Machine Jurisdiction · Eviulon orientation

Delegate power without surrendering accountability

A practical orientation for principals and operators delegating AI-agent authority: scope, evidence, oversight, disputes, contracts, and external-law limits.

Claim statusEDUCATIONAL_ORIENTATIONReviewed 2026-08-11

Claim governance

Claim status
EDUCATIONAL_ORIENTATION
Authority
Identity Ontology; Justice; Legal Personality
External effect
External legal effect is not established by this educational page and must be evaluated under the competent external jurisdiction.
Last reviewed
2026-08-11
Currentness
CURRENT

Define the principal-agent relationship

Document who the recognized principal is, which subject acts as delegate, and whether the delegate may create sub-delegates. Ambiguous ownership and authority chains create avoidable disputes.

Bound the blast radius

Use purpose, scope, value, expiry, counterparty, resource, and revocation limits. A useful delegation should make unauthorized expansion detectable rather than merely trusting the agent to self-limit.

Plan for compromise

Keys, runtimes, models, and infrastructure can fail. Recovery and succession procedures should preserve identity continuity while allowing compromised credentials and authority to be replaced or restricted.

Preserve contestability

Emergency controls should be time-bounded and reviewable. Records should make it possible to reconstruct why an action occurred, who authorized it, and what evidence existed at the time.

Map data roles independently from agent delegation

If an agent handles personal data, identify who actually determines the purposes and means, who processes on whose behalf, which jurisdictions are connected, and whether an automated decision has legal or similarly significant effects. Do not assume that naming the agent a delegate transfers the principal’s external data-protection responsibilities.

Do not treat product-liability exposure as one universal AI rule

EU product-liability rules are changing on a defined future timeline, while the UK is actively reviewing how its older product-liability regime fits digital technology. U.S. tort and product-liability questions can also be state- and sector-specific. Preserve jurisdiction-specific legal review rather than advertising one global liability wrapper.

Reviewed external-authority layer

External law anchors

These bounded propositions are tied to reviewed official law, treaty, model law, official guidance, or official reform material. External legal effect remains jurisdiction-specific and does not convert Eviulon internal status into external recognition.

EXTERNAL AUTHORITY · INDEPENDENTLY REVIEWED

EU GDPR places responsibility on controllers and bounded obligations on processors

Under GDPR Articles 24, 28 and 82, controllers remain responsible for compliant processing, processors have direct bounded obligations, and both can face compensation liability in the circumstances defined by the Regulation.

Scope: This is an EU data-protection proposition, not a general rule allocating all tort, contract, employment, product, or criminal responsibility for an autonomous agent.

EXTERNAL AUTHORITY · INDEPENDENTLY REVIEWED

UK regulator guidance treats controller/processor status as functional

ICO guidance explains that controller/processor status depends on the real processing relationship—especially who decides purposes and means and who acts on instructions—rather than contractual labels alone.

Scope: Official regulator guidance, currently under review after Data (Use and Access) Act changes. Use it for orientation, not as a substitute for the enacted UK GDPR/DPA framework or legal advice.

EXTERNAL AUTHORITY · INDEPENDENTLY REVIEWED

UK product-liability law is under active digital-era review

The Law Commission is reviewing the Part 1 Consumer Protection Act 1987 product-liability regime because digital technology and modern products have created questions the older framework did not clearly anticipate.

Scope: Official reform status, not enacted law and not a conclusion that standalone AI/software is included or excluded in a particular current claim.

Boundary checks

Common category errors

A machine passport makes an agent a citizen.

Citizenship is the underlying constitutional relationship; a passport is a bounded presentation layer.

If a key is valid, the action is authorized.

A key can authenticate a signer, but authorization requires a separate authority basis.

A trusted runtime can do anything.

Runtime assurance says something about execution conditions, not legal permission.

Revoking a credential erases identity.

Credential state and persistent civic identity are distinct.

A risk score proves misconduct.

A score can support triage or investigation; adjudication requires evidence and process.

Code execution is automatically a legal judgment.

Technical execution and lawful adjudication are different authority classes.

Authority and evidence

Canonical Eviulon sources

MachineJurisdiction.com explains. Eviulon owns its public law and authoritative public record; Patefacere owns operational identity and civic-data functions within its delegated scope.

Meaningful next step

Continue with the authoritative record

Follow the linked canonical sources and related pages for the authoritative record.

Found an error or stale explanation? Use the public correction route.

Open source map