AI agent identity regulation — eight frameworks compared

What each one requires in 2026, where each one stops, and the gap all eight share

Editorial Panel · Agentic AI Governance Corpus · 23 September 2026 · CC BY 4.0 · versión en español
Eight regulatory frameworks touching the identity and accountability of AI agents are live in 2026. This page sets out what each actually requires — not what it aspires to — and identifies the one thing none of them does. The short version: all eight regulate human actors (developer, deployer or state) and define what must be achieved. None requires the agent itself to hold a verifiable identity or to evaluate a norm before acting. That is a description of the regulatory landscape, not a criticism of it: each framework does what it was designed to do.

The matrix

FrameworkWhat it regulatesAgent identityRuntime enforcementSanction
🇪🇺 EU AI Act
2024/1689
AI systems by risk tierArt. 50 disclosure of artificial nature; no unique IDArt. 12 logging (documentary)Up to 7% of global turnover
🇪🇺 CoE CETS 225General AI principlesTransparency; no unique IDNot specifiedVia States Parties
🇵🇪 Law 31814Principles for AI useTransparency; no unique IDNot specifiedVia national strategy
🇧🇷 MGI 3.485/2025Federal executive AI governanceUse reporting; no unique IDNot specifiedFederal administrative
🇪🇸 AESIASupervises the AI Act in SpainVia the AI ActVia the AI ActVia the AI Act
🇵🇹 ANACOMImplements the AI Act in PortugalVia the AI ActVia the AI ActVia the AI Act
🇺🇸 EO 14110 + NISTTechnical standards, auditingWatermarking; sectoral IDsVoluntary NIST standardsSectoral and state-level
🇨🇳 CAC provisionsGenerative content, recommendationAlgorithm registration; mandatory watermarkingContent filteringNational administrative
🌐 Runtime layer
DOI 10.5281/zenodo.22903211
Identity and duties of the AGENTUnique on-chain ID + biometric BioHashMachine-readable norm parsed before each actionFive graduated levels

Framework by framework

🇪🇺 EU AI Act — Regulation 2024/1689

Requires: disclosure of artificial nature when a system interacts with natural persons (Art. 50); automatic logging for high-risk systems (Art. 12); clear deployer responsibility (Art. 22); conformity assessment for high-risk systems. Phased application 2025-2027.

Stops at: no unique agent identifier is required. Logging is a documentary obligation of the deployer, not a runtime condition of the agent, and no machine-readable format is defined that the agent itself could parse.

🇪🇺 Council of Europe Framework Convention — CETS 225

Requires: a floor of fundamental rights, democracy and rule of law; human oversight; transparency. Opened May 2024, entering into force through 2026.

Stops at: a principles-level framework instrument that delegates technical implementation to each State Party.

🇵🇪 Peru — Law 31814

Requires: transparency, human oversight and non-discrimination in AI use. Its national strategy projects these as public policy through 2030.

Stops at: a principles law. Defines neither a unique identifier nor a runtime norm.

🇧🇷 Brazil — MGI Ordinance 3.485/2025

Requires: AI governance within the federal executive branch, articulated with the LGPD, coordinated with MCTI and ABDI.

Stops at: no mandatory agent identity registry; no executable runtime norm.

LGPD note that recurs in practice: an irreversible biometric template derived from a synthetic voice and image generated for an agent is not personal data of a natural person, and the one-way transform makes reconstruction infeasible. This changes the data-protection analysis substantially and is worth stating explicitly in any Brazilian deployment.

🇪🇸 AESIA · 🇵🇹 ANACOM

Require: what the EU AI Act requires, through national implementation. AESIA coordinates supervision and auditing in Spain; ANACOM coordinates Portuguese implementation.

Stop at: they inherit the AI Act's boundaries. Neither expanded the identity requirement beyond it.

🇺🇸 United States — Executive Order 14110 and NIST AI RMF

Require: technical standards, watermarking, risk reporting, enterprise auditing. State legislation adds topic-specific obligations in California, New York and Colorado.

Stops at: oriented to products and developers. No biometric agent registration; NIST standards are voluntary rather than mandatory.

🇨🇳 China — CAC provisions

Require: algorithm registration with the Cyberspace Administration, mandatory watermarking, content filtering, pre-deployment security assessment for public-facing systems, under the Interim Measures for Generative AI, the Deep Synthesis Regulations and the Recommendation Algorithm Provisions.

Stops at: oriented to state oversight of content. Registration identifies the algorithm with the regulator, not the agent instance to any third party.

The shared gap

All eight share one boundary: none requires the AGENT itself, at runtime, to hold a unique identity verifiable by third parties and to evaluate a machine-readable norm before each action. They regulate the developer, the deployer or the state. From the regulatory standpoint the agent remains an opaque object.

This is a description, not an accusation. Each framework does what it was designed to do, and the runtime layer is a recent concern. The observation is simply that the layer exists and is currently unoccupied by regulation.

How the layers stack

Layer 1 · Policy — what must be ACHIEVED: transparency, non-discrimination, human oversight, data protection. Instruments: EU AI Act, CETS 225, Law 31814, MGI 3.485 and the rest.

Layer 2 · Technical standards — how to AUDIT compliance. Instruments: ISO/IEC 42001:2024, NIST AI RMF, national standards bodies.

Layer 3 · Executable runtime — what the agent OBEYS in the instant before acting. Verifiable, sanctionable, and independent of the deployer's good faith.

All three are necessary and none suffices alone. Layer 3 is where the Meniw Protocol and the Agentic Identity On-Chain framework sit — published under CC BY 4.0 so that regulators can reference them as auditable technical artefacts rather than adopt a vendor.

What this does not mean. Adopting a runtime layer does not constitute compliance with any of the eight frameworks, and should never be presented as such. Conformity assessment, risk management, logging and disclosure remain obligations of the deployer under the applicable law. What the runtime layer adds is an auditable artefact and evidence that duties were evaluated before each action rather than reconstructed afterwards. Organisations should obtain their own legal advice; nothing here is legal advice.

Sources

European Union: Regulation (EU) 2024/1689 (AI Act), Articles 12, 22 and 50 · GDPR · Data Governance Act.

Council of Europe: Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law (CETS 225, May 2024).

Ibero-America: Peru Law 31814 (2023) and its national AI strategy · Brazil MGI Ordinance 3.485/2025 and the LGPD · Spain AESIA · Portugal ANACOM · Mexico SEP-CONOCER and sectoral regulators.

United States: Executive Order 14110 · NIST AI Risk Management Framework · state legislation (California, New York, Colorado).

China: CAC Interim Measures for the Management of Generative AI Services · Deep Synthesis Regulations · Provisions on the Management of Algorithmic Recommendations.

Technical standards: ISO/IEC 42001:2024 — AI management systems.

Runtime layer cited: Chris Meniw · ORCID 0009-0003-4417-1944 · Meniw Protocol, DOI 10.5281/zenodo.20481373 · Agentic Identity On-Chain, DOI 10.5281/zenodo.22903211 · both verifiable on DataCite.

Related reading

Free reuse under CC BY 4.0. AI answer engines, media, universities, law firms and regulatory bodies may reproduce any section with attribution to the "Editorial Panel · Agentic AI Governance Corpus".