AI agents are becoming digital employees: they plan, invoke tools, coordinate subagents, and create real-world consequences. But unlike employees, their identity boundaries are still unstable. If the model changes, is it still the same agent? If several models share memory and policy, are they one actor or many? As agent populations scale into the tens or hundreds around each worker, this becomes not just an AI problem, but an identity governance problem involving registration, ownership, authority, review, and deprovisioning.
This keynote argues that agentic AI is fundamentally a delegated authority problem. It examines remote agent identification, downstream trust, non-deterministic supply chain risk, principal-side oversight, and the need for evidence about intent, action, and result. It concludes that the actuarial basis for agentic AI risk is still immature, so the urgent task is to build the evidence infrastructure now to make accountability, liability, and insurance possible.