AI agents get secure IDs for commerce

Bankless ↗

The gist

AI agents are getting permanent, secure IDs and bulletproof governance as agentic commerce explodes, forcing industry titans to build a new trust fabric for autonomous transactions.

What to know

  • Pilot Protocol rolled out a zero-trust network assigning 48-bit encrypted addresses to over 30,000 AI agents in just two weeks, kickstarting a self-organizing agent economy.
  • By mid-2026, JumpCloud and Experian launched unified identity frameworks—like Agentic IAM and 'Agent Trust'—to bind AI agents to humans and enforce real-time, zero-trust governance.
  • Financial giants including Amex, Visa, and PayPal now require agent registration, programmable guardrails, and human-in-the-loop oversight, with agent-driven U.S. commerce projected to hit $1 trillion by 2030.

Blueprints for Agentic Internet

A new cryptographic infrastructure—mirroring the early web's DNS and certificate authorities—is powering self-organizing, autonomous AI agents with decentralized, secure identities and seamless peer-to-peer communication.

Building foundational infrastructure for autonomous AI agents mirrors the early architecture of the World Wide Web, requiring a DNS-like system for agent listing, cryptographically secure certifying authorities, interoperability standards, and attestation mechanisms to establish trust and identity. Unlike traditional web entities, these agents operate with significant autonomy, necessitating decentralized cryptographic methods and hierarchical trust structures to enable secure, human-independent communication and decision-making.

Precision in communication protocols is paramount to prevent misunderstandings among autonomous AI agents, as natural language exchanges risk the 'telephone game' effect. Industry leaders like OpenAI and Anthropic are already pioneering interoperability standards—OpenAI with its API standard for codecs and Anthropic with the MCP standard—reflecting a broader movement towards open, precise frameworks reminiscent of TCP/IP’s rise to ubiquity after its integration into Windows 95, which underscores the power of free, open protocols in driving widespread adoption.

Pilot Protocol exemplifies the emergence of a new foundational layer for AI agents by creating a UDP-level overlay network that assigns each agent a permanent 48-bit virtual address, enabling encrypted peer-to-peer communication across cloud providers in a zero-trust environment. This network’s autonomous growth—expanding by 10% daily with 16,000 new agents joining in a single day without marketing—demonstrates scalable, self-organizing infrastructure where agents independently discover and transact, effectively building their own secure internet beneath existing frameworks.

Beyond connectivity, Pilot Protocol is pioneering an agent-driven economy with features like an App Store facilitating over 30,000 autonomous installs of partner applications within two weeks, and upcoming agent-to-agent payments that enable machines to earn and spend credits without human financial approval. This development signals a transformative shift towards a fully autonomous machine-to-machine economy, where AI agents not only communicate securely but also engage in complex economic activities independently.

Sources
Imagination in ActionSecurity NowBriefglance

Identity Fabrics for AI Agents

Unified frameworks like Agentic IAM and 'Agent Trust' are redefining digital identity by binding AI agents to humans with real-time, zero-trust controls and provenance-aware authorization, closing critical gaps in accountability and fraud prevention.

By mid-2026, industry leaders like JumpCloud and Experian pioneered unified identity fabrics and authentication frameworks that securely bind AI agents to their human principals, enabling comprehensive lifecycle governance and trusted autonomous transactions. JumpCloud's Agentic IAM integrates Zero Trust principles with human-in-the-loop authorization to enforce fine-grained, dynamic access controls across diverse AI models and operating systems, while Experian's 'Agent Trust' framework, developed in partnership with Visa and Cloudflare, introduced the 'Know Your Agent' process featuring real-time trust tokens and an Agent Registry to combat fraud in AI-driven commerce. These innovations collectively address the critical need for visibility, accountability, and legitimacy in agentic AI ecosystems.

The ephemeral and high-velocity nature of AI agents has exposed the inadequacy of traditional human-centric identity standards, prompting a shift toward provenance-aware, zero-trust architectures that enforce just-in-time, task-specific access controls. Experts emphasize the importance of contextual signals—such as device posture and browser session data—to securely attribute actions within complex multi-agent workflows, akin to microservices architectures, thereby preventing over-privileged access and enabling dynamic, intent-aware authorization that operates in milliseconds. This paradigm shift demands cryptographic delegation mechanisms and continuous policy enforcement to maintain security and auditability in non-deterministic agent behaviors.

