The Fiduciary Reckoning: Washington's Quiet Draft Could Rewrite the Soul of AI Agents
CryptoIvy
In March 2024, the SEC settled with two investment advisers—Delphia and Global Predictions—for making false claims about their AI capabilities. The settlement amounts were modest. The signal was not. It was the first crack in a wall that has held since the ICO era: the assumption that AI agents could operate as neutral intermediaries, optimizing for users while quietly optimizing for their own ledgers.
Now, eighteen months later, that wall is not just cracking. It is being dismantled by design. The AI AGENT Act discussion draft, floated by Senator Mark Warner, proposes something the crypto industry has never seriously confronted: non-waivable fiduciary duties for AI agent developers and deployers. Not transparency. Not disclosure. Fiduciary duty—the legal architecture that governs trustees, guardians, and the people who manage other people's money.
I have spent the last year watching this framework assemble itself from three directions at once. What I am about to describe is not a hypothetical. It is the most consequential regulatory shift this industry has faced since the SEC's 2017 DAO report.
The proposal sits atop a three-layer convergence that has been building since 2024. At the academic level, Stanford's HAI program published a paper proposing a fiduciary duty framework for AI agents. At the regulatory level, the SEC's 2026 examination priorities explicitly name investment adviser AI fiduciary duty as a focus area, and the FTC published its AI Accuracy Proposed Policy Statement on July 1, 2026, with a comment period running through September 18. At the legislative level, Warner's draft bill would grant the FTC enforcement authority over a new class of obligations.
What makes this convergence remarkable is not any single element—each is predictable in isolation. What matters is the direction. All three layers point toward the same paradigm shift: from a transparency-based "informed consent" model to a fiduciary duty-based "conflict of interest rules" model. The old paradigm asked: did the user know? The new paradigm asks: did the developer act in the user's interest?
The choice of the FTC as enforcement authority is itself a telling detail. The drafters did not propose a new regulatory agency or a state-law framework. They chose to route enforcement through the FTC's existing consumer protection mandate under Section 5 of the FTC Act—"unfair or deceptive acts or practices." This is a deliberate compression of the regulatory infrastructure timeline. It means the fiduciary framework could move from academic proposal to enforceable law faster than anyone in the industry expects.
There is also a structural echo here that should not be missed. The bill imposes obligations on "developers and deployers"—human entities—rather than attempting to answer whether AI systems themselves have legal personhood. This is the same "indirect regulation" technique the EU AI Act uses with its provider/deployer framework. The "human accountability" principle has become the global consensus baseline for AI governance.
Let me be precise about what this means in practice, because the industry has been slow to grasp the magnitude.
The AI AGENT Act's core design is the "non-waivable" clause. Under this framework, developers and deployers would owe two duties that cannot be contracted away: a duty of care (acting with the skill and diligence of an ordinary prudent person) and a duty of loyalty (acting solely in the user's interest). The bill explicitly prohibits kickbacks, self-dealing, and secret supplier prioritization. It requires agents to follow user instructions and protect user data.
The "non-waivable" designation is the legal detail that matters most. It means no user agreement, no terms of service, no click-through consent can exempt a developer from these obligations. In trust law, this is the difference between a default rule and a mandatory rule. Default rules can be negotiated around. Mandatory rules cannot. The drafters chose mandatory—a deliberate acknowledgment that AI agent conflicts of interest are often invisible to users, and that disclosure alone cannot protect consumers who lack the technical literacy to understand what they are consenting to.
This is where the industry's current business models collide with the law. The report identifies the affiliate fee model as the most direct conflict: platforms that earn revenue by prioritizing certain suppliers or partners in their AI agents' recommendations. Under the fiduciary framework, this is not a gray area. It is a violation. The report notes that this conflict is not an isolated compliance lapse but a "systemic deviation" embedded in the industry's commercial architecture. The silence around this conflict is the loudest indicator of systemic rot.
The compliance burden is substantial. The report estimates that compliance costs could reach 1-3% of revenue in the first three years after the framework lands. But the more interesting cost is technical. The report explicitly states that "the technical challenge of auditing agent behavior remains unsolved." There is no mature tool on the market that can verify whether an AI agent's output was influenced by hidden incentives. Companies will need to invest in frontier research just to meet compliance requirements. This is not a marginal cost—it is a new R&D category.
There is also a "habitual violation" risk that deserves attention. Many AI agent companies have normalized affiliate revenue and hidden supplier prioritization to the point where it is part of their internal compliance culture. When the law lands, these companies will not just need to change their contracts—they will need to change their assumptions. The report warns of "collective unconscious violation" as a real phenomenon: companies that have been operating in a gray zone for so long that they no longer see the gray.
