Code Is Not a Defense: Paul Grewal’s Move to Cognition and the Unbuilt Liability Stack for Autonomous Software

CoinCat Editorial

History rhymes, but the code doesn’t. That’s the phrase that keeps orbiting my head as I stare at the news that Paul Grewal, the general counsel who built Coinbase’s legal fortress, is leaving to join Cognition, the AI company behind Devin, the so-called “first AI software engineer.” The mainstream response is predictable: a prominent lawyer leaves a crypto exchange for a higher-profile AI startup. Talk about a pivot. But that’s surface-level. This is not just a talent transfer; it’s a structural signal. It tells me that the AI industry—specifically the sub-sector building autonomous coding agents—has quietly admitted that the binding constraint on growth is no longer model architecture or GPU supply. The binding constraint is legal accountability. And they have decided to put someone on the front lines who knows how to fight the government.

I don’t make that claim without evidence. Let me share some context. Grewal spent over five years at Coinbase, where he built a legal team and a legal strategy that treated the SEC as a rival, not a regulator. He filed a petition in July 2021 demanding formal rulemaking from the SEC on digital securities, effectively forcing the agency to show its hand. When the SEC later sent a Wells notice to Coinbase, Grewal did not cave. He published a response that framed the agency’s approach as “arbitrary and capricious” and used the regulatory process to rally public and political support. That’s the kind of legal aggression that’s rare in the corporate world. Most general counsels are risk-averse. Grewal is risk-tolerant. He’s an adversary. And now he’s bringing that adversary mindset to AI.

Why does that matter? Because AI coding agents are about to enter the most dangerous phase of any technology: the phase where the product can cause damage that is immediate, visible, and costly. A chatbot that gives bad legal advice can be dismissed. An AI that writes and pushes code to a production environment can expose customer data, empty a treasury, or violate a trade embargo. The legal fallout from such an event would make the current round of AI copyright lawsuits look like a parking ticket.

The Coinbase Rulebook: From Litigation to Policy

Let’s zoom out for a second. The crypto industry spent 2020-2024 building a legal and regulatory playbook that turned a decentralized-ish network of protocols into a functioning, if contentious, financial asset class. The central question was always “is a token a security?” The answer was never clear, and the lack of clarity created enormous uncertainty. Yet Coinbase survived, went public, and grew into one of the most important companies in the space. A lot of that survival can be attributed to Grewal’s ability to battle on multiple fronts: SEC enforcement, state regulators, policy advocates, and public relations.

Grewal’s strategy at Coinbase offers a template. In June 2021, when the SEC first approached Coinbase regarding its lending product, Coinbase did not settle. Grewal responded with a public blog post and a petition for rulemaking. The petition was legally significant because, under the Administrative Procedure Act, an agency has a limited time to respond to a rulemaking petition. The SEC eventually denied the petition, but the denial itself created a record that Grewal could use in later litigation. This is a clever tactic: forcing the regulator to articulate a legal rationale, then attacking that rationale as flawed.

In the AI space, Cognition could adopt a similar approach. The regulatory landscape for AI is in flux. The EU AI Act has imposed a set of obligations, but it’s still being implemented. The US has no comprehensive AI law, only executive orders and piecemeal agency actions. A company like Cognition could petition the FTC or the FDA (if it ever touches healthcare) to issue regulations on AI coding agents. It could also lobby for a “safe harbor” for software that is generated by AI, similar to the protection offered to online platforms. But the problem is that safe harbors are usually controversial. Section 230 was meant for speech, not for software behavior.

The “rulebook” insight is that legal strategy is not just about defending in court; it’s about actively creating the court’s jurisdiction. By hiring Grewal, Cognition is making a statement: we will not passively wait for jurisprudence; we will try to influence it. That’s a bold move for a startup. It shows that they have the balance sheet and the ambition to play the long game.

