The internet is about to fill up with agents nobody can vouch for
I spend a chunk of my working week checking passports, or something close to it: matching dates of birth, cross-referencing nationalities, looking for the small inconsistency that tells you someone isn't who they say they are. It's slow, careful work. It exists because a long time ago someone decided that a human crossing a border, opening a bank account, or signing a contract needs a way to prove who they are.
We never built that layer for AI agents, and the need for it is arriving fast.
The shift nobody's pricing in yet
Right now most people think of agents as chatbots with extra steps. Ask a question, get an answer, maybe it books a flight for you. That framing is already out of date. Agents are starting to negotiate with other agents, move money, request data, and act on behalf of people and companies without a human checking every step. The volume of that traffic is climbing fast, and it's going to keep climbing, because the entire pitch of agentic AI is removing the human from the loop wherever possible.
Here's the problem. Take the human out of the loop and you also take out the thing that made trust work on the internet up to now: a person, with a name and a reputation and something to lose, standing behind every request. An agent can write with total confidence. It can sound exactly like a real business, a real person, a real intent. Right now there's no reliable way for the thing on the other end, another agent or a website, to tell an agent acting for someone real and accountable from one with no one behind it at all.
This is the default state we're heading into if nothing changes.
Why identification, specifically
You could try to solve this with better content filters, better fraud detection, smarter CAPTCHAs. Those measures address symptoms. The real question is who bears responsibility for a request existing at all. Filtering content reacts to behaviour. Identification establishes accountability before an interaction starts, rather than inferring it afterward.
Consequence explains why this matters. A chatbot giving a wrong answer causes minor annoyance. An agent making a payment, sharing private data, or negotiating a contract on someone's behalf carries real stakes. At that scale, catching bad actors after the fact does not work as a strategy. The system needs verification that happens before entry, the way a border checkpoint works.
What a government can do
Governments do best by setting a floor for this rather than designing the whole system. That floor could be a minimal, interoperable identity standard for agents, similar in spirit to how domain registration or SSL certificates work: a baseline establishing how an agent proves which accountable party stands behind it, the minimum bar separating verified from self-asserted claims, and who issues that proof.
The trap to avoid is over-specifying it. If a government tries to build the whole trust system top down, it'll be too slow to keep up and too rigid to fit every use case. The standard should be thin, just enough that every business building agents, and every business receiving requests from them, can speak the same language about identity.
What a business can do without waiting
You don't need to wait for regulation to start acting like this matters. Any business putting agents into the world, or accepting requests from agents, benefits from deciding right now what proof it demands and at what threshold. A low-stakes interaction, browsing, casual content requests, needs almost nothing. A high-stakes one, payments, private data, contracts, should demand real, verified identity behind the request. That threshold-setting is something individual businesses can and should be doing on their own, before anyone forces them to.
Businesses that get ahead of this protect themselves and demonstrate accountable behaviour to the rest of the ecosystem.
What this opens up
Once identity becomes something agents can prove and present, a few things follow almost immediately.
You get the agent equivalent of cookies: persistent, accountable signals that let a website or service recognise a returning, verified agent instead of treating every request as a stranger. This changes how the web functions at a structural level.
You also get agent-to-agent interactions built on negotiation rather than blind trust. Right now if my agent talks to your agent, neither of us really knows who's on the other end. With identity in place, agents can set their own bar, demand proof proportional to what's at stake, and refuse to proceed if it isn't met. That's a fundamentally different internet to the one we have now, where either everything is allowed or everything gets blocked behind a CAPTCHA.
The snowball effect
Adoption here does not require a marketing campaign. It requires one agent refusing to deal with another agent that has no proof of identity. That refusal functions as the advertisement. The blocked agent, or whoever operates it, learns immediately that identity is the price of being taken seriously. Multiplied across enough interactions, adoption emerges as a natural consequence of how the system behaves. Trusted agents prefer dealing with other trusted agents. Sites that adopt the standard become the sites agents prefer to interact with. The effect compounds on its own.
The security risk
None of this is free of danger. The biggest risk is obvious to anyone who has spent time near cryptography: identity systems are only as good as the security underneath them. A verified flag becomes worthless, or worse than worthless, when the credential behind it can be forged, replayed, or stolen. Bad encryption compounds the danger: it distributes convincing fake identities at scale, a worse outcome than having no identity system at all, because people trust the label by then.
A second, quieter risk exists. Identity systems drift toward over-collection. What starts as proving accountability drifts toward collecting everything about a person, because over-collection is the easier system to build. Any serious version of this must resist that pull deliberately through minimal claims, selective disclosure, and proof without a dossier.
Passports exist for humans because a world without any way to vouch for a stranger does not scale past a village. Agents are about to operate at a scale no village ever reached. The real question concerns how this gets built: carefully, or in a hurry after the damage is already visible.