A company does not need to publish its strategy for competitors to learn it.

Sometimes it only needs to publish enough behavior.

That becomes a serious problem when autonomous AI agents begin negotiating, purchasing, routing, and settling transactions on observable infrastructure.

A procurement agent may never disclose its internal budget.

A treasury agent may never reveal its liquidity model.

A logistics agent may never publish its urgency score.

But if their actions are visible in real time, an adversary may be able to infer all three.

The deeper privacy problem in the machine economy is not merely that transactions reveal payments.

Transactions can become training data for a model of the organization itself.

The previous article looked at the privacy problem from the organization’s side: what information surfaces emerge when autonomous agents conduct business on observable infrastructure.

This one turns the telescope around.

Assume those signals are available to a capable adversary. What can an observer learn, predict, and eventually exploit by treating repeated economic behavior as a dataset?

The target is not just the transaction history.

The target is the policy that generated it.

Call this economic policy extraction: inferring an organization’s decision rules from the way its agents respond to economic conditions.

At its most deliberate, the adversary helps create those conditions. It changes the offers, observes the responses, and uses each interaction to decide what to test next.

Attack 1: Learn the agent’s bargaining policy

Imagine a company whose infrastructure agent routinely purchases compute capacity.

For months, its behavior is stable.

Then something changes.

The agent begins:

  • requesting additional GPU capacity,
  • accepting shorter delivery windows,
  • paying higher premiums,
  • interacting with new infrastructure providers,
  • and settling faster than usual.

Nothing explicitly says:

“We are launching a major AI product in six weeks.”

But an observer may not need the announcement.

Suppose the observer is another agent trained to correlate timing, counterparties, asset flows, failed bids, historical price tolerances, and external market data.

Over time it may learn rules such as:

“This buyer accepts a 6% premium when inventory coverage falls below three days.”

The buyer never published that policy.

Its behavior taught the policy to the observer.

Once learned, the pattern can be exploited repeatedly.

That creates a strange form of corporate espionage:

No one breaks into the company. They simply learn the policy from the agent’s observable behavior.

Attack 2: Reconstruct the coordination graph

Payload encryption is not enough if relationships remain visible.

An observer may not know what two organizations said to one another.

It may still learn:

  • which firms interact,
  • how often they interact,
  • which counterparties disappear,
  • which new suppliers appear,
  • which relationships suddenly become more active,
  • and which operational dependencies recur.

Taken together, those signals form a coordination graph.

That graph can be commercially sensitive in its own right.

Repeated interaction with a narrow group of providers may expose critical dependencies.

A sudden relationship with a new manufacturer may suggest a product launch.

Unusual activity between two firms may hint at a partnership, acquisition discussion, or supply agreement before either company announces it.

The content can remain encrypted while the strategy leaks through the graph.

Attack 3: Infer urgency from timing

Timing is often treated as harmless metadata.

In automated commerce, timing can be a bargaining signal.

Suppose a buyer agent normally waits twelve hours before accepting revised terms.

Then, during a supply shortage, it begins accepting within minutes.

A supplier may infer that the buyer’s fallback options are deteriorating.

Now imagine a logistics agent that suddenly books freight at unusual hours, pays for faster delivery, and retries failed capacity requests rapidly.

The message payload may reveal nothing.

The cadence may reveal urgency.

Once counterparties learn that timing correlates with operational pressure, they can price against it.

Privacy therefore has to consider behavioral metadata, not just secret fields.

Attack 4: Infer liquidity and financial stress

A treasury agent can leak information without publishing a balance sheet.

Observers may watch:

  • when assets are repositioned,
  • how much liquidity is staged before settlements,
  • whether payments are delayed,
  • whether collateral patterns change,
  • whether the agent increasingly seeks discounts,
  • or whether it begins using unfamiliar funding routes.

No single event proves financial stress.

But models do not need certainty to be useful.

A sufficiently rich behavioral record can produce a probabilistic view of the company’s liquidity position.

That view may be valuable to suppliers, lenders, traders, competitors, or hostile actors.

The danger is not merely disclosure of a number.

It is the cheap production of a forecast.

Attack 5: Cross-correlate on-chain behavior with public data

The most capable observer will not analyze transactions in isolation.

It can correlate economic activity with:

  • job postings,
  • earnings calls,
  • shipping data,
  • product launches,
  • DNS changes,
  • public cloud announcements,
  • procurement notices,
  • patent filings,
  • social-media activity,
  • and market prices.

A cluster of new GPU purchases may mean little by itself.

Combined with hiring for inference engineers, a newly registered product domain, and unusual data-center activity, it may become much more informative.

This changes the economics of surveillance.

Information that was technically public but practically difficult to interpret becomes much more valuable once machines can correlate it cheaply and continuously.

The relevant question is no longer:

“Could someone inspect this transaction?”

It is:

“What could a model infer after watching every transaction for a year?”

Attack 6: Economic policy extraction

There is an even more uncomfortable possibility.

