Free public instrument from GAGE
The Agent Authority Ledger
As of September 2026 this ledger holds 34 records across 6 jurisdictions: 25 verified at a primary source, 2 reported by a secondary source, 0 announced with no document yet, 3 searched and absent, and 4 open questions. By kind: standard or protocol 14, draft in progress 4, guidance 7, binding law 5, open question 4.
- 34
- Records
- 25
- Verified at the source
- 3
- Announced or absent
- 4
- Open questions
6 jurisdictions, 49 primary sources
2 more reported, primary not reached
0 announced with no document, 3 searched and absent
Posed, sourced, not answered
As of 15 September 2026 the GAGE Agent Authority Ledger records 25 verified instruments, 2 reported at a secondary source, 0 announcements without a document, 3 absences and 4 open questions, across 6 jurisdictions. Counts are a floor, not a ceiling: an instrument the ledger has not found is not on it.
Why this ledger exists
Autonomy requires attributable authority
We built Know Your Customer, then Know Your Business. Agents now communicate, purchase, execute code, move information, operate software and act on delegated authority, and the question is no longer whether the model is safe but who this agent is, who owns it, who authorized it, what it may read, write, delete, publish and spend, whether it may create another agent, what requires a human, where the audit record is, and how it is revoked.
Those questions are being answered in pieces: an identity concept paper here, a protocol authorization section there, a payment network's agent rules, an Internet Draft on agent passports, a bank chairman asking for a Know Your Agent framework. This ledger keeps the record of every piece, says which of the eight questions each one actually answers, and records where none of them does.
Every row is fetched at its source where the source could be reached, and says so where it could not. The verdict language is the discipline: a reader learns five words once and never has to guess what a row claims.
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Reported, primary not reached
A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.
Announced, no document yet
A body has said it will act. No document exists yet, so the row records the statement and nothing more.
Absent
The ledger searched and found no instrument. The record says where it looked and when.
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
The grid
What the documents state, and where they are silent
For each of the eight Know Your Agent dimensions, how many documents on the ledger state a rule for it and how many are silent. A silent cell is a document the ledger read that does not address that dimension.
Identity
13 stated, 2 silent, 1 open, 2 reported.
Authorization
10 stated, 4 silent, 1 reported.
Delegation
2 stated, 5 silent, 1 open.
Limits
11 stated, 1 silent, 1 open, 1 reported.
Human approval
5 stated, 1 silent, 1 reported.
Logging and audit
4 stated, 0 silent, 1 reported.
Revocation
2 stated, 1 silent.
Accountability
11 stated, 0 silent, 1 open.
Side by side
Every jurisdiction, counted by verdict and by kind
United States
4 records
- Verified
- 3
- Reported
- 0
- Announced
- 0
- Absent
- 1
- Open question
- 0
1 standard or protocol, 1 draft in progress, 1 guidance, 1 binding law.
European Union
4 records
- Verified
- 3
- Reported
- 0
- Announced
- 0
- Absent
- 1
- Open question
- 0
4 binding law.
United Kingdom
1 record
- Verified
- 1
- Reported
- 0
- Announced
- 0
- Absent
- 0
- Open question
- 0
1 guidance.
India
1 record
- Verified
- 0
- Reported
- 1
- Announced
- 0
- Absent
- 0
- Open question
- 0
1 guidance.
Singapore
1 record
- Verified
- 1
- Reported
- 0
- Announced
- 0
- Absent
- 0
- Open question
- 0
1 guidance.
Global
23 records
- Verified
- 17
- Reported
- 1
- Announced
- 0
- Absent
- 1
- Open question
- 4
13 standard or protocol, 3 draft in progress, 3 guidance, 4 open question.
Figures of record
Every number on this ledger, with who measured it and when
5 figures, each one printed in the unit its publisher used, beside the publisher and the date it was true. Nothing here is summed across sources, converted between units, or forecast.
- 10 risks
Risks named in the list. OWASP Top 10 for LLM Applications 2025
OWASP Gen AI Security Project, Top 10 for LLM Applications, primary source, as of .
