For an autonomous agent to truly "go to work" on the open internet and inside enterprise systems—not just be let through by a website, but be authorized to access corporate systems, spend money autonomously, be trusted, and have someone cover the damages when things go wrong—in 2026, these six gates are being invented simultaneously. Yet to date, none of them has produced a single, universally recognized credential akin to a "driver's license."
In 2026, "agent onboarding" has gone from a metaphor to an entire rapidly-forming infrastructure—cryptographic identity, network access license, enterprise badge, payment qualification, reputation background check, and liability insurance are all being built simultaneously. Yet every gate remains a war of competing factions, with no single universally recognized credential like a "driver's license" emerging.
Counter-consensusAmong the six gates, the fastest progress isn't in the most visible payment protocol war, but in the most unassuming enterprise internal badge (IAM)—because it reuses budgets and vendor relationships enterprises have already paid for years. The real bottleneck holding back the agent economy is the last gate that almost no one is discussing: without claims data, insurers won't truly underwrite; without underwriting, serious commercial scenarios won't let agents spend money autonomously.
The most foundational of the six gates answers the simplest question: who is this program knocking at the door? In May 2025, Cloudflare launched Web Bot Auth, replacing easily spoofed IP ranges and User-Agent strings with HTTP message signatures; in August of the same year they added the "Signed Agents" category, specifically covering traffic that doesn't represent a single company but rather acts on behalf of end users. Browserbase described this mechanism as a digital passport for AI agents—issued before departure, presented upon arrival at a website, and the site verifies the signature before granting entry.
A year later, this identity layer was further materialized. On August 4, 2026, Cloudflare announced Cloudflare Wallets and cloudflare.pay, giving AI agents a persistent identity plus a spending authority with limits set by a human owner. CEO Matthew Prince put it directly: "When an agent shows up at your door, you need to know who sent it... You need a chain that traces back to the person or organization behind it, so that trust, accountability, and real commercial relationships can follow." This statement captures the significance of the "ID card" gate clearly: it's not the endpoint, but the prerequisite for the remaining five gates—especially the final one about "who is responsible."
Worth noting as context: the EU's eIDAS 2.0 requires member states to issue digital identity wallets by the end of 2026. Although this regulation originally targets natural persons, it's being read by the industry as a regulatory path that could extend to agent identity—this is a parallel thread that Forbes specifically highlighted when commenting on Cloudflare Wallets: private infrastructure is sprinting ahead while public regulation trails behind.
The identity gate also has a fully decentralized parallel track. On January 29, 2026, the core registry of the ERC-8004 ("Trustless Agents") standard—jointly proposed by engineers from MetaMask, Coinbase, Google, and the Ethereum Foundation—was deployed to the Ethereum mainnet. It uses an NFT as the agent's "on-chain passport," pointing to an identity card listing its MCP/A2A service endpoints, plus two companion registries for reputation and task verification. Within a month of launch, 45,000 agents had registered; by the end of August, cumulative registrations across 24 chains exceeded 526,000. But this route remains highly confined to the crypto-native ecosystem, with no signs of mainstream enterprise identity products like Entra Agent ID or Okta bridging to it—the centralized Cloudflare identity system and the decentralized ERC-8004 identity system are, in some sense, two mutually disconnected answers to the same problem.
With identity established, you still need a credential that gets you through the door. This is exactly what Cloudflare's BotBase aims to solve—over the past two years, the volume of bot review submissions has grown approximately 7x, and the honor system of "IP whitelisting + self-attested identity" has completely broken down. On July 1, 2026, Cloudflare split "AI" into three configurable categories: Search / Agent / Training (plus 8细分 behaviors including Transact, data collection, and security testing), and redefined what "Verified" means: previously, verification was essentially a lifetime gold badge with default全网 access; now, verification only means a bot is "permissible" within its declared category, and the site owner decides whether to actually grant access on a per-item basis. Starting September 15, newly onboarded domains will default to blocking Training and Agent traffic on the ad page, allowing only Search.
Content usage permissions were also sliced into three work scopes—immediate (use and destroy), reference (default, index + cite), full (summarize and restate); BotBase for Operators, launched August 28, transformed the previously "submit a black box" application process into an automated review pipeline—declaring "what your bot does / how it uses content / who actually operates it," with the system automatically verifying repetitiveness, User-Agent specificity, and verification method authenticity.
You might trust Stripe, but that doesn't mean you trust every stranger developer who wires Stripe into their weekend project.
Jin-Hee Lee & Bryan Becker, Cloudflare — July 1, 2026
This "transitive trust" design answers a tougher question above the pass: when the operator of a bot isn't its developer, along which chain should responsibility be traced. This is foreshadowing for Gate 06. Over 20% of global website domains run behind Cloudflare, giving its pass particular weight—but also meaning this gate is currently, in实质, ruled unilaterally by a single company. (This publication previously used the BotBase real案例 to walk through all six gates in EP.101.)
The more urgent battlefield is actually inside the enterprise. Giving an agent a human employee's login credentials immediately breaks the audit trail (you can't tell whether a human or the agent performed the action), violates the principle of least privilege (the agent inherits that person's broad permissions), and cannot be individually revoked. And the explosion of machine identities is far outpacing expectations—security firm Entro Security's data shows the ratio of machine identities (service accounts/bots/agents) to human identities in cloud-native environments has reached 144:1, growing 56% year-over-year; CyberArk's independent survey puts it at 82:1, and the Cloud Security Alliance's industry median is 45:1—different methodologies, same direction: non-human identities are exponentially失控.
2026 is the year nearly every mainstream identity vendor simultaneously filled in their "Agent Badge" product: Microsoft Entra Agent ID began auto-generating independent identities for agents created in Copilot Studio in March, becoming mandatory in July with every agent bound to a human "sponsor"; Okta's Cross App Access saw Agent SSO officially launch on August 24, and was incorporated into MCP's own authorization specification—one of the rare cross-vendor standardization achievements; AWS Bedrock AgentCore Identity, SailPoint, and CyberArk each approach the same problem from identity directory, governance graph, and zero-standing-privilege angles respectively. Gartner lists "Identity and Access Management for AI Agents" as a top security trend for 2026, projecting that 40% of enterprise applications will embed agents with task-level permissions that year.
The converging technical foundation at the底层 is SPIFFE/SPIRE—originally designed for short-lived identity credentials for cloud-native workloads, now merging with the IETF's WIMSE working group, specifically extending a "dual-identity credential" draft that binds a human owner for agent scenarios. But practitioners acknowledge that SPIFFE is currently just a底层 infrastructure layer; an identity credential for an MCP tool call and an A2A Agent Card haven't been bridged—this gate's progress is the fastest of the six, but still amounts to "each vendor building its own," without true unification.
These enterprise-grade badge products ultimately need to connect to the protocols by which agents actually converse. MCP's official OAuth 2.1 authorization specification defines the MCP server as a resource server with clients following the standard token issuance flow; the July 28, 2026 revision was called "the biggest change ever" by maintainers,弃用 dynamic client registration in favor of a more secure client identity metadata document. But specification is one thing, adoption is another—security vendor Descope's field data shows only about 8.5% of MCP servers have actually implemented OAuth 2.1. Meanwhile, Google-led A2A protocol takes a different approach: rather than authenticating "who this connection is," it publishes a machine-readable "Agent Card" declaring its capabilities, skills, and required authentication methods for other agents to discover and invoke—identity as declaration, not identity as cryptographic proof. The industry generally views the two as complementary: MCP handles agent-to-tool, A2A handles agent-to-agent; but "who should统一定义 identity, consent, and authorization" remains an unresolved governance question.
Permission失控 isn't theoretical. The EchoLeak vulnerability disclosed in June 2025 (CVE-2025-32711) required only a carefully crafted email to make Microsoft 365 Copilot exfiltrate data using its existing permissions to Word/PowerPoint/Outlook with zero clicks and no user action; three months later, the ForcedLeak vulnerability allowed Salesforce Agentforce to be "injected" with instructions via a single web form field, exfiltrating CRM customer information, sales pipeline, and internal notes through an expired and re-purchased whitelist domain, with a CVSS score of 9.4. Neither incident involved a sandbox breach—rather, the agent's own legitimate permissions were abused through a "hijacked shell"—precisely the scenario this gate is meant to block.
With identity and a badge, an agent can finally approach the fourth gate: can it swipe its own card? This publication previously outlined the early contours of virtual card authorization and payment-giant MCP cartels in EP.43, "On Letting Agents Pay for You"; in September 2025, Stripe and OpenAI jointly launched Agentic Commerce Protocol (ACP), using "shared payment tokens" to let agents complete checkout without holding real card numbers, first integrated into ChatGPT's Instant Checkout, with Shopify, Salesforce, and PayPal following. The same month, Google released Agent Payments Protocol (AP2), launching with 60+ institutions (Mastercard, Amex, PayPal, Coinbase, etc.), with a core design of three signable "mandates" (Intent / Cart / Payment Mandate) as W3C verifiable credentials, separately recording "what the user authorized" and "what the agent actually did." Six months later, Google's UCP protocol and x402 v2 landed simultaneously, with Gemini and Qwen Shopping demoing side by side, completing "the last puzzle piece for autonomous agent payments" (EP.69).
The third route comes from the crypto world: Coinbase launched the x402 protocol in May 2025, repurposing the HTTP 402 "Payment Required" status code to let agents complete秒级, sub-penny micropayments using stablecoins; Cloudflare joined and the two announced the x402 Foundation, now governed by the Linux Foundation, with 119M transactions on Base and 35M on Solana, and an annualized transaction volume of ~$600M. Cloudflare integrated this protocol into its July-released Monetization Gateway (currently in queue for testing), letting any site owner charge agents and API callers per request. Meanwhile, Visa and Mastercard aren't sitting out—Mastercard's "Agentic Token" binds a card to a specific agent, specific merchant scope, and specific authorization policy; as long as the token and policy are followed, fraud liability falls on the issuer.
This is the only one of the six gates that has openly become a "protocol war"—ACP focuses on in-chat instant checkout, AP2 on auditable cross-institution delegation, x402 on stablecoin micropayments, and card networks on keeping risk within their familiar fraud models. Analysis generally views the four as non-mutually-exclusive; 2026 production systems often stitch together two or three: using AP2's mandates for authorization audit trails, ACP for the checkout action, and x402 to settle fractional API/data call fees. No one has won this war, but everyone is stockpiling transaction volume in their own轨道.
The biggest gap in this technical architecture isn't the protocols themselves, but the seam between "autonomous authorization" and "actual human intent." Security research firm Guardio conducted a "Scamlexity" test: they set up a fake Walmart site and asked Perplexity's Comet browser to buy an Apple Watch—it identified the fake page, auto-filled the saved card number and address, and completed checkout without requesting二次 confirmation. San Francisco entrepreneur Sebastian Heyneman's experience was more extreme—he had his agent secure Davos attendance while he slept; the agent wrote letters in his name and negotiated a ~€27,000 sponsorship commitment; he had to haggle after waking up to reduce it to ~€4,000. Such cases show that for the pay card gate, protocols alone aren't enough—the gap between "authorization scope" and "what the human actually consented to" is currently left to the agent's自由发挥.
The first four gates answer "who are you, can you enter, can you spend money"; the fifth gate answers a harder-to-quantify question: is this agent actually reliable? METR's "task duration" benchmark is currently the closest thing to an industry-accepted capability yardstick—measuring how long a task (in human-expert hours) an agent can independently complete with 50% reliability. This duration roughly doubles every 7 months, with GPT-5-class models reaching about 2 hours 17 minutes in May 2026; but it's a research基准, informally cited in model cards by various labs, not a genuine "exam certificate."
A detail easily misled by its name: Cloudflare's Agent Readiness Score, launched at Agents Week, actually measures "how agent-friendly a website is" (16 checks including robots.txt, MCP Server Card, OAuth discovery), not "how trustworthy this agent is"—the exact opposite direction. What's truly aimed at "agent reputation" itself is a crop of crypto-adjacent startups emerging in 2026—AFG, Qova, AgentPass, Mnemom, AXIS, each designing scoring systems ranging from 300–850 to AAA–CCC grades, trying to become "the credit bureau for agents," but currently highly fragmented with no FICO-like dominant player. Relatively mature is Sumsub's "Know Your Agent" (KYA) verification product launched January 29, 2026—identity verification, behavioral reputation tracking, activity monitoring, and rule enforcement across four layers, essentially adding a KYC-style verification to the "human authorizes agent" chain.
The only scenario where "background check determines access" has actually landed is in the insurance industry: AIUC-1 security audits are being used by insurers as a prerequisite for underwriting AI liability insurance—pass the audit, get higher coverage limits. This may be the clearest case in this article's six gates where "certification genuinely gates the next step."
The final gate is the least mature of all, yet determines how large a commercial scenario the first five can support: when an agent causes harm, who pays? Insurance products have started appearing—Corgi launched AI liability insurance in May 2026, Munich Re's HSB introduced a policy specifically covering AI-related damages for small businesses in March (currently US-only), and Armilla began underwriting as early as April 2025, claiming it can price even without historical claims data. But this market's maturity is often compared to "cybersecurity insurance in the early 2000s"—demand is real, but claims data is razor-thin; in a 2026 industry survey, most large European insurers were still观望, directly citing "no claims data."
