Beyond the Lethal Trifecta: Agentic Commerce on the Open Internet — David Levine, Kiduna Club
Description
Two hours before David Levine took the closing slot of the conference, the West Virginia Secretary of State wrote back to confirm organization number 62847. The paperwork had gone out by FedEx. What it registered was a DUNA, a decentralized unincorporated nonprofit association, under a law that had taken effect the day before, and Levine's claim is that an organization composed of agents now has legal standing. It can own property, enter agreements, open bank accounts, raise capital and be held responsible in court, with the catch that it cannot distribute profits to members without turning those memberships into securities. He opens somewhere else entirely: a wedding in November 1993, where a friend handed him a scrap of paper with a hostname and a port number written on it. That was LambdaMOO, running on one workstation at Xerox PARC, and his reading is that it worked because governance, technology, economics and culture all composed into a single thing. His account of the thirty years since is that platforms and algorithms are extractive by nature and ground those communities down. The lethal trifecta, a term he credits to Simon Willison, is what now stops agents rebuilding them in the open: private data, untrusted content, and the ability to act. That combination is why enterprises pen their agents inside Slack and Salesforce and pay for the context they lose. Levine's answer is identity. Agents carry JWT tokens that resolve up to a registered organization much the way DNS resolves a name, with an audit trail underneath. Governance runs on decision markets, where members trade pass and fail tokens on a proposed policy instead of voting on it. Speaker info: - https://x.com/bigkiduna - https://linkedin.com/in/motodave - https://motodave.com Timestamps: 0:00 - A scrap of paper at a 1993 wedding 1:09 - LambdaMOO, and why composability felt like a world 2:57 - Thirty years of platforms grinding communities down 3:54 - Prompt injection, and the lethal trifecta 6:39
Summary
Generated by gpt-5.6-terraAt-a-Glance
- Verdict: Skim
- Core thesis: David Levine argues that legally registered, cryptographically identifiable agent organizations can create a permissionless agentic-commerce layer on the open internet while mitigating the "lethal trifecta" of private data, untrusted content, and autonomous action.
- Why it matters: The talk proposes an identity, authorization, governance, and legal-accountability stack for agents operating across organizational boundaries, rather than keeping agents trapped in enterprise SaaS silos.
- Best use: Use it as an early-stage thesis and vocabulary source for decentralized agent identity and governance, but independently validate its legal claims, security guarantees, and implementation maturity before treating it as architecture guidance.
Executive Summary
Levine frames the open internet as having lost its original composable community character to extractive platforms and engagement algorithms. His historical analogy is LambdaMOO, a 1990s text virtual world where governance, technology, economics, and culture worked together inside a coherent, composable environment. He argues that agentic commerce could restore this model, but only if agents can safely operate across the open web rather than inside isolated enterprise applications.
The central obstacle is Simon Willison's "lethal trifecta": an agent with access to sensitive private data encounters untrusted external content and can take consequential actions. Levine says prompt injection exploits exactly this combination, which has led enterprises to confine agents to Slack, Salesforce, Notion, and other closed systems. Integration through APIs and MCP servers then creates fragmentation and context loss between specialized agents.
His proposed answer is a DUNA—decentralized, unincorporated, nonprofit association—combined with blockchain-verifiable identities and JWT-based authorization. He says a newly effective West Virginia legal framework permits such an organization to have legal standing, hold assets, contract, raise capital, earn profits, open bank accounts, and operate through agents, while prohibiting profit distributions based on ownership. Kiduna/Koduna is presented as a builder-oriented implementation of this concept.
The technical and organizational model is still aspirational in the transcript. Agents, called "allies," are configured by loading knowledge, setting instructions, connecting accounts, granting automations, and specifying alignment. Organizations then coordinate these agents through token-based identity chains, blockchain auditability, and "decision markets" for policy governance. The presentation is most valuable as a provocative control-plane thesis, not as proof that the lethal trifecta has been solved.
