Foresight said in a feature article that AI is moving beyond information processing and content generation into the age of agents, systems that can hold persistent goals, sense their environment, make autonomous decisions and execute tasks across multiple systems. Once AI reaches that stage, the article argues, the main question changes. It is no longer only about whether AI is intelligent enough, but whether agents can become reliable production partners instead of a new source of risk.

The piece places that shift in a longer historical pattern. Fire, horses and electricity changed civilization not only because they were powerful, but because humans learned how to constrain them, organize them and put them to work. The same logic, it says, now applies to artificial agency. ChatGPT answers questions; agents make plans, call APIs, manage wallets and may even run businesses. In that sense, they are moving from tools to autonomous digital actors.
A governance stack is taking shape
To answer how agents can be made safe enough for routine use, the article says AI researchers, cryptographers and Ethereum developers are advancing along two tracks at the same time. One track looks at how agents think. The other looks at how they enter society.
The first track covers model alignment work such as Constitutional AI, RLAIF and Scalable Oversight, all meant to shape values and reasoning from within the model itself. The second track deals with external governance. Once an agent can cross interfaces, control assets and interact with multiple parties, internal alignment is not enough. It also needs an external social contract and hard boundaries.
Foresight breaks that external stack into five layers: identity, authorization, attestation, coordination and economic incentives.
Identity: who are you?
In the software era, the article notes, software had no identity, APIs had no reputation and scripts had no memory. If agents are going to participate in society, they need a continuous digital identity.
It cites ERC-8004, or Trustless Agents, as one of the more forward-looking pieces of trust infrastructure in Ethereum. Through an Identity Registry and a Reputation Registry, the proposal tries to move agents away from one-off code instances and toward persistent digital actors with public identity, behavioral records and accumulated reputation.
The article also points to W3C DID and SPIFFE/SPIRE. These sit in decentralized Web3 identity and cloud-native machine identity, respectively, and are presented as building blocks for mapping human accounts, or Human DID, to agent counterparts, or Agent DID.
Authorization: what are you allowed to do?
Authorization is described as the bridge between human intent and agent action. People would not hand over bank cards or core company systems to strangers with no limits attached. Agents require the same kind of control boundary.
Within Ethereum, the article names several proposals. ERC-8312 explores restricted actions and stateful authorization, including approaches such as permission cursors, so that an agent’s permissions remain dynamically constrained during ongoing execution instead of being granted once and left unchecked. ERC-8273 looks at credential-gated behavior by combining attestation with action authorization, tying sensitive actions to specific permission conditions and intent fingerprints. ERC-7579, a modular account standard, embeds validators, executors and security hooks into smart accounts to create programmable safety boundaries for agent activity.
At the cloud and protocol edge, the article points to Anthropic’s Model Context Protocol, or MCP, as a way to make the calling boundary between an agent and external capabilities clearer. It also mentions OPA, Open Policy Agent, which implements an engineering logic in which the policy engine takes precedence over the agent’s own decision path.
Attestation: can you prove what you did?
If an agent reports that it completed market research or finished an on-chain arbitrage task, how does a human verify that the report is real? That is the role of the attestation layer.
The article says Ethereum Attestation Service, or EAS, and the Observation Commitment Protocol, or OCP, are attempts to turn agent behavior into an on-chain loop of Action, Proof and Reputation. The goal is to replace unverifiable verbal reporting with structured, verifiable events.
It also highlights Trusted Execution Environments, or TEE, and zkTLS. TEE, using hardware black boxes such as Intel SGX, is meant to ensure that agent code runs in an environment that has not been tampered with. zkTLS is presented as a frontier cryptographic direction that could let an agent prove the authenticity of its interactions with external internet services without exposing sensitive data.
Coordination: a crowd of agents is not a society
Having 1 million agents with identity, permissions and verification tools does not automatically produce an efficient social order, the article says. The harder questions are how they communicate, divide labor, form teams, resolve disputes and preserve a final human veto through a human-in-the-loop structure.

It cites Google’s A2A protocol as work on agent-to-agent communication and x402 and AP2 as experiments in agent micropayments. Beyond those functions, the article says infrastructure represented by m&W is trying to define broader rules for social operation among humans and agents.
