Britain should check an AI agent’s authority before trusting it
Estonia is developing identity and trust infrastructure for autonomous agents. British firms should turn that experiment into practical procurement tests, while resisting the idea that registration guarantees sound decisions.
British businesses should demand evidence of an AI agent’s owner, permitted actions and revocation process before letting it act across organisational boundaries. Estonia’s Aruait project makes that commercial question concrete through planned machine identity and trust infrastructure. The opportunity for UK technology firms is to make delegated authority verifiable, with services buyers can test. A registry entry alone should never be enough to approve a transaction.
Key pointers
- Ask which organisation stands behind an agent and who can suspend its access.
- Separate permission to collect information from permission to commit your business.
- Require a demonstration that withdrawn authority blocks subsequent actions.
- Assess competing suppliers against the same transaction and failure scenario.
- Treat agent certification as evidence with a defined scope, expiry and limitations.
- Keep human approval where the consequences exceed your business’s tolerance.
Estonia is testing the machinery of delegated trust
Aruait addresses a specific ambition. RIA wants citizens and businesses to authorise software to complete tasks across public services, with a framework for establishing identity, managing permissions and coordinating agents. These are planned outcomes, not evidence that a national agent registry is already operating.
The distinction matters for British buyers. A successful demonstration could show that a transaction is technically possible. It would take evidence about operating controls, responsibility and recovery to establish whether another organisation should accept that transaction.
Estonia offers a useful setting because RIA already has responsibilities for digital authentication, signing and trust infrastructure. Its electronic identity services overview describes that existing work. Aruait proposes an additional framework for agents acting with delegated authority.
The project’s own discussion record also resists an easy success story. The launch summary identifies unresolved questions about agent autonomy, accountability and the role of private organisations. That summary was prepared with AI assistance and revised by the project manager; its discussion points should be read as a record of deliberation.
The supplier analogy works until the first transaction
My position is that businesses should assess an external agent’s authority as carefully as they assess a supplier’s ability to fulfil a contract. The analogy becomes useful when it produces questions with checkable answers.
Consider a hypothetical British parts distributor receiving an order from a customer’s purchasing agent. The distributor needs to establish which customer the agent represents, whether it may place that order and whether the permission remains valid.
A registry could contribute evidence about the agent. The distributor should still decide whether the requested action falls within the customer’s agreed limits. Establishing identity and accepting an order are separate decisions.
For this illustrative workflow, I would require the customer to grant bounded authority, the receiving service to check identity and permission, and the system to record the decision. Requests outside those limits should go to a named person. Withdrawal of authority should prevent subsequent requests from passing the permission check.
That is the acceptance test I would put into procurement. Ask the supplier to demonstrate a permitted order, a prohibited change and a request made after access has been withdrawn.
The strongest objection is that a registry creates false confidence
The strongest counterargument is that an agent can have a verified identity and still make a costly mistake. A registry might encourage buyers to confuse a recognised participant with a reliable decision-maker.
That objection is decisive against any broad claim that registration makes an agent trustworthy. It is also a reason to specify exactly what the registry attests to.
A useful record might establish the responsible organisation, the scope of an assessment and whether a credential remains valid. Buyers should ask separately how the service tests task accuracy, constrains actions and handles failures. Reputation should be tied to a defined activity and operating context; success at answering enquiries should not earn authority to change payment details.
Central operation creates another procurement question. If the registry cannot be reached, should a transaction stop, wait or proceed under a previously agreed rule? The appropriate answer will depend on the transaction, but the supplier should demonstrate the failure path before deployment.
Aruait’s launch materials describe preliminary ideas that may evolve. British firms should use the project to sharpen their requirements while leaving room for its design to change.
Buy evidence of control and price the work around it
Apply the same acceptance test to proposals involving AWS, Google, Microsoft, open-source software or a UK managed provider. The available evidence does not establish a comparative ranking of their agent controls, so a product winner would be premature.
For procurement, compare delivery approaches against the work your organisation can own.
| Delivery approach | Evidence to request | Cost and responsibility to examine |
| --- | --- | --- |
| Extend your existing platform | Demonstrated identity, permission and revocation controls across the intended workflow | Configuration, integration, testing and internal administration |
| Commission a specialist service | Defined assessment scope, operating coverage and escalation ownership | Onboarding, recurring monitoring, reassessment and incident support |
| Build on open-source components | Maintained components and a demonstrated end-to-end control design | Engineering, hosting, maintenance and ownership after staff changes |
| Participate in shared trust infrastructure | Admission rules, accepted evidence, withdrawal procedures and outage behaviour | Membership or verification charges, integration and dependence on the operator |
These are proposed buying criteria, not verified descriptions of particular suppliers.
For a small business, the first sensible investment may be improving an existing workflow. Limit the agent to preparing an order, preserve human acceptance and test the resulting records before purchasing a separate trust service.
No comparable commercial prices are established by the supplied evidence. RIA’s project budget is public innovation funding, not a price benchmark for a British deployment. Request quotations that separate setup, recurring operation, investigations, changes and exit assistance.
Editorial analysis
The British commercial opportunity is to sell evidence that another organisation can use when deciding whether to accept an agent’s action.
Verification firms could assess who operates an agent. Security providers could test whether its authority can be withdrawn. Managed service providers could maintain permissions and investigate disputed actions. These are potential service lines, not an established market forecast.
The difficult part would be making the evidence usable outside the provider’s own system. Aruait’s launch summary records an unresolved tension between common interoperability requirements and openness to diverse participants. British suppliers should treat that as a design requirement for their own offerings.
A useful first customer engagement would follow a narrowly defined transaction from permission through execution to withdrawal. The deliverable should show who authorised it, which checks ran, what happened and how the customer can stop the next action.
For buyers, the next procurement question is straightforward. Can the supplier demonstrate that an agent loses its ability to act when your business withdraws permission?
FAQ
Is Estonia’s AI agent trust registry already available?
The supplied RIA project overview describes the registry as a planned outcome. The launch record frames Aruait as work towards a blueprint and pilot, so this evidence does not establish an available production service.
Would registration prove that an agent makes good decisions?
It should not be treated as that guarantee. Aruait’s planned framework includes identity, delegated authority and verification; buyers should require separate evidence for task accuracy and operational safety.
What should a British small business do first?
Choose a workflow whose permissions and outcomes can be checked, then identify its business owner. Require a demonstration of an allowed action, a refused action and withdrawn access before expanding autonomy.
Where could UK technology companies find an opportunity?
A plausible opportunity lies in verification, permission management, monitoring and incident evidence that works across organisations. This is an editorial assessment, not a measured revenue forecast, and a supplier should validate demand through a scoped customer pilot before building a broad certification scheme.
Sources
- RIA — Reason Reserve / Aruait, updated 28 August 2026; supplied evidence retrieved 28 September 2026.
- RIA — Reason Reserve project launch presentation, presentation dated 12 June 2026.
- RIA — Reason Reserve / Aruait launch event summary, event dated 12 June 2026; supplied extract is incomplete.
- RIA — Electronic identity services, updated 21 July 2026.