AI agents force digital trust rethink as identity checks miss authority, TechRadar says
A TechRadar article says AI agents are exposing a gap in digital trust: existing systems verify access and identity, but not who authorized an agent, what it can do, or for how long.
The article divides the problem into three checks: authentication, identity, and authority. Authentication asks whether a user can access a system. Identity asks who the user is. Authority asks who authorized the action, what the actor is allowed to do, and for how long. Most current infrastructure, the article says, was built for the first two checks. AI agents make the third impossible to ignore.
According to TechRadar, AI agents are completing transactions and handling administrative tasks that used to require a person, often with minimal oversight. Many systems that check who is on the other end of a request cannot distinguish a person from an agent, or a legitimate agent from an unauthorized one. These systems confirm that someone or something holds the right credentials, the article says, not whether it has authority for the action it is taking.
The article points to the UK’s recent work on identity infrastructure. The Data (Use and Access) Act has put Digital Verification Services on a statutory footing. Some use cases have introduced mandatory identity verification for directors and people with significant control. The article calls this progress but says a second question is emerging as agents act inside business workflows: not who someone is, but who is acting and with what authority.
Identity is only the first check, according to the article. Businesses that prove a person’s identity also need to check what that person is authorized to do. An employee approving a payment on a company’s behalf is one example: the organization needs to know who the employee is and whether they are currently entitled to approve the payment. Financial services and healthcare already add eligibility and role checks to identity verification, the article says, because identity alone does not show what someone is allowed to do.
AI agents make that distinction unavoidable elsewhere, the article argues. Identifying the agent behind a request does not show who authorized the action or whether it falls within the permission originally granted. The infrastructure built so far is stronger on identity verification than on applying delegated authority, and the article says that gap will widen as more business tasks are offloaded to agents.
The article calls for minimum necessary authority. The same discipline that identity design applies to documents should apply to authority: ask for and grant only what a transaction actually needs. An agent completing a task should be able to prove it holds a specific, limited mandate for that task, not standing access to everything behind it. Broad, standing access is easier to build, but the article says a single compromised or mis-scoped agent can do far more damage than a narrowly scoped one.
To prepare for delegation, the article says businesses should move the authority check earlier, so it is confirmed before an agent acts rather than discovered after something goes wrong. An organization should give an agent a specific, limited job rather than a copy of a person’s own access, and keep a clear record of who granted that authority and when it can be pulled.
For any agentic action, the article says a business should be able to answer five questions: Who, or what, is acting? Who authorized it? What can it do? Under what constraints? And is that authority still valid? The article says the test maps closely onto on-behalf-of, or OBO, delegation models already used in identity standards, which it describes as a promising foundation rather than something to build from scratch. Without those answers, a mis-scoped agent could quietly approve a payment it was never meant to touch. Waiting for a regulator to define the standard first would leave that exposure open longer.
The article says the government’s role is to extend what already exists rather than build new infrastructure from scratch. The DVS Trust Framework already recognizes delegated authority when a person acts on behalf of somebody else or an organization. The article says it does not yet address how that principle should apply when the delegate is software, and the UK now needs to work out how its existing delegated-authority thinking extends to that case. Whatever shape that takes, the article says an agent needs to be able to present a machine-verifiable mandate.