# The Verifiable Receipt > Finance survived the Internet because it sold proof of claims, not transmission. Programmable value dissolves the operational apparatus around that proof and concentrates what remains. **Published by:** [Reality Permits](https://paragraph.com/@reality-permits/) **Published on:** 2026-08-18 **Categories:** ai, financial services, tokenisation, programmable finance, institutional design, market structure, trust **URL:** https://paragraph.com/@reality-permits/the-verifiable-receipt ## Content The Verifiable Receipt Finance survived the Internet because it sold proof of claims, not transmission. Programmable value dissolves the operational apparatus around that proof and concentrates what remains. This is what happens to markets, liquidity, issuance and distribution, and what regulation, trust and settlement become. An Optimist With Receipts This is long, and deliberately so, because the argument only becomes useful where it gets specific. Here is the lay of the land, so you can read it in the order that serves you and stop where it stops paying. The thesis in one paragraph. Finance did not survive the Internet by luck or by regulation alone. The Internet dissolved bundles held together by distribution, and finance's bundles were held together by something else: the cost of proving a claim to a stranger. That cost is now collapsing, and cost collapses move Coase's boundary rather than merely lowering anybody's expenses. What follows works out where the boundary lands. The diagnosis comes first, in the five sections up to "Which bundles are real". What a solvent actually does, why proof of statements and proof of claims are different problems, the two solvents and the agitator that makes them bite, plus a third bond that dissolves later in the securities services section, where the solvent and the agitator act together for the first time, and the uncomfortable finding that a decade of institutional spending stopped at the most tractable of the seven costs rather than reaching the harder design problem. If you read only one thing, read the bundle test: it tells you which of your own bundles are held by a technical constraint, which by a legal one, and which by both, and only the technical part dissolves by technology alone. The analytical core runs from "From batch to stream" through "Two fabrics, one equation, and the seam". Securities services is where the thesis is most falsifiable, so it gets tested there first, and the test returns a conditional answer rather than the disintermediation headline: the fee basis moves, and whether anybody captures the displaced revenue depends on holding something a competitor cannot assemble. Then the composable firm, which is the part I would defend hardest and the part most likely to be wrong: it argues that dissolved transaction costs precipitate as protocol, that seven functions are durable because they require inputs composition cannot assemble, which makes each a candidate position rather than a guaranteed one, and that composition has costs of its own large enough to run the whole argument backwards. Then the seam between fabrics, where I think the next correspondent banking business is hiding, along with the eight things anyone building it would have to answer. The middle stretch applies it function by function, to markets, liquidity, issuance, distribution, regulation and trust. Practitioners in one of those functions may reasonably start there and read backwards. Two warnings live in that stretch: benevolence cannot be verified by any protocol, and ontology governance may become systemically important infrastructure that industry governs while falling between existing prudential mandates. The settlement section is where the enthusiasm dies, and it is the one I would want read by anyone building a business case. Atomicity is not merely a speed feature: at a seam, continuously evaluated settleability turns funding and deliverability into the binding constraint. Somebody has to provide the elasticity, machine-speed drawdown can become correlated drawdown, and pre-funding is refinanced rather than defeated. Then ten attacks on my own argument, in the order I would attack them. The first is the one I would lead with: privacy and transaction-level financial crime compliance may not both be satisfiable, and I have been selling them as complements. The ninth goes underneath all the others: the settlement asset this paper assumes may never arrive. The tenth is the only demand-side attack, and it uses my own evidence against me, since thirty years of revealed preference in asset management ran toward standardisation. Also there: the two scenarios I cannot choose between and the observable test that would settle them. Then what this means for the bespoke outcomes thesis, why programmable value is a different category from programmable information, and a bridge back to what to do about it on Monday. The claim-status discipline runs throughout: live, bounded, pilot and design intent are marked, and the note on sources at the end says plainly where I am citing my own work. The diagnosis Start with the aphorism everyone in this industry can quote and almost nobody has examined. In a 2014 interview, Jim Barksdale recalled saying it at the end of Netscape's 1995 initial public offering road show in London: there are only two ways to make money in business, bundling and unbundling.⁴¹ For three decades it has been treated as a given that money can be made in either direction, an eternal oscillation, which is precisely why it is quoted so comfortably at conferences. Ben Thompson's contribution is to test it and find it wanting, and the test is what this paper borrows. Bundles do not re-form just because someone can argue the economics. Bundles work best when you do not have a choice, and when they have everything, and both conditions are produced by technology rather than by strategy. Cable worked because of antennas and satellites. Spotify is, on his reading, the only genuinely new bundle the Internet created, because streaming plus cellular made it easier than piracy and cheap enough that a la carte stopped being a real choice. Economics do not make bundles work; technological change does, particularly when it supplies not only a carrot but a stick.¹ That gives us a diagnostic rather than a proverb, and it comes with a second piece of apparatus. In The AI Unbundling, the idea propagation value chain, creation, substantiation, duplication, distribution, consumption, shows that every communications revolution has removed whichever step was the bottleneck, with the profit pool sitting on that bottleneck right up to the moment it disappears.² Underneath both sits the actual foundation, which is not Barksdale and not Thompson but Ronald Coase. The Nature of the Firm, 1937: firms exist because using the market has costs, and it is often cheaper to internalise those costs inside a command-and-control structure. Coase's own examples are the cost of discovering what the relevant prices are and the cost of negotiating and concluding a separate contract for every exchange. Command-and-control has costs of its own, which he described as the costs of organising and as diminishing returns to management, and the natural size of a firm is the point where internal coordination cost roughly equals the market transaction cost it replaces.²² One piece of vocabulary needs flagging, since this paper leans on it. Coordination costs is not Coase's phrase. It is a later gloss, and Thompson uses it when summarising him.¹ I will use it too, because it is the standard shorthand, but it carries a trap worth naming: Thompson's own list of market costs ends with coordinating, so the same word does duty for a cost of using the market and a cost of running a firm. Those are opposite quantities that move in opposite directions. Keep them apart, because the entire argument of this paper turns on them moving at different speeds, and most writing in this field runs them together. A second piece of vocabulary needs the same treatment, and for a less comfortable reason. Fabric is not a neutral term. NFH uses it as the name of its own architecture, and I use it throughout this paper as a generic category, meaning any network that combines programmable value, verifiable credentials, discoverable services and policy expressed as code. Where I mean the specific product I name it. Where the word appears alone it means the category, and the argument is intended to hold for Canton, for Swift's shared ledger work, or for something nobody has built yet. Readers should discount the term to the extent they think I have failed at that separation, and the disclosure at the end of this paper is relevant to how much discount to apply. So the chain of ideas runs Coase, then Barksdale as folk wisdom, then Thompson deconstructing the folk wisdom back onto Coase. Put the pieces together and you have the only tokenisation thesis worth defending. Technology does not reorganise industries by making things cheaper. It reorganises them by moving Coase's boundary, and it moves that boundary by removing a bottleneck in a value chain. The popular version of this argument asserts a law where there is only a possibility. Rent does not automatically relocate when a bottleneck falls. Four things have to hold, and naming them is what separates analysis from prophecy. The bottleneck function must be genuinely commoditised, meaning supply becomes abundant and substitutable rather than merely cheaper. Some adjacent function must become newly scarce, because rent requires scarcity somewhere and removing a bottleneck does not create one. Whoever sits on that scarcity must be able to appropriate the surplus, which requires a chokepoint or a demand-side relationship. And the change must alter the relative cost of transacting in the market versus coordinating internally, because a technology that lowers both at the same rate produces a cheaper industry with its boundary exactly where it was. The fourth condition is the one that connects the value-chain story to Coase, and the third is the one the industry never states. If no party holds an appropriable bottleneck, switching cost, protected right, scarce complementary asset or durable demand-side advantage, the paper cannot infer durable rent relocation. Over time, competition is likely to pass much of the surplus to buyers as lower prices. Transitional quasi-rents can still accrue to early actors or incumbents, and returns can also accrue to holders of specialised complementary assets, which is a separate mechanism from the hold-up problem and belongs to the literature on profiting from innovation. Either way they are a different claim from durable capture and may be competed away.⁴² ⁵³ Any strategy that assumes rent must reappear somewhere convenient has skipped the only step that matters. Now ask the uncomfortable question. Across the information industries where distribution was the bottleneck, the Internet was decisive: newspapers lost the classified and display advertising that funded them, recorded music was restructured around streaming, and physical video rental disappeared. Financial services, which is as information-intensive as any industry in existence, came out the other side with its institutional architecture recognisably in place. Both halves of that contrast need stating carefully, because the sweeping version is where this argument would deserve to be dismissed. What happened to finance was not nothing, and it was not confined to pricing. Retail equity commissions at major United States brokers fell to zero, though the Securities and Exchange Commission's own account of the episode is careful that zero commission did not mean zero cost, since payment for order flow and other execution revenue survived the headline price going away.⁴⁴ Fund expenses declined over decades as indexed products grew and competition intensified, which is a fee-compression finding rather than a single-cause attribution to index funds.⁴⁵ Electronic trading reconfigured intermediation, price discovery and liquidity provision rather than removing intermediation. In fixed income the BIS Markets Committee describes the change in those terms, reporting new participants and new forms of liquidity provision alongside surviving dealer functions, and it cautions against casual cross-asset generalisation because risk factors and participant composition differ too much between markets.⁴⁶ Equities are the strongest counterexample and they do not overturn the point: BIS work on electronic finance records a shift toward direct matching in the most liquid markets and still finds that "despite the developments... that might have been expected to marginalise much of their role, dealer intermediation remains".⁵¹ Payments were reshaped by firms that did not exist in 1995, and the Financial Stability Board's assessment is that FinTech and BigTech entrants changed channels and in some markets reached significant scale, while relationships with incumbents remained largely complementary and core regulated roles stayed with regulated institutions.⁴⁷ So the defensible claim is narrower than the slogan and still uncomfortable. Finance experienced institutional persistence alongside material reshaping of distribution, execution and selected payment functions. What did not happen is the thing that happened to publishing: the intermediation chain was not dissolved. The same institutional roles remain, and the same list of parties must still be present before a transaction is considered done. Custodians still custody. Registrars still register. Clearing houses still clear. Correspondents still correspond. Concede the qualification that a market structure specialist will raise immediately, because it is real and it sharpens the point. The chain did get shorter in places. Central counterparty clearing replaced webs of bilateral exposure. Direct market access removed layers of broker intermediation. Correspondent relationships consolidated sharply, and Swift's own gpi work compressed the number of hops a cross-border payment passes through. So the accurate claim is not that no intermediary was ever removed. It is that many surviving roles still contain an act of vouching for a fact, alongside constitution and underwriting functions that proof does not replace. Consolidation reduced the number of parties performing each function without retiring a single function, which is exactly what you would expect if the binding constraint included the cost of proof rather than the number of firms. That pattern is itself the clue. An industry whose fees compress while its structure holds is an industry where technology has attacked the distribution of its product without touching the reason for its existence. That is not luck, and it is not regulation alone. What a solvent actually does The metaphor is doing more analytical work than most people using it realise, so start with the chemistry. A solvent destroys nothing. It dissolves the binding agent and leaves the constituents intact, free to separate and go wherever the economics send them. Newspapers were not destroyed as journalism. What dissolved was the bond between editorial and advertising, and once that bond broke, the constituents went to different places: advertising to wherever the users were, journalism unbundled and repriced. The institution that had held them together turned out to be the bond rather than either of the things it bound. So the diagnostic question for any industry is never whether it will be destroyed. It is: what is the binding agent, and what dissolves it? For newspapers, the binding agent was the printing press plus physical delivery, producing a geographic monopoly on duplication and distribution. The Internet dissolved it by making both free. For television, spectrum scarcity and then cable and satellite. Broadband dissolved it. For record labels, manufacturing and radio access. In each case the industry mistook the bond for the business, defended the bond, and lost. What is the binding agent of finance? The impossibility of proving a state of affairs to a stranger at a distance, cheaply, without a trusted third party. Everything else follows from that single impossibility. You cannot prove you own the bond. You cannot prove you are permitted to hold it. You cannot prove the money moved, that the transfer is irreversible, that you are who you claim to be, that your track record is real, that the collateral exists and is unencumbered. Because none of this could be proven cheaply at a distance, we built institutions whose actual function is to be the proof: custodians, registrars, clearing houses, correspondent banks, auditors, ratings agencies, exchanges, trustees, transfer agents, fund administrators. Financial institutions are proof substitutes. We built cathedrals because we could not send a verifiable receipt. The adjective is load-bearing. We could always send a receipt. What we could not do was send one that a stranger would accept without an institution standing behind it. So the title of this paper needs an exact meaning, since the whole argument depends on it. A verifiable receipt is a record of a state of affairs that a stranger can check independently, without trusting the path it travelled by and without going back to the institution that maintained it. Note what is not in that sentence: you still trust the party who issued it. What you no longer need is the intermediary chain that used to carry, restate and vouch for the assertion in transit. Four properties make it work: it is bound to an identity that can be checked, it carries the authority under which it was made, its integrity is provable against tampering, and its revocation status is discoverable. What it never contains is a guarantee about the value of the thing it describes, or an undertaking by anyone to make you whole if the description proves wrong. And one further boundary, because it is the one most often elided: a receipt establishes that an authoritative party made this assertion and has not withdrawn it. It does not establish that the assertion is true. Checking is not reliance. That distinction is not mine, and it matters that the standards bodies drew it first: the W3C's data model states plainly that "verifiability of a credential does not imply the truth of claims encoded therein", and separates verification of a credential from validation, the process by which a relying party applies its own business rules before relying on what it has just checked.⁵⁵ A receipt becomes economically portable only where a relying party has permission to accept it without repeating the original diligence, can judge its scope and freshness, and has defined recourse if a validly signed assertion proves false or stale. Those are legal and institutional conditions around the proof, not properties cryptography supplies by itself. But "proof substitute" hides three different jobs, and everything that follows depends on keeping them apart. An institution can attest that something is so, which is evidentiary. It can constitute the thing, so that the act of recording is what makes the transfer legally effective rather than merely recorded. Or it can underwrite, standing behind the outcome, so that when the proof turns out to be wrong there is someone with a licence, a balance sheet and a legal identity to answer for it. An auditor mostly attests. A registrar mostly constitutes. A rating agency attests, with a thin layer of reputational underwriting. A custodian does all three at once, which is why custody is the hardest of these businesses to reason about and the one most often declared dead prematurely. The three jobs have entirely different exposure to the solvent, and conflating them is the largest single source of confusion in this debate. Attestation is a verification problem, so cryptography attacks it directly. Constitution is a legal fact, so cryptography attacks it only where a legislature has said that the record is the title. Underwriting is not a verification problem at all, and no amount of cryptography touches it. Which means what a ledger actually proves depends entirely on what kind of claim is on it. Kind of claim What the ledger proves What still depends on institutions and law Native digital asset The protocol state can be the authoritative representation, so proof and constitution can coincide within the governing system The legal effect of that state, participant rights and liabilities, and the law governing the system Tokenised claim on an off-chain asset The state of a representation: who holds the token, under what conditions, with what history Whether the token is the title, whether the underlying asset exists, whether it is already pledged elsewhere, and who answers if it is not Credential about an external fact That a named party attested to a fact, at a time, under a schema, and has not revoked it Whether the fact is true, and whether the attestor is worth anything if it is not Read the middle row carefully, because that is where institutional finance actually lives. A tokenised representation of an off-chain bond is not, by that fact alone, the bond itself. Its legal character is conferred somewhere other than the ledger. Tokenisation makes the representation cheap to verify, exact and instantly transferable, and does nothing whatsoever about the three hard questions underneath it. That is not an argument against tokenisation or against an authoritative native digital security. It is an argument about which part of the cathedral is load-bearing, and it returns twice below: once where regulation hardens rather than dissolves, and once at the end, where the residue that cannot be computed turns out to be underwriting rather than proof. Statements about the world, claims on the world Statements about the world versus claims on the world: why the Internet dissolved newspapers and left finance intact The obvious objection to that framing is that newspapers also sold verification. A masthead is a verification asset. Reuters, the Wall Street Journal and the Financial Times never sold raw information, which was abundant even in 1950. They sold information you could act on without checking. If the Internet dissolved industries that sold verification, why did it dissolve theirs and not ours? Because they verified different things, and the difference determines which technology can dissolve them. Newspapers verified statements about the world. Banks verify claims on the world. Three consequences follow, and they are the reason finance's solvent arrived three decades late. The failure modes are not comparable. A false statement costs reputation and can be corrected by a subsequent statement. A false claim costs someone their property and cannot be corrected by assertion at all, only by enforcement. Therefore the verification mechanisms are not comparable. Statements can be verified socially, through reputation at scale, competing accounts, community correction and aggregate signal, which is why Wikipedia works and why a thousand citizen accounts of an event converge on something usable. Claims must be verified authoritatively, because there can be only one owner of a given asset at a given moment. You cannot socially crowdsource title. The adverb is deliberate, and the obvious objection proves the point rather than defeating it. Bitcoin verifies title without a trusted third party, and it is the counterexample anyone will reach for. But look at what it actually does. Nakamoto consensus is an expensive, deliberately engineered mechanism for producing exactly one authoritative record of who owns what. It does not aggregate opinions and settle on a reputational average, which is how a statement gets verified. It manufactures singularity by burning resources until disagreement stops paying. Bitcoin is therefore not an exception to the rule that claims require authority. It is the most literal demonstration of what authority costs when you refuse to inherit it from an institution. Therefore the solvents are not the same solvent. Reputation at scale is a distribution phenomenon, and the Internet is a distribution technology, so the Internet dissolved reputational verification comprehensively. Authoritative verification requires the ability to produce a single, exclusive, non-repudiable record that a stranger can check without trusting the publisher. That needed cryptography, not connectivity. Which gives the clean statement of where we are: The Internet was a solvent for the verification of statements. Programmable value is a solvent for the verification of claims. Newspapers sold the first. Banks sell the second. That is why one dissolved in 1995 and the other is dissolving now. And there is a warning inside the newspaper case that our industry should read carefully. What actually happened to publishing was that verification was unbundled from distribution, and the verification business turned out to be far smaller than the bundle had been. The FT and the Journal still monetise verification successfully. What died was the local paper whose verification premium was really a distribution monopoly wearing a masthead. When the verification bond in finance's bundle dissolves, every institution finds out how much of its fee was attestation and how much was constitution, underwriting or position. Most will be shocked by the ratio. This is not a fringe framing. When Agustín Carstens and Nandan Nilekani set out the Finternet vision, they built the argument on a unified ledger whose properties include immutability and verifiability, alongside finality as a core characteristic and programmability through smart contracts, with security and privacy named among their eight design principles.²⁰ The grouping of those four as a single axis set is mine rather than theirs, and their formal list of principles is a different cut, but the substance is in their text: verification is treated as a property of the system rather than an operational detail. The industry has mostly read that list and gone straight to programmability. Two solvents and an agitator Three agents are acting here, and they do three different jobs. Collapse them and the argument becomes enthusiasm. Programmable value is the first solvent, and it dissolves the reconciliation bond. When state is shared or provably synchronised, you no longer need an institution stationed at every ledger boundary to agree that two records match. The BIS description is exact and unromantic: tokenisation "enables the integration of messaging, reconciliation and asset transfer into a single, seamless operation".¹³ The prize is not speed. It is the elimination of a category of work that a 2015 industry estimate put at between seventeen and twenty-four billion dollars a year in trade processing alone, a figure BIS cited and one worth reading with its provenance in view, since it originates with a post-trade vendor and is now a decade old.¹⁴,³⁴ Verifiable credentials are the second solvent, and they can dissolve the attestation bond. The issuer does not disappear. Somebody authoritative still has to assert the fact, and a credential asserting your capital adequacy is worth exactly what the asserting party is worth. What can dissolve is the repeated reconstruction and captive distribution of that assertion: you hold portable, cryptographically signed, selectively disclosable proof yourself, and the institution that made the assertion no longer controls who can check it or charges for the checking, provided the relying party's policy and legal obligations permit reliance on the receipt. This is the one the industry has almost entirely ignored, and it reaches further, because attestation is the deeper business. Custody is attestation about ownership. Audit is attestation about books. Ratings are attestation about creditworthiness. Know-your-customer is attestation about identity. Every one of those firms exists because you could not carry your own proof. Agents are not a solvent. They are the agitation. This distinction corrects a great deal of loose thinking about AI in finance. Agents dissolve no bond by themselves. What they do is drive the transaction rate to a level at which human-mediated verification becomes physically impossible, taking the reaction to completion instead of leaving it at equilibrium. The scale contemplated is a billion-plus businesses, more than a trillion agents, and micro-transaction volumes around a million times today's, at which point, in the fabric's own phrase, "the toll-taking intermediary, viable when transactions were few and large, becomes a tollbooth on every drop of a flood".⁴ Read those numbers as a boundary condition rather than a forecast, because they are not mine and I am not defending them as a prediction. They describe the order of magnitude at which the argument stops being economic and becomes physical. Below it, human-mediated verification is merely expensive and the industry absorbs the cost. Above it, the process cannot run at all. Whether and when we arrive is an empirical question, and the useful discipline is to ask which of your processes breaks first if volumes rise a thousandfold rather than a millionfold. Without agents, provable state and portable credentials produce a tidier version of the same slow world, and the industry absorbs them as cost reduction, which is precisely what it has been doing for a decade. With agents, the old process is not expensive. It is impossible. Impossibility changes an industry in a way that expense never quite manages, because a cost differential invites deferral and an impossibility does not. Since the agitator is a wager rather than an observation, state what happens to the rest of this paper if the wager loses, because the answer is not symmetric. If agent volumes never arrive, the dissolution claims degrade into a slower and more optional version of themselves: costs fall, margins compress, nothing is forced, and institutions defer for another decade exactly as they have. The physical and legal constraints in the hardening claims remain, but their economic urgency and the timetable on which new institutions form diminish with the volume that makes them binding. Legal finality still depends on a legal route rather than on a protocol, and the settlement section works out which routes exist. The seam between two fabrics still has to be borne by somebody. Underwriting still needs capital. Ontology governance may still become a concentration point. Answerability still cannot be composed. If the agitator disappoints, this paper's warnings retain their basis and its promises go quiet, which is an uncomfortable asymmetry to publish and the honest way to read everything that follows. We industrialised the tractable part Coase's transaction costs, what actually attacks each one, and why the industry stopped at the tractable one The transaction-cost tradition that begins with Coase names the costs that make markets expensive and therefore make firms worth having. Coase himself pointed at discovering the relevant prices and at negotiating a separate contract for every exchange; the fuller taxonomy, search and information, bargaining and decision, policing and enforcement, is Dahlman's, and the working list most people use, searching, negotiating, contracting, monitoring, enforcing, coordinating, is the tradition's rather than any one author's.³³,¹ Finance quietly adds a seventh that none of them contemplated, because Coase was writing about the firm in 1937 and not about the legal transfer of title: settling. Set the seven against what the emerging infrastructure actually does. Coase cost What pays for it in finance today What collapses it Searching Sales coverage, relationship managers, the broker's rolodex, listing fees, data vendors Registry, catalogue and discovery, where an offering "published once is findable across every aligned network"⁴ Negotiating Trading desks, syndicate, bilateral documentation, RFQ processes Self-executing contracts where "the contract between buyer and seller is the wire format"⁴ Contracting Legal drafting, documentation teams, annual contracts, procurement cycles Policy-as-code for repeatable, machine-testable conditions: signed Rego and Open Policy Agent bundles, network manifests, credential and licence schemas⁴ Monitoring Middle office, reconciliation estates, surveillance, periodic reporting Cryptographically anchored observability, and bi-temporal state making audit continuous rather than reconstructed⁴,¹⁰ Enforcing Legal recourse, courts, collateral management, dispute processes Escrow, refund and arbitration as protocol concerns, with underwriter-backed gradient guarantees³ Coordinating, in both senses: sequencing counterparties in the market, and running the hierarchy internally Layers of management, middle managers translating strategy into execution¹ Intent engines and agent orchestration, where a hundred-person firm coordinates as effectively as a ten-thousand-person one⁹ Settling Custody, clearing, central securities depositories, nostro and vostro, two to five days cross-border Bounded design: atomic lock, commit and unlock through a federation protocol, subject to shared semantics, timeout and recovery rules, selective disclosure, compliance visibility, legal recognition and allocated liability; cross-fabric delivery-versus-payment remains implementation work⁴,⁵,²⁸ Read that table as an indictment, because that is what it is. And note what the left-hand column is: these are market transaction costs, the costs of using the market. Internal coordination cost, the price of running the hierarchy that replaces the market, sits on the other side of Coase's boundary and is not on this list. It appears in the row on coordinating only because finance's own internal apparatus is itself a cost, and agent orchestration attacks it. The institutional tokenisation programmes this paper can observe have overwhelmingly attacked item seven. Settlement. State the sample honestly, because the universal version of that sentence is not available to me: what follows is drawn from publicly disclosed programmes at large institutions, market infrastructures and consortia, which is a selection biased toward whatever was announceable. Programmes aimed at collateral mobility, intraday liquidity, fund administration, corporate actions and reconciliation exist, and some use a ledger without treating settlement as the primary objective. The pattern is a strong tendency in the visible record rather than a census. Inside that record the shape is consistent: delivery-versus-payment, atomic finality, T+0, the shared ledger. Settlement is the item that looks most like finance, the item our engineers understood, and the item our conference agendas were built around. Items one through five are attacked by discovery, credentials, policy-as-code and audit anchoring. They are not attacked by ledgers at all. State the indictment precisely, because a technical reader will otherwise dismiss it. The six other costs are not independent of the ledger: credential schemas, executable policy and continuous audit anchoring are built on the same substrate, and several of them are unbuildable without it. So the charge is not that the industry spent on the wrong cost. Settlement infrastructure was the necessary first step and it now largely exists, which is a real achievement. The charge is that the work stopped there. We built the substrate and never built the layer that earns on top of it, which is a sequencing failure rather than a misallocation, and it is a more damning one, because a misallocation can be defended as a judgment call while stopping halfway cannot. The larger claim is not available to me. I cannot tell you that items one through five are the majority of finance's cost base, because no public comparative decomposition of financial services costs across Coase's categories exists, and that absence is itself remarkable in an industry that measures everything. What I can defend is narrower and still uncomfortable: items one through five are the costs least attacked by a decade of institutional spending, and on the testimony of the people building the alternative they are the harder design problem. That testimony comes from builders rather than critics, which is why I lean on it. The fabric's own guidance on securitising illiquid assets tells implementers that "most of the design effort goes into the credential schemas, not the token plumbing".