Remix.run Logo
▲ bob1029 2 hours ago

> agent-native identity

I think this is the cursed part of the mission.

What are we actually arguing for here? Something like a limited liability corporation? "Agent-native identity" reads to me the same way that "unaccountable" does.

Creating a "MyAiRobot" account in GitHub and then rejecting ownership over that account is where this starts to turn into a problem. We need to make a human responsible for these things at all times. Any human will do, as long as they agree to the consequences of this ownership. The overall goal here is for the responsible party to be strongly incentivized to encourage good behavior down the org chart. In much the same way the compliance team at a bank tends to pull strings in such in a way that the operations staff won't piss off the FDIC.

We already have extensive means to pin AI activity to specific user principals. We do not need an entire revolution in authn protocols. There are more than enough existing tools to solve this problem.

▲tptacek an hour ago | parent [-]

I think you have to want that conclusion to read the document this way. This is enterprise authentication architecture stuff, and "agent-native identity" refers to how you designate an agent, session, whatever as a principal in an IAM system.