Anonymity in the agentic economy

Written byNicole Dunn
CategoryInsights
DateAugust 5, 2026
Share this article
  • Link copied!
Anonymity in the agentic economy - hero image

What we can learn from the internet’s first casualty

In the last 12 months, the internet’s primary consumer changed.

Machines now account for more than half of measured web traffic. The fastest growing segment is agentic AI: software acting on someone’s behalf, up 7,851% year over year. A new economic paradigm is forming, one where machines become the buyers. And it is rewriting the rules of the web as we know it.

The first casualty was the internet’s ad-funded business model. Websites price attention based on views, clicks, and conversions attributable to a human. Agents break this funnel entirely: they don’t view ads, don’t click, and don’t convert. Claude reads more than 70,000 pages for every visitor it refers; Google U.S. search traffic to publishers fell ~38%; Business Insider laid off 21% of staff citing “extreme traffic drops outside of [their] control.” It’s for this reason that Cloudflare announced it will block agents by default on ad-supported websites.

This is just the beginning of the agentic economy. In the near future, agents will select products, negotiate prices, and complete purchases. They will initiate payments, open bank accounts, make investment decisions, and allocate treasury balances. Anything you delegate today to an employee, adviser, or person acting under a power of attorney is plausibly in scope.

So, what can we learn from the internet’s first casualty?

The delegation economy

The ad model broke because the web had no way to tell who was on the other end of the interaction.

Today, agents can show up as either a human it is impersonating, or as an anonymous bot. Neither is actually true.

An agent is a new type of economic actor: it can be destroyed and respawned (non-persistent); instantiated in a million copies (non-singular), domiciled ambiguously (non-located), acts in milliseconds, and holds no legal personhood. It is linked to a principal (the person or business it acts for) and a platform operator (that runs it), but collapsed into neither.

Economic systems are built around actors with relatively stable identities. People and businesses accumulate histories, assets, obligations, licenses, reputations, and liabilities. Their actions can be evaluated in the context of what came before, and consequences can follow them into the future. An agent, by contrast, can disappear immediately after acting.

In times of radical change, I find it helpful to ask both what breaks, and what will stay the same?

What breaks: Every system, model, and policy that assumes the human is the actor. Take e-commerce: today’s internet assumes a person is making the purchase and participates at each step of the checkout. Interfaces, authentication, and risk signals are all built around human interaction.

With agents, authentication may not happen at the moment of purchase; authority is delegated rather than exercised directly, and intent becomes more obscure.

What stays the same: Accountability. Bearing consequences requires something to lose that persists: assets, liberty, legal standing, a reputation you can’t shed by reinstantiating. An agent that can be destroyed and respawned bears no consequences by design. Its actions must therefore ground out to a human or firm that can be held to them.

This means that the agentic economy is a delegation economy. For the foreseeable future, agents will act as representatives of people and businesses. The core trust problem, then, is accountability routing: binding every agents’ action back to a principal who is accountable.

Anonymity in the agentic economy - pattern graphic

Identity, delegation, audit

Accountability routing requires three distinct layers: identity, delegation, and audit.

Identity establishes who the agent represents. Is the principal a real person or registered business? Has that identity been verified? Is the business active and in good standing? Is the agent itself a recognized instance operated by a known platform or organization?

Delegation establishes what the agent is authorized to do. Who granted the authority? What actions are permitted? What limits apply? How long does the mandate last? Can the agent spend $10 or $10,000? Can it purchase a product but not accept financing? Can it negotiate terms but not execute the final agreement?

Audit establishes what actually happened. What instruction did the agent receive? What information did it rely on? What decisions did it make? What terms did it accept? Did it remain within the scope of its mandate? Where should liability fall if something went wrong?

These layers cannot substitute for one another. Identity alone does not prove authority; a verified agent acting for a real company could still exceed its mandate. A mandate is not sufficient if the underlying principal is fraudulent, dissolved, sanctioned, or impossible to hold accountable. Neither identity nor delegation is sufficient without an auditable record of the action itself.

The missing trust layer

Existing trust infrastructure is not designed to verify, scope, or underwrite ephemeral software acting on behalf of human or business principals. Every mechanism the internet has (such as passwords, sessions, OAuth grants) answers: is this the right human? An agent using those mechanisms can only impersonate. Delegation requires the agent to be legible as an agent: an actor with its own identity, bound to its principal, without pretending to be the principal.

Early experiments worked around this gap with closed loops: agents transact only with pre-vetted sellers. That works for coding agents, where a relatively small set of tools provides most of the value. It doesn’t scale to typical e-commerce, where supply is fragmented, merchant participation is required, and buyers expect agents to navigate the open web. It also doesn’t scale to enterprise procurement, financial services, or transactions involving regulated products and contractual obligations.

Open agentic commerce requires counterparties to make risk decisions about unfamiliar agents. Today, businesses primarily classify traffic as human or bot. In the agentic economy, that distinction becomes less useful. Some bots will be legitimate representatives of valuable customers. Some apparently human traffic will be automated, unattributable, or malicious.

What is missing is an interoperable, attested mechanism through which an agent can declare which human or business it represents.

Until this layer exists, websites will keep blocking agents at the checkout or the firewall. At best, letting agents in means accepting a collapsed business model or guest checkout experience at scale, disintermediating hard-won customer relationships. At worst, it exposes merchants to mass-scale, machine-speed fraud vectors that their existing systems are not built to handle.

The ad-supported web has already shown us both possible endings. If agents enter commerce as anonymous bots, merchants and financial institutions will block them. If they enter as verified, attributable representatives of real businesses and principals, the agentic economy scales.

Baselayer is building the infrastructure for the second future.

// LinkedIn post:

In an agentic economy, the risk paradigm shifts: agents introduce a new type of actor that intermediates digital handshakes and transactions, requiring new forms of identification and verification.

Baselayer is a key and integral partner for how we're leveraging Al to enhance our Identity Products. Our combined offering helps hundreds of financial institutions feel confident instantly onboarding & supporting millions of small businesses every
Ron Whyte
Ron WhyteSenior Vice President & General Manager - FIS Decision Solutions; PRESIDENT - Chex Systems, Inc.
Share this article
  • Link copied!
Call to Action
Join the Business Risk Network
Book a demo