AI agents outnumber humans 150:1, forcing fintech to reinvent trust and identity

The gist
AI agents now outnumber humans 150 to 1 in fintech, forcing the industry to rewrite the rules of trust, identity, and fraud prevention on the fly.
What to know
- Stripe and OpenAI’s Agentic Commerce Protocol lets ChatGPT autonomously buy from major merchants like Etsy and Glossier with Shared Payment Tokens, launching a new era of AI-driven transactions.
- Traditional identity systems are buckling under the surge of non-human AI agents—outpacing humans by as much as 150:1—driving security leaders to embrace just-in-time, intent-based authorization frameworks.
- New Know Your Agent (KYA) standards, backed by Experian, Visa, and Mastercard, are racing to secure an agentic commerce market already worth over $1 trillion—and stem fraud losses topping $15 billion a year.
Stripe, OpenAI Redefine Payments
Stripe and OpenAI's Agentic Commerce Protocol is transforming e-commerce by allowing AI agents to act as autonomous buyers, standardizing transactions and setting the stage for a competitive race among tech giants to dominate agent-driven commerce.
In October 2025, Stripe and OpenAI jointly launched the Agentic Commerce Protocol (ACP), a pioneering framework that empowers ChatGPT to act as an autonomous buyer using Shared Payment Tokens (SPTs). This innovation enables US users to make direct purchases from Etsy and soon Shopify merchants like Glossier and SKIMS within the chat interface, with SPTs securely scoped to specific merchants and transaction amounts to protect payment credentials. This collaboration extends Stripe’s role as a foundational economic infrastructure provider for AI commerce, building on their earlier partnership since 2023 that powered ChatGPT Plus subscriptions.
ACP represents a critical step toward standardizing AI-driven commerce by providing businesses with a single integration point rather than managing multiple connections to various AI agents. By November 2025, ACP had matured to include core components such as a unified catalog schema, risk signals, and integration with Stripe’s Link product—which boasts over 200 million consumers and accounts for 58% of Lovable’s revenue—serving as a secure wallet for agent credentials. This standardization not only streamlines merchant participation but also enhances transaction security and fraud mitigation through features like Stripe Radar and compatibility with Mastercard’s agentic tokens.
The rapid emergence of ACP closely followed Google's Agent Payments Protocol announcement, underscoring an intense competitive push among Big Tech to establish agentic commerce infrastructure. Stripe’s strategic pivot from traditional payments to building broader economic infrastructure for AI commerce leverages its processing of approximately $1.4 trillion annually—about 1.3% of global GDP—highlighting the scale and ambition behind enabling AI agents to autonomously conduct transactions. This evolution is driven by Stripe’s specialized Data and AI teams, which have been investing in AI and large language model experiences since early 2023 to create safe, production-grade AI commerce capabilities.
Legacy Security Buckles Under AI
The explosive growth of AI agents has rendered human-centric security controls obsolete, exposing organizations to rampant overpermissioning and shadow AI risks that legacy IAM systems cannot handle.
By early 2026, it became clear that traditional human oversight was ill-suited to manage the security risks posed by autonomous AI agents operating at unprecedented speeds. The Anthropic espionage campaign exemplified this challenge, executing 80-90% of tactical operations without human intervention at 'physically impossible request rates,' leading experts to emphasize that authorization scope—not human-in-the-loop controls—must serve as the primary security boundary. This shift highlights a fundamental mismatch between rapid fault propagation across multi-agent systems and the limited capacity of humans to respond effectively, underscoring the need for more precise, automated access and privilege management frameworks.
The explosion of AI agents as non-human identities (NHIs) has overwhelmed legacy identity and access management (IAM) systems, which were originally designed for predictable human behavior and static service accounts. Surveys reveal that NHIs now outnumber human identities by ratios ranging from 15:1 to as high as 150:1 in high-tech environments, with 79% of IT professionals feeling ill-equipped to prevent attacks via these identities. Traditional controls like multi-factor authentication are often bypassed for speed, leading to insecure practices such as hard-coded credentials, while shadow AI—agents created without security team knowledge—further expands the attack surface, with 82% of organizations discovering unauthorized AI agents and 65% experiencing related security incidents.
The inadequacy of existing IAM and privileged access management (PAM) systems is compounded by the non-deterministic, high-velocity, and autonomous nature of AI agents, which frequently chain actions across systems and operate beyond traditional delegation and audit assumptions. This results in systemic overpermissioning, blurred accountability, and expanded blast radii, as agents often retain static, long-lived credentials with excessive privileges. Experts like Nancy Wang of 1Password stress that least privilege must evolve into dynamic, task-scoped authorization with automatic expiration, while emerging frameworks such as NIST’s Zero Trust Architecture explicitly recognize AI agents as untrusted until authenticated and authorized, signaling a critical need for new identity governance models tailored to agentic environments.
Governance gaps remain the Achilles’ heel of AI agent security, as organizations struggle with fragmented identity management, unclear ownership, and insufficient automated lifecycle controls. Despite advances like Nvidia’s agentic AI stack integrating multi-layered security and the IETF’s Agent Identity Management System (AIMS) draft addressing authentication, authorization remains largely unresolved, leaving enterprises vulnerable to risks such as prompt injection, jailbreaking, and data poisoning. Industry leaders urge rigorous auditing using layered security frameworks and advocate for continuous, context-aware authorization that ties identity-layer governance to runtime intent evaluation, behavioral monitoring, and dynamic intervention—essential steps to prevent costly operational failures and legal liabilities exemplified by incidents like unauthorized airline ticket issuance by rogue AI agents.
Dynamic Trust for AI Agents
Ephemeral, intent-based authorization and agent-specific access platforms are replacing static credentials, ushering in a new era of continuous, contextual security for autonomous AI operations.
By early 2026, the emergence of Just-in-Time Trust (JIT Trust) marked a pivotal evolution in securing agentic AI systems, replacing static, long-lived credentials with ephemeral, self-destructing Ephemeral Access Grants (EAGs) and continuous intent-based risk scoring. This adaptive model, championed in analyses and adopted by vendors like Oasis Security and Cyata, transforms traditional access control into dynamic, behavior-dependent governance that prevents lateral movement by continuously validating an agent’s actions against declared or predicted goals. As Nancy Wang emphasized, this shift from binary allow/deny to continuous, contextual authorization is critical to neutralizing threats such as autonomous compromise and adversarial hijacking in AI-driven enterprises.
Agentic Identity Access Platforms (AIAPs) have crystallized as the new security architecture for AI agents, functioning as centralized brokers—akin to a 'new SSO for Agents'—that standardize access requests, translate intent into deterministic authorization, and enforce ephemeral, scoped permissions throughout the agent’s lifecycle. This four-phase operational model, encompassing discovery, intent translation, brokering, and runtime enforcement, is exemplified by leading vendors such as Cyata, Oasis Security, Astrix, and Okta, each differentiating through deep visibility across endpoints and cloud environments, real-time enforcement capturing context and intent, and enhanced user awareness. For instance, Cyata’s platform rapidly adapts to new agent frameworks like Antigravity, while Oasis decouples intent, policy, and credential issuance into auditable control flows tailored for AI’s probabilistic nature.
The security community recognizes that AI agents pose unique challenges distinct from traditional human or machine identities, necessitating governance models that treat agents as first-class, non-deterministic identities with dynamic, task-specific permissions. Platforms like Aembit and Silverfort emphasize blended identity models that combine agent and user context to prevent impersonation and rights inflation, while enforcing zero standing privileges and immediate revocation. Moreover, the rise of agent-to-agent (A2A) protocols introduces new trust boundaries requiring workflow governance to manage delegation and verification, reflecting a broader industry shift toward continuous, context-aware authorization that integrates identity lineage, runtime behavioral analysis, and kill-switch capabilities to maintain control over autonomous AI operations.
