Discusses mechanisms for verifying requests in the Agentic Web, revealing key challenges and solutions.
For most of the web’s history, a request arriving at a server carried an implicit signature: a person had, in that moment, clicked, typed or tapped. Rate limits, fraud checks, consent flows and terms-of-service enforcement were built on that assumption, even where it was never written down. Agentic AI removes it. A single instruction can now spawn an unbounded stream of downstream requests, issued by software executing a standing delegation rather than a person acting in the moment, and a server has no reliable way to tell which is which. This paper argues that the industry’s 2025–2026 response has concentrated on a narrower, more commercially urgent problem – proving which piece of software is making a request, through mechanisms such as Web Bot Auth, HTTP Message Signatures and agent payment mandates – while leaving the harder question of whether a human specifically authorised this instance largely self-asserted. It reviews the technical field: signed agent attestations, delegation chains built on OAuth extensions and Google’s Agent Payments Protocol, proof-of-personhood schemes, and behavioural signals, and sets out what each does and does not establish. Drawing on a disclosed cyber-espionage campaign in which a correctly authenticated agent executed an attacker’s will because the human-authorisation claim inside its instructions was itself fabricated, the paper contends that cryptography is currently being applied to the wrong layer of the problem. It closes with a layered framework connecting attestation, delegation and moment-level confirmation to the audit and friction mechanisms proposed earlier in this series.
No takes yet. Share an insight, caveat, or question.
Akash Narayan (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: