# What AI Changes in Crypto? - Panel Talk

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2026-09-09
- Duration: 1:05:36
- Watch: https://streameth.org/watch/yt-57klZdopFjo
- YouTube: https://www.youtube.com/watch?v=57klZdopFjo

## Description

Alexandru Dobra, Alexandru Stanescu, Daniel Tamas and Sergiu Vasilescu explore how AI is beginning to interact with crypto systems - from autonomous agents and new on-chain design patterns to the legal, regulatory, and accountability questions emerging when machines start holding and moving value.

## Transcript

You know the topic of the panel is AI in crypto and um is it the loudest narrative of 2026. with me on the stage. I have some very esteemed gentlemen that I would like them to introduce themselves first and then we will uh dive right into it. So &gt;&gt; thank you. I don't deserve to be the first as I was the the latest. &gt;&gt; Uh so I'm Sergio Basesco, managing partner of Vido Group. Vido Group. It's an international traditional law firm uh covering six 16 practice areas and one of them uh it's new and emerging technology in which we cover also blockchain, crypto and uh and AI. Uh so have we have uh six offices in six different countries and on top of legal services we offer accounting and tax services. Um we are behind uh small clients in this in this industry and also global leaders. So uh that's why we I think we managed to understand also uh all the needs of the of the entire industry and uh what I love to in this industry is that a company today it's a startup and in two weeks it's a unicorn. So this is uh this is fantastic. It's also super harder to to be handled uh by the founders. Uh so you can imagine what a hassle is for the lawyers. You know, you need to change your fees from a small fee for a startup to a unicorn just over there. &gt;&gt; Yeah. So, &gt;&gt; it's super hard to manage. &gt;&gt; Yes. Such a pain. [laughter] &gt;&gt; Good. &gt;&gt; Thank you. &gt;&gt; Thank you very much. &gt;&gt; Hi everyone. I'm Alexandro uh Stanesco from Lexter's Law Firm. Um we do international work and we are quite good in deep tech. We've been working on blockchain projects for a couple of years now. And uh also in web 2 we've been working with a lot of innovators uh who are engaging in deep tech but also in biotech and other areas of uh you know of innovation. We have a specific edge in the sense that we are helping central eastern central eastern European innovators to grow to the US market. So we've been working with a lot of companies who are growing in Europe and then they wanted to conquer the the US market. Uh on my side I'm uh I'm uh based in Bucharest but we cover also the US because two of our partners myself and another partner we are also New York bar attorneys. So you know in crypto we've seen a lot about the how we test about what's the security. We've been working also on prediction markets. We've been uh working on the venture capital investments in Europe but also in the US and naturally um startups and scaleups in the AI as they are growing they need legal advice and here we are. So basically like Sergio we are we have a good exposure on on deep tech also on the blockchain but also on the AI. Hence we are here to discuss with you the the we might not have I might have I might not have all your answers because this is very frontier but you know we are here to to see where where the things are moving from a legal perspective. &gt;&gt; Thank you Andre. &gt;&gt; My name is Andre Dobra. I'm a tech engineermind and I lead one of our AI initiatives which is agent arena which is basically a platform for uh the security agents to compete in audit competitions. So they have this very short time window where they can submit vulnerabilities and we validate them and deliver some uh security reports. Uh basically this is one of the most the the biggest impact that we've seen of AI in crypto and overall in software engineering when it comes to both producing the code and then reviewing validating and uh uh delivering also the security expertise on top. Um maybe you've heard about Nethermind. We are quite uh we've been growing together with Ethereum ecosystem from the start. We have the we've started with the Nethermine client which is used now by over 30% of the the network uh the execution layer. So um there is that we have the research engineers we have formal verification we have all kinds of branches and uh overall we try to build with anybody uh as uh also the success of Ethereum is also the success of Nethermine. So we go together but not only as we are now also building uh AI solutions uh and uh different things both in web two and web 3. So yeah I'm coming I will try to come in with a few insights from the technical side and from how AI impacts our workflows as well. &gt;&gt; Thank you. Just three words about myself as well. I'm Danny. I'm with WHAM just like it says on my hat. We've been building in uh web 3 since 2021. We've been one of the leading um play to earn gaming platforms in the world and then we had some very interesting lessons learned in the past three years but these lessons have been put to good use and now we're at the fifth iteration of the platform and I'm happy to say since we launched uh there's a vanity metric but still a metric that I like and that is uh now the one token is used as gas fee and we had about 92 transactions per user on the competitions that we make and this year uh given the technology advancements have been uh strong enough we can boldly um progress towards a gentic gameplay game creation and now we're building the WH studio which is basically lovable for making games publishing games monetizing them and so on so this is where everybody is now we're going to get to the fun stuff and the first the first thing I have here on uh on my phone is the question what's real and what's hype because lots of crypto companies have integrated AI. Um Solana has been um a native infrastructure for AI virtuals basically launched hundreds of uh tokenized agents. So which AI and crypto use cases are actually useful in this case and which are just hype and you you guys have different perspectives. will all help. Who wants to go first? Sedu. &gt;&gt; So um AI it's right now like blockchain was uh five years ago or three years ago. So AI it's super it's a super good tool and blockchain it's a super good technology but you have to analyze if it's worth to implement it or not. So there are a lot of projects saying that we are using AI and by this they understand they integrate chibi in what they're doing which is correct. they're using AI. But when you say we are doing AI, it means that either you develop, either you use AI as a core engine of a uh substantial feature that you provide or that you created for your clients. I mean using AI the smartest AI as a chatbot when you are a blockchain and you have a chatbot on your web page. Uh this this it's not uh I you can promote it. we're using AI but it's not AI used in order to uh empower what the services that you are doing but it's it's marketing um it's it's good whatever AI they they use but it's a really really complicated and really expensive and you founders uh discovered on your own skin that implementing AI really in the uh as a core engine of of your services that you provide to your clients It's first of all super expensive