Agent Identity: Why “A System Did It” Is Not an Answer

Agent Identity: Why “A System Did It” Is Not an Answer

FUTURES · FORESIGHT. The parts that describe what agent identity requires are established method (see the working paper Admissibility for AI Agents: A Record-Based Test). The live case is marked as established fact. The parts that describe how this dial may drift, 2026–2030 are foresight — indicators to watch, not events we claim will happen. A deep read of Signpost 5, companion to Signposts and Three Paths for the Agentic State.

When something goes wrong in an agentic system, the most common honest answer to “which agent did this, and who let it?” is a shrug. An agent planned across several steps, called some tools, wrote to some memory, handed a subtask to another agent, and produced an outcome — and no single identifiable actor, carrying named authority, sits anywhere in that chain. This signpost asks whether that shrug is still possible: can you tell which agent acted, under whose authority, and within what limits? Where the answer is no, everything downstream collapses, because you cannot record, refuse, or stop the action of an actor you cannot even name.

This is the dial the agentic era turns on. The first three signposts assumed you could point at the thing that acted. In a single-model system that assumption is usually safe. In an agentic system it is exactly what breaks first: agents delegate, spawn sub-agents, pass context between steps, and message one another, and an ordinary log preserves events without preserving who, under what authority, did which part. Agent identity is the precondition that makes the record readable, the human’s refusal targetable, and the stop reachable. Without it, the other dials have nothing to grip.

Why isn’t a name in a log enough?

Because identity, in the sense that matters, is three things bundled together, and a log usually captures none of them well: who the agent is (a stable, verifiable identity that survives across sessions and versions), what it was allowed to do (its authority — the tools, data, and actions permitted to it, and the limits on them), and who stands behind it (the human or department accountable for what it does). A string in a log tells you an event happened. It does not tell you that this agent was authorised for this action, that its autonomy was bounded at this level, or that a named party answers for the result. The gap between “an event was logged” and “an identified agent acted within named authority, and someone is accountable” is the whole of this dial.

Reading the dial

Accountable. Agents carry identity and authority that can be checked after the fact. Each agent has a verifiable identity, a declared scope of what it may do, an autonomy level that rises only with matching governance, and a named human or department accountable for it — and the audit trail records which agent acted, under whose authorisation, at every consequential step. This is the direction Singapore’s agent-identity work points toward: identity as a first-class, disclosed, traceable property of every deployed agent.

Ceremonial. The identity scheme exists on paper and is never enforced or inspected. Agents have identity cards no one checks, autonomy tiers no one audits, accountable owners named in a document no one reads after an incident. The framework is adopted; the discipline is not. This is the likeliest reading precisely because the leading framework is non-binding best practice — an identity regime that is recommended but not required drifts to Ceremonial by default, because nothing forces the paperwork to become practice.

Sealed. Agents act, delegate, and call tools with no traceable provenance. This is not a hypothetical failure — it is the current baseline the standards bodies are trying to escape: agents deployed as generic service accounts, with no dedicated identity, no bounded authority, and no accountability control. On this reading, “a system did it” is not evasion; it is a literally accurate description of a system built so that no agent can be identified and no authority traced.

Live case: Singapore’s agentic identity framework (established fact)

Singapore’s Model AI Governance Framework for Agentic AI, first issued in January 2026 and updated in May 2026, is the clearest reading of where the Accountable direction lies. It is the first national-level framework built specifically for autonomous agents, and it makes agent identity a named requirement: each agent should carry a traceable identity linked to a human accountable party, with an audit trail of which agent acted under whose authorisation. Its Agent Identity Cards set out an agent’s capabilities, limits, authorised action domains, and escalation paths in a standard disclosure format, and its graduated autonomy levels raise governance requirements as an agent is allowed to do more.

