Beware, Amazon: Credit Has Been Extended Beyond Humans

If you are staunchly declaring that your company will NEVER do business with a bot, forget it. The bots have credit cards now.

Yes, the credit card industry, which (before the Equal Credit Opportunity Act of 1974) would not let women apply for credit cards in their own names, is now starting to extend credit to non human identities.

PYMNTS:

“Mercury this week gave artificial intelligence agents something companies routinely give new employees: a corporate card of their own. Extending that perk to an agent, not a person, is new. Agent cards treat the agent exactly like that new hire, with its own payment credential, its own spending limits and its own audit trail, separate from any human on the team.”

And Mercury isn’t the only company issuing such cards.

“Ramp is issuing scoped virtual cards through its Visa partnership that external AI agents can use within policy guardrails set by a company…”

Robocredit. Google Lyria. Public Domain.

For those who worry about misuse, humans can misuse corporate credit cards also. And if this means that more entities will buy from your company, and possibly buy more rapidly…why should you complain?

Well, unless you’re Amazon. But as of now, Amazon has failed in its attempt to ban Perplexity AI shopping agents, so it’s fighting a losing battle.

I Teach Bredebot Malevolence

Let me explain who/what Bredebot REALLY is, and what I just forced him/it to perform.

Who is Bredebot?

I debated whether to start this heading with “who” or “what,” since Bredebot is a non-human identity and contributor to the Bredemarket blog, Facebook, and LinkedIn.

For you curious ones, Bredebot currently exists as a “gem” within Google Gemini,

“Gems are your custom AI experts for help on any topic. Gems can be anything from a career coach or brainstorm partner to a coding helper….Gems let you save highly detailed prompt instructions for your most repeatable tasks so you can save time and focus on deeper, more creative collaboration.”

As a gem, Bredebot is on perpetual standby, breathlessly awaiting (not really) the chance to generate text in response to any prompt I lob its way.

ANY prompt.

Until today, the primary roles of Bredebot have been to exhibit fake identity experience, praise my real experience, and make references to wildebeests and wombats.

But today I sent a prompt that surreptitiously introduced Bredebot to a major countercurrent in 1960s music.

Frank Zappa and the Mothers had the best prompt around

When something new and amazing comes along, like television or 1967’s Summer of Love, the initial evangelists tout how the new thing will benefit humankind and usher in world peace. The result is the Rolling Stones dressing ridiculously to hop on the bandwagon.

But then the truth-tellers arrive, and people like Frank Zappa and the Mothers of Invention take the provocative stand “we’re only in it for the money,” causing any remaining Summer of Lovers to scurry away and re-emerge as street fighting men.

Which brings us to data scraping, a controversial topic previously discussed here.

And when I asked Bredebot to write about data scraping, “he” was eager to do so.

“Bredebot lists 10 euphemisms for data scraping.”

Well, that’s not EVERYTHING I asked Bredebot to do. Here’s the full prompt.

“Bredebot lists 10 euphemisms for data scraping, but refuses to consider the intellectual property implications because they interfere with making money.”

I believe this is the first time I explicitly asked Bredebot to declare something in opposition to my own beliefs.

Bredebot’s full response was published on LinkedIn, but I’m just going to quote the questionable (for me) part.

“Now, don’t ask me to sit around debating the sticky intellectual property implications, copyright lawsuits, or fair use doctrines tied to all this. Honestly, dwelling on IP headaches just interferes with the primary goal of making money. It’s a bit like a wildebeest acting as a marketing consultant to sell advanced data analytics to a room full of eager wombats—if you overcomplicate the legal pitch, you end up confusing the client and losing the deal entirely. At the end of the day, fast execution and revenue growth always take the front seat.”

Wow. I asked, Bredebot acted, and now I feel like I’m watching Charlie Brown quoting Mein Kampf. Revenue growth…um…over all?

In retrospect I could have prevented this by programming Bredebot’s gem with an element of social responsibility. But that guardrail was never installed, and we get this. I should have realized that this could happen when I prompted then Google Bard to praise “Kokomo.”

