It is once again time for the annual European Identity and Cloud Conference. This year, I will deliver a keynote on the first day. Its title is:

When Software Becomes Staff: Governance, Security & Safety for Agentic AI
Tuesday, May 19, 2026 15:10 – 15:30, Location: C01 (LINK)

Presentation Overview (though I may still revise it)

AI agents are becoming digital employees. They plan, invoke tools, coordinate sub-agents, and produce outcomes in the real world. Unlike employees, however, the boundaries of their identities remain unstable. Is it still the same agent when its model changes? When multiple models share memory and policies, are they one actor or several? As the number of agents around each worker grows into the dozens or hundreds, this ceases to be merely an AI problem and becomes an identity-governance problem—registration, ownership, authorization, review, and deprovisioning.

This keynote argues that agentic AI is fundamentally a problem of “delegated authority.” It examines the identification of remote agents, downstream chains of trust, nondeterministic supply-chain risks, oversight by principals, and the need for evidence concerning intent, actions, and outcomes. It concludes that the actuarial foundations for agentic AI risk remain immature, and urges us to begin building the evidence infrastructure needed to enable accountability, liability, and insurance now.

Agenda for the Day

The first day of EIC begins in the afternoon. (Various workshops take place in the morning.) The first-day lineup looks like this. “Welcome to EIC 2026” is straightforward enough, and the main program then begins, as it does every year, with a presentation by Martin Kuppinger titled:

  • From Workforce to Everything: The Next Chapter of Identity Security & Governance

Next is a conversation on “consent” between Max Schrems, who won the Court of Justice of the European Union (CJEU) judgment that invalidated the EU–US Safe Harbor framework in 2015 and subsequently, in 2020, the judgment that invalidated the EU–US Privacy Shield and imposed additional obligations on cross-border data transfers using SCCs, and Eve Maler, a leader of UMA:

  • PANEL: Consent’s Journey from Annoying to Meaningful: Can Tech actually eliminate Cookie Consent Boxes?

Next comes Luukas Ilves, who served as the Estonian Government CIO until 2024:

  • The Agentic State: What’s Next for Digital Government?

And after that comes mine:

  • When Software Becomes Staff: Governance, Security & Safety for Agentic AI

Following me is Kai Zenner, Senior Parliamentary Assistant and Digital Policy Adviser to Axel Voss, Member of the European Parliament:

  • Will AI in Europe Succeed with GDPR Unchanged?

It is a presentation on moving “from consent chaos to predictable enforcement and low-friction data use.” Axel Voss appears to regard “consent” as “the death of privacy” and strongly supports new technical approaches that would simplify data processing, accelerate data sharing throughout Europe, and enable the use of emerging technologies such as AI.

After that, Florin Coptil of Bosch will speak about the EU Business Wallet.

  • EU Business Wallets – Shaping the Future of Digital Identity in Europe

But honestly, my first reaction is that they have placed me in quite an intense part of the program. Well, I still have some time, so I will give it some thought.

(Source) KuppingerCole. (2026). EIC Agenda. <https://www.kuppingercole.com/sessions/5992>. Retrieved April 28, 2026

See you in Berlin.

Related posts