Identity is the Foundation of Trust between Humans and AI Agents
Do you understand the identity-related risks of your AI Agent strategy?
AI Agents will be a cornerstone of digital life in the near future. But how do we know if they are trustworthy? Is the agent working for whom it says it is? Is the human really who it claims to be? Are the various the counterparties (people, agents, businesses) who they say they are? How do we know? What is the basis of trust in this new ecosystem?
All-digital identification will be the foundation of our trust layer. And it is a complex mess right now.
The good news is that there is rapid innovation on both the Human and the Agentic side of digital identity. Numerous new technical standards have emerged offering humans secure, privacy-protective ways to verify their identity online. Over 100 countries are issuing or trialing all-digital credentials, including India, China, the EU, Nigeria, the Philippines, Indonesia and Brazil. 25 US States are now issuing mobile drivers licenses as well. Adoption is accelerating worldwide as users and verifiers realize the massive benefits of strong security, privacy and digital efficiency. But the complexity accelerating too, with numerous technical standards and dependencies, emerging technology risks, proliferating issuers and unclear interoperability.
On the Agentic AI side, identity is also complicated which hinders widespread adoption. Some agents use existing identity protocols such as DID, OAuth 2.0 and OpenID Connect to identify its beneficiary and operator. But new agentic identity protocols (MCP, ACP, OpenAgents) may expand that to uniquely identify agents themselves. Which protocols should you support?
Combining the worlds of digital Human identification with Agentic identity creates exceptional complexity and with that, risk.
We can advise you on how to navigate these risks. To assess your landscape and strategy, to advise on the path forward, and to establish lasting risk management capabilities for years to come. Our network of experts has deep domain expertise and our proprietary risk intelligence data service can support critical operations with threat alerts and emergent risks.
Advisory and Risk Intelligence Services for Digital Identity
We are a boutique advisory firm serving select clients with three classes of service
Assessment Projects
Independent assessment and analysis:
Independent risk review
Expert strategy assessment
Vendor comparisons
Legal review
Technical standards review
Consultative engagements:
Strategy development regarding any aspect of Agentic AI and Human Digital identity
Guidance on how to establish a risk management program (controls, safeguards, governance) for key risks
Bespoke advisory projects
Ongoing support:
Operational risk intelligence regarding relevant credentials, technologies, companies and countries
Bespoke risk intelligence, including analysis of dark web patterns, public and private data sources
Dynamic threat alerts, based on breaches, hacks, updates, rulings and new laws
Independent oversight and governance of risk management practices
Advisory Work
Intelligence and Oversight
Why Credentis?
We are a small, nimble group of expert advisors who can respond rapidly to your needs. We can customize our projects to your exact scope, and rapidly scale up or down as priorities dictate.
Most of the team is based on the East Coast of the USA, but can travel anywhere in the world as needed.
