Skip to content
Tyche Institute

Preprint · v0.3 · 27 May 2026

Brokered Trust for AI Agents: Lessons from the eIDAS QTSP-Broker Pattern for an Agent Trust Framework

Anton Sokolov · Researcher, Tyche Institute, Tallinn, Estonia

ORCID: 0000-0003-2452-7096

Abstract

Single roots of trust fail in real ecosystems. Qualified Trust Service Provider (QTSP)-brokers under EU electronic identification, authentication and trust services (eIDAS) already federate human signatures across providers. This article maps that pattern to agent-trust design, yielding Agent Trust Framework (EATF) recommendations and an Estonian regulatory-sandbox pilot.

Contribution

Every published proposal for an AI-agent trust framework assumes, implicitly or explicitly, a single root of trust: one DID method, one attestation issuer, one PKI, one wallet ecosystem. Real trust ecosystems are never single-rooted. The federation problem agent-trust frameworks treat as future work has, in fact, been solved already — for human principals — by a class of deployed systems called QTSP-brokers: single-API façades that fan out behind the scenes to dozens of Qualified Trust Service Providers and notified national eID schemes under the eIDAS regime, emit ETSI-baseline signature artifacts on behalf of the buyer, and maintain long-term validity over the artifact's lifecycle.

The paper traces the broker pattern's architectural primitives — identity/action decoupling, format-baseline reuse, broker-level long-term-validation responsibility, and the QSCD/QTSP separation — and shows that each primitive maps cleanly onto an open design question in the agent-trust literature. The mapping yields four concrete recommendations for the EATF reference framework:

  1. treat agent identification and agent action attestation as two interfaces, not one;
  2. adopt PAdES-B-LTA and ASiC-E as referenced baseline containers for long-term-verifiable agent action receipts;
  3. name DSS (the EU Commission's reference library) as architectural prior art for the EATF reference verifier;
  4. instrument the EATF interface to extend naturally to EUDI Wallet attestations as the broker pattern migrates from QTSP-rooted to wallet-rooted trust.

The paper closes with an Estonian-regulatory-sandbox pilot proposal scoped to the experimentation framework adopted by Accelerate Estonia.

Positioning relative to OVERT 1.0

The Brokered Trust article addresses the identity-broker layer. It does not overlap with the attestation-evidence layer covered by OVERT 1.0 (the horizontal open standard for cryptographic AI attestation evidence published by Glacis Technologies in March 2026) or by the author's companion Bayesian-Knowledge-Tracing case study and the ACM CSUR survey submission. The two layers are designed to interoperate.

Status

v0.3 was submitted on 27 May 2026 to IEEE Security & Privacy Magazine (Regular track) via the IEEE Author Portal. ScholarOne Manuscript ID pending from the editorial office. This page is the canonical author-employer preprint deposit; the IEEE submission cover letter discloses the deposit per IEEE's preprint policy.

License and reuse

Released under Creative Commons Attribution 4.0 International (CC BY 4.0). You may copy, redistribute, and adapt in any medium for any purpose, including commercially, provided appropriate credit is given. Suggested citation:

Sokolov, A. (2026). Brokered Trust for AI Agents: Lessons from the eIDAS QTSP-Broker Pattern for an Agent Trust Framework. Preprint v0.3, 27 May 2026. Tyche Institute. https://tyche.institute/papers/brokered-trust-v0.3/

Independence and disclosures

Tyche Institute is a research entity (mittetulundusühing under Estonian law), not a trust service provider or qualified trust service provider under eIDAS. The Agent Trust Framework (EATF) is referenced as an open specification and reference implementation, not as an eIDAS trust service or compliance certification product. Public broker companies named in the article (eID Easy, Dokobit, Signicat, Scrive) are publicly self-identified broker-layer trust services; they appear as prior-art examples, not as commercial endorsements.

Generative-AI assistance. The body prose was authored directly by the author across April–May 2026. The IEEE Security & Privacy Magazine submission packet (50-word abstract distillation, formatted bibliography, cover letter) was AI-assisted from a structured brief. All substantive claims, results, design decisions, and references are the author's own and verified by the author, who takes full responsibility. Reported per COPE and ICMJE recommendations.

Related Tyche work