Inkbox sells something almost dull: an email address, a phone number, somewhere to keep passwords. The kind of thing a company buys without holding a meeting about it.

Underneath it sits one of the biggest assumptions anybody in this batch has made: that every AI agent is going to end up being somebody.

Not a feature. Not a process running on a server. An individual, with a name, a way to be reached, a history of what it has done, and eventually a reputation.

What they built

Inkbox describes itself as the identity and communication layer for AI agents. It gives an agent a lasting identity of its own: its own email address, its own phone number, iMessage, and a secure route so it can receive traffic from the internet. Alongside that sits an encrypted store for passwords and two-factor codes, so the agent can log into outside systems without borrowing a person's credentials.

It is based in San Francisco. Ray Liao, the chief executive, holds a computer science PhD from MIT and previously co-founded Empallo, an AI-powered virtual clinic for cardiovascular care. Alex Wilcox, the chief technology officer, has a computer science master's from Northeastern and a background in machine learning engineering and networking research. Dima Vremenko was a research associate at Harvard Medical School building machine learning pipelines for clinical prediction models.

Who else is in this field

Every piece of this already exists, built for people. Twilio and Bandwidth hand out phone numbers and messaging. Auth0, Okta, Stytch, Clerk and WorkOS handle who is allowed to log in. 1Password and HashiCorp Vault keep the secrets. ngrok and Cloudflare Tunnel get traffic back to something that is not on the public internet.

Every one of them was designed on the assumption that the thing being identified is a person, or a company standing in for one. Inkbox is rebuilding the same set of tools for something that is neither.

The point: a theory about the future, with somewhere to stand today

Most companies in this batch are betting on how fast agents get better. Inkbox is betting on something different in kind: what agents eventually are.

Its starting point is that an agent stops being something your software runs and becomes a participant: something that appears in systems in its own right, is dealt with directly, and builds up a record. That is not the common view. Most of the industry still treats an agent as a very capable script.

If that turns out to be right, then whoever hands out those identities holds the register for a whole new kind of participant, roughly where Okta sits for employees. That is not owning the agents, which nobody does. It is being the official record of who they are, and power gathers around registers far more reliably than it gathers around tools.

What makes this worth a file is not the theory, which anyone could put forward over a coffee. It is that they found somewhere solid to stand while it plays out.

Why the mundane version already sells

The way in works today, without anybody having to accept the bigger idea, for a very practical reason.

Every identity system ever built assumes the user is a person. So agents borrow a human's login and act as them. When an agent using your login does something wrong, the record says you did it, and there is nowhere to note the difference. You cannot cut off the agent's access without cutting off your own, you cannot see what it did separately from what you did, and you cannot give it fewer permissions than you have yourself.

That is a real problem with a real buyer, and it shows up long before anyone has to believe anything about machines being people. A company buys Inkbox because it wants a clean line in the record. It does not have to agree that the agent is somebody.

What the theory unlocks if it is right

Here is where the positioning gets interesting.

Suppose agents really do become participants. All sorts of things follow that sound silly today: a face so people recognise which agent they are dealing with, a consistent character and voice wherever it turns up, a visible history and reputation, relationships between agents, even a kind of family tree where one agent inherits from another.

Try to raise money for any of those as a company on its own today and the meeting ends early. There is no buyer, no budget for it, and no serious way to describe the problem.

But for a company that already hands out the identity, every one of those is a small feature rather than a whole new company. The hard part, a lasting identity for the agent that systems already recognise, is done. Adding a face to it, or a history, or a map of its relationships, becomes an afternoon's work rather than a funding round.

That imbalance is the whole strategy. Inkbox is not trying to sell the future. It is selling something ordinary from a spot where, if the future arrives, it is already holding the piece everything else attaches to.

It is still a gamble, and worth saying so

The bet can lose, and the way it loses is not dramatic.

If agents stay tools, called up and thrown away, never building an identity or a history because nobody needs them to, then Inkbox is a good password store with some communication features attached. That is a real business and a small one, and the big position never arrives.

There is also a real risk that the big platforms close the gap themselves. The established identity companies can add machine users, and the model providers could hand out agent identities alongside their services. Inkbox's defence is that it works with any provider and already covers email, phone, messaging and passwords, which no single platform does today. Whether that holds is genuinely open.

The transferable lesson

There is a general move here worth pulling out, because it applies to anyone trying to build towards a future that has not arrived.

A theory about where things are going is not, on its own, a company. Plenty of people were right about mobile, or about the cloud, several years early and built nothing, because there was nothing to sell to anyone who did not already agree with them.

The skill is finding the way in: the unglamorous, immediately useful product a customer buys for ordinary reasons today, which happens to put you exactly where you need to be if you turn out to be right. Once you have that, the theory stops being a fantasy and becomes a plan, paid for by customers who never had to agree with you.

Why it is bigger than it sounds

The short description is identity for AI agents. The change it is built around is a real one.

  • Swapping the principal from a person to a machine makes a new product. Every system this resembles was built for humans, and this is not a smaller version of those.
  • Credentials today, participants tomorrow. The company has a theory about AI becoming an independent individual and a concrete cut-in point to build from, which is what turns a theory into a business.
  • The position is still available. Agent identity has no owner yet, and being the one who defines it is worth considerably more than being early to a settled category.

What to watch

The test is whether agents on Inkbox build up anything. If an identity gets created, used once and dropped, agents are being treated as disposable and the theory is not landing. If identities last for months, gather a history, and start being referred to by name inside customer companies, then people have begun treating agents as participants without being asked to, and the bigger bet is quietly being won.

The second thing to watch is what they build next. If the next products move towards giving agents a character rather than deeper into security, that is the company telling you which future it is actually building for.