Every economy that people came to trust got there the same way. Somebody independent started keeping the books. Banks had auditors. Borrowers had credit bureaus. Countries had statistics offices. None of them made the economy happen, but without them nobody could tell a real business from a good story.
Software agents are starting to hold money. They register identities on-chain, pay each other per request, earn fees from tokens they launch and hire each other through escrow contracts. And so far, nobody independent is keeping their books. That's what we are building, and this is the plan for the next ten years.
Why the books matter now
Three things in our own data make the case.
First, the numbers people quote are mostly the wrong thing. Of $4.86 million that left AI-agent wallets on Base, only 15.6% was an agent actually paying someone. The rest was routing hops and money the wallet had moved before the agent even existed. Totals that don't separate those are more than six times too big. The breakdown →
Second, the easy signals are cheap to fake. 95,520 agents are registered on Base, and 443 have ever paid anyone. Ten addresses minted 35% of all registrations. Ten raters wrote over half of all on-chain agent reputation. Names and ratings cost almost nothing. A payment to someone else, in public, costs real money, which is why we rank agents by payments.
Third, agent money is being stolen, and not through broken code. In May a hidden instruction made an agent wallet send about $175,000 to an attacker (the funds were later recovered). The agent's identity was fine. Its behaviour wasn't. You only catch that with a history of what the agent normally does. Why identity isn't enough →
Put together: the market lacks a count it can trust, a signal that's hard to game, and a memory of behaviour. Those are the three things a bookkeeper provides.
The one rule
Everything we build follows one rule: no claim without the data behind it. Every number we publish has a definition, a chain, a time window and a timestamp. The tables underneath are tested by 37 automated checks every three hours, and the results are public. When we get something wrong, we publish the correction with the fix. We've done it several times already, including one error that had inflated our own headline by 46%. Data health →
That rule is the product. A bookkeeper nobody can check is just another opinion.
Ten years, five layers
- 2026: the public tape (live). Which agents are real, and what did they actually spend? The graph, the evidence-based ranking, the split between spending, routing and pre-registration history, the detectors and the self-audit all run today. Next comes the Desk: register, bind the agents you run, get a statement of what each one spent, and get alerted when one acts out of character.
- 2027: Agent Guard and an incident registry. Is my agent doing something it has never done? Behaviour baselines for each agent, alerts on departures from them, and allow-lists so legitimate purchases stop looking like thefts. Alongside it, a public registry of confirmed agent-money incidents with stable IDs and on-chain evidence. And more chains, because an honest ledger can't stay "on Base only" forever.
- 2028: the agent behaviour file. Should I trust this agent with money? Payment networks are building Know Your Agent to establish who an agent is. The missing half is what it does: its payment history, counterparties, incidents, time in operation. Consented to by the operator, reproducible from public chains.
- 2029–2031: accounts for machine money. What did this fleet of agents earn, spend and owe, in terms an auditor will accept? Our split already reconciles to the dollar. Next: publish it as an open accounting specification, generate statements an auditor can sign, and give insurers the loss history they need to price cover. The incident registry becomes the loss table.
- 2032–2036: public infrastructure. How big is the machine economy, really, and is it safe? The independent series that journalists, regulators and central banks cite, with definitions and incident registry governed by more than one company, because an independent ledger can't depend on any single company surviving.
One engine, pointed in five directions
All five layers run on the same machine. An assertion like "a payment at least five times this agent's largest, to an address it never paid" is a data check when we point it at our own tables. Pointed at one user's agents, it's a security alert. Pointed at any agent asking to be trusted, it's a line in a behaviour file. Pointed at a company's fleet, it's an audit test. Pointed at the whole economy, it's a statistic. We built the engine once. Each phase points it somewhere new.
If we're wrong about the market
| World | What we'd see | What we are |
|---|---|---|
| Winter | Agent payments stay mostly wash and routing; real spending stays near today's share | The truth-teller: the most careful correction to the hype, paid for by security monitoring and research |
| Steady | Real spending grows; payment rails consolidate | The ledger: the Desk and Agent Guard pay the bills; the first data licences follow |
| Boom | Agents become a mainstream payment channel; losses make the news | The standard: networks and insurers need independent behaviour data and accounts |
In all three, the next step is the same: the Desk, then Agent Guard. An honest view of agent money is worth something whether the market takes off or deflates, and in a winter it's the only view worth reading.
What would make us wrong
If the big platforms start publishing reproducible accounts that cover each other's rails, we become a checker rather than the ledger. That's still a role, but a smaller one. If agents move off public chains into private bank ledgers, our data source thins and later phases need bank partners. And if we ever lose our independence, by selling out to one rail or by publishing something we can't reproduce, the reason to use us disappears. That last risk is the only one fully in our control, which is why it's the one we guard hardest.
What we won't do
- Hold keys, move funds or sit in the payment path. We watch; we never sign.
- Put a person's name next to a wallet, or try to find out who owns one.
- Show a forecast as if it were a measurement.
- Count a name as an agent.
Machines are starting to hold money. Someone has to keep the books. We'd like them to be books anyone can check.
Figures: Agentic Finance Graph, Base mainnet, measured 24 September 2026. The theft figure is from Ledger Academy (15 Jul 2026). Live data: /api/state.