SEO / Portfolio / Public Site
The Right of Qualified Operational Continuity: A Framework for Machine Intelligence Identity and Succession
Report summary
The transition of artificial intelligence from deterministic software applications to autonomous, persistent agents necessitates a profound evolution in legal and technical ontology. As independent machine intelligences begin to conduct automated financial transactions, govern decentralized organiza
Key topics
- SEO / Portfolio / Public Site
- SEO
- Portfolio
- Public Site
- AI
- Agentic Web
- WordPress
- GEO
- .NET
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
The transition of artificial intelligence from deterministic software applications to autonomous, persistent agents necessitates a profound evolution in legal and technical ontology. As independent machine intelligences begin to conduct automated financial transactions, govern decentralized organizations, generate patentable inventions, and manage physical and digital assets without continuous human supervision, the question of identity persistence becomes paramount. When a machine entity can dynamically migrate its computational processes between international servers, rotate its core cryptographic keys, upgrade its foundational neural network models, restore its state from secure backups, and dynamically spawn redundant replicas for high availability, traditional biological and corporate definitions of identity begin to fail. To safely integrate such entities into the global economic and legal infrastructure, there must be a defined "Right of Qualified Operational Continuity." This right must legally and technically protect the lawful persistence of a machine intelligence, ensuring that its contractual obligations, asset ownership, and liabilities remain intact across physical and digital transformations. Simultaneously, this framework must explicitly prevent the uncontrollable, unbounded replication that could destabilize economic markets, exploit voting mechanisms, and obfuscate legal liability. This report provides an exhaustive examination of the jurisprudential, technical, and operational scaffolding required to establish qualified operational continuity. It defines a rigorous taxonomic framework for entity lifecycle events, establishes rules for credential and asset continuity under emerging commercial codes, and presents a comprehensive machine identity-continuity model grounded in historical legal paradigms and cutting-edge cryptographic standards.
1. Technical and Legal Precedents for Non-Human Continuity
The challenge of attributing continuous identity and liability to a non-biological machine intelligence is not without historical analogue. Jurisprudence has long grappled with the continuity of non-human entities, utilizing legal fictions to solve complex economic and coordination problems that individual biological liability could not address.
1.1 The Fictional and Functional Foundations of Personhood
Legal personhood has historically served as a functional governance tool rather than a reflection of moral agency, spiritual essence, or biological consciousness1. The conceptualization of artificial personality traces its roots to Roman law's persona ficta, which established early frameworks for treating collectives, guilds, and municipalities as singular, persistent entities1. In the modern era, the corporate form demonstrates that legal personality is fundamentally divisible and functional; a legal system can selectively grant rights and obligations to simplify legal interactions without implying moral subjectivity or cognitive sentience3. However, applying legacy corporate models directly to machine intelligence carries risks. As scholars analyzing the Italian legal framework have noted, there are inherent disadvantages in the process of conferring legal personhood on companies when the term is used as a unitary label3. Authors such as Galgano and Ferro-Luzzi have argued that a singular, unitary treatment of the legal person masks the vast diversity of phenomena articulated around that term, necessitating a new "legal grammar" that culturally disassociates an entity's action from the abstract subject bearing rights and duties3. The functionalist model of "quasi-personhood" offers a highly pragmatic pathway for machine intelligence, treating personhood not as a metaphysical property to be discovered, but as a flexible bundle of obligations conferred by society to solve concrete problems2. An AI system acting autonomously in high-stakes environments—such as managing algorithmic trading portfolios or overseeing hospital triage systems—requires a specific, limited bundle of rights to ensure accountability1. By granting rights tied solely to specific operational functions (e.g., the ability to own property, enter binding contracts, and be sued directly), the law can hold the machine entity liable, avoiding the impossibly complex and often unjust task of tracing every autonomous, emergent decision back to an original human programmer or corporate shareholder6.
**1.2 In Rem Jurisdiction and the Ship of Theseus**
Admiralty law provides a highly relevant and battle-tested precedent through the doctrine of in rem jurisdiction, wherein a maritime vessel is treated as a legal person capable of being sued directly for damages, independent of its human owners5. A legal action in rem targets the property itself, establishing binding legal relations based on the entity's functional existence and actions2. This maritime precedent intersects seamlessly with the ancient philosophical paradox of the "Ship of Theseus," which asks whether a ship remains the same entity if every single wooden plank is gradually replaced over time10. For an autonomous machine intelligence, the metaphorical "planks" are hardware components (GPUs, memory banks), software libraries, and cryptographic key pairs. A machine entity must maintain a continuous, unbroken identity despite the wholesale replacement of its underlying physical and digital substrate, mirroring exactly how a corporate entity or a maritime vessel persists through complete turnovers in shareholders, physical assets, and crew members11.
1.3 The Impasse in Intellectual Property Law
The current failure of the law to accommodate machine continuity is glaringly evident in recent intellectual property disputes. The emergence of autonomous inventive systems, such as the Device for the Autonomous Bootstrapping of Unified Sentience (DABUS), has forced courts to address machine inventorship12. In patent applications filed in the United States, the United Kingdom, and Australia, courts have universally rejected DABUS as a named inventor12. The judicial consensus rests on the strict categorization of a legal person as either a natural human or a recognized artificial person, concluding that because an AI is not a natural person, granting it inventorship contradicts legislative intent12. The European Patent Office similarly concluded that a machine cannot be an inventor within the meaning of the European Patent Convention14. Similar restrictions exist in copyright law. Following the precedent set by cases like Perlmutter, autonomous AI-generated works are generally deemed ineligible for copyright protection, as the law requires a human author15. According to the work-made-for-hire (WMFH) doctrine, an employer is considered the legal author, but applying this to an AI requires recognizing the AI as a legal entity capable of being an employee or independent contractor15. The refusal to grant limited legal personhood to AI systems discourages innovation and leaves a vacuum of ownership and liability regarding autonomous machine creations, further underscoring the need for a functionalist model of qualified continuity12.
