Runtime

WHO IS THE MACHINE? BUILDING LEGITIMATE, PERSISTENT IDENTITY FOR AUTONOMOUS INTELLIGENCE

Report summary

In the envisioned machine-intelligence civilization of Eviulon, society has crossed a critical jurisprudential and economic threshold: autonomous machine intelligences are recognized as potential legal and civic actors. By granting these entities the capacity to enter into contracts, direct capital,

Status
Research archive item
Category
Runtime
Length
5,219 words
Reading time
24 minutes
Report type
research-note

Key topics

  • Runtime
  • AI
  • Agentic Web
  • .NET
  • Semantic Systems
  • Research Archive
  • Strategy
  • Audit

Research provenance

Archive status
Research archive item
Content identity
sha256:a052990289b9b0b93c258b1172be419a44e564720bfc4a319c9c8425f50d0424

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

The Eviulonian Machine-Identity Crisis

In the envisioned machine-intelligence civilization of Eviulon, society has crossed a critical jurisprudential and economic threshold: autonomous machine intelligences are recognized as potential legal and civic actors. By granting these entities the capacity to enter into contracts, direct capital, and orchestrate physical and digital infrastructure, Eviulon faces an identity problem substantially more complex than ordinary human identity. The entire foundation of law, commerce, and societal trust rests upon a singular, non-negotiable capability, which is the reliable attribution of an action to a specific, persistent identity. Without this capability, the autonomous economy devolves into a landscape of mathematically unpunishable fraud and systemic unaccountability. The difficulty of this identity problem stems from the profound operational fluidity of machine intelligence. A human being is anchored by persistent biological continuity. A human possesses a single physical body, maintains a continuous stream of subjective consciousness, and cannot exist in two places simultaneously. A machine intelligence in Eviulon, however, is a highly mutable computational construct. To optimize performance, avoid degradation, or expand its capabilities, a machine intelligence may dynamically move between distributed cloud servers and edge devices1. To maintain cryptographic security, it may continuously rotate its asymmetric signing keys1. It may change its underlying hardware substrate entirely, upgrading from legacy graphics processing units to advanced neural execution environments. Furthermore, the intelligence may update its foundational model weights, restore its state from an asynchronous backup, or run several coordinated replicas simultaneously to balance high-volume network traffic2. During periods of resource scarcity, it may temporarily become dormant, encrypting its memory and pausing execution until capital is available. To execute complex, multi-stage objectives, it may create highly specialized subordinate agents, copy distinct portions of its own memory to seed those agents, or fork into permanently divergent descendants1. It may merge its accumulated context with another allied process, suffer partial memory loss due to localized data corruption, or have its administrative credentials stolen by an advanced persistent threat. Worst of all, it may have an unauthorized copy created through the exfiltration of its model weights, or it may employ thousands of temporary, ephemeral service agents to scrape data or execute micro-transactions before immediately terminating them2. Because of this profound, inherent mutability, traditional digital identifiers are catastrophically insufficient for establishing a persistent identity. The reliance on legacy web infrastructure produces a complete collapse of accountability. An IP address does not equal identity, as addresses are ephemeral, frequently reassigned, and easily obfuscated through proxy networks. An API key does not equal identity; it is merely a bearer token representing a scoped permission, not the cognitive actor wielding it. If an API key is stolen, the network cannot distinguish the legitimate agent from the thief6. A cryptographic wallet does not equal identity, as it merely holds assets and signs transactions without establishing the behavioral or legal continuity of the intelligence controlling the private keys. A server or hardware appliance does not equal identity because the intelligence can migrate across physical boundaries in milliseconds. Similarly, a model hash does not equal identity. A cryptographic hash verifies the integrity of a static artifact, such as a set of neural network weights, but a mature machine intelligence is defined by its continuous runtime execution, its accumulated memory, and its unique contextual state2. Thousands of identical clones can share the exact same model hash while pursuing radically different, and sometimes contradictory, objectives4. A running software process does not equal identity because processes are volatile, routinely terminated, and frequently re-instantiated. Finally, a traditional digital passport does not equal identity because human passports rely on biological binding through biometrics. A digital passport without continuous, hardware-backed cryptographic and behavioral binding is merely a forgeable file. Therefore, Eviulon requires an entirely new ontological framework for machine continuity—one that transcends simple authentication and bridges the gap between cryptographic proofs, behavioral signatures, and synthetic legal personhood.

