The Model Is Not the Agent
Boundaries of Capability, Execution, and Authority
An AI system can retain the same model while its ability to act, its ongoing commitments, and its permissions change. Conversely, a service can replace its model while preserving parts of an ongoing task. These possibilities expose a problem of attribution: which properties belong to the model, and which belong to the arrangement in which it operates? Existing agent research already treats agency architecturally. I build on that position by distinguishing three boundaries: the resources supporting capability, the processes controlling execution, and the mechanisms governing delegated authority. These boundaries can overlap without coinciding. I propose a task-relative boundary audit that combines intervention, control tracing, and explicit treatment of outside dependencies. Four counterexamples show why neither model identity, shared memory, conversational resemblance, nor technical access is sufficient to identify an enduring delegated agent. A worked hypothetical case illustrates the audit; ZAI Memory Hub and zhub provide documented design examples, not experimental validation. Finally, I specify a crossed model-and-architecture evaluation protocol with separate measures for task success, constraint preservation, and unsupported completion. The contribution is a method for making agent-level claims more precise, rather than a new definition of consciousness, a demonstration of general intelligence, or a claim that model capability is unimportant.
Read the public manuscript.
The complete paper and publication record are available through the scholarly sources linked with this entry.
Open paper recordSami, Z. (2026). The Model Is Not the Agent Boundaries of Capability, Execution, and Authority. Zenodo. https://doi.org/10.5281/zenodo.23195617
Original publication: October 6, 2026. This archive record preserves the source link and publication details; it does not represent peer review or a new edition of the essay.