Existing identity standards assume a person or a legal entity initiates a transaction. When an AI agent initiates it instead, there is no established way to verify what the agent is, what it is permitted to do, or who answers for it. Agent permissions also do not expire the way human access does when someone leaves an organisation.
