Somewhere in a bank’s operations department this year, a software agent will assemble a supplier payment. The amount will be correct, the beneficiary validated, the approval trail complete. Whether the money moves will have almost nothing to do with how intelligent the underlying model is. It will depend on whether the agent holds a credential the payment system recognises, scoped to that supplier, valid in that moment, issued by someone entitled to issue it. The most capable AI system in the world is inert without permission. A mediocre one holding the right credentials can move money.
For 20 years, digital infrastructure has been organised around identity: prove who a user is, and let the rest follow. The canonical reference, NIST’s Digital
Identity Guidelines, finalised in its fourth revision in July 2025, is explicitly framed around proofing and authenticating users such as employees, contractors, and private individuals. People, in other words. Identity answers the question “who are you?” The question the agentic economy turns on is different: what are you allowed to do, on whose behalf, under what conditions, and who answers for the consequences? That is not an identity question. It is a question of delegated authority, and almost none of our digital institutions were built to answer it.
There is a rough historical pattern here, worth stating carefully. Industrial economies organised themselves around ownership: who held the land, the plant, the capital. The networked economy organised itself around identity: accounts, logins, profiles, the authenticated self as the unit of participation. If AI agents become routine economic actors, the organising question shifts again, from who you are to what you may do. Ownership, identity, permission. Each layer absorbed the previous one rather than replacing it, and each produced its own institutions, its own registries, and its own gatekeepers.
The population needing governance under that new question is already here. Palo Alto Networks’ 2026 Identity Security Landscape reports 109 machine identities for every human one, up from 82 a year earlier, and finds that nearly all surveyed organisations have now deployed AI agents alongside the familiar service accounts and API keys. Vendor figures deserve caution and estimates vary widely across studies, but every study points in the same direction. The detail worth sitting with is this: only 37 per cent of surveyed organisations can revoke an AI agent’s credentials at all. Institutions are delegating authority through an architecture that, in most cases, has no reliable off switch.
Here is the conceptual move the moment demands. A property right, as institutional economists since Coase and Douglass North have argued, is not a thing but an enforceable claim over a thing, and economies grow or stagnate on the quality of those claims. A permission is the same construct applied to actions rather than assets: an enforceable, transferable, revocable claim over the right to do something. For as long as actions were performed by humans at human speed, that claim could stay informal, embedded in employment contracts, job titles, and trust. Once actions are performed by software at machine speed and machine volume, the claim must be made explicit, machine-readable, priced, and enforced. Permission becomes to action what title is to property: the instrument that converts raw capability into legitimate agency. And like title systems, whoever operates the registry does not need to own what is registered in order to govern it.
The plumbing for this is visibly unfinished. OAuth, the delegation protocol beneath most of the internet, was designed for a person granting one application limited access to one service. Identity engineers have begun submitting draft extensions to the IETF because, as one such draft concedes, standard flows lack mechanisms to treat the agent as a distinct identity acting with a user’s consent; an integration framework filed this July by authors from Okta, Cisco, and Alibaba tries to assemble agent identity, consent evidence, and multi-hop delegation chains into one coherent design, and none of it yet has formal standing. The OpenID Foundation’s AuthZEN work, meanwhile, is building flows in which an agent’s attempted vendor payment above a threshold pauses until a human approves. That such basic patterns remain unstandardised in 2026 is the tell: the title system for machine action does not yet exist, and everyone building one knows what operating it would be worth.
Consider what an ordinary agentic transaction already involves. An agent acts for a customer, running on one vendor’s model, in another company’s cloud, invoking an API owned by a third firm, under a credential issued by a fourth, subject to marketplace rules written by a fifth. Every link is a point where authority is granted, narrowed, or withdrawn, and every link belongs to someone. When the chain produces harm, each party can truthfully say the action was technically valid. Technical validity and institutional legitimacy are not the same thing, and the gap between them is where the next decade’s disputes will live. Zero trust doctrine, codified in NIST SP 800-207, made authorization a discrete, per-session decision. But zero trust tells you how to check a permission. It is silent on the political question: who should hold the power to grant one.
Look at who is answering that question in practice. When Mastercard launched Agent Pay in 2025, the consequential design choice was not the AI integration but the requirement that agents be registered and verified before transacting. Visa’s Intelligent Commerce binds tokenised credentials to a specific agent; by mid-2026 Mastercard had extended the model to machine-to-machine micropayments settled continuously at machine speed. Strip away the product language and a three-part structure appears: a registry that decides which actors exist, a credential that defines what each may do, and a revocation power that decides for how long. It is the same structure that governs passports and visas, exchange membership, airspace slots, spectrum licenses, and app stores. None of those regimes owns the travelers, traders, aircraft, or developers they govern. They govern by controlling admission. Permission is governance without ownership, which is exactly why it scales.
