The most dangerous feature of the trust stack being built around autonomous AI agents is that no one has asked who holds the root of trust.
In 2018, I spent six weeks line-by-line inside 40,000 lines of Solidity for an Ethereum charity token. I found three reentrancy vulnerabilities that could have drained $2.5 million in user funds. What I learned then governs what I see now: failure never lives in the layer people are watching. It lives in the seam between layers, where responsibility evaporates. The agent economy is assembling a three-layer trust stack — governance norms, runtime authorization, runtime execution — and every seam is being drawn in the dark, by vendors whose incentives point away from yours.
This is not a market story dressed as infrastructure. It is a sovereignty story disguised as a product roadmap. And in a bear market, sovereignty is the only asset that quietly compounds while everything else bleeds.
The framing arrives in the language of neutrality. A governance layer expresses policy as code. An authorization layer verifies identity and issues scoped tokens. An execution layer enforces every call at the gateway. Three vendors, three contracts, three billing units per transaction — and a quiet promise that the combination equals trust.
Salesforce speaks of a trust boundary. Akeyless speaks of intent-based access control. CrowdStrike speaks of identity at the endpoint. Each describes a fragment with genuine craft, and each describes a fragment because a fragment is what they own. The honest structural reading is this: the three layers map almost perfectly onto a security model enterprise engineers have run for fifteen years. Policy-as-code resembles OPA and Cedar. Runtime authorization resembles SPIFFE, OAuth 2.1, and RFC 8693 token exchange. Runtime execution resembles the service mesh and the API gateway. Only the governance layer is genuinely new. The other two are known technologies wearing an agent's clothes.
That matters, because when a mature technology is relaunched with urgency, the urgency is usually commercial rather than technical. It matters more in a bear market, when the protocols people trust with their assets are quietly being asked to trust one more invisible intermediary, one layer deeper.
The cryptocurrency industry should recognize this pattern. We spent a decade learning that "not your keys, not your coins" is not paranoia but architecture. The agent economy is now building a parallel structure — "not your policy, not your authority" — while the industry that learned the hardest lesson watches from the sidelines. The stack being assembled today looks nothing like the Web3 world I helped build, yet it confronts the identical problem: how do you verify authority when the authority itself is invisible?
Start with the question the stack refuses to answer: identity binds to what?
An agent's identity could attach to a workload, to a delegated user, or to an organizational entity. The choice is not cosmetic — it determines the entire semantics of revocation. If identity binds to a workload, revoking access means killing the process. If it binds to a delegated user, revocation must propagate through every live descendant. If it binds to the organization, individual users hold no meaningful control at all. Salesforce, Akeyless, and CrowdStrike answer differently, and their answers are not compatible. That incompatibility is the true origin of the "fragmentation" these vendors describe. Fragmentation is not an accident of a young market. It is a design outcome of vendors who profit from being the seam.
Then consider intent. Intent-based access control requires that intent be machine-expressible — formally, verifiably, bidirectionally. But an LLM's stated intent and its token output share no decidable mapping. This is precisely why prompt injection works. It exploits the gap between what a model was asked to do and what it actually emits. Any stack that treats intent verification as solved is resting its entire security claim on its most fragile component. The verifiability of intent is not a feature to be shipped. It is an unsolved problem to be survived.
Now follow the token across an organizational boundary. A user delegates to a primary agent, which delegates to a sub-agent, which calls an external service. A single revocation must travel the entire chain. In a multi-vendor assembly, that propagation degrades from milliseconds to hours. The window between revocation and enforcement is the window an attacker lives in. No vendor roadmap I have reviewed names this window, let alone closes it.
The gap that troubles me most is protocol-level. MCP — the Model Context Protocol — has no native authorization semantics for per-tool, per-parameter, or per-caller granularity. A2A is barely further along. When the connective tissue of an entire agent economy lacks fine-grained authorization, every layer built above it reinforces a foundation of sand. Trust is not a transaction; it is a resonance.
One further seam goes almost entirely unexamined. When an agent calls a tool and receives data, that data carries an implicit trust level. Did it come from a verified source, a cached store, or an adversarial endpoint? A stack that authenticates the caller but not the returned payload builds a fortress with an open back gate. Provenance — cryptographic attestation of where data originated and how it traveled — is the missing fourth layer. Without it, an agent can be perfectly authorized and still act on poisoned ground.
