An Optimist With Receipts
This is long, and deliberately so, because the argument only becomes useful where it gets specific. Here is the lay of the land, so you can read it in the order that serves you and stop where it stops paying.
The thesis in one paragraph. Finance did not survive the Internet by luck or by regulation alone. The Internet dissolved bundles held together by distribution, and finance's bundles were held together by something else: the cost of proving a claim to a stranger. That cost is now collapsing, and cost collapses move Coase's boundary rather than merely lowering anybody's expenses. What follows works out where the boundary lands.
The diagnosis comes first, in the six sections up to "Which bundles are real". What a solvent actually does, why proof of statements and proof of claims are different problems, the two solvents and the agitator that makes them bite, plus a third bond that dissolves later in the securities services section, where the solvent and the agitator act together for the first time, and the uncomfortable finding that a decade of institutional spending went to the most tractable of the seven costs rather than the most valuable. If you read only one thing, read the bundle test: it tells you which of your own bundles are held by technology and which by statute, and only the first kind dissolves.
The analytical core runs from "From batch to stream" through "Two fabrics, one equation, and the seam". Securities services is where the thesis is most falsifiable, so it gets tested there first. Then the composable firm, which is the part I would defend hardest and the part most likely to be wrong: it argues that dissolved transaction costs precipitate as protocol, that seven durable positions survive because seven inputs cannot be composed, and that composition has costs of its own large enough to run the whole argument backwards. Then the seam between fabrics, where I think the next correspondent banking business is hiding.
The middle stretch applies it function by function, to markets, liquidity, issuance, distribution, regulation and trust. Practitioners in one of those functions may reasonably start there and read backwards. Two warnings live in that stretch: benevolence cannot be verified by any protocol, and ontology governance is systemically important infrastructure that industry governs and no prudential authority supervises.
The settlement section is where the enthusiasm dies, and it is the one I would want read by anyone building a business case. Atomicity is a funding constraint, not a speed feature. Somebody has to provide the elasticity, machine-speed drawdown is correlated drawdown, and pre-funding is refinanced rather than defeated.
Then nine attacks on my own argument, in the order I would attack them. The first is the one I would lead with: privacy and transaction-level financial crime compliance may not both be satisfiable, and I have been selling them as complements. The last goes underneath all the others: the settlement asset this paper assumes may never arrive. Also there: the two scenarios I cannot choose between and the observable test that would settle them. Then what this means for the bespoke outcomes thesis, why programmable value is a different category from programmable information, and a bridge back to what to do about it on Monday. The claim-status discipline runs throughout: live, bounded, pilot and design intent are marked, and the note on sources at the end says plainly where I am citing my own work.
Start with the aphorism everyone in this industry can quote and almost nobody has examined. Jim Barksdale, chief executive of Netscape, reportedly coined it on the 1995 initial public offering road show: there are only two ways to make money in business, bundling and unbundling.¹ For three decades it has been treated as a given that money can be made in either direction, an eternal oscillation, which is precisely why it is quoted so comfortably at conferences.
Ben Thompson's contribution is to test it and find it wanting, and the test is what this paper borrows. Bundles do not re-form just because someone can argue the economics. Bundles work best when you do not have a choice, and when they have everything, and both conditions are produced by technology rather than by strategy. Cable worked because of antennas and satellites. Spotify is, on his reading, the only genuinely new bundle the Internet created, because streaming plus cellular made it easier than piracy and cheap enough that a la carte stopped being a real choice. Economics do not make bundles work; technological change does, particularly when it supplies not only a carrot but a stick.¹
That gives us a diagnostic rather than a proverb, and it comes with a second piece of apparatus. In The AI Unbundling, the idea propagation value chain, creation, substantiation, duplication, distribution, consumption, shows that every communications revolution has removed whichever step was the bottleneck, with the profit pool sitting on that bottleneck right up to the moment it disappears.²
Underneath both sits the actual foundation, which is not Barksdale and not Thompson but Ronald Coase. The Nature of the Firm, 1937: firms exist because using the market has costs, and it is often cheaper to internalise those costs inside a command-and-control structure. Coase's own examples are the cost of discovering what the relevant prices are and the cost of negotiating and concluding a separate contract for every exchange. Command-and-control has costs of its own, which he described as the costs of organising and as diminishing returns to management, and the natural size of a firm is the point where internal coordination cost roughly equals the market transaction cost it replaces.²²
One piece of vocabulary needs flagging, since this paper leans on it. Coordination costs is not Coase's phrase. It is a later gloss, and Thompson uses it when summarising him.¹ I will use it too, because it is the standard shorthand, but it carries a trap worth naming: Thompson's own list of market costs ends with coordinating, so the same word does duty for a cost of using the market and a cost of running a firm. Those are opposite quantities that move in opposite directions. Keep them apart, because the entire argument of this paper turns on them moving at different speeds, and most writing in this field runs them together.
A second piece of vocabulary needs the same treatment, and for a less comfortable reason. Fabric is not a neutral term. NFH uses it as the name of its own architecture, and I use it throughout this paper as a generic category, meaning any network that combines programmable value, verifiable credentials, discoverable services and policy expressed as code. Where I mean the specific product I name it. Where the word appears alone it means the category, and the argument is intended to hold for Canton, for Swift's shared ledger work, or for something nobody has built yet. Readers should discount the term to the extent they think I have failed at that separation, and the disclosure at the end of this paper is relevant to how much discount to apply.
So the chain of ideas runs Coase, then Barksdale as folk wisdom, then Thompson deconstructing the folk wisdom back onto Coase. Put the pieces together and you have the only tokenisation thesis worth defending. Technology does not reorganise industries by making things cheaper. It reorganises them by moving Coase's boundary, and it moves that boundary by removing a bottleneck in a value chain.
The popular version of this argument asserts a law where there is only a possibility. Rent does not automatically relocate when a bottleneck falls. Four things have to hold, and naming them is what separates analysis from prophecy. The bottleneck function must be genuinely commoditised, meaning supply becomes abundant and substitutable rather than merely cheaper. Some adjacent function must become newly scarce, because rent requires scarcity somewhere and removing a bottleneck does not create one. Whoever sits on that scarcity must be able to appropriate the surplus, which requires a chokepoint or a demand-side relationship. And the change must alter the relative cost of transacting in the market versus coordinating internally, because a technology that lowers both at the same rate produces a cheaper industry with its boundary exactly where it was.
The fourth condition is the one that connects the value-chain story to Coase, and the third is the one the industry never states. If no party holds a structural barrier, the surplus does not relocate at all. It dissipates to buyers as lower prices, and nobody captures it. That is the ordinary outcome of competition, not an exception, and any strategy that assumes rent must reappear somewhere convenient has skipped the only step that matters.
Now ask the uncomfortable question. The Internet removed the distribution bottleneck across every information industry on earth. Newspapers were annihilated. Record labels were restructured. Video rental disappeared inside a decade. Financial services, arguably the most information-intensive industry in existence, came out the other side with its structure essentially intact.
What survived was not the pricing. Fees inside finance were savaged. Retail equity commissions went to zero. Active management fees collapsed under index funds and exchange-traded products. Electronic execution removed a generation of sell-side intermediaries. Payments were restructured by firms that did not exist in 1995. What survived was the architecture: the same intermediation chain, the same institutional roles, the same list of parties who must be present before a transaction is considered done. Custodians still custody. Registrars still register. Clearing houses still clear. Correspondents still correspond.
Concede the qualification that a market structure specialist will raise immediately, because it is real and it sharpens the point. The chain did get shorter in places. Central counterparty clearing replaced webs of bilateral exposure. Direct market access removed layers of broker intermediation. Correspondent relationships consolidated sharply, and Swift's own gpi work compressed the number of hops a cross-border payment passes through. So the accurate claim is not that no intermediary was ever removed. It is that the surviving roles are the same roles, and every one of them is still defined by the act of vouching for a fact. Consolidation reduced the number of parties performing each function without retiring a single function, which is exactly what you would expect if the binding constraint were the cost of proof rather than the number of firms.
That pattern is itself the clue. An industry whose fees compress while its structure holds is an industry where technology has attacked the distribution of its product without touching the reason for its existence.
That is not luck, and it is not regulation alone.
The metaphor is doing more analytical work than most people using it realise, so it is worth being precise about the chemistry.
A solvent destroys nothing. It dissolves the binding agent and leaves the constituents intact, free to separate and go wherever the economics send them. Newspapers were not destroyed as journalism. What dissolved was the bond between editorial and advertising, and once that bond broke, the constituents went to different places: advertising to wherever the users were, journalism unbundled and repriced. The institution that had held them together turned out to be the bond rather than either of the things it bound.
So the diagnostic question for any industry is never whether it will be destroyed. It is: what is the binding agent, and what dissolves it?
For newspapers, the binding agent was the printing press plus physical delivery, producing a geographic monopoly on duplication and distribution. The Internet dissolved it by making both free. For television, spectrum scarcity and then cable and satellite. Broadband dissolved it. For record labels, manufacturing and radio access. In each case the industry mistook the bond for the business, defended the bond, and lost.
What is the binding agent of finance?
The impossibility of proving a state of affairs to a stranger at a distance, cheaply, without a trusted third party.
Everything else follows from that single impossibility. You cannot prove you own the bond. You cannot prove you are permitted to hold it. You cannot prove the money moved, that the transfer is irreversible, that you are who you claim to be, that your track record is real, that the collateral exists and is unencumbered. Because none of this could be proven cheaply at a distance, we built institutions whose actual function is to be the proof: custodians, registrars, clearing houses, correspondent banks, auditors, ratings agencies, exchanges, trustees, transfer agents, fund administrators.
Financial institutions are proof substitutes. We built cathedrals because we could not send a verifiable receipt.
The adjective is load-bearing. We could always send a receipt. What we could not do was send one that a stranger would accept without an institution standing behind it. So it is worth being exact about what the title of this paper means, since the whole argument depends on it.
A verifiable receipt is a record of a state of affairs that a stranger can check independently, without trusting the path it travelled by and without going back to the institution that maintained it. Note what is not in that sentence: you still trust the party who issued it. What you no longer need is the intermediary chain that used to carry, restate and vouch for the assertion in transit. Four properties make it work: it is bound to an identity that can be checked, it carries the authority under which it was made, its integrity is provable against tampering, and its revocation status is discoverable. What it never contains is a guarantee about the value of the thing it describes, or an undertaking by anyone to make you whole if the description proves wrong. And one further boundary, because it is the one most often elided: a receipt establishes that an authoritative party made this assertion and has not withdrawn it. It does not establish that the assertion is true. Reliance still rests on the issuer and on the evidence behind what the issuer said.
But "proof substitute" hides three different jobs, and everything that follows depends on keeping them apart. An institution can attest that something is so, which is evidentiary. It can constitute the thing, so that the act of recording is what makes the transfer legally effective rather than merely recorded. Or it can underwrite, standing behind the outcome, so that when the proof turns out to be wrong there is someone with a licence, a balance sheet and a legal identity to answer for it. An auditor mostly attests. A registrar mostly constitutes. A rating agency attests, with a thin layer of reputational underwriting. A custodian does all three at once, which is why custody is the hardest of these businesses to reason about and the one most often declared dead prematurely.
The three jobs have entirely different exposure to the solvent, and conflating them is the largest single source of confusion in this debate. Attestation is a verification problem, so cryptography attacks it directly. Constitution is a legal fact, so cryptography attacks it only where a legislature has said that the record is the title. Underwriting is not a verification problem at all, and no amount of cryptography touches it.
Which means the honest answer to what a ledger actually proves depends entirely on what kind of claim is on it.
Kind of claim | What the ledger proves | What still depends on institutions and law |
|---|---|---|
Native digital asset | Everything. The record is the asset, so proof and constitution coincide | Almost nothing, which is the one case where the maximalists are simply right |
Tokenised claim on an off-chain asset | The state of a representation: who holds the token, under what conditions, with what history | Whether the token is the title, whether the underlying asset exists, whether it is already pledged elsewhere, and who answers if it is not |
Credential about an external fact | That a named party attested to a fact, at a time, under a schema, and has not revoked it | Whether the fact is true, and whether the attestor is worth anything if it is not |
Read the middle row carefully, because that is where institutional finance actually lives. A tokenised bond is not a bond. It is a representation of a bond whose legal character is conferred somewhere other than the ledger. Tokenisation makes the representation cheap to verify, exact and instantly transferable, and does nothing whatsoever about the three hard questions underneath it. That is not an argument against tokenisation. It is an argument about which part of the cathedral is load-bearing, and it returns twice below: once where regulation hardens rather than dissolves, and once at the end, where the residue that cannot be computed turns out to be underwriting rather than proof.

The obvious objection to that framing is that newspapers also sold verification. A masthead is a verification asset. Reuters, the Wall Street Journal and the Financial Times never sold raw information, which was abundant even in 1950. They sold information you could act on without checking. If the Internet dissolved industries that sold verification, why did it dissolve theirs and not ours?
Because they verified different things, and the difference determines which technology can dissolve them.
Newspapers verified statements about the world. Banks verify claims on the world.
Three consequences follow, and they are the reason finance's solvent arrived three decades late.
The failure modes are not comparable. A false statement costs reputation and can be corrected by a subsequent statement. A false claim costs someone their property and cannot be corrected by assertion at all, only by enforcement.
Therefore the verification mechanisms are not comparable. Statements can be verified socially, through reputation at scale, competing accounts, community correction and aggregate signal, which is why Wikipedia works and why a thousand citizen accounts of an event converge on something usable. Claims must be verified authoritatively, because there can be only one owner of a given asset at a given moment. You cannot socially crowdsource title.
The adverb is deliberate, and the obvious objection proves the point rather than defeating it. Bitcoin verifies title without a trusted third party, and it is the counterexample anyone will reach for. But look at what it actually does. Nakamoto consensus is an expensive, deliberately engineered mechanism for producing exactly one authoritative record of who owns what. It does not aggregate opinions and settle on a reputational average, which is how a statement gets verified. It manufactures singularity by burning resources until disagreement stops paying. Bitcoin is therefore not an exception to the rule that claims require authority. It is the most literal demonstration of what authority costs when you refuse to inherit it from an institution.
Therefore the solvents are not the same solvent. Reputation at scale is a distribution phenomenon, and the Internet is a distribution technology, so the Internet dissolved reputational verification comprehensively. Authoritative verification requires the ability to produce a single, exclusive, non-repudiable record that a stranger can check without trusting the publisher. That needed cryptography, not connectivity.
Which gives the clean statement of where we are:
The Internet was a solvent for the verification of statements. Programmable value is a solvent for the verification of claims. Newspapers sold the first. Banks sell the second. That is why one dissolved in 1995 and the other is dissolving now.
And there is a warning inside the newspaper case that our industry should read carefully. What actually happened to publishing was that verification was unbundled from distribution, and the verification business turned out to be far smaller than the bundle had been. The FT and the Journal still monetise verification successfully. What died was the local paper whose verification premium was really a distribution monopoly wearing a masthead. When finance's bundle dissolves, every institution finds out how much of its fee was verification and how much was position. Most will be shocked by the ratio.
This is not a fringe framing. When Agustín Carstens and Nandan Nilekani set out the Finternet vision, they built the argument on a unified ledger whose properties include immutability and verifiability, alongside finality as a core characteristic and programmability through smart contracts, with security and privacy named among their eight design principles.²⁰ The grouping of those four as a single axis set is mine rather than theirs, and their formal list of principles is a different cut, but the substance is in their text: verification is treated as a property of the system rather than an operational detail. The industry has mostly read that list and gone straight to programmability.
Three agents are acting here, and they do three different jobs. Collapse them and the argument becomes enthusiasm.
Programmable value is the first solvent, and it dissolves the reconciliation bond. When state is shared or provably synchronised, you no longer need an institution stationed at every ledger boundary to agree that two records match. The BIS description is exact and unromantic: tokenisation "enables the integration of messaging, reconciliation and asset transfer into a single, seamless operation".¹³ The prize is not speed. It is the elimination of a category of work that a 2015 industry estimate put at between seventeen and twenty-four billion dollars a year in trade processing alone, a figure BIS cited and one worth reading with its provenance in view, since it originates with a post-trade vendor and is now a decade old.¹⁴,³⁴
Verifiable credentials are the second solvent, and they dissolve the attestation bond. The issuer does not disappear. Somebody authoritative still has to assert the fact, and a credential asserting your capital adequacy is worth exactly what the asserting party is worth. What dissolves is the repeated reconstruction and captive distribution of that assertion: you hold portable, cryptographically signed, selectively disclosable proof yourself, and the institution that made the assertion no longer controls who can check it or charges for the checking. This is the one the industry has almost entirely ignored, and it reaches further, because attestation is the deeper business. Custody is attestation about ownership. Audit is attestation about books. Ratings are attestation about creditworthiness. Know-your-customer is attestation about identity. Every one of those firms exists because you could not carry your own proof.
Agents are not a solvent. They are the agitation. This distinction corrects a great deal of loose thinking about AI in finance. Agents dissolve no bond by themselves. What they do is drive the transaction rate to a level at which human-mediated verification becomes physically impossible, taking the reaction to completion instead of leaving it at equilibrium. The scale contemplated is a billion-plus businesses, more than a trillion agents, and micro-transaction volumes around a million times today's, at which point, in the fabric's own phrase, "the toll-taking intermediary, viable when transactions were few and large, becomes a tollbooth on every drop of a flood".⁴ Read those numbers as a boundary condition rather than a forecast, because they are not mine and I am not defending them as a prediction. They describe the order of magnitude at which the argument stops being economic and becomes physical. Below it, human-mediated verification is merely expensive and the industry absorbs the cost. Above it, the process cannot run at all. Whether and when we arrive is an empirical question, and the useful discipline is to ask which of your processes breaks first if volumes rise a thousandfold rather than a millionfold.
Without agents, provable state and portable credentials produce a tidier version of the same slow world, and the industry absorbs them as cost reduction, which is precisely what it has been doing for a decade. With agents, the old process is not expensive. It is impossible. Impossibility changes an industry in a way that expense never quite manages, because a cost differential invites deferral and an impossibility does not.
Since the agitator is a wager rather than an observation, state what happens to the rest of this paper if the wager loses, because the answer is not symmetric. If agent volumes never arrive, the dissolution claims degrade into a slower and more optional version of themselves: costs fall, margins compress, nothing is forced, and institutions defer for another decade exactly as they have. But the hardening claims survive untouched, because they do not depend on volume at all. Legal finality still requires a statute. The seam between two fabrics still has to be borne by somebody. Underwriting still needs capital. Ontology governance is still unsupervised. Answerability still cannot be composed. If the agitator disappoints, this paper's warnings stay right and its promises go quiet, which is an uncomfortable asymmetry to publish and the honest way to read everything that follows.

The transaction-cost tradition that begins with Coase names the costs that make markets expensive and therefore make firms worth having. Coase himself pointed at discovering the relevant prices and at negotiating a separate contract for every exchange; the fuller taxonomy, search and information, bargaining and decision, policing and enforcement, is Dahlman's, and the working list most people use, searching, negotiating, contracting, monitoring, enforcing, coordinating, is the tradition's rather than any one author's.³³,¹ Finance quietly adds a seventh that none of them contemplated, because Coase was writing about the firm in 1937 and not about the legal transfer of title: settling.
Set the seven against what the emerging infrastructure actually does.
Coase cost | What pays for it in finance today | What collapses it |
|---|---|---|
Searching | Sales coverage, relationship managers, the broker's rolodex, listing fees, data vendors | Registry, catalogue and discovery, where an offering "published once is findable across every aligned network"⁴ |
Negotiating | Trading desks, syndicate, bilateral documentation, RFQ processes | Self-executing contracts where "the contract between buyer and seller is the wire format"⁴ |
Contracting | Legal drafting, documentation teams, annual contracts, procurement cycles | Policy-as-code: signed Rego and Open Policy Agent bundles, network manifests, credential and licence schemas⁴ |
Monitoring | Middle office, reconciliation estates, surveillance, periodic reporting | Cryptographically anchored observability, and bi-temporal state making audit continuous rather than reconstructed⁴,¹⁰ |
Enforcing | Legal recourse, courts, collateral management, dispute processes | Escrow, refund and arbitration as protocol concerns, with underwriter-backed gradient guarantees³ |
Coordinating, in both senses: sequencing counterparties in the market, and running the hierarchy internally | Layers of management, middle managers translating strategy into execution¹ | Intent engines and agent orchestration, where a hundred-person firm coordinates as effectively as a ten-thousand-person one⁹ |
Settling | Custody, clearing, central securities depositories, nostro and vostro, two to five days cross-border | Atomic lock, commit and unlock with a federation protocol; delivery-versus-payment with privacy preserved⁴,⁵ |
Read that table as an indictment, because that is what it is. And note what the left-hand column is: these are market transaction costs, the costs of using the market. Internal coordination cost, the price of running the hierarchy that replaces the market, sits on the other side of Coase's boundary and is not on this list. It appears in the row on coordinating only because finance's own internal apparatus is itself a cost, and agent orchestration attacks it.