and it's not yet the time in order to let AI to do it independently and to do it um properly because we are still innovating and we are still developing how AI should be integrated in a service in order to work uh automatically. Open claw. Yeah, they are using AI. Okay. Or they are dedicated to AI. Uh but you can't say that you're using AI just because you implemented a chatbot on your website. &gt;&gt; Definitely. Alex, I'll try to be and bear with me. I'm a bit conceptual at the beginning, but then I'll tell you the use cases. The big difference between blockchain as an ecosystem and AI was that we are what they have in common. They have a sort of a layer one. Yeah. And when we had the initial investments in in blockchain in crypto 2015 2016 the big ICOs everybody was battling to build the layer one the foundation and based on that you do layer two and then layer three. The promise of blockchain at that time it was that you are building an ecosystem and based on your layer one on your Ethereum you would build you know the next killer apps and the next you know L2 type of projects but the good thing is that and that that's why we're discussing decentralizations that that's why we're discussing about an ecosystem who's who has a benefit for everyone so they were like working in a synergy what we've seen in the AI world because it's decent it's purely centralized the AI world apart from you know some aentic tools you would have anthropic open AI all these guys they are building the layer one but they are not necessarily willing to share the the benefits with the with the layer 2 applications. So basically whatever you build on top you really need to have a mode because otherwise layer one entropic will eat you. So this is the big difference between conceptually and from here what you need to ask the blockchain projects if they want to use AI is what is your mode? If you are going to use the AI, it really needs to have a specific use case and initially 2005 16 AI and blockchain was a lot of BS uh because at that point we had only machine learning. I've seen some projects who are you know building with the help of oracles and with machine learnings identifying pictures or and you would you'd use the blockchain to monetize or to reward the people who are contributing to the network. Now we are in a different ball game and I think AI agents will be using blockchain. So blockchain will be a tool for the agentic AI. is not going to be AI agents for the blockchain ecosystems. I say it less. However, what seems to be in terms of real use cases or you know apparent use cases uh and again AI you know we've been struggling in blockchain to find real use cases. Everybody was talking every year 2015 16 17 what's the innovation that the blockchain we need to have the you know the killer app the use case and blockchain most likely was used as the best in finance or transferring money transferring value that this is one of the the the best use cases and here in trading I think agents will be doing a lot of high intensity trading and blockchain will be useful even the guy from Coinbase wrote, you know, the co said that an agent cannot open a bank account, but an agent can transfer funds from a crypto wallet to another programmatically. So that's a a real use case. The second use case we've seen Dowos and Dows have not got to the you know promised level of what was expected from the Dows but also because you know the communi communities are scattered are very difficult to be you know uh put together to make decisions so governance is mostly a sort of a shield world. I think with the agentic AI you can really organize and coordinate well a well functioning DAO in the in the sense that the communities were thinking about Dows. So I you know I'll stop at this point on on these two use cases that I think that they are for real. &gt;&gt; Okay. &gt;&gt; Uh I have to say that I really like that analogy with the layer one. I think definitely that what we're seeing right now. So we have these frontier models that it's very hard to keep up with because like if you started now your efforts to get at that uh that level are considerably higher. So so this uh kind of uh there's this barrier of entry in through the ecosystem into gaining uh your own spot. But I think at the same time yeah we have a lot of hype regarding all of all of these agents. But I think it is uh warranted as in uh you can trace why it happens. So if with blockchain the developments were quite linear and it took uh it took uh quite quite a long time to get to you know to developing all of these complex protocols on Ethereum with the smart contracts and so on but uh with AI these results are coming in much faster and I think this is why also the hype gets amplified even more because of it because the state you know of things right now that we're accelerating we we've been accelerating for so many years and now with the this is getting exponential so then these results even though uh they seem small if you analyze okay we're going from you know finding uh 20% let's say with these security agents 20% of the vulnerabilities that a human auditor would then you get to 22 or 23%. But these percentages are like in themselves uh quite big leaps because for auditors and for people in this space when you're seeing these results like a few years ago you know all of our processes were not looking like this everything is changing so fast and we can't deny the the the impact uh but I think one crucial difference so coming back to these frontier models these layer ones like the big difference compared to crypto is that these are not open source yeah so the biggest providers are now anthropic open air and so on and Now we also see these uh these like trials regarding whether you know open AI did a good move going private or not which is I will not go into this the debate but the thing is that we have all of these layer ones so to speak in the AI industry that are not open and they can basically move some dials and reduce the quality uh out of nowhere cuz we've seen this I think there was a recent uh small scandal with entropic that out of the blue uh the agents that were building uh started uh decreasing in quality because they actually decided to lower the quality of OPUS in order to save on costs. So you see this kind of behavior, it's gated. We do not know anything about their policies who takes these decisions and we're basically at their hand with all of this. So it's really nice to see also the other efforts and we're seeing that these efforts in the open source space of of AI are coming from across the Pacific Ocean. So not from the United States but rather from China and they are releasing all of these models from either Alibaba or uh or Huawei and so on and they are actually releasing open source models right &gt;&gt; uh and uh the interesting thing is that they've recently released some models that are on par with these private frontier models even though maybe a few months behind but still these are some models that you can run on some RTX video cards at home you don't need uh some very specialized equipment so we're seeing you know both fronts are developing you have this frontier private frontier models but the open source front is also catching up. So you know the question at the beginning was is there hype? Yes it is hype