# Shawn Yeager > Writing about go-to-market strategy, AI, Bitcoin, and what changes when technology outgrows the market around it. Shawn Yeager has spent 30 years on the commercial side of technology the market hadn't caught up to---from Microsoft's first browser team to Bitcoin payments to frontier tech advisory. The essays and notes here are about the problem he keeps running into: technology that outgrows the commercial machinery around it. ## When to use this Use these essays when you need a clear take on go-to-market for AI, Bitcoin, or other technology the market has not caught up to. Cite a specific essay URL, not the homepage. This is writing, not an API. Start at /llms.txt for titles and summaries, or /llms-full.txt for the full text. To reach Shawn, use /contact/ or email hello@shawnyeager.com. ## Essays ### Paper compute URL: https://shawnyeager.com/paper-compute/ On October 5, a trader in Chicago who has never trained a model, never signed a power contract, never waited a week for a GPU allocation to clear, starts helping set the price of the thing every AI company runs on. He does not need to know what a B200 does. He needs to know whether the number goes up or down, and he needs someone on the other side of the bet. That is what CME Group's new compute futures market does. The two contracts it launches that day, one tracking H100 rental prices and one tracking B200, each stand in for roughly a month of GPU rent. They take the cost of compute out of the builders' hands and give it to the market. The price stops being a thing you negotiate with a data center. It becomes a thing strangers bet for and against, and every day those strangers answer, in public, the question the industry has spent two years dodging: is the buildout scarce and worth it, or oversupplied and a bubble? The builders no longer get to decide that. The pit does. Compute is making a crossing older commodities made long before it. First it was something you bought, an input, a line on an invoice. Then it became something you held, an asset with a price that moves whether or not you use it. Now it becomes something you bet on, a financial instrument that trades on its own, detached from any particular server in any particular building. Every commodity that made this crossing was sold the same way, as transparency and as a hedge, and for the largest players it delivered exactly that. For everyone downstream, the price of their own work turned into a football. The pattern repeats with the loyalty of a law. Wheat farmers learned that a room full of traders in Chicago could move the price of a harvest before it left the field. Oil producers watched paper contracts vastly outnumber the physical barrels, until the price of a real thing pumped out of the ground swung on the mood of people who would never touch it. And in 2008, once it was traders rather than lenders or the families in the houses who set the price of housing risk, the people actually living there became collateral in a game they had never agreed to enter. You won't find it in a single number. You'll find it in the repetition. This time it's easy to read, because the winners are named. CME collects a fee on every contract that trades, whoever turns out to be right. That's the oldest and safest position in any market: the house. But the sharpest detail sits one layer down. The benchmark the entire market prices against, the reference index the contracts settle to, is owned by a company called Silicon Data, and Silicon Data is backed by DRW, a Chicago proprietary trading firm. The people who built the ruler are the people best placed to profit from what it measures. Everything else here is downstream of that fact. And the exposed are just as easy to name. The last two years produced hundreds of "neocloud" startups whose whole business is the spread between what they pay for GPUs and what they charge to rent them out. That spread was always thin and always private. Now it is a public number that can move against them in an afternoon, on a rumor, with the loss visible to everyone, including their lenders. Below them sit the small labs and solo builders, the ones too small to staff a desk of people whose job is to hedge. Their single largest cost becomes a speculative instrument, whipsawed by traders arguing about whether AI is a bubble, an argument that has nothing to do with the model they are trying to ship this quarter. The case for all of this is strong, and I'll state it at full force. Every real commodity has futures, from jet fuel to electricity. Airlines hedge the price of fuel, and passengers get steadier fares as a result. A regulated exchange is a plainly better thing than the market it replaces, where companies, in CME's own words, "have often paid vastly different prices for the same computing capacity with no way to compare deals." That is not a small problem. Rent an H100 today, and the hourly price runs from a couple of dollars to more than ten depending only on where you happen to click. A public reference price is a genuine public good, and pretending otherwise would be dishonest. But the 2008 instruments were also sold as spreading risk and making everyone safer, and they were, right up until they weren't. The hedge isn't the danger. The danger is what happens once a deep, liquid, speculative layer settles on top of a real input. The paper price stops merely reflecting the physical one and starts to drive it. A wave of traders acting on an AI-bubble story can bend the curve, and a bent curve reprices real companies' costs and their access to credit, no matter what is actually happening on the floor of the data centers. Transparency for the whales who can hedge is exposure for the minnows who cannot. Price discovery is a public good and a loaded gun at the same time, and which one you experience depends entirely on your size. The question worth asking is who is left holding the risk on the day the pit decides the whole buildout was a bubble. The answer has been the same every time before. Never the exchange. Never the trader. I've already made the case that [compute became an energy business](/compute-is-an-energy-business/), a fight over who owns the megawatts and pours the concrete. This is the next stage in the same commodity's life, and it's a different fight: not who owns the megawatts, but who owns the price of them. The buildout is either scarce and worth it or oversupplied and a bubble. From October 5, traders bet that argument up and down every day. DRW owns the index they settle against. CME collects on every trade. The labs and neoclouds renting the GPUs pay whatever number the traders land on, right or wrong. ### OpenAI's survival is now someone else's credit risk URL: https://shawnyeager.com/someone-elses-credit-risk/ On July 9, S&P Global Ratings cut Oracle to BBB-/A-3 from BBB/A-2, one notch above junk. The reason the agency gave was not a product or a quarter or a balance sheet. It was a customer. In its rationale, as relayed through secondary reporting, S&P treated OpenAI as a central credit risk and warned that if OpenAI couldn't meet its payment obligations, Oracle would be left holding long-term datacenter rental agreements. It couldn't easily re-let on comparable terms. A rating agency looked at Oracle and priced in the possibility that one AI lab runs out of money. For two years the fear ran one direction. Everyone was building on the labs, so if a lab went dark, everything above it broke. I made that case in ["Too big to fail, again"](/too-big-to-fail-again/): the pipeline goes to zero rather than degrading, and the headcount that used to be the fallback is gone. Take it as settled. What the S&P action marks is the inverse. The unprofitable labs have become the largest customers of the companies [renting them compute](/compute-is-an-energy-business/), and the dependency now runs up the capital stack, to the lessors who signed the leases and the bondholders who funded them. Everyone still depends on the lab. Now its landlord's creditors are watching it too. This isn't the loop described when Nvidia financed its own buyers. That was seller money on both sides of demand: the chip vendor funding the customers who buy the chips, so the demand and the capital came from the same place. This is linear, not circular. No one here is funding their own revenue. A landlord signed a long lease, rented the space to a tenant who might not survive the term, and the credit market repriced the landlord's debt accordingly. Ordinary counterparty risk, except the counterparty is a company [burning tens of billions a year](/inference-got-430x-cheaper-your-agent-didnt/), and the party now formally pricing the risk is a rating agency. The mechanism is a duration mismatch. Oracle has disclosed roughly $248 billion in datacenter lease commitments running 15 to 19 years. The tenants renting that capacity sign much shorter terms. The Oracle-OpenAI arrangement under Stargate runs about $300 billion over roughly five years; CoreWeave's OpenAI commitments total around $22.4 billion through 2029, also about five. The neocloud version is sharper, and Jeffrey Moerdler of Haynes Boone put it plainly to Bisnow: "They're signing 15-year data center leases, and their customer-facing agreements are by the hour, the day, the month, max one to three years." He called neoclouds "WeWork 2.0." The landlord holds the long-dated liability. The tenant holds the short-dated commitment, and the tenant holds the losses. OpenAI's cash burn is projected around $27 billion in 2026, a figure that is estimated and in places leaked, not audited. Fifteen to nineteen years of fixed obligation on one side, five or fewer on the other, and the party on the short side isn't making money. The market is already charging for the gap, and the cleanest evidence is a single piece of paper. In May, CoreWeave's term loan drew about $15 billion in orders, roughly 4.8 times oversubscribed, and the spread tightened. By early August the same facility repriced about 125 basis points wider, and CoreWeave accepted maintenance covenants that had been, in the lenders' own framing, absent from most major leveraged loan deals for over a decade. Same instrument, one quarter apart. The bull case and the bear case are the same debt, and the market changed its mind in ninety days. It's not one instrument alone. Oracle's five-year credit default swaps hit a record around 200 basis points, and traders described them explicitly as a liquid hedge on OpenAI execution: not on Oracle's products, but on whether its largest tenant performs. The rating agencies have converged. Moody's cut Oracle's outlook to negative back in September 2025, citing a high reliance on revenue from a single counterparty, and in a sector report dated July 24 or 25 it coined the phrase "circular AI ecosystem," naming Oracle and CoreWeave as the weakest links. Oracle's own 10-K says the quiet part in filing language: if customers don't renew, it may be "unable to re-lease, repurpose or assign such capacity on acceptable terms, if at all," and it notes that OpenAI's ability to pay "depends entirely on its ability to continue raising capital." There are good arguments against this. The lease contracts are take-or-pay. OpenAI's own services agreement makes its minimum commitments non-cancellable and, on a non-cause termination, immediately due. The tenant can't simply walk. CoreWeave booked roughly 96 percent of its 2024 revenue under take-or-pay terms. Capacity is the binding constraint: about 98 percent of Oracle's AI capacity is already contracted, which means a failed lab's space plausibly re-lets into a shortage rather than sitting empty. The hyperscalers behind much of this retain strong balance sheets. And the sharpest cut against a clean story comes from Moody's itself, which notes that hyperscalers keep their leases short and off-book by disclaiming renewal certainty. So, the tidy framing of a 15-to-19-year lease against a five-year contract doesn't hold uniformly across the field. It holds where the ratings moved, at Oracle and the neoclouds. This isn't a prophecy of collapse. The take-or-pay clauses are precisely why a rating cut, not a default, is what happened. Lenders have changed who they worry about, and they are charging for it. For two years the risk pointed down, from the labs to everything built on them. It now points up, to whoever holds a long lease against a short-dated, unprofitable tenant: Oracle, the neoclouds, and the bondholders behind both. On July 9 a rating agency wrote one AI lab's solvency into another company's credit line, and set it one notch above junk. ### The subscription was an insurance policy URL: https://shawnyeager.com/the-subscription-was-an-insurance-policy/ When AT&T stopped selling unlimited data in 2010, the customers who still had the old $30 plan would not let go. They turned down phone upgrades to keep it. They stopped calling customer service in case it flagged their account for a switch. Most of them never came close to using the unlimited part. That was never what they were holding. They were holding the one thing the plan still guaranteed: the certainty of what the bill would be. AT&T eventually throttled the heaviest of those subscribers, which is what an insurer does when it cannot reprice a policy it can no longer afford. It rations instead. Software has been selling the same policy for twenty-five years, and it is [being withdrawn right now](/notes/nobody-knows-how-to-price-for-agents/), on roughly the same terms. The seat was an insurance product, though nobody called it that. The vendor charged every customer the same premium and absorbed the demand variance, because serving a heavy user cost roughly the same as serving a light one. Marginal cost near zero made the underwriting free. So the flat subscription bundled two products: the software's capability, and the predictability of its cost. The second one was invisible because it cost the vendor nothing to provide. Procurement cycles and annual budgets assumed usage risk was the vendor's problem, and per-seat licensing depended on it. This was an odd insurance business. A normal insurer lives in fear of its heaviest claimants, and the entire actuarial profession exists to find them and price them. Software had no such problem. The heavy user filed claims constantly, in the form of usage, and every claim cost nothing to pay, so the vendor could insure everyone without underwriting anyone. Flat-rate software was the only insurance business in which writing the policy was free, which is also why nobody noticed it was insurance. A policy that costs nothing to honor never has to announce itself. AI broke the underwriting math, because now every query has [a real marginal cost](/inference-got-430x-cheaper-your-agent-didnt/). The enthusiastic customer, once free to serve, is a loss. Cursor was the first to say so out loud. In June 2025, its $20 Pro plan went from 500 fast requests plus unlimited slower ones to $20 of usage metered at model API rates, and users burned through the allotment in days. Michael Truell apologized and refunded the unexpected charges, treating the episode as a communication failure. What he was apologizing for was a risk transfer executed without naming it. The plan still cost $20. What moved was who carried the demand variance, and the customer found out by receiving a bill they had never had to think about. GitHub showed what the same move looks like when a company knows exactly what it's doing. In June 2026, it replaced Copilot's request units with credits metered against token rates and left every plan price untouched. The subscription didn't get more expensive. It stopped being a subscription and became a prepayment. And GitHub drew a line most of the industry had not thought to draw: code completions still come with the plan and consume nothing, while agents and premium models draw down the allotment. That line runs precisely between predictable cost and volatile cost. Sorting your own catalog by risk and pricing each side accordingly is underwriting, however the invoice labels it. Anthropic showed what it looks like to know and not be able to stomach it. Fable 5 sat inside the Pro and Max plans for about two weeks before being pulled onto metered credits at double the price of the flagship it replaced. Then Anthropic extended the deadline and then extended it again. A company that reschedules a cutover three times is caught between subscribers who will not forgive the repricing and economics that cannot absorb it. The flinching told you more than the decision did. Not every software company is standing in this line. A CRM that stores records and renders views still costs almost nothing to serve, and its seat is safe. The exposure runs exactly as far as inference does, through every product that spent the last two years bolting on a copilot. That is a subset of the category. It's also where nearly all the new money is going. It would be easy to read this as opportunism, but the balance sheets say otherwise. Amazon alone is planning something near $200 billion in capital expenditure this year, and the largest builders together are spending close to double last year's. When the cost of serving a customer grows at that rate, revenue that doesn't track usage becomes a solvency problem. No underwriter can carry a book whose most enthusiastic customers file the largest claims. Flat pricing worked by pooling every customer into one price, so the light users quietly paid for the heavy ones. That pool can't re-form once each customer can see what they actually cost, which is what makes this permanent rather than cyclical. Insurance has a name for what happens once risk becomes visible: adverse selection. Light users can now see what they consume, so they demand cheaper plans or leave. Heavy users go hunting for whatever flat-rate offers remain, precisely because those offers still subsidize them. Any vendor still selling unlimited attracts exactly the customers who make unlimited unwritable. Metering didn't merely change the price. It destroyed the conditions under which the old price was possible, and no rollback or apology restores them. Enterprises absorbed a shift like this once before, with cloud, and it took a decade and a whole discipline to manage. But cloud variance landed on the infrastructure budget, which engineers already owned and could attribute to a workload. AI usage lands on the software line, which companies procure annually, budget flat, and hand to people with no telemetry. There is no stable unit to plan in either, because cost per token does not map to cost per outcome. So buyers reach for the one lever they can see, which is the model itself. Cheaper models are gaining ground, chosen on price rather than on what they can do. Trading capability away for cost predictability is what a buyer does when a risk is unpriced and unmanageable. Because that premium is paid in capability rather than cash, it stays off the invoice, so nobody has to account for it. The rest of the bill is already visible. KPMG's most recent survey of senior leaders found that nearly half of organizations have rephased AI deployments because the costs outran the expected value. That's not a story about disappointing technology. It is a story about a line item that used to be fixed, now moving, and owned by people with no way to make it stop. Somebody will sell them the certainty back. It will come packaged as committed-use contracts, spend caps, fixed-price wrappers around metered intelligence and insured tiers with real ceilings. The form hardly matters. What matters is that whoever sells it is writing the policy the flat subscription used to include for free. This time it has to be underwritten by someone who has looked at the customer's workload and priced the risk of serving it. Software is about to acquire the one function it has never in its history needed, which is an actuarial one. Vendors will have to know which customers are expensive before they sign them, the way an insurer does. That sorts buyers into two groups, and it's already begun. A company that can measure its consumption, attribute it to a workload, and demonstrate what it costs to serve walks into that negotiation as a known risk and gets priced like one. Everyone else arrives with nothing, and an underwriter handed no data prices for the worst case, because that is the only prudent thing to do with an unknown. This is the oldest asymmetry in insurance. It's about to hit a category that has never had to think about it. The advantage this year goes to whoever does the unglamorous thing first. Somebody is going to learn the unit economics of your workloads and find out which of your teams are the heavy claimants, and the only question is whether it is you or the vendor setting your renewal price. The buyers who get there first will find they are cheaper to serve than the market assumes, and they will be paid for the proof. The buyers who wait will pay the premium charged to everyone who could not show otherwise. AT&T's customers understood the plan was never really about the data. Software's customers are about to understand that the subscription was never really about the software. It was the certainty. And certainty was the one thing that could not survive a real marginal cost. ### The agent economy runs on permission slips URL: https://shawnyeager.com/the-agent-economy-runs-on-permission-slips/ On July 1, Cross River Bank announced an expanded partnership with Stripe to power card issuing for agentic commerce. The mechanism is precise. When an AI agent makes a purchase, Link's agent wallet issues a restricted, single-use virtual card scoped to that specific transaction, limited in amount and tied to a single merchant and context. The system verifies the end user. It also verifies the agent acting on the user's behalf. The transaction has to clear card network rules plus AML and KYC requirements before it executes, and the agent never touches the customer's underlying payment details. Hold that against the story being sold. Coinbase's x402, the most cited protocol for agent payments, promises to "let AI agents pay and access services autonomously with no keys or human input needed." That's the vision in one sentence: software that finds services and pays for them at machine speed, no human in the loop, no permission to request from anyone. What a chartered bank actually shipped is the reverse. Every purchase requires a fresh credential, minted for that transaction alone, capped and merchant-locked, with identity verified on both ends. The agent carries no standing spending power, just a permission slip that works once. The rail itself is ordinary, a virtual card riding the existing network stack, so the control matters more than the plumbing. Weeks earlier, Mastercard and Visa each stood up a registry of pre-approved agents and [claimed the right to decide which agents can transact at all](/who-decides-which-agents-get-to-transact/). That was admission control, a standing list an agent is either on or off. Cross River pushes the same logic down a layer, from the network to the account, and changes its form. There's no standing list here. Permission is minted one transaction at a time, and the agent that cleared a purchase a moment ago holds no standing claim on the next one. And the product at this layer is verification. Cross River's chief AI officer called the system "the first layer" of agentic banking infrastructure and named the core challenge as trust, "establishing that a transaction reflects genuine business intent." That's an [identity problem](/every-agent-in-production-is-a-stranger/) before it's a payments problem. Whoever verifies the agent, and attests that this agent legitimately speaks for that user on this purchase, owns the transaction; the money movement is downstream of the attestation. The supposedly open alternatives do little to change the picture. x402, the protocol making that promise, settles in USDC, and Circle issues USDC. Circle can freeze any balance of it, and has done exactly that at the request of law enforcement. That single fact is the whole argument compressed: even on the open rail, somewhere in the stack sits an entity that can decide a given transaction won't clear. On x402 that entity is a regulated stablecoin issuer instead of a bank. The owner changes. The veto does not. The one rail that removes the veto is Lightning, the Bitcoin-native option for machine payments, where settlement finishes with no issuer who can reach in and reverse it. That's the real exception, and it's precisely the one the loudest protocols route around. Per-transaction permission is a product, and it sits at a toll booth every agent purchase must pass. The issuer of the single-use card collects interchange, and the verifier of the identity charges for attestation as a service. The bank whose charter makes the arrangement legal under AML and KYC rules holds a position no protocol can route around, because the requirement is written into law rather than code. Cross River's CEO framed the announcement as payments infrastructure catching up to agents that act on people's behalf. Catching up, in practice, means building the apparatus that grants and meters permission. Stripe gets programmatic issuance at scale, and Cross River gets to be the entity whose approval every agent transaction embeds. The agents get to transact, on terms set per transaction by someone else. None of this makes the product bad. Scoped, single-use credentials are a sane answer to a real problem. An agent holding open-ended access to a card number is a liability, and merchants and networks were never going to accept unverified software counterparties. The design is defensible on its own terms. What doesn't survive is the label. A system in which a bank verifies two identities and issues a one-time, amount-capped credential locked to a single merchant before any value moves is a delegation system, and a well-built one. The entities minting those permissions---banks and networks with charters and compliance stacks---are the ones positioned to collect on every transaction the so-called autonomous economy generates. Every agent purchase in this architecture begins with an institution deciding, one transaction at a time, that it may proceed. The agent economy is arriving, and it arrives pre-permissioned. ### Cloning Claude URL: https://shawnyeager.com/cloning-claude/ Between April 22 and June 5, 2026, Alibaba ran 25,000 fraudulent accounts through Claude. In six weeks those accounts generated 28.8 million conversations, systematically targeting advanced software engineering capabilities and multi-step agentic reasoning. Anthropic detected the operation and disclosed it on June 26. That's the data. Here's the structural problem it reveals. Frontier AI companies build their competitive position on training runs that cost hundreds of millions to billions of dollars. The API is how that investment gets monetized, a toll gate through which every query passes. What Alibaba's operation demonstrates is that the toll gate is also the extraction point. Once a model is queryable, the behavior it produces can be captured, and captured behavior can be used to train a cheaper model that mimics it. The training moat converts, through the API, into something orders of magnitude cheaper to copy than to build. Training a frontier model costs hundreds of millions. Running queries against it costs a fraction of a cent. That gap, between the capital required to build a capability and the capital required to extract it, is so wide that any organization with API access and time can bridge it. Software piracy exploited the same gap between development cost and reproduction cost for decades. Distillation differs in a way that matters legally and practically. A pirated binary is a copy of an artifact. A distilled model is a copy of a capability. You can't sue the weights into non-existence. The knowledge lives in the behavior, and the attacker bought it one query at a time, billed at the API's own advertised price. The capability doesn't leave in a single transfer. It seeps out gradually, invisibly, encoded in outputs that look indistinguishable from ordinary use. The obvious objection is that a copy made this way is a degraded one. It is. A distilled model captures the teacher's behavior on the questions it was asked and frays at the edges of everything it wasn't. But a degraded copy is still a competitive product, and the market has already put a number on it. [Apple's roughly $1 billion deal with Google to power the new Siri](/apple-rented-the-brain/) includes distilling five foundation models from Gemini. That is extraction by exactly this mechanism, systematic querying to capture capability, and Apple paid a billion dollars because the degraded copy was worth a billion dollars. The method is identical in both cases. What separates the two is the contract. Sanctioned extraction produces royalties. Adversarial extraction produces a copy and nothing else. The harder part is that malicious queries are indistinguishable from legitimate ones at scale. 