For most of my career, the industry has been answering one question: what are we connecting?
Fixed telephony connected places. Mobile connected people. IoT connected devices.
Agents are next, and they break the pattern.
A device reports. An agent decides. It calls a tool, spends money, and negotiates with other agents on behalf of a person or a company.
That moves identity out of the login and into liability.
Every action now has to answer four questions:
- Who authorized it?
- What were the limits?
- What data informed it?
- Who is accountable when it goes wrong?
This is not a theoretical problem. FIDO has a working group on it. The Decentralized Identity Foundation has a specification. Mastercard, Visa and Google are each pushing a framework of their own. These are separate efforts, not one standard.
The layer will be built. The open question is what it gets anchored to.
Europe has an anchor. Bank-issued eID has operated for years, and the European Digital Identity framework is creating a common wallet infrastructure across member states.
The United States has no equivalent national identity layer. The closest thing most people have is a driver’s license stored in a phone wallet. It is a holder for a document. It does not create a network where machines can verify authority, delegation and accountability.
This is where operators matter, but the usual argument is wrong.
Operators should not become identity providers. They have tried that before, and identity ownership is not their business.
What operators do have is unique: the ability to attest that a real, identity-checked, billed subscriber is bound to a device at national scale.
That is valuable, but authentication is only the beginning.
Knowing that a human is present tells you nothing about which agent that human delegated to, what permissions were granted, how long they last, or what happened after the action was taken.
The missing layer is not identity. It is the persistent record of agency: who acted, under what authority, using what information, and with what accountability.
In the past month, I have spoken with two people who reached the same conclusion from completely different directions. One arrived through ticket fraud. One through content provenance. I arrived through chain of title in licensing.
Three routes. One requirement: a verified principal, machine-readable permissions, and a trusted record of what happened.
Nobody is shipping that at scale. Not here, not in Europe.
So the question I would put to this industry: if operators authenticate and wallets identify, who keeps the record?