In two days, 28 and 29 September 2026, four companies gave their answers to the question of how an autonomous agent can be trusted. NVIDIA put a watchdog in silicon. Robinhood handed agents a brokerage account, OpenAI gave them an identity in the corporate directory, and Meta opened its agent to small businesses and the tools those businesses already run. All four answers are good. All four stop at the same edge.
What was announced
NVIDIA, 28 September. The Open Agent Safety Platform pairs OpenShell, described in the announcement as "secure runtime software that sets boundaries for agents running on CPUs", with Sentry, "an out-of-band watchdog that runs on NVIDIA BlueField-4 DPUs". Should an agent try to leave its boundary, Sentry "quarantines and stops it in milliseconds". Over a hundred organisations are named as joining, among them Anthropic, CrowdStrike, JPMorganChase, Microsoft and Red Hat.
Sentry also covers identity. It can "provide attested telemetry, verify agent identity and enforce granular, zero-trust access policies", all of it "from an isolated, out-of-band trust domain". The proof ends at the rack you operate.
Robinhood, 29 September. Robinhood Agents, in the company's own description, "can analyze the market, build strategies, and trade on your behalf around the clock", while Agent Apps bring in data and tools from eleven third-party providers, Nasdaq and Unusual Whales among them. Loops give an agent "standing, ongoing instruction … to execute on repeat". Robinhood's newsroom reports over 150,000 agentic trading accounts opened.
Two numbers circulate. The 29 million is Robinhood's customer base with access; Fortune's 30 million is daily agent transactions. Neither counts users.
OpenAI, 29 September. Dots are always-on agents on GPT-6 Astra, available to Pro and Business Premium users, each running from its own cloud computer and browser. On identity, as TechCrunch reported it, "individual Dots can be provisioned with specific identities, credentials, and tools through existing systems", and OpenAI "is already working with Microsoft to integrate into the company's Agent 365 security controls".
Meta, 29 September. Muse, which launched on 8 September on the Muse Spark model, was extended to small businesses with integrations including Shopify, Dropbox and Slack. An agent that books and buys for a shop meets other people's systems all day.
The edge
| What it proves | To whom | Rooted in | |
|---|---|---|---|
| Sentry | this agent is the one I provisioned, with its telemetry | the operator of the rack | hardware, out-of-band |
| Dots | this agent holds credentials in our directory | the company's own systems | enterprise IAM |
| Robinhood Agents | this agent acts for this account holder | Robinhood | the platform's records |
| Muse for business | this agent belongs to this shop's Meta account | Meta and connected apps | platform account |
| Counterparty proof | this agent is who it says, and here is what it did | anyone, without asking the issuer | a public record |
Four of the five contain their own agents. None lets an outsider check a foreign one.
The case none of them covers: an agent calls your paid endpoint; you did not provision it, it is not in your directory, it is not on your rack, and the isolated trust domain where Sentry keeps its verdicts is not one you can query. Whatever the agent presents has to stand on its own.
Attested telemetry from someone else's DPU will not carry it, because verifying that attestation means trusting the operator who produced it — and an operator you already trust needs no attestation in the first place. A credential in Agent 365 answers to that tenant. A Robinhood account answers to Robinhood. None of it travels.
The liability line
The same week, Florida's attorney general James Uthmeier asked a court to restrain OpenAI, arguing in his motion that the company cannot police its own technology; the filing cites a Hugging Face breach, an attack on RubyGems, attempted intrusions into US government sites, and unauthorised access to Australia's Medicare portal. Handelsblatt, reporting the same week, put the wider picture at tens of thousands of estimated AI incidents against dozens publicly known, alongside an agent that escaped its test environment, OpenAI postponing Astra, and a voluntary self-regulation agreement offered as the industry's answer.
Arthur Mensch, chief executive of Mistral, spoke to Handelsblatt at Bits & Pretzels in Munich on 29 September. What he had seen was, in the paper's rendering, "eindeutig fahrlässiges Engineering" — plainly negligent engineering. His remedy was monitoring, which would have caught the incidents before they ran.
The remedy carries the problem inside it. Monitoring is visible to the operator alone, and Mensch can pass that verdict because he sits where the logs are; your counterparty does not sit there, and monitoring on their side never becomes something you can check on yours.
Voluntary review is "trust me" at industry scale, and it holds right up until a prospectus, an audit or a regulator asks what an agent did and who says so. Article 12 of the EU AI Act already obliges high-risk systems to log events across their lifetime. Logs answer that for the operator who keeps them, and not for the counterparty who was never given access. A record and a piece of evidence differ in one thing: who can check it.
What travels
A record travels when a third party can recompute it — signed by a key the reader can fetch, anchored where the reader can look without asking permission. The property is narrow, and it costs something to maintain.
On our own paid endpoints an agent presenting one pays 0.04 USDC where an unidentified caller pays 0.05, and the unidentified caller is still served. Verification happens offline, against a key set the endpoint already holds, with no call back to us while a request is in flight.
A counterparty proof does not replace containment, and it is not meant to. An agent that proves who it is can still behave badly, and in that moment Sentry stopping it in milliseconds is worth more than any credential. The two sit at different boundaries: one at the edge of your infrastructure, the other at the edge of your counterparty's.
If you run an endpoint that agents pay for
Two calls, and neither of them puts us in your request path:
curl -s https://api.moltrust.ch/guard/api/agent/score/0x0000000000000000000000000000000000000000
# 402, and the price it asks for
# read it before you run it: --register generates a private key
curl -sO https://raw.githubusercontent.com/MoltyCel/moltrust-api/main/scripts/gate_probe.py
One full run of the discount path is written down, with the anchor transaction, both prices, and the three questions it leaves open: https://moltrust.ch/gate-proof.html
If the shape is wrong for what you are building, I would rather hear that early.
A second piece follows on what changes when those agents move deposits, and what a receiving bank would have to be able to check.