I spent 2017 interviewing founders who believed smart contracts would replace trust. We were wrong. Smart contracts didn't replace trust—they automated it. Now, in 2026, the same battle is playing out with AI agents, and the stakes are higher.
Over the past 60 days, three seemingly disconnected events landed on my desk: a Senate discussion draft that would hand the FTC enforcement power over AI agents, an SEC examination priority that explicitly targets AI-driven investment advice, and a Stanford paper that frames developers as fiduciaries.
Trust is no longer a promise; it’s a protocol. And in 2026, that protocol is becoming law.
I’ve spent a decade in the crypto education trenches. I’ve watched regulators circle DeFi, then NFTs, then stablecoins. Each time, they started with transparency. "Just disclose the risks," they said. "Let the market decide." That era is over for AI agents. The pivot wasn't gradual. It's structural.
The Old Playbook Is Dead
For years, the default regulatory posture toward algorithmic systems was a transparency-based "notice and consent" framework. Tell users what the model does, warn them about its limitations, and let them choose. The GDPR’s Article 50, which requires transparency from AI systems, was the purest expression of this logic.

The new American approach, crystallized in the draft AI AGENT Act from Senator Mark Warner (D-VA) and the FTC’s proposed policy statement on AI accuracy, doesn’t ask for disclosure. It imposes fiduciary duties. That means a non-waivable duty of care (act with the skill of a reasonably prudent person) and a duty of loyalty (act solely in the user’s interest). No kickbacks. No self-dealing. No hidden prioritization of suppliers.
This is not a tweak. It’s a paradigm shift.
Under the old model, a developer could say: "We told you the bot has conflicts. You consented." At common law, a fiduciary cannot escape liability by telling the beneficiary to waive the duty. The new framework borrows that logic. If the draft becomes law, any contract clause that tries to limit a developer’s fiduciary duty is void from the start.
The choice of the FTC as the enforcement body is the hidden tell. The FTC’s Section 5 authority over "unfair or deceptive acts" gives regulators an existing highway—no need to build a new regulatory city from scratch. This compresses the legal infrastructure timeline and accelerates the transition from academic proposal to enforceable law.
The Real Problem Is Your Revenue Model
Let’s get specific. Based on my years auditing protocol incentive structures in DeFi, I can tell you exactly where this hurts.
The single highest-risk compliance exposure isn’t misleading AI claims. It’s the affiliate fee model. It’s the platform that gets paid to recommend one vendor over another. It’s the "free" AI assistant that quietly prioritizes partners.
I’ve seen this pattern before. In DeFi Summer 2020, I watched incentivized liquidity pools create misaligned behavior. It took protocols years to untangle the incentive mess. But in crypto, at least, the incentives were visible on-chain. AI agents are a black box.
The SEC has already started moving. In March 2024, it settled with Delphia and Global Predictions over false claims about AI capabilities. In December 2025, it issued a risk alert on marketing rules related to AI. Neither case touched the deeper fiduciary core—conflicts of interest, hidden incentives, self-dealing. That’s the tell. The SEC is building enforcement precedents with the easy cases first.
Expect a case involving AI agent conflicts within the next 12 to 24 months. When that lands, it won’t be a settlement. It’ll be a sweeping statement about duty.
I attended the Crypto Ethics Summit in Stockholm in 2025, and one institutional lawyer put it bluntly: "Wall Street spent 30 years learning what ‘best execution’ means. You think AI agents get a pass because they’re software?" He was right. The SEC’s fiduciary framework is now extending into agentic AI—and it comes with personal liability. SEC enforcement actions against investment advisors routinely include industry bars for individuals.
This creates a two-track enforcement risk: the FTC goes after the corporate entity, while the SEC goes after the compliance officer and the tech lead who signed off on the recommendation algorithm. For founders, that’s not a compliance issue. That’s an existential one.
The Auditability Trap
The uncomfortable truth is that the technology to prove an AI agent didn’t act on hidden incentives doesn’t fully exist. My audit experience in DeFi taught me that verifying transaction history is straightforward when everything is on-chain. Verifying agent behavior is fundamentally different. You’d have to prove a negative: that no hidden incentive influenced the agent’s output.
The FTC’s proposed policy statement acknowledges this by calling for accuracy in AI claims. But the Warner bill goes further. It imposes a duty of loyalty. How do you audit intent?
The honest answer is: you can’t. Not yet. So we rely on governance structures—the presence of conflict-of-interest review committees, incentive audits, and third-party assessments—as proxies for fiduciary compliance.
This is where an interesting market dynamic emerges. The firms that crack the "agent behavior audit" problem first will own a new asset class of compliance infrastructure. Think of it as the Chainalysis moment for behavioral integrity. In 2020, blockchain analytics was a nice-to-have. By 2023, it was a compliance requirement. The same thing is about to happen to agent behavior monitoring.
The Contrarian Angle: Regulation Will Accelerate Crypto Adoption
Here’s what everyone is missing.
The crypto industry has spent years wrestling with an impossible question: how do you prove that code acts in someone’s interest? Blockchains solved part of it—verifiability. But verifiability of code is not the same as alignment with intent.
The movement toward fiduciary duty in AI agents creates an unprecedented pressure to solve "intent alignment" technically. And when you need to prove intent on an auditable, non-corruptible basis, the crypto toolkit—immutable logs, transparent incentive structures, decentralized verification—becomes crucial infrastructure.
This is not the death of decentralization. It’s the culmination of the transparency ethos. I learned to stop preaching and start listening to what regulators actually need. They need a way to verify that agent behavior hasn’t been captured by hidden incentives. That’s a technical problem.
The Compliance Disconnect and the Opportunity
There’s a timing gap worth exploiting. The FTC’s comment period ends September 18, 2026. The SEC’s examination priorities take effect immediately. Rules are forming at different speeds, through different mechanisms.
Meanwhile, industry self-regulation remains absent. Very few AI agent developers have published meaningful "fiduciary-aligned" standards. The trustless systems require trusting relationships—and a few early movers still have time to define what "reasonably prudent" means in practice.
The message for founders is simple: don’t wait for the FTC’s final language. This window is your chance to become the ISO 27701 of the AI agent era.
If that feels distant, consider the warning from the EU AI Act, which still centers on transparency and is now legally binding in Europe. US and EU frameworks are diverging. AI agent deployers operating on both sides are looking at dual compliance tracks: substantive fiduciary obligations in the US, procedural disclosure rules in the EU.
The Dark Side of the Good Intentions
What’s the downside? Compliance costs will rise. The technology to fully audit agent behavior remains unresolved, and large platforms with deep pockets will absorb the burden more easily than startups. This will accelerate market concentration.
There’s also a hidden tension: fiduciary duty requires understanding user preferences deeply to act in their best interest, while data protection laws demand minimizing data collection. No one has reconciled these two directives yet. A platform may soon be penalized either way.
But regulatory convergence is happening across all three pillars I’ve watched for years: academic thinking, legislative planning, and enforcement action. The convergence isn’t on what AI can do. It’s on who’s accountable when it does the wrong thing.
Code Is Law, But Empathy Is the Interface
In 2026, legal guardianship is being built into the architecture of AI systems. The question is whether we can build the trust infrastructure before the abuse cases rewrite the narrative.
AI agents are about to experience an accountability transformation. The smart plays are being made now. The innovators who build compliance into their systems—not as a patch, but as a founding principle—will end up leading the way.
Watch for the first conflict-of-interest enforcement action. I’m watching. If you build in this space, you should be watching too.