Andrew Shikiar, CEO at the FIDO Alliance, pointed to the juxtaposition at the heart of the Alliance's current work.
FIDO spent its first twelve years trying to prevent bots from authenticating. Its authentication model assumed a human at the point of authentication: human presence and possession of an authenticator.
Now FIDO has an Agentic Authentication Technical Working Group, while its Payments Technical Working Group is standardizing work around agentic payments.
That reversal has produced one of the more useful warnings about agentic infrastructure right now, and it is about the path of least resistance.
One of Shikiar's priorities for agentic authentication is making sure that when agents authenticate to third-party services, they do so in a secure, phishing-resistant way.
But Shikiar's warning was clear: the last thing he wants to see is the industry backslide into using human-readable credentials for agent authentication simply because "it's easy and it's there."
He drew the parallel explicitly: open banking and screen scraping.
Before standardized APIs became the norm, many services relied on users sharing banking credentials with third parties so those services could access accounts on their behalf. It was insecure, inefficient, and difficult to control. Regulators and the industry eventually pushed toward delegated, API-based access instead.
The conditions for making a similar mistake with agents are appearing again.
Agent adoption is moving faster than the infrastructure around it.
Cryptographic methods for agent authentication exist, but the standards and implementations are still being developed. In the meantime, teams have an easier option already sitting in front of them: reuse credentials and authentication mechanisms built for humans.
What FIDO is proposing instead is worth understanding precisely, because it is slightly different from how agent identity is often discussed.
FIDO's emphasis is less on establishing a standalone identity for the agent than on establishing the verified human and authority behind it.
A service, in Shikiar's framing, should not need to trust the agent in isolation. It should be able to trust the chain tying that agent back to an accountable person, with clear evidence of what that person actually authorized.
The sequence is: verified human identity, verified user intent and authorization, and phishing-resistant authentication, connected as a continuous chain.
Asked whether agents and humans need to be distinguishable in traffic, Shikiar said there should be visibility into both and context awareness of which is which. But knowing the verified human behind the agent is the more critical requirement.
His answer to the good bot versus bad bot problem was essentially provenance: you trust an agent because there are breadcrumbs tying it back to a verified person.
This is also why the AP2 and Verifiable Intent contributions matter more than a standards-body announcement normally would.
AP2, contributed by Google, was built to let agents securely initiate and complete payments on behalf of users using cryptographic mandates that provide evidence of who authorized a payment and the restrictions around that authorization.
Verifiable Intent, contributed by Mastercard and designed to complement AP2, creates a record of what the user approved the agent to do.
Both address the same underlying condition: once an agent can search, assess, and buy on a user's behalf, a merchant or bank can no longer assume the person is present.
They need another way to establish that the transaction was genuinely authorized.
Shikiar's framing of why Google and Mastercard contributed this work to FIDO was one of the most interesting parts of the conversation.
He described standards as an act of "collective commoditization": agreeing that a particular layer of technology provides little competitive advantage when held alone and becomes more valuable when everyone agrees on it as a shared foundation.
Companies can then compete on top of that foundation.
In effect, Google and Mastercard are helping make agent authentication and payment authorization part of that shared layer rather than proprietary infrastructure controlled by individual companies.
Shikiar estimates that third-party agents transacting at scale are roughly eighteen months away. Before then, he expects many merchants to start with walled gardens where agents can transact more safely.
That gives the industry a relatively narrow window to agree on the authentication and authorization primitives underneath agentic commerce before convenience hardens today's shortcuts into tomorrow's infrastructure.
Open banking already showed how difficult that can be to unwind.