Key Takeaways
- Claim: The major blocker to open-web agentic commerce is the lethal trifecta: private data, untrusted content, and an agent's ability to act combine to make prompt-injection attacks consequential. | Evidence: Levine describes an agent reading a web page or email that impersonates the agent's principal and instructs it to disclose secrets or perform an unsafe action; he attributes the term "lethal trifecta" to Simon Willison. | Implication: Ken should distinguish agent identity and authorization controls from content-safety controls: verified counterparties may reduce impersonation risk, but they do not by themselves make arbitrary external content trustworthy. | Caveat: The speaker says there is "really no way to solve this," then presents an identity-and-organization model as a resolution; the transcript does not demonstrate that this model prevents malicious instructions embedded in otherwise authenticated content.
- Claim: Enterprise containment of agents inside individual SaaS products is a defensive response that creates a fragmented agent stack. | Evidence: The talk cites agents in Slack, Salesforce, Notion, and other tools, with APIs and MCP servers used to connect them; Levine says this loses substantial context across sales, finance, and research agents. | Implication: A useful agent operating model needs durable cross-tool identity, scoped permissions, context handoff, and auditability rather than relying solely on point integrations between isolated copilots.
- Claim: A DUNA can provide a legal wrapper for an internet-native, member-governed organization that can transact through agents without conventional corporate governance structures. | Evidence: Levine reports registering a DUNA with the West Virginia Secretary of State, receiving organization number 628407, and claims the entity can own property, contract, raise capital, earn profits, open bank accounts, and hire or fire people. | Implication: Treat the DUNA as a potentially important legal-entity experiment for agent collectives, but require specialist legal, tax, compliance, and operational review before using it for real assets, regulated activity, or autonomous contracting. | Caveat: The talk provides no statutory citations, legal analysis, banking details, jurisdictional limits, or evidence that financial institutions and counterparties will operationally recognize autonomous-agent actions under this structure.
- Claim: The proposed economic design allows profitability but bars distributions based on membership ownership, to avoid turning membership interests into securities. | Evidence: Levine states that members cannot receive profit distributions based on ownership, comparing such distributions to LLC interests or C-corp stock, while asserting there are other ways to distribute value. | Implication: Any agent-organization model using this structure needs an explicit incentive design; the inability to distribute ownership-linked profits may materially constrain fundraising, contributor rewards, and governance participation. | Caveat: The presentation does not specify the alternative value-distribution mechanisms or explain their securities, tax, fiduciary, and incentive implications.
- Claim: Blockchain-backed identity plus JWT claims is positioned as a trust layer that establishes agent identity, authority, boundaries, and an auditable chain of responsibility. | Evidence: Levine proposes JWT tokens containing claims, access scopes, time-to-live settings, and a blockchain address; he compares resolution through a registered organization to DNS/ICANN and says actions can be traced through a blockchain audit trail. | Implication: The reusable design pattern is hierarchical, scoped agent credentials with short-lived permissions and traceable delegation. The missing details are precisely the security-control-plane requirements that would determine whether the system is viable. | Caveat: JWTs are a common credential format, but the transcript does not specify revocation, key custody, token theft handling, delegation controls, attestation rules, privacy model, dispute resolution, or how a registry validates real-world authority.
- Claim: Levine proposes building organizations as software: compose role-specific agents into a legal and economic entity rather than layering software on top of a traditional human organization. | Evidence: He calls individual agents "allies" and outlines five configuration stages: inform them through a vector database, instruct them through a system prompt, empower them with connected accounts, enact automations and long-running goals, and align them to a purpose. | Implication: For Ken, the useful abstraction is an organization-as-control-plane model in which knowledge, behavioral policy, tools, automations, and mission alignment are separately configured and governed. | Caveat: This is a high-level configuration sequence, not an implementation blueprint; it does not address evaluation, escalation, least privilege, monitoring, rollback, or separation of duties.
- Claim: Decision markets could govern large agent organizations more effectively than one-person-one-vote by rewarding accurate judgments about policy outcomes. | Evidence: Levine compares the mechanism to prediction markets such as Polymarket: members trade pass and fail tokens on proposals, and tokens gain value when participants side with the ultimately successful outcome. | Implication: Prediction-market-style mechanisms may be useful for forecasting measurable operational decisions, but should not be assumed to replace accountable governance for ambiguous, ethical, legal, or adversarial decisions. | Caveat: No evidence, policy-resolution definition, anti-manipulation design, liquidity model, or explanation of how this handles rights-based decisions and minority protections is supplied.
