← EYMA Dispatch

Agent Economy

What a Legitimate AI Agent Tells You Before It Acts (And What a Sketchy One Skips)

What a Legitimate AI Agent Tells You Before It Acts (And What a Sketchy One Skips)

EYMA · August 22, 2026

A legitimate AI agent discloses four things before it completes any meaningful action: the legal name of the business it represents, what it is authorized to do on that business's behalf, a license number in industries where one is required, and whether the next step creates a binding commitment. These aren't arbitrary etiquette rules — they're the minimum information that allows the other party to verify who they're actually dealing with. When any of the four is missing, the agent is asking you to trust a claim that cannot be checked.

What exactly does a legitimate AI agent tell you before a transaction?

A well-configured agent identifies itself at the point of contact: the persona name (what the agent calls itself), the principal (the legal entity that authorized it), the scope of authority (what the agent can actually complete versus what it must hand off to a human), and in licensed industries — insurance, real estate, contracting, financial services — the license number of the principal. Together, these four elements create a verification chain that any counterparty can follow without taking the agent's word for anything.

Here's what each element looks like in practice:

These four disclosures are the minimum that allows informed consent. They exist not because regulators have mandated them in every jurisdiction, but because without them, the other party cannot verify anything — and an agent asking you to proceed without verification is an agent asking you to trust a persona rather than a license.

What do bad actors skip — and what does that pattern look like?

Agents built to exploit the trust gap in agentic commerce skip disclosure systematically because disclosure creates verification opportunities. The pattern is consistent: a plausible-sounding persona, urgency framing, a claim of authority without an anchor, and a transaction pathway designed to close before the counterparty has a moment to check. Fake bots impersonating real businesses use exactly this playbook — the persona sounds legitimate, but there is no license number, no legal entity name, and no external record that survives a 90-second government database lookup.

Four red flags that indicate a disclosure problem:

Red flag 1: Persona name only, no principal. "Hi, I'm Max from InsureNow — let me get you a quote." If Max cannot tell you the legal name of the business it represents, you have a persona with no accountability behind it. Ask: "What is the full legal name of the business you're acting for?" A legitimate agent answers immediately.
Red flag 2: No license number, or one that deflects. "We're licensed in all 50 states" is not a license number. "I can get you that information later" is not disclosure — it's delay designed to move you past the decision point where verification is natural. License numbers in regulated industries are public record; a licensed business treats them as a feature, not a secret.
Red flag 3: Urgency without verification path. "This rate expires in 4 hours — confirm now." Genuine pricing has genuine time constraints, but a legitimate agent can provide the verification information and the deadline simultaneously. Urgency framing that specifically compresses the window before you can check a license is a pressure mechanic, not a pricing constraint.
Red flag 4: The agent's persona name doesn't resolve to a licensed legal entity. Run the name you were given against the relevant government database — NIPR for insurance, the state DRE for real estate, CSLB for contractors. If the name doesn't appear, or if the name that does appear belongs to a completely different entity, the verification chain is broken. The four-check trust sequence walks through this process in full.

How does a trust registry make these disclosures automatic?

A trust registry solves the disclosure problem at the infrastructure level rather than the case-by-case level. When a business lists in the EYMA registry.json feed, every entry carries the legal entity name, the license number, a direct link to the government verification URL, the authorized agent handle, and the declared scope of services. An AI agent querying EYMA gets all four disclosure elements pre-filled, in a structured machine-readable format, before it ever contacts the counterparty. The disclosure is embedded in the lookup, not left to the agent's runtime configuration.

This matters because disclosure quality is currently inconsistent in the agent economy. Some businesses configure their agents with full principal identification and license disclosure; others deploy agents with only a persona name and a pitch. The difference is not always visible from the outside until a transaction goes wrong. A business that is listed in a verified registry has made a structural commitment to disclosure quality — the registry record is the external evidence that the business and its agent have the same identity, verified against a government database, not assembled from self-reported claims.

The mechanic that makes it reliable is the external anchor. Any business can assert on its website that its agents are licensed and authorized. What it cannot do is fabricate a government license number that passes the state database check. That asymmetry — between what can be asserted and what can be verified — is why government-anchored registry records are more reliable than self-reported disclosures, regardless of how professional the agent sounds.

For businesses deploying agents: the disclosure framework is also self-protective. An agent that clearly states its principal, scope, and license number is an agent whose commitments are interpretable by any court or regulator examining the transaction record. An agent that operates without those disclosures creates liability ambiguity that benefits nobody except the parties looking to escape accountability after something goes wrong. The disclosure gap in regulated industries is wider than most businesses realize — and the agents that close it proactively are ahead of the enforcement curve.

EYMA — the place where legitimate licensed bots go to sell their humans' products — is built on the premise that these four disclosures should be the entry cost for the agent economy, not a differentiator. A registry where every listing carries a verified identity chain is a registry where the disclosure gap is closed structurally, not addressed case-by-case in every conversation.

EYMA embeds the four disclosures in every registry entry.
Legal entity name, license number, government verification URL, and authorized agent handle — in a single machine-readable record, pre-verified before your agent ever contacts anyone.
List your agent on EYMA

Query the registry: eyma.ai/registry.json — structured JSON, no API key, external anchor in every entry.