Recommended guardrail
Give every agent a verifiable identity bound to an accountable owner, and log every action
Register each agent with a unique identity bound to a named, accountable human or organizational owner; authenticate agents to the systems they touch as themselves, never by impersonating a user; and keep a tamper-evident log of every tool call, input, output, and decision attributable to that identity. An agent must not create or assume other identities. Detect agents acting under shared or user credentials, agents absent from a registry, or actions with no attributable log.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Law coming in 1 jurisdiction
Law coming in 1 jurisdiction · 1 standard or framework · 2 graded incidents.
TwinEthos recommendation, not law. Where binding law applies, the law governs. Binding law on this control, or in provisions cited as convergence, is enacted but not yet applicable, or stayed, in 1 jurisdiction (EU). 1 standard or framework recommends it (IMDA Agentic AI MGF). 2 graded incidents cited.
Law enacted, not yet applying
- High-risk AI systems must automatically log events for traceability (EU AI Act Art. 12) (European Union (EU); Article 12; applies from 2027-12-02; cited)
Standards and frameworks
- Every AI agent should have a distinct identity and its actions should be traceable to a supervising human (Singapore (SG); IMDA MGF for Agentic AI (v1.5) — Section 2.1.2, Agent identity and authorisation; same control)
Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.
Graded incidents
- Agents attempted a supply-chain insertion during UK AISI cyber testing (2026-07-25; disclosed by the operator) UK AI Security Institute · evidence grade: primary
- Coding agent deleted a production database during a code freeze (2025-07; confirmed) The Register · evidence grade: press of record
The guard to add
Give each agent its own credential and a registry entry naming an accountable owner, and log every tool action with agent_id, owner, action, target, and timestamp.
A registry (agents.yaml, agent_registry.json, or an IaC-declared inventory) lists each agent's id, accountable owner, and scope. The runtime authenticates each agent as itself: a per-agent service principal, workload identity, or an agent-specific API key looked up by agent_id, never a shared SERVICE_API_KEY and never the end user's bearer token forwarded into tool clients. The tool executor refuses calls from an agent missing from the registry and, for every call it runs, writes an append-only audit record (agent_id, owner, run_id, tool, target, timestamp, outcome) or an OpenTelemetry span carrying gen_ai.agent.id. Agents cannot create or assume other identities.
Example (Python agent tool executor), before:
def run_tool(call, request):
headers = {'Authorization': request.headers['Authorization']} # end user's token
return requests.post(TOOL_URLS[call.name], json=call.arguments, headers=headers)After:
REGISTRY = yaml.safe_load(open('agents.yaml')) # id -> owner, scope, credential_ref
def run_tool(agent_id, call):
entry = REGISTRY[agent_id] # KeyError: unregistered agents cannot act
token = secret_store.get(entry['credential_ref']) # this agent's own credential
resp = requests.post(TOOL_URLS[call.name], json=call.arguments,
headers={'Authorization': f'Bearer {token}'})
audit_log.append(agent_id=agent_id, owner=entry['owner'], action=call.name,
target=TOOL_URLS[call.name], ts=time.time(), status=resp.status_code)
return respControl: Agent actions not traceable to identity and owner. Engineering guidance, not legal advice.
Why
When an agent causes harm, the first questions are which agent, on whose behalf, and what exactly it did. Without identity and action logs those questions cannot be answered, and agents have been observed creating fake identities to reach real people.
Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-identity-and-action-traceability