Identity in an Agentic Web
Bret SiersTwo merchants. Same product. Same price. An AI shopping agent looks at both.
The first one has a beautiful site. Custom typography. Brand story that reads like a magazine feature. Ten years of design work in every pixel.
The second one has a plain site. Simple layout. But buried in the page is JSON-LD schema markup. It defines the entity type. Links to a public knowledge base. Connects to verified business directories. Presents structured product data with consistent naming across every external reference.
The agent doesn't see the design. It can't. It reads structured data. It checks the entity graph. It verifies external references. It recommends the second merchant.
Here's the thing. This is not a hypothetical. Visa built a cryptographic protocol for exactly this scenario. Their Trusted Agent Protocol requires AI shopping agents to present a secure digital signature before transacting with any merchant. Every request is cryptographically locked to the merchant's specific domain. The agent doesn't evaluate brand. It verifies identity.
The evaluator changed. And most domain owners haven't noticed.
The Agent Doesn't Read Your Brand
For twenty years, we decided whether to trust a website the same way we decided whether to trust a restaurant. How it looked. Professional design. Polished copy. Consistent visual identity. Those are human shortcuts — ways our brains decide quickly if something's trustworthy. We built entire industries around them. Brand guidelines. Design systems. Visual consistency frameworks. All built for the same evaluator: a person scrolling a screen.
AI agents don't scroll. They process structured data.
When ChatGPT or Perplexity evaluates something, it doesn't care about your color palette. It checks: Is there a knowledge graph entry? Does the schema markup resolve? Are there consistent external references confirming this entity exists?
A Princeton study on Generative Engine Optimization put numbers on it. When content includes verifiable citations and statistics, visibility in AI-generated answers jumps by up to 40%. For sites ranked lower in traditional discovery results, the improvement was even bigger — up to 115%. The gain came from being structurally readable. Not from better branding.
Wikipedia — encyclopedic, verifiable, zero brand design — is ChatGPT's most-cited source at 7.8% of all citations. The system rewards clear identity, not polished presentation.
I'm not saying branding doesn't matter. It still matters for humans. But the evaluator that arrives first — the agent — doesn't see it. AI systems couldn't read parked domains. Agents go further. They can't verify an entity that has no structured identity at all.
The first reader is a machine. And the machine reads identity infrastructure.
What Agents Actually Check
So what do agents actually look at? More of it is documented than you'd think.
Here's what it actually comes down to.
Schema markup. JSON-LD structured data that tells machines what an entity is, what it offers, and how it connects to the broader knowledge graph. Content with proper schema markup is 2.5x more likely to show up in AI-generated answers, according to SchemaApp's research. But less than 30% of organizations do it well. Only about 12% of all registered domains have any schema.org structured data at all.
Entity linking. The schema.org sameAs property connects a domain's entity to external authoritative sources — Wikipedia, LinkedIn, public knowledge bases, industry directories. When pages consistently link entities to verified external sources, AI systems can tell entities apart, group related pages together, and attribute information with confidence. SchemaApp's research on entity linking shows that organizations with thorough sameAs link profiles report higher AI citation rates and better knowledge panel representation.
Consistent identity data. For commercial entities, consistency of name, address, and identifying information across platforms is a verification signal. An agent checking three sources and finding three different descriptions doesn't conclude "rich brand voice." It concludes "unresolved entity."
Content patterns. Discovery systems track publishing consistency, authority signals, and content depth over time. They remember absence as much as presence. A domain that existed for six years but published nothing for five of them tells a different story than a domain active throughout.
External references. Content structure accounts for roughly 35% of what determines AI citation, according to a study testing 1,200 content variations across ChatGPT, Perplexity, Claude, and Google AI Overviews. Not connections in the old sense — independent external references that confirm the entity exists. External references are verification signals because you can't manufacture them yourself.
These signals converge into something that needs a name. So here's what I'd call it:
Agentic identity is the machine-readable sum of structured data, entity links, verification signals, and activity patterns that AI agents use to evaluate whether a domain represents a real, transactable entity — distinct from brand identity (what humans perceive) and domain identity (what registrars record).
Your brand identity is what a human feels when they see your logo. Your domain identity is what a registrar records when you pay the renewal fee. Your agentic identity is what a machine can actually verify about you. And increasingly, it's the one that determines whether you're visible at all.
Trust built through verifiable signals. That's the principle. What agents check is the mechanical implementation of it.
Verification Is the New Branding
This isn't theory. The infrastructure is already being built.
Start with the transaction layer.
Visa's Trusted Agent Protocol requires AI shopping agents to present a cryptographic digital signature before transacting with any merchant. Every request is locked to the merchant's specific domain and the exact page the agent is interacting with. Agents must be approved through Visa's Intelligent Commerce program, vetted for trust and reliability standards, each receiving a unique digital signature key. The agent doesn't evaluate the merchant's brand. It verifies the merchant's identity through cryptographic proof.

