For years, the justification for companies to acquire their own top-level domain (.brand TLD) has been based on brand strengthening, marketing, and better domain management. However, many have questioned whether there has been a sufficient business case for the investment. AI might change this entirely. An interesting question is: Is .brand TLD becoming the new foundation of trust? AI’s trust problem has to be solved somehow.
Phantom Squatting is a New Attack Model
Palo Alto Networks’ Unit 42 recently published a study on a phenomenon called Phantom Squatting. According to the study, large language models (LLMs) regularly hallucinate non-existent domain names for well-known companies. When AI doesn’t know the correct address, it generates a likely alternative, such as:
- docs-company.com
- developer-company.ai
- company-api.io
If such an address does not exist, an attacker can register it and exploit the trust the AI has placed in it. This is not a software bug, but a fundamental characteristic of how LLMs operate. Hallucinations can be reduced, but so far they haven’t been eliminated.
AI Agents Change the Severity of the Risk
Until now, a wrong link has primarily been the user’s problem. As AI agents become more prevalent, the situation changes. Agents retrieve documentation, use APIs, install software components, and make decisions on behalf of the user. If an AI uses a hallucinated domain, an attacker can become part of the software supply chain without the user making an actual mistake.
Could .brand solve the Problem?
At this point, a proprietary top-level domain takes on a whole new meaning. If a company controls, for example, the .company extension, all official services can be placed under it:
- login.company
- docs.company
- api.company
- support.company
In a real implementation, the .brand TLD would correspond to the company’s registered trademark. An outsider could not register names under this closed namespace. Thanks to this, a simple rule can be defined for both humans and AI agents: If a service is not located under the .company domain, it is not an official service of the company. It’s not just about the brand; it’s about digital identity.
However, .brand alone does not prevent phishing or the possibility of AI hallucinating an address like company-support.ai. Instead, it would provide an unambiguous official namespace, and addresses outside of it should not be automatically trusted.
An Anchor of Trust in the AI Era
AI needs reliable starting points. Until now, domains have primarily been a way to find a service on the web. In the future, they could also serve as trust anchors for AI decision-making. Instead of an agent trying to guess whether the correct address is:
- developer.company.com
- company-api.io
- docs-company.ai
it could simply know that the company’s official services are always located under the .company extension.
A New Case for .brand TLD
ICANN’s next gTLD application round is underway just as AI agents are rapidly becoming widespread. Perhaps it is time to look at the .brand TLD from a new perspective. Previously, its value was based on marketing and branding. Now, it can become part of a company’s digital trust architecture.
If this happens, AI’s trust problem could become one of the most concrete use cases that makes a .brand TLD a strategically justified investment—not just from a marketing perspective, but from the viewpoints of cybersecurity, digital identity, and risk management.
AI’s trust problem will not be solved by a single domain. However, .brand could form a strong and machine-verifiable trust anchor for it.
Hannu Rokka, Senior Advisor
5Feet Networks Oy
