Hook
Over the past 90 days, Coinbase engineers have pushed over 95% of their code changes through an AI-powered pipeline. That’s not a prediction—it’s a statistic CEO Brian Armstrong shared during a private roundtable with investors. And in the same breath, he argued that AI doesn’t need a new regulatory framework. The existing laws, he claimed—like UDAP (Unfair, Deceptive, or Abusive Acts or Practices)—are sufficient to police the behavior of autonomous agents.
This creates a paradox I can’t ignore. Here is a company that has effectively outsourced its core engineering function to an algorithm, simultaneously insisting that the same algorithm should not be subject to any specialized oversight. It’s the crypto industry’s oldest tension: code is law, but people are the protocol. And now we’re letting machines write the code, while refusing to write new guardrails for the machines.
This isn’t just a Coinbase problem. It’s a mirror reflecting the entire crypto ecosystem’s deepening dependency on generative AI, and its reflexive allergy to any hint of regulation—even when that regulation might protect the very communities we claim to serve.
Context
To understand why Armstrong’s position matters, we have to trace the historical relationship between crypto and regulation. From the ICO chaos of 2017 through DeFi Summer’s explosive growth, the industry’s founding narrative has been one of escape from centralized oversight. We built trustless systems precisely because we didn’t trust the legacy regulators. Every smart contract audit, every DAO governance proposal, every liquidity pool was a tacit declaration: we can self-govern better than any government.
But AI introduces a new variable. Unlike a human developer who can explain their logic in a courtroom, an AI model that generates 50,000 lines of Solidity code in a single session offers no such transparency. Its decision-making is a black box. And yet the industry—led by figures like Armstrong—argues that the existing legal framework, built for a world of human actors, is perfectly adequate to hold an autonomous system accountable.
Let’s be precise about what’s at stake. DeepMind CEO Demis Hassabis recently called for a new regulatory agency modeled on the Financial Industry Regulatory Authority (FINRA) to oversee AI development. OpenAI’s Sam Altman has echoed similar sentiments, albeit with more caveats. Both recognize that the speed of AI evolution outstrips the reactive capacity of current statutes. Armstrong, in sharp contrast, insists that we don’t need a new agency—just better enforcement of the old laws.
I find this position intellectually inconsistent. The same crypto leaders who champion decentralization precisely because existing financial regulators are too slow, too captured, or too inept to handle digital assets now suddenly argue that those same regulators are perfectly equipped to oversee AI—a technology that operates at machine speed and with automated agency. We can’t have it both ways.
Core: Tech Analysis + Values Conflict
Let me ground this in technical reality. During my tenure as an open-source evangelist, I had the privilege of auditing codebases that were partially AI-generated. The first project, a lending protocol that claimed 60% of its smart contracts were written by an LLM, had a critical vulnerability hidden in a token transfer function. The AI had correctly implemented the ERC-20 standard but had failed to account for a reentrancy guard in a low-level call. A human auditor caught it—but only because we had a dedicated security review. The point is: AI is excellent at pattern replication, but it has zero understanding of the underlying economic logic of a DeFi system.
Now imagine a scenario where 95% of Coinbase’s code—including portions of its order-matching engine, its wallet generation logic, its chain reorganization handling—is AI-written. Armstrong assures us that “sensitive areas like cryptography” are still human-reviewed. But what about the other 90% of the surface area? What about the front-end logic that decides what transaction data to display? Or the API that feeds data to institutional clients? Each line carries the risk of an emergent, non-obvious failure.
Armstrong’s reliance on UDAP is particularly telling. UDAP was designed to prosecute fraudulent behavior by businesses. It can fine a company that deliberately misleads customers. But if an AI agent, trained on biased data, inadvertently fails to execute a trade during a flash crash—is that an unfair act? The legal theory is untested. And while we wait for courts to catch up, users are exposed.
This is where my values framework kicks in. As an ENFJ and a blockchain evangelist, I believe technology exists to empower communities, not to serve corporate efficiency at their expense. When Coinbase proudly announces its AI-driven cost reductions—after laying off 14% of its workforce—the beneficiary is primarily the shareholder, not the user. The user still pays the same trading fees. The user still bears the risk of AI errors. But the user has no seat at the table when those safety decisions are made.
