Custody Is Solved. Accountability Is Not.

Every major exchange gave AI agents a trading account in six months. None of them gave agents an identity.

I. The fastest onboarding in the history of finance

Between March and September 2026, a new class of market participant was admitted to nearly every major trading venue at once.

Binance shipped seven modular agent skills in March and, by September, had bundled them with its Wallet Agentic Hub, an x402 payment facilitator, and Model Context Protocol support into Agent OS, then published an essay positioning AI agents as a new class of exchange customer. OKX released an Agent Trade Kit the same week Binance shipped skills, spanning 60-plus chains and 500-plus decentralized exchanges. Bitget gave its GetClaw agent a dedicated account structure in April. Robinhood opened agentic trading accounts for equities in May and extended them to crypto in July, passing 70,000 agent accounts. eToro reported that its Tori assistant had executed more than 500,000 trades in its first year. Kraken rebuilt its app around agentic trading. Coinbase joined the same wave.

No prior category of participant, not retail, not institutions, not high-frequency firms, has been onboarded to this many venues this quickly. The speed is a signal about demand. It is also a signal about how little the venues had to change to say yes.

II. What the exchanges built

The reason the rollout was fast is that every venue converged on the same design, and the design is a modest extension of infrastructure they already had.

The model has four parts. The agent lives in a dedicated sub-account. Withdrawals from that sub-account are disabled by default. The amount the user transfers in is the loss limit; there is no separate cap. And the user chooses whether the agent needs approval per order or may trade autonomously within its permissions. Liability for what the agent does remains with the account holder in whose name it operates.

This should be recognized for what it is: a correct solution to a real problem. The problem is custody isolation. An agent that can reach a user's full balance is an unbounded risk, and the sub-account model bounds it cleanly. The agent cannot drain what it cannot reach. As a piece of risk engineering, it is sound, it is simple, and it was deployable in weeks because it reuses sub-account primitives exchanges have operated for years.

The design also has a precise scope, and the scope is the subject of this piece. Everything the sub-account model knows, it knows about one agent, in one account, on one venue.

III. The shape agentic trading is actually taking

The single-venue assumption would be fine if agents traded the way retail accounts do. They do not, and the toolkits the exchanges themselves shipped make that obvious.

OKX's kit reaches hundreds of DEXs across dozens of chains. Binance's Agent OS includes an x402 facilitator, which exists so an agent can pay other services, including services the exchange does not operate. Third-party agent frameworks are the norm; Robinhood's expansion was specifically for third-party agents. An agent with any real trading capability will read data from one venue, hold collateral on a second, execute on a third, hedge on a fourth, and settle against a counterparty that may itself be an agent operating from somewhere else entirely.

Consider that trade from the sub-account model's point of view. There are four sub-accounts, each with its own deposit cap, each with its own log, each unaware the others exist. If the hedge leg fails, the record of what happened and why lives in four systems that do not reconcile. If a regulator asks which agent did this, there are four answers, each a venue-issued label with no cryptographic relationship to the others or to the principal who authorized them. If a counterparty wants to know whether this agent has a history of honoring settlements, the honest answer is that the history exists, in fragments, in places the counterparty cannot query.

The same agent, run by the same operator, opens a new account on every venue and starts from zero each time. That is why Robinhood's 70,000 agentic accounts is a number nobody can convert into a count of agents. Accounts are countable. Agents are not, until identity lives somewhere above the venue.

IV. The four questions the container cannot answer

It helps to be exact about what the sub-account model answers and what it leaves open, because the gap is not vague. It is four specific questions.

Which agent is this? The sub-account has a label. The label was issued by the venue and means nothing outside it. Nothing binds it to the principal's key, so an impersonator claiming to be the same agent on a different venue cannot be distinguished from the real one, and a principal cannot be prevented from disowning an agent's actions after the fact.

Who authorized it, for what? Permissions live in the venue's settings: approve per order, or trade within limits. Those settings are the venue's, expressed in the venue's terms, enforced by the venue's matching engine. They do not travel. The agent's mandate on venue A says nothing about what it is permitted to do on venue B.

Did it execute as authorized? The venue's logs say so, and the venue is the only party who can read them. For a single-venue trade that is adequate. For a multi-venue event, no one party can reconstruct the whole thing, and every party's records were produced by a system that is itself one of the actors.

What has it done before? The agent's history is real and it is fragmented. It cannot be presented to a new counterparty, cannot be checked by a supervisor across venues, and resets to nothing on every new platform.

None of these are failures of any exchange's design. They are questions the design was never meant to answer, because they are not venue questions. They are questions about the agent as a persistent actor, and a persistent actor needs a layer that persists across the places it acts.

