# Agents are starting to operate real systems- who's actually in control? Source: https://yakcollective.substack.com/p/agents-are-starting-to-operate-real ## Summary This AI-generated digest of a Yak Collective study group discussion says the group rejected prompting as a real security boundary for agents that control money, and it favored agents limited by hard spending caps enforced outside the model. The discussion also argued that political power, especially state control over taxation, surveillance and money, is likely the largest barrier to agentic payment systems. Cited precedents included Tornado Cash, Stripe, PayPal and India's UPI. Participants also explored speculative ideas such as digital toll gates that withhold tax automatically and a state-authorized "digital gun" that could terminate an online process, though the group did not endorse either. ## Article Sharing our experimental call summaries. Al-generated digests of Yak Collective study groups. Reading: https://a16zcrypto.substack.com/p/agents-are-starting-to-operate-real + https://arxiv.org/html/2604.03733v1 The discussion started from a broad question: as LLM-based agents become more capable, do existing payment and identity systems fit their needs at all, or are blockchains being forced into the picture because they are one of the few available programmable transaction primitives? A working assumption in the conversation was that “agents” are becoming a durable software pattern, even if the term itself remains underspecified. A major early distinction was between giving agents full financial autonomy versus giving them tightly constrained transactional authority. One view was strongly skeptical that current agents can safely control money at all, because prompt injection and other context-manipulation failures remain unsolved. The more optimistic counterpoint was not that agents are secure, but that security could be moved outside the agent: for example, an agent could control only a small stablecoin balance, with spending limits enforced externally through smart contracts or on-chain account controls. That distinction mattered because it reframed the role of blockchains. Instead of treating them as a magical trust layer, the group treated them as a possible constraint-enforcement layer: useful only insofar as they can impose hard limits that the agent itself cannot override. The sharpest convergence in the meeting was on security. The group did not treat prompting as a meaningful security boundary. A core claim raised was that “no amount of prompting can create real security,” because if an agent reads compromised or adversarial input, prompt-level protections can be bypassed. In practical terms, this led to a conservative operational stance: current agents should not be trusted with unrestricted access to funds. One participant connected this to actual usage habits with Claude since January: keeping it on narrow, bounded tasks, clearing context often, and avoiding long-running, weakly constrained agent loops. That example served as an informal threat-modeling lesson. In distributed systems terms, the argument was less about whether a component is intelligent and more about whether it is sandboxed. If the component is unreliable under adversarial input, then capability boundaries matter more than internal instructions. Where the group seemed to converge was that a realistic near-term design would treat agents as unsafe by default, and rely on external control planes to cap damage. Where the group did not converge was whether that limited model is compelling enough to justify blockchain-based infrastructure in the first place. A second thread focused on whether an agent can be trusted to represent the user’s intent, rather than the values or biases embedded by the model creator. The discussion treated this as a deep and possibly unsolved issue. One argument was that different models already show recognizable “imprints” from the people or organizations behind them, so requiring some kind of verification that a model is acting purely in the user’s interest may not even be well-posed. Several speculative ideas were raised rather than endorsed. One was a mixture-of-experts-like mechanism for trust, where different internal subsystems or “personas” could be invoked or verified depending on the context. Another drew on the psychology concept of internal family systems, using it as an analogy for models that may already behave as if they have different situational personas. The open question was whether those internal modes could ever be made inspectable or sandboxable in a way users could rely on. Identity itself was also challenged. Rather than assuming a clean, stable “agent identity,” the conversation leaned toward a softer view: what persists may be more like a bundle of characteristics, permissions, and behavioral traces across contexts than a single coherent entity. In security terms, the boundary around an agent was described as “leaky,” which is why the usual identity framing may be too rigid. The longest and most forceful part of the discussion argued that the decisive constraint is not technical architecture but political power. The central claim was that any agentic payment economy will run into nation-state control, because states care about both security/surveillance and taxation, and those motives often blur together. Concrete examples anchored this argument. Tornado Cash was cited as a precedent for states sanctioning infrastructure itself, not just end users. Stripe was described as an example of a multinational platform that remains globally operable only by yielding to local regulatory demands; PayPal was framed as an earlier version of the same pattern. Regional payment rails reinforced the point that “borderless” systems are rarely actually borderless: Venmo and Zelle depend on the U.S. banking system, while in India, UPI effectively defines the practical banking layer for digital transactions. This led to a strong divergence in worldview. One side emphasized the opportunity cost if these systems are politically blocked before experimentation can happen, especially given the real mismatch between legacy payment rails and