Principal — KYA Glossary

The principal is the human or organisation legally accountable for an autonomous agent’s actions. In KYA, every agent identity should resolve to exactly one accountable principal.

Why it matters

Software does not owe duties; people and organisations do. When an agent buys, files, negotiates, or deletes, the question “who is responsible?” must have an answer that is not “the model”. The principal is that answer.

This mirrors existing accountability concepts elsewhere:

  • AI regulation already assigns roles and duties to actors such as providers and deployers of AI systems (EU AI Act). The principal is the KYA-side anchor for accountability.
  • AI risk frameworks (NIST AI RMF) place accountability in governance structures, not in the system itself.
  • AML/CDD regimes make an individual legally responsible for a customer relationship; KYC/KYB establish who that is.

Note the distinction between a principal and an operator: an operator runs the agent’s infrastructure, while the principal is on whose authority and account it acts. Both may need identifying, but only the principal is the accountability anchor.

What a good principal record contains

  • A verified legal identity (tied to KYC/KYB where relevant).
  • The scope of the agent’s authority it grants.
  • A point of contact for revocation and incident response.

Related

Sources

  1. EU, Regulation (EU) 2024/1689 (AI Act) — https://eur-lex.europa.eu/eli/reg/2024/1689/oj (accessed 2026-10-03)
  2. NIST, AI 100-1, AI RMF 1.0 — https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf (accessed 2026-10-03)
  3. FATF, The FATF Recommendations — https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html (accessed 2026-10-03)
  4. ISO, ISO/IEC 42001:2023 — https://www.iso.org/standard/42001 (accessed 2026-10-03)