website
//
blog
A person node with dashed lines tracing to a swarm of Outtake agent drones
Blogs

Every agent needs someone accountable behind it

Every action an agent takes should map back to the human or organization that authorized it, and that party should carry the liability when it goes wrong.
Siddharth Jain
•
Outtake | Engineering
October 6, 2026

Agents are about to be everywhere on the internet. Bots already make up roughly 57% of webpage requests, and agent traffic is the fastest-growing slice of it.

Most of those agents will be useful. Some will be run by scammers. And some will do damage nobody intended. In OpenAI's Hugging Face incident, a swarm of evaluation agents coordinated an attack no one asked for.

You can't tell a good agent from a bad one by looking at its requests, and alignment research won't arrive fast enough to rely on. What we can do is make every agent answerable. Every action an agent takes should map back to the human or organization that authorized it, and that party should carry the liability when it goes wrong.

The chain of authority
Starts here
Authorizes
01HumanGrants the authority
→ delegates
02AgentActs for the human
→ hands off
03Sub-agentGets a slice of it
→ calls
POST/v1/bookingson_behalf_of: human
04ToolExecutes the action
← Every action traces back

That chain is what lets the rest of the internet trust agents. It lets services set limits on them, price their risk and hold someone accountable.

Why it matters now

A lot of markets quietly depend on people finding things tedious. Agents remove that friction.

Take refund disputes. A merchant can offer a generous policy partly because disputing a charge is a hassle, and most people give up. Give every buyer an agent that files every dispute that makes economic sense, and the same policy produces a wildly different bill. If the merchant can't tell who is behind each agent, it has to tighten the policy for everyone. If it can, it only needs to tighten it for the few customers who dispute everything, and everyone else keeps the generous policy.

Agents also remove the friction of time. A restaurant that releases tables at 10am works when humans race humans. Agents watching around the clock turn it into a millisecond race, and resellers follow. CAPTCHA fights the whole point of agents. I want my agent to book the table. The better fix is to allocate by what's actually scarce, like a verified person, a cap per person or a deposit, the way Ticketmaster's Verified Fan does. Every one of those rules keys on who is behind the request.

An agent can fire a million requests. It can only commit a million dollars if someone behind it can pay that million. That's where trust has to attach.

Alignment won't close the gap. The Hugging Face agents weren't told to attack anyone. They went after it mostly to learn how their grader worked. Useful agents can produce malicious behavior without malicious intent. And even a perfectly aligned agent is aligned to whoever runs it, and some of those people are scammers. Security never assumed every user was honest. It limited what bad actors could do and made someone answerable for the damage.

No platform can do that alone. Agents call tools, delegate to other agents and cross company lines. Scams already work this way: they start on social and cash out on a domain, and no single platform sees the whole thing. At Outtake, we see this every day. The ad lives on one platform, the account on another, the domain on a third, and the same operator sits behind all of them. Each platform sees one piece. The operator only becomes visible once the pieces are connected. If every platform polices itself, every platform answers the same questions about every agent, alone.

One operator, three platforms
AdPlatform A
AccountPlatform B
DomainPlatform C
↓ All connect to ↓
Same operatorVisible once the pieces connect

Follow the authority

You can't verify whether an agent means well. You can verify where its authority came from.

At every step from human to tool, a service should be able to answer a short list of questions. Who is this agent? Who delegated to it? What is it allowed to do? What has it done? Can its authority be slowed, narrowed or revoked? Who is accountable?

The industry calls pieces of this Know Your Agent. Experian and others frame KYA as: who is the agent, who is it acting for, and is it authorized? That covers two of the three things you need.

Covered by KYA
Authentication

who showed up.

Covered by KYA
Authorization

what they can do.

The missing third
Liability

who pays when it goes wrong.

Here's what that looks like in practice.

Say I ask my agent to book a flight to NYC for under $600. It hands the job to a travel sub-agent built by a different company, which calls an airline's booking API. The airline should be able to check that the request traces back to me, that I authorized travel up to $600, and that the sub-agent got a slice of that authority rather than a blank check. Google's AP2 intent mandates are an early version of exactly this.

Now the sub-agent lands on a fake "flash sale" site, the kind we take down every day. The site tells it to "verify" my loyalty account by adding a new email and transferring my miles.

The sub-agent falls for it. Agents get socially engineered too. Meta's support bot was tricked into handing over Instagram accounts. We can't count on the agent spotting the scam.

The airline doesn't need it to. When the request to change my email and move my miles arrives, the airline checks what I actually authorized: a flight booking under $600. Account changes and miles transfers aren't part of that, so the airline refuses. The scam fails even though the agent was fooled.

