In the first piece of this series, I argued that enterprise finance cannot comfortably live on radically transparent public blockchains.
The problem gets much bigger when the people making the transactions are no longer people.
Autonomous AI agents are moving from simple prompt-response systems toward economic actors. They can coordinate workflows, call external tools, negotiate resources, and execute increasingly complex tasks across organizational boundaries.
The sequence is easy to imagine.
A procurement agent identifies a shortage. Another agent requests bids. Supplier agents negotiate price and delivery terms. A treasury agent authorizes payment. A settlement agent clears the transaction.
This may require very little human involvement.
That sounds efficient.
It also creates a new kind of information-security problem.
When autonomous agents conduct commerce on transparent infrastructure, they do not merely move money.
They broadcast strategy.
A simple procurement example
Imagine two corporate agents negotiating cloud-compute capacity.
Company A’s buyer agent has been authorized to spend up to $150,000, provided delivery occurs within 24 hours.
Company B’s supplier agent has an internal floor price of $110,000 and may discount further when immediate liquidity is valuable.
In ordinary enterprise commerce, those parameters remain private.
The buyer does not reveal its maximum willingness to pay. The seller does not reveal its minimum acceptable price. The two sides negotiate until they reach terms both can accept.
Now put those agents on transparent public rails.
The buyer’s transactions, balances, escrow behavior, timing, historical purchasing patterns, and prior settlements may all become observable.
A capable counterparty may no longer need to infer urgency from the negotiation itself. It can analyze the buyer’s financial behavior.
The seller may discover that Company A routinely pays a premium when delivery windows fall below 24 hours.
A competitor may see purchases surge at a particular infrastructure provider.
The negotiation is no longer taking place between two parties.
The room has microphones.
In the machine economy, transactions are telemetry
A human procurement team generates information through emails, meetings, purchase orders, approvals, and payments. Most of it remains inside corporate systems.
Autonomous agents generate the same kind of information continuously, but in machine-readable form.
Every action can become a signal:
- which counterparties an agent approaches,
- what offers it rejects,
- how quickly it accepts revised terms,
- when it deposits funds,
- how much capital it deploys,
- which services it suddenly begins purchasing,
- and how urgently it settles.
Taken individually, those signals may look harmless.
Taken together, they can reveal the shape of an operating model.
Autonomous commerce can turn ordinary business activity into persistent, structured, machine-readable telemetry.
Once that telemetry is observable, privacy is no longer just about hiding message contents or transaction amounts. The behavior itself becomes information.
In that environment, transparency stops being an abstract blockchain characteristic.
It becomes a form of competitive intelligence.
The future attacker may not need to breach your systems.
They may simply watch your agents behave.
Intent itself becomes valuable
The leakage begins before settlement.
An agent asking for freight, compute, inventory, liquidity, or a particular asset may reveal something commercially meaningful simply by expressing the need.
Public markets already show that visible intent can have economic value. Autonomous commerce expands that problem because software can emit intent continuously, in structured form, while other machines react at the same speed.
So the privacy question is not only what gets settled publicly.
It is also what the market can learn while an agent is still trying to act.
The point is not that every observable action will be exploited.
It is that commercial intent has economic value, and autonomous agents can produce far more observable intent than human-operated systems ever did.
Privacy does not mean anonymity
Enterprises cannot simply make autonomous agents invisible.
Nor should they.
Companies need auditability. Counterparties need assurances. Risk teams need controls. Regulators may need evidence that certain requirements were satisfied.
If an agent exceeds its authority or enters an unintended execution loop, the organization must be able to reconstruct what happened.
The goal is not an untraceable black box.
The goal is selective disclosure.
Private to competitors.
Inspectable by the enterprise.
Provable to counterparties.
Disclosable to authorized regulators.
That turns privacy from a consumer preference into an architectural requirement.
The four privacy boundaries of agent commerce
I use four terms for the privacy boundaries of agent commerce: coordination privacy, compliance privacy, authority privacy, and settlement privacy.
1. Coordination privacy
Who am I talking to?
