Moca CEO: AI agents require provable identity
Moca Network CEO Kenneth Shek said AI agents must have verifiable identities and revocable, time-limited permissions before they can transact or access user data.
Kenneth Shek, chief executive of Moca Network and project director at Animoca Brands, said AI agents will need verifiable proof of who they represent and what they are allowed to do as they begin handling payments and personal data for users.
Shek predicts agents will move from answering questions to acting as digital representatives that can pay bills, redeem rewards, use loyalty status and verify personal information. He argued that conventional methods such as passwords, API keys and simple delegated credentials do not show the relationship between an agent and the human it represents or the exact limits of an agent’s authority.
To address those gaps, Moca proposes an “identity plus agent” approach and a policy layer called AIR on top of its identity system. Under this approach, a user grants specific, time-limited permissions to an agent. Those permissions can be revoked and enforced cryptographically so an agent can only access or verify data and spend money within defined limits.
Technical elements described by Shek include encrypted, continuously available decentralized storage for user-controlled records; onchain issuance and verification to create an audit trail; principal-agent binding to link an agent to a user; policy and delegation management to set permissions; and cross-chain interoperability for wallets and identity records.
Shek outlined choices for sharing information that range from full disclosure to selective disclosure and the use of zero-knowledge proofs, which let an agent prove a fact-such as being over a certain age-without revealing underlying data fields.
He also described a commercial shift: businesses are likely to screen for approved agents rather than only blocking bots. Approved agents could be treated as potential customers, but companies will need ways to confirm an incoming agent is tied to a real user and authorized to complete a payment or access data.
Everyday examples highlight the limits of current systems. An agent buying alcohol online must prove the buyer is of age; an agent booking a flight needs to show a user’s loyalty status; a shopping agent needs spending limits and location restrictions. Shek noted the next tests will be whether companies adopt interoperable credential standards, whether users trust permission controls and whether businesses will accept the costs of repeated verification.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