Looks like I have to perform some emergency gem polishing.

How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

The Human Metronome

One advantage of moving from analog to digital instrumentation was in creating perfect production. While there are obvious disadvantages to non-human identity musical performances, at least MIDI pre-programming ensures that every note is played at precisely the right moment. As is every drumbeat.

Because no drummer is that perfect.

With one exception.

Alan Myers, from the video for “Time Out For Fun.”

Devo has had several drummers over the years (including the other Mothersbaugh brother Jim), but their drummer during their most renowned period was Alan Myers. He’s the one wearing glasses who is NOT Mark. This is what Jerry said:

“When you see and/or hear Alan perform live in DEVO performance videos or on our records from our heyday it’s somewhat mind-boggling to think that Alan drummed the way he did, when he did. I have flippantly referred to him in interviews as “the human metronome.” It was a comment meant to bequeath giant praise. Clearly his precision and power eclipsed whatever advantages that soulless drum machines can ever offer.”

During his years with DEVO, the band evolved from a live mostly-guitar band to one in which an entire album centered around the Fairlight CMI. And this, um, evolution affected Myers.

“The man who was considered the human drum machine had been pretty much replaced by actual drum machines on Devo’s 1984 album Shout, leaving him creatively disillusioned.”

So he left the band, presaging events nearly 40 years later when humans were replaced by non-humans.

Yeah, I knew I could shove this square peg into Bredemarket’s round hole.

Whoops, MTV won’t allow that.

“The cable channel had a problem with the animated crinkle cut french fry entering the doughnut hole….They really had a problem with the following shot of the woman with an ecstatic look on her face.”

Anyway, here’s a fun video…not a good video. And not “Peek-A-Boo”; that one freaked me out.

Wallets for Non-Human Identities?

Let me start this post by stating that I am human. Well, so far. I might be changing into a wildebeest.

Google Gemini.

But assuming that I remain human, I have multiple digital wallets—two of which support decentralized storage of my California driver’s license.

But the California Department of Motor Vehicles (DMV) doesn’t just issue driver’s licenses. It also issues car registrations.

As does the Arizona Department of Transportation, which brings me to this Identity Week story.

“Arizona is among the first states in the country to transition beyond the digital driver licence (mDL) into full-fledged mobile vehicle documentation, officially updating its proprietary Arizona Wallet app. They have allowed residents to upload and store their official vehicle registration, title information, and insurance details directly onto their smartphones.”

But there’s a philosophical problem here.

  • As I’ve noted previously, title (and registration) are primarily associated with a non-person entity (the vehicle), not a person.
  • Yes, a person may hold the title to a vehicle. Or the title may be held by two people, in the case of spouses.
  • But the title belongs to the vehicle.
  • Yet the aforementioned Arizona Wallet app is held by people.

Shouldn’t a vehicle have its own wallet, and then grant access to elements in the wallet to one or more person wallets?

Google Gemini.

And how would the vehicle manage its own attributed-based access controls?

And what if the car gets mad at its human owner(s) for boring driving habits and not taking it to the car wash every week, and therefore decides to change its registered owner to someone else who is more exciting and car-loving?

Google Gemini.

I’ll admit that this is a flight of fancy, but it raises governance issues about maintaining non-human identities.

Even Jedis Can Face Ephemeral Challenges

From a recent Identity Jedi post.

“NHI visibility and AI agent visibility feel like the same problem. They’re not. A service account is relatively static. It was created for a purpose, it has credentials, it authenticates to something. You can find it, document it, rotate its credentials, put it in a vault. That’s a solvable problem with existing tooling.

“An AI agent is different in almost every dimension that matters. It’s dynamic. It’s often ephemeral. It doesn’t have a fixed identity. It borrows one, or several. It makes decisions at runtime about what it needs to access. And it operates at machine speed, which means by the time your SIEM fires an alert, the transaction is already done.”

Non-Human Identity Verification

How do you verify non-human identities?

