Sovereign Agents
Keywords: agent sovereignty · digital identity wallet · selective disclosure · eIDAS 2.0 · zero-knowledge proofs · AI agents · data ownership · exit rights
Two years from now, the most important software you run will not be an app. It will be an agent. It will book, negotiate, apply, comply, and pay on your behalf, and it will do all of it through conversations with other agents: the bank’s, the employer’s, the hospital’s, the government’s.
Which raises a question nobody is asking loudly enough yet, because the agents have not arrived at scale. When your agent sits down to negotiate with the bank’s agent, who does it work for?
Not who pays for it. That is easy. The real question has three layers. Whose intelligence does it run on? Whose credentials does it carry? And whose instructions does it follow when the two sides disagree?
Ask those three questions about the average European in 2026 and the honest answer is: the model is American, the identity is whichever login the counter demands, and the instructions are whatever the service’s terms of service say the agent may do. Three for three, and none of them are yours.
That is what I mean by sovereign agents. Not sovereignty as a flag on a data center. Sovereignty as agency that survives contact with a counter. This essay is the map of the three layers, what Europe already has, what it is missing, and the audit that tells you where you actually stand.
Renting intelligence becomes renting agency
I have written before about what it looks like when a continent rents its intelligence: the scenario where the world pays rent on American models, and the rent flows home as a million dollars a year per American adult while everyone else is mailed a ration. I called it what the structure is, colonialism with a new resource, and the point was never the invented numbers. The point was the shape: one owner, four billion tenants, and a payment calibrated to keep the tenants quiet.
The agent era upgrades that shape in a way that should make the tenants pay attention. In the model era, you rented answers. In the agent era, you rent agency: the capacity to act in the digital world at all. The company town did not just own the store. It owned the means of getting to the store.

Follow the same scenario one step further and you can see it. If your calendar, payments, applications, and compliance all flow through an agent, and that agent runs on the owner’s model under the owner’s policies, then the owner does not need to censor you. It can simply reprice you, or throttle you, or decide that your agent may not perform certain classes of negotiation. The hand on the switch moves from what the machine says to what the machine may do on your behalf.
In the model era, renting intelligence meant renting answers. In the agent era, it means renting your own agency.
This is why the sovereignty question gets more urgent, not less, as models get cheaper. Cheap models are not independence. They are a lower rental rate.
The three layers
Here is the whole framework. Sovereignty in the agent era is a compound of three owned layers, and the compound only works when all three hold.
Layer one: the intelligence. The model your agent runs on. Sovereignty here does not mean a frontier model built at home; that is the version of the argument that fails, because it fights the last war and loses to the scale of the winners. It means exit rights: the ability to move your workload to another provider or to your own hardware without losing the capability, and never depending on a single foreign switch. Redundancy across providers, open weights where the task allows, and honest awareness of which parts of your stack could be switched off by a government you did not vote for.
Layer two: the identity. The credentials your agent carries and the mechanism by which it discloses things about you. This is where the photocopy problem lives. An agent that negotiates by uploading documents is an agent that multiplies copies of your life across every counter it visits. The sovereign pattern is the opposite: signed credentials that answer questions without exposing sources, selective disclosure field by field, proofs instead of photocopies. The bank gets certainty. The originals stay home.
Layer three: the instructions. The policy your agent follows when interests conflict. Who wrote the rules it applies? When the bank’s agent pushes for more disclosure than a given task needs, does your agent hold the line because you wrote that line, or does it fold because the service wrote the default? This layer is the least discussed and the most decisive, because an agent with rented intelligence and borrowed rules is not your representative. It is the counter’s, wearing your face.
The three layers compound. Own the model but disclose through someone else’s identity system, and every negotiation still leaks through their lens. Own the credentials but run on a model whose instructions the provider controls, and your negotiating position is whatever the provider’s compliance team decided this quarter. Sovereignty is not a pie where one slice satisfies. It is a chain, and it fails at the first rented link.
📊 Process map: the agent-era stack, rented versus owned

