On October 1, 2026, DataDome officially joined Experian’s Agent Trust ecosystem, introducing a critical missing piece to agentic commerce: continuous intent verification. The shift moves beyond the traditional login-time identity check, where an AI agent is verified once and then trusted for the remainder of the session. Instead, the new framework mandates dynamic re-verification of every action to ensure it remains consistent with the agent’s original mandate. This effectively turns the 'per-decision gate' from a theoretical concept into a deployed product category, addressing the inherent fragility of static trust signals in autonomous workflows.
Splitting Trust into Who and What
The partnership delineates trust into two distinct operational questions that every agentic payment must answer. Experian handles the 'WHO' through Human-to-Agent Binding, a process that securely links verified consumers to the specific AI agents acting on their behalf. Kathleen Peters, Experian’s chief innovation officer, describes this as establishing trusted identity and delegated authority. Meanwhile, DataDome addresses the 'WHAT-ARE-YOU-DOING' component by verifying every request for intent in real time. Aurelie Guerrieri, DataDome’s CMO and alliances officer, claims their system flags drift from legitimate patterns instantly, delivering per-request verdicts in under two milliseconds. A valid Know-Your-Agent (KYA) credential no longer grants permanent immunity; the passport doesn’t mean the agent is still on mission.
The Black Box of Scoring Mechanics
Despite the high-profile launch, the actual per-decision mechanics remain unpublished, leaving a significant gap in transparency. The proposed model suggests fusing four signals: Identity (KYA credential status), Intent (alignment with recorded mandate), Behavior (consistency with session history), and Fraud/Risk (anomalies in counterparty or amount). Decisions would then be gated based on a fused confidence score: auto-execute above 0.80, hold for human confirmation between 0.50 and 0.79, and block-and-escalate below 0.50. However, without public documentation of the scoring loop, developers are left guessing how these bands are calibrated in production environments.
Live Testing Reveals Heuristic Limitations
Independent testing using a local heuristic harness revealed that simple models fail to discriminate between benign actions and risky drifts. In a scenario where an agent started in-mandate but attempted to bulk-export customer PII mid-session, the local heuristic returned a confidence score of 0.35 for both the initial catalog read and the subsequent data export. This 'fail closed' behavior highlights the necessity of sophisticated, real-time signal fusion rather than relying on blunt local heuristics. The data confirms that production-grade continuous verification requires complex, sub-millisecond analysis to distinguish legitimate workflow evolution from malicious drift.
The Week the Trust Layer Filled In
This launch is part of a rapid convergence in agent trust infrastructure over just four days. Mastercard introduced a probability score for agent-initiated transactions on September 30, while T54 released a KYA wallet with spending limits on October 3. DataDome and Experian’s contribution on October 1 adds the 'still-on-mission' verification layer. Together, these developments cover the who, the how-likely-agent, and the continuous intent checks. However, the absence of published, standardized scoring mechanics remains the primary bottleneck for widespread developer adoption.
Key Takeaways
- Continuous intent verification shifts trust from session-based to action-based, requiring sub-millisecond evaluation of every agent decision.
- Experian and DataDome split responsibilities between identity binding (WHO) and behavioral intent verification (WHAT).
- Current implementations lack transparency, with no public documentation of the confidence scoring bands or signal fusion weights.
- Local heuristics fail to distinguish between benign actions and risky drifts, proving the need for advanced, real-time signal fusion.
- Intent verification prevents drift but does not validate the wisdom of the original mandate, leaving gaps for social engineering attacks.
The Bottom Line
The trust layer for AI agents is finally getting real infrastructure, but the lack of published scoring mechanics keeps this a black box for developers. We need open standards for the confidence bands, not just vendor promises of sub-millisecond latency.