¹¹ Its guidance on building a data marketplace for agents says the hardest design decision is the licence-and-purpose credential model, and to solve that first.¹² Two separate pieces of guidance from the same corpus, then, both saying that basic ledger plumbing is the more tractable engineering problem rather than the core design bottleneck. Same authorship, so treat it as one considered position rather than two independent findings. So the honest summary of the industry's decade is uncomfortable. We industrialised the tractable part and stopped. We solved the one transaction cost Coase did not think worth listing, and left search, negotiation, contracting, monitoring and enforcement in PDFs, in email, in the judgment of experienced humans and in the reconciliation estate. We built the substrate and never built the layer that earns on top of it. Then we expressed surprise that beautiful settlement pilots did not become businesses. The word tractable is doing specific work here, and the sloppy version of this claim is false. Settlement is not cheap in any absolute sense: it carries the legal, liquidity and interoperability difficulties this paper spends a whole section on, and cross-fabric settlement is the hardest unsolved problem in the field. What is defensible is comparative and narrower. Relative to designing the credential schemas, licence models and policy artefacts around it, moving the token was the part our engineers knew how to finish, which is why it is what got finished. There is a second reason, and it is less flattering to my own indictment. The deployments that have reached production so far share a pattern: a concentrated sponsor, controlled participant group or local business case can justify the first step before ecosystem completeness. Broadridge's repo platform, intraday repo at a single bank, a tokenised money market fund and auto-collateralisation inside one central securities depository all have that shape. The bounded hypothesis I would offer is that adoption in this field has proceeded through unilateral-benefit wedges before it has produced broad network value, because a wedge can be funded by one budget holder against one business case while network value requires several parties to move together. Hold it as a hypothesis rather than a finding, because the same observed pattern is consistent with at least four other explanations: regulatory approval arriving first for contained perimeters, technical feasibility being higher inside one participant's estate, executive sponsorship following whatever can be demonstrated in one budget cycle, and balance-sheet constraints favouring internal deployments. The comparison that would distinguish them is observable and nobody has published it: matched programmes with similar technical difficulty and similar regulatory perimeter, differing only in how many parties must move together, compared on time-to-production. That reframes the indictment rather than softening it. Settlement got built because settlement had wedge economics: internal, controllable, demonstrable in one quarter. The other six costs are mostly shared-benefit problems, since a credential schema is worth little until several institutions accept it and a policy artefact is worth little until a supervisor recognises it. So the tractable part was also the individually profitable part, and the layer that earns on top is the layer that requires someone to solve a coordination problem before anybody earns anything. Which is a harder charge to answer, and a more useful one, because it tells you what to build: the wedge that works locally and composes later. Which bundles are real, which are theatre, and which are both Every no-choice bundle in finance is held together by a technical constraint, a legal one, or both, and only the technical part dissolves by technology alone. That is the working instrument this paper has been building toward, and it now gets applied to us. Read "legal" widely, since it covers tax treatment, fiduciary duty, licensing, capital rules and contractual allocation rather than statute alone, and a legal bond dissolves at the speed of policy rather than the speed of deployment. Most bundles worth arguing about are held by both, which is why the table below prices each one by the mechanism that actually binds it rather than sorting them into two bins. A bundle survives when users have no practical alternative and when it supplies the full required outcome, and on Thompson's reading both conditions are produced by technology rather than by strategy.¹ In finance the instrument needs one extension, and the extension is mine: either condition can equally be produced by legally enforced rules, or by rules and architecture together, rather than by anybody's preference. Cable satisfied both because of antennas and satellites. Newspapers satisfied both because printing presses centralised duplication. Amazon Prime does not qualify, being a logistics bundle rooted in the physical world. Apply the test to our own bundles and the picture stops being comfortable. Bundle we sell What actually holds it together Verdict under the test The universal bank relationship Balance sheet, licence, privileged access to payment rails Regulatory, not technological. Dissolves at the speed of policy Custody, servicing, reporting and FX The impossibility of reconciling incompatible ledgers Mixed, and the split matters. Shared state removes the reconciliation and duplicate-record component; asset control, servicing, tax, legal title handling, indemnity and accountable exception management are held by law and liability Listing, price discovery and clearing Netting economics and legal finality Mixed. Netting is real value; its bundling with a venue is not The fund wrapper: NAV, sleeve, dealing calendar The impracticality of holding thousands of positions individually Mixed. Programmability makes the operational manufacturing and cadence configurable; the fiscal, fiduciary and pooling wrapper is held by law and survives until those mechanisms change Index, data and distribution Trusted computation, plus brand and licensing Mixed. The trusted-computation component erodes as computation becomes independently verifiable; the index-licensing and brand component is contractual and demand-side, and survives on whatever appropriable position its holder has Settlement finality Insolvency law, jurisdiction, enforceable title Legal. Ordinary legal effect can arise under existing property, contract and account rules; insolvency protection and third-party priority depend on the applicable regime, and no technology supplies either. This is finance's Amazon Prime: not held by technology, so no technology dissolves it There is a second-order point hiding in the rule that bundles work best when you have no choice. In our industry, licensing is that condition, enforced by statute. Some regulatory mechanisms are bundle-preservation technologies, and which ones matters, because the general form of that sentence is false. Rules that reserve an activity to licensed entities, that require a designated system for a legal effect, that impose eligibility lists on who may hold what, or that make one institution answerable for a whole chain, all tend to hold a bundle together by removing the customer's choice. Rules that mandate access, interoperability, portability, unbundled pricing or open standards do the opposite, and the same authority often does both at once: the European framework that reserves settlement finality to designated systems also forced account-servicing interfaces open in payments. So the accurate claim is that finance's bundles dissolve at the speed of the specific mechanism binding each one, which is slower than gaming's and not uniform across the industry. What follows is that the decisive fight is fought in policy design rather than product design. Anyone building here who treats the regulator as an obstacle rather than as the battlefield has misread the terrain. From batch to stream: the securities services proof From batch to stream: five dissolutions in securities services, and the fee basis moving from stock to flow Everything above is a way of thinking. Here is what it looks like when applied all the way through one industry, and it happens to be the industry where the argument is most testable, because securities services is the purest proof-substitute business in finance. Verification of claims is the largest thing it sells, though as the taxonomy below shows it is not the only thing, and the difference decides what survives. What follows in this section is my own analysis of the sector rather than a summary of anyone else's, and where an empirical claim appears it is sourced to the operator making it. Start with the observation that makes the whole sector legible. A large operational layer of securities services rests on a batch assumption: settlement at end of day, net asset value calculated once daily, yield accruing and distributing periodically, reconciliation overnight, corporate actions in cycles. Each was rational for a specific reason, and the reasons have not aged equally. Some were technical constraints that have weakened. Others, including netting windows, legal record dates, tax lots, human review cut-offs and genuine bulk economies, remain load-bearing and are named as such later in this section. Funds pooled capital because aggregation was efficient when per-transaction costs were high. Net asset value was daily because compute was expensive and pricing required overnight runs. Transfer agents maintained registers because paper-based ownership required manual reconciliation. Settlement waited until end of day because networks were slow and coordination required human oversight. Read that list again through the bundle test and the conclusion is unavoidable, because every item names a technological condition rather than a commercial preference. The batch cycle is a bundling technology, and the fund's operational manufacturing layer is held together partly by the cost of doing things one at a time. Which gives us a third bond to add to the two named earlier, and it needs its dissolver classified rather than left vague, because the scheme set out above has only two solvents and an agitator. Programmable value dissolves the reconciliation bond. Credentials dissolve the attestation bond. The aggregation bond, which is one of the mechanisms holding the pooled fund together alongside its fiscal, fiduciary and regulatory ones, is dissolved by neither. It is dissolved by cheap per-event execution, which is the first solvent running at the agitator's frequency. Programmable value makes a single event cheap to settle; agent-driven volume is what makes settling every event separately the normal case rather than an expensive exception. That is the first place in this argument where the solvent and the agitator interact rather than merely coexist, and it predicts where else to look: any bundle held together by per-item cost rather than by legal or fiscal structure dissolves at the point where the frequency rises, not at the point where the technology arrives. Which licenses a blunt conclusion, stated narrowly enough to survive an operations director's first objection: mandatory batch is no longer a technical requirement, and cadence becomes a configuration choice rather than a constraint. Batch does not vanish, and several of its uses are load-bearing rather than inertial. Netting requires a window by construction, and a window is a batch. Tax lots, corporate action entitlements and record dates are legally periodic. Human oversight needs a cut-off to review against. Bulk processing remains cheaper per item where the items genuinely arrive together. What changes is that each of those becomes a reasoned choice with a stated purpose, rather than the default everything inherits. The residue is what should worry an incumbent: batch retained because a legal or netting requirement demands it is architecture, and batch retained because the overnight cycle is how the department is organised is inertia, and the fabric makes the difference visible for the first time. One caution on the word, since this paper uses it twice in unrelated senses. The aggregation bond here is the pooling of many small items into one processed unit, which is an operational economy. Thompson's Aggregator is a firm that owns the demand relationship at zero marginal cost, which is a market position. The first is dissolving. The second, as the attacks below concede, relocates and survives. Two primitives break it. Atomic value transfer collapses a process that currently runs across days rather than seconds and keeps counterparty risk live throughout. Continuous returns streaming collapses a return that currently arrives as semi-annual coupons, quarterly dividends, monthly lending fees and gains at disposal, leaving the investor to assemble a total return from several unsynchronised batch processes. Map the dissolution and it is unusually clean, because each item disappears for a stated technological reason rather than a competitive one. One discipline before the table, and it applies to the rest of this paper. A reader is entitled to know which claims describe something running today and which describe something an architecture intends. So each row carries a status: live means deployed and processing real value at some scale; bounded means live within a single platform or a limited participant set; pilot means tested with real or simulated value but not in production; design intent means specified and argued but not yet demonstrated. Batch world Stream world Why it dissolves Status Pooled funds Segregated managed accounts Aggregation was a response to per-transaction cost Design intent, and it collides with tax structure Daily net asset value Continuous real-time valuation Compute is no longer scarce Design intent. Tokenised money market funds are live, but continuous valuation is not what any of them claim Transfer agent The programmable ledger is the register Ownership no longer needs a separate record Bounded, live for tokenised funds on single platforms Overnight reconciliation Single authoritative state There is nothing to reconcile Bounded, true within a fabric, false across seams Batch settlement at T+1 Atomic delivery versus payment Coordination no longer needs a window Live within platforms, pilot across currencies What survives is worth reading closely, and the usual answer in the sector is that the only thing which cannot be automated is trust, with custody surviving by transforming into the fabric operator: identity verification, regulatory compliance and the trust layer for atomic operations, while corporate actions remain a custody function where the judgment stays human and the execution becomes real-time. That is directionally right and I sharpen it later in this paper rather than accept it, because two items on that survival list do not belong there. Then the consequence that matters most. Nothing rests. When value transfers in milliseconds, an investor will not tolerate money or assets sitting still. Cash immediately seeks yield-bearing instruments. High-quality assets are lent out, pledged as collateral or posted against margin. And the consequence can be the opposite of the disintermediation fantasy. The result need not be fewer transactions. It can be far more: more transfers, more oversight, more continuous benchmarking, with collateral quality assessed continuously rather than at the end of each day. This is not a thought experiment, which is the other thing the sector's sceptics need to absorb. Franklin Templeton runs an on-chain money market fund with a patent-pending feature that calculates and distributes yield proportionally, in its own words "down to the second, when a tokenized security is transferred from one party to another".²³ Kinexys at JP Morgan and Broadridge's Distributed Ledger Repo are in production. HSBC Bank plc passed Gate 2 of the Bank of England's Digital Securities Sandbox in July 2026 and was approved to participate as a Digital Securities Depository, subject to the notice's limits and conditions,³⁷ and the Monetary Authority of Singapore's Project Guardian is a live multi-jurisdiction pilot programme. Accrual on transfer is the single most useful data point in that list, because continuous returns streaming is the primitive people assume is furthest away, and it has been running since June 2025.²³ Note what it displaced, in Franklin Templeton's own account of the standard it is departing from: share ownership "often determined, and yield is typically calculated, at the end of a trading day and distributed to investors at the end of the month".²³ Three batch boundaries in one sentence. The economics are where this becomes a strategy question rather than an operations question, and since the model is mine I should show its mechanics rather than assert its output. What follows is illustrative arithmetic and not a forecast, fenced off so nobody quotes it as one. Illustrative arithmetic, not a forecast. Start with an assumption rather than a fact, because no non-duplicative industry figure for global assets under custody exists: published estimates range from around a hundred and twenty trillion to well over two hundred, they rest on different definitions, and multi-layer custody chains from global custodian to sub-custodian double-count the same assets more than once. Take a stock of roughly two hundred and twenty trillion earning one and a half to three basis points, which produces a fee pool in the region of thirty-three to sixty-six billion. Both inputs are assumptions and the argument does not depend on either, because what follows is a change in the basis of the fee, and a basis change survives any plausible level. Now price the same activity on flow, at basis points per transformation rather than basis points per annum on the balance. One base case makes it legible: a hundred trillion of annual transformation turnover at ten basis points is a hundred billion of fee revenue. That is roughly one and a half to three times the illustrative pool above, and it requires around half the custodied stock to change state once a year. Move either input and the sensitivity is obvious: at five basis points the same hundred billion needs two hundred trillion of turnover, and at fifteen it needs sixty-seven. The assumption doing the work is turnover, not the rate, which is why the rate is the wrong thing to argue about. That turnover assumption is large and it deserves to be visible rather than buried inside a per-transformation rate, because it is the actual claim: not that fees rise, but that a meaningful fraction of the world's custodied assets starts moving through billable state changes each year. The robust claim underneath does not depend on any of those magnitudes, and it is the part every securities services executive should read twice. The fee basis can change, and the fee lines exposed are specific rather than general. Where a charge is levied on the balance for maintaining a record, reconciling it and reporting on it, the activity being paid for is the one shared state removes. So name the lines, because a securities services executive cannot act on a claim about the sector. The exposed ones are safekeeping and record-maintenance fees on balances, reconciliation-driven charges, and reporting fees priced off holdings. Where a charge is levied for executing, servicing, transforming or standing behind an event, the activity survives and its natural basis becomes the event. The lines this mechanism does not touch are the ones paid for a licence, a balance sheet, an indemnity or a judgment: legal holding and registration in a regulated capacity, asset-servicing decisions requiring interpretation, tax and entitlement work with a liability attached, collateral and financing services, and exception management where the value is that somebody resolves what the machine could not. Now the limits of that finding, because the categorical version fails this paper's own rent test. A change in fee basis identifies which activity is being paid for. It does not identify who ends up with the profit. Durable capture by whoever processes the events requires the third condition to hold: an appropriable position. That means an exclusive access right, a switching cost, a legal designation, differentiated liability or risk-bearing, or a durable client relationship. Event processing has none of those by construction, and it is more contestable than balance-holding was, because it needs no licence to hold client assets. The competing outcome is therefore not merely possible, it is the base case in a commoditising market: the transformation gets priced down, the surplus passes to clients as lower total cost, and the institutions that keep economics are the ones holding the licence, the balance sheet, the client relationship or the liability rather than the ones running the pipeline. Custody economics are also multi-component and provider-, service-, asset-class- and market-dependent, combining safekeeping with settlement, asset servicing, corporate actions, income and tax processing, cash and foreign exchange, securities lending, collateral management and issuer services, so any statement about the basis of one fee line is not a statement about the sector's profit pool.⁴⁸ Which makes the conclusion conditional and still worth acting on. An institution whose economics rest on balance-based record-keeping fees is exposed by this change, and an institution that assumes the displaced revenue automatically arrives in its own event-processing line has skipped the appropriation condition. The pool may grow for whoever processes the events, or it may compress for everybody and settle where the licence and the liability sit. That is the same structural claim this paper makes about venues becoming caches and liquidity becoming a composition, arriving from the operations side and landing in a profit and loss account. It is also the cleanest available illustration of Coase moving, stated at the strength the evidence supports: the evidentiary and reconciliation content of five intermediary functions can stop being separately purchased steps, becoming properties of the shared state instead, and the revenue attached to performing those steps has nowhere obvious to sit. What does not move with it is the constitution and underwriting content of the same roles, which is why the fee basis changes rather than the function ending. Whether that revenue relocates to the party performing the transformation or dissipates into lower prices is decided by the appropriation test, not by the architecture. The fabric is the firm, and the firm is composable Here is the question the Coase framing invites and almost nobody asks. If transaction costs collapse and firms dissolve, what stands on the other side of the boundary? The lazy answer is nothing, a disintermediated market of peers. That is wrong, and the reason matters. Coase's transaction costs are functions, and functions do not vanish when you stop paying a firm to perform them. Search cost falls because somebody operates a registry and a discovery service and keeps them running. Verification cost falls because somebody issues credentials against a schema and maintains a revocation surface. Settlement cost falls because somebody implements atomic primitives and a federation protocol. Enforcement cost falls because somebody anchors an audit trail and stands up an arbitration path. When a firm dissolves, its transaction costs do not evaporate. They precipitate as protocol. The network fabric is not a faster rail and it is not infrastructure in the ordinary sense. It is the institutional residue of the dissolved firm, and it holds the functions the firm used to hold. But that formulation is only half the insight, and stopping there produces exactly the error this paper attacks elsewhere. It makes the fabric sound like one large successor institution, a single replacement for the many it dissolved, which would simply be aggregation with better plumbing. The fabric holds what the firm held, and it holds it in composable form, which changes the character of the thing entirely. Anything held in composable form is raw material for firms that do not exist yet. The fabric is the firm in the sense that it holds what the firm held. But it is not a firm. It is a composable firm: the substrate on which new firms are constituted, by composing what it exposes. This resolves a contradiction the Coase argument walks straight into if you are not careful. Take literally the claim that transaction costs collapse and firms shrink, and you arrive at an atomised market of individuals, which nobody believes and which contradicts the bifurcation this paper argues for later. Coase's framework offers two options, make or buy, internalise the cost or transact for it in the market. Composability does not add a third. It changes what buying means. The unit of purchase stops being a finished product from a single supplier and becomes a modular capability assembled at runtime, per outcome, from whoever is best placed to supply it. That is still buying. What is new is that discovery, contracting and settlement happen inside the transaction instead of around it, which produces a lower-friction, machine-addressable spot market rather than the frictionless one economists assume. Hold that distinction, because the next several pages are about the costs composition brings with it, and they are not small. Before claiming that as novel, it has to survive the economist who will object first, and the objection is a good one. Oliver Williamson already supplied the category. His answer to Coase was that the make-or-buy question is decided by asset specificity, the degree to which an investment is durable, transaction-specific and cannot be redeployed elsewhere without losing value. Low asset specificity goes to the market, high goes to hierarchy, and in 1991 he added the hybrid in between, as a discrete structural alternative rather than a midpoint.²⁶ On that reading, runtime procurement of standardised capabilities is simply market governance under low asset specificity, which is the most ordinary case in the whole theory. Nothing new at all. The objection is right on the taxonomy and wrong on the consequence, and the reason why is more interesting than the claim it replaces. Williamson is careful about something the popular version of his theory loses: "asset specificity, in any of its forms, does not by itself pose contractual hazards that require added governance".²⁶ Hazards need asset specificity plus three further conditions: contractual incompleteness, where disturbances arise that were too costly to specify in advance; strategic defection, where a party abandons the spirit of the agreement for its letter once the stakes are large enough; and the limits of court ordering, because "the courts cannot be relied upon to fill gaps and settle disputes in a timely, knowledgeable, and efficient fashion". Set the programmable fabric against that list and the result is precise rather than sweeping. Policy-as-code attacks the codifiable portion of incompleteness, because a machine-readable policy bundle specifies ex ante what documentation previously left to judgement. Without that qualifier the claim is self-refuting: incompleteness is by definition the set of disturbances too costly or impossible to anticipate, so no amount of ex ante specification reaches the remainder. What code removes is the anticipated-but-unspecified. What it leaves untouched is the unforeseen, which is where judgement and courts live. Deterministic execution and protocol escrow constrain one form of strategic defection inside an atomic transaction, because there is no state in which one leg has moved and the other has not. Between atomic transactions, defection remains available. More importantly, a composed outcome can acquire operational dependency at machine speed even where Williamsonian hold-up has not arisen: common-mode failure, service withdrawal or a failed provider can interrupt an outcome without either party having made a transaction-specific investment or behaved opportunistically. Williamsonian hold-up begins only where that dependency is paired with relationship-specific investment and appropriation. The third condition, the limits of court ordering, is untouched. Nothing in this architecture makes a court faster or better informed, which is this paper's existing point that programmable value cannot program a judge. So the formulation is stronger than the one I started with, and it is Williamson's own design variable turned into a product: A composable capability is an engineered reduction in asset specificity. Williamson noted in passing that specificity is a design variable, that a good can be "redesigned by reducing asset specific features" at some sacrifice in performance. A standardised, credentialled, discoverable capability is that redesign carried out deliberately and at scale, and programmable infrastructure can reduce specified transaction hazards within an atom without removing incompleteness, operational dependency or the limits of court ordering everywhere else. Which means composition does not abolish Coase's boundary or escape Williamson's. It can move the boundary toward market governance where the safeguards live in the protocol rather than in the relationship and the risk-adjusted external cost falls below the internal alternative. Where that inequality fails, relational contracting and hierarchy remain cheaper. And the concession that follows should be stated rather than hidden, because it is the sharpest risk in the whole architecture. Williamson's Fundamental Transformation, set out in The Economic Institutions of Capitalism, says that even where many suppliers competed for the work, "the relationship is effectively transformed during contract implementation into a bilateral supply relation thereafter. Identity thereafter matters".²⁶ Composition can recreate operational dependency at machine speed. An agent composes a liquidity outcome from a competitive field, and one second later it is mid-outcome and dependent on a capability provider it does not control, with no time to renegotiate and no alternative that can be substituted inside the window. That dependency does not by itself prove Williamsonian hold-up. It becomes hold-up where relationship-specific investment and appropriation are present; otherwise it is a systems-resilience and continuity problem. Either way, it has not been priced adequately in the composable architectures I have read. With that established, the firm does not shrink toward zero. It changes what it is made of, and its boundary is redrawn. Coase's firm was a container for internalised transaction costs, and its size was set where coordination cost met transaction cost. The composable firm is an arrangement of composed capabilities, and its boundary moves outward only when the risk-adjusted external cost, capability price plus composition cost plus expected loss from transferred context plus residual liability, falls below the internal coordination cost it replaces. Firms continue to exist where context and accountability make that inequality fail. Both terms in that sentence need definitions rather than assumptions, and the second one has been carrying more weight than it earned. Context depth is the quantity of accumulated, non-transferable knowledge required to produce an outcome correctly. Its operational test is not a feeling about how special a firm is. It is whether a competent outsider, given full documentation and the same capabilities, would get the answer wrong. Where the answer is no, the activity composes and the incumbent's familiarity with it is worth nothing. Where the answer is yes, ask why: because the knowledge lives in the judgement of people who have seen the failure before, because it is embedded in relationships that took years to build, or because it is legally or contractually not transferable at all. Those three are the components of depth, and each of them decays at a different rate under documentation, which is why some context genuinely is a moat and some is merely undocumented. And note where composition cost sits in the theory, since a reader who knows their Coase will ask. It is not a new category alongside market and internal costs. It is the form market transaction cost takes when the unit of purchase is a modular capability rather than a finished product, which is why Coase's boundary condition still governs the outcome. The difference is that the costs have moved from search, negotiation and contracting per deal to standards, conformance, credentials and integrity maintained continuously. Fewer of them are marginal, more of them are fixed, and that shift in cost structure is what favours scale in composition even as it lowers the cost of any single composition. Composition cost is not zero and it is not free, and the failure to name it is how this entire school of argument becomes marketing. Composing an outcome from capabilities you do not own requires paying for at least seven things: authoring and governing the standards and ontologies that make interfaces mean the same thing to both sides, integrating and maintaining conformance as those standards move, issuing and revoking the credentials that make each participant checkable, securing the integrity of the oracles and attestations that connect the ledger to the world, holding the cyber-resilience and operational capacity to be composable safely at machine speed, acquiring the legal recognition and capital that make your capability safe for a stranger to depend on, and running the composable system alongside the incumbent one for as long as migration takes, which means dual operation, reconciliation between the two, and the governance of a cutover on infrastructure that cannot be taken offline. That seventh component is the one every architecture diagram omits and every programme discovers. Legacy coexistence is a composition cost, not a transitional inconvenience preceding the real work. It is a permanent line item for as long as two systems must agree, and it scales with the criticality of what is being replaced rather than the elegance of what replaces it. Every one of those is a real cost, several of them are fixed rather than marginal, and two of them, legal recognition and capital, are exactly the costs incumbents already carry and challengers do not. Which produces the condition under which this entire argument runs backwards, and it should be stated plainly rather than buried: When composition cost exceeds the internal coordination cost it replaces, the boundary moves back and the firm re-internalises. Composability is not a direction of travel. It is a race between two falling costs, and nothing guarantees that the market's costs fall faster in any given activity. That is what makes the thesis falsifiable rather than merely directional, and it is also the answer to the practitioner's objection that all of this sounds expensive. It is expensive. The question is only whether it is less expensive than the management layers it replaces, and the answer will differ by activity, by asset class and by jurisdiction rather than arriving as a single verdict. Microsoft, resetting its games division, put a number on its own version of this cost: work passing through as many as fourteen layers of management in some parts of the company, with platform teams forty per cent larger than at the start of the generation while players and playtime declined.