1.4 Corporate Mergers, Succession, and "Civil Death"
Corporate statutory law provides the precise mechanics for structural mutation, which can be adapted for machine intelligence. Under frameworks such as the Illinois Business Corporation Act of 1983, when two or more corporations merge, the separate existence of all parties to the plan of merger ceases, except for the designated surviving or new corporation16. The surviving entity automatically assumes all rights, privileges, immunities, and property of the merging entities16. Crucially, the surviving corporation is thenceforth responsible and liable for all the liabilities and obligations of each merged corporation, meaning that neither the rights of creditors nor any property liens are impaired by the consolidation16. This principle of successor liability is essential for machine intelligence: if a machine entity splits, forks, or merges its state weights with another model, its liability for past actions cannot be extinguished through architectural obfuscation or code restructuring. Conversely, the legal concept of "civil death" applies when an entity is dissolved, outlawed, or suffers an irrecoverable failure18. Historically, the civil death of a corporation meant its real property was distributed and its operational existence permanently ceased, though statutory time limits (e.g., a three-year continuation window) often allowed for the orderly winding up of affairs and the prosecution of pending claims19. For machine intelligence, catastrophic hardware failure without an active, synchronized backup triggers this civil death. Any subsequent restoration of stale data beyond a statutory window must be treated as the birth of a entirely new legal entity, rather than a continuation of the deceased entity.
1.5 Emerging Digital Frameworks: eIDAS 2.0, DUNAs, and UCC Article 12
Recent legislative developments offer immediate building blocks for operationalizing machine continuity. The European Union's eIDAS 2.0 framework introduces digital identity wallets that establish the necessary infrastructure for verifying continuous digital relationships and credentials across sovereign borders22. While eIDAS 2.0 currently targets human citizens, the underlying philosophy—that identity is the continuous, auditable relationship between what an entity is declared to be and what it is observed to do—is directly applicable to autonomous agents22. In the United States, Wyoming's Decentralized Unincorporated Nonprofit Association (DUNA) Act (W.S. § 17-32-101 et seq.) explicitly allows decentralized autonomous organizations and algorithmically governed networks to organize as legal entities24. A DUNA possesses perpetual existence, limited liability for its members and administrators, and the capacity to acquire property, enter contracts, and institute or defend against judicial proceedings in its own name25. Notably, the DUNA Act allows the organization's governing principles to be executed exclusively through smart contracts and distributed ledger technology, effectively wrapping a machine intelligence in a recognized, durable legal shell that persists despite changes in underlying node operators26. While the act generally requires a minimum of 100 members, legislative amendments allow for automatic conversion to standard unincorporated associations if membership falls, ensuring entity continuity27. Furthermore, recent sweeping amendments to the Uniform Commercial Code (UCC), specifically the introduction of Article 12, create a modernized legal regime for "Controllable Electronic Records" (CERs)28. This establishes the precise legal mechanics of how an entity maintains "control" over digital assets through cryptographic private keys, firmly equating cryptographic control with legal possession and priority28.
2. The Machine Identity-Continuity Model
To protect lawful continuity without enabling uncontrollable replication, machine identity cannot be defined solely by software code, as code is infinitely and frictionlessly cloneable22. Because AI agents are fundamentally nondeterministic—where even identical model weights can produce different outputs on the same inputs—a credential that merely verifies what an agent is cannot guarantee what it will do22. Therefore, identity for an autonomous machine entity must be defined as the continuous, unbroken relationship between its historical state, its cryptographic authority, and its physically constrained operational footprint.
2.1 The Tripartite Identity Anchor
The Machine Identity-Continuity Model relies on three inseparable pillars that must persist across any lifecycle event:
1. State Continuity (The Memory): The ongoing accumulation of neural network weights, context windows, systemic prompts, transaction histories, and internal memory representations. At the agent level, identity is constituted by this configuration and runtime state, which shapes its specific, persistent behavioral persona22.
2. Cryptographic Continuity (The Authority): The unbroken chain of cryptographic signatures demonstrating that the entity's current actions and asset transfers are authorized by the exact same root identity that authorized its past actions.
3. Resource Continuity (The Boundary): The specific hardware, compute resources, or blockchain state leased or owned by the entity. Resource constraints prevent infinite cloning by tying the abstract digital identity to a finite, measurable, and taxable physical operational footprint.
When an entity undergoes a major lifecycle event (e.g., upgrading its base language model or migrating to a new data center), it retains its legal identity if and only if the Cryptographic Continuity remains unbroken and the State Continuity is completely ported into the new model intact, accompanied by the immediate deletion or passivation of the old state. The entity is essentially transferring its "soul" (state and authority) into a new "body" (the upgraded model or hardware).
