Artificial Intelligence is transforming how organizations operate. AI is no longer limited to generating content or answering questions. Increasingly, AI systems are executing business processes, accessing enterprise applications, interacting with enterprise systems, and even making autonomous decisions.
With the AI Act, the European Union has taken the first major regulatory step toward governing Artificial Intelligence through the world’s first comprehensive legal framework for AI. While the regulation establishes obligations around transparency, human oversight, and risk management, it leaves one critical question unanswered that will become increasingly important as AI adoption accelerates:
La Inteligencia Artificial está cambiando la forma en que trabajamos. Ya no solo genera contenido o responde preguntas; empieza a ejecutar procesos, acceder a aplicaciones, interactuar con sistemas corporativos e incluso tomar decisiones de forma autónoma.
Europa ha dado el primer paso regulando esta nueva realidad con el AI Act, la primera legislación integral sobre Inteligencia Artificial. Sin embargo, mientras el reglamento establece obligaciones sobre transparencia, supervisión y gestión del riesgo, deja abierta una cuestión que será determinante en los próximos años:
How should the digital identity of an AI agent be governed?
As digital identity becomes the new security perimeter for people, it must also become the security perimeter for autonomous AI agents.
What is the European AI Act and why does it change the rules?
The AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework governing the development, deployment, and use of Artificial Intelligence. Its goal is to ensure that AI systems operating within the European Union are safe, transparent, and respectful of fundamental rights while continuing to foster innovation. To achieve this, the regulation classifies AI systems according to their level of risk:
- Unacceptable risk, which is prohibited.
- High risk, subject to strict requirements covering risk management, data quality, human oversight, and regulatory compliance.
- Limited risk, which carries transparency obligations, including Article 50, requiring organizations to disclose when users are interacting with an AI system.
- Minimal risk, with no additional regulatory obligations.
The AI Act is being implemented in phases. The provisions banning unacceptable-risk practices and the AI literacy requirements are already in force. The transparency obligations under Article 50, including the requirement to inform users when they are interacting with AI, become applicable on 2 August 2026. Following a revised implementation timeline introduced in 2026, the more demanding obligations for high-risk AI systems are now scheduled to apply from 2 December 2027.
Beyond compliance, however, the AI Act signals a broader shift in how organizations must think about AI governance. AI is no longer viewed as just another technology tool. It is becoming a core business capability that must be governed with the same discipline applied to any other critical enterprise asset.
AI is no longer just responding, it is beginning to act
Until recently, Artificial Intelligence was primarily associated with systems that generated responses, such as writing text, classifying images, or suggesting answers. Today, we are entering the era of AI agents that can take action.
An AI agent can schedule meetings in an enterprise calendar, procure goods or services within predefined spending limits, execute end-to-end workflows without human intervention, interact directly with third-party APIs, sign documents or transactions on behalf of an organization, communicate with banks and payment platforms, and, in some cases, use digital certificates to authenticate itself to other systems.
In practice, a well-designed AI agent can operate much like an employee. It may access enterprise resources, receive specific permissions, and perform assigned tasks. Crucially, it should also leave a complete audit trail of every action it takes.
Once an AI agent is capable of acting like an employee, it is no longer merely an AI application. It becomes a digital identity.
The AI Act’s biggest blind spot: AI agent identity
The AI Act rightly addresses human oversight, system traceability, and transparency for end users. These are essential safeguards. However, it does not answer the questions that matter most to security, compliance, and IT leaders once AI agents begin operating within enterprise environments:
- Who is this agent?
- How does it authenticate itself?
- How can its identity be verified across every application it interacts with?
- Who determines and governs the permissions it receives?
Today, many organizations still perceive AI primarily as an advisory tool. But once AI agents begin acting autonomously on behalf of the business, these questions become far more than theoretical.
Recent identity governance research highlights the scale of the challenge. By 2026, non-human identities, including service accounts, API keys, machine credentials, and AI agent tokens, already outnumber human identities by a significant margin within most enterprises. At the same time, more than half of organizations acknowledge that ownership of these identities is unclear, with no defined accountability for reviewing or revoking privileges when they are no longer needed.
The AI Act governs how AI systems should behave. It does not govern, with the same level of clarity, the technical identity those systems use to operate.
The regulation answers the question: “What decisions may an AI system make?”
It does not yet answer another, equally important question: “Who is this AI agent, and who is accountable for its digital identity?”
Questions that still need answers
- Who is responsible for creating an AI agent’s digital identity?
- How should it authenticate itself to enterprise applications?
- What permissions should it receive?
- Who should approve and review those permissions?
- How should its access be revoked when it is no longer required?
- How should every action performed by the agent be audited?
- How can an organization demonstrate to regulators or auditors exactly which AI agent executed a specific operation?
The next evolution of regulation: governing AI identities
This is not the first time organizations have faced a challenge like this. When businesses began digitizing employee access, Identity and Access Management (IAM) emerged. When implicit trust in corporate networks was no longer sufficient, Zero Trust became the new security model. And when organizations needed a reliable way to verify the identities of people and entities across digital environments, digital certificates became a standard mechanism for strong authentication.
