The useful question is not whether Estonia succeeds

Emerging discussions about issuing state identities to AI agents have drawn attention, scepticism, and the predictable cycle of technology commentary. The useful question for a DACH Geschäftsführung is not whether such experiments become international law tomorrow. It is whether your organisation can already prove which human sponsor, service account, model version, tool call, and business process sat behind an autonomous action when a regulator, auditor, customer, or incident responder asks.

Treating agents as named identities rather than scripts changes access reviews, incident response, procurement contracts, and executive accountability. The organisations that adapt early will carry a governance advantage. Those that delay will face the same sprawling access risks and audit gaps that emerged when cloud identity governance lagged a decade ago, only faster and with higher stakes.

Why agents break the service account model

AI agents are not glorified cron jobs. A service account typically performs a bounded, repeatable task under static privileges: rotate a certificate, sync a directory, trigger a backup. An AI agent retrieves data across systems, interprets context, makes decisions, invokes APIs, spawns sub-tasks, and adapts its behaviour based on results. That operating pattern breaks every assumption baked into traditional non-human identity governance.

Speed and scale. Agents operate continuously, at machine tempo, across hybrid environments. A single agent may touch dozens of systems in seconds, each interaction requiring access decisions that most identity controls were never designed to evaluate in real time. The gap between action and review widens until it becomes operationally meaningless.

Dynamic privilege. Traditional service accounts receive a fixed set of permissions at provisioning time. Agents request access contextually, based on the task at hand, the data available, and the tools they are instructed to use. That fluidity is precisely what makes them useful and precisely what makes static role definitions inadequate.

Delegation and spawning. In emerging agent frameworks, systems can delegate sub-tasks to other agents, invoke third-party models via API, or spawn ephemeral instances to parallelise work. Each delegation introduces a new identity boundary, a new trust decision, and a new auditability challenge. The question "who did this?" no longer has a single answer; it has a chain of custody that must be reconstructed after the fact.

As one identity practitioner observed, this is not a variation of the service account problem; it is a fundamentally different class of risk, and it requires a fundamentally different approach to governance. Agents are identities. They need to be provisioned, monitored, governed, and deprovisioned just like any human or developer identity, but the governance model must accommodate speed, context, and delegation that static controls cannot handle.

What agent identity actually means in practice

Establishing a reliable identity for agents is the first challenge, and the "how" is still being debated. Some organisations treat AI agents as another form of non-human identity, similar to service accounts or machine identities. Others argue that agents should be their own category, distinct from both human users and machine accounts.

In any case, agents need verifiable identity infrastructure—potentially including certificates, attestation mechanisms, and policy-based access controls—that can be recognized and governed across environments. This is especially important because, in most enterprises, agents will operate across cloud platforms, on-premises systems, SaaS applications, and third-party APIs. Without a durable identity that persists across those boundaries, accountability fragments. An agent may have one identity inside a cloud platform, another inside an enterprise environment, and different credentials across the tools and systems it interacts with, but no single ownership record that survives as models, credentials, and tools change over time.

Human sponsorship. Every agent should have a named human sponsor who carries operational accountability for its actions. That sponsor is typically the asset owner in the affected business function, not a developer in IT or a data scientist in a centre of excellence. Anchoring accountability to the role that already carries the operational risk of the process prevents agent-based systems from drifting into the organisational grey zone between IT, security, and the business, which is exactly where unattributed action originates.

Traceable context. Every autonomous action should have traceable context: which model was invoked, which tools were called, which data was accessed, which business process was being executed, and which human instruction or policy triggered the sequence. That context must be captured at the time of action, not reconstructed weeks later during an incident review. The organisations that can produce this audit trail on demand will pass compliance reviews; those that cannot will face escalating scrutiny under frameworks like the EU AI Act and NIS2, both of which place explicit accountability requirements on high-risk AI systems and critical infrastructure operators.

Revocation and lifecycle. Agents can be created in seconds, duplicated, modified, delegated new capabilities, or even spawn additional agents. That ease of instantiation invites a glut of unmanaged identities if governance mechanisms for registration, attestation, revocation, and continuous monitoring are not in place from the start. The challenge is not just provisioning; it is ensuring that an agent's identity can be revoked instantly when its sponsor leaves the organisation, its business justification expires, or its behaviour deviates from policy.

