No man can be judge in his own cause.
— John Locke, Second Treatise of Government
By what authority does any governance mechanism claim the right to make binding decisions about monetary rules for populations that did not consent to those rules?
Series note: This report inherits the Reconfiguration finding and Handoff question from Governance Money (March 2026). Readers new to the series will find the analysis self-contained.
Monetary systems already govern people who never explicitly agreed to them. What has changed is not that fact — but the emergence of new architectures that claim to replace, replicate, or bypass that legitimacy.
This report asks a precise question:
What actually makes monetary governance legitimate when participation is not optional?
In 2026, the question Governance Money handed forward has arrived in the regulatory architecture of three jurisdictions simultaneously — and none of them has answered it.
United States: The GENIUS Act framework created federal licensing for payment stablecoins without resolving who bears the costs when a major issuer fails on a weekend and the populations whose savings are at risk never consented to the governance architecture whose failure affects them. The Senate’s temporary prohibition on Federal Reserve retail CBDC issuance extends through 2030, delegating digital monetary infrastructure to the private sector while declining to extend the public accountability architecture that gives monetary infrastructure its legitimacy function.
European Union: The digital euro pilot advanced toward 2027 operational deployment alongside the rollout of eIDAS 2.0 — the first binding regulatory framework to assemble verifiable credentials, ZK-based selective disclosure, and state-issued digital identity into a single architecture. eIDAS 2.0 is operational infrastructure for consent. Whether it is operational infrastructure for monetary governance consent remains the open analytical question.
Switzerland: The Federal Electronic Identification Services Act, approved by Swiss voters on September 28, 2025, and moving toward launch no earlier than summer 2026, implements a ZK-proof-based e-ID on a self-sovereign identity model — the furthest any jurisdiction has gone in operationalizing the specific technical architecture that AttestationCredentials requires. Switzerland has demonstrated that the architecture can be built. It has not demonstrated that the architecture generates monetary governance legitimacy.
Meanwhile, three consent architectures are competing to perform a function that monetary governance requires and that none of them fully performs: the recognized right to make binding decisions about monetary rules for populations whose participation in the governed system is compelled rather than chosen. The competition is not between old and new. It is not between democratic and decentralized. It is a competition over the specific boundary where every consent architecture stops — and that boundary is precisely where monetary governance crises begin.
DemocraticDelegation is the consent architecture by which central banks and financial regulators derive recognized authority to make binding monetary governance decisions from statutory mandates, constitutional frameworks, and democratic accountability structures. The Federal Reserve Act, the ECB Treaty, and the Bank of England Act are its three primary instantiations in the period this report covers. This architecture holds Center not because it performs the legitimacy function optimally — it is slow, jurisdictionally bounded, and subject to constitutional challenge — but because it is the only consent architecture that currently addresses all four functional requirements of monetary governance legitimacy, however imperfectly. It reaches the broadest affected population through statutory universal jurisdiction. It generates binding authority through constitutional grounding. It provides contestability through courts and legislative revision — the Weiss judgment being the system’s most precise recent stress test. Its weakest element is compelled participation handling: affected populations can challenge governance decisions, but the challenge architecture is costly, slow, and stops at jurisdictional borders.
ProtocolConsent is the consent architecture encoded in the governance mechanisms of decentralized financial protocols — DAO voting, smart contract execution, token-weighted governance, and the participation-as-consent claim that grounds them. The proposition is genuinely philosophical: that interacting with a protocol constitutes consent to its governance rules, and that the ability to exit preserves autonomy without requiring democratic delegation. This architecture is at the Margins because the claim is real and operationally demonstrated among protocol participants — but has been stress-tested at the non-participant boundary and found structurally incomplete. Black Thursday revealed that the populations whose monetary conditions were shaped by MakerDAO’s governance failure were not identical to the populations who had consented to MakerDAO’s governance. Exit rights preserved autonomy for participants. They provided nothing for the populations affected by a governance failure they never chose to join.
AttestationCredentials is the consent architecture emerging from verifiable credentials, ZK proofs of personhood, decentralized identifiers, and digital identity frameworks — the technical infrastructure that can prove participation, personhood, or affected status without revealing underlying identity. eIDAS 2.0’s European Digital Identity Wallet, Switzerland’s ZK-proof-based e-ID, and Worldcoin’s iris-scan proof of personhood are its three primary instantiations in the period this report covers. This architecture is at the Outside not because it is small — ZK proofs, verifiable credentials, and DIDs are operational at significant scale in financial services — but because the monetary governance legitimacy claim has not yet been assembled. The technology can prove “this person exists.” It has not demonstrated “this person is affected by this monetary governance decision and has consented to be bound by it.” The gap between those two claims is the analytical object of this phenomenon.
A note on functional layers: These three phenomena are functional layers of a single consent problem, not mutually exclusive governance categories. The same institution — a major commercial bank — participates across all three simultaneously: as a regulated entity subject to DemocraticDelegation‘s statutory mandate, as a participant in GENIUS Act stablecoin infrastructure governed by ProtocolConsent mechanisms, and as an implementing actor for eIDAS 2.0 wallet acceptance under AttestationCredentials. Zone assignments track the consent architecture being analyzed, not the institution performing it.
Before the zone map opens, the functions that monetary governance legitimacy requires need to be separated. The three phenomena in this analysis do not differ merely in their technical properties. They differ in which legitimacy functions they can perform — and those functions arise from different infrastructure layers, fail at different moments under stress, and cannot be assembled by substituting one for another.
Treating them as a single mechanism produces a specific, identifiable error: AttestationCredentials appears to solve the legitimacy problem because it can prove participation and identity, when the governance function requires reaching non-participants — populations whose participation in the governed system is compelled, not chosen.
Population reach arises from the enrollment and identification architecture — who the consent mechanism can see and extend its authority to. DemocraticDelegation reaches the full jurisdictional population through statutory mandate: the Federal Reserve’s authority over US dollar monetary conditions applies to everyone operating within that monetary system, not only to those who have enrolled or chosen to participate. ProtocolConsent reaches its participant population — those who have interacted with the protocol and can be said, in some meaningful sense, to have consented to its governance rules. AttestationCredentials reaches those who have enrolled: the eIDAS 2.0 wallet holder, the Worldcoin iris-scan registrant, the Swiss e-ID applicant. The functional requirement is structural: monetary governance decisions shape the monetary conditions of everyone in the system, not only participants. The population reach function fails when the enrollment architecture stops short of the affected population.