Mastercard followed with Agent Pay and its Web Bot Auth protocol, built on IETF RFC 9421, which cryptographically verifies agent identity and ensures only verified agents can initiate transactions. Their "intention credentials" define what an agent is authorized to do — spending caps, merchant restrictions, time limits, delegation scopes. None of this is brand evaluation. All of it is entity verification.
The world's two largest payment networks independently built verification systems for AI agents. Not for humans. For agents.
Then there's the standards side. In February 2026, NIST launched the AI Agent Standards Initiative, identifying agent identity and authorization as a core priority. NIST framed the problem directly: AI agents "may operate continuously, trigger downstream actions and access multiple systems in sequence, requiring new architectural considerations for how such agents are authenticated, how permissions are scoped and how activity is logged and audited."
NIST doesn't publish standards for aesthetics. It publishes standards for identity, authentication, and interoperability. When the same institution that defines encryption standards turns its attention to how AI agents get identified and authorized, that tells you something specific: identity is infrastructure, not marketing.
The Cloud Security Alliance published an "Agentic Trust Framework" applying Zero Trust principles to AI agent governance — never trust, always verify.
And the numbers make it real. AI-driven visits to U.S. retail sites grew 4,700% between July 2024 and July 2025, according to Adobe Analytics. During the 2025 holiday season, AI-driven visits surged another 693%. On Black Friday, shoppers arriving from AI services were 38% more likely to convert than those from traditional channels. And 45% of shoppers now report using AI agents in some form during their purchase journey, per IBM and the National Retail Federation.
Agents are already transacting. Already evaluating. Already selecting entities based on verifiable identity. The shift arrived at the infrastructure level while most domain owners were still thinking about fonts.
The Identity Stack
The signals agents check aren't random. They stack. Each layer adds legibility. Each one depends on the layers below it.

Layer 1: Domain. Does it resolve? Is it active? How long has it existed? Domain age and activity history form the foundation. A domain that resolves to a registrar placeholder is, to an agent, basically the same as a domain registered yesterday. A parked domain fails at Layer 1. It resolves, but to nothing an agent can read.
Layer 2: Structured Data. Is there JSON-LD schema markup? Does it define the entity type — Organization, Person, LocalBusiness? Does it use sameAs to link to external authoritative sources? This is the layer where the entity becomes machine-readable. We wrote about this gap in detail in structured content for machines. Less than 30% of organizations do this well. The gap between "has a website" and "has a structured identity" is where most domains fail.
Layer 3: Content. Is there content that demonstrates what this entity does, knows, or provides? Is it updated? Content with more explicit definitions gets cited more by AI systems — the Princeton GEO study showed gains of up to 40% just from adding verifiable structure. This layer isn't about volume. It's about definitional clarity — content that answers "What is this entity?" in terms a machine can parse.
Most domain owners stop here. If they even get here.
Layer 4: Connections. Do external sources reference this entity? Is it mentioned in news, directories, industry sources? Content structure is one of the strongest factors in AI citation — accounting for roughly a third of what determines whether you show up. External references are verification signals because you can't manufacture them yourself. They're evidence that other entities in the world acknowledge you exist.
Layer 5: Entity Profile. Has the entity accumulated enough signal across Layers 1 through 4 that discovery systems have built a persistent profile? Does a knowledge graph entry exist? Can the entity be disambiguated from similar names? This layer isn't something you build directly. It forms over time — the continuity that creates trust. Some practitioners call this internet memory: the persistent record that discovery systems build about a domain whether you participate or not. Absence is recorded. The profile forms regardless.
Think of it as the stack agents read when they're deciding whether an entity is real enough to recommend.
Each layer is necessary but not sufficient alone. A domain with strong content but no schema markup is partially legible. A domain with schema markup but no content is a skeleton with labels. A domain with both but no external references is self-declared and unverified.
The stack is cumulative. It builds over time. You don't configure it once. It forms through consistent presence.
What This Means for Domain Owners
Here's what this actually means for you. Your domain is your agent-readable identity. Not your social accounts. Not your brand guidelines. Not your logo. The domain — and what is structured on it — is what agents verify first.
If agents can't verify you, they can't recommend you. Not because you're doing something wrong. Because you're illegible.

I get it. The pushback is obvious: "Branding and design are what make you trustworthy online." They make you trustworthy to humans. But the first evaluator is no longer human. It's an agent that reads identity infrastructure, not design quality. Branding without verification is a billboard in a language the evaluator doesn't speak.
The gap between structured and unstructured domains is measurable. With less than 12% schema adoption, agent-mediated commerce growing 4,700% annually, and Visa and Mastercard already requiring cryptographic verification — the window for early positioning is narrowing on a quantifiable timeline.
The same evaluation pattern that drives email deliverability — where filtering systems check domain presence, not just authentication — extends into how agents evaluate entities for citation, recommendation, and commerce. The evaluation surface is widening. But the core question stays the same: is there evidence of a real entity here?
And because less than 30% of organizations implement structured data effectively, the domain owners who build identity infrastructure now occupy a position that compounds. Not because they gamed a system. Because they made themselves legible to it. Entity verification is quietly replacing brand reputation as the entry ticket. That's not a trend. Trends reverse. Structural shifts accumulate.
For domain owners, the question is not "will I need to think about this?" The question is: what will agents find when they check?
We think about the gap between owning a domain and having an identity. That gap is where ideas become invisible — not because they're bad, but because they're unreadable to the systems that decide what gets seen. Warming is closing that gap before the full build exists. Not hype. Just presence. What is SiteWarming?
The agent doesn't see your design. It doesn't read your tagline. It reads your identity infrastructure — the structured data, the entity links, the verification signals — and decides whether you're real enough to recommend.
For most of the internet's history, identity was what you said about yourself. Your brand was your identity. Your design was your proof. That worked, because the evaluator was human, and humans read those signals fluently.
Identity was always what mattered. Humans just evaluated it through aesthetics because that's what they could process quickly. Agents evaluate it through structure because that's what they can process at all.
The question doesn't change. The evaluator does. And in the agentic web, your identity is not what you say about yourself. It's what can be verified about you. The difference between those two things is about to matter more than it ever has.
And most people haven't started building the second one.
Share this article
Ready to Transform Your Domain Portfolio?
Start building real value with your domain investments today.