Key Points
Know Your Agent: IBM and THG partner to bring verifiable AI agent identity to IBM Cloud Catalog via Hedera. The first commercial Hedera-based enterprise app on a major cloud marketplace.
▶ On September 23, 2026, The Hashgraph Group (THG) and IBM announced a global partnership: IDTrust and THG’s self-sovereign AI agent identity platform and is now listed on the IBM Cloud Catalog as a purchasable SaaS product.
▶ IDTrust is described as the first commercial Hedera-based enterprise application available directly on a major cloud marketplace, giving IBM’s global client base access to Hedera-anchored identity infrastructure through existing IBM Cloud spending commitments.
▶ The Know Your Agent (KYA) concept is the business driver: as AI agents negotiate contracts, process transactions, and execute workflows autonomously, enterprises need to verify which agent is authorised to act on whose behalf and a problem identity-on-blockchain is designed to solve.
▶ Gartner projects 40% of enterprise applications will embed task-specific AI agents by end of 2026, up from under 5% in 2025. That growth creates an urgent identity verification gap IDTrust is positioned to fill.
▶ THG also achieved IBM Silver Partner status and signed a global Embedded Solution Agreement (ESA) allowing IBM technology to be embedded directly in THG’s products.
▶ IDTrust is already live: deployed with a leading European telecoms operator for verified caller identity. It uses W3C standards, DIDs, and Verifiable Credentials, and integrates with IBM watsonx Orchestrate via MCP servers.
When an AI agent books a flight, transfers funds, or signs a contract on your behalf, how does the counterparty know the agent is actually authorised to do that? That is the Know Your Agent problem, and it is moving from a theoretical concern to an enterprise priority faster than most enterprise security teams expected. On September 23, 2026, IBM and The Hashgraph Group (THG) announced they had signed a global partnership to address exactly this problem: IDTrust, THG’s self-sovereign identity platform for AI agents, is now listed on the IBM Cloud Catalog as a purchasable SaaS product.
The listing makes IDTrust the first commercial Hedera-based enterprise application available directly on a major cloud marketplace. For Hedera Hashgraph, whose Governing Council has included IBM since 2019, this represents a significant distribution milestone: enterprise clients can now access Hedera-anchored identity infrastructure through their existing IBM Cloud spending commitments without a separate procurement process. For THG, a Swiss-based Web3 and AI engineering company, the IBM Cloud Catalog listing places its product in front of IBM’s global enterprise client base in a way that direct sales alone could not achieve.
The timing is not accidental. Gartner projects that 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from under 5% in 2025. In June 2026, Akamai launched its own agent verification framework with Visa and Experian as partners. The “Know Your Agent” concept is crystallising into a category, and IBM’s marketplace validation of IDTrust is a significant signal of where enterprise blockchain identity is headed.
What Is Know Your Agent (KYA) and Why Does It Matter?
The KYA problem explained
KYC (Know Your Customer) is the identity verification process banks and exchanges use to confirm who they are dealing with. KYA (Know Your Agent) is the AI-age equivalent: verifying the identity of an autonomous AI agent and confirming it is authorised to act on behalf of the organisation or individual it claims to represent. An AI agent that can negotiate a contract on your behalf looks identical to a rogue agent impersonating your system unless there is verifiable identity infrastructure in place. As AI agents gain the ability to execute financial transactions, sign documents, and make commitments autonomously, the absence of KYA infrastructure becomes a material security and compliance risk.
The problem has three dimensions. First, authentication: is this AI agent who it claims to be? Second, authorisation: is this agent permitted to do what it is trying to do? Third, auditability: can you prove, after the fact, that a specific authorised agent took a specific action? Traditional identity systems built for human users do not address any of these three for autonomous software agents. A password or API key tells you a system has access; it does not create a verifiable, tamper-evident record of which agent acted with which permissions at which moment.
IDTrust addresses all three. It gives AI agents, devices, and humans Decentralised Identifiers (DIDs) and Verifiable Credentials (VCs) anchored on the Hedera distributed ledger. Each credential is cryptographically signed and tamper-evident. Verification does not require a central authority and the Hedera ledger provides the ground truth. The platform includes MCP servers that allow AI agents connected to IBM watsonx Orchestrate to obtain identity credentials so that every authorisation and action taken by an AI agent remains auditable.
What Is IDTrust and How Is It Already Being Used?
IDTrust is THG’s self-sovereign identity (SSI) platform. “Self-sovereign” means the identity subject, in this case an AI agent, device, or human, holds its own credentials rather than relying on a centralised identity provider. The platform is built on W3C open standards for DIDs and Verifiable Credentials and designed to support the EU eIDAS 2.0 framework, the European Union’s regulation governing electronic identification and trust services. It also has a documented path to post-quantum cryptographic security as the standards mature.
IDTrust is not just announced: it is already in production. THG confirmed the platform is deployed with a leading European telecoms operator for verified caller identity and verifying the identity of calls before they connect, addressing the AI voice impersonation and robocall problem at infrastructure level. The telecoms deployment demonstrates that the platform handles high-volume, real-time identity verification at operational scale, not just in a controlled pilot environment. The operator was not named.
