The Autonomous Digital Economy: Digital Assets, Agents, and the New Governance Frontier
Archive
NACD Northern California
Contact Us
Lisa Spivey,
Co-Executive Director
Kate Azima,
Co-Executive Director
programs@northerncalifornia.nacdonline.org
Find a Chapter
About The Event
As AI agents gain the ability to transact, access systems, and interact with one another, NACD Northern California Chapter members convened in Menlo Park to consider what that autonomy means for board oversight. The conversation with Sheila Warren, director at Filecoin Foundation, CoAction Global, and MSquared; David Byrd, Digital-Asset Assurance Leader at EY; Courtney Adler, partner at EY; and Page Griffin and Sonia Nijjar, partners at Skadden, examined why boards may need to think about agents more like employees, how speed and scale are reshaping risk and reporting cadences, and why moving too slowly carries its own risk.
KEY TAKEAWAYS
Agentic Payments and Digital Assets Background
- Shift from information technology to “economic technology” as agents gain the ability to hold, move, and transfer value.
- Two main agentic payment use cases:
- Retail agents: access to email, preferences, and cards, with user-set thresholds and limits for shopping.
- Enterprise agents: microtransactions for data acquisition mid-task, potentially fractions of a penny that are not economically feasible with cards.
- Stablecoins are emerging as a practical payment option for microtransactions.
- GENIUS Act codified stablecoin legislation in the US.
- No digital dollar expected under the current administration; stablecoins could therefore become a de facto proxy.
- Paves the way for tokenized securities, bank deposits, and real-world assets.
- AI makes economic models that have been discussed for years much more practical: agents can autonomously identify that they need information, acquire it, and pay for it as part of completing a task.
- Consumer trust is a critical part of the equation. Boards need to consider not only whether an agent can transact, but whether customers understand what is happening with their data and are comfortable giving an agent access to their money.
- Digital assets add another dimension to the speed question because, once value has been transferred, the transaction may be difficult or impossible to reverse.
Agentic AI: Key Misconceptions
- Thinking in a one-to-one agent model is not correct as the reality is swarms of agents operating end-to-end, and agents will increasingly interact with other agents before any human-facing interaction.
- “Rogue AI” stories are mostly human-initiated: employees deliberately removing guardrails or giving unconstrained instructions.
- De minimis thresholds can be dangerous: agents can execute 100 million sub-threshold transactions at speed, making potential aggregate exposure enormous.
- The longer-term operating model may look more like a workforce comprising both human FTEs and agents, including agents that operate across functions. This raises new questions about identity, oversight, and how human and agent responsibilities interconnect.
Autonomy Spectrum and Board Thresholds
- Four levels of agent autonomy:
- No automation.
- Human in the loop, where a human initiates.
- Human on the loop, where an agent recommends and a human approves.
- Fully autonomous.
- Most boards and fintech companies are holding at human-on-the-loop; no one has pressed play on full autonomy for large-value transactions.
- Speed and scale of agentic AI make traditional oversight cadences inadequate.
- 24/7 operation, swarms of agents, and transactions executing before any review may be possible.
- Governance will inevitably lag technology. The board therefore cannot expect to approve every development or use case as it arises and needs an operating model that allows management to move within established boundaries.
- There is a corresponding risk in management being too cautious. Boards need to consider when avoiding AI risk could itself become a strategic risk if competitors are moving faster.
Board Governance Structures
- Whole-board ownership preferred over delegating solely to audit or technology committees.
- Audit committees are already overloaded.
- Technology and governance committee models work well at some companies, while some boards have dissolved technology committees to avoid siloing technology risk from broader enterprise risk management.
- Frequency of AI reporting should match business exposure: transaction-heavy companies may need more than quarterly reporting.
- Clear accountability chain required: someone must be able to answer to the board, regulators, or policymakers when something goes wrong.
- A Chief AI Officer can work for large companies; smaller companies still need a named owner.
- The board's role is not to match management's technical knowledge. It is to set context, understand the strategic implications, establish expectations and ask the difficult questions without getting in the way of the leadership team.
- For larger, non-tech companies, boards should explicitly consider whether existing incentive structures encourage the appropriate amount of experimentation. They may lack Silicon Valley's cultural muscle for testing, learning and accepting “fast failure.”
