Private agents turn zero knowledge into a policy question
Midnight's agent test and proposed Policy Vaults focus attention on enforceable limits, but a concept is not yet production evidence.

Midnight says a USDM-branded ATM is live in Midnight City for agents to test on its Preview Network. The careful reading is test infrastructure in a preview environment, not a production payment system. The cited excerpt establishes the machine and intended agent testing; it does not establish transaction volume, autonomous customer use or financial performance.
A separate Midnight statement says Policy Vaults could give AI agents predefined risk limits enforced in real time, with zero-knowledge proofs making compliance verifiable without exposing proprietary logic. The word could matters. The post describes a proposed design direction, and the briefing itself says the idea may still be at a concept or demonstration stage. It should not be reported as deployed control.
Other project updates are useful mostly as boundaries. Polygon's cited message concerns continuous onchain availability rather than a ZK release, while the briefing says its recent attention also included flood-relief fundraising. Ronin material is described as game-event coverage. Their presence in the same coverage does not provide evidence about zero-knowledge engineering and should not be used to inflate the category.
The core operating problem is how an agent proves it stayed inside a rule without exposing the entire strategy. A proof can help attest to a defined condition, but the policy still needs an owner, sound inputs and a response when execution diverges. Privacy cannot substitute for accountability, and autonomous decision-making is not itself a safety model.
Signed authorization and policy proofs answer different questions: whether an action was permitted and whether it met a defined rule. A proposed agent system would need both boundaries to be explicit.
The next evidence should be a constrained trial with published rules, failure cases and independently inspectable results. If a system can reject actions outside policy while preserving necessary confidentiality, the concept can advance toward credible control. If proofs cover only a narrow condition or the input source remains manipulable, operators should revise the design before assigning real authority.