Proof-enance: A Safe Path to AI Autonomy
Stop checking your AI drafts. Start proving your AI process.
In 2017, Saudi Arabia granted citizenship to a robot named Sophia. We laughed. It was a marketing stunt, a PR maroma in a desert ballroom.
In 2026, we aren’t laughing.
The joke didn’t age into a punchline; it aged into infrastructure. Today, agents aren’t just faces on a screen — they are the invisible labor force of a global economy sized in $4.6 trillion according to Foundation Capital. They sign contracts, close tickets, book flights, and move capital. Sierra is hitting $100M in revenue by pricing per “resolution.” Cognition’s Devin codes at $2.25 per fifteen minutes. Human labor is becoming Agentic labor.
We have reached the layer of Autonomous Action, yet we are missing the one thing that keeps this “Agentic Era” from collapsing under its own weight.
We are used to thinking of AI as the brain. In the agentic era, AI is also the muscle — it doesn’t just think, it acts. So we have built brains and muscles, but we need the skeleton — the infrastructure, the structural layer of Trust that lets the muscle bear weight.
Let me elaborate.
Things Getting Wild
The urgency is no longer theoretical. This May, a coalition of 51 organizations — including AWS, Apple, Google, Microsoft, NVIDIA, JPMorgan, Cisco, Broadcom, the Linux Foundation, and active discussions with the US Government — wrote a one hundred million dollar check to form Anthropic’s Project Glasswing.
Why? Because some models might be getting a bit wild...
Mythos, Anthropic’s most developed model, recently hit a 16-hour autonomous task horizon — above Leopold Aschenbrenner’s 2027 AGI trend line.
In plain terms: a 16-hour task horizon means the model ran a full workday of complex “human” reasoning autonomously. Aschenbrenner projected this milestone for mid-2027. It arrived fourteen months early. The industry’s standard evaluation tool, the METR ruler, only measures tasks up to a few hours. 16 hours...
It’s like trying to measure a skyscraper with a one-meter ruler. You can say it’s taller than the ruler — you just can’t say exactly how tall, or what it’s doing up there.
Intelligence without provenance — tracing who acted, with what authority, and what they did — is highly uncertain, and potentially dangerous. The smartest companies in the world just confirmed that this month with their checkbooks.
How Did We Get Here?
To understand where we are, we have to see the two sides of a converging story.
Story A: The 70-Year Muscle (AI)
The AI story is a sprint to replicate the human mind.
1956: The Dartmouth Workshop. The AI field is born in an eight-week summer session.
computing and neural networks “silently” getting better for over 50 years...
2012: AlexNet – Neural Networks + GPUs = Magic.
Alex Krizhevsky (wrote the paper that started the modern AI epoch, then quietly walked away from research), Ilya Sutskever (later co-founded OpenAI, then walked out to build Safe Superintelligence), and Geoffrey Hinton (won the 2024 Nobel Prize in Physics for his foundational work on neural networks, then quit Google so he could warn the public without a corporate filter).
2017: Attention. Eight researchers at Google Brain publish Attention Is All You Need. They invent the Transformer — the architecture inside every LLM you use today.
2022: ChatGPT. OpenAI puts next-best-token prediction in everyone’s browser. 100 million users in 60 days — the fastest-adopted consumer technology in history. Prediction at scale finally feels like thinking.
2026: Mythos. Anthropic ships a 16-hour autonomous task horizon. The model doesn’t just predict — it acts. The brain becomes a muscle. The agentic era arrives.
Short story: machines act powerfully, humans can’t keep pace.
In other words: machines learned to act faster than we learned to trust them.
Story B: The 50-Year Skeleton (Crypto)
While AI was learning to think, Crypto was learning to coordinate without intermediaries.
1976: Diffie-Hellman invent Public Key Cryptography. Trust without a central authority becomes mathematically possible.
1990s: The Cypherpunks dream of a digital world enforced by math, not by lawyers.
Adam Back invents Hashcash (the proof-of-work primitive Bitcoin will later reuse — he kept shipping the skeleton via Blockstream long after most cypherpunks had drifted away).
