Ai Agents

Three Pillars for Bringing Agentic AI into Production
reading time: 13 minutes
Three Pillars for Bringing Agentic AI into Production

The current AI transition is often described as a revolution in software development.

Large language models generate code, tests, documentation and integrations. Natural language is increasingly becoming an interface to software construction, and development is becoming faster and cheaper.

But this is still, fundamentally, the traditional software model:

Requirement
Developer + AI
Code
Application
User
Outcome

AI has accelerated the construction of the application.

The AI Agent Economy Cannot Be Trusted: What Agency Theory Teaches, and Where Runtime Authority Needs a Different Instrument
reading time: 21 minutes
The AI Agent Economy Cannot Be Trusted.
Economics offers incentives, monitoring, delegation and control. Runtime software can also make some invalid authority states rejectable at the receiving boundary.

Economics has studied agency under asymmetric information for more than fifty years. Stephen Ross gave an early formal treatment of the principal-agent problem in 1973. Jensen and Meckling’s 1976 paper defined agency costs and integrated agency theory with property rights and finance to analyze ownership structure. Holmström, Grossman, Hart, Moore, Tirole and many others subsequently developed major parts of contract and organization theory. Work in this broader tradition later received Nobel recognition, including the 2016 prize to Oliver Hart and Bengt Holmström for contributions to contract theory.

From Hardy’s Compiler to Hardy’s AI Agent: When the Threat Model Changes, the Confused Deputy Returns
reading time: 87 minutes
From Hardy’s Compiler to Hardy’s AI Agent.
From Hardy’s Compiler to Hardy’s AI Agent.

The question. This article examines one narrowly defined security property: whether authority propagated across time and multiple execution boundaries remains verifiably attributable to the concrete execution and request for which it was granted.

The change of question in authority propagation: from actor selection to execution continuity

One scope condition should be kept in mind throughout this article: the following discussion of who concerns only the propagation of authority after initial authentication and authority origination. It addresses what happens when already-established authority is handed off, exchanged, resumed, attenuated, or otherwise continued across a later execution boundary. It does not claim that identity is unnecessary for authentication, initial authorisation, eligibility, accountability, revocation, or other security properties.

Trusting AI Agents, Who Is Acting?
reading time: 10 minutes
Sample Work Pool
Who Is Acting?

AI agent security is usually approached as an identity problem: the question becomes “what is the agent’s identity, and what is it allowed to do?”. This framing is inherited from decades of human-centric and client-centric authorization design, and it works reasonably well as long as the entity being authorized is stable, persistent, and accountable in its own right. AI agents are none of those things in practice, and the framing produces a steady accumulation of edge cases that identity-centric security models keep trying to patch without changing the underlying assumption.

LFDT - Trusted AI Agents by Design: From Trust Ecosystems to Authority Continuity
reading time: 1 minute

On March 3, 2026, LF Decentralized Trust hosted the session “Trusted AI Agents by Design: From Trust Ecosystems to Authority Continuity”, presented by Nicola Gallo.