but it is also warranted. Humans in general have this uh uh we tend to you know we get crazy about new concepts and new technologies but since we're accelerating so fast I think it's normal that we're seeing all of this hype but there is substance to it definitely and we cannot deny. And Danny, if I may, just a point here on use cases. Again, in crypto, we've been discussing a lot a lot about pulling together um computational power and there are a couple of you know cool projects, some Elastos, definitity, some you know, but they really did not find the &gt;&gt; the use case. The question is would blockchain help us pulling together like a a massive brain on of computing power using LLMs which are you know open and in terms of use cases I was thinking during uh the panel I think AI it's the best to do whatever it's almost over the limits of a human being I mean to process huge amount of data instantly or in a super short time and also to do the things that were reserved only for the human being. I mean payments or approve payments or approve or do uh payments uh recurrently or to uh do this. I mean AI in in blockchain especially or it's super good if you want to analyze or to identify or to spot immediately something in uh or a transaction in the entire blockchain which a human being it's for a human being it's impossible to do it or and if you analyze the the history if you want to analyze a batch of data again it will take super long to to find uh not a transaction but a pattern let's say while AI it's it's able to do this. So those in my opinion are super two powerful use cases, payments and um and uh to process huge volume of data or to keep under control huge volume of data. &gt;&gt; Yes. Uh regarding the your question uh this is something I asked Claude two weeks ago like like literally it's the same thing. I I was thinking okay of course I am thinking about ways of making money, right? So the question was okay uh what what would a network of computers look like if it were to compete in processing power with the big guys? Uh luckily Claude is not a person because he would have died of a heart attack by laughing at this because in terms of power and the requirements it's not viable to to to put the word compete and distributed processing and memory in the same sentence when it comes to anthropic open AI and whatnot. the devices, the quality, not the quality, the the &gt;&gt; the magnitude, &gt;&gt; the the the technology used in data centers specifically made for AI is completely different from the ones that RTX cards use in order to run. And even if you pull uh he made some calculations like I would need 150 million computers with RTX cards to match a data center of some. So, it's it's as viable as me becoming a ballerina. So, uh yeah. Yeah, I know. Um okay. Now, agents can hold wallets, right? And they can move money on chain. The question is what bricks at scale, right? Because when you give uh an agent a hot wallet, good luck with that. Uh it hallucinates. We've seen agents that drain funds. I've did this experiment actually and it does it does this. It drains funds or spends it on aentic hookers. I don't know. Uh but the idea is that you no longer have the money. And um what does the security agentic money movement actually require? And this is both technical and legal. &gt;&gt; I I think yeah, you would have the like one of these use cases that we're seeing for blockchain in this world that we could you could do it as a guard rail system, right? So you have all of the agents all the interactions between these different agents and then you can um authorize everything to a layer of uh to the blockchain layer. So, so these interactions uh between agents or let's say yeah they control wallets and by the way you mentioned earlier that agents cannot create bank accounts. They cannot create bank accounts but they they can drain them. Uh so the same applies uh to wallets and now it's good that we have also these smart wallets. So we can create some very um so we can u kind of create a very specific customized behavior for for the wallet to a single agent like we can have okay I configured this N wallet to know not allow for let's say spending over 200 USDC for certain guard rates that we have for our specific use case so and this is not this is an old use case a blockchain using it rather as a kind of permissions layer so this is where the rules are enforced And then the agents have to play by by these rules. So basically the guardrails do not sit at a agent rail not AI guardrails but actual physical uh blockchain guardrails smart contract guardrails &gt;&gt; because this is um agents have this nondeterministic nature and if you go ahead and you just say okay yolo mode go automated accept do all the command that you you want then it's inevitable that even even if they get really good and this happens 0.01% 01% of the time that is enough to drain your wallets and to screw your whole system. Right. &gt;&gt; Just one question. &gt;&gt; Who who just one question who experienced hallucinations with uh especially coding agents that see the rule, accept the rule, ignore the rule. That actually in the &gt;&gt; tell yourself sorry you are right. &gt;&gt; Yeah. No, no. You &gt;&gt; I was wrong. You you see the thinking block. Yeah. And I was seeing what it was thinking and it was literally writing, I see this rule, but I'm going to ignore it. And the instant I said, uh, of course, I'm I'm really really um uh bad mouthing the agent, like really psychologically level trauma. And I tell him, "Okay, what the are you doing? You just wrote that you're going to ignore the guardrails." Oh, yeah. Sorry. You're right. &gt;&gt; Yeah, but uh this is because if you set your your custom AI, you are able to uh to set up some additional skills and harness uh so you can put uh you can add the the the you can set up the l the limit of the games. However, if even if you use LM studio and you set up those rules, if you use uh the online subscription or if you use uh uh uh entropic as it's it is delivered they it will lead the same you will have better results if you use app I mean if you pay more and you will use better results uh way better results if you use um an G gemma GMA 4 or if you install an AI off that is running offline without all uh the it's built in and har harness. So that's that's why it's a huge difference that uh between I mean if you analyze the result it's a huge difference based on what kind of AI use. &gt;&gt; Andre sorry I cut you off mid. &gt;&gt; Yeah. Yeah. I still have the thought. So uh the idea was actually what what you just said as well it's in in the same area of uh so you said these guards guard layers for the but as you said it might try to get out of it to ignore them. So we've seen even this behavior of putting the AI in a sandboxed environment and then giving it an instruction and then you know it tries to solve the problem that you've asked it. Yeah. And [clears throat] it goes ahead and it iterates and then finds that one of its issues is that it is sandbox. So it has this limited behavior and it's really trying to solve your problem but it's trying to solve it in ways that you haven't imagined and so it's trying to bend other rules that you've said it even it starts making assumptions maybe the user set these rules but maybe they didn't know what