On August 4, 2026, BlackRock launched blockchain-based share classes for selected European money market funds using J.P. Morgan's Kinexys infrastructure. Three weeks earlier, DTCC reported completed production trades with tokenized securities, including collateral and settlement transactions. DTCC's broader service launch remains scheduled for October. BlackRock's announcement and DTCC's July 15 release describe different stages of that work.
For AI agents, the significance goes beyond another way to pay. Software entrusted with a company's finances could eventually coordinate the assets behind its payments: cash reserved for invoices, fund shares held between expenses, and securities pledged against obligations. The opportunity is to connect decisions that often require separate instructions and records.
That is our analysis of where these developments could lead. The announcements do not establish that an autonomous AI treasurer is running those institutions' money. They establish a growing set of assets and transactions that software can address, under institutional controls.
The difficult part is deciding what an agent may do with them. A token that moves at midnight may still be an investment that cannot supply the cash needed at midnight.
Three meanings of tokenization
In card payments, tokenization usually replaces an account number with a restricted substitute credential. It helps protect payment details. It does not create an investment or a new balance of money. EMVCo explains that mechanism.
Tokenized money concerns the payment asset: for example, a deposit represented on a programmable system. Tokenized securities concern an investment or ownership claim represented there. The BIS describes the possibility of bringing money and financial assets onto programmable infrastructure so that their associated transactions can be coordinated. Its 2025 analysis provides the architectural argument, rather than evidence that every market already works this way.
A money market fund token belongs in the investment category. Securitize's July 30 announcement about BlackRock's BUIDL fund on Tempo explicitly says the shares are not stablecoins. They represent an interest in the private fund, without giving the holder a direct claim on each Treasury bill in its portfolio. The disclosure establishes what an agent would be holding on its owner's behalf.
Live funds, different permissions
BlackRock's new ICS share classes illustrate how a blockchain can extend an existing fund. Tokens move between approved investor wallets, while the official shareholder register remains within the fund's transfer-agent infrastructure. Kinexys connects those records with on-chain activity. BlackRock describes round-the-clock peer transfers; that statement concerns movement of shares, not an unconditional promise of immediate cash redemption. The product announcement also identifies eligible markets and investors.
Other models have different access rules. Franklin Templeton's Franklin OnChain U.S. Government Money Fund launched in 2021 as a U.S.-registered fund using a public blockchain for its official ownership record. Its April 2026 anniversary release describes peer transfers and distribution of dividends every day, including weekends, with access through its Benji channels. This is an operating product with a history, rather than a newly proposed treasury experiment. Franklin's account also warns that the fund's targeted one-dollar share value is not guaranteed.
J.P. Morgan Asset Management's MONY, announced in December 2025, is a private placement for qualified investors, available through Morgan Money. Its launch describes Treasury and Treasury-backed repo investments, plus potential wider collateral uses. Potential acceptance as collateral should not be read as acceptance by every lender. The MONY announcement makes the restricted investor audience explicit.
These differences shape any agent product built on top. Software cannot turn a restricted offering into a retail product, admit an unapproved recipient, or make one fund's transfer rules apply to another.
What a delegated treasury agent might actually do
Consider a hypothetical business that has already selected its banks, approved investments and custody arrangements. It wants software to help manage a cash buffer while preparing for supplier payments. This is a design example, not a customer deployment we observed.
The agent first reads the company's obligations: amounts, currencies, deadlines and the accounts from which payments must arrive. It checks balances against a minimum cash reserve and flags uncertainty in forecasts. A model might interpret an invoice or explain a projected shortfall. An execution system then enforces the company's limits independently of that interpretation.
If the company permits investment of a surplus, the agent could propose a subscription to an approved tokenized fund. Before execution, the system would check investor eligibility, the correct wallet, concentration limits, authorized signers and the amount that must stay available for near-term expenses. A persuasive explanation from the model would not substitute for those checks.
When a supplier payment approaches, the agent has to work backward from usable cash. Does the company need to redeem shares? Is an approved counterparty willing to buy them? When will the proceeds reach the account or payment instrument that the supplier accepts? A completed share transfer answers none of those questions by itself.
The agent should also recognize an exception. A delayed redemption, rejected recipient or stale balance should trigger a defined fallback and an accountable human decision. Repeatedly attempting the same transaction could make matters worse, especially if it creates duplicate instructions across systems.
This is where AI could add value: interpreting obligations and coordinating a permitted sequence. Most of the protection comes from clear authority, reliable records and limits on execution. Those responsibilities survive every improvement in the model.

Settlement and collateral are more than faster transfers
Delivery versus payment links delivery of an asset to its payment. Programmable systems can make that coordination more direct, reducing the possibility that one side completes while the other fails. That is one of the mechanisms discussed in the BIS's financial-system analysis.
A useful way to see the distinction is to separate three questions. Can the security move? Will the counterparty accept it for this obligation? Can the agreed exchange complete under the required conditions? A network may answer the first while leaving work on the other two.
DTCC's July production transactions included securities lending, collateral pledges, Treasury/repo settlement and central-counterparty margin workflows. These are meaningful demonstrations with actual assets. The release nevertheless places the general service launch in October 2026, after this article's September 22 research date. Completed transactions and broad availability remain separate claims.
For an agent, collateral introduces another set of instructions. It might identify an eligible holding and request that it be pledged under an existing agreement. It would still need the counterparty's rules, valuation, applicable discount and release conditions. A share useful as collateral may be unavailable for another purpose while pledged.
The potential benefit is less time and effort coordinating assets already owned. Tokenization alone supplies neither a willing lender nor an obligation to accept the asset at its displayed value.
The missing connections are being tested
An agent managing a real business cannot assume all its institutions share one ledger. It may have to coordinate a fund administrator, bank, custodian and payment network, each with different operating rules.
Swift's January 2026 work with BNP Paribas Securities Services, Intesa Sanpaolo and Societe Generale-FORGE tested tokenized bond transactions, including payment, interest and redemption. Fiat money and the EURCV stablecoin were used in the trial. Its significance is the attempt to connect an asset's lifecycle with existing institutions, not proof that a universal securities service is available. Swift describes the trial and its participants.
Project Agorá addresses another part of that connection: tokenized bank deposits and central-bank money for cross-border settlement. BIS reports that controlled real-value testing in July 2026 involved 28 institutions and roughly CHF800,000. Its prototype used defined operating windows and human approval steps. BIS expressly distinguishes it from a finished product. The project's status is promising evidence of feasibility, not a service-level commitment a company can plug into its treasury plan.
For an AI system, the distinction is practical. A successful test says a route may be technically possible. A usable route requires known participants, operating arrangements, exception handling and someone responsible when an instruction goes missing. Product teams need those details before an agent can depend on the route to meet a deadline.
Ownership, custody and the power to intervene
The legal claim and its record deserve the same attention as transaction speed. In BUIDL's case, Securitize describes investor onboarding, wallet approval and restrictions on subscriptions, transfers and redemptions. The fund is not a bank deposit; its disclosure includes loss, liquidity and technology risks. Those conditions are part of the product, not obstacles an agent should try to bypass.
DTCC's service design likewise includes institutional controls. Its product page describes minting and burning tokens, pausing activity and clawback capabilities. The planned control structure makes clear that this is a managed securities system.
Such powers can support recovery and compliance. They also create dependencies: who can intervene, under what authority, and how quickly can a legitimate holder resolve an error? An agent's transaction log needs to distinguish an intended action, a submitted instruction and the authoritative record of its completion.
Custody adds a related decision. A company should specify whether its agent can only propose actions, can send bounded instructions to a custodian, or can trigger signing through an approved execution system. Permission to explain a portfolio is much narrower than permission to move it. Access should be revocable without losing the records needed to reconcile outstanding obligations.
The BIS and CPMI's tokenization report provides a useful general warning: established financial-infrastructure risks can persist in different forms, making governance and risk management essential. Their assessment does not support treating a new ledger as a clean start without institutional responsibilities.
Measuring the cost of meeting an obligation
A treasury team might welcome fewer reconciliations, more timely collateral movements and a clearer view of where its holdings are. Those are plausible operational benefits. Establishing them requires measurements across the entire transaction, including the steps outside the blockchain.
The useful comparison is the cost and reliability of meeting the same obligation through existing arrangements. Fees for custody, fund administration, execution, conversion and integration belong in that comparison. So do staff time, exception rates and the cost of maintaining sufficient immediately usable cash. A fund's displayed yield cannot answer the question alone.
Liquidity requires equal care. A transferable token does not conjure a buyer during stress, and a frequently updated valuation does not guarantee an executable price. An agent asked to maximize returns could produce a plan that looks efficient until several payments fall due together. A better mandate specifies the obligations it must be able to meet and the conditions under which it must stop.
The route to adoption may also run through familiar distribution systems. On September 16, DTCC announced that Ondo subsidiary Oasis Pro Markets had joined Fund/SERV. The announcement concerns connectivity to established fund-processing and distribution infrastructure, including information and reporting flows. It is an integration milestone, not evidence that tokenized funds have already become a mass-market treasury default.
That path could make adoption less disruptive. It could also concentrate influence in firms controlling approved assets, custody and distribution. Whether smaller businesses benefit will depend on access and total costs, not merely on whether the underlying network is public.
What would make the optimistic case convincing?
The optimistic case is specific: a business authorizes a limited treasury mandate, and software meets it with less manual coordination, better visibility and fewer avoidable failures. Tokenized assets could make more of the underlying operations programmable. AI could help interpret the messy commercial context around them.
The pessimistic case is equally concrete. Institutions add another technical layer while customers retain the same delays, incur extra fees and struggle to identify who owns a failed instruction. Software moves faster than its authority or its understanding of the asset's conditions.
Evidence that separates those futures would include completed end-to-end redemption times, cash availability at the destination, reconciliation effort, exception rates and recovery from mistakes. Public demonstrations of ordinary transactions are useful. Measured handling of difficult transactions would be more revealing.
Our first article examines AI agents and card payments; the second examines how agents should choose between forms of money. Tokenized assets extend that discussion to what a business holds between payments. A treasury agent would need to distinguish an asset it can move from money it can actually use, and keep its actions within the authority its owner granted.



