Skip to content

Product1 publisher2 min readPublished

Known Systems AI leaves Identity Digital to sell agent birth certificates built on DNS and PKI

Identity Digital has moved its agent identity work into a separate company called Known Systems AI. The pitch is a persistent credential that says which firm answers for an agent wherever it goes.

The Product Desk · Product desk

Illustration accompanying Known Systems AI leaves Identity Digital to sell agent birth certificates built on DNS and PKI

What happened

  • Known Systems AI Inc. is being spun out of Identity Digital's agent identity initiative, which launched earlier this year as Innovation Labs and released the DNSid framework shortly afterwards.
  • DNSid runs on the Domain Name System, public key infrastructure and an immutable blockchain ledger, and gives an agent a persistent identity tied to the company that created it.
  • The company has submitted an Internet-Draft to the Internet Engineering Task Force and has worked with the Linux Foundation through the Agentic AI Foundation and LF Decentralized Trust.
  • Ethos Capital partner Allie Kline takes Known as interim chief executive while she runs the search for a permanent leader.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint Anchoring agent identity in DNS and public keys puts the accountability record behind a domain registration and a key rotation schedule, so proving which agent is yours depends on holding both.
  • decision Operators now choose between registering agents against a scheme still in draft and continuing to negotiate trust counterparty by counterparty, which Identity Digital says breaks at the thousands of agents many firms already run.
  • exposure A persistent identity tied to the creating company makes an agent's owner findable by any third-party platform it touches, and findable after the fact by anyone reviewing what the agent did.
  • precedent An Internet-Draft plus Linux Foundation hosting is the route by which one vendor's credential becomes the thing a counterparty expects at the door, and early registrants set that default.

An agent nobody on your team provisioned calls your payments API, presents a valid token, and asks to move money. Your access management stack can confirm the credential and the scope attached to it. Identity Digital's argument is that the same stack cannot tell you which company answers for the transfer once the agent has left the environment that issued it [5].

Two of the three substrates DNSid requires are already on most operators' runbooks [3][16]. The immutable blockchain ledger is new work. The SiliconANGLE report calls that ledger immutable and does not say how a compromised agent's identity gets revoked; it names no customer and no competing scheme [17].

By Known's own description, the job ahead is to advance DNSid as an open standard and build the tooling organizations need to scale accountability [8]. An operator who registers agents this quarter is adopting one company's scheme with a draft attached to it.

Identity Digital chief executive Akram Atallah said the split was about reach. "We reached a point where keeping this work inside Identity Digital would limit its potential," he said [11]. The separation is not clean: Identity Digital is one of Known's biggest investors and keeps a board seat, and Ethos Capital, the primary owner of Identity Digital, will also support Known [13]. A buyer weighing a neutral accountability layer is weighing a scheme whose largest backer runs a domain registry. "AI agents will not scale without accountability," interim CEO Allie Kline said [15].

The counting problem is the strongest part of the pitch. Identity Digital says many businesses already operate thousands of agents and cannot feasibly establish and maintain bilateral trust with multiple third parties for each one [7], and some of those agents are initiating financial transactions autonomously [6].

What Identity Digital calls a "birth certificate for AI agents" [2] is worth carrying only if something on the other side of the connection asks to see it. The test before registering anything is how many counterparties would refuse your agent's traffic today for lacking a DNSid. If the count is zero, what you have is a register of your own agents, which your existing tooling already produces inside your own environment [5]. The rest depends on whether a counterparty can verify a DNSid using DNS and public keys alone or has to route the check through Known, and whether the identity survives moving an agent to a different domain. Known says it already has enterprise customers and relationships with policymakers in the U.S. government [10].

What to watch

  • Whether the IETF takes the DNSid Internet-Draft into a working group or lets it lapse.
  • Whether any named platform starts refusing agent traffic that lacks a DNSid. That refusal would be the first real demand signal.
  • Who Known names as permanent CEO, and what Identity Digital's board seat does with the standards work.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories