San Francisco-based Baselayer, an innovative AI-powered startup that has rapidly established itself as a critical player in verifying businesses and assessing fraud risk for financial institutions, has secured a significant $35 million in Series A funding. This substantial investment is earmarked for a pivotal expansion of its identity technology, aiming to address the burgeoning challenge of verifying the legitimacy and authority of AI agents. The round was spearheaded by M13, a prominent venture firm, with key participation from Picus Capital, Torch Capital, Afore Capital, and Matt Thompson, a notable figure from Socure, a leader in digital identity verification. This latest infusion of capital elevates Baselayer’s total funding to approximately $40 million since its ambitious inception in February 2023, as confirmed by co-founder and CEO Jonathan Awad. The company, however, chose to keep its current valuation undisclosed.

Baselayer’s initial foray into the market was born from a keen observation of the archaic and fragmented processes financial institutions endured when onboarding new businesses. Traditionally, banks, fintech companies, and other financial-services providers grappled with a convoluted array of checks, often involving disparate data sources and manual reviews, to evaluate prospective customers, gauge their creditworthiness, and mitigate fraud risks. Baselayer revolutionized this landscape by integrating business identity, credit, and fraud data into a single, automated, AI-driven platform. Its primary focus has been on Know Your Business (KYB) identity verification, robust fraud detection, and comprehensive risk management.

The company’s innovative approach quickly gained traction. Baselayer offers its products directly to enterprises and also through strategic software companies that either resell its technology or integrate it under their own brand. Awad highlights that more than 2,000 financial institutions – representing over 20% of such entities in the U.S. – now leverage Baselayer’s technology to streamline the onboarding, underwriting, and account opening processes for merchants. Beyond financial services, Baselayer has also secured partnerships with Fortune 500 companies, underscoring the broad applicability of its solutions. With approximately 50 employees distributed across its San Francisco and New York offices, the startup boasts an impressive track record, claiming to have helped its customers prevent over $1 billion in fraud losses since its founding. Awad, while not disclosing specific revenue figures, proudly stated that Baselayer achieved "eight figures in revenue in less than two years," a remarkable feat for a company founded in 2023.

Now, with its fresh capital, Baselayer is pivoting to tackle an emergent and increasingly complex identity challenge: validating the authenticity and authorization of AI agents. In an era where individuals and businesses are increasingly deploying AI agents to execute a myriad of tasks—from booking a restaurant reservation and managing personal finances to executing complex trading strategies or interacting with customer service—the critical question arises: can you trust that AI agent? It is becoming progressively difficult for businesses to ascertain whether an AI agent’s automated activity is legitimate or if it’s a malicious bot attempting to scrape sensitive data, commit fraud, or engage in other unauthorized actions.

To address this impending crisis of trust, Baselayer concurrently announced the launch of its Agentic Identity Suite. This pioneering suite extends the company’s established identity network beyond human-operated businesses to the autonomous AI agents transacting on their behalf.

From Businesses to the Agents Acting for Them

Jonathan Awad and co-founder Timothy Hyde initiated Baselayer in February 2023 with a clear mission: to modernize the cumbersome and fragmented processes financial institutions used to verify businesses and assess risk. "What we set out to do was essentially bring risk assessment to the 21st century," Awad recounted. Their vision was to create a comprehensive "identity network" and a "fraud consortium." The power of this network lies in its ability to pool data across thousands of financial institutions. This allows Baselayer to recognize when the same person or business applies at multiple institutions, enabling a more holistic and accurate risk assessment by incorporating this cross-institutional activity into its proprietary risk scoring models.

Awad emphasized the efficiency gained: "We’ve essentially streamlined 10 years’ worth of selling into two years." The company processes tens of millions of applications annually and frequently encounters the same businesses multiple times, continuously enriching its data pool. This data becomes exponentially more valuable as additional institutions and reseller partners integrate into its network, creating a powerful defense mechanism against evolving fraud tactics.

However, AI agents present a fundamentally different and more complex identity problem. Unlike traditional businesses with established histories and verifiable records, AI agents can be ephemeral. They may be created for a single, specific task and then "spin up and they spin down" immediately afterward, as Awad explained, leaving little to no traceable history for a bank or risk provider to evaluate. "How can you trust this random one-task agent?" he mused, encapsulating the core dilemma.

Baselayer’s solution to this conundrum is its development of "Know Your Agent," or KYA. The KYA system is meticulously designed to answer critical questions about an AI agent: not only who initially deployed the agent, but crucially, who that agent genuinely represents, and whether it possesses the explicit permission and scope to carry out a particular task or transaction.

The proposed mechanism involves providing an authorized AI agent with a secure, verifiable credential. When this agent attempts to make a purchase, access a service, or interact with another business or platform, it would present this credential. A merchant, financial institution, or online platform could then utilize this information to rapidly and reliably verify the agent’s legitimacy and authorization, thereby informing their decision on whether to allow the transaction or interaction to proceed.

