The RPIB consultation calls for input on one of my favourite topics, digital identity. The consultation says that digital identity frameworks, including the use Legal Entity Identifiers (LEIs) or other verifiable credentials, could provide opportunities to “enhance users’ payment experiences“. It goes on to note that this may require a complementary trust service layer that makes identities and associated attributes usable, portable and verifiable in real time. Well, you can guess my view on this. The Bank of England and DeliveryCo should treat digital identity as part of a fundamental trust infrastructure for people, organisations and AI agents systems working across all forms of money.
It will be increasingly important that these payment system users can present high‑assurance, reusable digital identities (perhaps held in digital wallets that could interoperate with the European Digital Identity Wallet) to support customer due diligence (CDD) activities. The new core infrastructure should assume that participants will rely on such credential‑based identity schemes, allowing users to prove attributes (eg, age, and residency) selectively rather than having to re‑onboard for each provider, as I just had to do when I changed accountants.
These proofs should be linked not only to traditional accounts but also to digital wallets, providing a consistent trust and liability framework across conventional forms of money, stablecoins and digital assets. This approach could build on common utilities so identity, fraud analytics and sanctions screening become shared services rather than duplicated, siloed functions.
When it comes to the identities of AI agents, as delegated and agent‑initiated payments become more common (whether as personal “copilots” or enterprise agents orchestrating across supply chains) agents will require their own distinct digital identities, separate from the human account holder, tied to cryptographic credentials that can be authenticated and revoked independently. Trust in agents depends on being able to verify not only which human they represent, but also which agent runtime they are, which organisation owns it and what capabilities and constraints have been delegated. The core conceptual architecture should therefore support a model in which humans, organisations and agents are all digital identities, each able to hold and present verifiable credentials binding them to specific roles, permissions and regulatory obligations with a clear separation between authentication (proving who or what is initiating a payment or instruction) and authorisation (what that entity is allowed to do, under what constraints).
In the Bank of England’s “Bank Underground” blog on the subject of agentic commerce, Prem Munday was kind enough to refer to some of my work in this field, observing that the economy needs methods to resolve how humans and their agents interact, “moving from Know-Your-Customer (KYC) to Know-Your-Agent (KYA) for payments, as highlighted by Dave Birch”. Indeed it does. And it needs them soon.