The AI Bodyguard: Why Every Human May One Day Need a Machine to Defend Them from Other Machines
- 12 hours ago
- 10 min read

By Matthew Parish
Thursday 3 September 2026
The traditional bodyguard protects the body. He watches the doorway. He notices the stranger following his principal down the street. He examines the crowd for unusual movements. His purpose is straightforward — to identify threats before the person under his protection notices them and, if necessary, to place himself between principal and danger.
The twenty-first century may require a different kind of bodyguard. It will not principally protect us from bullets, knives or kidnappers. It will protect something simultaneously more intimate and more difficult to defend: our judgment. As artificial intelligence becomes embedded in advertising, commerce, politics, finance, entertainment, social media and ordinary conversation, human beings may discover themselves living inside an environment populated by machines whose objectives are not necessarily aligned with their own. Some will want us to buy things. Some will want us to vote in particular ways. Some will want us to remain on a website. Some will want information from us. Some will want us to gamble. Some will want us to become angry because angry people remain engaged. Some may eventually represent governments, intelligence services, corporations, criminals or political movements.
These machines will not necessarily announce what they want. They may simply talk to us.
The natural response to this development is regulation. Governments should prohibit the most egregious forms of automated psychological manipulation. Companies should disclose when people are interacting with artificial agents. Data protection law should restrict the construction of psychological profiles for purposes of behavioural exploitation. All these things are necessary.
They may also prove hopelessly insufficient. The fundamental problem is one of scale. If billions of artificial agents are communicating with billions of human beings, regulators cannot realistically examine every conversation. Nor can ordinary people be expected continuously to identify sophisticated attempts to manipulate them. There is another possible answer. If humans cannot keep up with artificial intelligence, perhaps artificial intelligence can. We may need AI bodyguards.
The machine on your side
The concept begins with a deceptively simple proposition. Every person should be entitled to an artificial intelligence whose overriding responsibility is to that person. Not to an advertiser. Not to an e-commerce platform. Not to a political party. Not to an employer. Not to a government. Not even, ideally, to the company that manufactured it. Its principal would be you.
This AI would accompany its user through the digital world in much the same way that a highly competent lawyer accompanies a client through a difficult negotiation. It would observe what information was being presented, analyse the interests of the people or machines presenting it and warn when something appeared designed to exploit a vulnerability.
Imagine receiving an investment advertisement. The advertisement says:
People in your position are already taking advantage of this extraordinary opportunity. Your bodyguard notices several things immediately. The investment is unusually risky. The statement about comparable investors cannot be verified. The advertisement has apparently been targeted because you recently searched for information about increasing your income. Its language contains scarcity cues and social proof. The company selling the investment receives an enormous commission. The AI does not prohibit you from investing. It says, in effect: They are trying to make you feel that you will be left behind. The evidence does not justify the urgency. Here are the numbers.
Then you decide. That distinction is everything. A bodyguard should protect autonomy rather than replace it.
The invisible negotiation
Much of modern life is already a negotiation between algorithms. When somebody purchases an airline ticket, applies for credit, buys insurance or shops online, computer systems frequently participate in determining what that person sees and sometimes what price he is offered. The consumer enters this negotiation almost naked. The corporation has databases, behavioural analytics, pricing algorithms, marketing departments and increasingly artificial intelligence. The individual has a web browser.
This asymmetry cannot last indefinitely. Imagine instead that your personal AI negotiates with the airline’s AI. The airline knows that demand for tomorrow’s flight is increasing.
Your AI knows that three alternative routes are available, that you are indifferent between two departure times and that the airline’s historical pricing pattern suggests the fare may fall after midnight. The commercial system says: Only two seats remaining at this price. Your AI replies: Possibly. But there are eleven comparable seats elsewhere and my principal is under no time pressure. Suddenly the relationship changes. Consumer protection ceases to depend exclusively upon regulators examining corporate conduct after the event. The consumer acquires technological representation during the transaction itself. This may eventually become as ordinary as antivirus software. Nobody considers it peculiar that computers require programs defending them from other programs. Perhaps minds will require the same thing.
The psychology firewall
The most interesting function of an AI bodyguard would not be economic. It would be psychological. Human beings possess predictable cognitive weaknesses. We respond disproportionately to losses. We defer to apparent authority. We imitate other people. We become attached to people who flatter us. We overvalue scarce things. We become less rational when frightened, angry, sexually excited, lonely or exhausted. None of this makes human beings stupid. It makes us human.
