Kenneth Shek, head of Moca Network, just laid out a problem that's about to get very real. AI agents won't stay as passive chatbots forever. They're moving into territory where they'll spend your cash, verify your data, redeem rewards, buy things on your behalf. The moment that happens, a password stops being enough.
Right now, most people think of AI as something that answers questions. Shek flipped the script. "Every user will eventually have their own agent," he told Bitcoin.com News. "Once that happens, the agent is not just a chatbot anymore. It is doing things for you." That shift from answering to acting creates a mess nobody's really prepared for.
The credential problem nobody solved
Ordinary passwords and API keys were built for a different world. An API key lets one piece of software talk to another. A delegated credential gives limited access to an outside service. Both work fine when you're just reading data. But hand an agent your raw API key so it can spend money, and you've handed over a loaded gun with no safety. Shek put it bluntly: "You cannot just give the agent your raw key. You cannot just give it a broad API credential and hope everything works out."
The real questions nobody's asking yet are the hard ones. Who actually controls that agent? Which user does it represent? What data can it touch? How much money can it spend, and where? For how long? If you change your mind tomorrow, can you pull the plug? Traditional authentication systems were never designed to answer any of that. They're binary. You're either in or out. They don't map the precise boundaries of what a digital representative should be allowed to do on your behalf.
From blocking bots to welcoming the right ones
The internet spent two decades treating automated traffic like an enemy. CAPTCHA tests, fraud detection, bot filters. All designed to keep machines out. Shek expects that entire model to flip. "The world is moving from screening out bots to screening for the right bots," he explained. Websites used to block everything automated. Now, approved AI agents won't be treated as unwanted visitors. They'll be treated as customers.
That means businesses need a way to verify which agents are legitimate, which users they represent, and how much authority they actually have. A provable identity system isn't optional anymore. It's the infrastructure that lets the next phase of automation actually work. Without it, you're either handing agents too much power or locking them out entirely. Neither option scales.
This article is informational only and does not constitute financial or investment advice.


