Research Brief · Authority Does Not Travel by Default
Your data can move to a new system. Does the authority to use it move with it?
Micheal Charles Preble · Operant Dyad — Paper 3
The Question
When persistent human–AI relationship state crosses a technical or organizational boundary, what should a receiving system need to know before it uses, discloses, infers from, or acts on that state?
The Problem
Relationship state can remain useful across sessions, applications, models, and providers — and it can remain technically available after the legal basis for using it has narrowed, expired, moved to another actor, or become dependent on a different context. Different components of a continuity package can be governed by consent, contract, statute, institutional role, fiduciary duty, delegation, court order, guardianship, succession, or confidentiality — sources that differ in scope, purpose, object, recipient, jurisdiction, and duration, and that can change while the underlying state remains historically intact.
The Contribution
Argues that ownership is too coarse a master variable for this problem, that technical portability is not equivalent to lawful portability, and that source-side authority should not be treated as a context-free status that automatically survives migration. Proposes a multi-source, multi-incident model: authority can come from several different sources at once (consent, contract, statute, role, fiduciary duty, delegation…), and each source can govern a different incident of use (disclosure, correction, restriction, deletion, retention, migration, delegation, action, audit, challenge). Introduces retained-but-non-operative state: a record can survive for a legitimate historical, audit, or legal purpose while its ordinary authority to affect current interaction is removed or narrowed.
How the Argument Works
A comparative legal and institutional synthesis, not an empirical study. Grounded primarily in United States federal law with Texas used as an illustrative state-law layer (the Texas Data Privacy and Security Act, the Texas Responsible AI Governance Act effective January 1, 2026, the Uniform Electronic Transactions Act, the Revised Uniform Fiduciary Access to Digital Assets Act, and Texas trade-secret law), with EU law — the GDPR and the EU Data Act — used selectively where it sharpens correction, restriction, portability, or switching questions. The paper treats NIST's attribute-based access control model, OASIS XACML, and the W3C Verifiable Credentials Data Model as implementation neighbors that demonstrate authorization need not be a permanent property of a data object, not as sources of the paper's legal authority.
Why It Matters
A person may reasonably want to move between AI providers without reconstructing every correction and preference from zero — but a successful technical export only proves information can be transported, not that the exporter possessed every legal incident the destination needs for its intended use. The paper's destination-side revalidation principle asks the receiving system to evaluate current operability in its own context, rather than inheriting a context-free authorization status.
Evidence Status
Evidence status: Conceptual legal and institutional analysis, illustrative rather than exhaustive, bounded to U.S. federal law, Texas as an illustrative state layer, and selected EU law.
What This Does Not Claim
- Does not claim to invent contextual authorization, attribute-based access control, verifiable credentials, revocation, portability rights, guardianship law, or trade-secret law.
- Is not a fifty-state survey, a global comparative study, or an exhaustive treatment of any regulated sector.
- Does not currently meet the burden of proving no adequate cross-provider authority architecture already exists — and does not need to, to make its narrower contribution.
- Explicitly invites its own residual claim to be narrowed or closed if a sufficient architecture is shown to already exist (the paper calls itself “deliberately falsifiable”).
Open Questions
Whether mature, generally applicable mechanisms already provide a sufficient cross-provider architecture that binds heterogeneous relationship-state objects to their legal authority sources, carries lifecycle constraints interoperably, and produces destination-side revalidation is the paper's own open residual question — and it says explicitly that if the answer is yes, its contribution should be narrowed rather than defended.
Read / Cite the Research
Read the canonical paper record → · Full paper PDF · View on SSRN
Preble, Micheal Charles. “Authority Does Not Travel by Default: Legal Provenance and Revalidation in Persistent Human–AI Continuity” Available at SSRN 7359661, 2026.