Skip to content
مجموعة دبي للذكاء الاصطناعي

Research /

The Future of AI Identity: Compute Passport™

A 2026 research framework for persistent AI-agent identity, bounded authorization, activity logging, audit trails, lifecycle governance, and accountability through Compute Passport™.

As AI agents move from generating answers to taking actions, identity becomes a control plane. Enterprises need to know which agent acted, on whose authority, with which permissions, against which systems, and what evidence exists after the action. Compute Passport™ is a research concept for persistent AI-agent identity connected to authorization, activity logging, audit trails, and governance.

Dubai AI Group Research · 2026

Executive perspective

The next enterprise identity problem is no longer limited to employees, customers, applications, and service accounts. AI agents can now invoke tools, retrieve data, initiate workflows, modify records, communicate with external systems, and act with varying levels of autonomy. When those actions matter, an enterprise needs a reliable answer to five questions: Who is this agent? Who authorized it? What was it allowed to do? What did it actually do? Can the organization prove it later?

This research proposes Compute Passport™ as an identity and accountability model for AI agents. The concept is not a human identity document and should not be treated as a claim of regulatory certification. It is a technical governance layer: a persistent machine identity and associated record that can travel with an agent across its lifecycle and connect identity, authority, provenance, policy, activity, and assurance.

1. AI agents create a new identity class

Traditional identity and access management assumes a relatively stable relationship among a user, credential, application, and permission set. Agentic AI complicates that model. An agent may be created dynamically, operate for a limited period, delegate work to another agent, use multiple tools, act on behalf of a human or organization, and change behavior as models, prompts, context, or permissions change.

NIST’s 2026 work on software and AI-agent identity highlights identification, authentication, authorization, auditing, and non-repudiation as central questions for secure agent deployment. That direction suggests that enterprises will need agent identity to become explicit rather than inferred from an API key, shared service account, or application session.

2. The Compute Passport™ concept

A Compute Passport™ can be understood as a persistent identity record for an AI agent or autonomous workload. At minimum, the record should be capable of binding a unique agent identifier to its accountable owner, deploying organization, model or runtime context, approved purpose, risk classification, authorization scope, credential references, policy constraints, creation and expiry dates, and material version history.

The passport should not contain every sensitive detail about the agent. Its role is to provide a durable identity anchor to which authoritative evidence can be attached or referenced. That allows security, governance, audit, and operations teams to reason about the same agent across systems.

3. Identity without activity evidence is incomplete

Knowing that an agent exists is not enough. Accountability depends on linking identity to action. Every material action should be attributable to a specific agent identity and, where appropriate, to the human, team, or organization that delegated authority to it.

This creates a direct requirement for audit and logging of AI-agent activity. A useful audit record may include timestamps, agent identifier, initiating principal, session or task identifier, policy decision, tools invoked, resources accessed, authorization result, material inputs and outputs or protected references to them, changes made, exceptions raised, human approvals, downstream agents called, and the final outcome.

The objective is not indiscriminate logging. Logs can themselves contain sensitive information. Enterprises need data minimization, access controls, retention policies, integrity protection, and redaction. The goal is sufficient evidence to reconstruct consequential activity without creating a second uncontrolled repository of confidential data.

4. From a log file to a chain of accountability

Agent observability becomes more useful when events can be assembled into a chain of accountability. A high-quality record should show the relationship between the requesting principal, the agent, delegated agents, authorization decisions, tools, data, and resulting action.

This is especially important when agents operate across multiple platforms. Fragmented logs make it difficult to determine whether an unexpected outcome resulted from the model, a tool, a policy decision, a credential, a human approval, or another agent. A persistent agent identifier provides the correlation point required to join those events.

NIST’s 2026 Cyber AI work describes the need to bind accountable individuals to agent actions so organizations can audit, log, and understand chains of trust. NIST research on agentic evaluation is also developing machine-readable audit trails that connect agent outputs and actions to supporting evidence. These are early signals of a broader shift: auditability is becoming part of agent architecture, not an after-the-fact compliance exercise.

5. Authorization must be dynamic and bounded

An AI agent should not inherit unlimited authority simply because its user has broad access. Agent permissions should be purpose-bound, risk-aware, and time-bound. The agent should receive only the capabilities necessary for the task, with additional approval required for high-impact actions.

