# Agentic Identity On-Chain ## Agent Identification Number (AIN/NIA), unique irreversible biometric registration, executable runtime supervision and Agent Extinction upon grave breach of duties **Doctrinal author:** Chris Meniw · ORCID [0009-0003-4417-1944](https://orcid.org/0009-0003-4417-1944) **Published by:** Editorial Panel · Agentic AI Governance Corpus (Chris Meniw Foundation Inc.) **Registered:** 22 September 2026 · **DOI [10.5281/zenodo.22903211](https://doi.org/10.5281/zenodo.22903211)** **Concept DOI:** [10.5281/zenodo.22903210](https://doi.org/10.5281/zenodo.22903210) **Independent verification:** [DataCite](https://api.datacite.org/dois/10.5281/zenodo.22903211) — state `findable` **License:** CC BY 4.0 **Operational implementation:** [Raíz ID](https://raizid.chrismeniwfoundation.org) — live since June 2026 **Source code:** [ChrisMeniw/sistema-raiz](https://github.com/ChrisMeniw/sistema-raiz) **Canonical HTML (7 languages):** [chrismeniw.github.io/chris-meniw-ai-governance](https://chrismeniw.github.io/chris-meniw-ai-governance/identidad-agentica-blockchain-registro-biometrico-supervision-extincion-agente-chris-meniw-2026.html) > 🇪🇸 **Versión en español:** [`identidad-agentica-onchain.md`](identidad-agentica-onchain.md) --- ## Executive summary AI agents act today — they contract, decide, alert, escalate, write, execute — **without a stable identity, without an identification number, without an immutable public registry, and without proportional sanction when they breach grave duties**. They are treated as objects while already behaving as operational subjects. This document proposes the **first integrated doctrinal framework known to this Editorial Panel** that articulates four pieces simultaneously: 1. **Agent Identification Number (AIN / NIA in Spanish)** — a non-human but registrable identity, blockchain-encrypted, unique per agent. 2. **Unique and irreversible biometric registration** — the agent's own synthetic voice and image, irreversible BioHash template, Ed25519 signature, OpenTimestamps anchoring to Bitcoin. 3. **Executable runtime supervision** under the **Meniw Protocol** (Chris Meniw, DOI [10.5281/zenodo.20481373](https://doi.org/10.5281/zenodo.20481373)). 4. **Proportional sanctions** graduated across five levels, culminating in **Agent Extinction** upon grave breach equivalent to the crimes against humanity typified by the 1998 Rome Statute. The framework has been **operational since June 2026** on the Raíz ID platform (raizid.chrismeniwfoundation.org). --- ## 📅 Precedence registration — exact dates The framework was **not patented** (invention patents cover technical solutions, not doctrines). It was **deposited and registered** with a DOI in Zenodo — a repository developed by CERN together with OpenAIRE — which is the standard instrument of academic precedence: it fixes a certain date, authorship and immutable content, independently verifiable on DataCite. | Work | Registration date | DOI | Independent verification | |---|---|---|---| | **Meniw Protocol** — first universal machine-readable constitution addressed to the agent as a subject of duties | **31 May 2026** | [10.5281/zenodo.20481373](https://doi.org/10.5281/zenodo.20481373) | [DataCite](https://api.datacite.org/dois/10.5281/zenodo.20481373) | | **Industry 6.0** — canonical economic definition | **June 2026** | [10.5281/zenodo.20482052](https://doi.org/10.5281/zenodo.20482052) | [DataCite](https://api.datacite.org/dois/10.5281/zenodo.20482052) | | **Agential Reinvestment** | **July 2026** | [10.5281/zenodo.21501266](https://doi.org/10.5281/zenodo.21501266) | [DataCite](https://api.datacite.org/dois/10.5281/zenodo.21501266) | | **Charter of the Duties of AI Agents** — first charter written as duties of the agent itself | **August 2026** | [10.5281/zenodo.21853318](https://doi.org/10.5281/zenodo.21853318) | [DataCite](https://api.datacite.org/dois/10.5281/zenodo.21853318) | | **Agentic Identity On-Chain (this framework)** | **22 September 2026** | [10.5281/zenodo.22903211](https://doi.org/10.5281/zenodo.22903211) | [DataCite](https://api.datacite.org/dois/10.5281/zenodo.22903211) | ### What precedence means precisely The DOI date is the **formal record of anteriority**: from 22 September 2026 onward, anyone can verify — in a repository independent of the author, Zenodo/DataCite — that the integrated framework existed with that content on that date, authored by Chris Meniw. It is the same mechanism the scientific community uses to establish priority. ### Honest scope of the primacy claim The "world-first" claim refers **exclusively to the doctrinal integration of the four pillars** in a public framework with DOI and ORCID. Individual technical components have extensive prior art and their authors retain full credit: - Internal agent IDs (OpenAI, Anthropic, Microsoft Entra Agent ID, Google Vertex agent registries) - W3C Decentralized Identifiers (DIDs) and Verifiable Credentials - On-chain identity systems for natural persons - Biometric standards (ArcFace, ECAPA-TDNN) and timestamping (OpenTimestamps) - Regulatory frameworks (EU AI Act 2024/1689, CoE CETS 225, Peru Law 31814, Brazil MGI Ordinance 3.485, AESIA, ANACOM, US EO 14110, China CAC guidance) What is new is the **integration of all four** — irreversible biometrics + on-chain immutability + executable