But there’s a catch. Crypto’s legal battles were fought in the open, with a public ledger as a source of truth. In the AI space, the “evidence” is often hidden inside the model’s weights and training data. You can’t subpoena a neural network. You can’t depose a loss function. This lack of transparency will make every legal challenge murkier. A company can hire a thousand lawyers, but if they cannot explain why their model made a specific decision, they cannot mount a defense. This is the “black box” problem that intersects with legal discovery.

Introducing Cognition and Devin

Cognition is a startup founded by Scott Wu, a former competitive programmer, and his team. The company’s mission is to develop AI agents that can not only write code but also reason about software engineering tasks. Devin was announced in March 2024 with a famous demo video showing it creating a website from a prompt. The demo also showed Devin browsing Upwork, bidding and completing a job. The product is impressive, but the legal implications are massive. For instance, if Devin signs up for a freelance job and completes it, who is the contractor? If Devin’s output violates a nondisclosure agreement, who is legally bound? These are not hypothetical questions.

Code Is Not a Defense: Paul Grewal’s Move to Cognition and the Unbuilt Liability Stack for Autonomous Software

In addition, Devin is not just a single model. It’s a system. It uses a large language model as its core, but it has a code editor, a shell, and a web browser. It can plan, debug, and interact with external APIs. This means that its actions are context-dependent. If it interacts with a third-party API that has its own terms of service, Devin might agree to those terms on behalf of its user. Can an AI be bound by a terms-of-service agreement? According to most contract law, no. But if the user authorizes Devin to call that API, the user may be bound. This is the “agency” problem, and it’s a legal minefield.

The market for AI coding agents is expanding at a breakneck pace. According to a report by Menlo Ventures, enterprises are spending over $100 million a year on AI coding tools, and the adoption rate is climbing. GitHub’s Copilot now has over 1.3 million individual subscribers and tens of thousands of enterprise customers. These tools are not just suggesting autocomplete; they are writing entire functions, committing changes, and even creating pull requests. As of 2025, the capability of these models has improved drastically. Some models can solve complex programming challenges that were considered impossible two years ago. Devin, specifically, is marketed as an autonomous engineer that can handle a whole project with minimal human intervention.

But here’s the thing: autonomy brings accountability. If a model merely suggests code and a human reviews it, the human is the responsible party. If a model acts autonomously, the “responsible party” becomes a philosophical and legal black hole. This is the territory where Grewal’s expertise becomes valuable. He understands that in modern regulatory systems, the first company to articulate a clear liability framework often gets to set the standard.

The Autonomy Problem: Defining “Autonomous”

Let’s define terms. When Cognition says Devin is “autonomous,” what does that mean exactly? It means that Devin receives a high-level task and decides on the sequence of steps to complete it. It might create a new file, run a test, and commit a change without asking for permission. That’s autonomy in the engineering sense. But in the legal sense, autonomy is a much higher bar. A self-driving car is “autonomous” only if it can operate without a human in the loop, but even then, it has defined parameters. Devin has no such parameters. It can interact with any API, read any documentation, and make decisions based on its training. The term “agent” is used precisely because it acts on behalf of a principal. But a principal is only liable if the agent acts within the scope of authority. If Devin performs an action that the user did not contemplate, the “scope of authority” becomes unclear.

This is not just a philosophical issue. There are real-world cases. In 2024, a startup called Autocode had an AI agent that was supposed to update some code, but instead it executed a deployment that caused a temporary outage. The company was forced to apologize, but the question of “who is at fault” was never answered because no one sued. When the stakes become higher—say, a hospital’s code that controls a ventilator—the legal precedents will be fluid.

In the crypto space, we already have autonomous agents. The Ethereum DAO hack in 2016 was an autonomous code execution that drained $60 million. The legal response was ultimately a controversial hard fork, because there was no legal remedy. Fast forward to 2026, and we have AI agents that could re-implement a DAO or manage a treasury. The potential for an “AI DAO hack” is enormous, and the legal system is not ready.