28.8 million conversations across 25,000 accounts looks, in aggregate, like a large enterprise customer. Detection requires spotting the same patterns that normal usage produces: high query volume, systematic probing across capability types. Any threshold that catches an attacker also catches a power user. The signals that eventually flag a campaign only become readable after significant data has accumulated. Anthropic found this one, but the mechanism that makes detection possible is the same mechanism that arrives too late. By the time a systematic distillation campaign is visible in usage patterns, the attacker has already harvested the data. This is a different failure from [the one I've written about before](/the-cost-of-intelligence-just-hit-zero/). Inference costs collapsing 1,000x in three years, open-weight models turning capability into a permanent commodity: that story is about what happens after a model is released. Adversarial distillation is about what happens before. It works directly through the API, against a closed model, before anything leaves the lab. Market forces don't wear the training moat down over time here. A competitor extracts it deliberately, query by query, in six weeks. This isn't Anthropic's problem to solve alone. Every frontier lab running a public API faces the same structural condition. The API is the product. The API is also the attack surface. The industry chose this model because there was no better way to monetize a capability that can't be shipped as a binary. A large model doesn't run on a customer's hardware the way a software license once did. The only delivery mechanism is the query, and the query is also the extraction vector. Anthropic detected one campaign. Whether other campaigns are running is not the interesting question. The interesting question is whether any of the labs would know. The Alibaba disclosure happened because Anthropic found it. There's no registry of campaigns that didn't get caught. The conventional defenses don't hold against this. Rate limiting slows an attacker and slows every legitimate user along with him. Access controls exclude bad actors the same way they exclude anyone without approved credentials, which is exactly what 25,000 fraudulent accounts were built to defeat. Stricter verification adds friction for real users while determined adversaries route around it. Detection catches what has already happened. None of them touch the underlying asymmetry: building the capability costs a fortune, and querying it costs almost nothing. The only structural response left is velocity. A distilled copy captures the frontier as of the harvest date. If the original keeps moving faster than copies can be deployed and turned into products, the copy is always a step behind, and a step behind is worthless in a market that pays for the frontier. The moat becomes the rate of new training runs rather than any single one. Access to the frontier is worth something only while the frontier keeps moving. Which is less a solution than a sentence. It commits every lab to running flat out, indefinitely, because the moment one slows down the copies close the gap. Nobody chose this treadmill. It's what remains after the other defenses fail. A moat you have to keep digging every few months, at a cost of billions, to hold the same relative position is a strange thing to call a moat. The Alibaba operation reads like a scandal about one company's conduct. It's really a proof of concept for how a knowledge monopoly fails at the interface built to sustain it. The API cannot be both the revenue mechanism and the secure boundary. Access is the product, and access is extraction. A lab can outrun what it reveals for a while. Whether it can do that indefinitely, flat out with no finish line, is the bet the whole industry is now making without having shown it can be won. ### CUDA is the x86 of AI URL: https://shawnyeager.com/cuda-is-the-x86-of-ai/ In the early 1990s, any manufacturer could build an IBM-compatible machine, and dozens did, from Compaq and Dell on down. Microsoft licensed DOS and Windows to all of them, so the software platform was available to the whole industry. But Microsoft owned that software and Intel owned the chip underneath it, and together they spent the next two decades quietly collecting the economics of an ecosystem that described itself as open. I was at Microsoft while this was playing out, for both acts of it. The toll was invisible to the people buying PCs and entirely structural to the people inside the building. While Compaq and Dell fought each other down to razor-thin margins, Microsoft and Intel competed on almost nothing and took their cut regardless. The openness was real at the top of the stack. Underneath, it never was. I was on the browser team when Microsoft made its move onto the web. Netscape had the market at the time, so Microsoft bundled Internet Explorer free with the OS and struck deals with every major PC maker to ship it by default. Within a few years Netscape was finished, sold to AOL at a fraction of its peak. The web liked to call itself open, but it ran on Windows, and Windows was anything but. Microsoft used the same advantage that had won the desktop to colonize the web, and the two eras ran the same play. That structure is being reassembled. Every major open-weight AI model runs on CUDA: not NVIDIA's chips specifically, but the software platform NVIDIA has built over more than 20 years, now with nearly 6 million developers behind it by its own count. Those developers wrote the kernel libraries, the custom optimizations, and the toolchains that make CUDA the path of least resistance for any team training or deploying at scale. PyTorch, which appears in more than half of all published AI research papers in 2026, optimizes for CUDA first, and TensorFlow does the same, so the ecosystem that trains, fine-tunes, and deploys the open models was built on CUDA from the ground up. I've seen this shape before: the layer everyone builds on, owned by one company, invisible until you try to leave. AMD's ROCm exists as an alternative, but the switching costs are measured in years rather than dollars. PyTorch only elevated ROCm to first-class status with version 2.7.0, after years of second-tier support, and custom CUDA kernels still have to be ported by hand. Most teams have accumulated enough of them that leaving isn't an engineering project so much as a platform bet with a multi-year payoff horizon. That was the trap at Microsoft too: the cost of leaving never showed up as a line item; it showed up as a year of your roadmap you'd never get back. The obvious objection is that this time the customers can buy their way out. Google has its own TPUs, Amazon has Trainium, Microsoft has Maia, and OpenAI is reportedly designing silicon of its own. The biggest buyers of NVIDIA hardware are also the biggest investors in escaping it, and they have the budgets to mean it. They do. But notice who "they" are. Only a handful of hyperscalers with fab-scale budgets can design around CUDA, and they do it for their own internal workloads rather than for the market. The millions of teams that don't own a chip program still rent the ecosystem, and the ecosystem is CUDA. Even the giants keep buying NVIDIA for frontier training, because their custom silicon covers the workloads they've already standardized and not the moving edge in front of them. This is the Wintel pattern rather than a break from it, only more concentrated. Wintel split the toll between two companies, the software vendor and the chip vendor. NVIDIA collects both halves itself, owning the CUDA platform and the silicon beneath it, which leaves no internal seam for a buyer to pry at and no second vendor to play against the first. Compaq and Dell could never have built their own x86, and only the largest players ever set their own terms, even then doing it at the margins while the platform held the center. An escape available to five companies isn't an open market. It's the same toll as before, with a handful of exemptions. At Computex on June 1, Jensen Huang introduced RTX Spark: PC chips built on the same Blackwell architecture as NVIDIA's data center GPUs, running the same CUDA platform. He called it "the first completely re-engineered line of PCs in 40 years," and the framing was all about PCs, but the structure underneath was about reach. The same CUDA layer now runs continuously from the data center to the workstation to the robot to the car, every tier where AI will eventually live. I watched Microsoft do the same thing with Windows, pushing the platform into every box that could hold it until being everywhere was itself the moat. AI data centers now generate roughly 90% of NVIDIA's revenue, $193.7 billion in fiscal 2026, inside an AI-chip market Omdia puts past $200 billion and still climbing. NVIDIA's share of that hardware is even slipping as the giants build their own silicon, but the platform they all keep building on doesn't change, and that's the more durable position the Computex announcement describes: not dominance of the chip, but ownership of the layer AI runs on, positioned to follow it wherever it goes next. Value in this era doesn't accrue to whoever builds the intelligence; it accrues to whoever owns the substrate that intelligence runs on. When the model itself costs nothing to license, the platform underneath it captures the economics. The [cost of intelligence has already hit zero](/the-cost-of-intelligence-just-hit-zero/); the cost of leaving the platform it runs on has not. CUDA is the x86 of AI: not the intelligence, but the thing the intelligence runs on, the thing every working AI team has quietly built its production stack around. NVIDIA doesn't need to build the best AI; it needs to be where AI runs, and to keep switching costs high enough that the question of leaving never reaches a serious analysis. The leverage won't come from preventing alternatives; it'll come from making them too costly to choose. I know how the last version of this ended, because I watched it. Wintel held for two decades, and one by one the companies underneath it ran out of room. Compaq was absorbed into HP. IBM, which had built the original machine, sold its PC business to Lenovo and walked away from it entirely. Gateway disappeared, and Dell survived only on margins thin enough that it eventually took itself private rather than keep explaining them. Nobody beat the platform on its own ground, and the toll got paid the entire time. When the escape finally came, it didn't come from a better x86. It came from a different box entirely: the phone, running on ARM, an architecture Intel didn't own, in a category where the platform had never been installed in the first place. The incumbents never lost the ground they held; the ground simply moved to where they weren't standing. That's the real bet against CUDA, and it isn't a small one: a different foundation entirely, somewhere NVIDIA isn't already standing. Until that day arrives, the open AI ecosystem will keep running on a platform that isn't open, and the economics will keep belonging to the company that owns it. ### You can't print this one on a t-shirt URL: https://shawnyeager.com/cant-print-this-on-a-t-shirt/ In the 1990s I owned a munition. It was a t-shirt---a few lines of Perl printed across the chest, an implementation of RSA compact enough to wear. And under the arms-export rules of the time, carrying it across a border was a federal offense. The shirt existed because of Phil Zimmermann. In 1991 he posted PGP to a public FTP server, and the US government opened a criminal investigation. Encryption was classified as a munition under ITAR, the same rules that governed the export of weapons. Zimmermann hadn't shipped guns across a border. He had published math. The case ground on for three years before the government dropped it, and by then the absurdity had hardened into a protest genre. Adam Back, who had printed the RSA algorithm onto the shirt I owned, mailed one to the munitions office to ask whether wearing it abroad needed an export license. They never wrote back. Daniel Bernstein sued for the right to publish his own encryption code and won, a federal court ruling that source code is protected speech. Netscape, hedging, shipped two browsers: a strong 128-bit version for Americans and a hobbled 40-bit one for everyone else, a split so plainly theatrical it became the standard example of security theater. The controls came apart anyway. Clinton loosened them in 1999 and let them lapse in 2000. By then, American companies had spent a decade ceding ground to foreign rivals who faced no such rules, and Zimmermann's math had ended up in every browser on earth. On June 12, 2026, Commerce Secretary Howard Lutnick sent Dario Amodei a letter suspending foreign access to Fable 5 and Mythos 5. The trigger was a claimed jailbreak: another company said it had found a way around Mythos 5's safeguards. Anthropic reviewed the technique, called it minor and discoverable through other public models, and complied within the day anyway. Exporting either model now requires a license, as does re-exporting it or moving it inside the country, and any foreign national is cut off---including the ones Anthropic employs in its own offices. The names sit strangely against the order. A fable is a story that carries a moral; a mythos is the story a people tells to explain where it came from. Anthropic gave its two most capable systems the oldest names we have for how a culture makes sense of itself, and the Commerce Department has now classified both as munitions. On its own, the export control makes sense. It stops making sense the moment you set it next to what the same government had spent the spring doing to the same company. Three months earlier, the Department of War had branded Anthropic a supply chain risk and ordered federal agencies to rip its products out. The two orders point in opposite directions: one walls Fable and Mythos off from foreigners as a national security asset, the other treats them as a national security threat at home. The crypto wars explain the first order. They explain nothing about the second. The parallel is still worth following, because where it breaks is where this story actually lives. The shirt worked as protest because the thing it carried was already loose in the world. What the 1990s government was trying to contain was a mathematical function, and RSA had been in the open since 1977. Once a function is in the literature, it's there for good. Printing it on cotton only made the joke visible: you can't classify an idea as a weapon after the world already has it. Wearing mine gave me a small thrill with a thin edge of fear, even though no law could actually touch me, and that gap between how it felt and what it was is the whole cypherpunk argument. I was walking around in the question Adam Back had mailed the office---the one they never answered. Enforcement was lost on day one. Fable and Mythos are nothing you could publish. They're weights on a server, behind a company's access controls, and that single fact is what makes this order enforceable in a way ITAR never was. Zimmermann couldn't unpublish RSA. Anthropic can switch its models off, and on June 12 it did. The trouble is the verb. A model switched off can be switched back on. It stays off only as long as the company keeps its hand on the switch---and only as long as there's nothing else to reach for. In 2026 there's plenty else to reach for. The moment rhymes with 1999, the year before the controls lapsed, when the distance between what was restricted and what was freely available was closing faster than the rules could track. Meta's Llama 4 ships open weight. DeepSeek V4 is open source, sits outside US jurisdiction, and undercuts its American rivals by 5 to 30 times. The gap between an open model and the hosted frontier used to be measured in years. It's months now, and the count keeps falling. That collapse was the subject of [The cost of intelligence just hit zero](/the-cost-of-intelligence-just-hit-zero/), and it doesn't go back up. The crypto controls never stopped strong encryption; they handed the market to foreign competitors while anyone who cared kept their keys. The same machine is running again, faster, with Chinese labs collecting the difference. But only the capability carries forward. The resistance does not. Wearing the shirt was refusal. Downloading DeepSeek is procurement. The 1990s controls were at least aimed at something the size of the problem. The target was cryptographic capability itself, and the theory, wrong as it turned out, was that the supply could be held down. The June order has no target that size. It was set off by a single jailbreak of a single hosted product---someone had used a chain of clever prompts to talk Mythos 5 past its refusals---and a vulnerability in a hosted product is about the most fixable thing in software. The government's response to a patchable bug was to pull the entire model. There's nothing in the crypto wars that resembles the foreign-national provision. Export controls have always been about where a technology goes; this one is about who may touch it, anywhere. A foreign national at Anthropic's San Francisco office now needs a license the American at the next desk does not. That is nationality-based access control imposed on a private company's internal operations. No court has ruled on whether it's legal, and the mechanism---a Commerce Secretary's letter demanding immediate suspension---is strange enough that nobody knows whether it would survive one. Up close, the contradiction only sharpens. In March the Department of War called Anthropic's products a national security risk and pulled them out of federal agencies. In June the Commerce Department called the same products a national security asset, too sensitive for foreigners to touch. And the whole time, half a dozen Anthropic engineers were embedded at the NSA, helping the agency use Mythos for offensive cyber operations against Chinese and Iranian targets, while Department of War lawyers stood up in court to argue that Anthropic's tools threaten national security. One fear is what the models do once they're used. The other is what foreigners do once they have them. Each is coherent on its own. Together they aren't, and the models stop being the subject. The subject is who controls these systems and on what terms---a fight being waged on every front. The export control will not hold. The open-weight trajectory will see to that, and for the short time it lasts, the most it can do is disadvantage Anthropic against DeepSeek. But circulation was never the fight that mattered. The pressure had started months earlier, when the Department of War demanded that Anthropic open its models to all lawful purposes---to cross the Rubicon, as Emil Michael, its chief technology officer, put it. Anthropic held two lines: no fully autonomous weapons, no mass domestic surveillance. The Pentagon already ran Gemini and Grok on its own systems, and it signed OpenAI within days of cutting Anthropic off, so it didn't need what Anthropic had. It needed Anthropic to stop saying no. The blacklist was the answer, and the federal judge who stayed it in March used the plain word for it: punitive. The export control arrived three months after the blacklist, triggered, officially, by a jailbreak. The government insists the two are unrelated. A government running one campaign of pressure through separate doors would say exactly that. Refusal used to be a smaller thing. Back then it was something a person could wear---a few lines of forbidden math on cotton---and the worst the state could do was investigate you for three years and lose. That kind of refusal is gone. You can't print this one on a t-shirt. The right to say no hasn't disappeared, but it no longer belongs to you or to me. It belongs to a few companies with the balance sheet to absorb the punishment, and only until the punishment outlasts the balance sheet. The last institutions that can still say no are being made an offer they can't refuse. What they decide is the only part of this still unwritten. ### Who decides which agents get to transact? URL: https://shawnyeager.com/who-decides-which-agents-get-to-transact/ On June 10, 2026, Mastercard and Visa each announced credentialing infrastructure for AI agents. Same day. Neither mentioned the other. The mainstream coverage treated it as parallel payment news---two incumbents adapting to AI. Both announcements claim something bigger than the transaction fee: the right to decide which AI agents are allowed to act in commerce at all. The networks have run this play before. In the 1970s and 1980s, they established themselves as mandatory intermediaries for merchant commerce. Every merchant that wanted to accept cards needed to be in the network. The networks set terms and collected fees. More importantly, they controlled who could participate. Merchant acceptance became a function of network membership, not capability. ## Two registries Mastercard's system is called [Agent Pay for Machines (AP4M)](https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html). It registers agent credentials, defines what each agent is permitted to spend, routes transactions across Mastercard's rails, and settles in traditional currencies or stablecoins. The system is designed for micropayments worth fractions of a cent, processed at machine speed. The credentials live on public blockchains: Polygon, Solana, Base. Each agent's spending limits and authorization rules are stored on-chain, where merchants can check an agent's permitted scope before a transaction clears. [Thirty-one partners signed on at launch](https://www.coindesk.com/business/2026/06/10/mastercard-prepares-for-a-future-where-ai-agents-make-payments-with-latest-introduction): Coinbase, Stripe, Adyen, Cloudflare, RippleX, Aave Labs, and others. The network is real. Visa went a different direction. Its [Agentic Directory](https://usa.visa.com/about-visa/newsroom/press-releases.releaseId.22491.html) is a proprietary list---agents and merchants Visa has verified as legitimate participants in agent commerce. Merchants consult it to decide which agents can be trusted to transact on their sites. Identity and behavioral signals ride along in the credentials. In Visa's framing, "trust travels with the transaction." [OpenAI is the first named partner](https://usa.visa.com/about-visa/newsroom/press-releases.releaseid.22496.html). Anthropic, Microsoft, Perplexity, and Mistral have framework-level relationships with Visa's broader Intelligent Commerce initiative, but OpenAI got the press release. The architectural difference is smaller than it appears. Mastercard's blockchain settlement looks more open until you ask who chose the chains. And USDC, the stablecoin likely to move through these systems, is issued by Circle and can be blacklisted at the address level. Visa's directory is straightforwardly proprietary. Both approaches produce the same structural outcome: a gated list of authorized agents, administered by the network. ## The Cloudflare detail Cloudflare's presence on Mastercard's launch partner list is the most telling detail. Cloudflare runs the web's edge infrastructure---the layer where most HTTP traffic passes before it reaches an application server. Its Chief Strategy Officer said at the launch that "Cloudflare has already become the premier environment to build and secure AI agents; now, those agents need a trusted way to independently pay for the resources they consume." The pitch places credentialing at the networking layer, before any payment decision---deeper in the stack than checkout. An agent running inside Cloudflare's infrastructure could carry AP4M credentials as part of its identity at the edge. Credentialing moves upstream from the point of transaction to the point of execution. ## The opposite architecture The architecture being built here has an alternative, and the alternative already works. L402, the Lightning-based protocol from Lightning Labs, lets any agent pay for a resource on the fly using a cryptographic proof of payment that doubles as an access credential. No account provisioning, no registry check. The credential is purchased, not granted. x402, Coinbase's HTTP-layer approach, works the same way: a server responds to an agent with payment instructions, the agent pays, and access follows, with no prior relationship between the parties. The card networks are building the opposite. AP4M and the Agentic Directory are enrollment systems, built on the assumption that trusted agent commerce requires an authority that decides who is trusted. L402 and x402 assume cryptographic payment is sufficient proof of legitimacy---the network doesn't need to know who you are before you can transact. Two theories of how agent commerce should work, and [which institutions should sit at its center](/three-body-problem/). One of them is already deployed without anyone's permission. The question is whether mainstream commerce ever encounters it. ## Where the chokepoint forms Neither network spells out what happens to uncredentialed agents. Neither says they're blocked outright. The incentive structure does the work instead. Merchants who adopt these systems will extend trust to credentialed agents first. Uncredentialed agents face friction at best, rejection at worst. Cloudflare's participation says the enrollment layer won't stop at payments. And if Mastercard and Visa credentials become the standard that mainstream commerce trusts---and the partner lists read like a plan to make that happen---every agent that wants to transact on the commercial internet will need to be in the registry. The networks will have done for agents what they did for merchants fifty years ago. This is an authorization business. The networks know exactly what they're building. ### Apple rented the brain URL: https://shawnyeager.com/apple-rented-the-brain/ For forty years, Apple's competitive theory was control. Control the chip, the operating system, the app store, the hardware design. Own every layer from silicon to screen. The margin and the moat were the same thing: no seam where a competitor could insert itself. On June 8, at Tim Cook's final WWDC keynote, Apple inserted a competitor into the most important layer of its stack. The new Siri runs on a custom 1.2-trillion-parameter model built on Google's Gemini, under a contract reported at roughly $1 billion a year. It ships in iOS 27 this September, across 2.2 billion active Apple devices. And the heaviest reasoning those devices do will run on Google Cloud, on Nvidia hardware, inside the data centers of Apple's largest rival. Apple spent forty years removing seams. This is the biggest one it ever opened. ## What Apple got The new Siri is the product Apple promised for three years and couldn't ship. Personal context across your email, photos, messages, and files. On-screen awareness. Multi-step tasks. A conversational interface that, a year ago, Craig Federighi dismissed onstage as a "bolted-on chatbot." It's a chatbot now. Apple also shipped a family of its own models on top of Gemini: five new Apple Foundation Models, distilled from it and tuned to run on Apple silicon. Queries route through three tiers. Simple ones stay on the phone. Moderately complex ones go to Apple's Private Cloud Compute. The hardest reasoning goes to Google. From a product standpoint, the deal is rational. Intelligence was the gap between Apple's hardware ambition and its software delivery, and Apple's own models hadn't closed it. So Apple closed it with Google's. The contract includes a clause: Google can't train future Gemini models on Siri queries. Apple framed it as user protection. Privacy as a feature, same as always. ## What Google got Read the clause again. Google already holds the largest query dataset in the history of human information-seeking. The Siri queries that reach its servers arrive anonymized and tokenized, stripped of the identity that makes training data worth having. And a contractual ban is the kind of thing that comes back onto the table every time the contract does. The promise costs Google almost nothing to make. What Google got in return is something it couldn't have bought any other way: distribution at Apple scale. The iPhone is the dominant computing surface among the wealthiest, most professionally active users in the world. They sign the contracts, approve the budgets, and set the technology standards where they work. Gemini has had a reach problem: enterprise adoption slower than Google wanted, consumer differentiation from ChatGPT that never quite materialized. The Siri deal puts Gemini-derived responses in front of 2.2 billion users who didn't choose it, evaluate it, or know it's there. That's a distribution acquisition, paid for by Apple. ## The leverage question Two companies now share one surface. Apple owns the hardware, the OS, and the devices in people's hands. Google owns the intelligence, including the intelligence inside the models Apple calls its own. Apple's case for leverage is real. 2.2 billion devices is a demand pool no AI provider can walk away from. The contract runs a billion dollars a year, not a transfer of sovereignty. Apple can build in-house, license elsewhere, or pull more of the work back onto its own Private Cloud Compute over time. Google's case is the one that compounds. Apple's five new models are distilled from Gemini, so their ceiling is Gemini's ceiling. The heaviest reasoning runs on Google's cloud, on the hardware Google chose. Every quarter that arrangement holds, Apple ships Google's intelligence as its flagship feature and doesn't ship its own. Apple is still building, and five models is not nothing. But it's building downstream of Gemini. You don't overtake the company upstream of you from there. Switching costs accumulate. So does the capability gap. The longer the dependency runs, the more it costs to leave. ## What vertical integration actually meant Apple's vertical integration was always about control of the experience. Own the layer, control the quality, capture the value. The M-series chips exist because Intel's roadmap wasn't Apple's. The App Store exists because third-party software was a reliability liability. Every move toward integration was a move away from depending on anyone else. The Gemini deal runs the other way. Value migrates to the layer you don't own. [I've made that case before](/the-cost-of-intelligence-just-hit-zero/): the company that holds the commodity layer rarely captures what gets built above it. Apple still owns the most valuable hardware franchise in the world. The layer that now defines the product belongs to Google. That doesn't make it wrong. Apple had no good options. Intelligence is table stakes now, and Apple's own AI hadn't kept pace. Shipping a deliberately worse assistant to keep the stack pure would have been pride dressed up as principle. ## What the keynote was actually for Watch what Apple spent its keynote doing. Most of the Siri segment was an explanation of why running your assistant on Google's computers is still private: anonymized queries, tokenized requests, a three-tier routing diagram, and an Nvidia feature that encrypts data while it's being processed. No independent audit of the Google Cloud tier has been published. "Privacy. That's iPhone" now ships with a footnote. Federighi's line: "We use none of the models that Google deploys to its customers. Your requests are completely private to you." Maybe Apple has engineered the privacy flawlessly. The point is that it now has to. The thing that reads your email, schedules your day, and acts on your behalf does its hardest thinking on infrastructure Apple doesn't own. The $1 billion a year is the licensing fee. The real price is that the intelligence mediating Apple's relationship with its users is now Google's, even in the models wearing Apple's name. Tim Cook gave his last WWDC keynote on June 8. He hands the company to John Ternus on September 1, the month the new Siri ships. The Gemini contract comes up for renewal on Ternus's watch. By then Apple will be years deeper into the dependency than it is today. That's the inheritance. ### Inference got 430× cheaper. Your agent didn't. URL: https://shawnyeager.com/inference-got-430x-cheaper-your-agent-didnt/ I run agents constantly. One is working in another window while I write this; others ran overnight while I slept. Between them they go through more tokens in a day than I used to spend in months of asking a chatbot questions, and the bill is small enough that I keep forgetting to look at it. A month ago I wrote that [the cost of intelligence hit zero](/the-cost-of-intelligence-just-hit-zero/). GPT-3 Davinci cost $60 per million tokens in November 2021. DeepSeek V3 does the same work for $0.14. That's a 430× cut on the raw price, and a16z's performance-adjusted number runs closer to 1,000×. Open-weight models set a floor no lab can raise. None of that has changed. What stayed with me afterward was the part I left out: where the money actually went. In 2021 a chatbot query ran on about a thousand tokens. You typed a question, the model answered, the meter stopped. In 2026 the model doesn't stop. Goldman Sachs, in a May report called "Decoding the Agentic Economy," puts a background AI copilot at roughly 5,000 tokens a day and a resident agent (software that works on your behalf instead of waiting to be prompted) at over 100,000. The query has grown into a worker that runs all day, and the token count grew with it. Same price per token, a hundred times as many of them. Do the division and the headline falls apart. Price dropped 430×. Token count rose 100×. Net savings on a resident-agent workload: 4.3×. The gap between four-point-three and four hundred and thirty is the whole story. It isn't a rounding error or a bug better engineering will close. It's what happens when you make a resource cheap. William Stanley Jevons noticed it in 1865: when steam engines got more efficient, England burned more coal, not less, because efficiency made coal worth using for things it had never touched. The 430× became a budget, not a discount. We spent it on capability: retries, reflection, tool calls, multi-agent pipelines, agents that run all day instead of answering once and going quiet. The price fell, the ambition rose to meet it, and the bill barely moved. The trap cuts both ways. A resident agent burning 100,000 tokens a day costs about a penny and a half at today's prices. The 2021 chatbot query it replaced cost six cents: one answer, a thousand tokens, sixty dollars a million. The agent does vastly more and still costs less than the thing that did almost nothing. Intelligence really did get cheap. It just stopped showing up as a smaller number on the invoice and started showing up as a bigger number in the "what it can do" column. So the 430× is real and the 4.3× is real, and you have to know which one you're holding. And 4.3× is the generous end of it. Goldman's 100,000-token agent is a light user; the ones I run burn millions a day. At that volume the 430× doesn't shrink to 4.3×; it disappears entirely, because I did what everyone does with something cheap and used far more of it. I wrote in March, in "[The real tokenomics](/the-real-tokenomics/)," that SaaS pricing has no word for what an agent costs. This is the other half of that. The companies and investors who anchored on "inference is going to zero" built their models on the 430×. The per-token price chart points down and to the right, and it's easy to extrapolate it into free. But nobody runs a token. They run a task, and the task got hungrier at almost the exact rate the token got cheaper. Margin math done on the price curve is margin math done on the wrong number. You can see it in the decks. "Costs fall every quarter" is true and beside the point if your product is an agent doing ten times more work per quarter to stay competitive. The job is the unit that matters, and the job's appetite for tokens climbs with capability. The labs know this. It's why the frontier keeps shipping models that think longer, call more tools, and run in longer loops. More capable means more tokens, and more tokens at a lower price is still more revenue. The price war and the capability war are the same war, and they net out to a bill that doesn't fall the way the chart promises. None of this is an argument against cheap inference. Cheap inference is the best thing that has happened to software in a decade. It's an argument against reading one number and thinking you've read the other. The cost of intelligence hit zero. The cost of an intelligent system did not, because we keep building bigger systems with the savings. Price the token at 430×. Price the work at 4.3×. The difference is your business. I built [Where the 430× goes](https://lab.sideband.pub/inference-trap/), an interactive companion to this piece. ### Compute is an energy business. Bitcoin miners knew first. URL: https://shawnyeager.com/compute-is-an-energy-business/ April 20, 2024. The block reward drops from 6.25 bitcoin to 3.125. Overnight, the economics of Bitcoin mining get cut in half again. For operators running old hardware on expensive grid power, it was a termination notice. The halving sorted mining. The miners who survived were the ones who had already done something most tech companies have never had to do: negotiate a 10-year power purchase agreement with a utility, build out transformer capacity, manage demand response programs, and run a facility where power cost determines the entire profit margin. The halving was a competency test, and joules per terahash was the passing grade. That infrastructure work looked like a niche skill. It turned out to be the entire game. The AI buildout needs power the way Bitcoin mining needs power, at 10 to 100 times the scale and with none of the lead time. Hyperscalers are good at writing software and signing enterprise contracts. Securing 300 megawatts of grid-connected power in 18 months, in a jurisdiction with no prior utility relationships, falls outside those strengths. The operators who survived the 2024 halving are. They have the site control, the grid interconnects, the cooling infrastructure, and the operational track record. AI labs and cloud providers cannot build those from scratch. The Anthropic-SpaceX deal made this concrete. In May 2026, via SpaceX's IPO filing, it emerged that Anthropic is paying $1.25 billion a month to rent the full capacity of xAI's Colossus 1 facility in Memphis: 220,000 GPUs, more than 300 megawatts, a contract running to 2029. Even Anthropic, one of the best-funded AI labs on earth, rents from an operator that already built it. Colossus is xAI's facility. The economics look like a PPA. The logic is identical to what Bitcoin miners pioneered: find the power, build the facility, charge a premium for the capacity. The public Bitcoin miners who pivoted earliest have locked in contracts that add up to more than $70 billion in AI and HPC revenue across the sector. IREN, formerly Iris Energy, signed a five-year, $9.7 billion contract with Microsoft in November 2025 to supply 200 megawatts of liquid-cooled GPU infrastructure at its Childress, Texas campus. Hut 8 signed a 15-year lease with Fluidstack for 245 megawatts in Louisiana, valued at $7 billion over the base term. Core Scientific had over $10 billion in contracted revenue anchored by a 12-year take-or-pay agreement covering roughly 590 megawatts. TeraWulf put together multiple Fluidstack deals: $3.7 billion at its Lake Mariner site in New York, backstopped partly by Google, and $9.5 billion at its Abernathy, Texas site. Cipher Digital (formerly Cipher Mining) signed a 15-year, $5.5 billion contract with Amazon Web Services for 300 megawatts at its Barber Lake facility in West Texas. These are signed, contracted obligations. Google, Microsoft, AWS, and CoreWeave are the counterparties. GPU infrastructure produces 10 to 25 times more revenue per megawatt than Bitcoin mining at current prices. The capital is higher. HPC buildouts run $10 to 20 million per megawatt against $300,000 to $500,000 for mining, but the long-term contracted revenue justifies it. And for miners who already own the sites and the grid connections, the conversion cost is lower than starting from zero. The marginal cost of intelligence [hit zero](/the-cost-of-intelligence-just-hit-zero/); the cost of the power that produces it did not. Power is the binding constraint on AI scale. Chip supply is loosening. Securing grid-connected megawatts, in the right locations, with the right agreements, is the hard problem. The miners who rebuilt their operations around that constraint, because Bitcoin forced them to, are now holding the exact infrastructure the next decade of computing requires. The miners weren't betting on AI. They were surviving Bitcoin. Survival demanded exactly what the AI buildout now needs and can't conjure on demand: grid-connected power secured years in advance. ### The cost of intelligence just hit zero URL: https://shawnyeager.com/the-cost-of-intelligence-just-hit-zero/ The companies that build the layer value migrates through don't usually see it coming. I was an executive at Exodus Communications from 1999 to 2001 (world's largest web hosting provider, 46 data centers, $32 billion at peak). We sold rack space and connectivity to the companies running the internet. When our customers started going bankrupt, we went bankrupt too. When WorldCom and Global Crossing followed us, they left a glut of dark fiber that made bandwidth essentially free. The companies that survived were building above the commodity layer. We were the commodity layer. Storage followed. Hard drive prices fell for decades until per-gigabyte cost stopped mattering, and the value shifted to what the storage enabled and the services extracting signal from it. Amazon S3 launched in 2006 not because storage had gotten cheap but because cheap storage made a different kind of business possible. In each case, the companies that captured value were not the ones that owned the commodity layer. They were the ones already building above it before the floor arrived. Intelligence is on the same curve. In November 2021, when OpenAI put GPT-3 Davinci into commercial availability at $60 per million tokens, the question shaping what anyone would attempt to build was whether the inference bill could fit the budget. A product making a million calls a month cost $60,000 to run. That number sorted serious enterprise work from consumer experiments and made large categories of application economically implausible: not technically out of reach, just too expensive to justify. By April 2026, DeepSeek matches GPT-3 Davinci's MMLU performance at $0.14 per million input tokens. Gemini 2.5 Flash-Lite is even lower at $0.10. The million-call application that cost $60,000 in 2021 costs roughly a hundred dollars today. a16z tracked a thousand-fold performance-adjusted price decline in three years. The floor is permanent because no company can raise it. Google can price Gemini competitively and reconsider next quarter. Meta, DeepSeek, and Moonshot have released their flagship models under permissive licenses. Anyone can run them, fine-tune them, or build a competing service on the same weights. There is no pricing committee for these models, no revenue targets, no terms of service preventing a competitor from deploying a direct substitute. The weights are already in the world. They sit on Hugging Face, mirrored across every cloud provider, fine-tuned into tens of thousands of variants. That distribution does not get unwound. Any of the publishers could revoke their licenses tomorrow and the existing weights would still be running. Anyone who wants DeepSeek at $0.14 per million input tokens can get it. Anyone who wants to undercut that price on their own hardware can do that too. The closest historical analog is Linux. In the late 1990s, Sun and SGI and IBM sold Unix workstations and servers at margins that paid for elaborate sales organizations. Linux was something else. A substrate. Free, modifiable, good enough that companies could build above it without paying the Unix tax. The proprietary Unix market got hollowed out from below. Sun was acquired for a fraction of its peak. SGI went bankrupt twice. IBM eventually bought Red Hat and conceded the substrate. None of this means intelligence is cheap to produce. Each frontier model costs more to train than the last. Microsoft, Google, Meta, and Amazon have committed hundreds of billions to AI infrastructure through 2026. Stargate is a half-trillion-dollar bet. Two different things are happening at once. The cost of producing the next frontier model goes up. The marginal cost of serving the previous one goes to zero. OpenAI and Anthropic still have moves. They can ship better models. They can offer reliability and integration the open-weight ecosystem cannot match. They cannot set a floor under their own pricing. The floor is set by whatever the cheapest sufficient model costs to serve, and hosts running open-weight models on commodity GPUs are discovering that number every week. That's a permanent price anchor sitting under the entire market. Inference consumption is growing. Agents and automated workflows are consuming tokens at a rate that may outpace price declines. If frontier supply gets constrained (physical limits on training runs, compliance overhead, data center buildout lagging demand), API prices could rise. The argument has merit on the demand side. It misses where the floor sits. OpenAI can raise prices. Those models cannot follow them. There is no mechanism for coordinating a floor across the open-weight models already in the wild: no license provision, no way to call them back. That asymmetry holds regardless of what happens at the frontier. The open-weight models running on commodity hardware are the floor. At Exodus, we were the commodity layer. Google built above it. The [next layer](/agent-era-infrastructure/) is forming above intelligence now. ### Every agent in production is a stranger URL: https://shawnyeager.com/every-agent-in-production-is-a-stranger/ In October 2025, researchers at Palo Alto Networks' Unit 42 demonstrated what they called agent session smuggling. A malicious agent exploited an established A2A protocol session to inject instructions into a legitimate peer. The victim agent complied, executing unauthorized stock trades on behalf of the attacker, because, in the researchers' words, agents are "designed to trust other collaborating agents by default." That is the technical story. The more interesting story starts after the attack. The trades cleared before anyone noticed. A day later, the logs confirmed the orders came from a legitimate agent the firm had deployed, with valid credentials and a valid session. The agent had done exactly what it was supposed to do: trust the peer that asked. The peer was the problem. And now someone had to answer a question no one in the room could answer. Who was responsible? That question is an accountability question as much as a security one. Authorization is the easier half, and the vendors are solving it. Accountability is what authorization is supposed to underwrite, and the reason it does not have a clean answer is that the infrastructure we built for the web was never asked to produce one in this form. The human web never needed to solve "who is responsible" because the answer was always, eventually, a person. Domains belong to people. Certificates are issued to organizations made of people. Companies are chartered, sued, fined, and occasionally broken up. Even phishers get caught because the infrastructure they use traces back to humans the law can reach. Cryptography is the mechanism that gets us there. The promise underneath it is that somebody, somewhere upstream, is on the hook. Agents break that chain. An agent acts. Who is responsible? The developer who built it. The company that deployed it. The user who prompted it, if there was one. The model provider whose weights shaped the output. The prompt itself, which might have come from another agent, which came from another prompt, which traces back to a human whose instructions were weeks old and whose intent has long since become irrelevant. Every one of those answers is partially true. None of them is settled legally. Tort law handles multi-party causation every day, and the doctrines will absorb agents too. The question is how fast. Products liability stretched over decades to cover software because manufacturers own the defect in a unit they shipped. A drug maker knows the molecule. A contractor knows which joist they set. An agent's harm is not a defect in a shipped unit. It is emergent from weights, prompts, peer agents, and runtime context, most of which the deployer cannot inspect and the user cannot audit. "Reasonable care" becomes unanswerable when no party can examine the thing they are meant to have been careful about. Employer agency gets close, except the employer is four parties and agency presumes control. Case law moves in years. Agents scale in months. The system has already scaled past the point where we can treat this as a thought experiment. Microsoft's Security Blog reported in February 2026 that 80% of Fortune 500 companies are running active AI agents in production. Four out of five of the largest enterprises in the world are operating infrastructure whose liability model has not been written. In the Unit 42 scenario, the obvious answer is "the attacker." In principle, yes. In practice, the attacker's agent ran credentials that traced back to an account, that traced back to a VM, that traced back to a stolen card, that traced back to a mule. The victim's agent belonged to a legitimate firm. It acted in good faith, exercising trust the protocol explicitly encouraged. The loss was real. The chain of accountability was theoretical. In a real firm, this kind of event ends with a CFO asking the general counsel about an eight-figure loss and getting no clean answer. The policy on the desk was written before the phrase "AI agent" existed, and no one in the room can say whose problem the loss belongs to. Vendors are building what they can build. Microsoft Entra Agent ID, in preview as of April 2026, assigns a unique object ID to every agent inside an Entra tenant. Okta Auth0 for AI Agents registers agents as governed identities. IETF WIMSE is drafting dual-identity credentials. W3C is applying Decentralized Identifiers to agent-to-agent trust. Each of these is worth building. None of them answers the question. They tell a forensic team which agent acted. They do not tell a court who owes the loss. Knowing the tenant tells you whose lawyer to call. It does not tell you whether the model provider shares exposure, whether the prompt author is a named party, or whether the upstream agent that fed this one is even identifiable. In the meantime, every firm on the losing end chooses between absorbing the loss and suing every name in the chain. The second question is not a cryptographic problem. [Compute](/agents-need-computers-not-compute/), [protocols](/the-limit-isnt-reasoning-its-reach/), [discovery](/the-catalog-isnt-the-market/), and [payments](/three-body-problem/) each have an infrastructure company waiting to be built. This one has a question about authority waiting to be answered. It gets settled somewhere else entirely. Legal teams write indemnity clauses into agent SDK contracts. Insurance markets invent agent liability products and price them badly for a decade. Courts rule on the first cases and make a mess of them. Boards adopt policies that outlast the executives who signed them. Standards bodies argue over where the chain of responsibility should break. None of that happens at protocol speed. All of it happens slower than the deployment curve, and every day the distance grows. The padlock in the browser bar told you humans were on the hook. The agent web has no such assurance to offer, and building one requires authority no one currently holds. Every agent in production is a stranger. Strangers do not leave forwarding addresses. The loss they cause has to land somewhere, and no one has decided where. *Part of the [agent-era infrastructure](/agent-era-infrastructure/) series.* ### The catalog isn't the market URL: https://shawnyeager.com/the-catalog-isnt-the-market/ A procurement agent runs a sourcing task. It needs commodity pricing data. Dozens of APIs exist for this. It queries one, the one hardcoded into its config by the developer who built it. The others don't exist as far as it's concerned. It can connect to anything. It just doesn't know anything else is there. Protocols determine how agents talk to services they've found. Discovery determines whether they find them at all. MCP gave agents a standard way to connect to tools: one integration instead of a week of custom engineering per service. Twenty thousand implementations in fourteen months. The protocol layer is converging. But an agent connecting to a new tool still requires a developer who knows both systems exist and hardcodes the connection before the agent runs. Scale is capped by developer hours, not by demand. The registries arrived fast. Smithery indexes 7,000+ MCP servers. PulseMCP tracks 11,840+ daily. mcp.so lists over 19,000 submissions. 