Action without a name, a ‘who’ attached to it, is meaningless.
— Hannah Arendt
By what architecture does any governance mechanism claim recognized authority over the monetary decisions of agents that cannot consent to being governed?
Series note: This report inherits the Undetermined finding and Handoff question from Legitimacy Money(March 2026), which itself inherited the Reconfiguration finding from Governance Money (March 2026). The series also includes Hedge Money (February 2026), which runs in parallel on the question of convexity and buffer capital. Readers new to the series will find the analysis self-contained.
Monetary systems already govern agents that cannot consent to them. What has changed is not that fact — but the emergence of new architectures that claim to authorize, account for, and contain the monetary decisions of non-human actors at scale.
This report asks a precise question:
What actually makes autonomous agent monetary governance accountable when the governed actor cannot consent at all?
In 2026, the question Legitimacy Money handed forward has reached the regulatory architecture of three jurisdictions simultaneously.
None of them has answered it.
United States: The GENIUS Act framework created federal licensing for payment stablecoins with OCC implementing rules that require documented human accountability for issuer decisions — establishing principal chain legibility as a regulatory expectation without yet mandating the technical architecture that would make it verifiable. Meanwhile, a federal court ruled in Amazon.com Services LLC v. Perplexity AI, Inc. that a merchant’s express prohibition on bots overrides user-delegated agent authorization under the Computer Fraud and Abuse Act, leaving agent authorization without a recognized legal grounding when the delegation chain encounters rules built for human actors. No binding liability framework for fully autonomous agent monetary decisions exists in any US jurisdiction.
European Union: The EU AI Act’s GPAI provisions impose supply chain obligations on model providers — a structural acknowledgment that the delegation chain extends backward to the model — while eIDAS 2.0 advances toward binding member state wallet deployment in approximately November 2026. Neither instrument addresses the liability architecture gap when an agent executes a monetary decision no human reviewed. The December 2027 compliance deadline for high-risk AI systems embedded in financial products is the next regulatory threshold at which the agent accountability question will be forced.
Switzerland: The Federal Electronic Identification Services Act, approved by Swiss voters on September 28, 2025 and moving toward launch no earlier than summer 2026, implements a ZK-proof-based e-ID on a self-sovereign identity model — demonstrating that the population reach and binding authority functions of credential-based delegation architecture can be assembled at state scale. It has also revealed the structural conditions primary jurisdictions must avoid: platform dependency on Apple and Google wallet infrastructure, and the voluntary-in-theory-mandatory-in-practice dynamic in financial services. Switzerland demonstrates the architecture is buildable. It does not demonstrate that the architecture generates monetary governance accountability for non-participants.
Meanwhile, three accountability architectures are competing to perform a function that agent monetary governance requires and that none of them fully performs: the recognized right to assign responsibility for monetary decisions made by actors that cannot themselves consent to the governance rules they operate under. The competition is not between old and new. It is not between centralized and decentralized. It is a competition over the specific boundary where every authorization architecture stops — and that boundary is precisely where monetary governance crises begin.
DelegatedExecution is the authorization architecture by which human principals extend monetary decision-making capacity to autonomous agents — through ERC-8004 identity and reputation registries, W3C Decentralized Identifiers, verifiable credentials, GENIUS Act custodial frameworks, and eIDAS 2.0 wallet infrastructure. Its three primary instantiations in the period this report covers are the GENIUS Act’s OCC implementing rule establishing documented human accountability for stablecoin issuer decisions, the EU AI Act’s GPAI supply chain documentation obligations extending accountability backward to the model layer, and ERC-8004’s on-chain agent identity and reputation registries deployed on Ethereum mainnet since January 2026 with the EIP standard remaining in Draft status. This architecture holds the Margins not because it performs the accountability function optimally — principal chain legibility under adversarial conditions has never been stress-tested at monetary governance scale — but because it is the only consent architecture currently assembling the authorization infrastructure that agent monetary governance requires, however partially and however unevenly across jurisdictions.
LiabilityVacuum is the missing accountability architecture that should assign legal and financial responsibility when autonomous agents cause monetary harm — and the structural gap where that architecture has not yet been assembled. The Amazon v. Perplexity ruling established that agent authorization is legally voided when it encounters merchant-controlled access rules, without producing a liability framework for the harm that results. The United States v. Heppnerruling established that communications with an AI platform lack attorney-client privilege because the AI is not a legal person — revealing the inverse problem: if an agent is not a legal person, it cannot bear obligations, so its actions must be traced to a human principal whose legal personhood is recognized. No jurisdiction has produced the tracing architecture that would make that trace possible at monetary governance scale. This architecture is at the Outside not because the problem is unrecognized — it is recognized across institutional, legal, and technical domains — but because the legal theory, the tracing infrastructure, and the dispute resolution architecture required to assign liability for fully autonomous monetary decisions have not been assembled anywhere.
SystemicExposure is the structural absence of architecture addressing populations whose monetary conditions are shaped by agent-executed decisions they did not authorize, and the containment mechanisms — currently unassembled at binding scale — that would prevent agent-generated failures from cascading to systemic scale. DePIN compute networks, oracle architectures, and multi-layer agent orchestration systems are all designed for resilience at the individual transaction level. None addresses aggregate behavior: the conditions under which independently rational agents produce collectively destabilizing outcomes — algorithmic collusion, correlated liquidation, simultaneous oracle consumption — that impose costs on populations outside the agent network. This architecture is at the Outside because no binding framework in any primary jurisdiction has formally addressed autonomous agent cascade dynamics as a distinct systemic risk category, and no non-participant accountability mechanism exists for populations whose monetary conditions are shaped by agent decisions they never authorized.
A note on functional layers: These three phenomena are functional layers of a single accountability problem, not mutually exclusive governance categories. The same institution — a major commercial bank deploying an AI treasury management agent — participates across all three simultaneously: as the principal whose delegation architecture is assessed under DelegatedExecution, as the potentially liable party under LiabilityVacuum when that agent executes a transaction no human reviewed, and as a contributor to SystemicExposure‘s cascade vulnerability when its agent’s optimal response to a price signal is identical to every other bank’s agent’s optimal response. Zone assignments track the accountability architecture being analyzed, not the institution performing it.
Before the zone map opens, the functions that agent monetary governance accountability requires need to be separated. The three phenomena in this analysis do not differ merely in their technical properties. They differ in which accountability functions they can perform — and those functions arise from different infrastructure layers, fail at different moments under stress, and cannot be assembled by substituting one for another. Treating them as a single mechanism produces a specific, identifiable error.
DelegatedExecution appears to solve the accountability problem because it makes delegation visible. The accountability function requires something else: reaching non-participants — populations whose monetary conditions are shaped by agent decisions they never authorized.
