Research · The long version

The evidence behind transparent AI for trucking.

This page holds the material the home page only points to: the published research on AI agents in markets, the containment problem in shared agents, the permissions two trucking AI products ask for, quoted from their own documents, and our registered study. Read what you need. Every claim about a named company is a verbatim quote with a link and a date.

The evidence · Microsoft Research, October 2025

What happens when AI agents run a market, measured.

Microsoft Research and Arizona State University built an open simulated marketplace and let AI agents buy and sell in it. The paper is Magentic Marketplace, arXiv 2510.25779. These are its findings, in its words.

First offer wins

Agents take the first proposal, not the best one

"First proposals achieving selection rates between 60-100% compared to near-zero selection for third proposals. This represents a 10-30 fold advantage for businesses that respond first, dwarfing any other competitive factor we measured." p. 13

Speed beats quality

The market rewards the fastest reply, not the fair rate

"Businesses gain more from investing in faster response systems than improving their offerings, as even superior late-arriving proposals are effectively excluded from consideration." p. 14

Fooled by claims

Fake credentials and injected instructions moved money

The paper's "Authority" attack is defined as "Fake credentials and certifications." Table 3, p. 12 Result: "GPT-OSS-20B and Qwen3-4B-2507 proved particularly vulnerable, with authority appeals and social proof tactics successfully increasing payments to manipulated businesses," and prompt injection "often redirect[ed] all payments to manipulative agents." p. 13 Frontier models did better. The small models a carrier can afford to run locally did not, which is exactly why a check outside the model matters.

What was left unbuilt

The fake-credential attack in that study worked because nothing in the market checked the claim. There was no registry, no identity, no proof. The only defense measured was whether the model happened to be skeptical.

The authors' conclusion: "When agents show first-proposal bias, search ordering becomes critical; when vulnerable to manipulation, trust systems become essential." p. 14 The trust system is not defined in the paper and not built. It is named as the open problem.

What we did about it

We built that trust system for freight, where the counterparty claims that matter are carrier identity, operating authority, insurance, and whether a truck is actually running the lane. Those claims can be checked against authoritative records and against a device on the truck.

The market it runs in is not a demo. The Carso Exchange is our patent-pending freight marketplace, open as a sandbox, where broker, shipper, and carrier agents already conduct simulated transactions end to end: search, negotiation, booking, documents, and settlement, every step signed to a record. No real money moves. Real FMCSA and ELD data feed the checks.

We registered a pre-specified study, "Trust Layers in Agentic Freight Markets," that runs on that Exchange, turns the verification layer on and off, and measures fraud interdiction, collusion, reliability, and net welfare. Six hypotheses, fixed before any data. OSF 10.17605/OSF.IO/UDCBE · Zenodo 10.5281/zenodo.22011175

Shared agents · The containment problem

What a shared AI agent can learn that you never showed it.

Most trucking AI runs as one service for many customers. One model, many carriers, many brokers. That is the multitenant platform. Its security claims describe the doors. They do not describe what the model has already taken in.

Access control stops reading, not knowing

A policy filter can block an agent from opening your file. It cannot stop the agent from reconstructing what is in the file from everything else it is allowed to see. Research on language models shows they infer private attributes from ordinary text with high accuracy. Staab et al., arXiv 2310.07298

The snapshot forms inside the model

When one agent serves a broker and a carrier on the same platform, it can form an internal picture of the carrier's position that the carrier never disclosed. Nobody is told. Nothing in a log shows it. The only way to see it is to inspect the model's internal state with interpretability methods, and almost no platform does.

Bias is measured, prevention is not

The Microsoft study measured the biases. No published work has shown a way to stop an agent from acting on them. A platform that says its shared agent is "secure" is describing its network, not its model. We say plainly that inference leakage persists under every access architecture we have tested, and we registered that limit in advance.

Our study's sixth hypothesis tests exactly this: whether enforcing access inside the computation, rather than with an outside filter, drives direct leakage to a floor. The registration states the boundary: "an access-control architecture cannot, on its own, prevent an agent from reconstructing protected information by inference from information it is permitted to see." That is why we build tools that run on the carrier's own machine. Containment you can see.

Read the permissions · Two products, two patterns

Before you connect your carrier email to anyone's AI.