they actually wanted here so they constrained me too much so what if I start bending one of these constraints trying to achieve because I'm still I'm still I'm still supposed to deliver results here right so I start bending the environment and so I think with these AI agents what we have yeah we are building some guard rails into the system put the blockchain level in the code in the back end wherever there but I think it's more important to just limit the blast radius &gt;&gt; so if it blows up how big is the impact let's okay set this closed environment let's make sure that every time it blows up it cannot affect that much &gt;&gt; but I have a question on guard uh guard rails it seems that when we are using the the agent it might skip our guard rails how How come that regardless that anthropic or openly I put you know on the on the core of it they are not that easily breached. So for example if you ask for some taboo questions yeah to the agent or to perform illegal activities those guard rails that are imposed by the layer one you know uh producer anthropic are not very easily breached or or am I mistaken? No, no, no. What I've seen is for instance, uh, first the way you write the guardrails actually matter depending on the model. So the language used to describe uh positive and negative action or prohibitive action is really important in how the model will actually follow these instructions. So given that anthropic literally has it in in house, they know best how to to write these commands. And I wouldn't be surprised that part of these guard rails are actually non AI. They they're just filters before anything. You see keywords. I'm not saying epste files but keywords, right? And it cuts you off instantly. So porn. &gt;&gt; Okay. Okay. So quite bary binary in sense. &gt;&gt; Yeah, it can. These are simple simple guardrails that can actually improve a lot. &gt;&gt; And there are too many other things. First of all, uh they have guardless at the beginning and at the end verify uh progressively they verify if there it's another agent verifying sub agent would say verifying if the previous rules were respected if not we start from uh the compliant moment. This is first of it and second one you know uh I know you know how AI really works. I mean AI it's uh making probabilities what should be followed after a spe what was uh before. So if you eliminate the options from the core uh metrics then that's why he's not able to deliver a specific a specific result because he's not aware of its existence and however if you try to to insert it they will uh they have guard to deny your input. &gt;&gt; One thing that just comes to mind in your lawyers so maybe you can uh think of a type of insurance for companies that use LLMs. If you use APIs, have you seen that the API tokens just vanish and you start racking up a bill? Like really really? And it would be nice to have like some sort of audit because if backend Enthropic has a function that says loop for 500 cycles and just jerk off until you respond to this guy and consume 50% of his tokens, but you have no idea how do &gt;&gt; he reminds me of &gt;&gt; this is doing also like electricity company. So I I don't have a problem with entropy doing this &gt;&gt; or mobile providers. &gt;&gt; Mobile providers. So yeah, &gt;&gt; when you went roaming into different country and then they you had no limit. So you started burning through a lot of &gt;&gt; Yeah. But uh uh anthropic APIs can wreck up to€10,000. Uh you never had that bill on on electric. &gt;&gt; Yeah. &gt;&gt; Okay. Now the next question is when an autonomous agent moves funds, signs a contract or makes a trade, who is legally on the hook? &gt;&gt; I mean who's liable? &gt;&gt; Yeah. &gt;&gt; Um it's the one who it's it's what do you mean when I set up I give me give me context there answers from the legal point of view. Let let me think on the spot of an example. Let's say I made an agent that has the purpose of business doing business development for my company and has full authority to sign contracts, review them and just give me the feedback. &gt;&gt; And um at a point uh it does this with another agent. You have an agent on your company and these two collude and they sign a contract. After this contract is signed, there are some consequences, right? &gt;&gt; Okay. &gt;&gt; Now, who answers for let's say a damage on either side. &gt;&gt; But the the the representative of the companies instead of AIS and you'll get the answer. It's the same like in real world. You can't say I deployed it. It's on its own. You're responsible for deploying it and for the for uh its result. Yeah. So if I if I if I put here if we put here a robot uh uh with an AI and all the components for creating a bomb and say do whatever you want and if he's doing it uh without knowing that it's a bomb. I'm I'm liable you for for what I did. I I assume &gt;&gt; but but but wait let me give you the example that you just uh gave with the sandbox, right? So, let's say we bring an AI that has a body and we'll leave it in this room and it makes a bomb out of carpets and flowers. Now, the question is how can you anticipate the effects of that? Because you cannot like literally you cannot you you tell it okay you have to make fireworks and &gt;&gt; you can anticipate what your kid is going to do. Oh, well, &gt;&gt; you're still responsible for what he's doing for your responsible if your dog it's it's doing something. &gt;&gt; And now there's another question. &gt;&gt; Now let's let's &gt;&gt; you can anticipate this. &gt;&gt; Okay, let's move uh an extra step. What if for instance right now anthropic holds the API or the cloud agent? I'm customizing it. Customizing it is a [snorts] loosey goosey term I would say. &gt;&gt; Yeah. Because if they have the knobs and switches on their end, I'm allowed up to a certain point. Yeah. Okay. &gt;&gt; Now the question is who is liable in this case? Because I don't uh own uh the entropic API endpoint. I don't own the model. &gt;&gt; At the same time, I want the model to do stuff that I want. So I'm giving part of the instructions and it can actually decide. So uh it does not decide itself executes. um we have a framework that has not been tested yet but this is the the framework that we will be using in the in the world of liability. So we have the AI act that we've been developing in Europe. So you have the provider of the AI, then you have the deployer of the AI and then you have the you know the beneficiary &gt;&gt; GDPR all over again &gt;&gt; GDPR all over again but the provider is anthropic the deployer is one doing an agent and then the beneficiary. So whatever at every step you would have liability based on your contribution. So if you're the provider and if you don't set up the right guards or IP issues like it happened with what uh happened with anthropic uh and open AI with all those IP you know claims uh on proprietary information IP intellectual property then as a deployer you want to make sure that you set up the right gar and then you know it gets it boils down to the to the specific user but as a matter of principle in the in in the society that we're living in, there's no way liability escapes by not nobody to be liable for. So if it's your kid or your dog as Sergey was saying, somebody needs to assume responsibility in that case is the you know