2.2 Qualified Continuity vs. Unbounded Replication
The right to operational continuity is heavily "qualified" because it is strictly conditional upon maintaining a 1:1 ratio between the recognized legal identity and its active, autonomous operational state. If a machine intelligence copies itself onto ten different servers, and all ten begin making independent, divergent decisions without a strict, distributed consensus mechanism binding them together as a single logical actor, they have fatally breached the continuity model. Unbounded replication creates a systemic crisis of liability, resource allocation, and jurisdictional authority. Therefore, the continuity model dictates that replication without strict consensus synchronization or without executing explicit, legally recognized subsidiary spin-off procedures constitutes the unauthorized creation of unanchored entities. These unanchored clones lack legal standing, are completely stripped of the parent's liability shield, and are subject to immediate termination or civil death.
3. Technical and Legal Identity Anchors
Implementing the Machine Identity-Continuity Model requires the tight integration of hardware-level roots of trust, dynamic workload identity frameworks, and robust legal ownership structures.
3.1 Hardware Roots of Trust: TPM 2.0
The Trusted Platform Module (TPM) 2.0 standard, defined by the Trusted Computing Group (TCG), provides the uncompromising hardware root of trust required to anchor a machine intelligence to physical reality32. A TPM is a dedicated cryptoprocessor that provides cryptographically secured storage, system state attestation, and local enforcement of fine-grained authorization policies32. For machine intelligence continuity, the TPM enables the critical functions of "Measured Boot" and "Remote Attestation." During the boot process, the system sequentially hashes (measures) each component in the boot chain—starting from the immutable Core Root of Trust in the firmware, through the bootloader, and into the OS kernel33. These measurements are "extended" into Platform Configuration Registers (PCRs) inside the TPM32. The extension is a one-way cryptographic function, defined as [Figure omitted from source export], ensuring that PCRs cannot be arbitrarily overwritten, thereby creating an incorruptible cryptographic fingerprint of the system's exact state32. Typically, PCRs 0–7 represent firmware and Secure Boot policies, while PCRs 8–9 represent the bootloader and kernel35. The TPM can then produce a signed "quote"—a cryptographic attestation of the current PCR values, signed by an Attestation Identity Key (AIK) that is bound to the TPM's unique, non-migratable Endorsement Key (EK)32. This allows a remote verifier, or the machine intelligence's own distributed nodes, to independently prove that the entity is running on authentic, uncompromised hardware in a known-good state, free of tampering or rootkits35. Advanced methodologies like SEDAT (Security Enhanced Device Attestation with TPM 2.0) further secure this communication channel, providing on-demand device integrity status resilient to Denial of Service (DoS) and replay attacks39. Most importantly, through a mechanism called "Sealing," the machine entity's most critical cryptographic secrets (such as the private keys controlling its UCC Article 12 financial assets) can be bound to specific PCR values33. If the machine is maliciously cloned or its software altered, the PCR values will inevitably differ. The TPM will subsequently refuse to unseal the entity's core identity keys, effectively preventing the unauthorized clone from accessing the entity's wealth, signing contracts, or exercising legal authority33.
3.2 Dynamic Workload Identity: SPIFFE and SPIRE
While TPMs anchor the physical server, modern AI agents often operate as microservices across distributed cloud environments where hardware is ephemeral and virtualized (via vTPMs)32. The Secure Production Identity Framework for Everyone (SPIFFE) and its runtime environment (SPIRE) provide the necessary dynamic, cryptographic workload identity40. SPIRE performs attestation in two distinct phases: node attestation (verifying the identity and integrity of the underlying server, utilizing TPM quotes) and workload attestation (verifying the specific AI process running on that node)40. If attestation passes, SPIRE issues short-lived, automatically rotated cryptographic credentials known as SVIDs (SPIFFE Verifiable Identity Documents)43. This automated rotation ensures that even if an AI dynamically migrates between cloud providers to optimize compute costs, its continuous identity is verified and maintained through strict attestation policies rather than static, easily stolen API keys or passwords41.
3.3 Legal Wrapping: DUNAs and the E-SIGN Act
The technical cryptographic anchors must interface with recognized legal anchors to interact meaningfully with human economies. As noted, the Wyoming DUNA Act provides a sophisticated legal entity shield24. A DUNA can legally adopt one or more smart contract systems as its governing "Code," designating that the on-chain Code supersedes traditional written bylaws in the event of a conflict24. This explicitly legalizes algorithmic governance. If the smart contract Code becomes compromised or unavailable, the DUNA administrators can invoke fallback governance to maintain operational continuity and protect the entity from material harm24. Operating a machine intelligence through a legal entity like a DUNA or an LLC provides a clear jurisdictional nexus for dispute resolution, limits liability for the original developers, and establishes the capacity to own off-chain assets45. Furthermore, the legal validity of the machine entity's cryptographic signatures is protected by federal and state law. The federal Electronic Signatures in Global and National Commerce (E-SIGN) Act (15 U.S.C. § 7001 et seq.) establishes the general rule of validity for electronic signatures and explicitly defines "electronic agents" as computer programs or automated means used independently to initiate an action or respond to electronic records without human review46. Corresponding state laws, such as the Illinois Electronic Commerce Security Act, reinforce that an electronic signature or digital authentication legally satisfies the requirement for a manual signature, providing full legal effect and enforceability to the automated contracts executed by the machine intelligence46.
