# When an AI Agent Shows Up, Who’s Really Behind It?

> Source: <https://cryptonews.net/news/other/33297661/>
> Published: 2026-08-14 19:53:00+00:00

AI agents are becoming active participants in the internet economy: browsing websites, managing accounts, and completing purchases on behalf of users. As their capabilities grow, platforms face a new question: when an AI agent shows up, how do you know a legitimate human is behind it?

For years, platforms have relied on CAPTCHAs, rate limits, phone verification, and Know Your Customer (KYC) checks to separate legitimate users from automated abuse, tools built for an internet where automation was mostly something to stop.

That assumption is breaking down. Users increasingly want software to act on their behalf, and the numbers are large enough to matter. McKinsey estimates AI agents could mediate $3 trillion to $5 trillion of global commerce by 2030. Bain projects a narrower U.S. figure of $300 to $500 billion, roughly 15% to 25% of e-commerce. The spread reflects differing definitions of “agentic,” not a settled number, but either way it signals real pressure on platforms.

**A Harder Problem Than “Human or Bot”**

The old binary, human good, bot bad, doesn’t map cleanly here. A legitimate AI agent can generate automated requests and complete transactions without a human clicking every button, which looks a lot like abuse from a platform’s perspective.

Platforms are left choosing between imperfect options: block automation and frustrate authorized users, loosen restrictions and enable abuse, or lean on heavy verification that requires documents many users don’t want to hand over. There’s no clean solution.

The framing gaining traction among some builders is that the real question often isn’t “who exactly is this person?” but “is there one real, unique human behind this agent?”, a narrower ask that needs less personal data.

**Different Approaches to “Proof of Human”**

Several projects are building proof-of-personhood infrastructure, from biometric verification to social-graph attestation to hardware-based credentials, each trading off convenience, privacy, and resistance to gaming at scale.

One prominent example is World, whose World ID protocol is described in its developer documentation as a privacy-preserving way to prove someone is real and unique online without sharing personal information. World says zero-knowledge proofs let a service confirm a valid World ID without revealing it or linking activity across apps.

World has extended this into the agent space through AgentKit, which lets verified users delegate their World ID to AI agents, letting an agent carry cryptographic proof of a human behind it. Built with Coinbase on the x402 payments protocol, it lets a website request proof of a unique human before granting an agent access. World has since expanded integrations to Browserbase, Exa, Okta, Shopify, and Vercel.

Whether this model becomes a standard, or one of several competing approaches, remains open, and will likely hinge on how broadly platforms adopt it over time.

**What’s Still Unsettled**

In theory, a working proof-of-human layer could cut fake accounts and abuse without routing every user through document-heavy KYC, while sparing users from handing over unnecessary personal information.

Realizing that promise, though, will take more than good design. Open questions include how these systems perform at scale, how they handle someone running multiple legitimate agents, and how quickly bad actors adapt once a method becomes widely deployed. Such schemes will need to prove they’re meaningfully harder to spoof than the checks they replace.

The broader shift still seems real: as agents take on more tasks for people, platforms will need some way to reason about accountability beyond “human” or “bot.” World’s approach is one strong candidate for how that gets built, alongside competing standards and ideas still to come.
