Insight

When Your Next Customer Is an AI Agent: Trust, Identity, and Provenance on the Agentic Web

Software agents now research suppliers, compare products, and execute transactions on their principals' behalf. The trust infrastructure of the web was built for humans reading pages. What replaces it is being decided now — and it is cryptographic.

Attomus insight

Software agents now research suppliers, compare products, and execute transactions on their principals' behalf. The trust infrastructure of the web was built for humans reading pages. What replaces it is being decided now — and it is cryptographic.

Part 9 of 10 in Trust through mathematics

A growing share of the traffic arriving at any organisation’s website is no longer human. Some of it is the familiar crawling of search engines. But an increasing fraction is something newer: AI agents acting on behalf of specific people – researching a purchase, evaluating a supplier, summarising a market, shortlisting firms for a piece of professional work. The recommendation that once came from a colleague’s memory or a page of search results now frequently comes from a model’s synthesis of what it read.

This changes several things at once. Most public discussion has fixed on the marketing question – how does one get recommended by a machine? – which we will treat elsewhere. The deeper questions are about trust: how does anyone verify what is acting, for whom, and with what authority? And how does an agent – a reader with no childhood, no professional scepticism, no lunch with a friend who once got burned – decide what to believe?

The web’s existing trust apparatus answers none of this, because all of it quietly assumed a human was present.

The Identity Problem: What Is Acting, And For Whom?

The web has never had a working mechanism for asserting what kind of thing is making a request, let alone on whose behalf. User-agent strings are folklore; IP reputation is circumstantial; CAPTCHA – the whole institution of proving-you-are-human – is at once being defeated by capable agents and obstructing the legitimate ones. Sites today cannot tell a customer’s purchasing agent from a scraper, so they admit both or block both.

The emerging answer is, predictably, cryptographic. Proposals now moving through the standards bodies and into early deployment have agents sign their requests – HTTP message signatures binding traffic to a published key, so that “this request comes from operator X’s agent” becomes a verifiable claim rather than a header anyone can type. This is the same relocation of trust traced throughout this series: from assertion to signature.

Identity of the agent, though, is the easy half. The harder half is delegation: an agent transacting on behalf of a person needs to present not “I am an agent” but “I am authorised by this principal, for this scope, until this expiry”. The building blocks exist – OAuth’s token machinery, verifiable credentials, and the payment networks’ early agentic-commerce protocols, which bind a cryptographically signed mandate from the human to each transaction an agent executes. The shape that is settling is scoped, signed, revocable authority, with the human’s intent captured in a credential rather than inferred from behaviour. Organisations that learned to govern non-human identities properly – service accounts, API keys, workload identities – will find it familiar. It is the same discipline, now with a buying budget.

Diagram showing delegated agent credentials verified by a service rather than assumed

The Provenance Problem: What Should A Machine Believe?

Now reverse the direction of trust. The agent reading the web has its own difficulty: its corpus is increasingly written by other machines, at negligible cost, with whatever motive funded the generation. A human reader brings – imperfectly – a lifetime of calibration about what looks credible. An agent brings pattern-matching over text the adversary also writes. Content designed to manipulate model outputs, prompt injections buried in pages an agent will read, fabricated consensus spread across plausible-looking sites: the attacks are documented, cheap, and improving.

There are two families of response, and their relative weight is the interesting question. The first is reputational: agents inherit the old heuristics, preferring established domains, cross-checking claims, weighting sources by track record. This works about as well as it ever did, which is to say adequately until someone invests in defeating it.

The second is cryptographic provenance: binding content to its origin verifiably. The C2PA standard – content credentials, now shipping in cameras, creative tooling, and platform pipelines – attaches a signed, tamper-evident manifest recording who produced an asset and what has been done to it since. Signed publishing, transparency-logged claims, and verifiable authorship travel the same road as the supply-chain machinery in the previous post; they are the same idea, applied to information instead of software. None of it tells a machine that content is true. It tells the machine who is accountable for it – which converts an unanswerable question about truth into a tractable one about identity and track record. That conversion is what cryptography is for.

For organisations that publish anything – and every organisation now publishes – the implication runs ahead of the tooling: the value of being verifiably the source of your own claims is rising, because the cost of unverifiable claims is collapsing towards zero.

What This Asks Of Organisations Now

The practical agenda is shorter than the conceptual one, and consists mostly of doing properly the things you should already have been doing. Treat agent traffic as a constituency rather than a nuisance: decide what you want machine principals to be able to read, verify, and do, instead of letting CAPTCHA policy decide it by accident. Keep your factual surface – who you are, what you do, what you charge, what you have done – accurate, consistent, and machine-legible, because it is now read by literal-minded readers that cross-check.

Get your own non-human identity governance in order, because issuing scoped, revocable authority to your own agents is about to be an operational requirement, and the firms that conflate “the agent” with “the person it acts for” will repeat every service-account mistake of the last twenty years at transaction speed. And watch the delegation and provenance standards with procurement-grade attention, because they will arrive in contracts the way SBOMs did: suddenly, and citing a regulation.

The Shape It Takes

It would be easy to present the agentic web as unprecedented. The striking thing, surveying it from the vantage of this series, is how precedented it is. A new class of actor appears; the informal trust mechanisms that assumed the old actors fail; and the replacement, after some expensive improvisation, is the usual one – identity bound to keys, authority bound to signed credentials, content bound to provenance, everything revocable and everything logged. Trust by familiarity gives way, once again, to trust by mathematics.

The transition will be untidy, because they always are. But the direction is not in doubt, and it favours – for once – the organisations whose claims about themselves are precise, verifiable, and dull. Machines are an audience with a marked preference for the truth, consistently told. There are worse disciplines for the rest of us to acquire.