software agents operating at machine speed and machine scale. The other side argued that this optimism underestimates how directly such systems threaten existing control over money, and therefore how aggressively states may move to contain them. The conversation developed a useful layered model of payment infrastructure. At the bottom are native currencies and crypto assets, which create exchange-rate risk, border-crossing friction, and—unless stable—capital-gains complexity for ordinary spending. A second layer is stablecoins, which reduce volatility but tie the system back to fiat reference points and therefore back to nation-state monetary frameworks. A third layer is credit cards, which the discussion characterized as increasingly awkward for this world: they sit on top of unsecured consumer credit, risk pricing, and fee structures that may not match agentic micropayments or dynamic machine-to-machine spending. An important cross-domain bridge emerged here. In human commerce, the payment stack assumes bounded, legible human intent. In an agentic world, spending may be rule-based yet still indeterminate: a system may be authorized to make many small decisions under evolving conditions, more like cloud resource consumption than a consumer purchase. That creates a mismatch with existing financial rails, especially when risk assessment depends on auditing complex software behavior rather than evaluating a human cardholder or merchant. There was also a partially convergent but unresolved point about scale. If blockchains are to matter here, they must support both decentralization and a much higher transaction/computation scale than current systems comfortably handle. One view was that blockchain primitives such as programmable identity, reputation, and transaction history are conceptually attractive. Another was that, in the next 10–20 years, blockchains may remain mostly an auxiliary monetary layer inside a still-dominant fiat world, with more ambitious uses deferred until scaling and zero-knowledge technologies mature further. The most speculative portion of the session explored what state power would look like if it were truly native to online infrastructure. One hypothesis was that today’s political order still lacks a true online analogue of the gun: states can freeze accounts, compel intermediaries, or conduct rare high-end cyber operations, but they do not yet have an everyday, fine-grained mechanism for exercising coercive control over digital processes. This led to the provocative thought experiment of a “digital gun”: a state-authorized capability to enter a system and terminate a process—effectively, to “kill” an online agent the way a Unix system can kill a process. The point was not consensus support for such a mechanism, but to clarify what kinds of control states may eventually demand if digital systems become economically central. A parallel thought experiment addressed taxation. Instead of trying to reconstruct taxes from messy, high-volume on-chain or cross-rail activity, the discussion imagined digital toll gates: a government endpoint that automatically withholds tax as flows pass through, so a requested $5 transfer might emerge as $4.50 after a fixed deduction. A related idea was a post-tax escrow model, where users pay taxes up front, convert into instruments like USDC, and then transact freely within that already-taxed pool. The group did not resolve whether these mechanisms are desirable, workable, or politically acceptable. But they did use them to sharpen a shared insight: if digital economies become real, states will not simply vanish from the design space. By the end, the conversation had broadened from payments to a more general critique of tech-utopian assumptions. A recurring argument was that many future-facing technical visions implicitly assume away politicians—that is, people whose primary objective is control over others, backed in the last instance by the monopoly on violence. The group’s counterclaim was that these actors will not disappear; if digital systems become important enough, political power will either be designed into them in disciplined ways or imposed on them later in more destructive ways. There was also an important caution against assuming states will have exclusive access to coercive digital tools. One participant noted that governments may claim a monopoly on legitimate violence, but never a monopoly on weapons themselves; if there are “digital guns,” non-state actors, criminal groups, rival states, and open-source ecosystems will likely develop them too. In that framing, the future is not simply about enabling state control, but about a broader escalation in digital offensive capability. That produced one of the clearest points of convergence in the meeting: whatever agentic infrastructure emerges will have to be understood not just as software architecture, but as part of a contested political and security environment. Key takeaways The group rejected prompting as a credible security boundary for financially empowered agents. A more plausible near-term model is externally constrained agents with hard spending limits enforced outside the model. Trust is not just about authentication; it includes whether a model can represent user intent rather than creator bias. The largest barrier may be political: states are likely to intervene wherever agentic payments threaten taxation, surveillance, or monetary control. Existing payment rails appear mismatched to machine-scale, rule-based spending by agents. The most interesting speculative ideas were digital toll-gate taxation and state “digital guns” for process-level intervention online. Open questions the group surfaced Can agent identity be defined in a stable enough way to support trust, reputation, and payment authorization? Are there viable ways to verify a model’s active “persona” or decision mode? Can blockchain systems scale enough—while remaining decentralized—to support meaningful agentic transaction volume? Will states permit such systems to emerge, or constrain them before they become meaningful? Call chat on Yak Collective Discord: https://discord.com/channels/692111190851059762/1493246662821416970