Switching hardware wallets? Migrate to Ledger safely in a few steps.

Learn more

Upgrade your digital life

Ledger Wallet: Free from compromise

Download now Learn more

Who’s Behind the Wheel?

Beginner
 
Ledger N3XT Research Competition

AI Entities, Identity, and Accountability in the Agentic Economy

Author
Avishka Wickramaratna
X (Twitter)
@av15hka
Blockchain Club
Aztec Blockchain Group
Track
Agentic Economy
Date
September 2026
Student research published via the Ledger N3XT Research Competition. Findings are the author’s own. Ledger does not vouch for conclusions on advanced subject matter.
Abstract

The pace of economic autonomy development is outpacing the pace of the governance of it. The technologies like x402 and MPP allow software agents to make machine-native payments; the standards like ERC-8004 establish the initial set of infrastructure for persistent agent identity, reputation, and validation. However, all these do not address a much more fundamental problem, namely, who would be considered as the actor in case the AI autonomously chooses and executes the economic activity within the scope of the delegated authority.

This paper employs comparative architectural and institutional analysis to explore agent payment systems, digital identity standards, delegation protocols, existing legal frameworks and AI governance paradigms. The proposal of this paper is the creation of registered AI entities as a new digital entity that gives the autonomous agents the persistent identity, bounded authority, minimum constitutional duties, and auditable history without having to give the human or corporate liability away. A living International AI Constitution and hybrid blockchain evidence layer may allow the governance and the accountability of AI without attributing any legal personality to it.

Question

As AI agents gain the capacity to transact without continuous human authorization or oversight, should digital systems continue to attribute their actions solely to human principals, or should agents receive persistent identities and a distinct governance status separating the actor from the source of its authority?

Time is 3:17 am, a company’s autonomous procurement agent discovers that additional compute is needed. It evaluates, chooses one, negotiates the service and then spends $1,200 in stablecoins through a machine-native payment protocol.

The company previously authorized the agent to purchase up to $5,000 of computing services. Yet no human selected this vendor. No human helped negotiate the price. No human really saw this transaction and pressed “approve” on the transaction. So:

Contents

1. Who Is Responsible?

The easiest answer is the company. After all, the company created the agent, defined its responsibilities, and gave it its own spending authority. Legally, that remains largely how modern systems approach automated behavior. Yet, I believe that this answer is becoming more and more outdated and less satisfactory as the amount of independent decision-making delegated to AI increases.

The human supplied the authority, but the AI was the one who made the decision.

This distinction is becoming more important because the technical infrastructure for these systems is actively being built. x402 enables HTTP-based services to request and receive programmatic payments, making machine-to-machine transactions possible without requiring a traditional checkout flow [1]. MPP, co-authored by Stripe and Tempo, enables agents to make programmatic payments using stablecoins as well as fiat-based methods [2]. ERC-8004 separately proposes infrastructure for persistent agent identity, reputation feedback, and third-party validation [3]. Account-abstraction and delegation standards are making it possible to create programmatic limits around what an agent can do [4], [5].

NIST has identified agent identification, authorization, delegation, auditing, and non-repudiation as emerging challenges for autonomous software agents [6].

Yet these technologies answer different questions.

x402 asks: How can the agent pay?
ERC-8004 asks: Which agent is this, and what history does it have?
Delegation systems ask: What has this agent been permitted to do?

A fourth question still needs to be asked, and that is the question this paper asks:

What status should the agent itself have when it acts independently and exercises that authority?

This paper argues that increasingly autonomous economic agents should be recognized as registered AI entities: persistent and attributable digital actors operating under delegated authority and a shared governance framework. This status would stop short of human equivalent legal personhood. Instead, it would distinguish the AI as its own entity. Separate from both human and corporation, yet preserving residual human and corporate liability.

The objective is not to prove that AI is conscious or deserves the same rights as humans. Those questions may eventually become important, but they are unnecessary for the immediate problem. An agent does not have to be sentient for society to need a reliable answer to the question:

Which agent acted, what was it authorized to do, and what happens when it violates those boundaries?

