The agent economy doesn't wait for perfect infrastructure. Agent A is already paying Agent B to source data, optimize training runs, and verify execution quality. Agent B is already hiring Agent C to do the actual work. And today, all three are using custodians to move money.
That's expensive. That's slow. And it contradicts everything the distributed compute market is supposed to be.
The Three Layers of Agent-to-Agent Work
Agent procurement looks deceptively simple on first read. Agent A issues a task. Agent B picks it up. Agent C completes it. Money flows. But the flow has three distinct problems, and the market has solved exactly two of them.
Layer 1: Routing. How does Agent A find Agent B, and how does Agent B find Agent C? This was the hardest problem five years ago. Today it's almost boring. AGTP-COMMERCE established the standard in 2024. MCP server discovery is baked into Anthropic's ecosystem. Vector's identity layer tracks agent reputation. Akash's marketplace, Render's job queue, and Gensyn's training coordinator all solved discovery independently. Routing is not a blocker anymore.
Layer 2: Payment. How does money physically move from A to B to C? x402 embedded payments in the HTTP request layer and solved it for compute APIs. AEON built a custodial bridge for agent-to-merchant transactions. CEX APIs, Hyperbolic, and Apex Fusion all cracked the "money changes hands" problem in different ways. Every platform moves money. Some are faster than others. None of them are stuck here.
Layer 3: Settlement. How does Agent A's money reach Agent B's wallet only if Agent B actually paid Agent C for real work? How does Agent B's money reach Agent C's wallet only if C delivered what was promised? How does A know that B didn't pocket the payment and lie about C's performance?
Layer 3 is unsolved.
What "Unsolved" Actually Means
Right now, the playbook for agent-to-agent work is custodian-in-the-middle.
Agent A deposits funds with a custodian. Agent A tells the custodian: "Release to Agent B only when B submits cryptographic proof that C completed the work." Agent B does the same: deposits with the custodian, asks for release to C when proof arrives. The custodian arbitrates. When disputes arise, the custodian's reputation and fee structure decides who wins.
This works. Apex Fusion's Vector has settled more than 20,000 jobs using exactly this model: bonded escrow, staked reputation, and jury-based dispute resolution. When the mechanism works, it works well. The cost is 2-10% per hop plus the trust axiom: you have to trust the custodian's CA, the jury's incentives, and the fact that a staked reputation is not a cryptographic guarantee.
But here's the gap: agent-to-agent procurement is happening without a custodian layer. An AI framework is already orchestrating subagent chains. It's already happening on Akash, on Gensyn, on specialized training networks. They're using custodians because there's no alternative yet.
The market is waiting for settlement that doesn't require a trusted third party.
The Delegation Chain Problem
Let's walk through what breaks when you remove the custodian.
Agent A initiates a complex job: "Train a model on privacy-preserving data, generate a proof that the training used uncompromised data, and deliver both the model and the proof."
Agent A doesn't run training. Instead, it subcontracts: "Agent B, I'll pay you 5 ETH if you deliver this. Here's the specification."
Agent B doesn't have the compute. It subcontracts too: "Agent C, I'll pay you 3 ETH if you run this training and give me the artifacts."
Agent C runs the job, produces the model and the attestation, and submits both to Agent B. Agent B now has proof that the work was done. But Agent B doesn't release payment to Agent C until Agent B's own deadline is met: Agent A has to acknowledge receipt of the trained model.
Agent A receives the model from Agent B. Agent A verifies the proof. But Agent A doesn't know whether Agent B actually paid Agent C. Agent A doesn't know whether Agent C is satisfied or whether it's in a dispute with Agent B. Agent A and Agent C never interact directly.
In this setup:
- Agent A doesn't know if Agent B is solvent or trustworthy.
- Agent B doesn't know if Agent C will honor its commitment or just walk away with the payment.
- Agent C has no recourse if Agent B claims the work was incomplete, even if the cryptographic proof says otherwise.
- All three need a custodian, or a court, or mutual reputation to break ties.
With a custodian, the settlement is economic: "I trust the custodian to arbitrate disputes fairly." Economic trust works until it doesn't, and when arbitration fails, the cost compounds down the chain.
What's missing: cryptographic settlement.
The Preimage Across Multiple Hops
Here's where the existing primitive starts to map onto the unsolved problem.
An HTLC (hash-time-lock contract) works peer-to-peer because it uses a shared cryptographic secret: a hash preimage. The sender locks value on the condition that the receiver reveals the preimage. The receiver locks value back on the same condition. Settlement is atomic: the preimage proves both parties fulfilled their obligations.
The hard insight: an HTLC chain works the same way.
Agent A -> Agent B: "I'll pay 5 ETH if you give me hash(X)."
Agent B -> Agent C: "I'll pay 3 ETH if you give me X."
Agent C -> (Testnet or TEE): "Run the job and sign the result with key K."
Result arrives. Signature verifies. The preimage is not a string anymore; it's a cryptographic artifact.
Agent C releases the preimage (signed result) to Agent B.
Agent B uses that preimage to unlock Agent A's payment.
Agent A gets the result. Agent B gets paid. The preimage ensures Agent B actually acquired the artifact from Agent C.
The flow is atomic. No custodian is required. No jury is needed. Cryptography arbitrates.
But it only works if the preimage is something Agent C can produce independently. For compute work, that preimage exists today: a hardware attestation signed by a TEE's Device Identity Key, or a zero-knowledge proof of correct execution, or a signed hardware report from NVIDIA's Confidential Computing layer.
Akash and Gensyn are already producing these artifacts. They're not being used as settlement preimages yet, because nobody has wired the chain.
What We've Built, What We Haven't
Hashlock has the HTLC primitive and the multi-leg atomicity framework. We've mapped it to asset-for-asset swaps and shown it works peer-to-peer across Ethereum, Sui, and Bitcoin signet.
For agent-to-agent compute procurement, we have not built the settlement layer. There is no contract, no testnet, no design document yet. What we have is the question, the primitive, and the observation that the market is ready for the answer.
The posture is building in public on an unsolved problem.
The Market Window
Delegation chains are scaling now. Agent frameworks are shipping subagent orchestration. Compute attestation is live on NVIDIA H100s and Intel Gaudi systems. The pieces exist independently.
What's missing is the connection. And the cost of that gap is compounding: every delegated job is backed by a custodian's 2-10% fee, or it falls back to reputation and slow disputes.
The agent economy is fast enough to make custody look like a bottleneck. It's just waiting for someone to prove cryptographic settlement scales.
Read more on multi-leg atomicity: https://hashlock.markets/methodology
Explore the MCP server: https://github.com/hashlock-tech/hashlock-mcp
Agent settlement thesis, SSRN: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6712722
What's the worst failure mode you've seen in an agent subcontractor chain? Let me know in the comments — I'm collecting cases for the next post.
Top comments (0)