scaling trustcommunity

Building the Scaling Trust portfolio

How the portfolio fits together and what comes next.

The Scaling Trust Team · October 7, 2026 · 6 min read

AI agents are increasingly writing software, making purchases, and operating robots and machinery. Yet they struggle to interact in multi-principal, multi-agent settings where some agents may be untrustworthy, information asymmetry exists, and parties may have opposing goals. Decades ago, technologies such as encryption and digital signatures provided the foundations for trust between parties online, enabling the digital economy to thrive. Now, new technologies are needed to build the trust infrastructure for the agentic era.

Scaling Trust is ARIA’s £50m programme to build them: the frontier infrastructure and fundamental research for AI agents to coordinate securely on our behalf, across digital and physical worlds.

Success could mean AI agents can be trusted to act reliably on behalf of people and businesses, from negotiating deals to coordinating supply chains, opening up economic and social opportunities that are currently too risky to pursue. It could help people and businesses delegate more to agents with confidence, open up new forms of trade and collaboration that are currently out of reach, such as cyber-physical markets, and distribute the benefits of artificial intelligence as widely as possible, while helping people retain choice over the infrastructure their agents depend on.

Today we announced our first Scaling Trust Creators. Below you’ll find more about the programme’s structure, a map of the portfolio, and some ideas on what we think is still missing from it. We fund new teams every quarter, so consider the map a snapshot!

Portfolio Structure

Scaling Trust has three connected tracks, moving between theory, implementation, and experimental evidence.

Track 1: the Arena. A cyber-physical environment for evaluating agents owned by different people as they pursue open-ended, long-horizon economic tasks under adversarial pressure. See our September update on the Arena.

Track 2: the cyber-physical agent stack. An open-source stack for trustworthy agents spanning the digital and physical worlds: agent harnesses, secure protocol reasoners, but also tools for agents to use such as secure hardware and tamper proof sensors.

Track 3: fundamental theory. The science beneath the stack, including formal AI security, autonomous protocol generation, protocols for physical verification (both using trusted hardware or harnessing the properties of the physical world, which we call nature cryptography).

We made a map of how the portfolio fits together, divided by the programme tracks. It shows the teams awarded grants from our first solicitation, and the gaps still open for future solicitations.

Track 1Arenaevidence
Arena partners
Environment & challenge design
Physical build & operations
Security & red teaming
Community partners
Industry partners
Track 2Cyber-physical agent stackimplementation
Digital partners
Open-source practice, use cases
Digital stack
Agents · agentic loop
Agents · new models
Agents · negotiation
Tools · TEE sandbox, auditing
Integration
Glues the stack together
Physical stack
Physical verification · bridges, sensors, actuators
Physical environments · evals, benchmarks, harness
Cyber-physical partners
Real-world data and environments
Track 3Fundamental theorytheory
Theory of secure agent interaction
Generative security
Formal AI security
Secure agent interaction
Cyber-physical bridges
Physical verification theory
Secure hardware
Nature cryptography
Physical environments · evals, world models
The current portfolio on the same three-track skeleton introduced above. Hover or tap a project for what it will produce and how. Rounded cards are funded projects; square-cornered cards are partners, including Matta, a funded Creator in a partner role. Slots follow the programme's working portfolio map; empty cubes are functions with room for more teams. The Arena partnerships and the EPFL project are subject to contract.

Commentary

Several bets on the digital stack

We do not yet know the best architecture for secure agent coordination, so we are backing several approaches in parallel. Some work on the protocols agents use, from specifying and designing them to auditing them; others work on the agents themselves:

Integration across the stack

Ultimately, many different components are being built, and someone needs to glue them together in useful ways and work on their integration. That is the role of CCTI, our first integration partner: mapping how Creators’ work fits together, co-developing shared building blocks, and combining the pieces into an end-to-end application that shows where interfaces are missing.

Partners sit at either edge of the stack. Matta grounds the physical side in real manufacturing data; on the digital side, the slots for open-source practice and real use cases are still open. If you maintain open-source infrastructure, operate a real environment, or have a use case that needs agents to coordinate securely, reach out!

The Arena and the rest of the programme

We expect much of what Creators build to be put to work in the Arena, where agents run organisations that trade, make payments, and operate machines under adversarial pressure. In turn, the Arena will open up new needs for the rest of the programme.

Say an agent running one Arena organisation buys a part made by another. Using technology developed by CCTI, the seller could prove the part was produced to the agreed specification; with physical watermarking, the buyer could check which controller the robot making it was actually running.Martin Kleppmann describes this scenario, and how CCTI plans to make it work, in his announcement of CCTI. If red teams then trick the buyer’s agent into overpaying or leaking its budget, that failure points to what we should fund next.

Open source by default

Everything we fund is open source by default. People need to be able to inspect, test, and improve infrastructure they are being asked to trust, and to run, adapt, or replace the infrastructure their agents depend on. ARIA is funding the first versions, but open source lets a global community develop, maintain, and use them long after. We want to build this together.

What is still missing

Our first Creators are the nucleus of the portfolio, and we will keep building around them; the empty slots on the map show where there is room. We fund new teams every quarter through our rolling solicitation for Tracks 2 and 3, and the current round closes on 31 October.Teams funded through our joint call with Google DeepMind, the Cooperative AI Foundation and Schmidt Sciences will join this portfolio. Separately, ARIA’s Opportunity Seeds fund related projects outside the programme. We will announce both soon. If you see a slot you could fill, or one we have not drawn yet, we encourage you to apply.

Below are some directions we have been thinking about. They are not prescriptive, just areas we think could be interesting. Keep an eye out on our blog for other ideas as they come up!

Track 2: the cyber-physical agent stack

Track 3: fundamental theory