When AI Caught Up to DCF

Futuristic scene with a central ornate pillar, a robot at a desk inside a glass enclosure, and the headline 'Same Foundation New Pillar'.- the image communicates a tech-themed message about foundational change.

DCF launched, pointing at the Agoric and Cosmos ecosystems, doing what foundations do: grants, validator staking, governance participation, etc. The delegation round staked treasury with validators, aiming to strengthen the set and spread voting power more evenly across it. The language back then was Web3, the whole vocabulary of it, data security, scalability, privacy, and the downsides of centralized platforms. Standard for the moment, and honest about where the money came from, an endowment seeded by Agoric in BLD.

Our homepage now reads slightly differently, and it’s still evolving. Secure execution for smart contracts, distributed protocols, and autonomous AI agents, with AI safety resting on the same foundation as the blockchain work: systems where authority is granted, not assumed, and humans stay in command of what their software can do. That’s a shift in what the foundation says out loud, and it’s worth being honest about the shift rather than pretending the 2022 copy always read this way. The words changed. Something underneath them did not.

The mission didn’t actually change. What added a foundational pillar and are heavily focused on it.

The object-capability model DCF has backed from the start is decades old as research. An agent begins with zero authority, receives only what it’s explicitly handed, and can’t name or forge access to anything outside that scope. There’s a mathematical spine to it, authority carried by unforgeable references instead of ambient identity, which sounds abstract until you notice what it rules out.

You can’t misconfigure a permission you were never given. There’s nothing there to set wrong. For a long stretch, this was the kind of idea you’d find in a paper, or a niche runtime, or a security researcher’s slide deck. Correct, interesting, not yet load-bearing for much that anyone actually used day to day. That said, it has always been one of Agoric’s foundational technologies, thanks to Chief Scientist Mark S. Miller and his decades-long focus on system security and safety.

Then AI agents arrived and started running with the developer’s full permissions. Filesystem, shell, credentials sitting in ~/.ssh and ~/.aws, the network for exfiltration, git hooks for persistence. The same ambient-authority problem the capability people had been describing for years, except now it was sitting inside tools developers reach for every day, and the numbers turned ugly fast.

Prompt injection succeeding up to 84% against unprotected editors. The IDEsaster research finding every AI IDE it tested vulnerable to injection-to-tool-abuse chains. OWASP putting the whole class at the top of its December list for agentic applications. The research stopped being research around then. The threat model showed up in production, with a body count of proof-of-concept exploits behind it.

So the pivot isn’t DCF chasing a trend. It’s the trend arriving at work the foundation was already funding.

You can see it clearest in what carried over unchanged. Endo is the same secure-JavaScript platform it always was, SES underneath, compartments and hardened globals, built to run untrusted code without letting it escape its box. A few years ago that got described as supply-chain and prototype-attack defense, the concern being a malicious dependency buried somewhere in your node_modules. It’s the same code now, doing confinement for an AI coding agent, because the underlying problem turned out to be one problem wearing two faces. Untrusted code is untrusted code whether a compromised dependency wrote it or a language model did. The confinement layer doesn’t need to know which. It was never going to trust either.

That’s the tell that this is one foundation and not a foundation that changed its mind. The blockchain framing and the AI-safety framing are two views of a single idea. Coordination without a central party you’re forced to trust on the one hand. Software that acts on your behalf without holding authority you never granted it on the other. Both come down to the same rule, that authority is something handed out on purpose and not something the system assumes for you. A blockchain removes the assumption that you trust the operator in the middle. A confined agent removes the assumption that you trust the code running on your machine. Same word doing the work in both places, assumed, and the same answer to it.

Most foundations would need a rebrand to tell a story like this. New logo, new deck, a careful note about how the strategy has evolved. DCF gets to say it was already the story. The isolation work it backed when the language was still Web3 is the same work that matters now that the language is AI safety, and the words on the site moved because the world moved into them.

Not a pivot to AI, then. A decade of isolation work that was early, right up until it wasn’t.

For more information about Endo and object capabilities, visit GitHub.

If you arrived here without knowing much about DCF, check out our About page.

Related Posts

Over the weekend of May 31, 2026, hackers breached a series of high-profile Instagram accounts in a way that surprised

The moment you authorize an AI agent, you’re making a bet. A bet that the model won’t be fooled. That

We are excited to share that the DCF has received a Foresight Institute Grant to support the next stage of