Establishing one's digital identity has long revolved around confirming that a person is a human and validating their claimed identity. However, the rise of agentic AI has fundamentally altered this conversation, creating an urgent necessity for mechanisms that ensure authorization, accountability, and access control as autonomous AI agents become prevalent in both enterprise and consumer environments.
To delve into this evolving landscape, I consulted with Andrew Shikiar, CEO and Executive Director of the FIDO Alliance, along with Stavan Parikh, Google’s VP/GM of Payments, and Pablo Fourez, Chief Digital Officer of Mastercard. The FIDO Alliance has introduced new industry standards for agent-initiated authentication and payment processes through its Agentic Authentication Working Group to tackle these pressing questions.
Fourez likened this pivotal moment to past innovations like mobile commerce, which revolutionized trust and authentication methods. He believes we are on the brink of such a significant transformation once again. Shikiar noted that the foundational trust infrastructure of the internet was based on the premise of a human being at the keyboard. With agentic AI, that premise is challenged. To facilitate agentic commerce effectively, we need digital trust mechanisms that ensure AI agents act appropriately on behalf of users while safeguarding online environments and enabling the efficient delegation of tasks to these autonomous agents. Parikh underscored that establishing trusted verification will require new standards and protocols, similar to Google's agent payment protocol.
In terms of digital trust and agentic AI, the difference in securing agents compared to humans lies primarily in the nature of the verification problem. Securing digital commerce for human users typically involves protocols that confirm the identity of the person operating a device. However, the era of agentic commerce disrupts this traditional transaction model. Unlike humans, who authenticate once and behave predictably, AI agents are transient, function across multiple domains, and can delegate authority, which can then be delegated further.
Existing protocols such as OAuth 2.0, OpenID Connect, and SAML were designed with a deterministic approach that assumes predictable application behavior and a single authenticated entity, whether human or static machine. In contrast, agentic commerce encompasses autonomous agents that interact with numerous systems simultaneously, spawning subagents with their own access permissions and capable of making significant decisions in milliseconds without human involvement. This necessitates complex accountability structures that conventional identity frameworks are ill-equipped to handle. While human authentication focuses on validating identity, agent authentication must confirm both identity and the specific scope of authority granted, including what actions the agent may take, under which conditions, and for what duration. This demands a more detailed and adaptable security contract than traditional passwords or biometric systems can provide.
To effectively implement agentic authentication, frameworks must build on existing protocols by incorporating agent-specific credentials and metadata, while also facilitating the translation of flexible, natural-language permissions into auditable access control configurations. Organizations will need to provide machine agents with a structured set of pre-scoped access keys tailored for specific purposes. Developing trust and identity for agentic AI requires a fundamental change in mindset, which redefines the logic of trust in digital commerce.
The FIDO Alliance advocates a three-pronged strategy for fostering digital trust through verifiable user instructions, agent authentication, and reliable delegation. It allows users to explicitly authorize agents for specific actions, ensures systems can cryptographically verify that an AI agent is acting on behalf of an authenticated human, and defines strict user-controlled boundaries for agent-initiated payments and transactions. These advancements are supported by protocols from Google, such as the Agent Payments Protocol (AP2), designed for secure delegation and authorization, as well as Mastercard's Verifiable Intent framework.
As with the transition to mobile commerce, the emergence of agentic AI requires a comprehensive rethinking and reconstruction of digital trust mechanisms. Non-human identities are already more prevalent than human identities, by about 50 to 1 in the average enterprise, with a significant number of businesses suspecting AI agents of unauthorized data access. Legacy frameworks are inadequate to close this gap. Every delegation from a human to an agent, or from an agent to a subagent, must now be logged as a distinct, cryptographically verifiable relationship, creating an auditable and dynamic chain of command. Just as mobile commerce fundamentally changed transaction methods, agentic authentication seeks to redefine the parameters of autonomous action in society.
The key takeaway is that, although the underlying technical infrastructure remains largely unseen by end users, the business models and opportunities these advancements enable can be genuinely transformative. As the field of agentic authentication develops, it may follow similar transformative pathways seen in previous technological shifts.
The burgeoning role of AI agents brings pressing challenges related to authentication and identity management. As online retail prepares to transition into this agentic phase, companies are actively exploring strategies to foster trust in agentic commerce. Emerging protocols from the FIDO Alliance, in collaboration with Google and Mastercard, will shape not only how agents are secured but also the extent of autonomy organizations are comfortable granting at scale. The pivotal question remains not whether this change will reshape entire industries but rather which companies will seize the opportunity to innovate on this new foundation before others.