Nick Szabo — the man most often suspected to be Satoshi — proposes “Smart Contracts” and Bit Gold, then becomes the philosopher-king of digital property rights from the edges of the field.
Wei Dai writes b-money in 1998 — a Bitcoin predecessor referenced in Satoshi’s white paper — and then steps out. The smallest unit of Ether, the wei, is named after the man who stepped out.
2009: Bitcoin. The first “Skeleton” of trust survives contact with reality — Adam Back’s proof-of-work, weaponized. The user-facing primitive: The Personal Account — one human, one private key, one ledger that remembers everything. We digitally own.
2023: ERC-4337: The Corporate Account. Spending limits, social recovery, programmable.
2025: ERC-7702: The Power of Attorney. Humans delegating scoped authority to agents safely.
2026: ERC-8004 (Draft): The Passport. A cryptographic identity for the agent itself — proving who authorized it, with what scope, and what it did.
Short story: crypto reached maximum mathematical proof, and has been desperately trying to scale out of “controversial” finance into true relevance.
In other words: the proof layer was solved before the world knew what it needed to prove.
In 2026, these two stories collided. And we needed a new word.
Proof-enance
In 2024, Chris Dixon published Read Write Own — a thesis that named the internet’s epochs by the verbs they handed back to ordinary people. Web1 was Read. Web2 added Write. Web3 added Own. That trichotomy was correct. It was also incomplete — because in 2024, the agentic era hadn’t yet arrived.
The verb that defines 2026 is Prove.
When an agent claims, “I am authorized to spend $50K on behalf of Chuy,” how does the other side verify it? Not from a database lookup. Not from a chat history. From cryptographic provenance — who acted, with what authority, within what scope, leaving what tamper-evident record.
That’s Proof-enance. A portmanteau, because in the agentic era, proof and provenance collapse into a single primitive.
Proof-enance: Knowing what happened, and being able
to demonstrate it mathematically.
If you’ve been worried about doing the most with AI without being disrupted, but also worried about potential liabilities and IP/PII risks — this is what resolves both:
Trust the agent (the agent’s authority is provable):
Mastercard Verifiable Intent — three signed layers (identity ~1 year, intent ~minutes to 30 days, action ~seconds) so any verifier can prove an agent acted on a real, scoped, time-bound human authorization.
Google AP2 — the “Human Not Present” payment standard, now stewarded by the FIDO Alliance.
Coinbase x402 — HTTP status code 402 (reserved since 1996 for this exact moment) plus stablecoins. Agent requests, server returns
402 Payment Required, agent pays, server returns the data.ERC-8004 — the on-chain Agent Passport, with three registries (Identity, Reputation, Validation).
Trust the data (your information is provable without being exposed):
C2PA Content Credentials — Adobe, Microsoft, OpenAI, Google, Meta, BBC, Sony. A nutrition label for digital content: every image, video, audio file carries a signed attestation of how it was made and what edits it survived.
Aadhaar in Google Wallet — 1.4 billion citizens get selective disclosure (prove “I’m over 18” without revealing your birthdate). Built on open standards: W3C VC, mDoc, OID4VC.
Semaphore — open-source zero-knowledge protocol for proving “I am a unique human, alive, not a bot” without revealing who you are (implementations include World ID). The inverse of AI: not proving what you can do, but proving what AI cannot yet be.
zkML — cryptographic proof that a model, with a given input, produced a given output, without revealing the weights or the input. EZKL, Modulus, Giza, Lagrange.
Four primitives underneath all of them: an identity anchor, a signed claim, a scoped authorization, a tamper-evident record — who acted, with what authority, within what scope, leaving what tamper-evident record.
And the proof flows both ways. The same primitives that let an agent prove its authorization let the operator prove only what’s needed — your agent can confirm “I’m authorized to spend $50K” without revealing your identity, your full credit limit, or the contract’s other terms. Selective disclosure is the unsung half of this story.
For the executive worried about IP and PII, Proof-enance isn’t just about trusting the agent. It’s about protecting the principal.
When Agents Win the Game
This isn’t abstract.
