As AI agents begin to spend money, build relationships, and generate income on a user’s behalf, the debate is getting less abstract. A Foresight article frames the moment around three blunt questions: who is liable when an agent spends, where the real bridge between digital systems and the physical economy actually sits, and whether a score produced in the age of agents still belongs to the person it claims to represent.
The piece starts with the recent push by large firms to give machines payment rails. Over the past few weeks, Cloudflare introduced a stablecoin wallet for AI agents. Coinbase integrated x402 and stablecoin wallets into Amazon Web Services agent environments, allowing companies to set budgets and governance rules for agents. Google also released an agent payment protocol. In the article’s reading, these moves point in the same direction: machines are being equipped to pay on their own.
That raises a basic question. If a machine places an order, signs a contract, or spends funds for you, who ends up carrying the bill when something breaks? A machine has no legal identity, cannot be jailed, and cannot regret what it did.
Liability still has to be anchored to a person
The article argues that the answer starts with a deeper premise built into modern economic and legal systems: an actor is expected to bear consequences. A person can sign a contract because that person can perform and can also be punished for breach. A company can operate because it has legal personhood, assets, and can be sued. The credit system rests on that capacity to bear loss or penalty.
Agents disrupt that premise. They can act, evaluate, and optimize, but they cannot truly be responsible in the legal sense because responsibility requires something that can be taken away, and the agent itself owns nothing.
Seen from that angle, the plans from Google and Coinbase are doing much the same thing. They are pushing liability back toward humans. Google’s authorization credential records what a user allows an agent to buy, what spending cap applies, and who initiated the action. Coinbase’s budget and governance rules are set by the enterprise, not by the agent. The more autonomy the agent has, the clearer the human authorization trail must become.
The article treats that as a counterintuitive conclusion: autonomy and traceability do not move in opposite directions. They rise together. The broader the range of actions an agent can take, the tighter the recordkeeping framework behind it needs to be.
It places ATM’s agent product on that line as well. Users define the rules, and the agent operates within them, with the source of intent remaining on the human side. On its own terms, the article says, that logic holds.
What remains unresolved is the line between execution and decision-making. If an agent independently decides whom to contact, when to act, and where to direct resources, is that still execution, or has it crossed into decision-making? Once it becomes the latter, the point where responsibility is anchored may start to loosen. The article is explicit here: there is no settled answer yet, and anyone claiming to have one is telling a story.
RWA growth is real, but it is concentrated in financial assets
The second challenge is presented as the most concrete one because the data are strong and hard to wave away. According to the article, total onchain RWA market value reached $37.94 billion as of Aug. 7, 2026. The number of asset holders climbed to 1.6294 million, up 55.34% from the previous month, with more than 560,000 net new holders in a single month, the largest increase on record.
The numbers look strong. The article then asks what exactly has been growing. The answer is Treasuries, money market funds, private credit, gold, fund shares, and stocks. In other words, financial assets.
Machine tools are not onchain. Supply chains are not onchain. Orders inside Suzhou Industrial Park are not onchain either.
The reason, the article says, is simple. Financial assets are already information. Industrial assets are physical objects. A Treasury or a fund share is fundamentally a rights record in a ledger. Moving it onchain is mostly a shift from one ledger to another, which creates relatively little friction. A machine tool, a batch of materials, or a production line is different. To put that onchain, someone first needs sensors, traceability, standards, ownership confirmation, and a party willing to take responsibility for data authenticity. Every step adds cost, time, and coordination.
That makes the real bottleneck the conversion of physical things into trusted information. The phrase “digital-real integration” only starts to carry weight when that middle layer is made explicit.
The article points to ATM’s use of LUCA in actual travel consumption, including hotel and flight bookings that generate real order records. It treats that as a genuine opening between digital systems and the real economy, but it also draws a limit around it. This is a consumption-side use case, not a production-side one. There are still several layers between “being able to buy things” and “entering the production floor.”
It also explains why Suzhou matters in this discussion. The city is described as one of China’s top industrial centers by gross industrial output, with precision manufacturing, biomedicine, and nanotechnology. In a place where yield rates and delivery cycles speak louder than narratives, attractive claims about digital-real integration can be tested quickly against production data. If an idea can survive serious discussion there, it has a better chance of being real.
When influence becomes a score, does the score still belong to you?
The third challenge is the hardest one in the article because it targets the foundation of the whole system. If influence can be turned into a score and the score can be tied to rewards, what happens when agents can keep building connections 24 hours a day? At that point, is the score measuring the person, or the machine working harder than everyone else’s?