The Liability Stack: A New Framework for Code

Let me propose a “liability stack” adapted from the traditional tech stack. At the base, you have infrastructure: cloud providers, hardware, and operating systems. In the middle, you have model providers: OpenAI, Anthropic, and open-source models. At the top, you have agent builders: Cognition, and the users who deploy them. Each layer has a different exposure.

Infrastructure providers like AWS and Microsoft Azure have long had clauses that disclaim liability for customer actions. They’re the “common carriers” of the cloud. They have done a good job of insulating themselves. Model providers have also tried to shield themselves, but their position is weaker. A model might be the “product” that causes the harm, so plaintiffs will try to attach liability there. In the case of coding agents, the model is not the end product; the agent is. So the agent builder (Cognition) is now at the center of the storm.

The common legal strategy is to push liability down to the user through terms of service. I’ve seen this in many AI tools. But there is a legal doctrine that can override contracts: public policy. If a court decides that the use of AI in a high-risk setting is a matter of public safety, it may refuse to enforce an exculpatory clause. This is likely to happen in the software industry if a mass accident occurs. We already saw this in the autonomous vehicle space. Uber’s terms of service did not protect it from a wrongful death lawsuit when an autonomous vehicle (with a safety driver) killed a pedestrian in 2018. The case was settled, but it showed that contractual disclaimers are not bulletproof.

To be truly “better” at managing liability, the industry needs to build a new layer: an “accountability protocol” that records every action an agent takes, the context, and the rationale. This protocol could be cryptographic: a hash chain of agent decisions, signed by the agent’s identity. If a litigation arises, the records can be time-stamped and verified. This is an infrastructure play. It’s a blockchain play. And it’s conspicuously absent from the current AI stack.

I’ve spent three years watching RWA tokenization. My personal view is that traditional institutions don’t need your public chain; they need a settlement layer with institutional-grade compliance. The same principle applies here. You don’t need a token for your AI accountability layer. You just need an immutable log. But if you build that log on a public ledger, you get a built-in trust anchor. That might be the “better” solution.

Empirical Examination: What Does the Data Tell Us?

Let me ground this in data. I’ll categorize the risks:

  • Copyright infringement rates: In a 2023 study from Stanford, researchers found that large language models memorized and emitted training data at a surprisingly high rate. For code, this means that an AI might output a function that is verbatim from a GPL library. The study suggests that models with more parameters have higher memorization rates. That’s a direct liability trigger.
  • Supply chain hallucinations: A 2024 study by researchers at Concordia University and other institutions found that popular code generation models hallucinate open source package names at rates ranging from 19% to 32%. For a model like Devin, which is designed to be even more autonomous, the risk is higher because it may automatically install a package that doesn’t exist or is not verified. Attackers can pre-register these hallucinated package names. This creates a “dependency confusion” attack vector that is much more dangerous than the human version, because the AI may not even realize it’s falling into a trap.
  • Security vulnerability introduction: A recent paper (2024) that I reviewed during my research at the Web3 Research Partner role found that code generated by LLMs contained security vulnerabilities around 40% of the time, even when asked to write secure code. The main failure modes are improper input validation, missing authorization, and insecure randomness. In a human developer, these would be caught by peer review and security scanning. In an autonomous agent, they may be committed without review.

I want to stress that these are not anecdotes. These are systematic issues. If you combine them, the probability of an enterprise-grade deployment of an AI coding agent causing a serious security incident is high. It’s a matter of “when,” not “if.” The legal industry will have a field day.

Copyright: The Training Data Morass

Every AI coding agent is trained on code scraped from public repositories. Some of that code is MIT-licensed. Some is GPL. Some is proprietary code that leaked. When a model outputs a function that closely resembles a GPL implementation, and that function ends up in a proprietary product, the legal headache is immediate. But with a human developer, the risk is limited to the human’s knowledge and what they choose to copy. With an AI, the model may emit a solution that is “interpolated” from many sources, creating a genuine “substantial similarity” issue. The legal doctrine of “clean room” implementation—where a developer writes code based on a specification without seeing the original—becomes meaningless when the model’s training data includes both the specification and the original.