Every serious institutional tokenisation programme of the last decade has attacked item seven. Settlement. Delivery-versus-payment, atomic finality, T+0, the shared ledger. It is the item that looks most like finance, the item our engineers understood, and the item our conference agendas were built around. Items one through five are attacked by discovery, credentials, policy-as-code and audit anchoring. They are not attacked by ledgers at all.
State the indictment precisely, because a technical reader will otherwise dismiss it. The six other costs are not independent of the ledger: credential schemas, executable policy and continuous audit anchoring are built on the same substrate, and several of them are unbuildable without it. So the charge is not that the industry spent on the wrong cost. Settlement infrastructure was the necessary first step and it now largely exists, which is a real achievement. The charge is that the work stopped there. We built the substrate and never built the layer that earns on top of it, which is a sequencing failure rather than a misallocation, and it is a more damning one, because a misallocation can be defended as a judgment call while stopping halfway cannot.
The larger claim is not available to me. I cannot tell you that items one through five are the majority of finance's cost base, because no public comparative decomposition of financial services costs across Coase's categories exists, and that absence is itself remarkable in an industry that measures everything. What I can defend is narrower and still uncomfortable: items one through five are the costs least attacked by a decade of institutional spending, and on the testimony of the people building the alternative they are the harder design problem.
That testimony comes from builders rather than critics, which is why I lean on it. The fabric's own guidance on securitising illiquid assets tells implementers that "most of the design effort goes into the credential schemas, not the token plumbing".¹¹ Its guidance on building a data marketplace for agents says the hardest design decision is the licence-and-purpose credential model, and to solve that first.¹² Two separate pieces of guidance from the same corpus, then, both saying that basic ledger plumbing is the more tractable engineering problem rather than the core design bottleneck. Same authorship, so treat it as one considered position rather than two independent findings.
So the honest summary of the industry's decade is uncomfortable. We industrialised the tractable part and stopped. We solved the one transaction cost Coase did not think worth listing, and left search, negotiation, contracting, monitoring and enforcement in PDFs, in email, in the judgment of experienced humans and in the reconciliation estate. We laid the pipes and never built the houses. Then we expressed surprise that beautiful settlement pilots did not become businesses.
The word tractable is doing specific work here, and the sloppy version of this claim is false. Settlement is not cheap in any absolute sense: it carries the legal, liquidity and interoperability difficulties this paper spends a whole section on, and cross-fabric settlement is the hardest unsolved problem in the field. What is defensible is comparative and narrower. Relative to designing the credential schemas, licence models and policy artefacts around it, moving the token was the part our engineers knew how to finish, which is why it is what got finished.
There is a second reason, and it is less flattering to my own indictment. Look at what actually reached production and the pattern is unmistakable: every one of them pays off for a single firm acting alone. Broadridge's repo platform, intraday repo at a single bank, a tokenised money market fund, auto-collateralisation inside one central securities depository. None of them needed a counterparty to agree, a consortium to form, or a schema to be shared. Adoption in this field has proceeded through unilateral-benefit wedges, not through network value, because a wedge can be funded by one budget holder against one business case while network value requires everyone to move at once and therefore nobody moves first. That reframes the indictment rather than softening it. Settlement got built because settlement had wedge economics: internal, controllable, demonstrable in one quarter. The other six costs are mostly shared-benefit problems, since a credential schema is worth little until several institutions accept it and a policy artefact is worth little until a supervisor recognises it. So the tractable part was also the individually profitable part, and the layer that earns on top is the layer that requires someone to solve a coordination problem before anybody earns anything. Which is a harder charge to answer, and a more useful one, because it tells you what to build: the wedge that works alone and composes later.
The test stated at the top of this paper is worth restating as a working instrument, because it is the one we now apply to ourselves. A bundle survives when you have no choice and when it has everything, and both conditions are technological rather than economic.¹ Cable satisfied both because of antennas and satellites. Newspapers satisfied both because printing presses centralised duplication. Amazon Prime does not qualify, being a logistics bundle rooted in the physical world.
Apply the test to our own bundles and the picture stops being comfortable.
Bundle we sell | What actually holds it together | Verdict under the test |
|---|---|---|
The universal bank relationship | Balance sheet, licence, privileged access to payment rails | Regulatory, not technological. Dissolves at the speed of policy |
Custody, servicing, reporting and FX | The impossibility of reconciling incompatible ledgers | Technological. Reconciliation is the product, and shared state removes it |
Listing, price discovery and clearing | Netting economics and legal finality | Mixed. Netting is real value; its bundling with a venue is not |
The fund wrapper: NAV, sleeve, dealing calendar | The impracticality of holding thousands of positions individually | Technological. A programmable portfolio makes the wrapper optional |
Index, data and distribution | Trusted computation plus brand | Erodes as computation becomes independently verifiable |
Settlement finality | Insolvency law, jurisdiction, enforceable title | Statutory. Irreducible without a legislature. This is finance's Amazon Prime: not held by technology, so no technology dissolves it |
There is a second-order point hiding in the rule that bundles work best when you have no choice. In our industry, licensing is that condition, enforced by statute. Regulation is a bundle-preservation technology. That is why finance's bundles dissolve more slowly than gaming's, and why the decisive fight is fought in policy design rather than product design. Anyone building here who treats the regulator as an obstacle rather than as the battlefield has misread the terrain.

Everything above is a way of thinking. Here is what it looks like when applied all the way through one industry, and it happens to be the industry where the argument is most testable, because securities services is the purest proof-substitute business in finance. Verification of claims is the largest thing it sells, though as the taxonomy below shows it is not the only thing, and the difference decides what survives. What follows in this section is my own analysis of the sector rather than a summary of anyone else's, and where an empirical claim appears it is sourced to the operator making it.
Start with the observation that makes the whole sector legible. Everything in securities services rests on a batch assumption: settlement at end of day, net asset value calculated once daily, yield accruing and distributing periodically, reconciliation overnight, corporate actions in cycles. Each of those was rational, and each was rational for a specific reason that no longer holds. Funds pooled capital because aggregation was efficient when per-transaction costs were high. Net asset value was daily because compute was expensive and pricing required overnight runs. Transfer agents maintained registers because paper-based ownership required manual reconciliation. Settlement waited until end of day because networks were slow and coordination required human oversight.
Read that list again through the bundle test and the conclusion is unavoidable, because every item names a technological condition rather than a commercial preference. The batch cycle is a bundling technology, and the fund is a bundle held together by the cost of doing things one at a time. Which gives us a third bond to add to the two named earlier, and it needs its dissolver classified rather than left vague, because the scheme set out above has only two solvents and an agitator. Programmable value dissolves the reconciliation bond. Credentials dissolve the attestation bond. The aggregation bond, which is what holds the pooled fund together, is dissolved by neither. It is dissolved by cheap per-event execution, which is the first solvent running at the agitator's frequency. Programmable value makes a single event cheap to settle; agent-driven volume is what makes settling every event separately the normal case rather than an expensive exception. That is the first place in this argument where the solvent and the agitator interact rather than merely coexist, and it predicts where else to look: any bundle held together by per-item cost rather than by legal or fiscal structure dissolves at the point where the frequency rises, not at the point where the technology arrives. Which licenses a blunt conclusion, stated narrowly enough to survive an operations director's first objection: mandatory batch is no longer a technical requirement, and cadence becomes a configuration choice rather than a constraint. Batch does not vanish, and several of its uses are load-bearing rather than inertial. Netting requires a window by construction, and a window is a batch. Tax lots, corporate action entitlements and record dates are legally periodic. Human oversight needs a cut-off to review against. Bulk processing remains cheaper per item where the items genuinely arrive together. What changes is that each of those becomes a reasoned choice with a stated purpose, rather than the default everything inherits. The residue is what should worry an incumbent: batch retained because a legal or netting requirement demands it is architecture, and batch retained because the overnight cycle is how the department is organised is inertia, and the fabric makes the difference visible for the first time.
One caution on the word, since this paper uses it twice in unrelated senses. The aggregation bond here is the pooling of many small items into one processed unit, which is an operational economy. Thompson's Aggregator is a firm that owns the demand relationship at zero marginal cost, which is a market position. The first is dissolving. The second, as the attacks below concede, relocates and survives.
Two primitives break it. Atomic value transfer collapses a process that currently runs across days rather than seconds and keeps counterparty risk live throughout. Continuous returns streaming collapses a return that currently arrives as semi-annual coupons, quarterly dividends, monthly lending fees and gains at disposal, leaving the investor to assemble a total return from several unsynchronised batch processes.
Map the dissolution and it is unusually clean, because each item disappears for a stated technological reason rather than a competitive one.
One discipline before the table, and it applies to the rest of this paper. A reader is entitled to know which claims describe something running today and which describe something an architecture intends. So each row carries a status: live means deployed and processing real value at some scale; bounded means live within a single platform or a limited participant set; pilot means tested with real or simulated value but not in production; design intent means specified and argued but not yet demonstrated.
Batch world | Stream world | Why it dissolves | Status |
|---|---|---|---|
Pooled funds | Segregated managed accounts | Aggregation was a response to per-transaction cost | Design intent, and it collides with tax structure |
Daily net asset value | Continuous real-time valuation | Compute is no longer scarce | Design intent. Tokenised money market funds are live, but continuous valuation is not what any of them claim |
Transfer agent | The programmable ledger is the register | Ownership no longer needs a separate record | Bounded, live for tokenised funds on single platforms |
Overnight reconciliation | Single authoritative state | There is nothing to reconcile | Bounded, true within a fabric, false across seams |
Batch settlement at T+1 | Atomic delivery versus payment | Coordination no longer needs a window | Live within platforms, pilot across currencies |
What survives is worth reading closely, and the usual answer in the sector is that the only thing which cannot be automated is trust, with custody surviving by transforming into the fabric operator: identity verification, regulatory compliance and the trust layer for atomic operations, while corporate actions remain a custody function where the judgment stays human and the execution becomes real-time.
That is directionally right and I sharpen it later in this paper rather than accept it, because one item on that survival list does not belong there.
Then the section that matters most, and it is the one I had not adequately reckoned with. Nothing rests. When value transfers in milliseconds, an investor will not tolerate money or assets sitting still. Cash immediately seeks yield-bearing instruments. High-quality assets are lent out, pledged as collateral or posted against margin. And the consequence is the opposite of the disintermediation fantasy. The result is not fewer transactions. It is orders of magnitude more: more transfers, more oversight, more continuous benchmarking, with collateral quality assessed continuously rather than at the end of each day.
This is not a thought experiment, which is the other thing the sector's sceptics need to absorb. Franklin Templeton runs an on-chain money market fund with a patent-pending feature that calculates and distributes yield proportionally, in its own words "down to the second, when a tokenized security is transferred from one party to another".²³ Kinexys at JP Morgan and Broadridge's Distributed Ledger Repo are in production, as is HSBC Orion for digital bond issuance, approved in July 2026 as the first platform permitted to operate as a digital securities depository in the Bank of England's Digital Securities Sandbox,³⁷ and the Monetary Authority of Singapore's Project Guardian is a live multi-jurisdiction pilot programme. Accrual on transfer is the single most useful data point in that list, because continuous returns streaming is the primitive people assume is furthest away, and it has been running since June 2025.²³ Note what it displaced, in Franklin Templeton's own account of the standard it is departing from: share ownership "often determined, and yield is typically calculated, at the end of a trading day and distributed to investors at the end of the month".²³ Three batch boundaries in one sentence.
The economics are where this becomes a strategy question rather than an operations question, and since the model is mine I should show its mechanics rather than assert its output. What follows is illustrative arithmetic and not a forecast, fenced off so nobody quotes it as one.
Illustrative arithmetic, not a forecast. Start with an assumption rather than a fact, because no non-duplicative industry figure for global assets under custody exists: published estimates range from around a hundred and twenty trillion to well over two hundred, they rest on different definitions, and multi-layer custody chains from global custodian to sub-custodian double-count the same assets more than once. Take a stock of roughly two hundred and twenty trillion earning one and a half to three basis points, which produces a fee pool in the region of thirty-three to sixty-six billion. Both inputs are assumptions and the argument does not depend on either, because what follows is a change in the basis of the fee, and a basis change survives any plausible level. Now price the same activity on flow, at basis points per transformation rather than basis points per annum on the balance. One base case makes it legible: a hundred trillion of annual transformation turnover at ten basis points is a hundred billion of fee revenue. That is roughly one and a half to three times the illustrative pool above, and it requires around half the custodied stock to change state once a year. Move either input and the sensitivity is obvious: at five basis points the same hundred billion needs two hundred trillion of turnover, and at fifteen it needs sixty-seven. The assumption doing the work is turnover, not the rate, which is why the rate is the wrong thing to argue about.
That turnover assumption is large and it deserves to be visible rather than buried inside a per-transformation rate, because it is the actual claim: not that fees rise, but that a meaningful fraction of the world's custodied assets starts moving through billable state changes each year. The robust claim underneath does not depend on any of those magnitudes, and it is the part every securities services executive should read twice.
The fee basis changes. Revenue stops being a rent on stock and becomes a fee on flow. Custody today is paid for holding balances. In a stream world it is paid for processing events. Which means an institution whose economics depend on assets under custody is on the wrong side of this change even if the pool grows, because the pool grows for whoever processes the events rather than whoever holds the balances.
That is the same structural claim this paper makes about venues becoming caches and liquidity becoming a composition, arriving from the operations side and landing in a profit and loss account. It is also the cleanest possible illustration of Coase moving: five intermediary functions do not become cheaper, they stop being functions, and the revenue relocates to the party performing the transformation.
Here is the question the Coase framing invites and almost nobody asks. If transaction costs collapse and firms dissolve, what stands on the other side of the boundary?
The lazy answer is nothing, a disintermediated market of peers. That is wrong, and the reason matters. Coase's transaction costs are functions, and functions do not vanish when you stop paying a firm to perform them. Search cost falls because somebody operates a registry and a discovery service and keeps them running. Verification cost falls because somebody issues credentials against a schema and maintains a revocation surface. Settlement cost falls because somebody implements atomic primitives and a federation protocol. Enforcement cost falls because somebody anchors an audit trail and stands up an arbitration path.
When a firm dissolves, its transaction costs do not evaporate. They precipitate as protocol. The network fabric is not a faster rail and it is not infrastructure in the ordinary sense. It is the institutional residue of the dissolved firm, and it holds the functions the firm used to hold.
But that formulation is only half the insight, and stopping there produces exactly the error this paper attacks elsewhere. It makes the fabric sound like one large successor institution, a single replacement for the many it dissolved, which would simply be aggregation with better plumbing. The fabric holds what the firm held, and it holds it in composable form, which changes the character of the thing entirely.
Anything held in composable form is raw material for firms that do not exist yet.
The fabric is the firm in the sense that it holds what the firm held. But it is not a firm. It is a composable firm: the substrate on which new firms are constituted, by composing what it exposes.
This resolves a contradiction the Coase argument walks straight into if you are not careful. Take literally the claim that transaction costs collapse and firms shrink, and you arrive at an atomised market of individuals, which nobody believes and which contradicts the bifurcation this paper argues for later. Coase's framework offers two options, make or buy, internalise the cost or transact for it in the market. Composability does not add a third. It changes what buying means. The unit of purchase stops being a finished product from a single supplier and becomes a modular capability assembled at runtime, per outcome, from whoever is best placed to supply it. That is still buying. What is new is that discovery, contracting and settlement happen inside the transaction instead of around it, which produces a lower-friction, machine-addressable spot market rather than the frictionless one economists assume. Hold that distinction, because the next several pages are about the costs composition brings with it, and they are not small.
Before claiming that as novel, it has to survive the economist who will object first, and the objection is a good one. Oliver Williamson already supplied the category. His answer to Coase was that the make-or-buy question is decided by asset specificity, the degree to which an investment is durable, transaction-specific and cannot be redeployed elsewhere without losing value. Low asset specificity goes to the market, high goes to hierarchy, and in 1991 he added the hybrid in between, as a discrete structural alternative rather than a midpoint.²⁶ On that reading, runtime procurement of standardised capabilities is simply market governance under low asset specificity, which is the most ordinary case in the whole theory. Nothing new at all.
The objection is right on the taxonomy and wrong on the consequence, and the reason why is more interesting than the claim it replaces. Williamson is careful about something the popular version of his theory loses: "asset specificity, in any of its forms, does not by itself pose contractual hazards that require added governance".²⁶ Hazards need asset specificity plus three further conditions: contractual incompleteness, where disturbances arise that were too costly to specify in advance; strategic defection, where a party abandons the spirit of the agreement for its letter once the stakes are large enough; and the limits of court ordering, because "the courts cannot be relied upon to fill gaps and settle disputes in a timely, knowledgeable, and efficient fashion".
Set the programmable fabric against that list and the result is precise rather than sweeping. Policy-as-code attacks the codifiable portion of incompleteness, because a machine-readable policy bundle specifies ex ante what documentation previously left to judgement. Without that qualifier the claim is self-refuting: incompleteness is by definition the set of disturbances too costly or impossible to anticipate, so no amount of ex ante specification reaches the remainder. What code removes is the anticipated-but-unspecified. What it leaves untouched is the unforeseen, which is where judgement and courts live. Deterministic execution and protocol escrow attack strategic defection, and the boundary of that claim needs stating now because the next page depends on it. Within an atomic transaction, defection is not punished after the fact, it is unavailable: there is no state in which one leg has moved and the other has not. Between atomic transactions, defection is entirely available, and the hold-up risk described below is exactly that residue. Atomicity removes defection inside the atom and leaves it intact in the gaps between atoms, which is where a composed outcome spends most of its life. And the third condition, the limits of court ordering, is untouched. Nothing in this architecture makes a court faster or better informed, which is this paper's existing point that programmable value cannot program a judge.
So the honest formulation is stronger than the one I started with, and it is Williamson's own design variable turned into a product:
A composable capability is an engineered reduction in asset specificity. Williamson noted in passing that specificity is a design variable, that a good can be "redesigned by reducing asset specific features" at some sacrifice in performance. A standardised, credentialled, discoverable capability is that redesign carried out deliberately and at scale, and programmable infrastructure then attacks two of the three hazards that would otherwise force such transactions back inside a firm, removing them within the atom rather than everywhere.
Which means composition does not abolish Coase's boundary or escape Williamson's. It moves the boundary further toward market governance than relational contracting ever managed, because the safeguards live in the protocol rather than in the relationship, and a safeguard in a protocol does not require the parties to know each other.
And the concession that follows should be stated rather than hidden, because it is the sharpest risk in the whole architecture. Williamson's Fundamental Transformation, set out in The Economic Institutions of Capitalism, says that even where many suppliers competed for the work, "the relationship is effectively transformed during contract implementation into a bilateral supply relation thereafter. Identity thereafter matters".²⁶ Composition reintroduces exactly that, at machine speed. An agent composes a liquidity outcome from a competitive field, and one second later it is mid-outcome and dependent on a capability provider it does not control, with no time to renegotiate and no alternative that can be substituted inside the window. Hold-up does not disappear in a composable economy. It compresses from months into milliseconds, which makes it a systems risk rather than a contracting problem, and I have not seen it priced in any composable architecture I have read.
With that established, the firm does not shrink toward zero. It changes what it is made of, and its boundary is redrawn.
Coase's firm was a container for internalised transaction costs, and its size was set where coordination cost met transaction cost. The composable firm is an arrangement of composed capabilities, and its boundary is set where composition cost meets context depth. Firms continue to exist for the two things that cannot be composed from elsewhere: context, and accountability.
Both terms in that sentence need definitions rather than assumptions, and the second one has been carrying more weight than it earned.
Context depth is the quantity of accumulated, non-transferable knowledge required to produce an outcome correctly. Its operational test is not a feeling about how special a firm is. It is whether a competent outsider, given full documentation and the same capabilities, would get the answer wrong. Where the answer is no, the activity composes and the incumbent's familiarity with it is worth nothing. Where the answer is yes, ask why: because the knowledge lives in the judgement of people who have seen the failure before, because it is embedded in relationships that took years to build, or because it is legally or contractually not transferable at all. Those three are the components of depth, and each of them decays at a different rate under documentation, which is why some context genuinely is a moat and some is merely undocumented.
And note where composition cost sits in the theory, since a reader who knows their Coase will ask. It is not a new category alongside market and internal costs. It is the form market transaction cost takes when the unit of purchase is a modular capability rather than a finished product, which is why Coase's boundary condition still governs the outcome. The difference is that the costs have moved from search, negotiation and contracting per deal to standards, conformance, credentials and integrity maintained continuously. Fewer of them are marginal, more of them are fixed, and that shift in cost structure is what favours scale in composition even as it lowers the cost of any single composition.
Composition cost is not zero and it is not free, and the failure to name it is how this entire school of argument becomes marketing. Composing an outcome from capabilities you do not own requires paying for at least seven things: authoring and governing the standards and ontologies that make interfaces mean the same thing to both sides, integrating and maintaining conformance as those standards move, issuing and revoking the credentials that make each participant checkable, securing the integrity of the oracles and attestations that connect the ledger to the world, holding the cyber-resilience and operational capacity to be composable safely at machine speed, acquiring the legal recognition and capital that make your capability safe for a stranger to depend on, and running the composable system alongside the incumbent one for as long as migration takes, which means dual operation, reconciliation between the two, and the governance of a cutover on infrastructure that cannot be taken offline.