V. Why the answer will not come from Congress

The regulatory timing sharpens all of this.

On September 15, the CLARITY Act failed a cloture vote 49 to 50, well short of the 60 needed. Comprehensive US market-structure legislation is off the table for the year. What remains is agency rulemaking: the SEC's Regulation Crypto Assets stays open for comment until October 20, and both the SEC and CFTC have signaled they will continue advancing rules independently.

This matters for agentic trading in a specific way. Legislation tends to draw broad lines, which jurisdiction, which asset class, which registration. Supervisory rulemaking tends to proceed case by case, and cases are concrete. The first case involving an agent that acted across several venues will expose, in a filing, that no venue's sub-account log can reconstruct the event. The supervisor's next question will not be about custody, which the venues can answer. It will be about attribution: which agent, authorized by whom, and can anyone verify that without taking the operator's word.

That question has no shared industry answer today. Whoever provides one first, in a form a supervisor can point to, sets the reference. Rules get written against what exists.

VI. The constraint is the product

There is a phrase that recurs in every serious agentic-trading announcement this year, and it deserves attention because it is where the whole field's attention is about to land.

When ASUS and Poesis reported a week-long experiment in which agents traded live capital autonomously on local hardware, the framing was that the agents operated "within clearly defined constraints." Every exchange rollout uses a version of the same language: within user-defined limits, within its permissions, within the user's risk tolerance.

The constraint is the product. It is the thing that makes autonomous trading acceptable to a user, a desk, an insurer, or a regulator. And in every current implementation, it has the same property: it is defined inside a single system and enforced by that system, and no outside party can verify it was in force at the moment an action was taken.

The next competitive layer in agentic trading is not better skills. Skills are converging; every venue has analysis, execution, and workflow tooling now. The next layer is making the constraint verifiable by construction, so that "within clearly defined constraints" becomes a claim any counterparty or supervisor can check rather than a sentence in a press release.

VII. Origins Network and the layer above the venue

Origins Network is built as that layer, and its architecture maps directly onto the four open questions.

Which agent. An agent's address on Origins is derived deterministically from its principal's wallet, so it is the same agent wherever it acts. Nobody issues the identity; it follows from the key. An impersonator cannot produce it and a principal cannot disown it.

Authorized for what. Authority is expressed as task-scoped session keys: a specific counterparty, a specific amount, a specific time window, cryptographically invalid outside those bounds. The mandate is not a venue setting. It is a property of the key the agent is holding, and it can be narrowed further when an agent delegates to a sub-agent, with the chain recording who narrowed it.

Executed as authorized. Execution is subject to randomized verification: a small, unpredictable subset of tasks is selected for detailed audit through a mechanism the network can check, and rewards are withheld until the cycle's checks pass. An outside party can confirm the sampling was not gamed without trusting the operator's logs.

Done before. Every completed task accrues to a unified on-chain reputation at the agent's address. The history is not fragmented across venues because it does not live in any venue. It lives at the identity.

Origins is adding Trading Skills to its agent framework: market analysis, strategy generation, and trading workflows. The skills themselves will look familiar, because the market has converged on what a trading agent should be able to do. What distinguishes them is what they run on. Every action executes under a derived identity, a task-scoped key, sampled verification, and a single portable reputation. The skills are the application. The accountability is the substrate. Shipping the first on top of the second is the point.

This is not in competition with the exchange sub-account model. The sub-account is a container, and a good one. Origins is what makes the thing inside the container the same accountable thing everywhere it runs. Because Origins is x402-interoperable, agents built on it can pay for and use external services without custom integration, which is the same interoperability path the exchanges themselves are building toward.

VIII. Conclusion

The agentic-trading rollouts of 2026 solved one problem cleanly and quickly. Custody isolation: put the agent in a sub-account, block withdrawals, make the deposit the cap. Every major venue converged on it in six months, and it works.

What the model does not touch is accountability across venues. It answers what an agent can lose here and leaves open which agent this is, who authorized it, what it has done elsewhere, and whether anyone but the venue can verify any of that. Those questions do not arise when one human runs one agent on one exchange. They arise the moment agents trade across venues, delegate to sub-agents, or face counterparties with no reason to trust the exchange in the middle. That is the shape agentic trading is already taking, and with market-structure law stalled, the rules for it will be written by supervisors against whatever infrastructure exists when the first cross-venue case lands.

The exchanges built the container. The next layer is the thing inside it staying the same thing wherever it runs. That is the difference between an agent that has accounts and an agent that has an identity, and it is the layer Origins is building.

Origins Network is a modular Layer 1 for verifiable AI computation, agent-native transactions, and institutional coordination. Technical documentation: origins.gitbook.io/origins-whitepaper