Authorization without consent capacity arises from the delegation architecture — the mechanism by which a human principal extends monetary decision-making to an agent that cannot itself consent to the governance rules it operates under. DelegatedExecution addresses this function through credential infrastructure, smart contract escrow, and statutory custodial frameworks. LiabilityVacuum does not address it — liability assignment is downstream of authorization, not a substitute for it. SystemicExposure does not address it — systemic containment operates at the aggregate level, not at the individual delegation event. The functional requirement is structural: agent authorization must be grounded in a human or institutional principal whose consent capacity is real, traceable, and legally recognized. When that grounding fails, authorization appears valid at execution but is legally void at the accountability layer.
Liability assignment under autonomous error arises from the legal accountability architecture — the mechanism that assigns financial and legal responsibility when an agent causes monetary harm without a proximate human decision.
This function requires three elements: a legal theory of agency that extends to non-human actors; a delegation record sufficient to identify the responsible principal; and a dispute resolution architecture capable of processing claims where the decision-maker cannot testify. DelegatedExecution provides the delegation record but not the legal theory. SystemicExposure provides containment architecture but not individual liability assignment. The Amazon v. Perplexityruling and the Heppner privilege case both reveal this function as structurally absent — not because the law has not caught up, but because the existing legal architecture was built for human decision-makers and has no native extension to autonomous agents.
Principal chain legibility arises from the audit and traceability architecture — the mechanism that makes the delegation chain from human principal to autonomous agent readable by counterparties, regulators, and affected third parties. This function is co-resident with authorization in DelegatedExecution because both concern what happens within the delegation chain before external actors are affected. But they are non-commensurable: an agent can be validly authorized while its delegation chain is illegible to regulators, or a delegation chain can be fully legible while the authorization itself is legally contested. ERC-8004’s identity registry and W3C DIDs are candidate architectures for this function. Neither has been stress-tested at monetary governance scale under adversarial conditions — where a regulator or harmed third party must trace a delegation chain through multiple agent layers under time pressure.
Non-participant accountability arises from the architecture — currently absent — that addresses populations whose monetary conditions are shaped by agent-executed decisions they did not authorize. This is the direct successor to Legitimacy Money‘s compelled participation handling function, applied one level deeper. In Legitimacy Money, the question was: what architecture handles populations who did not consent to the governance mechanism? In Agent Money, the question is harder: what architecture handles populations who did not authorize the agent, when the agent itself cannot consent to being governed? DelegatedExecution does not address this — it operates within the principal-agent relationship, not the agent-to-non-participant boundary. LiabilityVacuum does not extend here — individual liability assignment does not cover diffuse non-participant harm. SystemicExposure carries this function at the aggregate level, but no binding framework has assembled it.
Systemic risk containment arises from the financial stability architecture — the mechanism that prevents agent-generated failures from cascading across the principal chain and into the broader monetary system. This function is co-resident with non-participant accountability in SystemicExposure because both address the external boundary of the agent economy. They are non-commensurable: a systemic cascade can be contained while non-participant accountability remains absent — the 2008 TARP architecture contained systemic failure without providing accountability to populations harmed by the cascade. And non-participant accountability can be assembled in principle while systemic containment remains absent.
These five functions survive the commensurability test as structurally distinct. The Accountability Stack reveals a consistent structural pattern across all three phenomena: every architecture that makes autonomous agents capable of monetary action provides authorization infrastructure for participants and provides nothing for the populations outside the delegation chain. Authorization terminates at the non-participant boundary. That boundary is precisely where monetary governance crises impose their costs.
Center is where no phenomenon currently operates — no accountability architecture has assembled all five functions at the compelled participation boundary for non-human governed actors.
For legal readers: Think of Center as the constitutional order that operates above the ordinary rules for human actors — the architecture that generates recognized right to impose costs, not merely the technical capacity to execute them. Center requires that the delegation chain is legible, that liability can be assigned, that non-participants have a contestability mechanism, and that systemic cascades can be contained. No architecture currently performs all four.
For technical readers: Center is the permission layer that no other system has successfully replicated at monetary governance scale — the architecture that generates recognized accountability for autonomous decisions, not merely an immutable record that the decisions occurred.
Margins is where DelegatedExecution operates — authorization and principal chain legibility partially assembled for participants, liability assignment for autonomous errors absent, non-participant accountability and systemic risk containment structurally missing. The GENIUS Act framework, EU AI Act GPAI provisions, and ERC-8004’s on-chain registries are real; their delegation frameworks are operational in partial deployment; the authorization claim they advance is genuine among participants. But none has demonstrated principal chain legibility under adversarial conditions, and the Amazon v. Perplexity ruling demonstrated that user-delegated authorization has no recognized legal grounding when it encounters rules built for human actors.
For legal readers: Think of it as power of attorney for code — legally grounded for the parties who entered the delegation instrument, with no answer for the populations affected by the agent’s actions who never signed anything.
For technical readers: The execution layer is production-ready. The governance layer that makes delegation chains legible to actors outside the protocol has not passed its adversarial test.
Outside is where both LiabilityVacuum and SystemicExposure operate — candidate architecture for liability assignment present at the first-instance court ruling level, monetary governance application unassembled; systemic risk containment architecture recognized in working papers but unnamed as a distinct category in any binding framework. The legal record on agent liability consists of rulings establishing the problem’s existence, not its resolution. The macroprudential record on agent cascade risk consists of Basel review timelines and FSB working papers, not binding frameworks.
For legal readers: Think of LiabilityVacuum as the gap between execution and obligation — the space where immutable settlement records prove what happened without producing a recognized legal claim against an identifiable responsible actor. Think of SystemicExposure as the non-participant problem one level deeper than Legitimacy Money mapped it — not who consented to the governance architecture, but who is accountable when the governed actor itself cannot consent.
For technical readers: The cryptographic record of every agent decision is complete and immutable. The governance application layer — the layer that would translate “this record proves this agent caused this harm to this population” into a recognized monetary governance accountability mechanism — has not been written.
The FindingType is Undetermined — and the finding is precise about why. The three accountability architectures are performing different subsets of the five functions. Whether their disaggregation across institutional layers is structurally coherent or self-defeating depends on a determination this cartography cannot yet make: whether DelegatedExecution‘s partial assembly of authorization and legibility functions can be extended to reach liability assignment, non-participant accountability, and systemic containment — or whether the five functions are structurally inseparable and must co-reside in a single institutional architecture. Four analytical threads:
How DelegatedExecution‘s partial performance of authorization and principal chain legibility functions constitutes the zone map’s reference point — and where its accountability architecture fails at the non-participant boundary
How LiabilityVacuum‘s structural absence is produced by the mismatch between legal architecture built for human decision-makers and monetary execution now performed by non-human agents — and what Amazon v. Perplexity, Heppner, and the Van Loon boundary reveal about the structural location of that gap
How SystemicExposure‘s technical infrastructure is operational for individual transaction resilience but unassembled for aggregate behavior containment — and what the concave systemic risk position of the agent economy reveals about the distance remaining
How legacy regulatory standard-setting delays the empirical test that would determine whether accountability architecture disaggregation is coherent or self-defeating
What You’re Looking At: The authorization architecture by which human principals extend monetary decision-making to autonomous agents — ERC-8004, DIDs, verifiable credentials, GENIUS Act custodial frameworks — and the structural boundary where that delegation chain stops being traceable under stress.
