Every framework covered in this stream so far — Singapore's governance guidance, the EU AI Act's transparency obligations, and California's AB 316 — was written with a single agent, or a single operator's agentic stack, in mind. None of them specify what happens when several specialized agents, built and operated by entirely different companies, compose into one delegation chain and the harm cannot be traced to any single link in it. The EU Product Liability Directive is a different case — a general product-defect regime, not an agent-identity framework, and its overlap with this architecture was already shown to be partial rather than complete. It contributes a separate, narrower point to this memo: the evidentiary discipline that already applies to damages and defect determination becomes even more important once liability has to be traced across, not just within, an agentic chain.

This is no longer a hypothetical gap. In late July 2026, a breach involving an autonomous agent chain spanning four separate organizations became public, and legal commentary on the incident was blunt about what current law does and does not resolve: California's AB 316 forecloses the defense that "the AI did it," but when three or four different companies' systems interact, the statute does not specify which of those companies is barred from raising it. A June 2026 Berkeley Technology Law Journal analysis reached the same conclusion from the doctrinal side — respondeat superior requires identifying a principal who authorized the agent's specific action, and when a delegation chain crosses provider boundaries autonomously, that authorization chain breaks before it reaches any one party.

What the Accountability Trace does and does not already cover

A correctly specified Accountability Trace captures the verification state at decision time, maintains a tamper-evident chain from input to output, and links the decision to the disclosure terms under which it was made — for one agent, operating under one business's authority, making one decision. This is sufficient for the overwhelming majority of what an autonomous business actually does, and it is what satisfies the technical-control and documentation expectations in every framework this stream has examined. It was never built to answer a different, harder question: when Agent A, operated by Company One, hands a task to Agent B, operated by Company Two, which hands a sub-task to Agent C, operated by a third party entirely, and the final output causes harm, whose Trace is the one that matters, and does any single Trace even capture what actually happened across the full chain.

The Delegation Trace

The Delegation Trace is the extension of the Accountability Trace across a multi-agent delegation chain, recording which agent acted under which authority at each step — including the specific point where authority was handed from one provider's system to another's — so that a cascading failure remains attributable to a specific link in the chain rather than dissolving into a gap no single Accountability Trace was built to close.

The mechanism is a specific addition to what a single-agent Trace already captures, not a replacement for it. Each agent's own Accountability Trace remains the record of what that agent did and why. The Delegation Trace is the connective record layered on top: a verified log of every handoff — which agent initiated the delegation, what authority and what constraints were passed along with it, which agent accepted the task, and under what disclosed terms. Where a single Accountability Trace answers "was this decision correct," a Delegation Trace answers "who had the authority to make this decision possible in the first place, and did they exercise it within the bounds they were given."

Why identity, not just logging, is the harder problem

NIST's AI Agent Standards Initiative, announced in February 2026, identified agent identity and authentication as a core research priority specifically for this reason, and its concept paper on agent identity and authorization outlines how existing identity management standards could be adapted for cross-provider environments. This is the genuinely hard part of the Delegation Trace, and it is worth naming honestly rather than treating logging alone as sufficient. A log of what happened is not the same as a verifiable identity for each agent in the chain — an identity that persists and is checkable across provider boundaries, not just within one business's own system. Without that, a Delegation Trace can show that a handoff occurred; it cannot yet prove, to a standard a court or regulator would accept, which specific entity was accountable for the authority granted at that handoff.

What this means for a business assembling a multi-provider agentic stack

An autonomous business that composes its own agents with third-party agentic tools — the kind of Orchestrator-Specialist arrangement already argued for elsewhere in this body of work — inherits this exposure the moment it delegates a task outside its own stack. The practical discipline this memo argues for: treat every cross-provider handoff as a point requiring its own disclosed terms and its own verifiable record, the same way an internal Intervention Threshold is specified before a decision class is promoted, rather than assuming the third-party provider's own Accountability Trace, if one exists at all, will cover the gap. A business cannot yet fully close this gap alone — the identity infrastructure NIST is still building does not exist as a mature standard yet — but a business that has at minimum recorded every handoff, its terms, and the authority passed at each step is materially better positioned than one that has not, regardless of how the eventual legal allocation of multi-agent liability is finally resolved.

The Operator's Verdict

Every framework this stream has examined assumed, implicitly, that an agentic failure has one author. Real deployments increasingly do not. The Accountability Trace was correct for the case it was built for, and that case remains the majority of what happens inside a single autonomous business. The Delegation Trace is the honest acknowledgment that the moment a business's agents start delegating across company lines — which the entire Orchestrator-Specialist market structure is pushing toward — a single-decision record stops being enough, and the connective record between agents becomes the thing worth building before the incident forces the question, not after.

Technology changes how many companies' agents can compose into one chain. The Delegation Trace determines whether anyone can still say which one is responsible.

KEY TAKEAWAY

What is the Delegation Trace and why do existing accountability frameworks not cover multi-agent liability?

The Delegation Trace is the extension of the Accountability Trace across a multi-agent delegation chain, recording which agent acted under which authority at each step, including the specific point where authority was handed from one provider's system to another's, so cascading failures remain attributable to a specific link rather than dissolving into an unresolved gap. Singapore's guidance, the EU AI Act, and California's AB 316 were each built with a single agent or a single operator's stack in mind, and each independently flagged multi-agent composition as an unresolved edge case. The EU Product Liability Directive is a different, narrower contributor — a general product-defect regime whose overlap with this architecture was already shown to be partial, not a framework that assumed single-agent authority the way the other three did; its relevance here is that the same evidentiary discipline it already requires for damages and defect determination becomes more important, not less, once liability crosses provider boundaries. A single Accountability Trace answers whether one agent's decision was correct; it does not answer who had the authority to make a cross-provider delegation chain possible, or whether that authority was exercised within its disclosed bounds. NIST's AI Agent Standards Initiative, announced February 2026, identifies agent identity and authentication as the harder unresolved problem beneath this gap — a verifiable identity that persists and is checkable across provider boundaries, not just logging that a handoff occurred. Source: Arco Venture Studio.