
Sovereign AI, The Next Episode
In the last four months, the agentic commerce world quietly shipped the most consequential piece of infrastructure nobody is arguing about. Experian launched Agent Trust in April, a “Know Your Agent” framework that binds a verified consumer to the AI agent acting on their behalf, issues a trust token per transaction, maintains an Agent Registry that continuously scores agents on their behavior.[1][2] Cloudflare enforces it at the edge. Visa’s Trusted Agent Protocol handles merchant-side verification. Skyfire supplies the identity layer.[3] Akamai joined in May.[4] Fastly in July.[5]
Nuvei announced its own KYA registry with agent risk scoring.[6] F5 wired Skyfire’s tokens into its bot defense platform.[7] Every major payment network has now shipped or unveiled a KYA primitive.
The engineering is good and the problem is real: agentic traffic to US retail sites surged 4,700% in a year,[8] and merchants cannot tell a legitimate shopping agent from a scraper.
Sovereignty was never a capability question. It’s a control question: who governs the crown jewels. Look at what got built, and ask who ends up holding what.
We’ve seen this architecture before
A private entity holds a file on you. It computes a score from behavior you didn’t consent to being observed. You can’t see the model. You can’t appeal the math. Your ability to participate in the economy depends on the number it produces. That’s a credit bureau. It took fifty years and multiple acts of legislation to put guardrails around that model for humans.
The agent economy is reconstructing it in eighteen months, with no equivalent framework, and, this is the part that should worry you, with the enforcement points already wired in before anyone thought to ask the governance question.
Here’s what makes this different from a badge on a website: the registry is checked before the request reaches your application. Fastly’s integration verifies identity, delegated authority, intent, and payment credentials at the edge.[5] That’s what makes the token worth paying for, and it means whoever runs the registry holds a switch.

Run it through the litmus test
Five pillars, five questions. Not to grade anyone pass/fail. Sovereignty is never binary. It’s control with an acceptable risk sidecar, and the point of the test is to name the risks out loud before you’re standing in front of a regulator explaining why you didn’t.
Territorial. The registry and scoring model are US-anchored. Your agents’ behavioral record lives there, whatever your data residency posture says about the rest of your stack.
Operational. You don’t control the observation pipeline. What gets logged about your agents, how long it’s retained, what signals feed the score: none of it is yours.
Technological. Closed scoring model. You cannot audit why your score moved. You cannot fork the registry. There is no self-hosted option.
Legal. A US-domiciled entity holds a record that includes consumer identity within consent boundaries. Every lawful-access question you’ve been asking about your inference layer now applies to your transaction layer.
Financial. Your agents’ ability to transact becomes contingent on someone else’s registry, priced per query, with no exit path. If your agents can’t operate without a third party’s score, you don’t have an agent strategy. You have a dependency with an agent strategy attached.
Five for five, and none of it is a build error. Experian built the half it is good at: binding a verified human to an agent and scoring behavior. The five gaps above aren’t defects in that work. They’re the half nobody in the ecosystem has built yet, and they’re the half that decides whether a European bank, a Gulf sovereign fund, or a German automaker can adopt any of this at all.
Credit where it’s earned
Not everything here is a land grab. Cloudflare’s Web Bot Auth, now with an IETF working group behind it, does something disciplined: it verifies who sent this request using HTTP Message Signatures (RFC 9421), and puts reputation scoring and end-user authentication out of scope.[9][10] It refuses to become the trust arbiter. That restraint is the best piece of architecture in this space, and the market has voted: AWS WAF, Akamai, and Vercel all gate agent traffic on it.[10]
Visa published its protocol to GitHub, built it on the same RFC 9421 foundation, and stated an intent to align with IETF, OpenID Foundation, and EMVCo.[8][11] Skyfire’s KYA protocol is open, JWT-based, and integrates without a proprietary SDK.[3]
The primitives are open. The judgment layer is where the enclosure happens. That’s the pattern worth learning to spot.
Who the registry answers to
There will be several of these registries. Experian’s. Nuvei’s. The card networks’. Probably a Chinese one, probably a European one before long. The question is who they answer to.
