Before DNS, you reached a computer on the early internet by knowing its number. Every machine kept a file called HOSTS — a hand-maintained list mapping names to addresses, copied around by hand. It worked while the network was a few hundred machines run by people who knew each other. It fell apart the moment the network outgrew the point where everyone could be vouched for by reputation. DNS replaced the honour system with a real one: a way to find, name, and verify any machine on earth, at machine speed, with no human in the loop to swear you were who you said.
The agent economy is running on the honour system right now. It is about to hit the same wall.
The claim
Identity is the second layer of the dependency stack — the layer that answers a question orchestration cannot. Not what happened, but who did it, on whose authority, and can they prove it? When one agent calls another, when a fleet from one company hands work to a fleet from another, something has to establish that the caller is what it claims to be and is allowed to do what it is asking. Today, nothing does. The company that builds that layer will occupy the position Verisign has held for a generation: a toll booth on every interaction.
Why agents can’t work without it
The current state of agent authentication, put plainly, is API keys and prayer. A key gets pasted into a config file, shared between services, and trusted forever, because there is no standard for anything better.
OAuth — the machinery behind every “Log in with Google” button — was built for humans. It assumes a person opens a browser and clicks. It has nothing to say about an agent fleet authenticating to another agent fleet at machine speed, without a human, across an organisational boundary. Take a routine workflow: customer onboarding runs as identity verification, then a financial-history check, then risk assessment, then account creation. Every hand-off is one agent asking another to act on a customer’s behalf. If you cannot prove which agent made each call, under whose authority, you cannot authorise it safely, audit it afterwards, or assign liability when it goes wrong. Strip identity out and the whole chain runs on trust nobody can verify.
The pattern that keeps repeating
Every network that ever carried value had to answer “who are you, and can you prove it” before the value could move. The internet is the clearest case. HTTPS went from roughly 10% of web traffic in 2010 to about 90% by 2020 — seven to eight years from optional to something a browser flags you for lacking. DNS made machines discoverable; SSL made them verifiable; only then could a stranger safely hand a website a credit card. Agent identity is sitting at the pre-DNS stage of that arc — API keys with no universal standard, fine at small scale, certain to break the moment millions of agents have to discover and authenticate each other across company lines.
Where the value actually goes
Watch who is funding the plumbing. Kite raised $18 million in 2025 specifically to build cryptographic identity and trust infrastructure for the agentic web — an early marker, the way LangChain’s raise marked orchestration. The structural prize is large and specific: Verisign is worth tens of billions for managing a couple of domain extensions, and whoever sets the standard for agent identity occupies the same kind of position — the DNS of the agent economy. My dated calls sit on top of this. Cryptographic attestation of agent actions becomes mandatory for enterprise deployment by 2030 (PRED-009); the leading agent trust-and-identity company is worth more than $50 billion by 2031, more than any single agent application company (PRED-010). Identity and attestation are twinned — identity establishes who an agent is, attestation proves what it did — and together they anchor a dependency layer I expect to clear $100 billion by 2030 (PRED-003).
Who is positioned to build it
Here is the part most coverage misses. Identity is one of the five components of the dependency layer, and one country has already built population-scale identity and payments rails from nothing. Aadhaar is the largest digital identity system on earth; UPI processes over ten billion transactions a month. India did not buy that infrastructure — it built it, at civilisational scale, before anyone else attempted it. A country with that institutional muscle memory is unusually well-placed to build identity again, this time for agents. It is a large part of why I expect India to rank second globally in agent-infrastructure revenue by 2030 (PRED-011). The agent trust layer is the next India Stack.
What to watch
The tells are specific. Google’s A2A protocol and Anthropic’s MCP are the most credible emerging standards, but both solve adjacent problems — inter-agent communication and tool access — not identity verification; watch for the standard that actually authenticates one agent to another. Watch the IETF, which has opened preliminary discussions about extending OAuth for machine-to-machine agent authentication. And watch the law: the first statutes requiring a unique, traceable identity for every autonomous agent (PRED-015) will convert identity from optional to unavoidable, the way Chrome marking HTTP “not secure” did for HTTPS. Someone will build the Let’s Encrypt of agent identity. That is the moment.
The contrarian point
Everyone is trying to secure the model — the prompt, the weights, the output. But the question production actually asks the first time an agent moves money is not “was the model good?” It is “who authorised this, and can you prove it?” That is an identity question, and identity is the precondition for ever trusting an agent with a consequence. The model you run is a runtime detail. The identity layer is where authority, audit, and liability live.
The trillion-dollar businesses of this economy will not own the smartest agent. They will own the layer that can prove which agent did what — and on whose authority.
The AI Agent Economy — Why the Next Trillion-Dollar Industry Has No Employees is out now on Amazon and Notion Press. This series expands Chapter 2: the dependency layer.
Go deeper: I unpack the agent identity problem here → https://atin-agarwal.com/blog/prediction-agent-identity-crisis/?utm_source=substack&utm_medium=newsletter&utm_campaign=aae-17

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.