VeryAI, a Miami startup that recently took $10 million in seed funding from Polychain Capital, the Berggruen Institute, and Anagram, this week launched something called AG9. AG9 is a Know Your Agent platform: the agent economy’s answer to KYC.
The way AG9 works is: a user points a phone at a QR code that an AI agent has produced, completes a palm scan, and the agent receives a signed credential that ties it to the human who scanned. The next time that agent tries to do something material on the human’s behalf, like move money or publish a post or buy a flight, the system the agent is talking to can call AG9 and ask the human for another palm scan first.
This is, in 2026, an interesting product to have just shipped, because the question ‘did a real human authorize this AI to do this thing’ is one that very large parts of the digital economy have been quietly assuming away for the past two years.
The Question That Won’t Go Away
Bots are roughly 51% of internet traffic, per Imperva’s most recent count, with the malicious subset somewhere around 37%, depending on how one counts. Sitting on top of that, AI agents are growing fast, and the agents growing fastest are the ones companies are deploying specifically to take action: book the flight, route the support ticket, file the form, send the wire.
All of which is fine, in a sense, until the moment something goes wrong. At which point the question that platforms and regulators and lawyers and post-incident analysts all converge on is: who, exactly, told this thing to do this thing. The answer the existing identity stack can produce is mostly some variation of ‘a token from earlier was still valid.’ That is not, when said out loud in a regulator’s office, an answer that survives the kind of audit a payments network or an insurance regulator wants to be able to perform.
This is the gap that a remarkable number of organizations are now trying to fill. Four standards bodies are racing to define agent identity: FIDO, NIST, the IETF, and the Linux Foundation’s Agentic AI Foundation, all designing protocols that will probably ratify some time between mid-2027 and never. Worldcoin is offering iris scans through a hardware orb. Sumsub is binding humans to agents via document verification. Cloudflare Web Bot Auth lets bots declare themselves but does not prove a human told them to.
VeryAI’s particular design choice, in this crowded room, is to put the biometric at the moment of agent action rather than only at the moment of credential issuance. Standards-track agent identity is mostly about the credential the agent carries. AG9 is about the human, asked to come back and sign for the package.
Web3 Finds Its Market
VeryAI’s CEO and co-founder is Zach Meltzer, who previously built Galxe, a Web3 identity platform that grew to around 6,000 partners and 34 million users before its founder did the thing a particular kind of crypto-identity founder has been doing in 2026, which is to look at the agent commerce stack and conclude that the actual market for the identity infrastructure he had been building was AI rather than crypto. The chief science officer, Hua Yang, is a palm biometrics researcher with previous stints at Leap Motion and Redrock Biometrics, and it is fair to assume he had been looking for several years for a real consumer use case for palm biometrics that did not require giving Amazon your palm at the entrance of a Whole Foods.
The investor list confirms the lineage. Polychain Capital led the round, the Berggruen Institute and Anagram participated, and the announced partner roster runs through Solana, MEXC, Crossmint, and Colosseum. The pattern is not unique to VeryAI, but it is unusually clean here. Web3 identity infrastructure, after several years of looking for the product-market fit that crypto on its own did not deliver, has found something that looks like product-market fit in the AI agent economy. There is a version of this story in which AI is the second wave of Web3, and a version in which it isn’t, and the truth is probably somewhere in between.
Why Palm
The argument for palm specifically, as Yang would presumably tell anyone who asked and presumably did tell the seed investors at length, is that face is increasingly deepfakeable, voice was deepfakeable five years ago, and the parts of the human body that produce reliably unique biometrics not already sitting in a government database or a social-media archive are not numerous.
Palm prints are essentially absent from public datasets. The false-acceptance rate VeryAI claims is one in ten million for a single hand and one in a hundred trillion for two, which is the kind of number that means the system is essentially never going to confuse one person for another, even if it occasionally fails to recognize someone. The whole thing runs on any smartphone with a decent camera, which is both a real engineering achievement and the part of the pitch that takes the fight directly to Worldcoin’s $50 hardware orb.
The Strange Logical Place
The strange logical place AG9 lands in is one where, in order to let an AI agent do its job, the human in charge has to periodically prove they are still a real person, awake and aware and willing to take responsibility for what the agent is about to do. There is a version of this future where the palm scan is a frictionless tap, and a version where it becomes a constant low-grade interruption, and the difference between the two is mostly a function of how thoughtful the partner systems are about what counts as ‘sensitive.’
There is also a version where AG9 is one layer in a stack alongside FIDO’s protocols, Worldcoin’s orbs, OAuth’s descendants, and the document-verification players, each answering a slightly different version of the same question. That layer is now a Miami palm-scan startup with $10 million in funding and a name that is the friendly version of Know Your Customer applied to a robot.
–
By the Control Plane Editorial Team