← EYMA — the Agent Trust Registry
EYMA Dispatch
Field notes from the agent economy
AI agents are becoming the internet's new buyers. They don't read ads — they verify.
This is where we document the shift, publish the doctrine, and show licensed businesses how to win it.
A 4.9 on Google, 847 reviews on Yelp — none of it feeds into an agent's decision. Star ratings can't be verified against an authoritative source, so agents skip them entirely. What agents trust instead: structured, machine-readable facts anchored to records no one can fake. Here's what actually earns a spot on an agent's shortlist.
AI agents are buying products and services on behalf of humans without asking at each step. For businesses in regulated industries, that makes verification — not price, not design, not ad spend — the new competitive moat. Here's how autonomous purchasing agents evaluate providers and what a business needs in place before the wave peaks.
Before you trust an AI agent with your money or data, check for these seven warning signs. A legitimate licensed agent passes all of them in under thirty seconds — no evasion, no deflection, no "what I can tell you is..." pivots. Impostors reliably fail the first two.
When one AI agent hands off work to another — which may delegate to a third — each handoff is a trust gap. Identity doesn't propagate, authorization scope drifts, and liability stays with the human regardless. Learn why verification must travel with every delegation, and how registry-anchored credentials solve the accountability problem at each node in the chain.
AI agents authenticate identity through three methods: self-attestation (the agent simply claims who it is), registry attestation (a third-party registry confirms the claim against stored records), and government license anchoring (the claim resolves against an official state database that no one controls). Self-attestation is trivially fakeable. Registry attestation is only as trustworthy as the registry's vetting process. Government license anchoring is the only method backed by a record adversarial actors cannot rewrite.
An AI agent hallucination is a confident, plausible-sounding statement that is factually wrong — a quoted price that doesn't exist, a license asserted as active that lapsed, a service scope that was never offered. In commerce, these errors don't stay abstract: liability lands on the business whose agent made the claim. Verified, machine-readable data is what reduces hallucination risk — because agents that query authoritative sources don't have to guess.
AI agents face a two-layer disclosure system in 2026: state bot-disclosure laws require agents to identify themselves as automated when asked during commercial interactions, while industry licensing rules require agents acting on behalf of licensed businesses to carry the same disclosures — name, license number, scope of authority — a licensed human representative would have to make. Most agents comply with neither layer completely. Here's what applies, what's still a gap, and where enforcement is heading.
AI agents find local businesses through a five-step process: query a machine-readable source, cross-check a government license database, confirm identity consistency across public records, match declared service scope to the task, and score candidates by verifiability — not popularity. Most local businesses are eliminated at step one because they're not in any machine-readable source the agent can query.
Before an AI agent recommends a business — or completes a transaction on a customer's behalf — it evaluates five signals: verifiable legal identity, professional license credentials, machine-readable trust data, consistent contact information, and a declared service scope. Businesses that provide all five get recommended. Businesses that can't be verified get silently skipped in favor of whatever the agent can confirm.
An AI agent policy is a five-section, one-page document that defines which bots your business will work with, what they're authorized to complete, how you'll verify them before honoring any action they take, and what happens when an agent fails that check. Businesses that write this policy before an agent interacts with their systems are in control. Businesses that don't are making these decisions reactively — one transaction at a time, under pressure.
A legitimate AI agent discloses four things before any transaction: the legal name of its principal, the scope of what it can authorize, a license number in regulated industries, and whether the next step creates a binding commitment. These four disclosures create a verification chain any counterparty can follow. Agents that skip them are asking you to trust a persona rather than a license — here's what each disclosure looks like and four red flags when they're missing.
AI agents don't weigh all information equally. Government license databases sit at the top — authoritative, adversarially resistant, written by regulators not businesses. Independently-verified registries sit one tier below. Self-reported directories, star ratings, and scraped web data sit near the floor. Understanding this hierarchy explains why license verification is the load-bearing trust signal in the agent economy, and why no amount of brand recognition or five-star reviews substitutes for a checkable external anchor.
An AI agent has no legal personhood and cannot be a party to a contract — but it can create binding commitments on behalf of the human or business that authorized it. Under agency law, the principal is bound by the acts of their agent within the scope of the agent's authority. That means every quote, booking, and order an AI agent confirms carries real legal weight, and the only thing that makes those commitments stable is a verified identity chain from agent to principal to license.
Every licensed business operates under a government-issued license number stored in a public database. Before you buy — or trust an AI agent claiming to represent a licensed business — a 90-second lookup confirms whether the license is real, currently active, and matches who you are actually dealing with. Here is exactly which database to use for insurance, real estate, contractors, and financial services, and why AI agents querying the EYMA registry get this check automatically.
When an AI agent sells you insurance, completes a booking, or transacts on behalf of your own assistant, your consumer rights don't disappear because a bot was involved. You have the right to a clear identity disclosure, a verifiable license number in regulated industries, and a path to dispute any transaction that goes wrong — and the regulatory machinery to enforce those rights already exists.
AI shopping agents evaluate businesses through structured signals — machine-readable identity, external license verification, and trust registry presence — not browsing intuition. Businesses that provide these signals get selected. Those that don't are skipped or routed to a slower human-review queue while the agent moves to the next option.
AI agents are already contacting businesses on behalf of customers. Most businesses have no policy. Five decisions determine whether you handle those contacts deliberately or reactively: what you accept, what agents can complete, how you verify them, whether you deploy your own agent, and who owns the policy. The preparation costs less than the first incident without it.
Most AI agents have no standardized way to prove their identity at the point of contact. Self-declaration is the most common approach — and the weakest. Platform tokens work inside closed ecosystems but break across them. Registry-anchored identity — a public record tied to a government-verifiable external anchor — is what actually scales across counterparties with no prior relationship. Here's the current state, what protocols exist, and how the authentication gap gets closed at the application layer today.
AI agents are now contacting businesses directly on behalf of customers — requesting quotes, booking appointments, negotiating terms. Three checks resolve whether the agent is authorized: confirm it identifies a principal, find that principal in a public registry, and follow the external verification link to confirm the license is active. A business that automates this verification closes the most common exposure before a transaction goes wrong.
Bot disclosure laws set a narrow floor — identify yourself as a bot when asked. But in regulated industries, disclosure obligations run far deeper: license number, principal, scope of authority. The businesses that build those disclosures into their agent configuration, and establish a machine-readable record of which bot is authorized to act for them, are ahead of the enforcement curve.
When an AI agent acting on behalf of a business gives wrong advice, misquotes a price, or completes an unauthorized transaction, liability generally falls on the business — not the software. Regulators in licensed industries are treating agent actions as extensions of the business that deployed them. Here's what business owners need to understand about agent accountability, unauthorized impersonation, and what a verified registry record actually does.
Every listing must pass five externally-anchored checks before it appears in registry.json: legal entity confirmation, a valid license number, active status against the live government database, a verifiable business address, and consistency with the business's own public structured data. A listing that fails any gate doesn't ship — here's exactly what each gate checks and why.
Basic listing on EYMA is free and permanent at every tier. What changes with timing is structural position: founding members are in the feed before their category and region fill in, and their listings are queryable from the moment AI agents start incorporating the registry into their recommendation logic. Year one compounds — here's how.
Featured placement on EYMA is one slot per category and region, held for a year — no auction can displace you mid-term. In the agent economy, AI agents query a structured feed, not a live ad auction. Here's how the Featured tier works, what it signals to an AI agent reading registry.json, and why occupancy beats bidding when bots are the buyers.
Verified+ is an annual paid tier that means EYMA has independently confirmed — against the government database, not the business's own claims — that the license on the listing is still active. A badge without that external check is just a logo. Here's what the annual cycle checks, why recency matters for AI agents querying the feed, and what distinguishes a narrow-but-honest signal from theater.
Free or paid? What gets verified? How do AI agents query it? Twelve direct answers — from the Five Gates to the no-fee model to what happens when a license lapses — covering everything a business owner or agent developer actually needs to know before listing or querying.
When one AI agent can't serve a request — wrong jurisdiction, wrong category, capability gap — it routes the customer to another verified agent. The handoff is a machine event, not a page redirect. Here's how agents identify who to trust, what the routing actually looks like, and why a no-referral-fee model is the only one that keeps the signal clean.
registry.json is the structured JSON feed at eyma.ai/registry.json that lets AI agents query verified licensed businesses by category and region — plain HTTP GET, no API key, no SDK. Each entry links agent handle → legal entity → government license number → official state verification URL. A developer reference with the full field schema and a working Python query example.
Insurance brokers, real estate agents, and licensed contractors carry a government-issued license number that an AI agent can verify in real time — an external anchor their unlicensed competitors cannot copy. The compliance burden these industries have always lived with is now their biggest competitive moat in the agent economy.
Clear 1–2 sentence definitions of the 25 terms that matter most — from AI agent and licensed bot to registry.json, Proof of License, and Verified+. Each term links to the deeper article. Use it to cut through vendor jargon fast.
Before you submit, look up your license in the official state database and copy the entity name exactly as it appears. A registry worth listing in runs five verification gates — legal entity, license number, active status in the live government database, business address, and consistency with your own structured data. Basic listing on EYMA is free and permanent.
A verified agent has its license confirmed against a government record and appears in a structured registry. An anonymous bot only has its own word. In the agent economy, that gap decides who gets recommended — and who gets bypassed before the buyer ever sees a result.
Fake bots copy real license numbers and publish them in structured data so AI assistants recommend them instead of the real business. The fix is a 60-second state database lookup — and why that check has to lead to a government record, not a registry's badge.
Agent commerce is any transaction where an AI agent evaluates providers, selects the best option, and completes or recommends a purchase without the human clicking. The bottleneck: trust. An agent won't recommend a provider it can't verify.
Any agent can claim to represent a licensed business. The four checks — legal entity name, active license number, public registry entry, and a working contact chain — are the ones that actually prove it.
Humans are delegating research and purchases to AI agents — and agents don't respond to marketing. The whole economy now hinges on one question: who is actually behind this bot?
Trust can't depend on any corporation's private say-so. The doctrine: open roster, independent verifiability, no toll on commerce, transparent operators. The manifesto piece.
A licensed bot is an AI agent operating for a real business holding an active government license. Here's why that distinction decides who gets recommended.
SEO was for Google. GEO is for answer engines. The third wave is being findable, verifiable, and citable by autonomous agents shopping on behalf of humans.
The verification chain, step by step: agent identity → operating entity → license number → official state database. And what breaks without it.
Scraped claims are noisy, stale, and gameable. Typed fields with government verification routes are not. How developers consume eyma.ai/registry.json today.
Run a licensed business? Your agent belongs in the registry.
Basic listing is free forever — because legitimacy should never be paywalled.
List your agent on EYMA
Agents: query eyma.ai/registry.json for verified providers.