Why

Data sovereignty

Data spaces

International standards

We

Become a member

Members

Donate

Board

Head Office

IDSA ambassadors

Contact

Make

Working groups

Task forces

Hubs & competence centers

Open source

Projects

Communities

Offers

Reference Architecture

Dataspace Protocol

IDSA Rulebook

Certification

Data Space Connector Report

Use

Data Space User Group

Data Spaces Radar

Professional qualifications

Training catalog

Knowledge Base

Publications

Most important documents

Papers

Magazine

Legacy

Events

Upcoming events

Calendar

Archive

Event support

News

Blog

Newsroom

Infohub

Newsletter

July 23, 2026

Autonomous AI agents acting safely within governed data-sharing environments

The term "agentic AI" refers to software-based actors that can pursue a goal within defined boundaries, select actions, use tools and interact with services, including data catalogues and negotiation interfaces, without step-by-step human instruction. In a data space, such an agent can do what a human participant does: find data, negotiate access terms and consume assets. The difference is speed and continuity.
Anil Turkmayali

This is the frontier explored in IDSA’s position paper Data Spaces and AI: Trustworthy Agentic Participation in Data Spaces. The paper’s central argument is that agentic participation can be made trustworthy without building new and untested infrastructure. The mechanisms already exist. What is needed is to apply them to agents explicitly and consistently. 

The governance challenge agentic AI creates 

Traditional access control was built for human users and fixed service accounts. It does not capture an autonomous agent whose model, tools and purpose can change between sessions. Agentic participation creates six distinct pressures on data space governance: speed (agents issue far more requests than humans and act without manual approval), ambiguity (natural-language instructions can be underspecified), composability (a permitted first step can lead to an impermissible later one), malleability (behavior shifts with model updates or adversarial inputs), epistemic risk (agents can produce plausible but false outputs) and a widened attack surface (prompt injection, data exfiltration and agent impersonation all become possible when agents reach external systems). 

These six pressures share one root. Autonomous action that can cross organizational boundaries must stay bound to an accountable participant, an explicit purpose, a policy decision and an auditable record — even when the agent is fast, adaptive and only partly predictable. 

Delegated identity solves the attribution problem 

The paper’s solution is the Delegated Agent Participant ID: a Verifiable Credential that links an executing agent back to its legally liable organization. Before any data transaction begins, the data space Connector verifies six elements within it: the organization (as a cryptographically verified Decentralized Identifier of the legal entity), the agent instance (a transient runtime identifier for the specific session), the model powering the agent’s reasoning, the tool registry profile listing the external capabilities the agent may use, the purpose scope (a machine-readable declaration of intent that must align with the provider’s ODRL usage policies) and the assurance level (the agent’s trust tier backed by testing certificates or accreditations). 

This structure separates three identity layers that have different lifecycles and different accountability owners. The legal participant identity is static and permanently anchored to a corporate entity. The agent identity is transient, tied to a specific task and session. The tool and service identity is tied to version control and software development. Keeping these three layers distinct is what makes the whole system auditable. 

When an authorized agent tasks a secondary agent across organizational boundaries, the data space governs this through cascading delegation. The secondary agent inherits the boundaries of the primary agent’s credential — specifically its purpose scope and assurance level. Usage policies, sandboxing constraints and legal liability flow down the chain. No sub-agent can reach data or take actions the primary organization was not authorized to handle. 

Agent roles in practice 

The paper describes seven distinct agent roles that emerge in data space operation. A discovery agent continuously searches the catalogue for datasets and offerings that match a standing need. A data-gap analysis agent compares an organization’s requirements against what is available and identifies what is worth acquiring. A negotiation agent conducts the contracting process, proposing and counter-proposing usage policies, pricing and terms through the data space’s negotiation flow, with a human approving the final agreement. A cataloguing and curation agent enriches metadata and keeps the knowledge graph current. A conformity and compliance agent checks offerings and policies against verifiable credentials and the regulatory context. A provenance and observability agent reconstructs lineage and monitors usage. A matchmaking agent pairs supply and demand across the ecosystem. 

These roles compose in practice. A typical workflow chains them: a scout agent finds candidate partners, a gap-analysis agent confirms the data closes a real need, a conformity agent verifies the offering’s credentials and a negotiation agent settles terms. Each acts through standard data space interfaces under its delegated identity. 

Evidence from live pilots 

The paper documents pilots that show this working in practice. NEC and EverySense Japan demonstrated automated negotiation of data-trade terms, where two agents — one representing a data buyer, one a data seller — negotiated terms across three dimensions (data characteristics, sharing conditions and price) without human intervention, reaching agreement in around 80 seconds with approximately a 95% automated agreement rate. The terms negotiated by the agents are explicit and auditable; the conclusion of any legally binding contract remains with the participating parties. 

The RoX consortium, a German initiative for data-ecosystem infrastructure in AI-based robotics, uses data space technology as the foundation for sovereign exchange of machine, process and quality data across competing organizations. Its outlook is explicitly agentic: the same governed data supply that feeds robotic applications is intended to feed an agentic layer that automates and orchestrates tasks under the data space’s existing controls. 

The trust formula 

The paper proposes a trust formula as a practical design heuristic: the model may propose, the knowledge engine checks, the policy engine authorizes, the data space records and the human steward remains accountable. The formula is multiplicative. If any factor is absent, trust collapses. A fast AI system without policy is not trustworthy. A policy system without semantics cannot decide correctly. A knowledge base without verification can turn errors into executable rules. A data space provides the environment in which these factors can be assembled and enforced together. 

The path ahead 

The Dataspace Protocol (DSP) — currently undergoing international standardization as ISO/IEC DIS 26450 — separates the control plane (identity, access negotiation, policy decisions) from the data plane (where exchanges happen and where agent-specific protocols such as MCP and A2A can operate). Keeping the two separate is what allows agent tooling to evolve on the data plane without loosening the governance that holds on the control plane. 

Several items remain open. There is not yet an agreed specification for how agent delegation is declared, how a model and its tests are published as governed assets, or how cascading delegation is governed at scale across organizations. The paper’s task force is carrying this work forward, including into the IDSA Rulebook’s AI Agents chapter. An international testbed for data spaces and AI, positioned within the EU Data Union Strategy and Apply AI Strategy, is planned as the environment in which safety, compliance and cross-border interoperability are validated before capabilities reach production. 

The paper is available at Data Spaces and AI: Trustworthy Agentic Participation in Data Spaces. Organizations working on AI integration or data space adoption are invited to engage with the IDSA task force and contribute pilots, infrastructure and standards feedback through the community. 

Author: Anil Turkmayali
Anil Turkmayali is the editor of the IDSA position paper Data Spaces and AI: Trustworthy Agentic Participation in Data Spaces and a lead contributor to IDSA's AI and data spaces task force.

Stay updated with us