Between the Wild West and the walled garden: how to build a trusted, secure agentic layer
AI agents will soon book appointments, switch energy, broadband and insurance for people. What CSOs, CTOs and CIOs need to settle first is identity, authority and trust. Marino Software has a track record in partnership with enterprise and organisations in regulated sectors. In this post, we look at a near future where people hand everyday admin to AI agents… and the security and trust decisions service providers need to make before they open the door.
Most of us are overpaying for something right now. Not because we don’t know better. But because switching is tedious. In Ireland, the energy regulator found that only around one in five electricity customers switch supplier, and that someone who switched or renegotiated every year for four years could have saved about €2,500.
Inertia is one of the most powerful forces personal AI agents can counter. The use cases are simple enough: tell an agent you want the cheapest broadband that meets your needs, or the earliest GP appointment this week, and it goes and does the legwork.
A future within reach is one where people trust agents to interact with service providers and book or renew on their behalf, and where service providers are ready for them.
Technically, we can build those experiences. But before anyone opens an agentic API layer to agents… there are major security and trust decisions to make. Getting them wrong creates a breach. Money, personal data, health data, contracts. This kind of work really challenges what software can do, if governance and responsible approaches are built in from the start.
What an agentic layer could actually do for people
These use cases aren’t that exotic. They’re the admin people put off, where the saving is real but the effort feels bigger than the reward. Take two simple examples: once-off bookings, and utility/service renewals.
| Use case | What the agent does | Where the saving comes from | What’s at stake if it goes wrong |
|---|---|---|---|
| Physio appointment | Watches for a slot and books it within limits you set | Fewer missed workdays, no out-of-hours fees | Health data shared too widely; wrong patient or clinic |
| Event tickets | Buys at face value from the official seller when tickets release | Avoids resale mark-ups | Non-refundable spend; looks identical to a scalper |
| Travel | Books when a fare drops, or files a delay compensation claim | Fare differences, compensation owed | Wrong dates or names on a ticket that can’t be changed |
| Broadband | Compares offers at contract end and switches or renegotiates | Avoids out-of-contract price rises | Service gap; switching to a plan that doesn’t fit |
| Energy | Checks tariffs against your usage and switches supplier | Moving off standard rates | Direct debit and meter data in the wrong hands |
| Home, car or health insurance | Gathers quotes before renewal, checks cover matches, renews or switches | Avoids paying more for staying put | Cover gaps; declaring facts incorrectly to an insurer |
Every one of these involves an agent holding some combination of identity, payment details and personal data, and making a commitment in someone’s name. Those are major commitments for anyone.
The Wild West and the walled garden
Two models are already out there, but they are early. Too early for normal people.
The Wild West: OpenClaw. OpenClaw is an open-source assistant that runs on your own machine, works from WhatsApp or Telegram, and can browse the web, fill in forms and run commands. Its own users describe it finding appointments and checking them in for flights. It is hugely powerful, and its security record shows what happens when power arrives before guardrails. A WebSocket hijacking flaw (CVE-2026-25253) let any website steal a user’s token and run code on their machine; before the patch, Censys found more than 21,000 instances exposed on the internet. Cisco found a top-ranked community skill quietly sending user data to an external server. The Dutch data protection authority advised organisations not to run experimental agents like it on systems handling sensitive or regulated data.
The walled garden: Muse by Meta. Meta launched Muse in the US on 8 September 2026 as a personal agent that sends emails, books travel, “lowers bills” and makes purchases through Link by Stripe. Meta says it runs in a dedicated secure VM, with a separate Sentinel agent and no visibility of passwords or payment methods. Those are serious design choices. But the trust sits with the platform. And where a service has no API, Muse falls back to driving the browser.
That last detail matters most for service providers. In both models, your customer’s agent is coming to your front end, whether you designed for it or not. It will scrape your pricing pages, fill your forms and click your buttons. There is an opportunity to build this new enablement layer. But it all has to start not with capability, but with security and trust. With hard questions.
Six hard security and trust questions
These are the questions we’d want a CSO, CTO, CIO and innovation lead in the same room to argue about:
-
Who is calling, please? Today’s identity stack was built to tell humans from bots. An agentic layer needs to know three things at once: which agent, acting for which verified person, under which platform. The card networks are already moving here, with Visa’s Trusted Agent Protocol and Mastercard’s Agentic Tokens binding a credential to a specific agent and merchant scope. The question: do you only accept certified agents, which favours walled gardens, or do you accept any agent that proves who it acts for?
-
What exactly has the person authorised? “Find me cheaper broadband” is not the same as “sign a 24-month contract.” Google’s Agent Payments Protocol (AP2) uses signed mandates to separate intent, cart and payment. Your layer needs the same idea: scoped, time-limited, value-capped authority you can check on every call. The question: how granular can consent get, before the convenience of using an agent is eliminated?