Not “are they secure.” They will be. Not “are they accurate.” They’ll be accurate enough. The question is structural: when a registry downgrades your agent, what is your recourse, and in whose courtroom?
Sovereignty isn’t a rating you receive. It’s the ability to keep operating when someone else changes their mind about you.
What the alternative looks like
This is not an argument against verification. Agents should be accountable. It’s an argument that accountability doesn’t require a bureau. The alternative is already technically available, and it maps back pillar for pillar:
- Verifiable credentials, not held scores. The claim is signed and travels with the agent. The registry holds proof of issuance, not a file on the subject. (Restores Operational: you control what’s observed about your own agents.)
- Local verification. The relying party checks a signature. It works if the registry is offline. No per-query meter. (Restores Financial: no metered dependency, no forced migration.)
- Portable identity across registries. If your credential only works inside one ecosystem, that’s not identity. That’s membership. (Restores Territorial: you choose which jurisdiction’s registry you sit in, and you can leave it.)
- Transparent revocation. Append-only log. If my agent gets downgraded, that decision is publicly auditable, not a black-box score adjustment. (Restores Legal: recourse exists, and it’s visible.)
- Auditable methodology. Publish how the judgment is made, or don’t ask to be trusted with it. (Restores Technological: you can inspect the thing that judges you.)
Five questions, not one score
Part of why this went unchallenged is that nobody agreed what “trusted agent” actually means. Every vendor answers a different slice and calls the whole thing trust. A merchant who integrates three of them still can’t tell you which questions are answered and which are silently open.
Here’s the frame I’d propose. Five questions, not one score:
- Identity: who is acting? Skyfire, Web Bot Auth, Visa TAP. Effectively solved.
- Authority: on whose mandate, within what limits? Experian’s Human-to-Agent Binding, Visa, Mastercard, Google AP2. Solved for consumers, nothing for enterprises.
- Conduct: how has it behaved? Experian, Akamai, F5, Nuvei. Fragmenting into closed, non-portable bureaus.
- Control: whose stack, which jurisdiction, who holds the keys? Nobody. This is where sovereignty lives, and it opens into its own five pillars.
- Recourse: who answers when it fails? Nobody.
Two of the five are empty. A third is consolidating into exactly the bureau model described above. And every enforcement point is already live.
This isn’t a competitive scorecard. Experian owns two pillars outright and has the ecosystem to reach the enforcement plane. Skyfire owns Identity. Visa owns Authority. The edge vendors own distribution. Every serious player in this market can point at a pillar and say that’s us, which means the empty pillars aren’t a market someone has to win. They’re a gap that gets filled by whoever is willing to build the half that doesn’t pay them directly.
Control and Recourse won’t be built by a bureau, because a bureau can’t credibly certify the limits of its own authority. They’ll be built alongside one, by parties with no stake in the score. Recourse in particular will take more than one: someone to hold the record, someone neutral to adjudicate, and someone with a balance sheet to pay.
Two rules make the frame usable.
No entity supplies a pillar’s evidence and issues that pillar’s verdict. Web Bot Auth already models this on purpose. It feeds Identity and refuses to judge it. An entity that issues the token, holds the registry, computes the score, and sells the query is writing the evidence and issuing the verdict from the same desk.
Ask for a vector, not a score. [Identity L3 | Authority L2 | Conduct L2 | Control L1 | Recourse L0]. A single number hides which question failed and makes a thin behavioral history look equivalent to a compelled jurisdiction. Set your own floor per pillar. The frame doesn’t set the threshold. It makes the threshold expressible.
The half nobody has built
Experian isn’t the villain. Building a registry is a correct and rational design for a company whose entire franchise is identity and fraud. They’d be negligent not to. The same is true of Visa, Nuvei, and everyone else in the picture. Each of them built a real thing that solves a real slice.
The failure is on the buy side. You are about to make your agents’ ability to transact conditional on infrastructure you didn’t design, can’t audit, and won’t govern, and you’re doing it in a year, while the standards bodies are still drafting.