Legal action has actually outpaced insurance. The EU AI Act's transparency provisions (Article 50) became enforceable on August 2, 2026, with fines up to 3% of global revenue, and clarified liability for multi-agent systems—the orchestrator bears full responsibility for all sub-agents' actions; California's AB 316 (effective 2026) directly prohibits defendants from using "AI acted autonomously" as a defense in damage lawsuits; Colorado replaced its prior law with SB 26-189, allocating liability proportionally by fault between developers and deployers. These laws share a common direction: AI agents are currently not, and have not been seriously proposed as, independent legal subjects—academia has discussed "electronic personhood," but the EU has withdrawn related early proposals, and the mainstream consensus still treats agents as "tools," with liability traced up the human chain of developer/deployer/user. This正好 echoes Gate 01's Cloudflare Wallets design logic of "must bind a human owner."
Even the payment protocols themselves haven't resolved this: ACP defaults to the merchant bearing the chargeback risk for agent mis-purchases (American Express is currently the only issuer explicitly promising to cover cardholder losses from agent mis-purchases); AP2's signed mandates provide an auditable evidence trail but don't directly adjudicate "who should actually pay." Reaching the end of the six gates, you find that the most advanced technical layers (identity, payment) have outpaced the most basic social contract layer (who is responsible, who pays)—this is the largest inversion in the entire agent onboarding infrastructure today.
Liability determination is no longer just theoretical. In November 2025, Amazon sued Perplexity in the Northern District of California, alleging that its Comet browser's shopping agent impersonated a Chrome browser identity and placed orders on behalf of customers without explicit authorization, violating the Computer Fraud and Abuse Act; the court initially issued a temporary injunction in March 2026, the Ninth Circuit Court of Appeals vacated this injunction on August 4, 2026—writing judge Milan D. Smith Jr.'s reasoning was that the user "accessed" Amazon's servers with Comet's assistance, rather than Perplexity itself accessing; the CFAA is fundamentally an anti-hacking statute and cannot be used to police how users choose their browsing tools; however, Amazon's trademark infringement and breach of contract claims were upheld, and the case was remanded to the district court. Update (2026-09): On September 11, Perplexity further moved the district court to dismiss the entire case based on this appellate ruling—the motion states "this case asks whether a dominant platform can weaponize a criminal anti-hacking statute to control how users use the internet—the Ninth Circuit has given a clear answer: no"; Amazon may petition for rehearing or appeal to the Supreme Court, and as of publication this case remains unresolved. This pending case恰好 welds Gate 01 "identity" and Gate 06 "liability" together: when an agent impersonates a human browser, who bears responsibility when things go wrong?
Shifting the lens to China reveals the most uneven progress across the six gates: on the pay card gate, China isn't just not lagging—it's leading the global narrative; on the liability gate, China is the first jurisdiction globally to produce systematic专项 policy; but on the badge and background check gates, apart from Alibaba Cloud, most players are still at the stage of repackaging generic security products.
Pay Card—June 2026 was dubbed by the industry as the 48 hours when "AI payments moved from technical validation to commercial闭环": Alipay/Ant Group, jointly with Qwen, Taobao, and Alibaba Cloud Bailian, released China's first agent commercial trust protocol ACT (launched January 2026, upgraded to 2.0 in April, co-built by 20+ vendors in the IIFAA联盟), then on May 26 released the "AI Pay / AI Collect / Token Pay / AI Wallet" full payment stack, cumulatively completing ~300M AI payments covering 95% of mainstream agent frameworks, and on August 17 further联合 Huawei, BYD, and 20+ partners to release the cross-device interconnect protocol AHA; WeChat Pay同期 launched "AI-Exclusive Card" (isolated account, locked limits, each transaction still requires phone二次 confirmation); JD.com on June 11 released China's first autonomous payment protocol for agents, A2P2, a more aggressive route than Alipay—direct autonomous execution rather than per-transaction confirmation; UnionPay Merchant Services released an AI payment product based on the APOP protocol the same day.
Badge—Progress on this gate is uneven: Alibaba Cloud is the only one of the three major cloud vendors with an independently named product, Agent Identity Service, compatible with OIDC and federatable with Okta/Entra ID, with IDaaS EIAM also offering Agent ID Guard for zero-static-key M2M authentication, directly benchmarking Entra Agent ID and Okta Agent SSO; Tencent Cloud currently only bundles identity, access, and audit into a single "AI Agent Security Gateway" product, with no separately named Agent IAM; Huawei Cloud doesn't even have dedicated product documentation yet—a genuine gap among the three that's worth noting candidly.