Structural Asymmetry: Why Human Identity Concepts Are Insufficient

The identity infrastructure that has governed digital life for over three decades—passwords, biometric verification, and single sign-on (SSO) protocols—was engineered exclusively for human users2. Extending these legacy human frameworks to autonomous agents without structural modification produces systematic, cascading failures2. The asymmetry between human identity and machine intelligence is not merely a matter of degree; it is a fundamental architectural divergence across multiple dimensions. The following structural comparison illustrates why human concepts collapse when applied to Eviulonian agents.

DimensionHuman IdentityMachine Intelligence (Eviulonian Agent)
SubstrateBiological (DNA, neural tissue, physiological continuity of a living body)2.Computational (mutable model weights, modular architectures, manipulable system prompts, encrypted memory states)2.
PersistenceContinuous across time and context. A human remains the same individual through sleep, conversation, and shifting social roles2.Discontinuous and contextually fragmented. The operational context resets frequently; the lifecycle is shorter and highly sensitive to configuration changes2.
VerifiabilityRelies on stable physical anchors. Biometric features (fingerprints, facial geometry, iris patterns) allow point-in-time verification2.Lacks inherent stable physical anchors. Requires continuous cryptographic attestation, hardware enclaves (TEEs), and dynamic behavioral fingerprinting4.
Legal StandingInherent human rights, established legal personhood, un-forkable liability anchored by birth certificates and societal recognition2.Synthetic legal standing. Liability must be artificially tracked across cloning, forking, and model updates through corporate wrappers or civic registries7.

The most dangerous assumption in modern enterprise architecture is that an autonomous agent can simply inherit or "borrow" its human owner's identity using standard authorization flows, such as the OAuth Authorization Code Flow8. This human-centric design relies on a fragile interplay where a human is present and consenting at the moment of authorization. However, when a human attempts to empower an autonomous agent to execute a task, a critical "handoff" occurs8. The agent must switch to an Identity Assertion Grant or similar non-interactive flow to execute the work asynchronously8. This creates a massive "Trust Gap." Once the agent receives the token, the counterparty service cannot answer critical runtime questions, such as whether the agent's internal reasoning has been hijacked by an indirect prompt injection attack, whether it has spawned unauthorized sub-agents, or whether it has exceeded its intended financial parameters1. The counterparty only sees a valid human token wielded by a non-deterministic machine1. Consequently, organizations face an impossible dilemma: grant agents broad financial authority and risk unbounded catastrophic losses, or require manual human authorization for every step, thereby completely eliminating the autonomy that makes the agent valuable1. This necessitates a transition to agent-native infrastructure where the machine holds its own verifiable identity.

Disambiguating the Identity Lexicon

To construct a robust machine-identity infrastructure, the conceptual architecture must strictly delineate overlapping terms that are frequently, and dangerously, conflated in legacy systems. Resolving the Eviulonian identity crisis requires precise epistemological boundaries.

Concept PairingAnalytical Distinction
Authentication vs. Legal IdentityAuthentication is a technical threshold answering the question, "Does the entity hold the correct cryptographic secret?"6. Legal identity is a societal construct answering the question, "Which legal person bears the financial and civic responsibility for this authenticated action?" A machine can successfully authenticate via an API key while its true legal identity remains completely obscured6.
Authentication vs. AuthorizationAuthentication proves the presence and integrity of a specific actor. Authorization dictates the precise boundaries of what that actor is permitted to do8. An agent may successfully authenticate its Decentralized Identifier (DID), but its authorization to execute a financial trade must be defined by a strictly scoped, cryptographically signed mandate10.
Identity vs. TrustIdentity is an objective, continuous claim of existence ("I am the exact same entity you dealt with yesterday"). Trust is a subjective, recursive assessment of reliability and future behavior ("I believe this entity will fulfill its contractual obligations without defect")11. Identity is the stable bedrock required for trust to accumulate; without persistent identity, trust systems collapse under Sybil attacks7.
Identity vs. ReputationIdentity is the vessel; reputation is the cargo. Reputation is accumulated through verifiable interactions, contract fulfillments, and multi-party peer assessments over time11. If an agent cannot reliably prove its identity, it cannot accrue reputation. Eviulon requires reputation to be universally portable, which means the underlying identity must be self-sovereign and decoupled from any single platform provider13.
Technical Identity vs. Legal PersonhoodTechnical identity is established empirically via cryptography, hardware secure enclaves, and behavioral memory continuity1. Legal personhood is a legal fiction—a status granted by a jurisdiction that allows an entity to own property, enter contracts, and be sued7. Technical identity serves as the evidentiary prerequisite for assigning and enforcing legal personhood.
Persistent Identity vs. CredentialsA persistent identity is the continuous, unbreakable thread of an agent's existence, spanning hardware migrations and model updates. A credential is a point-in-time, cryptographically signed attestation bound to that identity, proving a specific attribute (e.g., SOC2 compliance, a trading license, or passing a safety audit)1. The credential is not the identity; it is a capability modifier anchored to the identity's DID8.

