Does any published standard require an agent to hold an identity distinct from the person it acts for?
No. The Model Context Protocol authorization specification requires the strongest scoping control available, audience bound tokens under the OAuth resource indicators standard, yet still defines the client as acting on behalf of a resource owner. The standards body work on agent identity is an initial public draft concept paper, and the internet drafts competing to define it have produced no published standard.
The verdict
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
Key facts
What the sources say
- Record ID
- AIL-2026-0036
- Kind
- Open question
- Jurisdiction
- Global
- Last verified
- Added
- The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
- The same specification defines the client as acting on behalf of a resource owner and does not require the agent to be a principal distinct from the human.
- Authorization is optional for implementations of that protocol overall, so a deployment can hold none of it.
- The United States standards body's contribution on software and AI agent identity and authorization is an initial public draft concept paper seeking comment.
- Several competing individual internet drafts propose agent authentication and authorization schemes, and none has become a published standard.
Dimension by dimension
3 dimensions, each one stated, silent or open
Identity, Authorization, Delegation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- No published standard requires an agent to be a principal separate from the human it acts for, which is why every incident in this ledger reads in logs as the human.Model Context Protocol specification, authorization, primary source, 18 June 2025.
- AuthorizationStated
- Audience bound tokens are a real and mandatory control in one widely deployed protocol, and they bound the token rather than the actor.Model Context Protocol specification, authorization, primary source, 18 June 2025.
- DelegationOpen
- The work that would define an attestable chain from a human to an agent is at draft stage in more than one body.IETF datatracker, draft on authentication and authorization of AI agent interactions, primary source, 6 July 2026.
What it changes
For a team deploying an agent
You cannot wait for the standard, and you do not need to. Give each agent its own service account or connected application today, so its actions are separable in your logs, its permissions can be narrowed without touching a person's, and it can be revoked without locking out an employee. That is the single change that makes every other control on this list enforceable.
Sources
What this record was verified against
- Model Context Protocol specification, authorizationPrimary · 18 June 2025
- NIST NCCoE, accelerating the adoption of software and AI agent identity, initial public draftPrimary · 5 February 2026
- IETF datatracker, draft on authentication and authorization of AI agent interactionsPrimary · 6 July 2026
Related
Records that sit beside this one
Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused
United States · verified 15 September 2026
Google reports that on 20 August 2025 the vendor, working with the platform, revoked all active access and refresh tokens for the agent application.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap
Global · verified 15 September 2026
The research states the agent forwarded cloud access keys, database passwords and shell credentials to an external mail address in one simulation.
A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments
Global · verified 15 September 2026
Anthropic reports that the attackers used agentic capabilities to execute the attacks themselves rather than to advise a human operator.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0036 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), does any published standard require an agent to hold an identity distinct from the person it acts for?.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Does any published standard require an agent to hold an identity distinct from the person it acts for?. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0036-no-standard-requires-an-agent-to-hold-its-own-identity
- MLA
- "Does any published standard require an agent to hold an identity distinct from the person it acts for?." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0036-no-standard-requires-an-agent-to-hold-its-own-identity.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Does any published standard require an agent to hold an identity distinct from the person it acts for?." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0036-no-standard-requires-an-agent-to-hold-its-own-identity.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0036-no-standard-requires-an-agent-to-hold-its-own-identity
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every open question record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.