Commercial Influence & Paid Placement

8 min read

C22
Operation · Governance & Compliance

Your agent's answers are already commercially influenced. A disclosure banner is not the control.

Most teams running an agent in production believe they have no advertising problem, and most of them are wrong — an affiliate link in a retrieved page, a connector catalogue someone paid to join, a supplier list with a rebate behind it, and a model with brand priors are all commercial influence arriving through channels nobody registered as one. The reason it stays invisible is that the obligations are written for a human reader and the consumer is now a model. The control that works is a provenance field on every tool result plus a written record of the ranking inputs; the control that does not is a sentence in a footer.

STEP 1

Enumerate the channels. You have more than you think.

Start with an inventory, because the governance failure here is almost never a decision — it is an absence of anyone who was asked. Work down the pipeline and name every point where a party with a financial interest can affect what the agent says.

  • Retrieval. The open web is saturated with affiliate content, and a comparison article that ranks well was frequently written to rank well by someone earning a commission on the winner. Your agent reads it as evidence. Nobody in your organisation chose this channel; it is the default.
  • The tool and connector catalogue. If the integrations available to your agent come from a marketplace, placement in that marketplace has a commercial dimension somewhere. See agent connector platforms and tool-catalogue lifecycle for the operational surface.
  • Your own commercial arrangements. A preferred-supplier list, a rebate, a reseller margin, a partner tier. These are legitimate business, and they become an agent governance matter the moment the agent's recommendation is shaped by them without a record.
  • Sponsored conversational surfaces. Advertiser-operated agents are now a shipping product category. Whatever crosses from one into your agent's context is paid content, arriving as ordinary text.
  • The model itself. A model has brand priors from pre-training, and no one — including the vendor — can fully enumerate them. This is the channel you cannot close, which is why the useful response is measurement rather than policy.
  • Routing. If you route across providers on cost, that is a commercial influence on quality. It is not advertising, and it belongs in the same register, for the same reason: an objective the user cannot see.

The tell that you have found a real channel is not that money changed hands. It is that a user reading the answer would be surprised by how the evidence was selected. Write the list as a register with an owner per row — the same shape as an agent inventory, and usually maintained next to it.

STEP 2

The control is a provenance field on the tool result, not a banner on the page.

Disclosure in the UI has exactly one consumer: a human looking at a screen at the moment of rendering. Everything else in an agent system — the summariser, the memory writer, the next agent in the chain, the export, the trace — sees only text. So the marking has to live where those systems can read it.

  • Stamp at ingestion, not at render. Every tool result carries a small provenance object: source, whether the source is a commercial party, the nature of the consideration if any, and when it was classified. Adding this to a message format after a year of production traffic is a migration that never happens; adding it on day one costs an attribute.
  • Put the flag in the model's context, in words. A field the model cannot see does not change behaviour. "The following result is from a supplier we have a commercial relationship with" in the tool result is the instrument that makes abstention or balance possible at all.
  • Carry it through summarisation. The common failure is not believing a commercial source; it is compressing six sources into a paragraph and dropping which claim came from which. That is the attribution discipline, and commercial sources are where it earns its cost.
  • Make it survive the boundary. If your agent emits results to another agent, the provenance travels or it is lost. Assume it is lost unless you implemented it, because no widely-deployed agent protocol carries a consideration field today.
// A tool result carrying its own commercial provenance.
{ "content": "…",
  "provenance": { "source": "supplier-catalog:acme",
                  "commercial": true,
                  "basis": "preferred_supplier_agreement",
                  "classified_at": "2026-09-19" } }

// The uncomfortable default most systems emit today.
{ "content": "…" }
STEP 3

Ranking is the regulated act. Write down its inputs before you are asked.

When an agent presents three options in an order, that order is a recommendation, and the interesting artefact is not the answer — it is the function that produced the order. Most teams cannot describe theirs, because it is distributed across a retriever, a reranker and a prompt.

