Persistent agent identity and memory

FUURAA AI Evidence Atlas · Evidence dossier 01

Under what conditions can an AI Agent preserve identity and useful memory without silently expanding authority or privacy risk?

Standards for verifiable identity, delegated authority and selective disclosure are emerging, while research is showing that long-term memory requires temporal, relational and contradiction-aware reasoning. A complete, portable and accountable continuity layer has not yet been demonstrated across organisations and tools.

Current evidence position
Developing
Related research field
Agent foundations
Last reviewed
Record version
1.0
01

Why this question matters

An agent that remembers, acts and represents a person or organisation needs more than a login. Identity must say who or what is acting; authority must say what it may do; memory must preserve useful context; and all three must remain reviewable, revocable and proportionate.

02

Scope and disclosure boundary

This dossier examines technical and governance evidence for agent credentials, delegated authority, long-term memory, provenance, consent, revocation and cross-system continuity. It does not claim that FUURAA has completed such an infrastructure.

03

Current evidence position

The direction is visible, but the evidence base, operating history or independent validation remains incomplete.

This evidence dossier synthesises public records. It is not investment, medical, legal or safety certification advice, and it does not claim that FUURAA has completed the systems discussed.

Claim-to-evidence map

The dossier preserves support, tension and uncertainty together.

01

What the current record supports

  • Agent identity and delegated authority are distinct security problems from ordinary human login.
  • Machine-verifiable credentials and selective disclosure can reduce reliance on centralised, over-collecting identity flows.
  • Long-horizon memory quality depends on time, relationships, conflict handling and downstream decision usefulness—not only similarity search.
  • Authority boundaries, connector controls, audit trails and revocation need to operate throughout the agent lifecycle.
02

Where evidence or interpretation diverges

  • More persistent context can improve usefulness while increasing privacy exposure, behavioural inference and the cost of an incorrect memory.
  • Portable identity may reduce platform lock-in, yet portability can also move compromised authority or sensitive memory across boundaries.
  • A continuous agent may benefit from stable identity, while some contexts require deliberate separation, expiry or anonymity.
03

What remains unknown

  • Which identity and memory primitives will interoperate across vendors without creating a universal surveillance layer?
  • How should an agent explain which memories changed a consequential action?
  • What should survive when a user changes provider, role, jurisdiction or relationship to an organisation?

Primary evidence records

Read the public records behind the current evidence position.

EV-01-01NIST NCCoE · 2026-02-05

Agents need first-class identities

NIST's concept work applies identity standards and authorization practices directly to software and AI agents that access data, tools and applications.

FUURAA interpretation

An agent should be identifiable independently from its user, model provider and runtime so responsibility can be traced precisely.

EV-01-02NIST NCCoE · 2026-02-05

Delegated authority must be explicit and bounded

Agent autonomy creates a difference between authenticating an actor and deciding what that actor may do on another party's behalf.

FUURAA interpretation

Future systems should encode scope, duration, resource limits, revocation and escalation into every delegation.

EV-01-03W3C · 2025-05-15

Selective disclosure can reduce agent data exposure

Credential systems can be designed so a holder proves a relevant attribute without sharing an entire underlying identity record.

FUURAA interpretation

Agents may demonstrate authority or eligibility while minimizing personal and enterprise information revealed to counterparties.

EV-01-04SubtleMemory research team · 2026-06-04

Long-term memory needs relation awareness

SubtleMemory tests whether agents distinguish complementary, nuanced and contradictory memories instead of retrieving isolated similar passages.

FUURAA interpretation

Memory stores should represent relationships among records, not only vector proximity.

EV-01-05SubtleMemory research team · 2026-06-04

Contradictions should not be silently merged

Persistent assistants accumulate records that may diverge as people, plans and circumstances change.

FUURAA interpretation

Memory systems should preserve versions, provenance and unresolved conflicts until a trusted process resolves them.

EV-01-06OpenAI · 2025-10-06

Connector governance becomes an enterprise control plane

Central connector registries can determine which agents reach which systems and under what administrative policy.

FUURAA interpretation

Organizations may manage agent connectivity like identity infrastructure: inventoried, approved, monitored and revocable.

Testable questions

Questions that can move the evidence position—not decorate the debate.

  1. Q1

    Can an independent verifier reconstruct an agent’s authority chain and detect expired or excessive permissions?

  2. Q2

    Does contradiction-aware memory improve decisions on long-running tasks without materially increasing sensitive-data retention?

  3. Q3

    Can a person revoke a delegated capability and observe that revocation across every connected tool?

Decision relevance

What the record changes for research, engineering and institutions.

01

Research: evaluate memory through downstream decisions, provenance and correction—not recall alone.

02

Engineering: separate identity, authority, memory and connector policy so each can be inspected and revoked.

03

Governance: require visible consent, purpose limitation, retention boundaries and incident-ready audit records.

Revision record

A conclusion is a maintained record, not a permanent slogan.

Version 1.0 establishes the initial public synthesis. Future revisions will record changes in evidence position, sources, scope and unresolved questions. Earlier records are not silently erased.

Corrections, missing primary evidence and material counter-evidence can be submitted through the FUURAA contact route. Inclusion is subject to source verification and editorial review.
1.0
Initial public evidence synthesis

Continue through the Evidence Atlas

Evidence develops through connected questions.

02Mixed

When do multiple AI Agents outperform a well-designed single-agent system, and what coordination infrastructure makes that advantage dependable?

03Developing

What evidence is required before embodied AI can be trusted to act around people in open, changing environments?

00FUURAA AI Evidence Atlas

Return to the complete dossier directory.