As artificial intelligence (AI) systems become capable of performing complex operational tasks—like reconciling financial accounts, negotiating with suppliers, signing documents, and submitting legal filings—the focus is moving from what AI can do to who is responsible for its actions. Delegating authority to AI introduces new challenges regarding accountability: who authorized the AI, whose interests it serves, where its authority ends, and who is to blame if something goes wrong. These issues can't be solved by simply improving the AI's abilities. Instead, they require a clear system that sets boundaries for what the AI can do and creates a record that links each action back to the person who authorized it. AI systems can make mistakes, and these errors can quickly escalate into major problems. For example, an AI agent might accidentally send an invoice to the wrong customer or misinterpret an instruction, causing widespread errors across a market. The speed at which AI operates can turn even a small mistake into a big issue, especially when the AI has the power to send messages, submit legal documents, or move money. To manage these risks, AI agents can be legally tied to real people through secure identifiers that track the agent’s actions back to the person who deployed it. Clear permissions and rules that define the AI's authority can be set up so that its actions are visible and can be reviewed. These permissions can be very specific—for instance, an AI might be allowed to view financial records without making changes, or prepare a payment without actually approving it. These permissions can also be time-sensitive, such as expiring after one transaction or a specific period. Removing an AI agent’s authority should be simple, allowing a company to revoke its access without affecting the credentials of the person behind it. This ensures that the AI’s legal authority can last longer than the AI model itself, which might be updated or replaced over time. Estonia is exploring these issues by developing a state-backed system to register AI agents, available to both its citizens and international entrepreneurs. This system is part of Estonia's effort to adapt its fully digital public services to the growing use of AI in business. Under the current plan, individuals would receive a unique numeric identifier that can be linked to one or more AI agents acting on their behalf. Any operation performed by an AI agent would be treated as a machine’s action, with the natural person remaining legally responsible. Private service providers would also need to know whether an operation was done by a person or an AI agent, allowing them to apply appropriate controls and risk assessments. Estonia’s approach builds on its existing digital identity system, which already allows people to act on behalf of others with clear permission boundaries. This system could help establish clear mandates for AI agents, giving users more confidence that safeguards are in place to protect them from foreseeable AI errors. Before AI agents can be given significant decision-making power, they need a framework that is both technically and legally sound, clearly defining who they represent, what they can do, and who is ultimately responsible for their actions.