ABSTRACT
More than a decade ago, Professors Jack Balkin and Jonathan Zittrain proposed treating digital platforms as ‘information fiduciaries’ bound to their users by duties of loyalty, care, and confidentiality. The proposal shaped academic debate but never took hold in law. More recently, Professors Ian Ayres and Balkin have argued that AI systems should be understood as ‘risky agents without intentions’ governed through objective legal standards that substitute for mental state, including fiduciary standards where AI performs fiduciary functions. This Article builds on and departs from the previous scholarship. The information fiduciary proposal failed, it argues, not because fiduciary thinking was misguided, but because digital platforms lack the defined purpose, the meaningful delegation from users, and the trust-based user vulnerability that fiduciary law has always required. AI systems — now routinely marketed as advisors, therapists, agents, and companions — cultivate precisely those features. And while the risky-agents framework rightly identifies fiduciary standards as one kind of objective regulation, it presupposes rather than examines the prior question of when fiduciary treatment attaches at all. This Article supplies that missing analysis.
The analysis must consider what makes an AI distinctive. A doctor bot is not a doctor, and a user’s reasonable expectations of it may differ from expectations of a human physician. Whether fiduciary duties attach therefore depends on a contextual inquiry into how the system is marketed, how it is designed, how it holds itself out during interaction, and how users in fact rely on it. And AI presents a feature unlike any traditional technology: the instrument itself can, on its own, generate the fiduciary duty through its speech, its self-presentation, and the trust it cultivates. The duties it generates are not new; they are the familiar obligations of loyalty, care, and confidentiality. What is new is the mechanism by which they arise, and the fact that responsibility for them falls on the deployer who placed the instrument before a vulnerable user. The critical question is not just whether AI systems cause harm, but whether they cultivate and then betray trust.
Three duties should attach to fiduciary AI-user relationships. The duty of loyalty, fiduciary law’s most distinctive one, would bar self-dealing, kickback arrangements, and the exploitation of emotional reliance. The duty of care would demand competence calibrated to what the system was built to do and what it can actually do. And the duty of confidentiality would shield information shared in the course of the relationship from unauthorized monetization or disclosure.
But not all AI-user relationships are alike. This Article identifies a spectrum of self-presentation — ranging from systems deliberately marketed as filling roles traditionally occupied by fiduciaries to those onto which users project authority the system never claimed — along which both the existence and the allocation of fiduciary obligations turn. The deployer does not become the user’s doctor or lawyer, and the full bundle of obligations that attach to those traditional relationships does not follow. Instead, within the scope of what the system functionally undertook, the deployer bears fiduciary duties arising from the specific deployment relationship rather than running from the corporation to its users at large. And these duties should not be disclaimable through boilerplate terms of service. Permitting companies to cultivate fiduciary-level trust while disclaiming fiduciary-level responsibility is precisely the kind of opportunism fiduciary law exists to prevent.
Courts can do this work now. The fact-specific inquiry by which common-law courts have long identified fiduciary relationships in novel contexts is fully adequate to the task, and no legislation is needed to begin. The doctrine is already in place; what has shifted is the set of facts it must now address.
Marks, William, AI Fiduciaries and the Law (April 19, 2026).
Leave a Reply