Agent Identity launched on Product Hunt with a one-line pitch: give every AI agent real identities, inboxes, and a phone. The listing frames it as plumbing, and that framing is the tell. Provisioning an inbox and a phone number for a software process is a solved problem. Twilio has sold programmable numbers for years, and every cloud provider will hand you a mailbox in an afternoon.

What is not solved is the question the pitch skips past. When an agent has a phone number, a human on the other end of that line will assume a person is responsible for it. That assumption is the entire product, and it is also the entire liability.

The identity layer is the easy half

Strip the launch to its mechanics and Agent Identity sits in a crowded category. Agents need credentials to call APIs, addresses to receive mail, and numbers to place calls or pass SMS verification. The first two have established answers: OAuth scopes, service accounts, per-agent API keys, and catch-all mail domains. The phone number is the interesting one, because phone numbers are the closest thing the consumer internet has to a verified human identifier.

That is why so many signup flows still gate on SMS. A number is a weak identity, but it is a number a regulator can subpoena and a carrier can trace. Handing one to an autonomous process changes what that process can do on the open web. It can register accounts, receive one-time codes, and pass the checks that were designed to keep bots out.

The pitch does not say how Agent Identity handles that. It does not say whether numbers are shared across agents, whether they are recycled, or what happens when a number previously assigned to an agent gets reassigned to a human. Those are not nitpicks. They are the difference between a useful tool and a spam cannon.

Accountability is the unsolved problem

Here is the take. Identity for agents is not a provisioning problem, it is an attribution problem, and the two get confused constantly. Provisioning asks: can this agent have an inbox? Attribution asks: when this agent sends a fraudulent invoice, who is on the hook?

The second question has no clean answer yet, and the industry is quietly papering over it. An agent acting on behalf of a user is, in most legal frameworks, still the user’s action. An agent acting on behalf of a company is the company’s action. But agents increasingly act on behalf of other agents, in chains that no single party fully controls. When a procurement agent negotiates with a sales agent and both are operating inside delegated budgets, the chain of custody for a bad decision is genuinely unclear.

Giving each link in that chain a phone number does not resolve it. It might make it worse, by creating the appearance of a responsible party where none exists. A number that rings and a mailbox that accepts mail look like accountability. They are not the same thing.

What the launch gets right

None of this makes the product wrong. The instinct that agents need first-class identities is correct, and it is where the market is heading. Enterprises deploying agents in production are already hitting the wall. A support agent that cannot send mail from a real address gets filtered. A sales agent that cannot place a call cannot do the job it was hired for. A research agent that cannot receive a verification code is locked out of half the web.

The provisioning layer will get built, by Agent Identity or by the dozens of startups chasing the same gap. What matters is whether the layer ships with policy attached. The interesting version of this product is not “your agent gets a phone number.” It is “your agent gets a phone number, a spending limit, an audit log, and a kill switch, and the number is registered to a legal entity that will answer for what the agent does.”

That version is harder to demo, which is why the Product Hunt listing leads with the number.

The regulatory clock is running

The timing is not accidental. Regulators have started asking who is responsible for automated decisions. The EU AI Act’s transparency obligations for certain automated interactions took effect on a staggered schedule through 2025 and 2026. The FTC has been active on deceptive automated conduct. State attorneys general have pursued robocall and robotext cases against automated dialers for years, and an agent that places calls with a real number walks straight into that regime.

An agent with a phone number is a regulated entity in a way an agent with an API key is not. That cuts both ways. It creates compliance burden, and it creates a moat for whoever builds the compliance tooling first. The winners in agent infrastructure will not be the ones who mint identities fastest. They will be the ones who can prove, after the fact, which agent did what, on whose authority, and under what limits.

What to watch

Watch for three things from this category over the next two quarters. First, whether any of these products publish a real accountability model, meaning named legal entities, documented delegation chains, and logs that survive a subpoena. Second, whether carriers and mailbox providers treat agent-minted identities as first-class or start blocking them at scale, which would collapse the whole premise. Third, whether the first serious incident, an agent that commits fraud or harassment through a provisioned identity, produces a lawsuit that names the identity provider alongside the operator.

The plumbing will get built either way. The question is whether it gets built with a paper trail, or whether the industry ships a million phone numbers attached to nobody and waits for the first court case to explain what that means.