That seventh component is the one every architecture diagram omits and every programme discovers. Legacy coexistence is a composition cost, not a transitional inconvenience preceding the real work. It is a permanent line item for as long as two systems must agree, and it scales with the criticality of what is being replaced rather than the elegance of what replaces it.
Every one of those is a real cost, several of them are fixed rather than marginal, and two of them, legal recognition and capital, are exactly the costs incumbents already carry and challengers do not. Which produces the condition under which this entire argument runs backwards, and it should be stated plainly rather than buried:
When composition cost exceeds the internal coordination cost it replaces, the boundary moves back and the firm re-internalises. Composability is not a direction of travel. It is a race between two falling costs, and nothing guarantees that the market's costs fall faster in any given activity.
That is what makes the thesis falsifiable rather than merely directional, and it is also the honest answer to the practitioner's objection that all of this sounds expensive. It is expensive. The question is only whether it is less expensive than the management layers it replaces, and the answer will differ by activity, by asset class and by jurisdiction rather than arriving as a single verdict. Microsoft, resetting its games division, put a number on its own version of this cost: work passing through as many as fourteen layers of management in some parts of the company, with platform teams forty per cent larger than at the start of the generation while players and playtime declined.¹ Treat that as one firm's disclosure about itself rather than an industry constant, which is exactly how it was offered.
And this is the point at which the argument stops being about dissolution. A solvent in analytic chemistry takes things apart. A solvent in synthetic chemistry gets things into solution so they can react and form compounds that did not previously exist. Dissolution is the precondition for synthesis, and the interesting half of what follows a solvent is not what disappears but what becomes possible to make.
So what forms? Not an arbitrary list of roles, which is how this kind of taxonomy is usually presented and why it is usually forgettable. There is a derivation rule available, and using it disciplines the answer.
Every durable position in this economy corresponds to one necessary input to composition that cannot itself be composed. If an input can be assembled from other capabilities at runtime, nobody is needed to hold it. If it cannot, somebody must be, and that somebody has a reason to exist that survives the collapse of transaction costs.
Two qualifications before the list, because the rule is sharper when it is stated honestly. "Uncomposable" does not mean metaphysically unobtainable. Intent and context can be inferred, accumulated and represented, just imperfectly, and the residual between the approximation and the thing itself is precisely what the holder is paid for. Approximable but not substitutable is the accurate claim. And the positions this produces are not all firms: one of them is occupied by legislatures and central banks, which are durable holders of an uncomposable input without being anybody's competitor.
Run the rule and it produces seven, not the five I would have listed from intuition. Meaning cannot be composed, because composition presupposes shared semantics, so semantics must be authored and governed. Intent cannot be composed, because someone must express it, which requires a surface where intent becomes executable. Local context cannot be composed from elsewhere, by definition, since that is what makes it context. Answerability cannot be composed, because a balance sheet, a licence and a party who can be sued are not assembled from interfaces, and this is the input I originally mislabelled as reliability. Reliability is composable through redundancy; being answerable is not. Matching under uncertainty cannot be composed, because it requires somebody to take a position. Exclusive assets cannot be composed, meaning proprietary data rights, closed model weights and compute at a scale where replication is irrational, and note carefully that the uncomposable thing here is the exclusivity rather than the reliability of the output. Redundancy composes reliability, but only against independent failure. Common-mode and correlated failures survive every layer of redundancy you can buy, which is a second reason this position is durable and a caution against believing that composing three providers has made you safe. And legal effect cannot be composed, because statutory finality, insolvency immunity and sovereign money are conferred rather than engineered, which is the whole argument of this paper's settlement section arriving as a taxonomy entry.
Note what that last one is not. Nobody holds a durable position by running infrastructure well. They hold it by holding something others may not have: the licence to the data, the weights nobody else can inspect, or capital that makes competing at that layer irrational rather than merely difficult.
Two further qualifications, because the list is easier to state than to defend. First, the seventh is not a position a firm can decide to occupy. Six of these are commercial positions, available to whoever can hold the uncomposable input. The sovereign and statutory bridge is held by legislatures and central banks, and the most a firm can do is operate inside it under designation, which is a licence rather than a position. Read it as the boundary of the taxonomy rather than as a seventh strategy. Second, the rule verifies membership and does not generate the list. Given a candidate I can test whether its input is uncomposable, and no test tells me the enumeration is complete, so an eighth may exist and I would rather say so than imply a closed set. The two candidates most often proposed to me, oracle integrity and cyber-resilience, both fail the test for the same reason: they are already inside the seven composition costs above, which is where risks that must be managed live, as distinct from inputs that cannot be assembled. A third candidate is harder and I will name it rather than leave it out: bearing duration, meaning somebody has to hold the mismatch between when capacity is committed and when it is consumed. I read that as a form of matching under uncertainty, since taking a position across time is still taking a position, and the whole liquidity section above is an argument that the party who does it needs capital and a licence. But anyone who thinks duration is categorically different from matching has a case for an eighth entry, and the honest answer is that my rule cannot settle it, because the rule tests inputs and this is a dispute about how finely to cut them.

Durable position | Uncomposable input it holds | Why it exists | Its rent |
|---|---|---|---|
Ontology and semantic authorities | Meaning | Composition presupposes shared semantics, which must be authored and governed rather than assembled | Definitional authority |
Applications and intent surfaces | Expressed intent | Someone must express what is wanted, at a surface where it becomes executable | Attention and habit |
Outcome producers | Local context | Context is by definition not available from elsewhere, and outcomes require it | Context depth |
Capability manufacturers, risk-bearing | Answerability | A licence, a balance sheet and a suable party cannot be composed from interfaces | Regulatory standing and capital |
Capability manufacturers, computational | Exclusive assets: proprietary data rights, closed models, compute at irrational-to-replicate scale | Exclusivity cannot be composed by anyone lacking the right or the capital, even though the output is reliable and interchangeable | Control of the asset, not operational excellence |
Dynamic resource allocators | A held position | Matching under uncertainty in real time requires somebody to be long or short something | Allocation quality |
Sovereign and statutory bridges (public, not a firm-level position) | Legal effect | Finality, insolvency immunity and settlement money are conferred by statute, not engineered | Jurisdiction, and the seam between jurisdictions |
Read that table in financial services terms rather than abstract ones, because it produces the strategic conclusion of this paper. The risk-bearing capability manufacturer is the licensed institution, and the dynamic resource allocator is the market maker. A capability becomes trustworthy enough for strangers to compose precisely because there is a licence, a balance sheet, a resolution regime and somebody answerable behind it. And allocating capital, capacity and risk across time under uncertainty is the definition of underwriting, market making and treasury.
The split inside capability manufacturing is where the strategy gets uncomfortable, and pretending otherwise would be dishonest. Computational capability manufacturing is not a business incumbents win, and the reason is instructive rather than merely competitive. What defends that layer is exclusive rights and capital scale, and a bank's rights and capital are committed elsewhere by regulation. Concede hyperscale compute and foundation-model manufacturing. But concede that much and no more, because the boundary matters: domain-specific inference over proprietary financial context, and the governed orchestration of it, are defended by the same legal fencing that makes that context non-scrapable in the first place. Handing those over with the compute is a category error that costs the position this paper spends its final section defending. What those firms conspicuously do not want is a capital requirement, a resolution regime, a supervisory college and personal liability for directors. The risk-transfer layer is defended by exactly the obligations incumbents complain about, which is the most useful inversion available to anyone running one.
Which reframes the message to incumbents from a lament into a choice. The positions with the most durable economics are the ones incumbents already occupy, and they lose them only by continuing to sell verification instead of manufacturing composable capability, or by trying to win the layer where their obligations are a handicap rather than a moat.
There is a recursion here too. The ontology layer is itself a composable capability, which is precisely why its governance is systemically important and why this paper treats an ontology committee as an unpriced systemic risk rather than a standards body.
Two instances exist, and they are not at the same stage, which the claim-status discipline of this paper requires me to say plainly rather than blur into a single sentence about production. The NFH fabric family is a documented open-fabric architecture, describing itself as "the public, discoverable surface of a planetary value network" for discovery, contracting, settlement, identity and trust,³ whose adoption at institutional scale remains to be demonstrated. Canton is the one reporting live institutional flow at scale, more than nine trillion dollars in monthly transaction volume on chain, on company-stated figures in a filing with the Securities and Exchange Commission.³⁰ Note the unit, because it is routinely misreported: that is transaction volume passing over the network, not the value of assets tokenised on it, and the two differ by orders of magnitude. Separately, Broadridge's Distributed Ledger Repo platform averaged three hundred and sixty-five billion dollars of daily repo transactions in January 2026, again on company-stated figures.³¹
Intellectual honesty requires running the bundle test on both without charity, since the discipline of the argument is that bundles are technological artefacts rather than economic ones. NFH fabric bundles registry, catalogue, discovery, credentialling, adapters, observability, settlement, guarantees and arbitration. Canton bundles privacy, atomicity, interoperability and finality. Both are bundles. Both are subject to the same physics as Game Pass.
Run it, and something more interesting than a verdict emerges: they survive by completely different mechanisms, and neither is the mechanism it advertises.
NFH fabric fails the no-choice condition, and fails it deliberately. Its principles are decentralised, permissionless, open standards, user-centric, composable and agent-native, and the documentation is explicit that you may adopt one service or the full stack.⁴ On the no-choice test that is a death sentence. Except the test is being applied to the wrong category. Fabric is not trying to be a bundle. It is trying to be the market. And markets behave in the opposite way to bundles under abundance: they benefit from it, because liquidity and maximised choice are what make a market valuable rather than what dissolve it.¹ Registry, catalogue and discovery are the storefront function. Fabric is Steam, not Game Pass, and the composability that would kill it as a bundle is what qualifies it as a market maker.
Canton passes the no-choice condition far harder than its own marketing claims, and the industry keeps miscategorising why. Its foundational argument is that privacy, not capability, is the binding constraint on institutional adoption: a trader with exposed collateral positions is broadcasting strategy to be front-run, and a treasurer managing liquidity does not accept payment flows becoming visible to the world.⁶
But privacy here is not a feature competing with other features, and it is not a credential a participant presents. It is a mandatory policy precondition of the environment itself, set by data protection law, banking secrecy, market abuse rules and client confidentiality obligations that exist regardless of anyone's product preferences. A network that cannot satisfy it is not a less attractive option for regulated flow. It is not an option. Which is why it sits outside the bundle analysis entirely: you cannot unbundle a precondition, and no amount of cost advantage elsewhere compensates for failing it. And Canton partially satisfies the everything condition through architecture rather than acquisition: because synchronizers route and order encrypted packages they cannot decrypt, described in Canton's own primer as "a post office dealing with sealed envelopes which it cannot open," participants dynamically choose different synchronizers according to the trust requirements of a given transaction.⁵ You do not need the bundle to have everything if you can compose the trust set per transaction.
That last property is the most under-discussed idea in this entire field. Trust becomes a parameter of the transaction rather than a property of the network. The trust section later sets that claim's boundary: what becomes transaction-specific is the assurance a counterparty needs, priced and composed per deal. Trust in the counterparty does not disappear, and the part of it that rests on somebody being answerable cannot be parameterised at all.
Once the seven costs are separated, the supposed rivalry between institution-grade and open networks stops being a strategic choice and becomes a category error. They answer different questions on the same list. The equation in the title is worth writing down, since it governs the rest of this section: a transaction clears only if every one of the seven costs is answered, and no single fabric answers all seven. Settlement and privacy on one side, identity, discovery and authority on the other, with legal finality supplied by neither. Which means the interesting quantity is not the capability of either fabric. It is the cost of the join.
Canton is a settlement and privacy fabric. Sub-transaction privacy means each party records only the parts of a transaction that apply to them: in a delivery-versus-payment trade the bank sees the ten thousand dollars of cash and not the securities, while the registrar sees the hundred shares and not the cash.⁶ Consensus is proof-of-stakeholder, so only parties to a transaction validate it, and Super Validators operating the Global Synchronizer are, in Digital Asset's own phrase, "blind traffic controllers".⁷
NFH fabric is a discovery and authority fabric. Identity, catalogue, discovery, credentialling and audit are protocol concerns rather than application concerns, and autonomous software is a full network participant: an agent holds its own keypair in the registry, receives authority through a scoped, time-bounded delegation credential, can hold an account in its own name, accumulates reputation that counterparties sign against its registry entry, and discovers offerings natively rather than by scraping.⁸
And composition is not confined to composing capabilities. The phrase that carries the most weight is composing other types of value, and it is the tokenisation thesis proper rather than a flourish.
Today's financial system composes a fixed and remarkably small type system: cash, securities, derivatives, collateral, credit. It composes them slowly and expensively, and it cannot compose anything outside the set at all. Programmable value makes the type system extensible. Once any claim can be represented with policy attached, the composable set grows to include things that were never financial instruments: capacity, entitlement, reputation, attention, compute, data licences, energy, carbon, spectrum, receivables, future revenue, professional time, identity attributes, and permissions themselves.
Finance has always been a composition engine running over a fixed and very small type system. Programmable value makes the type system open. The industry is not being disrupted so much as asked to perform its existing function across a vastly larger domain, and almost nothing about how it is organised prepares it to do so.
The new value sits in composing across types rather than within them. An instrument combining a receivable, a capacity entitlement and a reputation credential, purpose-bound and settling atomically, is none of the three and has no existing product category. Cross-type composition is where genuinely new instruments come from, and it is the one thing today's institutions structurally cannot do, because their systems, licences, risk frameworks and organisational charts are all partitioned by asset type. The obstacle is not imagination. It is that the firm is shaped like the old type system.
Which brings us to the three things composition does not supply, because a novel instrument needs all three and no protocol confers any of them. It needs a legal-person principal, because someone with capacity must be the issuer and an agent cannot be. It needs a liability chain that survives the instrument's own novelty, so that when one composed leg fails there is an identifiable party answerable to the holder rather than a diagram of interfaces. And it needs a classification decision by someone with authority to make it, because whether the thing is a security, a deposit, a payment instrument, a derivative or none of them determines its capital treatment, its distribution rules and its investor protections, and that decision is made by regulators and courts on their own timetable rather than by whoever composed it. Composition produces the instrument. It does not produce the standing, the liability or the label, and those three are the actual gating items on cross-type composition rather than the engineering. State the boundary of that claim honestly: these are constraints of current law, not facts about the universe. Legislatures have conferred legal personality on entities that are not people many times over, and a jurisdiction that decided to grant limited standing to an autonomous agent could do so tomorrow. What that would not remove is the underlying requirement, because standing exists so that somebody with assets can be made to answer. Any legal innovation here relocates the accountable party rather than abolishing the need for one, which is why I treat this as a constraint that moves slowly rather than one that cannot move.
Neither fabric moves Coase's boundary alone. Canton answers whether a transaction can settle atomically and privately, and cannot answer who exists, what they offer, or who is permitted. NFH answers who exists and who is authorised, and cannot by itself host a trade where the visibility of the position is the risk being managed. The infrastructure that moves the boundary is both, federated, which makes interoperability between fabrics the central commercial question.
It would be wrong to say nobody is trying. The seam is contested by three different kinds of claimant, and what none of them has solved is more instructive than what all of them are building.
The official sector is trying to abolish the seam rather than own it. Project Agorá launched in April 2024 with seven central banks and, as of mid-2026, brings together eight, including those of five major reserve currencies, with more than forty private financial institutions convened by the Institute of International Finance, to test a multi-currency shared programmable platform holding tokenised central bank reserves and tokenised commercial bank deposits together. It is working the settlement finality, anti-money-laundering and privacy questions with central banks in the room, which is the part no private consortium can replicate.²⁸ Note the architecture, though: Agorá's answer to the seam is one shared platform, which is not composition, it is re-bundling, and it is the unified ledger concept made concrete. Note also the stage. Real-value testing in July 2026 totalled roughly eight hundred thousand Swiss francs.²⁸ That is a laboratory rather than a market, and the BIS says so itself, describing its Innovation Hub projects as "experimental in nature, for the purpose of investigating technological and practical feasibility".²⁸
Swift is claiming the seam as infrastructure, at the stage of a design. In September 2025 it announced work with more than thirty financial institutions to design and build a blockchain-based shared ledger, beginning with a conceptual prototype by Consensys, intended to "record, sequence and validate transactions and enforce rules through smart contracts" and explicitly designed for interoperability with existing and emerging networks, alongside separate orchestration services between systems.²⁹ Read the stage honestly, because the ambition is easy to mistake for the artefact: this is design intent with a prototype attached, not a running ledger. It is the incumbent-becomes-the-fabric move, executed by the one institution with a genuine claim to neutrality, and announced years before it can be judged. And its own scope statement concedes the limit exactly: "Swift's focus is on the infrastructure, the types of tokens that will be exchanged on the ledger is the territory of commercial and central banks".²⁹ Sequencing and messaging, yes. The legal character of what settles, no.
The cross-chain protocols are solving message passing. Chainlink's CCIP, with private transactions piloted by ANZ for cross-chain settlement of tokenised assets, along with the general interoperability layer, moves instructions and value representations between chains competently and makes no claim to statutory finality at all.
So the seam has serious contenders for the plumbing and nobody holding the legal problem. The tempting way to state that is incoherent, though. Statutory finality cannot be owned as a business. It is conferred by a legislature on a designated system, and no commercial party can hold it, sell it or licence it.
Which makes the seam business something more specific: coordinating and evidencing finality across fabrics, holding provable records of what settled where under whose rules, demonstrating to each side that the other leg is irrevocable under its own governing law, and standing behind the interval during which one leg is final and the other is not. That interval is the product, because a gap between two finalities is a risk position and somebody has to hold it.
Which makes the seam operator a correspondent bank, or a central counterparty, relocated, and the admission is stronger than the evasion. Those are two distinct functions and not necessarily one firm, which matters for anyone deciding what to build. Bridging the interval between two finalities is correspondent economics: hold assets both sides, extend credit across the gap, price the timing exposure. Absorbing the failure of a party mid-composition is central counterparty economics: mutualise, margin, default-manage. A single seam operator may do both, and the two can equally sit in different entities with different capital treatment. What cannot happen is that the interval goes unborne, because it is real and somebody carries it. Whether a business forms around bearing it is a separate question, and the honest answer is that it may take decades. Foreign exchange settlement risk has been named since Bankhaus Herstatt was ordered into liquidation on the afternoon of 26 June 1974, leaving counterparties who had paid Deutschmarks that morning holding nothing. No institution absorbed that interval for twenty-two years. Private netting arrangements, FXNET, ECHO and Multinet, formed through the 1990s after the BIS Allsopp report of 1996, and a purpose-built payment-versus-payment utility arrived only when CLS Bank began operating in September 2002, twenty-eight years after the loss that named the risk.³⁹ And the reason it took that long is the part worth carrying forward, because CLS was not the market maturing into a good idea. The Allsopp report set out a strategy in which central banks would judge private-sector progress and consider further action if it proved inadequate, and the industry built the utility under that pressure.³⁹ So the prediction has to carry its own timetable and its own trigger: the seam institutionalises after scale, after a loss, and usually because a supervisor makes clear that the alternative is worse, and until then the exposure sits bilaterally on balance sheets that were not designed to hold it. Which also reconciles the two clocks running through this paper. A private seam operator waits for coercion or catastrophe. A public or mandated one moves as soon as it has a mandate, which is why the ninth attack below, that the settlement asset may never arrive, is the same question asked from the other end. Inside a single fabric, atomic settlement removes the timing exposure correspondents exist to bridge, so the function does not disappear. It is squeezed out of the centre and concentrates at the edges, where different legal and operational realities collide. That is this paper's own Coasean logic applied to its own prediction: the function persists, and only its location, speed and concentration change.
Canton is admirably honest about the mechanism, if not about its consequence. Its own myth-busting material states that interoperability between Canton and Ethereum mainnet is no better than between a private EVM chain and Ethereum mainnet, because both "rely on the exact same overhead of APIs and message bridges. (i.e. the same way we have done systems integration for decades)".⁷ The consequence for atomicity is my inference rather than their concession, and it needs stating carefully, because the strong version is false. Atomicity across two ledgers is achievable. Hashed timelock contracts, two-phase commit and conditional-commit protocols all deliver the property that BIS defines as the "synchronous exchange of assets, such that the transfer of each occurs only upon transfer of the others", without either ledger becoming the single commit venue. What BIS actually says is about cost rather than possibility: an architecture of disparate ledgers is justified when data and governance requirements diverge, as they do across jurisdictions and asset classes, but "this flexibility introduces more complexity for cross-ledger coordination via interconnection protocols to achieve programmability and composability".¹⁴ That is the claim to make. The seam is not a hole in the technology, it is a coordination cost, and coordination costs are precisely the thing that gets priced, capitalised and eventually owned.
