For as long as products have had customers, the answer to that question was assumed rather than verified. You knew your customer through an application, an identity check, a consent step, a signature. The journey was built around that knowledge. Every disclosure, every checkpoint, every preference toggle existed because a human was presumed to be on the other side.

That presumption is no longer safe. The agent-mediated journey is not a future scenario; it is the current condition — a customer sending software to act for them: to search, compare, apply, buy, dispute. And it is arriving inside organizations whose entire customer architecture — how they authenticate, disclose, price, route, and execute — was designed for someone else.

The question is not whether to optimize for agents. It is whether the journey itself has to be rebuilt, with agent mediation as the default assumption and human touchpoints as deliberate design decisions rather than inherited ones. That is a larger question than it looks, and the reason it is larger is the whole point of this piece.

The identity problem has a name

Start with the part the industry has already named. Autonomous systems executing searches, logins, and transactions on a person’s behalf expose a gap in the frameworks built entirely around explicit human action — the identity and authentication assumptions that presume a person, present, acting. The name for the answer is Know Your Agent. KYA is to AI agents what Know Your Customer is to people: a way to establish who is acting, under what authority, and within what limits.

It is not theoretical. Identity providers are already shipping the substrate — signed credentials issued to authorized agents, session-level consent limits, transactions co-signed by both the user’s and the operator’s keys, agents linked back to a verified human identity through scoped consent tokens and continuous monitoring. Ping Identity frames the principle in one line: autonomy without identity is ungovernable. Supervisors across several jurisdictions are converging on a single idea — autonomy must not dilute accountability. The hardest question is not whether an agent can act. It is whether the organization can prove the agent had the authority to act.

03 · what it is allowed to do 01 · who is the agent Agent credential issued by a known identity provider signed key — verifiable, not claimed linked back to a verified human 02 · who authorized it Delegation principal category limit expires a verified human financing terms $5,000 in 24 hours in scope accepts $4,000 of terms recorded against the exact terms presented — the record extends out of scope attempts $9,000 refused at the boundary — and logged exactly as carefully 04 · how far the authority travels single hop is solved — recursive delegation is not human agent anchor lost KYC asks who the customer is · KYA asks what the agent may bind you to
The same four questions the standards are converging on, drawn as one object. One and two are what the agent presents; three is the boundary the system holds at every action; four is the one no shipped protocol answers. And the reason the seam has to be designed rather than adopted.

The reader changed while the site stayed the same

57.5% Share of web traffic that is now automated rather than human — the crossover Cloudflare recorded on June 3, 2026, roughly eighteen months ahead of its own forecast. Your pages are read by a machine before a person ever sees them.
~23,951 Pages one major AI crawler consumes per single referral it sends back. The surface is not being browsed. It is being harvested.

Sources: Cloudflare Radar / Matthew Prince, June 2026; crawler-to-referral ratios via Cloudflare data analysis, 2026.

The standard is already shipping

This is no longer a whiteboard conversation. Between April 2025 and 2026 the identity layer for agents went from proposal to shipped specification — several of them, from different corners of the stack, converging on the same shape. The convergence is the signal worth reading: independent groups, with no obligation to agree, are arriving at one definition of what it means to trust an agent. The framework the Decentralized Identity Foundation now stewards, renamed KYA-OS in 2026, states it as four questions every system should be able to answer before it lets an agent act.

Those four questions are the durable part. The vendors answering them will change — some will merge, some will be absorbed into the rails, some names here will read as quaint in a year. The questions will not, because they are the shape of the problem, not a product.

Question 1 · Who is the agent? — Visa & Skyfire, 2025
A cryptographic identity, not a user-agent string. This is the layer the card networks moved on first: Visa’s Trusted Agent Protocol (October 2025) signs an agent’s identity into request headers so a merchant can verify it against a directory of registered keys; Skyfire’s KYAPay — where the term Know Your Agent first appeared commercially — attaches identity to each request as a signed token.
Question 2 · Who authorized it? — AP2 & Mastercard, 2025
The binding back to a human principal. Google’s AP2 (open-licensed, September 2025) records every agent purchase as three signed mandates — what the user intended, what the agent assembled, what will be charged — each a verifiable credential the user’s key signs. Mastercard’s Agent Pay binds a tokenized credential to a specific agent and a specific consent policy, so the authorization travels with the transaction.
Question 3 · What is it allowed to do? — converging
Scope, declared and enforced. This is where discovery protocols meet identity: an agent advertises what it is and what it needs, and the counterparty checks that against what it is permitted before any task runs. The consent policy is not a checkbox captured once — it is a boundary the system holds at every action.
Question 4 · How far does the authority travel? — open
The hardest one, and the one still open. It is not enough to know an agent was authorized; you have to know for how far, for how long, and for what. And whether it may hand that authority to another agent downstream. This is where the shipped standards stop being able to help, and it is the seam the rest of this argument lives on.