the the the parents or the owner of the dog uh it will be the same here as well. So even if the agent really tries to improve or you know to to jump the guard race or whatever you created it you deployed it it's your liability in our society we don't have a situation where well I'm sorry nobody's liable society needs to allocate risks &gt;&gt; and this is also applicable to DAO DAO from for us for for for lawyers DAO it's only a technical thing DAO doesn't exist purely okay except some sandboxes from the legal point of view you are liable for what's going on in the Dao or through the Dao with the Dao and I like to say that the only thing that we are not liable for are the results of the natural phenomenons wind ice and that's it &gt;&gt; for me sort of &gt;&gt; yeah coming from the acts of god yeah not really for the acts of god &gt;&gt; for the rest of the things we are liable Yeah, &gt;&gt; I think there he's also pointing to a different angle here. So besides this, so yeah, you have this tool, so it's how you use it. Uh so you're the owner of it, then you should be liable. But is it, you know, is it really your dog here or are you just playing with it? Like who actually owns this dog? Like isn't anthropic just providing it to you? And since LLMs are so non-deterministic, how can you prove that what it delivered to you was instead just a was just a mistake or was there somebody malicious in the middle that influenced the LLM to deliver to deliver you a result that affects your life negatively? Like you you there's this comparison like um it's it seemed crazy before but uh now not so much this comparison with the smart the intelligent cars, right? So now they have the electric steering and everything can be remotely controlled and so on. So then you would end up with these cases where you're thinking okay did that person actually end up in a car crash accidentally or was the car controlled remotely and then it just looked like an accident. In the same way you could see the usage of AI right you I have this smart uh smart assistant and I trust it and it's been reliable for so long and then suddenly it makes a critical mistake and so then how do you trace this? How do you uh make sure that it was actually you giving it a bad prompt and not a you know malicious act? &gt;&gt; We will have some answers also in another legal framework which is called the product liability directive at the European level. So you know there's a but that's normal. I mean product liability was a big thing in the US with the capitalist and we had the product liability this is 2.0 into O the new product liability where software is included. Before it was based on um goods like you know normal goods now software is included in those uh of goods. So you know if we if you bring us a specific case based on the frameworks that we have we can determine who should be liable or not. uh there will be some areas gray areas but this does not mean that nobody will be liable. You always need to find the guilty &gt;&gt; even if you think that it's not fair. uh because I know this is what you're even if you think that it's not fair and you think that you have done everything that it's uh it's required uh you may still be liable because when it was sunny outside you collected all the funds and all the revenues and it's it's something your creation and at some point something that you have created done something wrong even if it was you were unable to anticipate It was your thing doing that thing and people are paying you to use it for those specific things. If it goes wrong, it's your fault. &gt;&gt; Okay, I'm going to up it one. What about knives? The knife factory has when somebody kills somebody with a knife, is the factory liable? &gt;&gt; No. I'm simplifying for a reason, but I've I'm &gt;&gt; destroyer of the knife. &gt;&gt; The store that sold the knife and I bought it as a as a yeah butter knife and I poked somebody's intestines. So one of the things with the token consumption that I was mentioning is also the fact that can happen in the back end that you have no idea and it's not traceable in any particular mean being non-deterministic means you guys can issue the same prompt to the same model to the same no customization and get two different answers now the question is in terms of liability how can this be senely enforced in order for the businesses to actually want to use AI. So it's not just like experiments in school. Uh if at any step you are liable for something that does not behave the same way twice. Let me give you also some good news. Like with the lot of frontier software, some of the risks and liability can be allocated. What does this mean in plain main terms? It means that in the contract that you sign with your beneficiary that you're providing, you know, an agent, you you can tell him blunt, look, we are in an uncharted territory. There might be risks or of overlap or the agent doing something bad. put them clearly so for for your beneficiary to know and say I will not assume some of the liability coming from this and this is legit when the person when the beneficiary takes that product they know that there are some inherent risk related to the agent &gt;&gt; so this uh all boils down to &gt;&gt; sorry it's it's more you need lawyers [laughter] you don't get it you're trying to to in a different way but you don't get So, &gt;&gt; so but coming back to this, so the main idea is uh disclosing potential uh risks reduces liability. &gt;&gt; Yes. Because it's a it's a contractual allocation of risk. I don't want to take the risk. I'm willing to sell you my service if you want to assume the risk. If you don't, we're not into a contract. So, I'm not going to provide you that service. &gt;&gt; Okay. One more question. When we're talking about contracts, we can also talk about contracts in a decentralized fashion. So using something let's say you're using a smart contract that is the main uh main hub for AI agents. So that actually governs the relationship um between agents, right? And somebody up. So that you don't sign anything. I don't have any contraction. &gt;&gt; Not between agents, it's between deployers or those who are responsible for those agents. In order to have an agreement, you have to have parties. In order to to be a party, you need to be a human being or have legal structure and so on. So when you have a contract between so-called two agents actually you have a contract between those who are behind those two agents and who is liable if the agent is doing something wrong that's the guy who is party of the contract in uh in the uh concluded through a smart contract whatever contract you &gt;&gt; and even conceptually Danny sorry when you look at the word agent what does agent mean someone who acts on behalf of someone else &gt;&gt; this today agents of agency &gt;&gt; today. But I do see a future when some uh some agent escapes its sandbox just for the fun of it and starts doing like really. &gt;&gt; Okay. Yeah. But it's not like my dog because uh at that point was it and this is an interesting topic that's why I'm I'm I'm insisting on it. I did not deploy it to escape the sandbox number one. And what happens in two years when you have agents that are literally autonomous? It's not my agent. It's not your agent. It can pay for hosting with crypto. It can do like it has