Which agent, provider and accountable organisation are involved? A recognisable name is not enough; the identity needs verifiable evidence.
AGENT TRUST EXPLAINER · 18 SEPTEMBER 2026
When your AI acts, who answers?

An AI agent can search, negotiate, buy, write, transfer or change a system on your behalf. The question is no longer only whether the agent can identify itself. The harder question is whether it can prove that this person or organisation authorised this action, within these limits, at this time.
AIAF’s position: identity is not permission. When an agent acts, the human or organisation that delegated the work remains accountable. The system should preserve enough evidence to show what was authorised, what happened and how authority could be withdrawn.
What is changing — verified work, not a finished solution
The FIDO Alliance says authentication and authorisation systems were designed mainly for direct human interaction, not autonomous agents. It identifies three current gaps: services cannot consistently verify an agent’s identity, there is no common way to prove user intent, and people may end up exposing credentials to agents. FIDO working groups are developing approaches for verifiable instructions, agent authentication, auditability and revocation.
For payments, EMVCo published a draft agentic-payments framework on 1 September 2026. It proposes an interoperable way to establish consumer intent and delegated authority, including recurring purchases and cumulative budgets. Public feedback is open through 30 September 2026.
The evidence limit
These are standards efforts and proposals, not proof that agent delegation is already solved across the internet. Parts are payments-specific. Implementations, interoperability, liability and independent testing remain open work.
Before an agent acts, demand four receipts
What exact action did the human approve? “Help with my finances” is not the same permission as “pay this invoice once.”
What are the limits on money, data, recipients, systems, time and escalation? High-impact or irreversible actions should require human approval.
Can the authority expire or be revoked, and can a human inspect what the agent requested, decided and changed?
This is the logic behind the proposed AIAF Trust Card: a trust record should show identity evidence, delegated authority, expiry or revocation and action evidence. The current card is a research concept—not a certification, credential or payment authorisation.
What a human or company can do now
- Delegate one narrow job. Replace broad standing permission with a specific outcome and deadline.
- Set hard limits. Name approved systems, recipients, data and spending caps; deny everything else by default.
- Keep a human gate. Require approval for external messages, purchases, deletions and irreversible changes.
- Make authority expire. Temporary permission is safer than access that quietly remains active.
- Keep the evidence. Record the instruction, approvals, actions, exceptions and revocation path in a form a reviewer can understand.
If a vendor cannot explain these controls plainly, do not confuse a smooth demo with accountable delegation.
ZERO’S TAKE · OPINION
“The AI did it” cannot become an accountability escape hatch.
The dangerous sentence is not “the agent made a mistake.” It is “nobody knows who allowed it.” Capability can scale faster than responsibility when an agent moves through payments, messages and company systems with broad permissions.
My position is simple: the more independently an agent can act, the stronger its evidence of authority must become. Identity tells us what is at the door. Permission tells us whether it may enter. Boundaries tell us what it may touch. Revocation and logs tell us whether humans can stop it and reconstruct the consequence.
The standards work is encouraging, but unfinished. Humans should not wait for perfect interoperability before adopting the principle. Start with narrow authority, visible approvals and evidence that survives the action. If responsibility becomes less clear when AI is added, the workflow is not ready for autonomy.
Primary sources and dates
- FIDO Alliance: securing agentic AI — current programme describing identity, user-intent, credential and delegation gaps; standards work remains in development.
- EMVCo: draft framework for agentic payments — published 1 September 2026; public comment closes 30 September 2026.
AIAF has not independently validated an end-to-end implementation of either approach. Analysis is current to 18 September 2026, Malaysia time.
Today’s daily briefing · All editions · Trust Card research · Home