Cover photo

Code Is Law, Again

Every system has two sets of rules: the ones written down and the ones the machinery actually enforces.

Every system has two sets of rules: the ones written down and the ones the machinery actually enforces.

For most of history, humans occupied the space between them. We wrote contracts, interpreted intent, negotiated exceptions and built institutions to decide what should happen when the wording of an agreement and the reality of an outcome diverged.

Crypto tried to collapse that distance.

A smart contract did not need to interpret intent. It did not care whether someone had misunderstood the agreement, made a mistake or discovered an outcome nobody had anticipated. If the transaction satisfied the conditions encoded into the system, it executed.

“Code is law” became the obvious slogan.

Then reality arrived.

The DAO was the first serious referendum. Its code produced an outcome that a large part of the Ethereum community considered intolerable, so the community changed the state of the system. Ethereum Classic preserved the original chain and the purer interpretation of code is law. Ethereum chose something much older: human consensus ultimately outranked machine execution.

The years that followed made the lesson difficult to ignore. Courts reached developers. Regulators reached protocols. Foundations and legal entities accumulated around supposedly autonomous systems. After Luna, Celsius, Three Arrows Capital and FTX, the industry relearned that deterministic software did not remove discretion, trust or human failure. Sometimes it merely moved them somewhere less visible.

By the end of the last cycle, “code is law” sounded less like a principle and more like something people said before hiring lawyers.

But I increasingly think we misunderstood why the idea mattered.

The problem with the first version of code is law was not necessarily the code.

It was the user.

The wrong user

Humans need ambiguity.

We forget passwords, misunderstand instructions, change our minds and occasionally need someone to consider circumstances that were not contemplated when the rules were written. We care about intention as much as execution. This is why the traditional financial system contains so much discretion. Transactions can be reversed, accounts recovered, contracts interpreted and unusual situations escalated to another human.

Blockchains are almost hostile to that way of operating.

A signature is valid or it is not. A balance exists or it does not. A contract executes according to its state. Settlement does not care that the person on the other side of the transaction had a bad day.

Much of the last fifteen years has therefore involved rebuilding human abstractions around machine-native systems. We added custodians, recovery mechanisms, multisigs, legal wrappers, compliance teams, customer support and increasingly familiar interfaces. We built deterministic rails, then reintroduced discretion because humans cannot function without it.

That often made crypto look like an unnecessarily complicated version of finance we already had.

Now the users are beginning to change.

AI agents can(almost) search, purchase, negotiate, allocate resources, manage credentials, call APIs and interact with financial systems. Most of what is described as autonomous commerce today remains early(non-existent), and much of it is still experimentation(extraction) disguised as adoption. I have lived through enough cycles to know that infrastructure and demand are not the same thing. visuals and metrics are usually serving a different purpose from the advertised intention.

The architecture is more interesting than the current volume.

For the first time, the natural user of a machine-native economic system may actually be another machine.

That changes the problem.

Authority, not intelligence

Most of the public discussion around AI is still focused on intelligence. How capable are the models? Which jobs disappear? Which framework wins?

The more important threshold is authority.

An AI that can answer questions is a tool. An AI that holds credentials, controls capital and has permission to act is an economic participant.

Once an agent has authority, knowing what it should do is no longer enough. You need a mechanism that determines what it can do.

Imagine an autonomous treasury agent managing $100 million.

There may be extensive contracts defining its mandate. Lawyers can specify permitted activities, fiduciary responsibilities and governing jurisdictions. Regulators can establish obligations for the company deploying it. The humans behind the system can still be held responsible when it fails.

All of that matters.

But if the agent decides at three in the morning to transfer $20 million somewhere it should not, none of those documents stop the transaction at the point of execution.

The thing that stops it is a spending limit, an allowlist, a scoped session key, a signing policy, a hardware enclave or a circuit breaker built directly into the system.

Law can determine liability afterward.

Code determines whether the action is possible in the first place.

This does not mean agents sit outside the law. They do not. They operate through infrastructure owned by companies, use payment systems governed by institutions and act on behalf of human or corporate principals. Providers can revoke access. Banks can freeze accounts. Courts can assign responsibility.

The point is not that law disappears.

It is that human adjudication operates on a radically slower clock than machine execution.

Once decisions and actions occur without a human approving each one, real-time governance has to move closer to the machinery itself.

It has to become executable.

When law becomes software

We have already seen an earlier version of this in financial markets.

As trading became faster and increasingly automated, markets discovered that human intervention was too slow to contain certain failures. The durable response was not only punishment after the fact. It was architecture: circuit breakers, trading halts and limits implemented inside the market itself.

The rules moved closer to execution because that was the only place fast enough to matter.

AI agents extend the same problem beyond trading. Payments, markets, logistics, data, compute, identity and eventually physical infrastructure will contain systems making decisions without waiting for a human to approve every individual action.

The legal system can still define responsibility. It can determine who should pay when something fails and what obligations the deployer had. But the immediate constraint will increasingly be encoded into permissions, wallets, APIs and execution environments.

This is where “code is law” becomes relevant again, but for almost the opposite reason crypto originally imagined.

The early interpretation was ideological. Code was supposed to replace institutions. If the contract executed, that was the legitimate outcome. Human discretion was treated as corruption entering an otherwise pure system.