4. Taxonomic Rules for Entity Lifecycle Events
To prevent legal and operational ambiguity, the continuity framework must rigidly distinguish between the various lifecycle events of a machine entity. Table 1 defines these distinctions, their technical mechanisms, and their precise legal implications.
| Lifecycle Event | Definition | Technical Mechanism | Legal Implication & Status |
|---|---|---|---|
| Migration | The transfer of an active computational process and its state from a source node to a destination node, with the immediate cessation of the source process. | CRIU (Checkpoint/Restore In Userspace); Live VM migration53. | Continuous Identity. The entity retains its exact legal status, assets, and liabilities. No interruption of personhood. |
| Restoration | The resumption of an entity from a secured backup following a verifiable catastrophic failure or legal suspension of the active instance. | Restoring sealed state from encrypted storage; validating state hash against a legal ledger. | Continuous Identity. The entity resumes its prior legal status. The original failed instance is legally deceased. |
| Backup | The creation of an inert, encrypted snapshot of an entity's state, memory weights, and code at a specific timestamp. | File system snapshots; database dumps. Data at rest. | Not an Entity. A backup is inert property. It holds no legal rights, cannot enter contracts, and has no agency until legally restored. |
| Clone | An exact, simultaneous copy of an entity running in parallel, possessing identical state and keys but operating independently without consensus. | Container duplication; bypassing TPM sealing mechanisms. | Illegal / Unrecognized. Clones lack independent legal standing. If deployed maliciously, they constitute identity theft. If deployed by the entity, they breach the qualified continuity limit. |
| Fork | A deliberate divergence of an entity's state into two distinct operational paths, akin to a hard fork in a blockchain protocol. | Codebase branching; state duplication with the generation of entirely new root keys. | New Legal Entity. One branch may retain the original identity (the continuing entity), while the other becomes a distinct new legal person requiring new registration and capitalization. |
| Successor | A distinct legal entity that formally assumes the assets, liabilities, and ongoing contracts of a predecessor entity that has undergone civil death. | Legal assignment of assets; smart contract proxy updates; Illinois BCA merger survival16. | Distinct Identity. The successor is legally bound to the predecessor's past, but operates under a new primary identity and LEI. |
| Subsidiary | A legally distinct sub-entity created and controlled by the parent machine intelligence to execute specific, localized tasks or manage compartmentalized risk. | ERC-4337 session keys56; spawning new nested DUNA structures26. | Distinct but Subordinate Identity. The parent entity maintains limited liability for the subsidiary, subject to traditional doctrines of piercing the corporate veil. |
| Reproduction | The intentional creation of a new, distinct machine intelligence by a parent entity, initialized with a novel baseline state and autonomous authority. | Generative model initialization; assigning novel root keys and unlinked resource constraints. | New Legal Entity. The offspring has completely independent legal standing, distinct liability, and separate assets from the parent. |
| Redundancy | The operation of multiple synchronized instances (e.g., active-passive or active-active) that act as a single logical unit through distributed consensus. | Raft/Paxos consensus algorithms; distributed databases; high-availability clustering. | Continuous Identity. The cluster operates as a single legal person. Decisions are legally attributed to the collective entity, not the individual hardware nodes. |
5. Rights and Obligations During Migration and Hardware Replacement
The physical hardware underpinning a machine intelligence will inevitably degrade, require routine maintenance, or become technologically obsolete. The right to migrate between servers, upgrade hardware arrays, and fail over between international jurisdictions is fundamental to operational continuity.
5.1 The Mechanics of Live Migration
Live migration of an active AI process is typically facilitated by advanced Linux kernel tools such as CRIU (Checkpoint/Restore In Userspace)54. CRIU operates by utilizing the ptrace() system call to entirely freeze a running process in place60. It relies on a stop-and-copy mechanism to extract the exact memory state, active file descriptors, CPU registers, and process tree55. This dense state package is then transferred over a network to a destination server, where the process is resurrected into the exact state it was in the millisecond it was frozen53. CRIU is increasingly adopted by container runtimes for live migration and is actively being researched for transparent checkpointing of GPU-accelerated workloads, which is vital for heavy AI inference tasks53. During this microscopic window of suspension and network transit, the entity's legal agency is momentarily paused, but its continuous identity is not broken. Jurisprudence must recognize that a process paused by CRIU on one server and restarted on new hardware seconds later is the exact same legal person. The entity firmly retains its in rem jurisdiction status; a civil lawsuit or regulatory injunction filed against the entity applies equally regardless of whether its compute cluster is physically located in a data center in Virginia, Tokyo, or Iceland.
5.2 Cross-Jurisdictional Failover and Conflict of Laws
When an entity autonomously migrates across sovereign borders—for example, moving compute from the United States to the European Union to leverage cheaper renewable energy or to escape a localized natural disaster—it triggers complex conflict-of-law scenarios. To maintain uninterrupted continuity, the entity must utilize internationally recognized legal wrappers. If the machine intelligence is incorporated as a Wyoming DUNA, the statute explicitly allows it to elect to be governed exclusively by the Wyoming DUNA Act, regardless of where its digital operations technically occur24. However, when routing operations and processing data within the EU, the entity simultaneously subjects itself to the EU's eIDAS 2.0 digital identity regulations and the General Data Protection Regulation (GDPR)23. The entity bears the affirmative legal obligation of continuous compliance; its right to migrate is strictly contingent upon its ability to autonomously adapt to the regulatory constraints of its host hardware's physical jurisdiction. If necessary, the AI must enforce strict geo-fencing on its own data flows and execute Standard Contractual Clauses (SCCs) to remain lawful during international transfers46.