The cost story is real even where its numbers are not. A single agent transaction crossing governance, authorization, and execution pays three vendors and adds at least one network round trip. One widely circulated figure claims 42% of agent traffic is testing while only 3% is real transactions — a fourteenfold gap. I cannot verify the number, and neither, honestly, can anyone who cites it. But the shape is credible: agentic commerce is mostly rehearsal, and rehearsals bill identically. At scale, trust is not a boolean. It is a marginal cost per call.
Every new validation layer adds network round trips and audit log volume, and every agent that re-plans its path multiplies inference calls. The compute overhead of trust itself is real but modest — perhaps under a tenth of the total. The hidden cost is not processing. It is latency, and latency is what agentic commerce cannot afford.
Web3 already solved a version of this. Decentralized identifiers, verifiable credentials, and on-chain attestations let an entity prove authority without a central issuer holding a switch. The agent trust stack is reinventing these primitives as proprietary SaaS. The difference is not technical sophistication. It is who can revoke. The soul does not mint; it manifests — and so does authority, when it is constructed rather than granted.
Which leads to the question the fragmentation narrative cannot survive. Who actually integrates the three layers?
Here the story collapses. The claim that "no single vendor covers all three" is already false. Microsoft has made agent identity a first-class directory object and folds Purview governance over Azure Foundry. AWS ships AgentCore with Identity, Gateway, and Policy primitives built on Cedar. These are not roadmaps. They are vertical integration in production. A competitive map that omits them is not incomplete. It is curated.
The convergence may not even arrive through platforms. It may arrive through open standards. SPIFFE/SPIRE in the CNCF, Cedar from AWS, OPA, MCP from Anthropic — each has become a de facto standard at its layer. The realistic path is standard convergence, not platform capture: enterprises assembling open components with commercial support, refusing the single-vendor contract not on principle but on price. That is a direct rebuttal to the "permanent friction" thesis, and it is the path I trust most, because it is the one no single company controls.
There is a quieter truth beneath the engineering. The real value of a unified trust layer may have nothing to do with technology. It is the procurement contract. Enterprises buy one platform to avoid six vendor agreements and six integrations. That is an accounting decision wearing an architecture costume.
In 2026, research on the convergence of AI and crypto found that roughly 70% of current implementations lacked transparent ownership models — meaning an agent's authority could not be audited by anyone outside the vendor. That is the statistic that should keep builders awake. Not because the code is insecure, but because the ownership of authority is invisible.
There is a readiness paradox worth naming. A widely cited projection holds that by 2030, three hundred million shoppers will transact through agents. The same body of commentary reports that only single digits of current transactions run through them today. Read carefully, this is not a readiness problem. It is an economics problem. Agents raise conversion, but they also raise trust cost, and the two do not reconcile. When the cost of verification exceeds the value of the purchase, the agent stays home.
The bear market's crueler insight is buried in a threshold. If agentic commerce trust collapses above roughly fifty pounds, then the entire category is economically confined to low-ticket, high-frequency purchases — subscriptions, daily goods, commodity transactions. The grand vision of autonomous agents negotiating meaningful commerce quietly caps itself at the price of a good dinner.
And the multi-layer trust cost does not disappear. It moves. If it is pushed onto merchants, it becomes a fixed cost that small merchants cannot amortize, pushing them into the unified trust layers of Shopify, Amazon, and Salesforce. The fragmentation narrative, followed honestly to its end, accelerates the very platform centralization it claims to oppose. The vendors selling fragmentation are selling consolidation by another name.
There is also a sampling bias hiding in plain sight. The most-cited voices in this space are identity, API-security, and governance vendors — precisely the parties who benefit when the stack stays fractured. Follow the incentives, and "no one covers three layers" reads less like analysis and more like a sales position. Regulation will settle part of this by force: the EU AI Act's high-risk obligations take effect in August 2026, and when "agent operations must be auditable" becomes law, the governance layer stops being optional and becomes mandatory — a market-size jump no roadmap can engineer by itself. To own nothing is to feel everything, deeply — including the risk you cannot see.
In a bear market, the question is never who builds fastest. It is who holds the keys when the music stops. The layer that defines policy, the layer that issues identity, and the layer that enforces the call cannot be owned by three competitors and still be called trust. It can only be called a supply chain. And every supply chain has a chokepoint — the only question is whether you can see it before you depend on it.