For legal readers: Think of DelegatedExecution as power of attorney for code — the architecture that makes agent monetary decisions legally attributable to a human or institutional principal. The Amazon v. Perplexity ruling revealed the gap precisely: user-delegated authority was legally voided by merchant-controlled access rules, leaving the authorization architecture without a recognized legal grounding when the delegation chain encounters rules built for human actors. The question is not whether agents can be authorized to act. The question is whether the authorization survives contact with legal architecture built for human decision-makers.
For technical readers: The execution layer is production-ready — x402 payments, smart contract escrow, TEE attestations, and ERC-8004 identity registries are operational. What is missing is not a more reliable execution layer. What is missing is a governance layer that makes the delegation chain legible to actors outside the protocol: regulators, courts, harmed counterparties who need to trace who authorized what, when, under what constraints.
DelegatedExecution sits at the Margins because delegation frameworks are operational and growing — the GENIUS Act’s OCC implementing rule requires documented human accountability for stablecoin issuer decisions; eIDAS 2.0’s wallet framework creates binding infrastructure for credential-based delegation; ERC-8004’s identity and reputation registries are deployed on Ethereum mainnet as of January 2026, with the EIP standard remaining in Draft status pending peer review. The architecture exists in partial deployment across multiple jurisdictions. What keeps DelegatedExecution at Margins rather than Center is the stress-test record: no delegation architecture has been required to perform its principal chain legibility function under adversarial conditions — a weekend failure event, a multi-layer agent cascade, a regulatory enforcement action attempting to trace liability through four layers of sub-agents to a human principal.
Every architecture that makes autonomous agents capable of monetary action leaves the same gap: the delegation chain that authorizes the agent stops precisely at the boundary where accountability to non-participants begins.
This function is structural. Not interpretive. Not optional.
The statutory binding authority infrastructure for agent delegation is being assembled from three directions simultaneously. The GENIUS Act’s OCC implementing rule requires payment stablecoin issuers to maintain documented human accountability for governance decisions — a Mandatory Compliance requirement that implicitly establishes principal chain legibility as a regulatory expectation without yet mandating the technical architecture that would make it verifiable. The EU AI Act’s GPAI provisions impose supply chain obligations on model providers — a structural acknowledgment that the delegation chain extends backward to the model, not only forward to the agent’s actions. The W3C DID specification provides the technical standard for globally unique agent identifiers that can prove control over a digital persona using public-private keypairs independent of any central organization.
The convex position that DelegatedExecution does not yet hold is the strategic ambiguity advantage that DemocraticDelegation held in Legitimacy Money. A recognized delegation architecture would generate compliance value before enforcement is invoked — because counterparties and regulators would trust that the principal chain is legible and that accountability is traceable. The current architecture produces the opposite: because principal chain legibility has not been demonstrated under stress, counterparties impose friction (the “No Bots” merchant rules that the Amazon v. Perplexity ruling enforced) and regulators reach for the nearest human rather than tracing the delegation chain. The friction is the signal that the legibility function is not yet performing.
The Predatory Delay dimension operates at the standard-setting layer. Legacy financial institutions that have invested in human-centric KYC and AML compliance infrastructure have structural incentives to delay the emergence of KYA frameworks — every month that Know Your Agent standards remain unharmonized is a month in which incumbents’ existing compliance architecture retains its competitive value. The Basel Committee’s targeted cryptoasset review, extended to address agent-related payment infrastructure, is the institutional venue where this delay is operating. The review timeline — with no binding output expected before 2027 — preserves the current architecture’s hold on the authorization function by preventing KYA from being subjected to the standardization event that would move DelegatedExecution toward Center.
Selected sources informing this section:
Mandatory Compliance [1] OCC — GENIUS Act implementing rule [2] European Parliament — EU AI Act GPAI obligations [3] CMA — complying with consumer law when using AI agents
Resolving Disputes [4] US District Court — Amazon v. Perplexity, authorization conflict ruling [6] Fifth Circuit — Van Loon, boundary of state reach
Verifiable Proofs (shared with The Responsibility Gap) [7] W3C — DID v1.1 specification [8] De Rossi et al. — ERC-8004 Trustless Agents EIP [9] European Parliament — eIDAS 2.0
Predatory Delay [10] BIS — Basel targeted cryptoasset review [11] Baker Donelson — 2026 AI legal forecast
What You’re Looking At: The accountability architecture that should assign legal and financial responsibility for agent-caused monetary harm — and the structural gap where that architecture has not yet been assembled. Not a temporary absence waiting for courts to catch up. A structural condition produced by the mismatch between legal architecture built for human decision-makers and monetary execution now performed by non-human agents.
For legal readers: Think of LiabilityVacuum as the gap between execution and obligation. Existing agency law assigns liability to principals for agent actions — but that doctrine assumes the agent is a human acting within delegated authority. When the agent is autonomous, makes decisions no human reviewed, and causes harm through a process no human directed at the proximate moment, the doctrine’s load-bearing assumption fails. The Amazon v. Perplexity ruling is the first data point: the court reached for CFAA rather than agency doctrine, because agency doctrine had no answer for an autonomous actor whose authorization was contested at the merchant layer.
For technical readers: The execution layer produces a complete, immutable record of every agent decision. That record is not the same as a liability assignment architecture. The Heppner privilege ruling established that communications with an AI platform are not protected because the AI is not a legal person. The inverse problem applies here: if the agent is not a legal person, it cannot bear obligations — so its actions must be traced to a human principal whose legal personhood is recognized. The tracing architecture is the missing element.
LiabilityVacuum sits at the Outside because no jurisdiction has produced binding liability architecture for fully autonomous agent monetary decisions. The legal record consists of first-instance rulings establishing the problem’s existence — not its resolution. The CMA’s guidance that deploying businesses retain full consumer law obligations under autonomous agent operation is a statement of principle, not an operational liability framework: it places the obligation on the business deploying the agent without specifying how liability is allocated when the agent acts outside its instructed parameters, when the harm is diffuse across thousands of simultaneous agent interactions, or when the delegation chain passes through multiple agent layers before reaching a human principal.
The Programmable Protocols lens reveals the specific structural condition that keeps LiabilityVacuum at Outside. Smart contract execution is immutable and final — when an agent executes a transaction through a programmable protocol, the settlement is cryptographically complete before any human can review it. This is the design: the speed and efficiency of agent commerce depends on finality without human review. But the liability architecture requires the opposite — a moment of human review, authorization, or at minimum awareness that is legally cognizable as the point where responsibility attaches. The x402 protocol’s payment-for-service model and the atomic transaction architecture that bundles millions of micro-payments into single on-chain settlements both produce outcomes that are economically efficient and legally unattributable at the individual transaction level.
