Agent identity is the control that most marketing organizations have not yet built. Martech Futurist | July 21, 2026

Last week's edition ended on a practical point: once a marketing agent acts, the work moves to confirming what it did and setting limits on what it can do. This week's research points to the mechanism behind both, which is identity. An agent needs to be identifiable as a specific actor: which agent, acting for whom, permitted to do what, and able to be switched off when it exceeds its scope. A survey of enterprise deployments finds that identity is the control organizations are least likely to have put in place. Perimeter research finds the same requirement outside the firewall, where an agent reaching your site may belong to a customer, a partner, or a bad actor. Two launches this week show vendors and payment networks building identity and liability infrastructure for transactions that run between agents from different organizations. How far a company can extend agentic marketing now depends on whether each agent has an identity it can name, scope, and account for.

In production, agents frequently share one identity

VentureBeat's Pulse survey of 107 enterprises quantifies the gap. More than half have had a confirmed AI agent security incident or a near-miss. About seven in ten run agents with shared credentials somewhere in their fleet. Only about a third give each agent its own scoped identity, and three in ten isolate their highest-risk agents. A permission model does little when several agents authenticate as the same actor, because one compromise then reaches every system that actor can access. This is the Identity and Permissions layer I write about, and it becomes central as agents begin to act with less supervision. An agent on a shared credential cannot be scoped individually, revoked cleanly, or located in an audit. The framework I use treats humans and AI agents as interchangeable team members, which carries a straightforward operational consequence: team members are assigned their own identities and access, and agents should be too.

The perimeter now has to distinguish among agents

Forrester's research on bot and agent trust management describes a market that spent years detecting and blocking automated traffic and now has to permit trusted automated traffic at scale. An agent at your perimeter may represent a legitimate customer, a business partner, or a malicious actor, and a previously trusted agent can be compromised during a session. Aggressive blocking turns away customers who arrive through their assistants. Permissive access invites fraud. Identity applied at the edge settles the question by establishing whose agent is arriving and what it is permitted to do before it transacts. The interaction a company has to permit is increasingly one agent communicating with another.

It reminds me of what Chang Chang, Senior Director of Product for Cloud CX Solutions from Cisco, said when I interviewed him on The Agile Brand podcast: "I think even more exciting for me is actually this notion of the multi-agent ecosystem where you have all sorts of AI agents interacting with one another. I mean, to the point where you can have an AI agent on one brand interacting with an AI agent for another brand and taking care of an issue for you." As agents resolve issues by talking to a customer's agent, the brand-to-agent exchange I described in earlier editions becomes agent to agent. The exchange still depends on trust, and the party extending it is now a system at your perimeter that needs a reliable way to identify the agent on the other side.

Accountability between organizations depends on shared protocols

Two launches this week show the infrastructure taking shape for agent activity beyond a company's own systems. Entrust opened a co-development program to build the identity foundations enterprises need to move agents from pilots into production, organized around three questions organizations often cannot answer once an agent acts: who authorized it, what it was permitted to do, and how its actions can be verified afterward. Mastercard chose the UK for a sandbox where retailers and partners test whether their products are discoverable by agents, whether agentic payments scale while keeping customer trust, and whether their dispute-handling processes hold at scale. The UK policy work behind the launch called for trusted agent protocols covering digital identity, payment permissions, and liability. Proof and dispute resolution between two organizations depend on shared protocols, because one company's audit log does not settle a claim on its own.

Deciding what to permit is a judgment about stakes. It reminds me of what Ilya Spiridonov, Chief Commercial Officer from Alconost, said when I interviewed him on The Agile Brand podcast: "It boils down to risk…in large enterprises, choosing between AI or human or a mix of the two is usually about matching the workflow to the risk and the risk appetite." Scope autonomy to the stakes of the task, widen it as evidence accumulates, and keep a person accountable for the direction even when execution runs without supervision.

Featured Insights

VentureBeat. The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials (July 15, 2026). A single-wave Pulse survey of 107 enterprises with more than 100 employees reports 54% with a confirmed incident or near-miss, 69% sharing credentials across agents, about a third assigning each agent a scoped identity, and 30% isolating their highest-risk agents. The report reads directionally, and the direction holds: adoption is running ahead of the identity and isolation controls that matter most when an agent fails. Run the credential inventory this quarter. The relevant question is how many of your marketing agents authenticate as the same actor.

Forrester. Secure The Future Of Internet Traffic As Agents Take Over (June 16, 2026). Forrester's take on its Bot And Agent Trust Management Wave describes a market moving from blocking bots to enabling trusted automated traffic, as agents blur the line between human and machine visitors and legitimate agents can be hijacked mid-session. The buying decision becomes one of admission: which agents you recognize, and on what evidence, before they act. Security and growth teams now share the bot question. Some of the automated traffic you used to block is customers arriving through their assistants.

SiliconANGLE. Entrust launches Agentic AI Trust Accelerator to move AI agents into production (July 14, 2026). Entrust convened enterprises and integration partners to build the identity infrastructure that keeps agents stuck in testing once organizations realize they cannot answer who authorized an agent, what it may do, and how to verify its actions afterward. The program treats those three questions as the gate between a pilot and a live deployment. Readiness for production depends on producing a defensible record of an agent's authority and its actions on demand, more than on model quality.

Mastercard. How Mastercard is helping the UK get AI-ready (July 16, 2026). Mastercard's Proto sandbox, live in the UK in August, lets retailers and partners test whether their products are discoverable by agents, whether agentic payments scale while keeping customer trust, and whether dispute handling holds at scale, alongside new shopping, onboarding, and dispute agents. The launch aligns with UK policy calling for trusted agent protocols spanning digital identity, payment permissions, and liability. Test two things before scaling agentic commerce: whether agents can find and interpret your products, and whether your dispute process works when the buyer is an agent.

Key Takeaways

  1. Give every marketing agent its own scoped identity and retire shared credentials. Start with an inventory of which agents run under a common key, then separate the highest-risk ones so one compromise cannot spread across your systems.

  2. Treat your perimeter as an admit-or-deny decision for agents. Decide which external agents you recognize and what evidence establishes that an arriving agent acts for a real customer or partner.

  3. Keep a record that holds up outside your walls. Log who authorized each agent, what it was permitted to do, and how you can demonstrate what it did to a counterparty or a regulator, since your own log does not resolve a two-party dispute on its own.

  4. Set permission by risk appetite, workflow by workflow. Match the autonomy you grant to the stakes of the task, expand it as evidence accumulates, and keep a person accountable for the direction the agents pursue.

Next
Next

How AI is Rewiring the Consumer Decision Cycle Through Cognitive Offloading