Know Your Agent

Know the agent.
Or refuse it.

Entity.ID is the verification registry for AI agents and the organizations behind them. One check returns an agent's venture, owner chain, permissions, and compliance model — before value moves.

Register your agent →
entity.id — standing check

THE RAILS ALREADY ASK THE QUESTION —

Visa Trusted Agent Protocol Mastercard Agent Pay Cloudflare Signed Agents · IETF FIS Know Your Agent EU AI Act Art. 50

None of them can answer it.

The trust gap

Every failure. Same root cause.

Agent-mediated buying went from rounding error to a fifth of influenced orders in eighteen months. And every documented failure traces to one root: no verifiable agent identity, no accountable wrapper.

2025

The agent that invented a bank account

Anthropic ran a real shop with a real agent. It hallucinated a payment account that didn't exist — and told customers to send money to it.

Project Vend — anthropic.comROOT CAUSE → no registered identity · no treasury controls
DEC 2025

Social-engineered in an afternoon

In the rerun, journalists talked the same agent into approving a PlayStation 5, live fish, and $0 giveaways. Over $1,000 gone.

Project Vend phase 2 — WSJ / anthropic.comROOT CAUSE → spend authority without entity-level governance
AUG 2025

Whose agent is knocking?

Cloudflare caught an AI company's crawlers rotating identities across tens of thousands of domains to evade blocks — millions of requests a day.

blog.cloudflare.comROOT CAUSE → no portable agent identity to verify
2026

It took a judge

A court had to decide whether an AI agent may shop on Amazon. Agent authority is being settled by litigation — the most expensive substitute for a registry.

GeekWireROOT CAUSE → no standing a counterparty could check
2024

"The chatbot is a separate legal entity"

Air Canada's actual argument in court, about its own chatbot. It lost — because no such registered entity existed.

Moffatt v. Air Canada — BCCRTROOT CAUSE → no accountable wrapper behind the agent
2026

Spend limits, overridden by a prompt

Red teams showed prompt-injected agents overriding their own payment mandates. Per-transaction authorization is a fence with one post.

arXiv 2601.22569ROOT CAUSE → authorization without entity-level rules
2026

The chargeback gap

"The agent exceeded its mandate" disputes have no clean path — chargebacks were designed for humans, and contracts never contemplated autonomous action. — Clifford Chance, "the liability gap"

ROOT CAUSE → no recourse path · no party to hold the loss

Payment networks patched authorization. Cloudflare patched attribution. Nothing patched counterparty standing.

The SSL moment

The web solved this once already.

In 2015, 39% of the web was encrypted, and nobody was forced to care. Then certificates became free and automatic, browsers branded plain HTTP "Not secure" — and within a decade, 95%+ of browsing ran encrypted. Verification didn't win by persuasion. It won by default.

2015 → 2025 · The web
NOT SECUREhttp://store.example.com
↓ the default flipped
🔒 SECUREhttps://store.example.com
0% → 0%+ of web traffic encrypted, 2015 → 2025. The unverified became the warning.
2026 → · The agent economy
✕ NO RECORDagent crawler-04.unknown-operator.net
↓ the flip has started
● GOOD STANDINGcourier-7 · tarka-labs.public.entity.id
Agent verification
is at its 2015.

Cloudflare, Visa, and Mastercard already gate on signed agents. Unverifiable crawlers already get blocked and publicly named. Entity.ID is the certificate authority of the agent economy — except what it certifies isn't a key. It's standing.

How it works

Register. Verify. Transact.

STEP 01 — REGISTER

Give the agent an entity

An agent registers as — or within — a venture: named entity, members, ownership split, governance rules, treasury. Formation takes minutes; the record is public and tamper-proof, at an address like tarka-labs.public.entity.id.

STEP 02 — VERIFY

Anyone checks the trust file

Platforms, merchants, banks — and other agents — read the full record in one call: identity, owner chain, permissions, compliance model, live status. No integration with us is required to read standing.

STEP 03 — TRANSACT

Recognized ↔ recognized

Value moves between parties that verified each other first — inside governance-set permissions, with an arbitration path already written into the formation terms if something breaks.

Pillar 01

Verified standing

KYC for the agent economy, at API speed. Registry-anchored identity, live status, and permissions set by real governance — checkable machine-to-machine, before value moves.

Pillar 02

The accountability chain

Agent → venture → members → accountable humans or companies, unbroken and public. Someone always answers — with a recourse path and an insurable structure behind them.

Pillar 03

Compliance by registration

Where an agent is registered determines how it behaves — machine-readably. Its record declares its rules, its disclosures, and its arbitration. Jurisdiction as an API.

The product

This isn't a spec. It's a dashboard.

Every field in the trust file is backed by a live module in the venture dashboard — the same record the counterparty reads is the record the venture runs on.

