Bitcoin News: MOCA CEO Explains Provable Identity for AI Agents

Artificial intelligence agents will require verifiable identity and clearly defined permissions as they begin executing financial and data tasks on behalf of users, according to Moca Network CEO Kenneth Shek. As agents transition from passive assistants to active participants in digital economies, establishing who they represent, what they can access, and how far their authority extends is becoming a core security and compliance concern.

Agents Move From Answering to Acting

The next phase of AI adoption is shifting from information retrieval to autonomous execution. In this model, agents can initiate payments, manage subscriptions, rebalance crypto portfolios, interact with decentralized applications (dApps), and exchange data with third-party services.

Shek argues that this evolution requires stronger identity assurance and permission boundaries. Without them, users and platforms face elevated risks of unauthorized spending, data leakage, and fraudulent activity in both traditional and blockchain-based environments.

Why Provable Identity Matters

For AI agents to operate safely at scale, identity must be both machine-verifiable and resistant to tampering. Key elements include:

  • Representation: Cryptographic proof that an agent is acting on behalf of a specific user or organization.
  • Access control: Explicit permissions for which accounts, wallets, APIs, or datasets the agent may use.
  • Scope of authority: Boundaries on what actions the agent can perform, with limits on value, frequency, and counterparty types.

These controls are essential as agents begin to spend funds, sign transactions, and share sensitive information. For crypto specifically, they help prevent misuse of private keys, reduce the risk of malicious approvals, and provide an auditable trail of agent-initiated activity.

Emerging Approaches in Crypto and Web3

Industry efforts are converging on a stack that combines cryptographic identity, programmable permissions, and transparent logs:

  • Verifiable credentials and decentralized identifiers (DIDs): Portable attestations that prove attributes (e.g., ownership, KYC status, or organizational affiliation) without exposing unnecessary data.
  • On-chain permissioning: Smart contract-based controls, including allowlists, spending limits, timed approvals, session keys, and account abstraction to constrain what an agent can do.
  • Key management and policy enforcement: Multisig and multiparty computation (MPC) to distribute signing authority, with policies that require human or policy-engine approval for high-risk actions.
  • Auditability: Immutable logs and event trails that record who authorized an action, which agent executed it, and under what policy.

Together, these tools can help align agent autonomy with user intent while meeting compliance obligations in regulated markets.

Implications for Exchanges, Wallets, and dApps

Platforms enabling agent-driven transactions will likely need to support identity verification for both users and agents, adopt granular permission frameworks, and implement runtime safeguards such as rate limits and risk scoring. Wallet providers may see increased demand for policy-based controls and recoverability. DeFi protocols may incorporate agent-aware access layers that distinguish between human and agent initiators, improving transparency and reducing abuse.

Shek’s call for provable identity reflects a broader shift: as AI agents become operational counterparts in digital finance, trust must be grounded in cryptography, explicit authorization, and verifiable accountability—principles that align closely with the design of public blockchains.

×