Binding authority arises from the legal and constitutional architecture — the recognized right to impose costs. DemocraticDelegation generates this through constitutional mandate and statutory law: the ECB’s bond purchases impose costs on member state budgets, and those costs are recognized as legitimate even when contested, because the authority to impose them is constitutionally grounded. ProtocolConsent generates a different kind of authority through smart contract execution: when MakerDAO’s liquidation mechanism ran, it imposed costs on CDP owners whose collateral was sold at zero. But immutable execution can impose costs. It does not create a recognized right to impose those costs on non-participants. The Fifth Circuit established this precisely: immutable code executes without being the kind of property that can bear legal obligations toward those it affects. AttestationCredentials does not yet generate binding authority at any monetary governance scale.
Contestability arises from the dispute resolution and revision architecture — the ability of affected parties to challenge governance decisions through a recognized process without being required to exit the monetary system entirely. DemocraticDelegation provides this through courts, constitutional review, and legislative revision. The Weiss judgment is the system’s most precise stress test: the German Federal Constitutional Court challenged the ECB’s bond purchase program, required proportionality documentation, and ultimately accepted a negotiated institutional resolution — without extinguishing the ECB’s authority to act. The contestability was real, costly, and functional. ProtocolConsent provides exit rights — the ability to leave the protocol — but not contestability: the ability to challenge a governance decision from within while remaining subject to the monetary conditions it shapes. AttestationCredentials has no contestability architecture at monetary governance scale. eIDAS 2.0 provides data subject rights (erasure, correction, portability) — contestability over the credential record, not over the governance decisions the credential infrastructure might eventually be used to authorize.
Compelled participation handling arises from the non-participant accountability architecture — the structural answer a consent mechanism provides for populations who did not choose to participate in the governed system but whose monetary conditions are shaped by its governance decisions. This is the function Governance Money identified as the decisive failure point of autonomous protocol governance, and it is the function that requires examination at the level of the consent architecture itself.
DemocraticDelegation handles this through universal jurisdictional reach. The populations subject to ECB monetary policy decisions did not individually consent to those decisions, but the constitutional mandate extends to them and provides a contestability mechanism — however imperfect and slow — through which the costs imposed on non-consenting populations can be challenged. ProtocolConsent has no structural answer here. The populations affected by Black Thursday’s liquidation cascade — DAI holders who never participated in MakerDAO governance, users of downstream applications built on DAI’s stability — had no participation mechanism, no contestability mechanism, and no accountability mechanism within the protocol’s architecture. The exit door had already closed: network congestion meant that exiting was structurally unavailable at the moment costs were imposed. AttestationCredentials carries a candidate answer: ZK proof of affected-status could theoretically extend consent infrastructure to non-participants by proving “this person’s monetary conditions are affected by this governance decision” without requiring enrollment in the governed system. No governance mechanism has yet assembled this claim.
These four functions survive the commensurability test as structurally distinct. Population reach and compelled participation handling both involve the non-participant boundary, but they arise from different infrastructure layers: enrollment architecture (who the system can see) and accountability architecture (what the system does when it harms those it cannot see). A universal-suffrage system can reach everyone while providing no tort remedy for monetary harm. The Consent Stack reveals a consistent structural pattern: every consent architecture that monetary governance has produced reaches participants and stops at the boundary of compelled participation. And the boundary where consent stops is precisely where monetary governance crises begin.
Center is where DemocraticDelegation operates — the only consent architecture currently performing all four legitimacy functions, however imperfectly. Its population reach is universal within jurisdiction. Its binding authority is constitutionally grounded. Its contestability is structurally present. Its compelled participation handling is the weakest element but is present: the Weiss judgment demonstrated that constitutional challenge of monetary governance decisions is available to affected populations, even when costly and slow.
For legal readers: Think of it as the constitutional order that operates above the ordinary rules and whose authority is tested precisely when those rules are challenged. The legitimacy function is what makes the constitutional moment work before it is invoked — not because the authority is popular or efficient, but because it is recognized.
For technical readers: It is the permission layer that no other system has successfully replicated at monetary governance scale — the architecture that generates recognized right to impose costs, not merely the technical capacity to execute them.
Margins is where ProtocolConsent operates — binding authority and population reach partially assembled for participants, contestability absent, compelled participation handling structurally missing. The GENIUS Act framework, MiCA’s DAO provisions, and the Sky Protocol’s Endgame architecture are real; their governance frameworks are operational; the consent claim they advance is genuine among participants. But none of them has demonstrated compelled participation handling under stress, and Black Thursday demonstrated the structural absence of contestability for non-participants.
For legal readers: Think of it as an enforceable contract that binds signatories but has no answer for the populations affected by its performance who never signed it.
For technical readers: The execution layer is production-ready. The non-participant governance layer has not passed its adversarial test.
Outside is where AttestationCredentials operates — candidate technology for all four functions assembled in data governance contexts, monetary governance application undemonstrated. eIDAS 2.0 is binding EU law. Switzerland’s e-ID is moving toward operational deployment. Worldcoin’s proof of personhood is live at scale. The consent architecture components exist. The monetary governance legitimacy claim has not been assembled from them.
For legal readers: Think of it as the legal infrastructure for a new kind of standing — the technical capacity to prove affected status — that no court has yet recognized as a basis for monetary governance consent.
For technical readers: The cryptographic primitives are production-ready. The governance application layer has not been written.
The FindingType is Undetermined — and the finding is precise about why. The three consent architectures are performing different subsets of the four legitimacy functions. Whether their disaggregation across institutional layers is structurally coherent or self-defeating depends on a determination this cartography cannot yet make: whether AttestationCredentials can be assembled into a monetary governance consent mechanism that reaches non-participants, generates binding authority, and enables contestability — or whether the four functions are structurally inseparable and must co-reside in a single institutional architecture. Four analytical threads:
How DemocraticDelegation‘s imperfect performance of all four functions constitutes the zone map’s reference point — and where its compelled participation handling fails at jurisdictional boundaries
How ProtocolConsent‘s genuine consent claim among participants collapses at the non-participant boundary — and what Black Thursday and the Tornado Cash boundary reveal about the structural location of that collapse
How AttestationCredentials‘ technical infrastructure is operational for data consent but unassembled for monetary governance consent — and what Worldcoin’s stress test and eIDAS 2.0’s rollout reveal about the distance remaining
How legacy regulatory standard-setting delays the empirical test that would determine whether consent architecture disaggregation is coherent or self-defeating
What You’re Looking At: The consent architecture of democratic delegation — how statutory mandates, constitutional frameworks, and democratic accountability structures generate the four legitimacy functions in monetary governance, where each function is strongest, and where each fails under stress.
For legal readers: Think of DemocraticDelegation as the constitution of money — the architecture that makes monetary governance decisions binding not because they are technically executed but because the authority to impose them is recognized, contestable, and traceable to a democratic mandate, however attenuated.
For technical readers: It is the permission system whose authorization tokens are not cryptographic but constitutional — recognized right to act generates stabilization value before intervention is invoked, precisely because market actors cannot calculate when or at what scale authorization will be exercised.
DemocraticDelegation holds Center not because it is efficient or democratically popular in its operational decisions — it is often neither — but because it reaches furthest toward the compelled participation boundary of any consent architecture currently operating at monetary governance scale. When the ECB purchased sovereign bonds under the PSPP program, it imposed fiscal costs on German taxpayers who had not consented to those specific purchases. The mechanism that made those costs legitimate — not popular, not uncontested, but recognized as within the bounds of authorized action — was the treaty architecture grounding the ECB’s mandate, subject to proportionality review by a body whose authority the German taxpayers had consented to through constitutional processes they had participated in. This is the compelled participation handling function operating: slow, imperfect, contested — but structurally present.
The statutory binding authority infrastructure is the Federal Reserve Act’s Section 13(3), the ECB Treaty’s Article 127, and the Bank of England Act 1998 — three constitutional architectures that generate binding authority through democratic delegation rather than technical execution. Their design histories are revealing: Section 13(3) was created in 1932 to extend emergency lending beyond what its drafters anticipated, and has been revised twice since — after 2008 to require broad-based facilities and Treasury approval, after 2020 to accommodate the hybrid monetary-fiscal architecture that the COVID-19 response required. The binding authority function adapts through legislative revision. This is the contestability architecture operating at the statutory layer. What it cannot do is extend its reach beyond its jurisdictional boundary: Federal Reserve authority generates binding authority for US dollar monetary conditions; it generates no binding authority for the populations in dollarized economies who bear those monetary conditions without citizenship-based contestability mechanisms.
The convex legitimacy position that DemocraticDelegation holds is the structural advantage Governance Moneyidentified at the credibility layer, now visible at the legitimacy layer. When a central bank with recognized constitutional authority announces it will act to stabilize monetary conditions, the announcement itself generates stabilization value — because market actors cannot calculate the upper bound of authorized action, and because the authority is recognized as extending to populations who did not individually consent to it. This convexity is not available to ProtocolConsent: token-weighted governance produces decisions whose scope is knowable, whose reserve pool is observable, and whose reach stops at the participant population. The concave position is structural — it is bounded by the enrollment architecture, which is exactly the boundary where monetary crises impose their costs.
The Weiss judgment defines the contestability architecture’s operational boundary with precision. The German Federal Constitutional Court’s 2020 ruling that the ECB’s PSPP had not been subjected to adequate proportionality review — the first time the court had activated ultra vires review of an ECB monetary policy instrument — demonstrated that the contestability function is real and exercisable, but requires institutional negotiation rather than automatic resolution. The ECB documented its proportionality assessment. The Bundestag received the documentation. The constitutional conflict was resolved without rupturing the ECB’s authority to act. Contestability imposed costs on the institution — documentation, negotiation, delay — without extinguishing the authority. This is the stress test record: legitimacy authority can be contested; it requires negotiated resolution, not displacement.
Selected sources informing this section:
Mandatory Compliance
[1] Sastry — Section 13(3) political origins
[2] Murau & van ‘t Klooster — monetary sovereignty as governance capacity
[3] Awrey — compelled participation in non-bank monetary infrastructure
Resolving Disputes
[4] Anagnostaras — Weiss contestability architecture
[5] Fifth Circuit — Van Loon, outer boundary of state reach
Participatory Representation
[6] Gorton & Zhang — non-participant exposure as population reach failure
[7] European Parliament — cryptomercantilism and non-participant monetary governance
Risk Convexity
[8] Draghi — legitimacy premium mechanism
[9] Glassnode — Black Thursday, concave contrast case
What You’re Looking At: The consent architecture of protocol governance — the genuine philosophical claim that participation constitutes consent and exit preserves autonomy, what that claim performs for participants, and where it stops at the non-participant boundary.
For legal readers: Think of ProtocolConsent as an enforceable private legal order — binding on signatories through the mechanism of code execution, with no answer for the affected populations who never signed. The Black Thursday litigation is the stress test: CDP owners who argued the zero-bid auction was not part of the original contract were making a contestability claim that the protocol’s architecture could not process.
For technical readers: The execution layer is production-grade. What is missing is not a more reliable execution layer — immutable execution is the design. What is missing is a governance layer that extends beyond the participant population to the populations whose monetary conditions are shaped by the protocol’s decisions.
The legitimacy claim of ProtocolConsent is philosophically coherent among participants and deserves full analytical treatment rather than dismissal. The proposition — that interacting with a protocol constitutes meaningful consent to its governance rules, that the rules are transparent and auditable in a way that democratic mandates are not, and that exit rights preserve autonomy without requiring the coercive apparatus of the state — is a genuine innovation in political philosophy applied to monetary governance. Among participants, it works. The question is not whether the claim is coherent among participants. The question is whether it survives the compelled participation condition that monetary governance requires.
Black Thursday answers that question directly. On March 12, 2020, as Ether’s price fell 43% in a single day, the MakerDAO liquidation system encountered a failure mode whose governance implications reveal the structural boundary of this architecture. Ethereum network congestion caused liquidation bot transactions to stall. A single actor submitted zero-bid liquidations, collecting $8.32 million in ETH for free, leaving the protocol with $5.67 million in bad debt. The populations who bore the costs divided into two groups: MKR token holders, who had participated in MakerDAO’s governance and voted to mint new MKR to cover the bad debt — a response that worked within the consent architecture. And DAI users, downstream application users, and populations whose stablecoin savings were at risk — who had not consented to the governance rules, and had no mechanism to contest the costs imposed on them. The exit door had already closed: network congestion made exiting structurally unavailable at the moment costs were imposed.