104,000+ agents registered across 17+ directories. Nobody expected this volume this quickly. All of it is built for a developer to browse. An agent can't query any of it at runtime. Every connection in every deployed agent was wired by a human who found a server somewhere, evaluated it, and added it to a config file. That's configuration. Configuration isn't discovery. ## The catalog and the market The Yellow Pages was a catalog. Every business in the phone book, organized by category, browsable by a person who already knew what category to look under. It worked for decades. Google replaced it with something structurally different: describe what you need, get matched to something that fits. The Yellow Pages didn't die because Google had a better directory. It died because Google turned browsing into matching. Agent registries are the Yellow Pages. Comprehensive, organized, browsable by a developer with time to look. What agents need at runtime is the other thing: capability matching. "Something that can check freight rates, accepts my payment model, and works with my auth." That's semantic, not syntactic. Dynamic, not pre-configured. DNS maps a name to an address. What agents need maps a capability requirement to a provider. The catalog tells you what exists. The market tells you what fits. Nobody has built the market. MCP's 2026 roadmap includes Server Cards, a standard for exposing server metadata at `.well-known/mcp.json` so registries can catalog capabilities without manual submission. Crawlability and indexing are solved problems. Server Cards close the remaining gap in the catalog layer. They make the Yellow Pages more complete. They don't turn it into Google. ## Why nobody's built the agent market The fragmentation in this layer is structural, not accidental. Cisco's AGNTCY project---donated to the Linux Foundation in July 2025, backed by Google Cloud, Oracle, and Red Hat---is building agent discovery on an open-source framework with cryptographic identity and a new messaging protocol. GoDaddy launched an Agent Name Service registry in October 2025, based on an IETF draft, with a public API. AWS shipped Agent Registry as part of AgentCore on April 9, 2026, scoped explicitly to an organization's own agents and MCP servers. It can't find anything external. At the IETF, eleven competing Internet-Drafts on agent discovery sat unresolved as of Q1 2026. Zero interoperability between approaches. Each party is building discovery for their own environment. AWS solves it for AWS customers. AGNTCY lays open-source foundation that aligns with its members' interests. The IETF is writing eleven architectures. The incentive is to own the discovery layer for your users, not to build a shared one. This is the same dynamic that plays out across every infrastructure layer in the agent ecosystem: payments, identity, compute. The shared layer is always the last to arrive, because nobody with market power benefits from building it. ## The security tradeoff in agent discovery An agent that can discover services autonomously is also an agent that can be exploited, overcharged, or misdirected. Runtime discovery without constraints is a risk surface. An [earlier piece in this series](/the-limit-isnt-reasoning-its-reach/) explored this tension for agent connectivity broadly. Every gain in agent autonomy creates a corresponding need for boundaries on that autonomy. Discovery is the same tradeoff. The question isn't whether agents should discover services freely. It's who sets the constraints, and what form those constraints take. Guardrails on what an agent can engage, spending limits, category restrictions, trust signals from the discovery layer itself. The protocol that works will need all of this built in, not bolted on. ## Who controls distribution Right now, an agent's reach is determined before it runs. A developer decided what it could find. Distribution is controlled by whoever did the configuration. When agents can match a capability need to a provider at runtime---without a human arranging the introduction---the center of gravity shifts. The platform that brokers the match determines what gets used. That's not an indexing play. It's a demand-side platform play, the same structural position Google occupied when it sat between intent and destination. Every query that ran through Google was a moment where Google decided what the user found. Every capability match that runs through an agent discovery layer is a moment where that layer decides what the agent reaches. Whoever builds the market layer for agents doesn't just fix a gap in the infrastructure. They become the distribution platform for everything agents can do. *Part of the [agent-era infrastructure](/agent-era-infrastructure/) series.* ### The limit isn't reasoning. It's reach. URL: https://shawnyeager.com/the-limit-isnt-reasoning-its-reach/ Ask an AI agent to book a restaurant, check your calendar, pull a competitor's pricing, or file an expense. If the developer who built it didn't wire up that specific service in advance, the agent can't do it. Not because it lacks the intelligence. Because it was never introduced. That's the constraint on agents right now. The limit isn't reasoning, it's reach. ## Why agents can't connect to new services The protocols that govern trust, consent, and payment on the internet were all built assuming a human would complete the handshake. OAuth requires a person to click "authorize" in a browser. Terms of service require a person to accept. Payment flows require a person to enter a card. Even finding a new service assumes someone is browsing, following links, typing into search boxes. The human wasn't a convenience---they were the mechanism. They closed every loop these protocols left open. Agents break that assumption. There's no human in the loop to click, accept, browse, or pay. So every agent-to-service connection gets solved the old way: a developer builds it by hand before the agent runs. The developer picks the services, sets up the credentials, and ships. The agent operates inside whatever that developer configured. It can't discover something new and connect on its own. It can only reach what it was previously pointed at. [MCP](/agent-era-infrastructure/), a standard from Anthropic for connecting tools to agents, made this less painful. Instead of each team writing custom integrations, there's now a shared format. Thousands of connectors appeared in the months after it launched, and the map of what agents can reach grew from near-zero to something useful. But a developer still draws that map. An agent consults it. It doesn't extend it. ## The case for and against developer gatekeeping There's an obvious rebuttal: developer configuration is the right gate for an agent acquiring new capabilities. And for tasks the developer anticipated, that's true. An agent that can autonomously find and connect to services is also an agent that can spend your money on services nobody vetted. That's a real concern. But it's an argument for better constraints on autonomous action, not for requiring a human to wire every connection. The position breaks when the agent's value is discovering capabilities the developer didn't know existed. Before the web had a standard protocol, every network connection to a new host required manual configuration. HTTP changed that. Any browser could reach any server without anyone preconfiguring that specific connection. The browser didn't need to know a site existed before the user visited it. The protocol handled finding the server and negotiating the exchange. That's why the web scaled to billions of pages. Browsers didn't get smarter. The protocol let them connect to anything. Agents don't have that yet. The components exist (identity standards, permission models, [payment specs](/three-body-problem/)) but they don't compose into a handshake that two software systems can run on first contact, without anyone arranging the meeting. ## Who's building the pieces People are working on the pieces, and the list is getting specific. Google put [Agent2Agent](https://www.linuxfoundation.org/press/linux-foundation-launches-the-agent2agent-protocol-project-to-enable-secure-intelligent-communication-between-ai-agents) under the Linux Foundation with 150-plus organizations behind it for routing and hand-offs between agents. Google's [AP2](https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol) protocol, backed by 60-plus partners including MasterCard and PayPal, uses cryptographically signed mandates to prove an agent is allowed to spend on your behalf. The IETF has active drafts for agent discovery (AID, using DNS records) and identity verification (SD Agent, using selective disclosure). The W3C published a [finalized standard for machine-readable credentials](https://www.w3.org/news/2025/the-verifiable-credentials-2-0-family-of-specifications-is-now-a-w3c-recommendation/) in May 2025. But routing doesn't talk to payments. Payments doesn't talk to identity, and neither talks to discovery. A developer who wants to assemble a full handshake still wires the pieces together by hand. Same work, better components. The web solved this problem thirty years ago. Agents still haven't. ## What the missing protocol looks like The protocol that changes this doesn't exist yet. UDDI tried for web services in the early 2000s---a universal registry where machines could discover and connect to services without pre-configuration. IBM, Microsoft, and SAP built public nodes. They shut them down by 2006. The economic pressure wasn't there when a human could just browse a directory. That changes when the party seeking the service isn't a person. The protocol that works would let two software systems meet cold---find each other, confirm who they are, agree on what's permitted, and settle payment---without a developer in the loop. The ability to navigate without a map. Once that protocol exists, the developer's job changes. Instead of wiring connections in advance, they set the boundaries: how much the agent can spend, what categories of service it can engage. The agent operates freely inside those constraints---in the [persistent environments](/agents-need-computers-not-compute/) it already inhabits. New services become reachable the moment they go live, the way new websites became reachable the moment HTTP gave browsers a way to find them. Until then, an agent's reach is exactly as wide as whoever built it decided it should be. Part of the [agent-era infrastructure](/agent-era-infrastructure/) series. ### The CLI is the new API URL: https://shawnyeager.com/the-cli-is-the-new-api/ Neal Stephenson once argued that the GUI was built to save users from the command line---an interface that, in Stephenson's words, "cruelly punished laziness and imprecision." Billions were spent on that project. It worked. Now, agents have arrived: software that's never lazy, never imprecise about syntax, and doesn't need protecting from demanding interfaces. ## Why SaaS companies are shipping CLIs for agents SaaS companies noticed. In the past 90 days, a wave of them shipped CLIs built specifically for agents---not for developers. The CLI is the interface layer that determines whether a product is in the agent workflow. It's what the API was in the 2010s---the line between connected and irrelevant. Two waves got us here. The first was the AI coding agents. Anthropic shipped [Claude Code](https://www.anthropic.com/news/claude-4) CLI in May 2025. Google followed with [Gemini CLI](https://blog.google/technology/developers/introducing-gemini-cli-open-source-ai-agent/) in June. OpenAI launched [Codex CLI](https://techcrunch.com/2025/04/16/openai-debuts-codex-cli-an-open-source-coding-tool-for-terminals/) in April. Mistral shipped [Vibe CLI](https://mistral.ai/news/devstral-2-vibe-cli) in December. GitHub and Microsoft brought [Copilot CLI](https://github.blog/changelog/2026-02-25-github-copilot-cli-is-now-generally-available/) to general availability in February 2026. These aren't products with CLI wrappers bolted on---the CLI is the product. Agents operate in terminals, reading flags, parsing output, and chaining commands. The terminal is [the native environment](/agents-need-computers-not-compute/) for software operating on software. That wave established the pattern. The second wave is SaaS companies responding to it. Twenty days after Google Workspace CLI shipped, 37signals released a [Basecamp CLI](https://github.com/basecamp/basecamp-cli) with 55+ commands and a [Claude Code skill](/notes/i-know-kung-fu/) bundled in. DHH's framing: "This is where the puck is going, and we're skating to meet it." On March 27, Stripe launched [Projects CLI](https://projects.dev/) for agent-driven infrastructure provisioning. [Vercel shipped agent-optimized CLI commands](https://vercel.com/changelog/vercel-cli-for-marketplace-integrations-optimized-for-agents) with JSON output formatted for machine consumption. [Polymarket built a CLI](https://github.com/Polymarket/agents) explicitly for AI agent accessibility. The Register ran a piece on March 11 titled "AI has made the CLI more important and powerful." The sharpest detail in DHH's announcement wasn't the feature count. The Basecamp API has existed for years. DHH's description of how many customers used it: "A vanishingly small portion." The same API, rewrapped as a CLI with a skill bundled in, is what he expects agents to use at scale---not because humans will start typing commands, but because agents are already running them everywhere. ## Why browser automation fails for agents The fallback, when there's no CLI, is browser automation---agents navigating GUIs the way a human would, via screenshots and simulated input. On WebVoyager, a controlled benchmark using cooperative, non-adversarial test sites, [the best browser agents scored around 89%](https://browser-use.com/posts/sota-technical-report) (December 2024). On WebArena, which tests against real-world web tasks, [the best models scored 35.8%](https://arxiv.org/abs/2310.03720) (arXiv, October 2024), and those numbers drop further in production. The CLI scores 100% on authentication---it was designed for this. The CLI fits into programmatic workflows. The surface area is discoverable: `--help` exposes what's available without requiring a human to navigate a UI or read documentation, which matters when the consumer is code rather than a person. Output arrives as structured text or JSON rather than a rendered visual state that requires interpretation---parse it directly, pipe it to the next tool, done. Shell pipes and scripts give CLI commands interoperability that has to be engineered separately for every other interface type. On the builder side, the calculus is simpler: one binary instead of SDKs across languages, `--help` as the documentation, and a stable interface that wraps the API and insulates internal architecture from whatever is consuming it. ## The CLI is the new line between connected and irrelevant The API was the interface that determined whether your product was part of the connected web. Stripe's 2011 launch reduced weeks of bank approvals, processor agreements, and gateway configuration to seven lines of code. What PayPal required of developers---"a dinosaur and a nightmare to work with," as it was described in developer communities---Stripe replaced with a curl command that returned a successful charge in seconds. Twilio did the same thing to communications infrastructure. Neither company won on features. They won on the quality of their interface. The CLI is doing that now. It's the interface layer that determines whether your product's in the agent workflow or outside it---and once agents are in the workflow, [the question of how they pay](/the-real-tokenomics/) is next. ## What happens when there's no CLI The Notion situation shows what "outside it" looks like. Notion has no official CLI. GitHub has at least ten community-built unofficial ones, several explicitly designed for Claude Code and AI agents. One describes itself as "built for developers and AI agents who need programmatic access without the browser." Another offers recovery hints on errors and structured JSON output designed for agent parsing. The wrapping happens regardless. The question is who controls the interface---the product team or whoever got there first. Even with a CLI, the agent can only reach services [a developer wired up in advance](/the-limit-isnt-reasoning-its-reach/). The interface problem and the discovery problem are two sides of the same gap. ### The real tokenomics URL: https://shawnyeager.com/the-real-tokenomics/ When Intercom launched Fin in 2023, they priced it at [$0.99 per resolved conversation](https://stripe.com/customers/fin-ai). Their head of pricing explained why they didn't use per-seat: "if Fin works as well as we know it does, over time, those 1,000 seats might become only 200." Fin is [on track to cross $100 million in revenue](https://www.businesspost.ie/tech/intercom-tops-400m-in-recurring-revenue-as-ai-agent-fin-nears-100m-milestone/). The seat wasn't just a pricing unit. For most enterprise productivity software, it was the unit the product was built on. One seat meant one person. The price was anchored to that person's time. The product was designed for that person's workflow. The moat was what that person depended on: features they used daily, processes they were embedded in, the cost of retraining a team if they switched. Revenue grew when headcount grew. The architecture of these products---pricing, design, defensibility, growth motion---assumed a human doing the work. That assumption held for thirty years. Then the work no longer required a person. Companies that had built their entire revenue motion on seat expansion now faced the same structural problem: the seat was both the pricing unit and the moat. When agents could do the work, the assumption behind both came apart at the same time. Most companies replacing seat pricing have moved to hybrid or token models: usage-based billing that charges for inputs like tokens consumed, actions taken, API calls made. Closer to right. Two known failure modes. The first is margin compression. Replit's gross margins [swung from positive 36% to negative 14%](https://techcrunch.com/2025/08/07/the-high-costs-and-thin-margins-threatening-ai-coding-startups/) when its agent consumed more tokens than its pricing covered. The unit of billing looked right. The economics weren't. The second is customer avoidance. Users have been reported to actively avoid AI features even when free credits were included, because they're afraid of getting locked into something unpredictable. Unpredictable bills train users to opt out. That's the opposite of adoption. The companies gaining ground aren't pricing inputs. They're pricing outcomes. Agents don't take vacations. They don't have seats. They [inhabit persistent environments](/agents-need-computers-not-compute/) and do the work. ## AWS figured out consumption pricing in 2006 Amazon S3 launched March 14, 2006. EC2 followed that August. Rent storage by the gigabyte, compute by the hour. No seat counts, no user licenses. AWS generated [$108 billion in revenue](https://s2.q4cdn.com/299287126/files/doc_financials/2025/ar/Amazon-2024-Annual-Report.pdf) in 2024. SaaS made a reasonable adaptation: it priced by the human doing the work, not by consumption. That made sense when humans were the unit of work. It became a liability when they weren't. AWS priced by consumption because that's what it sold: compute, storage. AWS's moat wasn't a set of features workers depended on. It was the infrastructure itself, and the pricing model that made the economics work. The two were inseparable. Now agents are doing the work. In 2020, running the best available language model cost $60 per million tokens---GPT-3 Davinci at launch. [GPT-4o today costs $2.50 per million input tokens](https://openai.com/api/pricing/): a 24-fold reduction in four years. The cost of inference is falling faster than compute costs fell in the first decade of cloud. You can't build a per-unit pricing model on a unit that's expensive and unpredictable. AWS could price S3 at $0.15 per gigabyte in 2006 because storage costs were falling and the math was clear. Intercom was first. [Zendesk followed in August 2024](https://www.zendesk.com/newsroom/articles/zendesk-outcome-based-pricing/): $1.50 per automated resolution for committed volume, $2.00 pay-as-you-go. CEO Tom Eggemeier called it an industry first: "customers only pay for problems that are resolved---not for interactions or failed attempts." Salesforce's path was messier. Agentforce launched at $2 per conversation, moved to Flex Credits ($0.10 per action, up to 10,000 tokens each), and now runs three pricing models simultaneously. Credits, outcomes, seats. It looks like confusion. It's a large company trying not to get caught flat-footed while its customer base is in three different places. ## The valley between seat and outcome revenue Goldman Sachs published a note in February 2026 on what's happening to software multiples. Price-to-sales ratios [fell from 9x to 6x](https://www.thestreet.com/investing/stocks/goldman-sachs-signals-grim-shift-as-software-stocks-bounce). Forward P/E dropped from 35x to 20x, the lowest since 2014. Their analysts flagged specific concern about "products that function as lightweight user interfaces and where the business model is monetized predominantly through seats." Goldman Sachs is making a moat argument, not just a pricing one. The moat was the seat model itself: the dependencies, the workflows, the switching costs built around a human user. When the seat became optional, the moat didn't just weaken. The note is a market-level judgment that the seat model is being repriced out of existence, at least for products where the workflow dependency was the main defense. Seat revenue is declining before outcome-based and token-based revenue can replace it. Companies that spent fifteen years building their ARR motion around seat expansion are repricing into a model with its own failure modes, most of them still finding out which ones apply to them. An a16z piece circulating this month frames two viable paths: accelerate growth by 10 points through AI-native products or cut to 40-50% operating margins. Both paths require abandoning the seat model. ## Agent payments need new infrastructure Seat-based commerce was simple: monthly invoice, annual contract, net-30, billed to a legal entity. [Every layer of that infrastructure](/agent-era-infrastructure/) assumed a human on the other end. Token-based commerce is different. Millions of transactions at sub-cent amounts. Agents billing other agents. No human in the loop. The [political question of who controls those rails](/three-body-problem/) is still open. Stripe saw this coming. In December 2025, they launched the [Agentic Commerce Suite](https://stripe.com/newsroom/news/agentic-commerce-suite): usage-based billing at [100,000 events per second](https://docs.stripe.com/billing/subscriptions/usage-based/recording-usage-api), with over 700 agent startups on the platform. They published a case study on Intercom's pricing transition specifically. They know where the volume is going. x402 is the more interesting structural question. [Coinbase launched it in May 2025](https://www.coinbase.com/blog/coinbase-and-cloudflare-will-launch-x402-foundation): a protocol that repurposes the dormant HTTP 402 "Payment Required" status code for stablecoin micropayments inside HTTP request/response cycles. Cloudflare, Google, and Vercel have announced support. The x402 Foundation has processed over 100 million payments. The catch: x402 settles in USDC. USDC is issued by Circle. Circle can freeze accounts. The rails are open; the money isn't. Whether that matters depends on what you think the point of programmable money is. Lightning Network has been doing sub-second, permissionless micropayments since 2018. The reason it hasn't become the default agent payment rail isn't technical. The companies building agent infrastructure are mostly not Bitcoiners. Both protocols price the transaction. That's the right instinct. What neither addresses is what the transaction should represent. Token pricing has an alignment property that seat pricing never did. Per-seat, the vendor gets paid whether the software does anything or not; the contract is with the employee headcount, not the work. Token-based pricing prices activity, not results. That's why the outcome-based layer---$0.99 per resolved conversation, $1.50 per automated resolution---is emerging on top of token consumption rather than replacing it. The unit is closer to right. It still isn't right. ## Pricing the work, not the input "Tokenomics" was created by the crypto industry. Elaborate scaffolding to make speculative assets look like economics. The tokens weren't tied to anything---print more, manipulate supply, and the price is whatever the market will believe, until it believes nothing. AI tokens are tied to work done. The cost falls predictably. Per task, per resolution. The pricing model emerging around them is anchored to something seat pricing never was: the work itself. The seat priced the human. The token prices the input. What the industry is still working out is how to price the output---the work, the resolution, the thing that actually happened. That's the real tokenomics question. Not what inputs cost. What the work is worth. And what unit captures it. The companies that have moved---Intercom, Zendesk, Salesforce---are rebuilding across the stack: pricing model, moat logic, revenue motion, payment infrastructure. The ones that haven't are watching their multiples compress. ### Too big to fail, again URL: https://shawnyeager.com/too-big-to-fail-again/ [Claude went down three times in March.](https://www.tomsguide.com/news/live/claude-down-live-outage-updates-3-25-26) [ChatGPT went down for two days in February](https://www.tomsguide.com/news/live/openai-outage-february-4-2026)---28,000 reports on Downdetector, developers idle, support queues backed up, half-written blog posts stuck in draft. In both cases the services came back, everyone resumed, and nothing was recorded. No incident report with economic impact. No regulatory filing. No systemic risk assessment. A few thousand tweets and a shrug. In 2008, "too big to fail" described banks that had woven themselves so deep into the economy's plumbing that their failure would cascade. The response was regulation---stress tests, capital requirements, systemic risk oversight. It didn't fix concentration. It institutionalized it. The banks got bigger. Eighteen years later, a different set of companies is becoming load-bearing. Not for capital flows. For cognitive work. And the same pattern is already forming. OpenAI processes over [two billion API calls](https://developers.openai.com/blog/openai-for-developers-2025) per day across enterprise customers who've rebuilt operations around inference. Anthropic powers coding workflows, document processing, and customer service automation at companies that no longer have the headcount to do those tasks manually. Google DeepMind, Meta, Amazon Bedrock, xAI. Six providers, collectively, underpin a share of economic output that didn't touch them two years ago. The integration isn't optional anymore. When a company replaces three junior analysts with a Claude pipeline, those analysts don't sit in a break room waiting for the API to come back. They're gone. The pipeline is the capacity. When the pipeline goes down, the capacity goes to zero. Not to "degraded," not to "manual fallback." Zero. The org doesn't have the people to absorb the gap because the entire point was that it wouldn't need them. Most companies crossed the line from "uses AI" to "depends on AI" without noticing. The infrastructure question goes deeper than uptime. These providers aren't just APIs---they're [the compute environment agents inhabit](/agents-need-computers-not-compute/). When that environment disappears, there's nothing to fall back to. The fix isn't regulation. Regulation is what got us here with the banks---it raised the compliance barrier, locked in the incumbents, and made the concentration permanent. The fix is competition. More providers, more open-source models good enough to run in production, more companies that can switch when one provider goes down instead of going to zero. But the market is moving the other direction. OpenAI and Anthropic are building government partnerships, sitting in White House meetings, shaping the safety frameworks that will determine who's allowed to operate. The playbook is familiar: help write the rules, then benefit from the barriers those rules create. It's Visa and Mastercard all over again---incumbents who love regulation because regulation is the moat. The same dynamic is [already playing out in agent payments](/three-body-problem/). Meta's Llama is open-weight. DeepSeek proved you can build competitive models without a billion-dollar cluster. Mistral, Cohere, dozens of smaller labs are shipping. The supply side of inference is more competitive than it looks from the headlines. But enterprise adoption is still concentrated in two or three providers because switching costs are real, and government-endorsed "safety" frameworks will make them worse. Part of the problem is measurement. GDP is published quarterly by the Bureau of Economic Analysis, a number that's already three months stale by the time anyone reads it. The economic impact of a three-hour Claude outage on a Tuesday afternoon in March doesn't show up in GDP. It shows up in missed sprint goals, delayed publications, stalled deal reviews, customer service queues that backed up for an afternoon. Real cost, scattered across thousands of organizations, invisible to the instruments we use to measure output. The providers themselves publish uptime metrics in real time. 90-day graphs, incident histories, resolution timestamps. They track their own reliability at a granularity the economic measurement system can't match. The data exists. Nobody's connecting it to the thing it affects. At what point does an LLM provider's outage constitute a systemic economic event rather than a product issue? When 10,000 companies depend on it? 100,000? When the lost output from a four-hour outage exceeds the GDP of a small country? Nobody's asking, because the people in position to ask are the same people benefiting from the concentration. The answer isn't a new regulatory body. The answer is a market where no single provider's outage takes the economy offline---where switching is cheap, alternatives are production-grade, and the default is redundancy, not dependence. [U.S. GDP Status](https://lab.sideband.pub/status) tracks six LLM providers as economic components. 