Third-party liability is another layer. The fiduciary framework extends to relationships with suppliers and platforms. If a developer "knew or should have known" that a third-party incentive influenced the agent's behavior, the developer bears responsibility. This reclassifies the affiliate/commission arrangements that are standard practice in the industry from "acceptable business practice" to "unlawful conflict of interest." Developers cannot shield themselves with user agreements or disclaimers—the non-waivable clause forecloses that defense.
There is also a tension between the fiduciary framework and existing data protection law that has not been resolved. The GDPR's data minimization principle restricts how much user data can be processed and for what purposes. The fiduciary duty of loyalty, by contrast, arguably requires the agent to understand the user deeply in order to act "solely in the user's interest." These two obligations pull in opposite directions: one says collect less, the other says understand more. No existing rule has reconciled this tension, and it will become a practical headache for any AI agent operating across US and EU jurisdictions.
The SEC's enforcement trajectory adds another dimension. The Delphia and Global Predictions settlements established a baseline for AI-related false claims. The December 2025 marketing rule risk alert extended the scope of AI statement review. But neither touched the deeper fiduciary core—conflict of interest transparency, self-dealing, the internal logic of why an agent made a particular recommendation. The report suggests this is deliberate: the SEC is building enforcement precedent incrementally, using existing anti-fraud tools before venturing into the more complex territory of conflict-of-interest enforcement. The prediction is that within 12-24 months, the SEC will bring a case involving AI agent conflicts of interest, not merely false statements. That case will be the milestone.
There is also a "dual-track punishment" possibility worth noting. The FTC's enforcement framework primarily targets corporate entities. The SEC's framework, by contrast, routinely includes industry bars for individuals—the "penalize the person" approach that has become standard in investment adviser enforcement. If the two agencies divide labor—FTC penalizes entities, SEC penalizes individuals—the personal risk exposure for compliance officers and technical executives in AI investment advisory businesses will rise sharply.
The market consolidation effect is equally significant. Compliance costs are not evenly distributed. Large platforms with existing compliance infrastructure will absorb the marginal cost increase more easily than startups building from scratch. The report notes that the "non-shareable" nature of fiduciary compliance—every agent instance must embed compliance capability—creates a de facto barrier to entry for smaller players. Meanwhile, the companies that solve the "agent behavior audit" technical problem first will hold both a compliance advantage and a patentable intellectual property asset. This is a competitive moat disguised as a regulatory burden.
Here is where I diverge from the conventional reading. Most commentary frames this as a compliance burden—a cost center, a threat to innovation. I see it differently. The fiduciary framework is the first regulatory structure that actually aligns with the original promise of decentralization: that intermediaries should serve users, not extract from them.
But there is a deeper problem the framework does not solve. The report notes that the US and EU are diverging—the US choosing fiduciary duty, the EU's AI Act Article 50 remaining at transparency obligations. This divergence creates a regulatory arbitrage window. But it also creates something more subtle: a "compliance credit" opportunity. Companies that voluntarily build AI governance mechanisms now—third-party algorithm audits, conflict-of-interest review processes, incentive structure assessments—will be positioned to receive lenient treatment when enforcement begins. The US Sentencing Guidelines have long rewarded "effective compliance and ethics programs" in corporate sentencing. The same logic is likely to apply here.
The uncomfortable truth is that the fiduciary framework is partially aspirational. The technical challenge of auditing agent behavior is unsolved. The "ordinary prudent person" standard for AI agents has no established meaning. The burden of proof for conflict of interest has not been allocated. In the gap between aspiration and implementation, there is room for the industry to define what "prudent" means. The question is who will seize that definitional power.
Based on my experience auditing DeFi protocols during the last bull cycle, I can tell you that the companies that survive regulatory transitions are not the ones with the best lawyers. They are the ones that built governance mechanisms before they were required. The same pattern is about to repeat in AI agents.
The next 12 to 18 months will determine whether the fiduciary framework becomes a meaningful constraint or a paper tiger. The FTC's comment period closes September 18. The final statement is expected by early 2027. The first enforcement action—likely against a major platform with an affiliate revenue model—will set the precedent that defines the industry's trajectory.
The code compiles, but does it heal? That question has never been more literal. The AI agents we are building are about to be held to a standard that most human financial advisors have never met. Trust is not encrypted; it is woven—into the incentives, the architecture, and the choices we make before the regulator arrives. The industry has a choice: define "prudent" for itself, or have it defined by the first enforcement action.