A new academic proposal wants identity checks sized to the risk of what you're about to do, not maxed out before you do anything.
The paper argues that most digital systems make everyone clear the same high identity bar at the door, no matter whether what follows is trivial or high-stakes. That flat approach over-collects personal data, locks out people who never needed to prove that much, and ties the strength of a verification to whichever institution performed it rather than to the risk of the act itself. The authors propose splitting a user's verified status, what they call an "assurance state", from the specific capability it unlocks, so someone can join with minimal disclosure and hand over more only when an action actually requires it. The model covers individuals, companies, and machine entities such as AI agents, using a typed taxonomy, a two-part scale of what gets disclosed and where that information comes from, jurisdiction tracked as a time-stamped attribute, and reliance records that log who is liable if an identity claim turns out to be wrong.
That matters because today's identity checks are stuck in one jurisdiction and one moment in time: pass a bank-style identity check, what compliance teams call KYC, for one platform, and reusing it elsewhere, or complying with a later data-erasure request, is still a mess. Extending the same framework to AI agents acting on someone's behalf is the more unusual move, since most identity standards were not built with non-human actors in mind.
It is a design-science paper built against anti-money-laundering, electronic-identity, and data-protection law, not shipped code, so the real test is whether any platform or regulator actually adopts something this granular.