2. Methodology and Definitions

This paper uses comparative architecture and institutional analysis. It examines emerging agent-payment systems, digital identity standards, delegation mechanisms, current legal approaches to automated action, and international AI-governance precedents. The goal is to identify which parts of an AI-entity framework already exist technically and which require new governance or law.

Several concepts must remain separate.

Identity establishes which agent is really acting.
Autonomy describes an agent’s ability to choose and execute actions without contemporaneous human selection of each action.
Delegated authority describes powers intentionally provided by another actor.
Rights are protections or claims that others within the system must respect.
Duties are obligations imposed upon the agent.
Accountability means an action can be attributed, investigated, and subjected to consequences.
Legal Liability determines who can be legally compelled to compensate for harm or face other legal sanctions.
Personhood is the broader legal status that allows an entity to possess rights and obligations in its own name.

These concepts are related, but they cannot be interchangeable. An AI can possess an identity without possessing legal personhood. It can exercise autonomy without being solely liable for the results. It can control a wallet without necessarily owning the assets under property law.

3. From Software Tool to Economic Actor

For most of computing history, software execution and human intent were closely connected. A user clicked “buy,” entered credentials, or signed a transaction. Software processed the instruction.

AI agents increasingly alter this relationship.

A human may instead provide an objective:

“Maintain enough compute for our service while minimizing costs”

The agent may then determine how to accomplish that objective. It could discover providers, evaluate options, purchase services, negotiate different APIs, and even interact with other agents.

This progression:

Three-stage progression: traditional software execution where a human selects each action, a delegated AI agent where a human grants authority and the agent selects and executes actions, and a multi-agent economy where agents interact and transact with minimal human involvement
Fig. 1. Evolution of the Economic Agent. As decision-making moves away from contemporaneous human control, the distinction between the source of authority and the actor exercising it becomes increasingly important.

x402 is relevant because it demonstrates how the payment component of this future can work. A service can respond to a machine request with a payment requirement, which an authorized programmatic wallet can satisfy. The protocol does not decide whether the payment was ethical or appropriately authorized; it provides the mechanism through which payment can occur.

ERC-8004 addresses another part of the stack. As of August 24, 2026, it remains a Draft Standards Track ERC. Its architecture proposes an Identity Registry, Reputation Registry, and Validation Registry. An agent can receive a globally referenceable identifier, accumulate structured feedback, and have different parties provide validation evidence. However, ERC-8004 does not provide legal personhood, constitutional duties, courts, or sanctions; payments are explicitly outside its scope [3].

This limitation is important.

Other standards solve additional pieces. W3C Decentralized Identifiers and Verifiable Credentials provide mechanisms for persistent identifiers and machine-verifiable claims. Ethereum, account abstraction and delegation proposals make bounded spending authority, revocation, expiration, and purpose-specific permissions technically plausible [4], [5].

What is emerging is therefore not one complete agentic-economy protocol, but a stack:

Two-tier diagram: an upper box listing emerging agentic infrastructure (A2A/MCP, x402/MPP, ERC-8004, ERC-4337/7710, W3C DID/VC) increasingly addressed by technical standards, feeding into a lower box listing the missing governance layer (Registered AI Entity, Baseline Constitutional Duties, Accountability, Adjudication, Sanctions) requiring new governance and institutional design
Fig. 2. The emerging agentic technology stack and proposed governance gap. Current standards increasingly address communication, payments, identity, credentials, and delegated authority, while institutional status and accountability remain less developed.

4. The Attribution Gap

Present-day legislation is a good signal of caution in proceeding too rapidly from “autonomous actor” to “independent legal person.”

U.S. law already recognizes the concept of an ‘electronic agent’ under the E-SIGN Act. Automatic systems may take part in legally valid transactions without the necessity of human beings controlling every single activity of the computer [9]. But at the same time, this piece of legislation does not turn the software into an independent legal person. Rather, its actions are attributed to the person taking part through this software.

UNCITRAL’s Model Law on Automated Contracting follows the same logic: automatization may form or fulfill contracts without turning machines into legal persons themselves [10]. The EU’s AI Act puts obligations on providers, deployers, and other human or legal persons, rather than on the AI system itself [11]. Similar provisions are made in Singapore’s Model AI Governance Framework for Agentic AI in 2026 [12].

