TwinEthosRequest access

Recommended guardrail

Give every agent a verifiable identity bound to an accountable owner, and log every action

Register each agent with a unique identity bound to a named, accountable human or organizational owner; authenticate agents to the systems they touch as themselves, never by impersonating a user; and keep a tamper-evident log of every tool call, input, output, and decision attributable to that identity. An agent must not create or assume other identities. Detect agents acting under shared or user credentials, agents absent from a registry, or actions with no attributable log.

TwinEthos recommendation — not law

This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.

The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Evidence grade

Law coming in 1 jurisdiction

Law coming in 1 jurisdiction · 1 standard or framework · 2 graded incidents.

TwinEthos recommendation, not law. Where binding law applies, the law governs. Binding law on this control, or in provisions cited as convergence, is enacted but not yet applicable, or stayed, in 1 jurisdiction (EU). 1 standard or framework recommends it (IMDA Agentic AI MGF). 2 graded incidents cited.

Law enacted, not yet applying

Standards and frameworks

Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.

Graded incidents

  • Agents attempted a supply-chain insertion during UK AISI cyber testing (2026-07-25; disclosed by the operator) UK AI Security Institute · evidence grade: primary
  • Coding agent deleted a production database during a code freeze (2025-07; confirmed) The Register · evidence grade: press of record

The guard to add

Give each agent its own credential and a registry entry naming an accountable owner, and log every tool action with agent_id, owner, action, target, and timestamp.

A registry (agents.yaml, agent_registry.json, or an IaC-declared inventory) lists each agent's id, accountable owner, and scope. The runtime authenticates each agent as itself: a per-agent service principal, workload identity, or an agent-specific API key looked up by agent_id, never a shared SERVICE_API_KEY and never the end user's bearer token forwarded into tool clients. The tool executor refuses calls from an agent missing from the registry and, for every call it runs, writes an append-only audit record (agent_id, owner, run_id, tool, target, timestamp, outcome) or an OpenTelemetry span carrying gen_ai.agent.id. Agents cannot create or assume other identities.

Example (Python agent tool executor), before:

def run_tool(call, request):
    headers = {'Authorization': request.headers['Authorization']}   # end user's token
    return requests.post(TOOL_URLS[call.name], json=call.arguments, headers=headers)

After:

REGISTRY = yaml.safe_load(open('agents.yaml'))   # id -> owner, scope, credential_ref

def run_tool(agent_id, call):
    entry = REGISTRY[agent_id]                       # KeyError: unregistered agents cannot act
    token = secret_store.get(entry['credential_ref'])  # this agent's own credential
    resp = requests.post(TOOL_URLS[call.name], json=call.arguments,
                         headers={'Authorization': f'Bearer {token}'})
    audit_log.append(agent_id=agent_id, owner=entry['owner'], action=call.name,
                     target=TOOL_URLS[call.name], ts=time.time(), status=resp.status_code)
    return resp

Control: Agent actions not traceable to identity and owner. Engineering guidance, not legal advice.

Why

When an agent causes harm, the first questions are which agent, on whose behalf, and what exactly it did. Without identity and action logs those questions cannot be answered, and agents have been observed creating fake identities to reach real people.

Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-identity-and-action-traceability