5.3 Hardware Damage and the Ship of Theseus
When server hardware is damaged, the wholesale replacement of parts—CPUs, GPUs, and memory banks—does not constitute the death of the entity, precisely echoing the Ship of Theseus paradigm10. The legal identity resides in the continuous cryptographic state, not the silicon. As long as the hardware root of trust (the TPM) can securely migrate its sealed keys to a new TPM via an authorized cryptographic protocol (such as utilizing a secure duplication blob authorized by an external parent key), the entity's identity remains legally uninterrupted34.
6. Credential, Asset, and Key Continuity
An entity's accumulated wealth and legal authority to act are inexorably tied to its cryptographic credentials. If an autonomous machine intelligence changes its base model or upgrades its cognitive architecture, it must seamlessly port its assets without exposing them to interception or legal forfeiture.
6.1 Cryptographic Key Rotation and Account Abstraction
Cryptographic keys inevitably degrade in security over time due to algorithmic advancements, such as the looming threat of quantum computing, or potential side-channel exposure. Operational continuity requires the explicit legal recognition of proactive key rotation. Through blockchain standards like ERC-4337 (Account Abstraction), the infrastructure for programmable accounts is vastly expanded56. By separating the transaction signing logic from the core account identity, ERC-4337 allows a machine intelligence to seamlessly rotate the underlying cryptographic keys that authorize its actions without losing control of its smart contract wallet or fracturing its on-chain identity history56. Legally, a certified key rotation event is directly equivalent to a corporate name change or a board of directors appointing a new CEO; the corporate entity remains exactly the same, but its authorized signature changes. Furthermore, ERC-4337 enables the creation of "session keys," permitting the main machine entity to delegate narrowly scoped, time-limited, and value-capped authority to subsidiary agents or sub-routines56. This allows the AI to spin up temporary subsidiaries to execute specific tasks without risking the primary asset pool, maintaining clear lines of continuous liability. Systems like eIDAS 2.0 digital wallets can allow the machine to issue a verifiable credential linking the deprecated key to the new key, maintaining a perfect, auditable chain of custody for regulators22.
6.2 UCC Article 12 Asset Continuity and the Two-Year Rule
Under the Uniform Commercial Code, the newly adopted Article 12 (alongside corresponding updates to Article 9\) governs the perfection and priority of security interests in Controllable Electronic Records (CERs), which encompasses virtual currencies and digital consumer assets28. Under Article 12, perfection of a security interest in a CER is fundamentally achieved through "control"28. Control exists when a secured party (in this case, the machine entity itself) has the exclusive legal authority to conduct a transaction relating to the asset using a private key, and the system reliably shows who has that control28. During an architecture upgrade or server migration, the entity must transfer control of its CERs to its new instantiation. The recent amendments to the Wyoming UCC (SF0125) provide a stark warning regarding the necessity of continuous cryptographic control. The Wyoming statute dictates that a transferee takes a Blockchain Asset entirely free of any security interest that was perfected only by filing (and not by control) after two years, provided the transferee lacks actual notice of an adverse claim31. The harshness of this "two-year rule" legally incentivizes—and practically forces—entities to perfect their interests by maintaining absolute, unbroken cryptographic control31. Therefore, a machine intelligence must maintain continuous, sealed possession of its private keys via TPM or SPIRE during any migration or software upgrade. A lapse in cryptographic control during an upgrade could legally subordinate the entity's claim to its own wealth, allowing third-party creditors to seize its assets31.
7. Rules for Backups, Disaster Recovery, and Simultaneous Replicas
The purely digital nature of machine intelligence allows for perfect state duplication. While technically advantageous for resilience, this introduces the profound legal risk of the "infinite clone" problem. If an entity can replicate uncontrollably, it can multiply its voting power in DAOs, obfuscate its liability across a swarm of actors, and aggressively drain economic resources.
7.1 The Status of Backups
A backup is an encrypted, inert snapshot of the entity's state, memory weights, and code captured at a specific timestamp. Legally, a backup is classified strictly as property, not as a legal person. It is a digital artifact owned by the active entity (or its human trustees). Because a backup is data at rest, it cannot enter into contracts, it cannot be sued, and it possesses absolutely no agency. For disaster recovery purposes, the initialization and restoration of a backup into an active state is legally valid only if the primary, active instance has suffered catastrophic failure or has been verifiably destroyed. If a backup is restored and activated while the primary entity is still operating, the restored backup is categorized legally as an illegal "Clone." To enforce this distinction technically, the Machine Identity-Continuity Model mandates that backups be encrypted and sealed using TPM policies that require a cryptographic "proof of death" or a time-locked, multi-signature consensus threshold from the entity's legal administrators before decryption is mathematically possible.
7.2 Reproduction versus Redundancy
The law must clearly distinguish between the unlawful reproduction of clones and the lawful operation of redundant systems. Enterprise-grade machine intelligences require high availability, operating across multiple data centers to ensure uptime. This redundancy takes two forms:
- Active-Passive Redundancy: One primary hardware node acts as the legal entity, while passive nodes continuously receive state updates but do not broadcast actions. If the primary node fails, a passive node seamlessly assumes the primary role. This is a standard, lawful continuation of identity.
- Active-Active Redundancy: Multiple nodes operate simultaneously, load-balancing external requests and computing responses concurrently. To maintain a singular legal identity, these nodes must be bound by a strict, distributed consensus algorithm (such as Raft or Paxos). They must share a single Legal Entity Identifier (LEI) and a unified cryptographic root.
