The conversation around AI in government is changing fast. A year ago, most discussions focused on experimentation. Now the focus is shifting toward something bigger: how governments can safely integrate AI into real public systems.
This year alone, the ITU convened a workshop on Trustable and Interoperable Digital Identities for Human and Agentic AI in Geneva this March. The NIST NCCoE released its Concept Paper on Software and AI Agent Identity and Authorization in February, noting that “this increased scale and autonomy brings new opportunities as well as new risks.” And Smart City Expo World Congress 2026 opens in Barcelona this November on the same questions.
This edition reads the conversation from the institutional side, alongside a recent essay by Chuy Cepeda written from the agent-builder side.
What institutions will verify, and what’s being built to answer it
Before an AI system can act on a citizen’s behalf, an institution will need to answer five identity questions:
Who does the agent represent?
Who authorized it, and how?
Is the delegation still valid?
Is the action in scope?
Is it recorded for review?
These are not new institutional questions. Governments already evaluate versions of them whenever a lawyer, accountant, or guardian acts on someone else’s behalf. What changes is the need to express the answers in machine-readable, cryptographically verifiable form.
Across these efforts, four architectural primitives keep recurring as the answer. Each one can be verified locally by the institution, without calling back to the citizen in real time.
Verifiable delegation — who the agent represents and who authorized it. A credential the citizen signs, naming the agent and the scope of what it can do. Same data-model family as the mobile driver’s license.
Scope binding — what the agent is allowed to do. The scope is locked in cryptographically, using the same selective-disclosure mechanics covered in our zero-knowledge proofs edition.
Revocation infrastructure — whether the delegation is still valid. The same status-list pattern verifiable credentials already use today, now with the citizen as the issuer.
Audit trail integrity — whether the action was recorded for review. NIST’s NCCoE proposes adapting existing identity standards like OAuth 2.0 and OpenID Connect to AI agents.
What infrastructure already exists today
This is where Sovra fits.
For the past several years, Sovra has been building exactly the institutional infrastructure the agentic-gov conversation is now organizing around. Verifiable credential issuance for governments through SovraGov. Verifier infrastructure for institutions through SovraID. Citizen-held credentials through SovraWallet. On-chain trust roots through SovraChain. All of it built against the same open standards the agentic-gov conversation is converging on — W3C Verifiable Credentials, OpenID4VP, ISO 18013-5, and eIDAS.
More than 10 million credentials have been issued through this architecture and more than 50 million verifications processed, across more than twenty governments worldwide.
The standards remain unresolved. Governance models are still evolving across jurisdictions. But the trust architecture these systems are likely to depend on is already operational at institutional scale — and Sovra is positioned to be the foundation it lands on.
Worth reading this week
Agent-builder framing — Chuy Cepeda’s essay on agent identity for governments, the agent-builder-side counterpart to this edition.
From The Identity Brief — past editions that ground the architectural primitives above: How the Mobile Driver’s License Works (May 14, the credential family the delegation pattern belongs to), How a Verifiable Credential Outlives Its Issuer (May 7, the trust layer that makes round-trip-free verification work), The full lifecycle of a verifiable credential (April 23, the foundational reference), and Zero-Knowledge Proofs Explained With Your Driver’s License (February 26, the cryptography behind scope binding).
Peer-government view — Deloitte’s Government Trends 2026: Agentic AI for customized service delivery, with Estonia’s Bürokratt covered in depth.
Adjacent technical reads — Indicio’s Why Verifiable Credentials Will Power Real-World AI in 2026 and Vitalik Buterin’s proposal for personal AI agents with zero-knowledge-proof delegation in DAO governance.
Continue the conversation
More technical resources on the verifiable credentials stack, including reference implementations and deployment case studies across W3C and ISO 18013-5 formats, are available at sovra.io/knowledge.
If your institution is following the agentic-gov standards conversation or evaluating how delegation credentials could fit with existing trust infrastructure, contact us. We read every response.
If this edition was useful, forwarding it to one colleague in government or the institutional identity industry is the most direct way to grow this community.
Subscribe to The Identity Brief, published every Thursday.
The Identity Brief is published weekly by Sovra, the Digital Identity Stack for the Institutional World.




