Users would have to share their authentication details with the negotiator, which would be a security risk but would mean the negotiator would be indistinguishable from the user.
The service providers certainly wouldn't like it but I'm not sure there's much they can do.