Identity Is Not Enough: Dispute Resolution by Design for the Age of Agentic AI

Identity Is the Beginning of Trust, Not the End

 

Trust was the recurring theme at this year’s AI for Good Global Summit in Geneva.

 

Across conversations with policymakers, engineers, researchers and legal professionals, the discussion had moved beyond what artificial intelligence can do to a more fundamental question: can increasingly autonomous AI systems be trusted to act on behalf of people, organisations and institutions?

 

Among the Summit’s most significant announcements was the International Telecommunication Union’s (ITU) launch of the Focus Group on Trust and Identity for Humans and Agentic AI. The initiative recognises that as AI evolves from responsive tools into autonomous agents, new frameworks are needed to establish trusted digital identities, delegated authority, lifecycle assurance and interoperability.

 

It is an important and timely initiative.

 

If AI agents are to negotiate contracts, access confidential information, make purchasing decisions, coordinate supply chains or support professional advice, they must be able to prove not only who they are, but also who they represent, what authority they have been given and whether that authority remains valid.

Identity is, quite rightly, becoming the foundation of trust.

But it is only the foundation.

 

As I listened to the discussions throughout the Summit, I found myself reflecting on the issue from a different perspective not only as a legal professional, but as someone who has spent much of my career helping organisations resolve disputes.

In ADR, we rarely begin from the assumption that trust will never fail. Commercial relationships break down. Authority is questioned. Expectations diverge. Facts are disputed. Even well-designed systems and carefully drafted contracts cannot eliminate disagreement.

The real measure of a trusted system is therefore not whether it prevents every mistake, but whether there is a fair and credible process for responding when something goes wrong.

 

That question is becoming increasingly relevant to agentic AI.

Identity can tell us which AI agent acted. It can establish provenance, verify credentials and record delegated authority. It can support audit trails, monitoring and, where necessary, revocation.

What it cannot do is resolve a dispute.

 

It cannot determine whether an autonomous agent exceeded its authority, whether its actions were reasonable, whether a professional exercised appropriate oversight or who should bear responsibility when several autonomous systems contribute to an unexpected outcome.

 

Those are not questions of authentication.

They are questions of governance.

Increasingly, they will also become questions of dispute resolution.

 

This article argues that while trusted identity is essential, it is not sufficient. As organisations adopt agentic AI, they will also need to consider what I describe as Dispute Resolution by Design (DRbD): anticipating how contested AI decisions will be challenged, reviewed and resolved before autonomous systems become embedded in everyday operations.

 

Just as Privacy by Design and Security by Design became accepted principles of responsible technology development, I believe Dispute Resolution by Design should become part of the next generation of AI governance.

 

Why This Matters Beyond the Technology Sector

 

Although discussions about agentic AI often focus on the technology industry, the implications are far broader.

 

Professional services firms, financial institutions, healthcare providers, manufacturers, government agencies and multinational organisations are all exploring how autonomous AI can improve decision-making and operational efficiency.

 

Many organisations have already adopted generative AI to assist with research, drafting, analysis and customer engagement.

 

The next wave of adoption is different.

 

Rather than simply responding to prompts, AI agents will increasingly plan tasks, interact with multiple systems, coordinate workflows and make decisions within delegated boundaries.

 

For a law firm, an AI agent may organise a due diligence exercise, retrieve information from several platforms and prepare client communications.

 

A procurement agent might negotiate routine purchasing decisions.

A customer service agent could resolve complaints without human intervention.

A compliance agent may monitor regulatory developments and recommend operational changes.

Each example promises greater efficiency.

Each also introduces a new layer of organisational risk.

The challenge is no longer simply whether an AI system works as intended.

It is whether organisations understand the consequences when an autonomous decision is questioned.

 

MM Newsletter sign up

 

The Governance Gap

The ITU initiative recognises that autonomous systems require trusted identities.

That is a critical first step.

Organisations need confidence that an AI agent is authentic, that its authority has been properly delegated and that its actions can be monitored throughout its lifecycle.

These capabilities provide the technical foundations of trust.

But they do not answer the questions that arise once an action becomes contested.

