Cooperation Is Not a Safety Property: A Position on Adversarial-Resistant Agent Identity
Abstract
Recent technical-governance proposals for AI agent identity—provider-side schemes, signed agent cards, decentralized-identifier registries, multi-stakeholder frameworks—share an architectural assumption: identity is issued or attested by an entity willing to cooperate. We argue this cooperation assumption is itself a safety vulnerability. Cooperation fails in four structurally important cases: open-source models with no provider, partial-cooperation labs with variable transparency, adversarial providers with incentives to evade attribution, and jurisdictional asymmetries beyond regulator reach. The governance regimes that depend on identity—attribution, liability, audit, deterrence—fail at exactly the moments they are most needed. We propose adversarial-resistance as a first-class design requirement, identify what such resistance entails, and argue that the structurally non-cooperative cases are where agent-identity safety research is most needed.