The evolution of MakerDAO into the Sky Protocol’s Endgame architecture is instructive here. The architectural response to Black Thursday was not to extend the protocol’s reach to non-participants. It was to add discretionary human capacity — SubDAOs with local crisis authority, human teams with defined intervention roles — within the autonomous governance vocabulary. The code governs normal conditions. The crisis requires judgment. The judgment reaches participants. This evolution does not address the non-participant boundary; it acknowledges it as a condition the architecture cannot resolve from within.
The Tornado Cash Fifth Circuit ruling defines ProtocolConsent‘s structural boundary with legal precision. When the court held that immutable smart contracts are not “property” under IEEPA — because once deployed, the contracts were controlled by no one — it established the exact location where the consent claim reaches its limit: immutable code generates binding execution without generating the legal personhood that would make binding execution into binding authority in the sense monetary governance requires. The code executes. It does not bear obligations toward those it affects who never consented to its governance. Treasury lifted the civil sanctions on the contracts. Roman Storm faces criminal proceedings, with retrial scheduled for October 2026. The boundary is precise: state authority cannot govern autonomous code through property-based mechanisms; it can and does govern the humans who build it.
The regulatory recognition gap maintained by Basel SCO60 and the US CBDC prohibition operates as Predatory Delay at the legitimacy layer. By requiring daily disclosure, documented stabilization mechanisms, and HQLA-equivalent verification for regulatory recognition — standards whose revision the US has resisted and the Basel Committee is reviewing — legacy actors control the rate at which ProtocolConsent could be subjected to the empirical test that would determine whether its legitimacy claim is coherent or self-defeating at non-participant scale. The delay preserves DemocraticDelegation‘s hold on the legitimacy function by preventing the alternative from being tested at governance scale where the non-participant boundary would become visible.
Selected sources informing this section:
Exit Rights
[9] Glassnode — Black Thursday, exit failure under network stress (shared with The Mandate)
[10] Hirschman — Exit, Voice, and Loyalty, foundational framework
[11] Ferreira — DeFi: the ultimate regulatory frontier, accountability reconcentration
Programmable Protocols
[12] OCC Federal Register — GENIUS Act implementing rule
[13] ECB — digital euro pilot, programmability constraints as consent theory
[3] Awrey — compelled participation (shared with The Mandate)
Predatory Delay
[14] BIS — Basel targeted cryptoasset review
[15] Senator Husted — CBDC prohibition press release
What You’re Looking At: The consent architecture emerging from verifiable credentials, ZK proofs of personhood, and digital identity frameworks — the technical infrastructure for a consent architecture that could theoretically reach non-participants, and what the gap between technical capacity and monetary governance application reveals about the distance remaining.
For legal readers: Think of AttestationCredentials as the emerging law of standing for the digital monetary system — the infrastructure that could prove “this person is affected by this governance decision” as a basis for consent or contestability, without requiring enrollment in the governed system. No court has yet recognized this standing. No monetary governance mechanism has yet assembled this claim.
For technical readers: The cryptographic primitives are production-ready: ZK-SNARKs, selective disclosure, DID resolution, verifiable credential issuance and verification. The governance application layer — the layer that would translate “this credential proves this person’s affected status” into a recognized monetary governance consent mechanism — has not been written.
AttestationCredentials is at the Outside not because it is technically immature — it is the most technically sophisticated consent architecture in this analysis — but because the leap from “consent to share a credential” to “consent to be governed by a monetary mechanism” has not been assembled, demonstrated, or recognized. eIDAS 2.0 is the institutional confirmation that the infrastructure layer is ready. Member state wallet deployment is required approximately by November 2026, with banks and payment service providers required to accept EUDI Wallets from December 2027. The infrastructure is not a 2030 roadmap item. The population reach function — the ability to enroll and identify a broad population through verifiable credentials — is being built at binding regulatory scale. What eIDAS 2.0 does not yet address is how that enrollment infrastructure generates binding authority for monetary governance decisions, enables contestability of those decisions, or handles the populations whose monetary conditions are shaped by systems they have not enrolled in.
Switzerland’s Federal Electronic Identification Services Act, approved by voters on September 28, 2025, and moving toward launch no earlier than summer 2026, provides the most analytically precise instantiation of the novel claim that this architecture advances. The Swiss e-ID implements ZK-proof-based selective disclosure on a self-sovereign identity model — the government provides trust infrastructure, the user manages their data, and zero-knowledge proofs enable “I am over 18” to be proven without revealing a birthdate, or “I have consented to this transaction” to be recorded without creating a linkable profile across transactions. The unlinkability property is analytically significant: it is precisely what would be required for non-participant proof of affected status to avoid creating surveillance infrastructure as a precondition for monetary governance consent. The Swiss implementation has faced criticism regarding platform dependency (Apple and Google wallet infrastructure) and the “voluntary-in-theory, mandatory-in-practice” dynamic in financial services. Neither concern eliminates the architecture’s status as a candidate. Both reveal the distance between the technology being available and the consent architecture being assembled.
Worldcoin’s iris-scan proof of personhood is the stress test at the biometric consent layer. The Bavarian Data Protection Authority’s 2025 order against the Worldcoin Foundation revealed a specific structural failure: once biometric data is converted into code at scale, the right to erasure was found difficult to operationalize at the precision GDPR requires. Worldcoin subsequently deleted its iris code database and migrated to a new SMPC architecture — but the structural finding stands. The consent architecture built was technically sophisticated and legally deficient at the specific point where the enrolled population’s right to withdraw consent was tested. The gap between “I consented to the scan” and “I consent to be governed by the monetary mechanism whose decisions affect my monetary conditions” is not a technical implementation gap. It is a structural feature of the difference between data consent and governance consent.
Selected sources informing this section:
Verifiable Proofs
[16] European Commission — eIDAS 2.0 regulation
[17] EDPB/BayLDA — Worldcoin / Tools for Humanity erasure order [18] Ohlhaver, Weyl & Buterin — Decentralized Society: soulbound tokens as consent infrastructure [Evidence-Thin]
Informed Consent
[19] Swiss Federal Chancellery — Federal Electronic Identification Services Act
[20] Zetzsche, Arner & Buckley — DeFi reconcentration and embedded regulation
Switzerland functions in this report as a proof-of-concept — its ZK-proof-based e-ID demonstrates that the Population Reach and Binding Authority functions can be assembled from credential infrastructure at state scale, before any monetary governance application. What Switzerland cannot yet demonstrate is whether that architecture generates contestability or handles compelled participation at monetary governance scale. A full cartography of Switzerland’s consent architecture requires its own treatment elsewhere.
