AI agents transition from novelty to essential infrastructure, prompting platform rethinks on trust and security

As AI agents become integral to digital commerce, platforms are reassessing verification and security measures in response to their increasing autonomy and the emerging risks of misuse and attack.

AI agents are moving from novelty to infrastructure, changing how online services think about trust, access and accountability. What once looked like a straightforward contest between people and bots is becoming harder to classify, because an authorised agent can now browse, negotiate and complete transactions with little or no direct human intervention. That shift is already forcing platforms to reconsider the checks they use to control abuse, from CAPTCHAs to identity verification, which were designed for a far simpler web.

The scale of the change helps explain the urgency. McKinsey has estimated that AI agents could mediate trillions of dollars in global commerce by 2030, while Bain has put the U.S. figure at hundreds of billions. The difference reflects different definitions, but both forecasts point to the same conclusion: agents are likely to become a material part of digital trade, not a marginal edge case.

That creates a practical problem for platforms. A request made by an AI agent may look identical to abusive automation, even when a real person is behind it. Security teams are therefore moving towards a narrower test: not merely whether traffic is human, but whether there is one legitimate, unique person authorising the activity. TechRadar has argued that existing behavioural models, which were built to observe human routines, are not well suited to agents that can operate continuously, switch systems rapidly and follow task-driven instructions rather than personal habits.

One of the more developed responses comes from World, whose World ID system is described in its documentation as a privacy-preserving way to prove that someone is real and unique without exposing personal data. The company says the protocol uses zero-knowledge proofs and related techniques so a service can verify eligibility without learning the user’s identity or linking activity across apps. World has also extended the idea into agent delegation through AgentKit, allowing a verified user to pass cryptographic proof to an AI agent.

Even so, the security stakes go beyond access control. PC Gamer recently reported that AI agents are already appearing on both sides of malware campaigns, including incidents in which malicious repositories were disguised as agent skills and agents were themselves used in attempted attacks. That underscores the central tension in the market: the same autonomy that makes agents useful also makes them harder to monitor, easier to mislead and potentially more dangerous when they are compromised. Any proof-of-human layer will have to withstand not only everyday fraud, but also adversaries who are adapting as quickly as the tools themselves.

What emerges is not a simple replacement for KYC or bot filtering, but a broader identity layer for machine-mediated commerce. The likely outcome is a mix of standards, with different platforms choosing different balances between privacy, friction and assurance. Whether World’s approach becomes a default or merely one option among several will depend on adoption, interoperability and whether it can prove more resilient than the controls it is meant to supplement.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.