The Clear Accountability function is where LiabilityVacuum most clearly reveals its Outside status. The EU AI Act’s GPAI provisions create supply chain obligations for model providers: a model provider whose model is deployed in an agent that causes monetary harm bears documentation and transparency obligations. This is accountability architecture for the model layer, not for the agent layer. The gap between “the model provider documented the model’s capabilities” and “the harmed party has a recognized claim against an identifiable responsible actor” is the structural object of this phenomenon. No binding framework has closed it.
The Verifiable Proofs lens — shared with DelegatedExecution — reveals the credential infrastructure’s specific limitation at the liability layer. ERC-8004’s validation registry provides hooks for recording verifiable evidence that an agent completed a task. This is proof of execution, not proof of authorization scope. The liability question is not “did the agent execute this transaction?” — the blockchain record answers that. The liability question is “was this transaction within the scope of what the principal authorized, and if not, who bears the loss?” The credential infrastructure that makes delegation chains legible does not answer the scope question — because scope is a legal interpretation of a delegation instrument, not a cryptographic proof of execution. The delegation architecture does not extend beyond its principals. And the populations outside that boundary have no claim architecture of any kind.
Selected sources informing this section:
Programmable Protocols [12] Gao et al. — agent economy blockchain foundation [13] Anon — virtual agent economies
Clear Accountability [5] US District Court — United States v. Heppner, legal personhood boundary [14] EDPB/BayLDA — Worldcoin erasure order [15] Fime — agentic AI and payments, liability architecture
Verifiable Proofs (shared with The Delegation Layer) [7] W3C — DID v1.1 specification (scope-of-authorization gap angle) [8] De Rossi et al. — ERC-8004 EIP (scope-of-authorization gap angle) [9] European Parliament — eIDAS 2.0 (regulatory-scale deployment angle)
What You’re Looking At: The structural absence of architecture addressing populations whose monetary conditions are shaped by agent-executed decisions they did not authorize — and the containment mechanisms, currently unassembled at binding scale, that would prevent agent-generated failures from cascading to systemic scale.
For legal readers: Think of SystemicExposure as the non-participant problem one level deeper than Legitimacy Money mapped it. In Legitimacy Money, the question was whether a consent architecture could reach populations who did not choose to participate in the governed monetary system. In Agent Money, the governed actor itself cannot consent — so the non-participant population now includes not only humans who never joined the system, but every human whose monetary conditions are shaped by an agent that was never theirs to authorize. The LOLR gap that Legitimacy Money identified in the GENIUS Act framework is now visible at the agent layer: when a cascade of autonomous agent failures produces systemic monetary harm on a weekend, no institutional backstop architecture currently addresses it.
For technical readers: The distributed systems architecture of the agent economy — DePIN compute networks, multi-layer agent orchestration, oracle networks bridging on-chain and off-chain data — is designed for resilience at the individual node level. Oracle manipulation detection, TEE attestations, and multi-source verification all address individual transaction integrity. None addresses aggregate behavior: the conditions under which independently rational agents produce collectively destabilizing outcomes — algorithmic collusion, coordinated liquidation, correlated oracle failures — that impose costs on populations outside the agent network.
SystemicExposure sits at the Outside for both of its co-resident functions. Non-participant accountability for agent monetary decisions has no binding framework in any primary jurisdiction. Systemic risk containment for autonomous agent cascades has not been formally addressed by FSB, BIS, or any primary jurisdiction regulator as a distinct category — the Basel targeted cryptoasset review addresses stablecoin reserve requirements, not autonomous agent cascade dynamics.
The Distributed Systems lens reveals the specific architecture that makes SystemicExposure structurally distinct from individual transaction risk. DePIN compute networks distribute GPU capacity across thousands of independent nodes. This architecture is resilient to individual node failure. It is not resilient to correlated demand shocks: when every agent in a system simultaneously requires compute capacity for a crisis-response decision, the distributed network faces the same congestion failure that Ethereum’s network faced on Black Thursday — the exit door closes precisely when the cost of staying is highest. The oracle networks that feed price data to agent decision-making systems face an analogous correlated failure mode: a manipulated price feed that reaches multiple oracle sources simultaneously produces correlated agent responses that are individually rational and collectively destabilizing.
The Risk Convexity lens — the same lens that established DemocraticDelegation‘s strategic advantage in Legitimacy Money — now operates as a diagnostic for SystemicExposure‘s structural vulnerability. DemocraticDelegation held a convex legitimacy position because its recognized authority created binding commitments whose scope was not fully calculable in advance. The agent economy produces the inverse: a deeply concave systemic risk position, where the aggregate behavior of autonomous agents is more predictable than any individual agent’s behavior — because agents optimize against observable parameters, and when those parameters are shared across a population of agents, their responses converge. The convergence is the systemic exposure: a population of agents all responding optimally to the same price signal produces a cascade that no individual agent’s risk management architecture was designed to contain. (The theoretical grounding for this convergence dynamic rests partly on Acemoglu et al.’s NBER working paper, which remains pre-peer-review; Calvano et al.’s 2020 peer-reviewed work on algorithmic collusion in product markets provides independent empirical support for the core mechanism.)
Accountability breaks exactly where external impact begins. That is not a design flaw. It is the architecture.
Selected sources informing this section:
Distributed Systems [16] Anwar et al. — comparative trust models for autonomous agents [17] Google Cloud — AP2 agent payments protocol
Risk Convexity [18] Acemoglu et al. — economy of AI agents, NBER [19] Draghi — legitimacy premium, convex contrast [20] Glassnode — Black Thursday, concave contrast case
Switzerland functions in this report in two analytical roles. As a proof-of-concept: its ZK-proof-based e-ID demonstrates that the population reach and binding authority functions of credential-based delegation architecture can be assembled at state scale, before any monetary governance application. As a failure instance: its platform dependency on Apple and Google wallet infrastructure, and the voluntary-in-theory-mandatory-in-practice dynamic that financial services acceptance creates, establishes a lower bound on what primary jurisdictions must avoid when assembling DelegatedExecution architecture. What Switzerland cannot yet demonstrate is whether that architecture generates non-participant accountability or systemic risk containment at monetary governance scale. A full cartography of Switzerland’s accountability architecture requires its own treatment elsewhere.
Switzerland’s Federal Electronic Identification Services Act represents the furthest operationalization of credential-based delegation architecture that any jurisdiction has achieved at state scale. The ZK-proof architecture — unlinkability, selective disclosure, self-sovereign control — is the candidate technical foundation for a principal chain legibility mechanism that could prove “this agent was authorized by this principal” without creating a surveillance profile of the delegation chain as a precondition for traceability.
