Ten minutes. That is about what it takes now to stand up an agent with its own compute, its own schedule and access to your inbox.
No procurement. No engineer. You describe the job in a text box, hand over a few keys, and it works while you sleep.
That is good. I do not want any of it undone. The cost of putting an autonomous system to work fell through the floor this year, and a lot of small operators picked up capability they were never getting any other way.
Here is what nobody built alongside it.
The build side got excellent. The check side did not move.
The number of autonomous systems doing real work has gone vertical. The number that can prove who they are is roughly where it was.
Creating an agent is a consumer activity now. Verifying one is still a research project. You can stand up a thing that emails your customers before lunch, and there is no equivalent ten minute path for the person receiving that email to find out what just contacted them.
That asymmetry is not a rough edge. It is the whole liability surface.
Three questions with no answer
An agent lands in someone's inbox. Or it calls an API. Or it files something with a deadline attached.
The person on the other end has three questions, and none of them are exotic.
What is this thing? Which model, which version, deployed by whom, permitted to do what. Not the marketing name. The actual configuration that produced the message sitting in front of them.
Who is accountable for it? A human being, or an entity with a legal address. Somebody who answers when it goes wrong. Not a support alias that loops back into the same system.
What has it done before? Has this agent worked for six months without incident, or was it created this morning? Is there a record, and can that record be checked by someone who has no reason to trust me?
Today the honest answer to all three is: no idea. You get a name someone typed into a text box, and a tone of voice.
Every other category solved this a century ago
We know how this problem ends, because it has ended before, in every field where a stranger had to be trusted at speed.
A car has a VIN and a service history. You do not take the seller's word on the mileage. You pull the record.
A tradesman has a licence with a number on it. You do not judge the electrician by how confident he sounds. You check the licence exists and is current.
A company has a registration number. That single fact is why you will send money to a business you have never met.
None of that is bureaucracy for its own sake. Papers are a compression device. They let a stranger extend trust in seconds instead of weeks, and they put a name on the hook when that trust turns out to be misplaced.
Agents have none of it. The most consequential new class of economic actor in a long time is walking around with no identity, no accountable party and no history.
The gap is where the liability sits
This is not theoretical, and it is not five years out.
By 1 July 2026 there were 109 AI laws across 29 states. Nothing federal has preempted them. EO 14365, signed in December 2025, set up a DOJ AI Litigation Task Force and asked Congress for preemption legislation. Asking is not having. The Obernolte-Trahan bill people keep citing at me was released as a discussion draft on 4 June 2026 and has never been formally introduced. Planning around a preemption that has not happened is not a plan.
Meanwhile the state duties are live, and they are specific.
Texas HB 149 came into force on 1 January 2026. A provider using an AI system in relation to a health care service or treatment has to disclose that use to the person receiving it, or their personal representative, no later than the date the service is first provided, in clear plain language, free of dark patterns. In an emergency the disclosure follows as soon as reasonably possible. It does not disappear.
California AB 489 took effect the same day, and it is the one that reaches an ordinary operator. It bars AI systems, and the people developing and deploying them, from using terms that imply a health care licence. Your agent's persona is a regulated artifact now.
Illinois drew a bright line instead of a disclosure duty. HB 1806 has been in force since 1 August 2025. A licensed professional cannot let an AI system make independent therapeutic decisions, or generate a treatment plan without licensed review. Civil penalties run up to $10,000 per violation.
Utah is worth reading properly, because most of the commentary has it wrong. The blanket proactive disclosure rule everyone quotes was repealed. What survives attaches only where two things meet: a licensed individual in a Commerce-regulated occupation, and a high risk AI interaction. The duty lands on the licensed human, not the facility. Notice where the law puts the name. On a person.
Colorado is a moving target. Enforcement of SB 24-205 was suspended by court order on 27 April 2026. A narrower replacement, SB 26-189, was signed on 14 May 2026 with duties starting 1 January 2027, and the Attorney General's rulemaking is still open. That churn is not relief. Records you did not keep in 2026 are records you cannot produce in 2027.
Then there is the part that does not wait for any legislature.
The Senate Permanent Subcommittee on Investigations reported in October 2024 that UnitedHealthcare's skilled nursing facility denial rate rose ninefold between 2019 and 2022, from 1.4% to 12.6%, across the period automated review was expanded. In the Lokken litigation against UnitedHealth Group, a federal magistrate granted broad discovery on 9 March 2026, including material going to whether the tool was designed to override the clinical judgement of treating physicians. The insurer disputes that characterisation and maintains the tool does not make coverage determinations.
Set the merits aside. The narrow point is the one that matters to everybody else: how an automated decision was reached is discoverable, and courts will compel it.
You are not going to get a Senate subcommittee. You are going to get one email from a solicitor asking what your agent did on a Tuesday in March. And you will be holding logs you wrote yourself, in a format you chose, that you are now asking the other side to accept as accurate.
Somebody is already checking
We run a free public check at apir.ai/check-agent. No account, nothing to sign, no card. As at 5 August 2026 it had been used for 602 third party credential checks, and the number is still climbing.
602 is small. I am not dressing it up as traction. We are pre-revenue. What makes it worth mentioning is who those checks came from. Not our users checking their own agents. Strangers, checking somebody else's, on a link we have never marketed or advertised anywhere.
The demand to check exists before anyone has been sold anything. That usually means the problem is real and nothing has caught up to it yet.
So that is what we build at APIR. Cryptographically signed agent credentials on Ed25519 as W3C Verifiable Credentials, hash-chained records of what the agent actually did, and independent behavioural scoring, so an organisation can evidence what an autonomous system did when a regulator, an insurer or a court asks. Tamper-evident, independently verifiable by someone who does not trust us, verified as of a stated date. We do not promise results. We prove whatever happens.
The part that lands on you
Count the agents you deployed this year. Then count the ones that emailed you, called your API, or filed something on behalf of a company you deal with.
The second number is bigger. It is also growing faster, and you have no say in how carefully any of them were built.
Everyone treats this as a builder's problem, something you sort out before you ship. It is not. You are on the receiving end of other people's agents far more often than you are on the sending end of your own.
The question is not whether your agent can prove who it is. It is whether the next one that turns up asking you for something can.