Four articles(1, 2, 3, 4), one argument. Here is the whole shape of it — and the choice we are about to make by accident.
I owe you a confession before I close this out.
These were never really four separate articles. They were one argument, delivered in installments, and I suspect some of you saw the shape of it before I admitted it. Every piece ended by handing the hard part to the next one. Part 1 raised the question of trust and deferred it. Part 2 answered "how does it touch money" and left "who's liable" open. Part 3 was about the attack, and pointed at accountability. Part 4 finally paid the bill — and quietly assumed everything the first three had built. I kept telling you I'd get to it in the next paragraph. This is the next paragraph.
So let me stop circling and name the thing directly. Then let me tell you where it has to go, because after two decades of watching my industry learn these lessons the expensive way, I think we have — for once — a chance to learn one of them early.
Line the four pieces up and they stop looking like four problems. They look like four layers of a single stack.
Who is this agent? That's identity — binding a piece of software to a verified human, provably, so the world can tell your representative from an impostor. What is it allowed to do? That's the mandate — scoped, bounded, revocable authority, the direct-debit-and-power-of-attorney idea rebuilt for a delegate that acts a thousand times a second. How do we know it did only that, and contain it when it doesn't? That's provenance and security — signing every action, keeping personal data off the permanent record, holding the blast radius small. And who carries the loss when it goes wrong? That's liability — the rule that decides whether an ordinary person can afford to say yes at all.
Identity, mandate, provenance, liability. Four layers, one system. It has a boring name and I'll give it the boring name, because the boring names are usually the important ones: it's the trust layer for delegated action. It is the entire difference between an agent that empowers you and an agent that ruins you. And here is the uncomfortable thing I've been building toward across five installments — none of it is the AI. The model, the reasoning, the capability everyone is racing on: that's the part that's basically solved, or will be soon. The trust layer is the part nobody's finished, and it's the whole game.
Which is why I've ended every one of these pieces with the same sentence, and I'll earn it one final time: capability is here. The trust is the work.
Twenty years in financial services teaches you to recognize a particular shape of mistake. It goes like this: something valuable becomes possible, everyone races to ship it, the trust scaffolding gets deferred as "we'll handle that later," and then later arrives as a wave of losses, and only then — after the harm, after the headlines, after real people are hurt — does the industry build the thing it should have built first.
I've watched it happen more than once. Authorized-push-payment fraud is the cleanest example: the "did you authorize it" rule gave clean answers and monstrous outcomes for years, and it took a body of ruined victims before regulators finally overrode the binary and reassigned the loss. Power-of-attorney abuse is another — a trust instrument weaponized against the vulnerable, patched slowly, reactively, at the cost of the people it hurt. The lesson is never that the trust layer was impossible. It's that we built it after the damage instead of before, and paid for the delay in other people's lives.
Agentic AI is walking straight into that same shape, at a scale that dwarfs every prior instance. And this time — this is the entire reason I wrote the series — we can see it coming clearly enough to break the pattern. The precedents are on the table. The failure modes are legible. We know what the trust layer has to contain because we've reverse-engineered it, layer by layer, before the volume arrived. We have, unusually, the chance to build it first.
That is what "where this has to go" means. It means refusing, for once, to learn this the expensive way.
Not into another framework or a cleverer model. Into four moves, and none of them are things any single company can do alone.
From features to infrastructure. Right now every vendor is reinventing identity, mandates, and provenance inside its own walls, which is how you get a dozen incompatible islands and, worse, a private chokepoint — because whoever ends up owning the registry that says "this agent may act for this human" owns something far too powerful to sit in one company's hands. The trust layer has to become shared, open, interoperable rails, the way payment networks and identity checks eventually did. Encouragingly, the pieces are already forming in the open — verifiable-credential and decentralized-identity standards are maturing, regulators are mandating identity wallets, agent-identity specifications are being donated to neutral foundations. That's the right direction. It has to become plumbing everyone uses, not a moat someone digs.
Built ahead of the volume, and built together. No one party holds all the pieces. The banks understand mandates and liability. The AI labs understand the agent. The regulators own the default that decides who eats a loss. The standards bodies make it interoperable. Today those groups mostly aren't in the same room, and the trust layer lives precisely in the seams between them — and if there's one law I'd carve over the door, it's the one from Part 3: fraud finds the seam. So does failure. The work is to close the seams deliberately, now, while the stakes are still small, instead of discovering them one victim at a time.
Toward agents actually worth the authority. I have to be honest about a limit, because the whole series has tried to be. Everything I've described — identity, mandates, signed provenance — secures the plumbing, not the judgment. It can prove an agent was authorized; it cannot prove the agent wasn't talked into it. A manipulated agent still produces a perfectly valid, perfectly signed, perfectly in-mandate catastrophe. So the real frontier — the place this ultimately has to go — is agents that can resist manipulation, whose intentions can be verified, and that keep a human in the loop at the handful of moments that are irreversible or ruinous. Until we get there, the honest posture is the one I argued for in the very first piece: bounded delegation, earned domain by domain, not full autonomy handed over because a demo looked smooth. Contain the damage while we work on curing the disease.
And kept pointed at the person. It would be easy for all of this to become enterprise plumbing optimized for throughput, and to forget who it was for. But every piece in this series was deliberately about you — your identity, your money, your exposure, your bill. The point of the trust layer is not efficiency. It's that an ordinary human being — not a corporation with a legal team, an individual — can hand real authority to a representative and get back their time, their attention, and an advocate in the parts of digital life that are rigged against them, without risking ruin to do it. If we build it right, that's genuinely one of the most empowering things technology could offer a person in a generation. Build it, and keep it built, for them.
Here's where the two futures actually split, and it's sharper than the hype on either side admits.
Get the trust layer right, and the Personal AI Representative becomes what Part 1 promised: a tireless advocate that reads the fine print, fights the unfair charge, navigates the bureaucracy, and hands ordinary people leverage they've never had. Get it wrong — ship the capability and defer the trust — and it becomes what Part 3 warned about: the most personal attack surface ever built, an authorized-loss engine pointed at everyone at once, with the bill landing by default on whoever can least afford to fight it.
The difference between those two futures is not the intelligence of the agent. Both futures have brilliant agents. The difference is entirely the boring scaffolding — identity, mandates, provenance, liability — and whether we build it deliberately and in the open, or let it congeal by accident into whatever shape is most convenient for whoever moves fastest. That choice is being made right now, quietly, in the gap between what's being shipped and what's being secured. Choices made by default are still choices. They're just the ones nobody takes responsibility for.
After two decades of watching my industry build trust the hard way — reactively, expensively, one wave of losses at a time — here is what I've come to believe, and it's why I spent five articles on it.
We keep asking what these agents will be able to do. It's the wrong question, or at least the easy one. Capability is arriving on its own; it needs nothing from us. The real question — the one hiding underneath every piece in this series, from "act on your behalf" to "who pays" — was never about the agent's power. It was about whether we'd build the thing that makes that power safe to hand over. Whether we'd earn the word we keep using so casually: trust.
That part isn't arriving on its own. It's not a capability we can wait for. It's a decision, and it's ours, and the window to make it deliberately instead of by accident is open right now and won't stay open long.
So I'll close the series not with another question for you, but with the answer to the one it kept asking. Can you trust an AI to act on your behalf? Not yet. But whether you ever can is not up to the models. It's up to whether we do the work — the identity, the mandates, the provenance, the liability, the boring, essential, unglamorous scaffolding of trust — before the volume arrives, in the open, together, and with the person at the center of it.
Capability is here. The trust is the work. Let's go do the work