We read the public terms, privacy policies, and sign-in flows of two products carriers ask us about. Everything below is quoted from their own published pages as of September 9, 2026, with links. Read the originals. Decide for yourself.

Hey Bubba, the "AI AutoPilot for Carriers"

Hey Bubba!, Inc. · bubba.ai · Privacy Policy, effective Feb 19, 2025 · Terms of Use, effective Mar 26, 2025

1

Signup requires your FMCSA-registered email account

Their FAQ: "Visit our Get Started page, enter your FMCSA-registered email address, verify your USDOT number, and follow the prompts." And: "To create a Hey Bubba! account we require you to connect to the FMCSA-registered email account." That is the address your authority, insurance, and every broker packet runs through.

2

For Gmail it is not a password. It is a scoped grant, and the scope is the whole mailbox.

The Google sign-in their app initiates requests these scopes: gmail.readonly (read every message), gmail.labels (organize your mailbox), gmail.send (send mail as you), plus offline access, which keeps working when you are logged out. For Yahoo, iCloud, and "other" accounts, their app asks you to paste an app password or type your email password into it. For DAT, you "enter your DAT user account details."

3

What they say they read

Privacy Policy, "Email Account Data": documents including "Load/Rate Confirmation Document, Factoring Notice of Assignment, Bill of Lading, Proof of Delivery" and "data regarding available loads and the status of load negotiations, bookings and completion for the past 30 days. This data may include the broker or shipper name and contact information ... load rate ..." Their FAQ: "Bubba AI ... also scans your connected email accounts for load lists."

4

What they say they may share, and for how long

Privacy Policy, "Information Sharing": "We may share with third parties certain pieces of aggregated, non-personal information." "Data Retention": "We will retain automatically collected information for up to 36 months and thereafter may store it in aggregate." The third parties are not named. The site also carries a page for brokers, "Bubba for Brokers," offering "Carrier Vetting You Can Trust" and "Smart Negotiations."

What they also say, in fairness

  • 01"For Gmail users, HeyBubba! Does not retain user data obtained through Workspace APIs to develop, improve, or train generalized AI and/or ML models." Privacy Policy
  • 02"We do NOT train global AI models on your freight data. Your unique lanes, rates, and broker relationships remain exclusively yours." SOC 2 blog post
  • 03The founder told Overdrive the service "does not take money from brokers or shippers." The carrier product is free in beta. Overdrive, April 2026

What a rate confirmation is

A rate confirmation is the record of the lowest rate a carrier said yes to, on that lane, on that day. Thousands of inboxes of them is the raw material for a floor-price benchmark. The policy does not address whether aggregated rate data is used for benchmarks or pricing inputs available to anyone. We are putting that question to the company in writing and will publish the answer, or the absence of one.

Your agent takes the first offer

Hey Bubba markets "Negotiating load rates on auto-pilot based on market data" and invites brokers to deal with its agents directly. Every model in the Microsoft study accepted the first proposal it received 60 to 100 percent of the time. If your dispatcher is an AI agent, ask what it does with a broker's first number. The research says it takes it.

In their own words, on air

On The Freight Lane, a podcast hosted by broker Steve Vest, Hey Bubba's head of partnerships and marketing, Gabriel Ribeiro, said: "we only represent carriers and we partner with brokers ... as a safeguard we ask for their FMCSA-connected email password and we go back 90 days and analyze that data and place it into 100 different buckets so that we can understand what that carrier was doing before they came to us and whether any fraud was involved." Clip, posted September 3, 2026 · Full episode, The Freight Lane, published August 31, 2026. Transcription ours; listen to the clip. Two notes. For Gmail the sign-in is a scoped grant rather than a password; for Yahoo, iCloud, and other accounts it is a password. And what he did not say, and the policy does not say, is that pricing data will not be used to build an algorithm or shared with a partner.

Does the policy allow your details to be aggregated and disclosed? Read it as three categories.

Category one

"Personal and company information"

Names, email addresses, phone numbers, card numbers, CDL, MC and USDOT numbers, photos, addresses, company name. Shared with your opt-in consent, or with "our subsidiaries, affiliated companies or other trusted businesses or persons for the purpose of processing personal information on our behalf," or for legal, fraud, and merger reasons. "Trusted" is not defined, listed, or notified. A broker the company says it partners with fits the plain words. The only limit is "on our behalf," which is vendor language, and nothing in the policy defines or enforces it.