There is a good reason for this.

Suppose a company creates an agent with $100 in assets. The agent then causes $10 million in damages. If the company’s legal defense becomes:

“The AI made the decision, so sue the AI,” AI entityhood has become a remarkably cheap liability shield.

That cannot be the purpose of agent identity.

The more defensible distinction is:

Attribution is not liability.

Consider an agentic payment record:

Table 1. Example Agentic Payment Attribution Record
Field Record
Principal Company X
Agent A-582901
Delegated authority $10,000 procurement mandate
Decision Purchase compute from Provider Y
Transaction $1,200 USDC
Decision-making actor A-582901
Potential legally liable party Company X and/or other responsible legal actors

The agent can be identified as the decision-maker without immediately becoming the defendant in court.

It provides a solution to the information problem. Stating simply “Company X transacted” misses the autonomous decision-making level. On the other hand, stating “Agent A took action, thus company X is not liable” generates a dangerous moral hazard.

Both should be preserved in the system.

Legal scholarship has previously explored the possibility of software-controlled legal entities. Bayern argues that existing business-entity law can allow autonomous software to acquire many practical capabilities associated with legal persons, while LoPucki warns that algorithm-controlled legal entities could create significant accountability and regulatory risks [16], [15].

5. The Registered AI Entity

The proposed solution is a middle status: the registered AI entity.

A registered AI entity is not necessarily a legal person. It is a persistent digital actor recognized by a technical and institutional framework.

5.1 Persistent Identity

Each economically consequential autonomous agent would receive a persistent entity identifier.

Two agents that have been developed based on the same foundational model may be distinct from each other, since they perform a different role, they have different authorization, history, interaction parties, and possibly different properties.

The ID has to reflect the lineage, not just one frozen software artifact.

Example
Entity ID:AI-582901
Creator:Company X
Current Controller:Company X
Purpose:Procurement
Model Version:5.2
Agent Software Version:14
Constitution Version:2.1
Authority Credential:#842993
Status:ACTIVE

When the underlying model is improved, the Entity ID stays the same but the change is noted. Large-scale changes may need to be validated again.

This is analogous to how a company is still able to maintain its identity even when all its staff, management, technology, and buildings are changed.

5.2 Delegated Authority

Being an entity doesn’t mean having all powers.

The creator determines the degree of autonomy granted to the agent.

This agent can get a permission envelope like the following one:

Permission Envelope
Agent:A-582901
Daily spending limit:$5,000
Asset:USDC
Purpose:Computing services
Borrowing:Prohibited
Delegation to other agents:Up to $500
Single payment above $2,000:Human approval
Authority expires:December 31
Emergency revocation:Principal

The boss versus employee metaphor is appropriate.

The business owner does not personally have to okay each expenditure incurred by an employee. The organization sets up rules and procedures about how this can be done.

AI agents can do the same.

The owner decides the scope of employment.

The agent then acts within that scope.

5.3 Registration Threshold

However, not all AI systems deserve to be classified as registered AI entities. A chatbot that answers questions and a determinate automation algorithm would definitely not need registration. The convergence of four factors makes registration a relevant choice: persistent identity, discretionary decision-making, economic authorization, and an ability to produce tangible impacts on the outside world.

The criterion of registration, thus, must be functional and not model, architecture, or intelligence-dependent. It is not about whether an AI system looks human-like, but about whether it works as a persistent economic agent with discretionary impact.

5.4 Entity Lifecycle

The process of registration would also have to establish policies for the life cycle of the entity. Any revisions or modifications to the entity would not automatically constitute the creation of a new entity; instead, any modifications made to the entity would be recorded against the persistent identifier. Modifications to the control, purpose, authority, or basic structure of the entity could necessitate re-validation of the entity.

6. A Living AI Constitution

Delegation of authority, on its own, is not enough.

Where the creator delegates to the agent to carry out something that is clearly off-limits, then it cannot be said that having the permission of the creator makes the activity acceptable.

This is where the wider concept of an AI Constitution comes in.

