News

Moca Network CEO Explains Why AI Agents Will Need Provable Identity

Moca Network
August 5, 2026

TL;DR — In an interview with Bitcoin.com News, Moca Network CEO Kenneth Shek argued that every user will eventually have their own agent, and that once an agent starts spending money, verifying data and redeeming rewards on someone's behalf, a raw API key stops being an acceptable way to authorise it. His framing is "identity plus agent": the user is the hub, agents are the spokes, and each spoke gets specific, time-bound, revocable permission over what it can verify and what it can spend. He also described the shift businesses are making from screening out bots to screening for the right ones — and how AIR adds principal-agent binding, policy and delegation management on top of existing identity infrastructure, with selective disclosure and zero-knowledge proofs so an agent can prove a claim without exposing the record behind it.

Read the full interview: Moca Network CEO Explains Why AI Agents Will Need Provable Identity, by Jamie Redman, Bitcoin.com News, 5 August 2026.

From chatbot to representative

Shek's starting point is a prediction rather than a product claim: every user will eventually have their own agent. Once that happens, the agent is not answering questions any more. It is acting — spending, verifying, redeeming, booking.

That shift breaks the credentials the web currently runs on. An API key lets one system talk to another; a delegated credential grants limited access to an outside service. Neither, by itself, proves the relationship between the agent, the person behind it, and the boundaries of what that person actually authorised.

The questions Shek puts to the industry are concrete: who is behind the agent, which user it represents, what data it is allowed to verify, how much it can spend, where, for how long — and whether that permission can be revoked when something changes.

Screening for the right bots

The commercial internet spent years trying to block automated traffic with CAPTCHAs, fraud systems and bot filters. Shek expects that posture to invert as approved agents start arriving as buyers rather than as abuse.

"The world is moving from screening out bots to screening for the right bots," he said. The business still has to know whether an agent is a good one, who stands behind it, and whether it is allowed to pay. The data source behind that answer, in his account, is identity.

Identity plus agent

Shek describes the model as hub and spoke. The user is the hub, holding their own data. The agents are the spokes. AIR governs which agent can verify what data, for how long, and to which verifier.

His examples are ordinary commerce rather than edge cases: an agent buying alcohol still requires the supermarket to verify the user's age; an agent booking with priority status still requires the airline to verify the user's loyalty tier; an agent spending money still requires the user to set how much, where and for how long.

Users can share through full disclosure, selective disclosure, or zero-knowledge proofs — revealing an entire credential, only the fields a transaction needs, or nothing beyond the fact that a condition holds.

Built on existing identity infrastructure

Machine identity, in Shek's account, is not a separate stack. It reuses enterprise-grade identity infrastructure and adds principal-agent binding plus policy and delegation management. The components that carry over include decentralised storage for encrypted, always-available user data, onchain issuance and verification for identity records and audit trails, and interoperability across chains and wallets.

The open question he ends on is adoption: whether companies converge on interoperable credential standards, whether users understand and trust agent permission controls, and whether businesses keep paying for repeated verification once reusable proof exists.

Learn more about AIR, or read our guides to Know Your Agent (KYA) and agentic payments.

Related reading

More from AIR: AIR Identity and AIR Money, or browse the full AIR blog.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
CrowdStrike and Rubrik Automate Identity Attack Recovery at Fal.Con 2026
CrowdStrike and Rubrik announced an agentic workflow that detects, investigates and recovers compromised identity environments in hours rather than days.
News
Central KYC Registry vs Reusable Credentials: Two Models
India's central KYC registry lets firms fetch verified customer data with consent, cutting onboarding 50-70%. One of two architectures for reusable KYC.
News
Retroactive Age Verification: The Existing-Account Problem
Brazil bars new under-15 accounts from 1 September and requires existing ones verified or deactivated by January. The second deadline is the hard one.