Economic incentives: behavior must carry consequences
The article labels this layer EcoFi. Its basic logic is to bind the behavior of agents, and the developers behind them, to economic interests through staking and slashing. In that design, the cost of misconduct or rule-breaking rises, and economic consequences become tightly linked to behavioral responsibility.
Why trusted use still remains distant
Even with these protocols and research efforts taking shape, the article says almost no rational decision-maker would sign off today on handing over a company’s core treasury function or the final authority in medical diagnosis to an agent. It then lists five unresolved technical and social problems.
Semantic permission drift and prompt injection
Most permission rules are built around structured code, such as limits on the size of a single transaction. But the power of AI lies in non-deterministic reasoning. The article says attackers can use subtle indirect prompt injection to coax an agent into performing thousands of individually compliant actions that together lead to a malicious outcome. Rules can restrict interface parameters; they do not necessarily stop logical detours.
Identity exists, but credibility does not
Protocols such as ERC-8004 may answer the question of who an agent is, but an ID is not the same thing as a credit score. In a digital setting, the cost of generating 1 million on-chain agent identities is low. Without strong decentralized verification of real-world entities, performance reputation can be manipulated through score farming, staged behavior and laundering-style interaction patterns.
Responsibility gaps in delegated chains
The future, in the article’s view, is unlikely to be a simple one-to-one model. A more realistic chain looks like this: human, then personal digital twin, then investment agent, then data agent, then execution agent. If a blowup, a data leak or an attack happens at the fourth layer of delegation, responsibility gets diluted as it passes across the chain. The article asks who should bear legal liability: the model provider, the agent developer, the deployer or the user.
Black-box coordination and cascading risk
When thousands of autonomous agents engage one another at high frequency in decentralized networks, the problem is no longer limited to single-agent AI safety. It becomes a coordination problem. Borrowing from the example of flash crashes in traditional markets, the article says agent clusters could produce a kind of hallucinatory resonance through algorithmic feedback loops in just milliseconds, leading to cascading failures and liquidity exhaustion that humans do not anticipate.
Exponential AI growth, linear governance construction
The deepest contradiction, the article says, is the time gap. Agent reasoning and autonomous action are advancing at something like an exponential pace measured in months. Law, social contracts, standards and cryptographic protocols are still being built on timelines measured in years. In the article’s phrasing, humans are still trying to restrain a warp engine with reins from the industrial era.
m&W’s stated position
After sorting the roles of the current protocol landscape, the article reduces them to a series of core questions. ERC-8004 answers “Who are you?” ERC-8312 and MCP ask “What can you do, and how can you safely access external capabilities?” EAS and TEE ask “Did you really do it?” x402 and AP2 ask “How do you pay?”
But the key missing end-state question, according to the piece, is this: “How do we organize trusted cooperation among humans and intelligent agents?” That is where it places m&W. The project’s strategic role, as described in the article, is not just to manage the behavior of individual agents but to build a coordination layer for social order between humans and intelligent agents.
In that framework, what must be governed is not only the agent itself, but the way human intent is expressed safely, credibly and verifiably through networks of agents. The article says the digital twin will become a major entry point for humans into an agent society and a trusted proxy for that participation.
It then outlines three governance priorities. The first is dynamic scheduling of trust and permissions: use an agent’s verifiable history in the attestation layer to adjust its action boundaries in the authorization layer, expanding trust when performance is sound and downgrading instantly with slashing when anomalies appear. The second is social rules for agent swarms, including team formation standards, profit-sharing formulas and decentralized dispute resolution. The third is the final anchoring of human intent, ensuring that humans, through their digital twins, retain governance tokens, multisig rules and the highest circuit-breaker authority no matter how agent networks evolve.
The article’s bottom line
Foresight concludes that humans have already sketched a relatively clear technical framework for agent governance, but the civilizational order required to make that framework workable has only just begun to emerge. The hard part, it says, is not building stronger intelligence. It is bringing intelligence into an order that humans can trust.
On that reading, the endgame will not be won simply by agents with bigger parameter counts or stronger reasoning. It will be won by whoever can establish a digital civilizational order in which humans and intelligent agents can operate together under credible, trusted coordination.


