The Last Moat: Identity Remains the Internet’s Unfinished Problem

In this article, Simon Jones, CEO at Sumvin, discusses the problem of identity as the missing layer of the internet.

The Last Moat: Identity Remains the Internet’s Unfinished Problem

The internet was designed without three things it needed: native money, native private keys, and native identity. We have spent thirty years building elaborate workarounds for all three. Card networks for money. Passwords for keys. Cookies for identity. Each is inelegant, each leaks, and each was built for a narrower problem than the modern web actually has. The whole stack works only because we have agreed not to notice the friction it generates: the abandoned carts, the password resets, the one-time passcodes, the hours of comparison shopping that produce only meager conversion rates.

The internet adapted around these gaps so successfully that most users stopped noticing them. But the workarounds are starting to fail under the weight of modern commerce, AI agents, fraud pressure, and rising expectations around convenience. Identity, in particular, remains strangely unresolved: the internet still treats every interaction as if it is happening between strangers.

The web was built to remember sessions, not humans 

Cookies were a brilliant solution to a problem nobody has anymore: they helped websites remember browsers, but never truly understood who was behind them. Advertisers extracted age, approximate gender, location, and a browsing graph that gets noisier as browsers strip third-party cookies and regulators tighten consent rules. The ceiling on what a cookie can know about you is low and getting lower.

Are you the same human who shopped here three months ago? Are you good for the order? Do you live where you say you live? Are you over 18? Cookies do not answer any of these. Logins answer some, but only after you have provided an email, created a password, and re-entered your card. Many drop-offs in e-commerce occur during the onboarding sequence, and it remains the dominant pattern because nothing better exists.

What changes when identity becomes portable

For decades, high-trust identity verification existed mostly inside regulated finance because that was where the incentives were strongest. But there is little reason the same standard should stop at banks and exchanges. A portable, verified credential could fundamentally change how people move through the wider internet: proving only what needs to be proven, skipping repetitive onboarding, and turning identity into something the user carries rather than something every platform rebuilds from scratch.

The conceptual model is simple. Your agent carries a verified credential that is cryptographically signed and presentable to any merchant that accepts it. The merchant no longer has to rebuild trust from scratch at every interaction. Instead of asking the user to repeat the same information again and again, they can request only the verified attributes needed for that moment, whether that is age, address, eligibility, payment ownership, or identity. The user stays in control of what is shared, while the merchant reduces duplicate data collection and unnecessary friction. The relationship shifts from platforms storing more consumer data than they need to a model where trust is carried by the user and shared selectively.

The bot problem, changed by the credential layer 

Every network service faces the same fundamental question at every interaction: Is this a real user or a bot? The status quo today is adversarial, and it is getting worse rather than better. As firewall providers tighten controls on bot traffic, it is the real user who pays the price: more CAPTCHAs, more OTPs, shorter session IDs, more frequent logins, more "are you human" checks at every turn. Every consumer platform spends a meaningful share of its engineering budget fighting traffic that should never have arrived, and degrades the experience of its actual customers in the process. Cheap, capable AI agents further accelerate the problem; the cost of generating plausible activity has collapsed.

A verified identity layer changes the economics. A bot does not have KYC credentials; it cannot meet the standards required by a tier-one bank. Verification stops being a reactive battle fought after the bot arrives and becomes a precondition ahead of arrival.

The benefit is multi-sided. It reduces reliance on CAPTCHAs, OTPs, and repeated human checks for trusted users. Merchants get traffic worth converting, along with a sharp reduction in chargebacks and trust-and-safety overhead. Network operators get cleaner data and better unit economics. AI agents acting legitimately benefit too, because they can be recognized as authorized parties rather than treated as threats by default. Every participant is net better off the moment the step is enabled, which is the test that any genuinely new piece of infrastructure should pass.

Four ordinary tasks, reimagined

The interesting part is not any single use case. It is how many ordinary online interactions start to change once identity becomes portable and reusable.