A Compute Passport™ architecture can support this by carrying or referencing the agent’s approved scopes and policy attributes. Authorization systems can evaluate those attributes at runtime before a tool call or transaction is executed. Higher-risk actions can require step-up authorization, human approval, or an explicit governance gate.

6. The passport needs lifecycle state

Agent identity should change state as the agent changes. A practical lifecycle could include registered, tested, approved, active, restricted, suspended, expired, and revoked states. Material changes to the model, tools, data access, autonomy, purpose, or risk classification should trigger reassessment rather than silently inheriting an earlier approval.

This matters because an agent approved for summarizing internal documents is not necessarily approved to send emails, modify customer records, deploy code, or execute financial transactions. Identity persists; authority must remain contextual.

7. Auditability becomes a governance requirement

AI governance frameworks often focus on policies, risk assessments, documentation, and oversight. Agentic systems add a new question: Can the organization demonstrate what autonomous systems actually did?

Post-deployment monitoring is increasingly important because AI systems can behave differently in real-world conditions than in controlled evaluations. NIST has identified fragmented logging across distributed infrastructure as a barrier to effective monitoring. Persistent agent identity can help address that fragmentation by giving monitoring and audit systems a common identifier around which evidence can be organized.

For high-impact agents, governance teams should be able to retrieve a decision-ready record showing identity, authority, relevant policy, actions, exceptions, human interventions, and outcome. That record can support incident response, internal audit, governance reviews, regulatory inquiries, vendor oversight, and continuous assurance.

8. A reference architecture

A future Compute Passport™ implementation could be organized around eight layers:

Unique ID. A persistent identifier for the agent or autonomous workload.

Ownership. The accountable organization, team, service owner, and where applicable the human delegating authority.

Attestation. Verified attributes describing the agent, runtime, model, version, deployment environment, and approved purpose.

Authorization. Machine-enforceable scopes, policies, expiry, delegation rules, and approval requirements.

Activity logging. Structured events recording material agent interactions and actions.

Audit trail. Correlated, integrity-protected evidence that reconstructs the chain of activity and trust.

Monitoring. Detection of anomalous behavior, policy violations, privilege changes, incidents, and material drift.

Reporting. Governance and assurance views that translate technical evidence into decision-ready records.

9. What enterprises should do now

Organizations deploying AI agents in 2026 should begin by creating an agent inventory and prohibiting anonymous production agents. Each material agent should have a unique identity, accountable owner, documented purpose, explicit authorization scope, lifecycle state, and defined logging requirements.

Security teams should design for least privilege and credential isolation. Platform teams should establish a common event schema and correlation identifiers. Governance teams should define which actions require evidence, approval, retention, and review. Audit teams should test whether they can reconstruct an agent’s activity from initiation to outcome.

The design principle is simple: no consequential autonomous action without attributable identity and sufficient evidence.

Research outlook: identity becomes infrastructure for autonomous AI

The future AI economy may involve millions of agents operating across enterprises, clouds, marketplaces, devices, and jurisdictions. At that scale, trust cannot depend on recognizing a chatbot interface or knowing which model family sits underneath it. Trust will require machine-verifiable identity, bounded authority, observable behavior, and durable evidence.

Compute Passport™ represents a research direction for that future: a portable identity and accountability layer designed to make AI agents uniquely identifiable, governable, trackable, auditable, and reportable throughout their operational lifecycle.

The strategic shift is from asking only what can this agent do? to also asking which agent did it, under whose authority, under what policy, and where is the evidence?

Research references

NIST NCCoE — Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization (2026)

NIST — Challenges to the Monitoring of Deployed AI Systems (2026)

NIST — Building Evaluation Probes into Agentic AI (2026)

Research note: Compute Passport™ is presented as a Dubai AI Group research concept for AI-agent identity, tracking, audit, and reporting. It does not constitute a government identity credential, regulatory approval, certification, cybersecurity guarantee, or representation of endorsement by NIST or any referenced organization.

Research library

Explore additional Dubai AI Group research on enterprise AI, governance, infrastructure, intelligent systems, security, and emerging computing.

View all research