TTL 66
One year from now, you might tell your AI agent to buy a case of wine. It won’t need to know your name, just that you’re over 18.
For the last two decades, digital identity was simple, because the person acting and the person authenticated were always the same person: you sent the email, posted on LinkedIn, bought the book on Amazon.
That’s ending now.
We’re moving into a world where agents act for us without a direct trigger for every step. Instead of approving each action, you give a goal, and the agent decides how to reach it: talk to another agent, book a table, buy a ticket, summarize a topic.
Say I need to move a Friday meeting: I tell Totoro, it contacts the other person’s agent directly, the two negotiate a few slots, and come back with two options for us to choose from.
For that to work at scale, agents need two things.
Identification: my agent has to find yours, and know it’s really yours.
Authentication: my agent has to prove it has the right to act on my behalf, and that right isn’t binary — it comes in layers.
Buying wine, my agent should prove only that its operator is an adult and nothing else; voting, it might need to prove citizenship too; and for something more sensitive, it may need my full identity — name, place of birth, everything.
Multiply this by every task running at any moment, and you get far more agents than humans. Most will be short-lived, spun up for one job then gone; others will persist for years.
Given this situation, someone has to run identification and authentication at that scale. And we, in the Domain Industry, might be the right people to do so.
As I said at Nordic Domain Days: if we don’t solve it with the infrastructure we already have, the DNS, someone else will (Meta, Google, Apple, maybe OpenAI or Anthropic).

If someone forwarded this to you, you can subscribe.
I also publish on paolo.blog and monochrome.blog.


Leave a Reply