
What Comes After the Cookie? Notes from Identity Week America 2026
9 min read
Lance Ennen
Share:
I was back in Washington, D.C. this week for Identity Week America 2026, held at the Walter E. Washington Convention Center.
Identity Week has some history for me. Several years ago, when Sebastian Mellen and I were starting Cerebrum, we were invited to exhibit and set up a startup booth. It was my first time attending. I later went to Identity Week Europe in Amsterdam, so returning to Washington gave me a useful opportunity to see how the conversation has changed.
The exhibition floor felt more compact than it did on those earlier visits. I do not know whether that reflected the layout, the mix of attendees, or something else, and I would not draw a broad conclusion from a single floor plan. What I can say is that the event still brings together an unusual cross-section of government identity programs, biometrics, secure documents, fraud prevention, digital wallets, open standards, established vendors, and startups.
For an early-stage company, that concentration still has real value. You can demonstrate a product, get immediate feedback, meet people working on standards, and compare what the market is discussing with what customers are actually trying to solve.
Agents were everywhere
The theme I could not miss this year was AI agents.
Nearly every part of the show found a way to talk about agent identity, non-human identity, agent authorization, human-to-agent delegation, or agent governance. One display promised to "control what humans, workloads and agents can do." Another focused on proving the human behind the AI.
Some companies are clearly doing deep work in this area. Others are still working out what the word agent means for their product. Either way, the underlying question is real:
When software acts for a person or a business, how does a website know who is behind it—and which information it should trust?

The exhibition floor brought together biometrics, physical identity, digital credentials, fraud prevention, and emerging agent technology. Photo by Lance Ennen.

Agent identity and authorization were visible throughout this year's conference. Photo by Lance Ennen.
Why I went to Washington
My main reason for attending was not to count booths. It was to catch up with Kenneth Shek, CEO of Moca Network and Director and Head of Projects at Animoca Brands.
Kenneth appeared in two sessions. On the first day, his presentation was titled "The internet was built for users. The next one is built for users + agents." On the second day, he joined a panel about whether digital wallets can give people more control and help unlock a decentralized future for identity.
On the day, the panelists on stage represented the OpenID Foundation, PayPal, and Moca Network. They discussed wallet adoption, privacy, interoperability, fraud, and the kinds of credentials wallets may eventually carry.
The discussion around business and KYB credentials was especially interesting. Wallets are often described as containers for personal identity documents, but portable business credentials could be just as consequential. A company could prove selected facts about its legal identity, registration, qualifications, or status without restarting the entire verification process in every new relationship.

The digital-wallet panel at Identity Week America 2026. The panelists on stage represented the OpenID Foundation, PayPal, and Moca Network. Photo by Lance Ennen.
Kenneth and I also spent time discussing the latest AIR³ and AIR Kit updates. AIR Kit is publicly positioned as a modular SDK that brings identity, money, and loyalty together through one integration. Its identity module lets platforms turn information they already verify into reusable credentials and create an economic model around credential verification without handing raw records to every relying party.
That economic layer matters. The identity industry has discussed portable credentials for years, but adoption also depends on practical questions: Who issues them? Who uses them? Why does a business integrate them? And who pays when a credential is verified?
The best conversations were not on stage
Some of the most useful time came between the formal sessions.
Kenneth invited me to lunch with Jeff Schwartz, founder and CEO of Dentity, and Moises Jaramillo, co-founder and CEO of OpaqAI. We spent less time on buzzwords and more time on the business questions: where verifiable credentials are already finding users, why organizations will pay for verified information, how open standards affect adoption, and what changes when AI agents begin acting for people and businesses.
Those conversations kept bringing me back to one question.
What comes after the cookie?
Calling verifiable credentials "the new cookies" is a useful provocation, but it is not literally correct.
Cookies are not disappearing. First-party cookies remain essential for functions such as keeping users signed in and remembering settings. Safari has blocked third-party cookies by default for years, while Chrome retained a user-choice model rather than eliminating them. The larger change is that cross-site behavioral tracking is becoming a less dependable—and less acceptable—foundation for understanding people online.
A tracking cookie helps a third party infer something about me from what I do. A verifiable credential is a signed claim from an issuer that I can choose to present as proof.
That difference could move parts of the web from passive observation toward explicit permission.
Instead of an advertising network inferring that someone meets an age requirement, a website could request proof of eligibility. Instead of copying a complete identity record, a service could ask for proof that a verification was completed. Instead of guessing whether someone belongs to a loyalty tier, a brand could verify a signed loyalty credential.
Privacy depends on how the system is designed. Selective disclosure can reveal only the attributes required for an interaction. In some implementations, a zero-knowledge proof can answer a narrow question without revealing the underlying value. Those features are not automatic in every credential system, but they show what is possible.
This is also becoming a browser question. The W3C has published the Verifiable Credentials Data Model 2.0 as a web standard, while the Digital Credentials API remains draft work aimed at browser-mediated credential exchange. The intended interaction is important: a site makes a request, the browser or user agent mediates it, and the user decides whether a wallet should return the requested proof. A website should not silently read everything a person holds.