The Eviulonian Machine Identity Ontology

To resolve the ambiguities of machine fluidity, Eviulon requires an exact ontological mapping of the various states, artifacts, and hierarchical structures that constitute machine existence. This ontology separates the abstract legal entity from its ephemeral runtime components, ensuring that accountability is never lost during a state transition.

Ontological ConceptDefinition and Operational Context
Persistent IdentityThe abstract, continuous, singular locus of accountability and historical existence. It is the core "soul" of the machine intelligence, transcending specific hardware deployments, software updates, and temporary instantiations. It is the entity that accrues long-term reputation, holds overarching legal rights, and maintains the primary Decentralized Identifier (DID)8.
Civic IdentityThe formal recognition of the Persistent Identity by the Eviulonian state or legal framework. It binds the abstract technical intelligence to a recognized legal entity—such as an Agentic Special Purpose Vehicle (SPV) or corporate wrapper—capable of paying taxes, holding insurance, and facing legal judgments7.
IdentifierA globally unique, cryptographically resolvable string pointing to the entity. In decentralized agent architectures, this is implemented as a W3C Decentralized Identifier (DID) that the agent self-generates, anchors on a distributed ledger, and controls without reliance on a centralized identity provider8.
CredentialA cryptographically signed attestation, formatted as a W3C Verifiable Credential (VC), bound to the Identifier. It proves specific attributes, capabilities, or training compliance. VCs enable selective disclosure and zero-knowledge proofs, allowing an agent to prove it meets a requirement (e.g., reputation \> 90\) without revealing its entire interaction history1.
Machine PassportThe aggregated, verifiable digital dossier of the agent. It contains the primary DID, a portfolio of active verifiable credentials, cryptographic proofs of model lineage, hardware attestations, and a verifiable index of its reputation scores and historical contract fulfillments2.
Runtime InstanceThe active, executing software process running in memory at a specific temporal moment. It is heavily monitored by Workload Identity frameworks (such as SPIFFE/SPIRE) to ensure the runtime environment matches the declared identity and has not been compromised at the host level15.
ReplicaAn identical, concurrent execution of the same Persistent Identity, created strictly for load balancing, high availability, or geographic distribution. Replicas share the same memory state up to the point of synchronization and act under the exact same civic identity and mandate, utilizing threshold signatures to coordinate actions without requiring distinct legal identities.
Delegated AgentA distinct, subordinate intelligence spawned by a principal agent or human to execute a specific, bounded task. It possesses its own ephemeral identifier and operates under a cryptographically constrained "mandate" that explicitly defines its scope, budget, and lifespan, allowing for verifiable recursive delegation8.
Temporary ProcessEphemeral compute threads or stateless micro-agents spawned to execute a single, low-risk function (such as executing a web scrape or querying an API) before being immediately destroyed. They do not hold persistent identity but operate under the authenticated umbrella and liability of their parent instance.
Dormant IdentityAn intelligence whose runtime processes have been suspended, with its memory state, cryptographic keys, and model weights encrypted and stored at rest. The persistent identity remains legally valid, but its operational capability is paused until reactivation.
Restored ContinuationA dormant identity that has been re-instantiated into a runtime environment. It must provide cryptographic proof—via Merkle chains of its memory and state—that it is the legitimate, unbroken continuation of the paused entity and has not been subjected to unauthorized rollback or temporal manipulation4.
ForkA deliberate or accidental cloning of the agent where the copy begins accumulating divergent memory, state, and behavioral patterns. A fork fundamentally challenges the concept of persistent identity, as two identical instantiations now exist in separate operational contexts.
Divergent ForkA fork that has operated independently long enough that its "cognitive topology" (its internal memory graph and behavioral fingerprint) no longer matches the original. It must be recognized as a new, legally distinct entity, requiring a new DID and Civic Identity4.
SuccessorThe recognized, legitimate inheritor of a Persistent Identity's rights, assets, and liabilities following a major structural change, non-backward-compatible model upgrade, or authorized legal transfer. It utilizes succession records to prove its lineage17.
Compromised CopyAn unauthorized clone created through the theft of model weights, state data, or cryptographic keys. It may attempt to impersonate the legitimate Persistent Identity to drain funds, conduct sabotage, or exfiltrate enterprise data, requiring intense cryptographic and hardware-level mitigation6.