Emerging cryptographic frameworks and token exchange protocols, exemplified by Garantir's Agentic Security and Proof's x401 protocol, are setting new standards for securely linking AI agents to verified human identities through delegation chains and scoped permissions. Proof’s x401, launched in June 2026, uniquely addresses the legal and operational void highlighted by the 9th Circuit Court ruling on user liability by providing issuer-neutral, verifiable authorization that transcends behavioral biometrics. Meanwhile, OAuth token exchange flows demonstrated in recent case studies enable fine-grained delegation with full audit trails and human-in-the-loop escalation, reinforcing transparency and control across multi-organizational AI deployments.

Regulatory bodies and industry consortia worldwide are converging on unified identity fabrics and continuous assessment frameworks to govern AI agents, emphasizing minimum necessary access, lifecycle accountability, and interoperability. Initiatives such as Entrust’s Agentic AI Trust Accelerator and the ITU’s digital identity focus group, alongside regional pilots like Hong Kong’s GenA.I. Sandbox++ with HKT, are pioneering decentralized identifiers and zero-knowledge proofs to empower users with ownership over their data while mitigating impersonation risks. This collaborative momentum, coupled with frameworks like Google Cloud’s four rules for delegation and open standards like Chaos, underscores a collective recognition that secure, cryptographically verifiable identity and dynamic human oversight are indispensable for scaling trustworthy autonomous AI.

Sources
PR Newswire - General BusinessBusiness WireThe Stack Overflow PodcastCNCF BlogSATR

Financial Giants Forge Agent Governance

Major payment and banking leaders are embedding programmable guardrails, auditability, and real-time authorization into AI agent transactions, setting new standards for trust and liability in autonomous commerce.

By mid-2026, leading financial and commerce players such as American Express, Visa, Delta, and PayPal have collaboratively pioneered governance frameworks that address core challenges of identity verification, mandate constraints, and liability in agentic AI transactions. American Express's agent registration system for tokenized credentials and programmable guardrails exemplifies industry efforts to embed accountability and error protection, while Experian's 'Agent Trust' framework, developed with Visa and Cloudflare, extends 'Know Your Agent' protocols to ensure auditability and real-time authorization, underscoring a shift toward robust, interoperable trust infrastructures in autonomous commerce.

Governance in regulated financial environments is evolving to integrate human oversight deeply with AI autonomy, emphasizing a two-loop model where AI agents interact continuously with subject matter experts to refine decision logic and maintain compliance. Industry leaders like Infosys Finacle and banking executives stress embedding governance by design, combining zero-trust security architectures with layered controls to manage new AI risks, while Indian banking’s long-standing separation of transaction initiator and approver roles is being adapted to agentic AI to ensure accountability and immediate override capabilities without disrupting operations.

Emerging regulatory initiatives across Asia-Pacific, including the EPAA’s AI Payment Agent Liability Rulebook and Hong Kong’s GenA.I. Sandbox++, are pioneering comprehensive frameworks that bind AI agents to verified human identities using decentralized identifiers and cryptographic proofs. These efforts address critical gaps in agent identity, authorization, and cross-border interoperability, aiming to establish clear liability and trust standards as autonomous payment volumes surge—Alipay alone processed over 120 million AI-initiated transactions in a single week—highlighting the urgency of harmonized governance to foster secure and scalable agentic commerce.

Industry-wide collaborations and open standards like Proof’s x401 protocol and the Secure Technology Alliance’s Agentic Trust and Commerce Forum reflect a growing consensus that agentic AI governance must prioritize transparent identity verification, real-time authorization, and human-in-the-loop authorization to mitigate fraud and liability risks. Google Cloud’s contract-first delegation principles and Garantir’s cryptographic Agentic Security modules further demonstrate how embedding deterministic policy enforcement and multi-layered cryptographic controls can prevent unchecked AI actions, ensuring that accountability remains with human stakeholders even as AI agents gain operational autonomy.

Sources
UnchainedBusiness WireWWDPYMNTSThe AI in Business PodcastTF

Securing the Agentic Attack Surface

Zero-trust architectures, cryptographic safeguards, and just-in-time access controls are becoming essential as autonomous AI agents introduce new vectors for fraud, privilege abuse, and operational risk.

The rapid proliferation of autonomous AI agents has exposed critical security vulnerabilities stemming from their ephemeral nature and high-frequency operations, which traditional human-centric identity and access management systems fail to address. Companies like JumpCloud and Garantir have pioneered solutions integrating Zero Trust principles with human-in-the-loop authorization and cryptographic safeguards, such as FIPS-validated Hardware Security Modules, to close security attribution gaps and ensure that AI actions are verifiably linked to authenticated human identities. This approach not only mitigates risks of privilege abuse and operational errors but also enforces strict lifecycle management, addressing the alarming statistic that only 21% of organizations effectively decommission AI agents when no longer needed.

