In short
Eye On A.I. Podcast Notes
Episode #257
Ankur Banerjee - How cheqd.io Is Building Trust for AI Agents with Decentralized Identity
Episode Overview
- Host: Craig S. Smith
- Guest: Ankur Banerjee, Co-Founder and CTO of cheqd.io
- Topic: The role of decentralized identity in the emerging AI agent economy.
- Key Idea: Just as humans require digital passports, AI agents will need decentralized identities to operate effectively and securely on behalf of users.
Key Themes & Takeaways
- The Need for Identity in AI
- AI agents require a form of identity to authenticate and validate their actions on behalf of users.
- Digital identity answers fundamental questions:
- Who am I?
- What am I allowed to do?
- Current systems like "login with Google" are basic and centralized, creating potential issues of trust and security.
- Ankur Banerjee's Background
- Extensive experience in digital identity, fraud prevention, and artificial intelligence.
- Founded cheqd in 2021 to address the challenges of online digital identity management.
- Trust and Digital Credentials
- Digital credentials allow AI agents to prove their identity and the permissions they have.
- Trust between agents is crucial; agents need to determine which other agents or services they can interact with.
- The Problem with Biometrics
- Biometrics (e.g., fingerprints, iris scans) can be useful but may not always be practical.
- Overreliance on biometrics can lead to issues of privacy and security.
- Emphasis on privacy-first solutions that do not require constant biometric checks.
- Web Standards for Agent Identity
- Current initiatives, such as the EU Digital ID Wallet, aim to create industry standards for decentralized identity.
- W3C (World Wide Web Consortium) is working on standards for digital credentials, making it easier for websites to adopt these technologies.
- Model Context Protocol (MCP)
- MCP enables structured access for AI agents to tools and information.
- It is crucial for how agents will interact with decentralized identity systems.
- Adoption by major AI platforms (e.g., OpenAI, Google) indicates growing recognition of the need for these protocols.
- Interoperability Between Systems
- Future AI agents may have built-in identity wallets, making credential management seamless.
- Collaboration with institutions like the Fraunhofer Institute to integrate decentralized identity with existing domain name systems.
- The Future of CAPTCHA and Online Verification
- CAPTCHA will continue to exist, serving as a basic proof of humanity.
- Advanced forms of identity verification will evolve to address more nuanced questions of identity and trust.
Conclusion The conversation highlights the importance of decentralized identity in the AI landscape. As AI agents begin to operate more autonomously, establishing a framework for identity and trust will be crucial for ensuring secure interactions with digital services and protecting user data.
Additional Notes
- Contact & Follow:
- Craig Smith on X: [@craigss](https://x.com/craigss)
- Eye on A.I. on X: [@EyeOn_AI](https://x.com/EyeOn_AI)
This episode presents a forward-looking perspective on how decentralized identity can shape the future of AI interactions, potentially influencing various sectors and applications.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00What an AI agent might need to do is to go and carry out that authentication. So when you talk about digital identity, it breaks down to questions of like, who am I? What am I allowed to do? So what is what the login with Google question or entering a username and a password, what that is doing is it's answering at a very basic level, who am I? I don't think any of these companies necessarily want to run it as a centralized service because, A, there's a lot of content, billions, billions of images and videos and so on. But if they become the centralized registry of what is AI generated or what is not AI generated, that then becomes a very big political challenge in terms of content moderation.
0:48Build the future of multi-agent software with agency. That's A-G-N-T-C-Y. The agency is an open source collective building the internet of agents. It's a collaborative layer where agents can discover, connect, and work across frameworks. For developers, this means standardized agent discovery tools, seamless protocols for interagent communication, and modular components to compose and scale multi-agent workflows. Join Crew AI, Langchain, Llama Index, Browserbase, Cisco, and dozens more. The agency is dropping code, specs, and services. No strings attached. Build with other engineers who care about high-quality multi-agent software.
1:42Visit agency.org and add your support. That's A-G-N-T-C-Y dot O-R-G, agency.org, and support the project. Let's start by having you introduce yourself. Tell us a little bit about your background, educational and professional background, as far as it's relevant to what we're talking about. Absolutely. And then tell me how you got to check and what you guys are doing in the larger context. Absolutely. So hi, my name is Ankur Banerjee. I'm the CTO and co-founder at Checked, which is a decentralized identity company. I'll go into a second to explain what decentralized identity is. But we are a fairly small startup.
2:32We started about four years ago in 2021. And the reason why we wanted to go and tackle some of these problems that we see cropping up in the online space around digital identity is because both me and my co-founders have had a background in working on digital identity and fraud within for governments for banks for enterprises large enterprises in in healthcare and education and and at the time we'd sort of been working since around 2017-2018 on how this could be moved to a new form of identity where people are at the center and in control. And we wanted to solve some of the challenges that we that we saw cropping up within the decentralized identity space.
3:29I also happen to have a background in working in AI and NLP before I got into digital identity, which relates to a lot of the recent advancements and developments that have been happening. And I've got a couple of patterns in that space myself, having worked, for example, on one of the world's first spoken chatbots in spoken Arabic. So, yeah, like, you know, it's been a bit of a full circle coming back to looking at some of the challenges that are cropping up in the AI and machine learning space, having spent a couple of years in the digital identity space. Yeah. Well, my interest was initially piqued by this issue.
4:18You know, I did an article on MANUS, the multi-agent system out of China. And a lot of people have, I don't have access, but have had access online and it's amazing it does amazing things but uh you send it out uh into the digital world or onto the internet and it very quickly runs into blow roadblocks and that have to you the human has to intervene to get them past those things like captcha and it occurs to me that everyone's talking about you know what microsoft calls societies of agents that will eventually be kind of a base layer to the economy taking care of a lot of the less creative work that bureaucracy that needs to be done and there's going to have to be a paradigm change in the uh in the way the internet is uh guardrails are set up uh to allow agents to do that was that at all part of your initial motivation or is is there a broader issue that i'm not seeing uh i think that was partly the motivation um how how does identity get solved for agents because if there's one way I can put it, a lot of the AI agents right now are like naive children.
5:52They would essentially go and believe everything that they say because there's not a lot of intelligence. And where I think it becomes quite interesting is I think there's a couple of different facets to where this identity aspect comes in. The first is you as an individual, when you go and ask an agent to go do something on your behalf, let's say make a travel booking or go and book a restaurant reservation on your behalf, it might need to prove that it's been given that task by a real human being and that it has permissions for a specific time and duration. And what I mean by that is obviously these services are also trying to keep out the bad actors who are running bots or AI to perhaps make those same travel bookings.
6:50Or the most famous example of this is Ticketmaster, when they're trying to prevent bots, which are being run by scalpers, from getting all of the Taylor Swift tickets. So big, big Taylor Swift fan myself. And if I wanted to delegate the task to an agent to say, when the tickets go on sale at, say, midnight. I don't want to be awake myself. I want to delegate the task of getting those tickets to an AI agent. How does the AI agent prove that it's acting on behalf of a real fan with certain real listening history to Taylor Swift on Spotify? And let that through, but don't let the other bots through.
7:36And then secondly, how do you prove, how does the AI agent prove that it has been given the permission by me to buy tickets for this specific concert or this specific artist, but not to go on a spending spree and book 50 different concerts. So I think that is increasingly going to become a challenge when services start interacting with agents. The second piece of this is agent-to-agent trust. Perhaps my agent needs to talk to an AI agent that is specialized in the process of ticket buying, maybe because it doesn't know how to do the specific task of ticket buying itself. So how does the AI agent perhaps understand that in this entire universe of different sites and services that it's coming across what is a trustworthy agent and what's just the equivalent of a scalper that it shouldn't talk to and so even when you start looking at the idea of agent to agent trust of whom they which other agent do they go and trust and which piece of content do they go and trust it becomes increasingly beyond just the simple problem of do you prove you're human online or do you prove you're an agent so it's it's a lot more multifaceted and not just binary yeah um and how how then do you solve that problem i mean it seems on the one hand a problem on on the agent provider side that the agent needs to be able to provide a verified identity but it's also a problem on the service provider side that they have to make their site available for whatever protocol you guys or whoever it is comes up with.
9:40So it's a little bit of a chicken and an egg. But how do you solve that? I think I'll explain the way that people are currently solving it, which is you essentially do the same thing that you do when you click login with Google or login with Facebook. So you would give ChatGPT or, you know, any other former sort of agent like Manos, for example, just unfettered access to some service. And that's how people are currently solving it um where we sort of got into this space is we originally started off building enterprise level tools for how does human identity get solved so for example how can people have a trustworthy tamper proof digital copy of all of the data that belongs to their life and then have the ability to go and delegate it as well.
10:41So there's a lot of governments around the world that are currently right now trialing or in the early stages of deploying some of these digital identity systems which also have baked in the capability of delegation. And the reason why the government's thought of it initially is there's very common scenarios where a parent might be acting as the guardian or the delegate on behalf of their child or um uh and a a person could be acting on behalf of somebody they care for who's who's who's older or perhaps you know less abled to carry out actions online um so initially we we'd started off solving around how does digital identity and decentralized identity work for humans and because within those contexts when we'd been working with large enterprises and governments, they'd already been thinking of those challenges and problems of how does permissions and delegations work across different humans.
11:48When this sort of AI agent revolution started off, it was like, that's an obvious answer to the problem in a completely different space. And we were early, I think, to recognize that and start applying the same techniques to the AI agent permissioning space and human to agent permissioning space. And what's quite interesting is there are governments like the European Union that is currently working on an initiative called the EU Digital ID Wallet Initiative, which is built on those exact same industry standards. um uh i i mean i i work as a ctu i checked but i'm also the on the steering committee for something called the decentralized identity foundation which has um loads of large companies that participate uh and set the specifications on on how do these digital identity standards work and uh it's an an easy sort of step to take to say, like the kind of robust permissioning, which is a lot more granular than what's been possible with login with Facebook or login with Google can now be applied in a completely different context where similar sort of challenges are present.
13:16Yeah. And it just as you were talking, I'm thinking of, I mean, not all sites are protected by captcha or the equivalent i don't know if that's the only system um a lot of places uh use two-factor identification and you could give an agent access to your um to your phone messages here for example and and just have them receive the code and input the code is that one way to to do this uh it's it it's part of the picture of doing this yes because what an ai agent might need to do is to go and and carry out that authentication um so when you talk about digital identity it breaks down to questions of like who am I?
14:11What am I allowed to do? So what is what the login with Google question or entering a username and a password, what that is doing is it's answering at a very basic level, who am I? What I'm allowed to do is authorization. And that is, I am allowed to read emails. Once I log in with this. I'm allowed to carry out a bank transaction. The kind of technology that we work on for decentralized identity goes a bit beyond those two questions. It is part of the journey, but it also helps to go and answer beyond the question of who am I and what am I allowed to do, which a lot of the current systems are quite capable of solving.
15:02It goes to then answer, what are my preferences? What is my history of interacting with a particular service? And having a full digital copy of that, which also actually comes into when you go and delegate an agent to act on your behalf. Let's say you've asked it to go and make a travel booking on your behalf. Not only is it a question of who is it acting on behalf of and are they allowed to make that travel booking or not, but also capturing through these digital credentials how many members do you have in your family? What do they like doing? Like, you know, what are their likes? What are their dislikes?
15:48Where have they already been? And being able to also provide that to AI agents in a in a machine readable form um in what what form i'm sorry in a machine readable form so in a way that i guess you know ai agents will be able to understand it because they they need to go and and then express that in in a set of actions they take on your behalf um so yes like i think being able to carry out the two-factor steps is definitely part of the picture because while it's going and making the booking on your behalf, it might need to carry out those actions. But at a broader level, it's about going a bit deeper than just the who am I and what am I allowed to do?
16:42And also look at what are the hopes and the preferences and the likes and the dislikes and being able to express that to AI agents as well in a sort of readable fashion. Now, what's perhaps like an extension to this is when we've been working on this for the government use cases, there's a large part of that is if you take a digital credential that has, say, been issued in France and take it across to the US and prove that you're allowed to enter the country at a border, let's say showing a driver's license or showing your passport. Governments needed a way of actually creating these things called trust registries or trust lists to say this is a recognized country with a passport that we trust or this is a type of driver's license that we trust.
17:46So we adapt the same technology to the AI agent space for the creators of these AI agents and perhaps third-party independent assessors and auditors to also go and issue digital credentials to AI agents to say this particular agent is trustworthy on the topic of travel bookings. This other agent is trustworthy on the topic of accountancy. And they can have a multitude of these, the same way that I have a lot of different pieces of plastic in my wallet. Some of these are my driver's license. Some of these are my residency permit. The same way an AI agent might hold multiple digital credentials that say, so these are the topics that an AI agent is good at.
18:38here's maybe a separate digital credential that proves it has been assessed against the EU AI Act and found to be an AI agent that is low risk rather than the high risk category. And you might choose to behave or trust an AI agent with that set of credentials a lot differently than something that is not able to go and prove those capabilities. yeah uh is is is there well let let's talk about the tech behind it all i mean i'm i'm thinking is there a biometric uh aspect to this i mean uh judging from your name you have some roots in uh the subcontinent and and i think india has the largest biometric database in the world absolutely is it tied in that in that case it's fingerprint I think unless it's evolved but is this going to be iris scans like the the world coin or world orb or whatever they call it is trying to do so i mean you can imagine a day when yeah when pieces of plastic and uh and paper passports uh are really things of the past and you walk up and scan your iris and maybe there's a secondary validation or verification so how does it work in in your case so that is definitely i think different than our vision or our technology to for starters because biometrics are great when you need a really high degree of assurance as it's called so things like when you travel across international borders typically your your passport has a chip on it that has your biometrics, your face biometrics usually.
20:47And that allows when you're going through e-passport gates or presenting it to an official for them to check if it's the same person that the passport was issued to who's entering through that e-passport gate. WorldCoin obviously is trying to do something very similar. The Aadhaar system in India ties things to biometrics. But in those government use cases, they're often trying to make a very high degree of assurance of use case happen. Usually in day-to-day life, you don't need that same level of assurance. And it's probably scope and mission creep and also a privacy risk to constantly have to prove biometrics in every other scenario.
21:39Just an example of this is many people, when you go through touch ID or face ID on your phone, it doesn't actually know that it's tied to one single human being. Many people will put their kids or their partners on the same device because it's easy to, you know, my hands are tied, I'm driving, can you reach my phone and check it? And that's completely allowed. Like, you know, I am trusting them as my partner or my kid to give access to my device and I should completely be allowed to do that. so the kind of technology that we work on I'd say it's very different from what Worldcoin is using and especially most other blockchain based use cases so most of the time on blockchain what you do is you go and write some information as the source of truth to a blockchain or a ledger and and you trust that everybody can see it at the same time which is great when you're thinking about things like money balances and you want everybody to have the same value.
22:55It's a really bad idea for biometrics and for any kind of personal information, because even if I agreed to do it today, and even if you apply any kind of encryption so that the data can't be read by anybody who shouldn't have access to it, you can never erase that. You can never take that back. So even if I'm a consenting user today, at some point, maybe 5, 10, 20 years in the future, that particular encryption technology is going to get broken, probably because of quantum. But even before quantum comes along, encryption standards go out of date all the time. And sometimes they have vulnerabilities in them.
23:41So instead of going and writing that information to some sort of blockchain or ledger, what we do is we only store the cryptographic information that is needed to verify the information on chain. So unlike most other use cases, maybe 5 % of the action is happening on a blockchain. The rest of it, the actual digital credentials themselves, are in tamper-proof files that you can store on your phone, on your laptop, on any sort of device. You can even print them out into backups in things that work like QR codes. interesting part of my history into how I got into this the very first project I worked on was to work on decentralized identity for refugees and with the UN High Commission for Refugees and one of the big aspects of that is do they have smartphones they did but they did have hundred dollar Chinese Android phones, which were good enough to hold a piece of digital identity that they'd been issued by the UN.
25:00And a large part of that was what happens when the phone dies? What happens if somebody loses their phone? So it is possible to back up as well, so that if you do lose your device, if it's out of power, there are alternatives that you can fall back to um but uh the the core of like the way our technology works is you have some cryptographic hashes or proof that get written to the chain um that allow me when i go and show that digital credential to you some uh anybody who sees it can cross check it against the blockchain and say i can see that the hash matches or i can see that the cryptographic seal is untampered and therefore I know I can go and trust this.
25:47And I guess the distinction that I'm taking from the kind of technology that WorldCoin is working on is these digital credentials, you can put biometrics into them, but by default, most of them don't. Because actually, putting in a biometric into every single piece of information that is related to you is is massive overkill and it's actually been a big debate amongst the browser vendors around the world where they want to put in something called the digital credentials api into every single large browser that exists and if every single thing that you held had a biometric it's very easy to go into the scope creep sort of area where governments say well before you access a pawn site you should have you should go and prove your identity with a digital credential like your driver's license that has your biometrics attached to it and and i don't think that's necessarily where the world should be moving towards build the future of multi-agent software with agency that's a g n t c y the agency is an open source collective building the internet of agents.
27:10It's a collaborative layer where agents can discover, connect, and work across frameworks. For developers, this means standardized agent discovery tools, seamless protocols for interagent communication, and modular components to compose and scale multi-agent workflows. Join Crew AI, Langchain, Llama Index, Browserbase, Cisco, and dozens more. The agency is dropping code, specs, and services. No strings attached. Build with other engineers who care about high-quality multi-agent software. Visit agency.org and add your support. That's A-G-N-T-C-Y dot O-R-G, agency.org, and support the project. Yeah.
28:03So how, what are the, I mean, the blockchain registry is kind of a validation. Yeah. A bit like the domain name system, the way that you might register YouTube.com or Google.com, and there's a registry that sits behind it that says, this is what that address leads to. In a very similar fashion, you create things that are called decentralized identifiers or DIDs. This is what a lot of the people in the group that's working on Decentralized Identity Foundation work on. Those DIDs are typically cryptographic hashes or cryptographic seals that are written quite often to a blockchain, but it doesn't necessarily have to be.
28:57And then you go ahead. And then on the other side, on your own devices, you create or you keep things that are called digital credentials or verifiable credentials, verifiable in a cryptographic sense. And what that means is if you show it to someone, They can cryptographically verify that they have been untampered. And you can also choose during these processes to apply additional steps for privacy, like apply something called selective disclosure. So, for example, if you want to know what my name is, I can show you a digital credential that was derived from my passport or driver's license without actually sharing my home address, which might also be on that same digital credential.
29:50But actually, that's irrelevant to the interaction that we are having. And so, therefore, I shouldn't need to go and show you the other parts of that. like my home address that maybe don't relate to the interaction. Yeah, which reminds me, I hate putting my address into those forms because you have no idea where it's going.
30:21And so is it the same process then that you're porting over to the digital identity of AI systems. And I started talking about agents and the issues that arise for identity with agents. But is it broader than agents? Are you looking at something larger than that? There's a, yes. So it's exactly the same technology. So the same way that you could go and describe a digital credential that has things like your passport, driver's license, education history, healthcare history, financial history into these digital credentials. You could similarly go and capture and put into these digital credentials.
31:14These are the topics that I trust this particular AI agent on. And this is the duration that it's authorized for. Or a company could go and issue a credential to that AI agent that says it's been accredited or assessed to this standard. The sort of tangential and related space that comes in is something called content credentials. and content credentials is a coalition that includes companies like Microsoft and Intel, Google, Adobe, who've been working on how can you have a chain of custody that proves a particular image or video or audio is AI generated or human generated. But again, not as a binary question, but as a chain of history of every single edit that has happened to that picture.
32:11Because editing is not bad. Like maybe you have a human model and you're using an AI backdrop. That's okay. But somebody who's viewing that picture should be able to see that there was a human model used and there was an AI backdrop that got inserted in. You can actually try this now, like if there's ever an image that you create using ChatGPT or DALI, go paste it into one of the websites that support reading content credentials, like LinkedIn, and you'll see a tiny logo that says CR, that stands for content credential, and you click on it and it will start showing you the history behind all of this.
32:57um now what's quite interesting is i don't think any uh of these companies necessarily want to run the run it as a centralized service because a there's a lot of content billions billions of images and videos and so on um but if they become the centralized registry of what is ai generated or what is not AI generated, that then becomes a very big political challenge in terms of content moderation. And so therefore, they don't want that problem. They want it to be self-contained and cryptographically provable along with the video or the piece of image that comes along to understand what edits happen to it.
33:48And also because I think some edits are fine. Maybe you use AI to remove a building from the background in a picture that you've taken on your holiday. Or Getty Images is blurring out the pictures that were taken by someone at a protest to protect their identity. What's quite fascinating is there are companies like Leica and Samsung that are building in the capability of starting this from the chip on the camera itself. So from the moment a picture is taken, every single step will have a content credential of what the edit was made to it. What we've been working on is how can then AI agents use this as part of their assessment of when they come across information to see is this trustworthy or not, the same way that a human might perhaps try and apply the same filter in a couple of years' time.
34:58um where where it also sort of like you know becomes quite interesting is when you then go and train ai agents a lot of the over the past sort of two or three years a lot of the data has become computer generated ai generated and essentially because these are very good parrots of parroting information. People do want to start distinguishing this training on what's based on actual human-generated data that it wants to go and mimic. And what is synthetic data? There are already studies that show at somewhere close to just 5 % or 7 % of the information being synthetic or AI-generated, it just starts producing garbage because it's not able to distinguish what's the right thing that it should be able to go and mimic versus just AI-generated slop that it shouldn't start skewing towards.
36:01Yeah. So how does – where do I go from this? Lots of different things there, yeah. Yeah. Well, let's focus on agents. How do you see this being implemented? And as I said, on the one hand, you need to build a critical mass of agents using this protocol. but on the other side, you need to build a critical mass of websites or other services that are accepting or have a reader or something that allows agents through based on this protocol. I think that's absolutely early days on a lot of these topics. One of the – what we've worked on is – I don't know if you've heard of something that came out of Anthropic called model context protocol or MCP.
37:02Yeah, of course. And it's a way of giving AI agents structured access to tools or structured access to different kinds of information. And so we're one of the first decentralized identity or digital identity sort of software, like, you know, creators to give MCP or create MCP tools that can talk and understand decentralized identifiers, that can talk and understand digital credentials that could either be credentials for the AI agent themselves, permissions that they have received from human beings, or additional credentials that have been attached to content in terms of content credentials. And what's been quite fascinating is a lot of these ideas were bubbling around for a long time within the identity as well as the AI industry.
38:00MCP only came out last year, November, so just before Christmas. and um i think what was sort of unsure for a while is how you know how does this scale beyond just the ai agents based on created by anthropic or or the people that support mcp what's happened within the past one or two weeks is openai has come out and said yes we are going to go and add this to open ai's chat gpt desktop app and to the um chat like open ai agent sort of toolkit and a very similar statement came out from google which is one of the other sort of large providers for ai agents and frameworks so what we start sort of seeing is the the problem is being recognized by people.
38:57That on one hand, we have Captcha and we have bot protection that we run on websites that keep AI agents out. On the other hand, every single one of these companies wants to give people the idea of like, actually, you know what, let's offload, take that task off your hands. And so they do want to go and solve these problems. The big breakthrough, I'd say, in terms of adoption that's happened is the number of services and the number of AI agent makers that have started supporting MCP or model context protocol within the last five to six months. yeah and so you you would uh check or some some other uh verified identity protocol would be or would be a tool that model context protocol could could uh interface with or integrate into a into a model is that right exactly and and what model context protocol is great at is is to capture those things into sort of rigid rules or, you know, sort of rules, because before that, people were doing the same thing that MCP does, but by using very long and complicated prompts, which is not guaranteed to work.
40:30And it's sort of like, you know, hit or miss on whether that works or not. We've also been engaged with some other emerging standards and protocols. There's some very interesting research coming out of Stanford on something called DISP, which is writing prompts as code. But I think the biggest sort of evolution on this side has been model context protocol. And what that sort of currently doesn't do is it entirely does not talk about how does identity get handled, how do you handle permissions, how do agents get some mechanism through which they can understand what is the content they're seeing and how trustworthy it is.
Read the full transcript
41:16And that's where CHEKT and hopefully other decentralized identity providers can add that sort of toolkit to the set of arsenal that AI agents have on how they can be trusted and how they can trust the information that are coming across. Yeah, and MCP is like the universal interface, right? So you don't have to use API keys and things like that. But how does an AI agent that has MCP in its architecture, I'm not quite sure how to say that, but how does it find Checked? do you have to does does the agent have to know about checked or or does when the agent runs into a roadblock uh does it cycle through all of the various uh verification uh tools out there through MCP and to find the one that's going to unlock that website.
42:34There's an answer for what happens now versus what happens in perhaps the future. So right now you have to tell the AI agent. Simplest example is Claude Desktop, which comes from Anthropic. It's one of the big places where people are testing and building all of this software. So you have to go and explicitly tell it that here's the set of tools that I'm attaching and giving to you. So you might go and attach a tool for Google search. You might go and attach a tool for understanding digital credentials and explicitly tell it that go use this. But given how core some of these problems are, two things that I expect to happen within the next year.
43:27The first is the same way that you have Apple Wallet or Google Wallet built in on your phone, and that's where you currently store digital credentials, or maybe there's a different digital ID app you use. agents will come with an identity wallet built in the way that they currently don't particularly do or handle right now. And this is where they'll store digital credentials they have been given to handle, as well as things that the humans that they work with give on their behalf. and the second thing is uh where mcp sort of evolves to is looking uh giving agents the the ability to autonomously determine which tools to go and pick yeah um and and and that again comes back to similar sort of challenges like uh which ai agents do we go and trust but because Because these trust models can often be started off by government lists or government trusted lists or maybe industry association lists of what's a trustworthy agent.
44:41That I think starts becoming the starting the launch pad for an initial set of tools that the AI agents can discover by themselves. and then from maybe those trusted tools or trusted agents, they can go and ask almost, in a sense, what are the other tools and what are the other agents do you trust and start discovering from that basis. So I think there's a lot of steps to get there because MCP itself is fairly new. But what I think is quite interesting in this space is the way that this can be expressed is explicitly what a lot of the decentralized identity digital credentials have been built to solve.
45:35And where is it? So right now, if you're, I mean, you can do this now, right? So if you're building an agent, you can pick, checked, or you can pick, I don't know who else is out there. This is all new to me. And give it access through an MCP to those tools. And then when the agent is out in the cyberspace and runs across something that is asking for it to verify its identity, it would cough up checked. But if that service or site doesn't use or recognize checked, I mean, what's going to happen that the, I'm going back to the Taylor Swift ticket issue. Will Ticketmaster just, you know, review all these various identity tools and, and add a whole bunch of them.
46:44So if you come in, if your agent comes in and offers check, check is one of the tools that the master uses, and it'll verify the agent's identity and let it through. Is that how you imagine that happening? Yeah, it would partly be that. They would need to understand the digital credential formats. Now, what's quite interesting is that this kind of technology is not just proprietary to us at Chekt. We have built our own improvements and additions on top. But a lot of the technology standards for this get set at places like W3C, which is World Wide Web Consortium. And that is the nonprofit organization that sets how HTML works and how websites work.
47:42So the same way that Ticketmaster has adopted HTML to go create its website, it would have to add support for the digital credential specification that has come from W3C. which is again yes that is a step that the website would need to take but given that a lot of the web standards do get set and adopted by companies from what's happening at w3c it's a it's a bit of an easier ask than saying just go and do this specific thing for what checked has done um it works not just with the kinds of digital credentials that we might build but hopefully someday that well coin also does well coin hopefully instead of going and doing their own thing uh hopefully adopts the digital credential standard that w3c has come up with and and expresses it in that format the second answer is the second part of that is we've also acknowledge the fact that not every single company is immediately going to switch over to starting to use decentralized identities.
49:01And so we worked with a research institute in Germany called Fraunhofer Institute. Fun fact, they're the people who invented MP3. So as a format back, back you know back in the 90s um so we work with fraunhofer on a piece of software and a specification that allows you to tie these decentralized identifiers that are written usually on blockchains to uh standard domain names so like this identifier will attach to Craig's home sort of, you know, domain name, and this one attaches to Chek's website, and this one attaches to Microsoft.com. And they're able to go through that entire list of accreditations or trust that additional credential that might have received, and translate it back to the traditional domain name system.
50:03What's quite powerful about that is there are already mechanisms that exist to understand, do I trust this website more than that website? And there's a lot of ranking that gets done by things like search engines or some sort of assessment that can be done. Because I fully understand that sort of transition from the way that identity and trust gets handled now to a decentralized way of doing it might take time and there will be people who are further ahead and people who are further behind. And so that's why we worked on this sort of project with Fraunhofer to look at what happens in the middle, what happens when maybe five companies have adopted decentralized identity but then the rest of the billions or millions of companies haven't done that yet how can they still go and utilize this um and and that's one of the other sort of like unique aspects of the work that we've done at checked um which uh a lot of the other sort of like you know models for example like the one that worldcoin is building doesn't actually accommodate that like know it's it's very much come across to like you know all or nothing into the new world which which i don't think is very pragmatic unfortunately um does this mean that that uh capture will eventually go away or or will capture run alongside there'll be you know if an agent runs into a site there'll be something unseen to uh yeah uh to the to the user that happens that allows the agent through i think captcha will still be around because captcha is solvable by ai but it's expensive so you know you have to be really motivated to take a screenshot of something and feed it to open ai to chat gpt it could probably solve it but do you care that much so it does take out a lot of low level automation and and the way that i sort of describe this proof of humanity or proof personhood is it lies on a spectrum at one end you have capture and just prove you are a human um there's a very different question which is proof that you are that specific human and prove that you're craigsmith or prove that you are a human that lives in the US or prove that you're a human that lives in the UK.
52:45Captcha doesn't solve that. Captcha is only looking at, are you non-automated to a very low level extent? And to be honest, there's definitely value in that. It just takes out the dumbest, simplest kinds of automation. that somebody might be able to write. Where you get into after that is, I think proof of humanity is useful, but sometimes there are other different aspects to that which also need to get solved. That don't necessarily get solved, like it's great that you can prove proof of humanity that is backed by a biometric and it's definitely a person, but people have multiple passports. people might go and register with multiple systems.
53:36And it still doesn't go and solve the question of like, are you specifically Craig Smith? And that's the, you know, legal identity that you have. It doesn't solve like, you know, do you live? Have you lived in a particular part of town for the last five years or 10 years? Those become more complicated questions. And And what's quite good about these industry standards that have been created at W3C is it's flexible enough to go and accommodate the whole range of those questions and not just one narrow piece of it, which is, are you a human or not? Yeah. Just as you're talking, I'm thinking about some of the verifications on the internet.
54:27So many websites will ask you, you know, to verify that you're over 18. Yeah. You know, YouTube, you have to log in with an identity in which you put in your birth date. But most is just a button. you know yes i'm over 18 which to me seems like a pretty big loophole for certainly for parents or concerned about what their children are seeing on the internet is uh is do you see that being solved i mean we're getting into human identity which is different from what you guys are doing but we are also working on on problems like that because at the core of it um the the big sort of problem we wanted to solve is decentralized identity and having a copy of your own data for yourself sounds great but why would any company ever do that like what's the commercial incentive or value for them.
55:41The reason why we have your data in a silo held by big tech companies is because they derive a lot of value out of it. They sell ads off the back of that. So they have absolutely zero incentive to give you a copy of your own information. Because they see it as that just lets you walk out of the door to our competitor more easily. And so, although the space has existed for a while, what we are quite uniquely doing at Checked is we built a privacy-preserving mechanism where if you use a digital credential that has been issued by a company to, say, maybe transfer across your e-commerce preferences or prove that you're above the age of 18 without revealing too much information.
56:33So not revealing your name, not revealing your actual date of birth, maybe from something that was issued by your bank, because your bank did a background check on you to before they allowed you to open the bank account. We built a mechanism that allows the bank to get paid in a completely privacy preserving fashion. They don't know who went and used the credential. They don't know what information got shared. They don't know absolutely anything about when that interaction happened. But it then starts giving them an incentive to give you a copy of that information. It doesn't mean the bank doesn't need to hold on to your information.
57:17Of course they do, because they're a customer. They need to know where you live. They need to know your name, et cetera, et cetera. But by giving you a digitally tamper-proof copy that you can then start using to prove that you're human online or prove you're above 18 or prove that you live at that specific address when you're about to go and buy a$5 ,000 MacBook and prove to Apple that you're not a scammer who's buying this with a stolen credit card, your bank knows that you've lived there for five years. there's a lot of value in answering that question. And we enable that to happen as well.
58:03So the AI agent piece of it has been a large part of the focus for, I guess, the last sort of like year and a half. But we actually have 50 different app developers and companies that are building solutions on top of the checked sort of network. Some of them, in fact, are going and solving problems for humans.
58:30And in various different sort of countries and use cases. Yeah.
From the publisher
AGNTCY - Unlock agents at scale with an open Internet of Agents. Visit https://agntcy.org/ and add your support.
What if AI agents needed digital passports to act on your behalf?
In this episode, Ankur Banerjee, Co-Founder and CTO of cheqd.io, reveals how decentralized identity is becoming the foundation of the AI agent economy.
From booking Taylor Swift tickets with an agent to proving you're a real person online, we explore why identity and trust are the hidden infrastructure shaping the future of AI.
Ankur explains how cheqd is building privacy-first tools that let AI agents verify who they are, what they can do, and who they're working for, all without handing over your data to big tech. We dig into the rise of digital credentials, the limits of biometrics, and how protocols like MCP are making the internet safe for autonomous agents.
If you've ever wondered how AI will operate on your behalf in the real world, this conversation offers a glimpse into what's coming next.
Stay Updated:
Craig Smith on X: https://x.com/craigss
Eye on A.I. on X: https://x.com/EyeOn_AI
(00:00) Why AI Needs Identity
(02:16) Ankur’s Path to cheqd
(05:39) Delegating Tasks to AI Agents
(11:26) Identity Lessons from Governments
(17:25) Trusting AI with Digital Credentials
(23:42) The Problem with Biometrics
(30:49) Web Standards for Agent Identity
(36:46) MCP and Agent Interoperability
(48:47) Bridging Web2 and Web3 Identity
(55:18) Why Companies Should Care About Decentralized ID




