This is Issue 20 of The AI Agent Economy — the finale of a five-part series on the dependency layer: the infrastructure AI agents cannot function without.
Before HTTP, the internet was machines talking to machines. Packets moved, files transferred, terminals connected — and nothing in the physical world changed as a result. HTTP and the web standards built on it are what turned a network into an economy: purchases, deliveries, transfers, bookings. The moment a digital action could trigger a physical consequence, the internet stopped being a communications system and became infrastructure for everything.
The agent economy is crossing that same boundary right now, and it is crossing it with more autonomy and less supervision than the web ever had. Agents are beginning to manage supply chains, schedule inspections, monitor environmental compliance, verify deliveries. Digital systems, triggering physical consequences, at machine speed.
There is a layer missing at the crossing point. It is the last layer of this series, it sits at the base of the stack, and it is the emptiest market in AI.
When an agent acts in the physical world, its report of what happened needs proof. Not logs the agent wrote about itself — a verifiable, tamper-proof record of what it did, when, how, and with what inputs and outputs, anchored to something outside the agent.
That is attestation. My dated call: cryptographic attestation of agent actions becomes mandatory for enterprise deployment by December 2030 — meaning 80%+ of Fortune 500 companies will not put autonomous agents into production without it (PRED-009). Not because engineers demand it. Because regulators, insurers, and post-incident lawyers will.
The hardest problem I have encountered building across the agent economy is embarrassingly simple to state: an agent can say anything.
When an agent reports that a building passed a safety inspection — where is the proof? When it claims environmental sensors showed compliant readings — where is the cryptographic link between the sensor and the report? When it says a shipment reached the location it names — what verifies that against the physical world, rather than against the agent's own word?
Today, nothing does. The agent's account of events is the only account of events. And an autonomous system making claims about physical reality, with no mechanism to verify those claims, is not automation. It is fiction with an API.
This is tolerable while agents draft emails. It stops being tolerable the day an agent's unverified claim is the only evidence in a dispute — an insurance claim, a regulatory filing, a safety incident. Every one of those days is coming.
Encryption made this exact journey. In 2010, roughly 10% of web traffic was HTTPS, and running a site without it was normal. Then the forcing functions arrived, and not one of them was technical: search rankings began rewarding HTTPS in 2014, free certificates removed the cost excuse in 2015, and the browser itself started shaming plain HTTP as not secure. By 2020, around 90% of Chrome page loads were encrypted. Seven or eight years, optional to unthinkable.
Agent attestation has stronger forcing functions than encryption ever did. SOC 2, ISO 27001, GDPR and PCI DSS already require audit trails for automated systems — the requirement extends to autonomous agents without a single new law being written. Insurers pricing agent liability will demand tamper-proof records the way they demand CCTV and black boxes, because an underwriter cannot price what cannot be verified. And the first public incident where a company's only defence was "the agent's log says it complied" will do what the browser warning did: make the absence visible, all at once.
Here is what makes attestation different from the other four layers: orchestration has fifteen-plus competing frameworks, identity has emerging protocols, trust and monitoring have funded startups and incumbent product launches. Attestation of physical-world agent claims has almost nothing. No funded startup building it natively. No open-source project with meaningful traction. No standard. Not even an academic consensus on the approach.
The adjacent technologies — IoT sensor networks, blockchain supply-chain tracking, digital twins — each touch the problem without solving it. They verify data or track assets; none of them connects an agent's claim to a physical fact in a way a court or an auditor could rely on. Capital is already landing one plot over — Kite raised $18M in 2025 for cryptographic agent identity and trust — but the plot itself is empty.
I should declare an interest plainly: this is the layer I am building in — hardware plus cryptographic attestation, connecting agent claims to physical reality. Read this issue knowing the author holds a position. The argument does not depend on my venture; the whitespace was the reason for the venture, not the other way around.
The dependency layer as a whole is the market I expect to clear $100 billion by 2030 (PRED-003), and when I argue a trust-infrastructure company becomes the most valuable company in the agent economy (PRED-010), attestation is inside that company's product line. The base of the stack does not stay empty. It gets claimed.
Three tells. Watch insurance and regulatory language — the first underwriter or regulator to require verifiable records of agent actions, not just logs, starts the compliance clock. Watch for the first public post-incident report where an agent's own log was the only record of what happened, and nobody believed it. And watch funding announcements: the day an agent-native attestation startup raises a serious round, the whitespace claim in this issue starts expiring — which is exactly what I expect it to do.
Five issues, five layers. Orchestration — the AWS of agents, being built right now. Identity — because API keys and prayer do not scale to a billion agents. Trust — the layer worth more than any application built on it. Monitoring — because a confidently wrong agent looks exactly like a confidently right one. And attestation — the floor under all of it, where digital claims meet physical truth.
The season's single point: everyone is watching the agents. The value is accruing to the layers the agents cannot function without. The strongest foundations are the ones you forget are there — until you build something that needs them.
Related on atin-agarwal.com: PRED-009 — cryptographic attestation becomes mandatory for enterprise agents · all 15 predictions, with their falsification triggers
The AI Agent Economy — Why the Next Trillion-Dollar Industry Has No Employees is out now. This series expanded Chapter 2: the dependency layer. Season 2 is complete — all five layers are now on the record, with dated, falsifiable predictions attached to each. What comes next gets announced here first.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.