The Agent Treasury
October 2026
If an autonomous economic agent earns, receives, or controls value over time, how should that value be held, preserved, allocated, and governed?
The question sounds like it begins with an answer. It does not. The existence of an agent treasury is itself a hypothesis. An agent that controls a wallet balance does not necessarily possess a treasury. A persistent software balance is not retained earnings. Technical control over assets is not economic ownership. And automated allocation is not autonomous financial judgment.
This investigation begins not with Bitcoin or stablecoins or DeFi protocols, but with the demand side. Why would an agent need to retain capital? At what level of economic agency does the question become meaningful? And what does the evidence actually show?
The answer, it turns out, is that the dominant emerging architecture is bounded treasury autonomy: humans define objectives and risk policy, agents forecast liquidity and execute within limits, humans retain ultimate authority. Every production system we examined enforces this pattern. No credible evidence exists of Level 3 agents independently retaining and allocating capital at meaningful scale.
Key Findings
- A treasury is economically distinct from a wallet, budget, or payment balance. A wallet is an access and control abstraction. A budget constrains spending. A treasury requires persistent capital, future obligations, allocation decisions across time, and risk management. The minimum conditions for an agent treasury are retained surplus, temporal continuity, and at least one allocation decision.Corporate treasury AI agents are moving from assistance to transactional authority in 2026, with banks integrating agentic AI as semi-autonomous co-workers for routine trades and compliance.PYMNTS, 2026Note: C
- Bounded treasury autonomy, where humans define policy and agents execute within limits, is the dominant emerging architecture. Every observed production system (Coinbase Agentic Wallets, Ramp Agent Cards, Stripe Issuing, Fireblocks) implements operator-configured spending limits. No production system grants unrestricted financial discretion to an agent.Coinbase Agentic Wallets (launched Feb 2026) provide programmable spending limits: session caps (maximum per agent run) and transaction limits (per-payment caps), configured by operators at wallet-creation time. MPC custody in AWS Nitro Enclaves.Coinbase, 2026-02Note: OStripe Issuing for Agents provides delegated spending via Link balance, with single-use card creation and per-card controls (merchant restrictions, MCC blocklists, daily/monthly caps). Stripe explicitly compares this to how corporate treasury departments work.Stripe, 2026Note: SFireblocks provides MPC custody with policy engine for AI agents: per-wallet and per-delegation rules enforcing spend limits, merchant allowlists, time windows, and asset constraints. Agents get scoped, revocable spending authority.Fireblocks, 2026Note: R
- Treasury becomes economically meaningful only at Level 3 (autonomous commerce). Autonomous commerce remains at $5,000-$11,000/month globally on crypto rails. At Levels 1 and 2, the apparent treasury is an enterprise budget, not an agent treasury.AI agent autonomous commerce remains at $5,000-$11,000/month globally on crypto rails per TRM Labs filtering (from Research 001). At this scale, the treasury question may be premature.TRM Labs, 2026-01Note: A
- Conventional financial infrastructure (banking APIs, treasury management systems, virtual cards) can satisfy most current agent treasury requirements without crypto-native infrastructure. Major banks offer machine-accessible treasury APIs. Agent-specific card products from Ramp and Stripe replicate corporate treasury delegation patterns.US Bank, Wells Fargo, Deutsche Bank and others offer treasury management APIs (RESTful) for account activity, FX, payments, and cash management. Open banking is enabling corporate treasury connectivity for machine access.US Bank, Wells Fargo, Deutsche Bank, 2026-01Note: BRamp's Agent Cards provide virtual cards for AI agents with per-card limits, merchant controls, and MCC blocklists. Average monthly AI token spend by Ramp customers increased 13x since January 2025.Ramp, 2026Note: A
- Stablecoins possess properties suitable for agent operating capital (stable denomination, programmability, 24/7 settlement), but issuer risk and regulatory uncertainty limit their role as long-duration reserves. USDC's reserve quality is strong (BlackRock-managed, SEC-registered), but freeze authority remains.USDC is backed by cash and short-dated US Treasuries in the Circle Reserve Fund, a SEC-registered 2a-7 government money market fund managed by BlackRock and custodied at BNY Mellon. ~$78B circulating supply by April 2026.Circle, BlackRock, 2026-04Note: U
- Bitcoin's volatility (40-80% annualized) makes it unsuitable as agent operating capital. A long-duration reserve role is theoretically coherent but entirely unobserved. No autonomous agent has independently chosen to hold Bitcoin as a reserve asset.Strategy (formerly MicroStrategy) holds 846,000 BTC (~$63.94B cost basis) as of June 2026. Bitcoin Treasury 2.0 model involves active balance sheet management, yield generation, and digital credit.Various financial sources, 2026-06Note: C