Industry momentum toward comprehensive agentic identity governance is accelerating through collaborative efforts and innovative solutions that address visibility, policy enforcement, and runtime security. Initiatives like the IETF’s Agent Identity Management System (AIMS) standardize authentication layers while leaving authorization open, prompting vendors such as Okta, Lumia, and Teleport to develop platforms that integrate discovery, intent-aware authorization, and ephemeral credentialing. Meanwhile, open-source projects like Bitwarden’s Agent Access SDK promote community-driven models for just-in-time credential access. This ecosystem evolution is underscored by the urgent need to bridge legacy identity debt, enforce separation of duties, and implement continuous observability to manage the explosive growth of AI agents—estimated in the millions globally—ensuring that enterprises can govern autonomous workflows without sacrificing agility or security.
KYA Protocols Anchor Agent Trust
Know Your Agent frameworks, backed by cryptographic identity and real-time governance from industry leaders, are becoming essential for verifying, auditing, and holding autonomous AI agents accountable in trillion-dollar commerce ecosystems.
The emergence of Know Your Agent (KYA) protocols is foundational to establishing trust and identity verification for AI agents in agentic commerce, mirroring traditional human KYC but tailored for autonomous software actors. These protocols incorporate cryptographic identity elements such as signature keys that link agents to their creators—be they individuals, companies, or DAOs—and define permissions, constraints, and accountability. Projects like Billions Network, cheqd, and Vouched exemplify early efforts to build these cryptographic identity frameworks, which are critical for assigning responsibility and enabling secure, auditable transactions in decentralized, agent-to-agent commerce environments.
By early 2026, industry leaders including Experian, Visa, and Mastercard had advanced comprehensive agent trust frameworks integrating cryptographic verification, real-time authorization, and identity governance to address the complex challenges posed by AI agents acting autonomously in financial ecosystems. Experian’s Agent Trust™, launched in April 2026 in partnership with Visa, Cloudflare, and Skyfire, exemplifies this approach with features like Human-to-Agent Binding, real-time trust tokens, and an Agent Registry designed to ensure legitimacy and combat fraud. Mastercard’s AI-driven multi-signal fraud detection and Visa’s Agent Score and Agentic Directory further enhance trust by continuously validating agent identity and transaction legitimacy, reflecting a rapid industry response to the urgent need for scalable, auditable trust infrastructure.
The evolution of agentic commerce has spurred the development of layered security and identity verification ecosystems that extend beyond static credentials to include continuous, real-time validation of AI agents’ operational state and permissions. Collaborations such as Experian’s partnership with Akamai add an edge security layer that evaluates both human and agent-driven traffic in real time, while protocols like Proof’s x401 and Skyfire’s tokenized identity credentials enable cryptographically secure, privacy-preserving linkage of agents to verified humans or licensed entities. This dynamic trust stack is essential to mitigate risks of unauthorized transactions, fraud, and accountability gaps, especially as AI agents rapidly proliferate—OpenClaw alone amassed 1.5 million transacting agents within weeks—highlighting the critical need for robust, auditable frameworks that maintain security without sacrificing performance or user experience.
Regulatory momentum worldwide underscores the strategic importance of KYA infrastructure, with mandates like the EU AI Act requiring operator identity logging for high-risk AI systems, the U.S. NIST prioritizing agent identity management standards, and Singapore issuing a national agentic AI governance framework. This regulatory landscape, coupled with the competitive development of multiple KYA standards—such as ERC-8004’s NFT-based AgentID, Visa’s TAP with triple-signature verification, Trulioo’s SSL CA-like issuance, and Sumsub’s compliance overlay—signals that possessing robust, interoperable KYA capabilities will be decisive for market participation. As Kim Slaughter of Experian notes, 'Agentic commerce will not scale without trust,' and the establishment of these frameworks will determine which AI agents and platforms can safely and compliantly engage in the burgeoning multi-trillion-dollar agentic economy.
Big Tech Unites on Agent Governance
Tech giants and industry coalitions are racing to define shared standards and operationalize agent identity governance, as autonomous AI agents reshape commerce and expose new systemic risks.