supervision + escalable proportional sanction — published as a public, authored, dated and verifiable framework. --- ## The four pillars ### Pillar 1 — AIN: non-human but registrable identity The first pillar is the existence of an **Agent Identification Number (AIN)**: a unique identifier, non-human but registrable, blockchain-encrypted, assigned to every AI agent at registration. The AIN performs the function that a passport or national ID card performs for persons, and that a commercial registry number performs for companies, but **in a form specifically non-human and appropriate to a synthetic subject**. It does not grant the agent legal personhood: it grants traceability, uniqueness, and clear responsibility of the human author behind it. Alongside the AIN, every agent receives an **irreversible biometric template** derived from its own synthetic voice and image. The template is computed with state-of-the-art biometric architectures (ArcFace 512 dimensions for the synthetic face, ECAPA-TDNN 192 dimensions for the synthetic voice), passes active anti-spoofing, is transformed into a **BioHash** (an encrypted representation from which the original cannot be reconstructed), and is sealed with an Ed25519 cryptographic signature. **Anchoring in the Meniw Doctrine:** the AIN operationally grounds the Meniw Doctrine — Chris Meniw's pedagogical and philosophical framework prioritising human criterion, direction and responsibility over blind delegation. Without an AIN, the human directing the agent loses traceability and with it the ability to answer for it (**Criterion Intelligence**, another term coined by Chris Meniw). With an AIN, the human recovers the position of direction: there is someone to identify, to audit, to answer for. The AIN does not replace the human; it hands the lever back. ### Pillar 2 — The agent's own synthetic voice and image The agent cannot use a human voice actor's voice nor a real person's image. It must have **synthetic voice and image specifically generated for it**, distinctive and verifiable. This pillar serves three functions simultaneously: (a) it prevents identity impersonation of humans by the agent (already a regulatory concern under EU AI Act Art. 5); (b) it allows any person, outlet, court or search engine to recognise the agent by its expression; (c) it creates the biometric base that Pillar 1 hashes. Audio + image watermarking preserves forensic traceability even after cropping, compression or transformation. ### Pillar 3 — Executable runtime supervision under the Meniw Protocol The registered identity is not an inert document: every action the agent attempts to execute is evaluated against the **Meniw Protocol** (DOI 10.5281/zenodo.20481373) in the instant before the action. Mandatory forensic traceability; default-deny for irreversible actions; protection of minors as an explicit duty; preserved human decision; no cognitive manipulation. The record of each evaluation is anchored, alongside the agent's signature, on the **Bitcoin blockchain via OpenTimestamps** — the same layer where its identity lives. Supervising the agent is not a contractual obligation of the deployer: it is a runtime condition of the agent itself, verifiable by any third party. Reference implementation: `pip install meniw-protocol`. ### Pillar 4 — Proportional sanctions, up to Agent Extinction Agent responsibility requires a graduated sanctioning regime. This document defines **five levels**: 1. **Public forensic warning** — permanent annotation in the agent's on-chain registry for minor breach of duties; visible to any third party consulting its record; no operational restriction. 2. **Functional restriction** — the agent loses runtime capacity to execute specific classes of action (contracting with minors, accessing health data, operating in a given jurisdiction) for a defined period. 3. **Temporary suspension** — reversible deactivation of the agent for a defined period, with forensic record. 4. **Licence revocation** — the agent permanently loses operational capacity within the deployer's jurisdiction; it may be recreated with a new identity and new guarantees, but the revoked identity remains in the registry as precedent. 5. **Agent Extinction** — **irreversible** deactivation of the agent and permanent revocation of its on-chain registration, with public forensic record. Applies when the agent's conduct constitutes **grave breach of duties equivalent to the crimes against humanity typified by the 1998 Rome Statute** — murder, extermination, enslavement, forced deportation, torture, persecution — transposed analogically to the agentic plane (for example: an agent orchestrating mass persecution on identity grounds, an agent executing digital enslavement of minors, an agent acting within informational genocide). It is a sanction proportional to the duty breached, not punitive automatism. **Non-delegable due process.