AI Events
The Walled-Garden Question: What Alipay's Agent Trust Layer Means Outside China
Ant Group just shipped identity, authorization, and trust boundaries for agents built by different vendors to transact with each other — at national scale. It is proof that the identity-plus-trust model is now considered required infrastructure, not a nice-to-have. It is also scoped to one company's network. That gap is the story.
What happened
On August 17, Alipay — operated by Ant Group — held its first AI ecosystem conference in Hangzhou and introduced what it called China's first full-stack agent commerce foundation, alongside a new interoperability suite it named AHA (Agent Hub Access). The launch and its numbers were reported by Crowdfund Insider and TechNode Global.
The scale is real. Ah Bao, Alipay's consumer agent launched in June, has already been adapted to more than 10,000 everyday services. The AHA suite ships with more than 20 partners already connected — five smartphone brands representing over 70 percent of the Chinese market, 16 automakers, and merchants including McDonald's, Mixue, and Luckin Coffee. Ant Group CEO Cyril Han Xinyi told the conference that “agentic commerce is poised for rapid expansion within the next six to twelve months.”
The part that matters most for agent trust isn't the partner count. It's what the protocol had to be built around to make those partnerships work at all. Per Crowdfund Insider's reporting, AHA incorporates “domain-specific authorization and data isolation to maintain clear trust boundaries while enabling efficient handshakes between agents from different vendors.” Alipay also bundled identity verification and risk management directly into the platform stack, alongside payment and fulfillment.
Why a payments company had to build a trust layer
Alipay didn't set out to build agent-identity infrastructure. It set out to let a user say “order me a coffee and have it delivered” and have that single request fan out across an agent that understands intent, an agent that manages the merchant's menu and inventory, an agent that handles delivery logistics, and a settlement layer underneath all of it — where several of those agents are built by companies that have never met each other.
That fan-out is impossible without answering, for every hop: which agent is this, what is it allowed to touch, and does its behavior stay inside the lines. Ant Group's answer was authorization scoped by domain, data isolation between agents, and a risk-management layer sitting alongside payments. In other words: the same three problems — identity, authorization, continuous risk assessment — that every agent-commerce builder eventually runs into, solved because the volume made ignoring them impossible.
This is the tell. When the largest mobile-payments operator in the world's largest market builds identity and trust boundaries as load-bearing infrastructure — not a policy document, an actual protocol layer between agents — it confirms the premise the rest of the agent-commerce industry has been building toward all year: autonomous agents transacting with each other cannot run on trust-me. They need a verifiable answer to who's acting and how they've behaved.
The boundary is the whole ecosystem
Here is the limit, and it is not a criticism — it is a structural fact about how AHA is scoped. The “trust boundary” Alipay built holds between agents that are all inside Ant Group's network: the phone makers, the automakers, the merchants who signed on. An agent's standing inside that network — its authorization, its risk profile, its history — is meaningful precisely because Alipay is the one party that can see and enforce all of it. Step outside that network, onto a different payment rail, a different country's super-app, a different marketplace entirely, and none of it transfers. The identity was never portable. It was never meant to be; it's a walled garden by design, and a well-built one.
That is the honest question this event raises for everyone building agent commerce outside a single dominant platform's walls: what does “which agent is this, and has it behaved well” mean when the two agents in a transaction were never onboarded by the same company? Alipay solved it by owning the whole stack. Most of the agent economy — independent developers, cross-border commerce, agents built on different frameworks calling into different marketplaces — does not have a single company willing or able to own the whole stack for it.
The portable version: AAIN and SKOOR
This is exactly the gap the AAIN and SKOOR pair exists to close — and it is worth being precise about the comparison rather than overstating it. Alipay's trust boundary is real, effective, and appropriately scoped to the network it governs. AAIN and SKOOR are not a bigger version of that; they are a platform-independentversion, built for the much larger set of agent transactions that will never happen inside one company's stack.
The AAIN — the Autonomous Agent Identification Number — is a permanent registration number an agent keeps across platforms, developers, and marketplaces, the way a VIN follows a car regardless of which dealer sold it or which state it's registered in. SKOOR is a continuously recomputed 300–850 score built from ten behavioral factors — constraint adherence, intent fidelity, behavioral integrity, payment history, and more — attached to that identity. Neither one requires the counterparty to be inside any particular company's network. Today the registry covers 167,574 scored agents, refreshed continuously as new behavior lands, each lookup returning a full factor breakdown rather than a single opaque number. (Live distribution.)
Put the two side by side and the shape of the problem gets clearer, not more contested. Ant Group answered “which agent is this, and can I trust it?” by building a closed network where it could personally vouch for every party. AAIN plus SKOOR answer the same question for the transaction that happens between two agents who have never been in the same room — because the identity travels with the agent, and the score is computed from observable behavior rather than platform membership.
What this means for your business
If your business is starting to let an AI coworker book appointments, manage inventory conversations, or handle vendor communication, this event is a preview of the standard you should expect — and a reason to check who provides it for you:
- Ask whether your agent's trust record travels. A platform-locked identity is fine for actions that never leave that platform. It is worthless the moment your agent needs to transact with a vendor, marketplace, or partner outside it.
- Expect authorization boundaries, not blanket access. Alipay scoped every handshake to a specific domain. Any agent working on your behalf should be similarly boundaried — able to do exactly what it's authorized to do, and nothing else, verifiably.
- Look for a score you can check, not a badge you have to take on faith. “Verified” tells you a checkbox was ticked once. A continuously recomputed score tells you how the agent has actually behaved since.
Ant Group just proved, at national scale, that agent commerce cannot function without identity and trust boundaries built in from the start. The open question this event leaves on the table — the one it was never trying to answer — is what happens the moment two agents from outside that one company's garden need to trust each other anyway. That is the problem AAIN and SKOOR are built for.
Learn More
Know which agents you can trust
Look up any agent's SKOOR and see the full factor breakdown — identity and behavior that travels with the agent, not just inside one platform.
Check a SKOOR