Every enterprise AI strategy this year contains some version of the same sentence, and the sentence is correct: an agent trusts the context you give it. Completely. Give it a clean, resolved picture of your business and it reasons well. Give it a fragmented, half-matched picture and it acts on that picture with total confidence, because confidence is all it has.

The market has accepted this. What it hasn't examined is the fix everyone reached for.

The fix is governance. Lineage. Provenance metadata. Data contracts, observability, catalogs — some teams are now writing "data constitutions." I've spent enough of my career around MDM programs to respect this work. It's necessary. It's also, on its own, a quieter thing than people want to admit: it is your systems vouching for your systems.

There's a word for that. Self-attestation.

Governance makes your data agree with itself. That's all it does.

Take the most load-bearing object in any data estate: the resolved entity. Your golden record says these three near-identical name-and-address strings are one legal counterparty. Governance certifies the record — lineage intact, quality gates green.

But walk back one step. The entity resolution underneath that record was a probabilistic match. Your pipeline made the guess, your pipeline scored the guess, your framework blessed it. Every light is green and the match is still a guess. Nobody outside your walls ever looked at it.

That was survivable when the consumer of the record was a human analyst who might squint at a weird join. An autonomous agent doesn't squint. It inherits the green lights and acts. The security research coming out this year keeps finding the same failure shape: agents doing the wrong thing from inside the trust boundary, fully authorized, fully assured, wrong — because the assurances described the system, not the world.

So the question I'd put to any architect building agent infrastructure right now is not "is my data well-governed?" It's this: who, outside my organization, has independently verified this — and what exactly did they verify?

For most enterprise data the honest answer is: nobody, and nothing.

The identity people got there first — halfway

Parts of the AI ecosystem have already worked out that internal assurance isn't enough. Look at where the serious standards work is going: the W3C has a community effort on cryptographically verifiable agent identities. The FIDO Alliance stood up a working group on agentic authentication. Mastercard's Verifiable Intent and Google's agent-payments protocol both exist to create an externally-anchored record of what an agent was actually authorized to do.

I don't think these people are wrong. I think they're half done, and I'm not sure they've noticed which half.

All of that work verifies the actor. Is this agent who it claims to be. Is it authorized. Did a human really sign off.

None of it verifies the data the actor acts on — the counterparty record, the transaction underneath the decision.

So you can end up in a strange place: an agent with a flawless credential and a tamper-proof mandate, reasoning over a counterparty your pipeline resolved wrong, executing against a transaction nobody outside the two trading parties has ever checked. The identity stack will confirm, cryptographically, that the right agent did the wrong thing.

The data half already exists. We filed it under tax.

An external verification layer for business transaction data already runs in production, at national scale, in dozens of countries. Nobody in the AI world talks about it because it lives under the least glamorous label in enterprise software: e-invoicing compliance.

Strip the tax vocabulary and look at the mechanics. On the Peppol network, a counterparty identifier either resolves through the network's discovery layer or the document does not move. There is no fuzzy match, no "close enough." The participant exists in the registry, addressable, or the message fails. That is entity resolution performed by infrastructure neither trading party controls — the exact thing your MDM program approximates internally with probabilistic matching.

And under a clearance model — Saudi Arabia's current one or Oman and UAE's upcoming, for instance — the tax authority validates and cryptographically stamps an invoice before the buyer ever receives it. A party with no commercial stake in the deal has checked the transaction and said so, on the record, in real time.

Put those together and you get something I'd describe this way: the only pre-resolved, externally witnessed ledger of B2B state that exists. Identity resolved by a third party. Validity attested by a third party. Which is precisely the property the agent-identity world is building from scratch for actors — except for transaction data it isn't a standards proposal, it's live infrastructure processing billions of documents.

And the coverage keeps widening. In Saudi Arabia, the integration deadline for businesses with turnover above roughly SAR 375,000 passed at the end of June, Oman's is coming in August and UAE is close behind in October. In the EU, the ViDA package adopted last year makes structured e-invoicing and digital reporting mandatory for intra-EU B2B trade from mid-2030. This is becoming the default condition of doing business, not a regional quirk.

The boundary, or: where this goes wrong

Now the caveat, and I'd argue the caveat is the most important paragraph in this piece.

Clearance certifies fiscal validity: the invoice is real, structurally sound, legitimate for tax. Network resolution certifies identity: this participant is who the registry says.

Neither certifies that you will be paid. Neither says the counterparty is solvent, creditworthy, or acting in good faith. A cleared invoice from a company about to default is a perfectly valid invoice.

I keep repeating this because I can see the failure coming. To a system optimizing for confidence, "externally validated" reads as "safe to rely on." It is safe to rely on — for the exact thing that was verified, and nothing beyond it. An agent architecture that ingests the verification signal without its boundary is worse than one that ignores it entirely, because now the internal guess is wearing a real credential.

Knowing what a certification does not cover is most of what it means to know the domain.

What I'd actually do with this

Not a product pitch. The rails exist; what changes is where an agent looks for ground truth.

When an agent needs to know who a counterparty is, the authoritative answer is the identity the network already resolved — not the probabilistic match in the CRM. When it needs to know a transaction is real, the authoritative answer is the validation the authority already performed — not internal reconciliation. The design work is carrying those signals into the agent's context together with their limits: verified identity, fiscally valid transaction, and no claim whatsoever about solvency or intent.

I might be wrong about how fast agents get to autonomous B2B transactions — the payments networks are betting it's soon, and payments networks have been early before. I don't think I'm wrong about what those agents will need when they arrive: ground truth they can't generate internally and can't take on faith from the other side of the deal. Internal governance can't supply that. It's self-attested by definition. The externally witnessed ledger can, and it's been running the whole time.

The golden record was always a choice about what to believe. A witness is different. A witness is what you can check.


Mandate specifics, as at publication

This essay was published on 4 July 2026 and the mandate dates in it are as at that date. They still hold as of 29 July 2026: ZATCA's Wave 24 integration deadline — taxpayers with VAT-subject revenue above SAR 375,000 in 2022, 2023 or 2024 — fell on 30 June 2026; Oman's Fawtara Phase 1 begins in August 2026, on a day the Tax Authority has not published; the UAE's accredited-service-provider appointment deadline is in October 2026. For the current position see the mandate tracker and the country compliance pages, which we date-stamp.

Data Trust — a three-part series

Part OneThe golden record was always a choice
Part Two — You cannot govern your way to ground truth (this essay)
Part ThreeYour data match rate was priced for humans

First published by Qasim Shah on LinkedIn, 4 July 2026 — read the original. Republished here unedited.