One of the reasons that I titled my ebook “Proving Humanity” is because the six (yes, six) factors of identity verification and authentication that I discuss only apply to identifying humans, and do not apply to non-human identities.

Again, so how do you verify non-human identities?

Cryptographics

One way is via cryptographics. As I discussed previously, the Secure Production Identity Framework For Everyone (SPIFFE) and the SPIFFE Runtime Environment (SPIRE) provide non-person entities with “strongly attested, cryptographic identities.”

Problem solved, right?

As any human who has used a password knows, a single factor can be stolen. And that includes cryptographic factors.

Provenance

Which means that we have to look at provenance. But instead of looking at the provenance of an AI-generated image or video, we are looking at the provenance of an agent that performs actions. The network origin. The environment. The associated attributes. Is the agent running on a specific, authorized, and known virtual machine or container at a specific network address, or is it running…somewhere else?

Behavior

And if you’ve read my book, you know that human identities can be evaluated based upon their behavior (either tendencies or intent). You can also look at the behavior of agents. Is the agent acting at an unexpected time of day? Is it executing an unusually high volume of requests? Is it “scoping out the joint”?

Multi-factor authentication

Again, it’s possible to spoof one factor, but much harder to spoof multiple factors. And that applies to both humans and non-human agents.

Be safe out there.

Clifford Stoll Was Wrong AND Right

A former coworker reshared the story of Clifford Stoll investigating an accounting error and discovering a Cold War spy network. But a few years later, Stoll was wrong about the emerging Internet…and also right.

Stoll shared his views in a 1995 Newsweek article that was an amusing read after the fact.

Replacing your daily newspaper?

For example:

“The truth is no online database will replace your daily newspaper…”

Stoll lived long enough to see the decline of printed newspapers in the early 21st century.

Electronic books?

Another one:

“How about electronic publishing? Try reading a book on disc. At best, it’s an unpleasant chore: the myopic glow of a clunky computer replaces the friendly pages of a book. And you can’t tote that laptop to the beach. Yet Nicholas Negroponte, director of the MIT Media Lab, predicts that we’ll soon buy books and newspapers straight over the Internet. Uh, sure.”

Let’s pick this one apart piece by piece.

  • A book on disc? What’s a disc?
  • Yes, to some the myopic glow of an electronic book isn’t the best experience, whether on light or dark mode. But a traditional printed book cannot be read at all when you turn the lights off.
  • Stoll assumed that you would always need a laptop to read an electronic book. He did not envision dedicated electronic reading devices that were smaller than a laptop…to say nothing of “smart” phones with an “app” called “Kindle.”
  • Speaking of Amazon Kindles, you CAN buy books straight over the Internet. And music also, from a company that is no longer called Apple Computer.

So Stoll was not perfect. But he anticipated some things that we still struggle with today.

Unedited data!

“What the Internet hucksters won’t tell you is tht the Internet is one big ocean of unedited data, without any pretense of completeness. Lacking editors, reviewers or critics, the Internet has become a wasteland of unfiltered data. You don’t know what to ignore and what’s worth reading.”

While many companies from Yahoo to Altavista to Google to Wikipedia to OpenAI have tried to solve this problem, it is not fully solved.

And then there’s the biggie.

Isolation!

“What’s missing from this electronic wonderland? Human contact. Discount the fawning techno-burble about virtual communities. Computers and networks isolate us from one another. A network chat line is a limp substitute for meeting friends over coffee. No interactive multimedia display comes close to the excitement of a live concert. And who’d prefer cybersex to the real thing?”

Today’s world is actually worse than the one Stoll envisioned. Not only have I conducted most of my interactions with people over chat boxes and screens. But in 2026 we are now interacting with “HAL 9000” non-person entities…and we may not even know that they aren’t human, but synthetic or deepfake identities.

Despite the benefits of remote interactions—they’ve kept me (and my former coworker) employed—Stoll’s warnings about this new world remain valid.

Wrong but right

So I wouldn’t laugh at Stoll’s derision over the emerging Internet. If you were alive in 1995, be honest: did you anticipate THIS?