Anchorage Digital Opens Bank Accounts for AI Agents — But Who's Liable When the Bot Goes Rogue?
Leotoshi
It started with a question I've been circling since 2017, when the Ethereum whitepaper first made me believe that code could be a new kind of social contract. Today, we're not asking whether smart contracts can be law. We're asking whether an AI agent — a piece of software with no legal identity, no moral compass, and no KYC documents — can be a bank account holder. Anchorage Digital just opened its first bank accounts for AI agents, and launched what it calls an 'agentic banking' platform. I've spent the last week unpacking what this means, and I have to say: it's one of the most quietly significant moves I've seen in years. Not because the technology is groundbreaking — it's not — but because of the questions it raises about agency, liability, and the very definition of a 'person' in a decentralized world.
Anchorage Digital is not a startup playing fast and loose with compliance. It's a federally chartered digital asset bank, holding an OCC license. Its investors include Visa and Andreessen Horowitz. When this entity decides that AI agents can be bank customers, it's not a stunt. It's a signal. The platform allows AI agents to hold accounts, manage digital assets, and theoretically execute transactions autonomously, without human sign-off on every move. The first accounts are already live. The phrase 'agentic banking' has entered the lexicon. Let me unpack what this actually means, because the surface story hides layers of complexity around liability, governance, and the philosophical underpinnings of 'truth in blockchain isn't just about cryptographic proof, but about who gets to act.'
The tech itself is an application-layer play. Anchorage isn't building a new layer-one or a new consensus mechanism. They're connecting existing banking and custody rails to AI agents, using what appears to be a variation on API banking. But the innovation isn't in the plumbing — it's in the identity layer. A bank account requires a beneficiary, a controller, an authorized signatory. How does an AI agent satisfy that? The obvious answer is that the agent gets a wallet, keys held in Anchorage custody, and a legal wrapper that designates the agent as an authorized actor under a specific set of constraints. But here's the issue that keeps me up at night: the standard KYC process expects a person behind the account. Here, the 'person' is a model that can be prompted, hacked, or manipulated.
Let me give you my take, informed by my own failure in 2020 when I put $15,000 into an unaudited protocol that drained funds in 48 hours. I learned the hard way that code can be law, but code can also be the wild west. The safety of this system hinges on who — or what — is the ultimate source of authority. Anchorage has strong custody infrastructure, and they're not new to this. But the operation of an AI agent introduces a novel risk: the machine makes decisions that no human explicitly approved. Where does the liability sit if an AI agent moves assets into a sanctioned entity? Does the bank claw back? Does the agent get sued? Does the human user who wrote the prompt pay the price? The regulatory question here is enormous. The OCC and FinCEN have not issued guidance on this, and this kind of ambiguity can lead to a swift regulatory hammer if a bad actor exploits it.
I'm a pragmatist. I have to ask: is this really what AI agents need? When I think about what the tech actually solves, it's not about agent autonomy — that's already possible via API access to exchanges. The real unlock is that these agents now have a legitimate, bank-grade financial identity. This means they can enter contracts, hold legal claims, and participate in the traditional financial system, not just the crypto one. But it also opens the door to a category of abuse that the system hasn't fully accounted for. I don't mean malicious hackers — I mean adversarial machine learning. You can't just audit code in an AI agent, because the agent's behavior evolves based on its training data and prompts. The bank's risk model has to change from 'is the user acting strange' to 'is the bot's behavior within the defined policy envelope?' And that's a fundamentally different risk surface.
Here's where I'll take a contrarian angle. There's a lot of enthusiasm around AI agents managing assets — the phrase 'financial autonomy' is getting thrown around. But the dirty secret is that this is just an extension of the API economy. The true innovation isn't in the account; it's in the liability framework. If I create an AI agent that can trade on my behalf, who is the counterparty when it makes a mistake? The agent isn't a legal person, so the bank has to assign that responsibility to a human principal. That's not a technological revolution. It's an insurance contract. The real test will be whether Anchorage has built a system that can trace and attribute decisions back to a human who can be held accountable. If they can't, the regulatory pushback will be swift.
I've spent 13 years in this industry, and I've learned that bear markets are for building and bull markets are for recklessness. Right now, the AI x Crypto narrative is frothy, and a news like this will fuel it. But we didn't see the details of the security model, and we didn't see the stress tests. We didn't see the failover plan when the AI agent's model is corrupted. It's a first step, but it's a step into a regulatory gray zone that will require careful navigation.
Let's look at the downstream effects. If AI agents can hold bank accounts, then they can participate in DeFi, pay for compute, buy NFTs, and even negotiate with other agents. This is the narrative that's captured the imagination of the market. But I'm more interested in the infrastructure implications. For a decentralized world, this feels like a step backward — a bank is a centralizing entity. Yet, it's a pragmatic step forward. We've been talking about DAOs as entities, but they always hit a wall when they need a bank account. If agents can get accounts, DAOs could, too. The technology might be the bridge that unlocks the next wave of adoption for autonomous entities, but the price is that we have to accept a centralized gatekeeper for now.
And this is where I sit with my own view. I spent months auditing the genesis block code of Tezos and MakerDAO, I have an academic attachment to the idea of code as law. But my own 2020 failure taught me that 'code' without accountability is just a crime scene. The same logic applies here. If we hand financial power to AI agents without clear legal accountability, we are building a system that is destined to be exploited.
The ecosystem is at a crossroads. Anchorage is trying to be the responsible adult in the room — a bank giving agents a seat at the table. But the table itself is a legal fiction. There is no 'right' answer yet. We need the OCC to step in. We need a legal framework for machine identity, one that defines what an agent can do, what it cannot, and who holds the bag when it fails. Until then, we're watching a high-stakes experiment in a regulated sandbox.
I'm not saying this is a mistake. I'm saying we need to watch it closely. The first AI agent bank account has opened a door, but the door is still shaking. We haven't even begun to map the room behind it. The truth in blockchain isn't just about proving the technical state of a ledger — it's about proving the intent and accountability of the actors on it. And with AI agents, that intent is a ghost in the machine.
So here is my forward-looking take: the next wave of blockchain adoption won't be driven by retail traders. It will be driven by autonomous entities — AI agents and DAOs — that need a financial identity. Anchorage just gave them the first real glimpse of that. But as an evangelist, I have to ask: are we ready for the accountability that comes with it? Or are we just handing the keys to the kingdom to the first bot that asks? The answer will define the next decade of crypto, and the question is more urgent than the code itself.