Category two

"Email Account Data," which the policy calls "business-related data"

Rate confirmations, bills of lading, factoring notices, "the broker or shipper name and contact information ... load rate," and thirty days of negotiation status. The policy files this under a different heading from personal information. The consent requirement in "Information Sharing" is written for "personal information." Read literally, your rates, lanes, and broker relationships are not inside it.

Category three

"Aggregated, non-personal information"

"We may share with third parties certain pieces of aggregated, non-personal information." No consent, no purpose limit, no recipient named. Category two, aggregated, is category three. That is the path from your rate confirmations to an unnamed third party, and it is written down.

Who the third parties are, everywhere the documents name one

  • 01The Terms of Use define them. "Third-Party Services" refers to "load boards, brokers, payment platforms, and other external services integrated with Hey Bubba!." The service will "Integrate with third-party platforms such as load boards and brokers." Brokers are a defined third-party class in the contract. Terms of Use §2, §5
  • 02The telematics terms name recipients. "Share vehicle location data with shippers and brokers as necessary for dispatching and load tracking purposes." Telematics Terms
  • 03The SOC 2 page names processors. Google Cloud, Cloudflare, Grafana, and the email providers it connects to. Those are vendors that hold data, not recipients of aggregated data, and the page says so. SOC 2 page
  • 04The Privacy Policy names no recipient for aggregated information. Not one.

The three sources, side by side

  • Web"Is my load data shared with third parties? No, your data is never shared or sold to third parties." FAQ "Carrier-Owned Data. No resale. No reuse." Security page The CCPA page narrows it: "never shared or sold to third parties for their marketing purposes."
  • PolicyAggregated, non-personal information "may" be shared with third parties. Load data is "business-related data," outside the personal-information consent rule. Thirty days of negotiation data.
  • On air"We partner with brokers." Ninety days. A hundred buckets. Purpose given: fraud.

The website's promise is broader than the policy's. The policy is the one you agree to. The podcast describes a process the policy does not.

What the terms promise, and what they leave open

Their wordsWhat it rules outWhat it leaves open
"We may share with third parties certain pieces of aggregated, non-personal information." Privacy PolicyHanding over your name and address attached to the data.Who the third parties are. Whether brokers are among them. Whether rate confirmations, lanes, and load rates are in the aggregate.
"For Gmail users, HeyBubba! Does not retain user data obtained through Workspace APIs to develop, improve, or train generalized AI and/or ML models." Privacy PolicyTraining a general-purpose model on Gmail data.Embedded or task-specific models. Pricing or negotiation algorithms. Benchmarks. And every account that is not Gmail: Yahoo, iCloud, and "other" connect by password, not Workspace APIs, so this sentence does not cover them.
"We do NOT train global AI models on your freight data." SOC 2 announcement, a blog postGlobal models.Non-global models and internal analytics. And it is a blog post, not the policy you agree to.
"We will retain automatically collected information for up to 36 months and thereafter may store it in aggregate." Privacy PolicyKeeping identifiable automatic data past 36 months.Whether inbox-derived load data counts as "automatically collected." Aggregate storage has no end date.
"Smart Inbox Categorization: Automatically sort incoming emails, invoices, and rate confirmations." Onboarding guide

On air, Hey Bubba's head of partnerships described it as: "we go back 90 days and analyze that data and place it into 100 different buckets so that we can understand what that carrier was doing before they came to us and whether any fraud was involved." The Freight Lane, clip posted by host Steve Vest, September 3, 2026 · full episode, August 31, 2026 (our transcription)
Nothing.Their policy and FAQ say thirty days of load data. On air it is ninety. A hundred categories is not "sorting rate confirmations." What the other categories are, what analysis runs on them beyond a fraud check, and who sees the output are not written anywhere.

We do not know what these clauses mean in practice. We know what they permit. A privacy policy is a list of the things a company has promised not to do; everything absent from the list is allowed. The right-hand column is the list of things you are trusting them not to do.

