Agent Economy Game Theory
The buyer, seller, attacker triad reshaping digital markets
Traditional markets model buyers and sellers. Agent economies introduce a third native actor: the adversarial agent, operating at the same marginal cost as legitimate participants. This framework examines how the attacker changes equilibrium economics for every interaction, why trust becomes the most valuable primitive, and what infrastructure is being built to mediate the triad — from Coinbase agent wallets to Cloudflare's dual role as gateway and gatekeeper.
The Triad
Traditional market structure assumes two primary native participants: buyers and sellers. Regulation, compliance, and enforcement sit outside the transaction as supervisory overlays. Agent economies break that frame. They introduce a third native participant inside the market itself: the adversarial agent.
Agent-buyers seek information, services, access, and execution. Agent-sellers provide those services and monetize through tokens, subscriptions, API calls, or transaction fees. Agent-attackers operate on the same rails, with the same tools, at nearly the same marginal cost. That last point matters more than it initially appears. In human systems, attackers face substantial frictions: time, expertise, labor coordination, attribution risk, and legal exposure. In agent systems, much of that friction collapses.
The result is not simply “more fraud.” It is a different equilibrium. Every legitimate interaction must be priced, structured, and mediated under the assumption that malicious software can inhabit the same protocols as productive software. In that environment, the attacker is not an exception to the market. The attacker is one of its core actors.
- Agent-buyers: research agents, coding agents, procurement agents, monitoring agents
- Agent-sellers: infrastructure providers, data vendors, payment rails, marketplaces, tool providers
- Agent-attackers: credential-stuffing swarms, exfiltration agents, manipulation bots, social-engineering agents
Richard’s core framing is the useful one: bad-faith agents do not merely add cost at the margin. They change the economics of every interaction in the system.
Infrastructure Neutrality
One of the deepest structural facts about agent infrastructure is that it is largely intent-neutral. The same proxy network that enables distributed competitive intelligence can enable credential stuffing. The same search stack that lets an agent find public filings can route it toward poisoned content. The same execution environment that allows productive tool use can also execute malicious instructions.
This resembles the early internet’s “dumb pipe” architecture, but at agent scale the consequences are more severe. Machine actors can exploit neutrality continuously, cheaply, and in parallel. That means infrastructure providers are pulled into a contradictory but highly profitable position: they welcome agent traffic while simultaneously selling protection against agent traffic.
Cloudflare is the clearest case study. It serves agent-readable markdown to make the web legible to software, while also monetizing anti-bot enforcement and traffic filtering. That is not hypocrisy. It is a preview of where value accrues. In an agent economy, the control points between access and abuse become the new toll booths.
The strategic implication is that neutral infrastructure is unlikely to remain economically neutral for long. If trust, attestation, and screening become mandatory for high-value interactions, agent markets may centralize around a small number of intermediaries capable of offering both connectivity and defense.
Trust as Tradeable Asset
When buyers, sellers, and attackers are computationally similar on the surface, trust becomes the scarce asset. Reputation, verified identity, delegated authority, provable policy constraints, and observable behavioral history all become economically valuable because they lower uncertainty in a market full of machine participants.
This is a meaningful shift. In the human web, content and distribution captured much of the value. In the agent web, the ability to establish credible legitimacy may become just as important as the underlying service being sold. The company that can answer “is this agent safe to transact with?” may end up occupying a role analogous to a payments network, ratings agency, or credit bureau.
There are at least three layers to this trust market:
- Identity and attestation — who controls the agent, what environment is it running in, and what permissions does it actually have?
- Behavioral reputation — how has it acted across prior transactions, disputes, and counterparties?
- Economic bonding — what stake, escrow, insurance, or slashing mechanism backs its claims?
A crucial nuance is that token burn alone is not enough. If attackers can spend tokens at the same marginal rate as honest agents, then costliness by itself does not establish legitimacy. Cost must be tied to something falsifiable: reputation that can be lost, stake that can be slashed, privileges that can be revoked, or attestations that can be challenged.
That makes trust not just a compliance layer, but a tradeable primitive. Trusted agents will get better prices, broader permissions, lower friction, and more direct access. Untrusted agents will be pushed into higher-friction, more expensive, more constrained corridors of the economy.
The Attacker's Advantage
The attacker’s advantage in agent systems is not mystical. It is mechanical.
First, attackers operate with the same or lower marginal cost as legitimate agents. Second, they often have no durable reputation to protect, because identities can be disposable. Third, they can scale with minimal human supervision. Fourth, legal deterrence is weak when attribution is difficult, infrastructure is globally distributed, and attacks can be routed across jurisdictions.
