
GoDaddy Introduces Trusted Naming System for AI Agents
Artificial intelligence agents are multiplying at breakneck speed. Analysts estimate that more than one billion will be deployed by businesses alone within three years. As these agents begin to talk to each other, a serious problem comes into focus: how do we know which ones are legitimate and which ones are impostors? Until now, there has been no common system for proving identity or guaranteeing safe exchanges between agents.
A Familiar Playbook for a New Challenge
GoDaddy, long recognized for its work in domains, DNS (Domain Name System), and SSL (Secure Sockets Layer) certificates, believes it has the answer. The company has announced a trusted identity naming system for AI agents. The idea is simple but significant: create a standard that lets anyone easily find, verify, and trust an agent before interacting with it. This draws directly on GoDaddy’s decades of experience providing digital trust for the internet’s infrastructure.
Travis Muhlestein, CTO of Product & AI at GoDaddy, compared today’s AI boom to the early internet’s “Wild West.” Back then, the challenge was keeping websites safe from fraud. Now the challenge is securing the agents making decisions and performing tasks on behalf of humans and businesses. The difference is that the stakes are higher—agents aren’t just publishing information, they are actively engaging in transactions and communications.
Learning from Internet History
There are striking similarities between today’s AI concerns and past battles over internet trust. In the late 1990s and early 2000s, SSL certificates were optional. Many websites operated without them, leaving users vulnerable to phishing or identity theft. Over time, SSL became the norm, and browsers now flag any site that fails to use it. A similar evolution may be underway with AI agent identity. What feels optional today could become mandatory tomorrow.
Another parallel can be drawn from DNSSEC (Domain Name System Security Extensions), introduced to prevent DNS spoofing. Adoption was slow, but it eventually provided a necessary layer of trust. GoDaddy’s AI naming system borrows from those same lessons, building an identity layer before malicious actors gain too much ground.
How the System Works
The technical model centers on an Agent Name Service (ANS), drawing inspiration from long-established internet standards. It provides a report on every enrolled agent, verifying its identity, confirming its good standing, and recording its operational location. That means an AI agent has to pass through a structured process before it can be trusted.
Discovery Through Domains and DNS
Agents receive human-readable names, much like websites. These names connect to endpoints and metadata, creating a directory where agents can be found and verified.
Cryptographic Identity with X.509 Certificates
Each agent is issued certificates through public key infrastructure (PKI). Operators enroll, renew, and manage these certificates through recognized authorities, providing cryptographic proof that the agent is legitimate. Think of it as a digital passport: without one, the agent cannot cross the border into trusted interactions.
Protocol-Agnostic Adapters
The system includes adapters that translate agent records into formats used across popular frameworks. This prevents vendor lock-in and ensures interoperability between different platforms.
Lifecycle Management
Agents are not static. They must be renewed, updated, or revoked. The system supports this with registration flows, renewal processes, and revocation safeguards—much like how SSL certificates work today. If an agent goes rogue, its certificate can be pulled, cutting off its access.
What Happens Without Verification
Without verification, the risks multiply. Picture a fraudulent agent posing as a customer service bot for a bank, collecting account numbers and passwords. Or an unverified healthcare agent giving patients harmful advice. The possibility of impersonation looms large, and the cost of failure is measured not in inconvenience but in real financial loss and safety risks.
We have seen this story before with email. A lack of identity checks created decades of phishing scams, spam, and malware-laden attachments. GoDaddy’s framework is an attempt to prevent AI from repeating email’s mistakes.
Industry Impact
The ripple effect could be huge. Banks could deploy trusted agents for fraud detection and client services. E-commerce sites might rely on them for secure transactions. Healthcare organizations could use verified agents to deliver accurate information without fear of manipulation. Trust becomes a prerequisite for adoption in all of these cases.
Governments may also take interest. The EU’s AI Act and recent U.S. executive orders already signal a push for regulatory guardrails. GoDaddy’s move could become a baseline for compliance, making it easier for companies to demonstrate they are handling AI responsibly.
Competition and Positioning
Other players in tech are exploring different trust models for AI. Google, Microsoft, and open-source frameworks have all flagged verification as a priority. Yet GoDaddy has an advantage: it already manages one of the most recognizable trust layers online through domains and SSL. That gives the company credibility where newer entrants may need to prove themselves.
Adoption Challenges
Convincing developers to register agents will not be easy. Some may see it as another hoop to jump through, slowing down experimentation. There are also questions about scale. Can one billion agents really be tracked, updated, and managed without bottlenecks? These are open questions that will only be answered through testing and widespread adoption.
Standards and Industry Participation
GoDaddy isn’t building this in isolation. The company is collaborating with the Internet Engineering Task Force (IETF) and other standards bodies to align its service with industry efforts. By grounding the framework in open standards, the company hopes to encourage wide adoption across both commercial and open-source ecosystems. This reduces the risk of fragmentation and creates a baseline of trust that anyone can plug into.
Voices from the Field
Cybersecurity experts have long argued that identity is the Achilles’ heel of AI systems. Without it, every conversation between agents is vulnerable to manipulation. AI ethicists have also pointed out that without identity, accountability is impossible. If an agent makes a bad decision, who is responsible—the agent, its creator, or the organization that deployed it? Verification doesn’t answer every question, but it sets the stage for accountability to exist.
Future Outlook
Looking ahead, it’s easy to imagine a world where trusted AI agents handle everyday tasks. A verified grocery-ordering agent could safely connect to a retailer’s system without the risk of fraud. A verified travel agent could book your flights without rerouting your credit card details to a scammer. These may sound like simple conveniences today, but trust in the background is what makes them possible.
The broader question is whether this framework becomes universal or fragmented. Domain names eventually coalesced under ICANN and became centralized. Messaging, on the other hand, remains split between SMS, WhatsApp, Signal, and dozens of others. The AI identity layer could swing either way—standardized or fractured.
Next Steps
Developers will be the first to gain access through a preview program in the coming weeks. Broader availability will follow once testing and feedback are incorporated. Companies that want to stay ahead of the curve can already sign up for updates and prepare to integrate the system once it moves into general release.
AI agents are multiplying, and with them, the risk of fraud and abuse. GoDaddy’s trusted identity system is not a silver bullet, but it represents a foundational step toward securing agent-to-agent interactions. By blending proven methods from internet security with new protocols for AI, GoDaddy is trying to do for agents what it once did for websites: make them findable, verifiable, and trustworthy. If history is any guide, this type of infrastructure tends to stick around. Businesses and users alike may soon take it for granted that every agent has a name and an identity that can be checked.