Trust Is the Next Bottleneck: Why the Agentic Economy Needs Confidential Computing

I’m giving a talk at Confidential Computing Summit 2026 in San Francisco on Tuesday. The title is “Trust Is the Next Bottleneck.” This essay is the argument behind the slides. The short version: we are building an economy of autonomous AI agents on a trust foundation designed for humans clicking buttons. That foundation is cracking. The fix isn’t better software — it’s hardware. The gap between authorization and execution OAuth tokens, API keys, and IAM roles answer one question: who authorized this action? ...

June 20, 2026 · 6 min · Pawan Khandavilli

AI Agents Have an Identity Crisis and OAuth Alone Will Not Fix It

Why multi-agent systems need verifiable delegation, not just valid tokens A human prompts an agent. That agent delegates to another agent. A sub-agent calls a tool, which calls an API, which touches real data and real systems. Now the key question: Who is acting at each step, and on whose authority? Most teams answer this with one of two lines: “We use OAuth through MCP.” “Our platform handles access controls.” Both can be true. Neither is enough for multi-step agent workflows. ...

February 25, 2026 · 3 min · Pawan Khandavilli

Google's AP2 Protocol: Building Trust in Autonomous Transactions

It’s been a while since I felt giddy reading a specification. The release of Google’s Agent Payments Protocol (AP2) brought back memories of my payments days—waiting eagerly for Visa and Mastercard to publish updates on network tokenization, or when Android introduced Host Card Emulation. Here’s what stood out. What Is AP2? The Agent Payments Protocol (AP2) is Google’s ambitious attempt to create a cryptographic foundation for AI agent–initiated commerce. Released on September 16, 2025 with backing from 60+ organizations, it tackles the central trust problem: ...

January 23, 2026 · 3 min · Pawan Khandavilli