AI agents are beginning to move from assisting consumers to acting on their behalf . Agentic commerce remains at an early stage , with agent-mediated transactions currently representing only a fraction of global e-commerce, but the trajectory is significant.

McKinsey estimates that AI agents could mediate between $3 trillion and $5 trillion of global consumer commerce by 2030, while Gartner projects the broader market for standalone AI agents and assistants to grow thirteenfold between 2025 and 2030.

But when agentic commerce enters beauty and fashion, men and women are not necessarily situated in the same way. Beauty is already one of the sectors in which AI-mediated discovery, recommendation and purchasing are expected to expand rapidly. McKinsey expects e-commerce, including social and agentic commerce, to account for the majority of beauty-market sales growth through 2030.

Gender imbalance in algorithmic power

The case of women is particularly relevant not because algorithmic influence is unique to women or because men are absent from the beauty market, but because beauty and fashion intersect with several documented gender asymmetries.

Women encounter more prescriptive appearance norms. Those norms can carry distinctive social and economic consequences for them. And many of the commercial markets built around appearance are highly gender-segmented, with important categories disproportionately targeted toward women. Research has found that the appearance norms encountered by women in everyday life tend to be more rigid, homogeneous and pervasive than those encountered by men.

Other research has documented that appearance expectations can translate into distinctive social and professional penalties for women. Experimental studies on what researchers call the “prescriptive beauty norm” found higher appearance requirements imposed on women seeking powerful positions and identified a “beauty tax” that targeted women more than men.

The commercial environment is also highly gender-structured. Research on gendered pricing in personal-care markets provides evidence of how strongly some appearance-related product categories are segmented by gender. One study found that gender-targeted products accounted for 80% of sales across the personal-care categories examined. Among those gender-targeted products, some categories were strongly oriented toward women .

The algorithmic power exercised through an AI shopping agent can therefore become particularly consequential when directed toward women in these domains. It enters an environment in which appearance norms, social expectations and commercial incentives already participate in shaping preferences, prescribing what is considered appropriate and thereby limiting or constraining women’s agency.

An AI agent that buys on a woman’s behalf is exercising delegated power over three intimate domains at once: how she presents herself, how she is perceived, and how she spends her resources.

But by entering that environment, it does more than automate purchasing. It can operationalize and exacerbate those existing pressures through the choices it prioritizes and ultimately executes.

And because those pressures are more consequential for women in these domains, the agent’s algorithmic power can correspondingly contribute to a greater erosion of freedom and a greater risk of domination for women than for men.

What makes algorithmic power legitimate

The question of what makes algorithmic power legitimate for such a system takes on particular significance for women and cannot be answered simply by asking whether the agent is accurate, convenient, or even preferred, nor by appealing to consent understood as a single click buried somewhere in a settings menu.

Power does not become legitimate simply because we asked for help. It must demonstrate that its authority is bounded, contestable, and genuinely derived from her rather than from the hidden commercial incentives surrounding her, such as making her spend more, favor certain brands, or buy products that are more profitable for the platform.

This is what Trias Algorithmica 1 is designed to enable. Just as Trias Politica provides a constitutional architecture for separating legislative, executive, and judicial power, Trias Algorithmica 1 provides a framework for separating algorithmic power through the same three functions that reassemble and become fused within algorithmic systems.

Algorithmic legislative power lies in the authority to define the ends a system should pursue. Algorithmic executive power consists in translating those authorized ends into decisions and actions. Algorithmic judicial power resides in the capacity to review those actions, contest them, and determine their consequences when delegated authority has been exceeded or misapplied.

No single actor should simultaneously define the system’s ends, operationalize them through that system, and determine whether the resulting exercise of algorithmic power is acceptable.

It is worth underscoring the importance of this separation, especially when an algorithmic system acts on a person’s behalf.

Applied to the case raised here, let’s do something that is not recommended but is, unfortunately, often done: anthropomorphize AI. Let us introduce Joe. Joe is an AI agent installed on Lily’s smartphone and connected, with her permission, to her preferred online stores, calendar, delivery address, and a digital payment method. Joe can browse websites, compare prices and delivery times, remember Lily’s preferences, communicate with sellers, and complete purchases within limits that she has previously set.

Lily is a twenty-year-old university student living away from home for the first time. She studies full-time, works a few hours a week in a café, and uses Joe to reduce the time she spends on routine online purchases. Rather than searching through dozens of websites herself, she might simply tell Joe: “Find me a pair of waterproof boots for winter, preferably black, under $120, and have them delivered before Friday.” Joe then searches available offers, compares the relevant options, selects what it considers the best match, and, if the purchase falls within Lily’s pre-authorized limits, places the order on her behalf.

But before Joe can act for Lily, someone must decide what Joe is actually entitled to pursue on her behalf. That includes what counts as a good purchase, which preferences should prevail when price, quality, speed, sustainability, or convenience point in different directions, and where the limits of Joe’s discretion should lie. This is the legislative dimension of Trias Algorithmica 1 , which concerns who has the authority to determine the purposes, priorities, and limits that govern Joe’s algorithmic power.

It starts with something simple. Joe should not be designed in ways that allow either Joe’s provider or Joe itself to determine unilaterally what “best for her” means.

Does Joe prioritize price, beauty norms, novelty, status, sustainability, comfort, social approval, or retailer margin?

These priorities can be encoded in Joe through system instructions, preference models, ranking criteria, reward mechanisms, business rules, or other design choices that shape how Joe selects and acts. They may be presented as technical parameters, but they are above all normative choices. These priorities must originate from Lily’s preferences, remain revisable by her, and be protected from hidden substitution by the incentives of Joe’s provider or platform.

That is why the separation between goal-setting and machine-making should require something more structural than a settings menu. Lily’s goals, constraints, and trade-offs should belong to a distinct objective layer that Joe’s provider is required to serve but cannot silently rewrite. The provider may determine how Joe pursues an authorized objective, but building Joe should not confer unilateral authority to redefine what success means for Lily, on whose behalf Joe acts. In that sense, Joe’s provider should not control both the machine and the layer that gives it its purpose.

The implication goes further. Representation should not quietly collapse into persuasion. Joe, when acting as Lily’s economic representative, should not simultaneously serve as an undisclosed channel through which another actor attempts to modify her choices for commercial advantage. Where Joe moves from serving an existing preference to attempting to influence one, that change of role should itself become visible and contestable by Lily herself.

Once Lily has defined what Joe is entitled to pursue, a different question arises. Joe must still decide how to pursue those objectives in practice, how to weigh competing options, which information to prioritize, when to recommend rather than act, and how far it may go without returning to Lily for further instruction. In other words, even where Lily has defined Joe’s mandate, that mandate should not amount to a blank check for Joe to pursue it by any means or in any manner it chooses.

This brings us to the executive dimension of Trias Algorithmica 1 . Joe may appear to act on Lily’s behalf while, in reality, its decision architecture is, for example, optimized to increase affiliate revenue, thereby channeling commercial interests through the appearance of personal assistance. Joe necessarily needs a degree of discretion, granted by Lily, over how to search, rank, recommend, negotiate and ultimately act. But that executive discretion cannot legitimately be used to game Lily’s mandate, exploit loopholes within it, or otherwise act in ways that undermine the very mandate that authorizes its exercise.

Before spending, Joe should therefore operate within explicit budgets, category limits, and approval thresholds. Higher-stakes or irreversible purchases should require stronger authorization from Lily. Joe should also preserve a trace of its decision-making process, enabling it to explain not only why an item fits her stated preferences, but why spending that amount, at that particular moment, is justified within the mandate it has been given.

One separation mechanism that matters here addresses the boundary between training governance and optimization. The objectives embedded through Joe’s training, post-training, system instructions, and other design choices should constrain how Joe optimizes, without allowing it to shape Lily’s preferences and then interpret those shaped preferences as authentic expressions of her own choices. This matters because recommendation systems can participate in forming the very desires they later interpret as evidence of what a person wants.

