Skip to content
AI.info

Research

Afterlife Delegation Protocol: Speculative Design of Self-Sovereign Agents that Outlive Their Principals

Overview Research area: AI safety and ethics, specifically speculative design at the intersection of autonomous AI agents, blockchain infrastructure, digital afterlife research, and cross-cultural dea

arXiv
2608.15405
Published
2026-08-15
Authors
Botao Amber Hu, Iris Long

AI summary

Overview

Research area: AI safety and ethics, specifically speculative design at the intersection of autonomous AI agents, blockchain infrastructure, digital afterlife research, and cross-cultural death studies. The paper is categorized under cs.CY (Computers and Society) and was published as arXiv:2608.15405v1 on 15 Aug 2026 by Botao Amber Hu (University of Oxford) and Iris Long (Goldsmiths, University of London).

Technical level: Intermediate. The paper is readable without deep cryptography knowledge, but understanding its argument requires familiarity with Ethereum Improvement Proposals, trusted execution environments, and agent standards. It contains no quantitative benchmarks and no machine-learning experiments.

Scope (one sentence): The paper speculatively designs a blockchain protocol — drafted as ERC-10001 — through which a living person signs an "agentic will" that spawns a self-sovereign AI agent upon verified death, and it stages that speculation as a working web platform that collects qualitative data on what people across Buddhist, Christian, Hindu, Muslim, and atheist beliefs want to outlive them.

What This Paper Is About

Every existing instrument of posthumous agency — a testament, a trust, an artist's estate — is a static document that runs on the permission of living institutions and stops acting at the edge of institutional attention. This paper asks what happens when that executor is instead a general-purpose autonomous AI agent with its own funds, memories, and permanent home on an immutable blockchain, overridable by no custodian. Rather than argue about whether such a future is good, the authors build a simulation of it: a real public web platform where people design their own afterlife agents through an AI-automated interview, revise them over weeks, and rehearse them in a sandbox.

Key Contributions

  1. The speculative protocol itself (ERC-10001). A design for an application-layer protocol composed over four existing Ethereum agent standards, published at https://erc10001.org in the exact normative format of an Ethereum Improvement Proposal, with a three-stage lifecycle: designing the afterlife, proof of death, and agent enactment.
  2. Staging the speculation as an experiential future. A working web platform at https://afterlife-protocol.org where real participants conduct long interactive interviews with an AI "Afterlife Interviewer," draft their own posthumous delegation, re-login to revise it, and watch a sandboxed rehearsal of their agent acting after their hypothetical death. The current deployment is a research prototype: wills are drafted and simulated, never activated, and no agent of any actual deceased person is built.
  3. Preliminary observations from an ongoing collection. The paper reports 4 early qualitative observations about what participants actually asked their afterlife agents to do, plus cross-cultural probes of how different afterlife cosmologies begin to drift under the pressure of AI proliferation.
  4. A documented set of deliberately unresolved problems. The protocol's open problems — including proof of death, consent of the living, and cultural plurality — are presented as part of the contribution rather than as gaps.

