deepidv
Back to News
The Deep Brief · Sep 25, 2026 · 4 min read

Who Verifies the Verifier? AI Agents Line Up for Identities

A new whitepaper says API keys cannot carry agentic commerce, as spoofed AI agents pass 80% of sites and regulators open KYC to verifiable credentials.

Rosalie Chirip
Rosalie Chirip
Senior Editor at deepidv
AI agents presenting verifiable credentials instead of API keys in an agentic commerce flow

The infrastructure question under agentic commerce got a blunt framing this month: who verifies the verifier? In a whitepaper titled Identity, Commerce, and the Agentic Web, decentralized identity firm Indicio argues that current infrastructure cannot safely carry the autonomous economy being built on top of it, because today's AI agents authenticate with API keys and bearer tokens, a shared secret proving possession of a string, not identity.

The numbers behind the warning are uncomfortable. A Gravitee survey of more than 1,600 technical leaders found 46 percent still using shared API keys for agent access, and 88 percent reporting confirmed or suspected agent-related security incidents in the past year. DataDome testing found spoofed agent identities approved on roughly 80 percent of sites tested, while Bain projects US agentic commerce at $300 to $500 billion by 2030.

Credentials, mandates, and the edge

Indicio's proposal extends the identity architecture built for humans to the agents acting for them. Agents would carry signed verifiable credentials rather than keys, checked against machine-readable trust lists, with delegated authority encoded in the credential itself: what roles this agent holds, what it may do, and for whom. The design keeps authority at the edge, with the user's device holding keys and credentials while agents request signed mandates for specific actions instead of receiving standing API access.

The regulatory ground is moving in the same direction. In early September, FinCEN and four fellow regulators issued joint FAQs confirming banks may accept verifiable digital credentials in Customer Identification Program compliance, and the payments networks are already racing to define agent rails with Google's AP2, Visa's Trusted Agent Protocol, and Mastercard Agent Pay.

The verification gap in the middle

What the whitepaper concedes is as instructive as what it proposes. Indicio has demonstrated an agent verifying a human's credential, biometrics included, without human review. The larger vision, unfamiliar agents establishing mutual authentication and transacting at machine speed under delegated authority, remains a gap between demonstration and deployment, and that gap is precisely where Know Your Agent programs live.

Someone has to verify the human principal behind the agent at enrollment, bind the mandate to that verified identity, and re-verify when the mandate escalates, which is the role Arc plays in the deepidv stack: a gateway where agents present credentials, mandates trace to liveness-verified humans, and every delegation lands in an evidence trail. The API key era of agent identity is ending the way the password era did: not because something better was invented, but because the incident rate made the status quo unpriceable.

AI Agent Identity FAQ

How do AI agents authenticate today?
Mostly with API keys and bearer tokens, shared secrets that prove possession of a string rather than identity. A Gravitee survey found 46 percent of technical leaders still using shared keys and 88 percent reporting agent-related security incidents in the past year.
What are verifiable credentials for AI agents?
Cryptographically signed credentials an agent presents to prove its identity, its delegated authority, and the human or organization it acts for, checked against trust lists rather than possession of a secret, with mandates issued per action instead of standing access.
What is Know Your Agent (KYA)?
The verification discipline for the agentic economy: verifying the human principal behind an agent, binding the agent's mandate to that verified identity, and re-verifying as authority escalates, so autonomous transactions stay traceable to accountable humans.
Can banks accept verifiable credentials for KYC now?
Yes. FinCEN and four fellow US regulators issued joint FAQs in September 2026 confirming that verifiable digital credentials can satisfy Customer Identification Program requirements, a milestone for credential-based onboarding.
How often do spoofed AI agents get through today?
DataDome testing found spoofed agent identities approved on roughly 80 percent of sites tested, which is the strongest single argument that shared-secret authentication cannot carry agentic commerce.
TagsAgentic AIIdentity VerificationGlobalSecurityIntermediateNews

Relevant Articles

What is deepidv?

Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.

Learn More