Agentic identity is needed if AI agents are to act, buy, and share data on people’s behalf, across systems that have never met them. Before any of that is safe, three things have to be proven: that the agent is real and who runs it, that the person agreed, and that the agent is allowed to act.
By Trevor Butterworth
AI agents are changing the terms of digital interaction to the degree that what had been the next big thing — web3 — has almost been forgotten. Agentic commerce, borne on forecasts running to trillions of dollars in value, has crowned the agentic web as the next phase of the internet.
The speed and velocity of the conceptual transition from “read, write, own” to “authorize and buy” is astonishing. The speed of the actual transition is likely to be more fraught as analysts, businesses, and consumers focus on the same obstacle: trust.
The questions the agentic web has to answer
Before your AI agent books, buys, or shares your data with another company’s agent, both sides have to answer the following questions:
1. Is the buyer agent real and how can I, if I’m the seller agent, trust the buyer?
- Is the seller agent real, and how do I trust that it represents the company I want to transact with?
- Did the buyer agree to the buyer agent engaging in this transaction?
- Is the buyer agent allowed to act and what is the scope of the action?
- How do I generate a tamper-proof record of all these decisions for audit against data protection law?
And then, as a bonus,
- Does the seller agent have permission to share the buyer’s mandate with another agent inside or outside the company, and how does it trust these other agents?
Why tokens can’t secure AI agents
Today’s world of API keys and access tokens cannot answer these questions. Indeed, when faced with non-human identity access management, it might be more useful to think of agents as superhuman identities, capable of reasoning and transacting at machine speed, thereby turning a difference of degree into a difference of kind.
A token proves that whoever holds it has a secret. It says nothing about who that holder is and is effectively useless the moment an AI agent crosses an organizational boundary.
That shared-secret problem didn’t protect against human identity fraud; it’s most certainly not going to protect against spoofed agents or an autonomous AI breach of the Hugging Face kind.
A trust layer for the agentic web
This is where decentralized identity steps in. In “Identity, Commerce, and the Agentic Web,” I explore how decentralized identity using verifiable credentials provides the trust layer that can make agentic commerce and the agentic web feasible.
This builds on a whitepaper I co-wrote back in 2023 on why copilots needed decentralized identities; it builds on our work on Indicio Proven AI, which replicates the technology and governance we deploy for people and organizations for AI agents. The application of this technology means that AI Agents that have never met are able to establish trust on first contact, with no shared login and no integration arranged in advance — at machine speed.
But the paper goes even further and explores how some of the neglected aspects of decentralized identity (decentralized governance, DIDComm, mediation unlinkable presentation) provide the operational and compliance infrastructure for a superhuman economy.
The market is already moving this way. Google’s Agent Payments Protocol carries its mandates as verifiable credentials, and NIST, the Cloud Security Alliance, and Singapore’s first agentic-AI framework are converging on the same idea.
At Indicio, we’ve already shown an AI agent verify a real person’s Digital Travel Credential before acting. Our work on decentralized governance was developed into a specification by the Decentralized Identity Foundation (Credential Trust Establishment). Our expertise in mediation is driving country-scale credential deployments.
It’s a long paper, but it attempts to describe what’s needed for the next digital transformation and how to make it work. Read how we see identity, consent, and authority becoming portable across the agentic web.



