AI + Web3 Integration · 5 min read ·
A practical guide to on-chain AI agent architectures, where to place compute and state, and the key security, cost, and UX tradeoffs.
On-chain AI agents are software agents that can observe state, decide, and act through blockchain transactions—often managing funds, interacting with DeFi protocols, and coordinating with other agents. The hard part isn’t the “AI” in isolation. It’s designing a system that is verifiable enough to trust, cheap enough to operate, and fast enough to be useful.
If you’re building an AI + Web3 product, you’ll quickly discover an uncomfortable truth: you can’t put modern model inference on-chain without major compromises. So most “on-chain agents” are really hybrid systems, where some parts are on-chain (state, policies, permissions, attestations), and the heavy compute runs off-chain.
Below is a concrete architecture map and the tradeoffs that matter.
There are three broad interpretations:
The best architecture depends on your product’s trust assumptions: do users need cryptographic guarantees, or is “auditable with strong incentives” sufficient?
A pragmatic on-chain agent system usually splits into five layers:
Identity + permissions (on-chain)
Policy + constraints (on-chain)
State + memory (hybrid)
Compute + decisioning (off-chain)
Execution (on-chain)
This decomposition lets you decide what must be trustless (on-chain) versus what can be trusted-but-audited (off-chain).
Pattern: The agent controls a smart account (ERC-4337-style) or vault with strict on-chain policies. Off-chain software proposes actions; on-chain modules enforce constraints.
Why it works: You get strong safety properties without pretending inference is verifiable.
Example: A treasury rebalancer that can only:
This is how many production “agents” should start: treat the model as an untrusted recommender and the contract as the enforcer.
Pattern: Off-chain inference outputs a signed decision (or a batch plan). Validators, a DAO committee, or a decentralized attestation network co-signs it. The chain checks signatures before execution.
Why it works: It’s cheaper than ZK, more decentralized than a single server, and aligns incentives. It also creates a clean audit trail: “who endorsed this action?”
Tradeoff: You’re trusting signers not to collude. This is often acceptable for mid-value actions or where governance already exists.
Pattern: The agent runs off-chain but submits a proof (ZK/validity proof) that “given inputs X, the model produced output Y.”
Why it matters: This is the closest you get to trustless AI.
Reality check: Proving large transformer inference is still expensive and complex. In practice, teams prove simpler things: risk checks, rule-based policies, or small models. If you need proofs, start by proving constraints and invariants, not full LLM reasoning.
Opinionated take: Most founders should prioritize constraint enforcement over inference verification. Users care more about “it can’t rug me” than “its chain-of-thought was proven.”
An agent that reacts in 2–10 seconds might be fine for DCA or rebalancing, but it will lose in fast markets to MEV and professional market makers.
Mitigations:
Blockchains like deterministic execution; LLMs are probabilistic.
Practical approach:
If your agent can sign transactions, you’ve created a target. Common guardrails:
A good rule: treat the LLM runtime as compromised. Your on-chain policy should still prevent catastrophic loss.
Agents rely on off-chain context: positions, prices, historical actions, and user preferences.
If you don’t commit to what the agent saw, disputes become impossible to resolve. Lightweight integrity patterns:
If you want something production-grade without over-engineering:
This gives users credible safety and transparency today, without betting your roadmap on bleeding-edge ZK inference.
On-chain AI agents are less about putting an LLM on Ethereum and more about splitting responsibilities: keep identity, permissions, constraints, and critical state on-chain; push heavy compute off-chain; and add verification where it delivers real user value.
The winning systems will be the ones that treat AI as a powerful but fallible component, surrounded by deterministic guardrails. Start with enforceable policies and auditable traces. Add attestations or proofs only when the economics justify the complexity. In AI + Web3, trust is a product feature—and architecture is how you ship it.