Which is the honest place to leave the standards, because it is where they honestly are. The research on these protocols is blunt about the limit: no deployed protocol can yet prove which human authorized which agent to take which action at the third or fourth hop of a delegation chain. The moment one agent delegates to another, the authorization loses its anchor. Single-hop is solved; recursive delegation is not. So the standard answers “is this a registered agent acting for someone” well, and “whose authority governs this specific act, four agents deep” not at all.

That gap is not a reason to wait for the standard to mature. It is the reason the design work cannot be deferred to it. A protocol can tell you an agent is credentialed; it cannot tell you where, in your journey, a human must re-enter to re-anchor an authority the chain has stretched too thin. That decision is yours to design — it is the seam between what an agent may propose and what your organization will permit, and no shipped spec draws it for you. The standard is arriving. The judgment about where it stops is the part that stays your job — and the organizational cost of getting it wrong, of bolting detection onto a system that never decided what an agent may be, is The Back of the Watch.

The identity layer is not fully resolved. But it has a name, active frameworks, infrastructure providers, and regulatory momentum. The organizations building their consent and identity architecture with KYA in mind will integrate the standard when it lands. The ones that aren’t will retrofit — under pressure, on someone else’s timeline.

The journey problem is bigger

The identity question is solvable. The journey question is harder, and it is where most organizations will make the expensive mistake.

Most of the conversation so far has been about making existing journeys agent-readable: structured data, API hygiene, machine-readable product information. Bolt-on legibility for a human-designed system. That is necessary and it is not sufficient. The more consequential question is whether the journey has to be rebuilt from the agent inward — with human touchpoints placed deliberately rather than assumed throughout.

This is a different kind of design problem, and it turns on one reframing: the human in the loop is not a safety feature. It is an architectural decision. You decide when the human enters, for what purpose, with what already established, and what they are being asked to affirm. Every other step can be agent-mediated. But the steps that require a human have to be designed for a human arriving from an agent-mediated upstream — not inherited from a journey that assumed the human was there from the first click.

Bolt KYA onto the old journey and you get a system that can now see the agent and still does the human thing to it anyway, faster. You detect the agent at the door and then hand it a disclosure written to be read by a person, a consent step that assumes a person was present at the beginning, an execution moment built for a person’s hand. Detection without redesign is a gear that reports the problem and changes nothing about it.

Confidence is not control

82% → 14% Executives confident their existing policies stop unauthorized agent actions, against the share of organizations that actually send agents to production with full security approval. A policy document and a runtime that can stop an agent mid-action are not the same thing.
70% Enterprise agents that hold more access than the equivalent human role — the over-permission that turns a single prompt injection into a full compromise.

Sources: Gravitee, State of AI Agent Security 2026 (900+ respondents); Teleport enterprise agent-access survey, 2026.

And the door is the wrong picture anyway. The costly failures do not happen at the wall — they happen after it, when an agent is admitted and then reaches further than it should, acts on what it should never have touched, writes where it should only have read. A surface is not a perimeter you lock or leave open. It has depth: reputation and legibility at the outer edge where the agentic world forms its picture of you, the wall itself, the membrane the wall opens onto — where every agent action is proven or stopped. And the core, which must be reachable without ever being rewritable. The identity, consent, and execution questions this essay is really about live in those inner layers, not at the door. That five-layer view is worked out in full in Own Your Surface; what matters here is that bolting a detector to the frame governs none of it.

Take the hardest case: the regulated journey

The shift shows at highest resolution where the rules are strictest, so take that case — a regulated financial product, where the law itself encodes the human assumption. It is the clearest illustration precisely because the seams are written down as statute, but the pattern generalizes to any organization whose customer journey carries obligations.

Watch a rebuilt journey, and where the human is required rather than assumed:

Pre-journey agent evaluate, pre-qualify Handoff human enters identity established Application agent + confirm human affirms the decisions Execution human required the signature cannot be delegated Servicing agent human at exceptions AGENT-MEDIATED HUMAN, BY DESIGN the human is placed, not assumed — every other step can be the agent's
agent stagehuman required
The rebuilt journey. Teal stages are the agent’s; the gold stage is where a human is required by design, not by inheritance. Bolt detection onto the old flow and every stage still assumes the person who is no longer there.