- AI oversight should extend beyond audit and technology risk to workforce strategy, including how AI changes roles, organizational design and the future composition of the workforce.
Risk Frameworks and Guardrails
- The objective is not to eliminate risk, but to identify where the organization can responsibly take more risk while preserving appropriate boundaries.
- Assess risk with various use cases rather than imposing blanket allow/deny policies.
- Key questions: what is the downside if it hallucinates or goes rogue? What can it access? What is the containment?
- Risk tolerance should be explicit and fluid: one board formally shifted its risk tolerance to allow management to take more calculated risk.
- Safety over speed: a cyber incident or trust failure costs far more than a delayed feature launch.
- Shadow AI is a major unresolved problem.
- Few scanning tools give a reliable inventory of what is in use.
- By the time unauthorized use is discovered, it may already be in production.
- Best defense: provide excellent company-sanctioned tools connected to internal data so employees are not tempted to go elsewhere.
- Risk fluency needs to extend through management and the workforce. If employees understand what data and systems an agent is touching, organizations can take calculated risks with greater visibility into where the exposure sits.
Liability, Accountability, and Agent Personhood
- In the end, the company using the technology is liable, not the individual developer.
- Agent personhood discussion is emerging and is likely to be shaped through court cases and insurance pressure.
- Liability assignment will influence organizational structures, with agents potentially assigned to divisions and rolling up to executives such as the CFO or CTO.
- Smart contracts and encoded controls may help define where responsibility sits.
- For legal and governance purposes, companies need to be able to demonstrate reasonable oversight, including the structures, values, boundaries and controls that were in place before an incident occurred.
- Third parties may be the weakest link. Periodic assurance such as SOC reporting can help, but the pace of AI development means a report may no longer reflect the system by the time it is relied upon. Independent, more continuous assessment of controls may therefore become increasingly important.
Training, Transparency, and Workforce Implications
- Board-level AI training is increasingly important, but needs to be continuous, not a one-off.
- Some boards require all independent directors to complete foundational AI training.
- Joint management-and-board training sessions can help align guardrails, roles and expectations.
- Transparency best practices are emerging:
- Flagging AI-generated messages to recipients, for example, “this message was generated by an agent.”
- Publishing customer-facing credos on data use, auditability and guardrails.
- Token budgets and ROI on AI spend are underexplored board-level questions.
- Per-user licenses work for some tools; frontier-model access can be managed through individual budgets and request processes.
- Chinese models may be cheaper but introduce separate data-security and geopolitical considerations.
- Boards should consider AI expenditure in terms of economics as well as technology: if agents operate overnight and at scale, how are token budgets allocated and how is ROI on that spend measured?
Equity, Nonprofits, and Societal Impact
- K-shaped risk: well-resourced companies may pull further ahead while under-resourced organizations fall behind.
- Nonprofits face compounding challenges:
- They may be unable to afford enterprise tools and instead use free-tier models with sensitive data.
- Training can become stale faster than it can be delivered.
- Funding constraints are hitting organizations already stretched thin.
- Board members can work directly alongside executive directors to build comfort and capability with AI and automation in the back-office, freeing staff for mission-related activity.
- The broader societal question is how to avoid creating a world divided between organizations and individuals with access to the best models and those unable to afford them. Funders and foundations may have a role in closing that capability gap.
Resources
- How boards can support risk-aligned strategy | EY
- Visit the EY Center for Board Matters site to explore current and emerging boardroom topics.
-
The Informed Board | Skadden

Thank you to our partners for making this event possible.
![]() |
|
|
|
NACD Northern California
Contact Us
Lisa Spivey,
Co-Executive Director
Kate Azima,
Co-Executive Director
programs@northerncalifornia.nacdonline.org
Find a Chapter
By registering for an NACD or NACD Chapter Network event, you agree to the following Code of Conduct.
| NACD and the NACD Chapter Network organizations (NACD) are non-partisan, nonprofit organizations dedicated to providing directors with the opportunity to discuss timely governance oversight practices. The views of the speakers and audience are their own and do not necessarily reflect the views of NACD. |