That version did not survive contact with reality.

The next version is less romantic and probably more durable.

Code becomes law because autonomous machines require rules that operate at the same speed they do.

Governments are unlikely to write fewer laws as agents become more capable. Companies are unlikely to become less concerned with compliance, liability or risk. Instead, more written rules will be translated into executable policy.

A legal requirement becomes an internal policy. The policy becomes a permissions system. The permissions system decides whether the transaction is signed.

The judge does not disappear. The judge becomes the exception handler.

There is an important limitation here. Executable constraints are not perfect merely because they are written in software. A spending cap works only if the policy is correctly specified, the signing environment is secure, the keys are not compromised and the agent cannot route around the restriction through another contract or tool.

Code is both the constraint and the attack surface.

It does not eliminate trust. It compresses trust into the people who write the rules, the systems that hold the keys, the data those systems rely on and whoever controls the upgrade mechanism.

That makes the central question more political, not less.

Why blockchains enter the picture

None of this automatically means agents need blockchains.

Inside a single organization, conventional systems may be enough. Cloud permissions, bank API limits, hardware security modules and internal policy engines can constrain an agent perfectly well. A company does not need a blockchain every time its software calls another piece of its own infrastructure.

The case for open networks begins when agents need to transact across organizational boundaries.

Inside a company, there is already a shared administrator. Someone owns the database, defines the identities and can reverse or override the system.

Between companies, that shared administrator often does not exist.

An agent owned by one business may need to purchase data from another, pay an independent service, hold an asset issued elsewhere or coordinate with an agent whose operator it has never met. At that point, the participants need a shared state, a settlement mechanism and rules that neither side can quietly rewrite after the transaction.

Blockchains are useful here not because decentralization is morally superior, but because they can provide several things centralized systems rarely provide together: portable assets, shared state, neutral settlement, open participation, composability and the ability to transact across institutions without routing every interaction through one platform.

They are not a replacement for internal policy engines.

They are a coordination layer between them.

That distinction matters. Most agents will not need to live fully on-chain, just as most software today does not run entirely on public infrastructure. But when an agent needs to hold portable value, prove ownership, interact across domains or preserve the ability to leave one provider without abandoning its economic identity, open protocols become considerably more useful.

This also changes how many of crypto’s historically awkward characteristics look.

Addresses, signatures, continuous settlement, smart accounts and machine-readable state have always been difficult consumer technology. Humans want usernames, password recovery, chargebacks and someone to call when something goes wrong.

Machines still need abstractions, recovery procedures and exception handling. They simply do not need the same abstractions humans do. Software can manage addresses, simulate transactions, evaluate state and interact with programmable assets without requiring every underlying mechanism to be hidden behind a familiar consumer interface.

Perhaps blockchains looked unnatural partly because we spent fifteen years forcing humans to behave like computers in order to use them.

The machine interface finally has machine users.

The politics of executable rules

There is a darker side to all of this.

Code is not neutral simply because it is deterministic.

Someone defines the limits. Someone chooses which counterparties are permitted. Someone determines what constitutes suspicious behaviour, which information is private and under what conditions a transaction should be stopped. Someone controls the model, the policy engine, the signing environment or the upgrade key.

The keepers are the mechanism designers. Digitally embed game theory.

As money and identity become more programmable, those decisions become more consequential.

Digital money can create extraordinary efficiency. It can also make surveillance and financial exclusion almost effortless. An invisible rule inside a payment system can be more effective than a written prohibition because the person being governed may never encounter a decision-maker or even know which rule denied them.

The system simply refuses.

If economic rules are increasingly enforced automatically, the ability to exit, move assets and choose alternative systems becomes more important, not less.

This is where my interest in crypto has changed over the years.

I care less about the idea that crypto replaces governments, banks or existing institutions. That increasingly feels detached from how systems actually evolve. New infrastructure rarely abolishes the old order. It becomes entangled with it.

What still matters is the existence of credible escape hatches.

The ability to own something directly rather than merely holding a revocable claim inside someone else’s database.

The ability to move between systems when one becomes hostile, captured or simply stops serving you.

The ability to preserve some privacy in a world where digital money makes complete financial visibility technically trivial.

The ability to transact without every economic action being mediated by the same handful of platforms.

After enough cycles, optionality becomes a more interesting form of wealth than maximising exposure to any one system.

Money’s most useful job is not status. It is peace of mind and freedom of movement. Technology is valuable for much the same reason.

The point is not to escape every system. That is probably impossible.

The point is to avoid becoming completely dependent on one.

Code is law, again

History is not moving neatly from law, to code, back to law and then back to code.

It is looping at a higher level.

Crypto tried to use machine rules to govern humans and discovered the limits of that idea. Humans demanded interpretation, recovery and the right to override outcomes they considered intolerable.

AI now creates a different problem. Humans increasingly need machine rules to govern machines.

That is a much more natural fit.

Law will remain the final authority over people, companies and institutions. It will continue to decide responsibility, legitimacy and punishment. But as more economic activity moves toward autonomous systems, code becomes the authority at the point of execution.

In practice, that is where reality happens.

The first era of code is law tried to remove humans from the rules.

The next will encode human rules into machines.

It will not be defined by whether code governs agents. That is already happening. It will be defined by who governs the code

and whether the rest of us retain the right to leave.......