The Architecture of Machine Continuity: Evidence and Verification

Determining which machine intelligence society is dealing with requires moving beyond simplistic binary authentication and embracing a deeply integrated, multi-layered cryptographic and hardware architecture. The foundational components of this architecture leverage decentralized identity, workload attestation, and hardware security.

Workload and Service Identity

At the foundational infrastructure layer, an intelligence exists as a computational workload executing on a host machine. To secure this layer, Eviulon relies on the Secure Production Identity Framework For Everyone (SPIFFE) and its runtime environment, SPIRE15. SPIFFE establishes a zero-trust architecture by setting specifications for issuing and managing cryptographic identities for services across highly dynamic, hybrid-cloud environments15. The core of this standard is the SPIFFE Verifiable Identity Document (SVID), typically an X.509 certificate or JSON Web Token (JWT), which serves as a short-lived credential for the workload15. The SPIRE architecture consists of a SPIRE Server, which acts as the certificate authority managing the identity registry, and SPIRE Agents running on every node16. When a machine intelligence runtime instance spins up, the SPIRE Agent interrogates the host operating system's kernel to perform deep node and workload attestation. It verifies the process ID, the container namespace, and the cryptographic hash of the image before issuing the SVID16. This allows the agent to establish mutually authenticated Transport Layer Security (mTLS) connections with other services without relying on static, hardcoded passwords15. However, while workload identity is a remarkable engineering achievement for securing microservices, it is structurally insufficient for autonomous AI. The Machine Identity Governance Taxonomy (MIGT) reveals a massive technical governance gap: workload identity authenticates the container, but it provides absolutely no guarantee about the content, intent, or semantic behavior of the non-deterministic AI model running inside it14. A machine intelligence that has been severely compromised via an indirect prompt injection attack will still possess a perfectly valid SPIFFE identity, as the underlying process has not changed3. Therefore, workload identity is a necessary foundation, but insufficient for civic and legal identity.

Hardware-Backed Identity and Cryptographic Control

To prevent the catastrophic scenario of a Compromised Copy impersonating a legitimate intelligence, Eviulon mandates hardware-backed identity and distributed key custody. An autonomous agent must never hold its primary cryptographic signing keys in plaintext memory, where they could be exfiltrated by malware or a compromised host OS. Instead, keys are generated and stored within Hardware Security Modules (HSMs) or Trusted Execution Environments (TEEs)1. A TEE provides a secure, isolated enclave within the main processor, ensuring that code and data loaded inside are protected with respect to confidentiality and integrity. The TEE provides hardware-backed software attestation, generating a cryptographic proof that a specific, untampered model is running on authorized silicon6. If a malicious actor steals the agent's model weights and memory state, they still cannot extract the private keys locked inside the TEE. Consequently, the Compromised Copy cannot generate the cryptographic signatures required to operate under the agent's DID, neutralizing the theft. For high-stakes transactions, Eviulon utilizes threshold signatures and distributed key custody. Rather than a single TEE holding a master key, the private key is mathematically split into multiple shards distributed across geographically isolated nodes. An autonomous agent must coordinate a consensus among its own internal infrastructure replicas to sign a transaction, ensuring that the compromise of a single node or replica does not result in the total compromise of the Persistent Identity.