Pre-journey is the agent’s. The agent evaluates options, pre-qualifies the customer, forms a recommendation. No human is present. The organization’s obligation begins here anyway: the agent has to find accurate, complete, structured information, because a misrepresentation formed before any human arrives is still the organization’s misrepresentation.

The entry point is a designed handoff. Not a landing page tuned for conversion — an identity-establishment event. This is where KYA engages, presence is verified, and the consent architecture begins. A deliberate threshold, not a checkbox inherited from a human-first flow.

The application is agent-assisted, human-confirmed. The agent does the work; the human affirms the decisions that carry weight — the rate, the term, the identity. The confirmation is designed as a moment, with the human given what they need to affirm meaningfully.

Execution requires the human, by law. Some signatures cannot be delegated. Statutes like the E-SIGN Act require clear intent to sign and consent to transact electronically — a human standard that an agent’s prior actions cannot satisfy without a chain of custody built deliberately to support it. The question is whether everything upstream prepared the human for this moment, or dropped them into it cold.

Post-origination returns to the agent. Servicing, monitoring, anomaly detection. The human re-enters only at exception points — and those exceptions have to be designed, not discovered during a complaint or an examination.

The rebuilt journey is not a technology project. It is a product and obligation-design project that happens to require new technology. Treat it as a technical integration and you build something that looks compliant until it isn’t.

The three layers that break

Three layers fail first when an agent arrives at a journey built for a human, and they fail quietly.

The information layer. Product information was designed for human comprehension — layouts, trust signals, things a person processes emotionally. An agent parses what is structured and machine-readable. If terms, eligibility, and cost are not in data the agent can represent accurately, it misrepresents the product, skips it for a competitor with cleaner data, or surfaces it with gaps that become someone’s liability downstream. That exposure begins before the customer ever arrives.

The consent layer. The checkbox model — I agree to be contacted — assumes a human reading and consenting at the start of a human-initiated journey. In an agent-mediated one, the customer asked an agent a question, the agent evaluated options, the agent recommended, the customer said proceed. At what point in that chain was consent established, and to what? Rules written for human-to-system interaction become operationally strange when the system is interacting with an agent acting for a human.

The execution layer. Signature workflows assume a human receiving, reading, signing. Where intent-to-sign is a legal requirement, an agent’s prior actions do not satisfy it without specific architecture to carry the chain of custody. Whether agent-mediated execution holds up is not settled. It is an open question that will eventually be litigated, and the organizations with a defensible design will be the ones that treated it as a design question early.

The posture: use the window

The frameworks that govern regulated products were written for humans, and the bodies that enforce them are behind the technology — not from inattention, but because the technology moved faster than any oversight cycle was built to absorb. That lag is a window — the same readiness gap, arriving as a compliance clock. The organizations that use it to design proactively will have built defensible architecture before the scrutiny arrives. The ones that wait will retrofit under it.

Concretely, that means building the information layer for two audiences at once — the human presentation that serves comprehension, and the structured, machine-readable layer that serves the agent — with neither compromising the other. It means triggering disclosure and consent at the designed handoff, scoped correctly, with an audit trail that holds regardless of how the journey was initiated. It means treating the API surface as a real interface, because it is the one through which agents meet the product before any human does. And it means mapping, explicitly, where a human is required — by law, by regulation, by risk — and designing those touchpoints for a human arriving from an agent-mediated upstream.

Underneath all of it is a single reordering. The old journey was built around the human: every layer assumed their presence, every disclosure was written for their eyes, every checkpoint designed for their hand. The new discipline is to design the agent journey first, then decide — deliberately, defensibly, with a regulator’s eye — where the human re-enters, what they are asked to affirm, and what they need to understand when they arrive.

That is not a technology decision. It is a reorientation of how an organization thinks about who its customer is and what it owes them. The ones that make it now will set the standard. The ones that wait will meet it on someone else’s terms, on someone else’s timeline, at a cost that compounds with every cycle they let pass.

The agent is already in the journey. The only question is whether the journey was designed for it.

The agent is already in the journey. The only question is whether the journey was designed for it.

Detecting the agent is a feature any vendor can sell you. Deciding what the agent is permitted to be. And rebuilding the journey around that decision — is the work no one can hand you. It is a question of authority wearing the costume of a technical integration.

This is Part II of The agent surface. Part I — The Primary Consumer Is Now an Agent — names the shift this piece operationalizes. The whole surface, in five layers, is Own Your Surface. On the authority beneath the journey: the Organization axis draws the line an agent runs into before it runs, and the seam is where what an agent may propose meets what the organization will permit.