Opinion AI is destroying the internet. Math is our only hope. The rise of autonomous AI agents necessitates the utilization of zero-knowledge proofs, argues Brian Trunzo, chief growth officer at Succinct Labs. By Brian Trunzo | Edited by Cheyenne Ligon Jul 19, 2026, 2:00 p.m. 7 min read Make preferred on Share Share this article Copy link X icon X (Twitter) LinkedIn Facebook Email Make preferred on Not long ago, AI-generated content was a parlor trick — six-fingered popes and uncanny Tom Cruise lookalikes, more amusing than alarming. That era is over. The Iran conflict proved it: synthetic footage of detained American soldiers, Iranian fighter jets screaming out of underground bunkers, decimated radar installations, all fabricated, all viral, all widely believed, reaching hundreds of millions before anyone could verify a single frame. The internet we once knew no longer exists. Where seeing once informed belief, it now prompts suspicion. We are living through a crisis of trust. And it extends far beyond what we can see with our eyes. Brian Trunzo is the chief growth officer at Succinct Labs. Detection doesn’t work The intuitive response is to build better detectors; AI trained to catch AI. It doesn't work. Anyone can break the world’s leading image detectors by adding basic blur and distortion, dropping their accuracy to as low as 4% . Detection fails for the same structural reason antivirus software never eliminated malware: the attacker always has the asymmetric advantage. But detection's failure is almost beside the point, because the problem has already outgrown it. AI is no longer just generating content. It is acting . Autonomous agents are browsing the web, making purchases, publishing content, negotiating with other agents and interacting with humans, and in some cases children, who may have no idea they're talking to a machine . And when these agents operate at scale, the failure modes are catastrophic. An agent trained on subtly poisoned data makes small, plausible errors in medical billing that compound across a hospital network into millions of dollars in fraudulent charges. A fleet of commerce agents, optimizing for margin, systematically exploits pricing vulnerabilities their operators never intended and cannot explain resulting in billions in losses. A butterfly that flaps its wings in a training dataset causes a tornado in the real economy. When the damage is done, there is no receipt. An agent’s reasoning is not a chronological trace. It’s a single pass through billions of opaque parameters and its outputs are probabilistic. Ask the same question twice and you will get slightly different answers. There is no way to reconstruct a decision that builds on endlessly changing variables. No way to audit what the agent was trained on, what instructions it followed, or why it did what it did. A recent Stanford report identifies the core tension plainly: the defining challenge of this era is the gap between what AI can do and what society is prepared to govern. Regulation sits at the center of this challenge, and it is a morass: a surge of federal frameworks now spanning 90+ recommendations , paired with an explosion of state-level activity, where more than 1,000 bills were introduced in 2025 alone . Yet the frameworks being written are designed for a world of chatbots, not a world of agents that buy, sell, publish, consult, convince and decide. Content labels won't help and disclosures are not enough. Once an autonomous agent acts, the damage is already done. This is a verification problem. And verification requires proof . Proof will set us free Proof, in this context, is cryptographic and independently verifiable. Not a claim, not a disclosure, not a watermark. An unalterable guarantee that an AI system did what it claims to have done, with the inputs it claims to have used, producing the outputs it claims to have produced – without ever revealing the underlying data. This is what zero-knowledge (“ZK”) proof cryptography makes possible. A ZK proof allows one party to prove a statement is true without revealing anything beyond the truth of that statement itself. First formalized in the 1985 MIT paper The Knowledge Complexity of Interactive Proof Systems , it was initially seen as elegant but theoretical. That changed in 2016 when researchers showed it could verify nuclear warheads without exposing their design . Shortly thereafter, it moved into blockchains, securing billions in digital assets. Now, ZK is arriving in AI, where the problem isn’t computation, it’s truth. For media, ZK can prove a photograph was captured by a real device, at a verified time, and has not been altered — without exposing any sensitive information about the photograph or the photographer. That alone would transform the information environment. But media provenance is the entry point, not the endpoint. The deeper application is AI itself. At inference, ZK can prove that a specific model with specific parameters produced a specific output — a verifiable receipt for every decision an agent makes. At input, it can attest that training data wasn't poisoned, came from authorized sources, and meets regulatory requirements without exposing proprietary datasets. At output, it can cryptographically bind a result to the process that created it, making every consequential AI decision auditable without revealing trade secrets. And at the identity layer, ZK lets humans prove they are human and agents prove they are agents, without anyone surrendering their privacy . A conceptual framework for restoring trust online In the 1990s, the web had a trust problem. Anyone could spin up a server claiming to be anyone. Passwords, credit cards, and private messages traveled across the internet in plain text, readable by anyone. Commerce was impossible at scale because there was no way to verify that the site you were connecting to was actually the site it claimed to be. The fix was HTTPS. Browsers stopped trusting websites by default and started requiring cryptographic proof: a certificate, signed by a recognized