Reputation is one of the oldest technologies in commerce. Long before formal credit bureaus, passports or platform ratings, people relied on signals of trustworthiness to decide whom to hire, lend to, trade with or admit into a guild. The digital economy did not invent this logic. It industrialised it. Every marketplace, social network, payments app and professional platform now operates some version of a reputation system, whether visible as stars and reviews or buried in fraud scores, moderation queues and ranking models. As of 2026, a further shift is under way: autonomous agents are beginning to participate in these systems directly, making offers, verifying counterparties, filtering opportunities and transacting on behalf of people and institutions.
That makes reputation too important to remain a patchwork of opaque platform mechanics. If agents are to book travel, negotiate contracts, source suppliers, manage subscriptions, apply for work or route payments, they will need ways to estimate trust. So will the humans and organisations dealing with them. Yet the more that trust is formalised into machine-readable scores, credentials and behavioural histories, the greater the danger that reputation becomes a portable instrument of exclusion. A low score can deny a seller visibility, a worker opportunities or a small firm access to customers. An inaccurate score can travel farther than the evidence on which it was based. And an unaccountable score can quietly substitute for judgement in domains where the costs of error are social as well as economic.
Reputation is becoming a form of economic infrastructure, not merely a user-interface convenience.
This is why reputation systems deserve to be treated as a foundational category of governance in the age of agentic AI. They sit at the intersection of identity, payments, labour markets, access control, platform power and administrative law. They determine who is seen as reliable, safe or worthy of preference. They convert context into a number, and then often detach that number from the context that gave it meaning.
From local trust to networked scoring
Traditional reputation was contextual. A trader was known in a town, a researcher in a field, a supplier in an industry. Digital platforms promised to make trust scalable by turning dispersed interactions into persistent records. That brought clear benefits. Unknown buyers and sellers could transact with lower friction. Fraud could be reduced. New entrants could accumulate credibility faster than in old closed networks. In some markets, ratings and reviews helped dismantle incumbency by allowing smaller actors to demonstrate reliability through performance rather than pedigree.
But scale changed the character of reputation. Once translated into data, trust no longer stayed local. It could be aggregated, ranked, inferred and re-used. A person did not merely have a history on a platform; they acquired an abstract standing within a platform’s model of the world. And because those models are tuned to optimise retention, safety, conversion or loss prevention, reputation often becomes less a public account of conduct than an internal control system.
That distinction matters. A customer review and a risk score may both affect someone’s prospects, but they are not equivalent. The former is legible and contestable, even if imperfect. The latter may be invisible, probabilistic and updated without explanation. For years this opacity could be dismissed as an unfortunate side effect of large-scale digital systems. With AI agents entering the picture, it becomes a first-order design choice.
Why agents change the stakes
Human beings tolerate a surprising amount of ambiguity in social trust. We infer tone, recognise exceptions and forgive isolated errors. Agents do not work that way. To operate at speed and scale, they need structured signals. They need to know whether a seller is credible, whether an invoice is likely to be fraudulent, whether a counterparty tends to honour commitments, whether a source is authoritative, whether a software agent can be permitted to call an API or execute a payment.
In practice, that means the agent economy will generate pressure for reputation to become machine-readable, portable and interoperable. Credentials attesting to past performance, organisational affiliation, domain expertise, service reliability or compliance status are likely to proliferate. So are behavioural traces from past transactions. The attraction is obvious: if trust signals can move with a person, firm or agent across contexts, markets become easier to enter and automation becomes easier to deploy.
The danger is equally obvious. Context is not friction accidentally left in the system; it is often what makes judgement fair. The history that is useful in one setting may be prejudicial in another. A dispute rate on a freelance marketplace may say little about someone’s fitness to obtain insurance, rent workspace or access credit. Yet once a reputation artefact exists in standardised form, institutions will be tempted to use it wherever it appears predictive.
The false promise of a universal score
Reputation is becoming a form of economic infrastructure, not merely a user-interface convenience.
The idea of a single portable reputation score is seductive because it seems efficient. One number appears to reduce uncertainty for everyone. It promises faster onboarding, lower fraud and easier discovery. It also flatters the modern administrative instinct that anything important can be rendered as a dashboard.
