New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Titus Capilnean - AI's Missing Link: Bridging Autonomy and Trust Through Digital Identity

ETHCluj MeetupTue, Oct 7, 2025, 12:00 AM

Speaker

Titus Capilnean

Digital identity represents the critical missing piece in AI's evolution from scripted NPCs to trusted autonomous agents. While AI capabilities continue to grow exponentially, the inability to establish trusted, verifiable identities has limited AI agents' participation in regulated markets and institutional systems. In order to establish trust, AI agents must be linked to credible real humans or institutions. Blockchain-native digital identity wallets and government-backed credentials will become the new standard for both consumers and AI agents, fundamentally transforming authentication and verification approaches. This shift acts as the catalyst that institutional players in regulated sectors have been waiting for. Through real-world examples - from AI participation in DeFi protocols to AI-enabled real estate transactions - we'll demonstrate how this convergence creates a trust framework for autonomous AI operations. By 2025, this fusion of AI and blockchain will establish a new paradigm where crypto becomes the transactional currency for AI agents completing tasks on behalf of users and companies while maintaining regulatory compliance and institutional trust.

Transcript

Good morning. Thank you for showing up even if it it was a late night. Um going to spend the next uh 20-ish minutes talking about uh identity and why that's a missing link and when it comes to deploying AI agents in production. Right now, all we see out there is mostly demos, mostly kind of YouTubers kind of showing you how to vibe code it. And like behind the scenes, there's not really a lot of them live in production like at large scale.

And there's a reason for it. We're going to talk about it today. Trust enables that autonomy that you need to break through uh when it comes to agentic AI. So, first a little bit about me and about Civic. Um I've been 15 years working on startups mostly um seven eight or those in crypto.

Um been building deep learning before LLMs were even a thing uh back in 2016. Uh then I did my own thing uh with an AI startup using uh rag if you know what rag is. U now it's like a pretty common way to retrieve data uh with the help of a agents. We did that when GPT3 came out. Uh just to kind of date that, it's like 2021 2022.

Um and then I came back to Civic to help build O N and O Z, which is like authentication and authorization for uh non-human identities, which is a technical way of saying like giving AI some sort of ID, some sort of label or name to be able to identify it. Um at Civic, we started off in identity uh back 10 years ago. So way back way back when uh there was no identity standards back then. We worked on the decentralized ids as standards, verifiable credentials as standards where um we saw oath rising as a standard. If you've ever implemented authentication, u we were contributing some of those early standards.

Uh and now we've shifted our focus to building tools for agent AI because we believe now AI and crypto are merging in a very very interesting way. And you'll see that at the end of my my presentation of what I think where I think the future is going, where we think the future is going when it comes to adding identity and um authentication to uh Agentic AI with crypto as the payment rails. So that's kind of like a small preview of where this is going. So let's start with a thought experiment. Uh and if the bank that you're working with would overnight just add an AI agent that can be tracked, cannot be uh identified, and that agent has access to all of your information.

Would you be fine with that? Would you be okay with that? um essentially be able to do any kind of change based on the logic that it wants. Um I I wouldn't I would say like this is not something I would want. I would want the at least the bank to know what that agent is doing.

Uh not at like a central level but more like at individual level at action level is possible at prompt level if possible. Um because like that that trust that we give to these tools and to to people comes with like who is doing this, who is behind this, like what's going on, not necessarily the uh what that what that uh agent will do essentially. So this is the the current barrier of uh of entry when it comes to Agentic AI and AI tools in general and honestly digital tools in general at the beginning as well is whenever you want to bring in a new tool even though that capability is exploding and everybody's kind of like following the the hype and whatnot. I want to bring in a new tool to my company. Guess who guess who I have to talk to?

Compliance it. It's like hey can I bring this thing in? Well the first question is like do you know what this will do? No. Okay, great.

Then find out what it does and then come back. Does it have access to all our information? Yeah, where is that going? Is that going to a certain server somewhere? Well, if it if it is, then can we stop it?