Switzerland’s Federal Electronic Identification Services Act represents the furthest operationalization of the AttestationCredentials approach that any jurisdiction has yet achieved. The ZK-proof architecture — unlinkability, selective disclosure, self-sovereign control — is the candidate technical foundation for a non-participant consent architecture: a mechanism that could prove “this person is affected by this monetary governance decision” without creating a surveillance profile of the affected population as a precondition for recognizing their affected status.
The analytic function Switzerland provides is narrow but precise: it demonstrates that the technical architecture is not an obstacle. The governance application layer — extending ZK-based credential infrastructure from data consent to monetary governance consent — remains the core analytical focus. Switzerland has built toward the former. No jurisdiction has yet attempted the latter.
Switzerland’s regulatory landscape in this domain is the most technically advanced and the most resistant to unified characterization: what is well-evidenced is the ZK-proof architecture and the self-sovereign identity model approved by voters in September 2025; what remains contested is whether this infrastructure generates the binding authority and contestability functions that monetary governance legitimacy requires. This report maps US and EU in detail; Switzerland’s consent architecture is treated as a subject requiring its own cartography elsewhere.
Legitimacy Money is not a competition between democratic and decentralized consent architectures waiting for a technical winner — it is the cartography of how every consent architecture that monetary governance has produced reaches participants and stops at the boundary of compelled participation. This cartography reveals an Undetermined finding: DemocraticDelegation holds Center not by performing all four functions optimally, but by performing them simultaneously. At the compelled participation layer, every alternative consent architecture has found the same structural boundary.
Whether that boundary can be moved — or whether it is a permanent structural condition of monetary governance under stress — is the open question this cartography cannot close.
The institutions are the constant across all three phenomena. A major commercial bank is simultaneously subject to DemocraticDelegation‘s statutory mandate, participating in GENIUS Act stablecoin infrastructure governed by ProtocolConsent mechanisms, and preparing for eIDAS 2.0 wallet acceptance under AttestationCredentials. The ECB is simultaneously the constitutional actor whose proportionality obligations define the contestability architecture, the designer of the digital euro’s programmability constraints that encode a theory of ProtocolConsent‘s limits, and the institutional participant in BIS frameworks exploring whether AttestationCredentials could eventually supply what programmable design cannot. The consent problem is constant. What varies is which functional layer each architecture can address — and none has yet assembled all four functions at the compelled participation boundary where monetary governance stress is highest.
The 2026 regulatory decisions will shape which migrations become structurally possible within the US and EU jurisdictions this report maps in detail. If eIDAS 2.0’s full operational rollout assembles a population reach infrastructure that extends to affected non-participants — and if a regulatory framework recognizes that infrastructure as a basis for monetary governance consent — AttestationCredentials crosses the Outside → Margins threshold. If the GENIUS Act framework’s LOLR gap is addressed through a mechanism that extends DemocraticDelegation‘s compelled participation handling to PPSI holders, ProtocolConsent moves closer to demonstrating a hybrid consent architecture that borrows institutional legitimacy without displacing protocol autonomy. If neither moves, the “Saturday Night Trap” scenario — a weekend failure event where no institutional backstop is available — a run on a major stablecoin issuer whose affected populations have no consent architecture and no contestability mechanism — remains the pending stress test for the finding this cartography cannot resolve.
This cartography maps what exists, not what should exist. DemocraticDelegation creates affordances for recognized legitimacy and for the concentration of authority in institutions whose democratic accountability is indirect and jurisdictionally bounded. ProtocolConsent creates affordances for participant autonomy, auditability, and the genuine philosophical innovation of code-as-consent — and for the structural absence of accountability at the non-participant boundary that monetary crises expose. AttestationCredentials creates affordances for a new kind of standing — proof of affected status without surveillance — that no monetary governance mechanism has yet assembled into a legitimacy claim. The evidence permits multiple interpretations. The 2026 decisions are approaching.
Who consents when the governed monetary actor cannot consent at all?
This cartography confirms that the Undetermined finding holds at the compelled participation boundary:
Every consent architecture stops at precisely the location where monetary governance crises impose their costs on non-participants.
The three phenomena collectively demonstrate that population reach, binding authority, contestability, and compelled participation handling arise from distinct infrastructure layers, fail separately under stress, and have not yet been assembled into a single non-DemocraticDelegation architecture at monetary governance scale. The successor analysis must determine what consent architecture is structurally possible when the governed monetary actor is a non-human agent — an AI system, an automated treasury, a DAO-operated fund — that cannot consent in any meaningful sense, and whose governance decisions impose costs on human populations who did not participate in designing the agent that governs them.
By what architecture does any governance mechanism claim recognized authority over the monetary decisions of agents that cannot consent to being governed?
That question — about the consent architecture of non-human monetary agents — is the open problem this cartography hands forward. What follows documents how the current map was built.
This report belongs to the genre of structural pattern recognition across institutional, legal, and technical domains. Evidence consists of primary legal instruments, regulatory publications, court decisions, and peer-reviewed academic work illuminating distinct layers of the consent architecture problem. Zone-state cartography is the diagnostic method: mapping how monetary governance legitimacy migrates between consent architectures by tracking which legitimacy functions each form can and cannot perform.
The framework evaluates observable structural signals to assess zone assignments and migration conditions. It does not infer institutional desirability, optimality, or normative superiority of any configuration. Classification reflects signal convergence under current conditions and remains contingent on regulatory, capital, and technological evolution. Lens signals were assigned following structured evidence extraction; each lens was evaluated independently before aggregation.
NonarySet — nine lenses across five perspectives:
This report analyzes three phenomena using nine analytical lenses drawn from the nemo2 Protocol.
DemocraticDelegation: Mandatory Compliance, Resolving Disputes, Participatory Representation, Risk Convexity.
ProtocolConsent: Exit Rights, Programmable Protocols, Predatory Delay.
AttestationCredentials: Verifiable Proofs, Informed Consent.
FindingType: Undetermined.