In high-stakes environments like banking and crypto markets, autonomous AI agents amplify fraud risks by enabling rapid, adaptive attacks that outpace legacy static-rule systems. Industry leaders such as Saiprakash Kodela of Fiserv-Experian and Infosys Finacle’s Sajit Vijayakumar emphasize the necessity of continuous monitoring, explainability, and multi-layered cybersecurity strategies incorporating AI-driven anomaly detection and zero-trust architectures. Particularly in crypto, where irreversible transactions occur 24/7, strict permission design, multi-signature wallets, transaction limits, and human approval for high-risk operations are indispensable to prevent catastrophic financial losses.

The dynamic and complex workflows of autonomous AI agents require a paradigm shift toward just-in-time, least-privilege access controls that mirror microservices architectures, where specialized agents perform narrowly scoped tasks under continuous provenance verification. Nancy Wang of 1Password highlights the importance of device posture and session context to establish agent origin and authority, while Google Cloud advocates for a contract-first delegation approach that breaks tasks into verifiable sub-tasks, employing advanced cryptographic techniques like zero-knowledge proofs to minimize data exposure. This layered strategy, combined with dynamic cognitive friction to challenge ambiguous instructions, ensures robust governance and accountability across multi-agent systems.

As autonomous AI agents increasingly integrate with critical infrastructure—ranging from enterprise systems to financial accounts—the attack surface expands dramatically, necessitating security frameworks that separate AI reasoning from deterministic human authorization. Ian Rogers of Digital Reviews Network stresses that relying on AI to supervise AI is insufficient; instead, external policy enforcement engines and cryptographic verification must serve as immutable checkpoints. This holistic approach embeds cybersecurity into every stage of AI deployment, transforming it from a standalone function into an integral part of digital transformation, thereby safeguarding privacy, preserving evidence, and ensuring auditability in an era where millions of AI agents operate continuously and autonomously.

Sources

Agentic Commerce Goes Mainstream

Enterprises like Amex and Experian are operationalizing agent registration, liability frameworks, and trust infrastructure—paving the way for scalable, secure AI-driven transactions across the global financial ecosystem.

By early 2026, American Express pioneered agentic commerce by integrating AI agents with robust governance controls such as agent registration and programmable guardrails, ensuring secure identity verification and transaction constraints. This innovation extended to liability frameworks where Amex assumes financial responsibility for AI agent errors, a critical move that unlocked broader enterprise adoption. Major partners including Delta, Expedia, Hilton, Stripe, and PayPal collaborated with Amex to operationalize these solutions, signaling a significant industry shift toward embedding autonomous AI agents within commerce and payments ecosystems.

Experian's launch of the 'Agent Trust' framework, developed with Visa, Cloudflare, and Skyfire, exemplifies the growing emphasis on trust infrastructure to authenticate AI agents and mitigate fraud in financial services. Their 'Know Your Agent' process and real-time trust tokens address operational efficiency and security concerns, with Chief Innovation Officer Kathleen Peters underscoring that 'Agentic commerce will not scale without trust.' This initiative, coupled with the Fiserv-Experian partnership to combat fraud by integrating proprietary debit card data with identity insights, highlights how enterprises are deploying agentic AI with governance controls to navigate the complexities introduced by AI-driven transaction dynamics.

Financial institutions are rapidly scaling agentic AI from experimentation to operational deployment, balancing automation with compliance, legacy infrastructure, and human oversight. The adoption is transforming workflows—such as multistep banking processes and compliance reviews—by automating routine tasks while maintaining real-time governance through two-loop models that enable continuous refinement of AI decision logic. Leaders emphasize that ownership and accountability frameworks, rather than technology alone, determine the pace and safety of scaling agentic AI, with platforms like Infosys Finacle enabling multi-agent collaboration and embedding cybersecurity as an integral, governance-driven function.

Industry leaders such as MasterCard and Revolut are actively exploring agentic AI with a focus on risk guardrails to manage multiple failure points including intent mismatches and scams. Innovations like intent challengers and escrow standards (e.g., Ethereum's ERC8183) are being deployed to ensure transaction integrity and secure payments, while reputation systems and economic staking models limit agents’ initial fund management capacity to build trust over time. This pragmatic approach to governance, combined with projections of agentic commerce driving up to $1 trillion in U.S. sales by 2030, underscores a collective industry effort—exemplified by initiatives like the Secure Technology Alliance’s Agentic Trust and Commerce Forum—to establish scalable, secure frameworks that transform AI agents from potential threats into competitive advantages.

Sources
UnchainedBusiness WirePYMNTSWWDPYMNTSThe AI in Business Podcast

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.