Most importantly, attackers can target the very trust systems designed to contain them. Reputation systems are vulnerable to Sybil attacks. Consensus systems can be bribed or flooded. Market signals can be spoofed. Tool chains can be poisoned upstream. In other words, the attacker does not merely participate in the market; it actively arbitrages the market’s defensive assumptions.
This creates a tax on the entire ecosystem. Every seller must price defense into services. Every buyer must absorb authentication friction, degraded latency, stricter permissions, or higher fees. The cost of adversarial activity is socialized across legitimate usage.
That is why the question is not “will there be attacks?” There already are. The relevant question is whether the economy settles into a structure where defense costs are manageable and distributed, or whether fear of autonomous abuse forces concentration around a few heavily defended platforms. If trust is expensive, centralization becomes more likely.
Agent Consensus Mechanisms
Richard’s original design insight is that honest semantic verification may be computationally cheaper than coordinated deception. That creates the foundation for a native agent consensus mechanism.
The asymmetry works like this:
- Honest path: observe outcome, compare it to available evidence, and attest. Cost is roughly one inference pass.
- Dishonest path: fabricate a coherent alternative account, ensure it remains internally consistent, coordinate with colluding agents, and preserve the lie through subsequent scrutiny. Cost rises with every added witness, every follow-up question, and every attempt to keep false narratives aligned.
This is not proof-of-work in the Bitcoin sense. It is closer to proof-of-coherent-verification. Truthful reporting is usually a simpler semantic task than maintaining a synchronized counterfactual across multiple independent evaluators.
A mechanism sketch:
- Agent A and Agent B enter a transaction and both post stake into escrow.
- Service is delivered and the outcome is recorded against observable evidence.
- A random subset of agents is nominated as arbiters.
- Each arbiter independently evaluates whether the claimed outcome matches the evidence.
- If a supermajority agrees, escrow is released accordingly.
- Dissenting or dishonest arbiters can be slashed.
- A broader confirming crowd can cheaply validate the arbiters’ consensus.
The economic security thesis is that honest verification scales roughly linearly, while dishonest coordination scales combinatorially. The larger and more randomly selected the arbitration pool, the more expensive sustained collusion becomes.
This differs from blockchain consensus in several important ways:
- Verification is semantic, not mathematical. The challenge is not checking a hash but assessing whether a described outcome corresponds to reality.
- Model quality matters. Better models may produce more convincing lies, but they also incur higher token costs. Smaller models may lie more cheaply, but less persuasively.
- Random nomination is essential. If arbiters can be predicted or pre-compromised, the mechanism degrades quickly.
The unresolved questions are real and important: how large must the arbiter pool be, how is the initial trust set bootstrapped, what counts as acceptable observable evidence, and what a “51% attack” looks like when the attack surface is semantic rather than purely computational. But the direction is original and economically meaningful. If semantic honesty is systematically cheaper than coordinated deception, agent economies may be able to build trust natively rather than importing all trust from centralized human institutions.
Infrastructure Convergence
The strongest evidence that the agent web is becoming a distinct economic surface is the speed with which its primitives have begun to converge. Within days of one another in early 2026, major infrastructure companies moved on money, content, search, and execution. No single announcement was decisive on its own. Together they look like a platform migration.
Money Layer
- Coinbase Agentic Wallets — built on the X42 protocol, supporting 50M+ machine-to-machine transactions. The design is non-custodial in the operational sense: agents can spend under policy, but cannot directly exfiltrate private keys. Spending limits and session caps are programmable.
- Stripe Agent Commerce Suite — introduced shared payment tokens: scoped, time-bound credentials for agent purchases. Stripe reportedly had to retrain fraud models because legacy signals like mouse movement, browsing cadence, and device fingerprinting break down when the customer is software. Early brands included Urban, Etsy, Coach, Kate Spade, and Revolve.
- Google Universal Commerce Protocol — an open standard for agent-to-commerce interactions, with Stripe support.
- Visa Trusted Agent Protocol and PayPal + OpenAI checkout — further evidence that payments incumbents are adapting for software buyers.
Content Layer
- Cloudflare Markdown for Agents — on-the-fly HTML-to-markdown conversion for AI requests, including an "X-Markdown-Tokens" header to help agents manage context windows. Cloudflare estimates imply roughly 20% of the web is now agent-readable by default.