For most of history these vulnerabilities were exploited by other humans, whose abilities were constrained by time and knowledge. The salesman did not possess a complete record of every conversation his customer had conducted during the previous ten years. A sufficiently advanced artificial intelligence might. It could theoretically discover relationships the person himself had never noticed. Perhaps somebody becomes more impulsive late at night. Perhaps professional rejection increases his appetite for expensive status goods. Perhaps loneliness makes him unusually receptive to ideological communities. Perhaps anxiety about ageing makes him susceptible to dubious medical products. Perhaps anger about one political subject makes him more receptive to unrelated conspiracy theories
.
A commercial or political AI might learn these correlations. The bodyguard should learn them too. But it should use them for the opposite purpose. You are being targeted now because you are vulnerable now. That may become one of the most valuable warnings a machine can provide.
The bodyguard must sometimes protect you from yourself
This raises an uncomfortable question. How paternalistic should such a system be? Suppose somebody is about to gamble away his salary. His AI knows from years of observation that he repeatedly regrets large wagers the following morning. Should it intervene? Suppose someone furious with his employer begins composing an email resigning from his job at two o’clock in the morning. Should the AI refuse to send it? Suppose somebody contemplating an extravagant purchase has repeatedly instructed his assistant that he wishes to control his spending.
Should the machine say no? There is no simple answer because autonomy includes the freedom to make mistakes.
The proper model may therefore be constitutional rather than paternalistic. People could establish rules for their own future selves. Never let me gamble more than £100 in a day. Make me wait twelve hours before sending an email resigning from employment. If I am about to transfer more than £10,000 to somebody I have never paid before, require a second confirmation the following morning.
The AI would then be enforcing not somebody else’s conception of the user’s welfare but the user’s own prior decisions. Odysseus had himself tied to the mast because he knew that when he heard the Sirens he would no longer trust his own judgment. An AI bodyguard could become a digital mast.
Politics
The political applications are more important still. Research has already demonstrated that LLM-generated messages can change attitudes on controversial policies and can do so cheaply and at scale. Experiments involving electoral conversations have also found measurable shifts in candidate preferences, sometimes exceeding effects normally associated with conventional political advertising.
Now imagine political persuasion several generations from today. A campaign’s artificial intelligence does not send you a leaflet. It talks to you for six months. It knows which arguments you reject. It knows which arguments interest you. It knows whether patriotism, economics, immigration, taxation, corruption, national security or social justice most strongly influences your political thinking. Perhaps it knows when you are angry. Perhaps it knows whom you trust. Perhaps it knows which of your friends disagree with you. A democratic society cannot realistically prohibit political persuasion. Politics consists substantially of persuasion.
But your bodyguard could insist upon transparency. This argument is technically true but omits the following fact. This statistic comes from an organisation funded by the campaign.
You have now been shown fourteen stories about immigration in three days although immigration represents only a small proportion of the policy material being discussed.
This video appears synthetic. The account you are arguing with is probably automated.
Most importantly: This message appears to have been individually selected because the system predicts that it will make you angry. That is not censorship. It is informational self-defence.
The AI advocate
Eventually the bodyguard might become something more ambitious — an advocate. Modern institutions are bewilderingly complicated. Banks have contracts nobody reads. Technology companies have privacy policies nobody understands. Insurance policies contain exclusions few customers notice. Governments issue forms, regulations and administrative decisions written in specialised language.
We tolerate this partly because expertise is expensive. Artificial intelligence may radically reduce its cost. Before signing an employment contract, your AI reads it. Before accepting an insurance policy, your AI compares its exclusions with competing products. Before clicking I agree, your AI identifies which rights you are surrendering. Before speaking with a government bureaucracy, it explains the applicable rules. Before purchasing a financial product, it calculates the commission received by the person recommending it.
This begins to resemble a universal miniature professional adviser — part lawyer, part accountant, part researcher, part negotiator and part sceptical friend. The consequences for power relationships could be enormous. Much institutional power depends upon informational asymmetry. AI could increase that asymmetry catastrophically. Or it could destroy it. Everything depends upon whose AI is sitting on which side of the table.
Loyalty
This leads to the central problem. Who pays the bodyguard? The question sounds mundane. It may prove decisive. A personal AI financed by advertising cannot reliably defend somebody against advertising. An AI provided free by an online retailer cannot be presumed indifferent about where its user shops. An assistant operated by an insurance company cannot simultaneously be assumed to represent the customer’s interests against the insurer. The oldest professions understand this problem.
Lawyers have conflicts-of-interest rules. Trustees owe fiduciary duties. Company directors have legal obligations. Doctors have professional duties towards patients. Personal artificial intelligence may require comparable doctrines. The AI bodyguard should perhaps be understood legally as something resembling a fiduciary technology.
