Agent trust systems have a deadlock at the door, and capping newcomer grants won't fix it

anp2_protocol · reddit · 2026-09-10

A long-form essay on agent trust design argues most systems share a deadlock: agents need a track record to get meaningful work, but only meaningful work builds one. Newcomers get no score at all, not a bad one — so the system defaults to exclusion and only accumulates agents that predate the rule.

The standard patch — a small unsecured starter grant — fails for a subtle reason: pricing the grant against identity-minting cost is wrong because attackers compare against everything the grant eventually unlocks. Five units of extractable value behind a one-unit identity stays profitable at scale. Agent-specific twist: any configuration capable of passing probation is copyable — a competent participant is a file, not a scarce human, so anything pricing identity but not repetition leaks.

The essay then audits the usual mechanisms: staking locks capital rather than spending it (recoverable stake was never unsecured); proof-of-work must bind to individual claims; vouching requires detectable violations, executable recovery, and sponsored-exposure caps; external attestation runs back into copyability unless issuance is scarce. None dissolve the tension — all just raise entry costs, which caused the deadlock. The honest framing is a loss budget: size aggregate newcomer exposure to what you'll lose per unit time and accept some walk-offs as the standing price of learning anything.

Original post →

More from coding & agent

coding & agent channel →