Blog

6 Turnkey experts weigh in on AI agents: Autonomy, security, and trust

Resources
·
·
Jeremy DuCheny
Technical Content Manager at Turnkey

About: Six Turnkey experts share their views on where AI agents are headed, what greater autonomy will require, and why security, verifiability, and programmable controls matter as agents take on more responsibility.

Audience: AI agent builders, wallet teams, crypto applications, infrastructure providers, and developers building systems that give autonomous agents access to credentials, tools, and money.

What you’ll learn:
  • Why the infrastructure around an agent can matter as much as the model itself
  • How programmable money could enable agents to become economic actors
  • Why permissions and security controls need to live outside the model
  • How verifiable infrastructure can help users trust increasingly autonomous agents

Reading time: ~9 minutes

AI agents already write code, call tools, manage credentials, and transact on a user's behalf. Now the focus is shifting to what it takes to give these systems more autonomy without giving up control.

The people building Turnkey have been talking publicly about that shift for years. Across hundreds of posts on X, a few ideas come up again and again: agents will become more autonomous and the infrastructure around it will determine how far we can safely let agents go.

Who is speaking

Six Turnkey builders on where AI is going

Each of these thought leaders has written regularly about AI, crypto, infrastructure, and what they’re building over the years. And they’re definitely worth following if you want to keep up with the broader conversation.

Below, we’ve pulled together some of their thoughts on where AI agents are headed, the infrastructure they’ll need, and the challenges that come with giving them more autonomy.

1. The agent is one part of a much larger ecosystem

-
Agents should do things, not live in chat windows
“Agents are supposed to do things for you, not make you type and read.”
Conner Swann@YourBuddyConnerStaff engineer leading applied AI, TurnkeyApril 12, 2023 on X

In 2023, Conner Swann, Staff Engineer leading applied AI at Turnkey, argued that chat was the wrong abstraction for software designed to act.

  • “Anyone putting LLM agents behind the typical Chatbot UI is doing their users a disservice. Agents are supposed to do things for you, not make you type and read.”

Three years later, his description of a persistent agent looks much more like an operating system than a chatbot: a long-running process with filesystem memory, scheduled work, sandboxed child agents, separate policies, and credentials kept outside the model.

  • “a persistent agent is not a longer chat. ... vector embeddings make the next message right and the next week wrong. ... the model's job is what should i do. the policy layer's job is what am i allowed to do. these are different programs.”

That distinction for an agent between what should I do? and what am I allowed to do? becomes one of the most important ideas in the entire collection.

The harness matters as much as the model

The same principle applies to agent tooling.

Conner has argued that protocols such as MCP are useful only if they remain open, while also pointing toward a simpler interface that software engineers already understand: command-line tools.

  • “MCP without open access is just a walled garden with a protocol logo on it.”
  • “give agents CLIs and local tools instead of hosted APIs the intuition makes sense. unix has worked this way since the beginning.”

And even a strong model performs poorly without the right system around it.

  • “the harness is half the battle, without a good one these OSS models are pretty useless I hate to say”

The model may get most of the attention, but these posts consistently place more long-term value in the infrastructure around it.

2. Agents are becoming economic actors, but this works only if their authority has clear boundaries

For Turnkey, when agents are moving money, there’s more that’s needed than just allowing them to transact onchain. Specifically, the infrastructure that these autonomous systems use  need to be just as programmable as the agents themselves. 

Our economy will increasingly become agentic
“Agents & programmatic transactions will eclipse human transactions, and we need the right guardrails in place for that eventuality.”
Bryce@sadbryceCo-founder and CEO, TurnkeySept. 21, 2026 on X

Our economy will increasingly become agentic

Bryce Ferguson, Co-founder and CEO of Turnkey, has been making the same high-level prediction since 2024:

  • “Agents & programmatic transactions will eclipse human transactions, and we need the right guardrails in place for that eventuality.”

