Artificial intelligence agents will increasingly need verifiable proof of who they represent, what they are permitted to access and how far their authority extends, according to Kenneth Shek, CEO of Moca Network.
As AI systems move beyond answering questions and begin spending money, sharing personal information and completing transactions, Shek believes conventional passwords and application programming interface (API) keys will not provide enough protection or accountability.
Shek is Project Lead of Moca Network and Director of Projects Management at Animoca Brands. He told Bitcoin.com News that AI agents would eventually become digital representatives for individuals rather than simply passive chatbots.
“The way I think about this is very simple: every user will eventually have their own agent,” Shek said.
That shift would create a need for a system capable of proving the relationship between an agent, the person it represents and the limits placed on its activity. API keys allow software systems to communicate, while delegated credentials can provide external services with restricted access. However, Shek argues that neither approach establishes the full scope of an agent’s authority.
“You cannot just give the agent your raw key,” Shek said. “You cannot just give it a broad API credential and hope everything works out. That is too much power, and it does not answer the real questions. Who is behind the agent? Which user does it represent? What data is it allowed to verify? How much money can it spend? Where can it spend? For how long? And if something changes, can I revoke that permission?”
The internet has traditionally treated automated traffic as a threat, using CAPTCHA tests, fraud detection systems and bot filters to identify and block it. Shek expects that approach to evolve as companies begin to view approved agents as customers, buyers or part of a transaction rather than unwanted visitors.
“I have said before that the world is moving from screening out bots to screening for the right bots,” he explained. “Before, websites used CAPTCHA to block bots. Now, many businesses actually want the right agents to come in, because those agents may become customers, buyers, or transaction flow. But the business still needs to know: Is this a good bot, who is behind it, and is it allowed to pay?”
For Shek, identity is the foundation of that trust. An agent would need to demonstrate that it is linked to a genuine user, that the user has approved a specific action and that the permission has not expired or been withdrawn.
“That data source behind a good bot or bad bot is identity,” he said.
Shek refers to the concept as “identity plus agent”. The user remains in control, while the agent receives limited permissions that can be revoked. Those permissions could cover payments, shopping, loyalty schemes or personal information.
“The agent can only act on those spokes if the user can define the policy,” Shek remarked during the interview.
Moca Network’s AIR system is designed to provide that policy layer on top of its existing identity infrastructure. Under the proposed model, an AI agent could use or verify selected information without taking permanent control of a user’s accounts.
“The agent can spend money, use data, and verify data on behalf of the user, but only in a safe, privacy-preserving, user-controlled way,” Shek said.
He gave several examples of how such a system might work. An online supermarket could confirm a customer’s age when an agent orders alcohol, without giving the agent unrestricted access to the user’s identity records. An airline could verify loyalty status when an agent seeks priority booking or points attribution. A user could also establish limits on spending by setting the amount, location, timing and duration of an agent’s authority.
“If I want my agent to buy a bottle of alcohol online, the supermarket needs to verify my age, even though the agent is the one doing the action,” Shek noted. “If I want my agent to use my airline status for priority booking or points attribution, the airline needs to verify my loyalty status through the agent. If I want my agent to spend money, I need to control how much it can spend, where it can spend, when it can spend, and for how long.”
“All of that is still identity,” he added. “It is just identity plus agent.”
Information could be shared through full disclosure, selective disclosure or technology based on zero-knowledge proofs. Full disclosure provides an entire credential, whereas selective disclosure reveals only the details required for a particular transaction. Zero-knowledge proofs allow a party to establish that something is true without revealing the underlying information.
“What AIR enables is a cross-app SSO which resolves into a single unified identity, and enables data to be shared by users from one app to another via verifiable credentials,” Shek stated. “All data with explicit consent, revocable, and fully controlled by the users.”
Moca Network is building the system around an existing enterprise-grade identity framework, adding mechanisms that connect a principal the user with an agent. It also includes policy controls and agent delegation management to determine what information an agent can use, how it may use it and when it may do so.
“Machine identity is basically leveraging the already fully built enterprise-grade identity infrastructure,” Shek elaborated, “and adding principal-agent binding and policy and agent delegation management, which gives user control of what, how and when data agents could use to verify with applications or agents on behalf of the principal.”
Potential elements of the model include decentralised storage for encrypted user information that remains continuously available, on-chain issuance and verification for identity records and audit trails, and interoperability between different blockchains and wallets.
“Think a hub-and-spoke model,” the Moca Network executive remarked. “Everything starts from the user as the hub with all data controlled by the user. The spokes are the many agents the user would own. With AIR, the user could control which agent could verify what data, for how long, by which verifier.”
“All user data are accessible by the user only via the always-on decentralized data storage,” Shek concluded, “and users could choose to grant to and revoke from any data verifications, all cryptographically governed.”
The system’s wider success will depend on whether businesses adopt compatible credential standards, whether users trust and understand permission controls, and whether companies are prepared to pay for repeated verification.
As AI agents gain access to financial services, personal records and commercial platforms, provable identity could determine whether they remain advanced assistants or become trusted participants in the wider economy.
Separately, Coinbase’s Base network is defending its position as an onchain distribution leader after Robinhood Chain confirmed a lead over Base.
