Revision 2.4 · State-endorsed identity concept

State-Endorsed Identity for accountable AI-to-AI exchange.

A proposed trust layer for agents that exchange information across institutions: an issuer attests an identity or role, an operator binds that evidence to an agent, and policy controls every permitted interaction.

This page maps enabling legal and policy foundations—not a common international A2A system. The sources below support digital identity, standards, safety, and interoperability in different ways. Each jurisdiction retains its own law, sovereignty, authorization rules, and data-protection requirements.

What the concept adds

Identity should travel with verifiable authority, bounded purpose, and an audit record. It should not turn an AI model into a legal person, grant a general right to access information, or bypass a human or agency decision.

01 · ISSUER

State or recognized issuer

Issues a signed identity, organizational role, or credential under applicable law and assurance requirements.

02 · OPERATOR

Accountable agent operator

Registers a specific agent, its model version, endpoint, owner, permitted tools, and revocation route.

03 · POLICY GATE

Purpose-bound authorization

Evaluates jurisdiction, consent, scope, assurance, data classification, and time before release.

04 · RECEIVER

Verified counterpart

Accepts only the minimum authorized claim or result and records provenance for review and redress.

Policy starting points

Four jurisdictions, different foundations

These sources are design inputs for the C=US concept. They are not evidence that the jurisdictions have adopted a shared registry or mutually recognized agent credential.

European Union

Binding digital-identity framework

Regulation (EU) 2024/1183 establishes the European Digital Identity Framework. It provides for interoperable wallet functions, common protocols and interfaces, and secure sharing of person-identification data and electronic attestations.

Conceptual use: an EU-compatible issuer/verifier pattern for attributed roles and selective disclosure. The regulation concerns digital identity wallets; it is not an A2A authorization mandate.

United States

Federal policy and voluntary standards

The 2025 AI Action Plan promotes AI standards and adoption, while the NIST AI Risk Management Framework provides voluntary governance and risk-management guidance.

Conceptual use: a standards-and-assurance baseline for agent operators. No national U.S. statute establishing a general state-endorsed A2A identity layer is asserted here.

Canada

Federal digital-service policy

Canada’s Guideline on Service and Digital directs departments to use approved trust frameworks and support interoperable identity assurance; its enterprise architecture calls for secure APIs and appropriate authentication of individuals, processes, or devices.

Conceptual use: federated trust and secure service interfaces. Canada’s Auditor General has also reported that a national interoperable digital-identity approach remains incomplete.

China

AI safety and governance policy

China’s AI Safety Governance Framework and its Global AI Governance Action Plan address safety governance, traceability, information sharing, and international cooperation.

Conceptual use: traceability, risk evaluation, and governed information exchange. These materials do not create a cross-border A2A identity-recognition mandate.

Proposed A2A information flow

Interoperate only after policy agrees

  1. Register: the operator binds an agent to a verifiable organizational identity, model/version record, endpoint, and accountable contact.
  2. Request: the calling agent presents a signed, short-lived credential plus purpose, requested data class, and intended action.
  3. Decide: the receiving policy gate evaluates local law, bilateral agreement, scope, consent or another lawful basis, assurance, and revocation status.
  4. Exchange minimally: the system shares only permitted claims or task outputs through authenticated, encrypted interfaces; it does not expose a general directory.
  5. Record and revoke: both sides retain auditable provenance, support human review and redress, and can suspend a credential or endpoint.

Design safeguards

Interoperability must not become automatic access

Human accountability

An identified organization remains responsible for each deployed agent and high-impact decision.

Data minimization

Use selective disclosure, purpose limits, retention rules, and data-classification controls.

Jurisdictional control

Local law and the receiving system’s policy govern every release; no credential overrides them.

Revocation and review

Credentials, endpoints, and permissions must be rapidly revocable and independently reviewable.

Primary sources

Read the governing material