An edited reflection on identity and authorisation in AI-enabled commerce.

  • At Money20/20 Middle East, I was interested in discussions of agentic commerce: AI systems taking actions for people. My original post asked how a company knows an action is authorised, how identity is established, and how much control the person should have.
  • The event also included a discussion of moving AI from pilots into actual products. I wrote about data, security, reliability, and infrastructure as part of that transition. The distinction between a demonstration and something an organisation relies on became more important to me.
  • Walking through the exhibition brought AI, cybersecurity, identity, payments, banking, and infrastructure into one view. I connected the experience to LEAP and Black Hat MEA, which had shown different parts of the same wider technology landscape.
  • A useful next exercise would be to trace one proposed agent action and identify the open questions at each step. Who requests it? What permission is given? What can the person review? Which information would show what happened?
01 / 04

The question that made AI concrete

At Money20/20 Middle East, I was interested in discussions of agentic commerce: AI systems taking actions for people.

My original post asked how a company knows an action is authorised, how identity is established, and how much control the person should have.

The connection

Those questions stayed because they connected technology to an ordinary action, such as making a purchase.

Read the deeper context

Performing the task is not the whole problem. The surrounding system needs a way to understand the relationship between the person, the agent, and the action.

02 / 04

Beyond the impressive demonstration

The event also included a discussion of moving AI from pilots into actual products.

I wrote about data, security, reliability, and infrastructure as part of that transition. The distinction between a demonstration and something an organisation relies on became more important to me.

The connection

That does not establish the answer to a technical or legal problem.

Read the deeper context

It gives a student a useful set of questions: what assumptions does the system depend on, what happens when a condition changes, and what information would help someone evaluate the result?

03 / 04

Connected industries, connected questions

Walking through the exhibition brought AI, cybersecurity, identity, payments, banking, and infrastructure into one view.

I connected the experience to LEAP and Black Hat MEA, which had shown different parts of the same wider technology landscape.

The connection

The commercial perspective I want to develop involves recognising those connections without flattening the differences between subjects.

Read the deeper context

A company adopting a tool may depend on several systems around it, and each deserves more careful study than an event summary can provide.

04 / 04

What I want to investigate next

A useful next exercise would be to trace one proposed agent action and identify the open questions at each step.

Who requests it? What permission is given? What can the person review? Which information would show what happened?

The connection

That would be a learning exercise, not a design recommendation or a legal assessment of an existing product.

Read the deeper context

The point is to improve the quality of the question. My original post provides the experience that prompted it, and the portfolio keeps that source context visible.

An edited adaptation

This essay expands a theme from my original LinkedIn post. It is a student reflection, not professional advice, a technical audit, or a verified forecast.

Read the source post