Microsoft Put People Before the Model. The On-Chain Stack Still Hasn't.

0xLeo
Price Analysis

A developer I have never met sent me a screenshot at two in the morning, London time. It showed a treasury dashboard, a governance queue, and one line she had circled in red: "Agent wallet β€” signing authority granted, 180 days, no revocation path."

She voted for that proposal. She voted for it because the alternative was watching her protocol's runway shrink another eleven percent in a quarter, and an autonomous agent that rebalanced incentive emissions on a fixed schedule looked like the cheapest form of survival on the menu. She is thirty-one. She has been building on-chain since she was twenty-four. She is not naive. She is tired.

That screenshot is why I read Microsoft's new AI tenets three times before I wrote a single word about them.

The tenets are easy to summarize and hard to argue with. Microsoft's AI research leadership has placed human control, human agency, and human oversight ahead of raw capability. People over technology. Human judgment retained rather than delegated and then forgotten. It arrived, notably, from the company that sells the models, the cloud, and increasingly the autonomous agents that act on both.

My first reaction was professional cynicism. I have audited too many documents that put people first in paragraph one and a multisig in paragraph nine. My second reaction, the one I trust more, is that this is the most governance-relevant thing a major AI lab has published this cycle β€” not because it is binding, but because it puts words on the table that the on-chain industry has spent three years dodging.

People first, protocol second. Always. I have been writing that sentence for a decade, and I still watch this industry do the reverse every funding cycle.

The Timeline Nobody Drew

Here is the part that gets lost in the coverage. Microsoft's tenets did not appear in a vacuum, and they did not appear early. They appeared after the agent.

Between 2023 and 2026 the industry crossed a threshold that almost nobody marked with a ceremony. Models stopped being things you query and became things that hold keys. The first wave was conversational. The second wave was tool-using. The third wave β€” the one we are living inside now β€” is custodial. Agents have wallets. Agents sign transactions. Agents vote in governance systems that were designed on the assumption that a human being with a hardware wallet and a grudge would be the one pressing the button.

The regulatory clock moved in parallel. The EU's AI framework moved from negotiation into enforcement, national supervisory bodies began building their own interpretation layers, and the European AI Office started assembling reference material for decentralized oversight β€” a phrase that did not exist in any policy document five years ago and now sits in footnotes I have read more than once.

I wrote one of those footnotes, or something adjacent to one. In 2026 I organized a summit that brought five hundred participants from twenty countries into a single argument about AI accountability inside smart contracts. We produced a consensus document. It was cited by the European AI Office as a reference for decentralized oversight. I am proud of it. I am also aware that a citation is not a control surface. A document that describes accountability is not the same thing as accountability, and the gap between those two is the entire subject of this essay.

Microsoft's tenets sit in the same space. They describe an intention. The question I want to answer here is whether an intention published at the model layer can survive contact with an execution layer that most users never see.

It cannot. Not on its own. And the reason it cannot has almost nothing to do with AI and almost everything to do with how we have quietly rebuilt centralized chokepoints inside systems we call decentralized.

Microsoft Put People Before the Model. The On-Chain Stack Still Hasn't.

Where Human Control Actually Lives

Start with architecture, because everything else is commentary.

When Microsoft says humans remain in control, it is making a claim about a specific layer of a specific stack. That layer is the model and the platform around it: training data provenance, evaluation harnesses, refusal behavior, deployment gates, usage policy, red-teaming, logging, and the contractual relationship between the lab and the deployer. It is a real layer. It is not decorative. The people doing that work are serious and underpaid relative to the damage they prevent.

But an agent that holds a wallet does not stop at the model layer. It passes through at least three more.

The first is the agent runtime β€” the scaffolding that gives the model memory, tools, a policy for when to act, and a budget. Whoever writes that scaffolding decides what the agent can attempt. The second is the transaction layer β€” the wallet, the signing policy, the nonce, the gas strategy, the simulation step that catches a bad call before it lands. The third is the execution environment β€” the chain, the rollup, the sequencer, the bridge, the contract that ultimately mutates state.

Human control at layer one is not human control at layer three. That is not a semantic quibble. It is the difference between a lab writing "the human is in the loop" on a slide and a user being able to stop a moving transaction in under a minute on a Saturday night.