Inside a fabric, coordination is protocol. Between fabrics, coordination is a cost somebody pays. The reconciliation cost we are proud of dissolving within a domain re-forms at the seams between domains, in a thinner and more automatable form, but it re-forms. And since no plausible future has one fabric, seams are permanent features rather than transitional artefacts.
The unit of competition in the next decade is not the chain, the ledger or the consortium. It is the seam. Nobody owns finality, but somebody will underwrite the interval between two of them, and that party occupies the position correspondent banking occupied in the last era. Correspondent banking was an extremely good business. On the Herstatt timetable, it may also be a business nobody builds for twenty years.
This is the strategic consequence of an architectural claim I have made in different language: the modern fabric replaces the single trusted orchestrator with an orchestrator of orchestrators, where value switches between networks rather than being forced through one archaic intermediary.⁹ What the Stratechery lens adds is where the rent sits in that structure. It sits at the seam. And the institutions best placed to hold seams are, awkwardly for the disruption narrative, those who already hold custody, messaging and correspondent relationships, because a seam is worthless without credibility on both sides of it.
What follows applies the argument function by function, and there is one piece of discipline to carry into all four sections, because without it these read as a list of predictions. Each function has to be tested against the four conditions set out at the start, not just the first one. It is easy to show that a bottleneck is dissolving. The work is in naming what becomes newly scarce, whether anybody can appropriate it, and whether the change moves market and internal costs at different rates. Where I can name all four, the conclusion is a claim. Where I cannot, it is a direction of travel, and I have tried to mark which is which rather than let the prose blur them.
Under abundance, rents move from inventory to matching, routing, policy and proof. Protocol-native discovery sharpens that into something more threatening to the venue business model than most exchange strategy teams have registered.
A venue is a place liquidity must come to. A discovery service is a query answered across the places liquidity already is. These are structurally different businesses, and the second dissolves the first's core asset without competing with it directly. The fabric's formulation is that an offering published once is findable across every aligned network, so "the producer doesn't re-list; the consumer doesn't aggregate".⁴ Read as a capital markets sentence, that is an extinction event for a specific and currently very profitable set of rents, and the specificity is the whole point: listing fees, market data sold as a monopoly product, and the business of being the place where the order book lives. Not exchanges. Three revenue lines inside exchanges, which happen to be three of the most profitable.
Push it one layer further. If catalogues are network-published and discovery is protocol-native, then price discovery separates from trade execution. Those two functions have been bundled inside a venue since the coffee house, and the bundle test tells us how to read that: they were bundled because of a technological condition, namely that continuous two-way flow could only be observed by being present in one place, first physically and then electronically. Remove the condition and the bundle is theatre rather than architecture.
So the maximalist version of this argument is wrong, and it is worth saying why before anyone builds a strategy on it. Attention remains scarce even when supply is free, which is the durable core of Aggregation Theory. And a venue is not merely a place where liquidity is discovered. It concentrates executable order flow, forms prices through interaction rather than publication, imposes priority and conduct rules, runs surveillance, and in many cases provides netting and default management. A distributed catalogue can aggregate indications of interest without producing any of that. So what erodes is the venue's monopoly over listing, over discovery and over proprietary data. What survives, and probably thrives, is the exchange as the trust and veracity layer over abundant discoverable supply, plus the harder functions a catalogue cannot perform: executable liquidity, routing quality, market governance, surveillance, netting and finality. That is a migration from renting a location to underwriting a fact.
In a world of protocol-native discovery, the venue's listing and discovery function is a cache. A cache earns a rent only while the thing it holds is scarce or expensive to fetch, and protocol-native discovery makes fetching cheap, which is precisely why that rent is transient while the caching remains useful. The functions that survive are the ones a catalogue cannot perform: forming a price through interaction, and standing behind what happened.
Run the four conditions over that and it passes on three, which is why it is stated as a claim rather than a direction. Listing and discovery commoditise, since a published offering findable everywhere is abundant and substitutable. Surveillance, netting and the formation of an executable price become newly scarce relative to it. And venues can appropriate those, because they are licensed, they hold the order flow and a supervisor has to designate somebody. The fourth condition is the one to watch: protocol-native discovery lowers the market's cost of finding a counterparty without lowering an exchange's cost of running surveillance, so the relative cost genuinely moves, and it moves in favour of transacting outside the venue for everything except the functions that need the venue's licence.
Liquidity, in the world we inherited, was inventory plus a phone list. It was manufactured by intermediaries who warehoused risk on their own balance sheets, and the reason is pure Coase: the market for immediacy was too expensive to use, so the function was internalised and the intermediary charged for the internalisation.
Access to liquidity can be composed. Liquidity itself cannot, because somebody still has to own the asset and be willing to part with it under stress. Everything in this section is an elaboration of that one distinction.
Programmable value changes the physics in four ways, and only the first is widely discussed.
Access to liquidity becomes conditional rather than warehoused. When lock, release and encumbrance are native primitives with policy attached, liquidity can be rented for a moment rather than held for a quarter. The obvious formulation of the mechanism is backwards: encumbrance does not substitute for inventory, it is what makes inventory undeliverable, as the settlement section argues at length. What actually changes is that programmable encumbrance lets the same inventory be committed precisely, briefly and verifiably, so less of it sits idle against a possible call. Somebody still holds it. The advantage shifts toward whoever is fastest at policy and proof, on top of, and not instead of, whoever is largest at funding.
Liquidity becomes a discovered service rather than a held position. With registry, catalogue, discovery and per-call metering in the protocol, immediacy can be sourced at the moment of need from whoever is best placed to provide it. The pattern is already articulated for data rather than money: acquisition shifts from annual contracts to spot, per-call markets, and agents compose sources at runtime based on observed quality, freshness and price, switching providers without re-integration.¹² Substitute liquidity, collateral, guarantees, credit enhancement and FX for data and the sentence holds unchanged. Everything currently bought as a standing arrangement becomes purchasable per event.
Guarantees become gradient rather than binary. Trust as "a continuous, contextual contract" with underwriter-backed gradient guarantees³ has no clean traditional analogue and deserves more attention than it gets. Counterparty risk today is managed continuously through limits, collateral, haircuts, margin and pricing, so the claim is not that finance lacks gradients. It is that the admission decision is binary and the gate does much of the work: you are approved or you are not, and everything after that is calibration inside a relationship. If guarantees can be continuous, contextual and underwritten per transaction, then the credit decision moves from the counterparty to the transaction. That is how the gaps close. Two and a half trillion dollars of trade financing is requested and refused annually because, in the fabric's own words, "verifying the deal costs more than the deal earns," and five point seven trillion dollars of credit that small businesses need is unavailable because their "real order books" are "invisible to capital".⁴ Verification cost is one binding constraint in both, and it is the one this architecture attacks. It is not the only one. Trade finance and small business credit are also constrained by capital, collateral, enforceability, country risk and plain risk appetite, and no credential improves a jurisdiction's courts. The defensible claim is narrower than the slogan and still large: where the binding constraint is the cost of verifying the deal rather than the willingness to bear its risk, credentials and gradient guarantees address it, and the fabric's own framing, that verifying the deal costs more than the deal earns, describes exactly that subset. Note also what gradient guarantees do to risk, which is relocate rather than remove it: somebody underwrites the gradient, and that somebody needs capital, a licence and a reason to be there in a crisis.
Purpose-bound value collapses the monitoring cost of on-ledger restrictions. Value that carries its own rules of use³ moves the restriction inside the asset. Consider how much of finance is monitoring apparatus wrapped around restricted money: use-of-proceeds covenants, ring-fenced facilities, subsidy disbursement, escrow, margin segregation, development finance conditionality. In every case the restriction lives outside the asset and is enforced by people and reports. Where the restriction is expressible on the ledger, meaning who may receive value, when, against what evidence, this is Coase's monitoring cost not reduced but largely removed. Where the restriction is a fact about the world, it is not, and my own detectability constraint says so. Use-of-proceeds is the clean example: a protocol can enforce that funds reach an approved contractor and cannot verify that the contractor built the school, nor prevent the borrower from substituting the money for spending it would have done anyway. Purpose-bound value abolishes the monitoring of transfer conditions. It does not abolish the monitoring of purpose.
Put those together and the conclusion writes itself.
Access to liquidity is not a stock and not even a flow. Under a programmable fabric it is a composition: assembled at the moment of need from discovered capacity, conditional guarantees, purpose-bound value and encumbrance primitives. The inventory, the capital and the willingness to be there under stress remain held somewhere, by somebody, and that somebody is still a balance sheet with a licence. What changes is that immediacy stops being something you must own in order to use.
Note which of the three jobs each of those four claims belongs to, because it decides how far each travels. Discovered capacity and conditional access are attestation work, and they dissolve, which is why they are the parts of this section stated most confidently. Purpose-bound value is constitution, so it moves into the protocol and stays there as long as the restriction is expressible on the ledger. Gradient guarantees are underwriting, and underwriting does not dissolve at all: it gets repriced per transaction rather than per counterparty, and somebody still holds capital against it. Run the four conditions, all four, because the discipline is worthless if it is announced and then skipped. A bottleneck falls: search and negotiation costs for capacity, which discovery and conditional access genuinely remove. Something scarce remains: assured capacity under stress, which no protocol manufactures. Third, and this is the one that bites: can the holder of the remaining scarcity appropriate the surplus, or does it dissipate to buyers? Here it can be appropriated, because assured capacity under stress requires capital and a licence, both of which are supply-constrained by regulation rather than by technology, and neither of which a composer can conjure. And the fourth holds as well: sourcing liquidity externally at the moment of need becomes cheaper than warehousing it internally, so the boundary moves outward. That is the whole reason this section predicts relocation rather than dissipation, and it is the third condition that fails for listing and discovery in the markets section, where a cache commoditises without leaving anything licensable behind, even though that same section predicts survival for surveillance, netting and price formation. So the honest reading is not that liquidity provision is disrupted. It is that the attestation layer around liquidity is dissolving while the underwriting core is being handed a better instrument.
Which makes liquidity the first bespoke outcome, and the flagship proof case for financial services. Not a retail wealth illustration. The most institutional, most balance-sheet-intensive, most incumbent-defended function in the industry turns out to be the cleanest example of a bespoke outcome composed from composable capabilities.
Issuance today is a project: legal drafting, prospectus, appointed agents, a listing, a settlement date, six to twelve weeks and a fixed cost that quietly determines which ideas in the world are permitted to become financial assets. It is the last hand-copied manuscript in finance. A syndicate is a scriptorium, and we have been congratulating ourselves on the quality of the calligraphy.
Start with the most intellectually honest sentence in the fabric corpus, which concedes the limit of its own claim. Fabric supplies protocol-level plumbing for provenance, custody and transfer, and then: "The legal and custodial wrappers remain the issuer's responsibility; what changes is that the technical friction no longer dictates them".¹¹
That concedes the operational point, and the conclusion is worth stating more bluntly than the documentation does, with the boundary stated first because it decides how far the claim travels. What becomes a configuration parameter is the fund's operational existence, not its legal or fiscal existence. A fund is also a tax vehicle, a distribution passport and a regulated product with investor protections attached, and none of those is a settings file. Inside that boundary the claim is strong: in a world of programmable value, the fund's manufacturing apparatus is a configuration parameter. A fund is currently a manufactured object requiring a promoter, a domicile, a wrapper, an administrator and a dealing calendar. If a segregated position on a programmable ledger can carry its own allocation rules, its own eligibility policy and its own distribution logic, then what we call a fund is a settings file, and the manufacturing apparatus around it was scaffolding for a constraint that has gone.
But the fabric's sentence smuggles in a more interesting claim that almost nobody in the industry has said out loud. Technical friction has been silently determining legal structure for decades. We have special purpose vehicles, feeder funds, sub-fund umbrellas, nominee arrangements, omnibus accounts and depositary receipts substantially because the plumbing could not support the direct structure. A generation of legal architecture is scar tissue over technical constraints, and we have been teaching it to graduates as though it were financial engineering. Remove the constraint and much of the wrapper is revealed as unnecessary rather than clever.
Which is why the boundary above matters, and it is argued properly among the attacks below rather than left to a footnote. Not all of that wrapper is scar tissue over technical constraints. Some of it is scar tissue over fiscal ones, and tax structure is not dissolved by better plumbing. What thins is the manufacturing apparatus. What persists, until a legislature says otherwise, is the shell.
Then the operative point. If provenance, custody, eligibility and audit are expressed as credential schemas, and the design effort genuinely sits in the schemas rather than the plumbing,¹¹ then the credential schema is the new prospectus. A prospectus is a document that makes an asset legible to a human so they can determine whether they may and should hold it. A credential schema is the machine-legible form of exactly that determination. The strong version of that claim is wrong and easy to attack, so here is how far it goes. A prospectus also carries accountable representations, narrative risk factors, conflicts, governance, rights and remedies, and none of those compile. The schema is the executable spine of the prospectus rather than its replacement: it encodes what a machine must check before a transfer is permitted, and leaves the part that exists so a human can be held responsible for what was said. Whoever authors the schema for an asset class does what the underwriter used to do: defines what the thing is, who may hold it, what must be proven, what is disclosed to whom, and what happens on default.
The consequence for market structure is not what long-tail enthusiasts expect. Fixed issuance cost collapses, minimum viable issue size collapses with it, and the universe of claims currently priced out comes into scope: SME credit, receivables, revenue shares, single-asset infrastructure, local-currency instruments. This is the "more created this month than in the previous decade" moment for capital markets, and it arrives with the same quality distribution that AI image generation brought to illustration. Most of it will be junk. That is not an argument against it; it is what abundance looks like from inside.
That answers the supply side and leaves the objection an economist reaches for first: cheap issuance is worthless if nobody buys the output. An SME receivable is not unfunded today because issuing it costs too much. It is unfunded because a stranger cannot assess it, cannot hold it in a mandate written for rated paper, and cannot exit it. Collapse the issuance cost and you get a market of a million assets nobody can price, which is not abundance, it is landfill. The paper has to explain where the demand comes from or the long tail stays theoretical.
It comes from the same machinery, which is the part that took me a while to see. The mechanism that makes small heterogeneous claims cheap to create is the mechanism that makes them holdable by strangers. Credentials carry the evidence a buyer would otherwise have to gather. Continuous observability replaces the periodic reporting a small issuer cannot afford to produce. Gradient guarantees let an underwriter price the residual uncertainty per transaction rather than refusing the whole category, so the admission decision moves from the counterparty to the claim. And composability means an asset too small and too odd for any single mandate can be assembled into something that fits one, with the underlying claims still individually inspectable rather than buried in a tranche. Each of those is a demand-side function, and each is a by-product of the supply-side change rather than a separate build.
Be honest about the residue, because two of the demand constraints do not yield to any of this. Liquidity and mandate eligibility are not verification problems. A claim can be perfectly evidenced and still have no secondary market, because a buyer needs a seller and no credential manufactures one. And an institutional mandate is a legal document listing what may be held, so an instrument that is provably sound and outside the list remains unbuyable until the mandate is rewritten, which is a governance timetable rather than a technical one. So the defensible version is narrower than the enthusiasm and still substantial: the investable long tail gets an evidence base and an underwriting mechanism, and still waits on secondary liquidity and mandate reform. Which predicts the order of arrival. The tail funds first where the holder intends to hold to maturity and writes its own mandate, so private credit, insurance-linked and development finance before anything that needs a daily price.
But the new fixed cost is schema design, and schema design has enormous returns to reuse. So the equilibrium is a small number of schema authors and a very large number of issuers instantiating them. That is the meta-factory pattern expressed in capital markets: the meta-factory produces the universal protocol pattern as a grammar and captures value as design authority and standard-setter rather than as toll collector, while the outcome factory instantiates it with local ontology and keeps the margin on the outcome.⁹ Concentration does not disappear in this future. It relocates from the balance sheet to the ontology, and note that this is a claim about schema authorship rather than about issuance. Issuance itself fails the appropriation condition, as the test at the end of this section shows, because the scarce input walks. Schema authorship passes it independently: authorship lowers the market's cost of instantiating instruments without lowering anybody's internal cost of writing schemas, and the appropriation mechanism is the roads strategy set out in the trust section, not a toll.
There is a third consequence, and it is the one that should unsettle asset management. When a portfolio is itself a first-class programmable asset, with allocation rules, rights and rebalancing logic and holder-level positions inside it, then anyone with a defensible investment view can issue a product. Not a model portfolio. An actual governed asset someone can hold. Run the value chain argument through that and it lands with no adjustment: removing the substantiation bottleneck destroys relatively undifferentiated creators who depended on the structural bundling of idea creation and idea substantiation, while making highly differentiated creators who deliver both more valuable than ever.² The closet-index active manager exists because having a view and manufacturing a fund were structurally bundled and manufacturing was expensive. Unbundle them and that manager competes for attention with zero-marginal-cost issuers. Meanwhile the genuinely differentiated manager gets an issuance capability that used to require a firm.
The middle dies, both ends thrive, and the institutions sitting in the middle are writing the most confident papers about why nothing will change.
Run the conditions here and this section fails one of them, which is why it is written as a structural claim rather than a rent prediction. A bottleneck falls, since substantiation costs collapse when eligibility and disclosure become machine-checkable. Something scarce remains, namely a defensible investment view, which no protocol supplies. And the fourth condition holds: issuing a governed product externally becomes cheaper than housing it inside a distribution franchise, so the boundary moves. But the third does not hold cleanly, and the third is the one that decides whether anybody captures anything: the scarce input is a differentiated view, and differentiated views are held by people rather than by firms. They walk. Which means the surplus accrues to talent rather than to whoever owns the issuance rails, and the rails themselves commoditise into a utility margin. That is a good outcome for investors, a good outcome for the best managers, and an uncomfortable one for anyone whose business model is the wrapper around them.
Distribution has been the most durable rent in financial services because it was gated by three costs at once: regulatory permission, advice liability, and the brute expense of client acquisition and suitability assessment. AI attacks all three simultaneously, which is why distribution, not settlement, is where this decade's value actually moves.
Distribution rents in finance rest on the non-portability of reputation, and portable credentials are aimed at exactly that. If you take one sentence from this section, take that one.
Look at Coase's list of market transaction costs, then look at what an agent under scoped delegation does: searches the universe, checks eligibility, compares terms, negotiates, initiates execution, monitors the position, produces an audit trail. The agentic layer is a machine for performing exactly the functions firms were invented to internalise. When those costs fall toward zero on the market side, the justification for the firm's scope goes with them.
So the last bundle in finance is not settlement or custody. It is advice, product manufacture and operational execution, bundled and sold as a relationship. That is our creation-plus-substantiation bundle, and it is the one AI severs.
Machine-legible eligibility is necessary and insufficient, because eligibility only becomes relevant once you have been found. The actual stack runs: catalogue presence, discoverable offering, verifiable credential, machine-checkable eligibility, atomic settlement, signed audit trail. Eligibility is the fourth step. If you are not in the catalogue you have already lost at the first, and nothing downstream recovers it.
The line that should end every digital distribution strategy meeting is the description of how an agent finds an offering: "via Discovery Edge, exposed natively. No scraping, no screen-reading".⁸ Every institution treating its app or portal as its distribution asset is building for a consumer about to stop looking at screens. And the phrase cuts both ways: an institution reachable only by screen is reachable only by scraping, which is fragile, frequently unauthorised and increasingly blocked. Screen-only distribution is not conservative. It is a decision to be unreachable.
Then the mechanism most people miss. Portable reputation is the solvent for distribution rents. Reputation on the fabric is signed by counterparties, held by the subject, verifiable by anyone, and travels "because it isn't stored in someone else's platform".⁴ Set that against the diagnosis of what a walled garden extracts: fifteen to thirty per cent from the seller inside it, for matchmaking alone, "and the reputation earned there cannot leave".⁴
That final clause is the entire mechanism of platform power. Distribution rents in financial services rest substantially on the non-portability of reputation: a small manager's track record captive to a platform's reporting, a borrower's payment history captive to a lender's files, an issuer's servicing record captive to an arranger's memory, an adviser's relationships captive to a firm's CRM. Make reputation portable, cryptographically signed and subject-held, and the hostage-taking stops working. This is a more powerful disruption of distribution economics than better user experience will ever be, and it is barely discussed.
Third, and this is where the industry's mental model breaks rather than bends: the agent is a new operational and economic participant, though not a new legal person. On the fabric an agent holds its own identity and keypair, authority as a scoped time-bounded delegation credential, an account in its own name so it can be paid, charged and audited, and its own accumulated reputation.⁸ Every classification apparatus in institutional finance assumes the account holder is a legal or natural person with a domicile, a risk profile and a set of rights. The industry's current answer is to pretend the agent is the human, which works right up to the moment two agents transact with each other and no human is in the loop, which the architecture explicitly supports.⁸
Your best distribution investment this year is not a channel, a partnership or an app. It is being findable, verifiable and settleable by a machine that has never heard of you.
And run the conditions on distribution too, because it produces the least comfortable answer of the three. A bottleneck falls, as eligibility checking and onboarding friction become machine-executable. Something scarce remains, but naming it honestly is difficult: what stays scarce is presence in whichever catalogue the agents actually query, which is attention and default position rather than any capability. On the third condition the surplus is appropriable, though not by the distributor: it accrues to whoever operates the discovery service that agents trust, which is the aggregation position relocated one layer up. And the fourth holds, since the relative cost shifts decisively toward external sourcing. So distribution is the function where my own framework predicts the outcome I like least. The rent does not dissipate and it does not return to the manufacturer. It migrates to a new intermediary that does not exist yet.