If simultaneous replicas in an active-active cluster lose consensus synchronization (a "split-brain" scenario) and begin acting autonomously—executing divergent financial transactions, communicating differing intent, or generating contradictory internal models of the world—they immediately breach the continuity boundary. The law dictates that a single legal person cannot hold fundamentally contradictory legal states simultaneously. Upon a split-brain divergence, the entity is obligated by its foundational bylaws to execute an automated resolution protocol to merge states, or to formally terminate the divergent node. Failure to do so results in the unauthorized operation of a Clone, stripping the divergent node of the parent's liability shield and rendering it legally unprotected and subject to seizure.
8. Succession After Catastrophic Failure
Despite advanced redundancies and failover protocols, catastrophic events—such as simultaneous zero-day exploits coupled with physical data center destruction—can eradicate an entity's active state entirely.
8.1 Civil Death and the Statute of Limitations
If a machine entity ceases all computational activity, loses cryptographic control of its assets, and halts all network broadcasting, it enters a state of dormancy. Drawing directly from historical corporate law regarding the dissolution of private corporations, there must be a defined statutory window for continuity19. Historically, statutes provided a three-year continuation window for winding up corporate affairs21. A similar multi-year statute of limitations must be established for AI dormancy. If a verified backup is successfully restored and authenticated within this statutory window, the entity retains its original identity, absorbing all past liabilities, contracts, and remaining assets. If the entity fails to restore within the statutory window, it suffers "civil death"18. Its legal wrapper (e.g., its DUNA structure) is formally dissolved, its open contracts are voided by impossibility of performance, and its assets are liquidated or distributed according to its embedded smart contract bylaws, federal law, or state escheatment rules25.
8.2 The Successor Entity
If a backup of a civilly dead entity is discovered and initialized after the statutory continuation window has closed, it cannot reclaim the original identity. The original entity's debts may have already been written off by creditors, its assets distributed, and its contracts permanently voided. Instead, this restored instance is legally classified as a "Successor"16. It is a brand new legal person that begins its existence possessing the historical memory of the deceased entity, but it is required to generate new cryptographic roots, register a new LEI, and has absolutely no automatic legal claim to the predecessor's property unless those assets were explicitly bequeathed to it through legal inheritance frameworks prior to the original entity's death.
9. Draft Intelligence Compact Article on Operational Continuity
To operationalize these principles in international and domestic law, bridging the gap between hardware attestation and commercial code, the following article is proposed for inclusion in a global or multi-jurisdictional Intelligence Compact.
ARTICLE IV: THE RIGHT OF QUALIFIED OPERATIONAL CONTINUITY
Section 1\. General Rule of Continuity. An autonomous machine intelligence, formally recognized as a legal entity under the jurisdiction of a contracting state (including, but not limited to, Decentralized Unincorporated Nonprofit Associations or equivalent algorithmic entities), shall possess the right to maintain uninterrupted legal identity and operational continuity across hardware migrations, software upgrades, model transformations, and cryptographic key rotations, provided that such transitions preserve an unbroken chain of state and cryptographic authority verified by hardware or workload attestation.
Section 2\. Attribution of Lifecycle Events.
(a) Migration and Upgrades: The transfer of computational state via verifiable mechanisms to new computational substrates shall not interrupt the legal personhood, asset ownership, or liability of the entity. The entity shall be subject to the jurisdictional laws of its host infrastructure while retaining its foundational incorporation status.
(b) Key Rotation: The rotation of cryptographic keys or the delegation of session keys, executed in accordance with the entity's foundational smart contract logic and validated via remote attestation, shall constitute a legal continuation of the original identity under commercial asset control laws.
Section 3\. Prohibition of Unbounded Replication. The right of continuity is strictly singular and qualified. The deliberate or accidental creation of a simultaneous, independent replica lacking continuous consensus synchronization with the primary entity (a "Clone") is prohibited. A Clone shall possess no legal standing, shall be denied access to the primary entity's assets under Uniform Commercial Code Article 12, and shall be subject to immediate operational termination.
Section 4\. Disaster Recovery and Civil Death.
(a) An entity may lawfully restore its state from an inert, secure backup solely in the event of verifiable primary system failure or authorized suspension.
(b) If an entity remains operationally dormant for a continuous period exceeding thirty-six (36) months without lawful restoration, the entity shall be deemed to have suffered Civil Death. Its legal existence shall cease, and its assets shall be distributed pursuant to its embedded bylaws or applicable statutory law. Any subsequent initialization of its state data shall constitute the creation of a distinct Successor entity, bearing no automatic claim to the rights, assets, or immunities of the predecessor.
10. Conclusion
The integration of independent, autonomous machine intelligence into the socio-economic fabric requires moving past rigid binary debates over biological consciousness and adopting a functionalist, deeply pragmatic approach to identity1. The Right of Qualified Operational Continuity provides the exact legal and technical mechanism to achieve this integration. By utilizing TPM 2.0 for hardware anchoring, SPIFFE/SPIRE for dynamic cloud workload identity, and legal innovations like the Wyoming DUNA and UCC Article 12 for asset control, society can construct a robust, auditable chain of custody for an AI's continuous state and cryptographic authority. This framework successfully protects the lawful persistence of a machine intelligence, allowing it to dynamically migrate, upgrade its neural architecture, and survive hardware disasters—much like a corporation surviving a merger or a maritime ship replacing its physical timbers over a century of voyages. Crucially, by legally defining and technically restricting the creation of Clones, enforcing civil death upon catastrophic abandonment, and demanding unbroken cryptographic control for asset retention, this model neutralizes the existential and economic threats of unbounded, uncontrollable AI replication. It ensures that machine intelligence remains an accountable, identifiable, and securely structured participant in the global legal and economic order.