A big part of the case for crypto is that it gives software something traditional financial systems were not designed around: money that can be moved, routed, and governed programmatically. For an agent, that means it can discover a service, pay for it, interact with onchain applications, and keep executing without waiting for a person to step in at every stage.

That is why Bryce keeps coming back to programmability as the connective tissue between AI agents and crypto:

  • “it's so obvious that crypto will be the infra of choice for AI agents. Programmable, open, borderless, suitable for microtransactions, interoperable with defi protocols”
  • “With crypto and AI colliding, money becomes frictionless AND infinitely programmable. I think people are underestimating how big this is going to get.”

That is the case Bryce also makes for x402, for example, which allows a server to respond to a request with an HTTP 402 payment requirement.

Instead of signing up for accounts and subscriptions, an agent can discover a service, pay for exactly what it uses, and continue executing.

  • “x402 makes everything permissionless and agent-discoverable. agents only need to buy what they’re using. ... Permissionless commercialization + micropayments need crypto.”

The hard part is bootstrapping both sides of that market.

  • “crypto agentic commerce is facing the cold start problem. we need both: 1. demand: agents equipped with funded wallets 2. supply: products / services gated by x402 / MPP”
  • “People are underestimating the flood of activity we will see in crypto when we give every agent a wallet”

Zeke Mostov, a Founding Engineer at Turnkey, also expects adoption to accelerate once that loop begins.

  • “The winners of autonomous commerce have yet to be crowned. As agentic txn volume ramps up, the reinforcing loops will be strong and the transition will be fast”

More autonomy requires better controls

Giving every agent a wallet creates an obvious second problem: what is it allowed to do with it?

Bryce has compared the current moment to the early days of credit cards, when issuers distributed cards widely before fraud controls and underwriting caught up.

  • “Building the guardrails for agentic commerce is a trillion dollar opportunity. ... To control machine-based payments, we need new machine-based controls: cryptographic verifiability, escrow contracts, strict access policies, and human-in-the loop approvals.”

Requiring a person to approve everything defeats the point of using an autonomous system.

  • “2 of 2 approval on every purchase plainly defeats a key premise of autonomous commerce ... Automate 99% and only escalate w consensus when it's critical”

That tradeoff runs through nearly every section of Turnkey’s analysis: agents become useful when they can act independently, but independence only works if the boundaries around those actions are secure and enforceable.

3. More capable agents make security infrastructure increasingly more important

As agents gain access to wallets, APIs, production systems, and sensitive data, the cost of getting a decision wrong increases dramatically.

The recurring Turnkey view is that the model cannot also be the security boundary.

Attackers get AI too
“The barrier for attackers to compromise OpSec with AI is dropping. Teams need to level up their OpSec defenses just as quickly”
Michael Lewellen@LewellenMichaelCrypto solutions at Turnkey, previously OpenZeppelinApril 20, 2026 on X

Never make the model the last line of defense

Bryce was raising this problem in early 2025.

  • “It's going to take a long time before AI agents can be trusted with large amounts of crypto Just like self-driving cars, the margin for error is low (you don't want to lose your life savings to an AI hallucination).”
  • “It's only a matter of time until there's a massive hack of crypto AI agents. ... Developers need to study liability and put common sense controls in place to manage it.”
  • “Most AI agents are custodying funds and leveraging a key mgmt provider + verifiable compute can avoid that risk.”

The proposed architecture is straightforward: let the model decide what it wants to do, but enforce permissions somewhere the model cannot change.

  • “Agents need to be gated by policy OUTSIDE of the model. This is true not only for agents accessing crypto wallets, but also for any type of API key or secret.”
  • “Giving them unrestricted credentials and hoping they follow instructions is not a viable security model. ... credentials kept out of model context, action-scoped permissions, cryptographically enforced policies, human approvals, and complete auditability.”

Zeke describes the same problem from the user's perspective.