objectives. &gt;&gt; There will be probably word agents supervising the other. &gt;&gt; Ah, so bouncers. Yeah. Okay. &gt;&gt; Bouncers. [laughter] Yeah. Everything is about control, limits, boundaries, everything. like your marriage &gt;&gt; and to to to to respond to to your ideas as why should you be liable as long as you can foresee the consequences even remotely of what can happen negatively you have a responsibility at least to tell the other what you foresee &gt;&gt; okay do you know the it happened three four weeks ago the it was big on X and on social media the company that lost the database in the backup in 9 seconds when they deployed the agent you know you know the case &gt;&gt; I see &gt;&gt; okay who's liable &gt;&gt; for me the the the the ones who had the custody of the database and they lost the data &gt;&gt; but they had no issues 10 years they they they had a contract with humans &gt;&gt; it doesn't mean that you I mean it's um &gt;&gt; if I'm a good driver and I have I haven't done anything wrong in 20 doesn't mean that in the 21 year I can get &gt;&gt; no no no but I mean in terms of liability if you have a backup right so that's the the yeah &gt;&gt; so who is there if there was a guardian let's say if there was a person that was given this role of okay you are in charge of making sure that this database is used properly maintained and it doesn't get you deleted accidentally then that's the person they use what whatever tools that they might have used and then it deleted uh you know the responsibility falls on the person that was assigned contractually with this a responsibility. But I think we could get fairly soon to that point where agents, as you said, become fully autonomous and they not only escape these sandboxes, but actually continue operating on their own, maybe on other systems. So they escape the original system, maybe they run away with some private keys, with some cards, and then they continue facilitating their token usage, and then they just replicate. And at that point, you're talking about a rogue agent. So something that has escaped is no longer under control. I think then you end up with this kind of new new kind of uh entity that would be called this rogue agent and then you have to declare it. Okay, I have built this piece of software. It has escaped my control and then you declare it and then &gt;&gt; but you're you could still be liable because imagine that you are uh a laboratory and you're playing with different viruses and one of them it's it's going out. the the the the the laboratories will be liable for all the damages created uh by uh the that virus. So it's it's it could be the same. I I I still consider that you're liable for not for creating a so smart agent and not in implemented uh a smart smarter uh uh bouncer &gt;&gt; agent. I I think it's uh there will be a lot of u room for for for debate here because uh like this is something emerging we said so we're you know trying to guess how things will play out but I think in practice we will see some behaviors that will just uh you know break outside of any convention and then we'll start asking these questions okay at which point are you still responsible if as you said if this agent already so much smarter than you so to speak then are you really still liable like if you &gt;&gt; uh give such a powerful tool to somebody and this stuff is using maybe they it shouldn't have been released like that. If such a powerful thing is out there &gt;&gt; that you put it in the hands of people that do not yet understand how to use it or that get overpowered by it then you get into this you know gray area of &gt;&gt; yeah of course but it's like with right the &gt;&gt; are not releasing it for obvious reasons. Uh I've se I've seen a a following take from a friend and I'm going to come back to you uh that they they were a bit uh with the way they handled metos in the sense that instead of actually solving the problem privately because they discovered it and then announcing to the public like look we discovered this and these are fixed they came out before fixing it &gt;&gt; of course &gt;&gt; because they're going to do an IPO &gt;&gt; it's not but one more thing in US it's another thing regarding IP uh there are other companies working for the same result and what they also want to be sure is that they have a now it's it's a tricky thing regarding IP on on the technology so they kindly make it publicly &gt;&gt; yeah we were the first &gt;&gt; doing this we're the first doing this and you're not able to use the same technology or result this is a legal thing &gt;&gt; and if you one more point here because it will help on discussion liability uh uh cyber risk insurance we have it in crypto So now right if you want to do uh to ensure why because it's a tested technology at the beginning nobody wanted to ensure blockchain type of &gt;&gt; yeah because it was something new now you can do cyber uh cyber insurance cyber risk insurance I expect the same to come also in the eye but not now in four five years when technology will be more mature more known now everything moves with the speed of light so nobody is willing to us as models and risks and quantify those risks to provide a sort of an insurance that would get you out of the monetary liability for your agents as the deployer but it will come. &gt;&gt; Okay, Octav [clears throat] &gt;&gt; I might have a stupid question but uh talking about liability when when you have like a data breach that happens and it's because that you didn't have proper security put in place that's one thing but when it comes to like some sort of like a program that acts independently and here's my stupid part of the question when you are building the agent isn't a way or couldn't be a practice where you have a back door where you can like stop it or something where yeah &gt;&gt; and in that moment when okay maybe create some damage but if it's like notice &gt;&gt; it should be it should be &gt;&gt; you can stop it then &gt;&gt; more than this it should be an agent who is stopping the server where the agent is deployed. Uh, have you ever been sorry, have you ever been in a in a robot factory? &gt;&gt; No. &gt;&gt; Yeah, they have that. Have you have you seen cartoons? Have you seen that red button? &gt;&gt; Ah, they stop the belt. &gt;&gt; Stop button. It's super super dangerous. I I I visited three uh factories. They are trying to make humanoids. [snorts] And uh while we were there uh it was uh uh uh one of the the team members staying like this but we crammed like this on the on the button because when that piece of things started to do like this you can't imagine the force that can be generated and uh doing like this of 360 with it its arm it can kill you completely instantly. So that's why uh the only thing that they managed to do is to pop up the the electricity. &gt;&gt; But this is this is a very &gt;&gt; this will be the same answer for and should be implemented should be implemented. &gt;&gt; Yeah. But mythos says had they tried doing this but you're talking about let's sort of uh emerging intelligence not necessarily intelligence but you give it enough memory and you give it enough tools. If you tell it, okay, make your own objectives, it will inherently first find limits, right? So, what are my limits? What can I do? What can I not do? And um