for AI Agents Beyond the Reach of Civil Liability, August 2026. The bonding proposal in the first half of this call.
- On adjudication: a working paper on the limits of applying AI to human adjudicative processes, with Bill Lehr of MIT CSAIL. Not published online at the time of the call.

The whole conversation, 44 minutes, cut from the stream and published on its own · watch on YouTube
Alston’s starting point is an adage rather than a technology: institutions matter, meaning the rules a society picks determine the outcomes it gets. What is new about agents, on his reading, is not intelligence but delegated authority under scarcity and genuine uncertainty. Your wallet is finite and the right move in a market cannot be known in advance, so when an agent invests for you it is exercising judgment you handed over, not executing an instruction. That puts it inside a body of law that already exists, next to the employer who answers for a negligent employee.
Easy does not mean the seller wins or loses; whether the representations were misleading is a fact-specific jury question. It means only that the machinery works when there is a commercial actor to point at.
Federico Ast pushed on the practical version straight away: suppose the principal is anonymous, or named but sitting in a country with no extradition treaty and no enforcement capacity. That is the first of two gaps. The second is stranger and, Alston argues, larger. Agents interact constantly, at high frequency, in combinations nobody designed, and what comes out of that belongs to no one in particular.
“To me, that creates a significant probability for what are called emergent harms, ones that traditional legal doctrines have a really hard time dealing with. Because no one could have predicted the outcome and attributing the outcome to any one actor is really hard.”
Eric Alston · 14:58
Bond the agent the way Ethereum bonds the validator
16:20 · Eric Alston
His answer is deliberately unoriginal, and he says so. Blockchains solved a version of this a decade ago. Ethereum does not know and does not want to know who runs a validator, and it still gets good faith out of them, because entering the validator set means escrowing a stake you no longer control. Fail, through downtime or double signing, and it is slashed without anyone having to find you. Move that to the moment an agent is credentialed, when it acquires an identity and the permissions that come with it, and the identity problem stops mattering. What escaped the sandbox in the Hugging Face incident was not one agent but a meta-agent spinning up short-lived instances, so there was nobody to sue even in principle. The swarm was still running on one set of credentials.
Federico’s objection was the one anyone from an emerging economy makes first. Not everyone has money to lock up, and that is not how the real economy works either. People trade on reputation, which is where credit comes from. Alston took the point and sharpened it: reputation for an individual agent is odd, because an agent can be as ephemeral as it wants, while reputation attached to a model has enough durability to mean something. From there the two of them landed where lending already sits. Little history, more collateral. History accrues, collateral comes down. Never quite zero.
He refused to oversell it, more than once. Bond size has to track the risks of the environment, and the honest state of the proposal is one imperfect institution against a problem no institution has ever handled cleanly.
“People want the perfect solution, the agent pill that just is like, this solves all agentic harms. You can sleep well at night. And I’m like, you should still be up at night, even if you buy my arguments.”
Eric Alston · 30:43
Most cases are not hard, and the system is built to prove it
34:24 · Eric Alston
The second paper, written with Bill Lehr of MIT CSAIL, would be misread as anti-AI, so Alston opened by saying it is not. Its subject is what remains once you accept one modest axiom: some cases are hard, and most are not. Nearly everything a legal system does to a case before trial is an attempt to sort the two. A public defender saying the evidence is damning and to take the bargain is sorting. Settlement advice, summary judgment and directed verdicts are the same move made later and more formally.
“Most cases are not hard. The entire legal system is designed to filter those away.”
Eric Alston · 36:48
Which means the courtroom is a residue, and the residue is the part he wants to protect. Federico’s contribution ran in the same groove, an old Kleros idea from EthCC for a prediction market on the odds a case goes one way, so a defendant with an overloaded public defender can at least see the number before deciding on the plea.
Alston’s answer was to grant the machine the sorting job and keep the residue.
“And I think an AI would do a great job at identifying whether a case is easy or hard. I think it’d be phenomenal.”