If that answer is no, then probably you can't integrate that tool in a in a bigger company. And that's a massive breaker for adoption. And I think that's the the biggest breaker right now is like if you don't know what the tool does and some some uh of the a deployments are black boxes then you can't really go to to production with it. And we believe identity is that bridge where if you're able to bring in your tool and you're able to put a label on it like an identifier on it and then track each of its actions and then guard rail it and then protect it from attacks then you have a much better chance of passing that compliance test or passing that uh that IT uh requirements like sock 2 or whatever you're using for uh for that as a bigger company. Um but essentially identity it unlocks these real world use cases for aenti.

Now what does that mean? I'm gonna talk about it in a few minutes. So let's talk about the problem first. Because agents lack this verifiable identity. There's no way to revoke what they did because you don't know what actually they did.

Um there's no way to roll back changes. Like if you give AI unlimited write data to your database, it might just decide that your database is like expendable and delete it. uh or your codebase is expendable or not good and delete it. I don't know if you guys remember a Silicon Valley show uh who know who knows the show. All right, there's an episode where Gilfoil essentially set up Son of Anton which was their internal AI agent.

Uh, and then Son of Anton essentially decided to delete all the code. And that was this was like what five six years ago in terms of um like when the show was released and now we see this happening with VIP coders just like oh I'm just going to update everything with auto approve and then you end up with three files and you started off with I don't know 20,000 lines of code. So you want to be able to know which agent did what when changes they did and then roll back those changes if they were wrong. Um that's why they're stuck in sandbox environments right now. they're kind of ringing fenced by nature in terms of hey it can only go in this database in in this particular space because we don't trust it to see all the production data and that's that's a big issue and then this is what um it all comes back to is like it will need to see those credentials it's like what authorization what authentication does this AI have is it tied to the person that's unleashing it or is it like an independent entity either way they need to know and it's good that they need to So what does the identity really mean from this perspective?

So you need to have a place to store that identity. So it starts with a wallet. You need to have credentials. So whatever is put in that wallet. So is it government ids?

Is it proofs of assets? Is it like attestations that were signed? You name it. And you need to have some sort of verification APIs to enable to check those credentials whether they're still valid or not or to have a independent way of checking those credentials. And that's in the ID standard for example you have a a cryptographic element they can check or in the passport right there's like also a challenge or in your credit card there's a challenge uh that you can tap into.

So why is this relevant now? Well big companies are implementing AI more and more. Um, I don't know if you guys heard, but last week there was a big breach. I would say not really a breach, more like a companywide bug. So, Asana integrated AI into their internal processes and they did not take into account there would be crosscontamination between client individual clients data.

So, company A's data ended up in companies B's responses even though company B was expecting their own response to be without their own data based on their prompt. um pretty big snafu I would say. Um and this was not for like any hacker coming in or anything. It was just a logic flaw in the way they implemented the MCP server. And I would say also comes down to the authorization and the authentication that they did behind that AI agent because they centralized everything around a single server and then they co-mingled client data in that whole context.

Um I mean MCP I have you guys heard about MCP what that is? One two three four. Okay I'm I have a slide about that too. It's the model context protocol. Uh it's a way of interacting with data from an agent perspective that entropic released last year.

They're now like I think over 40,000 MCP servers out there and it's growing every day. Um and it's becoming now implemented in production in companies like Asana. Um and it becomes like the crown jewel for attackers like be it a prompt injection be it like even exploiting a logic flaw you're able to essentially exfiltrate data in a scalable way from larger ors that gets gets pretty scary from that perspective. So I think there's four four things that you can do like today when you're thinking about AI agents is like how do you implement them discover endpoints lock scopes which means like what the can that can what can that AI do um and then real-time monitoring super important we do it now with our servers we should do it also with the AI servers make sure we know what they're doing and then u try to break it that's all the red team flow is uh is about it's like try to break your see if you can get as company A you can get companies B data in your sandbox before you release that to production. I would say that that's the the learning from this uh this breach.

