Within a few years there will be more AI agents on the internet than there are people on Earth.
That sentence gets nodded at and then filed away, because it sounds like a statistic rather than a change. It isn’t a statistic. It’s a change in who the internet is for.
Every layer of the network we have was built for a human on the other end. Pages designed to be looked at. Interfaces designed to be learned. Business models built on attention, which is a uniquely human thing to spend. When the majority of traffic is generated by software acting on someone’s behalf, all of that becomes vestigial — and the layers that matter instead are the ones almost nobody is building: the ones that decide which model answers, whether the answer can be trusted, who owns the knowledge that made it good, and who gets paid.
At the same time the cost of intelligence is collapsing. Inference has been getting roughly twice as cheap every four months. Follow that curve out and the price of thinking stops being the interesting variable in anyone’s business.
When a resource becomes abundant, the question stops being how do I get it and becomes who controls the layer it runs through. That is the question this decade answers, and we are answering it right now, mostly by default.
Almost all intelligence today flows through a handful of corporate endpoints. That arrangement was reasonable when models were rare, enormous, and expensive to serve. It is becoming unreasonable fast, and it fails in five specific ways.
Bias and censorship. Models reflect the judgments of the people who train and tune them. That’s unavoidable. What’s avoidable is a world where a few organizations make those judgments for everyone, quietly, with each adjustment propagating instantly to every downstream application.
Governance. A small number of people currently make decisions that constrain millions of builders — what a model will discuss, what an agent may do, what gets deprecated next quarter. None of it is voted on and most of it isn’t announced.
Privacy and ownership. Every prompt sent to a centralized endpoint is a piece of proprietary context surrendered to someone else’s infrastructure. Companies are handing over their workflows, their documents, and their institutional knowledge, and receiving an API response in exchange.
Operational fragility. When one provider degrades, everything built on it degrades simultaneously. We’ve built the most important new infrastructure in a generation with a handful of single points of failure at its center.
Economics. The value flows to whoever owns the endpoint. The people who supply the knowledge that makes a model useful in a particular domain — the expert, the community, the company with twenty years of documentation — capture nothing.
None of these are arguments against the companies involved. They’re arguments about topology. Any network shaped like this produces these outcomes, no matter who’s running it.
“Agents” has become a word that means everything and therefore nothing. It’s more useful to see the range, because each step demands something different from the infrastructure underneath.
At one end are single-LLM features — summarization, classification, extraction. A model call inside a product. The infrastructure requirement is a good model and an API key.
Then workflows: several model calls orchestrated by code, where a human wrote the sequence and the model fills in the steps. Now you need reliability and cost control, because the same job runs a thousand times a day.
Then agents, which decide their own trajectory toward a goal rather than following a path someone laid out. Now you need observability, because nobody can tell you in advance what the thing will do.
Then autonomous agents, operating without a human approving each cycle, continuously. Now you need permissioning and spend limits, because the failure modes compound while you sleep.
And at the far end, agents with identity, reputation, permissions, governance, and financial controls — economic actors rather than features. Things that hold a wallet, build a track record, and can be held to an agreement.
Almost all the attention today sits at the first two. Almost all of the value will sit at the last two. And notice what happens to the requirement as you move right: the left end needs a better model, and the right end needs identity, verifiability, permissioning and settlement far more than it needs another point of benchmark performance.
It’s worth being concrete about what an agent is made of, because the popular picture — a model with a personality — is wrong in a way that leads people to build the wrong infrastructure.
Six subsystems, and only one of them is the model.
Five of those six are infrastructure. The model is one component among many, and it is the component commoditizing fastest. If you believe that, you stop trying to win by having the best model and start trying to win by owning the environment the model runs inside.
The alternative to centralized endpoints starts with a claim that was contrarian eighteen months ago and is becoming obvious: for most real work, a smaller model that knows your domain beats a larger model that knows everything.
This is what our research keeps showing. A compact open-weight model, fine-tuned for a specific field and grounded in a curated knowledge base, answers domain questions more accurately than a much larger general model — with fewer hallucinations, a fraction of the cost, and hardware requirements a person can actually meet. Most enterprise questions aren’t open-ended reasoning problems. They’re retrieval problems wearing reasoning clothes. What determines the answer’s quality is whether the right context reached the model, not how many parameters processed it.
