Back to News
RSS feedgithub.com

UAI Proposes Verifiable Identity and Accountability for Autonomous AI Agents

Summary

Universal Agent Identity (UAI) is an open protocol and working reference implementation for making autonomous AI-agent actions attributable and independently verifiable. It separates identity, ownership, capabilities, authorization, action records, and verification instead of treating registration as proof that an agent is safe. The design defines four main artifacts: UAI-ID for a globally unique identity, a credential binding the agent to an owner and capabilities, a passport restricting where and until when it may act, and an action attestation recording outcomes such as ALLOW, DENY, QUARANTINE, ERROR, or EXCEPTION. Attestations are signed and hash-chained, while transparency evidence, inclusion proofs, checkpoints, witness signatures, and event-chain continuity can be checked by a local browser verifier without trusting the registry's API. The SDK evaluates policy before business logic runs and can use salted commitments, hashes, or other cryptographic representations to avoid sending sensitive inputs and outputs as plaintext. UAI also proposes federated registries that exchange signed identity statements; peering does not mean that every agent issued by a peer is trusted. The repository includes protocol specifications, JSON schemas, OpenAPI definitions, cryptographic and Merkle-transparency mechanisms, policy and governance components, smart contracts, Go/Python/TypeScript SDKs, MCP tooling, an end-to-end demo, and a two-registry federation prototype. The project identifies multi-hop federation, peer discovery, revocation propagation, route selection, and federation-wide discovery as unfinished areas. It explicitly states that identity does not prove software safety, authorization does not prove beneficial behavior, cryptographic evidence does not guarantee correct execution, revocation cannot stop already-running disconnected code, and the federation prototype is not production-ready. The reference implementation is Apache-2.0 licensed, while the specification additionally uses CC-BY-4.0.