Businesses and governments are considering AI agents for tasks such as reconciling accounts, negotiating with suppliers, signing documents and submitting public filings. But as these systems act independently, capability is only part of the challenge.
The central issue is accountability: who authorized an agent, whose interests it represents, where its authority ends and who is responsible when something goes wrong? A more advanced model alone will not resolve that gap.
The article argues that agents need clear permission guardrails and an audit trail linking each action to the person who authorized it. Permissions could allow an agent to view financial information without changing it, prepare a payment without approving it, or order from named suppliers up to a fixed amount. They could also expire after one transaction, one working day or a specific contract, with authority that can be withdrawn separately from the responsible person’s credentials.
Estonia began developing a state-backed AI-agent registration system in June. Under the current proposal, a person would receive a registered numeric identifier that could link to one or more agents. Operations would be treated as machine actions, with the natural person serving as the identity anchor and remaining liable within the authorization framework.
The proposal builds on Estonia’s digital identities and existing systems for delegated permissions. The article concludes that AI agents need a technically and legally binding framework defining who they represent, what they can do and who remains responsible.
Comments
0No comments yet. Be the first to comment.