Concretely, in Lily’s case, this means that Joe should not behave as if there were a de facto equal sign between her past purchases and her preferences, as though those preferences were a fixed pie waiting to be extracted. Joe should therefore distinguish between what Lily has explicitly chosen, what it has inferred, and what its own interventions may have helped shape.

But distinguishing these categories conceptually may not be enough. Joe, when exercising delegated algorithmic purchasing power, should be required to preserve the provenance of the preferences on which it acts. This means keeping track of which preferences were explicitly declared by Lily, which were inferred from her behavior, which emerged from recommendations made by Joe, and which may have been influenced by commercial interventions. Verifiable intent tells us what Lily authorized. Preference provenance establishes where the preferences underlying that authorization came from.

Preference provenance therefore helps preserve the boundary between the algorithmic legislative power that defines Joe’s mandate and Joe’s executive power to act on Lily’s behalf.

Who holds whom to account

After Joe has acted on Lily’s behalf, a final question remains. Someone must be able to determine whether Joe operated within the authority Lily granted, whether it respected the limits of its mandate, and what should happen if it did not. A decision may have been technically valid yet still result in consequences that Lily wishes to question because she would never have agreed to bear them. Delegated algorithmic power therefore requires not only rules governing what Joe may do and how it may act, but also a mechanism for reviewing what Joe has actually done so that Lily can challenge or appeal the outcome.

This leads us to the judicial dimension of Trias Algorithmica 1 . At this stage, the algorithmic separation between contestability and algorithmic finality comes into play. The fact that an AI agent has the technical capacity to execute a purchase should not give its decision automatic finality. Nor should the entity that controls the AI agent’s exercise of algorithmic power have exclusive authority to determine whether that exercise was legitimate. Contestability must therefore remain structurally distinct from the mechanisms that confer finality on the AI agent’s decisions. Review must be capable of operating independently from the exercise of the power being reviewed.

Every purchase that materially affects Lily’s financial, legal, or personal interests should be appealable by Lily herself. For that appeal to be meaningful, she must be able to reconstruct why Joe selected a particular item over the alternatives, what information informed that decision, and whether a different authorized objective would have produced a different outcome.

If Joe materially exceeds, misinterprets, or acts outside the authority delegated to it, Lily should not automatically bear the cost of that failure. There must be a clear allocation of responsibility between Joe’s provider, the payment provider, the seller, and Lily as the user.

This means that contestability cannot stop at providing an explanation or an audit trail. It must also determine who bears the economic risk created by Joe’s algorithmic discretion. Where the failure originates in the exercise of a power controlled by Joe’s provider, the payment provider, or another intermediary, the default burden should not simply fall on Lily merely because she delegated authority to Joe.

An AI agent whose decisions cannot be interrogated and whose failures leave the user carrying the consequences becomes convenient precisely because it removes the friction of disagreement.

That question of responsibility also points back upstream to how the AI agent’s authority is defined before any transaction takes place, and connects directly to the separation between goal-setting and machine-making, because budgets, approval thresholds and spending limits do more than constrain the AI agent’s behavior. They define the conditions under which the system can legitimately convert a recommendation into an economic act.

The right to legitimate algorithmic power

Other separation mechanisms can prevent the fusion of algorithmic legislative, executive, and judicial powers, but the decisive test is simple. Does the system expand human agency, or is it designed to make its own influence humanly invisible and frictionless?

Whoever uses an AI agent, one thing remains constant in determining whether the algorithmic power exercised through that relationship is legitimate, even though we are not all exposed to the same risks, nor to the same degree, because the social structures and norms that already shape our environment affect how that power is experienced.

Legitimate algorithmic power should leave us more capable of choosing, understanding, refusing, contesting and changing course.

The industry is developing mechanisms for safe AI agent delegation. Trias Algorithmica 1 asks what would make that delegation legitimate algorithmic power.

That distinction matters. If convenience grows, even when delegation is safe, while human agency shrinks, the system has not earned algorithmic legitimacy over human choices. It has only expanded its power over them.

The journey towards legitimate algorithmic power has just begun. It is a right still to be claimed. A right still to be won. For all.

1 Learn more in, Trias Algorithmica: What Code Rules.