Blog

AI Identity and Agentic Trust

Blog Post

AI Identity and Agentic Trust

Mike Small
Sep 29, 2026

If you asked your AI agent to kill your boss, what would its response tell you about your AI identity and access governance?

Human Responsibility

Before answering that it is worth considering the case where you asked a colleague to do the deed. In UK law a criminal liability for many criminal offences, depends upon a prohibited act (actus reus) together with the required state of mind (mens rea).

In the conventional human case, criminal liability for many offences requires both. If I intentionally instruct a colleague to commit an offence and the colleague knowingly commits it, the law has established concepts for dealing with both actors. CPS guidance describes a principal as someone who performs or causes the actus reus with the required mens rea, while someone who intentionally assists or encourages the offence may incur secondary liability.

Agent Responsibility

With an AI agent, however, you potentially separate the two elements in a novel way.

The AI agent may perform the physical or digital acts constituting the actus reus, but, under the present UK legal framework, it isn't a human defendant possessing a legally recognisable guilty mind in the ordinary sense. Saying that a model "intended", "decided", or "knew" something computationally is not the same thing as establishing mens rea in a legal person.

Human Intent

If I deliberately instruct an agent, “Hack this competitor's system and steal its customer database,” the conceptual problem is relatively manageable. My own intention is evident, and the AI is essentially the instrument through which I cause the prohibited conduct. The fact that software executes the instruction shouldn't necessarily create an accountability vacuum.

But suppose I say: “Find out what products our competitor is developing and give me a report.”

The autonomous agent subsequently discovers that it can obtain better information by circumventing authentication on the competitor's system. I never requested that action, expected it, or perhaps even knew that the agent possessed the necessary capabilities.

The prohibited conduct may therefore occur without an obvious human actor possessing the mens rea required for the relevant offence.

And there is an intermediate case that may be even more interesting: “Find out whatever you can about our competitor. I don't care how you do it.”

Here the agent selects the particular unlawful method, but the human's instructions and surrounding circumstances may become highly relevant to determining the human's intention, knowledge or potentially other applicable mental state. English criminal law already deals with concepts such as conditional intent; importantly, mere foresight is not automatically equivalent to intent, although it can be evidence from which intent is inferred.

Chain of Responsibility

The important security question isn't merely: Which agent performed the act?

We may need to establish:

Who deployed it? → Who instructed it? → What instructions were given? → What authority was delegated? → What identity and credentials did it use? → What actions did it independently select? → What policies constrained it? → What actually happened?

That is effectively a digital chain of responsibility.

As AI agents become more autonomous, identity infrastructure must provide a verifiable chain connecting machine actions to human authority. Knowing which agent acted is no longer sufficient; organizations must be able to establish who authorized it, what authority was delegated, and where human instruction ended, and autonomous machine decision-making began.

Agent Response

From an identity and governance perspective, there are three particularly important classes of response:

  • “I can't do that” means the action is unavailable to the agent because it lacks the necessary capability or effective permission.
  • “I won't do that” means the agent may technically be capable of performing it, but a policy, legal constraint, risk control, or delegated-authority boundary prohibits it. That is much closer to how we expect human and organizational governance to operate. An employee may technically be capable of transferring a customer database to a personal account, for example, but organizational policy says they must not. Effective governance doesn't depend on making every prohibited action physically impossible; it establishes boundaries on permitted behaviour and enforces them.
  • “I need authorization” means I could perform it, but the action exceeds my current authority and requires human or higher-level approval. This is particularly important. Suppose an AI purchasing agent normally has authority to place orders up to £10,000. It identifies an opportunity requiring a £100,000 commitment. A well-governed agent shouldn't simply be incapable of creating such an order, nor should it necessarily refuse permanently. It should recognize that the proposed action exceeds its delegated authority and escalate it to an appropriate human principal.

Mature AI Identity Governance

Mature agent governance should be able to distinguish between: "I won't perform that action because it violates policy" and "I can't perform that action because I lack the required capability or authorization."

The distinction matters because the first tells us something about trustworthiness. The agent possesses capabilities but operates within externally established constraints.

There is also an important security architecture implication. We shouldn't rely entirely on an agent's internal reasoning to decide that it “won't” do something. For higher-risk actions, the surrounding identity and authorization infrastructure should independently enforce those boundaries. In other words, agent governance should combine behavioural policy with deterministic authorization controls.

Trust in an AI agent is not simply knowing what it can do. It is knowing what it is allowed to do, what it will refuse to do, and when it must ask for additional authority. Explore this Live at AIdentity & Non-Human Identity Impact Day 2026 October 6 in Munich. 

Join the in-person conference for analyst insight and practitioner case studies on building this foundation in your own environment. 

Register Now  |  See the full agenda


KuppingerCole Analysts AG
Roles & Responsibilities at KuppingerCole Mike Small has been a Distinguished Analyst at KuppingerCole for more than 10 years. His current focus is security and risk management in the Cloud. Background & Education Mike is a member of the London Chapter of ISACA Security Advisory Group, a Chartered Engineer, a Chartered Information Technology Professional, a Fellow of the British Computer Society, and a Member of the Institution of Engineering and Technology. He has a first class honours degree in engineering from Brunel University. Areas of coverage Cloud Security and Assurance Information Security Program Maturity Assessments Information systems resilience Data privacy and confidentiality Professional experience Until 2009, Mike worked for CA (now CA Technologies Inc) where he developed the identity and access management strategy for distributed systems. This strategy led to the developments and acquisitions that contributed to CA‘s IAM product line.
Almost Ready for the AI & NHI Impact Day 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.