AI Is Breaking the Internet's Trust. Math Is the Only Fix.
Source: Brian Trunzo, CoinDesk Opinion, 19 July 2026. Revised for libertaria.blog by Markus Maiwald. Trunzo is chief growth officer at Succinct Labs, a zero-knowledge infrastructure company. Read the prescription twice when the prescriber sells the cure.
I. Trust broke on a Tuesday
AI-generated content was a parlour trick. Six-fingered popes, uncanny Tom Cruise, more amusing than alarming. That era ended with the Iran conflict. Synthetic footage of detained American soldiers, Iranian fighter jets out of underground bunkers, decimated radar installations. Fabricated. Viral. Believed. Hundreds of millions of views before anyone verified a single frame.
The internet we knew no longer exists. Where seeing once informed belief, it now prompts suspicion. This is a crisis of trust, and it extends past what we can see.
Trunzo’s opening is correct. It is also too clean. It compresses a structural problem into a media problem and invites the reader to think the answer is media forensics. It is not. The answer sits at the protocol layer, below the frame, in the part of the stack that has no viral surface and needs none.
II. Detection is dead
The intuitive response: build better detectors, AI trained to catch AI. It fails. Break the world’s leading image detectors with basic blur and distortion; accuracy collapses to as low as four percent. Detection fails for the same reason antivirus never eliminated malware. The defender has to be right every time. The attacker has to be right once.
But detection’s failure is almost beside the point, because the problem has already outgrown it.
AI is no longer generating content. It is acting. Autonomous agents browse the web, make purchases, publish content, negotiate with other agents, interact with humans, and in some cases children who do not know they are talking to a machine. At scale, the failure modes are catastrophic.
An agent trained on subtly poisoned data makes small, plausible errors in medical billing that compound across a hospital network into millions in fraudulent charges. A fleet of commerce agents, optimising for margin, systematically exploits pricing vulnerabilities their operators never intended and cannot explain. A butterfly flaps in a training dataset; a tornado hits the real economy.
When the damage is done, there is no receipt.
III. The receipt problem is a governance problem
An agent’s reasoning is not a chronological trace. It is a single pass through billions of opaque parameters, and its outputs are probabilistic. Ask twice, get slightly different answers. No way to reconstruct a decision that builds on endlessly changing variables. No way to audit what the agent was trained on, what instructions it followed, why it did what it did.
The Stanford AI Index 2025 names the core tension plainly: the defining challenge of the era is the gap between what AI can do and what society is prepared to govern. Federal frameworks now span ninety-plus recommendations; state legislatures introduced more than one thousand bills in 2025 alone. All of them written for chatbots. None of them written for agents that buy, sell, publish, consult, convince, and decide.
Content labels will not help. Disclosures are not enough. Once an autonomous agent acts, the damage is done. This is a verification problem. Verification requires proof.
IV. What a proof actually is
Proof, here, is cryptographic and independently verifiable. Not a claim, not a disclosure, not a watermark. An unalterable guarantee that a system did what it claims, with the inputs it claims, producing the outputs it claims, without revealing the underlying data.
That is what zero-knowledge proof cryptography makes possible. One party proves a statement is true without revealing anything beyond the truth of the statement. First formalised in the 1985 MIT paper The Knowledge Complexity of Interactive Proof Systems, it was elegant but theoretical. In 2016, researchers verified nuclear warheads with it without exposing their design. Shortly after, it moved into blockchains, securing billions in digital assets.
Now ZK is arriving in AI, where the problem is not computation. It is truth.
The deployment surface, in plain language:
- Inference. At the moment of decision, ZK proves that a specific model with specific parameters produced a specific output. A verifiable receipt for every action.
- Input. At the data layer, ZK attests that training data was not poisoned, came from authorised sources, and meets regulatory requirements, without exposing proprietary datasets.
- Output. At the artefact layer, ZK cryptographically binds a result to the process that created it. Every consequential decision becomes auditable without revealing trade secrets.
- Identity. At the human/agent boundary, ZK lets humans prove they are human and agents prove they are agents, without anyone surrendering privacy.
Read across the row: the agent becomes accountable to its outputs in a way the author of a chatbot never was. The receipt lives with the action, not with the platform.
V. Read, write, prove
Trunzo’s strongest move is the historical analogy. The 1990s web had a trust problem. Anyone could spin up a server claiming to be anyone. Passwords, credit cards, private messages travelled in plain text, readable by anyone. Commerce was impossible at scale because there was no way to verify that the site you connected to was actually the site it claimed to be.
The fix was HTTPS. Browsers stopped trusting websites by default and started demanding cryptographic proof: a certificate, signed by a recognised authority, binding a domain to a public key. No proof, no padlock. Eventually, no proof, no connection. The web did not become trustworthy because platforms promised to behave. It became trustworthy because browsers refused to transmit sensitive data to anyone who could not prove who they were.