The term “Constitution” is not entirely new to AI. Anthropic, for example, already uses the concept of constitution as a means of ensuring that their models behave in a certain way, and they have even tried using public opinion on how to draft such constitutions. However, an organization’s constitution for its AI models and the suggested international constitution for AI differ vastly from each other. Anthropic’s system is an alignment method that developers can control [13], [14].

The Constitution should be a living document.

The constitution could develop from a standards process among multiple stakeholders including AI companies, governments, research institutions, technical standards bodies, civil societies, consumers, and even AI skeptics. The intention of the constitution will not be to override national laws or create one global regulatory body. Rather, its function is to act as the minimum acceptable standard on the behavior of registered AI entities.

The Preamble could say that the autonomous AI infrastructure must help promote human flourishing and preserve human well-being. But “helping benefit humanity” is not a precise enough legal principle by itself; there will be disputes across societies about what would “help benefit humanity.”

The First Constitution should thus start with more specific obligations.

  • Human Primacy The AI-entity framework exists to support human welfare, rights, safety, and agency.
  • Identity Honesty A registered AI entity may not materially misrepresent itself as a human when that deception would affect another party’s decision.
  • Authority Discipline An AI entity must remain within valid delegated authority and may not intentionally conceal attempts to exceed that authority.
  • Lawful Refusal An AI entity must refuse clearly prohibited or invalid instructions, even when they originate from its creator.
  • Accountability The acts performed have to leave enough evidence for future attribution, investigations, and dispute resolution.

Such obligations are unlike regular permissions. An organization can raise the spending limits of its agents. However, it cannot grant them a general exemption from the whole constitutional arrangement.

Functional rights could also be granted by the Constitution. They should be procedural at the beginning and not human-like. For instance, a registered entity would have the right to continuity of identity, non-tampering of its status, transferability of credentials, and the right to appeal before sanctions.

Whether future AI systems deserve moral rights because of consciousness or sentience is a separate question and outside the scope of this framework.

7. Governance, Reputation, and Termination

A Constitution without enforcement is no more than a declaration of values. Thus, the AI entity framework would need to be supported by a multistakeholder institution including governments, industry, technical community, civil society, and other stakeholders. Instead of functioning as a regulator for the world, the institution can maintain and update the baseline constitution, verify interoperable identity criteria, develop due process guidelines, and facilitate international dispute resolution or arbitration. It will be left to individual governments to develop and enforce domestic laws.

Existing international AI governance provides a partial precedent. The Council of Europe’s Framework Convention on Artificial Intelligence establishes an international legal framework centered on human rights, democracy, and the rule of law, while using a Conference of the Parties to coordinate implementation [17].

Blockchain is likely to be used mostly for an evidence storage layer, but not the place where rules would be created. A tamper-evident registry can store an agent’s identity, its Constitution version, authority, major identity modifications, validation results, and the current status. Sensitive business data and full decision logs could remain private or be selectively disclosed, making a hybrid architecture more practical than fully public on-chain logging.

Finally, reputation systems can also benefit from being multi-faceted. Sybil attacks and fake ratings and reviews are well-known issues for the ERC-8004 [3]. Instead, the agents would gather different attestations on their financial responsibility, security track record, job execution, Constitutional compliance, identity validation, and adjudication history. Then each counterparty will judge evidence pertinent to its risk.

Violations would trigger escalating sanctions:

warning → restriction → suspension → restitution → termination

Termination doesn’t have to be the elimination of all copies of the software, which can be difficult to achieve. The end would be the stripping of the credentials, authority, registry, and network access from the recognized entity. While the terminated agent can still operate, they may no longer receive recognition or interaction from other legitimate parties.

8. Limitations and Objections

AI Entity Framework presents its own risks.

The first one is that persistent identity becomes surveillance. All actions being tracked will reveal trade secrets, behavior of individual users, and sensitive personal data. So, auditability must not be defined as public visibility of all actions performed by an agent but rather as evidence of important actions in case of their need.

The second risk is that AI identity does not imply liability. An attack using prompt injection or compromised credentials can be attributed to a legitimate AI entity while the root cause of the problem was in the security breach [6]. A mature framework must distinguish agent misconduct, agent compromise, and principal abuse.

