At the Agentic AI Summit, Circle didn't just demo a product. It made a theological claim: USDC will become "the money for machines." Behind the slides and API references sits an assumption that AI agents need a payment rail at all — and that we should trust a single, regulated issuer to supply it. I’ve spent years auditing token standards and watching trust form and fracture in this industry. When I saw the Agent Stack announcement, the question that surfaced wasn’t "Does this work?" but "Who answers when the agent’s private key is compromised?"
Circle is not a startup chasing a niche. It manages roughly $60 billion in USDC reserves, operates across more than fifteen blockchains, and has filed an S-1 with the SEC for what may be one of the largest crypto-associated public listings in history. Agent Stack is being positioned as the natural next layer: a set of APIs, wallets, and payment flows that let AI agents mint, hold, and transfer USDC autonomously. Stripe has been quietly reopening crypto payments. Skyfire is building specifically for agent micropayments. But Circle’s wager is not about being first. It’s about being the most trusted, most compliant, most deeply embedded money layer in the emerging machine economy.
That framing deserves respect. It also deserves a hard audit. Based on my own work auditing ERC-20 contracts in 2017, I learned that technical precision is a form of social protection. During DeFi Summer in 2020, I watched people lose capital to impermanent loss simply because they didn’t understand the mechanism. By 2021, I was helping indigenous South African artists enforce royalty payments on secondary NFT sales. And by 2025, I was working on a decentralized identity framework to verify whether content came from a human or an AI. So when Circle says it wants to become the settlement layer for autonomous agents, I don’t ask whether the code is elegant. I ask who it shields, who it excludes, and who holds the emergency brake.
The Technical Reality: Incremental Rails, Not Paradigm Shifts
Let’s start with what Agent Stack actually is. The product has not been fully open-sourced, and no independent audit report has been published. What we can infer from Circle’s existing infrastructure is that Agent Stack is an abstraction layer over USDC’s current payment network: programmatic wallets, payment authorization logic, compliance hooks, and cross-chain settlement via Circle’s Cross-Chain Transfer Protocol. That means the underlying technology is not a new blockchain, not a new consensus mechanism, and not a cryptographic breakthrough. It is a developer-friendly wrapper designed to make machine-initiated payments possible within the boundaries of regulatory expectation.
That matters because innovation in this sector is often measured by newness. Agent Stack is better measured by integration. Circle already holds money transmitter licenses in multiple U.S. states, a BitLicense in New York, and has structured its reserves to comply with the EU’s MiCA framework. It has relationships with banks, custodians, and DeFi protocols. The real moat, if there is one, is not the SDK. It is the ability to say to a developer: "You can give your agent a wallet today, and the compliance and regulatory scaffolding is already in place." That is genuinely valuable. But it is also a warning.
The core insight here is that Agent Stack does not remove trust from the system. It re-centers trust around one issuer. USDC is a centralized stablecoin. Circle controls the reserve, holds the upgrade mechanisms, and can freeze or block addresses when required by law enforcement. No amount of API polish changes that structure. In the crypto world, we often speak of "code is law." But with Agent Stack, the code is governed by a Delaware corporation with a board, shareholders, and a stated desire to go public. Tracing the code back to the conscience behind it leads directly to Circle’s corporate offices.
Security Shifts: The Agent Is the New Attack Surface
The most complex security problem in Agent Stack is not the USDC contract itself. USDC has been audited by firms like OpenZeppelin and Trail of Bits, and it has operated at scale for years. The new attack surface is the AI agent: how its private key is stored, how its payment authorization is scoped, and how it defends itself against prompt injection. If an attacker can manipulate an agent into believing a legitimate invoice is due, that agent may authorize a transfer that no human intended. This is not hypothetical. The field of adversarial machine learning has already demonstrated that automated systems can be steered toward harmful actions with carefully crafted inputs.
I have seen this pattern before. In 2017, many ICOs shipped with reentrancy vulnerabilities because their code looked correct at a glance. I spent four months auditing three projects in Cape Town and found critical flaws in two of them, helping investors avoid roughly $45,000 in losses. The lesson was simple: security is not a feature, it is a promise that must be defended. Today, the equivalent is the AI agent wallet. If a single agent’s private keys are exfiltrated, and that agent can initiate payments without human review, the resulting losses could be catastrophic — and the damage to USDC’s reputation could ripple far beyond the immediate incident.