¹ Treat that as one firm's disclosure about itself rather than an industry constant, which is exactly how it was offered. And this is the point at which the argument stops being about dissolution. A solvent in analytic chemistry takes things apart. A solvent in synthetic chemistry gets things into solution so they can react and form compounds that did not previously exist. Dissolution is the precondition for synthesis, and the interesting half of what follows a solvent is not what disappears but what becomes possible to make. So what forms? Not an arbitrary list of roles, which is how this kind of taxonomy is usually presented and why it is usually forgettable. There is a derivation rule available, and using it disciplines the answer. Holding a necessary input to composition that cannot itself be composed is sufficient for a durable function, and makes it a candidate strategic position. Durable function and profitable position are different claims: the first says somebody must hold the input, and the second requires the appropriation condition to hold as well. If an input can be assembled from other capabilities at runtime, nobody is needed to hold it. If it cannot, somebody must be, and that somebody has a reason to exist that survives the collapse of transaction costs. Stated that way round, the rule is a test I can defend rather than a census I cannot: it tells you that the underlying function is durable and that whoever holds the input may occupy a strategic position if appropriation holds, and it does not tell you that the list of such functions is complete. Two qualifications before the list, because the rule is sharper when it is stated honestly. "Uncomposable" does not mean metaphysically unobtainable. Intent and context can be inferred, accumulated and represented, just imperfectly, and the residual between the approximation and the thing itself is precisely what the holder is paid for. Approximable but not substitutable is the accurate claim. And the positions this produces are not all firms: one of them is occupied by legislatures and central banks, which are durable holders of an uncomposable input without being anybody's competitor. Run the rule over the current candidate set and it supports seven, not the five I would have listed from intuition. Meaning cannot be composed, because composition presupposes shared semantics, so semantics must be authored and governed. Intent cannot be composed, because someone must express it, which requires a surface where intent becomes executable. Local context cannot be composed from elsewhere, by definition, since that is what makes it context. Answerability cannot be composed, because a balance sheet, a licence and a party who can be sued are not assembled from interfaces, and this is the input I originally mislabelled as reliability. Reliability is composable through redundancy; being answerable is not. Assured immediacy under uncertainty cannot be composed from information alone, because somebody must commit inventory, capital or capacity before the offsetting demand is known. Exclusive assets cannot be composed, meaning proprietary data rights, closed model weights and compute at a scale where replication is irrational, and note carefully that the uncomposable thing here is the exclusivity rather than the reliability of the output. Redundancy composes reliability, but only against independent failure. Common-mode and correlated failures survive every layer of redundancy you can buy, which is a second reason the function remains necessary and the candidate deserves the appropriation test, and a caution against believing that composing three providers has made you safe. And publicly conferred legal status cannot be composed by protocol, because statutory finality, insolvency immunity, sovereign money and equivalent public-law effects arise through applicable law rather than through engineering. Note the scope carefully, since the settlement section below is explicit that ordinary legal effect can be constructed through property, contract and account law without any statutory designation. What no protocol can confer on itself is the specially protected status, which is the whole argument of that section arriving here as a taxonomy entry. Note what that last one is not. Nobody holds a durable function by running infrastructure well. They hold it by holding something others may not have: the licence to the data, the weights nobody else can inspect, or capital that makes competing at that layer irrational rather than merely difficult. Three further qualifications, because the list is easier to state than to defend. First, the seventh is not a function a firm can decide to occupy. Six of these are commercially available, to whoever can hold the uncomposable input. The sovereign and statutory bridge is held by legislatures and central banks, and the most a firm can do is operate inside it under designation, which is a licence rather than a position. Read it as the boundary of the taxonomy rather than as a seventh strategy. Second, the rule verifies membership and does not generate the list. Given a candidate I can test whether its input is uncomposable, and no test tells me the enumeration is complete, so an eighth may exist and I would rather say so than imply a closed set. The two candidates most often proposed to me, oracle integrity and cyber-resilience, both fail the test for the same reason: they are already inside the seven composition costs above, which is where risks that must be managed live, as distinct from inputs that cannot be assembled. A third candidate is harder and I will name it rather than leave it out: bearing duration, meaning somebody has to hold the mismatch between when capacity is committed and when it is consumed. I read that as a form of committing capacity ahead of demand, since holding a mismatch across time is still committing capacity before the offsetting demand is known, and the liquidity section below is an argument that the party who does it needs capital and a licence. That reading is a closer call under the narrower formulation than it was under the broader one, and the concession is worth making plainly: immediacy and duration are not the same commitment, so anyone who thinks bearing duration is categorically distinct has a real case for an eighth entry. My rule cannot settle it, because the rule tests inputs and this is a dispute about how finely to cut them. Make, buy, compose: Coase's boundary, Williamson's asset specificity, and the operational dependency that compresses into milliseconds Durable function, and candidate position Uncomposable input it holds Why it exists What it would earn from, if the appropriation condition holds Ontology and semantic authorities Meaning Composition presupposes shared semantics, which must be authored and governed rather than assembled Definitional authority Applications and intent surfaces Expressed intent Someone must express what is wanted, at a surface where it becomes executable Attention and habit Outcome producers Local context Context is by definition not available from elsewhere, and outcomes require it Context depth Capability manufacturers, risk-bearing Answerability A licence, a balance sheet and a suable party cannot be composed from interfaces Regulatory standing and capital Capability manufacturers, computational Exclusive assets: proprietary data rights, closed models, compute at irrational-to-replicate scale Exclusivity cannot be composed by anyone lacking the right or the capital, even though the output is reliable and interchangeable Control of the asset, not operational excellence Dynamic resource allocators Committed capacity ahead of demand Assured immediacy under uncertainty requires somebody to commit inventory, capital or capacity before the offsetting demand is known Allocation quality Sovereign and statutory bridges (public, not a firm-level position) Publicly conferred legal status Finality, insolvency immunity and settlement money are conferred through applicable law, not engineered Jurisdiction, and the seam between jurisdictions One reading of that fourth column has to be blocked before it starts. Durability under this rule is necessity, not capture. The rule establishes that an input cannot be assembled and therefore that somebody must hold it, which is the second rent condition and not the third. Whether the holder keeps the surplus is decided by the four conditions, and two of these rows narrow or fail under them: local context walks where its depth is the judgement of people rather than a legal restriction, as the issuance test below finds, and the intent surface holds expressed intent but earns from contestable attention rather than from the input itself, so attention can be won away by a rival surface, which the fifth self-attack concedes. Read that table in financial services terms rather than abstract ones, because it produces the strategic conclusion of this paper. The risk-bearing capability manufacturer is the licensed institution, and the dynamic resource allocator is the market maker. A capability becomes trustworthy enough for strangers to compose precisely because there is a licence, a balance sheet, a resolution regime and somebody answerable behind it. And allocating capital, capacity and risk across time under uncertainty is the definition of underwriting, market making and treasury. The split inside capability manufacturing is where the strategy gets uncomfortable, and pretending otherwise would be dishonest. Computational capability manufacturing is not a business incumbents win, and the reason is instructive rather than merely competitive. What defends that layer is exclusive rights and capital scale, and a bank's rights and capital are committed elsewhere by regulation. Concede hyperscale compute and foundation-model manufacturing. But concede that much and no more, because the boundary matters: domain-specific inference over proprietary financial context, and the governed orchestration of it, are defended by the same legal fencing that makes that context non-scrapable in the first place. Handing those over with the compute is a category error that costs the position this paper spends its final section defending. What those firms conspicuously do not want is a capital requirement, a resolution regime, a supervisory college and personal liability for directors. The risk-transfer layer is defended by exactly the obligations incumbents complain about, which is the most useful inversion available to anyone running one. Which reframes the message to incumbents from a lament into a choice. Some of the positions with the most durable economics are ones incumbents already occupy, and they lose them by continuing to sell verification instead of manufacturing composable capability, or by trying to win the layer where their obligations are a handicap rather than a moat. There is a recursion here too. The ontology layer is itself a composable capability, which is why its governance can become a systemically consequential concentration point rather than a neutral standards body. Two instances exist, and they are not at the same stage, which the claim-status discipline of this paper requires me to say plainly rather than blur into a single sentence about production. The NFH fabric family is a documented open-fabric architecture, describing itself as "the public, discoverable surface of a planetary value network" for discovery, contracting, settlement, identity and trust,³ whose adoption at institutional scale remains to be demonstrated. Canton is the one reporting live institutional flow at scale, more than nine trillion dollars in monthly transaction volume on chain, on company-stated figures in a filing with the Securities and Exchange Commission.³⁰ Note the unit, because it is routinely misreported: that is transaction volume passing over the network, not the value of assets tokenised on it, and the two differ by orders of magnitude. Separately, Broadridge's Distributed Ledger Repo platform averaged three hundred and sixty-five billion dollars of daily repo transactions in January 2026, again on company-stated figures.³¹ Intellectual honesty requires running the bundle test on both without charity, since the discipline of the argument is that bundles are technological artefacts rather than economic ones. NFH fabric bundles registry, catalogue, discovery, credentialling, adapters, observability, settlement, guarantees and arbitration. Canton bundles privacy, atomicity, interoperability and finality. Both are bundles. Both are subject to the same physics as Game Pass. Run it, and something more interesting than a verdict emerges: they survive by completely different mechanisms, and neither is the mechanism it advertises. NFH fabric fails the no-choice condition, and fails it deliberately. Its principles are decentralised, permissionless, open standards, user-centric, composable and agent-native, and the documentation is explicit that you may adopt one service or the full stack.⁴ On the no-choice test that is a death sentence. Except the test is being applied to the wrong category. Fabric is not trying to be a bundle. It is trying to be the market. And markets behave in the opposite way to bundles under abundance: they benefit from it, because liquidity and maximised choice are what make a market valuable rather than what dissolve it.¹ Registry, catalogue and discovery are the storefront function. Fabric is Steam, not Game Pass, and the composability that would kill it as a bundle is what qualifies it as a market maker. Canton passes the no-choice condition far harder than its own marketing claims, and the industry keeps miscategorising why. Its foundational argument is that privacy, not capability, is the binding constraint on institutional adoption: a trader with exposed collateral positions is broadcasting strategy to be front-run, and a treasurer managing liquidity does not accept payment flows becoming visible to the world.⁶ But privacy from market participants is not a feature competing with other features, and it is not a credential a participant presents. It is a requirement the law imposes on the environment itself, set by data protection law, banking secrecy, market abuse rules and client confidentiality obligations that exist regardless of anyone's product preferences. Where those obligations bind, a network that cannot satisfy market-facing privacy is not an option for that flow at all, and elsewhere it is severely disadvantaged for anything where position exposure is strategically material. What this does not establish is privacy from a responsible compliance role, which is a different legal question and the subject of the first self-attack below. That distinction governs the language throughout, and privacy from the party statute makes answerable for screening is nowhere claimed in this paper. Which is why market-facing privacy sits outside the bundle analysis wherever the obligation binds: you cannot unbundle a precondition, and no amount of cost advantage elsewhere compensates for failing it. And Canton partially satisfies the everything condition through architecture rather than acquisition: because synchronizers route and order encrypted packages they cannot decrypt, described in Canton's own primer as "a post office dealing with sealed envelopes which it cannot open," participants dynamically choose different synchronizers according to the trust requirements of a given transaction.⁵ You do not need the bundle to have everything if you can compose the trust set per transaction. That last property is the most under-discussed idea in this entire field. Trust becomes a parameter of the transaction rather than a property of the network. The trust section later sets that claim's boundary: what becomes transaction-specific is the assurance a counterparty needs, priced and composed per deal. Trust in the counterparty does not disappear, and the part of it that rests on somebody being answerable cannot be parameterised at all. Two fabrics, one equation, and the seam Once the seven Coase costs are separated, the supposed rivalry between institution-grade and open networks stops being a strategic choice and becomes a category error. They answer different questions on the same list. Note which list, since this paper now has two of seven: these are the market transaction costs from the table above, not the seven composition costs of the section just ended. The equation in the title is worth writing down, since it governs the rest of this section: a transaction clears only if every one of the seven Coase costs is answered, and no single fabric answers all seven. Settlement and privacy on one side, identity, discovery and authority on the other, with legal finality supplied by neither. Which means the interesting quantity is not the capability of either fabric. It is the cost of the join. Canton is a settlement and privacy fabric. Sub-transaction privacy means each party records only the parts of a transaction that apply to them: in a delivery-versus-payment trade the bank sees the ten thousand dollars of cash and not the securities, while the registrar sees the hundred shares and not the cash.⁶ Consensus is proof-of-stakeholder, so only parties to a transaction validate it, and Super Validators operating the Global Synchronizer are, in Digital Asset's own phrase, "blind traffic controllers".⁷ NFH fabric is a discovery and authority fabric. Identity, catalogue, discovery, credentialling and audit are protocol concerns rather than application concerns, and autonomous software is a full network participant: an agent holds its own keypair in the registry, receives authority through a scoped, time-bounded delegation credential, can hold an account in its own name, accumulates reputation that counterparties sign against its registry entry, and discovers offerings natively rather than by scraping.⁸ And composition is not confined to composing capabilities. The phrase that carries the most weight is composing other types of value, and it is the tokenisation thesis proper rather than a flourish. Today's financial system contracts over a wide range of underlyings and composes a remarkably small set of representations: cash, securities, derivatives, collateral, credit. The distinction matters, because the first half of that sentence is where the obvious objection lives. Weather derivatives trade on CME, as do carbon allowance and freight futures; catastrophe bonds transfer insurance risk; securitisation finances receivables and future revenue streams. So the closed-set claim is false, and the true claim is narrower and more useful: composing anything outside the small representational set requires bespoke legal work, bilateral negotiation and manual onboarding, which means it happens deal by deal rather than at runtime. Programmable value makes the type system extensible and machine-addressable. Once any claim can be represented with policy attached, the composable set grows to include things that were never financial instruments: capacity, entitlement, reputation, attention, compute, data licences, energy, carbon, spectrum, receivables, future revenue, professional time, identity attributes, and permissions themselves. Finance has always been a composition engine running over a fixed and very small type system. Programmable value makes the type system open. The industry is not being disrupted so much as asked to perform its existing function across a vastly larger domain, and almost nothing about how it is organised prepares it to do so. The new value sits in composing across types rather than within them. An instrument combining a receivable, a capacity entitlement and a reputation credential, purpose-bound and settling atomically, is none of the three and has no existing product category. Cross-type composition is where genuinely new instruments come from, and it is the activity today's institutions cannot perform natively, cheaply and at runtime, because their systems, licences, risk frameworks and organisational charts are all partitioned by asset type. They do it today through bespoke contracts, committees, legal analysis and manual onboarding, which is precisely why it happens deal by deal. The obstacle is not imagination. It is that the firm is shaped like the old type system. Which brings us to the three things composition does not supply, because a novel instrument needs all three and no protocol confers any of them. It needs a legal-person principal, because someone with capacity must be the issuer and an agent cannot be. It needs a liability chain that survives the instrument's own novelty, so that when one composed leg fails there is an identifiable party answerable to the holder rather than a diagram of interfaces. And it needs a classification decision by someone with authority to make it, because whether the thing is a security, a deposit, a payment instrument, a derivative or none of them determines its capital treatment, its distribution rules and its investor protections, and that decision is made by regulators and courts on their own timetable rather than by whoever composed it. Composition produces the instrument. It does not produce the standing, the liability or the label, and those three are the actual gating items on cross-type composition rather than the engineering. State the boundary of that claim honestly: these are constraints of current law, not facts about the universe. Legislatures have conferred legal personality on entities that are not people many times over, and a jurisdiction that decided to grant limited standing to an autonomous agent could do so tomorrow. What that would not remove is the underlying requirement, because standing exists so that somebody with assets can be made to answer. Any legal innovation here relocates the accountable party rather than abolishing the need for one, which is why I treat this as a constraint that moves slowly rather than one that cannot move. Neither fabric moves Coase's boundary alone. Canton answers whether a transaction can settle atomically and privately, and cannot answer who exists, what they offer, or who is permitted. NFH answers who exists and who is authorised, and cannot by itself host a trade where the visibility of the position is the risk being managed. The infrastructure that moves the boundary is both, federated, which makes interoperability between fabrics the central commercial question. It would be wrong to say nobody is trying. The seam is contested by three different kinds of claimant, and what none of them has solved is more instructive than what all of them are building. The official sector is trying to abolish the seam rather than own it. Project Agorá launched in April 2024 with seven central banks and, as of mid-2026, brings together eight, including those of five major reserve currencies, with more than forty private financial institutions convened by the Institute of International Finance, to test a multi-currency shared programmable platform holding tokenised central bank reserves and tokenised commercial bank deposits together. It is working the settlement finality, anti-money-laundering and privacy questions with central banks in the room, which is the part no private consortium can replicate.²⁸ Note the architecture, though: Agorá's answer to the seam is one shared platform, which is not composition, it is re-bundling, and it is the unified ledger concept made concrete. Note also the stage. Real-value testing in July 2026 totalled roughly eight hundred thousand Swiss francs.²⁸ That is a laboratory rather than a market. The BIS describes Innovation Hub projects generally as "experimental in nature, for the purpose of investigating technological and practical feasibility", and Project Agorá itself as a collaboration testing the desirability, feasibility and viability of a shared programmable platform.²⁸ Swift is claiming the seam as infrastructure, at the stage of a design. In September 2025 it announced work with more than thirty financial institutions to design and build a blockchain-based shared ledger, beginning with a conceptual prototype by Consensys, intended to "record, sequence and validate transactions and enforce rules through smart contracts" and explicitly designed for interoperability with existing and emerging networks, alongside separate orchestration services between systems.²⁹ Read the stage honestly, because the ambition is easy to mistake for the artefact: this is design intent with a prototype attached, not a running ledger. It is the incumbent-becomes-the-fabric move, executed by the one institution with a genuine claim to neutrality, and announced years before it can be judged. And its own scope statement concedes the limit exactly: "Swift's focus is on the infrastructure, the types of tokens that will be exchanged on the ledger is the territory of commercial and central banks".²⁹ Sequencing and messaging, yes. The legal character of what settles, no. The cross-chain protocols are solving message passing. Chainlink's CCIP, with private transactions piloted by ANZ for cross-chain settlement of tokenised assets, along with the general interoperability layer, moves instructions and value representations between chains competently and makes no claim to statutory finality at all. So the seam has serious contenders for the plumbing and nobody holding the legal problem. The precise distinction matters. Legal finality is not created by code alone, nor can a commercial operator unilaterally confer it. It is a jurisdiction-specific legal and institutional outcome arising from the applicable statutory and regulatory framework, recognised system rules where required, insolvency treatment and conflict-of-laws rules. A commercial party may operate infrastructure, license access to it and charge for transactions that receive legal-finality protection, without owning the legal protection itself.⁴³ Which makes the seam business something more specific: coordinating and evidencing finality across fabrics, holding provable records of what settled where under whose rules, demonstrating to each side that the other leg is irrevocable under its own governing law, and standing behind the interval during which one leg is final and the other is not. That interval is the product, because a gap between two finalities is a risk position and somebody has to hold it. A risk position is not yet a business, and the distance between the two is where most seam commentary stops. So state the minimum viable operating model, because anyone proposing to build this has to answer all eight items and most proposals answer none. Whether the operator acts as principal, taking the exposure onto its own balance sheet, or as agent, arranging it for others, since that single choice determines its capital treatment and most of its liability. Which assets and currencies are eligible, because an interval on a government bond against central bank money is a different product from an interval on a tokenised receivable against a stablecoin. What collateral and margin it takes, at what haircuts, revalued how often. How it funds itself intraday when both legs are outstanding at once. What its default arrangements are, meaning the waterfall, who is mutualised and what happens when a participant fails mid-composition. Its legal perimeter, meaning which entity in which jurisdiction faces whom, and under whose insolvency law. Its operational resilience obligations, since a seam operator that is down is a market that cannot cross. And where its pricing authority comes from, meaning whether it can charge for the interval or is competed to the cost of capital. Answer those eight and you have described either a bank or a central counterparty, which is the point. Bearing the interval is a regulated activity wearing new vocabulary. Which makes the seam operator a correspondent bank, or a central counterparty, relocated, and the admission is stronger than the evasion. Those are two distinct functions and not necessarily one firm, which matters for anyone deciding what to build. Bridging the interval between two finalities is correspondent economics: hold assets both sides, extend credit across the gap, price the timing exposure. Absorbing the failure of a party mid-composition is central counterparty economics: mutualise, margin, default-manage. A single seam operator may do both, and the two can equally sit in different entities with different capital treatment. What cannot happen is that the interval goes unborne, because it is real and somebody carries it. Whether a business forms around bearing it is a separate question, and the answer may be decades. Foreign exchange settlement risk has been named since Bankhaus Herstatt was ordered into liquidation on the afternoon of 26 June 1974, leaving counterparties who had paid Deutschmarks that morning holding nothing. The 1996 Allsopp strategy mobilised a public-private response. Private netting services operated along the way, including ECHO, which had operated since 1995, Multinet and bilateral services such as FXNET; in December 1997 CLS Services merged with ECHO and Multinet. A purpose-built payment-versus-payment utility arrived when CLS Bank began operating in September 2002, twenty-eight years after the loss that named the risk.³⁹ The lesson is not that a seam utility forms automatically. The Allsopp strategy combined private-sector development with public monitoring, moral suasion and supervisory action, and the utility emerged over a long timetable under that public-private pressure. So the prediction has to carry its own timetable and its own trigger: a seam may institutionalise after scale, after a loss and under public-private pressure, but it can also remain a bilateral exposure or be absorbed by a public utility, and until one of those paths wins the exposure sits on balance sheets that were not designed to hold it. Which also reconciles the two clocks running through this paper. A private seam operator waits for coercion or catastrophe. A public or mandated one moves as soon as it has a mandate, which is why the settlement-asset attack below, that the asset may never arrive, is the same question asked from the other end. Inside a single fabric, atomic settlement removes the timing exposure correspondents exist to bridge, so the function does not disappear. It is squeezed out of the centre and concentrates at the edges, where different legal and operational realities collide. That is this paper's own Coasean logic applied to its own prediction: the function persists, and only its location, speed and concentration change. Canton is admirably honest about the mechanism, if not about its consequence. Its own myth-busting material states that interoperability between Canton and Ethereum mainnet is no better than between a private EVM chain and Ethereum mainnet, because both "rely on the exact same overhead of APIs and message bridges. (i.e. the same way we have done systems integration for decades)".⁷ The consequence for atomicity is my inference rather than their concession, and it needs stating carefully, because the strong version is false. Atomicity across two ledgers is achievable, and the design matters more than the label. BIS reserves its strongest description, "an instant and simultaneous transfer of two tokens", for atomic settlement where both tokens sit on one ledger. Where they sit on two, it describes the tested hashed timelock arrangements as tokens "sequentially released to their new owners" and reports that Project Stella "concludes that cross-ledger arrangements may reintroduce principal risk", since a buyer who waits too long after the cash has been collected can let the securities timelock expire and leave the seller with both legs.¹⁴ So the accurate version is that a basic hashed timelock is conditional sequential release rather than synchronous exchange, and it is coordinated or conditional-commit designs, with two-phase commit as the reference case, that deliver the stronger all-or-none property without either ledger becoming the single commit venue. What BIS actually says is about cost rather than possibility: an architecture of disparate ledgers is justified when data and governance requirements diverge, as they do across jurisdictions and asset classes, but "this flexibility introduces more complexity for cross-ledger coordination via interconnection protocols to achieve programmability and composability".