The next big problem for AI agents is identity
Economy

The next big problem for AI agents is identity

Meta’s Muse launched three weeks ago. The company’s AI books flights, negotiates bills, processes payments and manages emails, all on its own, without asking permission for each step. Millions of people now have a piece of software acting on their behalf in the real world.

Nobody has figured out what happens when it gets something wrong. That is not a small gap. That is the next big problem in AI.

As agents like Muse move from novelty to infrastructure, a question the technology industry has avoided is becoming unavoidable: when an AI agent shows up to a bank, a payment platform or an e-commerce checkout, who checks its ID? Who verifies what it is, who sent it and whether it actually has permission to do what it is trying to do? The capability arrived before anyone built the system to govern it.

The identity gap nobody planned for

The entire architecture of digital identity was built around one assumption: a person is on the other side. Someone who can log in, give consent and be held accountable. AI agents do not fit that model. They run continuously, move between services and make decisions without the user directly involved at every step.

That is the identity gap. And it is one the technology industry built its way into without a plan for getting out. A 2026 report found that only 28% of organizations can reliably trace agent actions back to a human sponsor, and fewer than a quarter have any formal strategy for managing agent identity at all.

More AI:

Animoca Brands’ Moca Network recently took a direct shot at that problem with the launch of Moca Chain, an EVM-compatible Layer 1 built specifically around agent identity. Through its AIR system, businesses can verify who an agent represents and what it has been authorized to do.

Sachi Kamiya, director of venture and growth at Sentient Foundation, told TheStreet that the core of the problem is the absence of any shared standard. “The biggest gap today is that there is no standardized framework for verifying an AI agent: who it represents, what system it is running, and what authority it has been given.”

Not every agent should have the same keys

Knowing who an agent is and knowing what it is allowed to do are two very different things.

Consider the difference between asking an agent to find a restaurant and letting it move money between bank accounts. Both are things an agent could technically handle. The consequences of getting the second one wrong are a different matter entirely.

That is the authorization problem, and it sits on top of the identity problem. A verified agent still needs limits. Those limits need to be clearly defined, easy to enforce and even easier to revoke.

Kamiya compared the challenge to bringing on a new hire. “When you first hire someone, you don’t immediately give them full access to your bank account, inbox, corporate card, and company infrastructure. You start with smaller tasks, evaluate their performance, and gradually increase their authority as trust develops.”

The same principle needs to apply to agents. Start with narrow permissions. Expand them as trust is established. Both the platform building the agent and the person deploying it share responsibility for holding that line.

One person, many agents, no map

The problem goes deeper than what any single agent is authorized to do. Most people will not run just one agent. They will run several, each handling a different part of their life. One for travel. One for shopping. Another for routine financial tasks. Each of those agents will interact with services that have no idea they all belong to the same person.

That creates a problem that is easy to underestimate. A merchant running a promotion capped at two purchases per customer has no defense if one person sends a dozen agents to take advantage of it. Fraud systems built around human behavior may not catch the pattern at all.

Ajay Patel, head of World ID and chief revenue officer at Tools for Humanity, told TheStreet the issue starts at the architectural level. “Everything we use online today was basically built with the assumption that the entity interacting with a service is a human. Agents break that assumption.”

That balance does not yet exist in any reliable form.

Solving the agent identity problem is not a one-layer job.

10'000 Hours / Getty Images

Payments will force the issue

Every part of the agent identity problem gets more urgent the moment money is involved.

An agent that gives bad advice is a nuisance. An agent that makes an unauthorized payment is a liability. The difference is accountability, and accountability in the agentic AI space is largely still theoretical.

Patel further argued that the connection between identity and payments has always been tighter than most people realize. “I’ve said for a long time that payments are an identity problem. That becomes even more obvious with agents.”

For machine-to-machine commerce to function, merchants and financial institutions need more than proof that a valid agent is present. They need to know that the agent was specifically authorized to complete that transaction, by a real person, at that moment. For high-value actions, that may mean requiring a cryptographic record of human approval before any money moves.

The infrastructure the agentic economy still needs

Solving the agent identity problem is not a one-layer job.

The first layer is credentialing: cryptographic tools that let an agent prove what it is authorized to do without exposing the sensitive details behind that authorization. Zero-knowledge proofs are one approach being actively explored.

The second is standardized payment infrastructure. Agents need a common way to discover prices, authorize transactions and interact with other machines without relying on a patchwork of incompatible systems.

The third is model verification. A valid credential is not enough if the AI running behind it has been altered or replaced. Confirming that the model powering an agent is actually what it claims to be is a problem that Sentient Foundation, among others, is researching directly.

Kenneth Shek, CEO of Moca Network, further said the core gap is not authentication but authority. “Scalable data sharing is necessary for AI agents to act on behalf of humans, however the trust framework for delegation and authority is lacking. In the past, platforms have compromised user privacy to enable agent automation.”

None of those layers exists in finished form. The technology making agents more capable has moved fast. The infrastructure making them trustworthy is still catching up.

Related: Google set to challenge Meta Muse in the Agentic AI race