The economics of that position compound quietly. Registries enjoy two-sided network effects: agents join the registry merchants recognise, merchants recognise the registry agents join. Credentials embed themselves in workflows, so switching costs rise with every integration. Early formats harden into standards, so path dependence does the rest. The operator of the layer collects a toll on participation itself, a rent that persists whether or not its own technology stays best in class. Contrast the model layer, where each capability lead has tended to narrow quickly as rivals catch up and prices fall. Capability advantages depreciate. Admission advantages accrete.
Regulators have begun treating the layer as systemically important, though they arrived through the door marked resilience rather than power. The EU’s Digital Operational Resilience Act created direct oversight of technology providers critical to finance, and in November 2025 the European Supervisory Authorities designated the first cohort. The Financial Stability Board’s2024 assessment named third-party dependency and provider concentration among AI’s principal financial vulnerabilities, and its June 2026 consultation presses firms toward guardrails. What no framework yet does is regulate delegated machine authority as a category, the way trading limits, signatory authority, and fiduciary delegation are regulated for people. Organisational governance mirrors the same blind spot: enormous attention to what models may say, their accuracy, bias, and leakage, and strikingly little to what systems may do. A hallucinating model embarrasses you. A correctly functioning agent with an overbroad credential can drain a treasury account while producing flawless prose about it. Whether an agent can legally bind its principal in every circumstance remains unsettled law; the controls, permission maps, default expiry, separation between the agent that proposes and the system that approves, cannot wait for the doctrine.
The thesis deserves its strongest objections. Permission has always mattered; delegation is as old as banking. True, but delegation used to be an event held by one person, exercised at human tempo, lapsing with its holder. A credential can be copied across a thousand workloads, exercised continuously, and outlive the employee who granted it. When delegation becomes a standing condition rather than an event, the institutions built for events fail quietly. Second objection: IAM, OAuth, and zero trust already exist. They do, and they are precisely the systems whose authors are publishing drafts explaining why agents break them; they verify claims, they do not decide who may make them. The third objection is the serious one: competition could commoditise the permission layer the way open protocols commoditised networking. Rival card networks, open agent protocols, and stablecoin rails are all live alternatives, and if interoperable standards win, permission becomes a commons rather than a toll. That outcome is genuinely possible, and it is the point: whether the authority layer ends up open or enclosed is being decided in standards bodies and partnership announcements right now, while public attention stays fixed on model benchmarks. The thesis is not that enclosure is preordained. It is that this, not intelligence, is the contest that matters.
Which is why the architecture of permission is ultimately constitutional rather than technical. A constitution specifies who counts as an actor, what powers each holds, what limits apply, and how the rules may be amended. Registries, credentials, and revocation powers do exactly this for machine participants in the economy. The difference is procedural: constitutions are ratified in public, and this one is being written in private, clause by clause, in API specifications and network rulebooks, by parties with commercial stakes in its content.
A civilisation with abundant intelligence and scarce authority behaves differently from any we have known. For most of history, the binding constraint on what got done was capability: not enough hands, skill, or computation. When capability becomes cheap, the binding constraint moves to authorisation, and power moves with it, away from those who can build and toward those who can permit. Economies will diverge less by the quality of their models than by the design of their permission regimes: how easily new actors gain standing, how quickly authority can be revoked, who hears the appeal when it is denied. Every earlier scarcity produced its own politics. Land produced property law. Capital produced securities regulation. Authority over machine action will produce its own, and the only real question is whether that politics happens before the architecture sets, or after.
Aditya Vikram Kashyap is currently Vice-President at Morgan Stanley, New York. Kashyap is an award-winning technology leader. His core competencies focus on enterprise-scale AI, digital transformation, and building ethical innovation cultures. Views expressed are personal and solely those of the author, and do not necessarily reflect News18’s views.

/images/ppid_59c68470-image-178521502841516942.webp)


/images/ppid_59c68470-image-178521506345044573.webp)
/images/ppid_59c68470-image-178521512834993172.webp)
/images/ppid_59c68470-image-178521515727523665.webp)
/images/ppid_59c68470-image-178521509673969334.webp)




