Your AI opens a bank account for you. Who goes to jail if it lies?
The shift from simple AI assistants to agentic AI means machines can now execute financial decisions on your behalf. This presents a monumental compliance challenge for regulated industries, requiring an urgent rethink of digital identity and legal liability.
Most people still view artificial intelligence through the lens of a chat box. We tend to think of AI as a glorified autocomplete tool: a helpful assistant that answers queries, drafts emails, or summarises long PDFs.
This view is dangerously out of date.
We have entered the era of agentic AI. Today, there are at least ten to twenty advanced AI models capable of doing virtually everything a human can do behind a computer screen. These systems do not just chat: they act. They can take virtual control of a user's operating system, navigate websites, move cursors, copy data, and click buttons exactly like a human sitting at a desk.
Within the next three to five years, this will fundamentally dismantle how we interact with the digital economy. The era of manually logging into apps, navigating complex drop-down menus, and completing web forms is drawing to a close. Instead, the primary interface will shift to these LLM-Clients (Claude, ChatGPT, etc). We will simply instruct our AI: "Find me the best savings rate, open an account, and move my balance," or "Find a cheaper energy provider and switch my service."
For the consumer, this sounds like an overdue digital utopia. For businesses like banks, payment companies, and utilities, it is a compliance and identity nightmare. But even regular webshops will have to adjust when trying to take a slice of the agentic commerce cake that's building up on the horizon.
The numbers behind this shift are staggering. Analysts at Morgan Stanley and Bain estimate that AI agents could drive 15 to 25 percent of US e-commerce by 2030, worth somewhere between 300 and 500 billion dollars. Faced with a prize of that size, most merchants will not wait to be found: they will begin directing their technical implementations and marketing efforts straight at AIs and agents, optimising their product feeds, APIs and checkout flows to be discovered and transacted by machines rather than by humans.
We are hurtling towards an interface paradox.
Building an interface that allows an AI client to read data is a simple technical task. But allowing a machine to independently execute actions on a human's behalf creates a monumental crisis of trust.
Consider the foundational act of navigating the modern web. On virtually every website, users must explicitly click to accept terms and conditions, opt-in to tracking cookies, or consent to privacy policies.
These simple clicks are, in the eyes of the law, regulated actions. They carry immense legal weight. Yet, when an AI agent autonomously navigates a site and clicks "I agree" to terms the human user has never seen, the entire legal concept of consent begins to unravel.
If a business cannot definitively prove who authorised these actions, the digital economy faces a catastrophic vulnerability. Without a robust trust layer, we will see an explosion of disputes, unchecked data-harvesting, and a terrifying new reality: orphaned liability. When an AI makes an unauthorized financial commitment, shares sensitive medical data, or signs a binding contract (Yes, agreeing to terms and conditions in the checkbox is also a binding contract), who takes the fall? The developer who wrote the model? The business that accepted the automated click? Or the user who gave a vague verbal prompt over breakfast?
To survive this shift, every business operating online must be able to answer four crucial questions the moment an AI agent attempts any regulated action:
- Who authorised this action? There must be provable, explicit consent tied directly to a verified human or legal entity.
- On whose behalf is the client acting? We must never accept anonymous or unverified machine agents; there must always be an identified human principal.
- What is the exact scope of its mandate? There can be no blank cheques. The AI's permissions must be strictly bounded in money, time, and permitted actions.
- Who bears liability if it goes wrong? There must be an unbroken, legally resilient attribution chain that will survive the scrutiny of an ombudsman or regulator.
Our existing digital identity infrastructure is utterly unprepared for this. For two decades, we have focused exclusively on verifying the identity of a human sitting directly behind a screen. Now, we must solve a far more complex riddle: how to verify a machine acting on a human's behalf.
The answer is not a complex new technological gimmick, but a digital reimagining of a highly successful legal tool: a Power of Attorney for AI (POAA).
