Teaching The Internet Who They Are

Teaching The Internet Who They Are

​Michael Riedl, CEO at Team Internet Group PLC.

getty

​The internet has never been human-only. Crawlers, bots and scripts have been nearing parity with people online for years, surpassing human traffic in 2024 and reaching 53% of all web traffic in 2025, according to Imperva’s “Bad Bot Report 2026.”

But look at how those machines identify themselves. A crawler announces itself in an HTTP header literally called “user agent”: a machine declaring whose tool it is. Its identity is a self-declared string and a published IP list, an honor system policed by robots.txt.

Meanwhile, the automated systems that actually move money, from exchange algorithms to interbank messaging, operate differently. They work inside closed, credentialed clubs, where a machine must be identified and authorized before it can act.​

Overall, the internet’s trust architecture has always rested on a couple of assumptions: Behind every action stands a human or a legal entity. And machines are instruments, never counterparties.

When Machines Become Actors​

AI agents break that assumption. They negotiate, purchase, coordinate and transact with other agents, with little or no human intervention. An agent cannot be sued, fined or bound by contract, and no regulator looks to change that. But neither are they simply passive instruments. Agents are autonomous counterparties that remain someone’s legal instrument.

This is not a forecast. Mastercard launched Agent Pay in 2025, with tokens binding a payment credential to a specific agent identity. Visa’s Trusted Agent Protocol signs an agent’s identity into its requests. Coinbase’s x402 rail had processed roughly 165 million machine-to-machine payments across some 69,000 agents by April 2026.

The fraud arrived on the same schedule. DataDome counted nearly 8 billion AI-agent requests in the first two months of 2026 and found trusted agent names widely spoofed: 16 million requests falsely claiming to be Meta’s agent, one in 40 “Perplexity” requests an imposter. Agent registries are filling with unverified entries impersonating banks and payment apps. The honor system is failing in real time, and what is failing is not intelligence but identity.

Identity As The Missing Layer​

Here is the problem: An agent’s autonomy is operational, its accountability is legal, and the identifier is the tether between the two.

Platform-issued keys cannot carry that weight alone. A short-lived key answers “is this session valid.” It cannot answer “who is this, and what is their history.” Inside one platform, keys suffice. But the moment an agent crosses a boundary to transact, both sides need a shared referent for verification, reputation and recourse.

So where will that shared referent live? Audit the stack being built and I think the answer hides in plain sight: the domain name.

Take X.509, the certificate standard used across the web: Its certificates bind keys to domain names. OAuth and OpenID identify issuers through URLs on domains. Passkeys bind credentials to a domain. Even the most widely deployed method for decentralized identifiers, known as did:web, resolves through domain names. Google’s Agent2Agent protocol, now a Linux Foundation project, has each agent publish its card at a URL, on a domain, behind a certificate issued after proving control of that domain.

Every new layer bootstraps its trust from the oldest one. Where builders avoid the shared namespace, they have to substitute private directories, one per platform. But those walls are already showing their limits. Within months of launching competing products, both card networks joined Google’s AP2 protocol. Walled gardens do not scale.

The Case For A Shared Identity Layer

I think two objections to this model of agent identity deserve to be met head-on.

1. Agents are ephemeral.

A procurement agent may live for 90 seconds, and thousands of instances run in parallel, so reputation cannot attach to an instance. But I think that constraint points toward an answer.

Agent identity is best when hierarchical: a durable anchor owned by an accountable principal, delegating short-lived, scoped credentials to instances. Mastercard’s tokens already work exactly this way. If the identifier were the key itself, identity would die with every key rotation, and reputation with it.

A name is the link between who you are and what key you currently hold. That indirection is the feature. Reputation accrues at the anchor. So does liability.

2. The domain system’s accountability is imperfect.

Privacy services, shell companies, stale registration data. All real problems. But imperfect identity with a legal chain is still better than an identity system with no path to accountability.

Behind a privacy service there is still a registrar under contract, a court-order path, arbitration that resolves thousands of disputes a year. Behind a raw key pair there is nothing. Regulators are hardening exactly this layer: NIS2 now mandates accurate registration data.

The Harder Question Is Replacement

Could something replace the current domain name system (DNS) as the root? History says the odds are poor, largely for a structural reason. Application protocols get replaced because migration can happen one connection at a time. Namespaces almost never get replaced, because migration requires the whole world to agree on a new root of trust simultaneously. Twenty-five years into IPv6, IPv4 still carries most traffic, and that was mere addressing. Identity is a namespace-class problem.

Is this a decade early? Possibly, and early is the point. Email shipped without sender authentication, and 40 years of retrofitted fixes still leave billions in annual compromise fraud. The spoofing numbers show the same thing starting again, at machine speed. That is why I believe identity layers must precede volume. That is the one lesson the internet has taught twice.

I will offer a test. If, by 2035, a merchant can safely accept a large payment from an agent it has never seen, with no chain from that agent’s credential to a namespace-anchored principal, this argument was wrong. But I do not expect to be wrong on this topic.

The first commercial internet connected information. The second connected people. The third will connect autonomous counterparties. The defining challenge of the AI era will not be teaching machines how to think. It will be teaching the internet who they are.


Forbes Business Council is the foremost growth and networking organization for business owners and leaders. Do I qualify?


Read More

Zaļā Josta - Reklāma