Building trust into the next generation of digital services
By Bilel Jamoussi (ITU) and Goran Vranic (World Bank Group), with inputs from ITU and World Bank Group teams
Imagine an entrepreneur in a developing country asking an AI agent to help start a new business.
The agent registers the business online, applies for a trading permit, checks whether the business qualifies for a startup support programme, and arranges asset-based financing.
Whether it’s a business registry, a licensing authority, a support programme administrator, or a lender, they need to know one thing first – is this agent genuinely authorized by the applicant?
As governments accelerate digital transformation, this principle must extend from people to organizations and the autonomous AI agents increasingly acting on their behalf. In public administration, they could help people and businesses obtain credentials, benefits, permits, or licenses through one interface.
But before an agent acts, the government authority interacting with the agent must establish who controls it, whose interests it represents, what it may do, and whether it can be trusted, along with relevant privacy and cybersecurity measures.
New focus group
Answering such questions is the aim of the new ITU Focus Group on Trust and Identity for Humans and Agentic AI (TIDA).
The group is open to all interested experts from governments, standards bodies, industry, academia and international organizations, and participation does not require ITU membership; addressing governments’ requirements is high on the agenda. It is part of the work of ITU-T Study Group 17, the ITU standardization group responsible for security and identity management at the International Telecommunication Union (ITU).
The World Bank Group, as an observer in ITU’s TIDA Focus Group, will bring its experience working with governments on digital public infrastructure, digital identity, and digital government in developing countries. This perspective can help ensure that emerging approaches take into account the practical realities of implementation, including interoperability, institutional capacity, and different levels of digital maturity.
This also builds on ongoing collaboration between the ITU and World Bank Group on digital development and trusted digital infrastructure. Bringing together international standard-setting and experience from countries putting digital systems into practice can help advance approaches that are practical, inclusive, and fit for purpose.
For entrepreneurs, the result could streamline a potentially complex process: their AI agent applies for registering a company, secures the necessary permits, and lines up financing – and every party in the chain can prove that the entrepreneur asked the agent to do so.
But to fulfil this promise, trusted agent identities will be key. In practice, this means a verifiable digital credential that identifies the agent, links it to the person or organization that delegated the task, and records what the agent is authorized to do and for how long – identity together with authorization, rather than a legal identity of its own.
From digital ID to agent ID
An AI agent acting for a person or business must therefore carry trustworthy evidence linking it to an operator or delegating party and specifying its permitted capabilities and the duration of its mandate.
Responsibilities delegated to an agent should be specific, time-bound, traceable, and revocable. Each action by the agent should also produce auditable evidence of the authority who requested it, what data was used, and the result.
The progression from identifying people to identifying organizations – businesses and institutions, identified through business registries and unique business identifiers – and AI agents is a dependency chain – a chain of trust.
Earning trust every iteration
Valid identifiers establish what an agent is, but not whether it remains safe or compliant.
Trust must be evaluated throughout the agent lifecycle, because risks change whenever each agent receives new tools, connects to another agent, or needs access to sensitive data.
But trusted agents also depend on trusted data. While fragmented records and registries, inconsistent definitions, and poor metadata cause inaccurate or biased outcomes, agents using common data models, equipped with provenance information, quality controls, consent rules, and privacy safeguards can interpret information consistently and work with humans to make corrections when needed. This is AI-ready data.
Why international standards matter
The resulting public service architecture combines identity, data and cybersecurity standards.
AI developers and providers need common standards for agent identity, credentials, delegation, and accountability. The alternative – fragmentation – raises costs, complicates cross-agency services, and creates security gaps.
The new ITU Focus Group on TIDA is developing shared terminology, use cases, identity models, credential formats, assurance levels, lifecycle controls, and a common way for a government system to check an agent’s authorization before allowing it to act. These will take the form of technical reports and draft specifications that feed into ITU standards work.
With standards supporting mutual recognition, an agent authorized by a municipality can be recognized by national tax, health or social-protection systems. The same logic applies across national borders.
ITU’s Focus Group on TIDA, therefore, is working towards mutual recognition across borders, so that an agent authorized in one country or agency can be recognized by another, and any authority can establish which entity is acting and on what authority before the agent proceeds.
What can governments do today?
Agentic AI could rapidly make digital government services more proactive, accessible, and user-centric. Still, people’s confidence in it will depend on safeguards.
Governments can start with bounded, lower-risk uses for AI agents, such as pre-filling and status checks; maintain rigorous inventories of agents, mandates and permissions; test systems in controlled environments; require performance evidence from suppliers; and, just as importantly, align public-procurement strategies with open international standards.
A global campaign to recognize 16 September as International Identity Day aims to highlight verifiable identity as an enabler of inclusion and empowerment. The date, 16.9, echoes UN Sustainable Development Goal 16.9: Legal identity for all by 2030.
Legal identity, beginning with birth registration and digital ID, remains the foundation of that chain of trust: it is what allows people to be recognized, to register a business, and now to delegate a task to an AI agent acting in their name.
Countries investing early in these foundations will be better positioned to use agentic AI responsibly and build digital-government services worthy of public trust.