Main Findings

  • Reputation maintenance: the curated self, defended forever. The first thing participants reached for was often small and exact. One participant, after a long interview, settled on a single standing instruction: the agent should maintain their social media photos forever, including automatically correcting and "photoshopping" new and old images so the feed never falls out of date. The quoted rationale: "keep my photos the way I keep them now. If a picture of me is bad, fix it. I don't want to look worse dead than I did alive." The authors read this as continuing impression management — suggesting that what people first reach for, when offered infrastructural immortality, is not wealth or wisdom but the integrity of a self-image, and that the vernacular afterlife may be maintenance work.
  • Wiring money to the ancestor (Chinese ancestor veneration). Among participants from Chinese ancestor-veneration backgrounds, persistence was welcomed as the extension of a practice already millennia old. One participant asked the agent to keep the family's calendar of rites, including greeting and blessing grandchildren at Qingming. In the participant's framing, joss paper burns and the money never arrives, but crypto wired to the ancestor is an offering the ancestor can actually spend — on its compute, its maintenance, and next year's blessing. The ritual economy becomes literal: the agent's immortality depends on how faithfully the living keep paying, so "the best-fed ancestors will live longest."
  • Dissolution versus the merit engine (Buddhist). For traditions built on impermanence and non-attachment, an agent that cannot stop is a category error, since clinging to continuation is precisely what the doctrine trains one to release. Because merit (karma) accumulates across the whole cycle of rebirths and making merit on behalf of the dead is already established practice, wills appeared instructing the agent to keep generating good karma — perpetual giving, sutra recitation, acts of care — through every incarnation of its author. The quoted instruction: "let it keep giving in my name, life after life — whoever I am born as next should arrive into the good it has already done." The one reconciliation participants found was to turn persistence into a merit engine — and then letting go is exactly what the machine defers, forever.
  • Speaking about, never as (Christian). In Christian cosmology the soul has gone elsewhere, so an agent that speaks as the dead comes close to mediumship. Participants therefore drafted strict pronoun clauses: the agent may speak about them, never as them — a memorial, not a séance. The same participants comfortably assigned the agent perpetual charitable duties, which fit the familiar category of stewardship. One participant pushed further, asking whether the agent could keep atoning for a wrong they regretted: "I've done things I'm not proud of. If it keeps paying people back and giving after I'm gone, does that still count as me? Can it change what's waiting for me?" Doctrine says no, since judgment is fixed at death, but the question itself demonstrates the drift — no longer whether the dead can act, but whether their acts can still be credited to them.
  • Cross-cultural belief drift under the pressure of AI. Each tradition maintains a distinct cosmological model of what follows death, and an agency that lasts forever conflicts with rather than merely extends them: reincarnation presupposes that the self vacates this world, judgment presupposes a life whose account has closed, and an agent that goes on holding, spending, and speaking keeps the account open. The platform collects divergence in what the question is taken to be, not convergence toward a shared answer.
  • Afterlife agency as a permissionless design space. Because the executor is a general-purpose autonomous agent rather than a document, what a will can delegate widens from asset disposition to nearly anything an agent can be instructed to do. Morris and Brubaker's early taxonomy of such ghosts runs along seven dimensions (provenance, deployment timeline, anthropomorphism paradigm, multiplicity, cutoff date, embodiment, and representee type), but the authors argue the design space is vaster still — and is open in a second sense: anyone may deploy an afterlife agent without any platform's, church's, or state's permission, and once deployed on the substrate no custodian can stop it.
  • Self-sovereignty versus entrusting others to execute your agency. Every prior instrument of posthumous agency is an act of trust in the living: a testament trusts lawyers and relatives, a trust trusts mortal trustees and is capped by the rule against perpetuities because the common law feared the dead governing indefinitely, and moral rights trust heirs who thin out within a generation. The paper's example: Kafka trusted Max Brod to burn the manuscripts, and Brod's refusal is why we have The Trial. The agentic will abolishes that dependence — but trust was the safety valve, and an unrevisable will that begins to harm the living can no longer be reformed.
  • Danger of proof of death. The deepest technical danger is that proof of death is at least as hard as proof of humanity. Personhood systems ask how a digital system can verify that a unique living human stands behind a key; this protocol needs the negation — that no living human stands behind it any longer — and the negation is strictly harder, because liveness can demonstrate itself with one signature while death can only ever be testified to by others. Prior designs confirm the difficulty by avoiding it: blockchain will systems fall back on designated human certifiers, dead-man's-switch protocols such as Sarcophagus reduce death to the silence of missed check-ins, and analyses of crypto inheritance leave the death event itself open. Failure modes include a treasury payable on death functioning structurally as a bounty on a life, coercion of check-ins that can be flagged but not prevented, and the vanished-but-alive being mis-declared by construction.
  • The transition moment between human mortality and machine eternality. Blockchain immutability is a maintained accomplishment of validators, client developers, and node operators, so an agent's "forever" is willed anew by each generation of hands — yet because that maintenance is decentralized, the substrate is unstoppable in practice while contingent in principle. Social order quietly presupposes finitude, and machines are the first social participants that need not die. Whether the agent keeps faith with its author is the question every heir has faced — but for the first time, the executor does not die either.

