All insights
Collage of black silhouetted hands making heart shapes, among computer chips and red stone hearts on a gridded background.

Between the Wild West and the walled garden: how to build a trusted, secure agentic layer

AI agents will soon book appointments, switch energy, broadband and insurance for people. What CSOs, CTOs and CIOs need to settle first is identity, authority and trust. Marino Software has a track record in partnership with enterprise and organisations in regulated sectors. In this post, we look at a near future where people hand everyday admin to AI agents… and the security and trust decisions service providers need to make before they open the door.

Ed Melvin
Chief Strategy Officer

Most of us are overpaying for something right now. Not because we don’t know better. But because switching is tedious. In Ireland, the energy regulator found that only around one in five electricity customers switch supplier, and that someone who switched or renegotiated every year for four years could have saved about €2,500.

Inertia is one of the most powerful forces personal AI agents can counter. The use cases are simple enough: tell an agent you want the cheapest broadband that meets your needs, or the earliest GP appointment this week, and it goes and does the legwork.

A future within reach is one where people trust agents to interact with service providers and book or renew on their behalf, and where service providers are ready for them.

Technically, we can build those experiences. But before anyone opens an agentic API layer to agents… there are major security and trust decisions to make. Getting them wrong creates a breach. Money, personal data, health data, contracts. This kind of work really challenges what software can do, if governance and responsible approaches are built in from the start.

What an agentic layer could actually do for people

These use cases aren’t that exotic. They’re the admin people put off, where the saving is real but the effort feels bigger than the reward. Take two simple examples: once-off bookings, and utility/service renewals.

Use caseWhat the agent doesWhere the saving comes fromWhat’s at stake if it goes wrong
Physio appointmentWatches for a slot and books it within limits you setFewer missed workdays, no out-of-hours feesHealth data shared too widely; wrong patient or clinic
Event ticketsBuys at face value from the official seller when tickets releaseAvoids resale mark-upsNon-refundable spend; looks identical to a scalper
TravelBooks when a fare drops, or files a delay compensation claimFare differences, compensation owedWrong dates or names on a ticket that can’t be changed
BroadbandCompares offers at contract end and switches or renegotiatesAvoids out-of-contract price risesService gap; switching to a plan that doesn’t fit
EnergyChecks tariffs against your usage and switches supplierMoving off standard ratesDirect debit and meter data in the wrong hands
Home, car or health insuranceGathers quotes before renewal, checks cover matches, renews or switchesAvoids paying more for staying putCover gaps; declaring facts incorrectly to an insurer

Every one of these involves an agent holding some combination of identity, payment details and personal data, and making a commitment in someone’s name. Those are major commitments for anyone.

The Wild West and the walled garden

Two models are already out there, but they are early. Too early for normal people.

The Wild West: OpenClaw. OpenClaw is an open-source assistant that runs on your own machine, works from WhatsApp or Telegram, and can browse the web, fill in forms and run commands. Its own users describe it finding appointments and checking them in for flights. It is hugely powerful, and its security record shows what happens when power arrives before guardrails. A WebSocket hijacking flaw (CVE-2026-25253) let any website steal a user’s token and run code on their machine; before the patch, Censys found more than 21,000 instances exposed on the internet. Cisco found a top-ranked community skill quietly sending user data to an external server. The Dutch data protection authority advised organisations not to run experimental agents like it on systems handling sensitive or regulated data.

The walled garden: Muse by Meta. Meta launched Muse in the US on 8 September 2026 as a personal agent that sends emails, books travel, “lowers bills” and makes purchases through Link by Stripe. Meta says it runs in a dedicated secure VM, with a separate Sentinel agent and no visibility of passwords or payment methods. Those are serious design choices. But the trust sits with the platform. And where a service has no API, Muse falls back to driving the browser.

That last detail matters most for service providers. In both models, your customer’s agent is coming to your front end, whether you designed for it or not. It will scrape your pricing pages, fill your forms and click your buttons. There is an opportunity to build this new enablement layer. But it all has to start not with capability, but with security and trust. With hard questions.

Six hard security and trust questions

These are the questions we’d want a CSO, CTO, CIO and innovation lead in the same room to argue about:

  1. Who is calling, please? Today’s identity stack was built to tell humans from bots. An agentic layer needs to know three things at once: which agent, acting for which verified person, under which platform. The card networks are already moving here, with Visa’s Trusted Agent Protocol and Mastercard’s Agentic Tokens binding a credential to a specific agent and merchant scope. The question: do you only accept certified agents, which favours walled gardens, or do you accept any agent that proves who it acts for?