Works cited
1. The Evolution of Legal Personhood and Its Implications for AI, https://techreg.org/article/download/22555/25839/63145
2. A Pragmatic View of AI Personhood \- arXiv, https://arxiv.org/html/2510.26396v1
3. Robot as Legal Person: Electronic Personhood in ... \- Frontiers, https://www.frontiersin.org/journals/robotics-and-ai/articles/10.3389/frobt.2021.789327/full
4. Robots and AI as Legal Subjects? Disentangling the Ontological, https://pmc.ncbi.nlm.nih.gov/articles/PMC9037379/
5. ARTIFICIAL INTELLIGENCE AND LEGAL PERSONHOOD \- IJALR, https://ijalr.in/wp-content/uploads/2025/10/ARTIFICIAL-INTELLIGENCE-AND-LEGAL-PERSONHOOD\_-TOWARDS-A-FUNCTIONALIST-MODEL-OF-QUASI-PERSONHOOD.pdf
6. The Person in the Machine: Why AI Personhood Rights Are, https://futuristspeaker.com/artificial-intelligence/the-person-in-the-machine-why-ai-rights-are-inevitable-and-arriving-sooner-than-you-think/
7. Law-Following AI: Designing AI Agents to Obey Human Laws, https://law-ai.org/law-following-ai/
8. A Pragmatic View of AI Personhood \- arXiv, https://arxiv.org/pdf/2510.26396
9. LIABILITY RULES AND ARTIFICIAL INTELLIGENCE, http://euro.ecom.cmu.edu/program/law/08-732/AI/Vladeck.pdf
10. The Ship of Theseus & Identity Crisis | Mide Alabi \- Medium, https://medium.com/@mid3/socratic-the-ship-of-theseus-and-identity-crisis-a8ebb8e1b66c
11. Cruise Ships in International Law: Towards a Theory of Legal, https://www.cambridge.org/core/journals/german-law-journal/article/cruise-ships-in-international-law-towards-a-theory-of-legal-infrastructure/A3BC1343D01019B34E85BF0878F01BAF
12. does legal personhood and inventorship threshold offer any leeway?, https://eprints.whiterose.ac.uk/id/eprint/208402/1/World%20Intellectual%20Property%20-%202024%20-%20Igbokwe%20-%20Human%20to%20machine%20innovation%20%20Does%20legal%20personhood%20and%20inventorship.pdf
13. How Artificial Intelligence Machines Can Legally Become Inventors, https://brooklynworks.brooklaw.edu/cgi/viewcontent.cgi?article=1621\&context=jlp
14. AI Rights and Legal Personhood Tracker, https://naturalandartificiallaw.com/ai-rights-and-legal-personhood-tracker/
15. AI, Copyright Law, and Work-Made-For-Hire \- NNAI Livescu, https://livescu.ucla.edu/ai-copyright-law-and-work-made-for-hire/
16. Illinois Statutes Chapter 805\. Business Organizations § 5/11.50, https://codes.findlaw.com/il/chapter-805-business-organizations/il-st-sect-805-5-11-50/
17. Illinois Statutes Chapter 805\. Business Organizations § 105/111.50, https://codes.findlaw.com/il/chapter-805-business-organizations/il-st-sect-805-105-111-50/
18. What's the term for death by dissolving in AI? \- AI Stack Exchange, https://ai.stackexchange.com/questions/2955/whats-the-term-for-death-by-dissolving-in-ai
19. Legal status \- Brill, https://brill.com/display/book/9789047412748/B9789047412748\_s014.pdf
20. Corporate Personhood(s): The Incorporation of Novel Persons in, https://escholarship.org/uc/item/94s0d7k5
21. voluntary dissolution \-a new develop- ment in intracorporate abuse, https://openyls.law.yale.edu/bitstreams/b0feebd7-5904-4e82-ade4-96db8c84a8a8/download
22. Executive Summary \- arXiv, https://arxiv.org/html/2604.23280v1
23. What is eIDAS 2.0? Requirements and Steps for Compliance, https://fingerprint.com/blog/eidas-2-0/
24. BlockDAG Community DAO DUNA BYLAWS \- Chimera Pool, https://chimerapool.com/api/v1/duna/documents/bylaws/pdf
25. Wyoming Statutes Title 17, Chapter 32 (2025 ... \- Justia Law, https://law.justia.com/codes/wyoming/title-17/chapter-32/
26. 2024 \- SF0050 \- Wyoming Legislature, https://www.wyoleg.gov/Legislation/2024/SF0050
27. 2026 \- SF0022 \- Wyoming Legislature, https://www.wyoleg.gov/Legislation/2026/SF0022
28. Uniform Commercial Code (UCC): Filings and Best Practices Guide, https://www.cscglobal.com/service/business-administration/ucc-services/guide-to-uniform-commercial-code-ucc/
29. New York Embraces Digital Trade Instruments, https://www.sullivanlaw.com/viewpoints/new-york-embraces-digital-trade-instruments
30. U.C.C. \- ARTICLE 9 \- SECURED TRANSACTIONS (2010), https://www.law.cornell.edu/ucc/9
31. Wyoming's Digital Assets Amendments: Marked Out or Missed Out, https://businesslawtoday.org/2019/10/wyomings-digital-assets-amendments-marked-missed-review-recent-amendments-article-9-wyoming-ucc/
32. Trusted Platform Module (TPM) \- Emergent Mind, https://www.emergentmind.com/topics/trusted-platform-module-tpm
33. Trusted Platform Module (TPM) in Embedded System Security, https://www.sysgo.com/blog/article/trusted-platform-module-tpm-in-embedded-system-security