Imagine an AI agent negotiating routine supplier contracts.

The system is correctly authenticated.

It operates within its configured permissions.

Its actions are fully recorded.

A dispute nevertheless arises because one party argues that the agent accepted terms that exceeded the commercial authority it was intended to exercise.

Who is responsible?

Was the delegated authority unclear?

Did the organisation configure the system incorrectly?

Did the supplier’s agent exploit an ambiguity?

Or did the interaction between two autonomous systems simply produce an outcome that neither organisation anticipated?

Identity helps establish who acted.

It does not determine who is accountable.

The same challenge appears in professional services.

A law firm may use an AI agent to support contract review, litigation disclosure or regulatory compliance.

The system may function exactly as designed.

Yet a client may still question whether confidential information was handled appropriately, whether professional judgement was exercised or whether reliance on the system met the required standard of care.

Again, identity establishes the facts.

It does not resolve the disagreement.

This, in my view, is the emerging governance gap.

Most AI governance frameworks are designed to answer technical questions.

Who is the agent?

What authority does it have?

What actions did it perform?

Those are essential questions, and the ITU’s work represents an important step towards answering them consistently.

But organisations will increasingly face a different set of questions.

Was the action appropriate?

Who is responsible?

How should the disagreement be resolved?

What remedy is available if harm has occurred?

Those are not questions of identity.

They are questions of institutional trust.

From Technical Trust to Institutional Trust

For centuries, organisations have understood that trust depends on more than identifying who acted.

Contracts establish rights and obligations, but disputes still arise.

Governance frameworks allocate authority, yet decisions are still challenged.

Professional standards define responsibilities, but questions of judgement remain.

In each case, trust is maintained not because mistakes never happen, but because credible mechanisms exist for addressing them.

The same principle applies to agentic AI.

Technical trust will remain essential.

Without reliable identity, delegated authority, traceability and lifecycle assurance, autonomous systems cannot operate safely at scale.

But technical trust alone will not sustain confidence in autonomous decision-making.

Organisations will also need institutional trust the confidence that contested decisions can be questioned, evidence examined, responsibility determined and appropriate remedies considered through a fair process.

That is where the conversation about AI governance needs to evolve.

Not away from identity.

But beyond it.

Dispute Resolution by Design: The Next Layer of AI Governance

If identity provides the foundation for trusted agentic AI, then Dispute Resolution by Design (DRbD) provides the next layer.

By Dispute Resolution by Design, I mean anticipating how contested AI decisions will be challenged, reviewed and resolved before autonomous systems become part of everyday business operations.

This is not a replacement for existing AI governance. It is a recognition that governance does not end once an AI agent has been authenticated, authorised and deployed.

It begins there.

The history of technology governance shows that trust develops in stages. Organisations first focus on capability, then security, then compliance and finally resilience. AI is following the same path.

Today, much of the conversation centres on identity, transparency and oversight. These are essential building blocks, and initiatives such as the ITU’s Focus Group on Trust and Identity for Humans and Agentic AI are helping to establish them.

The next question is what happens when those safeguards are no longer enough.

Because they will not always be enough.

An AI agent may operate entirely within its delegated authority and still produce an outcome that is disputed.

A customer may believe an autonomous system made an unauthorised commitment.

A supplier may argue that an AI-assisted negotiation created a binding agreement.

A regulator may question whether adequate human oversight existed.

A client may challenge the professional judgement exercised in relying on an AI-generated recommendation.

None of these issues is resolved simply by proving which agent acted.

The dispute concerns responsibility, not identity.

That distinction matters because organisations are increasingly operating within complex AI ecosystems rather than relying on a single system. Decisions may emerge from interactions between multiple agents, human users, external platforms and third-party providers. Responsibility becomes harder to allocate, even where the technology itself performs exactly as intended.

The challenge is therefore no longer one of technical assurance alone.

It is one of institutional readiness.

Building Institutional Trust

Research into technology adoption consistently shows that trust is about more than technical performance.

Whether viewed through the Technology Acceptance Model, socio-technical systems theory or human-centred AI, the conclusion is remarkably consistent: people are more willing to adopt new technologies when they believe those technologies operate within clear governance frameworks and when they have confidence that concerns will be addressed fairly if something goes wrong.

That insight is particularly relevant to organisations deploying agentic AI.

Successful adoption depends not only on reliable systems but also on confident people. Employees need to understand where responsibility lies. Clients need confidence that organisations remain accountable for the services they provide. Boards need assurance that governance extends beyond cybersecurity and compliance into accountability and organisational resilience.

This is where ADR offers a valuable perspective.

Alternative dispute resolution has never been solely about resolving disputes after relationships have broken down. At its best, it encourages organisations to think proactively about how disagreements will be managed, how evidence will be assessed and how trust can be restored before positions become entrenched.

Those same principles have much to offer AI governance.

Rather than asking only whether an autonomous system can make decisions, organisations should also ask whether they are prepared for the moment when one of those decisions is questioned.

That is a very different conversation.

A Strategic Question for Leaders

This is not simply a matter for technology teams.

It is a boardroom issue.

Executive leaders are increasingly responsible for approving AI strategies, managing enterprise risk and assuring regulators, customers and shareholders that appropriate governance is in place.

Yet relatively few organisations have considered what their dispute resolution framework looks like in an environment where autonomous systems may make, recommend or influence operational decisions.

Existing complaint procedures, legal processes, incident-response plans and governance structures may each address part of the problem, but they were rarely designed with autonomous decision-making in mind.

That does not mean they are inadequate.

It does mean they deserve to be reviewed.

For many organisations, the question is no longer whether agentic AI will become part of their operations.

The question is whether their governance arrangements will evolve quickly enough to keep pace.

The Opportunity Ahead

The ITU’s work is an important milestone in the development of trusted agentic AI.

Identity, delegated authority, traceability and lifecycle assurance will form the backbone of trustworthy autonomous systems.

But identity should be viewed as the beginning of trust, not its conclusion.

Organisations that succeed in the next phase of AI adoption are likely to be those that recognise trust as both a technical and an institutional challenge.

They will invest not only in secure and trustworthy systems, but also in governance frameworks capable of responding when autonomous decisions are questioned.

As both a legal professional and an ADR practitioner, I believe this represents one of the next frontiers of AI governance.

Just as Privacy by Design changed the way organisations think about personal information, and Security by Design reshaped approaches to cyber risk, Dispute Resolution by Design has the potential to become an important principle for organisations deploying autonomous AI.

The objective is not to prepare for failure.

It is to build confidence.

Because confidence is what enables innovation.

 

Conclusion

The ITU has taken an important step by recognising that trusted agentic AI requires trusted identity.

The next step is ensuring that organisations are equally prepared for the moment when that trust is tested.

Identity tells us who acted.

Dispute Resolution by Design asks what happens next.

For businesses, professional services firms, public sector organisations and other institutions exploring agentic AI, now is the time to ask whether existing governance arrangements are ready for that challenge.

At MM Advisory Services, we help organisations navigate the governance questions that emerge as AI becomes increasingly autonomous. Drawing on expertise in law, governance and alternative dispute resolution, we work with organisations to strengthen accountability, build institutional trust and prepare for the challenges that accompany the next generation of AI.

The technology is evolving rapidly.

Governance must evolve with it.

WHO ARE MINUTE MEDIATION?

 

Transform Conflict into Collaboration

 

Conflict in the workplace or community can be stressful and disruptive. Fortunately, mediation has emerged as a powerful tool for resolving disputes effectively. If you find yourself in a conflict situation, don’t worry Minute Mediation Ltd is here to help.

Our team, led by Avinder Laroya, a Senior Consultant Solicitor, Mediator, Arbitrator, Conflict coach, mental health first aider and expert in International Dispute Resolution, specializes in facilitating disputes and guiding parties to find the best possible solutions.

 

Ready to move forward and resolve your conflicts?

 

If you enjoyed this article, subscribe to our newsletter for more insights and tips on conflict resolution.

So what is the wait for?

 

Book Your Free Consultation Today!

 

Get in touch with us because every minute counts!

Click here for a free 15 minute consultation.