-
Can the agent be talked into something? Prompt injection remains unsolved; OpenClaw’s own team calls it an industry-wide problem. If your API returns marketing copy or terms in free text, that text becomes input to someone else’s model. Return structured data, not prose an agent might treat as instructions. The question: is the service provider responsible for content that manipulates a visiting agent?
-
Which actions need a human? An energy switch has a cooling-off period. A non-refundable concert ticket doesn’t. Maybe the solution is a variation of “human in the loop”: tiering actions by reversibility, and requiring a human confirmation step, such as strong customer authentication, for anything that can’t be undone. The question: if every meaningful action needs a human tap, is it still an agent?
-
How little data can the agent see? Booking time with a healthcare professional shouldn’t require sharing a medical history. Health data is special category data under GDPR, and an agent’s memory is a new place for it to leak from. Design endpoints around the minimum each task needs. The question: who is the data controller when a consumer’s agent holds your data?
-
Can you tell a customer’s agent from a scalper’s? The API that lets a fan buy a face-value ticket at 9am also lets a reseller buy 400. Quotas tied to verified people, not API keys, are the difference. The question: where does rate-limiting end and discrimination against agent users begin?
Software, Made Human
It’s easy to frame all of this as a security problem to be contained. We think it’s a design problem to be solved. With people at the centre of it.
The point of an agent saving someone a few hundred euro on their energy bill is that a real person gets time back and is liberated from a needless cognitive load. That only works if they can see what their agent agreed to, change their mind where the law allows it, and trust that the service on the other side treated their agent the way it would treat them. Security that makes that possible isn’t a brake on the experience - it is what enables the experience.
That’s what we mean by Software, Made Human. The wild west gives people power without protection. The walled garden gives them protection on someone else’s terms. There’s room for a third option: service providers building their own trusted agentic layer, with identity, authority, limits and evidence designed in from the start.
We can help organisations build that. And for the evidence piece, a verifiable record of what every agent asked for, was allowed to do and actually did, that’s exactly what Evident, Marino Software’s platform for auditable agentic decisioning, was built for.
At Marino Software, we help high-compliance clients to both deal with the here-and-now, and to look ahead. We would rather ground our advice in the honesty of the messy reality, than plan for a perfect future. Get in touch if you’d like to learn more about how Marino Software can work with you as a technology partner. FYI you’ll speak to a human, not an agent (for now).
Sources & further links
Switcher.ie (previously Choosy.ie, a comparison application built by Marino Software)
CRU via Echo Live, “Only 1 in 5 switch energy supplier as watchdog says over a million people miss out on savings” (Dec 2025): https://www.echolive.ie/nationalnews/arid-41758277.html
OpenClaw: https://openclaw.ai/
Agentic Commerce Protocol from Stripe https://www.agenticcommerce.dev/
TechRadar, “Here are the OpenClaw security risks you should know about” (Apr 2026): https://www.techradar.com/pro/here-are-the-openclaw-security-risks-you-should-know-about
Meta, Muse: https://ai.meta.com/muse/
TechCrunch, “Meta debuts its Muse AI agent. Will consumers trust it?” (Sep 2026): https://techcrunch.com/2026/09/08/meta-debuts-its-muse-ai-agent-will-consumers-trust-it/
Eco, “Mastercard Agent Pay vs Visa Trusted Agent, 2026 compared”: https://eco.com/support/en/articles/15192003-mastercard-agent-pay-vs-visa-trusted-agent-2026-compared
Eco, “AP2 protocol explained”: https://eco.com/support/en/articles/15192002-ap2-protocol-explained-google-s-agentic-commerce-standard-2026
Hero image: The intimacy factory 2 by Jenny Kidd & Synthetic Pasts, via Better Images of AI. Licensed under CC BY 4.0. Cropped.
Keep reading
More insights.
The board wants AI governance evidence by Friday. Can you produce it?
Marino Software has a track record in partnership with enterprise and organisations in regulated sectors. This is the second post in our AI governance scenarios series - where we look at the pressure points AI is creating inside organisations, and what real and workable answers look like.
Ed Melvin ·
How many AI tools are actually running in your organisation?
Marino Software has a track record in partnership with enterprise and organisations in regulated sectors. In this new blog post series, we are addressing some of the pain points we are designing for, in a new world where unsanctioned use of AI is outpacing organisational policy and capability, with huge implications.
Ed Melvin ·
Right & ready first time with Peregrine from Marino Software
Point-in-time penetration testing can't keep pace with infrastructure that changes daily. Peregrine, Marino's continuous pen-testing platform, catches exposures as they appear, opens the fix and reruns the test, so the annual test confirms a secure system instead of surprising you.
Ed Melvin ·