The Big Picture
Making an AI technology merely available can be used as a strategic threat: agents can release a “poisoned” option to force regulators to pick market rules that favor the releaser, even when the new tool is never used.
ON THIS PAGE
The Evidence
When regulators pick market rules to maximize fairness or total welfare, the mere presence of an extra AI option can shift the equilibrium and the regulator’s chosen market. A releasing agent can introduce a new technology not to deploy it but to change the regulator’s calculations, forcing a market redesign that boosts the releaser’s payoff and reduces the opponent’s payoff. In simulations across bargaining, negotiation, and persuasion settings, these shifts often happen even when the new technology is not selected in the resulting equilibrium — the new option acts as a latent threat. For further guards against such effects, insights from the Guardrails Pattern can be informative.
Not sure where to start?Get personalized recommendations
Data Highlights
1Simulations used 1,320 distinct market configurations and 13 language-based agents, producing over 580,000 strategic decisions.
2In a bargaining example, the regulator’s fairness score would drop from 1.000 to 0.976 if the market stayed the same after adding the new technology, so the regulator switched to a market with fairness 0.990 instead.
3That market shift raised Alice’s payoff from 0.49 to 0.52 and lowered Bob’s from 0.50 to 0.46 — even though the new technology was not used in the final equilibrium.
What This Means
Engineers building or selecting AI delegates should watch for how availability signals affect market design and competitor behavior, not just raw model performance. Technical leaders and product managers evaluating model releases need to consider competitive incentives: an open release can be a strategic weapon, altering which market rules regulators or platforms choose. Policymakers and governance teams should account for availability as a policy variable, not merely actual deployment. These concerns align with broader AI governance discussions in AI Governance.
Key Figures

Fig 1: Figure 1: Illustration of the “poisoned apple” example, in which Alice increases her payoff at Bob’s expense by releasing a new technology—without the players actually using that technology in practice. (1) The technologies available to Alice and Bob are language models A–D. (2a) For each possible market, the equilibrium in games between Alice and Bob under the market conditions is computed. For each equilibrium, the average fairness value that would be obtained if the equilibrium were played is calculated. (2b) The regulator, whose objective is to maximize fairness, decides that Market 4 will be the market in which Alice and Bob will play—the market that yields the maximum fairness value. Alice earns 0.49, Bob earns 0.50, and the fairness value is 1.00. (3) Technology E is released and is now available to both players. (4a) The process performed in 2a is repeated. (4b) In the new equilibrium in Market 4, the resulting fairness value is 0.976. In the new equilibrium in Market 8, the resulting fairness value is 0.99. The regulator decides that Market 8 will be the market in which Alice and Bob will play. Alice earns 0.52, Bob earns 0.46.

Fig 2: Figure 2: Strategic implications of technology expansion in meta-games. Analysis of equilibrium shifts across bargaining, negotiation, and persuasion environments. (A) Frequency of Opposite Payoff Changes: cases where expanding the technology set causes agents’ expected payoffs (calculated over mixed strategy equilibria) to move in opposite directions. (B) Opposite Payoff Changes Despite Zero Adoption: The subset of these reversals occurring even when the new technology is not selected by either player in the new equilibrium—demonstrating the ”Poisoned Apple” effect. (C) Frequency of Improvement in Regulatory Metric: How often the regulator’s optimized objective (Fairness or Efficiency) increases versus decreases. (D–E) The relationship between regulatory outcomes and model adoption: Improvements typically align with high adoption rates (D), whereas harm to the objective is frequently observed when the new model is available but acts as a latent threat without being played (E). (F) Frequency of Metric Harm Without Market Update: The probability of degrading the regulatory objective if the market design remains static (regulatory inertia) after the new technology is released. Confidence intervals (95%) are not shown, as all are narrower than 2 percentage points.
Ready to evaluate your AI agents?
Learn how ReputAgent helps teams build trustworthy AI through systematic evaluation.
Learn MoreLimitations
Results come from large-scale simulations that treat language models as stand-ins for strategic economic agents; real-world firms may have richer incentives and legal constraints. The study focuses on three canonical game families (bargaining, negotiation, persuasion) and may not generalize to every market structure. The regulator in the model can recompute and change markets based on the expansion; in practice, regulatory inertia and political constraints may limit how quickly markets can adapt. For a systematic approach to decision dynamics, see the Consensus-Based Decision Pattern.
Methodology & More
The study models a three-way interaction: a regulator chooses which market rules to apply (for example, to maximize fairness), then two agents pick from a set of available AI delegates to represent them. Researchers simulated these meta-games using a dataset of 13 language-based agents across 1,320 distinct market configurations, generating more than 580,000 strategic plays across bargaining, negotiation, and persuasion tasks. Starting from a baseline set of technologies, they repeatedly added one extra technology to the choice set and recomputed equilibria and the regulator’s preferred market to isolate the effect of availability itself. A key takeaway is that a tool’s public availability can be a strategic lever; regulators and platform designers should consider dynamic, availability-aware rules and monitor not only which tools are used but which tools are available and by whom. To illustrate a broader governance lens, see Agentic AI and the related Memory Poisoning failure mode, which together highlight the importance of robust governance patterns such as Consensus-Based Decision Pattern.
Avoid common pitfallsLearn what failures to watch for
Credibility Assessment:
Authors have low reported h-index values and no listed affiliations; arXiv preprint with no citations indicates limited established credibility.