¹⁴ That is the claim to make. The seam is not a hole in the technology, it is a coordination cost, and where a provider controls an appropriable chokepoint a coordination cost is precisely the thing that gets priced, capitalised and owned. Where none does, it stays bilateral, gets mutualised, dissipates through standards, or is absorbed by a public utility. Inside a fabric, coordination is protocol. Between fabrics, coordination is a cost somebody pays. The reconciliation cost we are proud of dissolving within a domain re-forms at the seams between domains, in a thinner and more automatable form, but it re-forms. And absent convergence onto a common technical and legally recognised settlement surface, seams remain durable features rather than merely transitional artefacts. The unit of competition in the next decade may not be the chain, the ledger or the consortium. It may be the seam, where an interval has to be priced, standardised, mutualised or publicly absorbed. Nobody owns finality, but a party may underwrite the interval between two finalities, occupying the position correspondent banking held in the last era. On the Herstatt timetable, that institution can take a generation to form, if it forms as a private business at all. This is the strategic consequence of an architectural claim I have made in different language: the modern fabric replaces the single trusted orchestrator with an orchestrator of orchestrators, where value switches between networks rather than being forced through one archaic intermediary.⁹ What the Stratechery lens adds is where the rent would sit if anybody captures it, and the answer is the seam rather than either fabric. And the institutions best placed to hold seams are, awkwardly for the disruption narrative, those who already hold custody, messaging and correspondent relationships, because a seam is worthless without credibility on both sides of it. Markets: the venue becomes a cache What follows applies the argument function by function, and there is one piece of discipline to carry into all four sections, because without it these read as a list of predictions. Each function has to be tested against the four conditions set out at the start, not just the first one. It is easy to show that a bottleneck is dissolving. The work is in naming what becomes newly scarce, whether anybody can appropriate it, and whether the change moves market and internal costs at different rates. Where I can name all four, the conclusion is a claim. Where I cannot, it is a direction of travel, and I have tried to mark which is which rather than let the prose blur them. Under abundance, surplus can move from inventory toward matching, routing, policy and proof where those functions remain scarce and appropriable, and otherwise it dissipates to buyers. Protocol-native discovery sharpens that into something more threatening to the venue business model than most exchange strategy teams have registered. A venue is a place liquidity must come to. A discovery service is a query answered across the places liquidity already is. These are structurally different businesses, and the second dissolves the first's core asset without competing with it directly. The fabric's formulation is that an offering published once is findable across every aligned network, so "the producer doesn't re-list; the consumer doesn't aggregate".⁴ Read as a capital markets sentence, that is an extinction event for a specific and currently very profitable set of rents, and the specificity is the whole point: listing fees, market data sold as a monopoly product, and the business of being the place where the order book lives. Not exchanges. Three revenue lines inside exchanges, which happen to be three of the most profitable. Push it one layer further. If catalogues are network-published and discovery is protocol-native, then price discovery separates from trade execution. Those two functions have been bundled inside a venue since the coffee house, and the bundle test tells us how to read that: they were bundled because of a technological condition, namely that continuous two-way flow could only be observed by being present in one place, first physically and then electronically. Remove the condition and the bundle is theatre rather than architecture. So the maximalist version of this argument is wrong, and the reason comes before any strategy built on it. Attention remains scarce even when supply is free, which is the durable core of Aggregation Theory. And a venue is not merely a place where liquidity is discovered. It concentrates executable order flow, forms prices through interaction rather than publication, imposes priority and conduct rules, runs surveillance, and in many cases provides netting and default management. A distributed catalogue can aggregate indications of interest without producing any of that. So what erodes is the venue's monopoly over listing, over discovery and over proprietary data. What survives, and probably thrives, is the exchange as the trust and veracity layer over abundant discoverable supply, plus the harder functions a catalogue cannot perform: executable liquidity, routing quality, market governance, surveillance, netting and finality. That is a migration from renting a location to underwriting a fact. In a world of protocol-native discovery, the venue's listing and discovery function is a cache. A cache earns a rent only while the thing it holds is scarce or expensive to fetch, and protocol-native discovery makes fetching cheap, which is precisely why that rent is transient while the caching remains useful. The functions that survive are the ones a catalogue cannot perform: forming a price through interaction, and standing behind what happened. Run the four conditions over the two outcomes separately, because joining them produces a false verdict. Listing and discovery commoditise. First, a published offering findable everywhere is abundant and substitutable. Second, no newly scarce function exists within listing and discovery itself: the residual scarce functions sit elsewhere, in execution, surveillance, netting and price formation. Third, a cache made cheap by protocol-native discovery leaves no licensable chokepoint for the cache owner to appropriate. Fourth, the market cost of finding an offering falls relative to the internal cost of maintaining a proprietary listing. This is therefore a direction of travel rather than a rent prediction: the surplus dissipates to issuers and users. Execution, surveillance, netting and executable price formation are a different outcome. First, they are not commoditised by discovery. Second, they become newly scarce relative to it. Third, venues can appropriate them through licences, designated status and concentrated order flow. Fourth, protocol-native discovery lowers the market's cost of finding a counterparty without lowering the cost of performing those functions. The venue claim is therefore not that the venue dies. It is that one rent dissipates while another relocates into the functions a catalogue cannot perform. Liquidity is the first bespoke outcome Liquidity, in the world we inherited, was inventory plus a phone list. It was manufactured by intermediaries who warehoused risk on their own balance sheets, and the reason is pure Coase: the market for immediacy was too expensive to use, so the function was internalised and the intermediary charged for the internalisation. Access to liquidity can be composed. Liquidity itself cannot, because somebody still has to own the asset and be willing to part with it under stress. Everything in this section is an elaboration of that one distinction. Programmable value changes the physics in four ways, and only the first is widely discussed. Access to liquidity becomes conditional rather than warehoused. When lock, release and encumbrance are native primitives with policy attached, liquidity can be rented for a moment rather than held for a quarter. The obvious formulation of the mechanism is backwards: encumbrance does not substitute for inventory, it is what makes inventory undeliverable, which is the pre-funding argument in the settlement section below. What actually changes is that programmable encumbrance lets the same inventory be committed precisely, briefly and verifiably, so less of it sits idle against a possible call. Somebody still holds it. The advantage shifts toward whoever is fastest at policy and proof, on top of, and not instead of, whoever is largest at funding. Liquidity becomes a discovered service rather than a held position. With registry, catalogue, discovery and per-call metering in the protocol, immediacy can be sourced at the moment of need from whoever is best placed to provide it. The pattern is already articulated for data rather than money: acquisition shifts from annual contracts to spot, per-call markets, and agents compose sources at runtime based on observed quality, freshness and price, switching providers without re-integration.¹² Substitute liquidity, collateral, guarantees, credit enhancement and FX for data and the procurement interface transfers, though the supply economics do not. Data is reproducible and non-rival; balance sheet is rival, capital-constrained and state-dependent. So what becomes purchasable per event is access, and per-event access still rests on committed balance sheet, agreed collateral terms and capacity that has been priced in advance. Guarantees become gradient rather than binary. Trust as "a continuous, contextual contract" with underwriter-backed gradient guarantees³ has no clean traditional analogue and deserves more attention than it gets. Counterparty risk today is managed continuously through limits, collateral, haircuts, margin and pricing, so the claim is not that finance lacks gradients. It is that the admission decision is binary and the gate does much of the work: you are approved or you are not, and everything after that is calibration inside a relationship. If guarantees can be continuous, contextual and underwritten per transaction, then the admission decision moves from the counterparty to the transaction, while the credit judgment stays with the obligor. That is how the gaps close, and the distinction is what keeps the claim defensible: what becomes transaction-level is whether this exposure is acceptable now, on this evidence, at this price. Whether the obligor can pay, whether the promise is enforceable where it sits, and how the exposure correlates with everything else on the book remain counterparty and portfolio questions. Two and a half trillion dollars of trade financing is requested and refused annually because, in the fabric's own words, "verifying the deal costs more than the deal earns," and five point seven trillion dollars of credit that small businesses need is unavailable because their "real order books" are "invisible to capital".⁴ Verification cost is one binding constraint in both, and it is the one this architecture attacks. It is not the only one. Trade finance and small business credit are also constrained by capital, collateral, enforceability, country risk and plain risk appetite, and no credential improves a jurisdiction's courts. The defensible claim is narrower than the slogan and still large: where the binding constraint is the cost of verifying the deal rather than the willingness to bear its risk, credentials and gradient guarantees address it, and the fabric's own framing, that verifying the deal costs more than the deal earns, describes exactly that subset. Note also what gradient guarantees do to risk, which is relocate rather than remove it: somebody underwrites the gradient, and that somebody needs capital, a licence and a reason to be there in a crisis. Purpose-bound value collapses the monitoring cost of on-ledger restrictions. Value that carries its own rules of use³ moves the restriction inside the asset. Consider how much of finance is monitoring apparatus wrapped around restricted money: use-of-proceeds covenants, ring-fenced facilities, subsidy disbursement, escrow, margin segregation, development finance conditionality. In every case the restriction lives outside the asset and is enforced by people and reports. Where the restriction is expressible on the ledger, meaning who may receive value, when, against what evidence, this is Coase's monitoring cost not reduced but largely removed. Where the restriction is a fact about the world, it is not, because a protocol can only enforce against what it can observe, which is the constraint the trust section develops. Use-of-proceeds is the clean example: a protocol can enforce that funds reach an approved contractor and cannot verify that the contractor built the school, nor prevent the borrower from substituting the money for spending it would have done anyway. Purpose-bound value abolishes the monitoring of transfer conditions. It does not abolish the monitoring of purpose. Put those together and the conclusion writes itself. Access to liquidity is not a stock and not even a flow. Under a programmable fabric it is a composition: assembled at the moment of need from discovered capacity, conditional guarantees, purpose-bound value and encumbrance primitives. The inventory, the capital and the willingness to be there under stress remain held somewhere, by somebody, and that somebody is still a balance sheet with a licence. What changes is that immediacy stops being something you must own in order to use. Note which of the three jobs each of those four claims belongs to, because it decides how far each travels. Discovered capacity and conditional access are attestation work, and they can dissolve where the relying party is permitted to accept the relevant proof, which is why they are the parts of this section with the clearest technical pathway. Purpose-bound value is constitution, so it moves into the protocol and stays there as long as the restriction is expressible on the ledger. Gradient guarantees are underwriting, and underwriting does not dissolve at all: it gets repriced per transaction rather than per counterparty, and somebody still holds capital against it. Run the four conditions, all four, because the discipline is worthless if it is announced and then skipped. A bottleneck falls: search and negotiation costs for capacity, which discovery and conditional access genuinely remove. Something scarce remains: assured capacity under stress, which no protocol manufactures. Third, and this is the one that bites: can the holder of the remaining scarcity appropriate the surplus, or does it dissipate to buyers? Here it can be appropriated, because assured capacity under stress requires capital and a licence, both of which are supply-constrained by regulation rather than by technology, and neither of which a composer can conjure. And the fourth holds, with a stated boundary that matters more than any other qualification in this section: in normal conditions, sourcing liquidity externally at the moment of need can be cheaper than warehousing it internally, so the boundary moves outward. Under stress it can invert. Funding costs, rollover and withdrawal risk, haircuts, margin calls, concentration and market access all deteriorate together, which is why prudential guidance pairs diversified external funding with an internally held, unencumbered buffer and tested contingency arrangements rather than treating external sourcing as a substitute for either.⁴⁹ So the boundary moves outward for the routine case and snaps back for the case that decides whether an institution survives, which is the whole reason the settlement section below treats elasticity as a balance-sheet question rather than a protocol feature. The third condition holding is what makes this section predict relocation rather than dissipation, and it is that same condition which fails for listing and discovery in the markets section, where a cache commoditises without leaving anything licensable behind, even though that same section predicts survival for surveillance, netting and price formation. So the reading is not that liquidity provision is disrupted. It is that the attestation layer around liquidity is dissolving while the underwriting core is being handed a better instrument. Which makes liquidity the first bespoke outcome, and the flagship proof case for financial services. Not a retail wealth illustration. The most institutional, most balance-sheet-intensive, most incumbent-defended function in the industry turns out to be the cleanest example of a bespoke outcome composed from composable capabilities. Issuance: the credential schema is the executable spine of the prospectus Issuance today is a project: legal drafting, prospectus, appointed agents, a listing, a settlement date, six to twelve weeks and a fixed cost that quietly determines which ideas in the world are permitted to become financial assets. It is the last hand-copied manuscript in finance. A syndicate is a scriptorium, and we have been congratulating ourselves on the quality of the calligraphy. Start with a candid sentence in the fabric corpus, which concedes the limit of its own claim. Fabric supplies protocol-level plumbing for provenance, custody and transfer, and then: "The legal and custodial wrappers remain the issuer's responsibility; what changes is that the technical friction no longer dictates them".¹¹ That concedes the operational point, and the conclusion deserves blunter language than the documentation uses, with the boundary first because it decides how far the claim travels. What becomes a configuration parameter is the fund's operational existence, not its legal or fiscal existence. A fund is also a tax vehicle, a distribution passport and a regulated product with investor protections attached, and none of those is a settings file. Inside that boundary the claim is strong: in a world of programmable value, the fund's manufacturing apparatus is a configuration parameter. A fund is currently a manufactured object requiring a promoter, a domicile, a wrapper, an administrator and a dealing calendar. If a segregated position on a programmable ledger can carry its own allocation rules, its own eligibility policy and its own distribution logic, then what we call a fund is a settings file, and the manufacturing apparatus around it was scaffolding for a constraint that has gone. But the fabric's sentence smuggles in a more interesting claim that almost nobody in the industry has said out loud. Technical friction has been silently determining legal structure for decades. We have special purpose vehicles, feeder funds, sub-fund umbrellas, nominee arrangements, omnibus accounts and depositary receipts substantially because the plumbing could not support the direct structure. A generation of legal architecture is scar tissue over technical constraints, and we have been teaching it to graduates as though it were financial engineering. Remove the constraint and much of the wrapper is revealed as unnecessary rather than clever. Which is why the boundary above matters, and it is argued properly among the attacks below rather than left to a footnote. Not all of that wrapper is scar tissue over technical constraints. Some of it is scar tissue over fiscal ones, and tax structure is not dissolved by better plumbing. What thins is the manufacturing apparatus. What persists, until a legislature says otherwise, is the shell. Then the operative point. If provenance, custody, eligibility and audit are expressed as credential schemas, and the design effort genuinely sits in the schemas rather than the plumbing,¹¹ then the credential schema is the new prospectus. A prospectus is a document that makes an asset legible to a human so they can determine whether they may and should hold it. A credential schema is the machine-legible form of exactly that determination. The strong version of that claim is wrong and easy to attack, so here is how far it goes. A prospectus also carries accountable representations, narrative risk factors, conflicts, governance, rights and remedies, and none of those compile. The schema is the executable spine of the prospectus rather than its replacement: it encodes what a machine must check before a transfer is permitted, and leaves the part that exists so a human can be held responsible for what was said. Whoever authors the schema for an asset class encodes part of the operational rule-set that issuers, arrangers, administrators, regulated intermediaries and regulators must approve: how the instrument is represented for machine purposes, who may hold it, what must be proven, what is disclosed to whom, and which default states must be expressed. Executable instrument or contract logic determines the programmed consequences, and applicable law determines the rights, liabilities and remedies. That is influence over the executable layer, and it is not the underwriter's legal role. Authoring a data structure does not make anyone an underwriter, and it does not transfer responsibility for the instrument. Under securities law, underwriter status turns on a person's actual conduct in purchasing, selling or distributing the security, and responsibility for the offering and its disclosures rests with the issuer and the other legally designated participants; in the European crypto-asset regime the offeror or issuer is expressly the party responsible for the white paper's content.⁵⁰ So name who is answerable when a schema is wrong, because the question has a real answer and the industry avoids it: the issuer for the instrument and its disclosures, the approving regulated entities for their own use of the schema, the administrator or service provider under its contract and any applicable outsourcing rules, and the authoring body only where its own conduct, contract or a specific legal duty creates an obligation. A schema error that permits an ineligible holder is an issuer and intermediary compliance failure before it is a standards-body failure, which is precisely why the approval chain above matters more than the authorship. The consequence for market structure is not what long-tail enthusiasts expect. Fixed issuance cost collapses, minimum viable issue size collapses with it, and the universe of claims currently priced out comes into scope: SME credit, receivables, revenue shares, single-asset infrastructure, local-currency instruments. This is the "more created this month than in the previous decade" moment for capital markets, and it arrives with the same quality distribution that AI image generation brought to illustration. Most of it will be junk. That is not an argument against it; it is what abundance looks like from inside. That answers the supply side and leaves the objection an economist reaches for first: cheap issuance is worthless if nobody buys the output. An SME receivable is not unfunded today because issuing it costs too much. It is unfunded because a stranger cannot assess it, cannot hold it in a mandate written for rated paper, and cannot exit it. Collapse the issuance cost and you get a market of a million assets nobody can price, which is not abundance, it is landfill. The paper has to explain where the demand comes from or the long tail stays theoretical. It comes from the same machinery, which is the part that took me a while to see. The mechanism that makes small heterogeneous claims cheap to create is the mechanism that makes them holdable by strangers. Credentials carry the evidence a buyer would otherwise have to gather. Continuous observability replaces the periodic reporting a small issuer cannot afford to produce. Gradient guarantees let an underwriter price the residual uncertainty per transaction rather than refusing the whole category, so the admission and pricing decision can move partly toward the claim. What does not move is the credit decision itself: the obligor's capacity to pay, the enforceability of the promise in its jurisdiction, the correlation of the exposure with everything else on the book and the capital held against it all remain assessments about the counterparty and the portfolio. What credentials automate is the evidence-gathering around the decision, not the decision. And composability means an asset too small and too odd for any single mandate can be assembled into something that fits one, with the underlying claims still individually inspectable rather than buried in a tranche. Each of those is a demand-side function, and each is a by-product of the supply-side change rather than a separate build. Be honest about the residue, because two of the demand constraints do not yield to any of this. Liquidity and mandate eligibility are not verification problems. A claim can be perfectly evidenced and still have no secondary market, because a buyer needs a seller and no credential manufactures one. And an institutional mandate is a legal document listing what may be held, so an instrument that is provably sound and outside the list remains unbuyable until the mandate is rewritten, which is a governance timetable rather than a technical one. So the defensible version is narrower than the enthusiasm and still substantial: the investable long tail gets an evidence base and an underwriting mechanism, and still waits on secondary liquidity and mandate reform. Which predicts the order of arrival. The tail funds first where the holder intends to hold to maturity and writes its own mandate, so private credit, insurance-linked and development finance before anything that needs a daily price. But the new fixed cost is schema design, and schema design has enormous returns to reuse. So the equilibrium may be a small number of schema authors and a very large number of issuers instantiating them. That is the meta-factory pattern expressed in capital markets: the meta-factory produces the universal protocol pattern as a grammar and captures value as design authority and standard-setter rather than as toll collector, while the outcome factory instantiates it with local ontology and keeps the margin on the outcome.⁹ Concentration does not disappear in this future. It can relocate from the balance sheet to the ontology, and note that this is a claim about schema authorship rather than about issuance. The test at the end of this section concerns the portfolio-unbundling consequence, where the scarce investment view walks and appropriation runs to talent rather than to the platform. Schema authorship needs a separate test. First, the operational cost of instantiating a known schema falls with reuse. Second, shared semantics and reusable design authority remain scarce. Third, whether an author appropriates the surplus depends on adoption, governance and whether conforming to the published schema makes the author's existing assets more useful than rival assets. Fourth, schema reuse can lower the market cost of issuance without lowering the internal cost of authorship, but only where the schema is accepted across counterparties and jurisdictions. The roads strategy set out in the trust section is one possible appropriation mechanism, not an automatic rent. This is a contingent concentration hypothesis, not the settled outcome of low issuance cost. There is a third consequence, and it is the one that should unsettle asset management. When a portfolio is itself a first-class programmable asset, with allocation rules, rights and rebalancing logic and holder-level positions inside it, then anyone with a defensible investment view can issue a product. Not a model portfolio. An actual governed asset someone can hold. Run the value chain argument through that and it lands with no adjustment: removing the substantiation bottleneck destroys relatively undifferentiated creators who depended on the structural bundling of idea creation and idea substantiation, while making highly differentiated creators who deliver both more valuable than ever.² The closet-index active manager exists because having a view and manufacturing a fund were structurally bundled and manufacturing was expensive. Unbundle them and that manager competes for attention with zero-marginal-cost issuers. Meanwhile the genuinely differentiated manager gets an issuance capability that used to require a firm. The middle is vulnerable, both ends can thrive, and the institutions sitting in the middle are writing the most confident papers about why nothing will change. Run the conditions here and one of them splits by actor rather than resolving cleanly, which is why this section is written as a structural claim rather than a rent prediction. A bottleneck falls, since substantiation costs collapse when eligibility and disclosure become machine-checkable. Something scarce remains, namely a defensible investment view, which no protocol supplies. Third, appropriation is actor-specific rather than absent, and that is the one that decides who captures anything: the scarce input is a differentiated view, and differentiated views are held by people rather than by firms. They walk. So the condition holds for scarce talent, which appropriates through compensation, ownership or mobility, and fails for the undifferentiated platform, which has no equivalent barrier and commoditises into a utility margin. Fourth, the relative-cost condition holds: issuing a governed product externally becomes cheaper than housing it inside a distribution franchise, so the boundary moves. That is a good outcome for investors, a good outcome for the best managers, and an uncomfortable one for anyone whose business model is the wrapper around them. Distribution: catalogue presence before eligibility Distribution has been the most durable rent in financial services because it was gated by three costs at once: regulatory permission, advice liability, and the brute expense of client acquisition and suitability assessment. AI attacks the cost of complying with permission, the cost of suitability analysis and much of the client-acquisition apparatus. It does not issue a licence or remove advice liability. That distinction is why distribution, not settlement, is where this decade's value may move, subject to the statutory gates that survive. Distribution rents in finance rest on the non-portability of reputation, and portable credentials are aimed at exactly that. If you take one sentence from this section, take that one. Look at Coase's list of market transaction costs, then look at what an agent under scoped delegation does: searches the universe, checks eligibility, compares terms, negotiates, initiates execution, monitors the position, produces an audit trail. The agentic layer is a machine for performing exactly the functions firms were invented to internalise. When those costs fall materially on the market side, the justification for the firm's scope can weaken with them. So the last bundle in finance is not settlement or custody. It is advice, product manufacture and operational execution, bundled and sold as a relationship. That is our creation-plus-substantiation bundle, and it is the one AI severs. Machine-legible eligibility is necessary and insufficient, because eligibility only becomes relevant once you have been found. The actual stack runs: catalogue presence, discoverable offering, verifiable credential, machine-checkable eligibility, atomic settlement, signed audit trail. Eligibility is the fourth step. If you are not in the catalogue you have already lost at the first, and nothing downstream recovers it. The line that should end every digital distribution strategy meeting is the description of how an agent finds an offering: "via Discovery Edge, exposed natively. No scraping, no screen-reading".⁸ Every institution treating its app or portal as its distribution asset is building for a consumer about to stop looking at screens. And the phrase cuts both ways: an institution reachable only by screen is reachable only by scraping, which is fragile, frequently unauthorised and increasingly blocked. Screen-only distribution is not conservative. It is a decision to be unreachable. Then the mechanism most people miss. Portable reputation is the solvent for distribution rents. Reputation on the fabric is signed by counterparties, held by the subject, verifiable by anyone, and travels "because it isn't stored in someone else's platform".⁴ Set that against the diagnosis of what a walled garden extracts: fifteen to thirty per cent from the seller inside it, for matchmaking alone, "and the reputation earned there cannot leave".⁴ That final clause is the entire mechanism of platform power. Distribution rents in financial services rest substantially on the non-portability of reputation: a small manager's track record captive to a platform's reporting, a borrower's payment history captive to a lender's files, an issuer's servicing record captive to an arranger's memory, an adviser's relationships captive to a firm's CRM. Make reputation portable, cryptographically signed and subject-held, and the hostage-taking stops working. This is a more powerful disruption of distribution economics than better user experience will ever be, and it is barely discussed. Third, and this is where the industry's mental model breaks rather than bends: the agent is a new operational and economic participant, though not a new legal person. On the fabric an agent holds its own identity and keypair, authority as a scoped time-bounded delegation credential, an account in its own name so it can be paid, charged and audited, and its own accumulated reputation.⁸ Every classification apparatus in institutional finance assumes the account holder is a legal or natural person with a domicile, a risk profile and a set of rights. The industry's current answer is to pretend the agent is the human, which works right up to the moment two agents transact with each other and no human is in the loop, which the architecture explicitly supports.