The burden of proof has moved onto the deployer.
Two forces arrived in the same window: regulation that requires institutions to evidence how an automated decision was authorised, and agents that are now acting rather than suggesting.
The regulatory cliff.
The EU AI Act and the UK's Smart Data Framework both push in the same direction: transparency, auditability and explainability for automated decision-making. Institutions can no longer point at a model and describe its output as an unavoidable property of the system.
What supervisors are asking for is narrow and concrete. Who authorised this agent. What limits was it operating under. Why did it act as it did. A firm that cannot answer those three questions with tamper-evident evidence is carrying an exposure that sits with a named individual, not with a department.
Standards are still forming. Firms that adopt a protocol-level answer now avoid the cost of retrofitting one into deployments that have already scaled.
The infrastructure gap.
The preceding years were defined by copilots — systems that suggested, with a human making the commitment. The shift underway is to agents that act, and the difference is entirely a governance one.
Financial infrastructure was built for human-to-human or API-to-API interaction. It has no negotiation layer: no space where two competing agents at two different institutions can settle a price or hedge a risk without exposing proprietary information or creating a compliance and anti-trust problem in the process.
Nothing in the existing stack fills that role, because nothing in the existing stack was designed for a counterparty that has to prove its own authority.
Connectivity is solved. Trust is not.
General agent connectivity standards let agents talk to tools and to each other. None of them constitute a trust layer for regulated financial interaction — they carry no institutional identity, no enforceable mandate and no evidentiary record.
| Capability | General agent frameworks (MCP, ADK) | IAP |
|---|---|---|
| Agent-to-agent connectivity | Yes | Yes |
| Posture | Observe and log after the fact | Prevent before execution |
| Institutional identity binding | Not addressed | Bound to the legal entity |
| Mandate enforced before execution | Not addressed | Sealed in a TEE; the mTLS tunnel is withheld |
| Proof that a decision followed the rulebook | Not addressed | Zero-Knowledge Proof of Logic |
| Provenance of the data behind a decision | Not addressed | C2PA-signed manifest per interaction |
| Negotiation without data exposure | Not addressed | Zero-knowledge channel |
| Evidentiary record for supervisors | Not addressed | Signed manifest per interaction |
| Designed against financial regulation | General purpose | Financial services specific |
The comparison is not competitive. A trust layer sits above connectivity and depends on it — IAP is designed to work with the frameworks institutions have already adopted.
"You wouldn't run a stock exchange without a clearinghouse. You cannot run an AI economy without a trust layer."