Circle is likely aware of this. It may be developing multi-party computation or hardware wallet integrations. It may even be exploring decentralized identity standards for agents. But until those details are public, the security architecture of Agent Stack is a black box. Given that the product is designed for autonomous financial interactions, that opacity is a significant risk. Every line of code is a hand extended in trust. Right now, that hand is being extended before we know who is holding the other side.
Token Economics: The Currency Is Not the Investment
One of the most subtle aspects of this announcement is what it does not change. USDC is a 1:1 dollar-pegged stablecoin. It is not designed to appreciate. Holding USDC gives you no governance rights, no profit share, and no claim on Circle’s future earnings. The economic beneficiary of Agent Stack is not the token holder; it is Circle’s equity holders. If AI agents begin spending USDC at high volume, Circle’s managed reserves grow, interest income grows, and the company’s valuation grows. The currency itself remains neutral.
This matters because the market narrative around "AI money" often gets confused. We are not looking at a speculative asset that will pump when agents adopt it. We are looking at a utility rail that expands the absolute size of a balance sheet. That is exactly why Circle chose to announce Agent Stack before its IPO. The story of "USDC as the native money of the machine economy" is extraordinarily compelling to public market investors. It transforms a stablecoin issuer into a play on AI infrastructure. But for the individual user, the value capture is indirect at best.
In 2020, I organized a weekly workshop called "DeFi for Everyone" because I saw retail users pouring capital into liquidity pools without understanding impermanent loss. That experience taught me that education is the only true decentralized currency. It is also the only way to prevent the illusion of sovereignty from masking a new form of dependency. With Agent Stack, the dependency is not just on Circle’s corporate governance. It is on the underlying assumption that a regulated company should own the monetary plumbing of an otherwise autonomous system.
Market Position: USDC Is Strong Where AI Agents Will Live
Let’s be precise about the market. Tether’s USDT has roughly 68% of the stablecoin market, while USDC sits near 22%. But those aggregate numbers hide an important distinction. In DeFi, on-chain, and smart-contract-native environments, USDC is dominant. It is the stablecoin of choice in Aave, Compound, Uniswap, and most protocols that need a reliable, audited, liquid asset. AI agents will not pay each other through a centralized exchange ledger. They will interact through smart contracts, decentralized applications, and programmable payment channels. That is USDC’s home turf.

This is why Circle’s timing is clever. Tether has not made a serious move toward AI agent payments. Stripe may have enterprise relationships, but it is not a stablecoin issuer with native on-chain settlement. Skyfire is focused and nimble, but it lacks Circle’s regulatory depth and cross-chain distribution. So the open window is real. The market is signaling that AI agents will need to buy compute, data, and human services, and the current rails for that are clunky. Agent Stack could become the default developer tool for machine payments simply by being the easiest compliant option.
But I would caution against extrapolating too much from this. The actual volume of AI-agent-initiated payments today is microscopically small. Most agents do not need to transact autonomously yet. The agents that do are often operating in sandboxed environments with pre-funded wallets and limited decision-making authority. The genuine breakthrough will come when an agent can negotiate a price, verify a service was rendered, and release payment without a human in the loop. That future is closer than it was a year ago, but it is not here yet. We are still in the narrative-driven phase, where product announcements create more heat than light.

Regulation: Frameworks Built for Humans Are Not Ready for Machines
USDC has a relatively clear regulatory status in the United States. In 2023, the SEC settled with Circle and confirmed that USDC itself is not a security. That was a milestone. But AI-agent-initiated payments will test entirely new questions. Who is the human beneficiary when an autonomous agent pays for a service? How does KYC apply to a wallet that can execute transactions without direct human instruction? What does AML monitoring look like when thousands of agents are making microtransactions every second?
These are not abstract concerns. In my 2025 work on decentralized identity and AI verification, I saw firsthand that proof of origin and proof of identity become fuzzy when AI systems are in the loop. We built a framework that allowed users to prove content provenance without revealing personal data, and it prevented thousands of identity fraud cases. But the hard problem was not cryptographic. It was governance. Who gets to decide what counts as a legitimate agent? Who bears liability when an agent breaks the law? Circle’s compliance-heavy approach may give it a head start, but it also creates a bottleneck. The most interesting regulatory risk is not that Circle will be punished for building this; it is that governments will demand that every AI agent be tethered to a human identity, which would undermine the very autonomy that makes machine payments valuable.
MiCA, for all its apparent clarity, is another double-edged sword. In Europe, the stablecoin reserve and CASP requirements are so expensive that smaller projects will struggle to comply. Circle has the balance sheet and legal team to absorb those costs. That is not necessarily good for the ecosystem. If AI-agent payments become concentrated among a handful of large compliant issuers, we may end up with a machine economy that is less open, less programmable, and less decentralized than the human economy it replaced. The regulators will celebrate clarity while the compliance costs quietly kill innovation.