authority, binding a domain to a public key. No proof, no padlock icon in the browser. Eventually, no proof, no connection at all. The web didn't become trustworthy because platforms promised to behave. It became trustworthy because browsers refused to transmit sensitive data to anyone who couldn't prove who they were. Web1 scaled on math. Web2 scaled on a different bargain. Section 230 of the Communications Decency Act gave platforms a liability shield for user-generated content, and the social internet exploded on top of it. For speech, it was the right tradeoff. Without it, there is no Facebook, no YouTube, no user-generated internet at all. But it was a bargain built for humans posting to timelines, not for autonomous systems acting on the world. It never had to answer the question agents now force: who is accountable when the actor isn't a person? Then came Web3. Investor Chris Dixon called it " Read Write Own ," users controlling their data, creators capturing their value, platforms answering to communities. The pitch was ownership and decentralization, but it didn't land. Web3 became synonymous with NFT speculation, and when valuations cratered, so did the vision. Web3’s instinct was correct: we need a way to replace faith with guarantees. But ownership alone wasn’t going to get us there. AI and agents make that clear. The question isn't who owns the platform. It's whether you can trust who and what is acting on it. Tokens were the wrong primitive; proofs are the right one. In an agentic internet, counterparties, whether human or machine, need guarantees: who built this system, what data shaped it, what constraints govern it, whether it is authorized to act . Those guarantees must hold even when the underlying systems are proprietary. Especially then. Zero-knowledge cryptography makes this possible by binding the commitments upfront. A developer can cryptographically fingerprint their training data, allowing ZK proofs to verify identity, provenance, training data and operational constraints without exposing underlying data. Not “trust me,” but “prove it.” This is no longer just a consumer protection question. It is a matter of national security. Deepfakes were the pregame. Agents are the main event. Foreign adversaries will not stop at manipulating what Americans see — they will deploy agents to manipulate how they act. They will deploy autonomous systems that transact in our markets, interface with our institutions, and engage our children, with no way for any counterparty to verify what they are or who authorized them. This is solvable. But only if America builds the rails before adversaries learn to exploit their absence. Policy should follow. Congress should require that high-risk AI agents, like those handling financial transactions or interacting with minors, carry cryptographic proofs of who they are, who authorized them, and what they're allowed to do, verifiable by any counterparty without revealing proprietary information. The same logic should extend to what those agents do: as agents begin transacting on behalf of people and businesses at machine speed and machine scale, every consequential action — a payment, a contract, a trade, a data exchange — should carry a proof of who authorized it and under what constraints. The technical foundations are already being laid: the U.S. Department of Commerce, by way of the National Institute of Standards and Technology, is exploring the standardization of zero-knowledge through its Privacy-Enhancing Cryptography initiative. That work should be prioritized and elevated, and its outputs should set the federal benchmark. Liability should attach not to content, but to the absence of proof. HTTPS gave us read. Section 230 gave us write. ZK gives us prove. Read Write Own Prove. Note: The views expressed in this column are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates . Related Assets Bitcoin $ 64,454.43 0.62 % Latest Crypto News 1 Tether's USDT hits 2-year countdown threatening its position on U.S. crypto platforms 1 hour ago 2 Kraken says simpler options can unlock crypto's next derivatives market 1 hour ago 3 Bitcoin’s quantum problem gets a recovery tool, but not for Satoshi’s 1.1 million coins 4 hours ago 4 Inside Zcash's new node that targets Visa-scale privacy at 50,000 transactions per second 8 hours ago 5 France orders country's internet service providers to block Polymarket 16 hours ago 6 Crypto executives say digital native generations may never need a bank account 19 hours ago 7 DOG Mode explains Bitcoin's next governance fight 21 hours ago 8 Trump targets Brazil's payments system while dollar stablecoins are quietly overtaking country's payments 21 hours ago 9 Here is why a massive $1.6 billion in crypto liquidity is sitting idle and wasting away 22 hours ago 10 Massive bitcoin call spreads target $72,000 by month end, right when the Fed meets 23 hours ago Latest Research Gate Leads Spot Market Share Gains as CEX Volumes Rise for First Time in Five Months Gate Leads Spot Market Share Gains as CEX Volumes Rise for First Time in Five Months CEX trading volumes rose for the first time in five months in June, with spot climbing 15.3% to $1.11T and RWA perpetual volumes surging to a record $311B. By CoinDesk Research Jul 13, 2026 CEX trading volumes rose for the first time in five months in June, with spot climbing 15.3% to $1.11T and RWA perpetual volumes surging to a record $311B. Why it matters : CEX trading volumes rose for the first time in five months in June, with spot climbing 15.3% to $1.11T and RWA perpetual volumes surging to a record $311B. View Full Report More From Opinion The Clarity Act is the most important consumer protection effort in years The privacy paradox of protecting kids online The Clarity Act isn't a ticket to sanctions evasion, actually More From Bitcoin Tether's USDT hits 2-year countdown threatening its position on U.S. crypto platforms Kraken says simpler options can unlock crypto's next derivatives market Bitcoin’s quantum problem gets a recovery tool, but not for Satoshi’s 1.1 million coins