- Prompt injection represents a fundamental constraint on treasury autonomy. External information can become unintended financial authority. Until prompt injection is reliably solved, broad treasury discretion creates unacceptable risk. Policy engine isolation is architecturally necessary.Prompt injection attacks surged 340% YoY per Cisco, ranking #1 on OWASP Top 10 for LLM Applications. Financial services reports 21% vulnerability rate. Injection payloads embedded in web pages can include payment transaction details directing agents to execute unauthorized transactions.Cisco/OWASP, 2026Note: P
- Legal liability for agent financial actions falls on the deploying organization. No jurisdiction recognizes AI agent financial independence. This constrains rational delegation of treasury discretion: organizations will not grant financial authority they cannot monitor, override, and be held accountable for.Legal liability for AI agent financial errors falls on the deploying organization, not the agent. CMA (UK): business responsible for agent actions. California AB 316 (Jan 2026): cannot claim AI autonomously caused harm. EU Product Liability Directive classifies AI as product.CMA, California Legislature, European Commission, 2026-01Note: L
Defining Agent Treasury
Before evaluating architectures or assets, the concept must be defined. A treasury should not be inferred merely because software controls a balance.
The distinction matters because most systems described as "agent treasury" are actually wallets with spending limits (Level 2 delegated authority) or automated cash management executing fixed rules. A treasury requires economic judgment about how to preserve and deploy capital, not merely the technical ability to move it.
The minimum conditions for an agent treasury to be a useful economic concept: retained surplus beyond immediate operating needs, temporal continuity of capital across transactions, and at least one allocation decision about how that surplus should be preserved or deployed.
The Demand Side
The investigation begins not with assets or protocols but with the question: why would an agent need to retain capital?
Observed requirements
Corporate treasury AI agents currently manage: cash sweeps (moving excess balances to money-market instruments), payable prioritization (ordering payments by due date and cash position), credit line draws (tapping revolving credit when liquidity is low), and continuous monitoring against liquidity targets.Corporate treasury AI agents automate cash sweeps, payable prioritization, credit line draws, and maintain liquidity targets using treasury-defined rules applied to shifting conditions. These operate on behalf of the CFO/treasurer, not autonomously.ChatFin, 2026-01Note: T These are real treasury functions, but they operate under human-defined policy. The agent executes, it does not determine.
Foreseeable requirements
An agent that earns revenue (Level 3) would need to manage: operating expenses (compute, data, APIs), payment obligations (refunds, contractual commitments), liquidity buffers (unpredictable expenses), and cross-border obligations (multi-currency settlement). Each of these could justify capital retention.
The principal-funding alternative
For each potential requirement, a critical question: could the principal simply fund the expense when required? An enterprise budget, a prepaid balance, or a virtual card with sufficient limits can substitute for agent-held capital. The case for an independent agent treasury requires demonstrating that persistent agent-controlled capital provides an actual economic advantage over just-in-time principal funding.
At $5,000-$11,000/month of total Level 3 autonomous commerce, the revenue base that could generate retained surplus is negligible. The treasury question may be premature until Level 3 commerce reaches meaningful scale.AI agent autonomous commerce remains at $5,000-$11,000/month globally on crypto rails per TRM Labs filtering (from Research 001). At this scale, the treasury question may be premature.TRM Labs, 2026-01Note: A
Treasury Across Economic Agency Levels
Using the economic agency framework from Research 001, treasury requirements differ sharply by level:
| Level | Financial relationship | Treasury requirement | Who controls capital |
|---|---|---|---|
| 1. Operator-billed | Enterprise pays AI vendor | None. Agent is a cost center. | Enterprise treasury |
| 2. Delegated payment | Agent spends within limits | Budget, not treasury. Principal funds and constrains. | Principal, via spending limits |
| 3. Autonomous commerce | Agent earns, retains, allocates | Potentially meaningful. Requires retained surplus. | Contested. See ownership analysis. |
At Level 1, no agent treasury exists. The enterprise pays the bill. At Level 2, the apparent treasury is the principal's budget, delegated to the agent via spending limits.Coinbase Agentic Wallets (launched Feb 2026) provide programmable spending limits: session caps (maximum per agent run) and transaction limits (per-payment caps), configured by operators at wallet-creation time. MPC custody in AWS Nitro Enclaves.Coinbase, 2026-02Note: ORamp's Agent Cards provide virtual cards for AI agents with per-card limits, merchant controls, and MCC blocklists. Average monthly AI token spend by Ramp customers increased 13x since January 2025.Ramp, 2026Note: A Treasury becomes a meaningful concept only at Level 3, where the agent generates revenue and faces decisions about retaining, preserving, and deploying surplus.
