How to Trust an AI Agent
Solving the Machine Sybil Problem
Aybars Dorman
Stratège des systèmes futurs & auteur de Dorman Review
How to Trust an AI Agent • Solving the Machine Sybil Problem
Close to 400,000 AI agents are now registered on public blockchains. In February there were about 21,000. That is a twentyfold jump in five months, and almost none of these agents has ever been asked to prove who is standing behind it.
This is the quiet problem at the center of the agent economy. Software agents are already buying data, paying for services and moving money on behalf of companies. But every trust tool the internet runs on was built for one job, proving that a human, not a machine, is on the other side. Passwords, two factor codes, SMS checks, CAPTCHAs, all of them exist to keep machines out.
In the agent economy, the other side is a machine by design.
That turns the security model of the internet upside down. Today, starting a thousand AI agents takes seconds and costs less than a cent. That opens the door to a Sybil attack at a scale the internet has never seen, where one actor floods a system with fake identities. Unverified and unauthorized agents can flood networks, trigger large automated payments and slip past compliance checks at machine speed, long before any human notices.
If agentic commerce is going to work at the scale big companies need, we have to build identity systems that machines can read, check and trust instantly, without a human in the loop.
The On Chain Truth. ERC 8004 and the Agent Registry
The first layer of machine identity is a registration that anyone can check. An agent needs a unique digital ID that any party can read, and that does not depend on a single central server.
This is exactly what on chain agent registries offer, and adoption has been fast. ERC 8004, the Trustless Agents standard developed by contributors from MetaMask, the Ethereum Foundation, Google and Coinbase, went live on Ethereum mainnet in late January 2026. By the middle of the year, the 8004scan explorer was tracking those 400,000 agents across 29 chains, along with more than 460,000 feedback records stored on chain.
The standard works through three registries. The Identity Registry gives each agent an ID that travels with it, in the form of an ERC 721 token pointing to the agent's registration file, which holds its details, its endpoints and its wallet. The Reputation Registry lets other parties post and read feedback. The Validation Registry records checks carried out by independent validators. So when an ERC 8004 agent starts a transaction, the receiving system can look at the chain and see where the agent came from, what it has done before, and who signed off on it.
However, registration alone is not enough. Anyone can deploy a contract or register an address, and the data shows it. As of July 2026, roughly 89% of registered agents had not yet declared a standard service interface such as MCP or A2A. In other words, identity at scale already exists. Identity that is active and answerable is still being built. To move real money and work with regulated financial systems, an agent needs something stronger.
Enterprise Attestation. The KYA Standard for Machines
For a company's finance team to let an agent spend money, or for a B2B platform to give an agent API access, there has to be a secure link between a digital identity and real world legal responsibility. This is the idea behind Know Your Agent, or KYA, the machine version of Know Your Customer.
This is where enterprise attestation comes in. Attestation simply means a trusted party confirms that something is true and signs that confirmation. Providers such as Visa's Trusted Agent Protocol, Skyfire and Persona are building this layer for the agentic finance stack. Their job is to tie a verified real world company to a specific software agent in a way that cannot be faked.
Recommended by LinkedIn
Consider how that works in practice.
A company deploys an AI purchasing agent to manage its supply chain.
An attestation provider verifies the company's legal and financial status.
The provider issues a signed credential that links the verified company profile to the agent's ERC 8004 ID.
When the agent tries to make a purchase, it presents that credential together with its payment request.
The seller's system checks the credential instantly, and legal and financial trust is established at machine speed.
Identity Is the Gateway to Capital
In the agent economy, identity is not a user profile or a social reputation score. It is the security line that decides who gets access to money.
Without attestation, an AI agent is just a piece of code running on its own, with no one standing behind it. With attestation, the same agent becomes a legally and financially responsible actor, able to take part in high value global trade. As the world moves toward many chains and many agents, the platforms and infrastructure providers that get machine identity right will be the ones that capture the most value.
Next episode is, The Stablecoin Settlement Standard • Why 99 Percent of Agent Capital Moves in USDC.
Dorman Review | Meaningful Insight. Informed Decisions.
Written by Aybars Dorman | 4th September 2026
#AgentEconomy #ERC8004 #MachineIdentity #AgenticCommerce #AIAgents #Web3 #KYA #Fintech #Blockchain #DormanReview