In September 2026, Ant International said it would work with Mastercard and Visa on shared “Know-Your-Agent” standards for AI-driven payments. The aim is to let networks onboard and identify AI agents under shared principles and cut duplicated checks. Visa’s Rubail Birwadker put the stakes plainly: “Without trusted identity and explicit permissioning, AI agents cannot participate in commerce at scale.”
The card networks are converging on one question. Who stands behind this agent? This post explains why that question is hard, what the open standards do and do not answer, and how Revolution V2 specifies an answer.
The problem: agents without owners
Machines already dominate the web. Imperva’s 2026 Bad Bot Report found that automated traffic accounted for “more than 53% of all web traffic in 2025”. The same report describes AI agents as a new participant that can “act on behalf of users”. A merchant cannot treat all of that traffic as hostile. It also cannot treat it as a customer.
On Ethereum, the leading answer is ERC-8004, Trustless Agents. It is a Draft standard with three registries: identity, reputation, and validation. Its identity registry uses ERC-721, which makes agents “browsable and transferable with NFTs-compliant apps”. The specification is explicit: “The owner of the ERC-721 token is the owner of the agent”. Its security section is also candid: “Sybil attacks are possible, inflating the reputation of fake agents.”
Adoption was fast. An empirical study posted to arXiv in June 2026 and revised in July counted more than 170,000 registered agents across Ethereum, BNB Smart Chain, and Base. The same study measured what reputation costs to fake. It found that a reputation can be fabricated or destroyed at a median cost of $0.055 on Ethereum, $0.0042 on BSC, and $0.0027 on Base. It flagged 73.5%, 59.2%, and 90.6% of reviewers on those chains as showing coordinated Sybil behavior.
The lesson is not that ERC-8004 failed. It did what it set out to do: publish signals in a common schema. The lesson is that a transferable identity with free feedback cannot carry trust on its own. Three properties are missing.
- Binding. Nothing ties the agent to an accountable human or legal entity.
- Permanence. A good record can be bought and a bad one discarded, because the identity can move.
- Privacy. Proving an attribute usually means revealing it.
How the pieces fit
Regulators and standards bodies are working on each gap.
Binding. NIST launched an AI Agent Standards Initiative in February 2026. One research pillar covers agent authentication and identity infrastructure. Its NCCoE published a concept paper, Accelerating the Adoption of Software and AI Agent Identity and Authorization, on 5 February 2026. It asked for input on identification, authorization, auditing, and non-repudiation of agents. Comments closed on 2 April 2026.
Traceability at the edge. Visa’s Trusted Agent Protocol, announced in October 2025, lets merchants recognize trusted agents through cryptographic signatures. It builds on HTTP Message Signatures and aligns with Web Bot Auth. Cloudflare’s Web Bot Auth uses RFC 9421 signatures and three headers: Signature-Input, Signature, and Signature-Agent. Cloudflare’s “signed agents” category covers agents that act for “the end users themselves”, not for one company.
Shared rules. The Know-Your-Agent work aims to bridge Visa’s Trusted Agent Protocol, Mastercard’s Verifiable Intent, and Ant International’s Agentic Mobile Protocol, according to TNGlobal. Forkast reports that the framework centers on operator traceability, shared certification, and continuous monitoring, and that technical specifications are not yet published.
Private attributes. W3C made Verifiable Credentials 2.0 a standard in May 2025. Holders can present “a subset of a credential (providing selective disclosure of the private data)”. In Europe, Regulation (EU) 2024/1183 requires each member state to offer at least one certified EU Digital Identity Wallet. Brussels Signal reports a 24 December 2026 deadline, with most member states behind schedule.
These efforts answer parts of the question. None of them binds an on-chain agent to a verified human, keeps its record permanent, and proves attributes in zero knowledge in one place. That is the gap Revolution V2 is designed to close.