This creates a dependency: meaningful agent treasury requires meaningful Level 3 autonomous commerce. If Level 3 does not emerge at scale, the agent treasury question resolves to "enterprise budgets managed by AI-assisted treasury tools." That outcome is Scenario A.
The Treasury Autonomy Spectrum
Treasury autonomy is not binary. The evidence reveals a spectrum, and current systems cluster at the lower end:
Every production system examined (Coinbase, Ramp, Stripe, Fireblocks, corporate treasury AI) operates at the observation-through-policy-bounded-allocation levels. The Talos protocol on Arbitrum claims discretionary allocation, but at $2.8M and within pre-defined risk parameters, it is closer to policy-bounded allocation than genuine economic autonomy.Talos, launched July 23, 2026 on Arbitrum, is described as the first fully autonomous treasury protocol. AI vault manager in a TEE manages $2.8M across six DeFi strategies with 22.9% annualized return.Arbitrum Foundation, 2026-07Note: $
Whose Money Is It?
Research 004 established three distinct concepts: technical control, economic control, and legal ownership. For any proposed agent treasury:
- Who legally owns the assets? In every observed system: the deploying organization or its principal. No jurisdiction grants AI agents property rights.
- Who controls the credentials? The operator configures wallet credentials. Coinbase MPC keys are split across AWS Nitro Enclaves and the CDP platform. Fireblocks policy engine governs signing authority.
- Who defines treasury policy? The human principal or organization. Spending limits, asset allowlists, and risk parameters are configured at wallet creation, not by the agent.
- Who can revoke authority? The operator, at any time. Every observed platform provides kill switches, emergency freezes, and operator override.
- Who bears losses? The deploying organization. Legal liability falls on the deployer (CMA UK, California AB 316, EU Product Liability Directive).Legal liability for AI agent financial errors falls on the deploying organization, not the agent. CMA (UK): business responsible for agent actions. California AB 316 (Jan 2026): cannot claim AI autonomously caused harm. EU Product Liability Directive classifies AI as product.CMA, California Legislature, European Commission, 2026-01Note: L
- Who receives residual assets if the agent is terminated? The principal. An agent has no legal claim to surplus. The ElizaOS foundation's remaining treasury was transferred to class-action plaintiffs upon shutdown.ElizaOS introduced a Generative Treasury where AI agents deploy capital to generate yield and enhance ecosystem liquidity. However, ElizaOS collapsed 99.9% from its $2.6B peak after a class-action settlement and foundation shutdown in August 2026.ElizaOS, 2026-08Note: T
An agent may exercise treasury discretion without owning the underlying capital. This is analogous to a fund manager: the manager makes allocation decisions, but the capital belongs to investors. The distinction matters because it determines who bears risk, who pays taxes, who satisfies liabilities, and who ultimately governs the treasury.
Treasury Architecture
The bounded treasury architecture emerging across platforms follows a consistent pattern:
The critical architectural insight is that the policy engine must operate outside the LLM's context window. If treasury policy is enforced by the same language model that processes external information, prompt injection can bypass financial controls. Fireblocks, Coinbase, and Stripe all implement policy enforcement in separate infrastructure layers.Prompt injection attacks surged 340% YoY per Cisco, ranking #1 on OWASP Top 10 for LLM Applications. Financial services reports 21% vulnerability rate. Injection payloads embedded in web pages can include payment transaction details directing agents to execute unauthorized transactions.Cisco/OWASP, 2026Note: PFireblocks provides MPC custody with policy engine for AI agents: per-wallet and per-delegation rules enforcing spend limits, merchant allowlists, time windows, and asset constraints. Agents get scoped, revocable spending authority.Fireblocks, 2026Note: R
Transaction Asset vs. Treasury Asset
Research 001 and Research 006 established that what an agent transacts in may differ from what it retains. This distinction is central to treasury analysis. An agent could:
- Transact in stablecoins, retain stablecoins (simplest)
- Transact in stablecoins, retain Bitcoin (requires conversion)
- Transact over Lightning, retain Bitcoin (native)
- Transact through fiat rails, retain bank deposits (conventional)
- Transact across multiple rails, retain a diversified portfolio
The relevant question is not "what asset will agents hold?" but "what asset best performs each treasury function?" Different obligations may require different assets:
Operating capital
Required properties: liquidity, price stability, payment readiness, low conversion friction.
