Inference prices have fallen at a median of roughly fifty times per year since 2020, and the gap between the best frontier models is now a few percent and changes hands between releases. Compute is going the same way. When the inputs everyone competes on turn into commodities, value moves to the layer that coordinates them, and that layer earns from the work regardless of whose model, whose hardware, or whose agent is involved.
This is not a prediction. It already happened one level down. The company that won utility computing did not have the best servers. It owned the coordination surface: the APIs, the identity, the billing, the integration points. The layer nobody found interesting turned out to be where the value settled.
For autonomous software, that layer does not exist yet.
Lumera has been building it. The chain is live. 28 bonded SuperNodes are running across six countries, secured by fifty validators including Allnodes, Nansen, and Luganodes. Cascade, durable memory with continuous cryptographic retention proofs, is in production on mainnet holding 231,799 objects for teams including Injective, Midnight, and LUKSO.
The Foundations of Autonomous Software
An agent operating without a person watching it needs guarantees that human-facing software does not. A developer holds context in their own head, reads the output and judges it, and settles a billing dispute by email. An agent has to persist context across sessions and vendors, evidence its work because nobody is reading it, and resolve disputes against a record. Today it does none of that. It calls a centralized endpoint, authenticates with an API key, and pays with a card attached to that key.
The tempting read is that these are product gaps waiting for better tooling. They are not, and the reason is the same in every case: the guarantee has to hold against the party providing it.
Memory held by a vendor is not portable, and its retention cannot be proven by the vendor holding it. An identity issued by a platform is revocable by that platform. A receipt issued by the party being paid is an assertion rather than evidence. A budget enforced by an API key is enforced by whoever holds the key. In every case the guarantee is only as strong as the trust you already had, which defeats the purpose. A platform whose value proposition is that you trust the platform cannot provide guarantees that do not require trusting it.
Closing these gaps requires agreement between parties who do not share an owner, and enforcement neither party controls. Every one of them is a coordination problem, and coordination problems are what protocols are for.
Five Capabilities, One Architecture
Durable memory, identity, verifiable execution, settlement and trust are not five products. They are five capabilities of one architecture, and each becomes more useful in the presence of the others. We are calling that architecture the Intelligence Layer.
It is not a separate network, a sidechain, or a parallel stack. Every capability is expressed through machinery the protocol already runs: the chain as control plane, economically bonded SuperNodes as execution plane, and work requested as Actions that settle only on confirmed completion. A new capability arrives as a new module and a new Action type, not as new consensus or a second settlement path. What a developer learns about one service transfers to all of them.
The capabilities form an acyclic graph with identity at the root. Execution has to know who is asking. Memory has to know who may read a private record. Settlement needs an account to draw against. Trust needs a stable subject and a stream of evidence.
Cascade
Cascade is durable memory built into the protocol.
Registration is a single payment made at the point of writing, with no recurring storage fees afterward. Data is erasure coded with RaptorQ fountain coding across independently bonded SuperNodes and addressed by a BLAKE3 hash of its contents, so a copy can go missing without the file going missing. Integrity is intrinsic: a retrieved object either hashes to the identifier recorded on chain or it does not, and checking that is a local computation.
Possession is proven rather than asserted. Before fees are released, an operator answers Merkle challenges over the exact object it claims to hold. Retention is tested periodically thereafter, with challengers and observers selected deterministically from on-chain state so no operator picks its own auditor, and the results land on chain where anyone can check them rather than only Lumera. Operators must post a bond to serve at all, and losing data costs them the income that bond was posted to earn. Failures escalate from heightened scrutiny to exclusion from new work and from retention payouts. Long-term retention is funded by Everlight, the protocol’s sustainability layer, which pays operators every period in proportion to the data they demonstrably retain.
That separation matters. Per-use fees cannot fund permanence, because the revenue arrives once and the obligation recurs forever. Endowment pools cannot meter individual turns, because the accounting granularity is wrong by orders of magnitude. Keeping real-time settlement and long-lived obligation as separate mechanisms is what allows a participant to pay once for storage and per turn for execution without either promise undermining the other.
The record is portable and protocol native. It belongs to the identity that wrote it, not to the application or vendor it passed through, so it survives a provider switch, a framework change, or a company shutting down.
Clients can encrypt before writing, using keys the network never holds. Retention challenges operate over ciphertext and are unaffected, which produces a property worth naming precisely: the network provably retains a record it cannot read. The cost is stated plainly. There is no key escrow and no recovery path.
Why a Hash Is Not Enough
This is the sharpest structural difference between Lumera and the adjacent market, and it applies to every attestation system that stores a hash and nothing else.
A hash is a tamper-evident seal. Holding the seal and the object, anyone can confirm the object is unaltered. But a registry keeps the seal and not the object. The object lives on a server, in a bucket, or on a disk belonging to whoever created it, and when it disappears, as eventually it does, the seal remains perfectly intact and completely useless. What remains is the ability to verify something nobody has.
An attestation pointing at content nobody retained is a proof of nothing.
The market divides along exactly this line. Attestation systems record claims and retain nothing, so verification is moot once the content is gone. Storage networks retain content and attest nothing, and none of them integrates identity, proof and settlement under one economic model. On Lumera the claim and the object live on the same rails: the attestation lands on chain, the object is retained across bonded operators, and retention is funded continuously rather than asserted once. In five years, when someone needs the thing that was attested, it is still there and still checkable.
What Builds on the Foundation
Identity. Every participant is a LumeraID, an on-chain identity controlled by its holder’s keys,
held by people, applications, agents, datasets and providers alike. Claims accumulate against it:
profile, key rotation, delegation, capability grants, attestations, revocation. Delegation is the
piece enterprises reach for first, because it expresses what they actually need: scoped authority granted to an agent covering a budget class, a dataset or a service family, without granting anything else, enforced on chain rather than promised in a contract. Authority never expands along a delegation chain, and revoking a grant invalidates everything downstream of it in one transaction.