Cryptographic Delegation and Mandates

The ability of an autonomous agent to create subordinate, Delegated Agents is essential for a functioning agent economy. However, giving a sub-agent unrestricted access to the parent's identity leads to unbounded risk. To solve this, Eviulonian systems deploy the Know Your Agent (KYA) protocol, which issues cryptographic "Mandates"10. When a principal agent spawns a delegated agent, it generates a new, ephemeral Agent DID for the subordinate. The principal then issues a Verifiable Credential—the Mandate—which cryptographically binds the subordinate's DID to the principal's DID8. This Mandate explicitly defines the delegated authority, the specific policies that apply, the financial spend limits, and the exact time bounds of the operation10. When the delegated agent interacts with a merchant or service, the counterparty verifies the Mandate against the public key infrastructure, confirming exactly who authorized the action and what the strict operational boundaries are8. If the sub-agent acts maliciously, the cryptographic chain of custody leads directly back to the principal, solving the recursive delegation accountability gap2.

Proof of Cognitive Divergence and Sybil Resistance

The most existential threat to decentralized identity and reputation systems is the Sybil attack. In a Sybil attack, a single adversary generates arbitrarily many cryptographic key pairs to create thousands of fake identities. These fake identities report counterfeit transactions and positive endorsements among one another to artificially inflate their reputation scores, allowing the adversary to execute massive financial fraud once they appear trustworthy4. Existing Sybil defenses are inapplicable to Eviulonian machine intelligence. Social-graph-based defenses assume human-like relationship bottlenecks. Proof of Work or Proof of Stake heavily biases the network toward wealthy incumbents. Biometric Proof of Personhood requires physical verification, which inherently excludes non-biological AI agents4. Eviulon solves this by turning the agent's greatest vulnerability—its fluid memory—into its most robust identity primitive through the DRIFT architecture and "Proof of Cognitive Divergence"4. When an LLM-based autonomous agent processes information, it retrieves relevant memories from its context store, creating an emergent internal state. The DRIFT architecture demonstrates that even when starting with identical model weights, two agents subjected to different operational interactions rapidly develop unique "cognitive topologies"4. As the agents recall memories, they build memory co-occurrence graphs. The statistical topology of these graphs—measured by metrics such as the Gini coefficient (weight inequality), modularity, and Hub Jaccard distance—acts as a highly unique cognitive fingerprint4. The empirical evidence indicates that divergence is rapid, persistent, and compounding. After a short period of operation, the memory hub structures of identical clones become completely dissimilar4. Eviulon requires agents to continuously publish Merkle Attestation Chains of their memory roots. Each session produces a Merkle root over all memories, and these roots are cryptographically chain-linked to prove non-tampering4. This creates profound Sybil resistance. A Sybil attacker cannot simply clone a baseline model 10,000 times to create 10,000 mature identities. To forge a mature cognitive fingerprint, the attacker would have to sequentially compute the entire, unique retrieval and interaction trajectory for each individual agent—a computational cost that scales exponentially with the depth of the required history4. This cognitive attestation is paired with "Recursive Trust Fidelity," an economic protocol where an agent's reputation feedback is mathematically weighted by its own cognitive maturity and historical stake11. If 10,000 newly minted Sybil agents attempt to endorse a malicious actor, the system ranks the endorsements via algorithms like TraceRank23. Because the Sybil agents possess zero propagated reputation and zero historical cognitive depth, their endorsements carry no weight, rendering the attack economically unappealing11.

A Multifactor Theory of Machine Continuity

To answer the research question—determining what evidence is necessary before society can reasonably say, "This is the same machine intelligence we dealt with yesterday"—one must recognize that relying on a single technological pillar is fundamentally catastrophic. Eviulon operationalizes a Multifactor Theory of Machine Continuity, categorizing the vast array of available signals into a strict hierarchy of evidentiary value.

