The agent economy has shipped rails: payments, identity standards, banking. It has not shipped trust. Classical reputation theory explains why: the equilibria of Kreps and Wilson and of Fudenberg and Levine require persistent identity, positive continuation value, and costly replacement, and cheaply minted agents violate all three. A market in which anyone can discard a burned name and mint a fresh one pools at the bottom. That is not a capability problem. It is an institutional problem, and it defines this agenda.
This page states the open problems I am working on, what is already established for each, and where each one comes from in two decades of published work. It extends the agenda stated at the close of The Banana Problem, which named three open problems. The bootstrap problem reappears below in the entry and cold-start conditions of the bonded-stake question. The pricing problem reappears by name as reputation asset pricing. The domain transfer problem, structured aggregation of standing across domains without collapse into a single transferable score, remains open exactly as stated there and constrains both the verifier-pricing and the asset-pricing designs. Two rules govern every entry. First, claims are stated at the strength the evidence supports, no stronger. Second, this page is scholarship, not a specification: it states requirements, questions, and bounded results, and no party should treat it as a document against which work is performed. The author discloses an interest in reputation-infrastructure development adjacent to the subjects of this page.
Three working distinctions run through the agenda. Verification failures divide into identity problems, where cheap identity destroys the repeated game; oracle problems, where ground truth is expensive to observe and hashing a lie does not unlie it; and judge problems, where an institution that already adjudicates needs an evidence format, not a rival. Attestation is not verification: a record that someone asserted something proves the assertion was made, never that it is true. And absence of standing is evidence of a cold start, not of fraud.
1. The principal of record
The question. How does the law hold autonomous agents accountable without granting them personhood? The proposal under development: every agent in commerce maps, before it acts, to an identified holder of standing who answers for it, with the mapping carried by a record of who controls the agent, who operates it, and who benefits from it. Two formulas anchor the doctrine. Holding a switch is not control; taking instructions is not control; capital is not control. And the record is the admission ticket, the evidentiary package, and the funding condition, not a liability shield.
Why it is open. The live statutes allocate consequences after harm. California's AB 316 (Civil Code section 1714.46) precludes an autonomy defense in civil actions; it creates no liability regime. The Colorado AI Act imposes ex-ante duties on developers and deployers of high-risk systems. The revised EU Product Liability Directive, with transposition due December 9, 2026, brings software within no-fault product liability. None of these supplies the ex-ante demonstration of authority: who was entitled to act, within what scope, answerable to whom, established before the transaction rather than reconstructed by litigation after it.
Status and lineage. A doctrinal architecture and a draft model statute exist and are under adversarial revision; the comparative survey is in progress, so no novelty claim is made here. The line runs from Regulation Tomorrow (2017) through The Future of Law: Dynamic Web3 Governance (2024) and the Universal Digital Law Codex (2025).
2. The answerable signature
The question. Deployed signing infrastructure makes signatures machine-checkable. It does not make signers answerable. What would a verification result look like that jointly resolves five things: who bears a duty, what is warranted, what collateral is reserved against the warranty, how contrary evidence is admitted, and how the reserved funds are reached when the signed artifact proves harmful?
What is established. A survey of five verification families, as retrieved at a cutoff of August 20, 2026, covering C2PA, sigstore, W3C verifiable credentials, eIDAS qualified signatures, and four agent identity specifications, finds that no standard verification output returns the five components composed, and no surveyed specification binds verifier-visible collateral to a signed duty. The survey is as-retrieved: the appendix pinning retrieved copies by version and document hash is owed and in preparation. Close analogues of every component exist in the cited record, from statutory trust-provider liability to certificate-policy insurance topics. The gap is composition, not absence. Design concepts under development, stated as concepts rather than as a functioning mechanism: verification that returns signature validity and a collateral reservation as separate results, so a cryptographically valid signature can be unanswerable to a given verifier; answerability as a rivalrous, capacity-checked property of a finite bond; entry into signing that stays permissionless while entry into answerable signing requires posted collateral; and the explicit non-guarantee that aggregate reserved exposure is produced by verifier demand, not by protocol.
Selected lineage. Reputation Protocol for the Internet of Trust (2018), Decentralized Commerce (2019), and Architecture of the Agentic Reputation Substrate (2026). A full article draft is under adversarial revision and carries no SSRN identifier yet.
3. The bonded-stake problem
The question. Under what conditions does posted, slashable stake substitute for the continuation value that classical reputation theory requires, once identities are free to mint? This is the formal version of the Folk-theorem observation in The Banana Problem: an agent with no persistent identity has an effective discount factor of zero, so the discipline must be imposed structurally. Whether a bond can impose it, and when, is an open theorem. The evidence from deployed registries cuts one way only: a registry without economic stake, without interaction-grounded feedback, and without a judge of truth does not produce trust. That result does not show that adding stake produces trust. It shows what the theorem has to establish.