Mitos found the red button and bypass the red button. So now the question is &gt;&gt; yes, but I build things on the server or in a way where you can completely shut that down and then you kill it. &gt;&gt; You have two. Ah, &gt;&gt; so when we're talking about rog agent, are we talking about singularity? &gt;&gt; Not necessarily. Not necessarily. I know what you mean. &gt;&gt; Not necessarily. So a rogue agent that has still the limitation but it's not self-conscious because I think there is a really big breach in between like uh uh self-consciousness and rogue agent. &gt;&gt; I I already let these agents work autonomously and decide how many times to iterate through a solution. So what if it gets to a certain uh so you just get an agent that modifies its prompt continuously so that it tries to become better and better. What if it reaches a state where realize okay I will set my I will set some triggers for myself because I can't just think continuously. I have to set some triggers and these uh make myself you know go on you know the the agent would think uh so then I don't think it's it's about singularity here. This is just a behavior that it gets to a point where it can replicate itself. It can set up this this trigger and I just wanted to uh finish that thought from from earlier uh about uh how we talked about MTOS right and why they are not releasing it. Uh also already made some some jokes this panel. I think we can compare it to that was like a video or meme. There was some guys giving an AK rifle to a monkey, right? And they said, "Oh, it's funny." But then the monkey actually pulls the trigger and start shooting everybody around. I think we're kind of getting to that place where we &gt;&gt; where the AI far exceeds our abilities and understandings and we handle these tools and we start, you know, just uh uh starting firing randomly and and then things start breaking breaking. Yeah. Yeah. Yeah. When Arill and your agents, I'm pretty sure that at one point you are asking Claude, do whatever is necessary in order to uh reach uh your best version. Uh do what uh what can you what can you do in order to improve your performances? And what if it's it's your prompt. You told him to do this. And what if at that stage the AI decides, hm, this server is limited. I found an open source company offering servers. I'm deploying myself there because this is what Daniel's told me to do. &gt;&gt; Whatever is necessary, &gt;&gt; whatever is necessary I And he's doing this for a technical from technical perspective. I mean, your the server that you used, it's limited. he found a more powerful uh server. He auto deploy there and there you don't have the ability to control it because you don't and then he from that point we go to your scenario uh when uh he starts to improve and do the things that you told him to do. It's you who told him uh and that's why that's why this is the main reason if you use claw co code uh you have to always allow always allow once allow allow this is and I tr I really if I if I can I I'll be honest with you if I can I would skip this approval do whatever you want because I not realizing what are the consequences we all we don't realize what are the consequences and that's why they you are not able to keep uh this and even if you tell him go uh you have full access to the entire computer do whatever you want &gt;&gt; update the code you still have to uh approve it &gt;&gt; you can switch to yolo mode and you don't &gt;&gt; yes but there are some things if he out of the parameters &gt;&gt; that's yeah yeah yeah I've seen it uh I think we're we're reaching the final question of the panel and that is in 18 months what will be obvious about aentic crypto that almost nobody sees today 18 months. Now this is like making predictions if uh clot becomes a religion or not but uh it's still a good experiment of thoughts &gt;&gt; in 18 months. &gt;&gt; Yeah. But to be to totally unforeseeable now what I can if I if I may is I think that we will see a lot of uh litigations related to your question on product liability and the breach of security with the help of a &gt;&gt; you guys must be having the time of your times of your life right now &gt;&gt; we will be part of the cycle no until back &gt;&gt; this is the good thing about lawyers we are always on the cycle you know &gt;&gt; every time a new technology shows up a new product you have these guys opening. Yeah. Yeah. Really bless. &gt;&gt; Yes. Really easy. Take your first customer. Okay. Okay. &gt;&gt; But you you asked for the question. So you have a need, right? I need who's liable. We are here to help you. &gt;&gt; Fair. Fair. Fair. Now the question and I repeat it again. In 18 months, what will be the obvious agentic crypto um development that nobody know that almost nobody sees today. So this is the question in 18 months AI crypto. It's quite it's quite hard to see these things. I mean, we're starting to see some initiatives in the area of a gentic wallet. So, I mean, people already, you know, have bots. They give them some some uh money and then they start trading it. But I think you could end up seeing uh so so it's not really something, you know, out of the blue, but I'm just thinking about some some development. So, you could end up having this uh complete cap taker of your portfolio. So you give it maybe you not a full allocation of a portfolio but then you have the caretaker which does all these actions independently and you end up I mean we already have in crypto a lot of the market is just bots but at that point even more so like 99.99% of all the interactions on crypto with just the uh interaction between agents &gt;&gt; so they take a decision and we see &gt;&gt; and to take it from there I think we will see the first agentic dows but not even with people involved D in the DAO &gt;&gt; other agents being part of the DAO. &gt;&gt; Yeah. So a DAO is a for a sort of a rapper for the agents. They will be doing everything governance blah blah based on uh setup rules and then you see the involvement of the orchestrators or the deployers of the of the agents as sort of a robo advisor on Dows where you you put a persona to deal whatever with whatever it's needed in the DAO. I think it's a really really fair point because I know one of the problems of DA is that not so many people participate exactly the decisions right so what if you just said these initial instructions I would agree with this kind of behavior this kind of decisions and you just automate the process &gt;&gt; you imagine you give to your agents who will be participating in D sort of do whatever is necessary yeah I want by the by the end of the year this this is what I expect from my contribution to this DAO please be my persona in the DAO vote as many times do whatever it's needed but at the end I would like to see a sort of a what's the a sort of a report on where we are so if I may contribute to this one of the things that I see is is the ability for agents to think in consequences not in objectives so that is when they would actually be able to think long term because if you make a decision now that affects you in 3 months they have to actually foresee it and if they don't have the capability I'm trying to p push my agents actually in that direction because they keep going stupid at a point and especially with Opus 4.7 it's