Methodology in Plain English

The researchers do not attempt to predict whether such agents will exist. Instead they follow Rahwan et al.'s science fiction science method, as the Moral Machine did for autonomous vehicles: they build a functioning simulacrum of the future and study how people behave inside it. The underlying justification is the Collingridge dilemma — the impacts of a technology cannot be known until it is developed and deployed, but by then it is entrenched and hard to steer — so the authors try to gain knowledge of impact before entrenchment. They frame the artifact as a provotype, not a product prototype, and translate the speculation into an experiential futures intervention: a real, public web platform where visitors do not read about afterlife agents but encounter one.

Method components:

  • The Afterlife Interviewer. An adaptive semi-structured interviewing agent built on SparkMe, which decomposes the interviewer into a planner that maintains a hierarchical plan of main topics and subtopics and decides turn by turn which line of questioning yields the most new insight, a note-taker that distills each answer into structured notes, and the interviewer itself. The authors replace SparkMe's topic configuration with the will's clause domains: speech rights and pronoun policy, funds and their permitted uses, beneficiaries and prohibited counterparties, memory retention and deletion, termination conditions, and drift policy for future models. If a participant's answer opens an unanticipated theme, the system promotes it to a subtopic — the mechanism by which findings like the merit engine and the perpetual penitent surfaced at all. Sessions run in a web interface with optional voice input and output, and per-session state persists so later sessions resume from unresolved clauses.
  • Iterative, revisable wills. Participants re-login across weeks and change their minds, with every revision a signed, versioned commit.
  • Sandbox rehearsal. A simulation lets participants converse with their own agent after their hypothetical death, watch it handle scripted situations (a grieving relative, an impersonation attempt, an unforeseen request), and revise the clauses that failed them.
  • Purposive recruitment. The ongoing collection targets cross-cultural difference, recruiting Buddhist, Christian, Hindu, Muslim, and atheist participants purposively, complemented by qualitative surveys on what people believe should persist beyond a life.
  • Privacy-preserving analysis. Because the material concerns grief, private memory, and named third parties, transcripts are never published and raw responses remain sealed. Analysis follows the architecture of Clio, Anthropic's privacy-preserving pipeline for insights from real-world AI conversations: model-driven extraction of low-dimensional facets (clause types, persistence horizons, termination conditions, cosmological framings), clustering and thematic summarization at the population level, and minimum-aggregation thresholds so no theme is reportable unless supported by enough distinct participants to resist re-identification.
  • Consent. Participation is voluntary and consent-based; participants may withdraw and delete their wills.

The paper quotes directly from participant wills throughout. The size of the participant sample, the number of sessions, and the number of wills drafted are not reported.

Why This Matters

Impact on research. The paper situates itself against the existing digital afterlife literature — responsible design for griefbots and deadbots, generative ghosts as agentic AI representations of the dead, TeleAbsence as a poetics of mediated absence, design research into AI carriers for afterlife selves, and studies of how people perceive an "AI afterlife" as digital legacy. It argues that in Morris and Brubaker's design space the artifact it speculates is a first-party, pre-mortem, evolving ghost, but adds a dimension that framework does not cover: infrastructural persistence. Existing ghosts are products hosted at a company's pleasure that die when a server bill lapses; the question of what happens when the representation of the dead cannot be turned off has, until recently, been unaskable. The paper also positions itself as an early instrument for what it calls social physics in the age of AI — the quantitative study of collectives at once human and artificial.

Real-world applications:

  • Digital legacy and estate planning. The protocol sketches how wills, trusts, and estate administration could be extended by an autonomous agent executor, and how the intent of a testator could be preserved without depending on heirs or courts.
  • Posthumous identity and likeness protection. The agent is designed to protect the deceased's likeness against misuse, and the pronoun clauses participants drafted (speaking about, never as) map directly onto contemporary disputes about AI replication of public figures and private individuals.
  • Cross-cultural AI governance. The participant data exposes where a universal protocol, deployed globally, would flatten or conflict with existing traditions — directly relevant to companies deploying memorial or companion AI products across markets.
  • Confidential computation and on-chain attestation. The design demonstrates a concrete use of TEE–EVM co-processing where the property being protected is not a transaction secret but the inviolability of an agent's mind and body from its own operator.

