THE AGENT BECOMES A PRINCIPAL. The Birth of Machine Actors Inside Human Institutions
Synthocracy Institute — P0 / #17
5 September 2026
AI does not need legal personhood to acquire institutional power. It only needs an identity, a mandate, permissions, a place in the workflow, and the ability to act.
For most of the history of computing, an organisation could divide the actors inside its digital systems into two broad categories. There were people, and there was software. A person had an identity, a job, permissions and responsibility. Software was infrastructure. It processed instructions, stored records, executed predefined functions and appeared in logs as applications, services or machines.
That distinction is beginning to break.
Google now gives AI agents a dedicated identity type that it explicitly describes as a first-class principal, separate from both human identities and generic service accounts. Microsoft Entra Agent ID gives agents their own identities and introduces owners, sponsors and managers around them. An autonomous Microsoft agent can authenticate using its own identity and act without a human user being present. AWS is building authorization systems that determine which principal may invoke which agent tool against which resource and under which conditions. NIST has launched a national initiative around agent identity, authorization, authentication and interoperability. At the same time, China is developing national agent-interconnection standards covering identity, discovery, interaction and tool invocation. (Google Cloud)
These systems are technically different. They belong to different companies, standards traditions and political environments. They should not be collapsed into one architecture.
But they reveal a common transformation.
The AI agent is being moved from the category of software capability into the category of identifiable institutional actor.
This is not legal personhood. It is not citizenship. It does not establish consciousness, moral status, rights or independent sovereignty.
It is nevertheless a major redistribution of practical authority.
An entity that can be separately identified can be separately authorised. An entity that can be authorised can receive access. An entity with access can act. An entity whose actions are attributed to its own identity can acquire a persistent operational position inside an organisation.
The central governance question therefore changes.
It is no longer only:
What can the model do?
It becomes:
What is this agent allowed to do, in whose name, for how long, under whose responsibility, and who can remove that authority?
That is a Synthocracy problem.
Evidence boundary
This article distinguishes three registers.
[A — EMPIRICAL] describes documented technical systems, standards and institutional practices available as of 5 September 2026.
[B — ANALYTICAL] interprets the structural consequences of those systems.
[C — FORESIGHT] identifies plausible future developments that have not yet been established.
The article does not claim that AI agents have become legal persons, that companies are transferring corporate responsibility to machines, that there is already a single global agent identity infrastructure, or that the United States and China have adopted equivalent governance models.
Its narrower claim is stronger because it is observable:
Major technology providers and standards institutions are beginning to treat AI agents as separately identifiable, authorisable and governable actors within digital systems.
1. Principal does not mean person
The word principal requires care.
In identity and access management, a principal is an entity whose identity can be established and to which permissions can be attached. A principal may be a person, account, workload, service or another authenticated entity.
A principal therefore does not need consciousness.
It needs recognisability within an authorization system.
That distinction makes Google’s terminology remarkable.
[A — EMPIRICAL]
Google Cloud states that AI agents can receive a dedicated Agent Identity, which it describes as “a new, first-class principal type distinct from human identities or generic service accounts.” The identities are cryptographically protected and based on SPIFFE. Google says the architecture allows organisations to distinguish agents acting autonomously from agents acting on behalf of a human user and to apply agent-specific authorization rules. (Google Cloud)
This is not a philosophical statement.
It is an architectural one.
Yet architectural classifications matter because institutions increasingly exercise power through architecture.
A bank does not need to believe that an agent is a person before giving it permission to query a customer database.
A corporation does not need to recognise machine rights before giving an agent permission to modify a CRM record.
A cloud platform does not need a theory of machine consciousness before allowing an agent to initiate a deployment.
The question of machine agency therefore has an institutional form that arrives before the debate about machine personhood.
An agent can become an actor in the technical constitution of an organisation without becoming a subject in its legal constitution.
That gap deserves far more attention than it currently receives.
2. Microsoft has already built the beginnings of an organisational chart for agents
Google’s first-class principal is one signal.
Microsoft’s architecture goes further.
[A — EMPIRICAL]
Microsoft Entra Agent ID distinguishes autonomous agents from agents acting on behalf of users. Microsoft documentation states that autonomous agents may operate independently using their own identities, making decisions and taking actions without human intervention—for example in infrastructure management or security operations. Authentication can occur directly through the agent identity rather than through a human user’s identity. (Microsoft Learn)
But identity alone is not the most interesting part.
Microsoft also introduces three administrative relationships around the agent:
owner,
sponsor,
manager.
The owner handles technical administration.
The sponsor provides business accountability for the agent’s purpose and lifecycle.
The manager can occupy a position analogous to an organisational supervisor.
At least one sponsor is required for an agent identity. Sponsors can participate in access requests, lifecycle decisions and, during security incidents, decisions about whether agent behaviour was expected and whether suspension or permission changes are appropriate. Microsoft even provides lifecycle mechanisms designed to prevent orphaned agents when a sponsor changes role or leaves the organisation. (Microsoft Learn)
Pause on what has happened structurally.
The architecture now contains:
AGENT
↓
IDENTITY
↓
SPONSOR
↓
MANAGER
↓
ACCESS
↓
LIFECYCLE
↓
AUDIT
That resembles the administrative skeleton of a workforce relationship far more than the traditional relationship between an employee and a software tool.
Again, this does not make the agent an employee.
But it means that the infrastructure used to govern organisational participants is beginning to extend towards machine actors.
Microsoft also records actions made through agent identities as having been performed by an AI agent, rather than merely collapsing them into the identity of the person who created it. (Microsoft Learn)
That creates something extremely important for accountability:
actor separation.
The system can begin to distinguish:
the human who authorised,
from
the agent that acted.
This distinction is foundational for any serious future system of authority provenance.
3. AWS is turning mandate into executable policy
Identity answers one question:
Who is acting?
Authorization answers the next:
What may that actor do?
AWS AgentCore provides a particularly clear example.
[A — EMPIRICAL]
AgentCore’s policy architecture can evaluate authorization through three basic objects:
principal → action → resource.
AWS illustrates the model with deterministic rules that can, for example, permit a particular agent to issue a refund only below a specified financial threshold. Tool calls can be intercepted before execution, compared against policy and denied by default when no authorization applies. The decision can then be logged for monitoring and compliance. (Dokumentacja AWS)
The important part is not the refund example.
It is the movement of governance out of natural-language instruction and into machine-enforceable authority boundaries.
Consider two instructions.
The first says:
“Handle customer refunds responsibly.”
The second says, structurally:
principal: refund-agent
action: process-refund
resource: refund gateway
condition: amount < $1,000
The first is an intention.
The second is a mandate made executable.
AWS also supports user-delegated OAuth access in which the agent obtains explicit consent for specified scopes while maintaining separation between the agent’s identity and the user’s authorization. (Dokumentacja AWS)
That separation matters.
It gives us three distinct objects:
IDENTITY — which agent is this?
AUTHORITY — what may it do?
DELEGATION — whose authority is it using?
These are often blurred in ordinary discussions of AI agents.
They should not be.
4. The Internet is beginning to ask who the machine is
A second boundary is changing outside the enterprise.
Web infrastructure has historically attempted to distinguish people from bots primarily because automated traffic was often unwanted, abusive or difficult to attribute. CAPTCHAs are perhaps the most visible expression of that assumption.
But legitimate agents now need to browse and act.
AWS AgentCore Browser supports an emerging Web Bot Auth architecture in which agent traffic can cryptographically establish its identity to a website. A domain can then choose to allow, block, monitor or rate-limit verified automated traffic. (Dokumentacja AWS)
The old question was:
Human or bot?
The new question is becoming:
Which bot?
And shortly after that:
Whose bot?
Then:
With what authority?
Then:
Allowed to do what?
That progression is important because it turns machine traffic from an undifferentiated technical category into a population of potentially distinguishable actors.
The web was built primarily around human accounts and machine services.
The agentic web may require a third category: delegated machine participants.
5. NIST has recognised that identity and authority are now national infrastructure problems
This transformation is no longer confined to vendor product design.
[A — EMPIRICAL]
In February 2026, NIST launched an AI Agent Standards Initiative focused on interoperable and secure agents capable of autonomous action. Its stated areas include agent security, authentication, identity infrastructure and trustworthy interaction between humans and agents and among agents themselves. NIST explicitly observes that agents can already work autonomously for hours, manage emails and calendars, write and debug code, and shop for goods. (NIST)
Separately, the National Cybersecurity Center of Excellence issued a concept paper focused specifically on software and AI agent identity and authorization. NIST frames the problem around the fact that agents obtain access to data, tools and applications and therefore require appropriate identification and authorization controls. (NIST Computer Security Resource Center)
This is significant for a simple reason.
States standardise problems when those problems become infrastructural.
Identity standards did not become important because computer scientists found identity philosophically interesting. They became important because finance, administration, security, telecommunications and commerce could not function reliably without knowing which actor had done what.
Agent identity is beginning to enter the same institutional logic.
6. China is confronting the same structural problem
The political architecture differs.
The technical need does not disappear.
China’s emerging national agent-interconnection programme addresses identity, discovery, interaction and tool access at a system level. The purpose is to allow heterogeneous agents to recognise one another and interact across environments while supporting management and interoperability.
The crucial comparative insight is not that China, Microsoft, Google, AWS and NIST have created identical systems.
They have not.
It is that fundamentally different technological ecosystems are encountering the same structural requirements:
an agent must be identifiable;
its capabilities must be describable;
its authority must be bounded;
its interactions must be attributable;
other systems need a way to decide whether to accept it.
[B — ANALYTICAL]
This looks less like a vendor fad and more like a new infrastructure layer.
The internet required addressing.
Commerce required identity.
Cloud computing required workload identity.
Agentic computing may require actor identity plus delegated authority.
7. An agent no longer needs to borrow the human’s face
This may become one of the most consequential consequences of agent identity.
In the simplest agent architecture, the machine effectively borrows a human identity.
The human logs into an application.
The agent takes control.
The application sees:
Marcin Nowak performed action X.
But the real chain may be:
Marcin → authorised Agent A → Agent A performed X.
That distinction matters whenever the action causes a consequential result.
Who changed the financial record?
Who sent the message?
Who approved the transaction?
Who modified the infrastructure?
Who accessed the confidential document?
If the underlying systems record only the human credential, then machine agency is hidden inside human attribution.
This produces an attribution collapse.
Agent-specific identity can repair part of that collapse:
principal → mandate → agent → action → consequence.
It can make machine participation visible.
That is an important governance improvement.
But it also creates a new problem.
Once an agent can act under its own identity, the institution must decide what that identity means.
Does it represent:
the model?
a persistent agent instance?
a job?
a deployment?
a role?
a team?
a particular runtime?
a temporary delegation?
What happens after the underlying model is upgraded?
Does the identity remain the same?
If Agent A was created using model version 1 but silently moves to model version 4 with radically different capabilities, is it institutionally the same actor?
This is currently an underdeveloped governance question.
8. Identity continuity may become the hidden problem of agent governance
Consider an employee.
A company identifier usually points to a relatively stable human being even if the employee learns new skills.
An AI agent is different.
Its apparent identity can remain constant while almost everything beneath it changes.
Its model can change.
Its tools can change.
Its system prompt can change.
Its memory can change.
Its permissions can change.
Its reasoning budget can change.
Its environment can change.
Its capacity for autonomous action can change.
This creates a difficult proposition:
A persistent agent identity does not necessarily imply persistent agent capability.
Let:
where:
I = persistent agent identity,
M = model,
H = harness/runtime,
T = tools,
P = permissions,
C = context/memory configuration,
E = execution environment.
The identity I can remain constant while every other element changes.
That means conventional identity governance may be insufficient.
Humans receive access partly because organisations have assumptions about relatively stable properties of the person occupying the account.
Agent access may need to be reconsidered whenever the capability envelope changes materially.
This suggests a new practical control:
Capability Re-Attestation
A material change to the model, tools, memory, autonomy, permissions or runtime of an agent should trigger reassessment of the authority attached to its identity.
This is an analytical proposal, not an existing universal standard.
But it follows directly from the architecture now being built.
9. The human becomes the sponsor of machine authority
Microsoft’s sponsor relationship deserves more attention than it will probably receive.
It may represent an early answer to one of the central Synthocracy problems:
Where does responsibility go when the actor is not human?
Microsoft’s answer is not: responsibility goes to the agent.
It creates a human or organisational sponsor around the machine identity.
That architecture preserves a connection:
machine actor → human accountability anchor.
This can be represented as:
where:
H = human accountable principal,
M = mandate,
A = agent action.
The crucial requirement is that the connection between H and A must remain reconstructable.
If it breaks, responsibility becomes diffuse.
A human can say:
“The agent did it.”
The engineering team can say:
“The model only followed its instructions.”
The model provider can say:
“The organisation configured the agent.”
The organisation can say:
“The authorised user approved the workflow.”
The user can say:
“I never approved that particular action.”
Every statement may be partially true.
Together they can create an accountability void.
Agent identity alone does not solve this.
What is required is authority provenance.
10. Identity is not authority
This distinction should become non-negotiable.
An agent may possess a valid identity and still lack authority to perform a specific action.
Likewise, an agent may possess authority delegated by a human but still act outside the intended mandate.
And an institution may correctly authenticate an agent while incorrectly trusting it.
Therefore:
These distinctions prevent several future category errors.
A digitally signed agent request is not necessarily an authorised request.
An authorised request is not necessarily a legitimate decision.
A legitimate mandate does not ensure technically safe execution.