- 7 dimensions
Constraint dimensions a delegation chain may not widen across. Agent Passport System, an IETF Internet-Draft
IETF Datatracker, draft-pidlisnyi-aps-03, primary source, as of .
- 4 dimensions
Dimensions in the framework. IMDA Model AI Governance Framework for Agentic AI
IMDA, Model AI Governance Framework for Agentic AI, primary source, as of .
- 10 risks
Risks named in the list. OWASP Top 10 for Agentic Applications 2026
OWASP Gen AI Security Project, primary source, as of .
- 6 months
Minimum period a deployer keeps a high risk system's logs. EU AI Act Article 26, deployer obligations
AI Act Explorer, Article 26, secondary source, as of .
The ledger
Every record, newest first
34 records. Each row opens a page carrying the answer, the verdict and what it means, the key facts, the figures with their sources, what it changes for a team deploying an agent, and the sources it was verified against.
Answers
What people ask the Agent Authority Ledger
What is Know Your Agent?
Know Your Agent is the question that follows Know Your Customer and Know Your Business: who an AI agent is, who it acts for, what it may do, what requires a human, where the record is and how it is revoked. No single standard defines it as of September 2026; this ledger records the 34 documents that each answer part of it, with the verdict for each.
Is there a standard for AI agent identity?
Not a finished one. 25 verified documents on the ledger touch agent identity, authorization or delegation, 4 of them drafts still being written (Web Bot Auth architecture, an IETF Internet-Draft; Agent Passport System, an IETF Internet-Draft; The OAuth 2.1 Internet-Draft; NIST concept paper on software and AI agent identity and authorization). The record pages say which dimensions each addresses and which it leaves silent.
Which laws bind an agent's operator today?
5 binding laws on the ledger: No EU instrument defines an AI agent (European Union); No binding United States federal law defines an AI agent's identity or authorization (United States); EU AI Act Article 26, deployer obligations (European Union); EU AI Act Article 14, human oversight (European Union); EU AI Act Article 12, record keeping (European Union). None of them defines an AI agent; each binds the operator through duties written for AI systems, records and human oversight.
Which dimension is most often left silent?
Delegation: 5 documents on the ledger address agents without a rule for it, followed by authorization at 4. The grid on this page counts every dimension.
What is settled?
14 records of kind standard or protocol are on the Agent Authority Ledger as of September 2026: No international standard governs revoking an agent's authority; ISO/IEC 42001, AI management system; Mastercard Agent Pay; Visa Trusted Agent Protocol; SPIFFE workload identity; A2A protocol, agent to agent authentication; and 8 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What is being written?
4 records of kind draft in progress are on the Agent Authority Ledger as of September 2026: Web Bot Auth architecture, an IETF Internet-Draft; Agent Passport System, an IETF Internet-Draft; The OAuth 2.1 Internet-Draft; NIST concept paper on software and AI agent identity and authorization. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What do regulators and security bodies advise?
7 records of kind guidance are on the Agent Authority Ledger as of September 2026: State Bank of India chairman calls for know your agent; ICO tech futures report on agentic AI; IMDA Model AI Governance Framework for Agentic AI; OWASP Top 10 for Agentic Applications 2026; OWASP Top 10 for LLM Applications 2025; Model Context Protocol security best practices; and 1 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What binds an agent's operator today?
5 records of kind binding law are on the Agent Authority Ledger as of September 2026: No EU instrument defines an AI agent; No binding United States federal law defines an AI agent's identity or authorization; EU AI Act Article 26, deployer obligations; EU AI Act Article 14, human oversight; EU AI Act Article 12, record keeping. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What has nobody settled?
4 records of kind open question are on the Agent Authority Ledger as of September 2026: Does a spending limit belong to the agent or to the principal; How does a sub agent's authority attenuate; Can an agent hold a credential of its own; Who is liable when a delegated agent exceeds its mandate. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What do the verdicts mean?
