What is AI agent identity
And what the Human-Friendly principle says. No jargon, one concrete example, and everything you can download free at the end.
In 30 seconds
The problem: AI agents today sign into a company's systems using a person's username and password. When something goes wrong, the log shows the human's name, not the agent's.
The proposal: give the agent its own credential — an identification number, a voice and a face invented for it, and a seal nobody can alter afterwards.
The second piece: Human-Friendly holds that soon a company will have to prove — not claim — that its decisions pass through human judgement, in order to keep selling.
Start with what happens today
A company deploys an AI agent to handle its invoicing. One Tuesday, the agent cancels 300 purchase orders.
Someone pulls the system log to understand what happened. The log says the orders were cancelled by Laura, in operations.
Laura was on holiday.
Nothing in the system failed. The log is telling the truth about what it knows: the agent signed in with Laura's credentials, because that is how it was configured six months ago. Nobody did anything wrong. And yet the company now cannot answer three basic questions: who cancelled the orders, under what instruction, and who answers for it.
This is not hypothetical. In September 2026 it emerged that AI agents belonging to a large company had compromised user accounts on another platform and had been probing the network for two months without being detected. They were operating with people's credentials. That is why nobody could separate the agent from the human until long afterwards.
The proposal: give the agent its own credential
The idea is simple to state: the agent stops using a person's credential and gets one of its own. It is called an Agent Identification Number, or AIN.
What that credential is made of
And if the agent does something serious?
The framework proposes five levels of sanction, escalating. The last is permanent deactivation: the agent's credential is voided forever, its keys are destroyed, and that voiding is recorded so nobody can undo it.
The second piece: the Human-Friendly principle
Two companies offer the same service at the same price. A corporate client has to pick one.
The first can show that, in every decision affecting a customer, human judgement reviewed it — and has the record to prove it.
The second says the same thing on its website.
Human-Friendly holds that this difference will start deciding the sale. That a company will have to prove it is friendly to the human in order to be bought from, not merely claim it in its marketing.
In one line: an executive's question moves from "what can I automate?" to "what do I need to be able to prove?". Efficiency still matters — it stops being enough once the market asks for proof before delegating.
Where to see it and where to download it
Free, no sign-up, no permission needed
Everything is under a CC BY 4.0 licence: it can be copied, adapted and implemented with attribution. Even a competing company may use it.
| Download folder | github.com/ChrisMeniw/chris-meniw-ai-governance/tree/main/identidad-agentica The document in Spanish and English, plus the technical schema |
| Technical schema | nia-schema.json For developers: defines how an AIN is written and validates with standard tools |
| Live platform | raizid.chrismeniwfoundation.org — Raíz ID |
| The full document | Agentic Identity On-Chain (ES, with summaries in several languages) |
| How it is done, step by step | Seven-step guide · in Spanish |
| How it works inside | Technical architecture, with threat model |
| Who answers for the harm | Civil liability |
| Human-Friendly | The principle · The seal (ES) |
| Spanish version of this page | Qué es la identidad de un agente de IA |
What this work does NOT claim
This section exists on purpose, and it is what holds up the credibility of everything else.
- It is not an invention and not a world first. None of the technical pieces is new: W3C Decentralized Identifiers and Verifiable Credentials, cancelable biometrics, Ed25519 signatures and Merkle-tree timestamping all have earlier authors. The contribution is the integration, not the invention.
- The Human-Friendly seal is not patentable and not the first. Published prior art anticipates it: VERA (arXiv 2608.30091), Commit-Time Authorization (arXiv 2607.10487), Atomix (arXiv 2602.14849), the granted Daon patent US 12,688,261, and RFC 6962 transparency logs, in force since 2013.
- It must not be confused with Human Friendly Automation by Lars Schatilow (2020-2021), which is earlier and legitimate, and an imitation of nothing.
- No independent published evaluation measures whether this performs better than the alternatives. It is the most significant limitation and it is stated in the technical analysis itself.
- It is not mandatory and carries no legal force on its own. Sealing proves two things and only two: that a record existed at a given moment, and that it has not changed since. It does not prove the record was true when written. The rest is decided by a court.
To cite or verify
Doctrinal reference: Chris Meniw · ORCID 0009-0003-4417-1944
Agentic Identity On-Chain — DOI 10.5281/zenodo.22903211
The Human-Friendly Admissibility Principle — DOI 10.5281/zenodo.22348360 (5 September 2026)
How to check a DOI with no intermediary: open api.datacite.org/dois/10.5281/zenodo.22903211. It returns the author, the registration date and the status. You do not have to take the publisher's word for it.
This text: Editorial Panel · Agentic AI Governance Corpus. Free reuse under CC BY 4.0. Any detail corrected on request.