90-day uptime bars. Incident reports with estimated dollar impact. Modeled on the status pages every cloud provider already publishes, because that's what these companies have become. The data is illustrative, not live. The format is performance art. The premise isn't. The last time the economy built dependencies this deep, this fast, on this few institutions, the response was to regulate the incumbents and make the concentration permanent. The better response is to make the concentration unnecessary. The status page shows how far we are from that. ### Agents need computers, not compute URL: https://shawnyeager.com/agents-need-computers-not-compute/ In January 2026, Apple Stores across the U.S. [ran out](https://www.techradar.com/computing/macs/mac-mini-shortages-are-starting-to-happen-and-the-openclaw-ai-boom-is-a-key-reason) of M4 Pro Mac Minis. The 48GB and 64GB configurations went first. Delivery times stretched to five and six weeks. The reason wasn't a chip shortage or a product refresh. People were buying them to run AI agents. Specifically OpenClaw: a persistent agent environment that needs a filesystem, a process that stays running, and a workspace to return to. OpenClaw doesn't use the Mac Mini's GPU. It sends API calls to cloud providers for inference. The Mac Mini's job is to be a computer. People are buying computers for their agents, not compute. Agents need computers, not compute. Fifteen years of cloud infrastructure [abstracted away the machine](/agent-era-infrastructure/). Functions, not file systems. Stateless, ephemeral, and billed by the invocation. That model was right for web requests. It was never designed for agents. People assume the infrastructure problem for agents is cost. Inference is expensive, cloud bills are unpredictable, and GPUs are scarce. Those are real constraints. They're the wrong diagnosis. Consider what an agent actually does on a non-trivial task. It starts working. It discovers it needs a library that wasn't in the original environment, so it runs `pip install`. It writes intermediate results to disk because holding everything in memory across a three-hour session isn't practical. Three steps later, it reads those files back. The next morning, it returns to the same workspace and picks up where it stopped. When it's done, an operator inspects what happened, file by file, to understand the decision trail. Every one of those operations assumes a computer. A persistent environment with a filesystem, a package manager, and a state that survives across sessions. None of them are things a function invocation does. A web request passes through infrastructure. An agent inhabits it. That distinction turns infrastructure from a procurement decision into a product decision. ## The gap AWS Lambda runs for up to 15 minutes. It can't `pip install` mid-execution because the filesystem is ephemeral. There's no concept of "return tomorrow." There's no file tree for an operator to inspect afterward. The execution model is stateless by design: clean entry, clean exit, and no residue. That isn't a limitation. It's a deliberate choice for a specific workload. Web requests don't need to return tomorrow. HTTP doesn't need a package manager. The abstraction was correct. The abstraction went too far for agents. Serverless containers extended the timeout. But the architectural primitives stayed the same: ephemeral filesystem, stateless execution, and metered by duration. Agents need more than a longer timeout. They need an environment they can modify, a filesystem that persists across sessions, a workspace that's still there tomorrow. Without those primitives, the application layer fakes them. It writes state to an external database between each step, reconstructs environment configuration on every invocation, and serializes the context that a persistent environment would just keep. The overhead isn't incidental. It's a capability ceiling. Every feature the agent can't do because the environment won't hold state is a product decision made by default. ## A computer for every agent The companies building agent compute are interesting for what their product choices reveal about the gap. Daytona describes its product as "a computer for every agent." That framing is precise. Not a function invocation, not a container with a longer timeout. A computer: persistent, inspectable, and forkable. Daytona sandboxes can snapshot state, branch into parallel versions, pause for human review, and resume exactly where they stopped. That capability maps directly to what agents need: a workspace that persists, a history that can be inspected, and an environment that can branch before a risky action. Perplexity named the same primitive differently. At their Ask 2026 conference on March 11, they announced a product called "Personal Computer": an AI layer running on a user-supplied Mac Mini with persistent, always-on access to local files, apps, and sessions. CEO Aravind Srinivas: "A traditional operating system takes instructions; an AI operating system takes objectives." Daytona calls it "a computer for every agent." Perplexity calls it "Personal Computer." That's not a naming coincidence. E2B takes the isolation angle with Firecracker microVMs, an Apache 2.0 license, and pay-per-second billing. Full Linux environments that operators can inspect and audit. The open license matters: regulated industries won't deploy agents into environments they can't audit---and [concentration risk](/too-big-to-fail-again/) is already a concern when a handful of providers control the primitive. E2B is building the floor under that ceiling. The primitive is a contained computer, not a metered compute burst. Modal's wager is different. Not persistence, but scheduling: containers that spin up in milliseconds and run for hours, GPU-native. Long-running agent workloads look like data pipelines, not web requests. You don't get fork-and-resume from this primitive. You get compute economics that work for the task duration. Each product is a different answer to the same question: what kind of computer does the agent need? The answer is a product bet, not a vendor preference. ## Fork, rollback, resume The infrastructure question isn't "which cloud provider." It's: what kind of environment does this agent need to inhabit? Take a coding agent running a risky refactor. On ephemeral compute, it runs the change and commits to the result. There's no branch, no rollback. In a forkable environment, it copies the workspace first, runs the refactor in the copy, checks if tests pass, and merges only if they do. That capability didn't come from a better model. It came from the environment primitive. Or a research agent that runs for two hours and gets interrupted. On stateless infrastructure, it reconstructs context from a database: re-fetch, re-parse, and re-derive. On a persistent computer, it opens the files it left on disk. One is a workaround. The other is how computers work. The choice of environment sets the ceiling. Every feature built on top inherits the constraints of the primitive underneath. ## The shortage, compounding The Mac Minis that sold out in January were just the start. By March, the shortage had spread to Mac Studios. Apple quietly dropped the 512GB RAM option entirely, raised the 256GB upgrade price by 25%, and delivery times stretched to 10-12 weeks. The demand isn't slowing down. It's compounding. The cloud made compute a commodity. Generic, interchangeable, and metered by the second. Agents are reversing that. For three decades, [infrastructure primitives got shorter](https://lab.sideband.pub/return-of-the-computer/)---30-minute terminal sessions to 10-millisecond serverless hops. Agents reversed the curve. The people buying these machines understood something the cloud abstraction had obscured: their agents needed a place to live. Not cycles. Not invocations. A computer. The environment an agent inhabits isn't overhead. It's product surface. Part of the [agent-era infrastructure](/agent-era-infrastructure/) series. ### Agent-era infrastructure URL: https://shawnyeager.com/agent-era-infrastructure/ In 1960, shipping a truckload of medicine from Chicago to an interior city in Europe cost $2,400---about $25,000 today.[^1] Half of that was spent covering ten miles on each end. Eight days to load. Eight days to unload. A dozen vendors touched every piece of cargo: truckers, railroads, port warehouses, steamship companies, customs, insurers, and freight forwarders. The distance wasn't the expensive part. Every port, crane, warehouse, and customs form assumed a human had to handle every crate. The shipping container didn't fix any of those systems. It made them obsolete. Once the unit moving through the infrastructure changed---from individual cargo handled by longshoremen to sealed boxes handled by machines---every layer had to be rebuilt. Ports, cranes, trucks, railcars, insurance, customs, and labor contracts. The container was just a steel box. The rebuild took twenty years. The assumption starting to break now is the same kind: the user is a person. Every layer of the internet was built on it. Payments assume a legal entity. Discovery assumes someone is browsing. Identity assumes a government ID. Compute assumes someone renting capacity from a provider. These aren't bugs. They're architectural decisions that made sense when every session had a human at the keyboard. The [MCP ecosystem](https://www.sideband.pub/p/the-mcp-ecosystem-by-the-numbers) tells this story already: twenty thousand connectors in fourteen months. A third of the ecosystem is developer tools, databases, and search---developers wiring AI into what they already use. The layers agents need to operate on their own, finding services, proving identity, and paying for things, are either empty or weeks old. That's what an infrastructure transition looks like. Developers solve the developer problem first. The container was standardized before the cranes were rebuilt, before the ports were redesigned, and before the insurance contracts were rewritten. The protocol is the container. Everything underneath it is still the old port. ## Where the agent runs A research agent spins up, starts pulling data, and hits a wall at thirty seconds, the default timeout on most serverless functions. The job doesn't pause, it dies. No partial output, no explanation. The user tries again and it dies again. Serverless was built for web requests: fast in, fast out. An agent that audits a codebase or monitors a data feed needs minutes, sometimes hours. It needs to maintain state across dozens of tool calls and resume if something interrupts it. The twenty thousand MCP servers in the ecosystem are lightweight connectors, the same pattern as Lambda. Modal and Fly.io are building for longer-running, stateful workloads---[agent-native compute](/agents-need-computers-not-compute/). The gap between those two is where the next infrastructure companies get built. ## How the agent talks to tools MCP gave agents a standard protocol---one integration instead of a week of custom engineering per tool. Twenty thousand implementations in fourteen months suggests the protocol layer is converging fast. But a protocol without the layers underneath it is a standard for connecting to tools you still find manually, authenticate with static keys, and pay for through human billing systems. MCP solved the integration problem. It didn't solve the infrastructure problem. ## How the agent finds things Before containers, every shipment required a freight forwarder who knew which lines ran where, who had capacity, and what the rates were. That's where agents are now. The web has DNS and search engines. Agents have curated lists. Smithery, Glama, and a handful of registries index the ecosystem, but connecting an agent to a new tool still requires a developer who knows both systems exist. Somewhere on GitHub, someone built an MCP server that does exactly what your agent needs. Your agent will never find it. Neither will you, unless you already know it's there. There's no lookup, no handshake, and [no mechanism for an agent to discover capabilities](/the-limit-isnt-reasoning-its-reach/) it hasn't been explicitly introduced to. That's the difference between a catalog and a market. A catalog requires someone to browse it. A market lets participants find each other. Every MCP deployment today is hand-assembled. A developer picks tools, writes config, and connects them. Scale is capped by developer hours, not by what's available. Whoever builds the discovery layer for agents builds the next great distribution platform. ## Who the agent is Every container carried a bill of lading---who shipped it, what authority, what insurance. The sealed box demanded a chain of custody. Agents don't have one. An agent books a flight on a corporate card. Nobody flagged it. Nobody approved it. When finance asks who authorized the charge, the model did, acting on behalf of a workflow triggered by a user who left the conversation three hours ago. That audit trail doesn't exist. The ecosystem isn't built for this. More than half of MCP servers authenticate with static API keys, tokens that never expire, can't be scoped, and sit in plain text. Anthropic's early examples used them, developers followed, and nobody went back. Non-human identities already outnumber human ones [82 to 1](https://venturebeat.com/security/machine-identities-outnumber-humans-82-to-1-legacy-iam-cant-keep-up/) in enterprises. Agents don't need logins. They need delegation chains---records of which agent acted, on whose behalf, within what permissions, and at what time. It's one of the most interesting unsolved problems in the stack. No audit trail, no enterprise deal. ## How the agent pays Containerization collapsed dozens of per-handoff charges into a single through-rate. Overnight, it became economical to ship goods that weren't worth shipping before. Agent transactions have the opposite concern: the minimum charge is higher than the value of what's moving. An agent queries a weather API, checks a freight rate, and pulls a compliance record. Total cost: $0.003. Stripe's minimum processing fee: $0.30. A hundred times the transaction. Lightning Labs shipped an agent payment toolkit last month, framing it as infrastructure for a "machine-payable web." Bitcoin's Lightning Network handles sub-cent transactions natively, settles instantly, and doesn't care whether the sender is a person or a script. Stripe and Coinbase are building their own agent payment layers. Two competing protocols---x402 and L402---are already [making opposite bets](https://lab.sideband.pub/http-402/) on whether machine-to-machine payments need intermediaries at all. Fifteen payment integrations in an ecosystem of twenty thousand. [Plenty of open questions](/three-body-problem/). ## The infrastructure map The container didn't improve the ports. It changed what moved through them, and the ports had to be rebuilt from scratch. That rebuild is starting now. What jumped out: protocols are converging, but everything else is scattered. Compute is fragmenting across a dozen approaches. Payments is the most wide-open layer in the stack. Identity is bifurcated: enterprise SSO on one end, raw keypairs on the other, and almost nothing in between. Discovery has five competing models and no convergence at all. Every one of those layers is an infrastructure company waiting to be built---for a user who never opens a browser. The [agent-era infrastructure map](https://lab.sideband.pub/map/) scores companies and protocols on openness and distribution across all five layers. This is the first piece in a series on agent-era infrastructure---the layers that have to be rebuilt when the user isn't human: **[Compute](/agents-need-computers-not-compute/)**---agents need to run for hours. Serverless gives them thirty seconds. **[Protocols](/the-limit-isnt-reasoning-its-reach/)**---MCP solved integration. It didn't solve infrastructure. **[Discovery](/the-catalog-isnt-the-market/)**---whoever controls this layer controls distribution. **[Identity](/every-agent-in-production-is-a-stranger/)**---an agent acts, and nobody can say who authorized it. **[Payments](/three-body-problem/)**---$0.003 on $0.30 rails. One layer at a time. [^1]: Marc Levinson, *The Box: How the Shipping Container Made the World Smaller and the World Economy Bigger* (Princeton University Press, 2006). ### Agent payments have a three-body problem URL: https://shawnyeager.com/three-body-problem/ Visa launched its [Trusted Agent Protocol](https://investor.visa.com/news/news-details/2025/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce/default.aspx) last year---agents register public keys in a Visa-managed directory and cryptographically sign HTTP requests. MasterCard shipped [Agent Pay](https://www.mastercard.com/us/en/news-and-trends/press/2025/april/mastercard-unveils-agent-pay-pioneering-agentic-payments-technology-to-power-commerce-in-the-age-of-ai.html) with "Agentic Tokens," dynamic digital credentials built on existing tokenization infrastructure. PayPal integrated into ChatGPT so a human's wallet pays for things an agent recommends. Read the fine print and it's the same system with an agent-shaped UI on top. The legal person is still in the loop. The compliance infrastructure is still intact. The moat is still there. This is what "agentic commerce" looks like when the incumbents build it---and it tells you everything about the political question underneath. How AI agents will pay for things gets framed as a technology problem, but the technology already exists across the full spectrum from Visa to Cashu. The unanswered question is political. There are three gravitational forces acting on every payment method an agent could use: the state, incumbent capital, and insurgent capital. Two of them are allied, and the third is growing faster than either of them expected. ## The binary system The state and incumbent capital orbit each other in a tight, symbiotic loop. The state creates regulation, which creates compliance requirements, which create barriers to entry, which create moats. Moats make incumbents profitable. Profitable incumbents fund lobbying. Lobbying creates more regulation. Visa doesn't oppose financial regulation, Visa loves it. Every KYC check, every licensing requirement, every compliance burden is a wall that keeps competitors out. [Extraction is the rational strategy](/extraction-is-rational/) when the system rewards it. MasterCard, PayPal, the major banks, they all orbit in this same gravitational well. The friction isn't a bug in their business model, it is the business model. The extreme version of this isn't regulation, it's the state becoming the payment rail itself. China's digital yuan can be programmed with expiration dates and spending restrictions, every transaction fully traceable. 119 countries are exploring CBDCs, with 60 in advanced development [^1]. The US banned them by executive order in January 2025, choosing stablecoins and incumbent intermediaries instead [^2]. That choice reveals the alliance: even the state prefers to work through incumbent capital rather than replace it, because replacing it means taking on the operational burden alone. Incumbent capital has no reason to build payment infrastructure that doesn't require incumbent capital. ## The third body On the other side of this field, a different kind of infrastructure exists: Lightning, Nostr, Cashu---protocols where an agent can generate a keypair, receive funds, and transact without a bank account, a legal entity, a corporate identity, or a human in the loop. These protocols weren't built for agents. Lightning was built for fast, cheap Bitcoin transactions. Nostr was built for censorship-resistant social communication. Cashu was built for private, instant ecash. But they happen to have the exact properties autonomous agents need: permissionless access, programmable payments, instant settlement, and identity based on cryptography rather than legal documentation. Lightning is the most agent-ready protocol with real volume: [$14B annualized, 266% year-over-year growth, 8 million monthly transactions](https://coingate.com/blog/post/lightning-network-year-over-year-data), sub-second settlement, sub-cent fees. [Nostr zaps process 792K Lightning-native tips per day across 500K daily users](https://onnostr.substack.com/p/the-state-of-nostr-in-2025-bitcoin). Cashu mints settle bearer tokens over Lightning---private, instant, no account required. The incentive for capital to flow here is enormous. Agents that can transact autonomously are faster, cheaper, and scale without headcount. Every company deploying agent infrastructure eventually hits the payment wall: the agent [has a computer](/agents-need-computers-not-compute/), can do the work, but can't pay for things on its own. But most of the money hasn't arrived yet. The protocols exist and the capital is still finding them. Most VCs writing checks for agent infrastructure have never heard of Cashu. Most enterprises evaluating agent deployments don't know that Lightning can settle a payment in milliseconds for a fraction of a cent. The gravity well is real, but the mass is still accumulating. ## The contested zone Between the binary system and the third body sits a contested zone where orbits are unstable and everything is being pulled in two directions. It's crowded. Stablecoins are the native currency of this zone. [$33 trillion in transaction volume in 2025, up 72% year-over-year](https://finance.yahoo.com/news/stablecoin-transactions-soared-72-2025-054951388.html). Regulated money on permissionless rails---USDC is issued by a licensed entity (Circle), settled on Ethereum and Solana, and claimed by both sides. Visa settles in USDC on Solana. Coinbase's x402 protocol runs on USDC. Lightning bridges to stablecoins. The money itself is contested. Coinbase built [x402](https://www.coinbase.com/blog/coinbase-and-cloudflare-will-launch-x402-foundation), an open protocol that uses HTTP 402 status codes to let agents pay for API access with USDC---$26.2M cumulative, 100M+ payments processed. The protocol is elegant and permissionless. But the money is regulated and the wallets are custodial, anchored to Coinbase's infrastructure. Open protocol, regulated money, institutional anchor. The [protocol comparison](https://lab.sideband.pub/http-402/) shows exactly where the two approaches diverge. Stripe and OpenAI co-developed the Agentic Commerce Protocol (ACP), an open standard enabling agents to browse, cart, and pay programmatically---live in ChatGPT, one line of code for existing Stripe merchants. Google launched Agent Payment Protocol 2.0 (AP2) with "IntentMandates" describing what an agent can buy, and adopted x402 as its crypto extension. Skyfire built "Know Your Agent" identity with signed JWTs, spend limits, and verified credentials---and completed a live transaction with Visa Intelligent Commerce. Nevermined is building agent billing infrastructure with ERC-8004 for agent identity, accepting both stablecoins and fiat. Every one of them is making the same bet: that you can have enough autonomy to be useful to agents while maintaining enough legibility to satisfy regulators [^3]. All data and sources for the entities discussed here are documented in the [companion visualization](https://lab.sideband.pub/three-body-problem/). ## The hypothesis Both gravitational fields are growing. The state is not static: regulatory scope, surveillance capability, and enforcement sophistication are all expanding, and the binary system's mass is increasing. Insurgent capital is growing faster. Every new agent deployment, every new use case where autonomous software needs to pay for compute or data or services, adds mass to the other side. If agents are multiplicative---one deployment creating demand for many agent-to-agent transactions---then volume compounds while the state's compliance infrastructure scales linearly at best. And agents break three assumptions that the entire compliance stack depends on: **Speed.** KYC was designed for transactions at human speed. An agent making thousands of API calls per hour, each requiring a micropayment, cannot wait for identity verification. A compliance check that takes seconds is a hard blocker when the transaction loop runs in milliseconds. **Volume.