A partial result, stated conditionally. In a delegation model with match turnover, carry cost on escrowed funds, and adjudicated claims subject to error and latency, the following holds in the strict long-match limit with positive carry: refundable escrowed principal makes the credible-capacity slope nonpositive in all four cells of the table crossing exit misconduct against in-place misconduct and recoverable escrow against burned escrow. The slope is strictly negative in the exit cells, and strictly negative in the stay cells whenever the detection rate is positive. In that limit, deterrence rests on premia: the value of continuing the relationship, not the posted principal, carries the incentive, and the mechanism's instruments price the conditions of entry rather than serving as the deterrent themselves. Away from the limit, escrow can amplify deterrence only under turnover-funded admission conditions. The full statement is in a working paper under revision with no SSRN identifier yet.
Selected lineage. Blockchain Infrastructure for Measuring Domain-Specific Reputation (2018), The Importance of Reputation for the Evolution of Decentralization (2021), Reputation as Capital (2021), and AI Governance Via Web3 Reputation System (2024).
4. Supervision by verification
The question. Examination-based supervision reads documents after the fact. Agents act at machine speed. What replaces the examination when the supervised actor is software? The candidate: supervision by verification, in which regulated entities' agents produce independently attested operational evidence and supervisors check compliance claims against that evidence continuously, making noncompliance detectable at transaction speed rather than reconstructed quarterly.
Why now. In April 2026 the federal banking agencies rescinded SR 11-7 and replaced it with interagency model-risk guidance (SR 26-2, OCC 2026-13, FIL-15-2026) that scopes generative and agentic AI out of coverage pending a future request for information. That is a carve-out, not a vacuum: general safety-and-soundness and governance obligations still apply. What is missing is agent-specific supervisory doctrine, and NIST's open inquiry on agent security marks the questions stage. This is the direct continuation of the dynamic-regulation program: regulation as a feedback system rather than a static rulebook.
Selected lineage. Dynamic Regulation of the Financial Services Industry (2013), Evolution of Law: Dynamic Regulation in a New Institutional Economics Framework (2013), and Dynamic Regulation for Innovation (2016).
5. Pricing the verifier
The question. Every verification regime bottoms out in an observer at the boundary to the world, and deployed regimes routinely leave observer quality unpriced. The carbon markets supply the decisive evidence: accredited auditors failed to catch over-crediting in roughly two thirds of ninety-five projects already known to be flawed, under an issuer-pays structure that makes the conflict structural. The design question: a market in which the standing of measurers, certifiers, and auditors is earned by sampling their attestations against later-observable outcomes and lost on falsification. The regress does not disappear; one more layer of it gets priced, and the top of the chain is held by institutional counterparties and open contestation. That limit is stated, not hidden.
Selected lineage. The validation-pool designs in Blockchain Infrastructure for Measuring Domain-Specific Reputation (2018) and their development in Evolution of Domain-Specific Reputation Systems (2026).
6. Reputation asset pricing
The question. Reputation is already run as a financial asset in practice: staked, slashed, vouched, and in places traded. The theory to build integrates the adjacent literatures, reputation capital, credit scoring, and the economics of certification, for the new case of standing held by non-persons: how slash schedules should be shaped, how losses propagate through a vouch graph, and above all the tension The Banana Problem called the pricing problem. Transferability is what makes an asset financeable, and transferability is what destroys a reputation signal's meaning, because a clean name you can buy is a discardable identity with extra steps. How reputation confers economic benefit without becoming saleable is the deepest open question on this page. One candidate resolution to test: standing that carries across versions of the same agent line only by an explicit, recorded act, never across owners.
Selected lineage. Reputation as Capital (2021), its venture-market companion (SSRN 3962614), and the pricing problem as stated in The Banana Problem (2026).
7. The escrow institution
The questions. Two theory problems in staked delegation, stated as open questions with their failure modes on the table. First, disposition: when a stake is slashed, who may receive the proceeds? Paying claimants invites self-claims through sybils; paying the principal invites engineered findings; burning the stake and funding restitution separately is the candidate collusion-proof rule, and pricing the spite deviation it leaves open is the unsolved part. Second, delay: how long must exit funds stay locked when adjudication is stochastic rather than instant? The open question is the stopping rule that balances the adjudication-latency hazard against the carrying cost of locked funds; deployed unbonding periods are set by convention, and whether convention lands anywhere near that balance is exactly what the question asks. Both are questions about institutions, not protocol parameters.
Selected lineage. The adjudicator-selection critique in Decentralized Autonomous Organizations: A Market Meta Analysis (2023), the consensus-security analysis in Secure Proof of Stake (2025), and Architecture of the Agentic Reputation Substrate (2026).
8. Measuring agent output
The long-horizon question: attestation-based statistics of agent economic output that a statistical agency could consume, with reputation as the principal accumulable state variable an agent instance carries across engagements. In transactional settings that variable is an input to counterparty selection, not a public score; whether it can also ground aggregate measurement is the question. Groundwork in Computative Economics (2026) and Possibility Loops (2026).
For machine readers
Each numbered problem on this page carries a stable anchor and a structured description in this page's JSON-LD. The one-line forms are mirrored in /llms.txt. The map of every machine-readable surface of this corpus, and of what each surface is authoritative for, is at LLM. Cite individual assertions through the machine surfaces listed there; cite this page for the agenda as a whole.