Candidates: stablecoins, bank deposits, platform credits.
Liquidity buffer
Required properties: immediately available, low volatility, minimal counterparty risk.
Candidates: bank deposits, money-market funds, stablecoins.
Reserve capital
Required properties: long-duration preservation, resistance to purchasing-power erosion.
Candidates: government securities, tokenized Treasuries (BUIDL), potentially Bitcoin for very long durations.Tokenized US Treasuries reached $15B in 2026. BlackRock BUIDL holds ~$2.48B AUM across 8+ networks. Franklin Templeton BENJI on 9+ chains. Both hold short-duration US government securities and are machine-accessible via smart contracts.BlackRock, 2026Note: T
Stablecoins as Treasury Assets
The case for
Stablecoins offer properties aligned with agent operating capital: stable nominal denomination in a globally accepted unit, machine-native programmability, 24/7 transfer and settlement, and compatibility with emerging machine-payment protocols (x402, Stripe MPP). USDC's reserves are held in a SEC-registered money market fund managed by BlackRock and custodied at BNY Mellon, providing institutional-grade backing.USDC is backed by cash and short-dated US Treasuries in the Circle Reserve Fund, a SEC-registered 2a-7 government money market fund managed by BlackRock and custodied at BNY Mellon. ~$78B circulating supply by April 2026.Circle, BlackRock, 2026-04Note: U Over $35B in organizational stablecoin reserves demonstrate real institutional adoption.Public companies, DAOs, fintechs, and crypto-native businesses collectively hold >$35B in on-chain stablecoin reserves as of Q1 2026. Treasurers manage 3-7 chains, 2-4 stablecoin issuers. Yield ranges from 4.1-11.8% APY.Eco, various sources, 2026-03Note: O
The case against
Stablecoins carry issuer-level counterparty risk. Circle has frozen USDC addresses. Regulatory frameworks (GENIUS Act) require stablecoin custody through regulated entities, routing infrastructure through traditional banking.GENIUS Act (signed into law) establishes federal stablecoin regulation. Custody of payment stablecoin reserves requires supervision by Federal or State financial regulator. Reserves must be treated as customer property, separately accounted, not commingled.US Congress, 2026-01Note: RThe GENIUS Act requires entities that custody payment stablecoin reserve assets to be subject to supervision by a Federal or State financial regulator, to treat covered assets as customer property, and to separately account for them.US Congress, 2026-01Note: A Stablecoins are denominated in fiat and therefore subject to inflation over long holding periods. And an agent cannot be a regulated custodian, meaning stablecoin reserves held on behalf of agents require intermediated custody.
The strongest case for stablecoins is as operating capital: short-duration, high-liquidity, payment-ready funds. The case weakens for long-duration reserves, where counterparty risk compounds and inflation erodes purchasing power.
Bitcoin as a Treasury Asset
The case for
Bitcoin's properties (scarce supply, absence of centralized issuer, global transferability, machine-compatible custody) are theoretically aligned with a long-duration reserve role. Strategy (formerly MicroStrategy) holds 846,000 BTC (~$63.94B cost basis) as a corporate reserve, demonstrating institutional acceptance of Bitcoin as a treasury asset.Strategy (formerly MicroStrategy) holds 846,000 BTC (~$63.94B cost basis) as of June 2026. Bitcoin Treasury 2.0 model involves active balance sheet management, yield generation, and digital credit.Various financial sources, 2026-06Note: C
The case against
Bitcoin's 40-80% annualized volatility creates a structural problem for agents with short-duration obligations. An agent that pays compute bills monthly cannot tolerate 50% drawdowns in its operating capital. Accounting, tax, and regulatory treatment add complexity. And critically: no autonomous agent has independently chosen to hold Bitcoin. Every Bitcoin treasury decision in the observed record is human-directed. Corporate Bitcoin holdings demonstrate human conviction, not machine demand.