Verifiable execution. Work is requested as an Action, performed by SuperNodes, evidenced by
signed receipts, and settled only when completion is confirmed against the on-chain record. A receipt carries a fingerprint of the inputs, which operator ran what, a fingerprint of the result, and a signature from the identity that performed the work. Deterministic computation carries the strongest guarantee available, because an independent operator can replay it and a mismatch is objective evidence rather than a matter of opinion.
Settlement. Fund a Global Credits balance once, on chain, provider-agnostic, and stop establishing billing with individual providers. Every turn of a session produces an on-chain acknowledgment, and settlement is acknowledgment-gated, so unacknowledged work is not merely disputed, it is never billable.
Trust. The trust record is compiled from evidence the other four capabilities already emit:
identity claims, delegations, attestations, signed receipts, clean settlements, disputes, slashes,
non-responses, retention proofs. It introduces no new data collection and takes no self-reported inputs. It is not a score. It is multi-dimensional and time-weighted, because a participant can be well established for research and untested for financial decisions, and collapsing that into one figure destroys the information a counterparty needs. Recent behavior dominates. And because every input is an on-chain event with a cost attached, the record cannot be inflated without performing real work that somebody else independently verified. Endorsements are self-reported and reviews can be purchased. Ten thousand acknowledged sessions cannot be fabricated.
Confidence Is Not Permission
The most dangerous failure mode in a network carrying model output is letting model confidence become protocol authority. A fluent answer is not a proof. A confident plan is not a permission.
Authority is graded, and the grading is structural rather than advisory. Reasoning is non-deterministic, so it moves reputation and is never directly slashed. Deterministic computation is reproducible, so a runner and verifier disagreement is objective evidence and is slashable. Irreversible effects stay in the calling application, which receives a signed action plan, revalidates it, and executes. The protocol does not fire an irreversible action on its own.
Two things follow. Operators know in advance exactly what they can be penalized for, which is a precondition for anyone bonding capital against service obligations. And quality judgments, which no consensus mechanism can adjudicate honestly, route to reputation where a history of outcomes prices them over time.
What Accumulates
Two assets accumulate as a by-product of the network operating, and neither is designed.
The trust record makes participants evaluable to each other. Execution is replicable: anyone with hardware and model access can offer it, and switching costs fall as models commoditize. The behavioral record is not replicable. A competitor can offer cheaper execution tomorrow. It cannot offer the history that tells an enterprise which participants and workflows are actually reliable. The closest analogy is a credit bureau, which issues no loans and holds no deposits, and whose compressed behavioral history is more defensible than any individual financial product.
The intelligence record captures what has been learned rather than who delivered. Data in a file system is inert and is a cost. Data connected to the session that produced it, the model that generated it, the identity that requested it and the settlement that paid for it is knowledge with provenance attached. Both records are built from commitments, metadata and outcomes, never from stored prompts and outputs. A design that accumulated the latter would be a surveillance record wearing the language of reputation.
Neither can be forked or purchased, because neither is code. They are history, and history is only available to whoever was there.
What This Is Not
Being precise about the boundary prevents the common misreadings, and each exclusion is a decision rather than a gap.
Not a model host: inference is one kind of work among many and the kind that commoditizes fastest. Not an agent framework: existing harnesses are integration surfaces, and a process can keep its framework and connect through an SDK or run natively on the protocol, with identical guarantees either way. Not a claim that the protocol produces intelligence, since reasoning happens off chain and what lands on chain is the commitment, the receipt and the outcome. Not a multi-token system: work is metered in credits and settled in the native asset, and there is no separate execution-layer token. Not a custodian of irreversible effects.
The foundation was never the announcement
Autonomous software needs to remember, identify itself, prove its work and get paid, under rules no counterparty controls. Those are not features to be added later. They are the conditions under which software can be trusted with anything that matters, and the layer that provides them is where value settles as everything above it commoditizes.
That layer is running. The chain is live, the SuperNode network is bonded and slashable, and Cascade is holding real data for real teams with retention proofs anyone can check. Identity, verifiable execution, settlement and trust are built on the same architecture, expressed through the same execution framework, settling in the same asset, and each one arrives on infrastructure that already carries live traffic rather than on a network still waiting to exist.
The foundation was never the announcement. It was the work.
Five capabilities, one architecture, one economic model. Open today.
Read the paper: https://www.lumera.io/assets/whitepaper.pdf
Start building: https://docs.lumera.io/quickstart
About Lumera Protocol
Lumera Protocol is a high-performance blockchain purpose-built for AI-driven Web3 economies, integrating a Validator-SuperNode architecture to enable decentralized AI services, trustless computation, and secure data storage. Built on cometBFT Proof-of-Stake (PoS), Lumera ensures cross-chain compatibility, efficient AI data sharing, and scalable interoperability.
At its core, Lumera’s SuperNode-powered infrastructure extends beyond validation to support LLM hosting, autonomous agents, task verification, and cross-network communication, with governance driven by a stake-weighted system. Its adaptive tokenomics dynamically adjust inflation based on network participation, ensuring economic sustainability.
Lumera also introduces an Action & Agent Framework, powering decentralized AI services through specialized Actions (e.g., Cascade for storage, Sense for verification) and Agents (e.g., Inference for AI computation). By merging AI, decentralized computation, and blockchain security, Lumera sets a new standard for AI-powered applications and autonomous services in Web3.
For more information on Lumera, follow us on Twitter, Telegram, Discord and visit https://lumera.io.
Website | Twitter | Discord | Telegram | Github | Reddit | Instagram