The amber layer is the one nobody can rent to you. Instructions are written, not bought.
Own one layer and you are a customer. Own all three and you are a participant.
The wallet Europe already built
Now the part that surprises people: Europe is not empty-handed. It holds exactly one card that matters in this game, and it is not a frontier model.
The EU digital identity wallet. Mandated under eIDAS 2.0, it must be offered to every citizen by the end of 2026. On its face it is a document holder: your driving licence, your diploma, your bank identity, in one app. That reading undersells it badly. Built properly, it is a selective-disclosure machine at population scale: signed credentials that your software can present field by field, proving residency, age, income thresholds, or professional qualifications without surrendering the underlying documents.
Think about what the agent scene from that earlier blueprint needs. Your agent negotiating with a bank’s agent, answering questions without leaking data. The toolbox I described there, selective disclosure, zero-knowledge proofs, credentials instead of photocopies, is precisely what the wallet ships, except it is not a startup pitch when 450 million people get it by law. The regulation that banks spent years complaining about turns out to be the single strongest sovereign identity layer any bloc will have when agents arrive.
The bank gets certainty. The originals stay home.

Identity is also the layer where sovereignty is cheapest. Model sovereignty costs hundreds of billions; the gap is measured that way in Europe’s own diagnosis. Identity sovereignty is already funded, already mandated, already in the rollout. The wallet is the rare sovereign asset that arrives on schedule.
The missing piece is the wiring: nobody has yet connected the wallet to the agent protocols forming above it. MCP, Agent2Agent, the payment rails. The bloc that wires its identity layer into the agent layer first sets the default terms for everyone who follows, the same way the first country to standardize rail gauge quietly decided everyone else’s train geometry. Defaults are destiny, and the window for writing them is measured in months, not years.

📊 Process map: the photocopy problem versus selective disclosure

The wallet answers the bank’s questions without surrendering the documents. That is the mechanism agents need, at population scale.
What sovereignty does not mean
A blueprint without a failure list is a pitch. Here are the three ways this argument goes wrong, because it goes wrong often.
It does not mean closing the borders. The failure mode of every sovereignty argument is a slide into building everything at home, badly, at a price nobody pays. Exit rights are not autarky. Using an American model under European terms is fine; the sovereignty lives in the exit, not in the refusal. A tenant with a genuine walking-away option is a customer. A tenant without one is a subject, and the rent is whatever the landlord says it is this quarter.
It does not mean the state owns your agent. There is a version of this where sovereignty becomes a surveillance argument: a national agent infrastructure that knows everything your agent does, run by the same governments that built the databases Snowden taught us about. That inverts the entire point. The sovereignty that matters here runs bottom-up: your exit rights, your disclosure control, your instructions. A sovereign agent you cannot inspect is just a counter with a flag on it.
It does not mean the individual can do this alone. Left to the market, agent sovereignty will be purchased by corporations and forfeited by everyone else: enterprises negotiating exit clauses and disclosure limits, consumers accepting whatever defaults ship. The realistic path for individuals runs through institutions, employers, banks, professional bodies, writing sovereign defaults into the agents they provide, the way the wallet writes disclosure control into identity. Sovereignty of this kind is a purchase that only works at volume, which is exactly why the policy window matters more than the technology.
📊 Process map: the three failure modes and what sovereignty means instead

Every failure mode slides into one of these three ditches. The real thing sits between them: open but exitable, yours but inspectable, individual through institutions.
The audit, extended
In the essay on rented intelligence I proposed a ten-minute audit: list every AI model your organization runs on, flag the ones a foreign government could switch off, throttle, or reprice by decree, and read your unflagged remainder as your sovereign capability. For most European organizations that remainder was an empty column.
The agent era extends the audit by two rows.
List every agent that acts on your organization’s behalf: whose model it runs on, yes, but also whose instruction set governs it when interests conflict. And list every credential it discloses with: whether it presents proofs under your control or uploads documents into someone else’s drawer. Three columns now: intelligence, identity, instructions. Flag the rented links in each.
An agent with rented intelligence and borrowed rules is not your representative. It is the counter’s, wearing your face.
📊 Process map: the three-layer sovereignty audit