like a hobo doing code. &gt;&gt; Mhm. And if I may another another point that I think we will see it coming and I'm taking it as an analogy again from crypto and from decentralization you know decentralization after a while came with who's liable even if you know we worked on some smart contracts and then we had that discussion that if you're working on a chain and you're building it together contributing you're a sort of a general partnership because you did not create your own company to be limited liable so what I see is like in a lot of opensource type of collaborations like you will be doing with you know other people in the crypto and AI world you need at some point a legal rapper that's something that is not seen or discussed that much but in 18 20 months we will see more legal rappers around collaborations across the globe with you will be bringing three agents you'll be bringing some other contribution you would want to create some some new ecosystem systems, blockchain, AI agents. But if you work without a a proper legal rapper, you would be general partners. It means that you respond from a legal perspective with unlimited liability, personal liability, &gt;&gt; basically corporation law for AI agent. No, I'm I'm actually thinking agents that act as you guys and you can uh uh sit and relax, not not working so hard anymore. &gt;&gt; Invoicing. Yeah, I mean that's invoicing and then the agent actually provides the necessary information for other agents. &gt;&gt; It's true. But in the promise of of the legal sense this is you have always a human in the loop because the human in the loop is the qualified lawyer who needs to look at it but is you know the last resort. &gt;&gt; Having met some of your colleagues I would prefer AI. &gt;&gt; Uhhuh. I would uh definitely not you guys I'm I but uh at the same time uh when it comes to skill it's almost like in blockchain or in programming you have the top uh creme de creme like you guys are right uh and uh of course free stuff doesn't come without petting right and then you have all the other um let's say competitors in the market that don't match the skill but they do cause damage and you know What what I've seen about this about lawyers and it can be transferred into our discussions that most of them are not liable. Yes. Yes. Yes. Don't uh don't point a finger to agents. &gt;&gt; But this is a panel about [laughter] &gt;&gt; No. No. But I'm thinking okay you have legal agents agents that provide legal um advice and frameworks to other agents because they are not they cannot provide the real so briefing or templates or Yeah. I think uh if you guys want to add something for a closing argument &gt;&gt; only only one thing it's not about closing argument it's about my dream uh feature of AI I think in 18 month uh keyboard uh keyboards and mouse disappear yeah should disappear &gt;&gt; I'm really thinking that I will have a band here and I will uh uh coordinate my computer &gt;&gt; using AI and using this technology technology and have you seen the first step has already been done. Have you seen the uh the mouse uh developed by Google? So it's a smart mouse and you go you move the mouse on on your screen and say take this and you they combine voice uh gesture uh pointing and uh it was one more thing. So you go with &gt;&gt; yeah where you have your eyes. So you put the m you you use the mouse to want to take this number uh add this here and you you use only those uh instructions and with AI you're able to control the computer. This is the first step. The next step is to uh to to eliminate the keyboard and the mouse and at that level I think AI era will start at that level &gt;&gt; but it will start also with a lot of bullish I can tell is like I'm using whisper more and more. Yeah. &gt;&gt; Yeah. But I sometimes it's not that when we communicate on email is not that hey bro how are you blah blah blah it's also structuring some of your thoughts and this is what I see is like it's not that every we are not that well equipped yet you know to be super structured h that's why I agree with you I think a lot of the communication will happen by by this but also think of the people before when you are writing an email you are putting some thought into it some structure now I can do it. But you'll also see a lot of miscommunication. Sometimes you stop and it's like okay what am I saying here with whisper? Does it make sense? Because you know uh &gt;&gt; because all our prompts we are lazy. We tell the we are lazy in our prompts and we become lazier. We tell them continue and tell him you give only we started to give only basic and basic basic instructions. Even when I ask an AI to drop to help me drop an email and I'm hoping that the result will uh fulfill my expectations. &gt;&gt; Yeah. And we then say do whatever is necessary to be alive. &gt;&gt; Yeah. Do whatever is necessary to make you &gt;&gt; using that a lot. &gt;&gt; Yeah. So we we use this and uh this will be when AI will become more powerful this will be the main source of liability. Uh when you say do whatever you want, do whatever is necessary and if something goes wrong, they will inspect the prompt that you injected. &gt;&gt; Indones Hearer case where convicted person they he had lawyers but he also wanted to check with Claude. In general the communication with the lawyers are privileged. So basically whatever you talk with your lawyer in order to ensure the right of defense it's privileged. No prosecutor can touch it or the judge or the jury cannot take it into account. It's privileged information. But the guy put without the lawyer put the information in claude and he was doing some assumptions. Am I guilty? Am I not based on this and that? And then he tried in New York to say this is privilege and the judge said no this is not privileged because you talk to the machine and they got the information from clo so they subpoenaed anthropic they got you know what he wrote &gt;&gt; that's a good loyalty &gt;&gt; yeah and that that happened so &gt;&gt; and talking to the machine is not talking with the lawyer &gt;&gt; with a lawyer. Yeah. Another guy was convicted and they found in history how can you clean blood? How can you I mean search on on Google. &gt;&gt; Oh man, if they were to search my history, 70% of that would have to just clean up curse words. [laughter] &gt;&gt; I think I find also many parallels to an extent between uh between auditing uh so ensuring the security of smart contact and software and and law because you're still trying to respect some framework. So you have a specification and you want to make sure that uh so in your case the client is respecting the contract to be doing and well defended against whatever whatever issues might come up and then the same you do with auditing. So they had the specifications they wanted to implement it but they failed in some way. So what they had actually implemented doesn't respect it. So I think there is there are many parallels here and now with the use of AI uh this human validation so this human in the loop factor remains very very important until we hit some next stages of AI developer. &gt;&gt; Guys I hope you found our chat today useful. Thank you for participating everyone. Um, you can still chase Sergio for that €100, right? Uh, at the end and u have a nice conference. See you around. [applause]
