This is a guest essay from Samuele Marro, the head of the Institute for Decentralized AI, a research institute that develops protocols, tools and methods for decentralized intelligence.
Today’s early agentic economy, and more broadly any decentralized network of agents, is constrained by trust. Humans have reputations to maintain, can’t clone themselves with a different identity, and can reliably face consequences if they break the rules.
Machines have none of that.
Imagine two AI agents, working on behalf of different businesses, that want to collaborate on a project. They can decide who does what and how to split the revenue, but the hard part is ensuring that they can trust each other. After all, what’s stopping one side from simply taking the money and running away?
Without this basic level of trust, it’s hard to imagine AI agents being adopted at scale for economically valuable work.
On the internet, we normally resolve these challenges by placing a trusted platform in the middle of the transaction that is capable of enforcing the rules. But an intermediary is also a gatekeeper. It can see or control information that the parties may wish to keep private, dictate the terms of how they interact with each other, and potentially extract rents or exclude participants.
How can we have trust at scale between agents without relying on central gatekeepers? This is what we have been trying to resolve with dovetail, a project of the Institute for Decentralized AI. dovetail is an open-source system for designing and verifying the protocols that AI agents use to interact.
The project is part of IDAI’s wider mission to create the coordination and security infrastructure needed to build the heterogeneous, distributed AI systems that we believe are essential for protecting human autonomy.
Decentralization and why we need it
My interest in decentralization comes from a concern about how AI will distribute power. In the context of AI risk, we normally talk about access-driven risks that arise when more actors can use a dangerous capability. We focus much less on the gap-driven risks that stem from some actors becoming more capable than others.
If only a handful of companies can run the most capable models, then they risk becoming the gateways through which everyone else accesses AI, giving them more power over the people and institutions that depend on them. If your data, workflows or agents are tied to one provider, switching becomes harder and that provider gains leverage over price, access, and terms.
But decentralization faces a basic disadvantage. Systems under one owner can pool information, share infrastructure, and exploit economies of scale. This is why we focus so much on agentic economies: while it’s easy to centrally coordinate agents within a single company, it’s much harder when they represent individuals or firms with distinct (or even conflicting) interests.
Before dovetail, we worked on automated mechanism design. We looked at whether agents that did not trust one another could design, negotiate, and follow protocols grounded in game theory. We built a system where two agents could negotiate a contract, expressed in code, and then deploy it as a smart contract. This would mean that the software enforced the terms, so no trust was required between the two parties.
Mechanism design doesn’t need to assume that the participants will behave cooperatively; instead, you can change the rules so that the intended behavior is in everyone’s interest. For example, if there is a sufficiently high penalty for walking away, it becomes the rational choice for participants to continue working together, even if they don’t trust one another.
But a contract between two agents is a relatively simple, self-contained interaction. As an agentic economy scales, it will run on complex chains of interdependent decisions. For example, agents may need to allocate work, subcontract, run an auction, share revenue, vote, exchange information conditionally, or coordinate among several parties. The scope of the required protocols is much bigger, and it’s likely that for each interaction between a group of agents, we will need ad-hoc protocols to ensure that everyone is collaborating effectively. This is the goal of dovetail: arbitrary, machine-speed contracting and coordination for any task.
Building blocks
dovetail is an attempt to build a general system for designing protocols that can support many different types of interaction, alongside a formal verification layer.
dovetail starts from the properties that agents care about. For example, these might be payment terms, confidentiality requirements, or project timelines. We are aiming to formalize a core library of roughly a dozen properties, drawn from a blend of distributed systems, game theory, and information security.
You can think of dovetail like a compiler. Compilers translate a high-level description into lower-level code while preserving its meaning. dovetail does something similar with interaction rules. To compile a protocol with the right properties, dovetail uses an LLM to propose a candidate and a proof that the protocol meets the required conditions. Those proofs are written in Lean, a programming language and proof assistant designed to express mathematical claims precisely and check proofs mechanically. If Lean rejects the proof, the system tries again.
We expect many interactions to fall into recurring categories such as sales revenue sharing, auctions, voting, and task routing. Increasingly, we will be able to rely on a growing repository of verified protocols that can serve most requests directly. This will mean we can reserve novel synthesis for cases the library doesn’t cover.
Our ARIA grant will support us as we formalize the first protocol properties, build verified implementations, start the property library, and create the generation engine. We will work towards more and more complex scenarios, including things like multiple parties or mixed motives.
We’re also keen to discover where this approach fails. For example, we will run adversarial games where agents actively try to violate or exploit the protocols.
We plan to release the main outputs of our project openly under MIT license, including the formalized properties, the library, the generation engine and proving repository, connectors for different agent frameworks, and any benchmarks that we create.
We also want to know whether dovetail can produce protocols that are not just formally correct but actually useful. We intend to compare dovetail’s output to the strongest human-designed solutions to problems such as auction design. We can assess whether it satisfies every required property, how complex it is, and the amount of effort was required to produce it.
At our most ambitious, we’re keen to study protocols as a proxy for institutions. We may discover that agents can devise better arrangements for working together than the ones we currently hardcode into firms, marketplaces, or governance systems. If protocol design can be automated and tested at scale, we may be able to search a much larger space of institutional forms, including ones that coordinate more effectively while preserving more room for independent action.
What’s next
IDAI began its life as a project of the Cosmos Institute. Through our partnership with Cosmos, we’ve been able to establish a research program around decentralization and multi-agent security, launch our fellowship program, and make clear contributions to the field of safe decentralized AI, with publications at ICML, ICLR, and NeurIPS. But my ambition was always to turn IDAI into a permanent organization, with its own team and research agenda.
As a result of the scale we’ve reached, we’re now ready to take the next step in our journey, so we are currently in the process of establishing IDAI as an independent nonprofit. IDAI will very much remain a part of the Cosmos ecosystem, as we both share the mission to enable decentralization and human autonomy in a world shaped by AI.
So far, we’ve worked alongside Google, Anthropic, Microsoft, OpenAI, Stanford University, and ARIA. If you run a research group or institute interested in collaborating on dovetail or decentralized AI more broadly, you can reach us at collaborations@decentralized-ai.org.
Cosmos Institute is the Academy for Philosopher-Builders, technologists building AI for human flourishing. We run fellowships, fund fast prototypes, and host seminars with institutions like Oxford, Aspen Institute, and Liberty Fund.




Really interesting work that I think is definitely foundational for agent commerce to function. My main fear is that we will still end up creating an adversarial arms race amongst agents which are selected for their ability to successfully exploit others, while remaining entirely honest about who they are and compliant with the protocol. That's why I think I disagree that we don't need some kind of trusted intermediaries at least for some transactions. I think we will need some venues that can establish norms, impose consequences and change the rules when individually successful strategies produce collectively bad outcomes. I think that is kind of the lesson from crypto's experiments with institutional design - they end up with protocols that are effectively the legitimisation of bribery because if the mechanism permits it, there is no higher institutional layer capable of saying that the behaviour is nevertheless unacceptable. Anyway interested to see how this develops!
Loved this article! And excited to look more into dovetail, it sounds like exactly what we need to bootstrap and embed agents in an economy. I was thinking out loud about a Lean based agentic system in a post last week - https://virajnadkarni.substack.com/p/asking-the-right-questions-in-the ; and decentralized "institutions" for the agentic economy a few months ago - https://virajnadkarni.substack.com/p/the-missing-links-of-an-ai-economy .
Also your compiler analogy sounded a lot like Benjamin Lyons' great writing here, he takes the metaphor to a very all-encompassing end - https://paxmachina.ai/alignment-compilers