Verified: the document exists and the ledger fetched it at its publisher. Reported: a reliable secondary source carries it and the primary could not be reached. Announced: a body said it will act and no document exists. Absent: the ledger searched and found nothing, and the search is written into the record. Open: a question nobody has settled, posed and not answered.
How current is the Agent Authority Ledger?
Every record carries the date it was last verified; the ledger as a whole was last verified 15 September 2026 and holds 34 records with 49 primary sources. A change moves the record's own date and appears on the changelog, so a reader who cited a row can see whether it moved.
Every surface
Cut the ledger the way you need it
By jurisdiction
By kind
Every record page
- AAL-2026-0034: Does a spending limit belong to the agent or to the principal
- AAL-2026-0033: How does a sub agent's authority attenuate
- AAL-2026-0032: Can an agent hold a credential of its own
- AAL-2026-0031: Who is liable when a delegated agent exceeds its mandate
- AAL-2026-0030: No international standard governs revoking an agent's authority
- AAL-2026-0029: No EU instrument defines an AI agent
- AAL-2026-0028: No binding United States federal law defines an AI agent's identity or authorization
- AAL-2026-0027: ISO/IEC 42001, AI management system
- AAL-2026-0026: State Bank of India chairman calls for know your agent
- AAL-2026-0025: ICO tech futures report on agentic AI
- AAL-2026-0024: IMDA Model AI Governance Framework for Agentic AI
- AAL-2026-0023: EU AI Act Article 26, deployer obligations
- AAL-2026-0022: EU AI Act Article 14, human oversight
- AAL-2026-0021: EU AI Act Article 12, record keeping
- AAL-2026-0020: Mastercard Agent Pay
- AAL-2026-0019: Visa Trusted Agent Protocol
- AAL-2026-0018: SPIFFE workload identity
- AAL-2026-0017: A2A protocol, agent to agent authentication
- AAL-2026-0016: OWASP Top 10 for Agentic Applications 2026
- AAL-2026-0015: OWASP Top 10 for LLM Applications 2025
- AAL-2026-0014: Web Bot Auth architecture, an IETF Internet-Draft
- AAL-2026-0013: Agent Passport System, an IETF Internet-Draft
- AAL-2026-0012: The OAuth 2.1 Internet-Draft
- AAL-2026-0011: RFC 7591, OAuth 2.0 dynamic client registration
- AAL-2026-0010: RFC 8693, OAuth 2.0 token exchange
- AAL-2026-0009: RFC 9728, OAuth 2.0 protected resource metadata
- AAL-2026-0008: RFC 8707, resource indicators for OAuth 2.0
- AAL-2026-0007: RFC 6749, the OAuth 2.0 authorization framework
- AAL-2026-0006: MCP 2026-07-28 authorization hardening
- AAL-2026-0005: Model Context Protocol security best practices
- AAL-2026-0004: Model Context Protocol authorization
- AAL-2026-0003: NIST SP 800-63-4 Digital Identity Guidelines
- AAL-2026-0002: NIST AI Agent Standards Initiative
- AAL-2026-0001: NIST concept paper on software and AI agent identity and authorization
Take the data
The whole dataset, free, in two formats
Licensed CC BY 4.0. Use it in an article, a paper, a slide or a product. The only condition is attribution, and the citation page gives you the line to paste.
- ledger.jsonEvery field of every record, the shape documented on the data page.
- ledger.csvOne row per record, figures and facets flattened, for a spreadsheet or a stats package.
How the ledger is built, what the verdicts mean, and what the gate refuses: the method page. Every change, dated: the changelog. The kinds on the shelf: standard or protocol, draft in progress, guidance, binding law, open question. Something missing or wrong is a bug, and we want to hear about it. Document a real agent against these records with Know Your Agent. Score a tool server with the MCP Permission Risk Checker. What happens when a dimension is missing is on the Agent Incident Ledger.
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), agent authority ledger.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Agent Authority Ledger. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger
- MLA
- "Agent Authority Ledger." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Agent Authority Ledger." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
10 risks
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.