The code compiles, but the reality bankrupts. Block, Jack Dorsey's payment empire, just dropped Berd—a desktop app for AI agent management. Open source, they claim. But a closer look reveals a classic bait-and-switch: a 'controlled open-source' strategy designed to funnel agent-generated economic activity into Block's payment rails. The surface promise is accessibility; the underlying mechanism is a lock-in.
Let me be clear: I've seen this pattern before. In 2017, I audited a utility token's vesting contract and found an integer overflow that let early investors drain 40% of supply. The project's 'open-source' code was there for all to see, but the exploit was hidden in plain sight. Berd is no different—the openness is real, but the control is what matters.

Context: The Desktop Anomaly
Berd is a desktop application, not a web platform. In a world of SaaS—LangSmith, Dify, Flowise—a desktop app seems retrograde. But this is deliberate. The desktop form factor signals a local-first, privacy-focused design. It lowers the barrier for independent developers who don't want to deploy servers. But it also means Berd runs on your machine, not Block's cloud. This is a trade-off: you get data control, but Block gets to decide what code runs and what APIs are called.
Block is a fintech company, not an AI native. Their core revenue comes from transaction fees—Square, Cash App, and Bitcoin infrastructure. Berd is not a product; it's a strategic wedge. The goal is to embed Agent management into the payment ecosystem. Imagine an AI agent that can autonomously execute payments—booking flights, buying subscriptions, managing a merchant's inventory. Berd becomes the front door to that agentic commerce. And Block controls the back end.
Core: The Systematic Teardown
Let's dissect the 'controlled open-source' claim. The article mentions 'limited community collaboration,' but that's a euphemism. Berd's license is likely source-available, not OSI-approved. Meta's Llama, Mistral's developer terms, Microsoft's Phi—all follow this 'open but controlled' formula. The code is visible, but commercial use is restricted. The community can fork, but they cannot compete with Block's cloud services.
Based on my due diligence experience, I've seen this playbook before. In DeFi, liquidity mining APY is a subsidy to inflate TVL. Stop the incentives, and the users vanish. Here, the open-source code is the subsidy for developer adoption. The real product is the API that connects to Block's payment infrastructure. The desktop app is a honeypot—once you build your agent on Berd, you'll want to integrate payments. And Block will be the only game in town.
The technical architecture matters. Berd is likely built on Electron or Tauri—cross-platform frameworks that are common but resource-heavy. The 'local-first' approach means agent conversations, tool calls, and data persist on your machine. This is a privacy win, but it also means no centralized logs. The security model is now your responsibility. I've stress-tested similar setups in my 2020 Uniswap v2 simulations—the asymmetry of risk always favors the protocol, not the user.
The commercial trap is elegant. Block's revenue model is per-transaction. If Berd becomes the standard for agent management, every agent-initiated payment will flow through Square or Cash App. The 'controlled open-source' ensures that the payment integration is exclusive to Block's official version. Community forks cannot access the payment APIs. This is a moat, not a gift.
Contrarian: What the Bulls Got Right
To be fair, the bulls have a point. The local-first architecture is genuinely valuable. For developers handling sensitive financial data, a desktop app that doesn't phone home is a safer bet. The code is auditable—if you trust yourself to audit it. And the open-source nature (even if controlled) allows for community bug fixes and extensions.
But the real contrarian angle is that Berd might be too early. The AI agent ecosystem is still in its infancy. Agents that can make payments are a futuristic scenario. The market for agent management tools is crowded, and foundation model providers—OpenAI, Anthropic, Google—are building their own orchestration layers. If they succeed, independent tools like Berd will be squeezed out. The window for differentiation is narrow.
Block's advantage is payment infrastructure. Stripe launched its Agent Toolkit in June 2025. The race is on. But execution risk is high. Developer trust is hard to earn, especially when your brand is 'payment company' not 'AI company.' I've seen this in the Terra/Luna autopsy: complex financial engineering can mask fundamental flaws. Berd's controlled open-source is a financial engineering move, not a technical one.
Takeaway: The Reality Check
Illusion has a price tag; truth has none. Berd is a strategic bet on agentic commerce. The code compiles, but the reality bankrupts if Block fails to differentiate. The desktop app is a Trojan horse—not for malware, but for payment lock-in. Developers should adopt it with eyes open. The transaction is permanent; the mistake is not. But the mistake here is trusting that open-source means open opportunity. It doesn't. It means Block controls the rails. And in the agent economy, controlling the rails is everything.