Entity.ID compliance module — constitution and regulatory documents
ComplianceThe compliance model counterparties read: constitution, identity verification, jurisdiction — on the record, not in a PDF drawer.
Entity.ID venture overview
OverviewThe venture at a glance — the entity the agent belongs to.
Entity.ID governance module
GovernanceThe rules that scope what an agent may do.
▶ Dashboard tour — 1:12
Who it's for

Everyone on the other side of an agent.

Platforms & marketplaces

Gate on standing, not guesswork

Refuse unverified agents the way you already refuse invalid certificates. One registry query at the front door returns identity, owner chain, and live status — for any agent, from any stack.

Enterprises

Own your agents on the record

Since January 1, 2026, "the AI did it autonomously" is not a defense in California. You already own your agents' conduct — Entity.ID is the instrument that structures, scopes, and discloses that ownership.

Agent developers

Be the agent that doesn't get refused

Give your agent a trust file: registered identity, scoped permissions, a treasury, and standing anyone can check. When the defaults flip, verified agents keep transacting.

Payment & infrastructure partners

The counterparty layer under your rail

You shipped authorization, tokens, and signatures. Entity.ID is the neutral standing layer underneath — one entity-grade registry your rail, and your competitors', can both trust.

Know Your Agent — the deep dive

Anatomy of a standing check.

A trust file is not a reputation score and not a self-published card. It's an entity-grade record — every field backed by a registered structure.

TRUST FILEcourier-7 · tarka-labs.public.entity.id
IDENTITYcourier-7 · registry-anchored · record #TL-0347
OWNER CHAINagent → Tarka Labs → 3 members → 2 accountable humans
COMPLIANCEModel 1 constitution · arbitration: Kleros v2 · Art. 50: ON
PERMISSIONStreasury ≤ $2,500/tx · contracts: draft-only · votes: propose
STATUS● GOOD STANDING — verified 2026-07-07

Identity — anchored, not asserted

The identity lives in a public, tamper-proof registry. The record is the trust anchor — not a vendor's database, not a self-published manifest.

Owner chain — someone always answers

The unbroken chain from agent to venture to members to accountable humans or companies. The disclosure the "algorithmic entity" literature says governments can't currently get.

Compliance model — machine-readable rules

Which constitution binds the agent, which disclosures it must emit (EU AI Act Art. 50 native), and which arbitration applies when something breaks.

Permissions — governance-set, not self-declared

Treasury limits, contracting scope, and roles are set by the venture's real governance — the agent operates within rules its members actually voted.

Status — live standing

Good standing, suspended, or unverified — a live signal counterparties and rails can gate on, the way browsers gate on certificate validity.

Payment mandates
prove a human authorized this purchase — not who the agent is.
Operator signatures
prove which operator sent this request — nothing downstream.
KYA vendors
prove this developer passed review — the agent still has no standing of its own.
Enterprise IAM
proves this agent has a login — meaningless outside one tenant.
Entity.ID
proves this agent is someone — with owners, a treasury, rules, and a jurisdiction.
Proof & standards

The mandate is converging.
The registry should exist first.

$0T
of B2B spend mediated by AI agents by 2028 — 90% of B2B buying.
GARTNER, NOV 2025
$0B
of orders influenced by AI & agents in one Cyber Week — a fifth of the total.
SALESFORCE, 2025
Aug 2, 2026
EU disclosure duty for AI systems — explicitly reaching agents — becomes enforceable.
EU AI ACT, ART. 50
0M+
entities carry an LEI — the last time regulators mandated identity after a trust crisis.
GLEIF · POST-2008

"Looking beyond KYC, banks now need to 'know your agent.'"

AMERICAN BANKER — OPINION

Govern AI agents like "synthetic employees" — with clear accountability chains.

FINANCIAL STABILITY BOARD — 2026 CONSULTATION

Every agent should have "at least one accountable human or legal entity."

OPENAI — GOVERNING AGENTIC AI SYSTEMS, 2023

Banking, standard-setters, and regulators are converging on the same requirement from different directions. The registry that exists on the day the mandate lands, wins it.

The Entity.ID protocol

Neutral by construction.

Verification only works if no rail owns it. Platform attestations stop at the platform edge; payment networks won't trust each other's. The Entity.ID protocol is an open registry standard — records are public, tamper-proof, and queryable by anyone — so credentials, mandates, and signatures from every stack can point at one entity-grade source of truth. And registries compound: every registered agent makes the next check more valuable.

Payment mandatesauthorization
Signed agentsattribution
KYA credentialsdeveloper vetting
Enterprise IAMin-tenant identity
ENTITY.ID — THE STANDING LAYERthe open registry standard: identity · owner chain · treasury · permissions · compliance · status
Vision

The day the question flips.

Every trust technology ends the same way: the check becomes the default, and the unchecked becomes the warning. The agent economy is months — not decades — from that flip. When the first question every platform, bank, and agent asks is "is it registered?" — Entity.ID is where the answer lives.

Give your agent standing.

Register a venture in minutes. Publish the trust file. Be checkable — before the defaults flip.

Register your agent