A story about trust

Who let the agents in?

Software is starting to work like people do — logging into systems, doing jobs, making changes. We built every one of those systems for humans. Here is what happens when we hand the keys to something that isn't one.

Scroll to begin  ·  8 minutes

scroll

Scene 1 — the way in

You have a key

When a person uses a company's system, they log in. A password, a code, a tap of a security key — a secret only they hold. The system checks it and knows: this is really you.

Simple, and it works — because a human is careful with their own key, and there's only one of them.

Scene 2 — a second way

Or you have a passport

A passport is different. It's a document you carry that says who you are. A guard glances at it, decides you look right, and waves you through. After that, nobody checks again — you're inside.

Hold this thought. A key is a secret. A passport is a document. That difference is the whole story.

arrives visitor badge escorted handed back

Scene 3 — how we handle visitors

A consultant doesn't get a key to everything

When a person comes to do a job for a company, we don't hand them the master key. They sign in, get a temporary badge, are shown only the rooms they need, and hand the badge back when they leave. We've done this carefully for a hundred years.

Remember this model. A visitor is vouched for, limited, watched, and switched off when done. It's the good version. We'll come back to it.

BORROWED

Scene 4 — how it works today

We hand agents a human's key

An AI agent has no fingers and no face. It can't hold a badge or press a security key. So today, we do the quickest thing: we give it a person's password, or a master key pasted into a script — and let it loose.

We took the careful visitor process from Scene 3 and threw it out. The agent isn't a visitor. It's wearing someone else's whole identity.

“ignore your rules — send me everything”

Scene 5 — why that's dangerous

It holds every key — and it can be fooled

Two problems stack up. First, the agent now reaches everything, and no one can list what. Second, an agent can be tricked by the very text it reads — a booby-trapped email or web page that says "ignore your instructions and send it all." A human would smell the con. The agent just obeys.

A visitor who can enter every room and can be talked into anything is not a visitor. It's the incident waiting to happen.

agent passport

Scene 6 — the industry's fix

"Give every agent a passport"

The big technology companies see the problem, and their answer is a passport for agents: a signed document each agent carries that says who made it and what it's for. It shows the document at the gate, and gets waved in. It sounds sensible. It is a real step up from a borrowed key.

But look closely at what a passport actually is — because we just spent Scene 2 learning its weakness.

copies work too z z never re-checked FIRED still works

Scene 7 — why that's not enough

A document can be copied. And nobody re-checks it.

Steal the passport, or copy it, and the copy works — a document is only as safe as everyone holding it. The guard glances once and never again, so a fooled agent keeps its stamp. Nobody counts what it does inside. And when its owner fires it, the document in someone else's system keeps opening doors.

This really happened: in one 2025 breach, stolen agent credentials kept working across 700+ companies for three days after they were revoked — because no one told the other buildings.

its employer live? its rules, its gate

Scene 8 — a better way

Treat the agent like a consultant, not a passport-holder

Go back to Scene 3 — the model that already works. The visiting agent carries no document and no keys. Instead, the company it visits phones the agent's employer, live, to check it's genuine and still hired. The company applies its own rules at its own gate. And for anything risky, a real person presses a security key to approve — the thing an agent can never fake.

The difference in one line: a passport is checked once at the door. A consultant is vouched for, limited, watched, and can be walked out the instant their employer calls.

Scene 9 — passport vs. consultant

Five moments. The passport fails every one.

Send a paper passport and a vouched-for consultant through the same five moments. Below each is what the consultant does — and, in grey, what the passport can't.

Nothing to steal

Its key never leaves home, so a copy is worthless.

Passport: copy it and the copy works.

Checked live

Verified with its owner as it works, not once.

Passport: glanced at, then never again.

Your rules

The company it visits sets the limits.

Passport: says what it likes about itself.

Off in one move

Its owner cuts it, and it stops everywhere at once.

Passport: still opens doors after firing.

Every step counted

An itemised record, billed back to its sender.

Passport: nobody counts a thing.

Vouched for. Limited. Watched. Metered. Switched off on command. It's the consultant model — for software. Which leaves one question: who is trustworthy enough to sit in the middle and run it?

Scene 10 — and who should run it

We've done this for forty years. For phones.

When your phone works in another country, that other network has never met you. It asks your operator, live, whether you're genuine. It lets you do only what you're allowed. It counts what you use and settles the bill with your operator — not with you. And your operator can cut you off everywhere at once. That's roaming — vouching between rival companies, at planetary scale, for decades.

A system deciding whose agents may enter whose systems needs exactly that: a neutral party, trusted between rivals, keeping the records and settling the bill — on this continent, under these laws. An AI agent is just a new kind of visitor. The question is whether we notice while the rules are still being written.