So this is a pretty big deal last week. So let's talk about some use cases uh from an identified guardrailled AI agent perspective. This is more of a fictional one and I'm going to show you also a one in production. So let's say you want an a agent to draft ad copy and then get images as well. You want to spend under 500 bucks for this.

So you essentially set up those guardrails initially. You put that spending cap. Um you autoblock the the limits. Uh then you make sure the AI only has access to non-personal information uh data in your database. So you keep that data separate segregated uh and you restrict them to marketing specific data stores.

And then at the end of it, what you should get is when the spending cap is reached, in this case 497, let's say, uh when the next call is made to buy another image, it's like, hey, you've exceeded your uh limit already by the simulation of this particular next transaction. Therefore, you're now blocked. Give me the final deliverables. And this should be the framework where we build a gentic AI. Now let's look at one specific one from the real estate space.

You can now close real like a real estate deal in under 24 hours with the help of Agentic AI. And this is actually a use case live in production with Propy. Do you guys know what Propy is? No. Okay.

It's an ICO from 2017. Um it's a crypto company that put on real estate transactions on chain. They're not doing a super high volume, but they've been consistent over the time over time and they're one of the survivors of 2017's ICO craze. Um, it's like before memecoins, before NFTs, there were ICOs in crypto. Um, so they're they're able to do reduce manual steps by 70%.

They're able to close in 24 hours and they they pass all the kind of identity and compliance checks with the the way they're using Agentic AI to be able to create that escrow to verify all the documents, verify all the participants. Um, super cool use case. If you haven't seen it, propy U real estate, check it out. So, coming back to model context protocol, I know not everyone knows what it is. Uh, it's essentially USBC for AI.

That's I think the best way to describe it. Entropic calls it that. I think that's the best way to do it. If you're more technical, it's JSON RPC for uh agents with verification. It's a very very descriptive way of of calling it.

uh you can essentially add fine grain scopes to it and then uh they have an open source road map. It's very communitydriven from that perspective. They've added oath to it. You kind of have to build your own ship around it. It's kind of like a Linux style like kind of build your own spec around it.

Uh so that's why a lot of us are building on top of it to help more devs build faster essentially. So, what does a secure MCP server look like for with uh with civic o or with any O to be to be fair like um you want to bring in a method that's compliant with O because you want to be able to talk the same language. Uh you want to have an easy integration. So SDK drop in with a few lines of code, get a single client ID, that kind of stuff. Uh you want to have it be framework agnostic.

So like you can replace civic o with any o you can like add keylo you can add any other open source solution if you want uh but it's just easier with u with this tool I would say um and then uh you want to be able to use it in multiple frameworks so if you're building in node or next or react react native or even in python um you have to be able to integrate uh that particular tooling in and then obviously because I mean we're work we're working with coders here SDKs you want to have a CLI command line interface for authentication and this makes it in our opinion the fastest way to add authorization and authentication to MCP servers. So in this case, if I use in my in my company, if I use uh Claude's desktop, let's say, um I'm able to connect into my Gmail, connect into my calendar and then retrieve, for example, the emails from the past week for my account and also the calendar notes from uh from last week and then create a weekly report just like that in a few minutes instead of me having to go through like, oh, what did I do this week? Let me go through my notes. let me go through my emails manually and what's that and I'm sure because I'm authenticated and the is only authorized to access my emails and my calendar it doesn't go and retrieve my colleagueu's emails or my colleagueu's calendar or uh my colleague when they do it they don't get access to my emails and in some cases like might be an email about them so you might not want that we're also launching something really cool now um it's called civic labs and it's essentially a way to experiment with code in a kind of sandbox environment. Add guardrails, add um promp protection to your AI, create a proxy to manage all these processes and then also a kind of AI agent companion alpha.