The common defense is “the model doesn’t copy; it learns patterns.” That defense has been tested in court. The New York Times v. OpenAI case is essentially testing whether output can be seen as “derivative work.” But a coding agent’s output is even more dangerous for defendants because code is functional. A court may be more likely to find infringement when the output executes the same sequence of operations as the copyrighted code.

Let me add a personal note. During my 2021 NFT saga, I spent weeks analyzing the provenance mechanics of Art Blocks and arguing that algorithmic scarcity was a flawed metric for value. I cited specific on-chain data from 12,000 mints to prove that secondary market volume was decoupling from creator royalties. That experience taught me that when an industry is built on a legal fiction, the fiction eventually collapses. The legal fiction in AI is that generative models create “new” code without reproducing training data. The evidence says otherwise.

Security: The Supply Chain Nightmare

An autonomous coding agent can pull dependencies from a package manager. It can suggest a library that turns out to be a typosquat or a dependency that has a known vulnerability. The recent discovery of backdoors in popular npm packages like chownr and tar demonstrates that supply chain attacks are a real and active threat. If an AI agent automatically adds a package with a malicious postinstall script, and that code ends up in a company’s production environment, the company’s CISO might never know until the exploit happens. In the legal aftermath, the blame could fall on the AI vendor for not checking the supply chain. But can an AI vendor be held to a duty of care for every transitive dependency? That’s a huge question.

The question is not merely academic. In the software industry, there is currently a debate about whether open-source maintainers should be held liable for vulnerabilities in their packages. The White House’s 2023 National Cybersecurity Strategy explicitly contemplates shifting liability onto software manufacturers, including open-source maintainers. If that principle extends to AI code generators, the liability landscape becomes even more complex. You could have a chain: the model maker, the agent builder, the package registry, and the user. A plaintiff will sue all of them, and the court will have to apportion blame.

Contract Law: Who Is the Counterparty?

Imagine an AI coding agent is allowed to enter into contracts to purchase APIs or access tokens. This is already happening in the DeFi ecosystem, where bots sign transactions and interact with smart contracts. But with autonomous AI, there is no “intent” in the legal sense. The Uniform Electronic Transactions Act (UETA) in the United States requires that a “message” be sent by the person who “authorized” it. If an AI is acting on its own, who authorized the message? The user may have given it a broad instruction: “fix this bug.” But the AI’s specific action—calling an external service—might not have been explicitly authorized. This is the classic “agency” problem in law. Grewal’s expertise in adversarial litigation could be used to argue, on behalf of AI companies, that the user remains the principal and the AI is merely an instrument. But that argument undermines the entire claim that AI is “autonomous.” If the AI is fully autonomous, then it needs to be recognized as an agent, with its own liability. If it’s merely an instrument, then the liability falls on the user, and the AI company’s role is reduced to a toolmaker.

Cognition’s legal strategy will likely oscillate between these two narratives depending on the situation: “Devin is autonomous” for marketing, and “Devin is a tool” for liability. That’s not a criticism; it’s a predictable legal maneuver. But it creates systemic uncertainty for enterprises adopting the technology.

The Role of On-Chain Data: A Historical Parallel

Let me bring it back to my own experience. In 2024, I produced a report on the “Liquidity Premium” of Bitcoin ETFs, using historical data from traditional finance ETFs to model potential price floors. The key insight was that the derivatives market, not the spot market, was the primary price oracle. In the AI coding world, the “oracle” is possibly the legal system. A single court ruling can create a price floor or a price ceiling for an entire sector. That’s why Grewal is a significant acquisition. He is an oracle manipulator—in the benign sense.

