Scroll

Agent ID

Agent IA

Agent IA - It's okay. Who's responsible?

AI agents are already acting on behalf of companies. We explain who answers for their actions and how eIDAS allows to prove authorization, limits and actions.

Who is accountable for an AI agent?

News stories about artificial intelligence agents acting on behalf of companies are becoming increasingly common. Last September, Amazon blocked Muse, Meta’s shopping agent, claiming that it did not identify itself as an agent and that it was not possible to verify on what terms it was acting.

In July 2025, a Replit coding agent deleted a production database during a code freeze that existed only in the instructions given to the agent. As early as 2024, in Moffatt v. Air Canada, the tribunal had rejected the argument that the airline’s automated assistant was a separate entity, responsible for its own actions.

Three lessons result from these cases. First, the instructions are not sufficient without control at the point of execution. Then the counterparty needs to know who the agent is and with what limits it acts. Finally, whoever uses an AI agent always answers for what he does.

When the AI stops suggesting and starts acting

Until recently, artificial intelligence was limited to answering questions. Today, so-called AI agents querysystems, draft and send emails, prepare orders and initiate transactions on behalf of the organisations that use them. The change is profound. We have moved from dealing with a tool that suggests to dealing with a tool that acts.

This change raises two questions. When an AI agent performs an act, who answers for him? Besides, a bank, a supplier or a public entity never saw that agent. How can you know who acts and with what limits?

In this article, we seek to answer these questions in the light of the law in force and to identify the instruments that the eIDAS Regulation already provides for in order to address them.

1. The AI agent is not a person.

Let's start with the essentials: can an AI agent answer for his actions? No, you can't.

The Regulation (EU) 2024/1689 (IA Regulation) defines the AI system as a machine-based system. In addition, it clarifies that this system can function with varying levels of autonomy. Autonomy describes the degree of independence of the system from human intervention. However, it does not confer its own status.

Therefore, the AI Regulation does not confer rights or obligations on the system. All obligations fall on persons, in particular:

• the provider, which develops the system and places it on the market;

• the responsible for the implementation, which uses the system «under his own authority».

Portuguese law also goes in the same direction. In fact, Article 33 of Decree-Law No 7/2004 deals with contracts concluded exclusively through computers. Even without human intervention, he has to apply the common regime. So the agent is an instrument. Thus, the effects of its acts are produced in the legal sphere of those who use it.

2. Three questions to be asked before an AI agent

If the agent is an instrument, trust does not lie in him, but in the organization that uses him. So anyone who receives a request from an AI agent needs to answer three questions:

1. Who's the agent? A unique identifier, connected to a dedicated cryptographic key.

2. On whose behalf does it act and within what limits? The responsible organisation, the operations theagent may perform, the value limits, the prohibitions, the cases in which human approval is required and the period of validity of the authorisation.

3. What did it actually do? A record of each action, whether permitted or refused, that can later be verified by a third party.

The technical identity of agents is being addressed by a range of market solutions. The more demandingquestions are the second and the third, because they concern authority and proof. This is where the trustservices provided for in the eIDAS Regulation become relevant.

3. What EIDAS already offers

The Regulation (EU) No 910/2014, in the wording of Regulation (EU) 2024/1183, created a specific trust service. Designed precisely to attest to verified information, it is called an electronic certificate of attributes. In the qualified version, the person issuing it is a qualified provider of trusted services. In that case, it shall have the same legal effect as a certificate legally issued on paper (Article 45b(2)).

Which attributes may be included in an attestation? The Regulation defines ‘attribute’ as a characteristic,quality, right or permission of a natural or legal person or of an object (point (43) of Article 3).

Could, then, the agent himself be the entity to which the attribute respects? ETSI TS 119 472-1 applies under Implementing Regulation (EU) 2025/1569. This standard requires that all attributes of a qualified certificate refer to the holder. In addition, the holder must be a natural or legal person.

4. How the certificate authorizes an AI agent

This results in a construction consistent with the regulatory framework:

• The organisation shall be the holder of the certificate and the entity to which the attribute relates. That's why she's responsible for the acts of the AI agent.

• The attribute certifies the act of the organization. Its contents are the authorization given to the officer. However, what is certified is the act of the organization that grants it.

• Within the attribute is the agent identification: the identifier, the declared configuration, the permitted operations and the limits. There are also prohibitions and thresholds for human approval.

• An organization-controlled key is linked to the certificate. Thus, proof of possession of this key allows us to verify that those who present it have permission to use it.

• It is up to the qualified provider to verify the organisation: its identity and the powers of those who, on its behalf, grant authorisation.

• If the organisation withdraws the authorisation, the provider shall revoke the certificate. So any third party can check his condition.

In short, the certificate attests to the organisation's declaration of origin and legitimacy. However, it does not attest to the convenience or legality of authorised operations. These remain the responsibility of the organisation.

5. What the certificate does not do

Can a certificate prevent someone from manipulating an AI agent? You can't.

A malicious instruction hidden in an e-mail or document may lead the agent to try to do what he should not. It's called prompt injection. Actually, the certificate says what the agent can do, but it doesn't stop him from trying anything else.

Therefore, effective protection requires two complementary parts:

• A check at the point of execution. Before reaching the destination system, the action undergoes a verification against the authorisation. This system can be the email, ERP or payment platform. The action only advances if it fits the authorization. You assume someone can fool the agent. Control exists precisely so that the agent does not go beyond the limits.

• A record of each decision, with qualified time stamps. The qualified time stamp benefits from the presumption of accuracy of the date and time. It also benefits from the presumption of integrity of the data to which it relates (Article 41(2) of the EIDAS Regulation). Thus, it allows to demonstrate the exact moment of registration.

6. Good practice for those using an AI agent

Even before there is specific guidance from supervisors, any organisation using an AI agent may adopt some practices:

• An agent, a key, an authorization: each agent has his key, under the control of the organisation, and his certificate. Besides, never share credentials between agents or between agents and people.

• Minimum permissions: allow only the operations necessary for the function. In other words, anything that does not expressly provide for authorisation must be considered prohibited.

• Human approval in the relevant acts: setting value or risk thresholds. Above them, a person with authority must approve the operation. Moreover, the lack of response must be worth refusing.

• Time-limit commitments: separate the technical identity of the agent from the operational authorisation. Identity can last longer. On the contrary, authorisation should last less and deserve regular review.

• Without sub-delegation: no staff member shall be able to create other staff members or extend their own authorisations.

• Repeal when something changes: the compromise of the key should imply the revocation of the authorization. Similarly, a relevant change in the model or purpose, or deactivation of the agent, shall have the same effect.

• Transparency: natural persons should know when they interact with an AI system. This requires Article 50(1) of the AI Regulation.

Completion

The decisive question is not whether we can trust an AI agent, because the answer will always be uncertain. The decisive question is whether we can know on whose behalf it acts, limit what it can do and prove what it has done. The law in force and the trust services under the eIDAS Regulation already make it possible to answer these three questions.

So at DigitalSign we created a new trust service for AI agents. So organizations can take advantage of this technology safely. Learn more about our work with Qualified Electronic Attestation of Attributes (QEAA).

Continue reading