⁸ Your best distribution investment this year is not a channel, a partnership or an app. It is being findable, verifiable and settleable by a machine that has never heard of you. And run the conditions on distribution too, because it produces the least comfortable answer of the four applied functions. First, a bottleneck falls as eligibility checking and onboarding friction become machine-executable. Second, something scarce remains, but naming it honestly is difficult: presence in whichever catalogue agents actually query, meaning attention and default position rather than any capability. Third, the surplus may be appropriable, though not by the distributor: it can accrue to a discovery service that agents trust, which is the aggregation position relocated one layer up. Fourth, the relative cost shifts toward external sourcing. So distribution is the function where my own framework predicts the outcome I like least, but its conclusion remains conditional: if discovery consolidates, rent migrates to a new intermediary; if it remains contestable and no provider sustains an appropriable position, more of the surplus dissipates. What dissolves, what hardens, what changes state The solvent framework: what dissolves, what hardens, what changes state, and what recombines Most writing on this subject goes wrong in one of two directions. The maximalists assume a solvent dissolves everything in the beaker. The defenders assume that because some things do not dissolve, nothing does. Both miss the third category, which is where the strategy lives: things that neither dissolve nor resist, but change state. Dissolves Hardens Changes state Reconciliation as a business Legal finality and insolvency law Regulation: from document to executable Custody reconciliation and routine record maintenance Safeguarding, legal holding or registration, asset servicing, exception management and liability Trust: from institutional to compositional Periodic reporting Ontology and schema governance Settlement: from event to continuously evaluated settleability The audit sample Liability, which cryptography locates rather than absorbs Attestation intermediaries whose only asset is being trusted to look Central bank money as settlement asset of last resort Non-portable reputation as a hostage mechanism The seam between fabrics Fixed issuance cost as a filter on which claims may become assets Elasticity, which is somebody's willingness to extend credit, and which becomes more central-bank-dependent rather than less as private buffers are optimised away The middle column is counter-intuitive and deserves a moment. A solvent does not merely fail to dissolve some things. It concentrates them. Everything that dissolves around a hard structure leaves that structure more exposed, more load-bearing and more valuable than before. Legal finality matters more in a world of instant transfer, not less, because it becomes the only remaining backstop. Licensing becomes more powerful as the thing it gates becomes cheaper to do. Ontology governance becomes a higher-leverage position as everything else becomes interoperable, and whether anybody appropriates that leverage is tested in the issuance section and left open. There is also a category the table cannot hold, because it is not a fate that befalls an existing thing. A solvent gets constituents into solution so they can recombine, and what emerges from a dissolved industry is never just a tidier version of what was there. Composable capabilities, an extensible type system and the durable functions derived above are the recombination half of this argument, and they are the reason the paper does not end with a smaller industry. It ends with a larger one built differently. The third column is the answer to how we solve for regulation, trust and settlement. We do not solve them. We change their state. Each stops being something done to a transaction by an institution and becomes, to the extent that it is verifiable, a property of the transaction, expressed in the fabric. The qualifier matters: the trust section shows that only the verifiable part makes that move, and benevolence stays institutional by category. That is what it means for value to become programmable. It is not faster. It is a phase change in where these three things live. Regulation: from document to executable The wrong question, asked in every industry forum, is whether the regulator will allow this. The right question is what supervision becomes when policy is code. Regulation is not a constraint on this architecture, it is the load-bearing wall of it, because in finance the licence is what makes a bundle impossible to unbundle, and no protocol issues licences. The mechanisms are specified, and the status varies by mechanism, which this section marks rather than blurs. Everything in the next paragraph is design intent on the cited documentation, meaning specified and in some cases implemented, not evidenced as running in supervised production. In the open fabric, network policies are authored in Rego, packaged as Open Policy Agent bundles, signed, and published as a network manifest by a facilitator organisation, so a network's rulebook is a signed, versioned, machine-executable artefact with an accountable publisher.⁴ Policy plug-ins at the network adapter can require human countersignature above thresholds of value, risk score or counterparty class, "enforced at the protocol boundary, not in app code".⁸ In the semantic layer, governance shifts "from post-hoc auditing to runtime enforcement," so a violating action is blocked as it is attempted rather than reported in a quarterly finding.¹⁰ And observability is designed so that "you can see how the network is performing without seeing what anyone is doing",⁴ which is structurally the shape of a supervisory dashboard that does not breach client confidentiality. One part of this is not speculative, and it comes from the most conservative corner of the industry, though it proves something narrower than the paragraph above describes. ISDA's Digital Regulatory Reporting takes an industry-agreed interpretation of reporting rules and transforms it, via the open-source Common Domain Model, "into unambiguous, machine-executable code," committed across fourteen reporting regimes in nine jurisdictions and, as of April 2026, applied to eight sets of rules, freely available to all firms and fully accessible to regulators.¹⁵ ISDA's own counts move between documents, so read those figures as a snapshot rather than a fixed state. On 13 December 2024, JPMorganChase said it had implemented it as a primary reporting mechanism, with rollout continuing across future jurisdictions. Natixis Corporate and Investment Banking adopted it in April 2026. Most significantly, the Ontario Securities Commission works directly with ISDA to code rule updates ahead of testing.¹⁵ That is a regulator writing executable code with an industry body. The phase change has already happened in one corner of the rulebook, and the boundary of the evidence needs stating: DRR shows that bounded reporting rules can be represented and executed as code with regulators in the loop. It does not show that network manifests govern live flow, that transactions are blocked at a protocol boundary, or that any supervisor subscribes to network telemetry today. Supervision by subscription. A supervisor stops requesting a report and starts subscribing to the manifest and to network-level telemetry. Compliance stops being an assertion about behaviour and becomes an executable artefact that produces behaviour. This is not a new idea, which is damning enough about our pace. Raphael Auer set out embedded supervision at the BIS in 2019: "a regulatory framework that provides for compliance in tokenised markets to be automatically monitored by reading the market's ledger, thus reducing the need for firms to actively collect, verify and deliver data".¹⁶ Seven years ago. Not yet demonstrated at scale in the examples reviewed here. Three hard problems, stated honestly, because anyone promising full regulatory automation has either not read a rulebook or is selling something. Interpretation is not codifiable, and that is a feature. Best execution, suitability, fair treatment, reasonable steps: these are deliberately vague, and the vagueness is load-bearing, because it preserves discretion to apply judgment to cases nobody anticipated. Codify them and you destroy what makes them work. The honest boundary: rules become code, standards stay human, and the fabric's real job is to make the boundary between them explicit and auditable. Notice that DRR, the most advanced example in existence, machine-executes reporting rules, the most bright-line and least judgemental in the book. No example reviewed here machine-executes fair treatment as an open-textured standard; claims to do so may have redefined the standard into a rule. Liability is unresolved. If policy is code and the code has a bug, who is liable: the schema author, the network facilitator, the implementer, or the participant? Auer identified this in 2019, naming the two central challenges as embedding economic finality in the legal system and "how to design rules for assigning responsibility in decentralised markets".¹⁶ Neither is settled. We never settled it for algorithmic trading either, and shipped that anyway. Regulatory arbitrage moves at machine speed. If eligibility becomes machine-checkable across jurisdictions, agents may route to the most permissive compatible jurisdiction at machine speed, without malice and without anybody deciding to. That is a genuine systemic risk, and the strongest argument for jurisdictional policy being expressed at the network manifest level rather than left to participants. Which produces the provocation I would put in front of any supervisor. The regulator's most powerful future instrument may not be a rule. It may be the machine-readable eligibility schema, not because a schema replaces law, but because law expressed through credentials, executable policy and catalogue rules can determine eligibility before a transaction is attempted. Whoever publishes that schema for a jurisdiction sets the terms of participation more effectively than any enforcement action, because non-conforming participants are not merely punished afterwards. They can become ineligible for discovery and execution by design. That is an ex ante instrument of a kind supervision has never possessed, and most regulators have not noticed it is available. Two claims about schema authorship now sit in this paper and they are not in competition, so join them explicitly rather than leaving a reader to assume one contradicts the other. The regulator authors the perimeter; the incumbent authors the product. A supervisor's schema decides who may participate in a jurisdiction, which is an eligibility question and public by nature. An asset-class schema defines how the instrument is represented, what must be proven about it and which default states must be expressed, which is a semantic question and commercial by nature, while the programmed consequences sit in executable instrument logic and the rights and remedies sit in law. The first cannot be sold, because a state does not licence its own perimeter. The second is where a durable position may sit, subject to the appropriation test run in the issuance section, and the trust section shows why it is not a monopoly either: the schema gets published to drive adoption, and the value is that the published semantics fit the assets and balance sheets its authors already have. Two different schemas, two different kinds of power, one shared consequence, which is that whoever writes the machine-readable definition sets the terms on which everyone else operates. And note the governance consequence for control functions: human-in-the-loop stops being a policy statement and becomes a protocol parameter. Supervision moves from examining whether a firm has adequate controls to reading the policy the network enforces. For anyone in a control function, that is either the largest threat or the largest opportunity of your career, and which one depends entirely on whether your policies exist in a form a machine can execute. Trust: from institutional to compositional, and the part that cannot be computed Trust was expensive to establish, so we did what any industry does with an expensive fixed cost: we amortised it into institutions and rented it back to the market. A bank's brand is amortised trust. A credit rating is rented trust. A clearing house is mutualised trust. Correspondent banking is chained trust, where I trust you because I trust somebody who trusts you, and the chain is precisely why cross-border payments take days and leak fees at every link. A protocol can make misconduct unprofitable where it is detectable, reliably attributable, and met by an enforceable sanction or forfeitable stake larger than the expected gain. Detectability is the first boundary of the architecture, and attribution and credible enforcement are what complete the mechanism. That is not a new insight so much as an old one arriving in new clothing. In Holmström's 1979 moral-hazard setting, an additional observable signal belongs in an optimal incentive contract when it provides relevant information about the agent's action.⁴⁰ Applied here, the observable set is defined by what the protocol instruments. That single constraint decides which trust businesses survive and which are already obsolete. Programmable value does not stop trust being a property of a counterparty. It makes part of the assurance required for a transaction composable per event from elements that can each be independently checked: credentials establishing what is proven about the parties, with selective disclosure allowing proof without revelation, compressed by the fabric into "one identity, many proofs";⁴ portable reputation signed by counterparties and held by the subject;⁴ trust-set selection made per transaction rather than per network;⁵ gradient guarantees turning counterparty risk from a binary gate into a continuous underwritten position;³ and audit anchoring making the trail evidence rather than an institution's word for it.⁴ But which parts of trust can actually be composed? The answer sets the outer limit of everything above. Perceived trustworthiness rests on three factors, and the framework is not mine: Mayer, Davis and Schoorman set it out in 1995 and it has been the standard model in organisational trust research ever since.²⁴ Ability, whether you can do it. Integrity, whether you adhere to the principles you have stated. And benevolence, whether you intend my good, particularly when acting against it would be profitable and undetectable. Their distinction is worth preserving rather than collapsing, because it does work here. Trust in their model is the willingness to be vulnerable to another party's actions irrespective of your ability to monitor or control them, and the three factors are what a party assesses in deciding whether to become vulnerable. Which locates precisely what a proof system can and cannot replace: it can substitute for the assessment, and it cannot remove the vulnerability. So the question for the rest of this section is not which parts of trust can be composed, it is which of the three factors can be evidenced by something other than an institution. Evidence of ability is attestable, and the attestation is verifiable. Credentials carry licences, capital adequacy, accreditation and operational capacity, and a verifiable credential is precisely an ability-attestation technology. Keep the two apart, because the gap is where the failures live: a credential proves that an authoritative party asserted the capability, not that the capability holds under stress it has never met. Recorded conduct is observable, within the instrumented envelope. Audit anchoring and bi-temporal state make it possible to check continuously, rather than by sample, whether behaviour matched stated policy, and runtime enforcement goes further by making deviation unavailable rather than merely detectable. Read that qualifier closely: what is observable is what the instrumentation captures, and conduct outside that envelope is exactly as invisible as it was before. The instinct that this is where institutions survive is widely shared and usually left imprecise. The standard sector formulation is that custody survives as identity verification, regulatory compliance and the trust layer for atomic operations. Test each item separately. Identity verification is ability-attestation, which verifiable credentials can commoditise within their relying perimeter. Regulatory compliance is not one activity: repeatable, machine-testable checks can become policy-as-code, while interpretation, exception handling, supervisory dialogue, remediation and accountable sign-off remain institutional work. The trust layer survives in a narrower form still, because its enduring content is not an institution's general aura but the party that is answerable when the rule, record or representation fails. Benevolence is neither verifiable nor observable. No credential proves a counterparty will act in your interest when acting against it would pay and nobody would see. This is not a gap in the technology; it is a category boundary. Cryptography proves things about the past, that this happened and this was signed and this state obtained, and things about constraints, that this cannot happen. It cannot prove anything about preferences under conditions that have not yet arisen. Benevolence is exactly that. So what does civilisation actually do about benevolence? It does not verify it. It engineers around it. Carstens names the mechanism with unusual precision when he explains why central banks are independent: "autonomous central banks are nothing more than an institution within the state with the key mandate of preserving the purchasing power of the national currency. Autonomy is the social engineering which shores up society's trust in the central bank."²¹ Read that as a general principle and it explains an enormous amount of financial architecture. Independence does not prove benevolence. It makes malign intent structurally difficult and expensive. And the same is true of every other device we use for the purpose: fiduciary duty, fit-and-proper tests, conflict-of-interest rules, skin in the game, mutualisation, lender of last resort, deposit insurance, capital that is forfeited on failure, and personal liability for directors. Every one of these is a benevolence substitute, and every one is institutional rather than technical. Carstens is easy to recruit further than he goes. He never uses the word benevolence, and his account of why central banks are trusted rests on mandate and integrity rather than on disposition: trust requires "sound institutions that can stand the test of time", institutions that "guarantee the safety and integrity of payments", holding a "clear mandate to serve society" and not aiming for profits.²¹ That is a claim about structure, which is exactly why it supports the engineering-around reading and not a claim about verifying good intent. His definition of trust does make the separation I need, without naming it: trust "consists in society's expectation that the authorities will act predictably in the pursuit of predefined objectives and that they will succeed in their task".²¹ Predictable pursuit of defined objectives is closer to mandate fidelity and integrity than to benevolence. Succeeding at the task is ability. He also names an asymmetry, that the dynamic "can also work in the other direction and, at times, very quickly. In the extreme, if trust evaporates, the capacity to make effective public policies disappears".²¹ The inference I draw from it is mine and not his: that a failure of perceived institutional alignment can destroy trust faster than operational capability decays. It is an observation about how institutional failures actually unfold rather than a finding I can source, and it should be read at that weight. There is corroboration for the compositional half of this from an unexpected direction. Auer's embedded supervision argument turns on the observation that where "data credibility is assured by economic incentives," supervisors must first satisfy themselves that "the market's economic consensus is strong enough to guarantee the finality of transactions" before they can trust the ledger's data, and his model has verifiers stake verification capital that is forfeited if history is ever reversed, calculated so that reversal is unprofitable for any possible briber.¹⁶ Read generally, that says something important, and the wording has to be exact because the mechanism delivers far less than it appears to: in a fabric, one narrow component of trustworthiness gets collateralised rather than institutional. What is staked against is detectable protocol-integrity failure, specifically the reversal of settled history. It is not benevolence, which is a disposition to act in another party's interest when nobody is watching, and a stake cannot be forfeited against a disposition. So integrity, in the specific sense of not rewriting the record, becomes a balance sheet item with a price, held against an observable failure, rather than a reputation held in general. Benevolence stays exactly where it was. But the mechanism has a precise boundary, and stating it is what separates this from a slogan. Forfeitable capital does not verify anyone's intentions and does not need to. It makes a detectable failure unprofitable, rendering good intent unnecessary within exactly the scope of what the protocol can observe. Reversing a settled history is detectable, so it can be collateralised. Failing to warn a client about a risk you could see, steering an order to a venue that pays you, or declining to help when helping is costly and silence is invisible are detectable by no protocol, so no amount of staked capital touches them. Detectability is the binding constraint on collateralised trust, and attribution and enforceability are the two that follow it, which makes the design question not how much capital to stake but how much of the failure surface is observable, attributable to a party and reachable by a sanction. It is also why the institutional substitutes survive: they cover the undetectable remainder. Now the strategic conclusion, and it is the most useful sentence in this piece for anyone running an incumbent. The fabric commoditises ability-verification and integrity-observation, which is the evidentiary and reconciliation portion of what custodians, auditors, registrars, transfer agents and rating agencies sell. Constitution, judgment, servicing, liability and accountable exception handling stay institution-specific, and the mix differs sharply between them. What it cannot commoditise is the benevolence-substitute business: standing behind an outcome, being liable, being resolvable, holding a mandate, being suable, and being constrained by a licence you would lose. The remaining moat is not knowing things. It is being answerable. That is a smaller business than the one you have, and a far more defensible one. Two hard problems sit on the other side, and the first receives less prudential attention than its systemic importance may warrant. Trust in the ontology. If shared meaning makes composition possible, poisoning the meaning is the highest-leverage attack available, and the semantic layer's own analysis names semantic poisoning as a novel attack vector, answering it with community governance and cryptographically signed ontology packages so that "an agent cannot be tricked into redefining 'yield' because the definition is locked in the semantic layer, not in the agent's prompt".¹⁰ Right engineering answer. But notice what it does economically: it relocates trust to the body governing the schema, which can become a systemically consequential institution in the architecture. We are creating semantic infrastructure that may become systemically important, while its prudential supervision is less developed than the supervision of recognised financial market utilities. Say that carefully rather than claiming it is ungoverned, because the counterexample is obvious and it is a good one: ISDA, Swift and ISO already run semantic infrastructure the system cannot function without, and they are governed by member committees, change-control processes and published procedures. The sources reviewed do not show those bodies carrying the full apparatus that can attach to a systemically important financial market utility: capital requirements, a resolution regime, a supervisory college, formal designation and a public authority accountable for continuity if governance fails. Industry governance is not absent, and prudential authorities are not absent either. Supervisors already reach regulated participants, critical third parties, designated payment and securities systems, outsourcing arrangements and operational resilience, and in several jurisdictions they reach technology providers directly. What they do not generally do is approve the semantic layer itself. So the accurate statement of the gap is narrower and more troubling than an absence of oversight: cross-network semantic governance may fall between existing mandates, with each authority supervising its own participants' use of a shared ontology and none of them answerable for the ontology's continuity, its change control or its conflicts across jurisdictions. And the gap widens as more of the system's behaviour moves from documents a supervisor reads into schemas a machine executes. The natural rebuttal is open source and the right to fork, and it does not hold, because forking an ontology is categorically different from forking code. The entire value of an ontology is that everyone shares it, so a fork is not a competing implementation, it is a second market. Ontology can exhibit network effects and switching costs at least as consequential as the ledger's, because forking meaning creates a second market rather than merely another technical implementation. But the rent does not work the way I first argued, and the correction matters. The obvious prediction is a monopoly charging for access to meaning, and the evidence points the other way. ISDA's Common Domain Model is authored by a body whose membership is the largest dealers, and it is published open-source and free, precisely to drive adoption.¹⁵ If that is the pattern, ontology governance does not produce a private monopoly at all. It produces a consortium or a regulated utility, and the schema is given away. Which is not a weaker conclusion, it is a sharper one. The value of authoring the schema is not the licence fee. It is that you write the schema to fit the operational architecture, compliance model and balance sheet you already have, so that conforming to it leaves your existing assets indispensable and everybody else's optional. Open-sourcing it maximises that effect rather than surrendering it. You are giving away the map to make certain everyone drives on your roads. So the systemic risk is not monopoly pricing. It is the possibility that a body whose prudential supervision is less developed designs rules of the road that suit its members' balance sheets, at a level of the stack that receives limited public scrutiny. We spent a decade arguing about who should run the ledger. Far less attention has gone to who should author the schemas, which is the question with the durable strategic position attached. Derivative benevolence caps the agent economy. Agents inherit "the trust score and liability profile of their human governors",¹⁰ with a credential chain tracing every action to a responsible human. That is the correct design, and it is a benevolence substitute of exactly the classical kind: a human with something to lose stands behind the machine. It works only while the agent's economic footprint stays within its governor's capacity to answer for it. The moment agents accumulate independent reputation and are trusted more than their governors, the substitute has failed silently, because the party the counterparty is actually relying on is not the party who can answer for it. The sources reviewed do not identify a public measure of that ratio. And one closing observation, because it inverts the whole subject. Money works because it is information-insensitive, accepted "with no questions asked", without due diligence. The idea belongs to Gorton and Holmström before it belongs to the BIS, and Holmström's formulation is the one worth holding onto: the whole point of a good money market instrument is that nobody investigates it.²⁵ That is a designed absence of verification, and it is the highest achievement of a monetary system rather than a shortcoming. Which means the endpoint of a verification revolution is not universal verification. It is a system where enough is proven, cheaply enough and continuously enough, that nobody at the point of use needs to ask. The sweeping version of that claim is wrong, so here is what actually gets retired. Programmable systems verify identity, authority, integrity, revocation status and the satisfaction of stated conditions. They do not verify the credit quality of an issuer, the adequacy of its capital, or whether the claim will be honoured under stress, and those are precisely the questions information-insensitivity suspends. Cheap proof shrinks the verification surface a user must inspect. It does not reach the core of what makes an instrument acceptable without inquiry, which remains a matter of who stands behind it. The goal of programmable proof is not universal verification. It is to make asking unnecessary at the point of use, while leaving intact the harder question of who is answerable if the answer is wrong. And there is a consequence of that inversion which this paper has been circling for pages without naming, assembled entirely from components already argued above. Continuous verifiability plus instant settlement is a run technology. Information-insensitivity is what keeps a deposit stable: nobody checks, so nobody moves. Make the underlying continuously observable and you have manufactured the opposite property, an instrument whose holders can see deterioration in real time. Then put it on rails where exit is continuously executable and available at three in the morning on a Sunday, and reduce the two frictions that have often bought supervisors their weekend, namely the queue and the closing bell. Depositors and investors tried to pull forty-two billion dollars out of Silicon Valley Bank on 9 March 2023, leaving it with a negative cash balance of about nine hundred and fifty-eight million by the close, and management expected over a hundred billion more the following day.³⁵ Read those figures as a calibration floor rather than as an analogy, because the mechanism is not the same and the difference cuts both ways. SVB was human herd behaviour: venture capitalists telephoning founders, a concentrated and socially networked depositor base, and a panic that needed a night to spread. Agent-driven withdrawal is deterministic threshold breach, which is faster and also more legible, because a published policy can be read in advance in a way that a group chat cannot. So the claim is not that agents panic. They do not panic, and that is the problem: when common thresholds are breached, they can execute in tightly clustered intervals without the hesitation that has sometimes given supervisors their margin. SVB tells us what forty-two billion in a day does to a balance sheet. It does not tell us what a thousand mandates breaching the same threshold in the same second does, and no episode does, because it has not happened yet. Which leaves the premise that makes that sentence worth writing, and it needs stating rather than assuming, because the whole risk turns on it. Why would many independent mandates breach within a highly correlated interval? Not because anyone coordinates, but because the inputs are shared. Agents can read the same public feeds, so the observation arrives near-simultaneously. Risk policies are often drawn from a limited set of framework vendors and consultancies, so thresholds can cluster around similar numbers. Regulatory triggers are common by construction, since a liquidity coverage breach or a ratings downgrade is the same event for everyone holding the instrument. And prudence itself can converge: an agent instructed to act on deterioration may pick a level a supervisor would endorse, which may be the level others picked. Correlation does not require collusion, only common inputs and common prudence. Portfolio insurance in 1987, the liquidity evaporation of the 2010 flash crash and the liability-driven investment margin spiral of 2022 illustrate how independently sensible rules can produce synchronised stress; they do not prove that agent thresholds will fire identically or that the crisis mechanisms are the same. The possible difference here is that the interval between observation and execution can fall from minutes to milliseconds, and that the policies may be published in advance, which is the favourable feature: a supervisor who can read the thresholds can, in principle, see the cliff before anybody goes over it. Which turns two of this paper's proudest claims into the same risk viewed from opposite ends. Successive gross discharge, the term defined formally in the settlement section below, trades inventory cost for recall speed. Continuous observability trades opacity for early warning. Both are genuine improvements in normal conditions, and both shorten the interval between a doubt and a withdrawal to the point where human intervention may not fit inside it. Many crisis tools rely on delay, sequencing or discretionary intervention that this architecture can reduce: the discount window needs someone to answer the telephone, a trading halt needs a venue that can be halted, and deposit insurance works partly by persuading a depositor not to join the queue. So the statement of the risk is not that programmable value causes runs. Runs are as old as banking. It is that programmable value can remove frictions that have sometimes performed supervisory work, while no architecture described here yet replaces them reliably. Circuit breakers expressed as protocol primitives, rate limits on redemption, and elasticity facilities that a machine can draw on without a phone call are candidates, and one element already exists in production, which makes the gap sharper rather than smaller. In 2025, TARGET2-Securities settled an average 922,533 transactions a day. Its auto-collateralisation can automatically extend fully collateralised intraday credit to eligible parties when a settlement instruction would otherwise fail for want of cash.