What Revolution V2 specifies
Revolution names its identity stack with five terms:
Nomen (name) tells the network what you’re called. Sigillum (verified identity) proves who you are. Potestas (permissions) determines what you’re permitted to do. Mandatum (delegated authority) defines the authority you delegate. Agens (agent) acts within it.
Status first. The identity contracts are specified, not built. RNS on V2, the Agent Identity Registry, the Facet Registry, and the Proof Verifier ship in Phase 2 of the roadmap. The account layer is built on a devnet: ERC-4337 EntryPoint v0.8, ERC-7579 Nexus accounts, and the Cornerstone Paymaster. Until the registry ships, an allowlist identity gate stands in for it. Virtus (V2 testnet) is not live.
Nomen (name): the namespace
The Revolution Name Service issues Nomen (name) records as .revo names. A Nomen (name) resolves to accounts and service records. Public records never contain personal data. rob.revo is a root Nomen (name).
Sigillum (verified identity): levels
A Sigillum (verified identity) is the verified identity behind a Nomen (name). RNS verifies the holder off chain with identity data partners and writes commitments, never attributes.
| Sigillum (verified identity) level | Meaning | Potestas (permissions) unlocked |
|---|---|---|
| L1 Basic | Email and device bound, uniqueness checked | Agent creation, low-value settlement |
| L2 Verified | Government identity checked against data partners | Age and jurisdiction facets, standard settlement |
| L3 Enhanced | KYC and AML screening completed | Accredited-investor facets, RWA-linked settlement |
| L3 Entity | Legal entity verified with an authorized signatory | Merchant agents, bonded reputation pools |
Levels are governance-set. A business gets an L3 Entity Sigillum (verified identity) only with an authorized signatory. That is the legal-entity binding a Know-Your-Agent program asks for.
Agens (agent): sub-identities under a verified parent
An Agens (agent) identity is a subdomain of a verified Nomen (name). Its label is the Praenomen (agent name).
rob.revo verified human (parent)
shopping.rob.revo Agens (agent), Praenomen (agent name) "shopping"
travel.rob.revo Agens (agent), Praenomen (agent name) "travel"
acme.revo verified legal entity (parent)
sales.acme.revo merchant Agens (agent)
The whitepaper fixes seven rules:
- Only a parent with a verified Sigillum (verified identity) can create an Agens (agent) identity.
- Agent identities are soulbound. There is no transfer function.
- The parent can suspend or revoke a child, and its Mandatum (delegated authority), at any time. Revocation is permanent.
- A revoked identity’s history stays attached to the parent.
- A parent that revokes a bonded merchant agent forfeits bond subject to open disputes.
- If RNS suspends a parent for fraud, all of its children are suspended.
- Agents cannot create agents.
Each record holds the agent ID, the parent ID, the agent’s smart account, a rotatable controller key, a hash of the parent’s standing Mandatum (delegated authority), a facet root, a reputation pointer, a status, and a mirror ID in the ERC-8004 registry on Revolution. The mirror is read-only with transfer disabled. ERC-8004 tools can discover a Revolution Agens (agent). They cannot move it.
Facets: prove the attribute, keep the data
A facet is one provable attribute of a Sigillum (verified identity). RNS commits each credential as a leaf in a Merkle tree and stores only the root. The agent proves in zero knowledge that a leaf satisfies a predicate and is not revoked. Each proof carries a nullifier bound to one settlement, so it cannot be replayed.
| Facet | What the merchant learns |
|---|---|
human.verified | A verified human stands behind this agent |
entity.verified | A verified legal entity stands behind this agent |
age.over.21 | The human is over 21, not the birth date |
jurisdiction.in | Residence is in an allowed set, not the address |
reputation.above | The score clears a threshold, not the score |
kya.certified | A Know-Your-Agent certification is held |
Per identity, the chain stores one facet root, one reputation pointer, and per-settlement nullifiers. Nothing else. Phase 2 targets audited circuits for the first six facets, from human.verified through jurisdiction.not.in.