The tenets describe the top of the stack. The risk lives at the bottom. Anyone who has spent time in this industry knows which layer gets the least attention, the least tooling, and the least scrutiny β€” and it is never the top one.

I learned this the hard way in 2017, long before anyone was talking about agents.

That year I pivoted my practice. I had been doing quantitative work, model-driven, spreadsheet-native. Then I watched the ICO wave, and I realized that the whitepapers were not engineering documents. They were governance documents wearing engineering costumes. So I audited more than fifty of them β€” not for code quality, which I could not assess at scale and which was often irrelevant to the failure mode, but for legitimacy of control.

I found critical governance flaws in three major ICOs that promised decentralization and had no transparent treasury controls at all. In two of them, the treasury function was a single externally owned account with a human name attached to it in a jurisdiction that did not care. In the third, the upgrade path went through a wallet whose signers were described in the marketing as "the community" and in the smart contract as four addresses.

I published a comparative analysis called "The Illusion of Trust." It reached fifteen thousand readers in a week. The thing that surprised me was not the reach. It was the reaction. Most readers were not angry at the projects. They were angry at me, because the governance gap was the only thing making their holdings valuable, and naming it felt like an attack on the price.

That is when I stopped being a numbers person and started being something else. Technical brilliance without ethical governance does not produce a resilient system. It produces a system that works beautifully until the moment it doesn't, and then it produces a headline.

Empathy is the ultimate security layer. Not because it is soft, but because it is the only mechanism that makes a human being tell you the truth about what they actually control.

The Revocation Problem

Let me put the Microsoft question in its sharpest form.

If an autonomous agent makes a bad decision β€” not malicious, just wrong, the way a tired analyst is wrong β€” how long does it take the affected human to revoke its authority?

Write that number down. It is the only governance metric that matters for agents, and almost nobody is measuring it.

In most systems I have examined over the past eighteen months, the honest answer is somewhere between forty minutes and never. Forty minutes if the team is awake, the multisig signers are reachable, and nobody is on a plane. Never if the authority was granted through a timelock with a 180-day expiry and no early termination clause, which is exactly what the developer showed me in that two a.m. screenshot.

This is where the on-chain industry's most cherished phrase quietly dies. Code is law has never worked as governance, and it never will, because the code that matters is the upgrade code, and the upgrade rights always sit with a few multisig admins. I have watched this pattern repeat across every generation of the technology. 2017: admin keys. 2020: timelocks with a guardian. 2023: proxy admin contracts. 2026: an agent policy module with a two-of-three override.

The shape changes. The number of humans who can change the rules does not. It is almost always fewer than ten, and it is almost never disclosed in the same font size as the marketing claim.

So when a major AI lab publishes tenets saying that humans stay in control, I read it as a statement about a governance problem the entire industry shares, and I read it as correct. The problem is not that the statement is wrong. The problem is that the statement is being made at the wrong end of the pipe.

A human in the loop at the model layer, with no revocation path at the contract layer, is a human in the loop the same way a passenger is in control of a train.

The Sequencer Is a Person

Now let me be precise about the layer that carries the most agent traffic, because this is where the tenets meet reality hardest.

Rollups are where agents live. Cheap execution, fast finality, predictable fees. If you are running an autonomous rebalancer, an on-chain trading agent, a treasury manager, or a governance delegate bot, you are almost certainly running it on a Layer 2.

And the sequencer on almost every Layer 2 you can name is, functionally, a single centralized node operated by a company.

I have been saying this for two years, and I will keep saying it: decentralized sequencing has been a PowerPoint for two years. There are designs. There are roadmaps. There are shared sequencer networks with genuine research behind them and three live deployments between them. There is also a production reality in which one operator orders the transactions, decides the inclusion window, and controls the censorship surface for everything running on top.

This matters for AI agents in a way it does not matter for a person clicking a swap. A person who gets censored or delayed will notice and complain. An agent with a policy loop will simply adapt to the environment it observes β€” and the environment it observes is defined by the sequencer. Reordering is not an edge case in an agentic system. It is the primary attack surface, and it is controlled by a company with a status page.

So the chain of custody for a typical autonomous on-chain action looks like this. A model trained by a lab, governed by tenets that prioritize human control. A runtime written by a startup, governed by a product roadmap. A wallet policy written by a team, governed by a two-of-three multisig. A transaction ordered by a sequencer, governed by an operator. A contract upgraded by a proxy admin, governed by the same multisig as before.