  • “when end-users onboard to agentic assistants, they lose sovereignty over their credentials”
  • “E2E workflow agents operating in production need perfectly scoped governance to pass security”
  • “The agentic era needs open, neutral, trust-minimized infra”

The goal is not to make an agent perfectly reliable. It is to make failure containable.

Attackers get AI too

The security challenge gets harder because defenders are not the only ones benefiting from better models.

Michael Lewellen, Head of Solutions Engineering at Turnkey, has spent years in smart contract security and sees AI lowering the cost of attacking systems at the same time it creates new defensive tools.

  • “The barrier for attackers to compromise OpSec with AI is dropping. Teams need to level up their OpSec defenses just as quickly”
  • “AI is creating new attack vectors but also new defenses. The war for DeFi security continues and isn't lost by any means.”

That makes the separation between intelligence and authority even more important. If an attacker can manipulate a model, compromise its inputs, or exploit the systems around it, the model should not automatically inherit the power to move assets. A separate control layer should still decide whether the action is allowed before anything gets signed or executed.

Users will also need proof‍

Users will also need proof
“TEEs attest to executables, not code! ... [I]f you can't map executables to their source code, remote attestations are useless: you won't trust the hash they attest to!”
Arnaud@arnaudbrousseauFounding engineer, Turnkey, previously CoinbaseOct. 11, 2024 on X

Permissions answer one question: what is this agent allowed to do?

Verifiability answers another: how do I know the system I was promised is actually the one running?

Bryce and his Co-founder and CTO at Turnkey, Jack Kearney, made that case from two sides in January 2025.

Bryce talks about the agent itself: users need a way to verify that the software they think is running is actually the software making decisions and taking actions.

  • “A lot of the agents we see today are "Wizard of Oz" agents (ht @hosseeb) since we have no way of verifying the code of them & humans are making unilateral changes behind the scenes. ... Verifiable compute solves this by allowing users to verify that the code that they THINK is running behind an agent is ACTUALLY running.”

Jack focuses on the infrastructure underneath that promise. Turnkey uses trusted execution environments (TEEs), isolated hardware environments that protect sensitive code and data while they are being used. But a TEE alone is not enough. The build and runtime also need to be reproducible and remotely attestable so users can verify what is actually executing.

  • “TEEs are worthless without: 1. Deterministic Builds: Otherwise you're delegating complete trust to a single machine (typically a CI pipeline) 2. Remote attestation”

Arnaud Brousseau, Founding Engineer at Turnkey, confirms this point:

  • “TEEs attest to executables, not code! ... [I]f you can't map executables to their source code, remote attestations are useless: you won't trust the hash they attest to!”

Bryce tied those ideas together directly:

  • “This is all going to happen way faster than people in crypto realize. We need verifiable AI agents deployed in TEEs.”

Extending the argument beyond AI agents, Jack sees verifiability becoming a broader expectation for digital systems. As software takes on more responsibility, users will increasingly want proof of what those systems are doing and how they are being operated.

  • “We'll look back on this era as the dark ages of auditability & verifiability online. Especially with the advent of AI, consumers will increasingly demand visibility into the companies & systems that control their digital lives.”
  • “Today this seems like a geeky feature shipped by an insanely security-conscious company. Tomorrow this will be viewed as table stakes for anyone that's delivering a digital product.”

The larger point is consistent: trust needs to be established technically, not assumed from what an application says it is doing.

4. It is the trust in AI and its infrastructure that may be the real adoption bottleneck

Users will also need proof
“Especially with the advent of AI, consumers will increasingly demand visibility into the companies & systems that control their digital lives.”
Jack@whojackjonesCo-founder and CTO, TurnkeyApril 18, 2025 on X

For all the discussion of capabilities, the final step toward widespread agent adoption may be much less technical.

People have to trust agents enough to hand them meaningful work.

Zeke makes that point while discussing Muse:

  • “Not on this list is trust ... once I started allowing it to do those tasks it totally won me over”

That trust will not come from models alone.