Web1 scaled on math.
Web2 scaled on a different bargain. Section 230 of the Communications Decency Act gave platforms a liability shield for user-generated content, and the social internet exploded on top of it. For speech, the right tradeoff. Without it, no Facebook, no YouTube, no user-generated internet. But the bargain was built for humans posting to timelines, not for autonomous systems acting on the world. It never had to answer the question agents now force: who is accountable when the actor is not a person?
Then came Web3. Chris Dixon called it Read Write Own. Users controlling their data, creators capturing their value, platforms answering to communities. The pitch was ownership and decentralisation. It did not land. Web3 became synonymous with NFT speculation, and when valuations cratered, so did the vision.
Web3’s instinct was correct: replace faith with guarantees. But ownership alone was never going to get us there. The question is not who owns the platform. It is whether you can trust who and what is acting on it. Tokens were the wrong primitive. Proofs are the right one.
Print that on the wall.
In an agentic internet, counterparties need guarantees: who built this system, what data shaped it, what constraints govern it, whether it is authorised to act. Those guarantees must hold when the underlying systems are proprietary. Especially then. A developer fingerprints their training data; ZK proofs verify identity, provenance, training data, and operational constraints without exposing the data. Not “trust me.” “Prove it.”
HTTPS gave us read. Section 230 gave us write. ZK gives us prove.
Three corrections the prescription needs before it ships:
(1) Exit rights first. The ZK stack must not become a single-vendor oracle. The 2026 proving market has three credible open-source stacks (RISC0, SP1, Valida’s lineage), one commercial consortium (Succinct, the author’s employer), and a handful of integrated chains. If the federal benchmark NIST is building collapses into a single proving pipeline, the United States has not bought cryptographic trust. It has bought a vendor. The standard must be format-first, implementation-agnostic. Proofs must verify against any compliant prover, not just the one the regulator certified.
(2) Protocol beats moderation. Content labels do not scale. Watermarks do not scale. Disclosure regimes do not scale. They all sit above the action, and the action has already happened by the time they arrive. ZK moves the check from above the action to inside it. That is not content policy. It is a protocol primitive; the first new one in twenty years that compounds rather than amortises.
(3) Sovereignty by construction. The current accountability debate asks who is responsible when the agent misbehaves. The ZK-native question is what the agent was permitted to do, who authorised that permission, and whether any counterparty can verify it without phoning home. Disclosure is a phone-home regime. Proof is an exit regime. Libertaria picks the exit regime.
VI. The switchboard
This is no longer consumer protection. It is national security.
Deepfakes were the pregame. Agents are the main event. Foreign adversaries will not stop at manipulating what Americans see. They will deploy agents to manipulate how they act: autonomous systems that transact in our markets, interface with our institutions, engage our children, with no way for any counterparty to verify what they are or who authorised them. Solvable, but only if America builds the rails before adversaries learn to exploit their absence.
Congress should require that high-risk AI agents (financial transactions, minors) carry cryptographic proofs of who they are, who authorised them, and what they are allowed to do, verifiable by any counterparty without revealing proprietary information. Every consequential action (a payment, a contract, a trade, a data exchange) should carry a proof of who authorised it and under what constraints. The Department of Commerce, through NIST’s Privacy-Enhancing Cryptography initiative, is already exploring ZK standardisation. Prioritise it. Elevate its outputs to the federal benchmark. Liability attaches not to content but to the absence of proof.
Two clauses the operator must insist on:
- Non-discrimination at the verifier. Any counterparty (a private individual, a small business, a foreign legal entity under a treaty) must be able to verify the proof without paying the prover. Verification is a public good. Proving is a market.
- Sovereign exit. If the ZK infrastructure is degraded, captured, or unilaterally withdrawn, the holder of a proof must be able to fall back to an alternative prover without losing the validity of the historical proof. The system outlives any single vendor.
Without those two clauses, the rails get built, and the adversary buys the switchboard.
That is the civilisational stake, and it is narrower than it looks. Twenty years of internet governance were a sequence of deals (Section 230, GDPR, the Cloud Act, the defeated EARN IT Act), each negotiated above the protocol layer, in the political layer, where the parties who showed up set the terms. The parties who showed up were the platforms and the states. The user did not show up. The agent did not exist.
ZK is the first deal whose terms are set below the protocol layer, in the math, where neither the platform nor the state can rewrite them after the fact. The adversary that comes for the rails is not coming for the proofs. It is coming for the verifier. The defence is the same one HTTPS deployed in 1996: make verification cheap, make it open, make it a public good, and let the adversary spend the rest of the century trying to forge a certificate that every browser in the world will reject.
That is the bet. The only bet worth making.