19/03/2026
AI agents are taking actions in businesses right now. Booking, submitting, modifying, approving. Often without a human reviewing each step.
That's the point of them. But it creates a real question: if something goes wrong, who approved that action?
Passkeys require a physical human gesture to complete authentication. An AI agent can't do that. It has no hands. So agents typically run on long-lived credentials set up once and left running with no clear audit trail back to a human decision.
A YubiKey puts the human back in the loop. Before the agent gets access, a person physically touches the key. That touch is the approval event. It's auditable, timestamped, and tied to a real person.
We've written a practical guide to how this works for Australian businesses, covering the ASD Essential Eight context, real-world use cases, and how to get started.
Read it here: https://www.trustpanda.com.au/blogs/guides/ai-agents-are-running-your-business-whos-checking