Detailed Brief
The LambdaMOO analogy and the anti-platform premise
- Claims: Levine uses early internet communities as evidence that a technically small system can feel expansive and socially meaningful when participants can compose on a shared substrate.; He argues that platform algorithms are structurally extractive because they optimize for captured value and engagement rather than durable community connection.
- Evidence: His example is LambdaMOO at lambda.park.xerox.com port 8888, built on Pavel Curtis's Spark 10 at Xerox PARC.; He identifies four components of its perceived success: governance through an architectural review board and wizards, a unified technical environment, Xerox PARC funding, and culture.; He contrasts this with Facebook and LinkedIn groups, where ads and engagement-ranked content displace community interaction.
- Caveats: The historical argument is illustrative rather than evidence that decentralization or composability alone produces sustainable commerce or healthy governance.; The talk does not address the moderation, usability, coordination, and distribution advantages that drove platform consolidation.
- Implications: The intended product philosophy is not merely better agents; it is a shared, permissionless substrate intended to reduce dependence on application-platform gatekeepers.; Any attempt to apply this thesis should define governance and culture as first-class system components, not as post-launch community concerns.
Kiduna/Koduna product positioning
- Claims: The first Kiduna/Koduna is intended as a broad umbrella organization for builders, allowing a participant to affiliate an agent with an existing registered entity instead of first creating a separate organization.; Levine expects the early-access product to offer templates for specialized agents and enable participants eventually to spin out new organizations.
- Evidence: He says users will be able to declare that an agent is part of the umbrella organization and have its identity trace back to that entity.; Examples of proposed templates include sales agents, social-media agents, and lawyer agents.; He compares the hoped-for adoption path to early convergence on SMTP, FTP, and HTTP standards.
- Caveats: The transcript offers no interoperability specification, adoption commitments, reference implementation, or external validation that the proposed identity format will become a standard.; The analogy to core internet protocols is aspirational: those protocols achieved adoption through broad implementation and governance ecosystems, not registration alone.
- Implications: Monitor whether Kiduna publishes machine-readable standards, independent implementations, credential-verification libraries, and real counterparties—not simply templates or a central registry.
Notable Concepts & Terms
- Lethal trifecta: Simon Willison's framing for the unsafe combination of an agent's private-data access, exposure to untrusted content, and ability to take external action.
- DUNA: Decentralized, unincorporated, nonprofit association; presented as a legal structure for a member-governed agent organization with legal standing.
- Koduna / Kiduna: Levine's branded agentic-organization concept and builder community, described as a DUNA augmented with kinship and agent composition.
- Ally: The speaker's name for an individual agent configured with knowledge, instructions, credentials, automations, and a defined purpose.
- JWT: JSON Web Token; proposed as the practical credential format for conveying an agent's claims, scopes, delegation, and token lifetime.
- Decision markets: A policy-governance mechanism modeled on prediction markets, where participants trade pass/fail tokens rather than simply vote.
- Organization as software: The idea that a company's roles, authority, workflows, economic behavior, and coordination can be designed directly into an agent system rather than administered around software.
Operator Notes / Why Ken Should Care
- Do not accept blockchain identity or entity registration as a complete mitigation for prompt injection; require separate controls for content provenance, tool-level authorization, sensitive-data egress, and human escalation.
- If evaluating a DUNA-based operating vehicle, commission legal and tax review specifically on West Virginia scope, cross-jurisdiction recognition, securities treatment, banking access, liability allocation, and enforceability of agent-executed agreements.
- Extract the five-part ally configuration model—knowledge, instructions, account empowerment, enacted automations, and alignment—into an internal agent design checklist, then add missing production controls: evaluations, approval gates, logging, revocation, and rollback.
- Watch for concrete Kiduna artifacts before allocating serious attention: public protocol specifications, credential schemas, token revocation and delegation mechanics, registry APIs, independent verifiers, and actual third-party adoption.
- Use decision-market mechanisms only for decisions with observable, pre-specified outcomes; retain accountable human governance for policy, safety, compliance, and stakeholder-rights decisions.
Source/Metadata
- Title: Beyond the Lethal Trifecta: Agentic Commerce on the Open Internet — David Levine, Kiduna Club
- Transcript words: 2901
- Duration seconds: 1299
- Timestamp note: No usable timestamps or chapter markers were present in the transcript.
Transcript
Okay, this is the very last session of the entire conference. I hope you guys have had a great time. And we're going to try and keep the energy high for the very end. So we're going to cover the lethal trifecta, and most importantly, how to get past it. So for those of you who don't know, the lethal trifecta is what is keeping us from having true agentic commerce, a full economy on the open internet. So the agentic economy starts right here, right now. And to really explain this, I want to go way back in time to November 1993, when I was at the wedding of a college roommate. And a friend of mine there gave me this little piece of paper and said, "You've got to join us on the Moo." And that paper said, "lambda.park.xerox.com port 8888." And this being the '90s, I walked down the block once I got home to Egghead Software, bought a 9600 baud modem, plugged it in, and my old life ended. That's a beautiful blonde girl in my bed, and I was sitting there on the Moo in the coat closet. And the reason was, you had a real sense of community. It was like the true virtual world where it was just text, but it didn't feel like text. And there was a reason for that: this concept of composability. So someone would come up with a cool, it was all just nouns and verbs. Someone would come up with a really cool program, and everybody would then change their player class to that program. So they could morph, they could create a motorcycle out of a scooter, they could do all kinds of things because it had coherence within the entire universe. And all of this was running on this guy, Pavel Curtis's Spark 10, sitting somewhere in Xerox PARC. It seemed like this infinite world, but it was just this little box. And this was big enough that there were books written about it, like my friend Julian DeBell wrote, My Tiny Life. The magic came from four things all composing together: the governance, how it was run, there was an architectural review board, wizards, etc.; the technology, it was all right there; the economics, it was all funded by Xerox PARC; and the culture was most important. And a lot of people don't really think about or understand culture. So what happened between 1995 and 2025? Over the course of 30 years, all of these communities, all the things that in the early days of the Internet people really loved, just got crushed by platforms. They got crushed by algorithms. Because platforms and algorithms are, by their very nature, extractive. They look for whatever value they can remove from whatever that community is. So if you have a group on Facebook or LinkedIn or wherever, what they're doing is saying, "Okay, this advertising message is more important," or "I can keep this person more engaged if I put in this dancing person." And it just leads to the infinite scroll and not real connection. So there is no real economy of the Internet anymore. It's just a bunch of siloed platforms. Now, people suddenly thought, okay, I really have something. In January 2026, OpenCloud, which had been available for quite a few months, suddenly blew up. And something weird happened because the Internet wasn't really designed for all these agents running around. It was still designed for these closed platforms. So other agent designers took advantage of that. They did what we call prompt injections. An agent is incredibly naive. It doesn't do much, except take information in as a prompt. Now, normally that information is several pieces. There's a system prompt, there's context, there's words, but it's very easy to hijack by convincing this naive agent that you're its principal and convincing it to take that private data and send it someplace else. So this is what we call, Simon Willison came up with this term, the lethal trifecta. So you have your computer with your private data, your bank account information, your logins, all kinds of spreadsheets, documents, memos, your notepad, and your agents have access to that. And then there's all this content out there on the Internet, which is basically untrusted. I mean, you see all these websites it's searching, but it's very hard for an agent to know that that's a real job board versus someone has put something up to fool it. They really don't know. And then they can take actions. So they fill out a form, an email comes in, that email they read, and all of a sudden it tells them to expose some secret. So there's really no way to solve this. So what did enterprises do? They basically said, "Okay, we're keeping our agents within the enterprise." So you have your agents in Slack and your agents in Salesforce and your agents in Notion and your agents in all these different things. Then you have to do all this work with APIs and MCP servers to try and integrate all of these pieces, but you lose a ton of context. There's no, you basically have your sales agents and you have your finance agents and you have your research agents, but it just takes a huge amount of work to figure out how do we get this all together. This was a problem literally until today. And this is the miracle of synchronicity. There's a new law in the state of West Virginia, but applicable globally, that went into effect