The article traces the design back to Google’s PageRank, the algorithm that shaped search ranking. The core idea was that the importance of a page is not defined by what it says about itself, but by how many important pages link to it. Applied to people, the article says, influence is not determined by who speaks the loudest or spends the most, but by who forms real two-way connections with influential others.
The “two-way” part is central. One-sided attention does not count. Both sides have to lock assets and incur costs for the connection to be recognized. The aim is clear: make influence harder to buy from only one side. The article accepts that logic. Using cost constraints to fight score farming is, in its view, the right starting point.
But it immediately adds a warning drawn from the history of PageRank itself. Once a metric can be exchanged for benefits, people will organize around the metric. That is not a failure unique to one algorithm. It is a recurring feature of quantified systems. Schools use scores, so students study for scores. Platforms use engagement, so creators produce engagement-friendly content.
The next question is whether agents can weaken the original cost constraint. A two-way locked connection works as a defense only if creating that connection still requires human time and judgment. Someone has to meet, evaluate, and decide whether the relationship is worth the commitment. If an agent can screen, approach, and maintain contacts around the clock, the time-cost component can be bypassed. What remains is the asset-locking cost, and money can be stacked there.
The article says that loophole exists in theory. Whether ATM’s design has a hedge against it, and how large a scale that hedge can handle, still needs real data. The author also notes that this is not just one project’s problem. Any framework that tries to measure “human value” in the AI era will eventually run into it. The difference is whether a project avoids the issue or puts it on the table.
What matters is whether both sides share the same thread
To reframe the argument, the article turns to Suzhou embroidery, especially double-sided embroidery. The point is not only that both sides are real. The deeper point is that both sides are made from the same thread. They are not two different works. They are two faces of one work. Remove the thread, and both faces disappear.
From there, the article proposes a different test. The key question is not whether the virtual side is real. That framing sets the virtual and the physical against each other from the start. The better question is whether both sides come from the same thread.
If an agent builds relationships as an extension of a user’s intent, under settings defined by that user, in service of that user, and under that user’s responsibility, then the person and the agent still share one thread. In that case, both sides remain the same “you.” If the agent begins to form its own line by judging, deciding, and accumulating on its own, then the back side has already hollowed out no matter how polished the front looks.
This standard is stricter than a loose debate over what counts as virtual or real. It also loops back to the first question. Why does the authorization trail matter? Because it is the proof that the thread still leads back to a human source.
Why Suzhou University of Science and Technology is part of the setup
The article also explains why this stop is set at Suzhou University of Science and Technology. It points to the school’s stronger disciplines, including architecture, civil engineering, environmental science and engineering, and urban and rural planning. What those subjects share is an interest in turning a virtual blueprint into a physical structure.
An architect understands that a blueprint is not a building, but without the blueprint there is no building either. The blueprint is intangible, yet it determines whether the physical structure can stand, bear weight, and avoid cracking decades later. In that sense, the virtual and the real are not a true-false pair. They are different stages of the same thing.
The article argues that this is exactly the mode of thinking needed for the present discussion. Some in the industry treat the virtual side as everything and get lost in narrative. Others write it off wholesale as fraud. An engineering mindset looks elsewhere: can it actually be built, and once built, can it stand up to the wind?
The article leaves the verdict open and points to Aug. 22
The piece does not resolve the debate for the reader. On its own terms, the first question depends on a boundary that is getting harder to define, the second is stuck at conversion costs, and the third still lacks a full answer.
That, the article argues, is exactly why the questions deserve to be asked in person. It suggests taking several of them into the room: can the line between execution and decision-making by an agent really be drawn in technical terms, and if not, where is responsibility anchored; if current RWA growth is concentrated in financial assets, what specific link is blocking manufacturing from moving onchain, and can Suzhou produce the first workable case; when everyone uses agents and everyone’s score rises, how much differentiation is left in the metric?
The event details listed at the end are: Aug. 22, 2026, at Suzhou University of Science and Technology. The organizers are Dashu Caijing, Jinse Caijing, and Twinkle. ATM is the lead sponsor. Feixiaohao and DeBox are strategic partners.
The original article also includes a disclaimer stating that markets involve risk, investment should be approached with caution, the article does not constitute investment advice, and readers should judge whether any opinions, views, or conclusions fit their own circumstances before making decisions.