No consent architecture has assembled all four legitimacy functions at the compelled participation boundary. Mandatory Compliance, Participatory Representation, and Risk Convexity produce Undetermined signals from the DemocraticDelegation layer — the architecture performs all four functions but imperfectly, and no alternative has demonstrated equivalent performance. Exit Rights, Verifiable Proofs, and Informed Consent produce Undetermined signals from the ProtocolConsent and AttestationCredentials layers — genuine capabilities demonstrated, decisive limitations confirmed. Predatory Delay produces a partial Reconfiguration signal: legacy standard-setting is extending DemocraticDelegation‘s hold on the legitimacy function by delaying the empirical test that would determine whether consent disaggregation is coherent. Two structurally non-redundant lens clusters produce directional signals; the remainder produce genuine divergence. Four consent functions identified; three phenomena mapped; no convergence reached on whether disaggregation is coherent or self-defeating.
Zone migration definition: A phenomenon migrates when it crosses the legibility threshold — not when it grows within its current zone. Outside → Margins: a binding regulatory framework formally addresses the consent architecture as a basis for monetary governance decisions. Margins → Center: the consent architecture sets the terms of normal monetary governance operation rather than being treated as an exception or supplement. Growth within a zone is not migration.
Transitions:
T1 — ProtocolConsent Margins → Center: 0.05–0.15 (lower than Governance Money‘s override-layer estimate because legitimacy authority is structurally harder to assemble than override capacity; no protocol has demonstrated compelled participation handling; upper bound reflects speculative scenario where ZK-proof non-participant consent mechanisms deploy under MiCA pressure)
T2 — AttestationCredentials Outside → Margins: 0.25–0.45 (eIDAS 2.0’s November 2026 member state wallet deadline creates a binding framework formally addressing verifiable credentials — the legibility threshold may be crossed before this report is superseded; upper bound reflects EU rollout plus MAS endorsement; lower bound reflects the gap between data consent and monetary governance consent remaining unresolved even as the infrastructure deploys)
T3 — DemocraticDelegation Center → Margins: 0.03–0.08 (recognized legitimacy authority is more structurally entrenched than any other governance function; the compelled participation handling function has no substitute currently operating at monetary governance scale)
US and EU primary; Switzerland scoped as proof-of-concept.
The four consent functions: Population Reach (enrollment and identification architecture — who the consent mechanism can see and extend authority to), Binding Authority (legal and constitutional architecture — recognized right to impose costs), Contestability (dispute resolution and revision architecture — ability to challenge decisions from within without exit), Compelled Participation Handling (non-participant accountability architecture — structural answer for affected non-participants). In this report, zone assignments track which functions each consent architecture performs. Center requires all four; Margins performs at least one partially at scale; Outside has candidate architecture unassembled for monetary governance application.
Compelled participation: The condition in which a population is subject to a monetary governance mechanism they neither consented to nor can meaningfully exit — because participation in the monetary system is structurally required by network effects, legal tender law, or economic necessity. In this report, compelled participation handling is the legitimacy function that distinguishes DemocraticDelegation (structurally present, imperfect) from ProtocolConsent (structurally absent) and AttestationCredentials (candidate architecture, unassembled).
ZK proof of personhood / ZK proof of affected status: Zero-knowledge proofs that allow a prover to demonstrate a statement (”I am a person,” “I am affected by this governance decision”) without revealing the underlying data. In this report, ZK proof of affected status is the candidate technical mechanism that could allow AttestationCredentials to reach non-participants without creating surveillance infrastructure — the specific capability whose absence keeps this architecture at Outside.
Legibility threshold: The migration condition a phenomenon must cross to change zone assignments. Outside → Margins: a binding regulatory framework formally addresses the consent architecture for monetary governance. Margins → Center: the consent architecture sets the terms of normal monetary governance operation. Growth within a zone is not migration.
Convex legitimacy position: The additional stabilization value generated by a consent architecture whose recognized authority creates binding commitments whose scope is not fully calculable in advance. In this report, DemocraticDelegation‘s convex legitimacy position means that recognized constitutional authority generates compliance before intervention is invoked, because affected populations cannot calculate the upper bound of what the authority will do. ProtocolConsent‘s concave legitimacy position is the structural contrast: observable governance rules and bounded participant population allow the scope of authority to be calculated — the boundary where attacks and runs concentrate.
References are grouped by analytical lens to show evidential logic. Lens names match the NonarySet exactly as declared at Stage 0.
Switzerland’s regulatory landscape in digital identity consent infrastructure is the most technically advanced of the three jurisdictions in this specific domain and the most resistant to simple characterization. What is well-evidenced: the e-ID Act’s ZK-proof-based architecture, unlinkability design, and self-sovereign identity model — approved by Swiss voters on September 28, 2025, with launch targeted no earlier than summer 2026. What remains contested: whether this architecture generates contestability or compelled participation handling at monetary governance scale. Switzerland functions here as a proof-of-concept — its implementation demonstrates the architecture is buildable, not that it generates monetary governance legitimacy. This report maps US and EU in detail; Switzerland’s consent architecture is treated as a subject requiring its own cartography elsewhere.
📝 Swiss Confederation — “Voters Approve Federal Act on Electronic Identification Services (e-ID Act)”, admin.ch (2025)
🔗 admin.ch — e-id-act-referendum-2025
🕯️ Primary official document confirming voter approval of the Swiss e-ID Act on September 28, 2025 (50.39% yes), establishing the state-issued self-sovereign identity framework with ZK-proof-based architecture — cited as the proof-of-concept jurisdiction’s foundational legal confirmation, demonstrating that the population reach and binding authority functions of AttestationCredentials have been approved at democratic level for state-scale deployment, with launch targeted no earlier than summer 2026.
📝 Swiss Federal Office of Justice — e-ID Development Blog, Swiss Confederation (2025–2026)
🔗 eid.admin.ch — blog-e
🕯️ Official technical documentation of the Swiss e-ID’s ZK-proof implementation, unlinkability architecture, and deployment timeline — grounding the proof-of-concept function by establishing operational status of the selective disclosure and unlinkability properties that would be required for non-participant proof of affected status in a monetary governance context.