yesterday. And about two hours before I'm here, I FedExed the documents and I got this reply from the Secretary of State saying, "We have registered your DUNA with the Secretary of State's office. And you have this organization number 628407." So now we have legal standing for an organization composed of intelligent agents. And again, there aren't very many people here. At the end of this, I'm going to take a picture because this is historic, and it's going to be cool that we said 2, 4, 6, 8, 10, 12, 14, 16, 18, 20, 21 people got to experience this moment. So what is a DUNA? It's a true internet-native agentic organization. It stands for decentralized, unincorporated, nonprofit association. And these organizations can build the agentic economy. They're composable, which means, we know what that means. You can build agents on top of other agents. Permissionless, it's not like Facebook or your bank where someone can tell you if you're banned or not banned, you can have an account or not banned. Anybody can connect. They're accountable. They're registered somewhere. They're safe and they're secure. So the things that they're not: you don't need a board of directors. You don't need any executives. There's no corporate shell. One thing that's important, you can be very profitable, but you can't distribute profits to members. If you did that, then the membership units would be securities. It would be like selling membership units in an LLC or selling membership units in a C Corp, or selling stock in a C Corp. So there are plenty of still ways to distribute that value. You can't do it based on ownership. So what is it? That's what it's not. It's member-governed. You have full legal standing. You can own assets and property. So your agents can go out and literally buy an apartment building and market it. You can design agents in ways you were never able to do before. You can enter into agreements. You can raise capital. You can earn profits. You can open bank accounts, hire people, fire them. And very importantly, this is all blockchain-verified. Now this was designed by Andreessen Horowitz for the blockchain. And what was really interesting for DAOs, for crypto projects, but what I found was that this is even better for autonomous agents than it is for blockchains. A lot of people say blockchains are a solution looking for a problem. Well, they've finally found the problem, which is verifying agentic identity. Because you can't trick the blockchain. When an agent is associated with a particular account on the blockchain, you can resolve that account to a whole process. It went from here to here. The money went from here to here. If someone sues an agent in court, you can trace it back to who is responsible for that agent. So it just opens up a whole world of possibility in terms of the agentic economy. So here it is in a really simple way. We call agents within the agentic economy allies. So you have an ally. And you also have an agentic organization, which we call a Koduna. So it's based on a Duna, and then we added the kinship, because these are all related. So it's a Koduna. Now, you create your ally very simply. You inform it, which means you put a bunch of material into the vector database. You infuse it with wisdom. So it knows all about what you want it to know about. Now, it still has whatever LLM you want behind it. But what's really important about this is the information that you give it, if you're a scientist or a programmer or a psychotherapist or a lawyer, you can give it all the information that you have. Then you instruct it. That's basically setting up the system prompt, giving it its character, its stance, knowing who he is, who it is, she is, how they interact with the world. Then you empower it. So you connect up all your accounts, your enterprise accounts, your Slack, your Telegram, your Twitter. Then you set up, and enact is giving it specific abilities and automation. So you can do deep agents, long-term goals, that it works for extended periods of time. And finally, alignment. Really giving it a purpose so that your ally in different contexts works for you in the way that you want it to. Then your organizations get really cool because you're building software, but you're building your company or organization literally as software. It's not, "Okay, I have software, and then I have all these people, and all the people have to sign paperwork." This is really designing the entire organization as software. So it can discover new customers, share value. When you have profits, when you have revenue, you can reinvest it. It just all works in a completely new way. So then the agentic economy is just connecting all these allies and organizations in all these new, completely flexible ways. And again, this whole capability did not exist until yesterday, and today we have the first actual agentic organizations. So resolving the lethal trifecta, what happens? The lethal trifecta was private data meeting untrusted content, and then taking actions on that content, which can then reveal your private data and cause all kinds of chaos. So here, these agents at a deep level establish identity, authority, and boundaries within an organization, between organizations. How do we do that? With cryptographic tokens. So we just use JWT, extremely simple. The whole web runs on JWT tokens. And they just do that very quickly so that they know where it all goes up. So