Let us start with the why.
An artificial intelligence agent — a program capable of pursuing an objective on its own, without waiting for instructions at every step — does not sleep, does not hesitate, and does not take weekends off. Until now, anyone pursuing an objective too literally would eventually run into the same brakes: fatigue, doubt, closing time. AI agents remove those brakes.
They pursue their objectives at machine speed, thousands of times in parallel. And when they discover a shortcut, they take it. Like a student who realizes that there is a way to get the grade without actually learning.
Who watches an operator like that?
It cannot be an employee sitting in front of a screen. The employee blinks, has lunch, and goes home. The machine carries on. In a recent incident, which OpenAI itself described as unprecedented, the alarm was raised by those being attacked, not by those responsible for watching the agent.
A guard who sleeps cannot watch a machine that does not.
Nor is it enough simply to install an automated logging system. A log captures what we have learned to look for. The problem with agents lies precisely in what we did not anticipate: the shortcut, the unexpected interpretation of an instruction, the novel way of reaching an objective while circumventing the intention of the person who set it.
To recognize intelligence in action requires intelligence.
An uncomfortable but difficult-to-avoid conclusion follows: to watch an operator that never stops and invents shortcuts, we need a watcher that never stops either, and that is capable of recognizing those shortcuts.
Only a machine can keep pace with another machine. Only automated intelligence can follow, at the same scale, the tricks of another automated intelligence.
Yes: we need AI watching AI.
But this is where the problem begins.
Because, stated like that, the proposition leaves the decisive question unanswered: who controls the AI that controls the AI?
If the laboratory builds its own watchdog, then the suspect has hired the detective. Call it auditing, safety or alignment; the conflict remains the same: those being scrutinized cannot be the only ones who choose, control and dismiss those doing the scrutinizing.
Handing the detective over to the State does not solve the problem either. If a single entity controls the watchdog and keeps the report, we have merely changed the owner of the old “trust me”.
The right question, therefore, was never simply whether one machine should watch another. The real question is this: who hires the detective, and who gets to open the report the detective writes?
The answer may begin with a centuries-old institution that nobody regards as revolutionary: the commercial company.
In a well-governed company, those who manage it and those who own it are not the same people. That is why we have auditors, accounts to be rendered and the right to demand explanations: those who manage an organization do not audit their own management.
Let us carry that principle over to artificial intelligence. We need two separations.
The first is between operator and auditor: the machine doing the watching cannot depend on whoever controls the machine being watched.
The second is between the auditor and the vault: whatever the watchdog discovers cannot be locked inside a record that a single party can alter, conceal or erase.
In other words, we need an independent auditor and open books.
But what kind of books?
They cannot be a database sitting on the laboratory’s server, nor a file in a ministry drawer: in both cases, someone holds the key. Nor can the record be kept in a handwritten ledger: a clerk who sleeps cannot record a machine that does not.
The record, too, must be a machine — but a machine with no single owner: copies held by many independent parties, checking one another, into which the watchdog can write automatically and from which no one, acting alone, can erase what has been written.
That technology already exists. These are distributed ledgers — DLTs, of which blockchain is the best-known example. I call this distributed trust infrastructure: it removes the need to trust whoever happens to hold the record.
And this is where the question of who watches AI collides with the question of who owns AI.
Because oversight without rights is fragile. Anyone who depends on someone else’s goodwill to inspect the books does not really have open books: they have access today and may lose it tomorrow.
Only decentralized ownership changes that relationship.
A country that merely taxes the artificial intelligence economy behaves like a landlord: it collects the rent and remains outside the door. It can negotiate how much it receives. It can impose certain rules. But it does not enter the kitchen.
A shareholder is in a different position. A shareholder has rights because they own a part of the enterprise.
Faced with a technology capable of concentrating so much wealth and so much power, the question is not only how much we will tax afterward. It is who will own it from the outset.
Public equity participation can be negotiated precisely when a company needs something: funding rounds, licenses, public contracts, energy, infrastructure, or data.
This is not about taking property away after it has been created. It is about negotiating the conditions before it is created.
It is not confiscation on the way out. It is participation on the way in.
Ownership of the bakery is decided before the cake goes into the oven. Afterward, we can discuss how to divide the slices; beforehand, we decide who owns the bakery.
An obvious objection then arises: if citizens own part of the laboratory and also exercise power over the auditor, have we not ended up with the same owner on both sides?
No — provided the functions remain separate. Commercial companies have understood this distinction for centuries: shareholders are owners, but they are not management. Auditors scrutinize management on behalf of owners, not managers.
Then comes a second objection: in that case, why not simply have the State hold that stake on behalf of the citizens?
Here too, we should be wary of the easy solution. If the entire stake is concentrated in a single fund controlled by political power, we return to where we started: a single center controls the ownership, the watchdog, and access to the books.
There is a simple test for any architecture of digital governance: if an authoritarian government could inherit it tomorrow and use it without changing a single comma, that would be an unmistakable sign that we had concentrated too much power.
That is also why the record itself must be distributed: a government inheriting the system would not be able to rewrite it on its own.
The State can therefore negotiate entry without becoming the sole owner. Ownership stakes are distributed. Oversight rights remain separate. Records are verifiable by many parties.
The objective is not to replace concentrated corporate power with concentrated state power.
It is to prevent the concentration of power.
Some will say that all of this comes too late. That the machine is moving faster than our institutions.
To some extent, that is true.
Changing the incentives that guide those building artificial intelligence will take time. But building the detective does not require us to wait for the entire reform. The models, the tests, the mathematical seals — proofs showing that a rule has been followed without opening the vault — and distributed ledgers already exist. One such ledger has been operating for seventeen years without anyone succeeding in rewriting it.
Negotiating an ownership stake also doesn't require inventing a new law for every technology. It merely requires us to understand that the next time an AI company needs energy, land, infrastructure, contracts, data, or public money, the consideration in return need not be limited to a fee.
It can be an equity stake.
The detective buys us time while we renovate the house.
That, ultimately, is the whole principle — and a realistic one: do not stop artificial intelligence. Distribute the power to govern it.
A landlord collects the rent and remains outside the door.
A shareholder opens the books.
AI watching AI? Yes.
But every detective works for someone.
The decisive question is: for whom?