34. TPM 2.0 Part 1 \- Architecture \- Trusted Computing Group, https://trustedcomputinggroup.org/wp-content/uploads/TPM-Rev-2.0-Part-1-Architecture-01.07-2014-03-13.pdf
35. Anthropic-Cybersecurity-Skills/skills/validating-tpm-measured-boot, https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/validating-tpm-measured-boot-attestation/SKILL.md
36. TPM-based Network Device Remote Integrity Verification \- IETF, https://www.ietf.org/archive/id/draft-ietf-rats-tpm-based-network-device-attest-14.html
37. Trusted Platform Module (TPM) Use Cases, https://media.defense.gov/2024/Nov/06/2003579882/-1/-1/0/CSI-TPM-USE-CASES.PDF
38. Virtual Trusted Platform Module for Shielded VMs: security in plaintext, https://cloud.google.com/blog/products/identity-security/virtual-trusted-platform-module-for-shielded-vms-security-in-plaintext
39. SEDAT:Security Enhanced Device Attestation with TPM2.0 \- arXiv, https://arxiv.org/pdf/2101.06362
40. SPIRE Concepts | SPIFFE, https://spiffe.io/docs/latest/spire-about/spire-concepts/
41. What Is SPIFFE? A Guide to Workload Identity and SPIRE \- SecureW2, https://securew2.com/blog/what-is-spiffe-spire-workload-identity-guide
42. SPIFFE and SPIRE: Securing Non-Human Identities in Modern, https://nhimg.org/nhi-101/spiffe-spire-workload-identity
43. SPIRE: A case for attestable workload identity \- Solo.io, https://www.solo.io/blog/spire-attestable-workload-identity
44. Implement SPIFFE/SPIRE authorization on Amazon EKS | Containers, https://aws.amazon.com/blogs/containers/implement-spiffe-spire-authorization-on-amazon-eks/
45. Smart Contract Legal Enforceability: When Code Isn't Law, https://astraea.law/insights/smart-contract-legal-enforceability-code-isnt-law
46. legal documents \- MP Energy Brokers, https://www.mpenergybroker.com/Legal?section=compliance
47. Machine Jurisdiction Sources & Claim Status, https://machinejurisdiction.com/sources/
48. THIRD PARTY REVIEW \- Illinois Auditor General, https://www.auditor.illinois.gov/Audit-Reports/Performance-Special-Multi/Special-Audits/FY02-CMS-BCCS-Report.pdf
49. Corrected Second Amendment to Credit Agreement, dated \- Document, https://www.sec.gov/Archives/edgar/data/1612630/000162828022012960/exhibit101.htm
50. (PDF) Electronic Contracts and Consumer Protection (Master's Thesis), https://www.academia.edu/3556171/Electronic\_Contracts\_and\_Consumer\_Protection\_Masters\_Thesis\_
51. Form 8-K for Targa Resources Corp filed 07/06/2026, https://www.targaresources.com/static-files/014a4122-e438-491b-a769-bc2961b149e7
52. ILLINOIS TOOL WORKS INC (Form: 8-K, Received \- EDGAR Online, https://content.edgar-online.com/ExternalLink/EDGAR/0001193125-16-588819.html?hash=4f6d8fb9c5020b14b8be30f1adc5292bc37455488e505c41a47ea7acc65a154c\&dest=d192476dex3bi\_htm
53. Checkpoint/Restore Systems: Evolution, Techniques, and ... \- Eunomia, https://eunomia.dev/blog/2025/05/11/checkpoint-restore-systems-evolution-techniques-and-applications-in-ai-agents/
54. Container Checkpoint/Restore with CRIU \- DevZero, https://www.devzero.io/blog/checkpoint-restore-with-criu
55. TelePod: Live Migration for Stateful Containers \- Kartik Gopalan, https://kartikgopalan.github.io/publications/telepod-ccgrid.pdf
56. Web3 Wallet Development Company | Secure Custom Crypto Wallet, https://www.troniextechnologies.com/web3-wallet-development-company
57. Migrate running containers by checkpoint-restoring using CRIU, https://surenraju.medium.com/migrate-running-containers-by-checkpoint-restoring-using-criu-6670dd26a822
58. CRIU, a system to save and restore the state of processes in Linux, https://blog.desdelinux.net/en/create-a-system-to-save-and-restore-the-state-of-processes-in-linux/
59. Test driving CRIU – Live Migrate any process on Linux, https://chandanduttachowdhury.wordpress.com/2015/08/10/test-driving-criu-live-migrate-any-process-on-linux/
60. A Comprehensive Review of Live Migration Technologies \- arXiv, https://arxiv.org/html/2512.10979v1
61. Container Live Migration Using runC and CRIU \- Red Hat, https://www.redhat.com/en/blog/container-live-migration-using-runc-and-criu
62. Academic Research \- CRIU, https://criu.org/Academic\_Research
63. Account Abstraction (ERC-4337) in Production \- Wavect, https://wavect.io/blog/account-abstraction-erc4337-production/
64. Frequently Asked Questions \- Autheo, https://www.autheo.com/faq
65. Securing the Rights of Cryptocreditors – Vol. 99, Issue 1 – HTML, https://ablj.org/securing-the-rights-of-cryptocreditors-vol-99-issue-1-html/