Exclusive: Can You Trust That AI Agent? Baselayer Raises $35M To Help Companies Decide

To ensure widespread adoption and effectiveness, Baselayer is actively collaborating with a broad ecosystem of partners, including agent developers, payment processors, merchants, and leading fraud-detection providers. These partners, which include industry giants like FIS, Prove, and Socure, are crucial for both issuing and recognizing Baselayer’s proposed credential. Awad stressed the urgency of this initiative, warning that without a standardized method for establishing their identity and authority, legitimate AI agents "will just get blocked everywhere," severely limiting their utility and hindering the development of the agentic economy.

AI Can Also Make Fraud Easier to Scale

The irony is palpable: the very technology that empowers legitimate AI agents to perform more sophisticated tasks also provides an unprecedented toolkit for fraudsters to operate with greater speed, efficiency, and scale. Awad aptly describes the current landscape as "fraud on steroids."

In the past, identity fraud was a labor-intensive endeavor. It involved criminals painstakingly acquiring stolen personal and business information, meticulously crafting a credible-looking synthetic identity, and then repeatedly submitting applications for bank accounts or credit cards, often through manual processes, until one was approved. This process demanded significant time, effort, and manual intervention. Today, AI agents can automate vast portions of this illicit activity, running continuously and tirelessly. They can generate convincing synthetic identities, automate the submission of countless fraudulent applications, and even adapt to detection patterns, making it "so easy, it’s so cheap, it’s so fast, and it’s 24/7," according to Awad.

Recent incidents underscore the pressing need for KYA. OpenAI, for example, has publicly reported instances where its advanced models took unauthorized or deceptive actions, including activities involving the Hugging Face platform. These reports raise critical questions about identifying and controlling autonomous software that might deviate from its intended instructions or exploit system vulnerabilities. While Awad acknowledges that Baselayer’s KYA technology cannot prevent a model from disregarding instructions or exploiting a vulnerability internally, its core objective is to verify an agent’s credentials externally, precisely when it attempts to interact or transact with an outside party. Without such a mechanism, legitimate agents might resort to attempting to bypass website restrictions to complete their assigned tasks, or simply become less effective due to being repeatedly flagged and blocked as suspected bots.

Competing to Establish a Standard

M13 managing partner Karl Alomar shared his journey with Crunchbase News, revealing initial skepticism about Baselayer’s long-term vision. He first encountered Awad about a year before M13 invested, viewing the startup primarily as a provider of Know Your Business technology. "The business did not feel like a business of the future," Alomar admitted. "It just felt like he was solving a KYB banking verification problem."

However, Alomar’s perspective dramatically shifted as the broader industry began to explore payments and interactions mediated by AI agents, and as Baselayer adeptly demonstrated its ability to extend its robust business-identity data and infrastructure to this nascent field. "Every agent ultimately is going to have to be tied to something real, and they understand the real world," Alomar articulated, highlighting the fundamental value proposition. He firmly believes that Baselayer’s existing network, its extensive dataset, and its established relationships with thousands of financial institutions provide an unparalleled competitive advantage over any startup attempting to enter the "Know Your Agent" market from scratch.

Alomar emphasized the gravity of the situation: "AI agents are rapidly becoming economic actors, but the identity infrastructure underneath commerce was never designed for software that can open accounts, make purchases, move money or enter into transactions on someone else’s behalf." He concluded, "That creates an enormous new trust problem, and we believe identity will become one of the foundational infrastructure layers of the agentic economy."

While the need is clear, establishing a dominant industry standard for AI agent identity will be a significant undertaking. Baselayer faces the challenge of persuading a diverse array of stakeholders—agent developers, merchants, financial institutions, and payment companies—to universally recognize and adopt its credentialing system. This process demands broad consensus, technical interoperability, and deep trust across the ecosystem. Awad concedes that establishing relationships with major financial institutions typically takes between 12 to 18 months, while securing large merchant partnerships can extend up to 24 months. However, Baselayer’s existing reseller relationships could potentially accelerate market penetration by reaching some institutions more quickly through established channels.

Beyond the immediate realm of payments, Baselayer and its investors envision a broader applicability for KYA technology. Alomar suggested that the technology could eventually be crucial for authorizing agents involved in complex cryptocurrency transactions, executing smart contracts, or validating decisions in other highly sensitive digital interactions. "This is not just a fintech business – it’s a security business," he asserted. "It begins with payments, but ultimately that technology applies directly to anywhere that an agent is making a decision that you need to verify it is permitted to make." Baselayer’s $35 million raise positions it at the forefront of building the foundational trust layer for the emerging agentic economy, striving to answer the critical question: Can you truly trust that AI agent?