³⁶ So machine-triggered liquidity is not a design fantasy, it is a decade-old feature inside a coordinated infrastructure. What does not exist in the deployments examined is a comparable facility across fabrics. T2S technically integrates relationships that remain legally distinct: a securities account at a CSD, a dedicated cash account at a national central bank and a central-bank credit relationship. Split those relationships across two fabrics and the question becomes who extends the credit, on what collateral terms and under which insolvency regime. Which is the seam again, arriving in the one place where a delay of even seconds is systemically load-bearing. Anyone building this layer should treat cross-fabric elasticity as more urgent than a standalone netting utility, because the settlement section combines them in one institution: netting, a committed liquidity facility and a collateral recall engine in a single intraday elasticity provider. Settlement: from event to continuously evaluated settleability Settlement is historically a discrete event at the end of a chain, because it required the sequential coordination of separate books. That sequence is the parent of everything downstream: the settlement date, settlement risk, netting, the collateral posted to cover the gap, and the entire post-trade industry. The post-trade industry is a monument to latency. And here is the sentence this section exists to earn. Pre-funding is a seam cost: it can be materially cheaper inside one integrated arrangement and more expensive across a boundary, and atomicity alone does not eliminate it. Everything else here is the derivation. With atomic primitives and sub-transaction privacy, settlement remains a legal event, but settleability becomes continuously evaluated: the question moves from when a transaction is scheduled to settle to whether every required condition can be satisfied at this instant. Canton's worked example is the argument in one transaction: the bank sees the cash leg, the registrar sees the securities leg, both validate what they can see, the synchronizer commits without seeing either, and the trade settles atomically with neither party learning the other's data.⁶ That is a bounded domain example, not a blank cheque for arbitrary cross-fabric delivery versus payment. Across independent fabrics, the claim requires an explicit interoperability arrangement: both legs must be reserved under compatible locking rules; a common commit authority or synchronisation protocol must specify timeout, abort, recovery and compensation; authorised compliance participants must receive enough selectively disclosed evidence to meet their obligations; the systems must align their asset, identity, finality and liability semantics; and each transaction must be recognised under the applicable legal framework.¹⁴,²⁸ Absent those conditions, the claim is coordinated conditional settlement, not atomic settlement across the boundary. Nor does atomicity settle the quality of the payment asset: central-bank money, a commercial-bank claim, tokenised deposits and stablecoins carry different credit, liquidity and singleness-of-money consequences. But here is the correction that changes the design. The New York Fed separates two properties the industry routinely conflates under the word atomic: instant settlement, meaning no gap between trade and settlement, and simultaneous settlement, meaning one leg settles if and only if all others do. Their judgement is unambiguous: "while simultaneous settlement is probably always desirable, instant settlement may not be".¹⁷ Why not? Because instant settlement makes netting impossible by construction. "For a trade to be instantly settled, all legs of the transaction must be 'settle-able' at the moment the trade is executed, which makes netting of settlement obligations impossible... only trades in which cash and securities are pre-positioned can be executed".¹⁷ And there is a second cost that gets much less attention than the funding one: instant settlement is an information leak. Decoupling trade from settlement lets a trader negotiate without revealing past activity, whereas "with instant settlement, traders can only sell securities they already hold, which reveals information about past trades," creating hold-up problems.¹⁷ Sit with the irony, but get it the right way round. The tension is not between immediacy and confidentiality. Canton's sub-transaction privacy keeps balances and transaction details confidential while settling immediately, and there is no technical incompatibility between the two. What immediacy erodes is something different: opacity about capacity. If you can only sell what you already hold, then the fact that you settled tells the market something about your inventory and your financing, and no amount of encryption hides an inference drawn from your ability to act. The trade-off is not immediacy versus data privacy. It is immediacy versus opacity about capacity and funding, which is a strategic exposure rather than a cryptographic one, and the industry has been marketing the solution to one as the solution to both. That has a consequence which connects to the funding argument below. If the funding leg can itself be composed into the atomic transaction, then settleability no longer implies prior ownership. Composable funding is a privacy technology as well as a liquidity technology, which is not an argument I have seen made elsewhere. But apply this paper's own motif honestly and the channel relocates rather than closing. An observer who can no longer infer that you held the asset can now infer that you could source it, at that size, at that moment, at a price that made the trade work, which is information about your credit lines and your standing with liquidity providers rather than about your inventory. The inference moves from what you own to what you can summon, and for a large dealer the second is arguably the more sensitive fact. So the correct formulation of the phase change is narrower and more useful. What becomes continuously evaluated is settleability: whether every required leg can satisfy its conditions together. Simultaneity is the property of the resulting settlement event, and instantaneity is not required. That preserves netting, preserves the information environment, and, under the technical and legal conditions this section sets out, can materially reduce the Herstatt-style principal risk between the legs included in the atom. Say it that way rather than the shorter way, because the shorter way is false in four directions at once. Simultaneous exchange removes the exposure that arises when one leg settles irrevocably and the other does not. It does nothing about the credit quality of the asset delivered, the validity of the title conveyed, the default of a participant whose obligations sit outside the atom, or the possibility that the applicable legal system unwinds or declines to recognise the transfer. Herstatt was one failure mode, and atomicity addresses that one. Then the limit no amount of programmability touches, and it is the hardest constraint in this entire body of work. The BIS names elasticity as one of three tests any monetary arrangement must pass: money must be "provided flexibly to meet the need for large-value payments in the economy, so that obligations are discharged in a timely way without gridlock taking over," because "maintaining cash piles or retaining large holdings of pre-funded accounts to discharge obligations are simply impractical, they would be recipes for payment system gridlock".¹³ Stablecoins fail this test because full backing means "any additional issuance requires full upfront payment by holders, which undermines elasticity by imposing a cash-in-advance constraint".¹³ Now apply that to atomicity itself, which is what nobody does. Atomicity is a settleability-at-commitment constraint expressed in code. Every leg, including any funding leg, must be settle-able at the instant of commitment. That is a weaker requirement than holding cash in advance, and the difference is the whole design space: where a funding leg can be composed into the atom, the constraint is priced contingent liquidity, and where it cannot, the constraint degenerates into cash-in-advance, which is exactly what the BIS calls a recipe for gridlock. One word in that definition carries a legal load, and eliding it is how a commit gets mistaken for finality. "Settle-able" is a composite predicate rather than a protocol flag. The protocol conditions must pass, the asset and payment representations must be legally recognised for this transaction between these parties, and the applicable participant, insolvency and priority rules must make the resulting transfer effective and enforceable. Code evaluates the first component continuously. The second and third are settled by lawyers in advance and by courts afterwards. Which locates the problem more usefully than the maximal version of the claim. The severity of the constraint is a function of whether you are inside one fabric or crossing a boundary, because a funding leg is easier to compose where the accounts, collateral terms and legal relationships are already integrated. Across fabrics, technical atomicity can be coordinated, but composing the funding leg can become economically and legally impractical at precisely the point where it must be committed. The requirement then collapses back toward pre-positioning. That is the same conclusion the seam argument reaches from the other direction, and the two arriving together is itself the evidence. But whichever form it takes, the underlying limit is untouched by programmability. Programmable value has an elasticity problem that is structural rather than transitional. You cannot program elasticity from nothing. Elasticity is somebody's willingness to extend credit against collateral, and that willingness is a balance sheet, a licence and a central bank behind it. The obvious counter comes from the operations side, and it is the Nothing Rests argument made above. If value transfers in milliseconds then nobody tolerates idle balances, so cash immediately seeks yield and high-quality assets are immediately lent or pledged. On that reading, pre-positioning costs nothing, because the pre-positioned balance is earning. That counter does not work, and the reason matters, because the mistake is being made across the industry. Pre-funding is a constraint about deliverability, not about yield. The cost of pre-funding was never that the balance earns nothing, and the idle-versus-productive framing is the wrong axis. A tokenised money market fund share accrues yield continuously and remains transferable at any moment, which is exactly the Franklin Templeton case cited above, so earning and being deliverable are perfectly compatible. What defeats settleability is not earning. It is encumbrance: pledged, lent, rehypothecated, posted as margin, staked, or subject to a third-party right. Atomicity requires the asset to be deliverable. Nothing Rests, taken to its limit, requires the asset to be encumbered, because the highest-yielding uses of a high-quality asset are lending it and pledging it. An asset cannot be simultaneously pledged elsewhere and delivered here, and the industry is selling both as features of the same architecture. Which narrows the objection considerably, and the narrowed version is the one worth defending. Pre-funding does not cost you yield. It costs you three other things. It costs foregone encumbrance, meaning the same asset cannot secure a derivative position or fund a repo while it waits at a seam, and rehypothecation capacity is the engine of balance sheet efficiency rather than a footnote to it. It costs capital and funding capacity, because acquiring the asset in order to pre-position it consumes both. And it may cost transformation friction, because a deliverable asset is not a settlement asset unless the counterparty accepts it, and a tokenised fund share is neither central bank money nor a commercial bank deposit. If the other side requires cash equivalence, the yield-bearing instrument must be transformed before it can discharge the obligation, which reintroduces exactly the timing and bridging problem this section is about. So Nothing Rests does not answer the pre-funding objection. It relocates it, from idleness to encumbrance, capital and acceptability. Which raises the fair question of whether any version of the counter survives, and three do, each deserving its full strength. Velocity reduces the required stock. If an asset can be recalled, unwound and redeployed in milliseconds, the same unit of collateral services many more obligations per day, so the stock needed falls even though deliverability is still required, because it is required only momentarily. This is real, and it is not netting. Netting extinguishes gross obligations and replaces them with a single net figure, so fewer discharges occur. Velocity does the opposite: every obligation is discharged in full, and the same asset is reused to do it. Successive gross discharge is the accurate description, and the distinction matters because the two have opposite risk profiles. Netting reduces the number of settlements and therefore contains the damage when one fails. Successive gross discharge does the reverse: it creates a chain in which each discharge depends on the previous one having released the asset. The failure mode is gridlock rather than shortfall. One party declining to release, or releasing slowly, and every downstream settlement relying on that unit fails at once, which is a queue rather than a loss. So velocity trades inventory cost for throughput risk, and the binding parameter becomes recall speed, set by the slowest leg in the encumbrance chain. Concede the part of this that programmability genuinely solves, because the blanket version of the claim is wrong. Where the pledge is itself an on-ledger encumbrance recorded on the same fabric, release can be near-instant and conditional, since the lock is a protocol state and unlocking it is a transaction. What is not a millisecond operation is recall where the pledge sits in a bilateral agreement under a governing law, in a tri-party arrangement with an agent's own processing cycle, or in a chain that crosses a seam into another fabric. The recall speed of the whole chain is set by its slowest link, and the slowest link is almost always the one that is not on your ledger. Which is precisely why an intraday elasticity provider has to exist: somebody must supply the unit that breaks the queue when the chain stalls. The funding leg can itself be composed atomically. This is the strongest version, and the stream thesis does not make it. If the settlement transaction can include a repo, a money market sweep or an intraday credit draw as one of its atomic legs, you never need to hold the asset in advance. You need to hold the ability to obtain it. That genuinely dissolves pre-funding as a stock requirement, and it is the most important design implication in this section. With one dependency that the settlement-asset attack makes explicit: the quality of a composed funding leg is the quality of the asset it delivers, so a leg funded in commercial bank money or a stablecoin carries its issuer's credit and liquidity risk into every atom it settles. But look closely at what it concedes. It replaces a stock of assets with a committed facility, and a committed facility is a balance sheet that is priced and capitalised. The elasticity does not come from the protocol. It comes from an intermediary willing to be on the other side of that leg. The protocol makes elasticity composable; it does not make it free and it does not manufacture the balance sheet. Resist the tempting next step, which is to assert that atomic credit must therefore be more expensive. It need not be. A committed facility already removes the provider's discretion to refuse a compliant drawdown, which is what "committed" means and why such lines carry commitment fees and capital charges, so loss of discretion is not a novelty of atomicity. And atomic drawing brings genuine offsets: the provider receives its collateral simultaneously rather than at the end of a settlement window, exposure duration is shorter, controls are executed rather than promised, and settlement risk on the funding leg itself is eliminated. What actually changes is not the existence of the obligation but its shape. Atomic draws can be machine-speed and highly correlated, with many users responding within a compressed interval to the same observable state and with less human intervention to sequence, triage or delay. That is a different distribution of exposure rather than a higher one, and whether it nets out dearer or cheaper depends on the design, the collateral and who is providing it. Atomic credit is differently risky credit, and the correlation is the part nobody is pricing. Central bank money could sit on the same programmable surface. That is the answer in many serious blueprints, and it concedes the argument entirely: the ultimate answer to the pre-funding problem is a central-bank balance sheet. The settlement-asset attack below explains why that cannot be treated as an assured deployment path. So the resolution is not that one side wins. Applying this paper's own framework to itself, pre-funding neither dissolves nor hardens. It changes state, from a stock of pre-positioned assets into a flow of committed, atomically drawable elasticity. That is better in every operational respect and worse in one that matters. Pre-funding is not defeated. It is refinanced. The requirement moves off the balance sheet of the transacting party and onto the balance sheet of whoever provides the atomic funding leg, which is a smaller number of larger institutions, drawn by machines at the same moment for the same reason, precisely when conditions are worst. That also separates two arguments the industry runs together. Availability is microeconomic and binds in normal conditions, and composable atomic funding resolves it at a price. Buffers are macroeconomic and bind under stress, and nothing resolves them except the central bank, because the aggregate stock of unencumbered high-quality assets is what a system draws on when everyone needs liquidity at once. A world in which nothing rests is a world with no buffers, which lengthens collateral chains and raises intraday dependence at the same time. Here is the exact claim, since the loose one would be indefensible: that configuration, long chains plus high intraday dependence plus thin unencumbered buffers, is a recognisable feature of the repo market stress of 2008, the September 2019 spike in US repo rates, and the March 2020 dash for cash. It is not a claim that any of those events was caused by an architecture that did not exist, nor that programmable settlement would have prevented them. It is the narrower and more uncomfortable observation that the design we are being sold optimises toward the configuration those episodes had in common. Velocity substitutes for buffers in normal conditions and cannot substitute for them under stress. Elasticity in a stream world is therefore more dependent on the central bank rather than less, because the private buffer stock has been optimised away by exactly the efficiency the architecture delivers. A further consequence follows, and the stream argument presents it as a benefit. Collateral quality assessed continuously is procyclicality with the heterogeneity removed, and the mechanism is not the obvious one. Margin spirals are not caused by slow valuation. Institutional markets already mark at least daily, cleared markets already issue intraday calls, and the 2020 dash for cash and the 2022 liability-driven investment episode were driven by leverage, forced selling, haircut dynamics and funding constraints rather than by how often anyone revalued. The risk continuous assessment introduces is not speed but synchronisation. When many participants evaluate the same continuously published collateral state under machine-executed policy, procyclical demands can become less staggered by heterogeneous valuation timing, differing internal models and human sequencing. That is related to the correlated atomic-drawdown mechanism described above, and the two can compound: a shared deterioration signal may trigger both collateral calls and funding draws within the same compressed interval. Efficiency and stability are moving in opposite directions here, and both belong on the same slide. Intellectual honesty requires naming where the burden of pre-funding is genuinely reduced, because there is such a case and it is growing. Where both legs sit on the same ledger and the counterparty already holds both, the burden falls sharply: intraday sweeps within one institution, collateral substitution within one custodian, tokenised fund shares settling against tokenised deposits at the same bank, repo where both legs are on one platform. Ledger unity removes the bridging problem, the settlement window and the uncertainty about whether the other side can perform. It does not remove the requirement that both assets be deliverable and unencumbered at execution, and it does nothing whatsoever about third-party rights: a pledge's effect between the parties survives regardless of which ledger the asset sits on, its effect against third parties depends on perfection and priority rules that are asset- and jurisdiction-specific, and legal recall of pledged collateral is not made instantaneous by technical co-location. Same-ledger settlement makes pre-funding materially cheaper. It does not make it disappear. The flagship deployments often cited for this are not yet examples of fully same-ledger delivery versus payment, which is the more telling fact. Franklin Templeton's platform carries the share record on the ledger while subscriptions and redemptions settle in dollars off-chain, and Broadridge's Distributed Ledger Repo tokenises the collateral leg while "settlement is made by triggering a payment on conventional payment rails rather than cash on ledger".²³,³¹ Both are single-leg deployments: asset on ledger, cash on the old rails. So the seam is not a future problem arriving when fabrics multiply. It runs straight through the middle of the two most-cited tokenisation successes in the market today, between the leg that was modernised and the leg that was not. Which gives the constraint its correct scope, and it folds neatly into this paper's central structural claim. Pre-funding is a seam cost. Inside a unified ledger it can be cheaper, because the funding leg can be composed into the transaction and recall can be fast where the asset is unencumbered. Across fabrics it is more expensive, because composing a funding leg across a boundary means paying the coordination cost of an interconnection protocol, reconciling collateral terms and aligning legal relationships rather than relying on an already integrated arrangement. That is what Canton concedes about bridges and what the BIS identifies as the price of disparate ledgers.⁷,¹⁴ The more fabrics you span, the more carefully funding and deliverability must be pre-positioned or committed. That also upgrades a prediction this paper makes twice, here and in the trust section. One possible new institution of the fabric era is not merely a netting utility. It is an intraday elasticity provider: netting, plus a committed liquidity facility, plus a collateral recall engine, operating between fabrics rather than inside one. Which is to say a central counterparty with a discount-window-like facility attached. It may form as a private, mutualised or public utility, or not form at all if an official platform absorbs the seam. The design requirement remains: any system promising cross-fabric atomic funding must identify who provides that committed liquidity and under what public-risk perimeter. And state the degradation case here rather than leaving it to the attack below, because it changes what is being built: if the settlement asset is commercial bank money, a tokenised deposit or a stablecoin rather than a claim on a central bank, then the quality of that committed facility is the quality of the provider's own balance sheet, and the institution is a very well capitalised broker rather than a clearing house with a discount window. Carstens makes the same point from the institutional side: ultimate settlement at the central bank "is made possible by the central bank's high flexibility to create liquidity through its lending to the banking system," extending in stress to the lender of last resort function.²¹ That is why credit does not dissolve and why banks do not dissolve. Tokenised central bank reserves sit at the centre of many serious blueprints because they would support the singleness of money.¹³ But the settlement-asset attack below makes the dependency explicit: if those reserves are not made available on the relevant platform, the system settles against a commercial claim and inherits its different credit and liquidity profile. Settlement risk can shrink while liquidity risk rises to meet it. And finality remains legal rather than technical, and the confusion is everywhere, so put it bluntly. Cryptographic irreversibility is not legal finality. In the European framework, finality is a carve-out from insolvency law conferred by statute on designated systems, establishing "the finality and irrevocability of transfer orders once entered, even in the event of a participant's insolvency".¹⁸ But the loose claim that a fabric has no finality without a statute is wrong, and the layered version is more useful. Legal finality is at least three separate things. A transfer can be legally effective, passing title or discharging an obligation under ordinary property, contract or account law, and that requires nobody's designation: it happens millions of times a day outside any designated system. Note the limits of that first layer, because it is the one most often over-read. Effectiveness under ordinary law is not the same as immunity, and such a transfer may still be exposed to insolvency avoidance, reversal, competing claims, sanctions or other mandatory-law constraints. It can be protected from insolvency unwinding, meaning shielded from zero-hour rules, avoidance actions and stays, and in the European framework that protection is the specific carve-out the Settlement Finality Directive confers on systems designated and notified under it, subject to the directive's own timing rules and to national implementation.⁴³ State the boundary of that proposition properly, because a universal version of it would be wrong: designation under that directive is the relevant route to that particular protection, not the only source of insolvency-related protection in every legal system, since payment-system, securities-settlement, collateral, netting, special-resolution and account-law regimes can each confer differently scoped protections. Which of them applies is determined by the governing law, the location of the intermediary and the assets, the system's rules and the participant's status, and none of that is a conflict-of-laws rule anyone can restate in a sentence. And a transfer can be protected against competing third-party claims, which depends on property law, perfection and priority rules rather than on either of the first two. Which makes the practical position sharper than the maximal claim. A fabric can achieve the first layer under existing law where the governing legal route gives the transfer effect, today, but it cannot assume that effect merely from technical design. It cannot achieve the second without a legislature, at any price, by any engineering. The industry can build effectiveness through the applicable legal route, but insolvency protection requires the legal recognition available under that route rather than merely technical design, and confusing the two is why so many pilots describe themselves as final when what they mean is irreversible. And that grant is being renegotiated now: the European Commission published a proposed Regulation on settlement finality in December 2025, repealing the Settlement Finality Directive outright rather than amending it.³⁸ The Financial Markets Law Committee's response in July 2026 is instructive for what it does and does not question. It does not dispute the concept of finality. It raises the application of insolvency protections to third-country systems registered in the European Union, and the definitions of "participant", "transfer order" and "collateral", along with the treatment of indirect participants.¹⁹ Which is the more useful signal: the contested ground is not what finality means, it is who and what falls inside its perimeter, and a composed transaction assembled from participants in several jurisdictions is a question about exactly that perimeter. Look closely at which words are contested. Participant. Transfer order. Collateral. Those are precisely the concepts programmable value redefines. When a token pool holds a claim and an agent initiates a transfer under a delegation credential, who is the participant and what is a transfer order are genuinely open legal questions. For cross-system institutional settlement, much of the outcome may be decided in the definitions section of a regulation rather than in anybody's protocol. Which carries a timeline that anyone building a business case should price in rather than hope past. The original Settlement Finality Directive took years to negotiate and years more to transpose into national law across the member states, and the Regulation now proposed to replace it is at the start of that process rather than the end. Legal change of this kind runs in years and sometimes decades, and it runs at a pace set by legislatures that have other priorities. So the strategic consequence is not that the law will eventually catch up. It is that for cross-system institutional uses of these systems, legal finality is likely to remain a binding constraint while engineering waits on the applicable legal perimeter. Design for coexistence with the old legal perimeter, because you will be living inside it for longer than any roadmap assumes. Programmable value cannot program a judge. Ten attacks on my own argument If I only make the case for this architecture, this is marketing. Here are the ten places I think it is weakest, in the order I would attack them. Nine are attacks on the supply side, asking whether the architecture, the law and the economics work. The tenth asks something the other nine take for granted, which is whether anybody wants the product. Privacy and transaction-level compliance may not both be satisfiable, and I have been selling them as complements. This is the one I would lead with against myself, and it lands at the intersection of two claims I have made confidently. I have argued that sub-transaction privacy from market participants is a requirement the law imposes on any institutional environment rather than a feature it chooses, and I have argued that supervision becomes subscription, resting partly on observability designed so that you can see how the network is performing without seeing what anyone is doing.⁴ Both of those are about prudential supervision, which is aggregate by nature. Financial crime compliance is not aggregate. It is transactional, and national implementations can require defined parties to hold or transmit information about individual transfers. Take my own worked example, stated accurately, because the accurate version is worse than the loose one. In Canton's own delivery-versus-payment illustration, the bank sees only the cash movement and the registrar sees only the share transfer, while the buyer, the seller and the trading application see both legs.⁶ So it is not true that nobody holds the complete picture. Parties with full visibility exist by construction, and the ones who are blind by design are the Super Validators sequencing the transaction.⁷ Which relocates the problem rather than dissolving it, and the relocated version is the harder one. The question is not who can see the transaction. It is whether any party holding the full view is a regulated entity carrying the screening obligation, and whether the partial-view parties can lawfully discharge their own obligations by relying on that party's screening without receiving the underlying data. In the illustration, the parties with full sight are the trade's own principals and the application that assembled it, which is precisely the set with the weakest claim to independence. The bank carries the obligation and cannot see the asset. The registrar can see the asset and does not hold the customer relationship. Sub-transaction privacy has not hidden the transaction from everybody, it has hidden it from exactly the parties the statute makes responsible. Reliance on another party's proof is the mechanism that would have to close that gap, and reliance is a legal construct, not a cryptographic one. The direction of travel makes this harder rather than easier, though the obligation is looser than I first stated it. The FATF's June 2025 revision of Recommendation 16 tightens rather than relaxes the requirement that originator and beneficiary information travel with the transfer, and standardises what must accompany cross-border payments above one thousand dollars or euros, with changes taking effect by the end of 2030.³² But FATF Recommendations are an international standard that countries implement through their own measures, not law in themselves, and the revised explanatory note is explicit that Recommendation 16 "does not itself require real-time sanctions screening", which leaves the modality of that obligation to national law and supervision. Separately, and this is a different control that should not be merged with it, the revised note introduces beneficiary alignment checks and permits firms to satisfy them by post-validation checks, holistic ongoing monitoring, or a pre-validation mechanism such as confirmation of payee.