Reusable, user-controlled credentials were another recurring theme at Identity Week America. Photo by Lance Ennen.
The agent makes the idea much bigger
The most interesting possibility is not merely that a website could request one of my credentials.
It is that my agent could use my data and credentials, with my permission, to act for me.
Imagine asking an agent to shop for a shirt. It could already know my size, preferred materials, favorite brands, budget, and delivery preferences. It could compare products across multiple stores and apply rewards for which I am eligible.
Not every piece of that information should be a verifiable credential. My shirt size, music taste, and style preferences may simply be private, user-controlled data. Credentials are most valuable when another party needs to stand behind a claim: my age eligibility, loyalty tier, membership, professional qualification, event attendance, or verified business status.
An agent could combine both categories. It could use my private preferences to search, then present a narrowly scoped proof when a merchant needs to verify something. The merchant would not need a permanent cross-site dossier about me. It would receive the specific information required for that interaction.
The same pattern could extend beyond shopping. A travel agent could use membership and loyalty credentials. A music agent could understand my tastes and locate eligible presales or rewards. A business agent could present a verified organization credential when starting a new onboarding process.
The defining difference is permission. I should be able to decide which agent may use which information, for what purpose, and for how long.
From inferred audiences to permissioned audiences
This also suggests a different model for advertising and loyalty.
Much of digital advertising is priced around probability. A company pays to reach someone who is likely to fit a demographic, interest, or purchasing profile inferred from tracking data.
A credential-based model could let a brand pay for a verified, permissioned signal instead. That does not require exposing a person's identity or underlying records. It may mean proving only that the person qualifies for an offer, belongs to a community, attended an event, holds a particular membership, or meets another defined condition.
The economic value could flow to the issuer, the platform facilitating verification, the user through rewards, or some combination of them. The exact model is still evolving, but the direction is compelling: replace some behavioral surveillance with consent, verification, and a more direct exchange of value.
My biggest takeaway
I did not leave Identity Week believing that verifiable credentials will replace every cookie. They will not.
I left thinking they could replace some inference with proof, some data collection with permission, and some repeated verification with portability.
AI agents make that possibility far more useful. A static wallet is helpful. A user-authorized agent that can use the right preference or credential at the right moment could change how we shop, travel, access services, use rewards, and interact with the web.
The floor may have felt more compact this year, but the ideas were not. Identity Week remains a valuable place for startups and industry veterans to compare notes, challenge assumptions, and see which concepts are moving from presentations into products.
I went to Washington primarily to spend time with Kenneth and other people who have spent years building in digital identity. I left with a clearer way to frame what may come next:
Cookies helped websites remember us. Verifiable credentials could help us decide what is remembered, what is proven, and what our agents may use on our behalf.
The web learned about us by watching us. The next web may know us because we choose what to prove.
This post is firsthand reflection from Identity Week America 2026 at the Walter E. Washington Convention Center in Washington, D.C. All photos are my own, including the banner — the entrance to Identity Week America 2026. Public claims link their sources inline; conversations and stage observations are my firsthand account. See the editorial policy for how this site distinguishes reporting from opinion.

Written by
Lance Ennen
CTO & Technical Advisor helping startups and Fortune 100 companies build innovative digital products. Passionate about blockchain, AI, and scalable architecture.
Enjoyed this article? Share it with others