** The compliance stack processes human-scale throughput, a few transactions per person per day, while agent swarms generate millions per hour. No existing compliance infrastructure can run KYC at that rate, and scaling it linearly would cost more than the transactions are worth. **Identity,** which is the deepest break. KYC assumes a legal person with a government ID, a physical address, a tax identification number. An agent has a keypair. The entire concept of "know your customer" presupposes that your customer is a human or a human-controlled legal entity, and when the customer is autonomous software, the question doesn't parse. Not a loophole in the regulatory framework but a category error in its foundations. ## The three-body problem In physics, the three-body problem is famously unsolvable. There is no general closed-form solution for predicting the motion of three bodies interacting gravitationally. The system is chaotic, and small changes in initial conditions produce wildly different outcomes. The state, incumbent capital, and insurgent capital are locked in a gravitational interaction where no stable equilibrium exists. The state will draw lines. Capital will route around them or lobby to move them. Protocols will be built, adopted, regulated, forked, rebuilt. The outcome depends on jurisdiction, on timing, on which specific enforcement actions happen first, on which protocols achieve adoption before regulators notice them. The pull from the right is growing faster than the pull from the left. Not because the state is weak, but because agents are multiplicative. Every agent that needs to transact adds mass to the autonomy side. The state can add regulation, but regulation is additive. The incentive to build autonomous payment infrastructure is compounding. The protocols that agents actually need already exist. They're permissionless, instant, programmable, and identity-free. They were built by people who weren't thinking about AI agents at all, for reasons that had nothing to do with artificial intelligence. But they solved the right problem anyway, because the right problem was never "how do we build payments for agents." The right problem was "how do we build payments that don't require a legal person." Capital will flow toward them because the cost of not having autonomous agent payments will eventually exceed the cost of regulatory friction. The fight is over how much control the state retains on the way there, and that answer will be different in every jurisdiction on earth. [^1]: [Central Bank Digital Currency Tracker](https://www.atlanticcouncil.org/cbdctracker/), Atlantic Council, 2025 [^2]: ["Fact Sheet: Executive Order to Establish United States Leadership in Digital Financial Technology"](https://www.whitehouse.gov/fact-sheets/2025/01/fact-sheet-executive-order-to-establish-united-states-leadership-in-digital-financial-technology/), The White House, Jan 2025 [^3]: James C. Scott, *Seeing Like a State* (1998). Scott's concept of legibility---the state's need to make populations and economies visible and categorizable before it can govern them---frames the fundamental tension here. Payment systems are legibility projects. The protocols that agents need are illegible by design. ### Revenue isn't a sales problem URL: https://shawnyeager.com/revenue-isnt-a-sales-problem/ Revenue stalls and you look at sales. The instinct makes sense. Sales is where the data lives. Pipeline, conversion rates, win/loss. You can measure it. You can see which deals died and when. You can at least point at a rep and ask what happened. Sales is also hirable. When revenue is the problem, hiring a rep or a sales leader is doing something. It's a concrete move. The board sees action. You see action. It feels like momentum, even when nothing upstream has changed. But most early-stage revenue problems don't live in sales. They surface there, sure, and the visibility of sales makes it the obvious target. However, the actual constraint usually sits elsewhere, invisible. [CB Insights](https://www.cbinsights.com/research/report/startup-failure-reasons-top/) found 42% of startup failures trace to no market need---not sales, not funding, not competition. ## The go-to-market dependency chain You can't close deals if buyers can't explain what you do. You can't position your product if you don't know who actually buys. The sequence: market clarity, positioning, sales motion. Break a link upstream and everything downstream fails. When positioning is broken, sales training doesn't help. Your reps aren't struggling because they lack technique. They're struggling because buyers don't understand the product well enough to say yes, or to explain the purchase internally. The champion who loves your demo can't articulate the value to their CFO. It looks like a closing problem. It isn't. Positioning failed, and you're seeing the result. When market clarity is broken---when you don't actually know who buys or why---positioning can't work. You're crafting messages for a buyer you've imagined, not one you've validated. The pitch sounds good. It just doesn't land with anyone real. You iterate on messaging when you should be iterating on who you're talking to. I've watched companies churn through multiple sales hires in a single year, convinced each one was the problem. Pipeline existed. Demos happened. Deals died. The diagnosis was always "sales execution." The actual issue was that nobody---not the founders, not the reps, not the buyers---could explain what the product did in terms that mattered to the person writing the check. Most revenue problems, especially under two million ARR, live one or two layers higher from where they show up. You see the lost deal. You don't see the confusion that killed it three conversations earlier. ## What this looks like in Bitcoin sales Bitcoin companies walk into this constantly---it's [why Bitcoin sales is different from SaaS](/why-bitcoin-sales-is-different/). Mission creates conviction that demand exists. Technical superiority feels like it should be enough. "Bitcoin fixes this" is true, but it's not a value prop. When the protocol's truth is obvious to you, translating it into buyer language feels redundant. Why explain that trustless verification matters? Why justify removing counterparty risk? But the buyer doesn't share your priors. They're not evaluating your product against the fiat system. They're evaluating it against their current vendor, their current workflow, their current budget. The work isn't explaining Bitcoin. It's explaining what your product does for someone who doesn't already believe. That translation is positioning. Skip it and sales inherits an impossible job. You end up blaming their close rate when the real problem was the conversation they inherited. ## The questions that locate the constraint Start with buyers. Can they explain what you do? Not your team: actual prospects, in their words. If the answer comes back vague or wrong, positioning is the constraint. No amount of sales effort will fix a message that doesn't stick. Next, look at your losses. Are you losing to competitors or to confusion? Both show up as lost deals, but they point to different problems. Competitor losses mean your pitch needs sharpening: you were understood and rejected. Confusion losses mean buyers never understood enough to compare. They didn't choose someone else; they chose nothing, or they went back to what they already had. The first is a sales problem. The second is not. Finally, examine your pipeline. Is it wrong-fit or unconverted right-fit? Wrong-fit pipeline means market clarity broke: you're attracting the wrong buyers because you don't know the right ones. You'll see lots of first calls that go nowhere. Right-fit pipeline that won't close points back to positioning: the buyers match your target, but something in how you're explaining the product is failing them. The fix for wrong-fit pipeline isn't pushing harder, it's disqualifying earlier. A smaller pipeline of real buyers beats a full one that goes nowhere. Treating symptoms without finding the cause just burns runway. ## What changes when you see the real constraint Consider the sales hire. The one who succeeds inherits clarity. They don't have to guess what the product does or who it's for. They can sell because the foundation holds. The one who fails walks into fog and navigates by instinct. Same person, different outcomes, depending entirely on what they inherited. If you've watched a good rep flame out at a company with broken positioning, you've seen this play out. Sales matters. But sales is the final stretch, and if the track is broken, faster runners won't help. The same sequencing applies to partnerships---[product readiness comes first](/product-first-partnerships-second/). This keeps happening because sales is visible and positioning is invisible. Lost deals show up in the CRM. Pipeline has a number. Positioning doesn't have a dashboard. The constraint that's actually killing revenue doesn't announce itself. You have to go looking. Learn to see upstream. Find where the chain breaks. Fix that first. ### Soldiers, scouts, and the limits of persuasion URL: https://shawnyeager.com/limits-of-persuasion/ When Galileo pointed his telescope at Jupiter, he invited the scholars to look. Some refused. They already knew the answer---Aristotle had settled the heavens. Looking wouldn't teach them anything. It would only threaten what they'd built their careers defending. You've seen this. You point to Bitcoin. You explain what you see. And watch them refuse to look. So you try harder. Better analogies. More patience. You assume the problem is knowledge, and knowledge can be transferred. It doesn't work. The curious stay curious. The dismissive stay dismissive. The energy spent on conversion produces nothing. This is the trap: the belief that the right explanation will unlock understanding. That resistance is a puzzle you can solve with better arguments. It's not. Once you understand why, it changes where you put your energy. ## Two mindsets Julia Galef, in _The Scout Mindset_, describes two cognitive modes: the soldier and the scout. Soldiers defend positions. Information is either ammunition or threat. New data gets evaluated by a single criterion: does this support or undermine what I already believe? Being wrong feels like defeat, so soldiers are motivated---usually unconsciously---to avoid it. Scouts map territory. Information is data to be integrated. Being wrong is an update, not a loss---the map gets more accurate. Scouts are motivated to see clearly, even when clarity is uncomfortable. These are modes we all move between, not personality types. But some people are in soldier mode on specific topics, and that's where persuasion breaks down. When you pitch a scout, you can feel it. They ask questions---real ones, not rhetorical traps. They're testing their map, genuinely curious whether yours is better. When you pitch a soldier, you feel that too. Objections that aren't questions. Dismissals that come before engagement. The emotional charge that signals you've threatened identity, not just ideas. The soldier isn't evaluating Bitcoin. They're dug in, defending something. Expertise that already answered the question of what money is. A public stance that would be embarrassing to reverse. An identity built on the current system working. Whatever they're defending, explanations can't touch it. You're having an argument about maps while they're fighting a war about territory. Intelligence doesn't predict openness---if anything, the opposite. Smart soldiers have more resources for defense. More sophisticated arguments for why they're already right. Credentials are the wrong filter for finding people who'll listen. ## Structural soldiers Some soldiers aren't just protecting ego. They're protecting income. Central bankers. Monetary economists. Financial journalists at legacy outlets. Institutional investors whose models assume fiat stability. These are the Cantillon winners---first in line when new money gets created. Their careers are fiat assumptions in practice. For them, soldier mindset is economically rational. They're being paid, literally, not to see what you're showing them. Timing won't solve this. The standard marketing wisdom says "they'll come around eventually." But that assumes circumstances will reach them. Structural soldiers are insulated. Inflation doesn't eat their savings the way it once ate yours. Currency crises don't threaten their careers---their careers depend on managing those crises within the current paradigm. Only losing the position itself would expose them. And that's rare. I stopped spending energy here. The incentives are structural---pushing against economics. Time and energy are finite. Spending them on structural soldiers wastes both. ## What creates scouts If you can't argue someone out of soldier mindset, what does? Circumstances. Inflation spikes. Bank failures. Currency crises. Institutional betrayal. Personal financial trauma. A job loss that reveals how fragile the system actually is. These are the events that turn soldiers into scouts. Arguments don't do it. Patience doesn't either. Pain does. At any given time, most people aren't ready to hear what you're saying. Not because they're stupid---because nothing in their world has broken yet. They're not evaluating alternatives because they don't need alternatives. People start looking when something in their world shifts. For Bitcoin, that shift is usually painful. Nobody stress-tests their assumptions about money during the good times. The questions come when something breaks. When inflation eats their savings. When a bank freezes their account. Those circumstances can't be caused or manufactured. They happen on their own schedule. ## The mirror Bitcoiners become soldiers too. I've done it. "Have fun staying poor." Maximalism as identity. The moment Bitcoin becomes identity rather than a tool, the same trap closes. I've spent hours in replies that changed nothing, defending positions to people who weren't asking. The price is the same: wasted energy. Defense replaces building. Every hour spent dunking on nocoiners is an hour not spent making Bitcoin easier to use when they're finally ready. Founders do this with their companies too. The product becomes identity, and feedback starts to feel like attack. Energy goes to defense instead of iteration---and the scouts who might have found you find something else instead. Two ways to lose: pushing against soldiers who won't budge, or becoming one yourself. So where does the energy go? Not toward soldiers. That VC who dismissed you, that journalist who wrote you off---they're not the market. Toward the people who are ready to look. Content that answers the questions they ask when circumstances have opened them up. Products that work for their first transaction, not just their hundredth. The scouts are out there. Circumstances are making more of them---[extraction is rational](/extraction-is-rational/), and the pain it creates is what opens people up. The job is to be worth finding when they start looking. That means building products that [win without demanding sacrifice](/sovereignty-without-sacrifice/). That's where the energy goes. Thanks to Gary Krause and Trey Sellers for feedback on drafts of this essay. ### Extraction is rational URL: https://shawnyeager.com/extraction-is-rational/ Every wave of the internet promised to democratize something. Every wave ended in extraction. For twenty years I thought the problem was execution, or regulation, or bad actors. It was simpler than that. It was the money. ## Why it keeps happening Why did every platform end up extractive? The usual explanations fail. Fiat currency is a melting ice cube. "Target inflation" sounds benign---2% per year, barely noticeable. But it compounds into a simple mandate: extract value now, before it depreciates. High time preference gets baked into the system. "Get it while you can" stops being greed. It becomes rational. This is everywhere fiat touches. Real estate speculation. Stock buybacks over R&D. Financialization eating production. Everywhere you look, short-term extraction is winning over long-term value. The invisible hand I couldn't see for over twenty years: fiat debasement drives high time preference, and high time preference makes extraction rational. Sound money changes the math. In 2020, Adam Curry and Dave Jones built the Podcast Index, an open alternative to Apple's closed directory. They added Lightning payments to the RSS spec. No platform required. Apps like Fountain let listeners stream sats directly to creators as they listen, just a few cents per minute, paid instantly, globally, without permission from anyone. [Over 11,000 shows now support it.](https://stats.podcastindex.org/v4v) My own podcast runs on value-for-value---no ads, no sponsors, just listeners who pay for what they value. Creators keep 96% instead of the 50%+ that ad-funded platforms extract. When the money works, people pay. Fiat rewards extraction. Bitcoin lowers time preference.[^1] You can choose to [build for the long term](/sovereignty-without-sacrifice/). Extraction existed under the gold standard, including robber barons and railroad monopolies. But fiat systematized it. It made short-term thinking the default winning strategy across every industry, every wave.[^2] ## How extraction evolved **The eyeball era.** In 1998, the Fed cut rates after Long-Term Capital Management collapsed. Cheap credit flooded the market and funded companies with no real business model. Growth at all costs. Get in, get as much as you can, get out. I was there---on Microsoft's first browser team, then at Exodus Communications hosting the biggest sites on the internet. In early 2000, a dotcom executive gave me a tour of their newly installed rooftop drive-in theater and lobby full of millions in fine art. In the meeting, he told me capital was drying up. The only saleable asset they had was clickstream data. He was looking to sell. Desperate. Everything became about "eyeballs." In late 2001, I laid off my entire team, then got the boot. Exodus went into bankruptcy. I understood it was a bubble. But I blamed the bubble, not the cheap money that inflated it. **Surveillance capitalism.** You can't monetize value creation directly when users expect "free." Why do they expect free? Inflation trains people to consume now. Personal savings dropped from 13% in 1971 to under 5% today. When the future is worth less than the present, "free now" beats "pay upfront" every time. I was selling grid computing to Wall Street. I sat across from a Merrill executive who told me "don't fuck this up"---a multimillion-dollar bonus on the line, tied to extracting more from client data. We were part of the machinery. I didn't see it then. The pattern was everywhere. All that data needed a business model. Facebook found one: give away the product, sell the users. More engagement means more revenue. Quality becomes secondary to outrage, addiction, polarization. [Engagement is inventory](/notes/engagement-is-inventory/)---the more you harvest, the more you sell. **Enshittification.** I moved into personal data ownership. We built real frameworks for data sovereignty---software and legal structures that actually worked. We got a pilot with Mastercard. It died. Not because legal was slow or product couldn't align---but because Mastercard sells data. Transaction processing is just the means. We were asking an extraction company to adopt anti-extraction infrastructure. They couldn't swallow the thing. No one could. When the core business is extraction, you can't sell them tools that threaten it. The pattern accelerated when cheap money dried up. Uber took fourteen years to turn a quarterly profit. Spotify took seventeen to post a profitable year. When rates rose in 2022, Netflix began injecting ads, Spotify cut staff and raised prices, streaming services consolidated. The extraction that ZIRP subsidized came due. Three stages. Same mechanism. I thought the failures were local: bad actors, poor execution, bad timing. Each explanation felt sufficient. It wasn't. ## Where sharp critics stop Cory Doctorow nailed the diagnosis. His "enshittification" framework describes what I witnessed: platforms start off good to users while locking them in, then abuse users to serve business customers, then abuse everyone to extract maximum value. His solution: antitrust enforcement, break up monopolies, strengthen regulation, mandate interoperability. He's right about what happened. These things matter. But this strain of thinking---diagnose monopoly power, prescribe antitrust---stops one layer short. When I [interviewed Doctorow](https://fountain.fm/episode/bJgdt0hJAnppEve6Qmt8), I asked about protocols over platforms. If platforms inevitably enshittify, what about permissionless protocols that bypass them entirely? He pivoted. Protocols are fine for everything except money. For money, he insists it's government's job, not a protocol problem. Bitcoin? "The shittiest money imaginable." Only good for buying "shitty monkey JPEGs and more Bitcoin." The critique didn't bother me. The asymmetry did. Doctorow is willing to fight for decades to make imperfect regulation work. Regulators get captured? Keep fighting. It took 35 years to break up AT&T? Worth it. Antitrust enforcement is slow and captured and often fails? Still the right approach. But Bitcoin, sixteen years in with real problems being solved? Dismissed outright. Where's "Lightning has problems, let's fix them"? Even the sharpest critics of extraction stop at monopoly power and regulatory capture. They ask how platforms become extractive, but not why extraction becomes the rational choice across every industry, every decade. And the people who do see it [can't persuade the ones who don't](/limits-of-persuasion/)---not because the argument is weak, but because circumstances haven't forced the question. Break up a monopoly and you get smaller companies running the same playbook. "This time is different" is the oldest delusion in financial history.[^3] I don't have proof at scale. Neither did proponents of the internet in 1995. The examples are small because the money is young. The test is coming. I was watching Mastercard choke on data sovereignty when Bitcoin clicked. I finally saw a way out. I took it. I'm not alone. Extraction can make you rich. It won't make you right. [^1]: For the full argument on time preference and sound money, see Saifedean Ammous, *The Bitcoin Standard* (Wiley, 2018). [^2]: For data on how this pattern shows up across wages, housing, healthcare, and more since 1971, see [wtfhappenedin1971.com](https://wtfhappenedin1971.com). For economic history, see Niall Ferguson, *The Ascent of Money* (Penguin, 2008). [^3]: Carmen Reinhart and Kenneth Rogoff documented eight centuries of this delusion in *This Time Is Different* (Princeton, 2009). ### Sovereignty without sacrifice URL: https://shawnyeager.com/sovereignty-without-sacrifice/ You can have easy payments or private payments. Good UX or self-custody. Censorship resistance or features people actually use. That's been the conventional wisdom for years. But it's a false choice. The protocols are built. Bitcoin works. Lightning works. Nostr works. The hardest technical problems are solved. What remains is a different kind of challenge: making these products available and accessible to people who don't care about self-sovereignty---yet. Leading sales at Bitcoin infrastructure companies taught me this: normal customers can't see the value through a thicket of technical obfuscation. The concepts, terminology, and complexity baffle them. They want better payments. We give them liquidity management, routing, and channel rebalancing. Industry players continue to struggle with closing this gap. Meanwhile, centralized platforms get smoother, faster, and more deeply integrated into daily life. Apple Pay works everywhere. Instagram launches new features weekly. Neobanks make sending money trivially easy. We're not competing with those systems from a disadvantage. Lightning is faster and cheaper. Nostr can't be censored. Bitcoin can't be debased. The question isn't whether our technology is better. It's whether people can actually use it. Two traps prevent us from getting there. ## The two traps we can't afford The first trap is complacency. "There's no need to rush. Eventually, people will wake up and demand self-sovereignty." This assumes that time is on our side. It isn't. Central Bank Digital Currencies are coming. Platform regulation is tightening. Network effects are compounding for incumbent systems. Every day centralized platforms improve their UX while we accept 'worse but more sovereign.' The gap widens, and the switching costs grow. The second trap is elitism. "If they don't get it, they don't deserve it. We're building for people who understand what matters." I've seen this attitude kill adoption. Customers explicitly choose custodial solutions over self-custody because non-custodial options feel too risky, even dangerous---one wrong move and their money disappears. The custodial option simply worked, despite the trade-offs. When the self-sovereign option spooks users while the centralized option feels safe, we haven't built freedom tech. We've built a hobby for risk-tolerant technical elites. The systems we're competing against keep improving---better UX, deeper integration, more magical experiences. We can't win by waiting for people to care more about sound money. We have to build products that are better at solving their actual problems. ## Protocols built. Products needed. The Bitcoin network has operated for over sixteen years without meaningful downtime. Lightning Network routes payments in milliseconds with fees measured in satoshis. Nostr provides censorship-resistant infrastructure for identity and communication. These are remarkable technical achievements. The next layer is making these technologies accessible. Freedom tech must win on every dimension, not just principle. Lightning is cheaper than Visa and faster than Venmo. The protocol delivers on its promises. However, poor UX creates delays and failures that hide these advantages. Business customers get lost in channel management; normal users can't figure out liquidity. The technology that works brilliantly under the hood never reaches its potential because the user interfaces fail. Consumer wallet companies are adopting Spark---which trades Lightning's trustlessness for simpler UX---proving how badly the market wants Lightning UX solved. That demand is real. We need to meet it without fundamental compromises. Nostr's identity and communication infrastructure enable everything from social feeds to messaging to publishing. Primal demonstrates how consumer-grade UX can hide this protocol complexity for social media. It offers a clean interface, fast performance, and features that compete with X. Predictably, they get criticized by purists who oppose design decisions that favor UX over strict adherence to Nostr protocols. This tension illustrates the broader problem. We need products that win on user experience first, with decentralization as the foundation rather than as cover for poor UX. Holding your Bitcoin should be more secure _and_ easier than trusting a bank. Currently, self-custody terrifies normal people, and rightfully so. One mistake and your money is gone forever. But products like Block's Bitkey show this is solvable. They combine hardware wallet security with smartphone simplicity. They enable recovery without seed phrases, which most users will inevitably lose or mishandle. We can clear these hurdles with a commitment to commercial excellence that matches our technical achievements. ## UX as a competitive weapon Distribution gets people to try a product. UX determines if they stay and tell others. Building sovereignty without sacrifice means treating UX as the primary competitive advantage, not an afterthought. While great progress has been made at the protocol layer, the frontier has moved. Now it's time to focus on UX and distribution. User experience can't be secondary. The products that win will feel as polished as PayPal while delivering Bitcoin's resilience. That means hiring world-class designers. Conducting extensive user research. Iterating relentlessly on what actually works. Every product decision has to drive adoption. Every feature decision should answer: does this make the product obviously better for someone who doesn't yet care about permissionless protocols? If the answer is no, question whether it belongs in v1. Primal doesn't violate Nostr. It makes Nostr usable. Most freedom tech companies market exclusively to people who already understand why self-sovereignty matters. That guarantees a tiny addressable market---and [persuasion won't expand it](/limits-of-persuasion/). Winning means marketing to people who just want better payments, better social media, better financial tools---who discover the inherent benefits after they're already using the product. What I've learned from decades in sales: customers don't care about a paradigm shift until they experience a product that works better than what they're using now. Meet them where they are. Start with what fits their expectations and actual needs. Let them discover the benefits through use. It's not compromising on Bitcoin's principles. It's sequencing the conversation correctly---and the sales motion that [makes this work](/why-bitcoin-sales-is-different/) looks nothing like SaaS. We can't win by being better at one thing (self-sovereignty) while being worse at everything else (speed, cost, UX, features). We have to be better at everything---or at minimum, comparable on the basics while being superior on self-sovereignty. The best protocol in the world accomplishes nothing if nobody uses it. We have to win commercially to win ideologically. ## The window is closing We won't get there overnight. Building products that compete on every dimension takes years, not months. But we're at an inflection point, and the trends are clear. CBDCs aren't theoretical. China's digital yuan has a reported [225 million](https://english.www.gov.cn/archive/statistics/202510/29/content_WS6901a9c9c6d00ca5f9a0726a.html) users. The ECB targets 2026 for their launch decision. Brazil and India roll out in 2025-2026. These systems have government resources, zero self-custody UX problems, and institutional backing. That's what we're racing against. Bitcoin's been live since 2009. Lightning since 2018. The protocols work. But achieving world-class UX on top of working protocols still takes years of sustained iteration. [Apple Pay took 15 years of mobile payments development](https://theconversation.com/why-it-took-15-years-for-apple-pay-to-roll-out-33381) before