09/22/2026 | Press release | Archived content
As AI moves from generating information to taking actions, they require new infrastructure around data security and governance, identity and authorization. Before allowing an agent to transact, institutions need to know who deployed it, whether that person or business is trusted and what authority has been delegated to the agent. M13 believes the companies best positioned to establish that chain of trust are those that already have the underlying identity data, risk intelligence and institutional relationships.
"AI agents are rapidly becoming economic actors, but the identity infrastructure underneath commerce was never designed for software that can open accounts, make purchases, move money, or enter into transactions on someone else's behalf," said Karl Alomar, Managing Partner at M13. "What made Baselayer especially compelling is that Jonathan and Timothy are not starting from a whiteboard. They already have a network spanning more than 2,300 financial institutions, deep risk data, and infrastructure in production today. They have the distribution and the underlying trust graph to become the system institutions rely on to know not just who they are dealing with, but which agents are authorized to act for them."
Co-founder and CEO of Baselayer Jonathan Awad's interest in business credit started at home. His parents immigrated to build a better life, and an uncle started a company when Awad was young. Because the infrastructure for business credit and business fraud was so much thinner than the consumer equivalent, his uncle had to sign a personal guarantee. The business underperformed, and the default followed him into his personal credit.
That asymmetry became the founding insight. Consumer credit has decades of mature infrastructure behind it. Business credit never got the same attention from incumbents like Experian, Equifax, and Dun & Bradstreet, largely because there weren't enough small businesses to justify it. Then COVID hit, and Americans started forming small businesses in numbers the bureaus hadn't planned for, while those vendors stayed pointed at consumers.
Awad, who spent his career in risk management, brought that view to Timothy Hyde, a machine learning pioneer and now Baselayer's CTO. Hyde's condition was straightforward: give him proprietary data no one else has, and he could build scores that work. They founded the company in 2024.
Before any institution extends credit or opens an account for a business it can't see in person, it has to establish trust. Is this business real? Does this person own it? Should we work with them? At most of the 10,000-plus financial institutions in America, answering those questions is still slow, largely manual work that can run from a day to several weeks.
Baselayer turns it into an API call. The company maintains a trusted directory covering every business in America, the owners and employees attached to them, and now the agents they deploy. It is FinCEN and regulatory approved, which matters enormously to a compliance team at a community bank watching peers absorb billion-dollar fines.
The same problem is now arriving in a harder form. Visa, Mastercard, and American Express have all shipped agent commerce protocols in the past year, and Shopify turned on agentic sales channels by default for roughly one million merchants.
"Every era of commerce has required a new trust layer, but historically that infrastructure gets built only after fraud and abuse make the problem impossible to ignore," Awad said,. "Agentic commerce is moving too fast for the industry to repeat that mistake. We already help one in five U.S. financial institutions answer, 'Can I trust this business?' Now we're building the infrastructure they need to answer, 'Can I trust this agent, who does it represent, and what is it allowed to do?'"
Roughly one in five financial institutions and payments companies nationwide run on Baselayer, along with Fortune 500s and government agencies. Those customers have prevented more than $1 billion in fraud losses. Every profile request across that base feeds a shared signal back to everyone else on the network, which is how Baselayer came to operate the largest B2B fraud consortium in America, with a customer base rivaling bureaus that have been in the market for over a century.
Baselayer works with agent builders, card networks, and financial institutions including Prove, Socure, Exa, Parallel Web Systems, Natural, Nevermined, and Lane to bring identity and risk tooling to agent transactions. It also holds seats in the groups writing the rules the agentic economy will run on, including the FIDO Alliance Authentication Working Group, the Legal Context Protocol, and the x402 Identity Working Group, alongside Cloudflare, Google, Visa, and Mastercard.
Baselayer's approach to agents rests on a transitive property. If an institution already trusts a business, and that business has no history of deploying bad agents, that trust can extend to the agent it sends. Making that logic hold requires a foundation most entrants to the category are still assembling.
Data foundation. Baselayer starts from verified data on every business in America, its owners and its employees, checked millions of times by institutions moving hundreds of billions of dollars.
A network built as a consortium from day one. A single bank has no way to ask the bank down the road whether a business has applied there before. Baselayer tracks every profile request across its customer base and shares the signal back, which is how it came to run the largest B2B fraud consortium in America. Customers surface patterns no one institution could see alone, like bad actors incorporating clusters of unrelated businesses at a single address, which now routes automatically to review once the velocity crosses a threshold.
Delegated identity for agents, on both sides of the transaction. Merchants get an SDK that tells them whether a visitor is a bot or an authorized agent. The business deploying an agent gets a credential carrying the delegation of its identity, so the agent is recognized as an extension of a verified business rather than blocked as unidentified traffic. The logic follows the graph Baselayer already has: if the business is trusted and has no history of deploying bad agents, its agent inherits that trust.
The risk side is compounding faster than the commerce side. Every telecom has been hacked, and a real person's PII sells on the dark web for $20. An LLM is an efficient tool for recombining leaked data into synthetic identities at a scale and cost that didn't exist three years ago. Add instant settlement, whether through stablecoins or FedNow, and the money is gone before anyone reviews the file. Awad's line for it: "It's very easy to hand money out. It's very hard to get back."
Agents, meanwhile, will keep taking over anything repetitive a person can look up, log into, and click through. Awad doesn't expect them to become independent entities anytime soon, which keeps the delegation question central. Every agent will need to carry a verified identity back to a person or a business, or institutions will keep blocking it.
None of that is settled yet. The protocols that will decide how an agent proves who it represents are being written right now, in working groups and town halls, by whoever shows up. Awad worries about something else: "What conversations are we not in? And what's getting decided right now that we're not part of?"
Read the full funding announcement and learn more at baselayer.com.
Follow Baselayer on LinkedIn and X, and follow Jonathan Awad and Timothy Hyde for updates on the Agentic Identity Suite and the standards work behind it.