But universal scores are usually poor instruments for plural societies. Trust is not one thing. Reliability, civility, solvency, expertise, safety and legality are different qualities, measured with different evidence and judged against different norms. Combining them into a generalised metric creates the illusion of objectivity while hiding choices about weighting, recency, thresholds and remediation.
That is why attempts to formalise broad social scoring have attracted such concern. The EU AI Act places strict limits on certain forms of AI-enabled social scoring by public authorities, reflecting an understanding that cumulative evaluation of behaviour can become incompatible with rights when used beyond its original context. The principle extends beyond the public sector. Private platforms may not call their systems social scoring, but when reputation data follows individuals across domains and materially shapes access to opportunities, the functional resemblance grows stronger.
A portable score without contestability is not empowerment but exportable opacity.
Portability is valuable, but only under conditions
The case for portability should not be dismissed. Dependence on closed platform histories traps workers, sellers and creators inside proprietary ecosystems. A driver, host, tutor, designer or merchant may have years of evidence of good conduct, yet be forced to start from zero when moving to another platform. That entrenches incumbents and weakens user sovereignty. Interoperable credentials, if designed carefully, can reduce this lock-in.
Open standards such as verifiable credentials point towards one route: instead of exposing entire behavioural logs, a platform or institution can attest to limited facts. A credential might confirm that an entity completed a set of transactions above a threshold, maintained a service level during a period or passed a particular compliance check. The subject could then present that claim elsewhere without surrendering all underlying data. Properly implemented, this can support data minimisation and selective disclosure.
Yet portability alone does not solve power asymmetry. A portable reputation layer can still be coercive if counterparties are free to demand ever more credentials, or if a handful of dominant issuers come to define what counts as trustworthy. The issue is not simply whether data can move. It is whether the recipient can over-interpret it, whether the subject can refuse disclosure without economic penalty, and whether there are meaningful routes to challenge or contextualise adverse inferences.
The political economy of reputation
Reputation systems are often described as neutral coordination mechanisms. In reality they distribute power. Platforms decide what behaviours count, whose feedback matters, how long events remain salient, which disputes are upheld and how readily trust can be rebuilt after failure. These are constitutional choices disguised as product decisions.
There is a competition dimension too. Large platforms enjoy an informational advantage because they observe more interactions and can therefore build richer proprietary models. Smaller firms may either rely on these models indirectly, reinforcing concentration, or operate with thinner data and higher risk. Agent infrastructures may intensify this divide: the actors with the best reputation graph, transaction telemetry and model feedback loops will be best placed to broker trust for everyone else.
That should raise concern for policymakers interested in market contestability. Reputation can become an informal barrier to entry every bit as potent as distribution or compute. If a small business cannot carry proof of reliability out of one ecosystem, or if an autonomous agent cannot establish bounded trust without submitting to a dominant intermediary’s scoring regime, competitive markets become harder to sustain.
What makes a reputation system accountable
A portable score without contestability is not empowerment but exportable opacity.
An accountable reputation system is not one that never makes mistakes. It is one that makes limited claims, records provenance, supports appeal and constrains re-use. In practice, several principles matter.
- Purpose limitation. Signals should be tied to a defined use case rather than treated as general proxies for human worth or organisational legitimacy.
- Data minimisation. The least amount of information necessary to establish a claim should be disclosed, especially where identity, location or sensitive activity is involved.
- Provenance and recency. Recipients should know who issued a credential or score, what evidence underpins it and how recent that evidence is.
- Contestability. People and firms need routes to inspect, challenge and correct adverse data or inferences, in line with existing data protection norms.
- Context preservation. Reputation claims should not be detached from the domain in which they were earned.
- Expiry and rehabilitation. Not every mistake should become permanent infrastructure. Trust systems require ways for improvement to count.
These principles are not abstract. They align with legal and technical currents already visible in 2026: data protection obligations under GDPR, risk management guidance from NIST, the OECD’s work on trustworthy AI and digital identity, and a broader shift towards auditable claims rather than indiscriminate data sharing.