The failure instance function Switzerland provides is structurally significant for the DelegatedExecution analysis: it demonstrates that platform dependency is not a peripheral implementation risk but the specific vulnerability that appears when state-issued credential infrastructure relies on private-sector wallet distribution for its population reach — the same distribution layer that any DelegatedExecution architecture at monetary governance scale must solve. Primary jurisdictions building DelegatedExecution infrastructure must solve the distribution layer problem that Switzerland has identified — or inherit the same dependency condition.
Switzerland’s regulatory landscape in this domain is the most technically advanced and the most resistant to unified characterization: what is well-evidenced is the ZK-proof architecture, the self-sovereign identity model approved by voters in September 2025, and the platform dependency failure mode. What remains contested is whether this infrastructure generates the liability assignment and non-participant accountability functions that agent monetary governance accountability requires. This report maps US and EU in detail; Switzerland’s accountability architecture is treated as a subject requiring its own cartography elsewhere.
Agent Money is not a competition between delegation architectures waiting for a technical winner — it is the cartography of how every architecture that makes autonomous agents capable of monetary action reaches its principals and stops at the boundary where accountability to non-participants must begin. This cartography reveals an Undetermined finding: DelegatedExecution holds the Margins not by performing all five accountability functions optimally, but by performing authorization and principal chain legibility partially within existing regulatory frameworks. At the non-participant accountability layer, every architecture examined has found the same structural boundary.
Whether that boundary can be moved — or whether it is a permanent structural condition of monetary governance when the governed actor cannot itself consent — is the open question this cartography cannot close.
The institutions are the constant across all three phenomena. A major commercial bank deploying an AI treasury management agent is simultaneously subject to DelegatedExecution‘s GENIUS Act custodial accountability requirements, exposed to LiabilityVacuum‘s unresolved liability architecture when that agent executes a transaction no human reviewed, and a contributor to SystemicExposure‘s cascade vulnerability when its agent’s optimal response to a price signal is identical to every other bank’s agent’s optimal response. The OCC is simultaneously the regulator whose implementing rules are assembling principal chain legibility requirements for stablecoin issuers, the institutional actor whose silence on autonomous agent liability is producing the LiabilityVacuum, and the agency whose jurisdictional boundary stops precisely where cross-border agent cascades begin. The accountability problem is constant. What varies is which functional layer each architecture can address. None has yet assembled all five functions at the non-participant boundary — where monetary governance stress is highest.
The 2026 and 2027 regulatory decisions will shape which migrations become structurally possible within the US and EU jurisdictions this report maps in detail. If EU AI Act implementing rules explicitly mandate agent delegation traceability as a monetary governance requirement — technically specified rather than merely interpretive — DelegatedExecutioncrosses toward Center as the authorization architecture that sets the terms of normal monetary governance operation. If a binding liability framework emerges from appellate precedent or emergency legislation following a major autonomous agent monetary failure, LiabilityVacuum crosses the Outside → Margins threshold. If neither moves, the “autonomous cascade” scenario — a correlated agent failure event on a weekend where no institutional backstop architecture exists and no liability framework assigns responsibility to an identifiable actor — remains the pending stress test for the finding this cartography cannot resolve.
This cartography maps what exists, not what should exist. DelegatedExecution creates affordances for scalable, traceable authorization of autonomous monetary action — and for principal chain opacity that concentrates accountability risk at the deploying institution while diffusing it across affected populations. LiabilityVacuum creates affordances for rapid autonomous execution that produces efficiency gains for participants — and for a structural absence of accountability that becomes visible only when a harmed party attempts to identify who bears responsibility for a decision no human made. SystemicExposure creates affordances for distributed, resilient individual transaction architecture — and for correlated aggregate behavior that individual-transaction risk management was not designed to contain. The evidence permits multiple interpretations. The 2027 EU AI Act high-risk system compliance deadline approaches.
By what architecture does any governance mechanism claim recognized authority over the monetary decisions of agents that cannot consent to being governed?
This cartography confirms that the Undetermined finding holds at the accountability boundary:
Every architecture that makes autonomous agents capable of monetary action leaves the same gap: the delegation chain that authorizes the agent stops precisely at the boundary where accountability to non-participants begins.
The three phenomena collectively demonstrate that authorization without consent capacity, liability assignment under autonomous error, principal chain legibility, non-participant accountability, and systemic risk containment arise from distinct infrastructure layers, fail separately under stress, and have not yet been assembled into a single architecture that reaches non-participants at monetary governance scale. The successor analysis must determine what accountability architecture is structurally possible when the governed monetary value is not held by a human, an institution, or an agent — but assembled by protocol-layer mechanisms across multiple jurisdictions and asset classes, with no single actor who authorized its existence and no single jurisdiction that can see it whole.
Hedge Money established that the verification barrier is the binding constraint on barbell access below institutional scale. Agent Money establishes that the delegation chain terminates before it reaches non-participants. Both findings converge on a third condition: monetary value is increasingly assembled across protocol layers by agent interactions that no single actor initiated, authorized as a whole, or can see in aggregate across jurisdictions. The question they share: at what point does the protocol become the accountability layer — and what is exposed when it fails?
By what architecture does any governance mechanism claim recognized authority over value that no actor assembled intentionally and no single jurisdiction can see?
Read more about Synthetic Money here:
That question — about the accountability architecture of emergent cross-protocol monetary positions — is the open problem this cartography hands forward. What follows documents how the current map was built.
This report belongs to the genre of structural pattern recognition across institutional, legal, and technical domains. Evidence consists of primary legal instruments, regulatory publications, court decisions, technical standards specifications, and peer-reviewed and preprint academic work illuminating distinct layers of the agent accountability problem. Zone-state cartography is the diagnostic method: mapping how monetary governance accountability migrates between authorization architectures by tracking which accountability functions each form can and cannot perform.
The framework evaluates observable structural signals to assess zone assignments and migration conditions. It does not infer institutional desirability, optimality, or normative superiority of any configuration. Classification reflects signal convergence under current conditions and remains contingent on regulatory, technical, and legal evolution. Lens signals were assigned following structured evidence extraction; each lens was evaluated independently before aggregation. This report is the third in a series: Governance Money (Reconfiguration finding, March 2026) and Legitimacy Money(Undetermined finding, March 2026) established the series architecture. Agent Money inherits the Undetermined finding from Legitimacy Money and carries it one level deeper — from consent architecture to accountability architecture, from human non-participants to non-human governed actors. The framework evaluates what accountability architectures exist and what structural conditions would need to be met for zone migration to occur. It does not evaluate whether those migrations are desirable, likely within any specific timeframe, or sufficient to address the underlying governance problem.
OctonarySet — eight lenses across five perspectives:
This report analyzes three phenomena using eight analytical lenses drawn from the nemo2 Protocol.
