Who's really behind the login? AI agents are forcing a rethink
As AI agents act on our behalf, businesses must rethink identity, authority and trust.
The digital landscape is changing, and artificial intelligence agents are forcing a fundamental shift in the way we approach online security. Traditionally, passwords and multi-factor authentication have been relied upon to confirm a person's identity and access. However, AI agents are now capable of completing transactions and handling administrative tasks, often with minimal human oversight.
This raises three critical questions: authentication, identity, and authority. While most current infrastructure addresses the first two, it struggles to handle the third, which is where AI agents pose a significant challenge.
AI agents often operate without clear authorization, making it difficult to determine who authorized their actions, what they can do, and for how long. Most systems were designed to verify identities and confirm access, but they fall short when it comes to assessing delegated authority. This is particularly concerning as AI agents increasingly handle tasks within business workflows.
The UK has made progress in addressing the identity aspect through the Data (Use and Access) Act, which has put Digital Verification Services on statutory footing. Some organizations have even introduced mandatory identity verification for directors and individuals with significant control. However, these measures do not fully address the issue of authority.
Businesses need to move beyond identity verification and focus on applying delegated authority. This means granting agents specific, limited permissions rather than broad, standing access. Each agent should be able to prove its limited mandate and provide a clear record of who authorized its actions and when they can be revoked. This approach significantly reduces the risk of a compromised or mis-scoped agent causing extensive damage.
To effectively manage AI agents, businesses should address five key questions: who or what is acting, who authorized it, what it can do, under what constraints, and whether that authority is still valid. This aligns with existing identity standards and the concept of 'on-behalf-of' delegation, which could serve as a solid foundation for building a more robust security framework.
The UK government has a crucial role to play in extending existing delegated authority frameworks to cover AI agents. The DVS Trust Framework already recognizes delegated authority when a person acts on behalf of another organization. However, it does not yet address how this principle applies when the delegate is software. The UK needs to work on extending this thinking to cover AI agents, ensuring that they can present machine-verifiable mandates outlining who authorized them, what they can do, under what constraints, for how long, and whether that authority is still valid.
Digital wallets could potentially serve as a suitable infrastructure for storing these mandates alongside verified credentials.
By proactively addressing the third question of authority, the UK can establish a more secure and efficient online environment. This shift will move trust online from relying solely on login credentials to verifying who or what is truly acting behind the screen, under whose authority, and for how long. The UK has a narrow window to close this gap before agent deployments outpace the systems meant to govern them.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.