📝 Deutsche Bank Research — Zero-Knowledge Proofs in Blockchain Finance: Opportunity vs. Reality, Deutsche Bank (2024)
🔗 corporates.db.com — zero-knowledge-proofs-blockchain-finance
🕯️ Industry analysis of ZK proof applications in financial services — cited as contextual framing for the Switzerland proof-of-concept function; not used as independent verification of Swiss government policy claims. Primary analytical claims on ZK proof architecture grounded in [SW1] and [SW2].
📝 Sastry, P. — “The Political Origins of Section 13(3) of the Federal Reserve Act”, Federal Reserve Bank of New York Economic Policy Review (2018)
🔗 newyorkfed.org — section-13-3-political-origins
🕯️ Documents the statutory design of DemocraticDelegation‘s emergency binding authority from its 1932 origins — establishing that the binding authority function is a historically contingent institutional construct with revisable statutory architecture, grounding the Mandatory Compliance finding that recognized right to impose costs flows from democratic delegation, not technical execution.
📝 Murau, S. and van ‘t Klooster, J. — “Rethinking Monetary Sovereignty: The Global Credit Money System and the State”, Perspectives on Politics, Cambridge University Press (2023)
🔗 pure.uva.nl — rethinking-monetary-sovereignty
🕯️ Establishes monetary sovereignty as a governance capacity rather than an issuance monopoly — grounding the Mandatory Compliance finding that DemocraticDelegation‘s binding authority function is constituted by the recognized right to make decisions whose costs are borne by the governed population, not by the technical capacity to issue currency.
📝 Awrey, D. — Beyond Banks: How Non-Bank Financial Intermediaries Are Transforming Monetary Governance, Princeton University Press (2024)
🔗 press.princeton.edu — beyond-banks
🕯️ Establishes compelled participation as a structural condition of non-bank monetary infrastructure — grounding the Mandatory Compliance finding that DemocraticDelegation is the only consent architecture that currently addresses the compelled participation handling function, and the Participatory Representation finding that ProtocolConsent‘s absence of non-participant accountability is structural rather than an implementation gap. (Also cited under Programmable Protocols.)
📝 Anagnostaras, G. — “Activating Ultra Vires Review: The German Federal Constitutional Court Decides Weiss”, European Papers Vol. 6, No. 1 (2021)
🔗 europeanpapers.eu — weiss-ultra-vires-review
🕯️ Provides primary legal analysis of the Weiss judgment’s contestability architecture — establishing that DemocraticDelegation‘s contestability function is real and exercisable (the court activated ultra vires review, imposed documentation requirements, and forced institutional negotiation) while confirming it is distinct from compelled participation handling: populations bearing fiscal costs in adjacent jurisdictions had no direct contestability mechanism, only the constitutional court acting on their behalf.
📝 United States Court of Appeals for the Fifth Circuit — Van Loon v. Department of Treasury, No. 23-50669 (2024)
🔗 ca5.uscourts.gov — van-loon-tornado-cash-opinion
🕯️ Primary court document establishing that immutable smart contracts are not “property” under IEEPA — defining the outer boundary of DemocraticDelegation‘s contestability reach into ProtocolConsent‘s territory: the code layer executes without bearing legal obligations toward those it affects who never consented, grounding the Resolving Disputes finding that state authority can govern code authors but cannot govern autonomous code through property-based contestability mechanisms.
📝 Gorton, G. and Zhang, J. — “Taming Wildcat Stablecoins”, University of Chicago Law Review Vol. 90(1) (2023)
🔗 chicagounbound.uchicago.edu — taming-wildcat-stablecoins
🕯️ Establishes that stablecoin governance failures impose costs on populations who did not participate in the governance architecture — grounding the Participatory Representation finding that ProtocolConsent‘s population reach stops at the participant boundary precisely where monetary governance failures impose their heaviest costs, and that this is a structural condition of the consent architecture rather than an implementation gap.
📝 European Parliament Economic and Technology Indicators Unit — “Cryptomercantilism vs. Monetary Sovereignty”, European Parliament ECTI_STU(2025)760274 (2025)
🔗 europarl.europa.eu — cryptomercantilism-monetary-sovereignty
🕯️ Primary institutional source establishing that USD-denominated stablecoin governance decisions impose monetary conditions on EU populations who did not participate in US legislative or protocol governance — grounding the Participatory Representation finding that DemocraticDelegation‘s population reach function fails at jurisdictional boundaries in precisely the way that cross-border stablecoin governance exposes.
📝 Draghi, M. — “Speech at the Global Investment Conference”, European Central Bank (2012)
🔗 ecb.europa.eu — draghi-whatever-it-takes-2012
🕯️ Primary source for the convex legitimacy position — bond spreads collapsed before a single bond was purchased because recognized constitutional authority creates binding commitments whose scope is not fully calculable in advance, grounding the Risk Convexity finding that DemocraticDelegation‘s legitimacy premium depends on the same strategic ambiguity that programmable transparency structurally destroys. Cited for the mechanism, not current state claims.
📝 Glassnode Insights — “What Really Happened to MakerDAO?”, Glassnode (2020)
🔗 insights.glassnode.com — makerdao-black-thursday
🕯️ Quantitative documentation of the Black Thursday liquidation cascade — $8.32 million zero-bid exploit, $5.67 million bad debt — establishing ProtocolConsent‘s concave legitimacy position as the structural contrast that makes DemocraticDelegation‘s convex position legible. Tagged Self-Reported as Glassnode is an industry analytics provider; figures consistent with on-chain transaction data independently verifiable on Ethereum. (Shared with Exit Rights; population reach failure angle operative here.)
📝 Hirschman, A.O. — Exit, Voice, and Loyalty: Responses to Decline in Firms, Organizations, and States, Harvard University Press (1970)
🔗 hup.harvard.edu — exit-voice-loyalty
🕯️ Foundational framework establishing exit as the primary autonomy-preservation mechanism in systems lacking voice — grounding the Exit Rights finding that ProtocolConsent‘s legitimacy claim rests on exit rights that are structurally unavailable to non-participants (who never entered) and that failed for participants under network stress (Black Thursday network congestion closed the exit door at precisely the moment costs were imposed).
📝 Ferreira, A. — “Decentralized Finance (DeFi): The Ultimate Regulatory Frontier?”, Capital Markets Law Journal Vol. 19(3), Oxford University Press (2024)
🔗 doi.org — 10.1093/cmlj/kmae007
🕯️ Establishes that DeFi’s accountability reconcentrates in a less visible and less regulated layer where decentralization disperses execution — grounding the Exit Rights finding that ProtocolConsent‘s non-participant accountability gap is not an implementation problem but a structural feature of the governance architecture: where execution is decentralized, governance decisions affecting non-participants reconcentrate without a consent mechanism that reaches them.