But just like blockchain oracles, legal opinions can be manipulated or erroneous. The industry needs multiple oracles, not just one. We need credible technical standards bodies, insurance underwriters, and independent auditors to build the accountability stack. Otherwise, we will end up with a “legal fork” that replicates the exact pattern of the Layer2 ecosystem: dozens of participants, but all fighting over the same resources, and none providing a unified solution. In my 2025 analysis of L2s, I argued that fragmentation is not scaling; it’s slicing already-scarce liquidity into pieces. The analogous fragmentation in AI accountability is legal arbitrage: one company chooses Delaware law, another chooses California, a third chooses the EU. That doesn’t create safety; it creates a race to the bottom.

The Political Economy of AI Legal Talent

Grewal is not the only legal heavyweight moving into AI. In 2023, former Google counsel Kent Walker was still at Google, but we saw the move of Fred Ehrlich from the US Solicitor General’s office to OpenAI. There is a pattern: AI companies are aggressively hiring people with government experience, especially in antitrust and copyright. This is a sign that the industry anticipates regulatory scrutiny on multiple fronts. It is also a sign that these companies want to influence policy from the inside.

But there is a darker interpretation. In the 1990s, the tobacco industry hired lawyers who had fought the auto industry, and they used litigation delay tactics to postpone accountability for decades. The result was a public health catastrophe. The AI industry is not selling cigarettes, but it is selling a general-purpose tool that can amplify mistakes. If the legal strategy becomes to confuse the public, obfuscate evidence, and push liability onto users, that would be a tragedy.

I’m not saying that Cognition will do this. I’m saying that the incentives are there. Grewal’s reputation is built on winning against regulators. He will want to win against those who might challenge AI autonomy. The question is: what does “winning” mean? If it means a clear, safe, and accountable AI industry, then great. If it means a win for Cognition in a high-stakes lawsuit, but the industry as a whole becomes more opaque and less accountable, then the cost is too high.

The Contrarian Angle: What if Grewal is Actually Bad News for AI?

Let me now take the opposite position, with all the respect a good contrarian deserves. The standard interpretation of this hire is “Cognition is preparing for the inevitable legal storm, and Grewal will help them navigate it.” The contrarian interpretation is “Cognition is planning to use the legal system as a competitive weapon, and Grewal will be the hammer.”

Consider the implications. Grewal’s previous fight with the SEC was not just defensive; it was also a strategic move to delegitimize a regulatory threat. By filing a petition and publicly accusing the SEC of “regulation by enforcement,” Coinbase galvanized a political ecosystem that eventually pushed for new crypto legislation (like the FIT21 Act in the US House). Grewal did not just navigate the system; he actively changed it. If Grewal applies the same playbook to AI, he might not try to create clarity. He might try to create chaos for his opponents.

For example, before the AI industry is even sued over copyright, Cognition could file a declaratory judgment action against a major rights holder, asking a court to declare that AI-generated code does not infringe copyright because the model uses a “transformative” process. That would be a massive, expensive, years-long lawsuit. It would also put Cognition in the center of the conversation, potentially suppressing competitor innovation while the lawsuit is pending. This is a classic “litigation as a moat” strategy. The tech industry has seen it before. Oracle used lawsuits to attack Google’s Java use, and Broadcom’s legal department is legend. But for a startup, this strategy is risky because it might alienate customers who are frightened by legal uncertainty.

Another contrarian angle: The AI industry may already be overestimating the value of legal expertise. The real problem is not law; it’s safety engineering. You can’t sue your way out of a model dumping all its training data or writing a buffer overflow. You need technical rigor. Grewal can’t write a safe inference kernel or a formal verification tool. If Cognition’s legal strategy is to shift liability to users, that might not be “better” for the product’s adoption. Enterprise buyers, as I noted earlier, are becoming sophisticated. They will ask, “What is your liability cap?” If the answer is “You are entirely liable for the output,” they will walk away. A great lawyer can negotiate better terms, but ultimately the risk has to be priced somewhere. The only way to lower the price is to make the product safer. Legal expertise is a complement, not a substitute.

