How to Verify the Identity of an AI Agent


An AI assistant was asked to find the cheapest way to send money to a cousin in Canada. It searched, found a provider built for international transfers, recommended opening an account, and then stopped, because the provider needed to see identification.
That demo ran during a recent webinar on identity for the agentic economy, and that refusal is where every agentic workflow currently stops. The same wall blocks an agent from opening a bank account, applying for the policy it just found, making a trade or transferring funds.
"AI can even write code now, but why can't it open a bank account?" Darren Louie, Proof's VP of Product, asked in that session. "The truth is it's not because of a technology problem. It's because AI really hits this wall today anytime money or identity is involved."
Key takeaways
- Verifying an agent takes two answers: which software is calling, and which verified human authorized this specific action.
- An identity credential establishes who someone is. A verifiable record also establishes what they authorized an agent to do.
- An agent acting for a company needs a third answer, since a KYB record goes stale the moment ownership changes.
- x401 lets a service state its identity requirements in an HTTP response, so an agent can discover and satisfy them.
- FinCEN and the federal banking agencies added verifiable digital credentials to customer identification guidance in September 2026.
Machine identity and human authority are separate problems
Machine identity covers which software is calling and whether it is what it claims, which API keys already handle.
Human authority asks two things a machine identity stack cannot answer: which verified person stands behind this agent, and did they grant permission for this action. A bank needs both before it moves money.
The workaround people have already adopted makes it worse. "People are starting to put their usernames and passwords into these AI tools," Louie said. "There's no way to revoke their access, and there's no way to even tell the difference between me logging in versus my agent. So when things go wrong, who do we really hold accountable?"
The business behind the agent goes stale too
Most agents in financial workflows act for a company, which adds a question that Know Your Business checks answer only on the day they run. Ownership changes, vendors get acquired, somebody takes over a supplier's email account, and institutions keep relying on the old record. FinCEN flagged false business records as part of $212 billion in suspicious activity last year.
Our recent session with Enigma made the case that verifying a business and verifying the person authorized to act for it are separate problems, and that most institutions have solved only the first. Extending it to software actors is “Know Your Agent”: an agent initiating a payment needs a verifiable chain back to a human who authorized it.
What a verifiable record adds to a credential
"An identity credential does one thing. It proves who you are,” Louie noted during the webinar. “But a verifiable record does two things. It proves who you are, and it proves that you've given AI the authority to make these decisions or take these actions on your behalf."
Signing that record with a key tied to the individual means an agent can neither fabricate nor alter it, since changing the terms breaks the seal. It outlives the transaction too, so a dispute months later has something to examine.
Bounding what the agent may do stops the record being a blank check. Proof's authorization gap research surfaced one written for a machine: “The agent may open a new policy with any insurance company, up to $5,000 in price per premium. It may not accept a policy without a right-to-cancel clause. This permission expires on Friday.”
How a service tells an agent what it needs
A signed record only helps if the agent knows to get one, which is the gap x401 addresses. A service responds with a 401 carrying its identity requirements and the issuing authorities it accepts, the agent builds a wallet presentation request, and the wallet authenticates the person with a biometric before signing the attributes alongside the terms being approved.
"x401 gives every service a common way to ask for proof. Proof Digital ID gives people and organizations a high-assurance way to answer, with a signed record of who authorized what," Proof CEO Pat Kinsel said in our protocol announcement in September. Payment stays separate, handled by x402 and AP2.
What regulators have accepted
In September 2026, FinCEN and the federal banking agencies updated customer identification guidance to expressly include verifiable digital credentials, and we made our own credential generally available days later, anchored to an X.509 certificate issued after Kantara-certified IAL2 proofing establishes the holder, while NIST's concept paper on agent identity remains open work.
"If an agent is going to open an account, move money or change a beneficiary for me, the institution needs evidence that I am a real, verified person and that I authorized that specific action," Kinsel said. "Human identity and agent authorization are ultimately the same trust problem."
Which leaves one question for any vendor. When a customer disputes this transaction in nine months, what do you hand the investigator?
See how Proof turns a verified human into a signed authorization an agent can present >
















































.jpg)





























































.jpg)





