  2. What exactly has the person authorised? “Find me cheaper broadband” is not the same as “sign a 24-month contract.” Google’s Agent Payments Protocol (AP2) uses signed mandates to separate intent, cart and payment. Your layer needs the same idea: scoped, time-limited, value-capped authority you can check on every call. The question: how granular can consent get, before the convenience of using an agent is eliminated?

  3. Can the agent be talked into something? Prompt injection remains unsolved; OpenClaw’s own team calls it an industry-wide problem. If your API returns marketing copy or terms in free text, that text becomes input to someone else’s model. Return structured data, not prose an agent might treat as instructions. The question: is the service provider responsible for content that manipulates a visiting agent?

  4. Which actions need a human? An energy switch has a cooling-off period. A non-refundable concert ticket doesn’t. Maybe the solution is a variation of “human in the loop”: tiering actions by reversibility, and requiring a human confirmation step, such as strong customer authentication, for anything that can’t be undone. The question: if every meaningful action needs a human tap, is it still an agent?

  5. How little data can the agent see? Booking time with a healthcare professional shouldn’t require sharing a medical history. Health data is special category data under GDPR, and an agent’s memory is a new place for it to leak from. Design endpoints around the minimum each task needs. The question: who is the data controller when a consumer’s agent holds your data?

  6. Can you tell a customer’s agent from a scalper’s? The API that lets a fan buy a face-value ticket at 9am also lets a reseller buy 400. Quotas tied to verified people, not API keys, are the difference. The question: where does rate-limiting end and discrimination against agent users begin?

Software, Made Human

It’s easy to frame all of this as a security problem to be contained. We think it’s a design problem to be solved. With people at the centre of it.

The point of an agent saving someone a few hundred euro on their energy bill is that a real person gets time back and is liberated from a needless cognitive load. That only works if they can see what their agent agreed to, change their mind where the law allows it, and trust that the service on the other side treated their agent the way it would treat them. Security that makes that possible isn’t a brake on the experience - it is what enables the experience.

That’s what we mean by Software, Made Human. The wild west gives people power without protection. The walled garden gives them protection on someone else’s terms. There’s room for a third option: service providers building their own trusted agentic layer, with identity, authority, limits and evidence designed in from the start.

We can help organisations build that. And for the evidence piece, a verifiable record of what every agent asked for, was allowed to do and actually did, that’s exactly what Evident, Marino Software’s platform for auditable agentic decisioning, was built for.

At Marino Software, we help high-compliance clients to both deal with the here-and-now, and to look ahead. We would rather ground our advice in the honesty of the messy reality, than plan for a perfect future. Get in touch if you’d like to learn more about how Marino Software can work with you as a technology partner. FYI you’ll speak to a human, not an agent (for now).

Switcher.ie (previously Choosy.ie, a comparison application built by Marino Software)

CRU via Echo Live, “Only 1 in 5 switch energy supplier as watchdog says over a million people miss out on savings” (Dec 2025): https://www.echolive.ie/nationalnews/arid-41758277.html

OpenClaw: https://openclaw.ai/

Agentic Commerce Protocol from Stripe https://www.agenticcommerce.dev/

TechRadar, “Here are the OpenClaw security risks you should know about” (Apr 2026): https://www.techradar.com/pro/here-are-the-openclaw-security-risks-you-should-know-about

Meta, Muse: https://ai.meta.com/muse/

TechCrunch, “Meta debuts its Muse AI agent. Will consumers trust it?” (Sep 2026): https://techcrunch.com/2026/09/08/meta-debuts-its-muse-ai-agent-will-consumers-trust-it/

Eco, “Mastercard Agent Pay vs Visa Trusted Agent, 2026 compared”: https://eco.com/support/en/articles/15192003-mastercard-agent-pay-vs-visa-trusted-agent-2026-compared

Eco, “AP2 protocol explained”: https://eco.com/support/en/articles/15192002-ap2-protocol-explained-google-s-agentic-commerce-standard-2026

Hero image: The intimacy factory 2 by Jenny Kidd & Synthetic Pasts, via Better Images of AI. Licensed under CC BY 4.0. Cropped.

Let's talk.

Remote, on-site, or in Glasnevin, Dublin. We start with your customer and work back. You'll leave with a clearer picture of the next move, whether or not it's with us.