And technically correct execution does not answer who bears responsibility for the consequence.
Synthocracy begins precisely where these layers stop lining up neatly.
11. An AI workforce is being built administratively before it is defined legally
xAI provides a useful public-facing illustration of the same transformation.
[A — EMPIRICAL]
Grok Bot is presented as an always-on AI teammate. Bots receive their own cloud computer, sign into tools, work across applications, continue operating without constant human supervision, retain conversational context and return to the human when approval is required. (SpaceXAI)
Its security documentation exposes an interesting boundary: multiple Bots belonging to one user may share a cloud computer and access the same files, sessions and credentials; xAI explicitly warns that separate Bots should not be treated as a security boundary. (Grok API Documentation)
This exposes the difference between the social interface and the security architecture.
The social interface says:
“Here are several teammates.”
The underlying environment may still say:
“Here is one shared execution boundary.”
That is a perfect Synthocracy example.
The organisational metaphor can advance faster than the governance architecture underneath it.
A company may speak of:
AI workers,
AI analysts,
AI researchers,
AI managers.
But the relevant governance question is not what they are called.
It is whether each has separable:
identity,
authority,
credentials,
memory,
audit history,
responsibility chain,
and revocation mechanism.
12. The first machine organisations are beginning to appear
There is another threshold beyond the individually identified agent.
Agents increasingly coordinate with other agents.
That changes the problem again.
Research published this year as When Agents Evolve, Institutions Follow tested several multi-agent institutional structures while holding the underlying model constant. Across experiments, the performance difference between the best and worst organisational designs exceeded 57 percentage points within the same model family. The authors modelled institutional functions such as proposing, reviewing, execution and error correction and found that governance topology strongly affected collective performance. (arXiv)
The result should be treated as a research finding, not as proof that human political institutions map directly onto machine societies.
But it supports an important observation:
Organisation can become part of capability.
We already learned from Astra that:
MODEL ≠ DEPLOYED SYSTEM.
Multi-agent research adds another layer:
DEPLOYED SYSTEM ≠ ORGANISED SYSTEM OF AGENTS.
A future capability envelope may depend on:
where G is the governance topology connecting the agents.
Who proposes?
Who executes?
Who checks?
Who may veto?
Who escalates?
Who receives new tasks?
Who can create another agent?
These are no longer only political questions.
They are becoming systems-engineering questions.
And eventually they may become organisational-law questions.
13. The machine actor has arrived before machine responsibility
This is where the structural asymmetry becomes most important.
The technological stack is moving quickly towards:
identity ✔
authentication ✔
permissions ✔
memory ✔
tools ✔
execution ✔
workflows ✔
manager/sponsor relationships ✔
audit logs ✔
But the machine still cannot bear human responsibility in the ordinary institutional sense.
It cannot go to prison.
It cannot lose a professional licence.
It cannot be morally blamed in a way that satisfies institutional accountability.
It does not hold corporate fiduciary obligations.
It cannot personally compensate an injured party.
It cannot stand before a regulator as the ultimate bearer of a legal duty merely because its IAM identity appears in a log.
This produces a fundamental asymmetry:
Execution is becoming machine-addressable faster than responsibility is becoming machine-transferable.
That may be one of the defining governance conditions of the agentic era.
14. The Principal Gap
We can now define the central problem.
The Principal Gap
The Principal Gap is the distance between the operational authority an AI agent can exercise as an identifiable digital actor and the human or institutional responsibility that must ultimately answer for its consequences.
This concept should be used cautiously. It is an analytical Synthocracy term, not an established industry definition.
But it passes the translation test.
An agent can increasingly receive:
a name,
an identity,
access,
permissions,
tasks,
a sponsor,
a manager,
a computer,
and sometimes other agents.
What it does not receive is final responsibility.
The larger the difference between those two sides, the larger the Principal Gap.
Conceptually:
where the second term remains structurally close to zero for many forms of legal and moral responsibility.
This is not intended as a directly measurable scalar today.
It expresses the asymmetry requiring measurement.
A serious research programme could instead operationalise observable proxies:
scope of permissions;
value of transactions;
irreversibility of actions;
autonomous work horizon;
number of downstream systems;
delegation depth;
human intervention latency;
revocation latency;
quality of authority provenance;
clarity of accountable sponsor.
15. What changes when the agent becomes a principal?
[B — ANALYTICAL]
Five consequences follow.
First, agent inventory becomes governance infrastructure. An organisation cannot govern machine authority if it does not know which agents exist. Microsoft’s concern about orphaned agents demonstrates that machine lifecycle management is already becoming an institutional problem. (Microsoft Learn)
Second, authorization becomes more important than prompting. Safety instructions written in natural language cannot substitute for deterministic permission boundaries around consequential tools.