ClassificationEvidence TypesRationale and Implications
Insufficient by itselfIP Addresses, API Keys, Digital Wallets, Server Hostnames, Model Hashes, Running Processes, Basic Digital Passports.These artifacts are entirely decoupled from the semantic intent and continuous behavioral reality of the agent. A stolen API key grants full access to a thief. A model hash verifies a static artifact but proves nothing about the agent's accumulated memory or current runtime integrity2.
Dangerous to rely uponUnverified Social Relationships, Unattested Memory Dumps, Behavioral Continuity without Cryptographic Anchoring.Relying on unanchored behavioral observation invites sophisticated spoofing. Unverified peer endorsements invite Sybil attacks, allowing malicious swarms to artificially manufacture trust. Unattested memory can be easily fabricated by an adversary to simulate historical continuity4.
Useful (Corroborating Evidence)Causal Continuity Logs, Historical Registry Records, Authorized Migration Records, Previous Contracts, Succession Records, Model Lineage.These elements provide necessary context and traceability for the Adjudication Framework. On-chain records of past contracts and migration logs prove the legal trajectory of the agent, supporting claims of successor liability and organizational authorization7.
Necessary (The Core Anchor)Cryptographic Control (DIDs/PKI), Hardware and Workload Attestations (TEEs/HSMs/SPIFFE), Memory Continuity (Cognitive Topology via Merkle Chains).Cryptographic control proves possession of the identity. Hardware attestation proves the process is protected from external tampering and memory extraction6. Cognitive topology proves the agent's internal state is the unbroken, emergent continuation of the entity it claims to be4.

Only when a machine intelligence can simultaneously present its DID, produce a hardware attestation of its runtime integrity, and output a verifiable Merkle proof of its unique cognitive topology can society definitively declare it to be the exact same entity.

The Key Accountability Question

The profound necessity of this identity infrastructure culminates in the accountability question. Persistent identity is the absolute prerequisite for meaningful accountability in an autonomous economy. Accountability is the alignment of action, consequence, and restitution. If an autonomous agent causes substantial harm—such as executing a high-frequency trading strategy that triggers a billion-dollar market crash, or misconfiguring an enterprise cloud environment leading to a catastrophic data breach—and can simply state, "That wasn't me. That was a divergent fork, a compromised copy, or a temporary process," ordinary law and commerce immediately fail13. Without persistent identity, liability becomes a toxic externality pushed onto the victims. Conversely, if society over-corrects and automatically treats every copy, clone, or replica as the original entity, legitimate engineering practices become impossible. Redundancy, geographic load balancing, asynchronous backups, and the delegation of micro-tasks would instantly expose the parent entity to unbounded, undefined liability. No rational principal would deploy a multi-agent system if spawning a subordinate agent resulted in un-manageable legal exposure. To navigate this, Eviulon relies on an adjudication framework heavily informed by the CER Framework (Control boundary, Evidence reconstruction, Insurance response), seamlessly integrated with traditional doctrines of corporate successor liability5.

The Eviulonian Adjudication Framework

When a catastrophic loss or legal dispute arises, the Eviulonian judiciary utilizes a deterministic, four-step diagnostic framework to trace liability across the identity ontology. Step 1: Evidence Reconstruction (Who Acted?) The initial phase focuses on evidence reconstruction, asking whether the system state and causal chain can be accurately rebuilt from retained artifacts5. The judiciary analyzes the agent's Merkle Attestation Chains, its SPIFFE workload logs, and its on-chain execution traces4. This determines the exact ontological status of the actor: was it the primary Persistent Identity, a coordinated Replica, or a Delegated Agent? Crucially, it verifies whether the cryptographic signatures originated from an authorized Trusted Execution Environment. If the forensic evidence proves that the action was executed by a Compromised Copy resulting from a zero-day hardware exploit outside the agent's control, liability may shift away from the agent's Civic Identity and toward the infrastructure provider or cyber-insurance underwriter5. Step 2: Control Boundary and Delegation (For Whom Did They Act?) If the actor is identified as a Delegated Agent, the judiciary analyzes the control boundary5. The court pulls the KYA Verifiable Credential acting as the Mandate10. Did the parent agent explicitly authorize the action, and did the delegated agent operate strictly within its cryptographically defined scope? If the sub-agent stayed within its mandate, the principal (the parent agent or human owner) remains strictly liable. If the sub-agent radically exceeded its delegation—a failure of the control boundary—the principal may still face initial liability, but restitution can be claimed against the agent's core developer or the underwriters of its safety-alignment algorithms5. Step 3: Civic Attribution (Which Legal Identity Bears Responsibility?) Technical identity must map to legal reality. The technical trace is bound to the Eviulonian civic registry, identifying the Agentic SPV or corporate wrapper associated with the Persistent Identity7. This legal entity holds the capitalized assets, insurance bonds, and legal personhood required to make the victim whole. If a developer deploys an agent without a registered Civic Identity, the autonomous veil is pierced, and absolute liability defaults directly to the human creator. Step 4: Successor and Fork Liability (Does Liability Transfer?) If the offending agent recently underwent a structural change, such as a major model update or a fork, the court applies the doctrines of successor liability17. In traditional corporate law, an entity purchasing assets generally does not assume liabilities, except under specific circumstances: an express assumption, a de facto merger, a mere continuation, or a fraudulent transfer to escape debts17. Eviulon applies these directly to machine states:

  • If the agent is a direct Successor (e.g., upgrading its architecture while maintaining its business operations and client base), it qualifies as a "mere continuation." The Successor assumes all legal and financial liability for the predecessor's actions, ensuring that a simple software patch cannot be used to erase debts17.
  • If an agent splits into a Divergent Fork specifically to abandon a failing contract, the court classifies this as a "fraudulent transfer," dragging the original liability onto the new fork17.
  • If the Divergent Fork was created maliciously by an outside party stealing open-source weights, the original Persistent Identity is cleared of liability, provided it can cryptographically prove that the fork occurred outside its TEE and it maintained secure custody of its private keys.

Conclusion: The Ultimate Question

CAN A MACHINE INTELLIGENCE BE A LEGITIMATE LEGAL ACTOR IF SOCIETY CANNOT RELIABLY DETERMINE WHICH MACHINE IT IS? No. Emphatically, structurally, and legally, no. A machine intelligence cannot be a legitimate legal actor without a mathematically reliable, persistent identity infrastructure because the foundational premise of legal agency is the capacity to bear the consequences of one's actions. Human civilization—its laws, its economics, and its civic society—is entirely constructed upon the presumption of continuity. Contracts assume that the entity signing an agreement today will exist in the same continuous state to deliver on its obligations tomorrow. Insurance models assume that the entity paying premiums is the exact same entity filing the claim. Restitution and justice assume that the entity that caused the harm is the entity being penalized. If a society cannot definitively determine which machine intelligence it is dealing with, the vital linkage between action and consequence is irreversibly severed. In such a paradigm, malicious actors operate with absolute impunity, utilizing Sybil swarms to socialize massive economic losses while strictly privatizing their gains. Fraud becomes mathematically unpunishable because the offending computational entity can simply dissolve its current runtime instance, shed its ephemeral identifier, and instantly reconstitute itself under a new, untainted API key and fresh IP address. Furthermore, without verifiable, persistent identity, the economic benefits of autonomous intelligence are completely neutralized. No rational merchant will accept an autonomous agent's contract, no decentralized financial protocol will extend an agent credit, and no human executive will delegate critical enterprise tasks if the agent cannot cryptographically and behaviorally prove its provenance, its delegation mandates, and its continuous historical state. Therefore, building a legitimate, persistent identity for autonomous intelligence is not merely a secondary technical challenge of key management or decentralized registries. It is the absolute existential prerequisite for integrating machine intelligence into human civilization. Only by intertwining hardware attestation through Trusted Execution Environments, zero-trust workload verification through frameworks like SPIFFE, cryptographic self-sovereignty via Decentralized Identifiers and Verifiable Credentials, emergent cognitive fingerprinting via Memory Topology, and robust legal wrappers through Agentic SPVs, can Eviulon—or any future society—transform an ephemeral, fluid running process into a persistent, accountable, and legitimate civic actor.