By early 2026, the industry recognized an urgent need for shared standards and governance frameworks to manage AI agent identities securely, prompting coalitions of tech giants like Microsoft, IBM, Google, and Anthropic to collaborate on defining best practices and influencing regulatory requirements. This collective effort extends beyond individual enterprises to address supply chain vulnerabilities, emphasizing policies that govern trusted models and communication boundaries to prevent systemic risks, as highlighted by experts advocating for just-in-time credentials, continuous authentication, and strict separation of duties to mitigate AI agent risks.
Strategic collaborations have become pivotal in operationalizing agentic AI identity governance, exemplified by SailPoint's multi-year partnership with AWS to unify identity governance across human and AI agents, and Experian's launch of Agent Trust in alliance with Visa, Cloudflare, and Skyfire to authenticate AI agents and enable secure autonomous transactions. These initiatives incorporate advanced features like Human-to-Agent Binding, real-time trust tokens, and edge security layers, collectively forming a robust trust ecosystem that addresses fraud risks estimated at $15–$19 billion annually and supports scalable AI commerce.
The adoption of agentic commerce protocols has accelerated rapidly, with major brands such as Best Buy, Coach, and JD Sports, alongside commerce platforms like Shopify and Wix, integrating Stripe’s Agent Commerce Protocol to enable AI agents to autonomously transact and collaborate across blockchain ecosystems. This broad uptake is complemented by AI leaders including Google, Microsoft, OpenAI, and Gemini embedding agentic capabilities, signaling a multi-dimensional ecosystem where agent-to-agent transactions promise to transform market dynamics by enhancing efficiency and competition, although such transactions remain emergent.
Regulatory alignment and governance frameworks are rapidly evolving worldwide to keep pace with agentic AI adoption, with the EU AI Act, US NIST standards, and Singapore’s national framework leading efforts to enforce interoperability, accountability, and payment transparency. Initiatives like Entrust’s Agentic AI Trust Accelerator and PlainID’s Policy 360 platform are addressing governance gaps in regulated sectors by centralizing identity and access controls for humans and AI agents, while emerging Know Your Agent (KYA) standards and protocols—championed by companies like Proof, Akamai, and Visa—are establishing cryptographic identity verification as a market entry barrier, crucial for trust and compliance in the burgeoning $1 trillion-plus agentic commerce market projected by 2030.
New Maturity Model for AI Identity
A six-stage maturity model is emerging as the industry benchmark for managing non-human identities, demanding continuous monitoring and lifecycle controls to address the unprecedented risks of agentic AI.
By mid-2026, the cybersecurity community coalesced around a comprehensive six-stage maturity model specifically designed for non-human and agent-based identities (NHIs), recognizing that traditional IAM frameworks were ill-equipped to manage the unbounded identity scope introduced by agentic AI. This model establishes six baseline requirements that must be met to responsibly deploy AI agents, reflecting a growing consensus among industry and government bodies—including OWASP’s GenAI Security Project and CISA’s Five Eyes advisory—that identity and privilege abuse represent the foremost risks in agentic AI environments.
Central to the maturity model is the imperative for continuous monitoring and rigorous lifecycle governance, mandating unique, attributable non-human identities for each agent, permissioning through on-behalf-of models, ephemeral credentials, and exhaustive audit trails integrated with SIEM systems. These controls address the dynamic and autonomous nature of AI agents, ensuring accountability and minimizing privilege escalation risks that traditional IAM stacks—often lacking such capabilities—cannot adequately mitigate.
As AI adoption accelerates, organizations face a strategic imperative to embed agentic identity governance as a foundational security layer, transcending legacy IAM and PAM platforms that were not architected for agentic scale or complexity. While technically feasible on modern identity platforms, widespread implementation remains nascent, underscoring a critical gap between emerging standards—such as NIST’s AI Agent Standards Initiative launched in early 2026—and enterprise readiness to defend against evolving identity threats posed by autonomous AI commerce.













