Identity · CA
China Moves to Standardize AI Agent Identity Nationwide
Governments are starting to treat AI agents as entities that need formal identity infrastructure, not just software. Following Estonia's earlier move to assign digital identities to AI agents, China has announced plans for a national identity system for autonomous agents. According to reporting from Biometric Update, China has announced a plan to establish a "closed-loop system" with a unified identity management framework for all AI agents, according to the South China Morning Post.
The mechanism is a new national technical standard. The standard for "Artificial Intelligence Agent Interconnection" is China's first national standard focused on AI agent connectivity, and aims to solidify the institutional foundation for secure cross-domain interaction of AI agents. The plan sets out seven sub-standards covering core aspects as part of a unified framework that would allow enterprises to plug into standardized AI agent components.
This is notable because it's a state-level answer to a problem the industry has been circling for months without full agreement: how do you know which agent is acting, under whose authority, and whether it's allowed to cross into another organization's systems? Singapore's IMDA got there first with its January 2026 Model AI Governance Framework for Agentic AI, which requires each agent to carry a verifiable digital identity and an audit trail of which agent acted under whose authorisation. NIST followed in February with an AI Agent Standards Initiative built on the same diagnosis — that agents are commonly treated as generic service accounts without dedicated identity, authorization, or accountability controls.
What's different about China's approach is the scope: a single national standard meant to apply across enterprises rather than a voluntary framework agencies can adopt piecemeal. That's a meaningfully different bet than the W3C DID / Verifiable Credential approach favored in the West, where identity is meant to be portable and self-sovereign rather than centrally issued. Whether a unified, state-run identity layer interoperates with the DID-based schemes already shipping in payments (Visa's Trusted Agent Protocol, Google's AP2) and enterprise IAM (Microsoft Entra Agent ID, CrowdStrike's Continuous Identity) is an open question — and one that matters, since global commerce and cross-border agent-to-agent transactions will eventually need these systems to recognize each other's credentials.
The practical stakes are ordinary ones: fraud prevention, liability attribution, and the ability to answer, after the fact, which agent did what and on whose authority. Right now that answer differs by jurisdiction. A national standard from a market the size of China's raises the odds that agent identity becomes a genuine interoperability fight rather than a quiet convergence.