Now, with autonomous AI agents operating across enterprise infrastructure, the next step is becoming clear: AI Identity Governance.
AI Identity Governance is the discipline of managing the entire lifecycle of an AI agent’s digital identity, including secure authentication, authorization, traceability, auditing, and credential revocation.
It is not intended to replace the AI Act. Rather, it is the discipline most likely to complement the regulation as future legislation evolves to address the questions that remain unanswered today.
What future AI regulation should include
1. Verifiable digital identities for AI agents
Every AI agent should have its own unique, verifiable, and non-transferable digital identity rather than relying on shared credentials or identities inherited from other systems.
2. Strong authentication based on digital certificates
AI agents should never rely on shared user accounts. If an AI agent can perform actions with the same business impact as a human employee, it requires an authentication mechanism of equal or greater strength. Digital certificates provide a cryptographically strong way to verify an agent’s identity whenever it interacts with enterprise systems.
3. AI identity lifecycle management
An AI agent’s identity should follow the same lifecycle principles already applied to employees:
- Provisioning
- Modification
- Suspension
- Revocation
Every AI agent should be created with a clearly defined purpose and scope. Its permissions should be reviewed whenever its responsibilities change, suspended when it is no longer in use, and permanently revoked when it is decommissioned. Without proper lifecycle management, organizations inevitably accumulate orphaned AI identities: active accounts with privileged access but no owner, oversight, or accountability.
4. End-to–end traceability
Organizations need complete visibility into every action performed by an AI agent:
- Who performed the action?
- When did it happen?
- Where was it executed?
- What action was taken?
- Which privileges were used?
Without a complete and verifiable audit trail, investigating incidents or demonstrating compliance to regulators and auditors, becomes extremely difficult.
5. Zero Trust for non-human identities
The Zero Trust principle is simple: Never trust. Always verify.
The same approach already applied to users and devices should also extend to AI agents and every other non-human identity. No identity, human or machine should receive implicit trust simply because it exists within the corporate network.
6. Auditability and regulatory compliance
Organizations must be able to demonstrate:
- Which AI agent performed a specific action.
- Which digital identity it used.
- Who approved its privileges.
- What evidence exists for every operation it executed.
Security incidents documented throughout 2026 demonstrate that this is far more than a compliance requirement. It is often the difference between containing a security incident and losing control of it altogether.
Redtrust’s role in AI identity governance
At Redtrust, we have spent years helping organizations govern one of their most valuable assets: corporate digital identity.
Today, organizations primarily manage the digital identities of employees and legal representatives, along with corporate digital certificates.
Tomorrow, autonomous AI agents will join that list.
Trust will depend on more than whether an AI agent makes the right decisions.
It will also depend on our ability to identify it, authenticate it, govern its permissions, and provide verifiable evidence of every action it performs.
Conclusion
Artificial Intelligence will transform how organizations operate.
But trust will continue to be built on identity.
Today, we govern the identities of people. Tomorrow, we will also need to govern the identities of AI agents.
Frequently asked questions about the AI Act and AI agent identity
What is the AI Act?
The AI Act is the European Union’s Artificial Intelligence Regulation and the world’s first comprehensive legal framework governing the development, deployment, and use of AI systems. It establishes obligations based on the level of risk posed by each system.
How does the AI Act affect organizations?
Organizations that develop, deploy, or use AI systems must comply with requirements related to risk management, transparency, human oversight, cybersecurity, and traceability, particularly when operating AI systems classified as high risk.
What is an AI agent?
An AI agent is a software system capable of carrying out tasks autonomously, interacting with applications, making decisions within predefined objectives, and operating across enterprise systems with an increasing degree of independence.
Why does an AI agent need a digital identity?
An AI agent needs to authenticate itself to applications, access enterprise resources, use credentials securely, and perform actions on behalf of an organization. A verifiable digital identity enables organizations to control the agent’s permissions, audit its activities, and ensure complete traceability for every operation it performs.
What are non-human identities?
Non-human identities (NHIs) are digital identities assigned to entities other than people, including applications, services, devices, APIs, workloads, and AI agents. Managing these identities effectively is essential to reducing cybersecurity risk and meeting compliance and audit requirements.
What role will digital certificates play for AI agents?
Digital certificates can provide strong cryptographic authentication for AI agents, allowing them to prove their identity, establish trusted relationships with other systems, and securely authenticate each interaction.
What is AI Identity Governance?
Es el conjunto de políticas, procesos y tecnologías destinados a gestionar el ciclo de vida de la identidad digital de los agentes de IA, incluyendo su autenticación, autorización, trazabilidad, auditoría y revocación. A medida que estos agentes ganen autonomía, esta disciplina será un pilar fundamental de la ciberseguridad y del cumplimiento normativo.
This article was drafted with the assistance of AI and reviewed and edited by the Redtrust team.