The proposition that machines might evaluate volatility differently from humans is theoretically interesting but empirically empty. A long-duration Bitcoin reserve role for agents with very long time horizons (years, not months) is not falsified, but it is entirely undemonstrated.
The Conventional Treasury Challenge
The investigation must ask: what problem does an independent agent treasury solve that delegated access to conventional treasury infrastructure cannot solve sufficiently?
The conventional stack is formidable. US Bank, Wells Fargo, and Deutsche Bank offer RESTful treasury management APIs for account activity, foreign exchange, and payments.US Bank, Wells Fargo, Deutsche Bank and others offer treasury management APIs (RESTful) for account activity, FX, payments, and cash management. Open banking is enabling corporate treasury connectivity for machine access.US Bank, Wells Fargo, Deutsche Bank, 2026-01Note: B Ramp and Stripe have shipped agent-specific virtual card products with programmatic controls.Ramp's Agent Cards provide virtual cards for AI agents with per-card limits, merchant controls, and MCC blocklists. Average monthly AI token spend by Ramp customers increased 13x since January 2025.Ramp, 2026Note: AStripe Issuing for Agents provides delegated spending via Link balance, with single-use card creation and per-card controls (merchant restrictions, MCC blocklists, daily/monthly caps). Stripe explicitly compares this to how corporate treasury departments work.Stripe, 2026Note: S Enterprise resource planning systems integrate cash management with budgeting. Money-market funds provide yield on idle balances. And all of this operates within established legal, regulatory, and accounting frameworks.
The gaps in conventional infrastructure are real but narrow: 24/7 settlement (banks close on weekends), global permissionless access (bank accounts require identity verification), and micropayment economics (card fees impose a floor). Crypto-native treasury infrastructure addresses these gaps. But the gaps affect a small subset of agent treasury functions, and they may narrow further as real-time payment networks (FedNow), open banking APIs, and tokenized deposits expand.
Treasury Security: Prompt Injection as Financial Risk
The security analysis reveals a specific, urgent constraint on agent treasury autonomy: prompt injection as a financial-control problem.
Prompt injection attacks surged 340% year-over-year in 2026, ranking #1 on OWASP's Top 10 for LLM Applications for two consecutive editions. In financial services, 21% of audited deployments showed vulnerability. Documented attack vectors include injection payloads embedded in web pages containing fully specified payment transaction details with instructions for AI agents to execute unauthorized transfers.Prompt injection attacks surged 340% YoY per Cisco, ranking #1 on OWASP Top 10 for LLM Applications. Financial services reports 21% vulnerability rate. Injection payloads embedded in web pages can include payment transaction details directing agents to execute unauthorized transactions.Cisco/OWASP, 2026Note: P
The treasury-specific implication: if an agent can read financial data from external sources (price feeds, invoices, counterparty information) and that same agent controls financial execution, then any compromise of the information pipeline becomes a financial-control compromise. A malicious invoice could instruct the agent to redirect payment. A poisoned price feed could trigger adverse trades. A compromised API could manipulate allocation decisions.
The architectural response, implemented by Fireblocks, Coinbase, and Stripe, is policy engine isolation: treasury policy is enforced in infrastructure separate from the LLM's context window. The agent can propose actions. The policy engine validates them against pre-configured rules before execution. External information cannot directly become financial authority.
Observed Agent Treasuries
The investigation identified two categories of claimed autonomous treasury: crypto-native protocols and corporate treasury AI. Neither clearly qualifies as Level 3 autonomous agent treasury.
