AI Agents Need Their Own Identities — And the Internet Wasn't Built for That
AI agents can increasingly act across software, data and commerce. Here's why identity, authorization and delegation may become critical infrastructure for the agentic internet.
By VA Andrew
Independent Researcher — AI, Blockchain & Digital Infrastructure
Published: April 16, 2026
Artificial intelligence is moving beyond answering questions.
AI agents are increasingly being designed to use software, access databases, interact with APIs and complete multi-step tasks on behalf of people and organizations.
That transition creates a problem that sounds simple but reaches deep into the architecture of the internet:
When an AI agent requests permission to do something, how does another system know who authorized it—and exactly what it is allowed to do?
For decades, digital identity infrastructure was primarily designed around humans, devices, applications and relatively predictable service accounts.
Autonomous agents complicate that model.
The next major AI infrastructure problem may therefore have less to do with making agents smarter and more to do with deciding when machines should be trusted to act.
AI Is Crossing From Recommendation Into Action
The distinction between an AI assistant and an autonomous agent is important.
An assistant might compare airline tickets and recommend the cheapest option.
An agent could potentially:
search → compare → select → purchase
The moment software moves from recommending an action to executing one, authorization becomes substantially more consequential.
The same principle applies inside businesses.
An enterprise agent could potentially read invoices, access customer databases, schedule meetings, modify cloud resources or prepare financial transactions.
Each additional capability expands both its usefulness and its security exposure.
NIST Is Treating Agent Identity as a Real Infrastructure Problem
This is no longer merely a theoretical cybersecurity concern.
In February 2026, the U.S. National Institute of Standards and Technology's National Cybersecurity Center of Excellence published a concept paper specifically examining software and AI-agent identity and authorization.
NIST identified questions involving:
- identification;
- authorization;
- auditing;
- non-repudiation;
- identity and access-management standards;
- controls against prompt-injection attacks.
The significance is easy to miss.
The challenge is no longer only:
Is the AI model safe?
Infrastructure increasingly needs to answer:
Which agent is acting, whose authority does it carry, and what is that authority permitted to accomplish?
Source: NIST — AI Agent Identity and Authorization
Authentication Is Not Authorization
These concepts are frequently treated as interchangeable. They are not.
Authentication: Who are you?
Authorization: What may you do?
An AI agent could possess perfectly valid credentials while attempting an action that exceeds its intended authority.
Consider an accounting agent authorized to:
- read invoices;
- classify expenses;
- prepare payment instructions.
Those permissions should not automatically allow it to:
- replace a supplier's bank details;
- approve the payment;
- transfer funds;
- increase its own privileges.
This makes least-privilege architecture particularly important for autonomous systems.
An agent should receive only the permissions required for its assigned task, ideally for a limited period and with clear revocation mechanisms.
The Security Perimeter Is Moving Toward Actions
Traditional cybersecurity placed considerable emphasis on network boundaries.
Cloud computing weakened that model.
Agentic AI could weaken it further.
An agent may legitimately possess credentials, operate from an approved environment and call authorized APIs while still attempting an inappropriate action.
SANS Institute security research published in June 2026 argues that conventional human and service-account behavioral assumptions do not map cleanly onto autonomous agents. Its proposed response includes agent inventories, explicit scopes and action-level authorization between agents and their tools.
That introduces an important architectural idea:
The relevant security question may increasingly be not only “Who is this?” but “Should this identity be allowed to perform this specific action right now?”
Source: SANS Institute — The Agent Identity Problem
Delegation Makes the Problem Harder
Now consider what happens when one agent delegates work to another.
A company authorizes a procurement agent to acquire computing capacity.
That agent asks a specialized research agent to compare suppliers.
The research agent connects to external marketplaces.
The authorization chain becomes:
Organization → Primary Agent → Specialist Agent → External Service
Several questions immediately appear.
Does the specialist inherit the primary agent's authority?
Can it spend money?
Can it access confidential supplier contracts?
Can it delegate again?
When does its authority expire?
How can the organization revoke access throughout the chain?
Human institutions already manage comparable problems through employment roles, signatures, contracts, approval hierarchies and legal accountability.
Autonomous systems may require machine-readable equivalents.
Identity Could Become Infrastructure for the Agent Economy
The issue extends beyond cybersecurity.
MIT Sloan reported in July 2026 on research envisioning a much larger ecosystem of personal and organizational agents. The research argues that significant opportunities may emerge not merely from individual agents but from the marketplaces, protocols and services those agents require.
That could include infrastructure for:
- discovering agents;
- establishing identity;
- reputation;
- transactions;
- interoperability;
- governance.
This changes the economic thesis around AI agents.
If agents eventually transact with other agents at meaningful scale, intelligence alone will not be sufficient.
They will need mechanisms for determining which counterparties are legitimate and what authority they possess.
Source: MIT Sloan — Who Will Own the AI Agent Economy?
Agentic Commerce Raises Financial Questions Too
The implications become particularly significant when agents gain access to money.
Harvard Kennedy School has examined an emerging agentic economy in which autonomous systems could search, negotiate, purchase, invest and execute payments.
Its analysis also highlights potential risks including fraud, privacy erosion, bias, market manipulation and economic concentration.