Think about onboarding into anything new: a bank, subscription service, exchange, healthcare provider, or airline loyalty program. The current state is often a 40-minute exercise in retyping data that the internet already knows about you. A portable verified credential collapses that process from a forty-minute exercise into something much closer to account continuity than account creation. The same logic extends to onboarding.

Consider how people shop online today. Finding the cheapest legitimate version of a product can take 20 minutes to several hours of searching, comparing, checking ratings, and starting over when a cart is abandoned. With a verified agent acting on your behalf, this collapses to a single instruction. The agent queries the market, presents the best price, executes the purchase, and requests delivery to your verified address. The hours you used to spend browsing are gone. This is the cleanest use case for AI in consumer commerce: a long, repetitive task collapsed into intent and execution.

Once identity becomes persistent rather than session-based, even the structure of storefronts starts to change. Most websites greet every visitor identically: they cannot ask too much without losing the user, so they ask nothing and serve the average. With a verified identity presented at the door, the site can be entirely different the moment you arrive. The homepage is your homepage. The catalog is filtered by your size, budget, and previous purchases. Recommendations are grounded in real data that the merchant has been authorized to see. The closest analog is walking into a small shop where the owner knows you. The internet has never been able to do this at scale; now it can.

The same applies to financial decisions that currently begin with uncertainty. Entire categories of “apply and wait” interactions—credit, insurance, rentals, mortgages—become fundamentally different. You submit a long form and wait for a decision that may be a decline. With a verified credential, the provider runs the eligibility check in advance and greets you by name with the products you qualify for. No surprise declines. No fifteen parallel forms. You see the real offer first, then you choose.

How solving identity threads everything else

The four use cases I’ve outlined above look like separate products, but they run on the same primitive. Solve the identity once, and the rest are not features you have to build; they are what follows. Embedded loyalty ceases to be a separate card or app and becomes a property of the customer that any merchant can read and reward. Returns and warranties no longer require receipts; the credential carries the purchase history. Customer service knows who you are the moment a chat opens. Subscriptions travel across providers. Cross-merchant benefits become real because the user holds the loyalty ledger, not the merchant.

This is why identity is worth building as infrastructure rather than as a feature: it unlocks a class of consumer experiences, not a single one. Merchants get higher conversion, lower fraud, and customers they actually know. Consumers get a clearer view of the benefits they are entitled to and a shorter path to using them. Everything that today requires keeping score across a dozen apps, cards, and accounts can sit inside your personal credential.

AI for good: more control with less effort

The central question we should be asking is, does a particular feature give a user back time? If a tool collapses a 40-minute task into ten seconds with the same result, that is an unambiguous win, and the kind that compounds.

A verified-identity layer should therefore be seen as AI for good. It removes the most repetitive, lowest-value activity in the consumer's day and gives back meaningful time per week. The internet has been increasingly demanding of users' attention, particularly since the smartphone and social media era of the last fifteen years; a portable identity is the first piece of infrastructure in a long time whose explicit purpose is to demand less. Users remain in control of what information they share, while platforms can rely on verification standards already trusted in banking and cross-border finance. The goal is to let users prove what they need to prove, once.

Identity as infrastructure

The broader point is not that onboarding gets faster or checkout becomes cleaner, although both matter. It is that the internet begins to behave differently once identity stops being fragmented across thousands of platforms and becomes portable, verifiable, and user-controlled.

This is the direction that Sumvin—working with identity verification providers such as Sumsub—is pushing toward: bringing KYC-grade trust standards into ordinary digital interactions and agentic commerce. The same verification requirements trusted in highly regulated financial activity can form the foundation for smoother online consumer experiences.

For decades, the internet compensated for the absence of a native identity layer with passwords, cookies, repeated onboarding flows, and endless verification loops. That workaround era may finally be nearing its limit. Once identity becomes a reusable infrastructure rather than something rebuilt from scratch at every interaction, many of today’s assumptions about online commerce begin to look temporary. User onboarding, in particular, may have been the last major moat separating intent from execution.