We saw how chaotically things unfolded on Twitter over the weekend, ft. AI CEOs.
Dario Amodei, who runs Anthropic, said that the companies building the most powerful AI models should deliberately slow down. After a few hours, Sam Altman, Elon Musk and Demis Hassabis had broadly lined up behind the idea. This bothered me only because Elon Musk agreeing with this particular gang is an event on its own.
Essentially, the people pushing AI forward the fastest were now suggesting that perhaps everyone should slow down. Including, presumably, themselves?
Donald Trump was not convinced. Speaking in Ireland, he downplayed the warnings and returned to the geopolitical argument that has followed every attempt to regulate AI in America.
China is not going to stop, so why should the United States? His administration’s position remains that losing the AI race would be worse than moving too quickly.
Amodei is worried about models becoming capable faster than humans can understand or control them. OpenAI has already temporarily slowed parts of its own training while strengthening safeguards around models it now considers capable of serious cyber work. The company’s chief scientist, Jakub Pachocki, wrote last week that he expects AI systems to increasingly contribute to their own development and called the situation one requiring “extreme caution.”
The internet and I naturally arrived at the more entertaining possibility that all these people had seen something terrible and were politely trying not to tell us.
Maybe. But can AI end the human race? No one has a non-diplomatic answer, and we have no precedent to support either view.
As of now, we know AI agents are getting access to things.
Gmail, GitHub, Slack, calendars, company databases, cloud servers, social accounts, payment methods, CRMs, the ability to generate media, buy software, and publish content that other people can see.
So now, when you ask what this model is allowed to do, that becomes one of the larger infrastructure markets created by agents. The industry has been improving intelligence. Now companies have to build the layer around intelligence that decides where it is allowed to go.
So, this is the best monday to talk about Aident, one of the companies making that bet.
Not the possible apocalypse, we probably can’t stop that. But I have been testing a small version of the problem with Aident Loadout, which gives an AI agent access to outside tools while putting credentials, approvals, spending controls and an audit trail around what it does. Let’s see what it tells us about the broader AI permission problem and how the Aident Loadout experiment puts it to the test.
TOKEN2049: One Crypto Stage, Myriad Perspectives
The future of finance is being written, and you are invited!
This year, TOKEN2049 will celebrate the largest crypto and TradFi gathering. People from the largest banks, fund houses, and VCs will share the stage with leaders from top prediction markets, digital asset exchanges, crypto advisories, and blockchains.
TOKEN2049 is your front-row seat to the next financial revolution, shaped by deals, partnerships, and product announcements.
Dare to miss this lineup at your own risk!
Let us spoil you a bit with an exclusive 10% discount coupon!
In 2006, Twitter had a similar headache.
Third-party developers wanted their apps to use Twitter accounts, but the obvious way to make that work was terrible. A user would give another application their Twitter username and password, and that application would hold the credentials indefinitely.
Blaine Cook, then Twitter’s chief architect, started discussing a better system with people working on OpenID. What emerged in 2007 was OAuth, an open standard for delegated access. Instead of handing a photo-printing website a user’s entire Flickr password, for example, they could give it permission to access the photos it needs. The service got a limited token, and the user kept the master key.
That decision became part of the plumbing of the modern internet. Whenever Google asks whether you want to allow some app to access your calendar, or GitHub asks whether an application may read your repositories, you are living inside the solution to that old problem.
AI agents make this awkward again. OAuth is very good at answering one thing. Does an app have permission to access Gmail? It was designed for a time when apps did one clear, predictable thing. A calendar app had calendar features. A photo printer printed photos. We knew what we wanted out of the software. An agent is different because its useful feature is precisely that you have not programmed every action in advance.
For example, when you tell it to organise a launch, it decides this requires researching competitors, generating images, writing posts, opening X, publishing something, and perhaps updating a spreadsheet afterward. Tomorrow, you ask for something different, and the same agent discovers another set of tools.
So “has access to X” is no longer a sufficient security model.
Should it publish this particular post?
Can it delete one?
Can it message customers?
Can it spend $2 on research without asking? Can it use the same Gmail connection when you switch from Claude to another agent next month?
This is now permission because software is no longer that predictable. Agents are moving into companies faster than the systems controlling them.
Every time a company wants one agent to work across software owned by several different vendors, somebody needs to handle authentication, tools, policy and records of what happened. The more models become interchangeable, the stranger it becomes to rebuild those connections for every new agent.
Okta found that 81% of CISOs and security executives were concerned about AI agents having excessive access, while fewer than half were confident they could identify every agent in their organisation or centrally control what each one could do. Microsoft has responded by extending Entra identity infrastructure to agents, arguing that every agent should have its own identity, scoped permissions and audit trail.
That makes identity and access management a more useful neighbouring market than the entire AI industry. Traditional IAM already handles who can enter which system. Agents need another layer that decides what they can do once inside, like read or write, spend or not spend, delete or ask first.
Aident calls its product Loadout. The easiest way I’ve found to think about it is as a capability and control layer placed between an agent and the software it wants to use.
Aident says Loadout already connects to more than 1,000 apps and gives agents access to 27,000 different actions.
Instead of giving your passwords or API keys directly to the AI agent, you can store them inside Aident Vault. Connect an app once, and you can then use the same connection across tools like Claude Code, Codex, Hermes, ChatGPT, and Cursor.
Aident also keeps a record of what the agent actually did. You can see which action it ran, whether it succeeded, and how much it cost.
But first, let’s clarify what Aident means by “safety.”
Aident does not make an AI model aligned. It cannot guarantee that Claude, Hermes or some future agent will never make a stupid decision. What Aident tries to do is limit what happens after that mistake.
Your credentials can stay hidden from the agent. You can restrict what an app connection is allowed to do. You can also check an action before the agent runs it.
Aident splits agent control into two checks. Spending approval asks only whether the agent may spend money. You can let it auto-spend small amounts, like $10 on research, without asking you each time.
Action approval asks whether it may perform a specific act. That check applies even when the act costs nothing. Sending an email, deleting a file, publishing a post, or changing a customer record can still cause real harm. The two risks are different. Money risk is about the budget. Behaviour risk is about irreversible or high-impact actions. So an agent might spend $5 on its own, yet still need your OK before it emails anyone or deletes anything.
Finally, Aident’s audit trail keeps its own record of what happened. So instead of asking the agent if it has send that email, you can check an independent log to see whether the action actually ran.
So I gave it something ridiculous to do
I connected Aident to Hermes and asked it to create an online pet company.
The eventual brand was Blorb & Co. I wanted ten digital pets, all with specific personality, rendered in 3D. The agent had to research similar products and conversations on X, choose an audience, develop the positioning and
tone, create a logo, posters and campaign copy, animate a couple of characters, give all ten voices, build a quiz and website, and then actually publish an organic campaign.
Through Aident, Hermes used research tools such as Exa and SerpAPI and generated the characters and creative assets through Fal.
Then it produced voice lines through ElevenLabs, made two animated clips, created trading cards, and built a small meme system that was so stupid, but maybe it can be fixed with a bit more cleaning. I eventually connected my X account, and the agent published six posts.
Later I connected to Vercel and it deployed the interactive pet site.
The whole experiment cost roughly $3 in Aident usage.
The agent was not working through a workflow I had designed beforehand.
It searched the available capabilities, inspected what a tool expected, checked prices and then used the tool. When RedFoxHub’s X search broke, it moved to SerpAPI instead. The route changed while the work was happening.
A few things broke during the experiment. The text-to-speech tool expected a different input than the agent was sending and later ran into rate limits.
Vercel was the biggest headache. File uploads did not work properly, and some deployments looked successful even though the files were missing. I eventually got around this by putting the entire website into a single HTML file.
OAuth also required me to manually approve account access. That is actually a good security feature, although it was not always obvious what I needed to approve or where.
A permission layer can make outside software available to an agent, but it still inherits the unreliability, schemas, rate limits and strange decisions of all that outside software.
Aident’s product looked to me as an attempt to put one controlled surface over a very messy internet.
Btw, figure out which pet you are ( I am Nugget) -
The next question is how Aident makes money if much of what it connects to belongs to somebody else. Its current model gives us a rough answer. Loadout supports pay-as-you-go usage, paid Pro and Team plans, and additional credit purchases. For some built-in services, Aident supplies the underlying provider access and deducts the cost from a user’s Aident balance.
For other applications, you connect your own provider account or API key, in which case that provider can bill you directly.
That creates two businesses sitting on top of each other. The first resembles a software marketplace. Aident aggregates demand, buys or routes access to outside capabilities and gets paid as those capabilities are consumed. More agents doing more work should mean more transactions. This is the obvious revenue line, and it is the one I experienced while watching a few cents disappear every time Hermes generated something or ran a search.