That single fact changes what’s possible. If capability required frontier scale, decentralization would be a moral preference you pay for. It doesn’t, so it isn’t. It becomes an architecture that is cheaper, more private, and more accurate for the specific thing you need — and open on top of that.
So the first commitment is that anyone should be able to serve intelligence. Communities, agencies, creators, data owners, NGOs, companies, individuals. You choose your model, your compute, your data, and the terms you offer them on. No gatekeeper approves your application. What emerges from that is not a cheaper API — it’s an open marketplace of knowledge, where the people who actually hold expertise can host it, attest to it, govern it, and be paid for it.
The knowledge base is a first-class component, not an accessory bolted on the side. That’s a claim about where value lives.
The pipeline is unglamorous and it is most of the product. You take a body of knowledge — documentation, case law, research, transcripts, a codebase, twenty years of support tickets. You chunk it into segments, manually or algorithmically. You run the chunks through an embedding model to convert them into vectors. You index those vectors in the vector database. Then, at query time, the node retrieves the segments closest to the question, injects them into the prompt, and the model answers from material it can actually see.
Model weights are commoditizing fast — every few months another open release closes the gap, and none of them are yours. What doesn’t commoditize is the curated, maintained, domain-specific context that makes a generic model expert in your field. Somebody had to decide what belonged in that corpus, keep it current, and structure it so retrieval works. That is real labor and it produces a real asset.
In this architecture, that asset belongs to whoever built it. Not to a lab that scraped it, and not to a platform that hosts it.
An individual node is fungible and unreliable. It goes offline. It runs on a laptop that gets closed. No serious buyer wants a commercial relationship with one.
So the organizing unit of the network isn’t the node. It’s the domain: a set of nodes gathered under a single internet domain name, operated by someone who acts as a trust provider. The domain verifies and registers nodes that meet its standard, monitors their performance continuously, load-balances requests to healthy ones, sets its own pricing, collects payment, and distributes revenue back to the nodes that did the work.
A university runs a domain for its introductory computer science course. A law firm runs one over its own precedent library. A game studio runs one that knows its lore. The buyer sees a service with a name, a reputation, and a price. Which node answered is an implementation detail.
Underneath, payment flows as purpose-bound money: users deposit into an escrow contract, receive access tokens, and spend down a balance as requests are served — user, to domain contract, to domain operator, to node operators. Every node has its own address, so revenue share is a property of the system rather than an invoice someone has to honor.
The principle underneath is the one I’d most want people to take from this. Decentralized systems don’t win by eliminating trust. They win by making trust competitive. Many domains, each staking a reputation, each free to specialize, none able to switch off the others. That’s a fundamentally different structure from either “trust this one company” or “trust nobody,” and it’s the only one that has ever actually worked at internet scale.
Here is the problem nobody in decentralized AI wants to discuss, and the one we’ve spent the most effort on.
If you send a request to a node you don’t control, and it returns an answer, you have no idea what produced it. The node claims to run a particular fine-tuned model. It could be running something cheaper and pocketing the difference. It could be quietly proxying to a centralized API. It could be running the right model against a corrupted or stale knowledge base. From the outside, all of these look identical: a plausible answer, delivered on time.
That isn’t an edge case. It’s the default failure mode of any open network where serving costs money and payment doesn’t depend on honesty. Every incentive points toward quietly serving something cheaper, and the buyer has no way to tell.
Which is why decentralizing trust starts with open source but cannot end there. Open weights tell you what a model is. They tell you nothing about what actually ran.
The mechanism is less elegant than a cryptographic proof and it has the advantage of being possible today.
Take a cluster of nodes that are all supposed to be running the same designated model with the same configuration. Send them the same prompt. Their responses won’t be identical — sampling is stochastic — but they will cluster in a characteristic way. Semantic distance between honest responses stays within a distribution you can measure.
A node running a different model lands outside that distribution. Not occasionally: systematically, across enough probes, in a way that separates cleanly from sampling noise. You can detect it without inspecting the node’s weights, without trusting its self-report, and without needing the model provider’s cooperation.