An adversarial counterparty may not simply observe an agent.

It may deliberately probe it.

Offer slightly different prices.

Change delivery windows.

Introduce scarcity.

Delay responses.

Present alternative settlement terms.

Repeat the experiment, using each response to choose the next offer.

Each acceptance, rejection, counteroffer, delay, or switch to another supplier becomes feedback.

Over repeated interactions, that feedback can reveal how the company trades price against urgency, availability, delivery risk, and liquidity.

The negotiation becomes an interface for economic policy extraction.

Consider a supplier probing a procurement agent.

With delivery and settlement terms held steady, it raises the price. Then it tests earlier delivery at a premium, limited availability, or a discount conditional on immediate payment.

A single answer is ambiguous.

But repeated responses under different conditions may reveal where the agent changes course: when it pays to avoid a delay, when it switches suppliers, and when preserving liquidity matters more than securing a discount.

The supplier can test those estimates in later negotiations and keep refining them.

Eventually, it may shape an offer around the buyer’s likely acceptance threshold before negotiation begins.

This resembles model extraction in machine learning, except the target is not a classifier API.

The target is the company’s economic decision policy.

The adversary does not need to recover every rule or see the agent’s internal instructions. An approximate model can be valuable if it predicts which terms the organization will accept, resist, or abandon.

Even a private negotiation exposes some of those responses to the counterparty conducting the probe.

A systematic agent may be easier to learn than a human negotiator because its behavior is more consistent.

The more efficiently it follows policy, the cleaner the signal can become.

That is the irony: automation can make an organization operationally efficient and strategically legible at the same time.

Intent can be attacked before settlement

The problem also begins before a transaction is final.

Public blockchain markets already demonstrate how visible pending transactions can create opportunities for front-running, back-running, sandwiching, and other forms of value extraction.

Agent commerce broadens the underlying idea.

A logistics agent broadcasts an urgent need for freight capacity.

Another participant acquires scarce capacity first.

A procurement agent repeatedly raises bids for a component.

A supplier infers worsening inventory pressure.

A treasury agent moves funds into position ahead of an acquisition.

Observers infer that something significant is about to settle.

The point is not that every observable action will be exploited.

It is that commercial intent is information, and adversarial agents can react to it at machine speed.

What privacy architecture has to protect

The solution is not to make commercial activity unknowable.

A seller needs to know what it is selling.

A buyer needs to know what it is paying.

Auditors need evidence.

Compliance teams need relevant facts.

A company needs to reconstruct what its agents did.

The objective is narrower:

Do not reveal commercially sensitive information to parties who do not need it.

That means protecting more than the payment amount.

A useful architecture has to address all four privacy boundaries:

  • Coordination privacy: protect message contents, commercial intent, and relationship and contact metadata.
  • Compliance privacy: prove that parties satisfy an interaction’s regulatory or organizational requirements while limiting disclosure to the facts it requires.
  • Authority privacy: prove that an agent’s proposed action falls within its delegated mandate without revealing the full mandate, including budgets, limits, delegation structure, and remaining authority.
  • Settlement privacy: exchange value verifiably without unnecessarily exposing the parties, amounts, timing, or transaction graph.

If information is protected at only one boundary, an adversary may reconstruct it from exposure at the others.

That is why commercial privacy has to survive the entire lifecycle.

How the protocol family narrows those surfaces

The architecture I am working on separates these concerns deliberately.

AFP aims to reduce unnecessary coordination-graph leakage.

ZKC allows selected compliance facts to be proved without turning every proof into a globally linkable identity.

ZKM allows an agent to prove that a transaction falls within a private mandate without revealing the full budget or delegation graph.

ZKA provides private settlement so transaction values and parties do not have to become public merely because settlement is verifiable.

None of those mechanisms eliminates every side channel.

Timing and external behavior still matter.

Counterparties necessarily learn some information.

Privacy systems can reduce inference surfaces; they cannot make economic behavior consequence-free.

The enterprise question changes

Public blockchains are often praised for radical transparency.

That transparency is valuable when society wants the activity to be publicly auditable.

It is much less obviously desirable when the observable data is a company’s live operating behavior.

Autonomous agents raise the stakes because they turn economic activity into continuous structured data.

And structured data is exactly what modern models are good at learning from.

Before moving enterprise workflows onto transparent settlement or coordination infrastructure, organizations should ask more than:

“Is the transaction secure?”

They should also ask:

“What could an adversarial model learn by watching our agents operate—and by repeatedly testing what changes their decisions?”

Because in the machine economy, your transaction history may become something much more valuable than a ledger.

It may become an executable theory of your business.


Disclosure: I am an active contributor to the ZKA/ZKC/ZKM/AFP protocol family discussed here. My work on privacy-preserving agent infrastructure naturally shapes my view of the risks created by observable machine-to-machine commerce.


The next article turns to one of those exposed surfaces: delegated authority. It asks how an agent can prove that a purchase is authorized without revealing its full mandate.