The audit is honest precisely because most columns come back flagged. The remainder is your real position, not the one in the strategy deck.
The result is your true sovereignty balance sheet, and for almost everyone it is worse than the strategy deck claims. That is fine. The deck is where the fixing starts.
Key takeaways
- The agent era converts rented intelligence into rented agency: whoever controls the model, the credentials, and the instructions controls what your agent may do on your behalf.
- Sovereignty is a compound of three owned layers: exit rights on the intelligence, disclosure control on the identity, and self-authored instructions on the interface. It fails at the first rented link.
- Europe’s real agent-era asset is the EU digital identity wallet: selective disclosure at population scale by law, arriving at the end of 2026, exactly when agents begin negotiating. The missing piece is wiring it into the agent protocols.
- Sovereignty does not mean autarky, state-owned agents, or going it alone: it means exit rights, inspection rights, and sovereign defaults purchased at institutional volume.
- The audit now has three columns: models, agents, credentials. Flag what a foreign government could switch off or reprice. The unflagged remainder is your sovereign core.
The agents are coming regardless. The only question the next two years will answer is whether they arrive as your representatives or as the counter’s, wearing your face.
Sovereign the model if you can. Sovereign the wallet while it ships. But write the instructions yourself.
That layer is the one you can start on tonight.
Related reading:
- Share the Answer, Not the Data: the disclosure design that makes layer two real, proofs instead of photocopies.
- Perspective AI: the marketplace architecture where none of the three layers has to be rented at all.
- The Internet of Agents: the infrastructure layer this sovereignty map sits on top of.
- $1M for Americans, $1,200 for You: the rental scenario that makes the stakes concrete.
- Europe Is Running on Rented Intelligence: the original audit this one extends.
Common Questions
- What is a sovereign agent?
- A sovereign agent is an AI agent whose three defining layers you control: the model it runs on (you can leave the provider without losing the capability), the credentials it discloses with (it answers questions about you without surrendering your documents), and the instruction set it follows (written by you or your institution, not by the service it negotiates with). Own one layer and you are a customer. Own all three and the agent works for you.
- How does the EU digital identity wallet relate to AI agents?
- The EU digital identity wallet, mandated under eIDAS 2.0, must be offered to every citizen by the end of 2026. It carries signed credentials that support selective disclosure: your agent can prove you are a resident, over eighteen, or above an income threshold without handing over the underlying documents. That is precisely the mechanism agents need to negotiate with banks and employers without leaking data. It is Europe's strongest agent-era asset.
- Does digital sovereignty mean building a European ChatGPT?
- No. That is the version of sovereignty that fails, because it fights the last war. Model sovereignty means exit rights: the ability to move your workload to another provider or your own hardware without losing capability, and never depending on a single foreign switch. Identity sovereignty (the wallet) and interface sovereignty (agents whose instructions you write) matter just as much and are cheaper to own.
- Why should a company care about agent sovereignty now?
- Because the default is being set right now, the same way the cloud default was set in the 2010s. When your customers' agents start negotiating with your systems, the terms of disclosure, identity, and instruction control will be baked into the first protocols that reach scale. The ten-minute audit is to list every agent and model your organization depends on, and flag the ones a foreign government could switch off, throttle, or reprice by decree.
- What is the difference between data ownership and agent sovereignty?
- Data ownership is about documents: who holds the copies. Agent sovereignty is about agency: whose interests your digital representative serves when it acts in the world. You can own every document and still have zero sovereignty if the agent negotiating on your behalf runs on rented intelligence, discloses through someone else's identity system, and follows instructions written by the counter.