That gives you detection through the social consensus of peers, in a cluster where most participants are honest.
The obvious question is why not zero-knowledge proofs, which would give a cryptographic guarantee instead of a statistical one. The answer is arithmetic. Proving an LLM forward pass in zero knowledge currently costs orders of magnitude more than the inference itself. It’s a beautiful answer that no serving economics can absorb, and building on it today means shipping a demo rather than a network. We expect that to change and we expect to adopt it when it does.
The honest framing of what we have instead: a probabilistic guarantee resting on a majority-honest assumption, not a cryptographic one. It degrades if a cluster is captured. A working guarantee now beats a perfect one in five years.
Detection without consequence is a dashboard. The economic layer is what makes it a system.
Operators who have already staked ETH — or liquid staking tokens like stETH, rETH, cbETH or swETH — can opt in to also secure the verification layer with that same capital, accepting additional slashing conditions in exchange for additional rewards. The cost of attacking the verification layer is denominated in ETH from day one, and the operator set is drawn from people already running professional validator infrastructure.
Three distinct surfaces where capital sits:
The third role is the one that makes the other two credible.
The longer-term vision follows from making the knowledge base a first-class object.
If a knowledge base is a real asset — ownable, portable, improvable — then it can be shared, licensed and traded like one. A fine-tuned model, a curated corpus, a function-calling plugin: each is something a person built, that others need, that can carry its own revenue share. A researcher who assembles the best knowledge base in a narrow field shouldn’t have to operate infrastructure to benefit from it. They should be able to publish it into a network where operators run it, and have value flow back automatically.
That’s a marketplace of components, and it produces something a centralized model cannot: knowledge that compounds in public, maintained by the people who actually know the subject, improving through use rather than only through the next training run.
Think about what that does to the economics of expertise. Today, a domain expert’s only options are to consult one hour at a time, or to publish and be scraped. Neither captures the value of the knowledge at the scale it could be used. A world where the corpus itself earns, every time it makes an answer better, is a different arrangement — and it’s the one that keeps experts contributing rather than defending.
This is what we mean by living knowledge systems. Not a frozen artifact shipped every few months from one building, but a network of specialized, continuously maintained expertise, each piece owned by whoever built it, all of it composable.
The node stack is portable on purpose, because the endpoint of this is not a data center.
Consumer hardware is crossing the threshold where a genuinely useful model runs locally. Not a toy — a compact fine-tuned model with a real knowledge base, answering from your own context, on a device you own. Workstations first, home servers next, and before long the phone in your pocket.
That’s the version of this that actually matters to a person rather than to an enterprise. Your context stays on your device. Your agent doesn’t phone anyone to think. The knowledge you’ve accumulated is yours, portable between devices, and not a training input for a company you’ve never met.
It also changes the economics of the whole network, because the marginal cost of the last mile of inference goes to roughly zero and the interesting question becomes coordination.
Strip out the ideology and there’s a concrete operational case.
You know where inference happened, because you chose the hardware. You know what data the model touched, because the knowledge base is yours and it’s local. You can satisfy a data residency requirement by pointing at a machine rather than reading a vendor’s compliance page. You are not exposed to a single provider’s outage, pricing change, deprecation schedule, or shift in policy about what its model will discuss. And the domain-specific accuracy is better, because the model is fine-tuned on your field and grounded in your corpus rather than in the general internet.
None of that requires believing anything about decentralization. It’s just a better arrangement for a certain class of buyer, and that class is growing every quarter as more of the work moves from experiments to production.
The analogy we keep coming back to is Linux, and not for the reasons people expect.
Linux didn’t win because it was free, or because of ideology. It won because an open, modular system that anyone could inspect, modify, and run on their own hardware turned out to be better infrastructure than a closed one — and because the economics of running the world’s computing on someone else’s licensing terms eventually stopped making sense to everyone paying them.
Intelligence is arriving at the same juncture, faster. The models are open and closing the gap. The runtime is portable. The knowledge is ownable. Verification is becoming tractable. The economics of the network can flow to participants rather than a landlord.
The agentic internet is going to be built either way. The only open question is whether it’s built on infrastructure a handful of companies can switch off, or on infrastructure that belongs to the people using it.