In March 2026 I walked the 190 mile Coast to Coast trail from St. Bees to Robin Hood’s Bay, the first ten days solo and including high-level camps in serious weather conditions. As an aside I would thoroughly recommend this, and multi-day walks in general, but it goes without saying — be prepared! Given that I only committed to doing this in December 2025 I had a lot to plan and organise - kit to buy, a route to plan, accommodation to book (for non-camping nights), a significant and increasing amount of training to do and a website to create for sponsorship. I honestly do not think I would have been ready to start the walk on March 12th if I had not enlisted Claude.ai in every aspect of the preparations I just listed (and as my expedition medic once it was underway).
I mention this because for me as a relatively early adopter, asking Claude for recommendations has already reached the point where 9 times out of 10 I will just hit ‘buy’ on the first suggestion.. “who makes the best merino long-sleeve base layers, give me a link to buy in a ‘M’”. This is not out of laziness but based on gradually increasing trust that any extra research on my part will end at the same result.
And so to financial services where the impact of a wrong decision, the potential for serious harm being done by bad actors and for complexity to induce laziness (a Merino base layer is a more interesting purchase than a life assurance policy some would argue) requires careful supervision and means that our chosen agent should not be given delegated responsibility unless we can be sure that the results are in our best interest and are legitimate. As people’s trust in their own ‘personal’ agents grows we will face a critical question: when your AI agent connects to a financial service on your behalf, how does it know the service is who it claims to be?
A familiar problem, in an unfamiliar place
We have been here before. The early web had no way for a browser to know whether the site behind a padlock icon was really your bank. The answer was not to ask people to be more careful. It was infrastructure — certificates, signed by authorities a browser already trusts, checked automatically before you ever see the page. The trust moved into the plumbing, where it belonged.
The agentic web is arriving without that plumbing. An AI agent discovers a tool — increasingly, a Model Context Protocol server — that says it is a regulated mortgage broker, or a regulated insurer, or a regulated investment service. The agent has no standard, automatic way to check whether that claim is true. It can read the words “FCA regulated” in a description. It cannot verify them.
Call it the scam-connector gap. At the moment, anyone can stand up a connector and label it regulated. In a world where the consumer’s own agent is doing the choosing, that is not a marketing nuisance — it is an open door for impersonation, at exactly the moment when the human who might have noticed something off has handed the task to software.
What “verifiable” actually means here
The fix is not a register an agent has to look something up in, and it is not a logo a scammer can copy. It is a credential the firm carries and presents — one the agent can check by itself, in the moment, with no trusted third party in the loop at the point of use.
The mechanism is well understood, because it is the same one securing the rest of the internet. A regulated firm holds a credential that has been signed by an authority — in UK financial services, the natural signer is the regulator. The signature is mathematically tied to the authority’s key. A consumer’s agent, presented with that credential, can verify the signature on the spot. A genuine firm passes. An impersonator, lacking a valid signature, fails — and fails silently and automatically, before any harm is done, without the consumer ever needing to know the check happened.
This credential:
Is anti-impersonation, not endorsement. A verifiable credential answers one narrow question — is this firm who it says it is? — and nothing else. It says nothing about whether the firm is any good. Conflating the two would be worse than useless; it would launder reputation. The claim is identity, full stop.
Is a standard, not a product. The value only exists if it is open and shared. A proprietary “trust badge” owned by one company recreates the original problem one layer up. This belongs in the same category as the certificate standards that secure the web: useful precisely because everyone can verify against them and no one owns the verifying.
And it needs the authority to mean anything. A signature is only as good as the key behind it. A credential that asserts “regulated by the FCA” is meaningful only if it traces, cryptographically, back to the FCA. Which means this is not something a single firm can simply declare into existence. It is something that has to be built with the regulator, because the regulator is the only party whose signature carries the weight.
What are we doing at Ndever?
The agentic channel is still early enough that the trust layer can be designed deliberately, rather than retrofitted after the first wave of impersonation scams teaches everyone the lesson the expensive way. That window does not stay open for long. The cost of building trust into a channel rises sharply once the channel has scaled and the bad actors have arrived.
We are building toward this at Ndever — a regulated financial service reachable not only by people, but by their agents, with verifiable regulated status built into how it presents itself. We do not think the answer should be proprietary, and we do not think it should be ours alone. The right outcome is a shared way for any consumer’s agent to tell a regulated firm from something wearing its clothes.
There is more to work out — and some of it can only be worked out alongside the people whose signature would sit at the root of it. But the benefit of this being done in a robust and secure manner is that an insurance policy could be purchased via an AI agent with the same confidence as a merino sweater.