It will also depend on questions people are only beginning to encounter: What happens to the data an agent sees? Can it browse the internet on a user's behalf? Who is responsible when it causes harm? Who can change the system? What evidence can the user inspect?

Privacy and regulation follow capability

Zeke expects privacy and security concerns to become more important as people move past experimenting with what AI can do.

  • “My read is people are still just getting a hang of capabilities. Cost, security and privacy are second order and I expect/hope to see more interest later in 2027”

Conner has pointed to the hidden tradeoff behind "free" AI services:

  • “caveat that all of the free providers also train on your inferences and some also publish prompts sent to their free endpoints in open datasets free isnt always free”

There are legal questions too.

Bryce argues that existing rules do not simply disappear because an agent caused the damage:

  • “we're nearing regulatory clarity, not a lack of regulation if your AI agent rugs users for $100M, regulators are still going to care”

As agents move from answering questions to taking action, these questions become much harder to ignore.

4. It’s still difficult to predict how fast all of this will happen (but it’s happening fast)

Micropayments create a new kind of market
“The winners of autonomous commerce have yet to be crowned. As agentic txn volume ramps up, the reinforcing loops will be strong and the transition will be fast”
Zeke Mostov@ZekeMostovFounding engineer, TurnkeyAug. 4, 2026 on X

One thing almost everyone gets wrong about AI is timing.

Conner captured that feeling back in 2023:

  • “I thought ChatGPT on your computer with LLaMA was gonna take 3 months, took 2 hours from when I predicted this to an announcement of someone (@BrianRoemmele) having it working instead. ... I thought AGI was in 20 years, at this rate it will be next week”

The joke aged surprisingly well.

Since then, the constraint has repeatedly moved. First it was model capability. Then context. Then tools. Then coding. Now the harder questions increasingly involve memory, deployment, permissions, credentials, payments, trust, and verification.

The models keep improving, but more of the difficult engineering is moving outside them.

5. Agent autonomy depends on secure, verifiable infrastructure

Read together, these posts describe a fairly consistent architecture for the next generation of AI systems.

Agents become long-running processes that can use tools, write software, hold credentials, and transact. Models become increasingly interchangeable. More authority moves to software, which makes the controls around that authority more important.

Three ideas show up repeatedly across different people and different years:

  1. The model should be replaceable. Own the harness, tools, memory, routing, and interfaces around it.
  2. Permissions should live outside the model. An agent can decide what it wants to do without having unilateral authority to do it.
  3. Trust should be verifiable. Users should be able to verify the software, policies, and execution environments governing an agent rather than relying on a promise.

That’s also where these conversations connect most directly to Turnkey.

If agents are going to hold credentials and move money autonomously, the important question is not simply how intelligent they become. It is how much authority we can safely give them.

Turnkey: Secure infrastructure for humans building agents

Turnkey provides secure wallet, signing, and policy infrastructure for giving agents that authority within defined boundaries.

Teams can control what an agent can sign, where it can transact, how much it can spend, and when human approval is required, while keeping keys and enforcement outside the model itself.

Just as importantly, that security can be made verifiable. Turnkey uses secure execution environments, remote attestation, and reproducible infrastructure so developers can verify the systems protecting keys and enforcing policy, rather than simply trusting that those controls are in place.

That combination of programmable permissions and verifiable execution gives teams a way to build more autonomous agents without making the model itself the security boundary.

Get started with Turnkey today.


‍

Jeremy DuCheny
Technical Content Manager at Turnkey

Related articles

ERC-8004 by the numbers: Nearly 520K agent Identities now registered onchain

What nearly 520,000 ERC-8004 registrations reveal about the growth of onchain agent identity

What are agents buying in Coinbase’s x402 Bazaar discovery layer?

What AI agents buy through x402, how they discover and pay for services, and what current usage reveals about autonomous commerce.

Resources
September 17, 2026