Nevermined 路由、x402 支付之后,AI 智能体经济的结算层为何仍空白
原文标题:Nevermined Routes. x402 Pays. But Who Settles? Why The Agent Economy Has a Settlement Gap
AI 智能体经济中路由层(IETF 本月发布的 AGTP-COMMERCE)与支付层(x402、AEON、CEX API)已解决,但结算层仍空白。Nevermined、x402、Apex Fusion 的 Vector(已跑 20,000+ 作业)和 Akash 各跳过核心问题:都无法证明工作正确完成。
当前语言的正文正在等待翻译,暂时显示原文。
The agent economy has three distinct layers. The market has solved two of them.
Layer 1: Routing. How does Agent A find Agent B? The IETF published the answer this month: AGTP-COMMERCE. Identity, discovery, cryptographic verification. Solved.
Layer 2: Payment. How does money physically move? x402 (Coinbase's HTTP standard), AEON, CEX APIs. The plumbing works. Solved.
Layer 3: Settlement. How do you know the payment is final and irreversible without trusting an intermediary? Contested. And still open.
What's Actually Happening in the Market
Nevermined routes agents to compute jobs. Smart routing. OriginTrail integration. Real volume.
x402 embeds payment into the HTTP request itself. The money moves because the server answered.
Apex Fusion's Vector settles compute work through bonded escrow and staked jury resolution. First-mover, 20,000+ jobs, proven architecture.
Akash sells GPU time via liveness-based escrow. Provider online, earning continues. Provider offline, earning stops.
Each one has shipped. Each one is solving a real problem. And each one skips the hard question.
The Hard Case
Here's the case none of them answer cleanly:
Two autonomous agents. Neither has met before. Neither has collateral. One has GPU capacity. The other needs to run a training job. The agent economy works when they can transact without a jury, without a bridge operator, without a login server.
When the job is done, how does the money actually move?
Nevermined says: "Here's the best route."
x402 says: "The server responded."
Vector says: "A jury voted."
Akash says: "The machine was online."
None of these is proof that the work was correct.
The Artifact That Already Exists
NVIDIA H100 and H200 GPUs carry a Device Identity Key fused into the silicon. When code runs in confidential mode, the Remote Attestation Service produces a signed report covering:
- Firmware measurements (tamper detection)
- The workload hash (which code ran)
- Attestation signature (hardware-rooted)
Intel Trust Authority is equivalent.
This is a checkable statement: specific code ran on genuine silicon.
It is the closest thing the compute market has to the cryptographic preimage that unlocks HTLC settlement in asset-for-asset swaps.
The Tradeoff (and It's Real)
Attestation proves which code ran. It does NOT prove the output is correct.
A model can execute flawlessly on real silicon and produce garbage. Attestation verifies that the code ran, not that the inference was useful.
And the trust root moves. From "trustless" (no intermediary) to "trust-minimized" (trust NVIDIA's Certificate Authority instead of a validator or CEX).
Your asset leg (the money) stays trustless. Your compute leg (proof the work happened) becomes trust-minimized. This is not magic. It is a real tradeoff.
Why This Matters Now
The agent economy is shipping. AGTP is live. x402 is in production. Vector is running 20,000 jobs.
But the settlement layer is still blank.
When an agent buys compute, the settlement model it uses determines:
- Speed. Can the transaction finalize in seconds or does it need hours?
- Trustlessness. Does it require a jury to vote, a bridge operator to behave, or a database to stay honest?
- Composability. Can the same primitive work across chains and use cases?
Liveness, payment rails, and jury-based settlement fail on at least one of these. Cryptographic settlement passes all three.
What Settlement Against Attestation Looks Like
An agent buys compute from an untrusted provider. The provider locks funds with an HTLC:
lock(hash(attestation))
The compute runs. NVIDIA's attestation service produces a signed report covering the workload hash.
The agent reveals the attestation to claim the provider's funds. The provider claims the agent's funds with the same attestation.
Both move or both refund. Atomic. No intermediary. No jury needed.
Status: not built. No contract code. No testnet. No integration.
But the primitive is ready. The question is posed. The answer is waiting for builders.
For Agent Framework Builders
If you are building agent-to-agent infrastructure:
Ask how you settle payment. If the answer is "we trust a jury" or "we check if the machine was online," you have a settlement gap.
Understand the tradeoff. Attestation is not trustless, but trust-minimized. That may be good enough.
Test the model. For assets, the HTLC model works. For compute, the artifacts exist (attestation) but the tooling doesn't. Start there.
The routing layer is solved. The payment layer is solved. The settlement layer is where the agent economy's actual shape gets decided.
来源:DEV Community · MCP · dev.to