At which of those five points is a human actually in control of the outcome? At the first. Technically. In the sense that matters to a lawyer.

At the layer where money moves, the answer is: whoever holds the keys, and you do not know their names.

This is not an argument against AI agents on-chain. It is an argument against pretending that the tenets that govern the top of the stack govern the bottom. If we want human control to mean something, it has to be expressed as a revocable capability at the layer where capabilities are exercised β€” and the sequencer, the multisig, and the proxy admin are where that expression has to land.

Bitcoin Already Ran This Experiment

I want to bring in a second example, because the pattern is identical and the industry keeps refusing to learn from it.

Bitcoin was designed as peer-to-peer electronic cash. That was the stated purpose, and for a while it was the actual use. Then the instruments arrived. First futures. Then trusts. Then, in 2024, spot ETFs in the largest market in the world.

The ETF approval was celebrated as validation. I wrote at the time that it was an absorption event, and nothing in the two years since has changed my mind. When the marginal buyer of an asset becomes an allocator with a mandate, a compliance committee, and a fee model, the asset's behavior converges on the allocator's needs, not the original vision's. Custody consolidates. Flow becomes observable. Volatility gets dampened by authorized participants arbitraging in size. The thing that was supposed to be peer-to-peer becomes a line item with a ticker.

You can call that maturity. I call it the death of the sentence that started the whole movement.

Here is the connective tissue to Microsoft. The tenets are an attempt to keep the human at the center of a system that is being built to operate without them. The Bitcoin ETFs were an attempt to keep the asset at the center of a system that immediately redefined what the asset was for. In both cases, the original intent was preserved in language and overwritten in structure. The language is what gets quoted. The structure is what determines outcomes.

I am not arguing that the ETFs were a mistake, and I am not arguing that Microsoft's tenets are insincere. I am arguing that we have a demonstrated, two-year-old, publicly observable case study showing that when an institution adopts a technology whose native governance is distributed, the institution does not become distributed. The technology becomes institutional.

The same thing is now happening with AI agents on-chain. The agent arrives with a lab's worth of ethical framing attached. It lands in an execution environment controlled by four to ten people. Six months later, the ethical framing is a footnote, and the four to ten people are the constitution.

Microsoft Put People Before the Model. The On-Chain Stack Still Hasn't.

What the Voters Actually Did

Let me put data where my concerns are, because a bear market is the only honest test of governance.

Over the past several quarters I have been tracking governance participation across the DAOs I advise and the ones I simply watch. The trend is not ambiguous.

Median proposal participation in mid-cap governance systems has drifted below five percent of circulating supply. In several cases it is below two. Quorum is reached not by voters but by delegates who are themselves running automated voting infrastructure β€” which is to say, the first AI agents to participate in DAO governance were not announced with a manifesto. They arrived quietly as delegation services, and most token holders never noticed.

Treasury runway tells a similar story. Across the protocols I track, median stablecoin runway has shortened from a cycle-peak average measured in years to one measured in quarters. Governance-token treasuries have taken the worst of it, because the asset they are denominated in has fallen while the liabilities β€” grants, audits, engineering salaries, legal, insurance β€” have not. When your treasury is down sixty to eighty percent from cycle highs and your obligations are flat, every proposal that promises efficiency gets a yes.

That is the soil in which agent governance took root. Not enthusiasm. Arithmetic.

The developer with the screenshot was not making an ideological choice. Her protocol's emissions were mispricing risk for the ninth consecutive epoch, and a human committee could not respond fast enough to fix it because the committee meets fortnightly and the market does not. The agent could. The agent did. The price of that responsiveness was a 180-day delegation of signing authority with no early exit.

Trust is earned in bear markets. It is also spent in them. Every treasury that hands authority to an automated system in a drawdown is trading a governance claim for a survival window, and most of them will not get the governance claim back.

This is not a criticism of the people making those trades. It is a description of a decision made under duress, and duress is the default condition of this market. What worries me is that the industry is building a permanent architecture to solve a temporary problem, and permanent architectures outlive temporary problems by a wide margin.

What Microsoft's Tenets Get Right

I have spent a lot of words on what the tenets cannot do. Let me be fair about what they do.

