Agentic identity, while nascent, feels like an area we’ll see a lot of movement shortly. From Simon Taylor of Fintech Brainfood:
.Visa just gave AI agents their own card credentials.
…
It's the technology that takes your 16 digit card number and swaps it for a secure cryptographic token, so your real number never touches the merchant. That's what made Apple Pay work.
Visa Intelligent Commerce extends those tokens to agents.
Once an agent holds a token bound to it specifically, the agent has an identity on the Visa network. The same rails that already clear 300 billion transactions a year.…
Say your agent buys something and you tell your bank you never authorized it. With agent identity on the network, there’s a record that it really was your agent, acting inside the guardrails you gave it. That changes agents from being a hostile “bot” to a trusted customer.
It also rhymes with every agent problem I keep running into. Autonomy only works when the system can prove what the agent did.
Totally different industry (and a network rather than a system of record to boot) but still - this is functionally akin to what we’ll see many EHRs pursue this year. Bots are increasingly swarming with the permission of their mutual customers. The system of record can't tell a sanctioned agent from a scraper when both arrive as anonymous traffic or even usage attributed to a real user. This undoubtedly makes security harder!



