Issue 014 organizations name it2026 evidence
Autonomy widens the gap between the decision and the person answerable for it
The further an outcome sits from a human instruction, the harder it becomes to attribute - and agentic systems are increasing that distance faster than accountability structures are adapting.
How to fix it — 1 approach, 3 steps
Give every agent an identity that maps to a person
An action taken by an unidentified process cannot be attributed. Identity is the precondition of accountability, not a security detail.
Done when Every production agent runs under a distinct provisioned identity rather than a shared service account, each maps to an accountable human owner in the register, and agent credentials rotate and de-provision on the same schedule as human ones.
- Require every agent in production to run under a distinct, provisioned identity - never a shared service account.
- Map each agent identity to an accountable human owner in the register.
- Rotate and de-provision agent credentials on the same schedule as human ones.
The evidence — 7 documents
| Organization | Document | Position |
|---|---|---|
| AnthropicFrontier lab · July 2026 | Anthropic’s CISO guide to agentic AIOur reading Puts identity at the centre - something acted, and you must be able to say what - with each added capability, from read-only through tool calls, code execution and network egress, widening what that identity can reach.Four questions: what actions, and on whose behalf | names it |
| Clifford ChanceConsultancy · May 2025 | Agentic AI responsibilitiesOur reading Traces accountability thinning with distance: the more steps between a person and what the system did, the harder responsibility is to attach, and rising autonomy widens the gap.The AI responsibility gap | names it |
| Cloud Security AllianceInstitution · July 2026 | Defining non-human identityOur reading Notes that non-human identities are created by systems rather than business processes and run continuously without direct human oversight: a person reading a screen and pausing between actions creates natural moments to catch a mistake, while an identity executing thousands of operations a second offers no such window.Why NHI risks differ from human identity risks | names it |
| IBMHyperscaler | Agentic AI risk and opportunityOur reading Notes agentic systems can optimise for unintended objectives and behave unpredictably, complicating assurance and therefore attribution.Risks and key mitigations of autonomous action | names it |
| AccentureConsultancy · January 2025 | AI agent identity managementOur reading Proposes treating agent credentials with the rigour applied to human identity, making the acting entity attributable by construction.AI agent identity management | proposes a fix |
| Cloud Security AllianceInstitution · July 2026 | Defining non-human identityOur reading Proposes that where an agent acts for a human principal its actions be scoped by that person's permissions and recorded with delegator, intent and action in the audit log, so accountability survives the delegation.Agent identities; delegated access | proposes a fix |
| McKinsey & CompanyConsultancy | McKinsey: Rethinking AI decision-makingOur reading Proposes holding agents to the same scrutiny as employees - measured, monitored, retrained or retired - which locates accountability with whoever owns that management loop.Governance and oversight of agents | proposes a fix |