There’s a second reading of that same map, and it’s the more useful one. The incumbents have built Identity, Authority, Conduct, and the enforcement plane to check them. That’s three pillars and the rails. What’s missing is Control and Recourse, and neither can be supplied by the same party that holds the registry, for the same reason an auditor can’t audit themselves. They have to come from outside, and they have to be built to a published methodology that the incumbents can point at without owning. That’s not a competitive threat to anyone in this ecosystem. It’s the piece that makes the rest of it sellable into every jurisdiction that is currently saying no.
Agentcy Labs owns pillar four. That’s the partnership.
And we own one part of pillar five: the record. An append-only, auditable log of every trust decision made about a certified stack, and a published rubric an underwriter can actually price against. This isn’t theoretical. In February, ElevenLabs became the first company to go live with an insurance policy underwriting the actions of its AI agents, made possible by certifying against a published standard (AIUC-1) with more than 5,000 adversarial simulations behind it.[12][13] Coverage follows evidence. Nobody is producing the evidence for jurisdictional control. The other two parts of Recourse (who adjudicates a wrongful downgrade, who pays when an agent causes harm) need a neutral panel and a balance sheet. Those are partnerships too.
If you’re building the other three pillars, we should talk. If you’re an underwriter, an arbitration body, or a standards group reading this, you’re in this picture whether or not the agentic commerce ecosystem has noticed yet. Nobody here has a complete answer alone. The enterprises on the other side of the table are going to start asking for all five.
One question, while the answer is still negotiable:
When my agent gets a score, who does the registry answer to?
— Amit
References / Footnotes
- Experian, “Experian Announces Agent Trust to Power Trusted AI-Driven Commerce,” 30 April 2026. https://www.experianplc.com/newsroom/press-releases/2026/experian-announces-agent-trust-to-power-trusted-ai-driven-commer
- Experian Agent Trust product page. https://www.experian.com/business/products/agent-trust
- Skyfire, “Skyfire’s KYA Protocol Is Now the Identity Layer for Experian’s Know Your Agent Framework.” https://skyfire.xyz/skyfires-kya-protocol-is-now-the-identity-layer-for-experians-know-your-agent-framework/
- Experian, “Experian Expands Agent Trust Partner Ecosystem with Akamai,” 15 May 2026. https://www.experianplc.com/newsroom/press-releases/2026/experian-expands-agent-trust-partner-ecosystem-with-akamai-to-ad
- Experian, “Fastly Joins Experian Agent Trust Ecosystem,” 24 July 2026. https://www.experianplc.com/newsroom/press-releases/2026/fastly-joins-experian-agent-trust–ecosystem-to-advance-trusted-
- Nuvei, “Nuvei Supports Visa Trusted Agent Protocol to Advance Agentic Commerce.” https://www.nuvei.com/posts/nuvei-supports-visa-trusted-agent-protocol-to-advance-agentic-commerce
- F5, “F5 and Skyfire Secure Agentic Commerce.” https://www.f5.com/company/news/press-releases/f5-skyfire-secure-agentic-commerce
- Visa, “Visa Introduces Trusted Agent Protocol: An Ecosystem-Led Framework for AI Commerce,” 14 October 2025. https://investor.visa.com/news/news-details/2025/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce/default.aspx
- Cloudflare, “Forget IPs: using cryptography to verify bot and agent traffic.” https://blog.cloudflare.com/web-bot-auth/ and “Message Signatures are now part of our Verified Bots Program.” https://blog.cloudflare.com/verified-bots-with-cryptography/
- IETF Web Bot Auth working group drafts, Datatracker. https://datatracker.ietf.org/doc/draft-meunier-webbotauth-registry/
- Visa Developer Center, Trusted Agent Protocol specifications. https://developer.visa.com/capabilities/trusted-agent-protocol/trusted-agent-protocol-specifications
- ElevenLabs, “ElevenLabs secures first-of-its-kind AI Agent insurance,” 11 February 2026. https://elevenlabs.io/blog/aiuc-announcement
- AIUC-1, the Artificial Intelligence Underwriting Company standard. https://www.aiuc-1.com/

