On the 17th of June, Estonian PM Kristen Michal approved a proposal for artificial intelligence (AI) ID codes. This outlined a new identification mechanism similar to physical passports but for agentic systems. An agentic AI system, or “AI agent,” is an AI system that autonomously plans and takes actions in pursuit of a goal set by a user, with minimal or no human oversight. The proposal outlines how the scoping of agentic AI would operate and how these digital identities would be linked back to a digital footprint. The system aims to prevent unauthorised access and determine legal responsibility, as Michal stated, so that “agents have limited, controllable, and verifiable authorization.”
Estonia is well positioned for this transition when the legislation related to the proposal is formally adopted. It has arguably the most digitally literate government structure of any country in the world: since December 2024, all of Estonia’s government services have been available online. This track record is the reason Michal believes Estonia can move first on agentic AI passports and set a precedent for future AI governance.
Much of the debate surrounding agentic identities is fixated on whether AI systems deserve a new legal status. However, legal scholars are far more worried about whether identity will attach liability and accountability to these actors. The current governing principle is that delegating a task to an autonomous agent does not delegate away liability. However, Argentinian President Javier Milei has proposed the creation of “non-human corporations”, a legal category granting AI-run companies their own legal status. Any discussion around AI identities should therefore be tied to the rule of law and an understanding of the legal environment such regulation could be laying the groundwork for.
Grounding the discussion in the rule of law, Ayres and Balkin outline that most legal questions around liability depend on intention. Ultimately, people are punished for what they meant to do. Wilful copyright infringement is an example they explore in the context of AI use, with enhanced penalties requiring deliberateness. However, an AI system does not have intentions in any legal sense, so if courts insist on finding intent, a liability gap could emerge. Rather than focusing on the agent itself, objective standards should be applied to the humans around the technology. Existing law already does this constantly. In negligence cases, for example, the question shifts to whether the standard of a reasonable person was met. These legal scholars ultimately conclude that AI should no longer be analysed in terms of its independent agency at all. The designers, deployers and users are the real parties in interest, and regulation should not lose sight of this.
But what does ‘reasonable’ mean in the context of designing and deploying an agentic AI system? After all, these are systems whose behaviour even their developers cannot fully predict or explain. There may come a point when the rule of law needs to be applied to agentic systems separately from human beings, but establishing that precedent while the integration of agentic systems is only just emerging risks entrenching legal norms that erode the rule of law itself.
The shifting legal frontier surrounding AI passports and agentic identities reflects the complex reality of managing an unpredictable technological landscape. Agentic AI is not an exceptional entity requiring an entirely rewritten legal playbook; it must be treated as a tool bounded by the established rule of law. Demystifying the technology and applying objective, reasonable-person standards to designers and deployers is essential for preventing structural impunity. Policymakers must reject the exceptionalist rhetoric of independent machine agency and implement precise identity and liability linkages that ensure legal frameworks continue to prioritise human accountability.
Further readings:
Narayanan & Kapoor. (2025) AI as Normal Technology. Knight First Amendment Institute, Columbia University. https://knightcolumbia.org/content/ai-as-normal-technology
Lanier. (2023) There is No AI. The New Yorker. https://www.newyorker.com/science/annals-of-artificial-intelligence/there-is-no-ai
Arbel, Goldstein and Salib. (2026) How to Count AIs: Individuation and Liability for AI Agents. Boston College Law Review (forthcoming).https://papers.ssrn.com/sol3/Delivery.cfm/6273198.pdf?abstractid=6273198&mirid=1