But I would not want that to be the whole company. If Aident’s value were simply adding a margin to somebody else’s API, a customer making ten million calls would eventually work out that it can negotiate directly with the provider. Aident itself already supports BYOK, where users bring their own provider credentials and Aident’s deduction for the external action can fall to zero.
That business is the control plane. A company may happily bring its own OpenAI account, Salesforce contract, GitHub organisation and cloud bill while still paying Aident to decide which agents can reach them, store the credentials, apply approval rules, enforce spending policy, maintain the integrations and keep an audit record. At enterprise scale, governance and security can become the thing being sold rather than the underlying API call. Aident’s public pricing already points in this direction with paid plans and an enterprise tier around security, governance and customised deployment.
That is probably the healthier economics if Aident succeeds. Marketplace revenue grows with the amount of work agents perform. Subscription and enterprise revenue grow as Aident becomes more important to the organisation. One monetises traffic. The other monetises trust.
Aident is early to an opportunity that other companies have clearly noticed too. Composio helps AI agents connect to apps like Gmail, Slack and GitHub without developers having to build every connection from scratch. It supports more than 1,500 apps and is especially useful for companies building AI products for lots of users because each user can keep their own accounts and permissions separate.
Arcade is more focused on big companies. It lets businesses control exactly what an AI agent is allowed to do, keeps login details away from the agent and records every action. Those records can also plug into the company’s existing security systems.
Zapier is the giant in this market. Its MCP product lets AI assistants use more than 9,000 apps and 40,000 actions. Zapier says users have already created more than 450,000 MCP servers and made 18.5 million tool calls through them.
Zapier already owns a gigantic map of how business software talks to other business software.
The distinction is becoming smaller as Zapier moves deeper into agents, so saying that Zapier only runs fixed workflows would now be unfair. But its historical centre of gravity is still automation. Someone knows the workflow, connects step A to B to C, and wants it repeated reliably.
Aident starts from a slightly different assumption. The agent may not know which tool it needs until it starts the job. It discovers capabilities while working, inspects the current schema, preflights an exact action, checks the cost and then executes it. The wedge is making tool access, spending, and permissions feel native to an agent that decides its route as it goes. Even Aident’s own comparison concedes that Zapier remains difficult to beat for repeatable business workflows.
That also tells you who Aident is for right now.
If you want Gmail to copy every attachment into Drive, this is probably unnecessary. Zapier is excellent at those things, which is an underrated quality in infrastructure.
Aident becomes more interesting for developers building agents, teams using several different agent clients, and companies where agents are expected to move between research, communication, coding, media and outside APIs without a human rebuilding the integration every time.
I would say that the AI model itself may turn out to be the most replaceable part of an agent stack. A company might use Claude for one team today, move a workflow to ChatGPT next month, give developers Cursor or Codex, and switch again when a better model shows up a few months later.
Since the models are improving so quickly, committing too deeply to one of them may not make much sense.
Once agents start doing real work, companies still have to decide where the line is. Maybe an agent can draft a customer email but not send it. And if something goes wrong, someone needs to know exactly what it did.
Those decisions are just company rules, like the ones normal employees follow, but now software has to understand and follow them. Access and spending rules are currently fragmented across disconnected consoles, tokens, cards, and manual offboarding checklists.
As the market matures, the permission layer becomes an enforceable job description defining what an agent can see, spend, alter, publish, and escalate.
That is why I think Aident is sitting in an unusually good pocket of opportunity, even if the company itself is still early and parts of the infrastructure were rough in our test. Governments will probably spend years arguing over how powerful the models themselves should be allowed to become.
If agents become normal parts of how companies operate, that rulebook has to live somewhere outside the model itself. Which makes the opportunity slightly different from the race to build the smartest agent. The valuable position may be owning the layer a company trusts enough to let all of those agents through.
Token Dispatch is a daily crypto newsletter handpicked and crafted with love by human bots. If you want to reach out to 170,000+ subscriber community of the Token Dispatch, you can explore the partnership opportunities with us 🙌
📩 Fill out this form to submit your details and book a meeting with us directly.
Disclaimer: This newsletter contains analysis and opinions of the author. Content is for informational purposes only, not financial advice. Trading crypto involves substantial risk - your capital is at risk. Do your own research.