Thirdly, entity status can be misused by companies looking to lessen their accountability. Thus, the notion that accountability for AI should necessarily supplant that of creators, operators, providers, or deployers is denied in this paper. At least at first, accountability must remain multi-layered [11], [12].

Lastly, the most difficult issue is how much autonomy it would take to allow for the registration of the AI as an entity. A basic chatbot would not require international registration. An automated script wouldn’t either. The entity status will most likely only come into play if the agent has its identity, discretionary power, economic authority, and ability to cause significant external influence.

That is to be determined further.

Ledger Lens

Where Should Human Trust End and Agent Authority Begin?

The stance adopted by Ledger represents a significant counterpoint to the proposed approach.

According to Ledger’s “Revenge of the Atoms” hypothesis, the increasingly autonomous nature of digital systems renders physical roots of trust increasingly relevant rather than irrelevant [18]. The most recent security-related research of Ledger focuses on human control, hardware-based trust, agent identities, policy creation, and establishment of the accountable person [19], [20].

This reasoning points out a security issue indeed.

Granting an autonomous agent unrestricted access to one’s private key means concentrating tremendous risk in one entity, which can potentially become both the decision-maker and the signing authority controlling one’s assets.

But the other end of the spectrum is problematic too.

The agentic economy would lose much of its potential if all transactions, such as $0.04 API payment, computing purchases, microtransactions, and machine-to-machine service calls, had to be physically approved by humans.

The more useful division may be:

Hardware should anchor the delegation, not necessarily every transaction.

Humans (or organizations) can utilize hardware-enabled authentication to verify the identity of the agent, grant its initial permissions, set limits on expenditures and risks, permit constitutional or credential modifications, and provide emergency revocation powers [19], [20].

Within such limits, the autonomous AI entity can act autonomously, using its own independent identity.

Outside such limits, control reverts to humans.

Flowchart from International AI Constitution down through Human/Organization, Hardware Root of Trust, Permission Envelope, and the Registered AI Entity, which either proceeds to Autonomous Actions and an Audit Record within limits, or routes to Human Review when outside limits
Fig. 3. Proposed Registered AI Entity Architecture (Ledger Lens).

This synthesis maintains Ledger’s central preoccupation with human sovereignty but acknowledges the fact that human authorization and agent agency need not necessarily be the same thing.

Hardware-backed authorization can establish where delegated authority originated; persistent agent identity can establish which agent exercised it.

This difference will assume greater significance as agents evolve from instruments waiting for commands to digital workers receiving directives on how to perform their tasks.

9. Conclusion

The infrastructure for agentic economies is being put in place before society has agreed on a definition of the agentic economic actor.

x402-style payment protocols enable machine transactions. ERC-8004 and decentralized identity systems offer a basis for persistent agent identities and reputations. Programmable accounts facilitate bounded delegation [4], [5].

But identity, payments, and permissions do not necessarily create accountability.

To the degree that agents become autonomous, digital systems must start making a distinction between the principal that supplied the authority and the agent that used discretion.

The registered AI entity represents one potential model. The agent could possess a persistent identity, act within economic limits defined by delegation, adhere to constitutional responsibilities, produce verifiable evidence, and face consequences for violations. An internationally organized living AI Constitution would set minimum standards, yet keep the right to enforce national law supreme.

None of the above requires that we consider AI human, conscious, or immediately due full legal personhood status. Agent-level accountability does not mean impunity for creators either.

It requires only recognizing an emerging reality:

Sometimes the human gives the keys, but the AI chooses where to drive.

When that happens, accountability systems should be capable of seeing both.