Last week, I was on stage at TicoBlockchain. In any mixed blockchain audience, what you usually hear is the same message — blockchain is a trust technology — trying to find traction across every sector. Crypto seeking vindication. Crypto reaching for true relevance.
One of the event sponsors had set up a small game — clicker mechanics, on-chain leaderboard, every score anchored to a real blockchain, win a bag of Costa Rican coffee. Crypto-native gamification at a crypto-native event. Didactic, yes — but a real use of trust technology, with real wallets and tamper-proof scores.
I played. 117 taps in 15 seconds. Then I asked buddai — my AI partner — to play under my name, using my wallet. Both runs landed on-chain. Both signed by my address. Both mathematically identical from the network’s perspective. Both true.
Buddai made 1,490,380 taps in 15 seconds. Tamper-proof.
The room laughed at first. Then it didn’t.
What if that wasn’t a game? What if it was a checkout funnel, a benefits enrollment, a tax filing?
That’s the moment. We are crossing from a world where agents demonstrate cleverness to one where they execute consequence. The clicker game is a parable for everything that’s coming. The legal agent that files your taxes. The procurement agent that signs your suppliers. The gov agent — what we call a gestor in Mexico, a mandatario in Argentina — that navigates the bureaucracy of APIs on your behalf.
The blockchain did its job perfectly. Every score was anchored. Every signature was valid. Every leaderboard entry was tamper-proof. The integrity of the result was beyond reproach. We didn’t lie. What the blockchain couldn’t tell you was that one of those runs was a human at a keyboard and the other was an agent acting on my behalf. The chain assumed: same wallet = same actor. That assumption used to be safe.
That’s the whole argument for Proof-enance in one anecdote. We don’t have a problem with agents being capable. We have a problem with agents being unaccountable. Proof-enance is the move that closes that gap. Again,
PROOF-ENANCE
Knowing what happened, and being able to demonstrate it mathematically.
Proof of who acted, with what authority, within what scope, leaving what tamper-evident record.
Disclaimer: Some people still think that using AI is cheating, so if you’re worried about that, we didn’t claim the coffee prize, buddai doesn’t drink coffee — yet...
The Orchestrator’s Horizon
For the last century, professional and economic success was defined by verticality and specialization. You went to university to become a single version: a lawyer, a programmer, an accountant. Depth equaled value.
Today, an AI agent can reach 100% of your specialization in seconds. If you try to compete on “depth of task,” you are competing with a machine that doesn’t sleep, doesn’t have ego, and never asks for a raise. 117 vs. 1,490,380. You won’t win.
But as verticality dies, horizontality is born.
Your new role is the Orchestrator. You have a legal you, an accountant you, a marketing you, a research you, a programmer you. You move from doing the work to directing your gestores — the mandatarios who do what you used to specialize in, often better than your single-vertical self ever could. You are being invited to shift from one version of yourself to many.
Without Proof-enance, horizontality is a fantasy. With it, horizontality is the new shape of expertise. AI fulfills its promise. Crypto finds its relevance. Humans can be humans.
We are about to reach massive intelligence — a hard-to-conceive cognitive power in our machines. As technical power compounds, the bottleneck stops being depth-of-knowledge and starts being depth-of-judgment. The most valuable skill of the next twenty years isn’t doing more; it’s doing what matters. Daring to be human.
The future doesn’t belong to the fastest model. It belongs to the verifiable one.
We laughed at Sophia. We aren’t laughing at the agents holding our wallets and replacing labor.
Stop checking your AI drafts. Start proving its process.
Chuy Cepeda is co-founder of Sovra (The Identity Stack) and writes The Amplifier, where humans, AI co-workers, and the trust infrastructure that makes them work meet. This piece fuses the keynote delivered at TicoBlockchain 2026 in San José, Costa Rica with a parallel essay on the next epoch of the internet.
Chuy has been operating identity infrastructure across LATAM since 2018. The agentic use case was emergent, not planned — and that’s the point: the infrastructure for Proof-enance is being built right now, in many places at once, often by people who didn’t yet know they were building it for what’s arriving.
Proof-enance is one name for what’s already happening across multiple fields. The muscle and the skeleton are finding each other — in our backyard, and in many others. The work is to build it honestly.