Third, identity must travel with action. If agent activity disappears into a human account, authority provenance is lost.
Fourth, upgrading the agent may require re-authorising it. Persistent identity combined with changing capability creates a new version-governance problem.
Fifth, human accountability must attach to the machine before something goes wrong, not be reconstructed afterwards from corporate responsibility diagrams.
These are not distant ASI problems.
The infrastructure creating them is being deployed now.
16. A minimal Agent Authority Record
The Synthocracy Institute should turn this analysis into an instrument.
For every consequential organisational agent, a minimal record should be able to answer:
| Field | Question |
|---|---|
| Agent identity | Which agent acted? |
| Runtime identity | Which model/version/runtime was operating? |
| Sponsor | Which human or organisational unit is accountable for its continued existence? |
| Mandate | What purpose was the agent authorised to pursue? |
| Permissions | Which systems, tools, data and actions can it access? |
| Delegation source | Whose authority enabled those permissions? |
| Delegation depth | Can the agent pass authority to another agent? |
| Autonomy boundary | Which actions require human escalation? |
| Capability version | Has the agent materially changed since authorization? |
| Audit trail | Can its action trajectory be reconstructed? |
| Stop authority | Who can immediately suspend it? |
| Revocation path | How rapidly do revoked credentials propagate? |
| Consequence recovery | Which actions can be reversed? |
This is where research becomes governance infrastructure.
The Institute’s masterplan already defines its purpose not as building a private vocabulary but as making moved decision power visible, challengeable and usable by outsiders.
The Agent Authority Record could become one practical implementation of that commitment.
17. What we do not yet know
A revolutionary thesis is valuable only if it leaves its unknowns visible.
We do not yet know whether first-class agent identity will become a universal architectural pattern or remain fragmented across ecosystems.
We do not know whether organisations will reliably preserve the distinction between agents acting autonomously and agents acting on behalf of humans.
We do not know whether agent identities will remain attached to stable capability profiles.
We do not know how delegation will propagate through multi-agent chains.
We do not yet have a broadly accepted equivalent of corporate signing authority for autonomous agents.
We do not know how quickly revocation propagates through long-running or nested agent processes.
We do not know whether machine-readable sponsorship will become enough for legal attribution.
We do not know which agent incidents will require external reporting.
And we do not know what happens when a highly capable agent has technically valid authority but reaches a consequential result its human sponsor never anticipated.
These are open research problems.
They should remain open until evidence closes them.
18. Foresight — from agent identity to agent institutions
[C — FORESIGHT]
If present trends continue, agent identity could become the base layer for something larger.
An agent identity can receive permissions.
A permitted agent can hold a role.
A persistent role can acquire history.
History can support reputation.
Reputation can influence discovery.
Discovery can influence delegation.
Delegation can produce hierarchy.
Hierarchy can produce machine organisations.
At that point, the relevant unit may no longer be:
human + AI assistant.
It may become:
human institution + machine institution.
The transition does not require consciousness.
It does not require legal rights for AI.
It does not even require AGI.
It requires only that agents become persistent enough, interoperable enough and authorised enough that organisations begin treating them as durable participants in institutional processes.
That path is no longer purely speculative.
Its first layers are visible in current identity systems.
Conclusion — The institution now has another kind of actor
For years, debates about AI governance centred on models.
Which model is safest?
Which model is most capable?
Which model should be regulated?
Astra has already complicated that picture by demonstrating how much capability can depend on runtime, harness, context and tools.
Agent identity complicates it further.
The institutional object is becoming:
That object is no longer well described by the word model.
And once the object can authenticate, invoke tools, access resources, retain state and perform actions under its own identity, it is no longer well described merely as a passive tool either.
The deeper transition of 2026 may therefore turn out not to have been that machines became intelligent enough to deserve a new philosophical label.
It may have been that human institutions quietly built a place for them to act.
Google calls that place a first-class principal.
Microsoft gives that principal a sponsor.
AWS gives it enforceable permissions.
NIST is developing identity and authorization standards around it.
Agent systems are giving it computers, memory and increasingly long-lived work.
Multi-agent research is beginning to give these actors organisational structures.
The legal system may still regard responsibility as human and institutional.
The technical system is already learning how to address the machine directly.
That gap is where Synthocracy begins.
AI does not need to become a person to become a participant in power.
It needs an identity.
It needs authority.
It needs somewhere to act.
And those three conditions are now being built.
The agent has not become sovereign.
It has become addressable.
That may be the more important threshold.
