Research Poster · Authority Does Not Travel by Default

Authority Does Not Travel by Default: Legal Provenance and Revalidation in Persistent Human–AI Continuity

Micheal Charles Preble · Operant Dyad — Paper 3 · SSRN 7359661

Problem · Background · Research Question

Problem

Relationship state can remain intact and technically available even when the authority governing its use has narrowed, expired, or moved to a different actor.

Background

Builds on mature access-control (NIST ABAC, OASIS XACML), credentialing (W3C Verifiable Credentials), and legal (GDPR, EU Data Act, U.S. state privacy law) traditions as implementation and legal neighbors, not as the paper's own inventions.

Research question

What legally material provenance and authority-state information should a continuity architecture preserve so a receiving system can evaluate current operability?

Central diagram: the boundary map (13 non-collapse findings)

  • Technical portabilityis notlawful portability
  • Source authorityis notdestination authority
  • Retentionis notoperative use
  • A guardianis nota universal controller
  • A supporteris not automaticallya substitute decision-maker
  • Third-party presenceis nota universal veto
  • Automationis notlegal authority
  • Provider custodyis notprovider supremacy
  • Person-centerednessis notexclusive personal legal control

Propositions / Observable Implications

  • Multi-source, multi-incident: a single continuity package can be governed by several different authority sources at once, each covering a different incident of use.
  • Lifecycle state: the underlying record and the authority governing it can move on different timelines — a delegation can expire while the actions taken under it remain auditable.
  • Destination-side revalidation: a technically valid source-side assertion may be accurate and still insufficient for the destination's proposed operation.

Evidence Required

A comparative legal and institutional synthesis grounded in real, cited primary authority: the Texas Data Privacy and Security Act, TRAIGA (eff. Jan. 1, 2026), Texas UETA, RUFADAA, the Stored Communications Act, GDPR Articles 15–22 and 77–83, and the EU Data Act Articles 23–31. Not an empirical study — no new data was collected.

Limitations

U.S.-law-primary, with Texas used only as an illustrative state layer, not uniform national law. EU law used selectively, not comprehensively. Some underlying project research had to be reconstructed from preserved materials during an August 2026 rebuild; reconstructed material was treated only as a recovery aid, never as independent legal authority.

Falsifiers / Open Questions

The paper explicitly calls its residual claim “deliberately falsifiable”: if a sufficient cross-provider authority architecture is shown already to exist, the claim should be narrowed or closed rather than defended as novel.

Citation / QR

Suggested citation
Preble, Micheal Charles. “Authority Does Not Travel by Default: Legal Provenance and Revalidation in Persistent Human–AI Continuity” Available at SSRN 7359661, 2026.

research.perfinitive.com/publications/authority-does-not-travel