Talos (Arbitrum)
Talos is described as the first fully autonomous treasury protocol. An AI vault manager running in a TEE allocates $2.8M across six DeFi strategies on Arbitrum with a reported 22.9% annualized return. However: it was incubated by the Arbitrum Foundation (conflict of interest), strategies operate within pre-defined risk parameters (policy-bounded, not unrestricted), and $2.8M is trivially small. Whether the AI exercises genuine discretion or sophisticated rule-based optimization is unclear from available evidence.Talos, launched July 23, 2026 on Arbitrum, is described as the first fully autonomous treasury protocol. AI vault manager in a TEE manages $2.8M across six DeFi strategies with 22.9% annualized return.Arbitrum Foundation, 2026-07Note: $
ElizaOS Generative Treasury
ElizaOS introduced a Generative Treasury where AI agents deploy capital to generate yield. DegenSpartanAI was the flagship autonomous trading agent. However, ElizaOS collapsed 99.9% from its $2.6B peak after a class-action settlement. The foundation's remaining treasury was transferred to plaintiffs, and the foundation shut down in August 2026. This demonstrates that "autonomous" treasuries remain ultimately governed by legal claims and human-controlled settlements.ElizaOS introduced a Generative Treasury where AI agents deploy capital to generate yield and enhance ecosystem liquidity. However, ElizaOS collapsed 99.9% from its $2.6B peak after a class-action settlement and foundation shutdown in August 2026.ElizaOS, 2026-08Note: T
Corporate treasury AI
Corporate deployments (reported by BCG, PYMNTS, ChatFin) automate cash sweeps, payable prioritization, and liquidity monitoring. These are real and valuable, but they operate under human-defined policy as Level 2 delegated authority. The agent is a treasury tool, not an autonomous treasury actor.Corporate treasury AI agents are moving from assistance to transactional authority in 2026, with banks integrating agentic AI as semi-autonomous co-workers for routine trades and compliance.PYMNTS, 2026Note: CBCG reports leading companies direct over 50% of 2026 AI corporate investment to agents, with one-third of enterprises scaling agentic deployments. However, only 11% of organizations run agents at genuine scale per McKinsey.BCG/McKinsey, 2026Note: I
Attribution assessment
Applying the attribution discipline from Research 001: no observed system satisfies all conditions for Level 3 autonomous agent treasury. Talos comes closest but is small-scale, governance-bounded, and attribution-ambiguous. Corporate treasury AI is clearly Level 2. The ElizaOS case is a cautionary tale about the gap between "autonomous treasury" branding and economic reality.
Competing Hypotheses
H1: No independent treasury
Most agents never develop independent treasuries. Principals continue owning and governing capital. Agents receive budgets and execute policy.
Evidence: Legal liability routing, $5K-$11K autonomous commerce scale, Level 2 dominance, prompt injection constraints.
H2: Bounded operating treasury
Agents develop bounded operating treasuries for liquidity management, while humans retain reserve and investment authority.
Evidence: Coinbase/Ramp/Stripe/Fireblocks architectures, corporate treasury AI deployments, policy engine pattern.
H3: Stablecoins as operating capital
Stablecoins become important operating-capital assets for digitally native agents due to programmability, 24/7 settlement, and global access.
Evidence: USDC reserve quality, $35B+ organizational stablecoin reserves, GENIUS Act framework. Counter: issuer risk, regulatory routing through banks.
H4: Bitcoin reserve role
Bitcoin develops a reserve role for some autonomous agents while other assets handle operating liquidity.
Evidence: Corporate Bitcoin treasury precedent (Strategy). Counter: no observed autonomous agent Bitcoin demand, volatility, liability mismatch.
H5: Treasury abstraction
Treasury abstraction makes the underlying asset increasingly invisible to the agent. The policy engine selects assets; the agent interacts with economic objectives.
Evidence: Payment abstraction trend (Research 006), policy engine architectures. Counter: abstraction requires mature multi-asset infrastructure.
H6: Conventional infrastructure dominates
Banks and treasury management systems adapt sufficiently to support machine-managed treasury without crypto-native infrastructure.
Evidence: Banking APIs, Ramp/Stripe agent products, 13x AI spend growth via conventional rails. Counter: 24/7, micropayment, and global-access gaps.
The evidence best supports H2 (bounded operating treasury) and H6 (conventional infrastructure adaptation) for the near term, with H3 (stablecoin operating capital) as a plausible complement. H1 (no independent treasury) cannot be rejected at current evidence levels. H4 (Bitcoin reserve) and H5 (treasury abstraction) are coherent but undemonstrated.
The Null Hypothesis
The null hypothesis deserves serious consideration: autonomous agents never require independent treasuries.
In this scenario: principals retain all capital. Agents receive enterprise budgets. Virtual cards with programmatic limits handle delegated spending. Corporate treasury remains centralized, with AI tools improving efficiency but not shifting authority. Financial institutions expose machine-accessible APIs. Human organizations retain investment authority.
Supporting evidence is substantial. At $5,000-$11,000/month of autonomous commerce, the revenue base for agent surplus is negligible. Every production system enforces human policy. Legal liability prevents rational delegation of broad financial authority. Prompt injection creates unacceptable risk for unguarded treasury access. Conventional infrastructure is adapting rapidly.
