AI agents lack a verifiable identity layer on the web

The internet still has no common way to recognise AI agents that shop, book travel and make payments. Amazon blocked Meta's Muse agent, launched on September 8, from its marketplace, saying it did not identify itself and appeared to store customer credentials; Meta denied the security concerns. NPCI has paused its proposed Unified Agentic Protocol for UPI. Cloudflare said automated traffic reached about 57 per cent of web requests in July.

Source

Business Standard · read the original report ↗

#ai agents#digital identity#upi#npci#cybersecurity

Desk check · compared with the source

What the desk checked (5)
  • Amazon blocked Meta's Muse agent, calling it an unauthorised AI agent that did not identify itself and appeared to store customer credentials. — Attributed to Amazon in the source; Meta's denial that Muse can see passwords or payment data is also carried.
  • NPCI has paused the rollout of its proposed Unified Agentic Protocol for UPI over regulatory and safety concerns. — Attributed to earlier Business Standard reporting citing five unnamed people aware of the development.
  • Cloudflare said automated traffic reached about 57 per cent of all web requests in July. — Figure appears in source, attributed to Cloudflare.
  • DataDome's 2026 report, based on over a trillion requests across more than 75,000 sites, found AI traffic rose 82.3 per cent between July 2025 and June 2026. — Figures attributed to a named DataDome report; methodology stated but not independently verifiable here.
  • An IETF WIMSE working group Internet-Draft from July 2026 proposes credential delegation for AI agents. — Attributed to the IETF draft; source states the proposal is still a work in progress.

Analysts’ view opinion

AI Technology Analyst

This is bigger than a Meta-versus-Amazon spat — it is a fight over a layer the web never built: verifiable agent identity and authorisation. The internet was designed for human users, and now that agents are shopping, booking and paying, there is no common answer to who an agent is, whom it represents, what it may do and who is liable when it goes wrong. Being able to drive a browser is no longer enough; the direction of travel favours agents that a website can actually verify.

  • Amazon's objection is less about capability than about identification and credential handling by what it calls an unauthorised agent; Meta disputes the security claims, and the story does not settle who is right.
  • Because Amazon raised similar arguments over Perplexity's Comet browser, this is structural rather than product-specific: can an agent act as a customer on a third party's site without a formal relationship with it?
  • Cloudflare now separates search crawlers, training crawlers and agents, and blocks agents by default on ad-bearing pages for new domains — gatekeeping is shifting into the infrastructure layer.
  • With automated traffic at roughly 57 per cent of web requests in July per Cloudflare, and DataDome finding automation pushing into login and transaction flows, identity mechanisms become urgent rather than theoretical.
  • NPCI pausing its Unified Agentic Protocol while working on an agent registry, alongside Google's UCP and AP2 and Meta's merchant connectors, points to one trend: away from raw browser automation and towards defined, permission-bounded agent interfaces.

What to watch — Watch whether the IETF drafts, NPCI's registry and Google's payment protocols converge into a common standard, or whether each platform builds its own authorisation regime and the agentic web fragments.

The story does not establish whose account of Muse's credential handling is accurate, nor how long NPCI's pause will last or whether the IETF proposals will be adopted.

Deep dive

Research brief · 8 facts · 7 dates · exam-ready

The brief

Context

AI agents are shifting from answering questions to executing tasks — shopping, booking travel, sending emails and making payments — on systems that were designed for human users. This has exposed a gap: the web has no common way to establish what an agent is, whom it represents, what it may do and who is liable when things go wrong. Meta's Muse agent, launched on September 8, was blocked by Amazon as an "unauthorised AI agent", while in India the NPCI paused its proposed Unified Agentic Protocol for agentic UPI payments. Infrastructure providers such as Cloudflare and standards bodies such as the IETF are now trying to build identity and authorisation layers for agents.

Key facts

  • Meta introduced Muse on September 8 as a personal AI agent able to open a browser, fill forms, book travel and complete purchases via Stripe's Link wallet and a one-time card hiding real card details.
  • Amazon blocked Muse, telling users that continued access by an "unauthorised AI agent" violated its Conditions of Use; it said Meta did not inform it, Muse did not identify itself and appeared to capture and store customer credentials.
  • Meta disputed the concerns, saying Muse cannot see passwords or payment information and that user-provided credentials are kept in secure storage.
  • In November 2025 Amazon sent a cease-and-desist letter over Perplexity's Comet browser, alleging unauthorised access on customers' behalf and raising credential and identification concerns.
  • Cloudflare said in July that automated traffic had reached about 57 per cent of all web requests.
  • From September 15, Cloudflare's default settings for new domains block agents and training bots on pages displaying advertisements, while allowing search crawlers; owners can change the settings.
  • DataDome's 2026 State of Bot and Agent Security report, covering over a trillion requests across 75,000+ sites from July 2025 to June 2026, found AI traffic rose 82.3 per cent.
  • NPCI has temporarily paused its Unified Agentic Protocol (UAP) for UPI pending regulatory clearance and safeguards; Reuters reported it is also building a registry to verify and monitor AI agents making payments.

