AI

AI Agents Need IDs: The Identity Arms Race Has Begun

Autonomous agents transact freely → financial systems scramble for control

Level 1

What Happened

Two startups raised fresh funding this week to solve a newly critical problem: verifying the identity and permissions of AI agents operating inside financial and enterprise systems. Baselayer closed a $35 million Series A to expand its Agentic Identity Suite for financial institutions, while Palma.ai secured $1.8 million in pre-seed funding to govern multi-agent ecosystems across enterprise platforms.

Key Points

  • Baselayer raised $35M led by M13 to build identity and fraud infrastructure specifically for autonomous AI agents transacting inside financial systems.
  • Palma.ai raised $1.8M pre-seed to centralize permissions governance across AI agents using the Model Context Protocol standard.
  • Both companies target the same root problem: legacy identity systems were built for humans and companies, not autonomous software.

Sources

VentureBurn

VentureBurn

Level 2

Why It Matters

The emergence of agentic commerce is exposing a structural gap in the global financial and enterprise security stack. Identity infrastructure built over decades assumed a human or a registered legal entity sat at the end of every transaction. That assumption no longer holds.

Key Points

  • Stripe reports that roughly 70% of its API requests now originate from AI agents, signaling that agentic activity has already crossed the threshold from experiment to mainstream infrastructure load.
  • McKinsey projects agentic commerce could redirect $3 trillion to $5 trillion in global retail spending by 2030, making the identity gap a systemic financial risk, not just a product opportunity.
  • Visa, Mastercard, American Express, and Shopify have all launched agent commerce protocols in parallel, confirming industry-wide urgency rather than isolated startup speculation.
  • The Model Context Protocol, used by Palma.ai as its integration backbone, is an open standard connecting AI models to live business data, meaning the permissions problem is already embedded in enterprise infrastructure at scale.
  • Baselayer's claim of preventing over $1 billion in fraud losses across 2,300 institutions gives it rare production-grade credibility in a space where most players are still pre-revenue.

Sources

VentureBurn

VentureBurn

McKinsey & Company

Stripe

Level 3

What Changes

The funding of Baselayer and Palma.ai signals a structural shift in how financial and enterprise technology vendors must think about trust, compliance, and transaction authorization. The agentic economy does not slot neatly into existing regulatory or operational frameworks. Concrete changes are already underway across payments, enterprise IT, insurance, and regulatory compliance.

Sources

VentureBurn

VentureBurn

FIDO Alliance

McKinsey & Company

winners

  • Baselayer's 2,300-institution network gives it a distribution moat that pure-software identity startups cannot replicate quickly, positioning it as a likely acquisition target or category standard-setter.
  • Palma.ai benefits from early-mover advantage in MCP governance, a layer that every enterprise deploying Claude, Gemini, or Copilot will eventually need to address.
  • Card networks like Visa and Mastercard, which are already building agent commerce protocols, gain legitimacy and urgency for those investments as the identity problem gets formally named and funded.
  • Enterprises that adopt agentic governance tooling early will operate with lower fraud exposure and cleaner audit trails, giving them a compliance advantage as regulation catches up.

losers

  • Traditional fraud detection vendors built on static rule sets face direct obsolescence pressure as Baselayer explicitly markets against their inability to handle dynamic, agent-driven transactions.
  • Enterprises that delay implementing agent identity governance face compounding liability as regulators begin scrutinizing autonomous system activity inside critical infrastructure.
  • Mid-market financial institutions without dedicated AI risk teams are the most exposed: they have the agent activity without the oversight tooling.
  • Open-source MCP implementations without centralized policy enforcement become security liabilities the moment enterprises move from pilot to production.

implications

  • Compliance and legal teams at financial institutions will need to define what constitutes authorized agent action, creating a new category of internal policy work that does not yet have established frameworks.
  • Cyber insurance underwriters will likely begin requiring documented agent identity and permissions governance as a condition of coverage, accelerating enterprise adoption of platforms like Palma.ai.
  • The FIDO Alliance and x402 Identity Working Group participation by Baselayer alongside Cloudflare, Google, Visa, and Mastercard suggests that standards formation is happening now, and whoever shapes those standards will have lasting structural influence.
  • Developer tooling will bifurcate: agent developers will need to build identity attestation into their systems from the start, not retrofit it after deployment.

minority report

  • The entire agentic identity category may be solving a problem that hyperscalers solve by default. If Google, Microsoft, and Amazon embed agent identity natively into their cloud stacks, standalone identity infrastructure vendors could find themselves squeezed out before they achieve scale.
  • Baselayer's fraud prevention figures are self-reported and unaudited; the $1 billion claim may reflect gross attempted fraud flagged rather than actual losses prevented, which would significantly change its competitive narrative if scrutinized under due diligence.

Level 4

What Happens Next

The next 12 to 24 months will determine whether agentic identity becomes a standalone category or gets absorbed into broader platform plays. The regulatory clock is beginning to tick, standards bodies are active, and capital is starting to concentrate. Several second-order dynamics will shape the outcome.

Sources

VentureBurn

VentureBurn

McKinsey & Company

FIDO Alliance

second order

  • As agent identity standards solidify through bodies like FIDO and x402, early participants including Baselayer, Cloudflare, Google, and Visa gain disproportionate influence over what compliance looks like, effectively writing the rules their own products satisfy.
  • The separation of identity from capability from authorization in agentic systems will create an entirely new consulting and integration services market, likely captured first by the large systems integrators already embedded in financial institutions.
  • Palma.ai's audit trail feature, which logs every agent action into a tamper-evident record, will become a regulatory baseline expectation rather than a premium differentiator as financial regulators issue guidance on autonomous system accountability.
  • Widespread agent identity infrastructure could paradoxically accelerate agentic commerce adoption by removing the trust barrier, pulling forward McKinsey's $3 to $5 trillion estimate by several years.

prediction

  • Within 18 months, at least one major data breach or fraud event will be attributed to an unverified AI agent operating inside a financial institution, triggering emergency regulatory guidance and accelerating procurement cycles for companies like Baselayer.
  • Baselayer will be acquisition-targeted by a major payments infrastructure company such as FIS, Fiserv, or Mastercard within three years, given its existing distribution across 2,300 institutions and the strategic value of its identity network.
  • The Model Context Protocol will become a mandated disclosure item in enterprise AI vendor contracts, elevating Palma.ai's governance layer from optional to contractually required for large enterprise deployments.

minority report

  • The agentic commerce boom may stall at the enterprise procurement gate. Large financial institutions historically take five to seven years to integrate new identity infrastructure vendors, meaning the addressable market remains largely theoretical for the next investment cycle regardless of market size projections.
  • Regulatory backlash against fully autonomous financial agents could cap the market ceiling entirely. If the EU or US Treasury classifies autonomous transaction execution as requiring human-in-the-loop approval above certain thresholds, the core use case for both companies contracts sharply.

Level 5

What This Means

The simultaneous emergence of Baselayer and Palma.ai is not a coincidence. It is evidence of a category crystallizing in real time. The agentic identity problem is structural, not cyclical, and the window to establish category leadership is narrow. For operators across finance, enterprise technology, and security, this is a strategic inflection point that demands active positioning rather than a wait-and-see posture.

What This Means

Agent identity is now a board-level risk item.

Financial Institutions

With 70% of Stripe's API traffic already originating from AI agents and Baselayer's network spanning 2,300 institutions, the agentic transaction load is not a future scenario. Risk and compliance officers must begin mapping which agents have access to which systems today, before regulators define the disclosure requirements tomorrow. Waiting for regulatory clarity is itself a risk posture.

The Model Context Protocol is your next perimeter.

Enterprise CISOs and IT Leaders

MCP is already the dominant bridge between AI models and live enterprise data. Every AI tool that accesses internal systems through MCP is currently managing its own permissions in isolation. That is not a governance architecture. Palma.ai's centralized policy layer addresses this, but CISOs do not need to commit to a specific vendor today. They do need to audit their MCP exposure immediately and define a permissions governance policy before the next procurement cycle embeds autonomous agents deeper into core workflows.

Agentic infrastructure is the picks-and-shovels play of the AI cycle.

Venture Capital and Investors

Application-layer AI is crowded and margin-thin. Infrastructure for the agentic economy, specifically identity, permissions governance, audit, and compliance tooling, carries network effects, data moats, and switching costs that application software rarely achieves. Baselayer's institutional network and Palma.ai's MCP integration layer both exhibit these properties. The category will likely consolidate around two to three players within four years, making the current pre-consolidation window the highest-return entry point.

Agent commerce protocols need an identity layer to function at scale.

Payments and Card Networks

Visa, Mastercard, and American Express have launched agent commerce protocols, but protocols without verified agent identities are authorization frameworks built on an unverified foundation. Baselayer's participation in the x402 Identity Working Group alongside these networks positions it as the identity substrate those protocols will rely on. Networks that co-develop standards with Baselayer gain a structural advantage in the agentic commerce era.

Detected Trends

Agentic Identity Infrastructure

emerging-category

A distinct infrastructure category is forming around verifying, authorizing, and auditing AI agents in financial and enterprise contexts, separate from both traditional identity management and AI application development.

Standards-Driven Market Formation

structural-shift

Industry standards bodies including FIDO and x402 are actively shaping the agentic identity landscape, meaning early participants in standards formation gain lasting structural influence over compliance requirements.

MCP as Enterprise Security Surface

risk-vector

The Model Context Protocol is rapidly becoming the primary access layer between AI models and enterprise data, creating a new and largely ungoverned security perimeter inside organizations.

Sources

VentureBurn

VentureBurn

McKinsey & Company

Stripe