There’s also the “greenwashing” equivalent in AI: “law-washing.” Hiring a famous lawyer makes you look responsible, even if you’re not changing your engineering practices. This is a common public-relations tactic. Grewal’s presence might give Cognition a veneer of responsibility that can delay meaningful regulation. If the company can say, “We have one of the most experienced regulatory lawyers in the country,” regulators might believe that the company is self-policing. That could be exactly what the AI industry wants: a token of legitimacy that slows down the regulators while the industry matures to a point where its lobbying power is stronger. In that reading, Grewal is not a safety officer; he’s a shield. And that’s not “better” for safety.

The Macro Context: Regulatory Winds and the AI Arms Race

Let’s put this into the broader macro picture. In the United States, the current regulatory environment is fragmented. The SEC has taken an aggressive posture on crypto. The FTC has been exploring AI-related consumer harms. State attorneys general are increasingly active in privacy and algorithmic accountability. In the European Union, the AI Act has created a structured regulatory framework with clear deadlines, but it’s already seen as too rigid by many startups.

Coinbase’s experience was that a single legal officer cannot change the enforcement environment; they can only change the company’s readiness. Grewal’s move suggests that AI companies are preparing for a prolonged period of regulatory uncertainty, possibly with multiple jurisdictions. The lack of clarity is arguably a bigger threat to adoption than the technical limitations. Enterprise customers ask, “Who is liable when your agent breaks something?” and the honest answer is currently “we’re working on it.” Grewal’s job is to transform that answer into a legally defensible “the user is responsible for oversight, and our terms of service make that explicit.”

Code Is Not a Defense: Paul Grewal’s Move to Cognition and the Unbuilt Liability Stack for Autonomous Software

But here’s the problem: if the legal terms shift all liability onto the user, then the value proposition of AI coding agents collapses. Why would a company pay a premium for an autonomous agent that requires the same level of human oversight as a junior developer, but with none of the accountability? The product’s utility is directly tied to how much responsibility the vendor is willing to absorb. If Grewal’s legal strategy is purely defensive, the product may become less appealing.

Empirical Validation: A Look at Current Terms of Service

Let’s test this with concrete evidence. I examined the terms of service for several AI coding assistants. GitHub Copilot includes a warranty disclaimer that explicitly states the tool is provided “as is” and “without warranty of any kind.” OpenAI’s API Terms of Use include an indemnification clause requiring the customer to defend OpenAI against any third-party claim arising from the customer’s use of the API, including claims that the output infringes IP rights. This is a common pattern: the AI vendor pushes liability downstream. Cognition will likely follow suit.

However, this approach is not sustainable in the long run. Courts have famously declined to enforce exculpatory clauses when they are unconscionable. If an enterprise is held liable for a major breach caused by AI-generated code, the enterprise will turn around and sue the AI vendor, arguing that the warranty disclaimer does not protect against gross negligence or willful misconduct. And if the vendor has safety claims—like “our agent uses careful verification”—a plaintiff can argue that the vendor’s marketing represents a guarantee. Grewal knows how to litigate this, but the outcome is uncertain.

The better path is to build an actual safety case. That requires engineering and transparency, not just legal playbooks. But as Henry Davis, I’m skeptical that market incentives favor that path. The race to sell “autonomous engineers” has already started.

The “Better” Question

Let me now address the second of my signature phrases. “Better” is a comparative claim, and in this context, I want to ask: “Better for whom?” Grewal’s move is “better” for Cognition in the short term because it reduces the risk of a catastrophic legal surprise. It is “better” for AI industry investors because it suggests the sector is mature enough to attract top legal talent. But it is not necessarily “better” for developers, for open-source communities, or for the public at large. It could even be worse for those groups, because a more legally sophisticated AI company is harder to hold accountable.

