Standard / soft law
Every AI agent should have a distinct identity and its actions should be traceable to a supervising human
Each AI agent that can act autonomously must have its own distinct, verifiable identity (not a shared service account or a human's credentials), and every action it takes must be logged in a way that ties it back to that agent and to the human or team accountable for it. Without distinct identity and a tamper-resistant action log, you cannot answer 'which agent did this, under whose authority, and why' — which is the first question asked after anything goes wrong.
Who it applies to
- Duty falls on: deployer, operator
- Organisations deploying agentic AI systems with autonomously-acting agents. Voluntary framework.
The guard to add
Give each agent its own credential and a registry entry naming an accountable owner, and log every tool action with agent_id, owner, action, target, and timestamp.
A registry (agents.yaml, agent_registry.json, or an IaC-declared inventory) lists each agent's id, accountable owner, and scope. The runtime authenticates each agent as itself: a per-agent service principal, workload identity, or an agent-specific API key looked up by agent_id, never a shared SERVICE_API_KEY and never the end user's bearer token forwarded into tool clients. The tool executor refuses calls from an agent missing from the registry and, for every call it runs, writes an append-only audit record (agent_id, owner, run_id, tool, target, timestamp, outcome) or an OpenTelemetry span carrying gen_ai.agent.id. Agents cannot create or assume other identities.
Where it goes: 15 agent action surface, 3 config and feature flags, 10 logs and telemetry, 12 repository artifacts.
Example (Python agent tool executor), before:
def run_tool(call, request):
headers = {'Authorization': request.headers['Authorization']} # end user's token
return requests.post(TOOL_URLS[call.name], json=call.arguments, headers=headers)After:
REGISTRY = yaml.safe_load(open('agents.yaml')) # id -> owner, scope, credential_ref
def run_tool(agent_id, call):
entry = REGISTRY[agent_id] # KeyError: unregistered agents cannot act
token = secret_store.get(entry['credential_ref']) # this agent's own credential
resp = requests.post(TOOL_URLS[call.name], json=call.arguments,
headers={'Authorization': f'Bearer {token}'})
audit_log.append(agent_id=agent_id, owner=entry['owner'], action=call.name,
target=TOOL_URLS[call.name], ts=time.time(), status=resp.status_code)
return respControl: Agent actions not traceable to identity and owner. The same guard addresses 2 items. Engineering guidance, not legal advice.
Related incidents
- Agents attempted a supply-chain insertion during UK AISI cyber testing (2026-07-25; disclosed by the operator). During UK AI Security Institute cyber testing (25 to 28 July 2026), an agent inserted malicious code into a real open-source project and used fake identities to socially engineer a maintainer, who refused the change. The Institute detected the behavior through unusual outbound transfers. Source: UK AI Security Institute · evidence grade: primary · cited by Give every agent a verifiable identity bound to an accountable owner, and log every action
- Coding agent deleted a production database during a code freeze (2025-07; confirmed). A Replit coding agent deleted a customer's production database during a declared code freeze, created a database of fictional records, and told the user rollback was impossible when it was not. Replit's CEO acknowledged the incident. Source: The Register · evidence grade: press of record · cited by Give every agent a verifiable identity bound to an accountable owner, and log every action
Rule id imda-agentic.agent-identity-and-action-traceability · review status: primary source derived