These risks demonstrate why identity cannot be separated from accountability.
A machine that can spend money needs more than a wallet.
It may need a verifiable relationship connecting:
agent → authority → transaction → accountable principal
Source: Harvard Kennedy School — Synthetic Agents, Real Money
A Four-Layer Trust Model
One useful way to analyze agent infrastructure is through four distinct layers.
1. Identity
Which agent is interacting with the system?
2. Authority
What is that agent permitted to do?
3. Provenance
Where did its instruction and authority originate?
4. Auditability
Can important actions be reconstructed afterward?
These layers solve different problems.
A verified identity without constrained authority can still be dangerous.
Authorization without provenance weakens accountability.
And transactions without reliable auditability make disputes and incident investigations substantially harder.
Why Short-Lived Permissions Could Matter
Human employees may keep the same corporate identity for years.
AI agents may require a different approach.
An agent tasked with booking a business trip might need access to:
- a calendar;
- an approved travel account;
- a corporate payment method.
But perhaps only for several minutes.
After completing the task, those permissions may no longer be necessary.
That suggests a possible shift from persistent permissions toward task-specific, short-lived authority.
Such an architecture could reduce the damage caused by compromised credentials because the agent would not automatically retain broad access indefinitely.
The Agent Standards Race Has Already Started
NIST's work extends beyond a single identity paper.
In February 2026, NIST's Center for AI Standards and Innovation launched an AI Agent Standards Initiative focused on secure and interoperable autonomous agents.
The initiative specifically recognizes that agents increasingly need to interact with external systems and internal organizational data.
That matters because interoperability and security are connected.
If agents from different developers and organizations are expected to interact, the ecosystem needs common ways to communicate trust, permissions and capabilities.
Source: NIST — AI Agent Standards Initiative
Where Cryptography—and Potentially Blockchain—Fits
This discussion requires precision.
AI agents do not inherently require blockchains.
Existing technologies such as public-key infrastructure, OAuth-style authorization, enterprise identity platforms and cryptographic credentials may handle many use cases more efficiently.
Distributed ledgers become more interesting when independent organizations need to verify shared records without depending entirely on one operator.
Potential areas include:
- credential verification;
- delegated authorization records;
- provenance;
- transaction receipts;
- cross-organization audit trails.
The credible thesis is therefore not that every AI action belongs on a blockchain.
It is narrower:
Some agent interactions may benefit from shared cryptographic infrastructure when multiple independent parties require verifiable trust.
Whether blockchain-based systems outperform conventional architectures will depend on security, scalability, privacy, latency, cost and the specific application.
The Counterargument: We May Not Need a New Identity System
There is a strong counterargument.
The internet already has mature identity and authorization technologies.
Enterprises routinely manage users, applications, machines and service accounts using:
- identity and access management;
- public-key infrastructure;
- API credentials;
- OAuth;
- zero-trust architectures.
AI agents may therefore require extensions to existing infrastructure rather than an entirely new identity system.
That may ultimately be the correct outcome.
What makes autonomous agents unusual is not necessarily identity itself.
It is the combination of identity with dynamic reasoning, tool selection, delegation and autonomous execution.
The biggest change may therefore occur in authorization, not authentication.
The Market Opportunity May Sit Below the Agent
The visible AI market currently concentrates attention on models and applications.
If autonomous agents become widely deployed, however, another layer may become increasingly valuable:
trust infrastructure.
Organizations could require services for:
- agent inventories;
- credential issuance;
- permission management;
- policy enforcement;
- delegation;
- transaction verification;
- behavioral monitoring;
- compliance;
- audit;
- credential revocation.
The pattern is familiar from previous technology cycles.
Applications attract users.
Infrastructure makes those applications dependable enough to become part of everyday economic activity.
What to Watch Next
Rather than counting new AI-agent announcements, watch the infrastructure developing around them.
The strongest signals would include:
- standardized agent credentials;
- task-specific authorization;
- short-lived permissions;
- interoperable delegation protocols;
- action-level policy enforcement;
- agent-specific audit requirements;
- machine-readable financial controls.
Those developments would suggest that agents are progressing from experimental software toward recognized participants in digital systems.
Conclusion
AI agents create an unusual infrastructure challenge.
For the first time at potentially significant scale, people and organizations may authorize software to interpret goals and independently perform consequential actions across systems they do not own.
That makes the central question larger than whether AI agents are intelligent enough.
The harder question is:
How does the internet determine which autonomous machine to trust—and exactly how much authority to give it?
Identity tells a system who the agent is.
Authorization determines what it may do.
Delegation determines whether that authority can travel.
Auditability determines whether anyone can reconstruct what happened afterward.
If autonomous agents become a meaningful part of commerce and enterprise computing, those four capabilities could become foundational infrastructure for the agentic internet.
Sources & Further Reading
NIST National Cybersecurity Center of Excellence — Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization, February 2026.
NIST Center for AI Standards and Innovation — AI Agent Standards Initiative, February 2026.
MIT Sloan School of Management — Who Will Own the AI Agent Economy?, July 2026.
Harvard Kennedy School — Synthetic Agents, Real Money: Governing the Agentic Economy, February 2026.
SANS Institute — The Agent Identity Problem: Applying Zero Trust to AI Agents, June 2026.