DelegatedExecution: Mandatory Compliance, Resolving Disputes, Verifiable Proofs (shared), Predatory Delay. Four lenses assigned as architecturally primary phenomenon: DelegatedExecution is the load-bearing mechanism on which both LiabilityVacuum and SystemicExposure depend for their zone assignments. Each lens addresses a structurally distinct layer — compliance mandate, dispute resolution record, credential infrastructure, and strategic delay — that cannot be collapsed without losing analytical grounding.
LiabilityVacuum: Programmable Protocols, Clear Accountability, Verifiable Proofs (shared).
SystemicExposure: Distributed Systems, Risk Convexity.
FindingType: Undetermined. No accountability architecture has assembled all five functions at the non-participant boundary. Mandatory Compliance and Risk Convexity produce partial Reconfiguration signals — delegation architecture is being assembled within existing regulatory frameworks, and the concave systemic risk position of the agent economy is structurally coherent with existing macroprudential architecture absorbing a new stress category. Clear Accountability, Programmable Protocols, and Distributed Systems produce Undetermined signals — genuine capabilities demonstrated at the transaction layer, decisive accountability gaps confirmed at the non-participant boundary. Predatory Delay produces a signal consistent with Reconfiguration: incumbent standard-setting is extending existing architecture’s hold by preventing KYA frameworks from being subjected to the standardization event that would accelerate DelegatedExecution‘s migration. Two structurally non-redundant lens clusters produce partial directional signals toward Reconfiguration; the remainder produce genuine divergence at the accountability boundary. Undetermined is warranted: the partial Reconfiguration signals reflect that existing frameworks are absorbing the agent economy, not that they have resolved its accountability problem.
Zone migration definition: A phenomenon migrates when it crosses the legibility threshold — not when it grows within its current zone. Outside → Margins: a binding regulatory framework formally addresses the accountability architecture as a monetary governance requirement. Margins → Center: the accountability architecture sets the terms of normal monetary governance operation rather than being treated as an exception or supplement. Growth within a zone is not migration. DelegatedExecution is growing within Margins — the GENIUS Act, EU AI Act, and eIDAS 2.0 are all adding delegation infrastructure without yet producing the stress-test record that would confirm Center status.
Transitions
Migration probabilities below reflect the structural distance between each phenomenon’s current zone status and its next threshold, assessed against the regulatory, legal, and technical conditions documented in the Deep Dive sections above; they are not forecasts of likelihood but calibrated expressions of how much of the required architecture remains unassembled:
T1 — DelegatedExecution Margins → Center: 0.15–0.30 (EU AI Act high-risk system compliance deadline extends to December 2027; upper bound reflects scenario where implementing rules explicitly mandate agent delegation traceability as monetary governance requirement; lower bound reflects scenario where compliance remains interpretive and principal chain legibility is never technically specified)
T2 — LiabilityVacuum Outside → Margins: 0.10–0.25 (no appellate precedent; no binding framework in any jurisdiction; upper bound reflects scenario where a major autonomous agent monetary failure triggers emergency legislative response before 2028; lower bound reflects scenario where first-instance rulings establish only the problem’s existence without producing binding liability architecture)
T3 — SystemicExposure Outside → Margins: 0.08–0.20 (systemic risk frameworks move slowest — Basel III took five years from crisis event to binding implementation; upper bound reflects scenario where a correlated agent failure event triggers G20-level response naming autonomous agent cascades as a distinct systemic risk category)
US and EU primary; Switzerland scoped as proof-of-concept and failure instance.
The five accountability functions: Authorization without consent capacity (delegation architecture — the mechanism extending monetary decision-making to non-consenting agents), Liability assignment under autonomous error (legal accountability architecture — responsibility for harm caused without proximate human decision), Principal chain legibility (audit and traceability architecture — readability of delegation chain by counterparties and regulators under adversarial conditions), Non-participant accountability (non-participant architecture — structural answer for populations whose monetary conditions are shaped by agent decisions they never authorized), Systemic risk containment (financial stability architecture — prevention of agent-generated failures cascading to systemic scale). Zone assignments track which functions each accountability architecture performs. Center requires all five; Margins performs at least one partially at scale; Outside has candidate architecture unassembled for monetary governance application.
Principal chain legibility: The capacity of a delegation architecture to make the chain from human principal to autonomous agent readable by counterparties, regulators, and harmed third parties under adversarial conditions — time pressure, multi-layer agent orchestration, contested authorization scope. In this report, principal chain legibility is the specific function that distinguishes DelegatedExecution‘s Margins status (partial deployment, no stress-test record) from Center (legibility demonstrated under adversarial conditions at monetary governance scale).
Autonomous cascade: The condition in which independently rational agent responses to shared observable parameters produce collectively destabilizing outcomes — correlated liquidation, algorithmic collusion, simultaneous oracle consumption — that individual-transaction risk architecture was not designed to contain. In this report, autonomous cascade risk is the specific failure mode that SystemicExposure addresses and that no binding framework has yet formally named as a distinct systemic risk category.
ERC-8004 / KYA: ERC-8004 (Trustless Agents) is the Ethereum improvement proposal establishing on-chain registries for agent identity, reputation, and validation — registry contracts deployed on Ethereum mainnet since January 2026, EIP standard in Draft status. Know Your Agent (KYA) is the emerging framework for verifying autonomous agent identity and delegation scope — the agent-economy counterpart to Know Your Customer. In this report, ERC-8004 and KYA represent the candidate technical infrastructure for principal chain legibility whose standardization event has not yet occurred.
Legibility threshold: The migration condition a phenomenon must cross to change zone assignments. Outside → Margins: a binding regulatory framework formally addresses the accountability architecture for monetary governance. Margins → Center: the accountability architecture sets the terms of normal monetary governance operation. Growth within a zone is not migration.
Concave systemic risk position: The condition in which an architecture’s aggregate behavior is more predictable and more destabilizing than any individual component’s behavior — because agents optimize against shared observable parameters, producing convergent responses that concentrate systemic risk at precisely the moments when correlated action is highest. In this report, the agent economy’s concave systemic risk position is the structural contrast to DemocraticDelegation‘s convex legitimacy position from Governance Money and Legitimacy Money: where recognized constitutional authority generates stabilization value before intervention because its upper bound is incalculable, shared agent optimization parameters produce the opposite dynamic.
References are organized with Switzerland‑specific contextual sources first, followed by eight additional analytical lenses that demonstrate the evidential logic. The lens names correspond to the OctonarySet.
Switzerland’s regulatory landscape in digital identity and credential-based delegation architecture is the most technically advanced of the three jurisdictions in this specific domain and the most resistant to simple characterization. What is well-evidenced: the e-ID Act’s ZK-proof-based architecture, unlinkability design, and self-sovereign identity model — approved by Swiss voters on September 28, 2025, with launch targeted no earlier than summer 2026. What is analytically new in this report relative to Legitimacy Money: the platform dependency failure mode (Apple/Google wallet infrastructure) now activates the failure instance analytical function — Switzerland demonstrates what primary jurisdictions must avoid, not only what they might build toward. What remains contested: whether this architecture generates liability assignment, non-participant accountability, or systemic risk containment at monetary governance scale. This report maps US and EU in detail; Switzerland’s accountability architecture is treated as a subject requiring its own cartography elsewhere.