The privilege problem that no one is talking about

AI agents often require broad access across hybrid environments and critical business systems to be effective. The challenge is that agents operate continuously while most identity controls remain static. As organisations grant more authority to non-human identities, long-standing assumptions about trust, least privilege, and access review begin to fracture.

Continuous operation vs. static review. Traditional access reviews happen quarterly or annually. Agents act every second. By the time a review cycle completes, the agent's actual access footprint may have expanded across dozens of new systems, data sources, and APIs. The review becomes a historical record, not a control.

Privilege creep at machine speed. Agents accumulate privileges as they are granted access to new tools, data, and systems to complete tasks. Unlike human users, who may request access once and use it sporadically, agents use every permission they hold, continuously. That usage pattern accelerates privilege creep and increases the blast radius of a compromised agent identity.

Cross-boundary trust. Agents frequently operate across organisational boundaries, invoking third-party models, SaaS APIs, and partner systems. Each boundary crossing is a trust decision, but most enterprises lack the infrastructure to enforce consistent identity verification, attribute-based access control, or cryptographic attestation across those boundaries. The result is that agents inherit the weakest link in a chain of federated trust relationships, many of which were never designed for autonomous, high-frequency interaction.

The organisations that adapt early will treat agent identity as a first-class governance problem, not an extension of existing service account management. That means building or adopting identity platforms capable of real-time access decisions, contextual privilege grants, and continuous monitoring of non-human identities at scale.

What DACH mid-market firms should do now

Inventory non-human identities separately. Most organisations track human identities in one system and machine identities in another, if at all. Start by inventorying every non-human identity that can take autonomous action: service accounts, API keys, model inference endpoints, agent instances, and any credential that can invoke a tool or access data without direct human intervention. Treat this inventory as a living document, not a one-time audit.

Anchor every agent to a named sponsor. Do not allow agent identities to be provisioned without a named human sponsor who carries operational accountability. That sponsor should be the business function owner, not a technical proxy. Make sponsorship a required field in the provisioning workflow and enforce it through identity governance tooling.

Capture context at the time of action. Build or adopt logging infrastructure that captures the full context of every autonomous action: model version, tool calls, data accessed, business process, and triggering policy. That context must be structured, searchable, and retained long enough to satisfy emerging audit requirements under GDPR, the EU AI Act (as implementation standards develop), and sector-specific regulations. Retrofitting this capability after an incident is too late.

Treat agent identity as a board-level risk. The accountability gap created by autonomous agents is not a technical problem that IT can solve in isolation. It is a governance problem that requires executive sponsorship, cross-functional ownership, and investment in identity infrastructure that most mid-market firms have deferred. The organisations that recognise this early will carry a compliance and operational advantage as regulatory scrutiny intensifies.

Prepare for external accountability standards. While today's AI systems are advancing rapidly, the infrastructure needed to support trusted accountability across organisational boundaries does not yet exist. Open accountability standards will emerge, likely driven by industry consortia, cloud platforms, or regulatory mandates. DACH firms that build agent identity governance on extensible, standards-ready infrastructure will adapt faster than those locked into proprietary, closed-loop systems.

The governance advantage belongs to early movers

Security leaders should approach this moment the same way they approached cloud identity challenges a decade ago. Organisations that delayed identity governance in cloud environments eventually faced sprawling access risks and audit issues. AI agents are following the same path, only faster. Every AI-driven service should have a verifiable identity. Every autonomous action should have traceable context. And every organisation needs a secure, centralised, and intelligent foundation for governing both human and non-human identities.

The maturity gap between human and non-human identity governance is where the next wave of compliance failures will originate. The honest first step is not to score well on a maturity model; it is to score truthfully, report human and non-human identity governance separately, and treat the gap between them as a board-level risk. Emerging proposals around agent identity are a signal, not a solution. The question is whether your organisation can already answer the accountability questions that regulators, auditors, and customers will ask.


A Diagnostic maps your current non-human identity posture, identifies the highest-risk agent deployments, and produces a prioritised roadmap for governance that satisfies both operational and compliance requirements — before the next audit cycle or incident exposes the gap.

Request a Diagnostic →