AI agents force digital trust rethink: Why identity isn’t enough
AI agents are forcing businesses to rethink digital trust beyond authentication and identity verification. The UK’s Digital Verification Services framework leads on identity but lacks provisions for delegated authority, leaving gaps in AI-driven workflows. Startups and operators must now verify not just who is acting, but what they’re authorized to do—and limit exposure to misuse.
Editor, Lazyfounder

AI agents are forcing businesses to rethink digital trust beyond authentication and identity verification. The UK’s Digital Verification Services framework leads on identity but lacks provisions for delegated authority, leaving gaps in AI-driven workflows. Startups and operators must now verify not just who is acting, but what they’re authorized to do—and limit exposure to misuse.
30 SEC SUMMARY
- AI agents are reshaping digital trust by requiring verification of authority and delegation, not just identity.
- Current infrastructure struggles to distinguish between humans and AI agents or verify their authority.
- The UK’s Digital Verification Services (DVS) framework advances identity verification but lacks delegated authority provisions for AI.
- Businesses are advised to grant minimal, task-specific authority to AI agents and verify it before actions are taken.
- Expanding the DVS framework to include delegated authority could address security gaps in AI-driven transactions.
TABLE OF CONTENTS
- AI agents challenge traditional digital trust models
- UK advances identity verification but lags on delegation
- Businesses must adopt new practices to mitigate risks
- Background: Why delegation matters
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- AI agents require verification of authority and delegation, not just authentication and identity.
- Most existing infrastructure cannot distinguish between humans and AI agents or verify their authority.
- The UK’s Digital Verification Services (DVS) framework advances identity verification but lacks delegated authority provisions.
- Businesses are advised to grant AI agents minimal, task-specific authority and verify it before actions are executed.
- Expanding the DVS framework to include delegated authority could address security gaps in AI-driven workflows.
AI agents challenge traditional digital trust models
According to TechRadar, digital trust has long operated on the assumption that a human is behind every login or decision. AI agents are disrupting this model by introducing the need to verify not just identity, but also authority and delegation. The shift means businesses must now answer questions like who authorized an action, what the agent is permitted to do, and for how long.
Current infrastructure, however, was not designed for this complexity. Most systems can authenticate a user or device but cannot distinguish between a human and an AI agent—or between a legitimate agent and an unauthorized one. This gap creates risks for transactions, administrative tasks, and other automated workflows where oversight is minimal.
UK advances identity verification but lags on delegation
The UK has made progress in identity verification through the Data (Use and Access) Act, which established Digital Verification Services (DVS) on a statutory footing. The DVS Trust Framework provides a standardized approach to verifying identities, but it does not address delegated authority—for humans or AI agents.
TechRadar reports that while identity verification confirms who someone is, it does not clarify what they—or an AI agent acting on their behalf—are authorized to do. This limitation leaves a critical gap in scenarios where AI agents operate with delegated authority, such as automated payments, data access, or contractual agreements.
Businesses must adopt new practices to mitigate risks
To reduce risks, TechRadar recommends businesses adopt practices that limit the scope of AI agent authority. Agents should be granted only the minimal necessary permissions for specific tasks, reducing exposure if an agent is compromised or misconfigured. Broad, standing access increases the potential for damage, especially in high-stakes sectors like finance or healthcare.
Businesses are also advised to verify authority before an AI agent acts, rather than discovering issues after the fact. This requires systems capable of answering five key questions for any agentic action: who is acting, who authorized it, what it can do, under what constraints, and whether the authority remains valid. Machine-verifiable mandates—documents or tokens that encode these details—could provide a scalable solution, potentially stored and managed in digital wallets alongside verified credentials.
Background: Why delegation matters
The rise of AI agents builds on trends in cybersecurity and digital identity, where reliance on static authentication—like passwords or biometrics—has long been insufficient. Recent research highlights that nearly half of organizations fail cyber resilience tests during attacks, often due to poor coordination or unchecked authority. AI agents amplify these risks by automating actions at scale, making delegation errors harder to detect and more costly.
Meanwhile, businesses face pressure to reduce IT costs, sometimes at the expense of security or governance. Cheaper hosting solutions, for example, may lack the safeguards needed to manage delegated authority, creating hidden vulnerabilities. The challenge of AI agents extends this problem: cutting corners on authority verification could expose startups to fraud, regulatory fines, or reputational damage.
What this means
Lazyfounder analysis — our interpretation, not reported fact.
For founders and operators, this shift signals a fundamental change in how digital trust must be architected. Authentication alone is no longer sufficient—systems must now verify not just who is acting, but what they’re authorized to do. This complicates product design, especially for startups building AI-driven workflows or delegated authority features.
The UK’s progress with the DVS framework is a step forward, but the absence of delegation standards leaves a gap that could become a liability as AI agents proliferate. Startups in fintech, healthcare, or any sector handling sensitive transactions will need to proactively design for these checks—or risk exposing users to fraud or misuse.
The call for machine-verifiable mandates also hints at an emerging opportunity: tools that dynamically validate AI agent authority in real time. Founders who solve this problem could create a competitive moat, especially in regulated industries where compliance is non-negotiable.
Key takeaways
- AI agents demand a new layer of trust infrastructure beyond traditional authentication and identity verification.
- Current systems are unprepared to verify the authority of AI agents, creating security and operational risks.
- The UK’s DVS framework is a model for identity verification but lacks provisions for delegated authority.
- Businesses must adopt practices like minimal authority grants and pre-action verification to mitigate risks.
- The absence of standards for AI agent authority could become a bottleneck for scaling AI-driven transactions.
FAQ
What’s the difference between identity verification and authority verification?
Identity verification confirms who someone—or something—is, such as through biometrics or government-issued credentials. Authority verification determines what they are permitted to do, such as accessing data, approving transactions, or acting on behalf of another entity. AI agents require both, as they often operate with delegated authority.
Why can’t current infrastructure handle AI agent authority?
Most systems were designed for human users, where authority is often implicit (e.g., an employee’s role) or managed through static permissions. AI agents introduce dynamic, delegated authority that changes based on tasks, temporal constraints, or revocation. Existing infrastructure lacks the flexibility to verify these nuances in real time.
What risks do businesses face if they ignore delegated authority?
Without proper verification, businesses risk unauthorized actions by AI agents, such as fraudulent transactions, data breaches, or regulatory violations. Compromised or misconfigured agents could exploit broad permissions, leading to financial losses, legal liabilities, or reputational damage. High-risk sectors like finance or healthcare are particularly vulnerable.
How could digital wallets help manage AI agent authority?
Digital wallets could store machine-verifiable mandates—documents or tokens that encode an AI agent’s authority, including who authorized it, what it can do, and any constraints. This would allow businesses to dynamically validate authority before an agent acts, reducing the risk of misuse. Wallets could also integrate with existing identity verification systems for seamless verification.
Related on Lazyfounder
Sources
- TechRadar · 2026-10-05
Who's really behind the login? AI agents are forcing a rethink
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


