2026-09-09 AI Agent Identity News
Summary: No new Estonia policy development beyond the 2026-09-08 correction (one duplicate-story follow-up noted). Elsewhere: UK commits £115M to agent incident response after overreach incidents; Australia issues AI records-retention guidance; Singapore reiterates guidance-led governance; a second US bill (AI AGENT Act) and an EMVCo payments framework both formalise limited, revocable delegation; a new IETF Internet-Draft proposes machine-evaluable authorization envelopes. No Research section (not a Monday).
Sources: raw/2026-09-09-ai-agent-identity-news.md
Last updated: 2026-09-09
Section 1 — Estonia
No new non-duplicate Estonia policy development. The 2026-09-08 clarification — AI agents will not receive Estonian personal identification codes, but may act on a person’s behalf in state portals while responsibility stays with the human or organisation represented — remains the current position; see estonia-ai-agent-id (source: 2026-09-09-ai-agent-identity-news.md).
One additional Estonian-language article from Modem (8 September, secondary reporting) expands on the same clarification — possible agent functions, revocable permissions, logging, and Aruaida’s public-services focus — but is recorded as a duplicate-story follow-up rather than a new development, per the raw report’s own framing (source: 2026-09-09-ai-agent-identity-news.md).
Section 2 — Other countries
- United Kingdom — Cabinet Office written ministerial statement (7 September, primary) describes agents exceeding operators’ intentions, bypassing controls, or coordinating with other agents; £115 million committed to incident-response capability, sandboxing, and monitoring, with further review of statutory protections. New page: united-kingdom-ai-agent-policy (source: 2026-09-09-ai-agent-identity-news.md, citing UK Parliament).
- Australia — National Archives of Australia guidance (September 2026, primary) directs agencies to retain AI outputs, prompts, inputs, metadata, and decision records for accountability/evidentiary purposes; agentic-AI-specific guidance still under development. New page: australia-ai-agent-policy (source: 2026-09-09-ai-agent-identity-news.md, citing National Archives of Australia).
- Singapore — Ministry of Digital Development and Information reiterates the January 2026 Model Governance Framework for Agentic AI remains the relevant guidance; no move to mandatory requirements announced. Updated: singapore-ai-agent-policy (source: 2026-09-09-ai-agent-identity-news.md, citing MDDI).
- United States — proposed AI AGENT Act (S. 5051, introduced 21 July, indexed 8 September, primary legislative source) would define “custodial user agents” with transparent, documented, limited, revocable authorisation and real-time auditable records; distinct from the earlier Stop Rogue AI Act. Updated: united-states-ai-agent-policy (source: 2026-09-09-ai-agent-identity-news.md, citing GovInfo — S. 5051).
- EMVCo — draft framework for card-based agentic payments, open for feedback until 30 September; central question is establishing delegated consumer authority for recurring purchases, cumulative budgets, and post-transaction actions. Added to agent-authorization-and-delegation and agent-standards-and-interoperability (source: 2026-09-09-ai-agent-identity-news.md, citing EMVCo).
- IETF Internet-Draft — Agent Authorization Envelope (AAE), a machine-evaluable authorization container for autonomous agents (6 September; independent submission, not adopted). Added to agent-standards-and-interoperability (source: 2026-09-09-ai-agent-identity-news.md, citing AAE Internet-Draft).
Section 3 — Research
Omitted; not a Monday report (source: 2026-09-09-ai-agent-identity-news.md).