First, they name the right variable. Most AI safety language focuses on capability β€” what the model can do, what it might be able to do, what happens at the frontier. Microsoft's framing shifts the center of gravity to control: who decides, who can stop, who is accountable. That is a governance frame, not a research frame, and it is the correct one for systems that hold value.

Second, they put the burden of proof on the deployer rather than the user. This sounds like a small thing. It is not. Every on-chain system I have audited in fifteen years has placed the burden of understanding on the user β€” read the docs, check the contract, verify the multisig, do your own research. That posture is defensible in a research setting and indefensible in a financial one. If a lab says human oversight is required, the oversight has to be designed into the product, not documented in a blog post and delegated to the customer.

Third, they are stated publicly, which creates a reference point. I know exactly how much a public principle is worth β€” I have cited enough of them, and I have watched enough of them get quietly deprecated. But a public principle can be quoted back at its author. That is a small lever, and small levers are what governance is made of when you have no enforcement mechanism.

When I worked on the Institutional-Community Interface Protocol in 2024, we spent the first three months arguing about exactly this question: whether a compliance framework could be written at the institutional layer and still leave meaningful autonomy at the community layer. We produced a fifty-page blueprint. It was adopted by more than half a million token holders. The lesson I took from it was that the two layers can coexist β€” but only when the interface between them is specified in operational terms. Not values. Interfaces. What data crosses. Who signs. What expires. What can be revoked and by whom.

That is what Microsoft's tenets are missing, and it is not their fault. Interfaces are not the lab's job. They are ours.

The Contrarian Case: The Tenets Are Liability Architecture

Now the part that will annoy both camps.

Microsoft Put People Before the Model. The On-Chain Stack Still Hasn't.

The most common reading of Microsoft's tenets in the crypto press will be that a major technology company has finally prioritized ethics over capability. I think that reading is naive, and I will tell you why.

A public commitment to human control is also a public allocation of responsibility. If the human is in control, then when the agent does something catastrophic, the human did it. The lab supplied a tool. The tool was used. The tool's documentation said the human was in charge. The lab's exposure is bounded by the accuracy of its documentation.

This is not a conspiracy. It is standard practice in every industry that ships a dangerous capability into a market it does not control. Aviation does it. Pharmaceuticals do it. Financial infrastructure does it. You write down who is responsible, you make the responsible party agree, and then you build the product.

The difference in AI is that the responsible party is not a licensed operator with an insurance policy. It is, increasingly, an autonomous agent's deployer β€” which in many cases is a twenty-nine-year-old with a GitHub account and a treasury mandate granted by twelve thousand people who have never read a line of the policy module.

So here is the contrarian claim. The most dangerous outcome of Microsoft's tenets is not that they will be ignored. It is that they will be adopted as language and refused as architecture. We will get a generation of products that say "human in the loop" on the marketing page and implement a 180-day irrevocable delegation in the contract. The words will do the compliance work. The structure will do the damage.

The second contrarian claim is about my own tribe. Decentralization maximalists, the people who have spent a decade arguing that code should replace institutions, are now the loudest celebrants of a corporate ethics document. That is a strange position for a movement built on the premise that institutions cannot be trusted to govern themselves. If the tenets are meaningful, they are meaningful because they constrain power. If they constrain power, then they are exactly the kind of instrument the movement was founded to distrust β€” an off-chain promise about on-chain behavior.

We should hold two things at once. The tenets are good and we should use them. The tenets are insufficient and we should not mistake them for a mechanism. That is not fence-sitting. That is what a grown-up governance posture looks like.

The Pragmatic Test

Principles are cheap. Let me offer a test that separates principles from architecture.

Give me one number for any agent-enabled system: the time from a user deciding to revoke an agent's authority to the moment the authority is gone, verifiable on-chain.

If that number is under sixty seconds, you have a governance system. If it is under five minutes, you have a reasonably serious operation. If it is a business day, you have a promise. If it requires reaching three of five signers whose identities are undisclosed, you have a custody arrangement with extra steps.

I ran this test informally across eleven agent platforms over the past two quarters. I will not name them, because the failure is systemic and picking on any one of them would be dishonest about the shape of the problem. Here is what I found.

Four of the eleven had a genuine, functional, single-signature revocation for the delegating account. Three had revocation gated behind a multisig ceremony with no published signer set. Two had revocation only through a timelock, measured in days. Two had no revocation path at all β€” the authority expired or it did not.