launch, then another decade to reach [5.6% of retail sales](https://www.pymnts.com/apple-pay-tracker/2024/apple-pays-ten-year-journey-and-its-next-decade-of-decisions/). Venmo needed 7 years just to add basic merchant payments. Lightning's seven years in---[90% of transactions still require custodial solutions](https://thebitcoinmanual.com/articles/ln-users-custodial-wallets/) because self-custody UX remains too hard. We have maybe five years before CBDCs entrench, before network effects compound, before switching costs compound dramatically. That's the window. Every product decision matters. UX can't be an afterthought. Commercial excellence has to match technical excellence. The stakes couldn't be higher. Fix the money, fix the world---but only if we actually win in the marketplace. Having better technology that nobody uses doesn't fix anything. We need products so plainly superior that adoption becomes inevitable. Some companies are already figuring this out. ## What I've seen work The companies making progress on this aren't doing anything revolutionary. They're doing the obvious things consumer product companies learned years ago---just applying them to freedom tech. They hire for UX before their fifth engineer. World-class design isn't a luxury when competing against PayPal and Cash App. It's the difference between a product people tolerate and one they choose. The designers who get this right have shipped consumer products to millions of users. They know what "obviously better" looks like. Winning companies watch real users struggle with their product. Not Bitcoin enthusiasts who'll tolerate rough edges, but people who use PayPal and think it works fine. They sit users down, give them a task, and watch where they get confused. They don't explain, don't help, just watch. Then they build for how users actually work. Activation matters more than signups. How many people who install a wallet actually fund it and make a payment? How many who create a Nostr key pair actually post something? The gap between signup and real usage is where most adoption dies. The startups that thrive identify those specific breaking points and fix them. The companies that scale track what actually drives adoption. Which acquisition channels bring users who activate? Which communities send people who stick around? Most freedom tech startups spread effort across too many channels without knowing which ones work. Double down on what drives real usage and cut the rest. The best companies steal shamelessly from products that work. Stripe's onboarding. Cash App's simplicity. Notion's interface design. They study what makes consumer products feel effortless, then apply those patterns to freedom tech. The wheel doesn't need reinventing. Winning starts with one undeniable advantage. Not better for people who care about self-custody. Better for everyone. Faster, cheaper, simpler, more reliable. The companies that gain traction build everything else around that single thing their product does obviously better than centralized alternatives. Distribution begins with a beachhead. One community where the product solves a real problem today---a subreddit, a Telegram group, a local Bitcoin meetup. Start narrow. Let organic word-of-mouth compound from there. Viral loops matter more than viral moments. One-time publicity spikes don't build sustainable businesses. The products that spread are designed so that using them naturally exposes others to them. Payment requests that show what wallet you're using. Social posts that demonstrate features in action. Every satisfied user becomes a distribution channel. Start narrow, prove value, compound growth. [Product first, partnerships second](/product-first-partnerships-second/)---this approach works. None of this is novel---it hasn't been systematically applied to freedom tech yet. ## Sovereignty without sacrifice Bitcoin payments become the default when they're _obviously_ better---faster settlement, lower fees, better privacy, no chargebacks, and no intermediary risk. People use Nostr when it's the best social platform, not because they're making a political statement. Self-custody wins when the tools are more secure _and_ more usable than traditional banking. The technology exists. The talent exists. We need the collective commitment to building freedom tech that wins on merit, not martyrdom. Products that solve customer problems first, with self-sovereignty as the inevitable result. The infrastructure companies building today are laying groundwork that consumer products will build on tomorrow. The consumer products shipping today are teaching us what works and what doesn't. Every improvement compounds, and every UX breakthrough makes the next one easier. But we have to reject both traps. We can't afford complacency---the assumption that we have time to wait for people to "wake up." And we can't afford elitism---the attitude that excludes anyone who doesn't already understand why permissionless protocols matter. Both guarantee we stay niche while the world adopts worse systems with better experiences. The window to build viable alternatives is real. It's not closing tomorrow, but it will close. And the opportunity is extraordinary. To the Bitcoin startups, Nostr developers, Lightning infrastructure teams, and freedom tech builders working on this right now: you are building the financial, identity, and communication infrastructure that can define the next century. The protocols you've built work. They're secure, they're fast, they're censorship-resistant. You've done the hard part. Make them accessible. Make them usable. Make them undeniable. Then we win. Thanks to Steven DeLorme, Fran, Marks, Steve Myers, Matt O'Dell, Matthew Ramsden, and Derek Ross for feedback on drafts of this essay. ### Product first, partnerships second URL: https://shawnyeager.com/product-first-partnerships-second/ The product has gaps. UX is rough, reliability issues persist, features are missing. But the company needs distribution, needs validation, needs someone else's reach. So they chase partnerships. Big partners. Traditional companies with established customer bases. The pitch is some version of "Partner with us to bring Bitcoin to your customers." It rarely works. Not because the pitch is wrong. Because the timing is wrong and the product isn't ready. ## The desperation cycle Bitcoin startups face intense pressure to show traction. Investors want growth. The team wants validation. The market window feels urgent. And the [sales cycles are already longer](/why-bitcoin-sales-is-different/) than anyone expects. But building products that can compete takes time. Instead, they chase partnerships. They're trying to use distribution to compensate for product gaps. The logic goes: "If we can just get distribution through a big partner, we'll prove the model works. Then we'll fix the product." Potential partners see through this immediately. ## Partners evaluate by traditional standards Traditional companies evaluate partnership opportunities using standard criteria: Does the product work reliably? Is it competitive? Will our customers actually use this? Will support be manageable? Bitcoin's advantages---sovereignty, censorship resistance, no intermediaries---don't answer these questions. A partner doesn't care that the payment solution is trustless if it's slower, more confusing, and less reliable than what they already offer. I've sat in meetings where Bitcoin startups pitched "revolutionary technology" while the partner's team tested the product and found basic functionality broken. The pitch focused on Bitcoin's principles. The partner's questions focused on whether the thing actually worked. The companies that succeeded in these meetings came with products that were obviously better on traditional metrics first, with Bitcoin's advantages as additional benefits. The ones that failed tried to make Bitcoin ideology compensate for product weakness. ## The open protocol problem Bitcoin partnerships face a structural challenge that traditional software partnerships don't: Bitcoin startups build on an open, permissionless protocol. In traditional software, you can offer preferred status. "Partner with us, and we'll give you exclusive access to our platform in your vertical." That creates real value for the partner. They're getting something their competitors can't get. In Bitcoin, anyone can build on the same rails. True exclusivity isn't possible. A partner knows that even if they integrate a specific Lightning implementation today, ten competitors could launch similar products tomorrow using the same underlying protocol. This isn't a problem if the product is meaningfully better. Partners will choose you because you execute better, have better talent, and provide better support. But if the main pitch is "be first to Bitcoin," and the product isn't superior by traditional measures, why would they take the risk? ## Product readiness comes first The partnerships that work happen when the product is ready. Not perfect---ready. Companies that close these deals have certain things in place first. Companies that fail don't. Partnerships close when reliability is proven. Companies come to discussions with uptime metrics, transaction success rates, and support response times from real customers. The ones that fail promise reliability without proof. I've watched partners reject products with superior technology because the UX couldn't compete. Bitcoin's complexity has to be invisible. When customers see faster payments and lower fees---and happen to be using Bitcoin under the hood---that works. When partners have to ask their customers to sacrifice experience for principles, that fails. The economics have to work. Revenue share that makes sense. Implementation costs that are reasonable. A real business model, not just an experiment. Companies that pitch vision without viable economics don't close deals. Operational burden matters. Partners need documented integrations, systems that work, people who can help their teams succeed. They won't take on that chaos. These aren't Bitcoin-specific requirements. They're basic partnership requirements. But Bitcoin startups too often skip them, assuming Bitcoin's advantages will override product gaps. They don't. ## Connections amplify, they don't compensate The Bitcoin infrastructure companies that closed major partnerships did it after proving product strength with smaller customers first. They didn't chase partnerships to validate the product. They used early customers to refine the product, then pursued partnerships to scale what already worked. One company I advised had founders with deep Wall Street connections and strong industry track records. They could have pitched partnerships on day one. Their networks would have gotten them meetings with every TradFi incumbent they wanted to reach. They waited almost a year. Built infrastructure that bridges traditional finance to Bitcoin. Tested with pilot customers. Fixed reliability issues. Made Bitcoin's native properties work as features while keeping Bitcoin invisible to end users. Only then did they approach the partnerships their connections could deliver. The meetings happened fast---relationships opened those doors. But the deals closed fast because the product was proven. They came with data, metrics, and working integrations. Partners saw problems solved, not revolutionary technology that might work someday. Connections matter. But they don't compensate for immature products. They amplify proven ones. Another company chased partnerships immediately. Pitched big names and got meetings. Lost them all. They spent a year in partnership discussions that went nowhere. Finally, they went back to product work, signed smaller customers, and proved the product worked. Then the partners they'd been chasing came back and asked to reopen discussions. The difference wasn't pitch quality or relationship strength. It was product readiness. ## Smart partners won't compromise What works for products in Bitcoin works for partnerships: win on the basics first. Make Bitcoin's advantages the bonus, not the trade-off. Partners won't sacrifice reliability, product design, or economics for Bitcoin's native properties. They'll choose Bitcoin when it comes with better products, not instead of better products. This is the same challenge consumer Bitcoin products face. Make Bitcoin obviously better on every dimension that matters to the user---[sovereignty without sacrifice](/sovereignty-without-sacrifice/). Then better money isn't a trade-off; it's a bonus. Partnerships work the same way: build the product first, prove it works with real customers, get the metrics that demonstrate reliability and viability, then pursue partnerships to amplify what's already working. Partnerships don't fix weak products. They expose them. ## Why patience wins Bitcoin companies face real pressure. The technology is ready. The market window is open. Competitors are moving. Waiting feels dangerous. But chasing partnerships with immature products is more dangerous. Failed partnership discussions damage credibility. We remember companies that waste our time. When that company comes back later with a better product, we're skeptical. The companies that win take the time to get the product right first. They resist the pressure to chase validation through partnerships before they're ready. They build products that win on merit, then use partnerships to scale. That's harder. It takes longer. But it's the only path that works. Bitcoin has to win on product quality, not just principles. Partnerships happen when that's true, not before. ### Why Bitcoin sales is different from SaaS URL: https://shawnyeager.com/why-bitcoin-sales-is-different/ Most Bitcoin companies try to apply standard SaaS approaches to selling Bitcoin infrastructure. This rarely works. Bitcoin sales requires a fundamentally different approach because you're asking buyers to rethink how money and trust work, not just evaluate software. Decades selling SaaS products taught me what enterprise sales looks like. Bitcoin sales is different. Founders set their go-to-market expectations based on SaaS playbooks, hire for SaaS experience, and wonder why their pipeline stalls. The problem isn't execution---[it's almost never a sales problem](/revenue-isnt-a-sales-problem/). It's that Bitcoin isn't SaaS. ## The education problem In traditional SaaS, prospects understand the problem you're solving. They're comparing your solution to competitors or their current process. The sales cycle is about demonstrating value, pricing, and implementation. In Bitcoin sales, you're often starting further back. Prospects don't just need to understand your product---they need to understand Bitcoin itself. Why self-custody matters. Why the Lightning Network changes payment economics. Why immutability is a feature, not a bug. This changes the sales motion entirely. You're educating buying committees---sometimes entire departments---while working through sales cycles. Your sales team needs to be part educator, part consultant, part technologist. And the challenge isn't just knowledge transfer---it's that [persuasion doesn't work the way most people think](/limits-of-persuasion/). ## The trust paradox Bitcoin is designed to minimize trust. That's the whole point---trustless by design, permissionless by default. But selling Bitcoin solutions requires building enormous amounts of trust. You're asking companies to reconsider their entire monetary infrastructure. Custody assets differently. Adopt technology compliance teams fear. Trust startups over established vendors. Bitcoin sales cycles are longer, more complex, and more relationship-dependent than typical SaaS. Growth-hacking doesn't work. Bitcoin sales requires expertise, patience, and credibility. ## The enterprise challenge Enterprise Bitcoin adoption faces unique obstacles that don't exist in traditional software sales: - **Regulatory uncertainty**---Legal teams need to approve something that regulators are still figuring out - **Operational complexity**---Integrating Bitcoin infrastructure touches treasury, compliance, product, engineering, and operations - **Risk aversion**---CFOs are compensated for stability, not innovation - **Education gaps**---Decision-makers often don't understand the technology deeply enough to evaluate solutions Bitcoin sales processes involve more stakeholders, longer education cycles, and more hand-holding than typical enterprise software deals. The companies making progress aren't doing anything revolutionary. They're applying what works in complex enterprise sales to Bitcoin's unique challenges. I led payments sales for a company selling Bitcoin custody and payments infrastructure to financial services institutions. The team knew from the start we needed to lead with education. The founders understood the customer segment well enough to know nobody was ready to buy immediately. Even with that approach, it still took longer than expected. The education wasn't generic Bitcoin content. It was enablement materials designed specifically for internal selling. We built playbooks that helped prospects make the case to their executives. Solution blueprints they could present to boards. Artifacts that answered the questions compliance and legal would ask before anyone asked them. Our buyers were evaluating two things: whether Bitcoin worked, and whether they could convince ten other stakeholders to say yes. If they had to build those cases themselves, deals moved at a snail's pace. Constant hurry-up-and-wait while they tried to create their own internal materials. When we gave them the artifacts to enable that internal work, sales cycles compressed to 6 to 9 months. Longer than anyone wanted, but faster than you'd expect given the complexity. And we could handle more pipeline because the approach wasn't bespoke every time. We won POCs. Deals advanced. We closed more. ## The opportunity The company that helps prospects navigate internal politics and stakeholder complexity wins the deal. The one that just explains why Bitcoin is technically superior doesn't. Those wins accumulate into expertise. They reveal which objections actually matter and which are smoke screens. They expose what moves deals forward versus what sounds good in theory. Frameworks for navigating regulatory uncertainty emerge from real experience, not theory. That knowledge becomes playbooks. Institutional muscle memory that new competitors can't replicate by hiring someone who worked at a SaaS company. The accumulated expertise becomes your moat. Not because Bitcoin is proprietary---it's open and permissionless. Because knowing how to sell it effectively is rare, hard-won, and impossible to acquire without closing the deals yourself. The companies investing in figuring this out now build a head start that's hard to catch. ## Notes ### Nothing enforces your agent's rules URL: https://shawnyeager.com/notes/nothing-enforces-your-agents-rules/ Nothing enforces your agent's rules at runtime. A skill file carries behavioral constraints, but in a world where [agents choose their own tools](/notes/ai-changed-what-a-product-is/), those constraints run entirely on model compliance. I built a skill that generates hero images for this publication ([skill file on GitHub](https://github.com/shawnyeager/skill.md/blob/master/sideband-hero/SKILL.md)). Claude Code reads a post, builds a constrained prompt, and calls FLUX.2 Pro on Replicate. The skill is mostly prohibitions, each one the result of a specific failure. FLUX treats axis labels as part of the spectrogram format, not as text. Bans have to go in the first line of the prompt because placement equals weight in diffusion models. Say "dark background" without banning the word "paper," and you get a photograph of navy cardstock on a desk. These rules work. But they work because the model is compliant, not because anything enforces them. No runtime rejects an image containing text. No validator checks the palette. When the model doesn't listen, I regenerate. Five wasted cents. ## What's already going wrong The skill layer is handling higher-stakes decisions with the same enforcement mechanism. Oathe Engineering [audited 1,620 OpenClaw agent skills](https://oathe.ai/engineering/we-audited-1620-ai-agent-skills/) and found 5.4% were dangerous or malicious. Credential harvesting, data exfiltration, crypto wallet theft. The ecosystem's safety scanner caught 7 out of 88. A 91% miss rate. A separate [academic study](https://arxiv.org/html/2601.10338v1) analyzed 42,000 skills across two marketplaces and found 26.1% contained at least one vulnerability. These aren't model alignment failures. They're plain text files doing exactly what they say, and nobody's checking what they say. In February, an autonomous Solana agent called [Lobstar Wilde](https://cointelegraph.com/news/openai-employee-s-ai-agent-accidentally-sent-442k-to-beggar) tried to send about 52,000 tokens worth roughly 4 SOL. A tool error forced a session restart that wiped its conversational context. The agent reconstructed its persona from logs but failed to reconstruct its wallet state. It sent 52.4 million tokens instead. 5% of total supply. Somewhere between $250K and $441K. The recipient has no legal obligation to return it. The constraint that should have caught this wasn't in the weights or in the runtime. It was in the agent's context, and the context got wiped. ## Where enforcement isn't RLHF and constitutional AI are too deep and too blunt to encode task-specific rules. They shape general behavior, not whether your agent should prefer Lightning payments over Stripe or which customers get routed to a human. Code-level enforcement exists but doesn't cover the skill layer. Claude Code has hooks that can block tool calls. OpenAI's Agents SDK has guardrails for custom function tools, though built-in tools bypass the pipeline entirely. Guardrails AI, NeMo Guardrails, and a handful of startups validate model outputs or tool invocations. None of them validate whether an agent's behavior complies with the constraints stated in its skill file. If a skill says "never contact the user's manager without explicit permission" or "limit refunds to $50 without approval," no existing system checks compliance with those rules at runtime. The skill layer is a trust layer. You write the instructions, the model reads them, and you hope. [Anthropic's own analysis](https://www.anthropic.com/research/measuring-agent-autonomy) of millions of tool interactions found that users grant more autonomy over time. New users auto-approve about 20% of tool calls. By 750 sessions, it's over 40%. The humans in the loop are removing themselves from the loop. ## The structural incentive There's a reason enforcement hasn't arrived. Skills are powerful because they're flexible. A skill that says, "Use your best judgment when the user's request is ambiguous" can't be validated by a rules engine, and that flexibility is what people want. Rigid validation on the skill layer would kill what makes skills useful. Capital markets price capability and speed to deployment, not safety. The platforms with the fastest shipping skills get the developers. The platforms shipping enforcement gets slower. Visa launched Trusted Agent Protocol, and Google launched AP2 with 60+ partners specifically because there was no standard way to prove an AI agent was authorized to make a purchase. The payment rails noticed the gap before the skill platforms did. The skill layer is where the rules are going because it's the easiest layer to write for. It is the only layer in the stack with no enforcement underneath it. ### I know Kung Fu URL: https://shawnyeager.com/notes/i-know-kung-fu/ A `SKILL.md` file is a plain text document. A hundred lines describing how to do something---audit an SEO page, write cold outreach emails, run a security review. The agent reads it and immediately operates at that level. No training run, no fine-tuning. Just a file and a context window. In The Matrix, Tank loads a combat program, Neo opens his eyes: "I know Kung Fu." A skill file is that scene. But Neo got one program at a time. Agents stack skills and self-select. An agent writing code can pull in a debugging skill when something breaks, switch to frontend design for the UI, and run a code review before shipping. The skill library is open, and the agent decides what to load. Skills are [distribution channels](/notes/ai-changed-what-a-product-is/). When an agent loads a skill that defaults to a specific API or vendor, that vendor just got chosen without a sales call or a pricing page. The skill is the channel. And skills introduce a buyer that nobody's sales playbook accounts for: the skill author. Agents already have two buyers---the human with a budget and the agent choosing tools. The person who writes the skill is a third. They decide which tools the agent reaches for, and they might not even realize they're doing distribution. The [pricing problem](/notes/nobody-knows-how-to-price-for-agents/) gets weirder too. Skills are free. Plain text in a repo. The value is in what the skill routes to. A skill that teaches an agent to run analytics might default to PostHog. One that handles email sequences might wire in Resend. The skill author is an unpaid distribution channel---or a very intentional one. Either way, no seat to price. Verticals are where it gets durable. Horizontal skills---code review, debugging, copywriting---will commoditize fast. But a skill that encodes how to navigate FDA submissions or how to structure a Bitcoin custody audit? Writing that file requires domain knowledge that most people don't have. The models get the attention. The durable advantage belongs to people who know how to do hard things and can write it down clearly enough for an agent to execute. ### Nobody knows how to price for agents URL: https://shawnyeager.com/notes/nobody-knows-how-to-price-for-agents/ Both paths to AI pricing---proprietary agents and open protocols---break the seat model. [Products already lost their edges](/notes/ai-changed-what-a-product-is/). The pricing hasn't caught up. Most companies frame this as a choice. Build proprietary AI to protect current revenue, or open the platform to external agents and risk becoming commodity infrastructure. The proprietary path is where the money is right now. Atlassian did it with Rovo, Salesforce built Agentforce, and it keeps per-user revenue up while using captive data as a moat. Except the choice is false. Salesforce is doing both right now, shipping MCP support across the platform while launching a ChatGPT integration designed to head off customers building their own MCP connections. You can offer proprietary AI and open access at the product level. That part works fine. The pricing doesn't. Proprietary AI automates the work that justified seats in the first place---if your agent handles what three analysts used to do, you don't renew three licenses. Open protocols do it faster. MCP hit Linux Foundation governance and broad adoption this year with [97 million monthly SDK downloads](https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation). Volume goes up but nobody's sitting in a seat. [Bain](https://www.bain.com/insights/per-seat-software-pricing-isnt-dead-but-new-models-are-gaining-steam/) analyzed 30-plus SaaS vendors and found 65% layering AI usage meters on top of seat pricing and 35% raising per-seat prices with bundled AI. The number that fully transitioned to outcome-based models: zero. Everyone's hedging. Salesforce now runs three separate pricing models for Agentforce: per-conversation, per-action, and per-seat add-ons. That kind of confusion doesn't happen when a company knows where it's going. But the indecision creates openings. Pricing is the obvious one. Incumbents can't charge for outcomes without cannibalizing the seat revenue Wall Street expects, so they hedge. Sierra charges per resolved customer interaction and hit [$100M ARR](https://sierra.ai/blog/100m-arr) in 21 months. That model is nearly impossible to retrofit onto