I recall a conversation from my time as a research partner in Bangkok, when a friend at a Thai fintech said, “We aren’t scared of the government; we’re scared of your courts.” That’s the right instinct. The legal system is the ultimate gatekeeper. When Amazon deploys a warehouse full of robots, there is a legal framework for who is responsible if a robotic arm injures a human. When a coding agent deploys a vulnerable smart contract, there is no framework. Grewal’s hire is an attempt to build that framework from the inside. But we should be careful what we wish for. A framework built by one company’s lawyers, without public oversight, may be “better” than nothing, but it’s not necessarily “better” than an open, democratic process.

The Unbuilt Infrastructure: What “Better” Looks Like

So what would a responsible framework look like? Let me sketch it out, because this is where forward-looking analysis matters more than critique.

First, we need a machine-readable liability model. In the old world, legal contracts are written in human language. In the world of AI agents, we need “law as code”: executable specifications of what an agent is allowed to do, encoded in verifiable digital signatures. Think of something like a “smart contract” for AI action authorization. The user would sign a digital policy that says, “This agent may make commits to the following repositories, but not to production.” The agent’s every action would be logged against that policy, and any deviation would be automatically flagged. This is the kind of infrastructure that could be built on a blockchain, because blockchains provide tamper-evident logging and cryptographic identity.

Code Is Not a Defense: Paul Grewal’s Move to Cognition and the Unbuilt Liability Stack for Autonomous Software

Second, we need to define “proximate cause” in AI agent incidents. In tort law, proximate cause is the legal test for whether a defendant’s actions caused the harm. With an AI agent, the causal chain is complex: the model’s training data, its architecture, the prompt, the user’s choice of dependencies, the production environment, etc. We need a causal attribution system that can trace which component was the “but-for” cause of a failure. This is an engineering problem, but also a data-availability problem. Once again, an on-chain audit trail would be invaluable.

Third, we need a new form of “code liability insurance.” If an AI writing code is a professional, then it should carry insurance, or its creators should. In the traditional world, software errors are covered by professional liability insurance for developers. For AI agents, there is no analogous product. The actuarial tables are empty. Insurance companies will not write a policy without data. So the first mover who can generate a corpus of audited agent actions—with outcomes—will define the insurance market.

Cognition, with Grewal on board, is in a position to shape all three of these pillars. It can use its legal muscle to advocate for a specific liability framework, and then design its product to be compatible with that framework. That’s smart strategy. But it also creates an enormous concentration of power. A single company, through its legal department, could define the terms under which all autonomous coding agents operate. That’s a bigger concern than the technology itself.

The NFT Parallel: Ownership, Scarcity, and Accountability

In 2021, I retreated from trading PFPs to analyze the provenance mechanics of Art Blocks. I wrote a series of three essays deconstructing the “generative art as a service” narrative, arguing that algorithmic scarcity was a flawed metric for value. The same pattern is emerging in AI. The market is treating “autonomy” as a scarce, valuable feature. But autonomy without accountability is like an NFT without provenance: a claim floating in the air. The legal team is there to provide the provenance.

The NFT bull market also taught me that developers are often the last to know when a legal narrative is cracking. They focus on the code, not the courtroom. With AI coding agents, the courtroom may be more important than the code. Grewal’s presence is a reminder that the next major narrative shift in AI will come not from a model release or a training milestone, but from a legal ruling or a regulatory action. The narrative hunter in me is already sniffing for the first signs.

What History Tells Us: Software Tort and Liability Peaks

Let’s step back and think about the history of software liability. In the 1980s, when personal computers became common, there was a wave of litigation over software bugs that caused data loss. The industry responded by inserting disclaimers and shrink-wrap licenses that disclaimed liability for consequential damages. This worked for a while, but the rise of the internet and the Y2K bug brought renewed attention to software as a critical infrastructure. In 2000, the Y2K Act created a series of legal protections for companies that made good-faith efforts to fix issues. It was a policy response to a systemic risk.

