FIDO Alliance, backed by Google and Mastercard, is building cryptographic identity standards for AI agents making payments and transactions on users' behalf.
The FIDO Alliance announced two new working groups to develop industry standards for authenticating and validating AI agent transactions. Initial contributions come from Google and Mastercard. The initiative targets agent hijacking, rogue instructions, and payment fraud — producing cryptographic tools and privacy-preserving frameworks for verifying that agents are acting on legitimate, authorized instructions. No timeline for finalized standards has been published yet.
Any agent you're building that touches payments, account actions, or third-party APIs will eventually need to comply with whatever cryptographic identity framework FIDO produces. The architecture decisions you make today — how agents authenticate, how instructions are signed, how actions are logged — will either align with or conflict with these emerging standards. FIDO's track record (passkeys, WebAuthn) means this will likely ship and get enforced by major platforms.
Audit your current agent's action authorization flow this week: document how your agent proves it's acting on behalf of a verified user, and identify gaps where a malicious prompt injection could forge or hijack an instruction.
Open Claude.ai and start a new conversation
Tags
Sources