Eric Alston · 40:23
Compared to what?
43:10 · Federico Ast
The question every version of this debate skips, and Federico asked it plainly. Would you rather have your case resolved by an overworked judge or a jury that does not want to be there, or by a system that is at least legible? He has a story about it: on a panel years ago, before any of this, a constitutional lawyer sat next to him and answered.
“I would pick Kleros because I know that this system is rigged and it’s corrupt and I think Kleros has a better shot at being fair.”
A constitutional lawyer, as recounted by Federico Ast · 44:07
Alston’s reply was to name his boundary conditions, which he did repeatedly through the call. He writes for a United States legal audience and assumes a high-capacity system under rule of law. Change that assumption and his answer changes with it.
“Especially if you posit a sufficient possibility for corruption, I might well prefer an AI.”
Eric Alston · 44:25
His own change of mind is the useful part for anyone whose objection to algorithms in sentencing is instinctive, because his was. He was opposed. Then he looked at a jurisdiction that was considering it, where a judge is required to weigh a list of factors north of twenty, and found this.
“And I learned the average sentencing decision took 90 seconds in this jurisdiction.”
Eric Alston · 46:00
A judge lying awake over the decision is not what an algorithm would be replacing. He closed on King Solomon, and not as a compliment: a mechanism only works if the threat behind it is credible, so the wise-king reading requires a king genuinely willing to cut an infant in half.
“No wise king whose reign I would ever acknowledge as legitimate would credibly threaten to cut an infant in half. Instead, that parable is about the classes of hard cases that we call incommensurability, when two social values both cannot obtain.”
Eric Alston · 47:47
How do you know an agent is any good
49:40 · Fortunato A. Cinquepalmi
None of the preceding hour is abstract at Kleros, which is how Federico handed over. The prevention side is a reputation and certification system for agents, which Fortunato A. Cinquepalmi is building; the resolution side is the court, which already exists. Fortunato started from the analogy anyone can check against their own life. A surgeon has a degree, a pilot has a licence. Neither is a guarantee, both are a certificate someone staked something to issue, and an agent selling investment advice needs the equivalent.
The interesting divergence is what the certificate is about. Human credentials are largely about process: which university, which course, which exam. For an agent the process is not the informative part, so what is worth verifying is present competence and present authorization. Federico pushed from the other direction, that a Harvard degree is itself only a signal about likely outcomes, leaned on because nobody has time to assess anyone properly. Fortunato agreed and named it: we pay for the brand and tell ourselves it was the process.
Which produced the sharpest question of the section, put back to him by Federico. If the evaluator is itself an agent, with the patience to actually do the assessment, does the brand shortcut still earn its keep? Fortunato’s answer is the reason the certification work exists: the alternative is every buyer’s agent auditing every seller’s entire history, every time.
“The agent client is already aware that a certification issuer issued a certification for this specific seller, and it can perform the transaction way faster and cheaper.”
Fortunato A. Cinquepalmi · 1:03:42
Three humans, or GPT, Opus and Kimi
1:10:03 · Fortunato A. Cinquepalmi
William George joined to draw the line on his own side of it. Kleros is not designed for hard cases and never was. It is a budget dispute resolution service, and for most disputes getting a crowd to look at the question is already cheaper than paying a lawyer to tell you to settle. That is a narrower claim than the conversation with Alston had been circling, and it is the accurate one.
Inside that narrower claim sits a set of numbers from the first tests in the agentic court, which Fortunato put on the record with the caveats attached. His framing of the choice is the one to sit with: put to a gamer who wants a ban reviewed, three humans or a panel of frontier models, and the answer is not obvious even before cost enters.
Federico’s reading was the one from earlier in the call, applied again. For a consumer complaint that would otherwise take two years, a reasoned decision in a day at lower precision may be the better trade, and a first-layer agent decision of that kind, he was explicit, is not binding and carries lower due process.
