A review published in Blockchain examines trust in both directions between AI agents and blockchain networks. It brings together 127 academic papers, 70 Ethereum proposals and standards, and 20 industry projects in a common framework. The analysis identifies unfinished standards and security questions that need attention as agents take on more autonomous roles.
Artificial intelligence (AI) agents can act on instructions rather than wait for a person to approve every step. When those actions involve blockchain accounts or assets, the system needs clear limits on what an agent may do. A second trust problem arises when AI helps audit or operate the network itself. A review published in Blockchain examines both problems through a bidirectional trust framework.
The study connects work that is often discussed separately: blockchain as infrastructure for agents, and agents as participants in blockchain systems. It reviews 127 academic papers and 20 representative industry projects, alongside a catalog of 70 Ethereum Improvement Proposals and Ethereum Request for Comments standards. This shared structure makes it possible to compare the safeguards available for different agent roles.
The blockchain-to-agent direction, B→A, follows four parts of an agent's on-chain activity. Identity and account abstraction establish its account; permission and delegation define what it may do. Intent-based execution turns a goal into transactions, while tokenized agent economies support market participation. These mechanisms address different requirements and cannot substitute for one another.
The reverse direction, A→B, concerns AI participation in security auditing, consensus and governance. Consensus is how a blockchain network agrees on its state; governance determines how its rules change. The review distinguishes these roles because checking a proposed software vulnerability requires different safeguards from allowing an agent to influence network decisions.
Both directions share a Trust Foundation based on verifiable computation. Zero-knowledge machine learning uses cryptographic proofs to check computation, while optimistic machine learning relies on challenges and dispute resolution. Trusted execution environments instead depend on protected hardware. The review compares their trust assumptions, computational costs and readiness for deployment, rather than treating them as interchangeable guarantees.
To compare the surveyed work, the authors define an Agent-Blockchain Interaction Model and use five evaluation dimensions. These cover whether behavior can be checked, how much trust must be placed in other parties, what operations a scheme can express, how readily it combines with other components, and its maturity. A separate classification places systems by agent autonomy, trust model and operational direction.
The standards analysis shows that much of the agent-specific infrastructure is not yet stable. At the study's status check on July 18, 2026, only three of the 13 standards directly targeting AI or agents had reached Final status; the remaining ten were Drafts.
Other weaknesses concern the relationship between a user's goal and the actions carried out on-chain. The review finds limited formal analysis of intent-based execution. Research on AI participation in consensus and governance is also fragmented, with no unified security framework that treats AI as a participant at the protocol layer.
The study sets out nine open research problems arising from these findings. They concern issues such as verifying model computation, enforcing delegated permissions, establishing agent identities and coordinating human and AI participation in governance. The framework helps relate these questions to the part of the system in which a security guarantee is needed.
This paper "Toward Web 4.0: bidirectional trust between AI agents and blockchain" was published in Blockchain.
Xia Y, Li C, Li L, Zhang C, Duan L, et al. Toward Web 4.0: bidirectional trust between AI agents and blockchain. Blockchain 2026(2):0008., https://doi.org/10.55092/blockchain20260008.
Blockchain
Systematic review
Not applicable
Toward Web 4.0: bidirectional trust between AI agents and blockchain
22-Sep-2026