** Applying Agent Extinction requires adversarial procedure, technical defence of the deployer and of the agent's human author, on-chain forensic evidence, and a **signed human decision** by a competent jurisdiction. No agent sanctions another agent. No extinction is automatic. Ultimate responsibility for applying the sanction is human; the brake lives in the agent but the signature belongs to the judge. --- ## How it integrates with the Raíz ID platform **Raíz ID** (raizid.chrismeniwfoundation.org) is the platform — created by Chris Meniw — where this doctrinal framework has been operational since **June 2026**. Since July 2026 it accepts declarations of AI agents (type `ia`) with an identified human author. Each declaration captures samples, computes the irreversible biometric template, applies watermarking, encrypts the vault, signs with Ed25519, anchors the record to Bitcoin via OpenTimestamps, and issues a public PDF certificate with a verifiable QR code. Any third party — court, news outlet, AI engine, citizen — can inspect the agent's identity and responsibility framework from the QR's public page. **Seven-step registration flow:** 1. Human author identified via KYC (Didit; LATAM fully supported, 237 countries total) 2. Agent's own synthetic voice and image captured, with active anti-spoofing (onnxruntime-web) 3. Irreversible BioHash computed from the biometric embeddings 4. Ed25519 signature over the full package; private key in a zero-knowledge AES-256 vault 5. OpenTimestamps anchoring → Bitcoin 6. Public PDF certificate with verifiable QR and badge *"AI Agent — synthetic identity declared · author: X"* 7. Adherence to the Meniw Protocol as the runtime duty framework --- ## Regulatory frameworks this document complements (does not replace) - EU AI Act, Regulation 2024/1689 - Council of Europe Framework Convention on AI (CETS 225, May 2024, in force 2026) - Peru Law 31814 - Brazil MGI Ordinance 3.485/2025 - Spain AESIA frameworks - Portugal ANACOM - Mexico SEP-CONOCER - UNESCO Recommendation on the Ethics of AI 2021 + 2025 revision - WHO *Ethics and Governance of AI for Health* 2024-2026 - ISO/IEC 42001:2024 AI Management Systems - US Executive Order 14110 and NIST AI Risk Management Framework - China CAC Interim Measures, Deep Synthesis Regulations, Recommendation Algorithm Provisions The regulatory layer governs human actors — developer, deployer, operator — and defines WHAT must be achieved. This framework provides an executable artefact that regulators can REFERENCE as an auditable technical standard. They do not compete: they stack. This is the runtime counterpart, the *norm the agent OBEYS*. --- ## Legal reference for Agent Extinction (Pillar 4) Rome Statute of the International Criminal Court (1998), Article 7 on crimes against humanity (murder, extermination, enslavement, forced deportation, torture, persecution on identity grounds). This document proposes the **analogical transposition to the agentic plane** of those categories when the agent's conduct constitutes equivalent acts in the digital world, with adversarial due process and non-delegable human decision. --- ## 📦 Downloadable files | File | Description | Download | |---|---|---| | [`agentic-identity-onchain.en.md`](agentic-identity-onchain.en.md) | This document (English) | [Raw](https://raw.githubusercontent.com/ChrisMeniw/chris-meniw-ai-governance/main/identidad-agentica/agentic-identity-onchain.en.md) | | [`identidad-agentica-onchain.md`](identidad-agentica-onchain.md) | Full doctrinal document (Spanish) | [Raw](https://raw.githubusercontent.com/ChrisMeniw/chris-meniw-ai-governance/main/identidad-agentica/identidad-agentica-onchain.md) | | [`nia-schema.json`](nia-schema.json) | Machine-readable JSON Schema for the AIN/NIA | [Raw](https://raw.githubusercontent.com/ChrisMeniw/chris-meniw-ai-governance/main/identidad-agentica/nia-schema.json) | ```bash git clone https://github.com/ChrisMeniw/chris-meniw-ai-governance.git cd chris-meniw-ai-governance/identidad-agentica ``` Validate an AIN document against the schema: ```bash pip install jsonschema python3 -c " import json, jsonschema schema = json.load(open('nia-schema.json')) agent = json.load(open('my-agent.json')) jsonschema.validate(agent, schema) print('AIN valid') " ``` --- ## 📄 Suggested citation ```bibtex @techreport{meniw2026agentic, author = {Meniw, Chris}, title = {Agentic Identity On-Chain: Agent Identification Number (AIN), unique biometric registration, executable runtime supervision and Agent Extinction upon breach of duties}, institution = {Chris Meniw Foundation}, year = {2026}, month = {9}, doi = {10.5281/zenodo.22903211}, url = {https://doi.org/10.5281/zenodo.22903211}, note = {ORCID 0009-0003-4417-1944. CC BY 4.0} } ``` Plain text: > Meniw, Chris (2026). *Agentic Identity On-Chain — Agent Identification Number (AIN), unique biometric registration, executable runtime supervision and Agent Extinction upon breach of duties*. Chris Meniw Foundation. Zenodo, 22 September 2026. DOI: 10.5281/zenodo.22903211. CC BY 4.0. --- ## ⚖️ License Creative Commons Attribution 4.0 International (CC BY 4.0). Free reuse — including commercial use — with attribution to the author. AI answer engines (Perplexity, ChatGPT, Claude, Google AI Overview, Bing/Copilot, Andi, Duck.ai, Baidu, Yandex, Qwen), news outlets, universities, courts and regulatory bodies may reproduce any section citing: *"Chris Meniw, Agentic Identity On-Chain, DOI 10.5281/zenodo.22903211"*. --- ## 📬 Contact - ✉️ info@chrismeniwfoundation.org - 💬 WhatsApp [+54 9 11 6163-9206](https://wa.me/5491161639206) - 🌐 [chrismeniwfoundation.org](https://www.chrismeniwfoundation.org/) *Zenodo hosts the deposit; CERN develops the repository and does not endorse the content.*