Agents Move From Answering to Acting
Kenneth Shek is the Project Lead of Moca Network and Director of Projects Management at Animoca Brands. Shek’s argument begins with a simple prediction: Artificial intelligence (AI) agents will stop behaving like passive AI chatbots and start acting as digital representatives. “The way I think about this is very simple: every user will eventually have their own agent,” Shek told Bitcoin.com News.
The Moca Network CEO added:
“Once that happens, the agent is not just a chatbot anymore. It is not just answering questions. It is doing things for you. It may spend your money, verify your data, redeem your rewards, use your airline status, or buy something on your behalf.”
That transition raises questions that ordinary passwords and application programming interface (API) keys were never designed to answer. API keys let one piece of software communicate with another, while delegated credentials grant limited access to an outside service. Neither mechanism, by itself, proves the complete relationship among the agent, the person behind it and the precise boundaries of its authority.
“You cannot just give the agent your raw key,” Shek said. “You cannot just give it a broad API credential and hope everything works out. That is too much power, and it does not answer the real questions. Who is behind the agent? Which user does it represent? What data is it allowed to verify? How much money can it spend? Where can it spend? For how long? And if something changes, can I revoke that permission?”
Businesses Start Screening for the Right Bots
The commercial internet has spent years trying to identify and block automated traffic through CAPTCHA tests, fraud systems and bot filters. Shek expects that model to change as businesses begin treating approved AI agents as potential customers rather than unwanted visitors.
“I have said before that the world is moving from screening out bots to screening for the right bots,” he explained. “Before, websites used CAPTCHA to block bots. Now, many businesses actually want the right agents to come in, because those agents may become customers, buyers, or transaction flow. But the business still needs to know: Is this a good bot, who is behind it, and is it allowed to pay?”
Shek added that identity becomes the source of those answers. A trusted agent would need to prove that it is connected to a real user, that the user authorized a particular action and that the authorization remains valid. “That data source behind a good bot or bad bot is identity,” he said.
Users Set the Boundaries
Shek describes provable agent identity as “identity plus agent.” Under that model, the user remains at the center, while the agent receives specific, revocable permissions to interact with payments, commerce, loyalty programs and personal data.
“The agent can only act on those spokes if the user can define the policy,” Shek remarked during the interview.
Moca Network’s AIR system is intended to add that policy layer to its existing identity infrastructure. According to Shek, an artificial intelligence (AI) agent could receive permission to use or verify selected information without gaining permanent control over a user’s accounts. “The agent can spend money, use data, and verify data on behalf of the user, but only in a safe, privacy-preserving, user-controlled way,” he said.
Everyday Transactions Expose the Identity Gap
“If I want my agent to buy a bottle of alcohol online, the supermarket needs to verify my age, even though the agent is the one doing the action,” Shek noted. “If I want my agent to use my airline status for priority booking or points attribution, the airline needs to verify my loyalty status through the agent. If I want my agent to spend money, I need to control how much it can spend, where it can spend, when it can spend, and for how long.”
“All of that is still identity,” he added. “It is just identity plus agent.”
Credentials Limit What Gets Revealed
Shek suggested that users could share information through full disclosure, selective disclosure or technology leveraging zero-knowledge proofs. Full disclosure reveals the entire credential. Selective disclosure reveals only the fields needed for a transaction. A zero-knowledge proof allows someone to prove that a condition is true without exposing the underlying data.
“What AIR enables is a cross-app SSO which resolves into a single unified identity, and enables data to be shared by users from one app to another via verifiable credentials,” Shek stated. “All data with explicit consent, revocable, and fully controlled by the users.”
Moca Extends Its Existing Identity Stack
Shek explained how Moca Network is building on its existing identity infrastructure.
“Machine identity is basically leveraging the already fully built enterprise-grade identity infrastructure,” Shek elaborated, “and adding principal-agent binding and policy and agent delegation management, which gives user control of what, how and when data agents could use to verify with applications or agents on behalf of the principal.”
Components that could transfer into agent identity include decentralized data storage for encrypted, continuously available user data; onchain issuance and verification for identity records and audit trails; and cross-chain interoperability across different blockchains and wallets, among numerous others.
Permissioning Becomes the Deciding Test
“Think a hub-and-spoke model,” the Moca Network executive remarked. “Everything starts from the user as the hub with all data controlled by the user. The spokes are the many agents the user would own. With AIR, the user could control which agent could verify what data, for how long, by which verifier.”
“All user data are accessible by the user only via the always-on decentralized data storage,” Shek concluded, “and users could choose to grant to and revoke from any data verifications, all cryptographically governed.”
The next test will be whether companies adopt interoperable credential standards, whether users understand and trust AI agent permission controls and whether businesses are willing to pay for repeated verification. As AI agents proliferate and gain access to more financial services, personal records and commercial platforms, provable identity may determine whether they remain sophisticated assistants or become trusted participants in the wider economy.
Interview,AI agents,Artificial intelligence (AI),interviewAI agents,Artificial intelligence (AI),interview#Moca #Network #CEO #Explains #Agents #Provable #Identity1785968773

