Identity · CA
Hadfield's Case for an 'Agent ID' Layer of Legal Accountability
Gillian Hadfield published a piece arguing that current AI governance debates are missing a basic layer: infrastructure that makes individual agents accountable to legal and financial systems, the way a driver's license or a corporate registration number does for humans and companies. The article's framing is blunt about the gap: Society is not prepared for a flood of agents. We need new protocols and standards, such as Agent ID, to make agents accountable to our legal and financial systems.
The proposal isn't just another technical credential scheme. It sits alongside a growing academic literature trying to figure out what documentation an agent needs to carry before anyone can hold it, or its operator, responsible for what it does. Recent work on "Auditable Agents" makes the underlying problem explicit: existing accountability proposals tend to stop at the authorization moment rather than covering an agent's full runtime lifecycle. As one paper notes, prior work "extend[s] OAuth-style credentials with agent-specific delegation tokens, achieving full Policy Checkability and Responsibility Attribution through machine-readable policies and signed tokens, but covering only the authorization moment and not the full execution lifecycle." The same paper's review of adjacent efforts — hash-chained audit trails, model lifecycle cards, observability dashboards — finds that most of them leave responsibility attribution and evidence integrity unaddressed even when they solve for monitoring.
That's the gap Hadfield's Agent ID concept is aimed at: not just knowing which model powers an agent, but establishing a durable identifier that regulators, courts, and financial institutions can actually use to attach liability. It's a different problem from discovery (finding an agent) or routing (handing off a task). It's closer to what a corporate registry or a national ID system does for legal persons — giving an entity a stable handle that persists across the messy reality of an agent being redeployed, forked, or delegated to sub-agents.
The stakes are practical, not abstract. As agents start executing financial transactions, signing contracts on behalf of principals, or interacting with regulated systems, someone downstream needs a way to answer "who is accountable for this action" without reverse-engineering a vendor's internal logs. A model card tells you what a model can do; a deployment card tells you how it's configured; neither tells a court or a bank which legal entity stands behind a specific agent's specific action months later.
The open question Hadfield's piece leaves for standards bodies is whether Agent ID becomes a government-run registry, a private-sector credentialing layer, or something federated across both — and whether it arrives before or after the flood of agents she's warning about.