That is the Accountable direction made concrete — and also the Ceremonial risk made concrete, in the same document. The framework is non-binding. It describes best practice, it does not compel it. So Singapore sits, at the time of writing, exactly on the Accountable–Ceremonial seam: the design points the right way, and whether it reads Accountable or Ceremonial in deployment depends entirely on whether anyone inspects the identity cards, audits the autonomy levels, and checks the audit trail after an incident — or whether the cards become filing. Meanwhile the standards work elsewhere confirms how far the baseline still is from either: absent a scheme like this, agents are treated as generic service accounts with no identity at all. (The governance-side test — how agent identity becomes one of the records an agent must carry to be admissible — belongs to our research strand.)

What to watch, 2026–2030 (foresight)

Outside-checkable indicators of which way this dial is drifting. All can be read from public frameworks, procurement standards, and deployment disclosures:

  • Binding versus best practice. Does agent identity move from recommended to required anywhere? A named requirement that stays voluntary everywhere is the strongest signal the dial is parked on Ceremonial.
  • Whether anyone inspects. Identity cards and autonomy tiers only count if someone reads them after an incident. Watch for audits that actually reconstruct which agent acted under whose authority — or their absence.
  • Identity surviving delegation. When an agent hands a task to a sub-agent or another agent, does the identity and authority travel with it, or does provenance dissolve at the first hand-off? Delegation is where traceability is most often lost.
  • Autonomy without matching governance. Watch for autonomy levels climbing while the governance attached to each level stays flat — capability rising faster than the accountability meant to bound it.
  • The service-account default. The clearest Sealed indicator is the quiet one: agents deployed into real workflows as generic accounts, with no identity scheme applied at all, because doing so was optional and skipping it was faster.

The direction of travel is the signal: identity schemes that stay voluntary, that no one inspects, that dissolve at delegation, attached to autonomy that keeps rising — that combination is agent identity existing as documentation while provenance quietly disappears from practice.

The honest tension

A verifiable identity and authority scheme for every agent is not free, and maximal identity is not automatically the goal. Full provenance across every tool call and hand-off carries real cost, can collide with privacy, and can harden into a bureaucracy that slows legitimate automation without adding accountability anyone uses. And identity alone proves nothing if no one ever checks it — an unread identity card is not better than no card, only more expensive. So the standard the dial holds is not “identify everything maximally.” It is: when an agent takes a consequential or hard-to-reverse action, can you establish which agent it was, what it was authorised to do, and who is accountable — well enough to challenge it? If the honest answer is that no agent can be named and no authority traced, the system is unaccountable by construction, whatever identity scheme it nominally adopted.

What this dial cannot see from outside

You can usually confirm that an identity framework has been adopted. You can rarely confirm, without an incident, whether the identity was ever checked — whether anyone reads the cards, audits the tiers, or reconstructs the chain of authority when something goes wrong. Adoption is visible; enforcement is not, until a failure tests it. The stress test is the runaway hand-off that no one can trace back to a named agent and a named owner. That limit is itself a reading: an identity scheme whose reality can only be established after an untraceable failure was closer to Ceremonial than its adoption suggested.

FAQ

Isn’t logging which agent ran already agent identity?
No. A log entry records that an event occurred. Agent identity means a verifiable actor, a bounded authority, and a named accountable party — so you can establish not just that something ran, but that this agent was allowed to do this, and who answers for it.

What’s the fastest way to read this dial?
Ask: after a bad outcome, can you name which agent acted, what it was authorised to do, and who is accountable — and did anyone actually check? If the scheme exists but no one inspects it, the dial is Ceremonial, not Accountable.

Does a framework like Singapore’s put a country on Accountable?
It points the right way, but on its own it is non-binding. Whether it reads Accountable or Ceremonial depends on enforcement and inspection — on whether the identity cards and autonomy tiers are ever actually read after an incident.

Is this foresight or established method?
Both, marked separately. What agent identity requires is established method; the Singapore framework is established fact. How the dial may drift through 2026–2030 is foresight.



Synthocracy Institute — Power & Accountability When AI Co-Decides