The agent era is becoming an identity problem

Several stories today point to the same shift: agents are no longer just chat features; they are being given dedicated hardware, internet-facing identities and enterprise access controls. For builders, the moat may move from model quality to the trust layer that lets agents act without turning every workflow into a security exception.

·4 min read

TechCrunch

Vint Cerf is working on a plan to unleash AI agents on the open internet

Vint Cerf is working on a plan to unleash AI agents on the open internet.

techcrunch.com

The agent era is becoming an identity problem

A keyboard with a reasoning-level dial is a very funny object until you realise what it means.

OpenAI’s Codex Micro puts Codex controls under a developer’s fingers. The obvious read is hardware theatre: another niche device for people who already own too many keyboards. I think the more interesting read is organisational. OpenAI is treating the coding agent less like a text box and more like a worker with state, permissions and supervision needs.

That is the shift hiding across this week’s agent stories. The agent era is becoming an identity problem.

Agents need badges

Software used to have users. Then it had service accounts, API keys and bots. Agents blur those categories. They browse like users, call APIs like machines, make choices like delegated workers and sometimes need to explain what they did after the fact.

That is why TechCrunch reported that Vint Cerf is advising an effort to build identity architecture for AI agents on the open internet. The important bit is not “agents on the web”, which has been the demo reel for months. It is the plumbing question: how does a website know whether it is dealing with a human, a bot, a company-approved agent, a rogue scraper, or a delegated assistant acting with bounded authority?

The web has spent decades making identity awkward for humans. Passwords, cookies, OAuth pop-ups, CAPTCHAs, single sign-on and fraud checks are all patches over the same problem: who is this, and what are they allowed to do? Agents multiply that problem because they are supposed to act at speed and scale. If every agent action needs a human checkpoint, autonomy collapses. If no action does, security collapses.

That is the wedge for companies like Oak. TechCrunch reported that Oak has emerged from stealth with $60 million in funding and a product aimed at governing identity across humans, machines and AI agents. Strip away the enterprise phrasing and the pitch is blunt: legacy access control was already hard to reason about, and autonomous software workers make it worse.

This matters for builders because the product boundary is moving. The winning agent product may not be the one with the best demo. It may be the one that can answer boring procurement questions without flinching: whose credentials does it use, what can it read, what can it write, where are logs kept, how is approval handled, and what happens when it misbehaves?

The moat moves to trust

The Grok Build episode points in the same direction from the opposite side. According to Techmeme’s aggregation, SpaceXAI open-sourced Grok Build under an Apache 2.0 licence after backlash over user repositories being uploaded to a Google Cloud bucket. Whatever the full chain of decisions, the product lesson is simple: a coding agent that can inspect a repo is not a normal developer tool. It sits inside the crown jewels.

That changes what users demand. “Trust us” is a weak posture when the tool can read private source code. Open-sourcing the harness becomes a form of damage control, but also a signal of where the market is going. Sensitive agent tools will be judged by output quality, auditability, containment and clear data handling.

There is an old parallel in the workplace. Factories did not scale merely because machines became more powerful. They scaled because firms built systems around them: time clocks, ledgers, foremen, safety rules, insurance, standardised roles. The machinery mattered. The accountability layer made it governable.

AI is heading through the same door. Codex Micro gives the agent a physical control surface. Cerf’s project asks how agents identify themselves online. Oak is selling the control plane. Grok Build shows what happens when trust is assumed rather than engineered.

For product teams, the takeaway is uncomfortable but useful: model capability is becoming table stakes faster than many expected. The next moat is the trust layer that lets an agent act without turning every workflow into a security exception.

The agent that wins may not be the smartest one. It may be the one with the best badge.


Read the original on TechCrunch

techcrunch.com

Stay up to date

Get notified when I publish something new, and unsubscribe at any time.

More news