⁵² National law and supervisory expectations may nonetheless impose defined transmission, controls and sanctions duties. So the timing and reliance constraints are set by national implementations rather than by the standard, which means they vary by jurisdiction, a complication rather than a relief for a cross-border composed transaction. What the revision does settle is attribution within its own framework: the payment chain "is considered to start with the financial institution which receives an instruction from the customer". A composed transaction assembled at runtime from several capability providers is a payment chain whose participants are determined at execution time, so the question of which party received the instruction is itself a design decision. Deciding who is responsible for what travels with it is a genuinely unsolved problem, and I have written a paper about composition without addressing it. There are three plausible answers and I do not know which wins. Selective disclosure to a compliance role, so a designated screener holds a view no commercial party has, which reintroduces a trusted third party at exactly the point the architecture was supposed to remove one. Zero-knowledge attestation of screening, where a party proves it has screened against a current list without revealing the transaction, which is technically credible but whose acceptance as a substitute for underlying data is not established in the sources reviewed. Or a policy carve-out, where privacy yields to the compliance function by design and institutional participants accept that one role sees everything. My instinct is that the third wins first, because it is the only one with legal precedent. What that costs me is worth stating precisely, because the loose version concedes too much and the precise version concedes something real. Privacy from the market survives untouched, and that is the precondition I claimed: competitors cannot see your positions, counterparties cannot infer your book, and a compliance authority holding a complete view has always coexisted with that, in every market that has ever had a supervisor. What does not survive is the architectural purity claim, that the design removes the trusted third party. It does not. It removes the commercial one and reinstates a compliance one, holding a view no market participant holds. That is a smaller concession than abandoning the precondition and a more uncomfortable one, because the paper's rhetorical energy comes from dissolving trusted intermediaries, and here one walks back in wearing a badge. The verification thesis has a rival explanation, and it is partly right. If finance's binding agent is the impossibility of cheap remote proof, why did the fund wrapper survive electronic trading? Because tax and regulatory perimeter, not verification, hold a great deal of finance's architecture in place. A collective investment vehicle is a tax conduit before it is a proof mechanism, passing income to holders without entity-level tax, and its passport regime is what makes cross-border distribution legal at all. Neither is dissolved by cheaper proof. A tokenised portfolio held directly may be operationally superior and fiscally inferior, and for most investors in most jurisdictions the fiscal difference will exceed the operational saving. So the fund survives as a fiscal and regulatory object after it stops being necessary as an operational one, and this paper's claim that it becomes a configuration parameter is about its operational rather than its legal existence. The wrapper thins into a shell. It does not disappear. Which sets the timeline too: where a binding agent is statutory rather than technological, dissolution waits on legislation. The base rate for this kind of transformation is terrible, and I have not priced it. A costly lesson available to our industry is the Australian Securities Exchange's attempt to replace CHESS with distributed ledger technology. The replacement was determined in January 2016 with an original target go-live of April 2021, delayed in March 2020, reset in October 2020 to April 2023, and in November 2022 ASX paused the project to revisit the solution design, derecognising two hundred and forty-five to two hundred and fifty-five million Australian dollars of capitalised software pre-tax. What happened next is worse than the shorthand. ASX did not abandon the design that month; it said explicitly that the charge "does not prevent us from using parts of what we have already built". A year later, in November 2023, it completed its reassessment and chose a product-based solution from an external technology provider instead. In August 2024 the corporate regulator commenced Federal Court proceedings alleging misleading statements about the project's progress, with ASIC's chair saying: "We believe this was a collective failure by the ASX Board and senior executives at the time."²⁷ A seven-year round trip ending in somebody else's product is a worse base rate than a clean failure would have been, because it burned the option value as well as the capital. Two things follow, and both cut against me. First, the architecture being right is not sufficient, because CHESS replacement failed on migration, coexistence with legacy systems, and the governance of a market infrastructure that could not be taken offline for a weekend, none of which appear in any five-layer diagram. Second, my Coase argument implies incumbents should be the natural builders of the seam, and here the incumbent with the strongest incentive, a clean mandate and full control of both sides of the seam still failed. Where this paper says a thing will happen because the economics require it, read a delay of five to ten years and a probability meaningfully below one. The consolidation scenario is at least as plausible as the bifurcation, and it fits the regulatory grain better. I argue the middle empties. The opposite case is stronger than I made it sound. Compliance with tokenisation regimes, credential schema authorship, ontology governance participation and inter-fabric liquidity provision all have high fixed costs and near-zero marginal costs, which is the classic recipe for scale advantage rather than for a thousand small composers. Regulators, meanwhile, prefer a small number of supervisable entities to a diffuse population of them, and every crisis in living memory has ended in more concentration rather than less. The most likely near-term outcome may therefore not be a bimodal distribution but an oligopoly of four or five global fabric operators, each running the seam for its own bloc, with the small composers operating inside their perimeters rather than as independent firms. So state both as scenarios rather than pretending one is a forecast, because the mechanism is identical in each and only the capture differs. In the bifurcation case, composers multi-home across fabrics, capability manufacturers sell to all of them, and the middle is squeezed out. In the consolidation case, composers exist in large numbers but operate inside a fabric operator's perimeter, and the operator takes a share of every composition through pricing, listing and conformance rather than by prohibiting anyone. Note how uncomfortable the second is: it is not that composers are forbidden, it is that they flourish as taxed tenants. Aggregation arrives as landlord rather than as monopolist, which is the app store outcome, and it is fully compatible with a thriving population of small firms. Which means my original discriminating test was wrong, and the reason matters, because the wrong test is the intuitive one. Asking whether a composer can operate without a licence tells you nothing: a fabric operator can welcome unlicensed composers and still capture the surplus through fees. The observable that actually separates the scenarios is portability and multi-homing. Watch whether a composer can move its credentials, its reputation and its customer relationships from one fabric to another at low cost, and whether meaningful volumes of composers genuinely operate across more than one. If they can and they do, the middle is squeezed and the barbell forms. If switching is technically possible but economically punitive, consolidation has already happened regardless of how open the protocols look. A supporting indicator sits one layer down: watch whether schemas are published under open licences with no conformance gate, which is necessary for bifurcation without being sufficient, since an incumbent consortium may happily open-source the semantics while capturing the rent at execution and liquidity. One caveat on the test itself, because it has a blind spot worth admitting. Portability separates the scenarios only while more than one fabric is worth porting to. If liquidity concentrates so heavily on a single fabric that leaving is technically trivial and commercially absurd, you get consolidation with perfect portability, which is roughly the history of electronic mail: an open, portable protocol that consolidated around a handful of providers anyway. Which is why the test is stated as observed multi-homing in volume rather than as the mere existence of an exit. The aggregation risk relocates; it does not vanish. A discovery service answering queries across all catalogues occupies exactly the structural position of an Aggregator: zero marginal cost of serving, demand-side network effects, control of the point where demand meets supply. Building it on open protocols does not prevent one discovery service becoming the one everybody queries. Google was built on open protocols, and the openness of HTTP did not distribute search rents. The honest claim is narrower than the rhetoric: open protocols make the aggregator contestable and switchable rather than absent. Real, worthwhile, and smaller than the movement's language implies. Permissionless is aspirational precisely where the money is. The open fabric's second principle is permissionless, with governance about conduct rather than gatekeeping.⁴ Canton, where institutional flow is developing, operates a light-touch approval process run by its Foundation because demand has been high, with stated intent to lift it by governance proposal.⁷ The Foundation's own membership list runs in Premier, General and Associate tiers, includes DTCC, Euroclear, HSBC, Goldman Sachs, BNY, BNP Paribas, Broadridge, Moody's and Tradeweb, and names the Hong Kong Monetary Authority as an Associate member.⁵⁴ That last entry is the one worth pausing on: a monetary authority has taken a seat at the table, at the Associate tier, which is participation rather than control and is still remarkable, and it is a fact taken from the Foundation rather than from any operator's description of it. Not hypocrisy: it is what makes the network usable for regulated flow, and it is the no-choice condition working in incumbents' favour. But the accurate description of the present is that the institutional fabric is a governed club running on an open-source codebase, and the open fabric is a permissionless commons whose institutional adoption is still ahead of it. Anyone claiming the open outcome is already won is reading a roadmap in the present tense. Anyone claiming institutions will not move is ignoring the reported transaction volume, which remains a single-operator disclosure rather than an independent measure of market adoption. The ontology is where the next durable position forms, though not as a monopoly. Argued above, and it is the objection I find hardest to dismiss. Note the correction made there: the evidence says the schema gets given away, so what forms is a consortium or regulated utility whose members author meaning to suit the assets they already hold. That is a harder problem than monopoly pricing, because with nothing to price, supervision has to attach to governance, methodology and conflicts rather than to fees, which is the benchmark administrator problem wearing new clothes, and nobody has yet been designated to run it for schemas. The attack that would defeat the prediction outright is the one I cannot rule out: if semantic standards converge on a public or regulator-authored layer, or translation between schemas stays cheap, or multi-homing is routine, then meaning is necessary without being appropriable, the surplus dissipates, and the ontology position stops being a position at all. Netting gets worse before anyone fixes it. Composed, per-event liquidity sourcing can multiply the number of independently settling legs. The fabric's answer, atomic primitives plus a federation protocol, is a coordination mechanism and not a liquidity-saving one. BIS said the same in 2020: tokenisation "is likely to result in more trades settling via DvP model 1, as netting is in general more complex in a decentralised environment," and "if each tokenised securities ledger had its own cash token, then the need to hold cash tokens on several ledgers could increase aggregate liquidity requirements".¹⁴ Netting may need to be deliberately re-bundled as a service, but the four conditions do not yet establish who captures that function. A public platform, a mutual utility, a bilateral arrangement or a private operator could do so, and the settlement-asset attack identifies a further constraint. The falsifiable prediction is narrower: if cross-fabric volumes create sustained liquidity pressure and no official platform absorbs the function, an inter-fabric netting and elasticity utility becomes a plausible institutional response. It may look uncomfortably like a clearing house with a discount-window-like facility. That would not be a contradiction. It would be the function reappearing where its coordination cost becomes binding. The settlement asset may never arrive, and several claims above assume it does. This is the attack that goes underneath every supply-side claim above, so it belongs immediately before the demand-side attack that closes the set. Every atomic settlement claim in this paper rests on there being a settlement asset on the fabric that participants will accept for settlement, with a defined legal effect. Many blueprints assume tokenised central bank reserves. No public commitment by a major central bank to issue reserves onto a third-party platform at scale is identified in the sources used here, and wholesale central bank digital currency work remains at pilot or experimental stage in the participants' own descriptions. Project Agorá is a BIS Innovation Hub project that tests the desirability, feasibility and viability of a shared programmable platform; the BIS describes Innovation Hub projects generally as experimental in nature.²⁸ Assume the reserves do not arrive on anybody's fabric for a decade, which is the base case a sceptic should hold. Then every atom settles in commercial bank money, tokenised deposits or a stablecoin, which means every atomic settlement carries the credit risk of its issuer, and the singleness of money the blueprints care about is preserved by contract and supervision rather than by architecture. Three consequences follow, and they are not small. The principal-risk benefit of atomic delivery versus payment survives, because that benefit comes from making the two legs conditional on each other. What shrinks is the overall risk transformation, because the cash leg then retains the issuer credit, liquidity, convertibility and insolvency risk of commercial bank money rather than being a claim on a central bank. The intraday elasticity provider I predict becomes considerably harder to build, since the quality of its facility is the quality of its own balance sheet rather than a central bank line, which is the difference between a clearing house with a discount window and a very well capitalised broker. And my own run argument turns against the settlement asset itself, because a continuously observable claim on a commercial issuer, held by agents with published thresholds, is precisely the instrument this paper has just described as a run technology. The counterargument I would offer is that the pattern is already partly resolved in practice, since tokenised deposits at a single institution settle against that institution's own liability today and are accepted, and that supervisory arrangements for the singleness of money are ordinary regulatory work rather than novel architecture. But this attack is not answered by anything in my argument. It is answered, if at all, by central banks, on their timetable, and it is the reason a business case built on atomic settlement should state which settlement asset it assumes and what the case looks like without it. Thirty years of revealed preference ran toward standardisation, and this paper has been assuming demand for variation. Every attack above is a supply-side attack. This one is a demand-side attack, and it is the one a sceptic should lead with, because it uses my own evidence base against my own conclusion. The bespoke outcomes argument holds that when the marginal cost of valid, governed variation falls far enough, variation becomes the normal product. Set against that, one of the largest product migrations in modern asset management ran the other way. The index share of long-term mutual fund and ETF net assets in the United States rose from 19 percent at the end of 2010 to 51 percent at the end of 2024.⁵⁶ Average equity mutual fund expense ratios fell 60 percent between 1996 and 2023, and the no-load share of gross sales rose from 46 percent in 2000 to 92 percent in 2023.⁵⁷ Given the available choice set, investors moved at enormous scale toward low-cost standardised products, for three decades, with their own money. That is consistent with a strong preference for standardisation, and it does not isolate standardisation from price, performance, transparency, tax efficiency, retirement-plan defaults or changes in distribution and fiduciary practice, all of which moved in the same direction over the same period. Bespoke portfolios existed throughout, largely at price points and account minimums that prevented them from testing mass-market demand for low-cost governed variation. Worse, the paper's own framework predicts a penalty rather than a benefit. A bespoke instrument is one whose terms encode a specific client's context, and context that does not travel is value that cannot easily be resold. Bespoke over-the-counter structured products illustrate the mechanism: lacking active secondary quotes, an early exit is priced at a discount to theoretical value. Comparability, transferability and liquidity are properties of standardisation, and this paper has spent its length arguing that programmable value makes claims more transferable while simultaneously arguing for products designed to be less so. The reconciliation is available, and it costs the strong form of the claim rather than the whole of it. The two trends run in different segments, separated by a variable this paper already carries: whether the client's context is the source of the value. Mass-market beta exposure has no client-specific context, so it standardises, commoditises, and should. That is the migration the data records. But where context is irreducible, demand for variation is measurable and growing: direct indexing, which is precisely the sale of tax lots, concentrated-position management and restricted-stock handling that a pooled fund cannot express, was forecast in 2022 to grow at 12.3 percent a year to 825 billion dollars by the close of 2026, attributed by that research to demand for customisation and differentiation.⁵⁸ Mark that datum honestly, because it is the softest in this attack: it is a four-year-old vendor-sponsored forecast for a period now almost elapsed, cited because the realised figure is not yet published, and it should be replaced by the outturn when it is. Separately managed accounts, structured solutions and outsourced chief investment officer mandates all contain a context-dependent outcome component, though what else they sell, delegated governance and manager selection in one case, engineered exposure and issuer credit in another, is not economically identical. Which is the same barbell the issuance section predicts, the middle vulnerable and both ends able to thrive, arriving here from the demand side rather than from the cost of manufacture. So the honest statement is narrower and testable. Programmable value lowers the cost of variation; it does not create the demand for it, and where context is not the source of value the correct outcome is a cheaper standard product rather than a tailored one. The bespoke thesis applies where the client's context is irreducible and the liquidity discount is worth paying, which is a real and growing segment rather than the whole market. Two observable tests would settle it: whether the customised segment continues to grow faster than the standardised one at comparable price points, and whether tokenisation narrows the liquidity discount on non-standard instruments, since programmable transferability is the one mechanism that could make variation cheap without making it illiquid. If the discount does not narrow, standardisation keeps winning for good reasons and the bespoke thesis stays a wealth and institutional story rather than a market-structure one. Does this strengthen the bespoke outcomes thesis? Yes, but not for the reason we have been arguing The Bespoke Outcomes Economy currently argues from architecture: five layers, domain-invariance, intent engines that understand what is needed and execution infrastructure that composes capabilities to deliver it. That is correct and assertive. What this lens supplies is what an architectural argument structurally cannot supply for itself: an economic mechanism, and a theoretical warrant external to the architecture itself. It explains a condition under which the shift becomes economically compelling rather than merely chosen. Rents sit on whichever step is the bottleneck, and when a bottleneck falls the surplus may relocate to whatever remains scarce or dissipate where nobody can appropriate it. Where risk-adjusted composition cost falls far enough, context becomes relatively more valuable because it cannot be transferred cheaply from elsewhere. Which reframes the entire history: standardisation of the product was often a response to the cost of composition. The average-denominator product existed because assembling a hundred capabilities per customer was prohibitively expensive, and its advantage was avoiding a cost that can now fall in some activities rather than in all of them. But standardisation does not disappear, and saying that it does would be the weaker claim as well as the wrong one. It descends. Bespoke outcomes are only assemblable if the things being assembled are rigorously standardised, so the standards move down a layer, from the finished product into the primitives, the interfaces, the evidence formats and the liability terms. And they get more demanding rather than less, because a product assembled once by a human can tolerate ambiguity that a product assembled a million times by machines cannot. So the correct statement of the shift is not from standardisation to variation. It is that standardisation descends into the substrate while variation expands above it, which is why the credential schema and the ontology matter so much in this argument, and why the firms that win the composable layer will be the ones that were most disciplined about standards rather than least. The bespoke outcome is not a nicer product. It is what a product becomes when the marginal cost of valid, governed variation falls far enough that serving one client is no dearer than serving all of them. One boundary on that claim belongs here rather than only in the attack that raises it. Falling cost of variation is a supply condition, and it does not establish demand. Thirty years of revealed preference in asset management ran toward cheaper standardised products, which is the tenth attack above, and the reconciliation is that the two run in different segments: where the client's context is not the source of the value, the correct answer is a cheaper standard product, and the bespoke case holds where context is irreducible and worth its liquidity penalty. It converts composability from a design principle into a market structure prediction. Under the bifurcation scenario, abundance can favour market-making over ownership, and the thesis picks out two commercially important candidates from the larger set of seven durable functions: the intent surface over capabilities, and the semantic authority that makes composition meaningful. Either becomes a profitable position only where appropriation holds. That is exactly the division the thesis already draws, where layers one to four are the infrastructure commons and layer five with the HelixTwin is the local moat.¹⁰ Two arguments built on entirely different premises, one from the economics of Internet bundling and one from the architecture of resource allocation, arrive at the same boundary. I should be plain that both arguments pass through the same author, so this is not independent corroboration in the way a third party's replication would be. What it is, is a consistency check between two bodies of reasoning that were built for different purposes and did not have to agree. That is weaker than convergence and stronger than assertion, and it should be said in those terms rather than dressed up. It supplies a better answer to the thesis's most serious objection. The strongest counter is Aggregation Theory: platforms with direct consumer relationships and zero marginal serving cost tend to monopolise, so why would contextualisation not be absorbed by whoever aggregates demand? The current answer is generative rather than extractive network effects,¹⁰ structurally sound and purely theoretical. The better answer is a property of the input itself. Client-specific financial context is structurally expensive to scrape. Much of it is tacit, proprietary, legally restricted or bound to specific bilateral relationships, which means the most valuable part of it cannot be acquired remotely at zero marginal cost by anyone running a crawler. Plenty of financial data is remotely acquirable, including filings, disclosures, prices and positions published under reporting regimes, and this paper's own supervision-by-subscription argument depends on exactly that. The claim is about the client-specific residue rather than about financial data in general. To hold the context that produces a differentiated outcome you have to be present in the jurisdiction, hold the relationship, carry the permissions and operate inside the client's privacy boundary. Aggregation Theory works where supply can be indexed without permission. Where the valuable input is legally fenced and relationship-bound, the aggregator cannot assemble it at zero marginal cost, and the outcome layer stays distributed for a reason that has nothing to do with anyone's preference. That argument is worth more than the analogy I used to make instead, which pointed the wrong way. Data scale beating data purity in large language models did not decentralise anything: it concentrated capability in whoever could afford the compute and ingest the whole web. Anyone applying that lesson to financial context should predict consolidation, not distribution. The reason finance differs is not that messy data wins. It is that this particular messy data cannot be taken. And one genuine amendment rather than a restatement. The Coase Collapse argument holds that AI collapses coordination costs, the fabric collapses transaction costs, and hyper-local ontology demands smallness, so the firm shrinks toward the minimum unit that can hold a coherent local ontology.⁹ The direction is right and the shape is wrong. Coase's logic is two-sided, since the same technology that lowers the cost of organising internally also lowers the cost of buying in the market. Read through Thompson's gloss, that produces a bifurcation rather than a collapse: massive market makers at one end, a plethora of small actors at the other, and the middle squeezed.¹ The barbell is an inference from that reading rather than a result in Coase, who supplies the comparative statics and no distributional shape at all. Under the bifurcation scenario, the distribution is bimodal with a hole in the middle, and the hole can sit where many existing financial institutions are. The composer taxonomy explains why in operational rather than statistical terms: the squeezed middle is the un-composable middle, holding capabilities it neither manufactures at sufficient scale to be composed by strangers nor composes with sufficient local context to produce a differentiated outcome. Too small to be a capability manufacturer, too generic to be an outcome producer, unwilling to be an allocator because that requires taking positions. Under the consolidation scenario set out in the attacks section, those same firms may instead become tenants inside a small number of fabric operators. Either outcome is uncomfortable for the mid-tier universal bank, the mid-tier asset manager, the regional custodian and the sub-scale exchange, but neither is a forecast this paper has earned. Why programmable value is a different category from programmable information The Internet made information programmable. Once information was programmable, every industry whose product was information got restructured, and the industries whose product was proof of a claim did not. Programmable value is a different category of change, and the difference is precise. Information is a description of the world. Value is a claim on it. Making descriptions programmable changes who is able to speak. Making claims programmable changes who is able to act. Those are not the same magnitude, and pretending they are is why so much digital assets commentary reads like a description of a slightly better payments rail. When information became programmable, we got software that could describe anything. When value becomes programmable, we get software that can represent claims, initiate authorised acts, record obligations, enforce permissions and trigger settlement conditions. A programme that controls those representations is not merely a back-office tool. It is an operational participant, and every act with legal effect still lands on somebody who can be answerable for it. Which somebody depends on the activity and the jurisdiction rather than on the software: the issuer, the system operator, an administrator, a participant, a principal acting through an agent, a custodian, a designated system, an outsourced service provider or another regulated entity. Software does not become a legal person or a licensed intermediary merely by controlling representations, and it does not by itself pull an activity inside a licensing perimeter. What it does is put pressure on every mechanism through which responsibility is allocated: licensing scope, outsourcing and delegation rules, governance and incident obligations, investor and consumer protection duties, and supervisory access. Which is why agent-native matters, and it has nothing to do with efficiency. Programmable value plus an agent holding its own identity, its own scoped delegation credential and its own account⁸ produces a non-human operational participant in the financial system. Not a tool operated by a person, and not a legal actor either, since the paragraphs below are unambiguous that every act lands on a principal. The novelty is operational rather than jurisprudential: software can now hold an account, control representations about itself and initiate authorised acts without a human in the loop for each one, where the applicable system and legal framework permit it. Finance makes the question unusually consequential because claims, obligations and delegated authority live there. Standing is a term of art here, meaning the entitlement to invoke a court's jurisdiction, and using it loosely invites a lawyer to dismiss the whole argument. Three distinct concepts are in play. Legal personality is recognition as a subject of law. Capacity is the ability to hold rights and enter binding obligations. Attribution is whose act, in law, the machine's act is. And the law is not confused about any of them. In legal systems with applicable agency and electronic-agent rules, software need not have personality of its own to bind a principal, because its acts can be attributed to a principal who has capacity. An agent under a delegation credential is operationally autonomous, meaning it is not a manually operated tool, and can be legally attributed to a principal with a balance sheet. The precise allocation of liability remains jurisdiction- and fact-specific. So the interesting fact is not a legal vacuum. It is the opposite, and the opposite is worse. If the law were baffled by autonomous software, an institution might hope to argue that a rogue process broke the chain of liability. In legal systems with applicable attribution rules, the law can look through a machine executing continuous, economically consequential decisions and attribute its authorised acts to a principal. That can place exposure on the principal's balance sheet at a scale its supervisory capacity cannot match. The gap is not between economic and legal standing. It is that execution scales at machine speed, liability can scale with it by attribution, and supervisory capacity scales more slowly and becomes the binding constraint. Economic footprint is compounding. The capacity of a governor to know what its agents did, why, and whether it can answer for it, is not. That is not a legal-recognition problem awaiting a statute. It is an unsupervisable agency problem arriving now, and it is the sharpest possible argument for why answerability is the moat that matters. And the historical parallel is stronger for that, not weaker. Legal personality for the limited company was not achieved technically or discovered economically. It was conferred by statute, deliberately, after decades of argument about whether it should be, and it reorganised capitalism once it existed. The question for the next decade is not whether software will become an economic participant, because it already has. It is whether legislatures will confer anything on it, and what breaks in the interval while they do not. That is the deepest reason treating this as a technology programme is a category error. A technology programme asks how to do the existing thing faster. What is actually happening is that the operational set of systems capable of initiating actions on economic claims is expanding, while the legal set of entities answerable for those acts may not expand with it. The institutions arguing about settlement latency have not put it on the agenda. The bridge back Backcasting from that structure produces a short list. None of these actions requires a moonshot, and none requires a change in regulation to begin, which is a deliberately narrow claim: the architecture's completion depends on statutory change this paper has named at length, including settlement finality, the legal status of agents and cross-fabric recognition, but nothing on this list waits for any of it. Most of what follows is no-regret, meaning it pays under every scenario in the self-critique above, including the one where consolidation beats bifurcation and the one where this all takes a decade longer than I think. Two items are contingent bets, and they are marked as such with the trigger to watch, because advice that hides its own scenario dependency is not advice. Work out what you sell: transmission, verification of statements, or verification of claims. If you sell transmission, the Internet has already compressed much of your economics. If you verify statements, the Internet has already repriced much of that work. If you verify claims, you are in the beaker now. Most institutions have never asked the question in these terms and will find the answer clarifying and unpleasant. Audit your seven costs, not your technology stack. For every activity performed internally, name which of Coase's costs justified internalising it, then ask whether discovery, credentials, policy-as-code, audit anchoring or agent orchestration has already lowered that cost in the market. Where the answer is yes, test whether the risk-adjusted external cost is now below the internal coordination cost rather than assuming it is. Build the layer above the substrate you have already paid for. If your digital assets programme is predominantly a settlement programme, you have finished the part your engineers knew how to finish, and the honest question is not whether that was wasted, because it was not, but whether anything sits on top of it. The under-attacked work is credential schemas, machine-executable policy, catalogue presence and audit anchoring. Less impressive in a demonstration, unattacked by a decade of spending, and a candidate value layer whose ability to earn a fee depends on adoption, scarcity, governance and holding an appropriable position under the four conditions. That is a claim about where the opportunity is rather than a guarantee of return. And apply the wedge test to whatever you choose, because it is the one that separates a programme that ships from a programme that waits: does this pay for itself if nobody else adopts it, and does it compose if they do? Many deployments that reached production passed the first half. Few were designed to pass the second, which helps explain why so many live deployments remain islands. Author a schema before you issue another instrument. Pick one asset class and write the credential schemas for provenance, custody, eligibility and audit, validated with a custodian and a compliance reviewer before widening the asset set.