AI agents are booking meetings, executing transactions, managing access, and making decisions on behalf of real people and organisations. Right now. But as we rush to delegate, a critical question goes unanswered: who is the agent, and who is responsible for what it does?
This keynote traces the identity and accountability crisis at the heart of the AI agent revolution through three fault lines:
1. The Binding Problem
An agent acting on your behalf needs a cryptographic identity, not your password. Yet in practice, most agent deployments still use credential delegation, the same model as a shared service account. We will examine the technical challenge of binding an agent's actions to a human mandate, and why current IAM infrastructure was never built for this.
2. The Accountability Gap
Anthropic's legal challenge over AI use in military applications without human oversight is not a US defence story. It is a preview of the accountability questions every enterprise will face. When an agent makes a decision with real consequences, who is liable? The vendor? The deployer? The human who authorised the agent? The agent itself? Current regulatory frameworks diverge sharply, and China's ban on synthetic AI relationships for minors shows how quickly the geopolitical landscape can shift.
3. The Four-Question Framework
You will leave with a practical assessment framework: is your organisation ready, legally, technically, and ethically, to say yes to the bot?