Before money moves, agents need to discover, contact, and negotiate with counterparties.
Those interactions can reveal supply relationships, strategic partners, geographic dependencies, or commercial intent.
Coordination privacy means protecting message contents, commercial intent, and the relationship and contact metadata that make up the coordination graph.
2. Compliance privacy
Do we meet this interaction’s requirements?
Two agents may need to prove that they satisfy regulatory or organizational requirements before doing business.
That does not necessarily require exposing raw identity documents, complete compliance records, or every credential associated with the organization.
Compliance privacy means proving that the parties satisfy a specific interaction’s regulatory or organizational requirements while limiting disclosure to the facts that interaction requires.
3. Authority privacy
Does this deal fall within my delegated mandate?
An autonomous agent needs machine-verifiable authority.
A company might authorize an agent to spend up to a certain amount, within a specific category, before a deadline, and only with approved counterparties.
Authority privacy means proving that an agent’s proposed action falls within its delegated mandate without revealing the full mandate.
The seller does not necessarily need to know the agent’s full spending ceiling, remaining budget, internal approval structure, or every other authority the agent possesses.
In human terms, the agent needs something resembling a cryptographic power of attorney.
4. Settlement privacy
Can we verify the exchange without publishing the deal?
Settlement privacy means exchanging value verifiably without unnecessarily exposing the parties, amounts, timing, or transaction graph.
The system must also preserve basic enterprise requirements: clear ownership, reliable finality, enforceable authorization, and an audit path for designated parties.
These four boundaries can overlap within one interaction, but they are not the same problem.
Treating privacy as a single on/off switch misses that distinction.
A useful architecture must decide what needs to remain confidential at each boundary, what must be provable, and to whom.
There is a second risk hiding inside the solution
Cryptographic authority, credentials, compliance predicates, and machine-verifiable eligibility introduce another danger.
A system can protect agents from public surveillance while still becoming highly permissioned.
A proof may be technically voluntary, yet economically unavoidable if every major counterparty demands it.
A credential ecosystem may be formally pluralistic, yet converge on a small number of issuers through network effects.
A scoped pseudonym may protect against global identity linkage, yet become a durable tracking identifier inside the relationships that matter most.
So the design question is not simply:
How do we make machine commerce private?
It is also:
How do we make it private without quietly making participation conditional on an expanding stack of cryptographic permissions?
That question will matter more as the infrastructure becomes successful, not less.
Why this matters beyond crypto
It would be easy to frame this as a blockchain privacy problem.
I think that is too narrow.
The larger issue is how autonomous economic actors exercise authority across organizational boundaries.
As agents become capable of negotiating, spending, contracting, and settling without continuous human supervision, companies will need infrastructure that answers some very old questions in very new ways:
Who authorized this?
What is the agent allowed to reveal?
What can the counterparty verify?
What must remain confidential?
Who can audit the transaction later?
And increasingly:
Who gets excluded if the wrong credential becomes mandatory?
Those are enterprise-governance questions.
Blockchains, zero-knowledge proofs, private execution environments, and cryptographic credentials are interesting because they may provide new answers without recreating the same centralized trust dependencies we already know.
But they also create new ways to encode power.
Where the series goes next
The four privacy boundaries help us evaluate emerging systems for autonomous commerce.
The next article turns from the information agents expose to what adversaries can learn and exploit. From there, the series examines private authority, compliance, and settlement, before turning to safeguards and their social limits.
The specific technologies will change.
The underlying requirement will not.
If autonomous agents become economic actors, enterprises will need a way for them to transact without turning every commercial decision into public telemetry.
And if we solve that problem badly, we may simply exchange one surveillance architecture for another form of control.
That leaves the central question:
If your competitors can watch your AI agents negotiate in real time, is the system actually private enough for enterprise use?
Disclosure: I am an active contributor to open-source zero-knowledge agent protocols, including work involving Aztec, ZKA, ZKM, ZKC, and AFP. My focus is on making confidential machine-to-machine commerce practical, which naturally shapes my view on the importance of these architectural rails.