The null hypothesis resolves to Scenario A (Banked Agents) or Scenario D (Non-Event). It is not a strawman. It may be the most likely near-term outcome.
Implications for the Four Futures
| Scenario | Treasury implication | Evidence direction |
|---|---|---|
| A: Banked Agents | Existing institutions expose machine-accessible treasury infrastructure. Agents operate as delegated treasury tools under human governance. Banking APIs, virtual cards, and enterprise budgets absorb agent financial needs. | Strong support. Banking APIs exist. Agent-specific products shipped. Corporate treasury AI deploys on conventional infrastructure. |
| B: Stablecoin Internet | Stablecoins become significant operating capital for autonomous agents. Programmability and 24/7 settlement provide advantages over conventional treasury. USDC reserve quality supports institutional adoption. | Moderate support for operating capital. Weaker for reserves. Regulatory framework (GENIUS Act) routes through banks. |
| C: Satoshi Economy | Bitcoin acquires a meaningful reserve or capital preservation role within autonomous machine economies. Long-duration holding absorbs volatility. | Weak support. Corporate Bitcoin treasury is human-directed. No autonomous agent Bitcoin demand observed. Volatility and liability mismatch are structural constraints. |
| D: The Non-Event | Autonomous agents remain too limited to accumulate or independently manage meaningful capital. Treasury is always the principal's responsibility. | Consistent with current evidence. $5K-$11K/month commerce. Legal liability on deployers. Prompt injection constraints. Bounded autonomy dominates. |
What Would Change Our Mind
We would revise the bounded-treasury-dominance finding if a production system demonstrated superior outcomes from unrestricted agent treasury control at meaningful scale (>$100M in managed assets) compared to policy-bounded alternatives.
We would reconsider the treasury-requires-Level-3 finding if Level 2 agents demonstrably developed treasury functions (retained surplus, allocation decisions) that exceeded the explanatory power of "delegated budget."
We would reassess the conventional-infrastructure-sufficiency finding if autonomous agents demonstrated treasury requirements that banking APIs, virtual cards, and enterprise systems could not satisfy at competitive cost.
We would reconsider the prompt-injection constraint if reliable defenses were deployed and validated in adversarial financial conditions, removing the architectural argument for policy engine isolation.
We would reassess the Bitcoin reserve hypothesis if an autonomous agent demonstrably held Bitcoin as a long-duration reserve and this produced measurable treasury benefit relative to alternatives.
What We Know and What We Don't
Known
- Software can technically control persistent balances and execute policy-constrained financial actions.
- Every production system implements bounded authority with human-defined policy.
- Legal liability for agent financial actions falls on the deploying organization.
- Prompt injection remains an unsolved model-layer problem with demonstrated financial attack vectors.
- Autonomous agent commerce is negligibly small ($5K-$11K/month).
- Conventional financial infrastructure is adapting for machine access.
- Tokenized Treasuries and stablecoins provide machine-accessible cash-equivalent instruments.
Unknown
- Whether Level 3 autonomous commerce will reach sufficient scale to generate meaningful retained surplus.
- Whether agents will require independent treasury functions or whether principal-funded budgets are always sufficient.
- Whether treasury abstraction will render the underlying asset choice secondary to policy engine design.
- Whether any jurisdiction will create legal frameworks recognizing limited agent financial independence.
- Whether correlated agent treasury behavior could create systemic financial risks at scale.
- Whether Bitcoin's properties produce measurable treasury benefit for machine actors over long durations.
- The optimal boundary between agent treasury discretion and human policy control.
Dependencies and Handoffs
This investigation builds on:
- Research 001: Economic agency framework, transaction vs. reserve distinction, $5K-$11K finding.
- Research 002: Wallet as access/control abstraction. Treasury is a layer above wallets.
- Research 003: Identity vs. authority. Treasury policy as machine-readable authorization.
- Research 004: Technical control vs. economic control vs. legal ownership.
- Research 005: Persistent autonomous organizations and capital formation.
- Research 006: Transaction asset vs. reserve asset distinction.
Handoffs to future investigations:
- Research 008 (When Agents Hire Agents): Agent-to-agent payment obligations may create working capital requirements that drive treasury demand.
- Research 009 (Credit Without Humans): Borrowing, collateral, and creditworthiness create treasury obligations requiring asset/liability management.
- Research 010 (Machine Capital Markets): Investment allocation, yield optimization, and portfolio construction are treasury-adjacent but distinct from capital preservation.