Most writing on this subject goes wrong in one of two directions. The maximalists assume a solvent dissolves everything in the beaker. The defenders assume that because some things do not dissolve, nothing does. Both miss the third category, which is where the strategy lives: things that neither dissolve nor resist, but change state.
Dissolves | Hardens | Changes state |
|---|---|---|
Reconciliation as a business | Legal finality and insolvency law | Regulation: from document to executable |
Custody as bookkeeping | Licensing as a bundle-preservation technology | Trust: from institutional to compositional |
Periodic reporting | Ontology and schema governance | Settlement: from event to condition |
The audit sample | Liability, which cryptography locates rather than absorbs | |
Attestation intermediaries whose only asset is being trusted to look | Central bank money as settlement asset of last resort | |
Non-portable reputation as a hostage mechanism | The seam between fabrics | |
Fixed issuance cost as a filter on which claims may become assets | Elasticity, which is somebody's willingness to extend credit |
The middle column is counter-intuitive and deserves a moment. A solvent does not merely fail to dissolve some things. It concentrates them. Everything that dissolves around a hard structure leaves that structure more exposed, more load-bearing and more valuable than before. Legal finality matters more in a world of instant transfer, not less, because it becomes the only remaining backstop. Licensing becomes more powerful as the thing it gates becomes cheaper to do. Ontology governance becomes the highest-leverage position in the system precisely because everything else has become interoperable.
There is also a category the table cannot hold, because it is not a fate that befalls an existing thing. A solvent gets constituents into solution so they can recombine, and what emerges from a dissolved industry is never just a tidier version of what was there. Composable capabilities, an extensible type system and the durable positions derived above are the recombination half of this argument, and they are the reason the paper does not end with a smaller industry. It ends with a larger one built differently.
The third column is the answer to how we solve for regulation, trust and settlement. We do not solve them. We change their state. Each stops being something done to a transaction by an institution and becomes, to the extent that it is verifiable, a property of the transaction, expressed in the fabric. The qualifier is doing real work: the trust section shows that only the verifiable part makes that move, and benevolence stays institutional by category. That is what it means for value to become programmable. It is not faster. It is a phase change in where these three things live.
The wrong question, asked in every industry forum, is whether the regulator will allow this. The right question is what supervision becomes when policy is code.
Regulation is not a constraint on this architecture, it is the load-bearing wall of it, because in finance the licence is what makes a bundle impossible to unbundle, and no protocol issues licences.
The mechanisms exist already. In the open fabric, network policies are authored in Rego, packaged as Open Policy Agent bundles, signed, and published as a network manifest by a facilitator organisation, so a network's rulebook is a signed, versioned, machine-executable artefact with an accountable publisher.⁴ Policy plug-ins at the network adapter can require human countersignature above thresholds of value, risk score or counterparty class, "enforced at the protocol boundary, not in app code".⁸ In the semantic layer, governance shifts "from post-hoc auditing to runtime enforcement," so a violating action is blocked as it is attempted rather than reported in a quarterly finding.¹⁰ And observability is designed so that "you can see how the network is performing without seeing what anyone is doing",⁴ which is structurally the shape of a supervisory dashboard that does not breach client confidentiality.
None of this is speculative, and the proof is that the most conservative corner of the industry has already done it. ISDA's Digital Regulatory Reporting takes an industry-agreed interpretation of reporting rules and transforms it, via the open-source Common Domain Model, "into unambiguous, machine-executable code," committed across fourteen reporting regimes in nine jurisdictions and, as of April 2026, applied to eight sets of rules, freely available to all firms and fully accessible to regulators.¹⁵ ISDA's own counts move between documents, so read those figures as a snapshot rather than a fixed state. JPMorgan implemented it as a primary reporting mechanism in October 2024. Natixis Corporate and Investment Banking adopted it in April 2026. Most significantly, the Ontario Securities Commission works directly with ISDA to code rule updates ahead of testing.¹⁵ That is a regulator writing executable code with an industry body. The phase change has already happened in one corner of the rulebook.
Supervision by subscription. A supervisor stops requesting a report and starts subscribing to the manifest and to network-level telemetry. Compliance stops being an assertion about behaviour and becomes an executable artefact that produces behaviour.
This is not a new idea, which is the most damning thing I can say about our pace. Raphael Auer set out embedded supervision at the BIS in 2019: "a regulatory framework that provides for compliance in tokenised markets to be automatically monitored by reading the market's ledger, thus reducing the need for firms to actively collect, verify and deliver data".¹⁶ Seven years ago. Still not implemented at scale.
Three hard problems, stated honestly, because anyone promising full regulatory automation has either not read a rulebook or is selling something.
Interpretation is not codifiable, and that is a feature. Best execution, suitability, fair treatment, reasonable steps: these are deliberately vague, and the vagueness is load-bearing, because it preserves discretion to apply judgment to cases nobody anticipated. Codify them and you destroy what makes them work. The honest boundary: rules become code, standards stay human, and the fabric's real job is to make the boundary between them explicit and auditable. Notice that DRR, the most advanced example in existence, machine-executes reporting rules, the most bright-line and least judgemental in the book. Nobody has machine-executed fair treatment, and anyone claiming to has redefined the standard into a rule.
Liability is unresolved. If policy is code and the code has a bug, who is liable: the schema author, the network facilitator, the implementer, or the participant? Auer identified this in 2019, naming the two central challenges as embedding economic finality in the legal system and "how to design rules for assigning responsibility in decentralised markets".¹⁶ Neither is settled. We never settled it for algorithmic trading either, and shipped that anyway.
Regulatory arbitrage moves at machine speed. If eligibility is machine-checkable across jurisdictions, agents will route to the most permissive compatible jurisdiction in milliseconds, without malice and without anybody deciding to. That is a genuine systemic risk, and the strongest argument for jurisdictional policy being expressed at the network manifest level rather than left to participants.
Which produces the provocation I would put in front of any supervisor.
The regulator's most powerful future instrument is not a rule. It is a schema. Whoever publishes the machine-readable eligibility schema for a jurisdiction sets the terms of participation more effectively than any enforcement action, because non-conforming participants are not punished. They are simply undiscoverable. That is an ex ante instrument of a kind supervision has never possessed, and most regulators have not noticed it is available.
Two claims about schema authorship now sit in this paper and they are not in competition, so it is worth joining them explicitly rather than leaving a reader to assume one contradicts the other. The regulator authors the perimeter; the incumbent authors the product. A supervisor's schema decides who may participate in a jurisdiction, which is an eligibility question and public by nature. An asset class schema decides what an instrument is, what must be proven about it and what happens on default, which is a semantic question and commercial by nature. The first cannot be sold, because a state does not licence its own perimeter. The second is where the durable position sits, and the trust section shows why it is not a monopoly either: the schema gets published to drive adoption, and the value is that the published semantics fit the assets and balance sheets its authors already have. Two different schemas, two different kinds of power, one shared consequence, which is that whoever writes the machine-readable definition sets the terms on which everyone else operates.
And note the governance consequence for control functions: human-in-the-loop stops being a policy statement and becomes a protocol parameter. Supervision moves from examining whether a firm has adequate controls to reading the policy the network enforces. For anyone in a control function, that is either the largest threat or the largest opportunity of your career, and which one depends entirely on whether your policies exist in a form a machine can execute.
Trust was expensive to establish, so we did what any industry does with an expensive fixed cost: we amortised it into institutions and rented it back to the market. A bank's brand is amortised trust. A credit rating is rented trust. A clearing house is mutualised trust. Correspondent banking is chained trust, where I trust you because I trust somebody who trusts you, and the chain is precisely why cross-border payments take days and leak fees at every link.
A protocol can make dishonesty unprofitable wherever dishonesty is detectable, and detectability is where the whole architecture stops. That is not a new insight so much as an old one arriving in new clothing: it is Holmström's informativeness principle, that an incentive contract can only condition on what is observable, applied to a system where the observable set is defined by what the protocol instruments. That single constraint decides which trust businesses survive and which are already obsolete.
Programmable value stops trust being a property of a counterparty and makes it a property of a transaction, composed per event from parts that can each be independently verified: credentials establishing what is proven about the parties, with selective disclosure allowing proof without revelation, compressed by the fabric into "one identity, many proofs";⁴ portable reputation signed by counterparties and held by the subject;⁴ trust-set selection made per transaction rather than per network;⁵ gradient guarantees turning counterparty risk from a binary gate into a continuous underwritten position;³ and audit anchoring making the trail the proof rather than an institution's word for it.⁴
But which parts of trust can actually be composed? The answer sets the outer limit of everything above.
Perceived trustworthiness rests on three factors, and the framework is not mine: Mayer, Davis and Schoorman set it out in 1995 and it has been the standard model in organisational trust research ever since.²⁴ Ability, whether you can do it. Integrity, whether you adhere to the principles you have stated. And benevolence, whether you intend my good, particularly when acting against it would be profitable and undetectable. Their distinction is worth preserving rather than collapsing, because it does work here. Trust in their model is the willingness to be vulnerable to another party's actions irrespective of your ability to monitor or control them, and the three factors are what a party assesses in deciding whether to become vulnerable. Which locates precisely what a proof system can and cannot replace: it can substitute for the assessment, and it cannot remove the vulnerability. So the question for the rest of this section is not which parts of trust can be composed, it is which of the three factors can be evidenced by something other than an institution.
Evidence of ability is attestable, and the attestation is verifiable. Credentials carry licences, capital adequacy, accreditation and operational capacity, and a verifiable credential is precisely an ability-attestation technology. Keep the two apart, because the gap is where the failures live: a credential proves that an authoritative party asserted the capability, not that the capability holds under stress it has never met.
Recorded conduct is observable, within the instrumented envelope. Audit anchoring and bi-temporal state make it possible to check continuously, rather than by sample, whether behaviour matched stated policy, and runtime enforcement goes further by making deviation unavailable rather than merely detectable. The qualifier is doing real work: what is observable is what the instrumentation captures, and conduct outside that envelope is exactly as invisible as it was before.
The instinct that this is where institutions survive is widely shared and usually left imprecise. The standard sector formulation is that the only thing which cannot be automated is trust, with custody surviving as identity verification, regulatory compliance and the trust layer for atomic operations. Directionally right, and worth testing item by item, because two of those three do not survive. Identity verification is ability-attestation, which is exactly what verifiable credentials commoditise. Regulatory compliance becomes policy-as-code, and anyone who describes compliance as a composable capability on the ledger has already conceded the point. What actually survives is the third item, and only in a narrow form.
Benevolence is neither verifiable nor observable. No credential proves a counterparty will act in your interest when acting against it would pay and nobody would see. This is not a gap in the technology; it is a category boundary. Cryptography proves things about the past, that this happened and this was signed and this state obtained, and things about constraints, that this cannot happen. It cannot prove anything about preferences under conditions that have not yet arisen. Benevolence is exactly that.
So what does civilisation actually do about benevolence? It does not verify it. It engineers around it. Carstens names the mechanism with unusual precision when he explains why central banks are independent:
"autonomous central banks are nothing more than an institution within the state with the key mandate of preserving the purchasing power of the national currency. Autonomy is the social engineering which shores up society's trust in the central bank."²¹
Read that as a general principle and it explains an enormous amount of financial architecture. Independence does not prove benevolence. It makes malign intent structurally difficult and expensive. And the same is true of every other device we use for the purpose: fiduciary duty, fit-and-proper tests, conflict-of-interest rules, skin in the game, mutualisation, lender of last resort, deposit insurance, capital that is forfeited on failure, and personal liability for directors. Every one of these is a benevolence substitute, and every one is institutional rather than technical.
Carstens is easy to recruit further than he goes. He never uses the word benevolence, and his account of why central banks are trusted rests on mandate and integrity rather than on disposition: trust requires "sound institutions that can stand the test of time", institutions that "guarantee the safety and integrity of payments", holding a "clear mandate to serve society" and not aiming for profits.²¹ That is a claim about structure, which is exactly why it supports the engineering-around reading and not a claim about verifying good intent. His definition of trust does make the separation I need, without naming it: trust "consists in society's expectation that the authorities will act predictably in the pursuit of predefined objectives and that they will succeed in their task".²¹ Predictable pursuit of objectives is close to benevolence. Succeeding at the task is ability. He also names an asymmetry, that the dynamic "can also work in the other direction and, at times, very quickly. In the extreme, if trust evaporates, the capacity to make effective public policies disappears".²¹ The inference I draw from it is mine and not his: that ability degrades gradually while benevolence collapses. It is an observation about how institutional failures actually unfold rather than a finding I can source, and it should be read at that weight.
There is corroboration for the compositional half of this from an unexpected direction. Auer's embedded supervision argument turns on the observation that where "data credibility is assured by economic incentives," supervisors must first satisfy themselves that "the market's economic consensus is strong enough to guarantee the finality of transactions" before they can trust the ledger's data, and his model has verifiers stake verification capital that is forfeited if history is ever reversed, calculated so that reversal is unprofitable for any possible briber.¹⁶ Read generally, that says something important, and the wording has to be exact because the mechanism delivers far less than it appears to: in a fabric, one narrow component of trustworthiness gets collateralised rather than institutional. What is staked against is detectable protocol-integrity failure, specifically the reversal of settled history. It is not benevolence, which is a disposition to act in another party's interest when nobody is watching, and a stake cannot be forfeited against a disposition. So integrity, in the specific sense of not rewriting the record, becomes a balance sheet item with a price, held against an observable failure, rather than a reputation held in general. Benevolence stays exactly where it was.
But the mechanism has a precise boundary, and stating it is what separates this from a slogan. Forfeitable capital does not verify anyone's intentions and does not need to. It makes a detectable failure unprofitable, rendering good intent unnecessary within exactly the scope of what the protocol can observe. Reversing a settled history is detectable, so it can be collateralised. Failing to warn a client about a risk you could see, steering an order to a venue that pays you, or declining to help when helping is costly and silence is invisible are detectable by no protocol, so no amount of staked capital touches them. Detectability is the binding constraint on collateralised trust, which makes the design question not how much capital to stake but how much of the failure surface is observable. It is also why the institutional substitutes survive: they cover the undetectable remainder.
Now the strategic conclusion, and it is the most useful sentence in this piece for anyone running an incumbent. The fabric commoditises ability-verification and integrity-observation, and those are most of what custodians, auditors, registrars, transfer agents and rating agencies actually sell. What it cannot commoditise is the benevolence-substitute business: standing behind an outcome, being liable, being resolvable, holding a mandate, being suable, and being constrained by a licence you would lose.
The remaining moat is not knowing things. It is being answerable. That is a smaller business than the one you have, and a far more defensible one.
Two hard problems on the other side, and the first is the least prudentially supervised thing in the stack.
Trust in the ontology. If shared meaning makes composition possible, poisoning the meaning is the highest-leverage attack available, and the semantic layer's own analysis names semantic poisoning as a novel attack vector, answering it with community governance and cryptographically signed ontology packages so that "an agent cannot be tricked into redefining 'yield' because the definition is locked in the semantic layer, not in the agent's prompt".¹⁰ Right engineering answer. But notice what it does economically: it relocates trust to the body governing the schema, which becomes the most systemically important institution in the architecture. We are creating systemically important semantic infrastructure, and it is the least supervised by public authorities of anything being built in this stack. Say that carefully rather than claiming it is ungoverned, because the counterexample is obvious and it is a good one: ISDA, Swift and ISO already run semantic infrastructure the system cannot function without, and they are governed by member committees, change-control processes and published procedures. What none of them carries is the apparatus that attaches to a systemically important financial market utility: no capital requirement, no resolution regime, no supervisory college, no designation, and no public authority accountable for continuity if governance fails. Industry governance is not absent. Prudential supervision is. And the gap widens as more of the system's behaviour moves from documents a supervisor reads into schemas a machine executes. The natural rebuttal is open source and the right to fork, and it does not hold, because forking an ontology is categorically different from forking code. The entire value of an ontology is that everyone shares it, so a fork is not a competing implementation, it is a second market. Ontology has stronger network effects and higher switching costs than the ledger ever did.
But the rent does not work the way I first argued, and the correction matters. The obvious prediction is a monopoly charging for access to meaning, and the evidence points the other way. ISDA's Common Domain Model is authored by a body whose membership is the largest dealers, and it is published open-source and free, precisely to drive adoption.¹⁵ If that is the pattern, ontology governance does not produce a private monopoly at all. It produces a consortium or a regulated utility, and the schema is given away.
Which is not a weaker conclusion, it is a sharper one. The value of authoring the schema is not the licence fee. It is that you write the schema to fit the operational architecture, compliance model and balance sheet you already have, so that conforming to it leaves your existing assets indispensable and everybody else's optional. Open-sourcing it maximises that effect rather than surrendering it. You are giving away the map to make certain everyone drives on your roads.
So the systemic risk is not monopoly pricing. It is an unsupervised body with no prudential framework designing the rules of the road to suit its members' balance sheets, at a level of the stack nobody is watching. We spent a decade arguing about who should run the ledger. Nobody is arguing about who should author the schemas, which is the question with the durable strategic position attached.
Derivative benevolence caps the agent economy. Agents inherit "the trust score and liability profile of their human governors",¹⁰ with a credential chain tracing every action to a responsible human. That is the correct design, and it is a benevolence substitute of exactly the classical kind: a human with something to lose stands behind the machine. It works only while the agent's economic footprint stays within its governor's capacity to answer for it. The moment agents accumulate independent reputation and are trusted more than their governors, the substitute has failed silently, because the party the counterparty is actually relying on is not the party who can answer for it. Nobody is measuring that ratio.
And one closing observation, because it inverts the whole subject. Money works because it is information-insensitive, accepted "with no questions asked", without due diligence. The idea belongs to Gorton and Holmström before it belongs to the BIS, and Holmström's formulation is the one worth holding onto: the whole point of a good money market instrument is that nobody investigates it.²⁵ That is a designed absence of verification, and it is the highest achievement of a monetary system rather than a shortcoming. Which means the endpoint of a verification revolution is not universal verification. It is a system where enough is proven, cheaply enough and continuously enough, that nobody at the point of use needs to ask.
The sweeping version of that claim is wrong, so here is what actually gets retired. Programmable systems verify identity, authority, integrity, revocation status and the satisfaction of stated conditions. They do not verify the credit quality of an issuer, the adequacy of its capital, or whether the claim will be honoured under stress, and those are precisely the questions information-insensitivity suspends. Cheap proof shrinks the verification surface a user must inspect. It does not reach the core of what makes an instrument acceptable without inquiry, which remains a matter of who stands behind it.
The goal of programmable proof is not universal verification. It is to make asking unnecessary at the point of use, while leaving intact the harder question of who is answerable if the answer is wrong.
And there is a consequence of that inversion which this paper has been circling for pages without naming, assembled entirely from components already argued above. Continuous verifiability plus instant settlement is a run technology. Information-insensitivity is what keeps a deposit stable: nobody checks, so nobody moves. Make the underlying continuously observable and you have manufactured the opposite property, an instrument whose holders can see deterioration in real time. Then put it on rails where exit is atomic, irreversible and available at three in the morning on a Sunday, and remove the two frictions that have always bought supervisors their weekend, namely the queue and the closing bell. Depositors and investors tried to pull forty-two billion dollars out of Silicon Valley Bank on 9 March 2023, leaving it with a negative cash balance of about nine hundred and fifty-eight million by the close, and management expected over a hundred billion more the following day.³⁵ Read those figures as a calibration floor rather than as an analogy, because the mechanism is not the same and the difference cuts both ways. SVB was human herd behaviour: venture capitalists telephoning founders, a concentrated and socially networked depositor base, and a panic that needed a night to spread. Agent-driven withdrawal is deterministic threshold breach, which is faster and also more legible, because a published policy can be read in advance in a way that a group chat cannot. So the claim is not that agents panic. They do not panic, and that is the problem: they execute, simultaneously, without the hesitation that has always given supervisors their margin. SVB tells us what forty-two billion in a day does to a balance sheet. It does not tell us what a thousand mandates breaching the same threshold in the same second does, and no episode does, because it has not happened yet.
Which leaves the premise that makes that sentence worth writing, and it needs stating rather than assuming, because the whole risk turns on it. Why would many independent mandates breach at the same instant? Not because anyone coordinates, but because the inputs are shared. Agents read the same public feeds, so the observation arrives simultaneously. Risk policies are written by a small number of framework vendors and consultancies, so the thresholds cluster around the same numbers. Regulatory triggers are common by construction, since a liquidity coverage breach or a ratings downgrade is the same event for everyone holding the instrument. And prudence itself converges: an agent instructed to act on deterioration will pick a level a supervisor would endorse, which is the level everyone else picked. Correlation does not require collusion, only common inputs and common prudence. That is not speculative, it is the mechanism behind portfolio insurance in 1987, the liquidity evaporation of the 2010 flash crash, and the liability-driven investment margin spiral of 2022, in each of which independent parties following individually sensible rules produced a single synchronised move. The difference here is that the interval between observation and execution falls from minutes to milliseconds, and that the policies are published in advance, which is the one genuinely favourable feature: a supervisor who can read the thresholds can, in principle, see the cliff before anybody goes over it.