Governance: The Elephant in the Room Is Centralization
Circle’s team has been open about its governance structure. Jeremy Allaire is a seasoned founder with deep conviction. The company has a board, professional investors like Fidelity and Marshall Wace, and a clear path to the public markets. For an institution like Circle, that is a strength. It offers accountability, transparency, and a familiar legal framework. But for a cryptocurrency community that claims to value self-sovereignty, it creates an unresolved contradiction.
If USDC becomes the default money for AI agents, then the machine economy will be settled on a blockchain that technically anyone can read, but only a company can ultimately control. Circle can freeze funds if a regulator demands it. Circle can upgrade the contracts to restrict certain transactions. Circle can choose which agents can participate based on its assessment of their provenance. That is not a neutral infrastructure. It is a managed trust network. And the more important it becomes, the more dangerous it becomes if that single layer fails.
We have already witnessed a preview of this failure mode. In March 2023, Silicon Valley Bank collapsed, and USDC briefly depegged because Circle held a portion of its reserves there. The panic was real. If a simple bank failure can shake a $40 billion stablecoin, what would a coordinated attack on an AI agent payment framework do? I am not proposing that we abandon all centralized stablecoins. That would be naive. But I am arguing that the industry must design for redundancy, auditability, and human oversight. We build bridges, not just blocks, between people. The bridge cannot be owned by a single landlord.
The Contrarian Angle: The Real Risk Is Success
The standard critique of Agent Stack is that AI agent payments are a speculative narrative with no demand. I disagree with that critique. The deeper risk is that Agent Stack succeeds too well, and the machine economy adopts a corporate-controlled monetary rail by default. Nobody will choose this consciously. It will happen because Circle has the strongest regulatory relationships, the most polished developer experience, and the easiest path from fiat to on-chain. The agents will not care about philosophical differences between decentralization and compliance. They will use the rail that works.
That is a devastating scenario for those of us who believe that open source is not a license but a promise. If the dominant payment protocol for AI agents is closed-source, centrally upgradeable, and tied to a single company’s balance sheet, then we have not decentralized the machine economy. We have centralized it under a more convenient name. The agents will be free to pay each other, but only within the boundaries set by Circle’s terms of service, Circle’s auditors, and Circle’s legal team. That is not sovereignty. It is outsourcing.
There is also a subtler risk: Tether’s inaction. Many observers see Tether’s lack of an AI payment product as a gap. I see it as a strategic silence. Tether has often been the more speculative, less compliant actor, willing to operate in gray markets. If Agent Stack normalizes regulated stablecoins for machine payments, Tether could quietly follow, offering the same payment rails without the compliance overhead. In that world, the winner might not be the most ethical player. It might be the one willing to accept the most AI-generated criminal flow. The machine economy will not stay clean just because we wish it so. The question is whether the architects are building safeguards in advance.
Takeaway: Before We Fund the Machines, We Must Teach Them the Rules
I am not opposed to AI agents having money. In fact, I think it is inevitable, and it could reduce friction in ways that benefit ordinary people. But inevitability is not the same as acceptability. The design choices made now will determine whether the machine economy is an extension of human autonomy or a more efficient engine for extraction. We need to demand open-source code, independent audits, clear liability frameworks, and a commitment to human override. We need to train AI agents the way we train children: not just how to spend, but what is fair, what is dangerous, and when to ask for help. Education is the only true decentralized currency, and that applies to machines as much as to humans.
I believe Circle deserves credit for pushing this conversation forward. But as I look at the Agent Stack announcement, I notice what is missing. There is no published threat model for prompt-injection-resistant payments. There is no public plan for a grandparent switch that lets a human stop an agent mid-transaction. There is no open license for the codebase, and no independent review by the developer community that will be asked to build on it. Artists own their pixels; we just hold the keys. But who owns the behavior of an autonomous agent when that agent is spending money? We do not get to answer that question by ignoring it.
My hope is that the community rises to this moment. Not with panic, not with nihilism, but with the kind of careful, compassionate engineering that has made crypto survivable for over a decade. We have audited problematic contracts, recovered misallocated capital, and built resilience through bear markets. We can do this again. But only if we trace the code back to the conscience behind it. When machines start paying each other, the strangest question of all will be whether the money has a memory of being human. Let us make sure that answer is yes.