The AI Agent Registry Is the Wrong Trust Layer | Elacity
Visa and Mastercard are building the registry that decides which AI agents may act. A registry entry is standing power someone else can revoke. There is a better shape for permission.
The AI Agent Registry Decides Who Gets to Act. Approval Is Not Permission.
Soon a software agent will hold your logins, spend from your account, and carry a standing permission to act on your behalf. You have not been asked the question that decides everything: who gets to say that agent is allowed, and who can switch it off?
In the summer of 2026 the answer started to harden, and almost no one noticed. The layer that decides which agents may act is being built as an AI agent registry, owned and run by the same institutions that already sit between you and your money.
A registry is a real answer to a real problem
On June 10, 2026, at its Payments Forum in San Francisco, Visa unveiled an Agentic Directory, a registry of agents and merchants it has verified as legitimate participants in agentic commerce. Alongside it came Agent Score, which rates whether an agent can navigate a merchant's site, and a partnership that puts Visa payments inside OpenAI's agents.
The same day, Mastercard launched Agent Pay for Machines, a rail it says can settle sub-cent, machine-to-machine payments across cards, bank accounts, and stablecoins, with more than thirty launch partners.
Regulators are pushing the same direction. Since August 2, 2026, the EU AI Act's transparency rules have been in force, requiring systems that talk to people to disclose that they are AI, under penalties that can reach 15 million euros or 3 percent of global turnover. An agent that must be identifiable needs an identity, and an identity begs a registry to hold it.
The problem this solves is real. A merchant genuinely needs to know which of the thousand agents knocking on its checkout are safe to serve. Visa has spent sixty years solving that exact coordination problem for strangers. Calling the registry a land grab would miss why it works.
An AI agent registry is standing power
Look closely at what a verified-agent registry actually is. It is a list of agents that carry standing approval to act, an approval that exists whether or not the agent is doing anything at this second.
That standing approval is ambient authority: power shaped by who you are rather than by what you are doing right now. It is the oldest bug in computing, and it is why one poisoned instruction can turn a helpful agent into an attacker wielding all of its permissions at once.
Put that bug under a single registry and you concentrate it. Whoever runs the list decides who is on it, scores them, can throttle them, can price a place on it, and can pull an agent mid-transaction. Your agent's right to act becomes a line item in someone else's database, revocable by them, not by you.
The alternative is permission that expires the instant it is used
There is a different shape for this, and it is already built. Instead of granting an agent standing approval, grant it nothing by default.
In Elacity's model every action an agent takes requires a narrow, revocable, expiring capability that you issue and that is checked at the moment of use, then gone. This is zero standing privilege carried down to the key itself: the agent can use a key to sign or pay while the secret exists in the clear only for a split second inside a sealed sandbox, so there is nothing for the agent to keep and nothing for an attacker to lift.
Revoke the grant and the action stops mid-flight, fail-closed. Humans and AI agents pass through the same gate, so there is no separate class of blessed machine to spoof your way into. Your own device is the source of truth about what is permitted, not a directory you do not control. This is the trust and safety layer the agent economy actually needs: not a gatekeeper, but a gate you hold.
Visa let strangers transact without trusting each other. Elacity lets humans and AI agents compute together without surrendering their keys.
Be precise about what ships today. The hard primitive, a key an agent uses but never sees and a capability it holds only for an instant, exists now. The full agent product around it, agent wallets with an autonomous approve-and-kill loop, is being built. The aim is trust-minimized, not magic: shrink how much you must trust anyone, including us, rather than pretend trust disappears.
A directory can list. It should not grant.
None of this makes discovery worthless. You may still want a directory that helps a merchant find reputable agents, the way a phone book helps you find a plumber.
The line that matters is whether the list merely describes or actually grants. A directory that says here are agents people have found reliable is a convenience. A registry that says only agents we approve may act is a chokepoint, and building the whole agent economy on one is a decision about power, not a technical footnote.
The agent era will run on permission. The only open question is whether that permission lives in a registry someone can revoke over your head, or in a capability that answers to you and expires on its own. Settle it for the second, before the first sets.
Follow Elacity on X for how the ownership layer for AI agents is being built.