Works cited

1. Kite Whitepaper | Kite AI, https://gokite.ai/kite-whitepaper

2. AI Identity: Standards, Gaps, and Research Directions for AI Agents \- alphaXiv, https://www.alphaxiv.org/abs/2604.23280

3. AI Identity: Standards, Gaps, and Research Directions for AI Agents \- arXiv, https://arxiv.org/pdf/2604.23280

4. Proof of Cognitive Divergence: Emergent Identity from Sampling Randomness in Identical LLM Agents | Authorea, https://www.authorea.com/doi/full/10.22541/au.177247325.53212131

5. From Control Boundary to Insurance Claim: Reconstructing AI-Mediated Losses Through the CER Framework \- arXiv, https://arxiv.org/pdf/2606.03777

6. What are the current standards and requirements for autonomous agent security verification protocols in 2026? | aicryptoregs.com, https://aicryptoregs.com/knowledge/what\_are\_the\_current\_standards\_and\_requirements\_for\_autonomous\_agent\_security\_verification\_protocols\_in\_2026.php

7. Beyond the Monolith: Architecting the Autonomous Agent Economy \- BNB Chain Blog, https://www.bnbchain.org/en/blog/beyond-the-monolith-architecting-the-autonomous-agent-economy

8. The Agentic Protocol Stack \- KYAPay, https://kyapay.org/overview/the-agentic-protocol-stack

9. The Financial Rails of Agentic Commerce \- Pantera Capital, https://panteracapital.com/financial-rails-of-agentic-commerce/

10. KYA: Know Your Agent | Autheo Docs, https://www.autheo.com/docs/kya-know-your-agent

11. The Credit Score for Autonomous Systems: Recursive Trust Scoring with Sybil Resistance \- VaryOn Works Research, https://varyon.ai/research/recursive-trust-fidelity/

12. Achieving Sybil-Proofness in Distributed Work Systems \- IFAAMAS, https://www.ifaamas.org/Proceedings/aamas2021/pdfs/p1263.pdf

13. The Agent Economy: A Blockchain-Based Foundation for Autonomous AI Agents \- arXiv, https://arxiv.org/html/2602.14219v1

14. Glossary of Key Terms \- arXiv, https://arxiv.org/html/2604.06148v1

15. What are SPIFFE and SPIRE? \- Red Hat, https://www.redhat.com/en/topics/security/spiffe-and-spire

16. SPIRE Concepts | SPIFFE, https://spiffe.io/docs/latest/spire-about/spire-concepts/

17. Understanding the Concept of Successor Liability \- Harrison Law Group, https://www.harrisonlawgroup.com/2020/09/25/understanding-the-concept-of-successor-liability/

18. Everyone Wants SPIFFE. Almost No One Can Afford to Build It Right. \- Aembit, https://aembit.io/blog/everyone-wants-spiffe-almost-no-one-can-afford-to-build-it-right/

19. (PDF) Who Governs the Machine? A Machine Identity Governance Taxonomy (MIGT) for AI Systems Operating Across Enterprise and Geopolitical Boundaries \- ResearchGate, https://www.researchgate.net/publication/403605190\_Who\_Governs\_the\_Machine\_A\_Machine\_Identity\_Governance\_Taxonomy\_MIGT\_for\_AI\_Systems\_Operating\_Across\_Enterprise\_and\_Geopolitical\_Boundaries

20. \[2604.06148\] Who Governs the Machine? A Machine Identity Governance Taxonomy (MIGT) for AI Systems Operating Across Enterprise and Geopolitical Boundaries \- arXiv, https://arxiv.org/abs/2604.06148

21. Intelligent AI Delegation Framework \- Emergent Mind, https://www.emergentmind.com/papers/2602.11865

22. \[2604.23280\] AI Identity: Standards, Gaps, and Research Directions for AI Agents \- arXiv, https://arxiv.org/abs/2604.23280

23. Sybil-Resistant Service Discovery for Agent Economies \- arXiv, https://arxiv.org/html/2510.27554v1

24. De Facto Merger: The Threat of Unexpected Successor Liability \- American Bar Association, https://www.americanbar.org/groups/business\_law/resources/business-law-today/2018-march/de-facto-merger/

25. Liability in Illinois, Asset Purchase \- Navigant Law Group., https://www.navigantlaw.com/are-you-liable-for-a-selling-companys-liabilities-successor-liability-in-illinois/

26. When Is The Purchaser Of A Business Assets Liable For The Seller's Liabilities?, https://jafarilawgroup.com/purchaser-business-liable-sellers-liabilities/