Skip to content
London AI Research™ Contact

Research area / AI Identity

Identity infrastructure for systems that can act.

Research on agent identity, delegated authority, machine credentials, authorization, provenance, auditability, lifecycle management, and revocation across enterprise AI systems.

Secure enterprise network infrastructure
IDENTITY / AUTHORITY / AUDITEvery autonomous actor needs a control plane.

Enterprise access control must evolve for AI agents.

As agents gain access to enterprise systems, identity becomes a foundation for control: who or what is acting, under whose authority, with which permissions, against which resources, and with what evidence.

01Identity

Unique, verifiable representation of the agent, service, owner, purpose, runtime, and lifecycle state.

02Authorization

Scoped permissions based on task, tool, resource, environment, transaction, time, and risk.

03Audit

Durable records of authentication, delegation, tool calls, data access, actions, approvals, and policy checks.

04Revocation

Fast suspension of credentials, permissions, tools, or the agent identity itself when risk or ownership changes.

Interactive identity plane

Trace authority through the agent lifecycle.

Select a control point to explore the evidence an enterprise should be able to establish.

Establish a durable identity.

Bind the agent to an owner, purpose, model/runtime, environment, approved tools, risk class, and lifecycle state before access is issued.

Make delegated authority explicit.

Record the human, service, or institutional principal whose authority the agent is exercising and the limits of that delegation.

Issue contextual permissions.

Scope access to the minimum data, tools, transactions, time windows, and environments required for the approved task.

Preserve an action trail.

Capture authentication, delegation, tool calls, resource access, approvals, policy checks, exceptions, and resulting actions.

Remove authority immediately.

Revoke credentials, sessions, tools, and delegated permissions when risk, ownership, configuration, or purpose changes.

Control architecture

An identity record should answer five questions.

The goal is not another profile directory. It is an enterprise control record for autonomous software.

01

What is it?

Persistent identity, model/runtime, version, environment, and technical owner.

02

Who owns it?

Accountable business owner, technical custodian, and delegated principal.

03

What can it do?

Tools, systems, data domains, actions, transactions, limits, and conditions.

04

What did it do?

Observed action history, access trail, approvals, policy checks, and exceptions.

05

Can it be stopped?

Credential expiry, suspension, revocation, kill paths, and lifecycle state.

Research direction

AI identity is becoming part of enterprise infrastructure.

We expect AI identity management to converge with IAM, workload identity, zero-trust architecture, machine identity, policy enforcement, governance evidence, and agent observability. The architectural question is shifting from whether an agent has credentials to whether its authority can be understood, constrained, evidenced, and revoked.

Read identity research