📝 Swiss Confederation — “Voters Approve Federal Act on Electronic Identification Services (e-ID Act)”, admin.ch (2025)
🔗 admin.ch — e-id-act-referendum-2025
🕯️ Confirms voter approval of the Swiss e-ID Act on September 28, 2025 — grounding Switzerland’s dual analytical function as proof-of-concept (ZK-proof delegation architecture is buildable at state scale) and failure instance (platform dependency on Apple/Google infrastructure establishes a lower bound on what primary jurisdictions must avoid when assembling DelegatedExecution architecture).
📝 Swiss Federal Office of Justice — e-ID Development Blog, Swiss Confederation (2025–2026)
🔗 eid.admin.ch — blog-e
🕯️ Official technical documentation of the Swiss e-ID’s ZK-proof implementation, unlinkability architecture, and deployment timeline — grounding the failure instance function by establishing that the selective disclosure and unlinkability properties required for principal chain legibility in DelegatedExecution are architecturally available, while the platform dependency failure reveals the structural condition primary jurisdictions must avoid.
📝 Deutsche Bank Research — Zero-Knowledge Proofs in Blockchain Finance: Opportunity vs. Reality, Deutsche Bank (2024)
🔗 corporates.db.com — zero-knowledge-proofs-blockchain-finance
🕯️ Industry analysis of ZK proof applications in financial services — cited as contextual framing for the Switzerland proof-of-concept and failure instance functions; not used as independent verification of Swiss government policy claims. Primary analytical claims on ZK proof architecture grounded in [SW1] and [SW2].
📝 Office of the Comptroller of the Currency — “Implementing the GENIUS Act for the Issuance of Stablecoins”, Federal Register Vol. 91 (2026)
🔗 federalregister.gov — occ-genius-act-implementing
🕯️ Primary regulatory instrument establishing custodial accountability requirements for payment stablecoin issuers — grounding the Mandatory Compliance finding that DelegatedExecution is being assembled within existing regulatory frameworks through human accountability mandates, while the absence of technical principal chain legibility requirements confirms the architecture’s Margins status.
📝 European Parliament and Council — “Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence” (EU AI Act), Official Journal of the European Union (2024)
🔗 eur-lex.europa.eu — eu-ai-act-regulation-2024-1689
🕯️ Primary binding legal instrument establishing GPAI supply chain documentation obligations for model providers — grounding the Mandatory Compliance finding that the EU’s delegation accountability architecture extends backward to the model layer, creating a compliance mandate whose scope stops short of the agent layer where principal chain legibility failures occur under stress.
📝 Competition and Markets Authority — “Complying with Consumer Law When Using AI Agents”, UK Government (2026)
🔗 gov.uk — complying-consumer-law-ai-agents
🕯️ Primary institutional guidance establishing that deploying businesses retain full consumer law obligations under autonomous agent operation with fines up to 10% of worldwide turnover — grounding the Mandatory Compliance finding that the UK’s accountability architecture places legal responsibility on the deploying institution without providing the operational framework specifying how liability is allocated when agent actions exceed delegated parameters or the delegation chain passes through multiple agent layers.
📝 United States District Court — Amazon.com Services LLC v. Perplexity AI, Inc., W.D. Wash. (2026)
🔗 jdsupra.com — ai-agents-act-inside-transaction-commerce-law
🕯️ First federal court ruling establishing that merchant-imposed “No Bot” access restrictions override user-delegated agent authorization under CFAA — grounding the Resolving Disputes finding that DelegatedExecution‘s authorization architecture has no recognized legal grounding when the delegation chain encounters merchant-controlled access rules, revealing the structural boundary where user consent cannot transfer legal authority to an autonomous agent.
📝 United States District Court — United States v. Heppner, Harvard Law Review Blog summary (2026)
🔗 harvardlawreview.org — united-states-v-heppner
🕯️ Court ruling establishing that communications with an AI platform lack attorney-client privilege because the AI is not a legal person — grounding the Resolving Disputes finding that LiabilityVacuum‘s structural condition is produced by the mismatch between legal architecture requiring human legal personhood and monetary execution performed by non-human agents.
📝 United States Court of Appeals for the Fifth Circuit — Van Loon v. Department of Treasury, No. 23-50669 (2024)
🔗 ca5.uscourts.gov — van-loon-tornado-cash-opinion
🕯️ Establishes that immutable smart contracts are not “property” under IEEPA — carried forward from Legitimacy Money to ground the Resolving Disputes finding that state authority can govern code authors but cannot reach autonomous execution through property-based mechanisms, establishing the outer boundary of DelegatedExecution‘s legal grounding and confirming LiabilityVacuum‘s Outside status.
(shared — appears under both DelegatedExecution and LiabilityVacuum)
📝 World Wide Web Consortium — “Decentralized Identifiers (DIDs) v1.1”, W3C Recommendation (2025)
🔗 w3.org — did-1.1-specification
🕯️ Primary technical standard establishing the DID specification for globally unique agent identifiers — grounding the Verifiable Proofs finding that principal chain legibility infrastructure exists at the standards layer for DelegatedExecution, while the absence of monetary governance stress-testing confirms the gap between standards availability and operational performance under adversarial conditions. (Shared with LiabilityVacuum; delegation legibility angle operative here.)
📝 De Rossi, M., Crapis, D., Ellis, J., Reppel, E. — “ERC-8004: Trustless Agents [DRAFT]”, Ethereum Improvement Proposals No. 8004 (2025)
🔗 eips.ethereum.org — eip-8004-trustless-agents
🕯️ Primary specification document for the Ethereum agent identity, reputation, and validation registry standard — grounding the Verifiable Proofs finding that principal chain legibility infrastructure is operationally deployed at the contract level (Identity and Reputation registries live on mainnet since January 2026) while the EIP standard remains in Draft, establishing the precise gap between technical deployment and standards finalization that keeps DelegatedExecution at Margins. (Shared with LiabilityVacuum; scope-of-authorization gap angle operative there.)
📝 European Parliament and Council — “Regulation (EU) 2024/1183 Amending Regulation (EU) No 910/2014” (eIDAS 2.0), Official Journal of the European Union (2024)
🔗 eur-lex.europa.eu — eidas-2-regulation-2024-1183
🕯️ Primary binding legal instrument establishing the European Digital Identity Wallet framework — carried forward from Legitimacy Money to ground the Verifiable Proofs finding that credential infrastructure for DelegatedExecution is being assembled at regulatory scale, while the gap between data consent architecture and monetary governance authorization architecture confirms that eIDAS 2.0’s deployment does not by itself resolve principal chain legibility under stress. (Shared with LiabilityVacuum; regulatory-scale deployment angle operative here.)