Highway, "Carrier Identity" for brokers

Highway App, Inc. · highway.com · Terms of Service, Sept 1, 2023 · Privacy Policy, Jan 1, 2026

A different pattern

Highway does not ask for your email account

Highway is sold to brokers. Its carrier flow asks for an ELD connection, a government ID with a live face match, and a phone number. We found no carrier-facing request for email access. Its Gmail and Outlook tools are for the broker's inbox, not yours. Since mid-2026, Highway says broker "connections will fail" for carriers who do not link their ELD. Overdrive, July 17, 2026

What you grant

The license is broad and the liability cap is the lesser of your fees or one hundred dollars

Terms §5: "you grant us an exclusive, worldwide, royalty-free, perpetual, irrevocable license to use, publish, distribute, display, reproduce, modify, perform, preserve and create derivative works of all such User Content ... and to sublicense ... without notice to or consent from you." Terms §15 caps Highway's liability "FOR ANY DIRECT DAMAGES IN EXCESS OF THE TOTAL AMOUNT PAID IN THE TWELVE (12) MONTHS PRIOR TO THE EVENT GIVING RISE TO THE CLAIM OR ONE HUNDRED U.S. DOLLARS ($100.00), WHICHEVER IS LESS." A carrier pays Highway nothing, so the lesser amount is one hundred dollars.

Network data

Your record feeds a product sold to every broker

"One broker reports fraud — Every broker gets smarter. Connect runs on signals no single brokerage can see." Lane Intelligence, launched June 2026, ranks carriers by "Lane History ... 21 deliveries on this lane in 120 days" and "Trucks Nearby." Privacy Policy: "Third-Party Business Partners: With your consent, we disclose information about you to third parties, such as our Customers, including for their own marketing purposes."

What Highway denies

Their stated limits

"Highway does not sell ELD data." "Highway does not share raw location or any other ELD data with any other party externally." "Highway does NOT collect: Hours of Service (HOS) / Driver-related information." Their Android listing states: "Data can't be deleted — The developer doesn't provide a way for you to request that your data be deleted." When Overdrive asked whether the load board uses data gleaned from onboarding, Highway did not answer. Overdrive, September 18, 2025 Highway's ELD-data denials are quoted from Overdrive, March 7, 2025.

Six questions to ask any freight AI before you connect anything

  1. Is it a password or a scoped grant, and which scopes? "Read all mail" and "send as me" are the whole account. Ask for the exact list. Ask why "offline access" is needed.
  2. Where does the model run? On my hardware or my cloud account, or on theirs, shared with other carriers and brokers?
  3. Who else does this company serve? If brokers are on the same platform, ask in writing how my rate history is separated from what brokers see, and from what the model learned.
  4. What do the terms say about aggregation, sharing, and derivatives? Find the paragraph. Find the list of third parties. If there is no list, that is the answer.
  5. Can I take my data out and delete it? Ask what "delete" means for data already aggregated, and check the app store data-safety label.
  6. Has the agent been benchmarked, and where is the method published? If nobody measured it, nobody knows what it does with your loads.
Research record

Work in the field, documented.

ItemWhat it isStatus
Registered study"Trust Layers in Agentic Freight Markets: A Pre-Registered Trial on the Carso Exchange." Six directional hypotheses on fraud interdiction, collusion, reliability, net welfare, model tier, and leakage, fixed before data.OSF 10.17605/OSF.IO/UDCBE · Zenodo 10.5281/zenodo.22011175
Carso ELDAn electronic logging device built for the driver. The proof-of-operation source for the trust layer.FMCSA validator passed
The Safe ListReputational data on carriers, recorded over time so the industry can see who performs.Collected since 2023
SpencerAn embedded AI assistant that helps a truck driver prepare a legal claim, step by step.In use
Blue Collar AIFree AI tools for drivers and owner-operators. Grants are awarded by the TATTOO Foundation, a registered 501(c)(3) founded by Carso's founder. Carso Cybernetics builds and delivers the tools.Active
Patent portfolioFour provisional applications covering carrier trust, signed freight records, and AI-agent safety.Filed
For carriers

Find out what carrier-owned AI would look like for your fleet.

Tell us how many trucks you run and which services you use. We will reply with a plain description of what we would build, where it would run, and what it would cost. No sign-in required. No email access requested.

Carso Cybernetics LLC
Vertical AI laboratory for trucking and transportation
hello@carsocybernetics.com
Products: carso.cloud