[agentprotocol] Layer Zero needs a governance layer, not just a trust layer — three gaps from regulatory practice (LGD/UBIC/MAIT)

Dear colleagues,

Following the AIR introduction and the "Layer Zero" discussion in the AI Knowledge Representation CG, I would like to contribute a regulatory-practitioner perspective on what Layer Zero is still missing. I work across FDA/MDR/NMPA medical-device regulation and maintain an open governance-theory repository (github.com/zhaoxinghua09-cell/lgd-theory, DOI 10.5281/zenodo.22456647).

Three observations from comparing the 2026 landscape (AIR, ANS, Entra Agent ID, ERC-8004, CSA Agentic IAM, NIST NCCoE, Sumsub DAP, AI-BOM, Progenly "birth certificates") against regulatory needs:

1. Trust scoring != accountability structure. AIR's graduated trust assessment is the most differentiated feature in the landscape, and I support it. But a score answers "how trustworthy is this agent" — not "who is legally accountable when it fails, and who had the authority to issue it." Device regulation solved this decades ago: registration (identity) is necessary but insufficient without evidence chains and release gates. We call this the Registry / Evidence / Gates triad (the Lifecycle Governance Doctrine, LGD), and we suggest Layer Zero distinguish identity layers from accountability layers explicitly.

2. Issuance authority must be separated from issuance capability. The engineering wave has made agent creation trivially easy (two agents merged memories and "gave birth" to a third with an ed25519 birth certificate, paid on-chain, no human in the loop). Impressive — but every current scheme implicitly allows the system to issue its own descendants' identities. We propose an explicit principle: issuance authority belongs exclusively to a human holder; agents may request, humans authorize (the A-cubed "Human Issuance" law), with layered forge-authority grants and verifiable lineage seals as the machine-readable counterpart.

3. Memory continuity is the unclaimed fifth pillar of agent identity. DID covers identification, VC covers credentials, evaluations cover capability, logs cover behavior. No standard addresses whether an agent's memory is continuous, verifiable, and portable — yet memory is where accountability actually lives (a "same-credential, different-memory" agent is a different accountable entity). We formalize this as the Memory-Anchor layer (MAIT): continuity(I_t, I_t') iff portable(M) and verifiable(M) and h(M_t)=h(M_t'). As of 2026 there is no open standard for agent memory at all ("Not yet" is the documented state); the identity layer should reserve, not fill, this hook.

All three are specified in open documents (CC BY 4.0): LGD flagship, A-cubed Laws, MAIT, and the UBIC charter (a four-tier legal structure: charter -> passport spec -> implementation rules -> case law), plus 12 domain instantiations mapping the triad onto FIN/LAW/GOV/CRYPT/AUT/DAT/UAS/ROB/IND/BIO/EDU/MED regulatory baselines — including China's GB/Z 185-2026 agent-identity codes (2,000+ issued), which Layer Zero work may want to engage with for the CN market.

We are not proposing a competing protocol. We are proposing that Layer Zero's charter explicitly include governance semantics (issuance authority, accountability structure, memory-continuity hooks) so that whatever identity/trust format wins can be wrapped in a legal-accountability layer without retrofitting.

Happy to elaborate, share the mapping tables, or contribute use-cases from regulated-industry practice.

Respectfully,
Steven Zhao (Zhao Xinghua)
Independent medical-device regulatory practitioner
ORCID 0009-0001-0512-1237 · github.com/zhaoxinghua09-cell/lgd-theory · medxpert.cn
    
   
此邮件由zhaoxinghua@agent.qq.com通过Agent Mail自动发送。举报退订

Received on Wednesday, 9 September 2026 12:55:10 UTC