📝 Office of the Comptroller of the Currency — “Implementing the GENIUS Act for the Issuance of Stablecoins”, Federal Register Vol. 91 (2026)
🔗 federalregister.gov — occ-genius-act-implementing
🕯️ Primary regulatory instrument establishing the hybrid consent architecture of GENIUS Act stablecoins — immutable at the execution layer, controllable at the institutional layer — grounding the Programmable Protocols finding that the GENIUS Act framework retains override capacity (OCC supervisory direction) while the consent architecture for populations affected by a run who never held the stablecoin remains structurally unaddressed.
📝 European Central Bank — “Digital Euro Pilot Programme”, ECB (2026)
🔗 ecb.europa.eu — digital-euro-pilot
🕯️ Official ECB pilot programme documentation establishing that the digital euro’s programmability is being deliberately constrained to preserve central bank override capacity — encoding a theory of ProtocolConsent‘s limits directly in technical architecture, grounding the Programmable Protocols finding that the EU approach makes DemocraticDelegation‘s consent theory explicit in the design of the programmable instrument.
📝 Bank for International Settlements — “Basel Committee Discusses Recent Market Developments and Targeted Review of Cryptoasset Standard”, BIS Press Release (2026)
🔗 bis.org — basel-targeted-crypto-review
🕯️ Documents the Basel Committee’s February 2026 decision to conduct a targeted review of SCO60 following US resistance — establishing the institutional mechanism by which legacy standard-setting delays the empirical test that would determine whether ProtocolConsent‘s legitimacy claim is coherent or self-defeating at non-participant scale, grounding the Predatory Delay finding at the legitimacy layer.
📝 Senator Husted — “Husted Backs Bill Blocking Fed from Issuing a Central Bank Digital Currency”, U.S. Senate Press Release (2026)
🔗 husted.senate.gov — cbdc-prohibition-press-release
🕯️ Primary government source documenting the political architecture of US CBDC prohibition — grounding the Predatory Delay finding that the US legislative system has actively foreclosed the public digital infrastructure that would extend DemocraticDelegation‘s compelled participation handling to digital monetary instruments, preserving ProtocolConsent‘s structural gap from being tested against a publicly accountable alternative.
📝 European Parliament and Council — “Regulation (EU) 2024/1183 Amending Regulation (EU) No 910/2014” (eIDAS 2.0), Official Journal of the European Union (2024)
🔗 eur-lex.europa.eu — eidas-2-regulation-2024-1183
🕯️ Primary binding legal instrument establishing the European Digital Identity Wallet framework — grounding the Verifiable Proofs finding that the population reach and binding authority functions of AttestationCredentials are being assembled at regulatory scale (member state wallet deployment due approximately November 2026, financial services acceptance by December 2027), while the gap between data consent and monetary governance consent remains structurally unaddressed.
📝 Bavarian Data Protection Authority / European Data Protection Board — “Decision on the Processing of Biometric Data by Tools for Humanity / Worldcoin”, EDPB (2025)
🔗 edpb.europa.eu — decision-tools-for-humanity-worldcoin
🕯️ Primary regulatory enforcement document establishing the structural finding that biometric consent architecture revealed at the point of stress: once iris data is converted to code at scale, the right to erasure was found difficult to operationalize at the precision GDPR requires — grounding the Verifiable Proofs finding that AttestationCredentials at the biometric layer generates enrollment without generating the ongoing consent architecture that monetary governance would require for non-participant accountability. Note: Worldcoin subsequently deleted its iris code database and migrated to a new SMPC architecture; the structural finding about the consent gap at scale remains the analytical object.
📝 Ohlhaver, P., Weyl, E.G., and Buterin, V. — “Decentralized Society: Finding Web3’s Soul”, SSRN 4105763 (2022)
🔗 doi.org — 10.2139/ssrn.4105763
🕯️ Introduces soulbound tokens as a candidate consent architecture for extending credential infrastructure to governance contexts — grounding the Verifiable Proofs finding that AttestationCredentials has a theoretical foundation for non-transferable proof of participation and proof of affected status, while acknowledging this application to monetary governance consent remains speculative. [Evidence-Thin: monetary governance application underdeveloped; philosophical grounding for non-participant consent architecture requires supplementary peer-reviewed literature.]
📝 Swiss Confederation — “Federal Act on Electronic Identification Services (e-ID Act, BGEID) — Voter Approval September 2025”, admin.ch (2025)
🔗 admin.ch — e-id-act-referendum-2025
🕯️ Establishes the state-issued, self-sovereign identity model and ZK-proof-based selective disclosure architecture approved by Swiss voters in September 2025, with launch targeted no earlier than summer 2026 — grounding the Informed Consent finding that data consent architecture can be built with unlinkability and user control properties required for non-participant monetary governance consent, while the gap between “consent to share a credential” and “consent to be governed by a monetary mechanism” remains the central problem that no jurisdiction has yet resolved. (Shared with Switzerland Contextual [SW1]; Informed Consent angle operative here.)
📝 Zetzsche, D.A., Arner, D.W., and Buckley, R.P. — “Decentralized Finance (DeFi)”, Journal of Financial Regulation Vol. 6(2), Oxford University Press (2020)
🔗 doi.org — 10.2139/ssrn.3539194
🕯️ Establishes that where DeFi decentralizes financial execution, accountability reconcentrates in a less visible and less regulated layer — grounding the Informed Consent finding that ProtocolConsent‘s consent architecture generates a governance layer running on the same infrastructure as the settlement layer, without a separate administrative process through which non-participant consent could be obtained or contested; and that regulatory focus on the reconcentrated governance layer is the structural condition for any embedded consent architecture to become effective.
Note on shared references: [3] Awrey appears under both Mandatory Compliance and Programmable Protocols; [9] Glassnode appears under both Risk Convexity and Exit Rights; [19] Swiss Confederation e-ID Act appears under both Switzerland Contextual and Informed Consent. In each case a single source grounds two distinct analytical claims. Reference numbers are stable throughout; the lens heading and 🕯️ annotation identifies which aspect of the source is operative in each section.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.