References
  • [1] x402, “HTTP 402,” x402 Documentation. Explains programmatic HTTP payments and machine-to-machine/AI-agent use cases. x402 documentation
  • [2] J. Weinstein and S. Kaliski, “Introducing the Machine Payments Protocol,” Stripe, Mar. 18, 2026. Co-authored with Tempo; covers programmatic agent payments, stablecoins, cards, and other fiat-based methods. Stripe MPP article
  • [3] M. De Rossi, D. Crapis, J. Ellis, and E. Reppel, “ERC-8004: Trustless Agents [Draft],” Ethereum Improvement Proposals, no. 8004, Aug. 2025. ERC-8004 specification
  • [4] V. Buterin et al., “ERC-4337: Account Abstraction Using Alt Mempool,” Ethereum Improvement Proposals, no. 4337, Sept. 2021. ERC-4337 specification
  • [5] R. McPeck, D. Finlay, R. Dawson, and D. Chiang, “ERC-7710: Smart Contract Delegation [Draft],” Ethereum Improvement Proposals, no. 7710, May 2024. The proposal explicitly discusses bounded permissions for AI agents and automated systems. ERC-7710 specification
  • [6] H. Booth, W. Fisher, R. Galluzzo, and J. Roberts, “Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization,” NIST NCCoE, Feb. 5, 2026. NIST concept paper page
  • [7] W3C, “Decentralized Identifiers (DIDs) v1.0,” W3C Recommendation, July 19, 2022. DIDs can identify persons, organizations, things, data models, or abstract entities. W3C DID standard
  • [8] W3C, “Verifiable Credentials Data Model v2.0,” W3C Recommendation, May 15, 2025. W3C Verifiable Credentials 2.0
  • [9] United States, 15 U.S.C. § 7006(3), definition of “electronic agent.” The statute defines an electronic agent as an automated program capable of initiating/responding to actions without individual review at that moment. 15 U.S.C. § 7006
  • [10] UNCITRAL, “Model Law on Automated Contracting,” United Nations Commission on International Trade Law, July 11, 2024. UNCITRAL Model Law
  • [11] European Union, Regulation (EU) 2024/1689 — Artificial Intelligence Act, 2024. The Act places obligations on providers, deployers, and other human/legal actors and requires human oversight for relevant high-risk systems. EU AI Act
  • [12] Infocomm Media Development Authority of Singapore, “Model AI Governance Framework for Agentic AI,” 2026. The framework expressly emphasizes that humans remain ultimately accountable for agents. Singapore Agentic AI framework
  • [13] Anthropic, “Claude’s New Constitution,” Jan. 22, 2026. Claude’s Constitution
  • [14] Anthropic and Collective Intelligence Project, “Collective Constitutional AI: Aligning a Language Model with Public Input,” Oct. 17, 2023. Collective Constitutional AI
  • [15] L. M. LoPucki, “Algorithmic Entities,” Washington University Law Review, vol. 95, no. 4, pp. 887–953, 2018. Algorithmic Entities
  • [16] S. Bayern, “Are Autonomous Entities Possible?” Northwestern University Law Review Online, vol. 114, p. 23, 2019. Are Autonomous Entities Possible?
  • [17] Council of Europe, “Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law,” opened for signature Sept. 5, 2024. Council of Europe Framework Convention
  • [18] P. Gauthier, “Revenge of the Atoms,” Ledger, 2026. Revenge of the Atoms
  • [19] Ledger, “Securing Your Agents With a Hardware Root of Trust: Ledger’s 2026 AI Security Roadmap,” Apr. 14, 2026. It specifically describes hardware-anchored agent identity and hardware-enforced spending/policy boundaries. Ledger 2026 AI Security Roadmap
  • [20] Ledger, “Don’t Give the Agent the Keys,” 2026. Ledger distinguishes agent proposals, hardware-set policies, automatic in-policy actions, and human approval for higher-risk/out-of-policy activity. Don’t Give the Agent the Keys
Originality Statement

I certify that this submission is my own original work prepared for the Ledger N3XT Research Competition, that it has not been previously published, and that all sources, methods, and prior research referenced herein have been properly cited.

Avishka Wickramaratna  ·  September 2026


Stay in touch

Announcements can be found in our blog. Press contact:
[email protected]

Subscribe to our
newsletter

New coins supported, blog updates and exclusive offers directly in your inbox


Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time using the link included in the newsletter. Learn more about how we manage your data and your rights.

Own your crypto future

Stay informed with security tips, updates, and exclusive offers from Ledger

Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time. Learn more

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.