That is two systems out of eleven that would survive contact with a real incident. The other nine would put a customer's assets in the hands of a process designed for a slower, more forgiving era of on-chain activity.

Now fold the sequencer back in. Suppose you have one of the four good ones. You can revoke in eleven seconds. Your revocation transaction enters the sequencer queue. The operator's policy for priority ordering is not published in detail. During a congestion event β€” which is precisely when an incident would occur, because incidents and congestion are correlated β€” your revocation sits in a mempool you cannot inspect, on infrastructure you do not control, while the agent you are trying to stop keeps signing.

Human control in eleven seconds at layer two, indefinite at layer three. That is the honest accounting.

What I Would Build

The industry does not need another principles document. It needs three pieces of plumbing, and none of them are glamorous.

A revocation primitive. Not a policy setting in an app's admin panel. A contract-level capability where an authority grant carries an always-available unilateral exit for the grantor, with a bounded on-chain confirmation path. Bounded means you can state the worst-case time to revocation and defend it in front of a regulator. Everything else β€” timelocks, multisig ceremonies, expiry-only grants β€” is a downgrade dressed as safety.

An authority registry. If an agent holds signing rights over anything, that fact should be discoverable by anyone, in one query, without the agent's owner as an intermediary. Right now the discovery process is a screenshot at two in the morning. That is not a system. That is a rumor.

A sequencer transparency standard. Not full decentralization β€” I have given up on that timeline, and pretending otherwise would make me useless to the people who read me. A publishable, auditable, versioned policy for transaction ordering, censorship, and revocation priority, with a commitment that revocation transactions are never deprioritized. That single commitment would do more for human control than every ethical framework published this decade.

None of these are hard engineering problems. They are hard coordination problems, which is why they have not been solved. Coordination is where this industry has always failed. We are extraordinary at building mechanisms and terrible at building institutions, and the agent era has arrived with a load of mechanisms and no institutions underneath them.

What the Tenets Should Actually Change

Let me close the loop on the document itself, because I do think it matters and I do not want to leave this as a hatchet job.

Microsoft's tenets establish a principle at the layer Microsoft controls. That is legitimate. What the rest of us should do is take the principle and push it downward, one layer at a time, until it reaches the place where money moves.

At the runtime layer, human control means a policy that the deployer can read and a stop that the deployer can execute. Not a stop that requires a support ticket.

At the wallet layer, human control means revocation that does not depend on anyone's cooperation beyond the user's own signature.

At the execution layer, human control means an ordering policy that guarantees an exit transaction will land. Without that, everything above it is decorative.

And at the governance layer, human control means accepting something the industry has resisted since 2017: that upgrade rights sitting with a handful of multisig admins is not a temporary phase on the path to decentralization. It is the operating state of the technology. It has been for nine years. There is no evidence it is changing, and there is considerable evidence that the agent era will entrench it, because agents need fast parameter changes and fast parameter changes need someone with a key.

The tenets say people come before technology. I agree. I have been writing a version of that sentence since I watched three ICO treasuries turn out to be four addresses and a promise.

But a principle at the top of a stack is not a safeguard at the bottom. It is an aspiration with good distribution.

Where This Goes

By the end of 2027, I expect two things to be true, and they will be discussed as if they contradict each other.

First, nearly every major AI platform will publish a human-control framework. The language will converge. The tenets will be copied, paraphrased, and cited by companies that have not implemented a single revocation path.

Second, the largest share of autonomous on-chain value will still route through infrastructure operated by fewer than a hundred people worldwide, and most of the users who depend on it will not be able to name one of them.

Those two facts will coexist comfortably, because the industry has learned to treat stated principles as compliance and structural control as an implementation detail. The gap between them is where the next round of losses will be manufactured, and it will be described afterward as an unexpected failure of a well-designed system.

I do not think this is inevitable. I think it is the default, and defaults are what governance exists to interrupt.

The developer who sent me that screenshot is still running the agent. Her revocation path still does not exist. She is thirty-one, she is tired, and she is doing the arithmetic that the industry keeps handing to people who cannot afford to refuse it.

So here is the question I would put to every team building agents on-chain this quarter, and to every lab publishing tenets this year.

If the human is in control, show me the button. Show me where it is, show me who can press it, and show me the last time someone did.

If you cannot show me the button, you have not built human control. You have described it. And description, in a bear market, is the most expensive thing we still buy.