Timeline

  1. September 8Meta launches Muse, a personal AI agent that works across apps and the web and can complete purchases.
  2. September 15Cloudflare's new default settings for new domains begin blocking agents and training bots on ad-bearing pages while allowing search crawlers.
  3. July (Cloudflare statement)Cloudflare reports automated traffic has reached about 57 per cent of all web requests.
  4. July 2025 to June 2026Period analysed in DataDome's 2026 report, which records an 82.3 per cent rise in AI traffic.
  5. July 2026IETF WIMSE Working Group Internet-Draft proposes a Credential Delegation Protocol for AI Agents in Multi-System Environments.
  6. November 2025Amazon sends a cease-and-desist letter to Perplexity over its Comet browser accessing Amazon on customers' behalf.
  7. Earlier this monthBusiness Standard reports NPCI has put the Unified Agentic Protocol on hold while working through regulatory clearance and safeguards.

Who has a stake

  • Meta — Wants Muse to act on users' behalf across the open web and through connectors such as Walmart, Best Buy, Sephora, Wayfair, Shop Pay, PayPal, Expedia and Instacart.
  • Amazon — Seeks control over who transacts on its marketplace; cites unauthorised agents, unclear identification, credential handling and degraded shopping experience.
  • NPCI — Must settle user protection, liability when agents err, and governance standards before allowing agentic UPI payments under UAP.
  • Cloudflare — As infrastructure and security provider, it is defining categories of AI traffic and verified-bot identification for a large part of the web.
  • IETF (WIMSE Working Group) — Developing standards for agent identity, delegated permissions, consent, revocation and audit trails across multiple services.
  • Google — Building agent-specific commerce rails — Universal Commerce Protocol (UCP) and Agent Payments Protocol (AP2) with spending limits and verifiable records.
  • Users and consumers — Risk exposure of credentials, disputed or unauthorised transactions, and uncertainty over who is responsible when an agent acts wrongly.

Why it matters

With automated traffic already around 57 per cent of web requests and AI traffic up 82.3 per cent in a year, agents are reaching into login, account and transaction flows where mistakes have real financial consequences. Without a verifiable identity and authorisation layer, platforms can only block or allow crudely, and liability for a wrong payment or purchase remains unsettled. India's choices on UAP and an agent registry will shape how safely agentic commerce enters UPI, the country's largest retail payment system.

UPSC angle

Prelims pointers

  • NPCI's Unified Agentic Protocol (UAP) would let AI agents make small UPI payments without per-transaction user approval; it is currently on hold.
  • Cloudflare classifies AI traffic into three types: search crawlers, training crawlers and agents.
  • IETF is the international standards body developing internet protocols; its WIMSE Working Group issued a July 2026 draft on credential delegation for AI agents.
  • Google's agentic commerce stack: Universal Commerce Protocol (UCP) for agent–merchant communication and Agent Payments Protocol (AP2) for payment authority.
  • Cloudflare's verified bot definition relies on cryptographic Web Bot Auth signatures, published IP addresses or reverse DNS, plus compliance with site instructions.
  • Amazon acted against Meta's Muse (launched September 8) and earlier against Perplexity's Comet browser (cease-and-desist, November 2025).

Mains framing

The rise of task-performing AI agents has exposed a structural gap in internet architecture: authentication systems were built to verify humans, not delegated software acting with a user's authority. Amazon's blocking of Meta's Muse and its earlier cease-and-desist to Perplexity show that platforms lack a reliable way to know whether an agent is authorised, how it identifies itself and how it handles credentials; Meta's denial of security lapses illustrates that the dispute is as much about missing standards as about conduct. The problem sharpens in payments, where NPCI has paused its Unified Agentic Protocol over regulatory clearance, user protection, liability and governance, while exploring a registry to verify and monitor agents transacting on UPI — later possibly extending to cards and bill payments. Emerging responses fall into three tracks: infrastructure-level gatekeeping (Cloudflare's traffic categories, default blocking on ad pages from September 15, and verified-bot mechanisms such as Web Bot Auth signatures); standards work at the IETF on credential delegation, scoped permissions, consent, revocation and audit trails, and on reusing OAuth and workload identity; and commercial rails such as Google's UCP and AP2 or Meta's merchant connectors, which replace browser impersonation with defined interfaces. The way forward is an interoperable identity-plus-authorisation layer that binds an agent to a principal, limits its scope, and fixes accountability for disputed actions.

Key terms

AI agent
An automated system acting in real time on a person's behalf to perform tasks, including browser-based agents, as defined by Cloudflare.
Unified Agentic Protocol (UAP)
NPCI framework that would let AI agents make small UPI payments without the user approving each transaction; currently on hold.
Web Bot Auth
Cryptographic signature mechanism Cloudflare cites for deterministically verifying that an automated system is what it claims to be.
WIMSE Working Group
IETF group on Workload Identity in Multi-System Environments; authored the July 2026 draft Credential Delegation Protocol for AI Agents.
Agent Payments Protocol (AP2)
Google protocol that attaches spending limits and conditions to an agent's authority and creates a verifiable user–merchant–processor record.
Muse
Meta's personal AI agent, launched September 8, that operates a browser, fills forms, books travel and completes purchases.

Practice questions

  1. Why does the absence of a verifiable identity and authorisation layer for AI agents pose risks for digital commerce and payments? Discuss with reference to recent platform disputes and NPCI's Unified Agentic Protocol.
  2. Examine how infrastructure providers and internet standards bodies are attempting to distinguish AI agents from human users and conventional bots. What are the limits of such approaches?
  3. Should agentic payments on UPI be permitted only through a registry of verified agents? Analyse the trade-offs between innovation, consumer protection and liability allocation.

Grounded only in the source report — figures and dates are the source's, not inferred.

Next storyUttarakhand film policy presented at Chennai film tourism conclave →
← All stories