For most of my career, the telecommunications industry has been answering one question: what are we connecting?
Three major paradigm shifts. Fixed telephony connected places. Mobile communication connected people. IoT connected devices and sensors.
Agents are the fourth, and they break the pattern.
A device reports. An AI agent decides. It calls a tool, spends money, and negotiates with other agents on behalf of a person or a company.
That moves identity out of the login and into liability.
Every action now has to answer four questions:
- Who authorized it?
- What were the limits?
- What data informed it?
- Who is accountable when it goes wrong?
This is not a theoretical problem. FIDO has a working group on it. The Decentralized Identity Foundation has a specification. Mastercard, Visa and Google are each advancing a framework of their own. On August 4, Cloudflare announced wallets and a payments handle that give an agent an identity and a way to spend. These are separate efforts, not one standard.
The layer will be built. The open question is what it gets anchored to.
Europe has an anchor. Bank-issued eIDs, such as Sweden’s BankID, have operated successfully for years under the Electronic Identification, Authentication and Trust Services framework, and the European Digital Identity framework is creating a common wallet infrastructure across member states.
The United States has no equivalent national identity layer. The closest thing people have today is a state-issued driver’s license stored digitally in their iPhone’s Wallet. But a digital wallet is a holder for a digital document. It does not create an identity framework in which machines can verify authority, delegation, and accountability.
This is where mobile network operators matter, but the usual argument is wrong.
Operators should not become identity providers. They have tried that before, and identity ownership is not their business.
What operators do have is unique: the ability to attest that a real, identity-checked, billed subscriber is bound to a device at national scale.
That is valuable, but authentication is only the beginning.
Knowing that a human is present tells you nothing about which agent that human delegated to, what permissions were granted, how long they last, or what happened after the action was taken.
The missing layer is not identity. It is the persistent record of agency: who acted, under what authority, using what information, and with what accountability.
In the past month, I have spoken with people from several firms, and although we came from different directions, we reached the same conclusion. One arrived through ticket fraud. One through content provenance. I arrived through chain-of-title in licensing.
Three routes. One requirement: a verified principal, machine-readable permissions, and a trusted record of what happened.
Cloudflare has now shipped the first two. Its wallets give an agent a stable identity, and the guardrails around them — an allowance, an approved merchant list, a maximum transaction size — are machine-readable permissions in all but name. Reserving a handle is live; the rest is promised for the coming months.
What the announcement does not describe is the third. Not what is retained, nor for how long, nor under whose authority an action was taken, nor who answers for the outcome. A payment receipt proves an agent paid. It does not prove the agent was allowed to.
So the layer is being built, quickly, by serious people, and it is being built as identity and payments. Nobody is shipping the record at scale, in the United States or in Europe.
Which is the question I would put to the industry: if operators authenticate and wallets identify — and now pay — who keeps the record?