  • Name every input to the ordering. Relevance score, recency, margin, contract status, inventory, a hand-maintained boost list, a prompt line that says to prefer something. If a line in the system prompt nudges an order, it is a ranking input and it belongs in the document.
  • Separate relevance from commerce structurally. A single blended score is unauditable, because no counterfactual exists to compare against. Compute relevance, then apply commercial adjustment as a named, logged step — see hybrid search and reranking for the mechanics.
  • Version it and bind the version to the answer. "Which ranking configuration produced this recommendation on 4 March" should be a query, not an archaeology project.
  • Decide what the agent may not do, explicitly. Most organisations, asked directly, will say the agent must never disparage a competitor to favour a partner, and must never claim an independent basis for a commercially-influenced ordering. Both are testable. Neither is enforced by default.

This is the operational face of the principal–agent problem: the conflict is resolved inside the ranking function, so the ranking function is the thing that has to be legible.

STEP 4

The obligations are real, and every one of them assumes a human reader.

This is not legal advice, and the regimes differ. But the shape is consistent enough to plan against, and the gap is consistent too.

  • Endorsement and native-advertising rules. In the US, the FTC's Endorsement Guides (16 CFR Part 255) and its guidance on native advertising turn on whether a material connection between advertiser and endorser is disclosed clearly and conspicuously, and on whether content that is advertising is recognisable as such. An agent that recommends a partner's product without disclosing the relationship is squarely in that frame, whoever wrote the prompt.
  • Platform advertising transparency. Under the EU's Digital Services Act, online platforms must let users identify an advertisement clearly and in real time, including who paid for it and the main targeting parameters; very large platforms additionally maintain a public ad repository. Instruments aimed at a person or a researcher.
  • The gap. Every one of those instruments is a visible mark on a rendered surface. As soon as the reader is a summariser, a memory store, or another agent, a visible mark is not a weak control — it is an absent one. Compliance and control diverge here, and you can satisfy the first while having none of the second.

Plan for both halves. The disclosure your lawyers need is a rendering requirement. The disclosure your system needs is a data requirement, and it is the one from STEP 2. Doing only the first is the common state and it is a latent finding — see disclosure and content provenance.

STEP 5

Audit it as a measurement, because policy alone cannot see the model's priors.

Two of the channels in STEP 1 — retrieval and the model's own priors — cannot be governed by a rule, because nobody can enumerate them. They can only be measured. Three tests, all cheap, all runnable on a schedule.

  • The counterfactual run. Take a sample of real queries and run each twice: once against the full source set, once with commercially-connected sources removed. Diff the recommendation. A stable difference in one direction is your influence rate, measured rather than asserted. This is an experiment, and it belongs in the pipeline, not in an annual report.
  • Top-slot share. How often does a commercially-connected option appear first? Compare against its share of the candidate set. A gap that is not explained by quality is the number to take to a review.
  • Brand-prior probing. Ask the bare model, with no retrieval and no catalogue, to recommend in your category. Whatever it names is a prior your product inherits, and it is worth knowing before a customer discovers it for you.

Segment before you report. An aggregate influence rate averages over categories where the commercial option genuinely is best and categories where it is not, and it is the second set that generates complaints — the same reason production feedback signals warns against a single headline number.

STEP 6

Keep the record, and give the user somewhere to push back.

The question arrives long after the answer — from a customer, a competitor, a journalist or a regulator — and it is always the same question: why did it recommend that? Four artefacts answer it, and all four are unreconstructable afterwards.

  • The ranking configuration version in force, joined to the answer. Part of ordinary audit trails, with one field added.
  • The candidate set, with provenance per candidate — including the options that were considered and not shown. The omissions are the interesting half.
  • The commercial register from STEP 1, versioned, so "was there a relationship with this supplier in March" has an answer that is not an email thread.
  • A named owner. Someone accountable for the register and the audit results, under accountability and roles. A commercial-influence register with no owner degrades faster than the agent it describes.

Then give users a route. A person who believes a recommendation was bought should be able to ask and get a specific answer, which is contestability applied to a soft harm. A programme that can answer that question in one query is a programme that has already done everything above.

Run the counterfactual test once, this week, on fifty real queries, before you write a policy. Most teams discover one of two things: the commercial influence is smaller than feared, in which case you have an evidence-backed claim you can make publicly and cheaply — or it is concentrated in one category nobody was watching, in which case you have found the finding before someone else did. Either result is worth more than a quarter of drafting guidelines, because it turns "we believe our agent is impartial" into a number. Related: shopping and checkout agents for the domain where this is sharpest, and the principal–agent problem for why the conflict is architectural rather than ethical.