Just as a traditional power of attorney allows a trusted professional to sign documents and make decisions on your behalf, we urgently need an international, standardized framework that extends identity and authorization to autonomous systems. This requires three non-negotiable layers. First, what we can call a “Proof of Human”: a high-assurance verification of the natural person behind the screen. Second, a “Proof of Authority”, which is the scoped, signed mandate dictating exactly what the AI is permitted to do. Finally, a “Proof of Authenticity”, creating an immutable audit log of who did what, and when, for the regulator's and audit eyes.
| Traditional digital identity | Identity for agentic AI | |
|---|---|---|
| Baseline assumption | Businesses can infer a human is present via browser signals (cookies, clicks, sessions). | Businesses are blind. An API call from an agent looks identical whether a human requested it or a machine hallucinated it. |
| Consent and authorisation | A human user manually clicks "I agree" or completes a checkout flow. | The agent acts under a predefined "Power of Attorney" (standing grant) or triggers a live biometric prompt for explicit consent. |
| Access limits and permissions | Fixed access levels granted at login (e.g., standard user vs. admin). | A user-controlled permission matrix that dictates what an AI can auto-approve (like basic terms) versus what requires human intervention (like moving money). |
| Access duration | Long-lasting session cookies or access tokens managed centrally. | Standing grants that stay active for a user-defined period (e.g., two weeks) and can be revoked at any time. |
| Evidence and disputes | Standard server logs showing when an account logged in and what was clicked. | A cryptographic, signed receipt bound to the exact terms accepted, proving human consent without exposing private biometric data. |
Crucially, this transformation is not just external.
The very operations of regulated businesses (risk assessments, compliance, and customer support) will increasingly rely on "internal AI twins". Yet, no sensible regulator will ever permit a financial institution to be fully automated from end to end. The successful AI-first organisation will not be defined merely by how much it automates, but by how cleanly it specifies the checkpoints where fresh, provable human authorisation is mandated.
We are moving from a world where identity is about access to a world where identity is about delegation. The organisations thriving in this new era will be those that offer services that are fully accessible to AI customers, not forgetting that every machine-mediated action must be demonstrably authorised, have a strictly defined scope and be fully auditable.
If we fail to build this trust framework today, the agentic AI revolution will stall. The bottleneck is no longer raw algorithmic capability, but basic systemic safety. Until we can verify who is pulling the strings behind the machine, we cannot afford to hand algorithms the keys to our digital lives.
Preparing your organisation for the agentic future
The transition to agentic AI forces us to rethink how we establish trust in digital environments. We are moving beyond simply verifying a single human typing at a keyboard. We must now verify the secure delegation of authority to a machine. This is an immediate operational requirement, not a distant theoretical issue. Financial institutions and online businesses must implement clear, auditable frameworks to prove who is authorising automated actions. Those who build these secure delegation layers today will confidently lead the next generation of digital commerce.
Frequently asked questions about agentic AI and identity
-
Agentic AI systems are advanced models capable of taking independent actions, such as navigating websites or moving funds, rather than simply generating text.
-
It complicates consent because a machine might accept terms the human user has never seen. This makes it difficult to prove legal authorisation without updated digital identity frameworks.
-
A Power of Attorney for AI is a proposed framework that extends legal authorisation to machines. It relies on proof of the human, proof of authority, and proof of authenticity to create a clear audit trail.
-
Internal AI twins are automated systems used within a business to handle operations like risk assessments, compliance checks, or customer support. While they help speed up processes, regulated businesses must still ensure these systems have strict checkpoints where human authorisation is verified.
-
Orphaned liability happens when an AI makes an unauthorised financial commitment or error, but it is entirely unclear who is legally responsible. Without a clear trust framework, businesses cannot easily determine if the user, the AI developer, or the platform should take the fall.
-
Current digital identity infrastructure was built specifically to verify a human sitting directly behind a screen. It is not designed to verify a machine that is acting on behalf of a human, which requires a completely different approach to secure delegation and authority.
*An earlier version of this article was published on Finextra. This version has been updated for the Signicat blog.