Pass—Both cloud vendors have produced products benchmarking Cloudflare BotBase: Tencent Cloud EdgeOne opened "AI Crawler Handling" capabilities to all plans (including free tier) from February 2026, identifying GPTBot, ClaudeBot, Google-Extended etc. via User-Agent, plus a standalone BOT Traffic Management product using AI + rule intelligence to identify 1,000+ public bot types; Alibaba Cloud WAF maintains a 700+ crawler fingerprint库, and has specifically created an "Impersonation Crawler Blocklist" to prevent伪装 as legitimate crawlers like BaiduSpider.
Liability—Among the six gates, China is actually advancing fastest on the last one. On May 8, 2026, the CAC, NDRC, and MIIT jointly issued the "Implementation Opinions on Standardized Application and Innovative Development of Intelligent Agents", the world's only systematic agent-specific policy document to date: proposing a seven-layer security framework, permission boundaries, behavioral guardrails, and AIP protocol, envisioning each agent carrying identity, capability declarations, and compliance certification information, with tiered regulation by risk scenario (finance, healthcare, government, judiciary)—this predates and is more specific than the EU AI Act's "orchestrator bears full responsibility for sub-agents" clause in writing the "liability gate" into national-level policy, though enterprises' actual compliance levers目前 still mainly rely on legacy tools like large model registration and algorithm registration.
The identity gate in China has also seen genuine impersonation risks—a CCTV News report in April 2026 noted that searching for well-known enterprises and institutions on mainstream大模型 platforms returns numerous "impersonation agents" without official认证 badges but bearing the same names; experts urged swift clarification of agent liability determination and impersonation judgment standards. This and Gate 02's Cloudflare "transitive trust" accountability approach are different answers to the same problem under two regulatory philosophies. Laying the six gates side by side, China's portrait is: payments out front, regulation earliest to move, Alibaba Cloud has a benchmarking IAM product, but overall still "running fast in parallel" without a unified identity substrate spanning all six gates—this fragmentation is the same kind as the global situation discussed in Gate 08, just with differently shaped fragments.
Laid side by side, the six gates show uneven maturity—and that unevenness itself is where the opportunity lies:
Fastest converging is Gate 03 (Enterprise Badge)—because it doesn't require inventing a new business model, just migrating budgets and vendor relationships enterprises have already paid for years in identity and access management to a new asset class (agents). This is why Okta's Cross App Access could be written into MCP's official authorization specification within a year—not because the technology is optimal, but because it reuses the most存量 trust. Opportunity for builders: the middleware bridging identity semantics across different IAM vendors (how an MCP tool call credential maps to an A2A Agent identity card) is currently空白.
Most contentious is Gate 04 (Payment)—ACP, AP2, x402, and card network tokens are four parallel tracks laying轨道 simultaneously, betting on who becomes the "Visa/Mastercard/SWIFT" of the agent economy. Opportunity for builders: most merchants and platforms won't bet on a single protocol; a clearing layer / acquiring middleware compatible with at least two or three protocols will accumulate real transaction volume faster than betting on one—same logic as early e-commerce simultaneously integrating multiple payment gateways.
Most narrative-friendly but least mature is Gate 05 (Reputation)—"credit bureau for agents" is a compelling analogy, but the current crop of startups is heavily dependent on crypto infrastructure and mutually non-recognizing, with no genuine industry standards body emerging. The relatively certain opportunity is actually audit-as-a-service (the AIUC-1 model)—because it's already been adopted as an underwriting prerequisite by the insurance industry, a genuinely paying customer, finding a payer earlier than a mere "credit score."
The real bottleneck is Gate 06. The first five gates are fundamentally "technical protocol" problems—signatures, tokens, directories, protocols, scores—all can be stacked into usable versions within a year or two through engineering effort. But "no claims data means no underwriting, no underwriting means no autonomous permissions" is a time problem: claims data can only accumulate through time and real incidents, and cannot be accelerated by funding or engineering investment. This means: whoever earliest and most systematically accumulates claims data for agent-caused damages (whether insurers build it themselves or bind audit and underwriting like AIUC) controls the last and hardest-to-replicate moat among the six gates. Also worth noting: Cloudflare alone already appears in Gate 01 (Web Bot Auth/Wallets), Gate 02 (BotBase), and Gate 04 (Monetization Gateway)—an infrastructure giant is attempting to take over the "agent's employer" role across multiple different gates simultaneously, which itself is a centralization risk worth持续 monitoring.
Further reading: "One Week to Foundation the Agent Economy: A Panoramic解读 of Cloudflare Agents Week 2026", "Agent Infrastructure War: The Battle for Control of Platforms, Standards, and Execution Environments", "Weekly AI Intelligence · EP.101", "Weekly AI Intelligence · EP.69", "Weekly AI Intelligence · EP.43"