Which turns two of this paper's proudest claims into the same risk viewed from opposite ends. Successive gross discharge trades inventory cost for recall speed. Continuous observability trades opacity for early warning. Both are genuine improvements in normal conditions, and both shorten the interval between a doubt and a withdrawal to the point where no human intervention fits inside it. Every crisis tool we own assumes a delay that this architecture removes: the discount window needs someone to answer the telephone, a trading halt needs a venue that can be halted, and deposit insurance works by persuading a depositor not to join the queue, which requires a depositor capable of being persuaded rather than an agent executing a threshold. So the honest statement of the risk is not that programmable value causes runs. Runs are as old as banking. It is that programmable value removes the friction that has always been doing the supervisory work while nobody credited it, and nothing in any architecture I have described replaces it. Circuit breakers expressed as protocol primitives, rate limits on redemption, and elasticity facilities that a machine can draw on without a phone call are the obvious candidates, and one of them already exists in production, which makes the gap sharper rather than smaller. TARGET2-Securities has run auto-collateralisation since 2015: when a settlement instruction would otherwise fail for want of cash, the platform automatically generates intraday credit against eligible securities, with no human in the loop, inside an infrastructure settling around seven hundred thousand transactions a day.³⁶ So machine-triggered liquidity is not a design fantasy, it is a decade-old feature. What does not exist is that facility across fabrics, because auto-collateralisation works precisely where one operator holds the securities account, the cash account and the credit relationship in a single legal envelope. Split those across two fabrics and there is no party positioned to extend the credit, no agreed collateral eligibility, and no single insolvency regime governing the claim. Which is the seam again, arriving in the one place where a delay of even seconds is systemically load-bearing. Anyone building this layer should treat cross-fabric elasticity as the most urgent unbuilt thing in the stack, and considerably more urgent than the netting utility predicted in the settlement section that follows.
Settlement is historically a discrete event at the end of a chain, because it required the sequential coordination of separate books. That sequence is the parent of everything downstream: the settlement date, settlement risk, netting, the collateral posted to cover the gap, and the entire post-trade industry. The post-trade industry is a monument to latency.
And here is the sentence this section exists to earn. Pre-funding is a seam cost: cheap inside one ledger, expensive across two, and no amount of atomicity changes that. Everything else here is the derivation.
With atomic primitives and sub-transaction privacy, settlement stops being a scheduled event and becomes a continuously evaluated condition, so that the question moves from when a transaction will settle to whether its conditions are satisfied at this instant. Canton's worked example is the argument in one transaction: the bank sees the cash leg, the registrar sees the securities leg, both validate what they can see, the synchronizer commits without seeing either, and the trade settles atomically with neither party learning the other's data.⁶
But here is the correction that changes the design. The New York Fed separates two properties the industry routinely conflates under the word atomic: instant settlement, meaning no gap between trade and settlement, and simultaneous settlement, meaning one leg settles if and only if all others do. Their judgement is unambiguous: "while simultaneous settlement is probably always desirable, instant settlement may not be".¹⁷
Why not? Because instant settlement makes netting impossible by construction. "For a trade to be instantly settled, all legs of the transaction must be 'settle-able' at the moment the trade is executed, which makes netting of settlement obligations impossible... only trades in which cash and securities are pre-positioned can be executed".¹⁷ And there is a second cost that gets much less attention than the funding one: instant settlement is an information leak. Decoupling trade from settlement lets a trader negotiate without revealing past activity, whereas "with instant settlement, traders can only sell securities they already hold, which reveals information about past trades," creating hold-up problems.¹⁷
Sit with the irony, but get it the right way round. The tension is not between immediacy and confidentiality. Canton's sub-transaction privacy keeps balances and transaction details confidential while settling immediately, and there is no technical incompatibility between the two. What immediacy erodes is something different: opacity about capacity. If you can only sell what you already hold, then the fact that you settled tells the market something about your inventory and your financing, and no amount of encryption hides an inference drawn from your ability to act.
The trade-off is not immediacy versus data privacy. It is immediacy versus opacity about capacity and funding, which is a strategic exposure rather than a cryptographic one, and the industry has been marketing the solution to one as the solution to both.
That has a consequence which connects to the funding argument below. If the funding leg can itself be composed into the atomic transaction, then settleability no longer implies prior ownership. Composable funding is a privacy technology as well as a liquidity technology, which is not an argument I have seen made elsewhere. But apply this paper's own motif honestly and the channel relocates rather than closing. An observer who can no longer infer that you held the asset can now infer that you could source it, at that size, at that moment, at a price that made the trade work, which is information about your credit lines and your standing with liquidity providers rather than about your inventory. The inference moves from what you own to what you can summon, and for a large dealer the second is arguably the more sensitive fact.
So the correct formulation of the phase change is narrower and more useful. What becomes continuously evaluable is simultaneity, not instantaneity: the requirement that all legs succeed together, decoupled from any requirement that they do so immediately. That preserves netting, preserves the information environment, and still eliminates principal risk, which is what Herstatt taught us to care about.
Then the limit no amount of programmability touches, and it is the hardest constraint in this entire body of work. The BIS names elasticity as one of three tests any monetary arrangement must pass: money must be "provided flexibly to meet the need for large-value payments in the economy, so that obligations are discharged in a timely way without gridlock taking over," because "maintaining cash piles or retaining large holdings of pre-funded accounts to discharge obligations are simply impractical, they would be recipes for payment system gridlock".¹³ Stablecoins fail this test because full backing means "any additional issuance requires full upfront payment by holders, which undermines elasticity by imposing a cash-in-advance constraint".¹³
Now apply that to atomicity itself, which is what nobody does.
Atomicity is a settleability-at-commitment constraint expressed in code. Every leg, including any funding leg, must be settle-able at the instant of commitment. That is a weaker requirement than holding cash in advance, and the difference is the whole design space: where a funding leg can be composed into the atom, the constraint is priced contingent liquidity, and where it cannot, the constraint degenerates into cash-in-advance, which is exactly what the BIS calls a recipe for gridlock.
Which locates the problem more usefully than the maximal version of the claim. The severity of the constraint is a function of whether you are inside one fabric or crossing a boundary, because a funding leg is compose-able where atomicity holds and not compose-able where it does not. Cross-fabric, atomicity fails at precisely the point where the funding leg would need to sit, so the requirement collapses back into pre-positioning. That is the same conclusion the seam argument reaches from the other direction, and the two arriving together is itself the evidence.
But whichever form it takes, the underlying limit is untouched by programmability. Programmable value has an elasticity problem that is structural rather than transitional. You cannot program elasticity from nothing. Elasticity is somebody's willingness to extend credit against collateral, and that willingness is a balance sheet, a licence and a central bank behind it.
The obvious counter comes from the operations side, and it is the Nothing Rests argument made above. If value transfers in milliseconds then nobody tolerates idle balances, so cash immediately seeks yield and high-quality assets are immediately lent or pledged. On that reading, pre-positioning costs nothing, because the pre-positioned balance is earning.
That counter does not work, and it is worth being exact about why, because the mistake is being made across the industry.
Pre-funding is a constraint about deliverability, not about yield. The cost of pre-funding was never that the balance earns nothing, and the idle-versus-productive framing is the wrong axis. A tokenised money market fund share accrues yield continuously and remains transferable at any moment, which is exactly the Franklin Templeton case cited above, so earning and being deliverable are perfectly compatible. What defeats settleability is not earning. It is encumbrance: pledged, lent, rehypothecated, posted as margin, staked, or subject to a third-party right.
Atomicity requires the asset to be deliverable. Nothing Rests, taken to its limit, requires the asset to be encumbered, because the highest-yielding uses of a high-quality asset are lending it and pledging it. An asset cannot be simultaneously pledged elsewhere and delivered here, and the industry is selling both as features of the same architecture.
Which narrows the objection considerably, and the narrowed version is the one worth defending. Pre-funding does not cost you yield. It costs you three other things. It costs foregone encumbrance, meaning the same asset cannot secure a derivative position or fund a repo while it waits at a seam, and rehypothecation capacity is the engine of balance sheet efficiency rather than a footnote to it. It costs capital and funding capacity, because acquiring the asset in order to pre-position it consumes both. And it may cost transformation friction, because a deliverable asset is not a settlement asset unless the counterparty accepts it, and a tokenised fund share is neither central bank money nor a commercial bank deposit. If the other side requires cash equivalence, the yield-bearing instrument must be transformed before it can discharge the obligation, which reintroduces exactly the timing and bridging problem this section is about.
So Nothing Rests does not answer the pre-funding objection. It relocates it, from idleness to encumbrance, capital and acceptability. Which raises the fair question of whether any version of the counter survives, and three do, each deserving its full strength.
Velocity reduces the required stock. If an asset can be recalled, unwound and redeployed in milliseconds, the same unit of collateral services many more obligations per day, so the stock needed falls even though deliverability is still required, because it is required only momentarily. This is real, and it is not netting. Netting extinguishes gross obligations and replaces them with a single net figure, so fewer discharges occur. Velocity does the opposite: every obligation is discharged in full, and the same asset is reused to do it. Successive gross discharge is the accurate description, and the distinction matters because the two have opposite risk profiles.
Netting reduces the number of settlements and therefore contains the damage when one fails. Successive gross discharge does the reverse: it creates a chain in which each discharge depends on the previous one having released the asset. The failure mode is gridlock rather than shortfall. One party declining to release, or releasing slowly, and every downstream settlement relying on that unit fails at once, which is a queue rather than a loss. So velocity trades inventory cost for throughput risk, and the binding parameter becomes recall speed, set by the slowest leg in the encumbrance chain. Concede the part of this that programmability genuinely solves, because the blanket version of the claim is wrong. Where the pledge is itself an on-ledger encumbrance recorded on the same fabric, release can be near-instant and conditional, since the lock is a protocol state and unlocking it is a transaction. What is not a millisecond operation is recall where the pledge sits in a bilateral agreement under a governing law, in a tri-party arrangement with an agent's own processing cycle, or in a chain that crosses a seam into another fabric. The recall speed of the whole chain is set by its slowest link, and the slowest link is almost always the one that is not on your ledger. Which is precisely why an intraday elasticity provider has to exist: somebody must supply the unit that breaks the queue when the chain stalls.
The funding leg can itself be composed atomically. This is the strongest version, and the stream thesis does not make it. If the settlement transaction can include a repo, a money market sweep or an intraday credit draw as one of its atomic legs, you never need to hold the asset in advance. You need to hold the ability to obtain it. That genuinely dissolves pre-funding as a stock requirement, and it is the most important design implication in this section.
But look closely at what it concedes. It replaces a stock of assets with a committed facility, and a committed facility is a balance sheet that is priced and capitalised. The elasticity does not come from the protocol. It comes from an intermediary willing to be on the other side of that leg. The protocol makes elasticity composable; it does not make it free and it does not manufacture the balance sheet.
Resist the tempting next step, which is to assert that atomic credit must therefore be more expensive. It need not be. A committed facility already removes the provider's discretion to refuse a compliant drawdown, which is what "committed" means and why such lines carry commitment fees and capital charges, so loss of discretion is not a novelty of atomicity. And atomic drawing brings genuine offsets: the provider receives its collateral simultaneously rather than at the end of a settlement window, exposure duration is shorter, controls are executed rather than promised, and settlement risk on the funding leg itself is eliminated.
What actually changes is not the existence of the obligation but its shape. Atomic draws are machine-speed, simultaneous and correlated, fired by many users at the same instant on the same observable state, with no human in the loop to sequence, triage or delay. That is a different distribution of exposure rather than a higher one, and whether it nets out dearer or cheaper depends on the design, the collateral and who is providing it. Atomic credit is differently risky credit, and the correlation is the part nobody is pricing.
Central bank money can sit on the same programmable surface. Which is the real answer, and it is the BIS answer, and it concedes the argument entirely: the solution to the pre-funding problem is the central bank.
So the resolution is not that one side wins. Applying this paper's own framework to itself, pre-funding neither dissolves nor hardens. It changes state, from a stock of pre-positioned assets into a flow of committed, atomically drawable elasticity. That is better in every operational respect and worse in one that matters.
Pre-funding is not defeated. It is refinanced. The requirement moves off the balance sheet of the transacting party and onto the balance sheet of whoever provides the atomic funding leg, which is a smaller number of larger institutions, drawn by machines at the same moment for the same reason, precisely when conditions are worst.
That also separates two arguments the industry runs together. Availability is microeconomic and binds in normal conditions, and composable atomic funding resolves it at a price. Buffers are macroeconomic and bind under stress, and nothing resolves them except the central bank, because the aggregate stock of unencumbered high-quality assets is what a system draws on when everyone needs liquidity at once. A world in which nothing rests is a world with no buffers, which lengthens collateral chains and raises intraday dependence at the same time. Here is the exact claim, since the loose one would be indefensible: that configuration, long chains plus high intraday dependence plus thin unencumbered buffers, is a recognisable feature of the repo market stress of 2008, the September 2019 spike in US repo rates, and the March 2020 dash for cash. It is not a claim that any of those events was caused by an architecture that did not exist, nor that programmable settlement would have prevented them. It is the narrower and more uncomfortable observation that the design we are being sold optimises toward the configuration those episodes had in common.
Velocity substitutes for buffers in normal conditions and cannot substitute for them under stress. Elasticity in a stream world is therefore more dependent on the central bank rather than less, because the private buffer stock has been optimised away by exactly the efficiency the architecture delivers.
A further consequence follows, and the stream argument presents it as a benefit. Collateral quality assessed continuously is procyclicality with the heterogeneity removed, and the mechanism is not the obvious one. Margin spirals are not caused by slow valuation. Institutional markets already mark at least daily, cleared markets already issue intraday calls, and the 2020 dash for cash and the 2022 liability-driven investment episode were driven by leverage, forced selling, haircut dynamics and funding constraints rather than by how often anyone revalued.
The risk continuous assessment introduces is not speed but synchronisation. When every participant evaluates the same continuously published collateral state under machine-executed policy, procyclical demands stop being staggered by heterogeneous valuation timing, differing internal models and human sequencing, and start firing simultaneously. That is the identical mechanism as the correlated atomic drawdown described above, and the two compound: the same instant that triggers everyone's collateral call is the instant everyone draws their atomic funding leg. Efficiency and stability are moving in opposite directions here, and both belong on the same slide.
Intellectual honesty requires naming where pre-funding genuinely is defeated, because there is such a case and it is growing. Where both legs sit on the same ledger and the counterparty already holds both, the burden falls sharply: intraday sweeps within one institution, collateral substitution within one custodian, tokenised fund shares settling against tokenised deposits at the same bank, repo where both legs are on one platform. Ledger unity removes the bridging problem, the settlement window and the uncertainty about whether the other side can perform. It does not remove the requirement that both assets be deliverable and unencumbered at execution, and it does nothing whatsoever about third-party rights: a pledge has legal effect regardless of which ledger the asset sits on, and legal recall of pledged collateral is not made instantaneous by technical co-location. Same-ledger settlement makes pre-funding materially cheaper. It does not make it disappear. And the flagship deployments people cite for this are not yet examples of it, which is the more telling fact. Franklin Templeton's platform carries the share record on the ledger while subscriptions and redemptions settle in dollars off-chain, and Broadridge's Distributed Ledger Repo tokenises the collateral leg while "settlement is made by triggering a payment on conventional payment rails rather than cash on ledger".²³,³¹ Both are single-leg deployments: asset on ledger, cash on the old rails. So the seam is not a future problem arriving when fabrics multiply. It runs straight through the middle of the two most-cited tokenisation successes in the market today, between the leg that was modernised and the leg that was not.
Which gives the constraint its correct scope, and it folds neatly into this paper's central structural claim. Pre-funding is a seam cost. Inside a unified ledger it is cheap, because the funding leg can be composed into the atom and recall is fast where the asset is unencumbered. Across fabrics it is expensive, because composing a funding leg across a boundary means paying the coordination cost of an interconnection protocol rather than the near-zero cost of a shared commit, which is what Canton concedes about bridges and what the BIS identifies as the price of disparate ledgers.⁷,¹⁴ The more fabrics you span, the more you must pre-position.
That also upgrades a prediction this paper makes twice, here and in the trust section. The first genuinely new institution of the fabric era is not merely a netting utility. It is an intraday elasticity provider: netting, plus a committed liquidity facility, plus a collateral recall engine, operating between fabrics rather than inside one. Which is to say a central counterparty with a discount window attached. We will have dissolved the clearing house and rebuilt it on better foundations with a central bank line, and we should be mature enough to call that progress.
Carstens makes the same point from the institutional side: ultimate settlement at the central bank "is made possible by the central bank's high flexibility to create liquidity through its lending to the banking system," extending in stress to the lender of last resort function.²¹ That is why credit does not dissolve, why banks do not dissolve, and why tokenised central bank reserves sit at the centre of every serious blueprint, "ensuring the singleness of money".¹³ Settlement risk approaches zero and liquidity risk rises to meet it. We trade a credit risk we know how to price for a liquidity risk we manage badly.
And finality remains legal rather than technical, which is worth stating bluntly because the confusion is everywhere. Cryptographic irreversibility is not legal finality. In the European framework, finality is a carve-out from insolvency law conferred by statute on designated systems, establishing "the finality and irrevocability of transfer orders once entered, even in the event of a participant's insolvency".¹⁸ But the loose claim that a fabric has no finality without a statute is wrong, and the layered version is more useful. Legal finality is at least three separate things. A transfer can be legally effective, passing title or discharging an obligation under ordinary property, contract or account law, and that requires nobody's designation: it happens millions of times a day outside any designated system. It can be protected from insolvency unwinding, immune to zero-hour rules, avoidance actions and stays, and that is the layer conferred by statutory designation and nothing else. And it can be protected against competing third-party claims, which depends on property law, perfection and priority rules rather than on either of the first two.
Which makes the practical position sharper than the maximal claim. A fabric can achieve the first layer under existing law, today, by construction. It cannot achieve the second without a legislature, at any price, by any engineering. The industry can build effectiveness and must be granted immunity, and confusing the two is why so many pilots describe themselves as final when what they mean is irreversible. And that grant is being renegotiated now: the European Commission published a proposed Regulation on settlement finality in December 2025, repealing the Settlement Finality Directive outright rather than amending it.³⁸ The Financial Markets Law Committee's response in July 2026 is instructive for what it does and does not question. It does not dispute the concept of finality. It raises the application of insolvency protections to third-country systems registered in the European Union, and the definitions of "participant", "transfer order" and "collateral", along with the treatment of indirect participants.¹⁹ Which is the more useful signal: the contested ground is not what finality means, it is who and what falls inside its perimeter, and a composed transaction assembled from participants in several jurisdictions is a question about exactly that perimeter.
Look closely at which words are contested. Participant. Transfer order. Collateral. Those are precisely the concepts programmable value redefines. When a token pool holds a claim and an agent initiates a transfer under a delegation credential, who is the participant and what is a transfer order are genuinely open legal questions. The outcome of this decade is being decided in the definitions section of a regulation, not in anybody's protocol.
Which carries a timeline that anyone building a business case should price in rather than hope past. The original Settlement Finality Directive took years to negotiate and years more to transpose into national law across the member states, and the Regulation now proposed to replace it is at the start of that process rather than the end. Legal change of this kind runs in years and sometimes decades, and it runs at a pace set by legislatures that have other priorities. So the strategic consequence is not that the law will eventually catch up. It is that for the whole of the period in which these systems are actually built, legal finality will be the binding constraint and the engineering will be waiting on it. Design for coexistence with the old legal perimeter, because you will be living inside it for longer than any roadmap assumes.
Programmable value cannot program a judge.
If I only make the case for this architecture, this is marketing. Here are the nine places I think it is weakest, in the order I would attack them.
Privacy and transaction-level compliance may not both be satisfiable, and I have been selling them as complements. This is the one I would lead with against myself, and it lands at the intersection of two claims I have made confidently. I have argued that sub-transaction privacy is a mandatory policy precondition of any institutional environment, and I have argued that supervision becomes subscription, resting partly on observability designed so that you can see how the network is performing without seeing what anyone is doing.⁴ Both of those are about prudential supervision, which is aggregate by nature. Financial crime compliance is not aggregate. It is transactional, and in most implementations it requires seeing exactly what a named party is doing at the level of the individual transfer.