Um you can try all these tools out if you go to our our dev docs. But we're super excited about them. um what I describe now the fact that I can go in and create that meeting report in uh like few easy steps is a result of the MCP hub for example um you can go and request access to it and you can deploy it in your own uh your own sandbox and try it out so we're we're looking for feedback we may or may not have bounties for it so check it out so I promised a vision of the future at the at the beginning of the presentation I think beyond 2025 live. Uh, we're going to have agents that can book travel for us. I think we're going to have agents um that can help us sign leases, even like escrow with crypto.

And I think we're going to have agents that can file taxes for us for those who have to do that. Um, and there's something that's really bringing things together in the space like I think beyond identity, beyond authentication, authorization. Um, we've uh we've seen a a standard that was very very unknown. um be kind of brought back to life with crypto as the rails. Who here knows 404?

You know 404 when uh you get an error like hey uh page not found. Okay, so at the beginning of the internet, there was another standard that very few people know about called 402, which is payment not found, which was meant to do metering for certain like pages or resources that are gated uh behind some sort of payw wall. That was impractical back then because online payments did not exist. But then online payments came uh came about through intermediaries. We have a lot of like these payment processors.

it's still non-trivial to deploy. Um when USDC came out and USDT and like all these stable coins came out on uh on blockchain rails, then this became practical. So I think it was like last month uh Coinbase came out with X42 which is the crypto application of the 402 standard which is like I expect the payment in USDC on base before giving access to this resource that you're trying to consume. It's like an API or it can be like a hidden page. It can be an article.

It can be a book that you're selling. It can be something that you're uh you're putting out there that you want people to pay for. And you can set the amount and then you can check the chain for uh essentially the verification of that transaction and then release the resource once that's there and that's possible thanks to essentially crypto as a rails. And I think all these other use cases can be can be done as well with crypto as rails like pay for for travel. There's Travala.

There's like other platforms that accept crypto as payments. Uh for real estate, I already showed you Propy. Uh they're doing cool stuff on uh onchain. You can now like pro uh port that to like leasing platforms where you just rent stuff with uh with crypto. And then uh taxes, man, like even now 2025 is still a pain uh to file your crypto taxes.

I know how many of you had to go through hundreds or thousands of transactions and then um figure out, oh, when did I buy this and then what transaction attaches to what did I sell now versus like three years ago that I bought on some weird exchange that don't doesn't work anymore. So, we have all this information on chain. Can we just get it with AI process it real quick and then get it done? So, I'm really excited about that future. So, I'm going to leave you with three easy things to uh to try out.

Um, this code will take you to docs. So, in case you're weirded out by scanning an anonymous QR code, it's docs. It won't steal your keys. Um, but I think when it comes to AI agents, question every agent like what what do they do? What what data they have access to?

Uh, what MCP servers are are we bringing in? Did we just copy a third party anonymous MCP server from a GitHub that we don't know where it came from? We didn't verify the code and now we're just letting it run wild in our database. Um, who can see what that agent is doing? Is it just the user?

Is it the whole org? Is it a third party because it it it calls another endpoint where it sends some information that you don't want it to send. So, make sure you have that visibility control built in. And then, yeah, try out our SDK. Um it's free to start.

Um it's very very friendly builder builder plan and uh we have also a special offer for uh friendly builders. We have a 10K credit program that's running now. So if you're building uh with Civic O and you want to showcase it, build in public, tell us, send send us a note at bdscivic.com and we'll give you some credits to to work with beyond the the general free tier. So I think at the end of the day, trust shouldn't be a patch.

It should be a default feature. Uh all agents should have a form of identity and we should be able to track what they are doing and not issue like anonymous central one that coingles data otherwise we end up like Asana in this case. So that's it. Thank you so much. [Music] Apologies for that guys.

far away from the speaker. I've learned my lesson. We have some questions. Can we go to the next slide? Oh, okay.

So, how long until we start assigning AI agents a digital identity?