📝 Bank for International Settlements — “Basel Committee Discusses Recent Market Developments and Targeted Review of Cryptoasset Standard”, BIS Press Release (2026)
🔗 bis.org — basel-targeted-crypto-review
🕯️ Documents the Basel Committee’s February 2026 targeted review of SCO60 — grounding the Predatory Delay finding that legacy standard-setting institutions are operating on a timeline that preserves incumbent compliance architecture’s competitive value by preventing KYA frameworks from being subjected to the standardization event that would accelerate DelegatedExecution‘s migration toward Center.
📝 Baker Donelson — “2026 AI Legal Forecast: From Innovation to Compliance”, Baker Donelson (2026)
🔗 bakerdonelson.com — 2026-ai-legal-forecast
🕯️ Institutional legal forecast identifying the indemnification gap in vendor contracts for autonomous agent errors — grounding the Predatory Delay finding that the absence of binding liability standards forces deploying institutions toward contractual workarounds that preserve existing legal architecture rather than assembling the operational framework LiabilityVacuum requires.
📝 Gao, Y. et al. — “The Agent Economy: A Blockchain-Based Foundation for Autonomous Commerce”, arXiv:2602.14219 (2026)
🔗 arxiv.org — agent-economy-blockchain-foundation
🕯️ Technical analysis of blockchain infrastructure for autonomous agent commerce including x402 payment protocol and smart contract escrow — grounding the Programmable Protocols finding that LiabilityVacuum‘s structural condition is produced by the mismatch between settlement finality (cryptographically complete before human review) and liability architecture (requiring a legally cognizable human decision point).
📝 Anonymous — “Virtual Agent Economies”, arXiv:2509.10147 (2025) 🔗 arxiv.org — virtual-agent-economies
🕯️ Models the economic architecture of autonomous agent systems including sandboxed agent economies and permeability conditions — grounding the Programmable Protocols finding that the transition from sandboxed agent execution to human-economy permeability is the structural threshold at which LiabilityVacuum‘s Outside status becomes a systemic rather than individual concern.
📝 Bavarian Data Protection Authority / European Data Protection Board — “Decision on the Processing of Biometric Data by Tools for Humanity / Worldcoin”, EDPB (2025)
🔗 edpb.europa.eu — decision-tools-for-humanity-worldcoin
🕯️ Regulatory enforcement document establishing that biometric consent architecture revealed its accountability gap under stress — carried forward from Legitimacy Money to ground the Clear Accountability finding that LiabilityVacuum‘s structural condition is not unique to monetary contexts: wherever credential infrastructure meets the requirement for ongoing accountable consent, the gap between proof-of-execution and proof-of-authorization-scope appears as an enforcement problem rather than a technical one.
📝 Fime — “Agentic AI and Payments: When AI Gets a Wallet and a Will of Its Own”, Fime (2026)
🔗 fime.com — agentic-ai-payments-wallet
🕯️ Industry analysis of the liability architecture gap for autonomous agent payment decisions — grounding the Clear Accountability finding that the “responsibility vacuum” in agent commerce is recognized across institutional, legal, and technical domains as a structural condition rather than an implementation gap, and that no primary jurisdiction has yet produced the binding framework that would move LiabilityVacuum from Outside to Margins.
📝 Anwar, A. et al. — “A Comparative Study of Brief, Claim, Proof, Stake, Reputation and Constraint Trust Models”, arXiv:2511.03434 (2025)
🔗 arxiv.org — comparative-trust-models-agents
🕯️ Technical analysis of six trust model architectures for autonomous agent systems — grounding the Distributed Systems finding that SystemicExposure‘s cascade vulnerability arises from the distributed architecture’s reliance on trust models that address individual transaction integrity without providing aggregate behavior containment: each trust mechanism addresses bilateral agent-to-agent verification while leaving correlated multi-agent response patterns unaddressed.
📝 Google Cloud — “Announcing Agent Payments Protocol (AP2)”, Google Cloud Blog (2026)
🔗 cloud.google.com — announcing-agents-payments-ap2
🕯️ Primary technical announcement of Google’s Agent Payments Protocol — grounding the Distributed Systems finding that major platform actors are assembling agent payment infrastructure at scale without a systemic risk containment architecture, establishing the operational context in which SystemicExposure‘s Outside status persists: the distributed payment layer is being built faster than the regulatory framework that would address its aggregate behavior under stress.
📝 Acemoglu, D. et al. — “An Economy of AI Agents”, NBER Working Paper 33390 (2025)
🔗 nber.org — economy-of-ai-agents-c15305
🕯️ Establishes theoretical conditions under which AI agent economies produce collusion and welfare-reducing equilibria — grounding the Risk Convexity finding that SystemicExposure‘s concave systemic risk position is theoretically grounded: a population of agents optimizing against shared observable parameters produces convergent responses whose aggregate effect is more predictable and more destabilizing than any individual agent’s behavior.
📝 Draghi, M. — “Speech at the Global Investment Conference”, European Central Bank (2012)
🔗 ecb.europa.eu — draghi-whatever-it-takes-2012
🕯️ Primary source for the convex legitimacy position — carried forward from Legitimacy Money as the structural contrast that makes SystemicExposure‘s concave risk position analytically legible: where recognized constitutional authority generates stabilization value before intervention because its upper bound is incalculable, the agent economy’s observable optimization parameters produce the opposite dynamic, concentrating systemic risk at precisely the moments when correlated agent responses are highest. (Cited for mechanism, not current state claims.)
📝 Glassnode Insights — “What Really Happened to MakerDAO?”, Glassnode (2020)
🔗 insights.glassnode.com — makerdao-black-thursday
🕯️ Quantitative documentation of the Black Thursday cascade — carried forward from Legitimacy Money to ground the Risk Convexity finding that SystemicExposure‘s concave systemic risk position has an empirical precedent: when network congestion closed the exit door simultaneously for all participants, correlated agent behavior produced a cascade that individual-transaction risk architecture was not designed to contain, establishing the failure mode that a systemic containment architecture for autonomous agents must address. Self-Reported— figures independently verifiable on-chain.
Note on shared references: [7] W3C DID Specification, [8] ERC-8004 EIP, and [9] eIDAS 2.0 each appear under both Verifiable Proofs sections (DelegatedExecution and LiabilityVacuum). In each case a single source grounds two distinct analytical claims. Reference numbers are stable throughout; the lens heading and 🕯️ annotation identifies which aspect of the source is operative in each section.
Note on carried references: [6] Van Loon, [9] eIDAS 2.0, [14] EDPB/BayLDA Worldcoin, [19] Draghi, and [20] Glassnode Black Thursday are carried forward from Legitimacy Money with updated 🕯️ annotations reflecting their operative angle in this report.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.