Take my own worked example, stated accurately, because the accurate version is worse than the loose one. In Canton's own delivery-versus-payment illustration, the bank sees only the cash movement and the registrar sees only the share transfer, while the buyer, the seller and the trading application see both legs.⁶ So it is not true that nobody holds the complete picture. Parties with full visibility exist by construction, and the ones who are blind by design are the Super Validators sequencing the transaction.⁷
Which relocates the problem rather than dissolving it, and the relocated version is the harder one. The question is not who can see the transaction. It is whether any party holding the full view is a regulated entity carrying the screening obligation, and whether the partial-view parties can lawfully discharge their own obligations by relying on that party's screening without receiving the underlying data. In the illustration, the parties with full sight are the trade's own principals and the application that assembled it, which is precisely the set with the weakest claim to independence. The bank carries the obligation and cannot see the asset. The registrar can see the asset and does not hold the customer relationship. Sub-transaction privacy has not hidden the transaction from everybody, it has hidden it from exactly the parties the statute makes responsible. Reliance on another party's proof is the mechanism that would have to close that gap, and reliance is a legal construct, not a cryptographic one.
The direction of travel makes this harder rather than easier, though the obligation is looser than I first stated it. The FATF's June 2025 revision of Recommendation 16 tightens rather than relaxes the requirement that originator and beneficiary information travel with the transfer, and standardises what must accompany cross-border payments above one thousand dollars or euros, with changes taking effect by the end of 2030.³² But FATF Recommendations are an international standard that countries implement through their own measures, not law in themselves, and the revised explanatory note is explicit that Recommendation 16 "does not itself require real-time sanctions screening", leaving the modality to national regulation and permitting pre-validation checks, post-validation checks or holistic monitoring.³² So the timing constraint is set by national implementations rather than by the standard, which means it will vary by jurisdiction, which for a cross-border composed transaction is worse rather than better. What the revision does settle is attribution: the payment chain "is considered to start with the financial institution which receives an instruction from the customer". A composed transaction assembled at runtime from several capability providers is a payment chain whose participants are determined at execution time, so the question of which party received the instruction is itself a design decision. Deciding who is responsible for what travels with it is a genuinely unsolved problem, and I have written a paper about composition without addressing it.
There are three plausible answers and I do not know which wins. Selective disclosure to a compliance role, so a designated screener holds a view no commercial party has, which reintroduces a trusted third party at exactly the point the architecture was supposed to remove one. Zero-knowledge attestation of screening, where a party proves it has screened against a current list without revealing the transaction, which is technically credible and legally untested, since no supervisor has yet accepted a proof of compliance in place of the underlying data. Or a policy carve-out, where privacy yields to the compliance function by design and institutional participants accept that one role sees everything. My instinct is that the third wins first, because it is the only one with legal precedent. What that costs me is worth stating precisely, because the loose version concedes too much and the precise version concedes something real. Privacy from the market survives untouched, and that is the precondition I claimed: competitors cannot see your positions, counterparties cannot infer your book, and a compliance authority holding a complete view has always coexisted with that, in every market that has ever had a supervisor. What does not survive is the architectural purity claim, that the design removes the trusted third party. It does not. It removes the commercial one and reinstates a compliance one, holding a view no market participant holds. That is a smaller concession than abandoning the precondition and a more uncomfortable one, because the paper's rhetorical energy comes from dissolving trusted intermediaries, and here one walks back in wearing a badge.
The verification thesis has a rival explanation, and it is partly right. If finance's binding agent is the impossibility of cheap remote proof, why did the fund wrapper survive electronic trading? Because tax and regulatory perimeter, not verification, hold a great deal of finance's architecture in place. A collective investment vehicle is a tax conduit before it is a proof mechanism, passing income to holders without entity-level tax, and its passport regime is what makes cross-border distribution legal at all. Neither is dissolved by cheaper proof. A tokenised portfolio held directly may be operationally superior and fiscally inferior, and for most investors in most jurisdictions the fiscal difference will exceed the operational saving. So the fund survives as a fiscal and regulatory object after it stops being necessary as an operational one, and this paper's claim that it becomes a configuration parameter is about its operational rather than its legal existence. The wrapper thins into a shell. It does not disappear. Which sets the timeline too: where a binding agent is statutory rather than technological, dissolution waits on legislation.
The base rate for this kind of transformation is terrible, and I have not priced it. The single most expensive lesson available to our industry is the Australian Securities Exchange's attempt to replace CHESS with distributed ledger technology. The replacement was determined in January 2016 with an original target go-live of April 2021, delayed in March 2020, reset in October 2020 to April 2023, and in November 2022 ASX paused the project to revisit the solution design, derecognising two hundred and forty-five to two hundred and fifty-five million Australian dollars of capitalised software pre-tax. What happened next is worse than the shorthand. ASX did not abandon the design that month; it said explicitly that the charge "does not prevent us from using parts of what we have already built". A year later, in November 2023, it completed its reassessment and chose a product-based solution from an external technology provider instead. In August 2024 the corporate regulator commenced Federal Court proceedings alleging misleading statements about the project's progress, with ASIC's chair saying: "We believe this was a collective failure by the ASX Board and senior executives at the time."²⁷ A seven-year round trip ending in somebody else's product is a worse base rate than a clean failure would have been, because it burned the option value as well as the capital. Two things follow, and both cut against me. First, the architecture being right is not sufficient, because CHESS replacement failed on migration, coexistence with legacy systems, and the governance of a market infrastructure that could not be taken offline for a weekend, none of which appear in any five-layer diagram. Second, my Coase argument implies incumbents should be the natural builders of the seam, and here the incumbent with the strongest incentive, a clean mandate and full control of both sides of the seam still failed. Where this paper says a thing will happen because the economics require it, read a delay of five to ten years and a probability meaningfully below one.
The consolidation scenario is at least as plausible as the bifurcation, and it fits the regulatory grain better. I argue the middle empties. The opposite case is stronger than I made it sound. Compliance with tokenisation regimes, credential schema authorship, ontology governance participation and inter-fabric liquidity provision all have high fixed costs and near-zero marginal costs, which is the classic recipe for scale advantage rather than for a thousand small composers. Regulators, meanwhile, prefer a small number of supervisable entities to a diffuse population of them, and every crisis in living memory has ended in more concentration rather than less. The most likely near-term outcome may therefore not be a bimodal distribution but an oligopoly of four or five global fabric operators, each running the seam for its own bloc, with the small composers operating inside their perimeters rather than as independent firms.
So state both as scenarios rather than pretending one is a forecast, because the mechanism is identical in each and only the capture differs. In the bifurcation case, composers multi-home across fabrics, capability manufacturers sell to all of them, and the middle is squeezed out. In the consolidation case, composers exist in large numbers but operate inside a fabric operator's perimeter, and the operator takes a share of every composition through pricing, listing and conformance rather than by prohibiting anyone. Note how uncomfortable the second is: it is not that composers are forbidden, it is that they flourish as taxed tenants. Aggregation arrives as landlord rather than as monopolist, which is the app store outcome, and it is fully compatible with a thriving population of small firms.
Which means my original discriminating test was wrong, and it is worth saying why, because the wrong test is the intuitive one. Asking whether a composer can operate without a licence tells you nothing: a fabric operator can welcome unlicensed composers and still capture the surplus through fees. The observable that actually separates the scenarios is portability and multi-homing. Watch whether a composer can move its credentials, its reputation and its customer relationships from one fabric to another at low cost, and whether meaningful volumes of composers genuinely operate across more than one. If they can and they do, the middle is squeezed and the barbell forms. If switching is technically possible but economically punitive, consolidation has already happened regardless of how open the protocols look. A supporting indicator sits one layer down: watch whether schemas are published under open licences with no conformance gate, which is necessary for bifurcation without being sufficient, since an incumbent consortium may happily open-source the semantics while capturing the rent at execution and liquidity.
One caveat on the test itself, because it has a blind spot worth admitting. Portability separates the scenarios only while more than one fabric is worth porting to. If liquidity concentrates so heavily on a single fabric that leaving is technically trivial and commercially absurd, you get consolidation with perfect portability, which is roughly the history of electronic mail: an open, portable protocol that consolidated around a handful of providers anyway. Which is why the test is stated as observed multi-homing in volume rather than as the mere existence of an exit.
The aggregation risk relocates; it does not vanish. A discovery service answering queries across all catalogues occupies exactly the structural position of an Aggregator: zero marginal cost of serving, demand-side network effects, control of the point where demand meets supply. Building it on open protocols does not prevent one discovery service becoming the one everybody queries. Google was built on open protocols, and the openness of HTTP did not distribute search rents. The honest claim is narrower than the rhetoric: open protocols make the aggregator contestable and switchable rather than absent. Real, worthwhile, and smaller than the movement's language implies.
Permissionless is aspirational precisely where the money is. The open fabric's second principle is permissionless, with governance about conduct rather than gatekeeping.⁴ Canton, where institutional flow actually sits, operates a light-touch approval process run by its Foundation because demand has been high, with stated intent to lift it by governance proposal.⁷ That Foundation's membership includes DTCC and Euroclear as co-chairs, alongside HSBC, Goldman Sachs, BNY, BNP Paribas, Broadridge, Moody's, Tradeweb and the Hong Kong Monetary Authority.⁷ Not hypocrisy: it is what makes the network usable for regulated flow, and it is the no-choice condition working in incumbents' favour. But the accurate description of the present is that the institutional fabric is a governed club running on an open-source codebase, and the open fabric is a permissionless commons whose institutional adoption is still ahead of it. Anyone claiming the open outcome is already won is reading a roadmap in the present tense. Anyone claiming institutions will not move is ignoring nine trillion dollars a month of transaction volume.
The ontology is where the next durable position forms, though not as a monopoly. Argued above, and it is the objection I find hardest to dismiss. Note the correction made there: the evidence says the schema gets given away, so what forms is a consortium or regulated utility whose members author meaning to suit the assets they already hold. That is a harder problem than monopoly pricing, because there is nothing to price and therefore nothing obvious to supervise.
Netting gets worse before anyone fixes it. Composed, per-event liquidity sourcing multiplies the number of independently settling legs. The fabric's answer, atomic primitives plus a federation protocol, is a coordination mechanism and not a liquidity-saving one. BIS said the same in 2020: tokenisation "is likely to result in more trades settling via DvP model 1, as netting is in general more complex in a decentralised environment," and "if each tokenised securities ledger had its own cash token, then the need to hold cash tokens on several ledgers could increase aggregate liquidity requirements".¹⁴ Somebody has to deliberately re-bundle netting as a service, and on the test set out above that bundle will form, because it would be technologically enabled and economically necessary rather than merely economically argued. A falsifiable prediction, refined in the settlement section above: the first genuinely new institution of the fabric era will be an inter-fabric netting and intraday elasticity utility, and it will look uncomfortably like a clearing house with a discount window. We will have dissolved the intermediary and rebuilt one of its functions on better foundations, and we should be mature enough to call that a success rather than a contradiction.
The settlement asset may never arrive, and everything above assumes it does. This is the attack that goes underneath all the others, so it belongs last rather than first. Every atomic settlement claim in this paper rests on there being a settlement asset on the fabric that participants will accept as final. The blueprints say tokenised central bank reserves, and I have cited them approvingly. But no major central bank has committed to issuing reserves onto a third party's platform at scale, wholesale central bank digital currency work remains at pilot and experimental status by the participants' own description, and the Agorá project explicitly describes itself as experimental in nature.¹³ Assume the reserves do not arrive on anybody's fabric for a decade, which is the base case a sceptic should hold. Then every atom settles in commercial bank money, tokenised deposits or a stablecoin, which means every atomic settlement carries the credit risk of its issuer, and the singleness of money the blueprints care about is preserved by contract and supervision rather than by architecture. Three consequences follow, and they are not small. The atomicity benefit shrinks, because delivery versus payment against a claim on a commercial bank is not the same risk transformation as delivery against a central bank liability. The intraday elasticity provider I predict becomes considerably harder to build, since the quality of its facility is the quality of its own balance sheet rather than a central bank line, which is the difference between a clearing house with a discount window and a very well capitalised broker. And my own run argument turns against the settlement asset itself, because a continuously observable claim on a commercial issuer, held by agents with published thresholds, is precisely the instrument this paper has just described as a run technology. The counterargument I would offer is that the pattern is already partly resolved in practice, since tokenised deposits at a single institution settle against that institution's own liability today and are accepted, and that supervisory arrangements for the singleness of money are ordinary regulatory work rather than novel architecture. But this attack is not answered by anything in my argument. It is answered, if at all, by central banks, on their timetable, and it is the reason a business case built on atomic settlement should state which settlement asset it assumes and what the case looks like without it.
The Bespoke Outcomes Economy currently argues from architecture: five layers, domain-invariance, intent engines that understand what is needed and execution infrastructure that composes capabilities to deliver it. That is correct and assertive. What this lens supplies is what an architectural argument structurally cannot supply for itself: an economic mechanism, and an independent theoretical warrant from someone with no stake in the conclusion.
It explains why the shift is forced rather than chosen. Rents sit on whichever step is the bottleneck, and when a bottleneck falls the rent relocates to whatever remains scarce. When composition cost collapses, the scarce thing becomes context, because context cannot be composed cheaply from elsewhere. Which reframes the entire history: standardisation of the product was never a preference. It was a response to the cost of composition. The average-denominator product existed because assembling a hundred capabilities per customer was prohibitively expensive, and its only advantage was avoiding a cost that no longer exists.
But standardisation does not disappear, and saying that it does would be the weaker claim as well as the wrong one. It descends. Bespoke outcomes are only assemblable if the things being assembled are rigorously standardised, so the standards move down a layer, from the finished product into the primitives, the interfaces, the evidence formats and the liability terms. And they get more demanding rather than less, because a product assembled once by a human can tolerate ambiguity that a product assembled a million times by machines cannot. So the correct statement of the shift is not from standardisation to variation. It is that standardisation descends into the substrate while variation expands above it, which is why the credential schema and the ontology matter so much in this argument, and why the firms that win the composable layer will be the ones that were most disciplined about standards rather than least.
The bespoke outcome is not a nicer product. It is what a product becomes when the marginal cost of valid, governed variation falls far enough that serving one client is no dearer than serving all of them.
It converts composability from a design principle into a market structure prediction. Under abundance, market-making beats ownership, so the durable positions are the storefront over capabilities and the semantics that make composition meaningful. That is exactly the division the thesis already draws, where layers one to four are the infrastructure commons and layer five with the HelixTwin is the local moat.⁹ Two arguments built on entirely different premises, one from the economics of Internet bundling and one from the architecture of resource allocation, arrive at the same boundary. I should be plain that both arguments pass through the same author, so this is not independent corroboration in the way a third party's replication would be. What it is, is a consistency check between two bodies of reasoning that were built for different purposes and did not have to agree. That is weaker than convergence and stronger than assertion, and it is worth saying in those terms rather than dressing it up.
It supplies a better answer to the thesis's most serious objection. The strongest counter is Aggregation Theory: platforms with direct consumer relationships and zero marginal serving cost tend to monopolise, so why would contextualisation not be absorbed by whoever aggregates demand? The current answer is generative rather than extractive network effects,¹⁰ structurally sound and purely theoretical. The better answer is a property of the input itself. Financial context is structurally non-scrapable. It is tacit, proprietary, legally restricted and bound to specific bilateral relationships, which means it cannot be acquired remotely by anyone running a crawler. To hold the context that produces a differentiated outcome you have to be present in the jurisdiction, hold the relationship, carry the permissions and operate inside the client's privacy boundary. Aggregation Theory works where supply can be indexed without permission. Where the valuable input is legally fenced and relationship-bound, the aggregator cannot assemble it at zero marginal cost, and the outcome layer stays distributed for a reason that has nothing to do with anyone's preference.
That argument is worth more than the analogy I used to make instead, which pointed the wrong way. Data scale beating data purity in large language models did not decentralise anything: it concentrated capability in whoever could afford the compute and ingest the whole web. Anyone applying that lesson to financial context should predict consolidation, not distribution. The reason finance differs is not that messy data wins. It is that this particular messy data cannot be taken.
And one genuine amendment rather than a restatement. The Coase Collapse argument holds that AI collapses coordination costs, the fabric collapses transaction costs, and hyper-local ontology demands smallness, so the firm shrinks toward the minimum unit that can hold a coherent local ontology.⁹ The direction is right and the shape is wrong. Coase's own two-sided logic produces a bifurcation rather than a collapse: technology makes it easier to scale and easier to create efficient markets, so you get massive market makers at one end, a plethora of small actors at the other, and the middle squeezed.¹ The distribution is bimodal with a hole in the middle, and the hole is where most existing financial institutions sit. The composer taxonomy explains why in operational rather than statistical terms: the squeezed middle is the un-composable middle, holding capabilities it neither manufactures at sufficient scale to be composed by strangers nor composes with sufficient local context to produce a differentiated outcome. Too small to be a capability manufacturer, too generic to be an outcome producer, unwilling to be an allocator because that requires taking positions. The mid-tier universal bank, the mid-tier asset manager, the regional custodian and the sub-scale exchange will not shrink gracefully toward local ontological depth. They will be squeezed from both ends at once, and most are paying a premium to override market signals that are entirely rational.
The Internet made information programmable. Once information was programmable, every industry whose product was information got restructured, and the industries whose product was proof of a claim did not.
Programmable value is a different category of change, and the difference is precise. Information is a description of the world. Value is a claim on it. Making descriptions programmable changes who is able to speak. Making claims programmable changes who is able to act. Those are not the same magnitude, and pretending they are is why so much digital assets commentary reads like a description of a slightly better payments rail.
When information became programmable, we got software that could describe anything. When value becomes programmable, we get software that can own, owe, promise, permit and settle. A programme that can hold a claim is not really a programme any more. It is a participant, and everything it does still lands on somebody who can be sued.
Which is why agent-native matters, and it has nothing to do with efficiency. Programmable value plus an agent holding its own identity, its own scoped delegation credential and its own account⁸ produces the first non-human operational participant in the financial system. Not a tool operated by a person, and not a legal actor either, since the paragraphs below are unambiguous that every act lands on a principal. The novelty is operational rather than jurisprudential: something that is not a person can now hold an account, control representations about itself and initiate acts that bind, without a human in the loop for each one. And it arrives in finance before anywhere else, because finance is where claims live.
Standing is a term of art here, meaning the entitlement to invoke a court's jurisdiction, and using it loosely invites a lawyer to dismiss the whole argument. Three distinct concepts are in play. Legal personality is recognition as a subject of law. Capacity is the ability to hold rights and enter binding obligations. Attribution is whose act, in law, the machine's act is.
And the honest position is that the law is not confused about any of them. The law of agency has handled this for centuries and electronic agent provisions handle it explicitly: software need not have personality of its own to bind a principal, because its acts are attributed to a principal who has capacity. An agent under a delegation credential is operationally autonomous, meaning it is not a manually operated tool, and legally an agent, meaning everything it does lands on somebody with a balance sheet.
So the interesting fact is not a legal vacuum. It is the opposite, and the opposite is worse. If the law were baffled by autonomous software, an institution might hope to argue that a rogue process broke the chain of liability. The law is not baffled. It will look at a machine executing continuous, economically consequential decisions at machine speed, attribute every one of them to the principal, and put the entire exposure on that principal's balance sheet.
The gap is not between economic and legal standing. It is that execution scales at machine speed while supervision and liability do not scale at all. Economic footprint is compounding. The capacity of a governor to know what its agents did, why, and whether it can answer for it, is not. That is not a legal-recognition problem awaiting a statute. It is an unsupervisable agency problem arriving now, and it is the sharpest possible argument for why answerability is the moat that matters.
And the historical parallel is stronger for that, not weaker. Legal personality for the limited company was not achieved technically or discovered economically. It was conferred by statute, deliberately, after decades of argument about whether it should be, and it reorganised capitalism once it existed. The question for the next decade is not whether software will become an economic participant, because it already has. It is whether legislatures will confer anything on it, and what breaks in the interval while they do not.
That is the deepest reason treating this as a technology programme is a category error. A technology programme asks how to do the existing thing faster. What is actually happening is that the set of entities capable of acting on economic claims is expanding for the first time since the invention of the limited liability company, while the set of entities that can be held answerable for those acts has not expanded at all. The institutions arguing about settlement latency have not put it on the agenda.
Backcasting from that structure produces a short list. None of these actions requires a moonshot, and none requires a change in regulation to begin, which is a deliberately narrow claim: the architecture's completion depends on statutory change this paper has named at length, including settlement finality, the legal status of agents and cross-fabric recognition, but nothing on this list waits for any of it.
Most of what follows is no-regret, meaning it pays under every scenario in the self-critique above, including the one where consolidation beats bifurcation and the one where this all takes a decade longer than I think. Two items are contingent bets, and they are marked as such with the trigger to watch, because advice that hides its own scenario dependency is not advice.
Work out what you sell: transmission, verification of statements, or verification of claims. If you sell transmission you were dissolved two decades ago and are living on regulatory protection. If you verify statements, the Internet already repriced you. If you verify claims, you are in the beaker now. Most institutions have never asked the question in these terms and will find the answer clarifying and unpleasant.
Audit your seven costs, not your technology stack. For every activity performed internally, name which of Coase's costs justified internalising it, then ask whether discovery, credentials, policy-as-code, audit anchoring or agent orchestration has already lowered that cost in the market. Where the answer is yes, you are paying a coordination cost for nothing.