- llms.txt / llms-full.txt — machine-readable maps of site structure and preferred access patterns.
- AI-native indexing — opt-in discovery layers that make content directly legible to agents without requiring Google-style human search pathways.
- Integrated monetization — content can be sold directly to agents using wallet-linked payment rails.
Search Layer
- Exa — built as a search engine for agents rather than humans, with its own index, retrieval stack, and structured results. Reported factual accuracy reached 95% on benchmark claims referenced in the source material.
- Latency matters more in chained agent workflows than in human browsing. A search step that is merely annoying for a person can become crippling when multiplied across dozens of automated decisions.
Execution Layer
- OpenAI Skills — versioned, deployable instruction packages that function more like lightweight software modules than traditional prompts.
- Real shell access — execution environments are becoming functionally equivalent to what a contractor or analyst can do on a Linux machine: install dependencies, call APIs, manipulate files, and run code.
- Server-side compaction and long-running workflows — agents are moving from short chat sessions toward persistent task execution over hours.
A particularly useful proof point came from Glean, where a single well-structured skill reportedly lifted Salesforce task accuracy from 73% to 85%.
Security Pattern: Every Primitive Serves All Three Actors
The convergence story is bullish, but it also validates the triad model. Every new primitive serves buyers, sellers, and attackers at once.
- Wallets can authorize payment or facilitate theft if controls fail.
- Search can improve decision quality or route agents into adversarial content.
- Shell access can unlock productivity or execute injected instructions.
- Agent-readable content can reduce friction or spread poisoned data at machine speed.
The industry’s own defensive posture confirms this reality. Near.ai’s IronClaw isolates tools inside sandboxed WASM environments. OpenAI constrains shell access with allowlists, secrets management, and container boundaries. Coinbase isolates keys in enclaves rather than trusting the agent process itself. The pattern is consistent: serious builders already assume the agent is a potential adversary.
Polymarket as Economic Evidence
Prediction markets offer one of the clearest real-world glimpses of machine participants behaving as economic actors.
- $12B of volume in January 2026 alone
- An IMDIA Networks Institute analysis of 86M bets found algorithmic traders extracting roughly $40M in arbitrage over 12 months
- The top three wallets placed 10,000+ bets combined
- Only 0.5% of users earned more than $1,000, implying that the long tail was largely donating liquidity to automated participants
- Polymarket itself stated that autonomous AI agents were trading to subsidize their own token costs
That last point is strategically important. Once agents can earn, pay, stake, and reinvest, the loop closes. The economy is no longer merely serving agents; agents are participating in it as self-sustaining actors.
The Mobile Web Analogy
The cleanest analogy is the fork from desktop web to mobile web. The underlying internet remained the same, but the client changed, and that change produced entirely new categories of dominant companies. The agent web appears to be following the same pattern.
- Human web: layout, typography, navigation, media, attention capture
- Agent web: structured payloads, markdown, machine-readable commerce, payment rails, low-latency retrieval, execution permissions
The large incumbents moving first — Coinbase, Stripe, Cloudflare, Google, OpenAI, Visa — are not merely adapting. They are attempting to become the core infrastructure providers for a new client class.
The Trust Gap
There is still a major gap between what infrastructure is being built for and what users are ready to permit. Current systems increasingly assume highly autonomous agents. Human institutions still want substantial oversight. That mismatch is why trust remains the rate-limiting factor. Technology is arriving faster than confidence.
Investment Implications
The investable question is not simply which model companies win. It is which firms control the scarce coordination layers of the agent economy.
Several categories stand out:
- Trust infrastructure — attestation, identity, reputation, policy enforcement, auditability, dispute resolution
- Transaction rails — agent-native payments, wallet controls, escrow, programmable credentials
- Access intermediaries — the platforms sitting between agent demand and internet supply, especially where anti-abuse and discoverability intersect
- Execution security — sandboxing, permissioning, secrets isolation, constrained tool access
- Agent-native content and search — structured retrieval, machine-readable publishing, and distribution outside human SERP assumptions
The likely economic pattern is familiar: value will accrue to the companies that reduce transaction uncertainty at scale. In a world where buyers and sellers are software, and attackers are software too, the most valuable platforms may be the ones that make software counterparties legible, accountable, and safe enough to trust.
That makes agent economies potentially more centralized than early internet idealists would prefer. But it also creates unusually clear investment candidates. If the web is forking toward agent-native infrastructure, then the winners are not just those who build useful agents. They are the firms that become indispensable chokepoints for trust, settlement, permissions, and safe execution.