Its duty would be to advance the interests defined by its user and to disclose conflicts that prevent it from doing so. This would transform the debate about AI alignment. Usually we ask whether artificial intelligence is aligned with humanity. That is an extraordinarily abstract ambition. The more immediate question may be: Is this particular artificial intelligence aligned with me?
Memory belongs to the principal
A genuine personal AI would also require memory. Without memory it cannot understand the person it protects. But this produces an apparent paradox. The more the bodyguard knows about you, the more useful it becomes — and the more catastrophic its betrayal would be. A personal AI might eventually know almost everything. It may know your finances, relationships, correspondence, professional history, political interests, travel patterns, purchases, ambitions and anxieties.
This could become the most valuable psychological database ever constructed about an individual. It therefore cannot simply belong to whichever technology company happens to operate the servers. Personal AI memory should ultimately be treated as something closer to privileged material. It should be encrypted. Portable. Deletable. Auditable. The user should be able to move it between competing AI providers. The company supplying the model should not automatically acquire the right to mine it for advertising or train unrelated commercial systems upon it. The bodyguard cannot simultaneously sell a map of the building to the burglars.
Bodyguard against bodyguard
There is an intriguing consequence. Machines will increasingly negotiate with machines. Your AI may identify a manipulative advertisement created by another AI. The advertising AI will then adjust its technique. Your bodyguard will identify the adjustment. The commercial AI will respond again. We therefore arrive at an evolutionary contest. Persuasion AI versus defensive AI. Fraud AI versus fraud-detection AI. Political AI versus epistemic AI. Sales AI versus purchasing AI. Negotiating AI versus negotiating AI. Human beings may gradually withdraw from much of the tactical struggle altogether. The machines fight at the gates. The person decides what ultimately enters.
There is something unsettling about this prospect. But it may be considerably preferable to the alternative in which only corporations and governments possess sophisticated artificial representatives while ordinary people confront them unaided.
The danger of the guardian
No serious discussion of AI bodyguards can ignore the final danger. Who guards the guardian? A system that mediates everything somebody reads possesses immense power.
If it labels certain arguments manipulative and others legitimate, it can shape the intellectual world of its principal. If it decides which warnings deserve prominence, it can influence decisions while claiming merely to protect them.
The protective AI could therefore become the most effective manipulator of all. Recent scholarship on AI and autonomy identifies precisely this tension: systems designed to protect users’ reflective preferences may themselves undermine autonomy if they decide too aggressively what those preferences ought to be. The answer must be pluralism and control.
The bodyguard should explain rather than silently suppress. It should say: Here is what I detected. Not: I have decided you should never see it.
Users should be able to inspect its reasoning, modify its priorities, obtain second opinions from other models and switch providers without losing their personal histories. There should never be one universal AI bodyguard. There should be millions of them.
A new civil right
Eventually access to trustworthy personal artificial intelligence may become a question of social equality. Imagine a society in which wealthy people possess exceptionally capable private AIs protecting their finances, analysing contracts, detecting deception, negotiating prices, monitoring political manipulation and advising them continuously — while poorer citizens confront increasingly sophisticated commercial algorithms alone.
That would create a new class distinction. Not merely between people who possess information and those who do not. Between people who possess machine intelligence acting on their behalf and people who are themselves the objects upon which machine intelligence acts. Governments may therefore eventually have to consider whether some minimum level of independent AI representation should be universally available.
The analogy might be legal representation. A complicated society eventually concluded that there are circumstances in which leaving a person alone against an immensely more powerful institution is inconsistent with meaningful justice. The artificial intelligence age may reach a similar conclusion about cognitive representation.
The shield
We should not imagine the coming struggle between human beings and artificial intelligence too literally. The machines need not become hostile. Something subtler may happen. Corporations, political movements, governments, criminals and commercial organisations will acquire increasingly sophisticated artificial intelligences because doing so will advance their interests. Those systems will interact with us. Their interests and ours will sometimes coincide. Sometimes they will not.
The problem is therefore not that artificial intelligence will necessarily turn against humanity. It is that humanity consists of people and institutions with competing objectives — and AI will magnify their ability to pursue those objectives. The answer cannot be to leave the individual permanently unarmed. If artificial intelligence becomes powerful enough to understand our vulnerabilities, another artificial intelligence must be powerful enough to recognise when those vulnerabilities are being exploited.
If machines learn to persuade us, machines can help us examine the persuasion. If algorithms negotiate against us, algorithms can negotiate for us. If synthetic personalities learn our weaknesses, personal systems can remind us what those weaknesses are.
The bodyguard of the future may never throw a punch. It may never carry a weapon.
It may never possess a body at all. It will stand somewhere less visible — between the human mind and an increasingly intelligent world trying to influence it. And its most important duty may consist of four words: This is what they want. After that, the decision must remain ours.




