Moca Network CEO Explains Why AI Agents Will Need Provable Identity
TL;DR — In an interview with Bitcoin.com News, Moca Network CEO Kenneth Shek argued that every user will eventually have their own agent, and that once an agent starts spending money, verifying data and redeeming rewards on someone's behalf, a raw API key stops being an acceptable way to authorise it. His framing is "identity plus agent": the user is the hub, agents are the spokes, and each spoke gets specific, time-bound, revocable permission over what it can verify and what it can spend. He also described the shift businesses are making from screening out bots to screening for the right ones — and how AIR adds principal-agent binding, policy and delegation management on top of existing identity infrastructure, with selective disclosure and zero-knowledge proofs so an agent can prove a claim without exposing the record behind it.
Read the full interview: Moca Network CEO Explains Why AI Agents Will Need Provable Identity, by Jamie Redman, Bitcoin.com News, 5 August 2026.
From chatbot to representative
Shek's starting point is a prediction rather than a product claim: every user will eventually have their own agent. Once that happens, the agent is not answering questions any more. It is acting — spending, verifying, redeeming, booking.
That shift breaks the credentials the web currently runs on. An API key lets one system talk to another; a delegated credential grants limited access to an outside service. Neither, by itself, proves the relationship between the agent, the person behind it, and the boundaries of what that person actually authorised.
The questions Shek puts to the industry are concrete: who is behind the agent, which user it represents, what data it is allowed to verify, how much it can spend, where, for how long — and whether that permission can be revoked when something changes.
Screening for the right bots
The commercial internet spent years trying to block automated traffic with CAPTCHAs, fraud systems and bot filters. Shek expects that posture to invert as approved agents start arriving as buyers rather than as abuse.
"The world is moving from screening out bots to screening for the right bots," he said. The business still has to know whether an agent is a good one, who stands behind it, and whether it is allowed to pay. The data source behind that answer, in his account, is identity.
Identity plus agent
Shek describes the model as hub and spoke. The user is the hub, holding their own data. The agents are the spokes. AIR governs which agent can verify what data, for how long, and to which verifier.
His examples are ordinary commerce rather than edge cases: an agent buying alcohol still requires the supermarket to verify the user's age; an agent booking with priority status still requires the airline to verify the user's loyalty tier; an agent spending money still requires the user to set how much, where and for how long.
Users can share through full disclosure, selective disclosure, or zero-knowledge proofs — revealing an entire credential, only the fields a transaction needs, or nothing beyond the fact that a condition holds.
Built on existing identity infrastructure
Machine identity, in Shek's account, is not a separate stack. It reuses enterprise-grade identity infrastructure and adds principal-agent binding plus policy and delegation management. The components that carry over include decentralised storage for encrypted, always-available user data, onchain issuance and verification for identity records and audit trails, and interoperability across chains and wallets.
The open question he ends on is adoption: whether companies converge on interoperable credential standards, whether users understand and trust agent permission controls, and whether businesses keep paying for repeated verification once reusable proof exists.
Learn more about AIR, or read our guides to Know Your Agent (KYA) and agentic payments.
revolution today




.png)