I mean, I would argue that we've already started. uh if you add an UU ID like a like a unique identifier to the AI agent once you spin up a session that's already a form of identity for that agent. So you're making a call. Instead of making that call completely kind of anonymized and and centralized, like you're making that call on my behalf, add a a unique identifier to it so that you can go back and see it in the logs. Hey, this uh call belonged to Titus.

It was done at this time and it had this scope and that's I think for the agent. It's a formative identity. It's not going to be as complex as a human identity, but like we we have to start somewhere. So how easy is easy to use civic to create full-blown set of accounts for AI agent?

So you can get up and running with O in under five minutes. Um I've tried it myself. You can just like add ask cloud code. It's like hey here's the docs for this react uh implementation of o get the client ID from o.cvi.

com civ.com and it's up and running. Now, if you want to add a Gentic AI identity, then you need to integrate one of the labs components uh that we have. I think the the proxy middleware is is one to try out. The AI hub is another one to try out.

Those are still in alpha. So, I would say get in touch with our dev team. Our CTO will be more than happy to walk you through exactly how it works. uh they made sure to go through the hard part uh which means managing like token uh authentication token life uh making sure that uh the AI stays connected to your uh your endpoints so you only have to integrate essentially the SDK for it. Uh but yeah, we're looking for feedback for that part.

It's still early days.

Hope I answered both questions. Do we have any more questions? Anyone in the audience that would like to ask a question? Okay, I have a question for you. How long until we see agents going mainstream as in being widely utilized by companies and individuals?

But when I say AI agents, I mean more than just chat GPT agents that can autonomously be act on your behalf.

So I would argue they're already there in a few orgs. Like I for example have automation that gives me social media posts every day about it the topics that I'm interested in I want to post about to my audience and every day I get a notification on my phone. It's like hey your posts are ready for review. Um, that that's one use of AI agents. I think a year ago I would have said five years.

Today I'm going to say a year and a half to two years. I think it's all moving extremely fast. And as we're building these foundational tools, it'll be easier and easier for people to integrate and to deploy safely because I think if you're giving again right access to an AI agent into your database, there's going to be a level of um error to it. And if you are not able to catch that error and then roll back then that error compounds over time. That's the problem with Agentic AI in a recursive way because that's what MCP enables.

Um you're if you start off with a 5% error and that compounds every iteration that at the end of it you get almost 100% error. Uh so you need to be able to separate the error from the the correct output and also have a roll back mechanism. But that's all like being built right now as a infrastructure.

Thank you. I think do you have a question sir? Did you try to raise your Oh, one more question. Okay. Yeah.

Could you please come? I was afraid. Oh, let me turn on your mic.

My question is actually about the mistakes. Uh how do you catch those little mistakes and what's the probability of the mistake when you do for example the taxation of your crypto? That can be crucial one. Yeah, that's a great question. Um, when I was building with LLMs in the mix, like a data pipeline, we had to prevent hallucinations a lot of the times.

Um, for example, GPT loves to invent phone numbers and email addresses. It loves it like it does it doesn't find it and like no, it's it's this company at whatever.com. It's like this name at no, it's not that. Um, so you need to go back to your data source and have some mechanical checks.

That's one way of looking at it. It's like, hey, does this data that I was expecting match the source data even though I've transformed it? Like I need I still need to have some anchors from the original data. Kind of like how you do you would check the work of a of a person, right? That's processing your data.

You're sending it to a BO coming back. It's sort of the same thing. Um the other thing that you can do is you can have an adversarial uh approach to it where you have one LLM that's the producer LLM and you have another language model or two or three other models that need to agree with each other that this initial LM did the work right which is a mixture of experts uh implementation that some companies do internally but you can also like kind of mix and match and can combine your models to obtain the final output that's like of high quality versus letting one model decide everything on its own. Um those are kind of a few options today uh that you can do and then uh if you want to uh catch and you want to also roll back so you have to you want to save at least one or two versions of history of that particular data point to know like what actually was changed. So you can go back and say like, hey, this was bad.

No, let's roll back to the previous step.

Automatic transcript — names and jargon may be misspelled.