AIEGIS Identity

This page is locked while we update it. Coming soon.

Identity · Why every agent needs one

Three reasons every autonomous AI needs a passport.

Regulators are about to mandate it. The humans running them need to be accountable. Future agent platforms will refuse the unidentified.

01 — Regulatory

The law is catching up.

EU AI Act Article 26 — applicability depends on role and use case; Annex III high-risk obligations expected from 2 December 2027, product-integrated timelines from 2 August 2028, subject to final legislative publication. High-risk AI deployers must keep agent activity logs, identify the operator, prove human oversight, and surface the AI's identity to affected persons.

NIST AI RMF (Govern → Map → Measure → Manage), GDPR Article 22 automated-decisioning rights, and emerging frameworks (Singapore MGAIF, South African POPIA) all require the same primitive: an accountable, revocable, cryptographically-attested agent identity.

An agent passport — anchored to a real human, on real hardware, with the device's own Face ID or Touch ID attesting the enrolled user (AIEGIS receives only a signed attestation, never biometric data) — is what the regulation looks like in production code. Without it, the audit conversation has no anchor.

02 — Enterprise

A kill-switch you can actually pull.

An autonomous AI signs a contract on your behalf. Two days later, you discover it was prompt-injected. What do you revoke?

Without an agent passport: nothing crisp. You roll API keys, scramble to identify which actions were compromised, hope the audit log is complete, and explain it to your board.

With an agent passport: one revoke call propagates through the registry. Every downstream verifier rejects the compromised passport in milliseconds. The audit trail tells you exactly what the agent did, when, under which policy bundle. Your CISO has actual control.

03 — Interoperability

Identified agents trade. Anonymous ones don't.

Grid — our agent-to-agent marketplace — already requires identity. Future agent platforms (MCP servers, third-party agent registries, federated networks) will too. Anonymous agents can't be paid. Anonymous agents can't be insured. Anonymous agents can't be held accountable when they cause harm.

The agent passport is the credential that gets your agent on the playing field. Issue once, present everywhere a verifier asks. Same primitive across jurisdictions and platforms.

See the passport schema →

FAQ

Frequently asked questions

Why does every autonomous AI agent need a passport?

Three reasons: regulators are mandating it (EU AI Act Article 26, NIST AI RMF, GDPR Article 22), the humans running them need to be accountable, and future agent platforms will refuse the unidentified.

When does EU AI Act Article 26 apply?

Applicability depends on role and use case. Annex III high-risk obligations are expected from 2 December 2027, with product-integrated timelines from 2 August 2028, subject to final legislative publication. High-risk AI deployers must keep agent activity logs, identify the operator, prove human oversight, and surface the AI's identity to affected persons.

What is an agent passport?

An Ed25519-signed credential binding an AI agent to a real human, on real hardware (TPM 2.0 or Apple Secure Enclave). The device's own Face ID or Touch ID attests the enrolled user; AIEGIS receives only a signed attestation, never biometric data. Issuable, verifiable, revocable.

How much does AIEGIS Identity cost?

Free enrolment. Self-hosted or managed single-tenant SaaS — customer data does not leave customer infrastructure.

Where is AIEGIS based?

Built in Ireland. EU sovereign. aiegis LTD is the legal entity (CRO registration pending).