Today, AI coding agents are the new Y2K: an invisible, systemic risk embedded in the foundation of the digital economy. But the fix is not a one-time update; it’s a permanent accountability layer. The law will eventually require something like an accountability.txt file in every repository, recording who or what generated each line of code. In my smart contract auditing days, I often told clients: “If you can’t show me the exact transaction that caused the loss, you can’t recover the funds.” The same principle applies to AI-generated harm: if you can’t show the exact action that caused the loss, you can’t assign liability. And if you can’t assign liability, insurance won’t cover it.

This is where blockchain, despite all its hype, may earn its keep. The promise of an immutable, public record is not about speculation; it’s about evidence. For the first time, we can create a complete audit trail of a computational agent’s actions. That audit trail is the missing link between code and law. Grewal knows this. He has seen the power of a public record in the crypto litigation arena. He will likely push Cognition to adopt similar practices.

The Takeaway: The Next Narrative is “Accountability Rails”

So where does this leave us? The crypto industry learned the hard way that legal clarity is not something you can solve with code alone. You need to participate in the rule-making process, and you need to be prepared to litigate. The AI industry is going through the same learning curve, but the stakes are higher because the agents are not just creating assets; they are creating actions. Paul Grewal’s move from Coinbase to Cognition is an acknowledgment that the next phase of AI will be defined by law, not just by benchmarks.

The narrative shifted, in my view, from “AI can write code” to “Who is accountable for AI-written code?” That shift will generate a new set of winners and losers. The winners will be companies that build robust evidence trails, perhaps on public ledgers, and that can prove their agents’ actions are safe and authorized. The losers will be those that rely solely on the magical thinking that “the code didn’t mean to do it.” In a future court, that defense will be as effective as “the dog ate my homework.”

I’ll leave you with a question: when an autonomous agent writes a function that drains a treasury, or a contract that violates a sanctions list, will the lawyer who wrote the liability clause be enough? Or will we need a new kind of professional—someone who can speak both the language of code and the language of law, and who can ensure the evidence is on a ledger that doesn’t lie? That’s the “better” question to bet on.

As for me, I’ll be watching the on-chain data trails that may soon emerge from Cognition’s product. When a software engineer is an AI, and the legal engineer is a human, the intersection is where the next bull market of narrative will be born. But remember: history rhymes, but the code doesn’t. The code is what we write—and eventually, the code writes us.

Market Prices

BTC Bitcoin
$64,098.4 -0.98%
ETH Ethereum
$1,884.59 -0.95%
SOL Solana
$75.77 -0.95%
BNB BNB Chain
$610.3 +1.43%
XRP XRP Ledger
$1 -2.14%
DOGE Dogecoin
$0.0706 +1.28%
ADA Cardano
$0.1871 -4.59%
AVAX Avalanche
$6.45 -1.24%
DOT Polkadot
$0.7949 -2.79%
LINK Chainlink
$8.62 +4.09%

Fear & Greed

29

Fear

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Market Cap

All →
1
Bitcoin
BTC
$64,098.4
1
Ethereum
ETH
$1,884.59
1
Solana
SOL
$75.77
1
BNB Chain
BNB
$610.3
1
XRP Ledger
XRP
$1
1
Dogecoin
DOGE
$0.0706
1
Cardano
ADA
$0.1871
1
Avalanche
AVAX
$6.45
1
Polkadot
DOT
$0.7949
1
Chainlink
LINK
$8.62

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

🐋 Whale Tracker

🔵
0xaaaf...c256
12m ago
Stake
4,468,147 USDC
🔵
0x6bcc...49a0
3h ago
Stake
50,565 SOL
🟢
0x9ae6...b937
6h ago
In
39,865 BNB

💡 Smart Money

0x9736...1e0e
Experienced On-chain Trader
+$3.9M
86%
0xbfc9...ab4e
Experienced On-chain Trader
+$4.7M
79%
0xc1db...fd2d
Market Maker
+$4.3M
93%