AI agents are moving fast from novelty to necessity, and in a new op-ed for AIJourn, Vouched CEO Peter Horadan argues the industry is handling their access all wrong. Today, agents don't have identities of their own, they simply borrow ours, either by taking over a logged-in browser session or riding on a durable OAuth token. That means when an agent places an order, changes a setting, or accesses an account, businesses have no way of knowing whether a human or an AI actually did it.
Horadan's core argument: agents must have their own identity, separate from the humans who deploy them. He lays out four reasons this is non-negotiable as agents take on more consequential work:
Horadan draws a direct parallel to banking in the early 2000s, when screen-scrapers demanding usernames and passwords pushed the industry to invent OAuth 2.0, letting users grant limited, revocable access without handing over full credentials. He argues agentic identity needs that same kind of dedicated framework, one that blocks human-to-agent credential sharing outright and gives people a real, auditable way to authorize what their agents can and can't do.
Read the full article to see why this matters.
Originally published on The AI Journal. For full article, visit the source.