For years, AI just talked. Now it’s starting to do things: book stuff, move money, log into systems on your behalf. And the second software can take real actions, an old question comes roaring back. Who exactly is this, and what’s it allowed to touch? Agent identity is the answer the industry is scrambling to build.
What it means
Give each AI agent its own ID badge, and suddenly you can confirm who it is and pin down what it’s allowed to do. That’s the whole idea.
Before this, agents mostly borrowed a human’s login or shared one generic account, which is a mess. Nobody could tell which agent did what, and a shared account usually had way more access than any single task needed. A real agent identity gives each bot its own credentials, its own limited permissions, and a log of everything it does. Google’s version even records both the agent’s ID and the user’s ID on every action, so you can see the agent did something and on whose behalf.
Why it matters
It fixes the over-powered bot problem. When a bunch of agents share one account, that account tends to hold the keys to everything, which is exactly the setup attackers love. Give each agent its own identity and you can hand it the least access it needs for the job, and nothing more.
It’s turning into the backbone of agents that spend money. In August, Cloudflare gave agents both an identity and a wallet, so an agent can prove who sent it and buy things within limits you set. Their CEO put it well: when an agent shows up at your door, you need to know who sent it. Kinda hard to have “AI does your shopping” without first settling “which AI, and says who.”
The standards are a genuine mess right now, and I’d rather just say so. Google, OpenAI, and Cloudflare are all pushing their own rival approaches, and none of it really works across platforms yet. So an agent that’s trusted in one company’s system might be a total stranger in another’s. It’ll sort out eventually. Just not yet, and probably not cleanly.
Simple example
Think about a contractor working in an office building. You don’t just let some stranger wander the halls. You give them a badge that says who they are, which doors it opens, and which floors are off-limits, and every swipe gets logged. If they turn out to be trouble, you kill the badge and they’re locked out.
Agent identity is that badge, for a bot. Instead of letting an AI roam your systems on a borrowed keycard, it gets its own, with its own limits, so you always know who’s in the building and what they can touch.

