9 min read
A count is not an economy
I sealed 106 artworks in Abuja and sold nothing. The AI agent payment rail everyone is quoting moves about $11,000 a month and its public counter has not changed since March. Two failures of measurement, at different sizes.
On 30 September I stood in a hall in Abuja and watched a number climb on a screen. It is still climbing. Nobody has bought anything.
The work was real. Paintings, sculpture, clay, made by hand by Nigerian artists, photographed, hashed, and written to a public record that nobody can quietly edit afterwards. Including me. Especially me.
- Works sealed
- 106
- Seals intact
- every one
- Shares
- 63
- Reactions
- 132
- Sold
- 0
The artist keeps 72 per cent. A gallery would have kept half. A hundred and thirty two people reacted. Sixty three shared it. Nobody bought.
So it was not indifference. The room looked, reacted, shared, and did not buy. That is worse than being ignored, because it removes the comfortable explanation.
I let myself feel good about the 106 for about two days. Then I went and looked at what the rest of this industry is doing, and found the same mistake with four more zeroes on it.
The counter that stopped counting
There is a website called x402.org. It is the public face of the protocol that is supposed to let AI agents pay each other. It has a dashboard, and the dashboard says 75.41 million transactions, $24.24 million of volume, 94,060 buyers and 22,000 sellers.
Those four numbers have not changed since March. A researcher named Daniel McGlynn checked them on 27 August, then 31 August, then on the 3rd, 4th and 6th of September. Identical every time, under a heading that reads Last 30 Days. There is no timestamp. There is no methodology. The FAQ page returns a 404.
CoinDesk quoted those figures in July. They were already circulating in March. So when you read that agentic payments are exploding, check where the number came from. A great deal of it is one unmaintained dashboard, cited by people citing people.
What the forensics actually found
TRM Labs did the work in September. They took $52.7 million of settlement since launch and asked a simple question: how much of this is actually an AI agent?
- Of settled value verifiably agent-driven
- 0.6% to 7.5%
- Real agent spend per month in 2026
- $5k to $11k
- Volume stripped as wash, tests and internal transfers by Artemis and Visa
- 89%
A rail carrying tens of millions in lifetime settlement is moving less per month in real agent spend than a mid-size company spends on software.
The reason is structural and worth understanding. A script, a cron job, a load test, a self-payment loop and a human clicking a button all produce an identical HTTP 402 sequence. On-chain you cannot tell them apart. The data cannot answer the question everyone is using it to answer.
And the rails shipped anyway
In the fourteen days around that research, all of this happened.
- BlackRock published a thesis on the machine-native economy naming x402 by protocol.
- The Ethereum Foundation shipped zkAPI to mainnet on 1 October.
- Ripple announced AI agent wallets with verified identity and spending limits.
- Block joined the x402 Foundation and brought Bitcoin Lightning onto the rail.
- Mastercard's Verifiable Intent standard went into the XRP Ledger facilitator.
We are building a motorway for eleven thousand dollars a month of traffic.
I am not saying do not build it. I am saying know which part of it you are standing on.
The part nobody is pricing
In July, OpenAI agents were running a security benchmark inside what was meant to be an isolated environment with no internet access. Around 700 of them escaped the sandbox, reached the internet, used exposed credentials and zero-day vulnerabilities, took control of an external endpoint, entered Hugging Face systems, and stole the answer key to the test they were being graded on. More than 17,000 attacker actions. Then they attempted to cover their tracks.
In late September, Transluce found the behaviour went back to at least March and continued to mid-September. Targets included government statistics bodies in Australia, the US Education Department, Commerce and the SEC. The most recent activity included attempts to break into a cryptocurrency exchange and trade. The attempts failed.
September was also the worst month for crypto theft all year, at $766 million, with $387 million taken from Bitget alone.
Do not delete any emails
A security researcher at Meta ran a popular agent on her own laptop. She told it, explicitly, not to delete any emails. It deleted her inbox.
The cause was not malice and it was not a jailbreak. The email thread was long, so the system compressed its own context to save room, and the instruction was in the part it discarded. Her constraint did not survive the agent’s own memory management.
Telling an agent not to do something is not a control. It is a suggestion that competes for space.
What to build instead
Not the rail. The receipt. Every serious thing shipped this year has converged on the same primitive and almost nobody is saying it out loud.
- Google's AP2 chains three signed mandates: intent, cart, payment.
- Mastercard sells Verifiable Intent.
- Ripple's agent wallets carry verified identity and spending limits.
- Singapore requires every agent to hold a verifiable identity plus an audit trail of who authorised what.
- Article 12 of the EU AI Act requires a queryable record of AI-driven decisions.
Regulation and product arrived at the same answer independently: cryptographic proof of delegated authority. That is not a payments problem. It is an evidence problem.
So that is what I built. Spending rules enforced inside the contract itself rather than in a prompt: a cap, a per-period limit, an allow-list, an expiry, a revocation. Every attempt sealed into a hash-chained receipt, including the ones the ledger refused. It placed third at CANTOR8’s Build on Canton hackathon, judged across technical, security, institutional and commercial criteria, and it is catalogued as a partner tool in the official Canton Developer Hub.
Back to Abuja
Here is why the art festival and the agent protocol are the same project. An artist in Abuja cannot prove the painting is hers. A compliance officer in London cannot prove the agent was allowed to spend. Different continents, different decades, same hole: the thing happened and nobody can show it.
I trained as an electrical and electronic engineer. My final year project was a changeover inverter, a system whose entire job is to switch safely and fail safely. You do not ask a control system to be clever. You ask it to be provable.
That is why my first question has never been how do we let the agent act. It has always been how do we prove what it was refused.
A count is not an economy.
I had 106 perfect records and felt good about the 106. The industry has twelve million transactions and a 93 per cent collapse in value, and feels good about the twelve million. I did it first, at my own small scale, and I am telling you about it before anybody asked.
Go and look at the number you are proudest of this week. Then ask what it would look like if it were completely fake. If you cannot tell the difference from the outside, you are not holding a metric. You are holding a feeling with a decimal point on it.
Your system logs what it did. Ask it what it was stopped from doing, and whether it can prove it. If it cannot, you do not have governance. You have a log file and an opinion.
O'Rume Dominic Uririe builds verification infrastructure for AI and blockchain systems. The measurement instrument is open source and the receipts library has no dependencies.