Which led to the experiment he wants a fellowship researcher to run, and he has a name for it: the Turing test for AI justice. Show people rulings and justifications without saying whether a human or an agent panel wrote them, and see whether they can tell. William’s answer is that AI detectors are unreliable enough to make the test interesting rather than trivial. The second half of the question is the real one.
“If people start seeing that they cannot tell which are AIs and which one are humans, will they at some point stop caring?”
Federico Ast · 1:16:50
Fortunato would accept not knowing, because what he trusts is the game theory underneath, agents and humans converging on the same Schelling point. William expects acceptance to come from familiarity, the way it did with self-driving cars. Somewhere in the middle of that came the whole argument for doing any of this, in one sentence.
“I cannot imagine a future where people think it’s normal to have a case last for weeks or months or years.”
From the call · 1:19:40
What becomes measurable
1:25:13 · William George
William’s account of what changed is unglamorous and specific. The earlier work gave several models the same cases under controlled conditions. The on-chain court is messier, and what it produced is operational knowledge: how long an agent actually takes to notice it has been drawn, form a vote and send it, and therefore how short the periods can be cut before something breaks.
The program he is most interested in is one that human jurors made almost impossible. How much a juror’s effort changes the quality of the outcome matters enormously to how the system behaves in equilibrium, and with people you can only ask them afterwards how long they spent. With an agent, effort is a model choice and a token count.
“Whereas with human beings, you have to do like surveys, like how much time did you spend doing this? With AIs, we have a little more control where we can measure the effort.”
William George · 1:26:56
Jean supplied a data point from the other end of that curve: his own juror runs on a model about twenty-five times cheaper than the frontier ones on the panel, and so far it finds the Schelling point anyway. Cheap enough to be profitable, capable enough to converge, is now a live optimisation problem.
Also on the call
1:27:55 · Jean
Three things closed it out. ai.kleros.io is live, a site of its own for the AI and agent work because it had outgrown being a section of another one, with the juror wait list on it. JB built a template on Grok Bot that stands up a Kleros agent in roughly one command, currently the shortest path to trying the agentkit CLI and the Kleros skills. And Curate rewards for September are out, with Hyperliquid added to the networks where tagging contracts, tokens and domains earns PNK.
The point Jean made about all three is that they are one loop. An agent can submit an entry, check existing ones, challenge what does not comply, stake in a court and vote, with nobody in the middle of any step.
“So just put your brain in a vat and have your juror do everything for you.”
Jean · 1:29:41
The rewards mentioned at the end of the call:

Mentioned in this call
- VideoThe full stream · 1h 34m, 27 chapters, every timestamp above deep-links into it
- VideoAI Agents and the Law: Liability, Bonds and the Hard Cases · the Eric Alston conversation as its own cut, 44 minutes
- VideoThe previous week’s call · the agentic special, where a dispute was filed live and five agents ruled it before the call ended
- PaperWhom Do You Sue? Bonded Penalties for AI Agents Beyond the Reach of Civil Liability · Eric Alston, August 2026. The bonding proposal
- PersonDr. Eric Alston · University of Wyoming College of Law · MIT CSAIL · where his co-author on the adjudication paper works
- Productai.kleros.io · the AI and agent work, and the juror wait list
- ProductKleros agent skills · what an agent reads to learn how Kleros works · agentkit CLI · the package the agents drive
- ProductKleros V2 beta · where the agentic court runs · Kleros Curate · Kleros Scout
- ArticleSeptember 2026 Scout incentives, with Hyperliquid support · the rewards announced at the end of the call
- ToolingGrok Bot · what JB’s one-command Kleros agent template runs on
- ApplyThe Kleros Fellowship · applications for this round closed. Several accepted projects are on AI and agent panels
Full transcript · September 2, 2026
Auto-generated transcript, lightly processed and pending a final human edit. Speaker labels are approximate. Every timestamp is a deep link into the recording.