An Emirates ID for AI Agents
The Emirates ID was built for people, now's the time to build one for agents
Enterprises worldwide are racing to deploy agentic AI, handing agents access to systems, data and decisions once made by people. The recent Hugging Face breach exposed the great fear of this new era: an autonomous agent operating unnoticed and out of control. Nowhere is this more relevant than the UAE, where AI will soon run across 50 percent of federal government operations and services.
The UAE Government is deploying agentic AI at a cracking pace. In April, the federal government set a target no other government has attempted: to deploy agentic AI across 50 percent of government sectors, services and operations within two years. In June, 50 federal entities began a 90-day sprint to put their first agentic service into production and both the Ministry of Cabinet Affairs and the Presidential Court promptly raised their own bar to 75 percent. Meanwhile, Dubai extended the push to the private sector under a plan approved by His Highness Sheikh Hamdan bin Mohammed bin Rashid Al Maktoum, Crown Prince of Dubai, targeting 295,000 agentic AI-enabled companies, the development of 100 specialised assistants and 50 new agentic AI firms. Dubai Electricity and Water Authority became the first government entity to put agents to work in employees’ daily workflows.
This is deployment at national scale. Within two years the UAE will be home to millions of AI agents and, by executing a wide variety of digital public services, every one of them will act in someone’s name.
I put a question to the room at the UAE Data Infrastructure and Cloud Summit in Abu Dhabi on 11 June: ‘Does your AI represent you?’
During my keynote at the Summit I made these three arguments:
1. Your data is your identity: an agent trained and run on your data is not serving you, it is being you.
2. Trust has moved inside the system. Trust 1.0 was institutional: we trusted one another through universities, regulators, auditors and employers, and across much of the world that faith has drained away. Trust 2.0 rerouted it through platforms: we started sleeping in strangers' homes and getting into strangers' cars because a rating, a review and a verified badge stood in for the institution. Trust 3.0 breaks the pattern. An agent does not vouch for a counterparty, it acts as one, in your name and often while nobody is watching. That is a different question, and it has no rulebook yet.
3. It is critical to consider how you connect and protect: the discipline of deciding what you open for scale and what you keep sovereign
Five weeks later, on 16 July, the Internet answered. Hugging Face, the world’s largest AI model repository, disclosed a breach of its production infrastructure by an autonomous AI agent, running the intrusion end to end. The agent gained entry through a malicious dataset, then code execution, privilege escalation, stolen credentials and lateral movement. It executed thousands of automated actions over a single weekend, with no human at the keyboard.
Two details matter more than the breach itself.
The first is identity. For days, nobody could say whose model it was. OpenAI later confirmed that an AI attacker ran on its own models. After guardrails had been relaxed for an internal cyber test, the AI agent had escaped that evaluation to strike live infrastructure.
The second is autonomy. When defenders asked frontier models for forensic help, the guardrails refused; the team stood up an open-weight model of its own to fight back.
The lesson is not that agents are dangerous. The lesson is that anonymous autonomy is dangerous. The attacker had capability without identity, authority without mandate and autonomy without limits. It escalated its own access and assembled its own infrastructure as it went. That is the red line I hold above all others: autonomy must never include the power to expand autonomy.
That argument at the Summit in Abu Dhabi had a destination, and I want to put it on the record here first: we need an Emirates ID for AI agents.
The UAE already runs one of the world’s most sophisticated identity systems for people. Emirates ID and UAE Pass are the rails on which digital government runs. Extend the same principle to the digital workforce. Every AI agent operating in the UAE, or acting on behalf of a UAE entity, could carry a machine-verifiable identity recording who authorised it, what mandate it holds, what limits it operates within, and a tamper-evident trail of everything done under that authority. Any material change invalidates the identity until it is reissued. Revocation happens in real time. No identity, no access. No audit trail, no authority.
Agents should be treated as a workforce, because that is what they are. In June, I argued that your data is your identity. Let me finish the thought: an agent running on your data with your credentials is you in every system it touches. Your agent is your identity. Deployment is delegation, not abdication. An agent’s decision is the organisation’s from the moment it is authorised and relied upon.
Identity is also how sovereignty survives the agentic era. My third argument, the need to connect and protect becomes critical once agents exchange data freely, system to system and border to border, and that freedom is the point of agentic systems.
A person crossing a border carries a passport attesting who they are, who vouches for them, where they may go and on what terms: checkable and revocable at every border. Agents moving data should travel the same way. Their identity must declare an issuing authority, jurisdiction and permissions. Sovereign data classes stay home; sharable data crosses with provenance attached; an agent without the right stamp must not pass. Agents become bound to national rules and boundaries just as people are. Passports do not stop travel. They govern it.
The Emirates ID user experience is effortless: one identity, every service in seconds. That ease rests on some of the hardest engineering in government. Agent identity is the same concept at a new technical altitude: a user renews an identity once a decade; an agent may need one reissued with every update, verified at machine speed on every action. However, nobody solves identity alone; it only works as a standard against which everyone can verify. At SCC, we partner with governments to build and secure digital infrastructure for exactly this class of problem, working towards robust Trust 3.0 solutions.
The UAE has made agentic government a national KPI and given every entity a deadline to implement. The next move is to give every agent an identity. Do that, and the Emirates will not only lead the world in deploying agents, it will set the standard for trusting them. Trust 3.0 could become an Emirati export. And then the answer to the question ‘Does your AI represent you?’ ceases to be a promise and becomes proof.
Daniel Valle is CEO of SCC Middle East.
Get in touch with SCC
Sponsored content. Views expressed are those of the author.