Human reputation and agent reputation are not identical
One of the most consequential design errors would be to collapse the reputation of a person into that of the agents acting for them. Agents will vary in capability, alignment and operating conditions. A purchasing agent may make conservative choices; a trading agent may accept higher risk; a scheduling agent may merely optimise convenience. Their failures should not all be imputed to the principal in the same way, nor should the principal’s own standing automatically grant unrestricted trust to any software acting in their name.
This suggests a layered model. A human or institution may have credentials relating to identity, authority and accountability. An agent may have separate credentials relating to software provenance, permissions, security posture, audit logs and domain-specific performance. The relation between the two should be explicit: what the agent is authorised to do, within what limits, and with what liability arrangements. Without this separation, reputation becomes dangerously fungible.
The importance of bounded delegation
Delegation is not only a convenience issue but a governance one. If an agent can act on behalf of a principal, counterparties need confidence that the delegation is real and constrained. Equally, principals need protection from over-broad inferences drawn from an agent’s activity. A robust reputation architecture therefore needs to distinguish between identity, authority and performance, rather than treating all trust as a single transferable asset.
The real question is not whether agents will use reputation, but whether people will be able to inspect, challenge and contain it.
Abuse will not be exceptional
Any system that influences access to income, services or visibility will be gamed. Reviews can be bought, identities fabricated, behaviour staged, complaint campaigns weaponised and collusive rings formed. Generative AI lowers the cost of many such attacks by making synthetic activity easier to produce at scale. Agents could be used to simulate reliability, flood marketplaces with convincing but coordinated behaviour, or poison competitors’ standing through automated disputes and strategic interactions.
The lesson is not that reputation systems are futile. It is that they must be designed with adversarial pressure in mind. That includes rate limits, provenance checks, anti-collusion analysis, separation of testimonial feedback from risk scoring, and a reluctance to treat engagement itself as evidence of trustworthiness. Some forms of reputation may need to be expensive to earn precisely because cheap signals are easy to counterfeit.
Due process is the missing layer
Much of the digital economy has normalised consequential decisions without procedural safeguards. Accounts are suspended, listings buried, payments delayed and recommendations curtailed, often with limited explanation. When reputational judgements are folded into automated systems, the harm can be diffuse and difficult to contest. A seller may simply notice declining visibility. A worker may experience more rejections. An agent may lose privileges without any clear event to appeal.
This is where the language of consumer rights and administrative fairness becomes relevant. If reputation acts as infrastructure, then some of the norms associated with due process ought to travel with it: notice, explanation, review, correction and proportionality. Not every trust decision requires courtroom formality. But systems that systematically shape participation in economic life should not operate as inscrutable black boxes.
What policymakers should resist
There will be pressure to solve trust through centralisation: national reputation rails, mandatory shared blacklists, broad fraud exchanges, universal agent passports. Some narrowly tailored coordination mechanisms will be justified, especially for security and anti-fraud purposes. But history suggests that centralised scoring systems tend to sprawl beyond their original remit. Data collected for one purpose acquires another. Temporary risk controls become durable classification regimes.
Policymakers should therefore resist both laissez-faire opacity and bureaucratic overreach. The right objective is not a single trust layer for all of society. It is a federated environment in which claims can be verified, uses are limited, rights are preserved and no actor can unilaterally determine a person’s or small firm’s economic legibility.
A sovereign approach to reputation
For individuals, one-person enterprises and small institutions, the central question is sovereignty. Can they accumulate and present evidence of trust without surrendering themselves to permanent surveillance? Can they move between platforms without losing all standing? Can they authorise agents to act for them without exposing their entire history? Can they recover from mistakes? Can they understand how they are being judged?
A sovereign approach does not mean the absence of verification. On the contrary, it often requires stronger verification of narrower claims. What it rejects is the assumption that more data, more centralisation and more predictive scoring necessarily produce more trust. In many cases they produce dependency. Trustworthy reputation systems should help smaller actors prove what matters while revealing as little as possible beyond that.
That, ultimately, is why this category matters. Reputation systems are not a side topic within platform design. They are emerging as the hidden infrastructure of the agent economy, determining who may act, transact and be taken seriously in increasingly automated markets. The task for 2026 and beyond is to ensure that portability does not outrun accountability, and that trust remains a relationship grounded in evidence, limits and rights rather than a universal score from which there is no practical appeal.