“Code is law, but people are the protocol.” I wrote that phrase in 2022, during the depths of the bear market, when numerous smart contract exploits had shattered trust. I meant it then, and I mean it now: no matter how elegant the technical architecture, the ultimate arbiter of a system’s safety is the community that governs it. And governance isn’t about voting on proposals once a quarter; it’s about the constant, active surveillance of the code that runs your life.
Armstrong’s refusal to support a dedicated AI regulator isn’t just a policy preference. It’s a signal that he believes technology is self-validating. That if the code runs, it must be good. That the market will punish bad AI, so we don’t need government intervention. But we know from crypto’s own history that markets are terrible at punishing bad code until after the damage is done. We didn’t need a new regulator for smart contracts—until we lost $8 billion in hacks. By then, the damage was irreversible.
Contrarian: The Pragmatist’s Test
Now, let me play devil’s advocate. Am I being too alarmist? Perhaps.
There is a coherent argument that existing anti-fraud laws, like UDAP, and common law negligence should be sufficient to handle AI-caused harm. After all, if a company uses an AI tool and it causes injury, the company is still liable. The legal principle of respondeat superior—let the master answer—traditionally holds an employer responsible for an employee’s actions. If AI is an employee, then Coinbase is liable. No new law needed.
Moreover, Armstrong might argue—correctly—that creating a new AI regulator now, while the technology is still evolving, risks codifying premature rules that stifle innovation. Crypto itself was nearly killed in the U.S. by the SEC’s enforcement-first approach. A similar fate could befall AI development if we lock in a rigid framework.
I respect that argument. I lived through the 2022 bear market where overregulation drove talent and capital offshore. I’ve seen how the best-intentioned rules can strangle a nascent ecosystem. But there’s a difference: smart contracts execute exactly as programmed, no deviation. AI models—especially large language models and generative autonomous agents—exhibit emergent behaviors that their creators cannot predict. The attack surface is not just code; it’s training data, inference bias, and model drift.
Consider this: if an AI agent deployed by a DAO hacks a bridge because it learned from a corrupt dataset, who is liable? The developer who wrote the agent’s prompt? The DAO that voted to deploy it? The token holder who staked into the DAO? Current law has no clean answer. UDAP won’t help. A specialized agency, however, could establish a liability framework specific to autonomous systems—for example, requiring that all AI agents on-chain have a registered “responsible human” akin to a registered crypto custodian.
— Root: The 2022 Bear Market taught me that when trust breaks, recovery takes years. Governance isn’t about voting; it’s about preserving the social contract. Without a clear accountability framework for AI, that contract is broken before it’s signed.
Takeaway: A Vision Forward
So where do we go from here?
I am not calling for a ban on AI-generated code. I’m not siding with regulators who want to freeze innovation. But I am calling for the crypto community—my community—to grow up. We cannot simultaneously be the industry that demands radical transparency in every transaction and be the same industry that asks users to blindly trust the outputs of a black-box AI that we ourselves refuse to have regulated.
Armstrong’s position is understandable from a corporate strategic perspective. But it is not sustainable from a values perspective. The crypto ethos was built on the idea that trust is earned, not assumed. Trust in AI should be earned through auditable behavior, transparent governance, and—yes—accountable regulatory frameworks that evolve with the technology.
I propose a middle path: instead of opposing any new regulation, let’s advocate for AI regulatory frameworks that are as decentralized as the systems they oversee. A self-regulatory organization (SRO) for AI, as Hassabis suggested, but governed by protocol communities, not corporate lobbyists. An SRO that requires on-chain transparency for all AI agents that control above a threshold of total value locked. An SRO that mandates periodic adversarial audits—the AI equivalent of smart contract audits—before any agent can be deployed on eternal public infrastructure.
We have the technical capability to build this. We have the governance tools. What we lack is the will.
The next time a CEO tells you that AI doesn’t need a new regulator, ask them: if your AI writes a bug that drains a liquidity pool, will you personally guarantee every user’s loss? If they say yes, maybe follow their lead. If they say no—as most will—then we need a system that doesn’t rely on charity.
— Root: DeFi Summer showed me that when incentives align, communities can self-regulate better than any government. It’s time we apply that same lesson to AI. Code is law, but people are the protocol—and people must own the machines, not the other way around.