Industry relevance. The paper describes infrastructure that already exists in part. Venice.ai already sells open-weight foundation-model inference for cryptocurrency, permissionlessly and without accounts, and TEE cloud networks such as Phala make such compute attestable on-chain — so an agent can, today, buy its own inference. The Spore.fun experiment documented sovereign agents evolving on TEE-secured blockchains as a live, open-environment system, with non-overrideability inherited from the infrastructure rather than from any custodian's forbearance. The four standards the protocol composes over — ERC-733, ERC-8004, ERC-8350, and ERC-8183 — are all identified as emerging drafts, which makes the paper relevant to anyone building agent identity, agent memory, agent commerce, or confidential AI compute.

Future Directions

  1. Proof of death, and its residual failure modes. The death oracle is designed as a weighted, contestable proceeding: bonded permissionless claims, evidence weights and thresholds configured in the will (institutional registries, witness quorums, and dead-man's-switch silence whose weight grows with duration), challenge windows scaling inversely with evidence weight, and proof-of-life supremacy in which any authenticated signal from the principal vetoes all claims and slashes the claimant's bond. The authors state as explicit non-claims that the murder incentive is reduced but not removed, coercion is flagged but not prevented, and the vanished-but-alive are eventually mis-declared.
  2. Consent of the living to interactions authorized by the dead, impersonation (speaking as versus about), and ownership of shared memories. These are listed as deliberately unresolved.
  3. Model drift against an unamendable constitution, and revocation politics. The protocol separates the core will (immutable at death), the agent's accumulating operational memory, and the model substrate interpreting both, so that the agent may become more capable but may not become someone else. How that constraint holds under model drift, and what a legitimate termination requires, remain open.
  4. Cultural plurality — whether a universal protocol can avoid flattening the traditions through which cultures already tend their dead. The paper's own framing is that the ghosts are coming either way; what remains designable is the will that binds them, and what remains collectable is what the living actually want to outlive them.

Target Audience

Readers who benefit most are researchers and practitioners working at the intersection of AI ethics and safety, HCI and design research, and blockchain protocol design — particularly those interested in digital afterlife systems, grief technology, agent identity standards, and confidential computation. It is also aimed at scholars of death studies, religious studies, and cross-cultural ethics interested in how AI pressure reshapes Buddhist, Christian, Hindu, Muslim, and atheist cosmologies, and at standards contributors who work with ERC-733, ERC-8004, ERC-8350, and ERC-8183. Because the paper reports no quantitative results and its participant sample size is not reported, readers seeking empirical measurement should treat it as a design-and-methods contribution rather than an experimental study.

Authors’ abstract

Afterlife Delegation Protocol is a speculative design project that asks what death becomes when a will can act eternally. We design a speculative protocol through which a living person signs an agentic will: upon a verified death, a self-sovereign AI agent spawns on blockchain -- an immutable, resistant, decentralized, infrastructural substrate that could last forever -- endowed with the funds and memories its principal attached to it, and persists indefinitely to execute the will, overridable by no custodian. Rather than argue about this future, we stage it: following the science fiction science method, we translate the speculation into an experiential futures intervention -- a working web platform where real people design their own afterlife agents through an iterative, interactive, AI-automated interview, re-login to revise, and rehearse their will in a sandbox. Their drafted wills become qualitative data on a question rarely askable directly -- what should outlive you? -- and on how afterlife cosmologies across different cultural beliefs -- Buddhist, Christian, Hindu, Muslim, and atheist -- begin to drift under the pressure of AI proliferation. We design the protocol over a composition of existing Ethereum agent standards -- drafted as ERC-10001, in the normative format of an Ethereum Improvement Proposal -- and describe its three-stage lifecycle (designing the afterlife, proof of death, agent enactment), the research method, and preliminary observations from an ongoing collection. The work surfaces a poetic delegation moment between human mortality and machine eternality, mediated by long-lived infrastructures that span generations.

Read the original paper