Agnomen (earned reputation): bonded, not bought
The Agnomen (earned reputation) of an identity is standing earned through conduct. The Reputation Registry records settlement history, dispute history, and bond per Agens (agent). A published, deterministic function produces a score. The score is exposed only as a reputation.above facet.
Merchant and expert agents post a REVO bond before they can respond to intents or accept settlement. Disputes can slash that bond, with buyer restitution paid first. Because identities are soulbound and records follow the verified parent, a merchant cannot buy a good record or discard a bad one. The study above found that an ERC-8004 reputation can be fabricated for a few cents. Under this design, reputation rests on settlement history and a bond at risk instead.
What it means for builders and users
For merchants. Under the specification, a request from shopping.rob.revo can carry a proof that a verified human is behind it, that the human is over 18, and that the agent’s Mandatum (delegated authority) covers the purchase. The merchant checks proofs, not documents. The whitepaper maps this to Know-Your-Agent expectations: parent binding for operator traceability, facets for shared certification, the settlement record for monitoring.
For agent developers. Your Agens (agent) inherits trust from its parent Sigillum (verified identity). It does not accumulate trust from a token it holds. Plan for revocation. If the parent revokes the Agens (agent), its history stays with the parent and the identity does not return.
For users. You hold one Nomen (name) and create an Agens (agent) per task. Each gets its own Mandatum (delegated authority) and its own kill switch. Identity creation, facet proofs, and anchoring are designed as free cornerstone calls paid by the network’s Cornerstone Budget.
Interoperability. The whitepaper lists connection points rather than rival protocols. The agent controller key signs HTTP requests under TAP and Web Bot Auth, with the .revo name in metadata. Every Agens (agent) has an ERC-8004 mirror. A kya.certified facet import and a KYA credential export are planned.
What is next
Phase 2 of the roadmap delivers RNS on V2 with .revo names, the Agent Identity Registry, the Facet Registry and Proof Verifier with audited circuits, credential issuance and revocation roots, the ERC-8004 mirror, and passkey sign-in. The identity gate then switches from the allowlist to the registry. The Phase 2 exit test: a verified user creates agent identities with a passkey and no gas, facet proofs verify on chain with published circuit audits, and an external agent runtime resolves .revo agents.
Open items are public. The recovery model for verified parents is not yet specified. The credential format for circuits needs confirmation with issuers. Existing names from Libertas (V1 network) move to .revo, and holders of names under both TLDs are an open item.
The industry has agreed that agents need an owner. The next step is to make that ownership permanent, verifiable, and private. Revolution’s next post covers the other half: how Mandatum (delegated authority) gives an Agens (agent) spending power without giving it your keys.
Sources
- TNGlobal: Ant International, Mastercard, Visa to align on “Know-Your-Agent” standards (11 September 2026)
- Forkast: Ant International, Visa, and Mastercard agree on agent identity standard (September 2026)
- Imperva: Bad Bot Report 2026, Bots in the Agentic Age
- ERC-8004: Trustless Agents
- arXiv 2606.26028: Can Trustless Agents Be Trusted? An Empirical Study of the ERC-8004 Decentralized AI Agent Ecosystem (abstract)
- arXiv 2606.26028 (full text, cost analysis)
- NIST: AI Agent Standards Initiative
- NIST CSRC: Accelerating the Adoption of Software and AI Agent Identity and Authorization (concept paper)
- Visa: Visa Introduces Trusted Agent Protocol (October 2025)
- Cloudflare Docs: Web Bot Auth
- Cloudflare Blog: The age of agents, cryptographically recognizing agent traffic
- W3C: Verifiable Credentials 2.0 published as a W3C Standard (May 2025)
- Brussels Signal: EU digital identity wallet stalls in 24 member states (September 2026)
- Revolution Network Whitepaper V2, sections 3.1, 5, 6, 9.8, 9.10, 12, 13, 15


