The missing identity layer for AI agents
AI agents now act across organizations with no verifiable identity. A new paper maps five gaps we have to close.
A paper from Takumi Otsuka, Kentaroh Toyoda, and Alex Leung takes on the part of the AI agent conversation most people leave for later: identity. Agents now run real transactions and whole workflows across organizations, handing work down chains of sub-agents with no person watching each step. The authors define identity for an entity that has no body, no lasting memory, and no legal standing, then run a gap analysis across the agent identity lifecycle.
They set human identity frameworks against what exists for agents and find the human models do not carry over. Five gaps stay open: verifying what an agent actually intends, tracing accountability when one agent hands work to another, keeping an agent's identity intact over time, seeing into how these systems are governed, and sustaining all of it in operation. Their read is that these gaps call for foundational research, because the differences between people and agents are structural and everyday engineering fixes do not reach them.
Identity is the layer accountability sits on. If you cannot say which agent acted, on whose behalf, and with what authority, every governance rule above it is writing without a signature. These standards are being set now, and the people who will answer for what agents do should be in the room before the defaults harden.