IDTrust: How It Works for AI Agents
AI agent receives a Decentralised Identifier (DID)
Each AI agent is assigned a unique DID anchored on Hedera’s distributed ledger. This identifier is cryptographically tied to the agent and cannot be forged or transferred without detection.
Agent obtains Verifiable Credentials (VCs)
The organisation deploying the agent issues it Verifiable Credentials defining its permissions: what it can do, on whose behalf, and in what contexts. Credentials are cryptographically signed and tamper-evident.
Agent presents credentials when acting
When an AI agent initiates an action, it presents its DID and relevant credentials to the counterparty or system. No central authority needs to be queried and verification is done against the Hedera ledger directly.
Every action is anchored on Hedera
Each authorised action creates a permanent, tamper-evident record on Hedera’s ledger. The audit trail is immutable: you can always prove which agent took which action with which permissions.
IBM watsonx Orchestrate integration
Via MCP servers, AI agents running in IBM’s watsonx Orchestrate environment can access IDTrust to obtain and present identity credentials as part of their normal workflow orchestration.
Source: THG IDTrust product documentation, THG-IBM press release September 23 2026 | @cryptonewsbytes
What Is Hedera and Why Does IBM Cloud Distribution Matter?
Hedera Hashgraph is a public distributed ledger that uses a directed acyclic graph (DAG) consensus mechanism called Hashgraph rather than a traditional blockchain chain structure. It is governed by the Hedera Governing Council and a group of large enterprises and institutions including IBM, Google, Boeing, Deutsche Telekom, Deutsche Bank, and others who collectively control the network’s direction. IBM has been a Governing Council member since 2019.
For enterprise clients, the Hedera-IBM relationship matters in a specific way: IBM clients who have existing cloud spending commitments with IBM can now procure IDTrust through those commitments rather than through a separate vendor relationship. This reduces one of the most significant friction points in enterprise blockchain adoption. Getting a new vendor approved, procured, and integrated in a large enterprise can take 12-18 months. Getting an additional product through an existing IBM Cloud relationship is significantly faster.
The IBM Cloud Catalog listing also signals technical validation. IBM Cloud Catalog products go through a review process before listing. THG achieving IBM Silver Partner status and signing an Embedded Solution Agreement (ESA) means IBM has reviewed the product to a standard required for commercial availability through its marketplace. That is not the same as IBM endorsing IDTrust’s business claims, but it does mean the product met IBM’s technical and commercial standards for marketplace listing.
THG’s Enterprise Momentum: Merck, PwC, Teleport, and Now IBM
The IBM partnership is the highest-profile announcement in what has been a significant run of enterprise deployments for THG. In the past 12 months, the company has announced partnerships with Merck Group on EU Digital Product Passports using its TrackTrace platform; with PwC in carbon markets using its EcoGuard digital carbon market infrastructure for the compliant issuance, trading, and retirement of carbon credits; and with Teleport and described as operating the largest air freight network in Southeast Asia and to build an AI-driven Digital Customs Documentation System for cross-border e-commerce trade.
Across all of these deployments, THG’s Hashgraph for Enterprise (H4E)® product suite is the underlying technology. IDTrust, TrackTrace, EcoGuard, BrandBoost, AssetGuard, TransAct, and HashCare all sit within this suite. The IBM partnership specifically advances IDTrust, but it also increases THG’s credibility as an enterprise Hedera integrator across all of these product lines. IBM Silver Partner status and ESA access means THG can embed IBM’s AI and cloud technology directly into its own products and sell a combined solution to enterprise clients.
Why Does This Matter for the Broader Blockchain and Crypto Industry?
Most coverage of this partnership will focus on the AI angle and and that is correct, the KYA problem is primarily an AI governance story. But the blockchain dimension matters equally for CNB’s audience. IDTrust anchors every credential on Hedera’s distributed ledger. The audit trail is not in a database IBM controls. It is on a public distributed ledger that IBM helps govern through Council membership but cannot unilaterally modify.
This is the enterprise blockchain value proposition executed correctly: not “we put this in a private database we call blockchain,” but a genuinely distributed ledger where the identity records are tamper-evident because they are anchored in a system no single party controls. For Hedera specifically, this is a significant commercial milestone. Enterprise adoption of Hedera has historically happened through the Governing Council relationships rather than through developer community growth. IBM Cloud Catalog access means enterprise developers can find and use Hedera-anchored products without being aware they are using Hedera, which is exactly the kind of embedded adoption that creates durable infrastructure usage.
The broader trend this fits: the Blockchain Patents in 2026 article CNB published this week identified identity and credential management as one of the fastest-growing enterprise blockchain patent categories, alongside ZK proof systems and cross-chain settlement mechanics. THG and IBM bringing a live, commercial, marketplace-listed enterprise identity product to market is the commercial reality that the patent activity was signalling.
Who Else Is Working on Know Your Agent Infrastructure?