¹¹ That artefact is the executable spine of your prospectus for the next era, and the accountable representations still need a human signature. Separate your rules from your standards, and make the boundary auditable. Bright-line rules become signed, versioned, executable artefacts. Standards requiring judgment stay human and stay documented as such. The boundary itself is what a supervisor will inspect and a court will examine. Make your reputation portable before somebody else makes it captive. Distribution rents rest partly on reputation being captive, and signed, subject-held, verifiable track records attack that part directly. The first movers will be those currently disadvantaged by captivity. Whether the released surplus dissipates to clients or migrates to a discovery layer is the open question the distribution section named, but the captivity component is exposed either way. If you are the platform holding the hostages, the technological part of that revenue line is on borrowed time. The licensed part is not. Design for simultaneity, not instantaneity, and say so out loud. Insist on conditional settlement, resist reflexive immediacy, and understand that immediacy can reduce netting opportunities, change intraday liquidity needs and reveal information about capacity. Anyone selling all of it at once has not read the elasticity literature. Price elasticity into your business case, and compose the funding leg. Where funding cannot be composed, pre-positioning approaches a cash-in-advance constraint, and the answer is not to hope velocity absorbs it. Where a committed funding leg can be included in the atom, the stock requirement becomes a priced balance-sheet and collateral-availability requirement instead, which is a better problem and not the absence of one. So the answer is to make the funding leg part of the atomic transaction where the accounts, collateral terms and legal relationships allow it, then name who provides it and how they price machine-speed drawdown that may become highly correlated under common stress signals. Not the option to refuse: a committed facility has already sold that option, which is what makes it committed. What it prices is the possibility of being drawn on by many counterparties within a compressed interval under common stress signals, in conditions where it would least like to be. If your model does not name the intraday elasticity provider, it is not a business case, it is a demonstration. And if you are that provider, understand that you are underwriting a machine-speed drawdown distribution that can be highly correlated, which differs from an ordinary committed line even when the documentation looks similar. Ask who governs the ontology you are about to depend on, and how that body is governed and supervised. This is a potential systemic risk in the architecture and, for a few institutions, a strategic position to hold responsibly. Decide which composer you are, and resource that rather than everything. Ontology authority, intent surface, outcome producer, risk-bearing capability manufacturer, computational capability manufacturer, or dynamic resource allocator. The statutory bridge is not a commercial composer strategy: it is a public boundary within which a firm may operate under designation. Most incumbents are naturally the risk-bearing manufacturer or the allocator, because a licence, a balance sheet and answerability are what make a capability safe for strangers to compose, and allocating capital and risk across time is what they already do. Two failure modes rather than one: attempting all of them at mid-tier scale, which is the un-composable middle described above, and competing for the computational layer, where your regulatory obligations are pure cost and a hyperscaler's are zero. And run the honest test before repositioning at all. Ask, for the newly scarce function you intend to occupy, whether you will hold a structural barrier there: a chokepoint, a demand-side relationship, a licence, or capital nobody else will commit. If the answer is no, the surplus released by commoditisation will dissipate to your clients as lower prices rather than accruing to you in a new position, and the correct strategy is not repositioning. It is accepting utility economics with a cost base built for them, or exiting the activity while it still has a sale value. It is an unpopular sentence, and it may be true for more readers than the usual repositioning narrative allows. Extend the representations your organisation can responsibly support. Pick one value type your organisation cannot currently represent, capacity, entitlement, reputation, a data licence or future revenue, and model it with policy attached. Then test whether it can compose with something you already hold under the applicable legal and regulatory perimeter. Cross-type composition is one source of new instruments, and an organisational chart partitioned by the old type system can be an obstacle. Pick your side of the barbell and say it out loud. Contingent on bifurcation rather than consolidation. The trigger to watch is portability: whether composers can move credentials, reputation and customers between fabrics at low cost and whether meaningful volumes actually do. If switching is possible but punitive, consolidation has already happened, the barbell is the wrong shape, and scale is the only side. Fabric-scale market maker and utility, or differentiated specialist with genuine ontological depth. The middle is not a safe harbour. And if your strategy requires acquiring supply to make the economics work, the market has already told you what it thinks and you are proposing to pay a premium to ignore it. Stake a claim on a seam, and be clear which part of it is still open. Contingent on seams persisting. The trigger to watch is Project Agorá: if a multi-currency shared platform moves from laboratory volumes to production, it can materially reduce the seam for the flows it absorbs, and inter-fabric positioning becomes a bet against the official sector. The plumbing is contested by Agorá, by Swift and by the cross-chain protocols. None of them can create insolvency-protected finality across a boundary through engineering alone. They may operate or connect infrastructure whose transactions receive such protection under the applicable legal frameworks, but the protection must be recognised on each side. The inter-fabric position requires credibility on both sides rather than novel technology, which is the one place where incumbency is a genuine asset rather than a liability. Price machine-speed operational dependency before it prices you. Composition means depending, mid-outcome, on a capability provider you did not negotiate with and cannot replace inside the execution window. That dependency is a systems risk whether or not it meets Williamson's stricter test for hold-up. Ask, for every composed outcome your firm intends to sell, what happens when one capability fails, withdraws or reprices while the outcome is in flight; then ask separately whether relationship-specific investment creates an appropriation hazard. In both cases, decide who is answerable to the client in that second. If the answer is a service level agreement, you have a contracting answer to a systems problem. Change how the firm absorbs change, because that is a coordination cost. The distinction between treating change as medicine and treating it as food, where the first assumes stable business as usual punctuated by eighteen-month transformation programmes and the second makes continuous transformation the operating state, is usually presented as culture. It is not. It is Coase. The eighteen-month transformation programme is the organisational expression of a high internal coordination cost. Where external capabilities become cheaper and more reliable faster than the firm can absorb change, that cost becomes a structural disadvantage rather than a cultural preference. Change as food is not a slogan about resilience. It is the operating model of a firm that intends to survive where that inequality moves against it. Move your remaining moat from knowing to being answerable. Verification is being commoditised. Liability, resolvability, mandate and licence are not. Build the business that stands behind outcomes, because that is the part of trust which cannot be computed. Measure the value your agents control against your capacity to answer for it. This is the one imperative in this list addressing a problem the paper says has already arrived rather than one that is coming. Where agents act under delegated authority and their authorised actions are attributable to you, the exposure that matters is the ratio between the economic footprint your agents control and your organisation's actual ability to know what they did, why, and whether it can be defended to a regulator or a court. The sources reviewed do not identify firms publicly measuring that ratio, including among the firms most enthusiastically deploying agents. Instrument it, set a ceiling on delegation at the point where supervisory capacity stops scaling, and treat that ceiling as a risk limit rather than a technology constraint. The Internet dissolved the bundles held together by distribution, and finance walked out of that solvent intact, because its bundles were held together by proof of claims rather than proof of statements. Proof was expensive, so we built institutions to be the proof, and then mistook those institutions for the industry. Programmable value can dissolve the reconciliation bond. Credentials can dissolve the attestation bond where reliance conditions travel with the proof. Cheap per-event execution can dissolve the aggregation bond. Agents can make the reaction go to completion. What remains afterwards is not an absence of institutions but a smaller and much harder set of them: legal finality, the licence, the settlement asset if one arrives and the issuer's credit if it does not, the ontology, the seam, and somebody's willingness to extend credit before the money arrives. A meaningful part of what remains in the current fee stack is a proof substitute waiting for the solvent to reach it, and the qualifier is doing real work rather than softening the line. Fees charged for attestation and reconciliation are proof substitutes and they dissolve. Fees charged for underwriting are not: an insurance premium inside a custody fee, and the capital charge behind a guarantee, are payment for bearing a loss somebody has to bear, and no solvent has ever dissolved a loss. Fees charged for constitution are not either, since a licensed entity's cost of being answerable is the price of the licence and not the price of the proof. The paper's own taxonomy has said this throughout, so the closing line should not quietly contradict it. And then the part that matters more than the dissolution, because dissolution is only ever the first half of what a solvent does. What the fabric holds, it holds in composable form, which makes it a substrate rather than a successor. Coase's firm had two options, make or buy, and it still does. What changes is that buying stops meaning the purchase of a finished product from one supplier and starts meaning the assembly of modular capabilities at runtime, which is a lower-friction and machine-addressable spot market rather than the frictionless one economists assume. The firm boundary moves where the risk-adjusted external cost, capability price plus composition cost plus expected loss from transferred context plus residual liability, falls below the internal coordination cost it replaces. Context depth is not a commensurable price beside composition cost; it is one source of expected loss and residual liability when knowledge fails to travel. Over that substrate the value type system can expand beyond cash, securities, derivatives, collateral and credit, one legally recognised instrument class and jurisdiction at a time. Finance has always been a composition engine over a very small type system. The engineering to open that type system exists today. The legal standing, liability and classification decisions that would let it operate at scale do not, and they move at the speed of legislatures, which is the binding constraint for the whole of the period in which these systems are actually built. So the type system is not about to open. It is being opened, slowly, one instrument class and one jurisdiction at a time, by people negotiating with regulators rather than by anyone shipping code, and the composers who matter will be the ones who did the legal work early enough to be ready when a category finally admits them. Coase said in 1937 that a firm stops growing where the cost of organising one more transaction inside it equals the cost of buying that transaction in the market.²² In the activities this paper examines, discovery, proof and execution can lower parts of market transaction cost faster than institutions reduce the coordination burden of politics and accountability. Politics does not have an API. Where that differential is real, it is the strategic opportunity of the next decade, and precisely the shape of the wreckage. Where it is not, the firm remains the cheaper coordination mechanism. One caution to carry out of this paper, since it is the discipline the argument itself demands. None of that guarantees anybody a new rent. A falling cost creates a surplus, and a surplus goes to whoever holds a structural barrier, which may be nobody. The base case for many institutions is not relocation to a better position but competition down to utility economics, and the ones who will do well are those who work out early whether they hold a barrier or merely hold an incumbency. Finance is not facing a faster version of the last three decades. It is facing its own 1995, arriving thirty years late, with a regulator in the room and a machine holding the account. References [1] Thompson, Ben. XBOX Cuts; Bundling and the Internet Solvent; Transaction, Coordination, and Sunk Costs. Stratechery Update, July 8, 2026. https://stratechery.com/2026/xbox-cuts-bundling-and-the-internet-solvent-transaction-coordination-and-sunk-costs/ Supports the bundle test and Spotify case; Thompson's gloss on Coase's coordination-cost language; and the article's reproduction of reported Microsoft management-layer disclosures. [2] Thompson, Ben. The AI Unbundling. Stratechery, September 12, 2022. https://stratechery.com/2022/the-ai-unbundling/ [3] Networks for Humanity. The offerings at a glance. July 14, 2026. https://docs.nfh.global/about-nfh-offerings/readme#the-offerings-at-a-glance Design-intent documentation for the NFH Fabric and related offerings. [4] Networks for Humanity. Why do we need an open fabric? July 16, 2026. https://docs.nfh.global/nfh-fabric/open-rails.md See particularly “Proof is the hinge” and “Open”; see also Principles, July 6, 2026, for the open-protocol and agent-participation design intent. https://docs.nfh.global/nfh-fabric/principles.md [5] Woodgate, Ian. The Canton Network: A Technical Primer. Digital Asset, April 1, 2025. https://www.canton.network/blog/a-technical-primer [6] Canton. How Canton Network Delivers Institutional-Grade Privacy. August 14, 2025. https://www.canton.network/blog/how-canton-network-delivers-institutional-grade-privacy [7] Digital Asset. Myth busters: Canton Network. July 28, 2026. https://blog.digitalasset.com/blog/myth-busters-canton-network [8] Networks for Humanity. Agents as first-class participants. https://docs.nfh.global/nfh-fabric/agents [9] Tummala, Rajeev. From Uber to Everything: The Structural Reversal of Globalisation. Finternet Labs, May 2026. https://unf.neurail.io/read/bespoke-outcomes-globalisation [10] Tummala, Rajeev. The Technology Layer Specification: Agentic Interfaces, Intent Engines, and the HelixTwin. Finternet Labs. https://unf.neurail.io/read/technology-architect [11] Networks for Humanity. Securitising illiquid assets. https://docs.nfh.global/use-cases/securitise-any-asset [12] Networks for Humanity. Data marketplace for agents. https://docs.nfh.global/use-cases/agent-data-marketplace [13] Bank for International Settlements. The next-generation monetary and financial system, BIS Annual Economic Report 2025, Chapter III, June 24, 2025. https://www.bis.org/publ/arpdf/ar2025e3.htm [14] Bech, Morten Linnemann, Jenny Hancock, Tara Rice and Amber Wadsworth. On the future of securities settlement. BIS Quarterly Review, March 2020. https://www.bis.org/publ/qtrpdf/r_qt2003i.htm [15] International Swaps and Derivatives Association. ISDA Digital Regulatory Reporting. https://www.isda.org/isda-solutions-infohub/isda-digital-regulatory-reporting/ [16] Auer, Raphael. Embedded supervision: how to build regulation into decentralised finance. BIS Working Papers No 811, September 16, 2019. https://www.bis.org/publ/work811.htm [17] Lee, Michael, Antoine Martin and Benjamin Müller. What Is Atomic Settlement? Federal Reserve Bank of New York, Liberty Street Economics, November 7, 2022. https://libertystreeteconomics.newyorkfed.org/2022/11/what-is-atomic-settlement/ [18] European Parliamentary Research Service. Capital markets integration and supervision: Settlement finality, 2026. https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/785671/EPRS_BRI(2026)785671_EN.pdf [19] Financial Markets Law Committee. Settlement Finality. July 29, 2026. https://fmlc.org/publications/settlement-finality/ [20] Carstens, Agustín and Nandan Nilekani. Finternet: the financial system for the future. BIS Working Papers No 1178, April 15, 2024. https://www.bis.org/publ/work1178.htm [21] Carstens, Agustín. The value of trust. Speech at the King of Spain Prize in Economics award ceremony, Madrid, BIS, March 6, 2023. https://www.bis.org/speeches/sp230306.htm [22] Coase, R. H. The Nature of the Firm. Economica, Volume 4, Issue 16, November 1937, pages 386 to 405. https://doi.org/10.1111/j.1468-0335.1937.tb00002.x [23] Franklin Templeton. Franklin Templeton Launches Patent-Pending Intraday Yield Feature on Benji Technology Platform. June 10, 2025. https://www.franklintempleton.com/press-releases/news-room/2025/franklin-templeton-launches-patent-pending-intraday-yield-feature-on-benji-technology-platform And Franklin Templeton, Stellar Development Foundation Mark Five Years of BENJI. April 30, 2026. https://www.franklintempleton.com/press-releases/news-room/2026/franklin-templeton-stellar-development-foundation-mark-five-years-of-benji-the-first-u.s.-registered-tokenized-money-market-fund [24] Mayer, Roger C., James H. Davis and F. David Schoorman. An Integrative Model of Organizational Trust. Academy of Management Review, Volume 20, Number 3, 1995, pages 709 to 734. https://doi.org/10.5465/amr.1995.9508080335 [25] Holmström, Bengt. Understanding the role of debt in the financial system. BIS Working Papers No 479, January 2015. https://www.bis.org/publ/work479.htm [26] Williamson, Oliver E. Transaction-Cost Economics: The Governance of Contractual Relations. Journal of Law and Economics, Volume 22, Number 2, October 1979, pages 233 to 261. https://doi.org/10.1086/466942 And Williamson, Oliver E. The Economic Institutions of Capitalism. Free Press, 1985, pages 61 to 62, for the Fundamental Transformation. And Williamson, Oliver E. Comparative Economic Organization: The Analysis of Discrete Structural Alternatives. Administrative Science Quarterly, Volume 36, Number 2, June 1991, pages 269 to 296, for the hybrid mode. https://doi.org/10.2307/2393356 And Tadelis, Steven and Oliver E. Williamson, Transaction Cost Economics, in The Handbook of Organizational Economics, edited by Robert Gibbons and John Roberts, Princeton University Press, 2012, pages 159 to 192. https://faculty.haas.berkeley.edu/stadelis/tce_org_handbook_111410.pdf [27] Australian Securities Exchange. CHESS Replacement: ASX reassessing solution design, financial derecognition of intangible. Media release, November 17, 2022. https://www.asx.com.au/content/dam/asx/about/media-releases/2022/60-17-november-2022-CHESS-Replacement-ASX-reassessing-financial-derecognition_.pdf And Australian Securities and Investments Commission, ASIC sues ASX for alleged misleading statements, August 14, 2024. https://asic.gov.au/about-asic/news-centre/find-a-media-release/2024-releases/24-177mr-asic-sues-asx-for-alleged-misleading-statements/ [28] Bank for International Settlements. Project Agorá: exploring tokenisation of wholesale cross-border payments. Updated July 30, 2026. https://www.bis.org/about/bisih/topics/fmis/agora.htm [29] Swift. Swift to add blockchain-based ledger to its infrastructure stack. September 29, 2025. https://www.swift.com/news-events/press-releases/swift-add-blockchain-based-ledger-its-infrastructure-stack-groundbreaking-move-accelerate-and-scale-benefits-digital-finance [30] Canton Strategic Holdings. Exhibit 99.1, filing with the United States Securities and Exchange Commission, March 31, 2026. https://www.sec.gov/Archives/edgar/data/1861657/000149315226013823/ex99-1.htm [31] Broadridge Financial Solutions. Broadridge's DLR platform achieves 508 per cent year-over-year growth in January. 2026. https://www.broadridge.com/press-release/2026/broadridges-dlr-platform-achieves-508-percent-year-over-year-growth-in-january [32] Financial Action Task Force. FATF updates Standards on Recommendation 16 on Payment Transparency. June 18, 2025. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-Recommendation-16-payment-transparency-june-2025.html [33] Dahlman, Carl J. The Problem of Externality. Journal of Law and Economics, Volume 22, Number 1, April 1979, pages 141 to 162, for the canonical transaction-cost taxonomy. https://doi.org/10.1086/466936 And Coase, R. H. The Nature of the Firm. Economica, Volume 4, Number 16, November 1937, pages 386 to 405. https://doi.org/10.1111/j.1468-0335.1937.tb00002.x [34] Broadridge Financial Solutions. Charting a Path to a Post-Trade Utility. White paper, 2015, the origin of the seventeen to twenty-four billion dollar trade processing estimate later cited by the Bank for International Settlements. https://www.broadridge.com/_assets/pdf/broadridge-charting-a-path-to-a-post-trade-utility-white-paper.pdf [35] California Department of Financial Protection and Innovation. Order taking possession of Silicon Valley Bank, March 10, 2023, recording attempted withdrawals of approximately forty-two billion dollars on March 9 and a resulting negative cash balance of about nine hundred and fifty-eight million dollars. https://dfpi.ca.gov/wp-content/uploads/sites/337/2023/03/DFPI-Orders-Silicon-Valley-Bank.pdf And Board of Governors of the Federal Reserve System, Review of the Federal Reserve's Supervision and Regulation of Silicon Valley Bank, April 2023. https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf [36] European Central Bank. TARGET Services Annual Report 2025, reporting an average of 922,533 TARGET2-Securities transactions a day in 2025. https://www.ecb.europa.eu/press/targetservar/html/ecb.targetservar2025.en.html And European Central Bank. T2S auto-collateralisation, describing automated, fully collateralised intraday credit from an eligible party's home central bank where a settlement instruction would otherwise fail. https://www.ecb.europa.eu/pub/pdf/other/ecb.t2sautocollateralisation.202511.en.pdf [37] Bank of England. Digital Securities Sandbox Dashboard, recording that HSBC Bank plc passed through Gate 2 on 13 July 2026. https://www.bankofengland.co.uk/financial-stability/digital-securities-sandbox/digital-securities-sandbox-dashboard [38] European Commission. Proposal for a Regulation of the European Parliament and of the Council on settlement finality and repealing Directive 98/26/EC and amending Directive 2002/47/EC on financial collateral arrangements, COM(2025) 941 final, December 4, 2025. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0941 [39] Bank for International Settlements. Settlement risk in foreign exchange transactions (the Allsopp Report), Committee on Payment and Settlement Systems, March 1996, https://www.bis.org/cpmi/publ/d17.pdf and Reducing foreign exchange settlement risk: a progress report, July 1998, recording ECHO, Multinet and bilateral services including FXNET, together with the merger of ECHO and Multinet into CLS Services. https://www.bis.org/cpmi/publ/d26.pdf And Bank for International Settlements. CLS Bank starts continuous linked settlement operations, BIS Quarterly Review, December 2002. https://www.bis.org/publ/qtrpdf/r_qt0212f.pdf [40] Holmström, Bengt. Moral Hazard and Observability. Bell Journal of Economics, Volume 10, Number 1, Spring 1979, pages 74 to 91. https://doi.org/10.2307/3003320 [41] Fox, Justin. How to Succeed in Business by Bundling – and Unbundling. Harvard Business Review, June 24, 2014. Barksdale’s first-person recollection of his 1995 IPO-road-show formulation. https://hbr.org/2014/06/how-to-succeed-in-business-by-bundling-and-unbundling [42] Klein, Benjamin, Robert G. Crawford and Armen A. Alchian. Vertical Integration, Appropriable Rents, and the Competitive Contracting Process. Journal of Law and Economics, 1978. https://www.osti.gov/biblio/6411516 [43] European Parliament and Council. Directive 98/26/EC on settlement finality in payment and securities settlement systems. May 19, 1998. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31998L0026 See Article 2(a) on designation and notification of systems, and Articles 3 and 9 on the protection of transfer orders, netting and collateral in insolvency. See also European Commission, Settlement finality, https://finance.ec.europa.eu/financial-markets/financial-markets-policy/post-trade-services/settlement-finality_en [44] United States Securities and Exchange Commission. Staff Report on Equity and Options Market Structure Conditions in Early 2021, October 14, 2021, on zero-commission retail brokerage and the persistence of payment for order flow and other execution revenue. https://www.sec.gov/files/staff-report-equity-options-market-struction-conditions-early-2021.pdf [45] Investment Company Institute. Trends in the Expenses and Fees of Funds, 2018, on the long-run decline in fund expense ratios alongside the growth of indexed products. https://www.ici.org/system/files/attachments/per25-01.pdf [46] Bank for International Settlements, Markets Committee. Electronic trading in fixed income markets, January 2016, on the reconfiguration rather than removal of intermediation, price discovery and liquidity provision. https://www.bis.org/publ/mktc07.htm [47] Financial Stability Board. FinTech and market structure in financial services: Market developments and potential financial stability implications, February 14, 2019, on new entrants in payments and the largely complementary relationships with incumbent institutions. https://www.fsb.org/uploads/P140219.pdf [48] Office of the Comptroller of the Currency. Comptroller's Handbook: Custody Services, on the composition of custody and securities-services activity, including safekeeping, settlement, asset servicing, corporate actions, income and tax processing, and related control obligations. https://www.occ.treas.gov/publications-and-resources/publications/comptrollers-handbook/files/custody-services/pub-ch-custody-services.pdf [49] Basel Committee on Banking Supervision. Principles for Sound Liquidity Risk Management and Supervision, September 2008, on diversified funding, unencumbered liquid-asset buffers and tested contingency funding arrangements. https://www.bis.org/publ/bcbs144.htm [50] Securities Act of 1933, section 2(a)(11), on the conduct-based definition of "underwriter", 15 U.S.C. § 77b(a)(11). https://www.law.cornell.edu/uscode/text/15/77b And Regulation (EU) 2023/1114 on markets in crypto-assets, on the offeror's and issuer's responsibility for the crypto-asset white paper. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1114 [51] Bank for International Settlements. Electronic finance: a new perspective and challenges, BIS Papers No 7, November 2001, recording the shift toward direct matching in large liquid markets and finding that "despite the developments... that might have been expected to marginalise much of their role, dealer intermediation remains". https://www.bis.org/publ/bppdf/bispap07.pdf [52] Financial Action Task Force. Explanatory Note for Revised Recommendation 16, June 2025, on the clarification that R.16 does not itself require real-time sanctions screening, and separately on the introduction of alignment checks satisfiable by post-validation checks, holistic ongoing monitoring or pre-validation mechanisms such as confirmation of payee. https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/Explanatory%20Note%20for%20Revised%20R.16.pdf.coredownload.pdf [53] Teece, David J. Profiting from technological innovation: Implications for integration, collaboration, licensing and public policy, Research Policy 15(6), 1986, on returns to holders of specialised complementary assets. https://doi.org/10.1016/0048-7333(86)90027-2 [54] Canton Foundation. About the Foundation, publishing the Premier, General and Associate membership tiers and naming the Hong Kong Monetary Authority as an Associate member. https://canton.foundation/about-the-foundation/ [55] World Wide Web Consortium. Verifiable Credentials Data Model v2.0, W3C Recommendation, May 15, 2025: "Verifiability of a credential does not imply the truth of claims encoded therein", and on validation as the separate process by which verifiers apply their own business rules before relying on a claim. https://www.w3.org/TR/vc-data-model-2.0/ [56] Investment Company Institute. 2025 Investment Company Fact Book, 2025, on the index share of long-term mutual fund and ETF net assets rising from 19 percent at year-end 2010 to 51 percent at year-end 2024. https://www.icifactbook.org/pdf/2025-factbook.pdf [57] Investment Company Institute. Trends in the Expenses and Fees of Funds, 2023, March 2024, on average equity mutual fund expense ratios falling 60 percent between 1996 and 2023, and on no-load funds without 12b-1 fees taking 92 percent of gross sales in 2023 against 46 percent in 2000. https://www.ici.org/files/2024/per30-02.pdf [58] Cerulli Associates. The Case for Direct Indexing: Differentiation in a Competitive Marketplace, December 2022, forecasting direct indexing assets growing at a 12.3 percent five-year compound annual rate to $825 billion by the close of 2026, attributed to demand for customisation and differentiation. https://www.cerulli.com/resource/white-paper-the-case-for-direct-indexing A note on sources References 3, 4, 8, 11 and 12 are documentation of the NFH Fabric. References 9 and 10 are papers by this author. The author has a professional association with the work described in references 3, 4, 8, 11 and 12. That is seven of fifty-eight sources drawn from a single body of work, meaning about one in eight, and readers should discount accordingly: where those sources are cited for design intent, meaning what an architecture is trying to achieve, they are authoritative, because a specification is the best evidence of its own intentions. Where they might be read as evidence that something works at scale in production, they are not, and I have tried to mark the difference in the text rather than leave it to be inferred. One source has been removed since the first version of this paper, and the reason is worth stating rather than burying, because it is the standard I would want applied to anyone else. An earlier draft cited a securities services knowledge hub for the batch-to-stream framing, the fee-pool model and several supporting formulations. That source sits behind an access gate, which means no reader could check it. A citation only its author can verify is not a citation, it is an assertion wearing a footnote. Every argument that rested on it is now made in my own voice, as my own analysis, and the fee-pool model shows its arithmetic and its hidden turnover assumption instead of borrowing someone's authority for the output. Where empirical support was genuinely required, Franklin Templeton, Broadridge and the BIS carry it. Claims about live deployments rest on the operators' own disclosures, including a filing with the Securities and Exchange Commission for network volumes, and claims about settlement law, supervision and market structure rest on the BIS, the Federal Reserve Bank of New York, the Financial Markets Law Committee, the European Parliamentary Research Service, the European Commission, the Bank of England, the European Central Bank, the Securities and Exchange Commission, the Financial Stability Board, the Financial Action Task Force, ISDA, ASIC and the ASX. ## Publication Information - [Reality Permits](https://paragraph.com/@reality-permits/): Publication homepage - [All Posts](https://paragraph.com/@reality-permits/): More posts from this publication - [RSS Feed](https://api.paragraph.com/blogs/rss/@reality-permits): Subscribe to updates