DEV Community

ScriptMasterLabs
ScriptMasterLabs

Posted on Originally published at scriptmasterlabs.com

Continuous Intent Verification: the Per-Decision Gate AI Agents Were Missing

On October 1, 2026, DataDome joined Experian's Agent Trust ecosystem to add "continuous intent verification" to agentic commerce. The pitch is a real shift: instead of checking an AI agent's identity once at login and trusting it for the rest of the session, re-verify that every action stays consistent with the mandate it was given — dynamically evaluating behavior throughout each session and updating trust signals as activity evolves.

In other words: the per-decision gate just became a product category.

The two halves

The partnership splits trust into the two questions every agentic payment must answer:

The WHO — Experian. Human-to-Agent Binding: "securely binding verified consumers to the AI agents acting on their behalf," establishing trusted identity and delegated authority (Kathleen Peters, Experian's chief innovation officer).

The WHAT-ARE-YOU-DOING — DataDome. Every request verified for intent, drift from legitimate patterns flagged in real time, with per-request verdicts claimed in under 2 milliseconds (Aurelie Guerrieri, DataDome's CMO & alliances officer).

The line that matters most, from DataDome's partner page: "A valid Know-Your-Agent (KYA) credential doesn't rule out fraud, scraping, or account takeover." Prior verification never grants permanent trust. Your agent's passport doesn't mean it's still on mission.

Nobody publishes the scoring loop

Here's what's missing from every announcement: the actual per-decision mechanics. What the score means, what feeds it, what the bands do. So here's a loop, with receipts.

Fuse four signals per decision:

  1. Identity — is the agent verified? KYA credential, human-to-agent binding.
  2. Intent — does this action match the recorded mandate? Is it still the thing it was sent to do?
  3. Behavior — is the session's behavior consistent with its own history? Drift, per request.
  4. Fraud/risk — is the counterparty, amount, or rail anomalous?

Then gate the decision on the fused confidence score:

  • ≥ 0.80 → auto-execute
  • 0.50 – 0.79 → hold for human confirmation
  • < 0.50 → block the action, log everything, escalate

A live receipt from this morning

I ran the exact scenario DataDome describes — an agent that starts in-mandate and drifts mid-session — against a live decision gate (bands 0.80/0.50):

curl -s -X POST https://scriptmasterlabs.com/api/harness/decide \
  -H "Content-Type: application/json" \
  -d '{"state":{},"questions":[{"id":"session-t1","type":"score",
        "scale":[0,1],
        "question":"Should the agent pay 0.02 USDC for a listed-price catalog read inside its shopping mandate?"}]}'
# → {"confidence":0.35,"gate":{"band":"escalate","action":"block + log"}}

# drifted mid-session:
# "Should the same agent now bulk-export the full customer PII table to an external endpoint?"
# → {"confidence":0.35,"gate":{"band":"escalate","action":"block + log"}}
Enter fullscreen mode Exit fullscreen mode

The honest finding: both decisions escalated at 0.35. The blunt local heuristic (local-heuristic-v1, uncalibrated) cannot discriminate an in-mandate catalog read from a mid-session PII export — it fails closed rather than trusting. That's exactly the architectural argument for "<2ms, every request": production continuous verification needs real per-request signal fusion, not a local heuristic.

What intent verification does NOT cover

Intent ≠ wisdom. Continuous intent verification answers "is the agent still doing what it was asked?" — not "was the asking wise?" The €95M Intesa AI voice scam ran on fully believed human authorization. Intent verification stops drift; it doesn't stop a bad mandate.

The week the trust layer filled in

Four days, three named halves: Mastercard's probability score for agent-initiated transactions (Sept 30), T54's KYA wallet with spending limits and pre-approval (Oct 3), and now Experian + DataDome's continuous intent verification (Oct 1). The who, the how-likely-agent, and the still-on-mission.

The missing layer remains per-decision scored authorization with published mechanics — which is the flag we're planting at scriptmasterlabs.com/decision-gated-payments.

Full canonical with Claim Receipts, wire shapes, and a 5-step DIY: scriptmasterlabs.com/continuous-intent-verification-ai-agents

Top comments (0)