A private negotiation is not very private if everyone can see the deal the moment money moves.

That is the settlement problem.

Two companies may negotiate confidentially.

Their agents may keep budgets, mandates, supplier relationships, and commercial terms private.

They may prove compliance without revealing identity dossiers.

But if the final payment lands on a transparent ledger with the payer, recipient, amount, timing, and transaction history exposed, much of that privacy collapses at the last step.

The settlement layer becomes the leak.

For autonomous commerce, that may be the difference between private enterprise infrastructure and a public telemetry feed.

The question is:

How do two parties prove value moved correctly without publishing the transaction to everyone else?

That is settlement privacy: exchanging value verifiably without unnecessarily exposing the parties, amounts, timing, or transaction graph.

For an autonomous agent, settlement has another obligation.

The transaction must consume delegated authority and move actual value as one indivisible transition. Both succeed or neither does.

The payment must preserve both commercial privacy and the principal’s control over what the agent may spend.

The previous article explored how to prove compliance without unnecessary disclosure. That privacy now has to survive the moment value moves.

Settlement is where privacy either survives or dies

It is tempting to think of privacy as something that happens before payment.

Encrypt the negotiation.

Hide the procurement workflow.

Protect the mandate.

Use private credentials.

Then settle normally.

But the settlement itself can reveal enough to reconstruct the commercial relationship.

Suppose an AI procurement agent negotiates a $100,000 infrastructure purchase.

The negotiation may be private.

The agent’s spending ceiling may be private.

The supplier’s floor price may be private.

The compliance checks may be selective.

Then the buyer sends a public transaction.

Now an observer may learn which address paid, which address received, the amount, the timing, the asset, the frequency of prior interactions, and the transaction graph connecting both parties to other activity.

Even if the public cannot immediately map those addresses to legal entities, repeated activity gives analysts and machine-learning systems material to work with.

A private workflow with transparent settlement is only partially private.

Validity does not require public visibility

A settlement system does not need to publish every detail to prove that a transaction is valid.

For a simple transfer, it needs to establish a narrower set of facts:

  • the sender controls spendable value,
  • that value has not already been spent,
  • the transaction conserves value,
  • the recipient receives the intended value,
  • the transaction is bound to the correct settlement context,
  • and the resulting state is final under the rules of the system.

Those are statements about validity, not inherently about public visibility.

Zero-knowledge systems let us separate the two.

The network can verify:

“This transition is valid.”

without learning every private input that made the transition valid.

That distinction is the foundation of private settlement.

Authority and value must settle as one transaction

Now add autonomous agents and delegated authority.

A valid payment proves that value moved correctly.

It does not, by itself, prove that the agent stayed within its principal’s spending limit.

Suppose an AI buyer has a private mandate allowing it to spend $100,000.

A $100,000 purchase must do two things:

  1. consume $100,000 of the agent’s authorized mandate, and
  2. move $100,000 of actual value.

Those are two parts of one transaction. Both must succeed or neither does.

That is authority/value atomicity.

If the mandate is consumed but the payment fails, the agent loses authority without completing the purchase.

If the payment settles but the mandate is not consumed, the agent may be able to spend beyond its principal’s limit.

Neither outcome is acceptable.

Nor can two simultaneous purchases be allowed to consume the same authority, even if each payment would be valid on its own.

For a principal’s spending limit to mean anything at machine speed, the settlement system must enforce it as value moves.

Conceptually:

PRIVATE AUTHORITY        PRIVATE VALUE
      │                       │
      └──────────┬────────────┘
                 ▼
        one atomic settlement
                 │
           ┌─────┴─────┐
           ▼           ▼
 mandate consumed   value settles

       both succeed or neither does

This is one of the reasons ZKM and ZKA are designed as separate layers that can be cryptographically conjoined.

ZKM answers:

Is this agent authorized to make the spend?

ZKA answers:

Is this value transition valid?

The questions remain distinct. The transaction depends on both answers.

The settlement rules must bind the authorization and value transition to the same transaction and commit their state changes together.

Verifying both proofs is not enough if one state change can succeed while the other fails.

That is stronger than checking an authorization token in one service and then hoping a separate payment service behaves consistently.

It makes the principal’s mandate an enforced condition of settlement.

Authority/value atomicity is a central architectural requirement for machine commerce.

Privacy protects the terms of the transaction. Atomicity ensures that the agent cannot complete it without consuming the authority required to act.

Private notes instead of public balances

One useful mental model is to stop thinking of an account balance as a public number.

Instead, think of value as private notes.

Each note represents spendable value controlled by a holder.

The note is committed cryptographically.

When the holder spends it, the system produces a nullifier that marks the old note as consumed and creates new commitments representing the outputs.

Conceptually:

Private input note
       │
       │ valid proof
       ▼
   nullifier
       +
private output notes

The public system sees enough to prevent double spending and verify correctness.

The parties see what they need for the transaction.

Everyone else sees much less.

This is the model behind ZKA’s private value-transfer layer.

Private does not mean unverifiable

A common misconception about private payments is:

If the public cannot see the amount, how can anyone know the system is solvent or that money was not created out of nowhere?

Visibility and verifiability are different properties.

A zero-knowledge circuit can enforce value conservation privately.

The proof can establish that the consumed value equals the value created by the transaction, even if the exact values are hidden from observers.

The same applies to ownership and double-spend prevention: the system verifies the proof rather than trusting the sender’s claim.

This is the core shift:

The ledger does not need to reveal the transaction in order to reject an invalid one.

For enterprise infrastructure, that is enormously important.

We want correctness to be public.

We do not necessarily want commercial terms to be public.

The counterparty still needs to know what it received

Private settlement should not become absurd.

If I sell you $100,000 of compute capacity, I need to know that I received $100,000 worth of the agreed asset.

Privacy from the public does not imply privacy from the counterparty.

The recipient can receive the private note opening needed to recognize and later spend the payment.

An auditor can receive viewing-limited material.

A regulator may receive information through an authorized disclosure path when required.

The public settlement record does not need to become the universal database for all of those audiences.

The principle is simple:

Different parties can know different things because they have different legitimate roles.

Finality is part of settlement too

Submitting a transaction does not mean it has settled.

Autonomous agents need a precise definition of completion.

Did the payment reach the network?

Was it included?

Is it safe?

Is it finalized?

Could it still be reorganized?

If software is going to release goods, activate compute, transfer intellectual property, or begin another dependent workflow, those distinctions matter.

A good machine-to-machine payment system therefore needs finality-aware evidence.

The parties should be able to bind the commercial obligation to the exact settlement and observe when that settlement reaches the level of finality their agreement requires.

That is why the AFP payment profile separates the commercial quote from the settlement receipt.

The commercial agreement remains bilateral.

The settlement remains cryptographically verifiable.

The public still does not need the entire commercial context.

Private settlement still has governance risk

Privacy does not solve the control problem by itself.

Suppose a payment system hides transaction details from the public but gives an administrator the ability to pause withdrawals, invalidate notes, redirect funds, replace the verifier, or rewrite ownership.

That system may be private.

It is not sovereign.

In the architecture I am exploring, note validity is intended to depend on cryptographic validity rather than administrative permission.

The rule should be:

The protocol can reject an invalid proof. An administrator should not be able to rewrite a valid property right.

That boundary matters because confidential infrastructure can otherwise become a more sophisticated gatekeeper rather than a less trusted one.

Exit is the ultimate test

Every private settlement system should answer one question:

What happens when the operator disappears?

Can the holder still exit?

Can the holder construct the required proof?

Does withdrawal require a fresh compliance credential?

Does an administrator need to co-sign?

Can a third party freeze the path?

A privacy system that works only while an intermediary cooperates remains dependent on it.

ZKA treats withdrawal as a custody operation rather than a compliance interaction.

A counterparty may refuse to do business with you.

A verifier may reject your credential.

A mandate may expire.

A commercial relationship may terminate.

None of those events should strand value already under your control.

That gives us another useful rule:

Compliance may gate an interaction. It should not gate the exit.

Private settlement is not universal secrecy

Timing can leak information.

Deposits and withdrawals can create correlation surfaces.

Counterparties necessarily learn information about their own transactions.

External bridges can introduce additional leakage.

And if a party later discloses its records, privacy cannot make that information undisclosed again.

The goal is not perfect opacity, but avoiding commercial exposure simply because the settlement infrastructure is public.

That is a much more achievable and useful standard.

The question ahead

Enterprise finance has traditionally relied on private ledgers operated by trusted institutions.

Public blockchains inverted that model by making settlement globally inspectable.

Private zero-knowledge settlement offers a third possibility:

shared verification without shared visibility.

The network can establish that a transaction obeyed the rules.

For an agent spending under a mandate, those rules must join authority and value: the authorized spending capacity is consumed in the same transition that settles the payment.

The counterparties can know what they need to know.

Auditors and regulators can receive authorized evidence where required.

And everyone else does not automatically get a permanent copy of the commercial relationship.

For autonomous commerce, that distinction will become increasingly important.

Because when two AI agents settle a $100,000 transaction, the real question is not simply:

Did the payment happen?

It is:

Who actually needs to know the details in order for the payment to be trusted?

My answer is increasingly:

The parties who need the information.

Not the entire internet.


Disclosure: I am an active contributor to the ZKA/ZKC/ZKM/AFP protocol family discussed here. The settlement architectures described above remain draft-stage work and should be evaluated as proposals rather than production assurances.


Private, authorized settlement still leaves a question of power: what must the infrastructure never be allowed to do? The next article sets out the six Freedom Safeguards.