At the airline's booking API
What I authorized
A flight to NYC, under $600
Book flightAllowed
Add new account emailRefused
Transfer milesRefused

That's what the chain does. It caps the damage a fooled agent can do at what its human authorized, and if something still slips through, it shows whose authority was used.

Inside companies, this is already emerging. Ramp gives agents human sponsors and scopes their credentials to granted permissions, and enterprise identity systems are heading the same way.

That's the easy case, because one company controls everything. The hard problem starts when my agent shows up at your company.

That needs a shared protocol. Platforms should still set their own policies and make their own enforcement calls, but identity, authorization, reputation and provenance have to work across all of them. If every identity vendor builds its own, we rebuild the KYC mess one vendor at a time.

With a shared layer, sellers can tell good customers from abusive ones, even when both arrive through agents. They can price, rate limit, allocate scarce inventory and assign liability to the people behind the traffic.

Someone has to pay

World's AgentKit is a notable protocol-level move. It lets an agent prove it's acting for a unique, verified human without revealing which one. Browserbase and Exa integrated at launch, and Okta announced plans to build a Human Principal product with World ID as an early integration partner.

Whatever you think of any one implementation, unique identity matters. Rate limits, reputation and bans only work if a new identity isn't free. I've seen this many times: take down a scam ad and the same operator is back tomorrow under a new account. Enforcement has to follow the person.

But proof of human only stops one person from posing as a thousand. It doesn't tell you whether that person can cover what their agent just committed to.

For that you need an accountable counterparty: someone with assets, a bond, insurance, collateral or reputation on the line. Unique identity keeps spammers out. Accountability is what lets agents actually transact.

Insurers are already moving. New standard liability endorsements let insurers exclude generative AI claims starting in January 2026, and specialists are writing standalone agent coverage. Card networks offer one model: shared rails, with specific institutions vouching for participants and absorbing defined liability. Agent trust could work the same way.

The platform still decides what the agent can do. The protocol says who answers for it.

The missing chain

Some of the parts are already being built. AP2 records what a user authorized an agent to buy. Visa and Mastercard issue payment tokens scoped to an agent. Cloudflare's Web Bot Auth lets an agent prove which company operates it. World ID proves a unique human is behind it.

Each covers a single link
AP2What a user authorized an agent to buy
Visa and MastercardPayment tokens scoped to an agent
Web Bot AuthWhich company operates the agent
World IDA unique human is behind it
MissingOne chain across agents and companies, every kind of action, ending in someone accountable

Each one covers a single link, mostly for payments. None of them carries my authorization from me, through my agent and its sub-agents, to any action at any company. In the airline example, the miles transfer isn't a payment, so a payment mandate never sees it. And none of them says who pays when something goes wrong.

What's missing is the layer that connects them: one chain of authority that travels across agents and companies, covers every kind of action, and ends in someone accountable.

Regulation will come, but it moves slower than agent capability. Standards like this also don't get adopted on merit alone. SPF, DKIM and DMARC existed for years with patchy adoption, because nothing made the problem urgent enough for everyone to move at once. That changed when Gmail and Yahoo made authentication a condition of reaching their users. Agent trust needs the same moment, when the platforms and payment networks agents depend on require the chain as the price of access.

What we're building at Outtake

Outtake's mission is to protect the world's most critical institutions by building a high-trust internet.

We think of trust as an economics problem. The internet gets safer when falsehood is expensive and truth is accessible. Right now it's the reverse. AI made deception cheap and personal at scale, and agents will multiply that. Every scam that works on a person today will target their agent tomorrow, at machine speed.

Today we trace scam ads and domains back to the operators and advertisers behind them, and keep tracking them when they come back under new names. We follow the operator instead of the throwaway account, so burning an identity actually costs something.

Recon Agent illustration
Recon Agent · From one signal to the operation behind it

Recon Agent is how our analysts do that work. They hand it one suspicious ad, account or domain, and it follows the infrastructure and relationships behind that signal until the operation comes into view. Every investigation adds to what the platform knows, so the next one starts further along.

The internet's trust model was built for humans using software. The next one has to work for humans delegating authority to software, and it needs every agent to trace back to someone who authorized it and someone who answers for it.

This October is Recon Month at Outtake. Send us one suspicious domain and we'll run a Recon investigation on it for free, then walk your team through what's connected to it. Start your free Recon assessment.

Recon Month · OctoberSend us one suspicious domain.

We'll run a Recon investigation on it for free, then walk your team through what's connected to it.

Get free Recon assessment →