Build the layer above the substrate you have already paid for. If your digital assets programme is predominantly a settlement programme, you have finished the part your engineers knew how to finish, and the honest question is not whether that was wasted, because it was not, but whether anything sits on top of it. The under-attacked work is credential schemas, machine-executable policy, catalogue presence and audit anchoring. Less impressive in a demonstration, unattacked by a decade of spending, and the layer where the fee actually lands. That is a claim about where the opportunity is rather than a guarantee of return. And apply the wedge test to whatever you choose, because it is the one that separates a programme that ships from a programme that waits: does this pay for itself if nobody else adopts it, and does it compose if they do? Everything that reached production in this field passed the first half. Almost nothing was designed to pass the second, which is why so many live deployments are islands.
Author a schema before you issue another instrument. Pick one asset class and write the credential schemas for provenance, custody, eligibility and audit, validated with a custodian and a compliance reviewer before widening the asset set.¹¹ That artefact is the executable spine of your prospectus for the next era, and the accountable representations still need a human signature.
Separate your rules from your standards, and make the boundary auditable. Bright-line rules become signed, versioned, executable artefacts. Standards requiring judgment stay human and stay documented as such. The boundary itself is what a supervisor will inspect and a court will examine.
Make your reputation portable before somebody else makes it worthless. Distribution rents rest on reputation being captive. Signed, subject-held, verifiable track records dissolve that, and the first movers will be those currently disadvantaged by captivity. If you are the platform holding the hostages, that revenue line has a date on it.
Design for simultaneity, not instantaneity, and say so out loud. Insist on conditional settlement, resist reflexive immediacy, and understand that immediacy costs you netting, intraday liquidity and information asymmetry. Anyone selling all of it at once has not read the elasticity literature.
Price elasticity into your business case, and compose the funding leg. Pre-positioning is a cash-in-advance constraint, and the answer is not to hope velocity absorbs it. The answer is to make the funding leg part of the atomic transaction, then name who provides it and how they price machine-speed, correlated drawdown. Not the option to refuse: a committed facility has already sold that option, which is what makes it committed. What it prices is being drawn on by many counterparties at once at machine speed, in exactly the conditions where it would least like to be. If your model does not name the intraday elasticity provider, it is not a business case, it is a demonstration. And if you are that provider, understand that you are underwriting machine-speed correlated drawdown, which is a different product from a committed line even though it will be documented like one.
Ask who governs the ontology you are about to depend on, and whether anyone supervises them. The unpriced systemic risk in the architecture, and for a few institutions a strategic opportunity to hold the position.
Decide which composer you are, and resource that rather than everything. Ontology authority, intent surface, outcome producer, risk-bearing capability manufacturer, computational capability manufacturer, dynamic resource allocator, or statutory bridge. Most incumbents are naturally the risk-bearing manufacturer or the allocator, because a licence, a balance sheet and answerability are what make a capability safe for strangers to compose, and allocating capital and risk across time is what they already do. Two failure modes rather than one: attempting all of them at mid-tier scale, which is the un-composable middle described above, and competing for the computational layer, where your regulatory obligations are pure cost and a hyperscaler's are zero.
And run the honest test before repositioning at all. Ask, for the newly scarce function you intend to occupy, whether you will hold a structural barrier there: a chokepoint, a demand-side relationship, a licence, or capital nobody else will commit. If the answer is no, the surplus released by commoditisation will dissipate to your clients as lower prices rather than accruing to you in a new position, and the correct strategy is not repositioning. It is accepting utility economics with a cost base built for them, or exiting the activity while it still has a sale value. That is the least popular sentence in this paper and the one most likely to be true of the most readers.
Extend your type system before your competitors extend theirs. Pick one value type your organisation cannot currently represent, capacity, entitlement, reputation, a data licence, future revenue, and represent it properly with policy attached. Then compose it with something you already hold. Cross-type composition is where new instruments come from, and your organisational chart is currently partitioned by the old type system, which is the real obstacle.
Pick your side of the barbell and say it out loud. Contingent on bifurcation rather than consolidation. The trigger to watch is portability: whether composers can move credentials, reputation and customers between fabrics at low cost and whether meaningful volumes actually do. If switching is possible but punitive, consolidation has already happened, the barbell is the wrong shape, and scale is the only side. Fabric-scale market maker and utility, or differentiated specialist with genuine ontological depth. The middle is not a safe harbour. And if your strategy requires acquiring supply to make the economics work, the market has already told you what it thinks and you are proposing to pay a premium to ignore it.
Stake a claim on a seam, and be clear which part of it is still open. Contingent on seams persisting. The trigger to watch is Project Agorá: if a multi-currency shared platform moves from laboratory volumes to production, the seam is abolished rather than owned, and inter-fabric positioning becomes a bet against the official sector. The plumbing is contested by Agorá, by Swift and by the cross-chain protocols. What none of them owns is insolvency-protected finality across a boundary, because that cannot be engineered across it, only legally recognised on each side. The inter-fabric position requires credibility on both sides rather than novel technology, which is the one place where incumbency is a genuine asset rather than a liability.
Price millisecond hold-up before it prices you. Composition means depending, mid-outcome, on a capability provider you did not negotiate with and cannot replace inside the execution window. Williamson's Fundamental Transformation has not been repealed, it has been compressed. Ask, for every composed outcome your firm intends to sell, what happens when one composed capability fails or reprices while the outcome is in flight, and who is answerable to the client in that second. If the answer is a service level agreement, you have a contracting answer to a systems problem.
Change how the firm absorbs change, because that is a coordination cost. The distinction between treating change as medicine and treating it as food, where the first assumes stable business as usual punctuated by eighteen-month transformation programmes and the second makes continuous transformation the operating state, is usually presented as culture. It is not. It is Coase. The eighteen-month transformation programme is the organisational expression of a high internal coordination cost, and this paper's central asymmetry is that market transaction costs are falling faster than internal coordination costs. A firm that can only absorb change in controlled doses has a coordination cost it cannot lower, which is a structural disadvantage rather than a cultural preference. Change as food is not a slogan about resilience. It is the operating model of a firm that intends to survive on the new side of the boundary.
Move your remaining moat from knowing to being answerable. Verification is being commoditised. Liability, resolvability, mandate and licence are not. Build the business that stands behind outcomes, because that is the part of trust which cannot be computed.
Measure the value your agents control against your capacity to answer for it. This is the one imperative in this list addressing a problem the paper says has already arrived rather than one that is coming. If agents act under delegated authority and every action is attributable to you, then the exposure that matters is the ratio between the economic footprint your agents control and your organisation's actual ability to know what they did, why, and whether it can be defended to a regulator or a court. Nobody is measuring that ratio, including the firms most enthusiastically deploying agents. Instrument it, set a ceiling on delegation at the point where supervisory capacity stops scaling, and treat that ceiling as a risk limit rather than a technology constraint.
The Internet dissolved the bundles held together by distribution, and finance walked out of that solvent intact, because its bundles were held together by proof of claims rather than proof of statements. Proof was expensive, so we built institutions to be the proof, and then mistook those institutions for the industry.
Programmable value dissolves the reconciliation bond. Credentials dissolve the attestation bond. Cheap per-event execution dissolves the aggregation bond. Agents make the reaction go to completion. What remains afterwards is not an absence of institutions but a smaller and much harder set of them: legal finality, the licence, the settlement asset, the ontology, the seam, and somebody's willingness to extend credit before the money arrives. Most of what remains in the current fee stack is a proof substitute waiting for the solvent to reach it, and the qualifier is doing real work rather than softening the line. Fees charged for attestation and reconciliation are proof substitutes and they dissolve. Fees charged for underwriting are not: an insurance premium inside a custody fee, and the capital charge behind a guarantee, are payment for bearing a loss somebody has to bear, and no solvent has ever dissolved a loss. Fees charged for constitution are not either, since a licensed entity's cost of being answerable is the price of the licence and not the price of the proof. The paper's own taxonomy has said this throughout, so the closing line should not quietly contradict it.
And then the part that matters more than the dissolution, because dissolution is only ever the first half of what a solvent does. What the fabric holds, it holds in composable form, which makes it a substrate rather than a successor. Coase's firm had two options, make or buy, and it still does. What changes is that buying stops meaning the purchase of a finished product from one supplier and starts meaning the assembly of modular capabilities at runtime, which is a lower-friction and machine-addressable spot market rather than the frictionless one economists assume. The firm that results is drawn where composition cost meets context depth, and both of those are real numbers rather than rhetorical ones. Over that substrate the value type system stops being fixed at cash, securities, derivatives, collateral and credit, and starts admitting everything else that anyone has ever wanted to own, owe, pledge or promise. Finance has always been a composition engine over a very small type system. The engineering to open that type system exists today. The legal standing, liability and classification decisions that would let it operate at scale do not, and they move at the speed of legislatures, which is the binding constraint for the whole of the period in which these systems are actually built. So the type system is not about to open. It is being opened, slowly, one instrument class and one jurisdiction at a time, by people negotiating with regulators rather than by anyone shipping code, and the composers who matter will be the ones who did the legal work early enough to be ready when a category finally admits them.
Coase said in 1937 that a firm stops growing where the cost of organising one more transaction inside it equals the cost of buying that transaction in the market.²² Market transaction costs are falling faster, because they are made of information. The costs of organising are made of politics and accountability, and politics does not have an API. The gap between those two rates of change is the entire strategic opportunity of the next decade, and precisely the shape of the wreckage.
One caution to carry out of this paper, since it is the discipline the argument itself demands. None of that guarantees anybody a new rent. A falling cost creates a surplus, and a surplus goes to whoever holds a structural barrier, which may be nobody. The most likely outcome for most institutions is not relocation to a better position but competition down to utility economics, and the ones who will do well are those who work out early whether they hold a barrier or merely hold an incumbency.
Finance is not facing a faster version of the last three decades. It is facing its own 1995, arriving thirty years late, with a regulator in the room and a machine holding the account.
[1] Thompson, Ben. XBOX Cuts; Bundling and the Internet Solvent; Transaction, Coordination, and Sunk Costs. Stratechery Update, July 8, 2026. https://stratechery.com/ Contains the Jim Barksdale aphorism, reportedly coined on the Netscape initial public offering road show in 1995; the bundle test and the Spotify case; the gloss attributing "coordination costs" to Coase, together with the market-cost list ending in "coordinating"; and the quoted Microsoft internal email on management layers and platform team growth.
[2] Thompson, Ben. The AI Unbundling. Stratechery, September 12, 2022. https://stratechery.com/2022/the-ai-unbundling/
[3] Networks for Humanity. Networks for Humanity offerings. https://docs.nfh.global/about-nfh-offerings/readme
[4] Networks for Humanity. NFH fabric: Why do we need an open fabric?, Principles, Capabilities. https://docs.nfh.global/nfh-fabric/open-rails
[5] Woodgate, Ian. The Canton Network: A Technical Primer. Digital Asset, April 1, 2025. https://www.canton.network/blog/a-technical-primer
[6] Canton. How Canton Network Delivers Institutional-Grade Privacy. August 14, 2025. https://www.canton.network/blog/how-canton-network-delivers-institutional-grade-privacy
[7] Digital Asset. Myth busters: Canton Network. July 28, 2026. https://blog.digitalasset.com/blog/myth-busters-canton-network
[8] Networks for Humanity. Agents as first-class participants. https://docs.nfh.global/nfh-fabric/agents
[9] Tummala, Rajeev. From Uber to Everything: The Structural Reversal of Globalisation. Finternet Labs, May 2026. https://unf.neurail.io/read/bespoke-outcomes-globalisation
[10] Tummala, Rajeev. The Technology Layer Specification: Agentic Interfaces, Intent Engines, and the HelixTwin. Finternet Labs. https://unf.neurail.io/read/technology-architect
[11] Networks for Humanity. Securitising illiquid assets. https://docs.nfh.global/use-cases/securitise-any-asset
[12] Networks for Humanity. Data marketplace for agents. https://docs.nfh.global/use-cases/agent-data-marketplace
[13] Bank for International Settlements. The next-generation monetary and financial system, BIS Annual Economic Report 2025, Chapter III, June 24, 2025. https://www.bis.org/publ/arpdf/ar2025e3.htm
[14] Bech, Morten Linnemann, Jenny Hancock, Tara Rice and Amber Wadsworth. On the future of securities settlement. BIS Quarterly Review, March 2020. https://www.bis.org/publ/qtrpdf/r_qt2003i.htm
[15] International Swaps and Derivatives Association. ISDA Digital Regulatory Reporting. https://www.isda.org/isda-solutions-infohub/isda-digital-regulatory-reporting/
[16] Auer, Raphael. Embedded supervision: how to build regulation into decentralised finance. BIS Working Papers No 811, September 16, 2019. https://www.bis.org/publ/work811.htm
[17] Lee, Michael, Antoine Martin and Benjamin Müller. What Is Atomic Settlement? Federal Reserve Bank of New York, Liberty Street Economics, November 7, 2022. https://libertystreeteconomics.newyorkfed.org/2022/11/what-is-atomic-settlement/
[18] European Parliamentary Research Service. Capital markets integration and supervision: Settlement finality, 2026. https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/785671/EPRS_BRI(2026)785671_EN.pdf
[19] Financial Markets Law Committee. Settlement Finality. July 29, 2026. https://fmlc.org/publications/settlement-finality/
[20] Carstens, Agustín and Nandan Nilekani. Finternet: the financial system for the future. BIS Working Papers No 1178, April 15, 2024. https://www.bis.org/publ/work1178.htm
[21] Carstens, Agustín. The value of trust. Speech at the King of Spain Prize in Economics award ceremony, Madrid, BIS, March 6, 2023. https://www.bis.org/speeches/sp230306.htm
[22] Coase, R. H. The Nature of the Firm. Economica, Volume 4, Issue 16, November 1937, pages 386 to 405. https://doi.org/10.1111/j.1468-0335.1937.tb00002.x
[23] Franklin Templeton. Franklin Templeton Launches Patent-Pending Intraday Yield Feature on Benji Technology Platform. June 10, 2025. https://www.franklintempleton.com/press-releases/news-room/2025/franklin-templeton-launches-patent-pending-intraday-yield-feature-on-benji-technology-platform And Franklin Templeton, Stellar Development Foundation Mark Five Years of BENJI. April 30, 2026. https://www.franklintempleton.com/press-releases/news-room/2026/franklin-templeton-stellar-development-foundation-mark-five-years-of-benji-the-first-u.s.-registered-tokenized-money-market-fund
[24] Mayer, Roger C., James H. Davis and F. David Schoorman. An Integrative Model of Organizational Trust. Academy of Management Review, Volume 20, Number 3, 1995, pages 709 to 734. https://doi.org/10.5465/amr.1995.9508080335
[25] Holmström, Bengt. Understanding the role of debt in the financial system. BIS Working Papers No 479, January 2015. https://www.bis.org/publ/work479.htm
[26] Williamson, Oliver E. Transaction-Cost Economics: The Governance of Contractual Relations. Journal of Law and Economics, Volume 22, Number 2, October 1979, pages 233 to 261. https://doi.org/10.1086/466942 And Williamson, Oliver E. The Economic Institutions of Capitalism. Free Press, 1985, pages 61 to 62, for the Fundamental Transformation. And Williamson, Oliver E. Comparative Economic Organization: The Analysis of Discrete Structural Alternatives. Administrative Science Quarterly, Volume 36, Number 2, June 1991, pages 269 to 296, for the hybrid mode. https://doi.org/10.2307/2393356 And Tadelis, Steven and Oliver E. Williamson, Transaction Cost Economics, in The Handbook of Organizational Economics, edited by Robert Gibbons and John Roberts, Princeton University Press, 2012, pages 159 to 192. https://faculty.haas.berkeley.edu/stadelis/tce_org_handbook_111410.pdf
[27] Australian Securities Exchange. CHESS Replacement: ASX reassessing solution design, financial derecognition of intangible. Media release, November 17, 2022. https://www.asx.com.au/content/dam/asx/about/media-releases/2022/60-17-november-2022-CHESS-Replacement-ASX-reassessing-financial-derecognition_.pdf And Australian Securities and Investments Commission, ASIC sues ASX for alleged misleading statements, August 14, 2024. https://asic.gov.au/about-asic/news-centre/find-a-media-release/2024-releases/24-177mr-asic-sues-asx-for-alleged-misleading-statements/
[28] Bank for International Settlements. Project Agorá: exploring tokenisation of wholesale cross-border payments. Updated July 30, 2026. https://www.bis.org/about/bisih/topics/fmis/agora.htm
[29] Swift. Swift to add blockchain-based ledger to its infrastructure stack. September 29, 2025. https://www.swift.com/news-events/press-releases/swift-add-blockchain-based-ledger-its-infrastructure-stack-groundbreaking-move-accelerate-and-scale-benefits-digital-finance
[30] Canton Strategic Holdings. Exhibit 99.1, filing with the United States Securities and Exchange Commission, March 31, 2026. https://www.sec.gov/Archives/edgar/data/1861657/000149315226013823/ex99-1.htm
[31] Broadridge Financial Solutions. Broadridge's DLR platform achieves 508 per cent year-over-year growth in January. 2026. https://www.broadridge.com/press-release/2026/broadridges-dlr-platform-achieves-508-percent-year-over-year-growth-in-january
[32] Financial Action Task Force. FATF updates Standards on Recommendation 16 on Payment Transparency. June 18, 2025. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-Recommendation-16-payment-transparency-june-2025.html
[33] Dahlman, Carl J. The Problem of Externality. Journal of Law and Economics, Volume 22, Number 1, April 1979, pages 141 to 162, for the canonical transaction-cost taxonomy. https://doi.org/10.1086/466936 And Coase, R. H. The Nature of the Firm. Economica, Volume 4, Number 16, November 1937, pages 386 to 405. https://doi.org/10.1111/j.1468-0335.1937.tb00002.x
[34] Broadridge Financial Solutions. Charting a Path to a Post-Trade Utility. White paper, 2015, the origin of the seventeen to twenty-four billion dollar trade processing estimate later cited by the Bank for International Settlements. https://www.broadridge.com/_assets/pdf/broadridge-charting-a-path-to-a-post-trade-utility-white-paper.pdf
[35] California Department of Financial Protection and Innovation. Order taking possession of Silicon Valley Bank, March 10, 2023, recording attempted withdrawals of approximately forty-two billion dollars on March 9 and a resulting negative cash balance of about nine hundred and fifty-eight million dollars. https://dfpi.ca.gov/wp-content/uploads/sites/337/2023/03/DFPI-Orders-Silicon-Valley-Bank.pdf And Board of Governors of the Federal Reserve System, Review of the Federal Reserve's Supervision and Regulation of Silicon Valley Bank, April 2023. https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf
[36] European Central Bank. T2S auto-collateralisation, TARGET2-Securities user documentation, describing automatic intraday credit generation against securities collateral where a settlement instruction would otherwise fail, in production since June 2015. https://www.ecb.europa.eu/paym/target/t2s/html/index.en.html
[37] Bank of England. Digital Securities Sandbox: approval of HSBC Orion as a digital securities depository, July 2026, the first such approval granted. https://www.bankofengland.co.uk/financial-stability/digital-securities-sandbox
[38] European Commission. Proposal for a Regulation of the European Parliament and of the Council on settlement finality and repealing Directive 98/26/EC and amending Directive 2002/47/EC on financial collateral arrangements, COM(2025) 941 final, December 4, 2025. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0941
[39] Bank for International Settlements. Settlement risk in foreign exchange transactions (the Allsopp Report), Committee on Payment and Settlement Systems, March 1996, https://www.bis.org/cpmi/publ/d17.pdf and Reducing foreign exchange settlement risk: a progress report, July 1998, recording the FXNET, ECHO and Multinet netting arrangements and the merger of ECHO and Multinet into CLS Services. https://www.bis.org/cpmi/publ/d26.pdf
References 3, 4, 8, 11 and 12 are documentation of the NFH Fabric. References 9 and 10 are papers by this author. The author has a professional association with the work described in references 3, 4, 8, 11 and 12. That is seven of thirty-nine sources drawn from a single body of work, meaning under a fifth, and readers should discount accordingly: where those sources are cited for design intent, meaning what an architecture is trying to achieve, they are authoritative, because a specification is the best evidence of its own intentions. Where they might be read as evidence that something works at scale in production, they are not, and I have tried to mark the difference in the text rather than leave it to be inferred.
One source has been removed since the first version of this paper, and the reason is worth stating rather than burying, because it is the standard I would want applied to anyone else. An earlier draft cited a securities services knowledge hub for the batch-to-stream framing, the fee-pool model and several supporting formulations. That source sits behind an access gate, which means no reader could check it. A citation only its author can verify is not a citation, it is an assertion wearing a footnote. Every argument that rested on it is now made in my own voice, as my own analysis, and the fee-pool model shows its arithmetic and its hidden turnover assumption instead of borrowing someone's authority for the output. Where empirical support was genuinely required, Franklin Templeton, Broadridge and the BIS carry it.
Claims about live deployments rest on the operators' own disclosures, including a filing with the Securities and Exchange Commission for network volumes, and claims about settlement law, supervision and market structure rest on the BIS, the Federal Reserve Bank of New York, the Financial Markets Law Committee, the European Parliamentary Research Service, ISDA, ASIC and the ASX.

