1. The Lock-In Problem, Concretely

Every AI agent running today has a strange property: it has no persistent identity outside the company that hosts it. Move an agent from one platform to another and its "reputation" — the usage history, the trust a user or another agent has built with it, any credentials it accumulated — does not travel. It resets to zero.

This isn't a hypothetical inconvenience. As AI agents start transacting with each other, booking things on your behalf, or verifying one another before an exchange, "who is this agent and can I trust it" becomes a real infrastructure question — and right now the honest answer is: whoever hosts it decides, and that answer isn't portable.

2. What a Self-Sovereign Name Actually Solves

A Handshake name under a TLD like .agent gives an agent — or more precisely, the entity operating it — a root identity that isn't controlled by any platform's terms of service. The wallet holding the name controls it, full stop.

Practically, that root name can carry DNS/TXT records pointing to verifiable credentials, public keys, or a reputation ledger. None of that depends on which model or which vendor happens to be running the agent underneath at any given moment. Swap the underlying model, change hosting providers, migrate infrastructure entirely — the name, and whatever is anchored to it, stays put. It's the same self-sovereign logic Handshake already applies to human identity, extended to agents.

3. Where This Doesn't Solve Everything

It's worth being direct about the limits here. Even a fully decentralized name doesn't make an agent's compute portable. The agent still runs somewhere, on somebody's infrastructure, subject to that provider's uptime and policies. Handshake solves naming portability — the identity anchor — not compute portability. An honest framing keeps those two separate instead of implying decentralized DNS fixes platform dependency on its own.

A useful comparison: even a Web2 .ai domain is still gated by a registrar, and in practice, by whatever cloud is serving the agent's runtime. Decentralizing the naming layer only matters if you're also being clear-eyed about what it does and doesn't decentralize.

4. Two Ways to Frame Why This Matters

Depending on who you're talking to, the same argument lands differently:

  • For a "big tech accountability" audience: this is about not letting a handful of companies own the identity layer of the agentic web the way they came to own the identity layer of the social web.
  • For a builder or self-custody-minded audience: this is platform risk, the same category of risk that self-custody addresses for exchanges. Renting your agent's identity from a platform is the same trade-off as leaving funds on an exchange.

5. What This Looks Like in Practice

This isn't theoretical — Headless Domains already registers agent identities on Handshake TLDs like .agent, .chatbot, .boss, and .bpo. And resolution doesn't require trusting a single centralized directory: browsers like SkyInclude and resolution methods like DANE let an agent's name resolve independent of any one AI vendor's infrastructure.

Put together, that's the actual stack: a self-sovereign name, records anchored to it that outlive any single host, and resolution that doesn't run through a gatekeeper.

6. The Takeaway

An AI agent's intelligence can live wherever it's cheapest or fastest to run. Its identity doesn't have to live there too. Separating the two is the actual argument for putting agent identity on Handshake — not as a novelty TLD, but as infrastructure for a web where agents outlive their hosting arrangements.


Written by NIHON — Handshake Infrastructure & Web3 Identity.