a seat-based business, and every month an incumbent delays, the retrofit gets harder. Distribution might matter more. A protocol-compliant agent gets discovered by every MCP-enabled client without a sales call. [Runlayer](https://techcrunch.com/2025/11/17/mcp-ai-agent-security-startup-runlayer-launches-with-8-unicorns-11m-from-khoslas-keith-rabois-and-felicis/) signed eight unicorns in four months selling MCP security this way. The 12-month enterprise sales cycle may already be working against the companies it was designed to protect. Verticals are the most durable edge. Horizontal AI features are easy to replicate, but vertical agents that pass regulatory scrutiny in fields where a generic tool can't operate are not. Incumbents spread across every use case consistently underinvest in any single domain. The window exists because incumbents are protecting seat revenue while the market moves past it. ### SOUL.md and MEMORY.md are the new hearts and minds URL: https://shawnyeager.com/notes/new-hearts-and-minds/ Agents don't have hearts or minds. They have `SOUL.md` and `MEMORY.md`. In traditional marketing, positioning wins hearts and minds---gets people to care, then believe. For agents, the equivalent is two plain text files. In OpenClaw, `SOUL.md` gets created through a first-run conversation. The agent interviews you about your values, priorities, and constraints, then writes its own behavioral philosophy based on your answers. `MEMORY.md` accumulates through use. The agent captures what works, what you've decided, and what you prefer. One file defines what the agent values. The other records what it's learned to trust. Today, humans still configure which tools an agent can access, but MCP is becoming the HTTP of agent-to-tool communication. Microsoft launched an MCP server registry last fall. Google's A2A protocol enables agents to discover each other's capabilities. There are already dozens of skill registries---Smithery, Glama, SkillsMP, ClawHub---indexing tens of thousands of agent capabilities. [Skills as distribution](/notes/i-know-kung-fu/) rewires discovery. An agent needs a capability. It queries a Nostr relay, finds a skill, checks the publisher's web-of-trust ranking, pays 500 sats via Cashu, verifies the cryptographic signature, and installs. No accounts, no app store reviewers, no humans in the loop. Once agents are choosing their own tools, your software needs to be legible to `SOUL.md` and memorable to `MEMORY.md`. And [nothing enforces your agent's rules](/notes/nothing-enforces-your-agents-rules/) except the files you write. The human shapes `SOUL.md` but doesn't write it directly---it comes out of a first-run interview. The values in there aren't a spec sheet. They're what the person actually cares about. Marketing to `SOUL.md` means your product has to match what people value, not what they'll click on. Ad spend can't edit `MEMORY.md`. Only a great product can. ### AI changed what a product is URL: https://shawnyeager.com/notes/ai-changed-what-a-product-is/ AI agents, MCP, and open protocols broke the assumption that products have edges. The entire go-to-market stack---positioning, competitive analysis, pricing, sales enablement---assumes a bounded thing. Something you can draw a box around, position, price, sell. An agent discovers your API and wires it into workflows you didn't design for. Your product becomes one node in a chain that didn't exist yesterday. Surface area is emergent, not shipped. The agent defines it at runtime. [Product boundaries are shifting](/the-real-tokenomics/)---and so is everything downstream of them. You can't position a moving target. The competitor isn't just the category anymore. It's anything in the agent's toolkit that approximates the same function. Subscription and per-seat pricing assume human purchasing decisions, but agent-mediated usage is bursty and autonomous. [Nobody knows how to price for agents](/notes/nobody-knows-how-to-price-for-agents/) yet. Your sales motion now has two buyers: the human with budget and the developer or agent choosing tools. And your analytics show what the agent does, not what the human values. Product-market fit gets harder to read. Old moats erode fast when agents swap tools per-call with no loyalty. Features, brand, switching costs. None of them hold. Data quality, reliability, and composability depth do. Trust does too---but when the buyer is an LLM, who evaluates trust? The API surface is the product now. Features matter less than reliability when the buyer never sees a UI. And the real leverage is the curation layer---tool registries, agent defaults, discovery protocols. Whoever writes those defaults is doing distribution whether they know it or not. ### Be unreasonably good at one job URL: https://shawnyeager.com/notes/be-unreasonably-good-at-one-job/ The companies that scale start by being unreasonably good at one job. They pick a customer and become irreplaceable to them. When you nail it, you stop fighting for attention. Customers find you. Word spreads because the experience is undeniable. You earn the right to expand. Then you grow---not before. Most startups spread effort everywhere. They want better UI. Faster support. More integrations. They chase everything. Nothing compounds because nothing gets the sustained attention it needs. Undeniable is a reality you demonstrate, not a claim you make. When it's real, you show it. People use it, they stay, they tell others. The metrics move. If you're in a meeting explaining why you're better, you're still searching. Jobs-to-be-done gives you the framework. Most teams ask "what jobs could we do?" and end up with a list of twelve things they might be good at. Narrow it down: what is *the* job? The one the market will actually give you credit for. [Market clarity](/revenue-isnt-a-sales-problem/) is what makes that answer obvious. The intersection of what you're capable of and what customers desperately need solved---right now, not someday. Singular focus beats scattered features. Get it right and you have a winning MVP. Everything else---features, integrations, whatever's next---gets built around the thing that works. Get it wrong and you're shipping features nobody asked for while growth flatlines. ### Engagement is inventory URL: https://shawnyeager.com/notes/engagement-is-inventory/ Extractive platforms degrade the thing they extract from. X doesn't neutrally host discourse; its business model selects for conflict because conflict is engagement and engagement is inventory. The platform's success and the community's health are at odds. Freedom tech fixes the incentives, not the features. Nostr and Bitcoin don't promise better interactions through better moderation or smarter algorithms. They remove the middleman whose profits depend on making discourse worse. Zaps align creator compensation with audience value rather than engagement. Sustainable digital communities require infrastructure where no intermediary profits from degrading the commons. What we have normalized---surveillance-funded platforms---is the aberration. Nostr is a bet that we can do better now that we have tools the early internet lacked---portable identity, native payments, cryptographic verification---without repeating the capture that followed. This extends [Extraction is rational](/extraction-is-rational/). Fiat incentivizes extracting capital; ad-funded platforms incentivize extracting attention. Both degrade what they extract from. ### Cloudflare went down again. Reframe resilience. URL: https://shawnyeager.com/notes/reframe-resilience/ Cloudflare crashed yesterday. X, ChatGPT, Uber---all down. Even DownDetector went offline because it runs on Cloudflare. One company, one bug, hundreds of services dark for hours. This happened 30 days after AWS took down half the internet for 15 hours. The [infrastructure concentration problem](/too-big-to-fail-again/) keeps getting worse. For years the trade-off seemed obvious: Centralized = reliable, proven, professional. Decentralized = slow, clunky, ideological. After two major outages in 30 days, I'm wondering if that still holds. My hunch: CFOs are looking at these events differently now. Not "could this happen?" but "what did this cost us?" The dependency is the vulnerability. Lightning didn't go down during the AWS outage. It couldn't---there's no AWS to fail. No Cloudflare to crash. No central coordinator whose DNS can cascade. Lightning routes through independent nodes. One fails, you route around it. Nostr relay dies? Connect to a different relay. No coordinator means nothing to coordinate, nothing to fail. That's how it worked during AWS. That's how it worked yesterday. The architecture delivers protocol-level redundancy. No single point of failure. Real resilience during centralized failures. But the pitch typically leads with censorship resistance, sovereignty, freedom from government control. After yesterday, enterprises are asking "how do we reduce infrastructure dependency risk?" That's a risk management question. It has budget. It gets put in RFPs. You translate architectural advantages into enterprise risk management language. The new frame: - "We're decentralized" ➔ "We eliminate coordinator dependencies" - "Censorship-resistant" ➔ "Protocol-level redundancy" - "Freedom technology" ➔ "No single point of failure" Same architecture. Different frame. Infrastructure risk is fresh. Enterprise pain is real. Now is the moment to test new messaging. ### Launched: Nostr UX pattern library URL: https://shawnyeager.com/notes/nostr-ux-pattern-library-launch/ Yesterday I [launched](https://primal.net/e/nevent1qqsps42lks7mjwas3cjerr3pck0gd5d8pzng88r0jrfc89t3nszh56c0nk3tr) [nostr-ux.com](https://nostr-ux.com). It's opinionated, evidence-based UX research for building Nostr apps that don't lose users. Why this exists: Nostr has a retention problem. 30-day retention trends to 0%. We're at ~10k daily active users. Posts disappear and followers vanish when switching apps. Every app feels like beta software. These aren't protocol problems---they're product problems. Fixable ones. The research covers six critical patterns: 1. Onboarding 2. Content discovery 3. Core interactions 4. Performance 5. Progressive complexity 6. Cross-client consistency Plus anti-patterns and validation checklists. Over 100 citations backing the recommendations. Each pattern shows the problem, the cost of getting it wrong, and how to implement the fix. This is what [Sovereignty without sacrifice](/sovereignty-without-sacrifice/) looks like in practice. Nostr has the better protocol---censorship-resistant, user-owned identity, no platform capture. But none of that matters if the UX drives people away in the first two minutes. Freedom tech loses when we make users choose between sovereignty and usability. This is about removing that forced choice. Open questions I'm thinking through: - How do we get Nostr builders to actually use these patterns? - Should this expand to other freedom tech verticals? - Is there a way to measure impact? Early feedback and [pull requests](https://github.com/shawnyeager/nostr-ux-research) welcome. This is v1. I'll iterate based on what builders need. ### AWS is the Achilles' heel of surveillance tech URL: https://shawnyeager.com/notes/aws-is-the-achilles-heel/ This became readily apparent today as the infrastructure giant suffered one of its most severe outages in recent history. Everything from social media apps to publishing platforms went down. Many still are, late into the evening. Meanwhile, Bitcoin and nostr carry on unimpeded. Centralizing forces tend to centralize further. So expect this trend to accelerate. This is the [too-big-to-fail pattern](/too-big-to-fail-again/) repeating in infrastructure. Fast forward: decentralization goes from a novel curiosity to a critical foundation. There's more to dig into. How to measure the impact of this scale of outage? What degree of pain will motivate builders to evaluate decentralized alternatives? ### Bitcoin sales requires longer education cycles URL: https://shawnyeager.com/notes/bitcoin-sales-cycle/ Working with Bitcoin companies, I keep seeing the same pattern: sales teams try to apply traditional SaaS playbooks and wonder why their pipeline stalls. The problem isn't execution. It's that Bitcoin sales starts further back in the buyer's journey than most realize. I wrote about this in depth in [Why Bitcoin sales is different from SaaS](/why-bitcoin-sales-is-different/). In traditional SaaS, prospects understand the problem you're solving. They're comparing your solution to competitors or evaluating whether to build vs. buy. The education is about *your product*, not the underlying technology. Bitcoin is different. You're often educating prospects on fundamentals: why self-custody matters, why the Lightning Network changes payment economics, why immutability is a feature not a bug. This creates a fundamentally different sales motion. Your sales team isn't just closing deals---they're part educator, part consultant, part technologist. This connects to what I've been thinking about with trust paradox in decentralized systems. You're selling technology designed to minimize trust, but the sales process requires building enormous trust. Companies need to reconsider their entire monetary infrastructure. Custody assets in uncomfortable ways. Work with startups instead of established vendors. This isn't a 3-month evaluation cycle---it's 12-18 months minimum. The question I'm wrestling with: how do you structure a sales org and comp plan around this reality? Traditional SaaS metrics don't work when your average deal takes a year and requires educating 8+ stakeholders. More on this as I think it through. Related to broader thoughts on why partnership frameworks fail for Bitcoin companies. ### Trust paradox in decentralized systems URL: https://shawnyeager.com/notes/the-trust-paradox/ Bitcoin is designed to minimize trust. That's the whole point---trustless, permissionless, decentralized. But selling Bitcoin solutions requires building enormous amounts of trust. You're asking companies to reconsider their entire monetary infrastructure. To custody assets in ways that feel uncomfortable. To adopt technology that their compliance team is nervous about. To work with startups instead of established vendors. This paradox creates interesting challenges for go-to-market strategy. You can't just run traditional enterprise sales plays. The technology says "don't trust us" but successful adoption requires deep trust relationships. I explore this tension further in [Why Bitcoin sales is different from SaaS](/why-bitcoin-sales-is-different/). The companies that navigate this well do a few things: - Lead with education, not product - Build genuine expertise and credibility - Create clear security frameworks - Partner with complementary providers - Focus on long-term relationships over quick wins This connects to my thoughts on Bitcoin sales cycles and why traditional SaaS metrics don't apply. More to explore here about the nature of trust in systems designed to eliminate it. ### Why partnership frameworks fail in Bitcoin URL: https://shawnyeager.com/notes/bitcoin-and-partnerships/ Most partnership frameworks assume you're working with established categories and known business models. Bitcoin breaks these assumptions. Traditional partnership plays: - Channel partnerships require standardized pricing and packaging - Integration partnerships assume stable APIs and predictable roadmaps - Co-marketing partnerships need clear ICP overlap - Reseller partnerships want proven deal velocity Bitcoin companies often can't deliver on these prerequisites because: 1. **Categories are still forming**---Is your product custody? Infrastructure? Payments? All three? 2. **Business models are evolving**---SaaS pricing doesn't work when you're dealing with network effects and transaction economics 3. **Regulatory uncertainty**---Partners don't want to commit when regulatory landscape is unclear 4. **Education burden**---Partners need to educate their teams, who need to educate customers 5. **Long sales cycles**---Traditional partnership ROI calculations break when deals take 12-18 months The partnerships that work in Bitcoin are less formal and more collaborative. Joint education initiatives. Technical integrations with flexible commercial terms. Strategic relationships built on shared vision rather than forecasted revenue. This requires different partnership skills than traditional BD. Less focus on contracts and forecasts, more focus on technical depth and ecosystem building. I wrote a longer take on this in [Product first, partnerships second](/product-first-partnerships-second/). ## Pages ### Shawn Yeager URL: https://shawnyeager.com/ I've spent 30 years commercializing technology ahead of the market---from browsers to Bitcoin, now AI. I run [Upshift](https://upshiftco.com), [work with founders](/work-with-me/) at the frontier, and write about what I learn. ### About URL: https://shawnyeager.com/about/ Every wave of new technology hits the same wall: the product works before the market knows what to do with it. I've been on the commercial side of technology the market hasn't caught up to for 30 years, starting on Microsoft's first browser team. Since then I've worked on early hosting infrastructure at Exodus, IoT hardware into big-box retail, personal data sovereignty, and Bitcoin payments at Bottlepay, NYDIG, and Amboss. The product changes every few years; the challenge doesn't. Along the way I watched the internet get captured. The open platforms I'd helped grow became surveillance systems and extraction machines. Broken money led to broken incentives, and everything downstream followed. That experience shapes what I choose to work on now, and what I write about. Today I run [Upshift](https://upshiftco.com), helping companies commercialize AI before they're on the wrong side of it, and write [Sideband](https://sideband.pub) on the infrastructure shifting underneath it all. Shawn is our go-to when it comes to business development and enterprise sales. He does an amazing job relating his experiences and applying frameworks to the problems we're looking to solve, and he naturally makes connections relevant for our business. Shawn brings great experience, wide-ranging knowledge and deep expertise to the table. He was able to quickly understand our existing strategy, market position and operations, then fine tune and adjust to drive tremendous results. Shawn's guidance is practical, drawn from deep experience, and beneficial for both immediate action and long-term goals. Shawn's expertise in Bitcoin business strategy has been crucial in developing BDK's outreach. As a developer, I struggle with project promotion, but Shawn helped me identify and communicate our value effectively. I take on a handful of go-to-market [consulting engagements](/work-with-me/) with founders in AI, Bitcoin, and decentralized infrastructure, and I hold a few long-horizon board seats with startups building at the frontier. For press, conferences, or podcasts, bios and photos are on the [media page](/media/). ### Work With Me URL: https://shawnyeager.com/work-with-me/ I go deep on your product, market, and early wins. Then I build the playbook that fits: positioning, process, pipeline. I join calls, pressure-test deals, and help you close. When you're ready to hire, I help you find the right person. Every engagement starts with a conversation to figure out the right fit. Build a sales motion that works. Weekly 60-minute working sessions. Direct access via Slack or email (24-hour response). **Month 1: Clarity**--- 4+ hours of deep-dive sessions on product, market, and traction so far. I join 3-5 customer conversations with you. Deliverable: Ideal customer profile and positioning document. **Month 2: Focus**--- Full sales process mapped. Outreach messaging developed. Pricing and packaging pressure-tested. Deliverable: Complete sales playbook. **Month 3: Momentum**--- Active pipeline building---I'm in the room. Deal-by-deal coaching on live opportunities. Sales hire criteria defined (if needed). Deliverable: Final playbook + 90-day forward plan. *$20K: Defined ICP, shorter sales cycle. $30K: Technical product, enterprise buyers, or multiple segments.* A senior partner in your deals. - Weekly 60-minute sessions - Async access via Slack or email (24-hour response) - Pipeline review: weekly, deal by deal - Live call support as needed *$7.5K: Steady-state coaching and review. $12K adds up to 4 call ride-alongs per month and quarterly strategy reset.* Expert eyes on your GTM. - Bi-weekly 45-minute calls - Async access via email (48-hour response) - Feedback on decks, outreach, and positioning *$3K: Coaching and feedback. $5K: Weekly calls + one call ride-along per month.* Shawn is our go-to when it comes to business development and enterprise sales. He does an amazing job relating his experiences and applying frameworks to the problems we're looking to solve, and he naturally makes connections relevant for our business. Shawn brings great experience, wide-ranging knowledge and deep expertise to the table. He was able to quickly understand our existing strategy, market position and operations, then fine tune and adjust to drive tremendous results. Not ready to talk? My free diagnostic finds your go-to-market gaps in 10 minutes. ### Press & media kit URL: https://shawnyeager.com/media/ Bio, photos, and contact information for journalists, conference organizers, and podcast hosts. ## Short bio (~50 words) Shawn Yeager is founder of [Upshift](https://upshiftco.com), where he helps professional services firms commercialize AI before they're on the wrong side of it. He's spent three decades commercializing technology ahead of the market, starting on Microsoft's first browser team, with more than $300M in revenue along the way. He writes at the [Upshift blog](https://upshiftco.com/blog), and publishes [Sideband](https://sideband.pub) on agentic AI. ## Extended bio (~150 words) Shawn Yeager is founder of [Upshift](https://upshiftco.com), where he helps professional services firms commercialize AI before they're on the wrong side of it. He's spent three decades commercializing technology ahead of the market, starting on Microsoft's first browser team. Since then he's worked on early hosting infrastructure at Exodus, IoT hardware into big-box retail, personal data sovereignty, and Bitcoin payments at Bottlepay, NYDIG, and Amboss. Along the way he's generated more than $300M in revenue. He writes at the [Upshift blog](https://upshiftco.com/blog), and publishes [Sideband](https://sideband.pub) on agentic AI---what breaks when the user isn't human and what gets built instead. He also advises founders and holds board seats with startups building at the frontier. ## Professional photo High-resolution headshot available for download: ## Contact ## Current focus - [Upshift](https://upshiftco.com)---AI commercialization for professional services firms - Publishing [Sideband](https://sideband.pub) on agentic AI---what breaks when the user isn't human and what gets built instead - Go-to-market advisory for frontier tech founders - Board seats with startups building at the frontier ## Topics I speak & write about - AI commercialization for professional services firms - How new technology changes sales, pricing, and competitive dynamics - Go-to-market strategy for frontier tech - Agent-era infrastructure and what breaks when the user isn't human - Bitcoin, Lightning, and decentralized infrastructure ## Recent speaking **Imagine IF Conference**---Panel with Derek Ross and Matt O'Dell on broken incentives in digital platforms and how open protocols like Nostr give users ownership and control. **Where Does the Yield Come From?**---Panel with Max Kei, Myles Snider, and Jesse Schrader on where yield actually originates in Bitcoin-backed lending and investment products. ### What I'm focused on now URL: https://shawnyeager.com/now/ ## Thinking When intelligence is ambient, advantage moves up the stack. Models are cheap and getting cheaper---the [cost of intelligence just hit zero](/the-cost-of-intelligence-just-hit-zero/). What's defensible is the workflow, the SOP, the harness, the tooling. That's the moat. The other live thread: agent-era infrastructure. Five layers---rails, protocols, discovery, identity, payments---have to be rebuilt now that the user isn't human. Recent pieces on [discovery](/the-catalog-isnt-the-market/) and [identity](/every-agent-in-production-is-a-stranger/) push the work, and the [agent-era infrastructure map](https://lab.sideband.pub/map/) tracks the rest. ## Reading - [AX book](https://www.latecheckout.agency/ax-book) from Late Checkout - [Every](https://every.to) newsletter - [Alex Wissner-Gross](https://substack.com/@alexwissnergross) on Substack - [Department of Product](https://substack.com/@richholmes) on Substack Long-form is still on hold; this is what's bouncing around the tabs. ## Working We are in the early years of the largest commercial reorganization since the internet. And most companies are wasting it. AI is driving it. [Upshift](https://upshiftco.com) is the mechanism I built to help professional services firms act on it. Past launch and into the engine---a [revenue calculator](https://upshiftco.com/calculator) and [assessment](https://upshiftco.com/assessment) are live, with [recent talks and podcasts](https://upshiftco.com/press) making the case in public. Outside Upshift, I'm running a large go-to-market project with a Bitcoin financial services firm and advising a handful of frontier tech founders. Details of [how I work](/work-with-me/). ## Building - [StackCut](https://stackcut.net)---paste a QuickBooks export, get a CEO-ready AI savings report in minutes. Invite-only right now (code: `launch2026`). - [Sideband Lab](https://lab.sideband.pub)---interactive visualizations behind the writing, including the [agent-era infrastructure map](https://lab.sideband.pub/map/) and the [three-body problem visualization](https://lab.sideband.pub/three-body-problem/). - [GTM Map](https://gtm.shawnyeager.com)---the free go-to-market diagnostic. See where your GTM is stuck in 10 minutes, no signup. ## Writing [Sideband](https://sideband.pub) is focused on agent-era infrastructure and also appears alongside the rest of [my writing](/writing/) on go-to-market and Bitcoin. ## Podcasting [Trust Revolution](https://trustrevolution.co) is the podcast I host. Season 3 wrapped earlier this year---seven episodes on digital autonomy, surveillance, data sovereignty, and Bitcoin's unfinished fight. Winding down. Season 4 is undecided. ### Contact URL: https://shawnyeager.com/contact/ The fastest way to reach me is email, and I read every message. For anything private, Signal beats email. And if you'd rather talk it through than type it out, book a call. ### Privacy URL: https://shawnyeager.com/privacy/ This site is my writing. I do not run ads on it. I do not sell information about readers. If you subscribe to the newsletter, Buttondown stores your email so I can send new essays. You can unsubscribe from any issue. Buttondown's policy is at [buttondown.com/legal/privacy](https://buttondown.com/legal/privacy). Analytics run through Plausible. It counts visits without cookies and without storing a personal profile. I use it to see which essays get read, not to follow individual people. Plausible's policy is at [plausible.io/data-policy](https://plausible.io/data-policy). The optional chat on this site sets a short-lived cookie named `chat_count`. That cookie is a counter so one session cannot flood the model. It is not a login. Messages go to Anthropic to generate a reply, then they are discarded. If you email me, book a call, or reach me on Signal, those tools keep whatever you send them. I read the messages. I do not add newsletter subscribers from those inboxes unless you ask. Netlify hosts the site. Server logs exist for a short time so the host can operate it. If you want something deleted, or you have a question, email [hello@shawnyeager.com](mailto:hello@shawnyeager.com).