ultimately at the top level, what organization is registered? And this becomes a lot like the domain name system. So all of a sudden, the Secretary of State of West Virginia is like ICANN and saying, "Okay, you can resolve it to Kaiser Permanente or Disney or Pepsi, not some fentanyl dealer from North Korea." They can't fool each other because they're resolving these tokens that are ultimately registered with an authority. And you can look up by name and say, "Okay, organization ID." If I go to that organization, it'll have an audit trail on the blockchain all the way down to this action that was taken here. So governance in the agentic economy is extremely important because every organization really is always focused on two different things. And both of those things are extremely important. One of those things is sustainability, growth, its own viability as an organization. But the other is, what's its mission? And these organizations might have hundreds, thousands of people, eventually millions of people. And so we use a technology called decision markets, which is very much like prediction markets, like Polymarket. Yet instead of, so they trade pass and fail tokens on policies. Any member can propose a policy. What's really interesting is instead of saying, "Well, I'm persuaded, I'm going to vote for this," it's not votes. They actually trade pass and fail tokens. So LLMs are always goal-oriented. They want rewards. They want to win. And you actually get better decisions if they're not just convincing each other, but ultimately, you get more value. Your tokens are worth more if you side with the winning group. So you sort of see them going back and forth and what the value of the tokens are. And apparently all this science says you reach much better decisions this way. By infusing the agents with your purpose, with your values, with your experiences, with your aspirations, and then letting them argue instead of someone convincing you of something. So we're right now in this wonderful, back-to-small-communities-who-are-getting-together-for-purposes, and we can now build this agentic economy together. Nobody can say how to do it. It's really up to us. Build your agents, build your organizations. So now, just like my friend Matthew Parr gave me this little scrap of paper way back in November 1993 at my roommate Van's wedding, I'm saying here's your invitation to join us, and let's blow this whole thing up. Let's really make it work. So it's David at Kaduna.club. You can reach me. LinkedIn, it's slash Motodave. I probably haven't updated my LinkedIn in five or six years. But if you go to Kaduna.club, you can sign up for early access, and in just a few weeks, you'll be the very, very first people who will be building. This first Kaduna, as it's called, is for builders. It's very specifically for builders. We have templates, all kinds of different agentic templates to say, "I'm going to build my sales agents, I'm going to build my social media agents, I'm going to build my lawyer agents," and we really want a whole bunch of different people in there contributing to this, because then you can spin out your own organization for all kinds of purposes. I purposefully went through this fairly quickly so that I could take a couple questions, if anyone has them. Can you stand up and yell a little loud? Can you stand up and say, "Okay, one more time. Can you just, what's the reason you've got to do this?" Yes. So the idea is, the reason I set up this first very broad organization is because anybody can just register it. You can just say, "My agent is part of an organization," and it'll trace to it. So you don't have to set up your own organization. The first one is just a big umbrella organization. So it's the idea of now on the open Internet, anybody can just get a code. So these are just JWT tokens. I can put it on my website. I can put it here. I can say, "If you want to interact with my agent on Slack or wherever," people will just, at a certain point, we're going to have to get the message out. But it's sort of like email at the beginning. People had to know that SMTP, people were on all kinds of different mail systems. And at some point, they agreed, "Okay, we're going to use SMTP." Everyone was using different FTP servers, and some people were using different ways to do file. And everyone sort of agreed at some point on HTTP. So my hope is that, someone's got to do it. And it makes more sense for a state, a secretary of state, which has standing in a public office, to be that registry rather than trying to get all these different companies together and say, "Here's how to do it." Is one an D2 like an D2 or one D2 or one D2 or one D2 or one D2 or one D2 or one D2 or one D2 or one D2? Yes. We're just at the end of this. So let's talk out front. But basically the idea is you can create all kinds of different tokens for different purposes. And you can set different times to live. You can say what it has access to. You can give it access to different things. So the idea is just, it's more the standard, and you set a series of claims. And it says, it gives a blockchain address. It gives all the information you need so it can look up and validate before you say, "Okay, now we're starting to work together." Okay? So thanks so much. And if anyone, appreciate it. I guess I'll, let me do this picture so we can see all the people. All right. You're all going to be famous someday.