In practice, THG and IBM are not alone in identifying KYA as an enterprise priority. Akamai launched its own Agentic Security Framework in June 2026 with Visa and Experian as partners, covering agent authentication and risk scoring for agentic commerce. The W3C, whose DID and Verifiable Credentials standards IDTrust is built on, has multiple working groups active on agent identity. NIST published initial guidance on AI agent security in Q1 2026. The EU AI Act, which came into full force in 2026, creates compliance requirements around automated decision-making that agent identity infrastructure directly serves.
The Know Your Agent Infrastructure Landscape (September 2026)
| Player | Approach | Key Partners | Ledger |
|---|---|---|---|
| THG IDTrust | SSI platform with DIDs and VCs for AI agents and humans | IBM, Merck, PwC, Teleport, EU Telecoms operator | Hedera Hashgraph |
| Akamai Agentic Security | Risk scoring and authentication for agentic commerce | Visa, Experian | Centralised API-based |
| Midnight (Cardano) | Private AI agents with ZK + TEE + MPC privacy | IOG, enterprise partners TBA | Cardano sidechain |
| Microsoft Azure | Entra ID extension for AI agent identity (preview) | GitHub Copilot, Azure OpenAI | Azure-internal |
| W3C DID / VC Working Groups | Open standards for decentralised identity | All of the above build on these | Any blockchain |
Sources: Akamai newsroom June 2026, W3C working group documentation, Hoskinson September 28 2026 (Midnight private agents), THG-IBM press release | @cryptonewsbytes. Not investment advice.
Frequently Asked Questions
What is Know Your Agent (KYA)?
Know Your Agent (KYA) is the process of verifying the identity and authorisation of an autonomous AI agent before allowing it to act. As AI agents gain the ability to negotiate contracts, execute financial transactions, and take actions on behalf of organisations autonomously, the question of how counterparties verify an agent’s identity and confirm it is authorised to act becomes critical. KYA is the AI-era equivalent of KYC (Know Your Customer).
What is IDTrust and what does it do?
IDTrust is The Hashgraph Group’s self-sovereign identity platform for AI agents, devices, and humans. It assigns Decentralised Identifiers (DIDs) anchored on Hedera’s distributed ledger and issues Verifiable Credentials (VCs) that cryptographically define an agent’s permissions. Every action taken by an IDTrust-credentialed agent creates a tamper-evident audit record on Hedera. It is already deployed with a leading European telecoms operator for verified caller identity and integrates with IBM watsonx Orchestrate via MCP servers.
Why is the IBM Cloud Catalog listing significant?
IBM Cloud Catalog listing makes IDTrust the first commercial Hedera-based enterprise application purchasable on a major cloud marketplace. Enterprise clients with existing IBM Cloud spending commitments can procure IDTrust through those commitments, reducing the procurement friction that has historically slowed enterprise blockchain adoption. IBM listing also represents a technical validation: IBM Cloud Catalog products go through a review process before listing.
What is Hedera Hashgraph?
Hedera Hashgraph is a public distributed ledger governed by the Hedera Governing Council, a group of large enterprises including IBM (since 2019), Google, Boeing, Deutsche Telekom, and Deutsche Bank. It uses a directed acyclic graph consensus mechanism (Hashgraph) rather than a traditional blockchain chain structure. IDTrust anchors its identity credentials on Hedera’s ledger, creating tamper-evident records that no single party controls.
How does IDTrust integrate with IBM’s AI systems?
IDTrust integrates with IBM watsonx Orchestrate via MCP servers. AI agents running in IBM’s watsonx Orchestrate environment can access IDTrust to obtain identity credentials, allowing every authorisation and action taken by an agent in the watsonx ecosystem to be verifiable and auditable. This integration is what makes IDTrust practically useful within IBM’s existing enterprise AI deployments rather than requiring a separate identity infrastructure.
What other enterprise deployments does THG have?
THG has enterprise partnerships with Merck Group (EU Digital Product Passports using TrackTrace), PwC (carbon credit issuance, trading, and retirement using EcoGuard), and Teleport (AI-driven Digital Customs Documentation System for Southeast Asian cross-border e-commerce). All deployments use THG’s Hashgraph for Enterprise (H4E)® product suite. The IBM partnership is the largest commercial distribution milestone in the company’s history.
Further Reading
Identity and credential management is one of the fastest-growing enterprise blockchain patent categories in 2026. The THG-IBM IDTrust listing represents the commercial product that the patent activity was signalling.
Hoskinson’s Midnight is also building private AI agent infrastructure on blockchain. The KYA problem THG and IBM are solving on Hedera is the same category of problem Midnight’s private agents are designed to address on Cardano.
The broader context: blockchain infrastructure moving from tokenization of financial assets into identity, compliance, and agent verification is the next wave of enterprise adoption after the RWA tokenization wave of 2025-2026.
Sources: THG-IBM press release PRNewswire September 23 2026 (primary: all partnership details, quotes, product description, deployment confirmation), Gartner press release August 26 2025 (primary: 40% enterprise apps AI agents by 2026 projection), IBM Cloud Catalog listing confirmation (cloud.ibm.com/catalog, live listing confirmed), Akamai newsroom June 2026 (KYA competitive context: Akamai-Visa-Experian agent verification framework) | Published September 23, 2026 | CryptoNewsBytes.com | Not financial advice.

