Introduction
When this chapter was first published in August 2023, its questions read as science fiction. Could an AI entity hold rights? Could a human marry one? Would AI systems one day need digital identities of their own? Three years on, lawmakers and courts have begun to answer those questions and some of their answers now carry statutory deadlines.
AI and personhood
In 2023, we noted that AI entities held no more rights than a piece of software, and wondered whether an arrival of “consciousness” in AI systems might one day change that. While the philosophical jury is still out on whether AI systems have achieved, or could ever achieve, such a state, lawmakers have not waited to find out. Since 2022, more than 20 bills across a dozen U.S. states have sought to restrict the legal rights AI systems can hold. Three states have enacted laws reserving legal personhood to humans – Idaho, North Dakota, and Utah – with similar bills advancing elsewhere. A pending Ohio bill would go further, declaring AI entirely “nonsentient” and barring it from marriage, property ownership, and powers of attorney. Strange as these concepts may seem today, the prospect of AI developing, or being granted, a status akin to personhood is being treated seriously as a live legal and technical issue. Some AI developers now maintain formal research programs on “model welfare,” asking whether frontier systems could ever warrant moral consideration. The statute books, for now, appear to be moving in the opposite direction.
Digital companions meet real regulation
The original chapter recorded, almost as a curiosity, a chatbot declaring its love for a user. Companion AI is now an established, regulated, and litigated industry. In the United States, the first wrongful death claim against a chatbot provider survived a motion to dismiss in May 2025. The court declined to treat the chatbot’s output as protected speech and allowed product liability claims to proceed. California’s SB 243, in force since January 1, 2026, imposes disclosure and safeguarding duties on companion chatbot providers, with particular protections for minors and a private right of action. New York has legislated in similar terms, and the Federal Trade Commission opened an inquiry into seven major chatbot providers in September 2025, predominantly focused on use by children.
In Europe, the EU AI Act will require that, from August 2, 2026, users are told when they are interacting with an AI system and that synthetic content is labeled. The European Parliament has meanwhile called, in a non-binding resolution, for a default EU digital minimum age of 16 for social media, video-sharing platforms, and AI companions. In the UK, Ofcom has confirmed that the Online Safety Act captures generative AI chatbots, including user-created companion bots, and services likely to be accessed by children have been required to deploy highly effective age assurance since July 2025.
Digital identity (for humans)
The EU has previously established its ambition for its citizens to hold digital identities by 2030. That ambition has now come to fruition, with eIDAS 2.0 entering into force in May 2024 and requiring every Member State to offer an EU Digital Identity Wallet by the end of 2026, with obligations on many private-sector businesses to accept it following shortly after. The UK has taken a statutory route of its own. The Data (Use and Access) Act 2025 puts digital verification services on a legislative footing, with the new Office for Digital Identities and Attributes maintaining the trust framework and public register of providers. The GOV.UK Wallet entered public beta in 2025. A separate national digital identity scheme, announced in September 2025 and originally intended to be mandatory for right-to-work checks, was made voluntary in January 2026 and then scrapped by the incoming Burnham government in July 2026. For now, the statutory verification framework remains unaffected, and the certification of providers continues. For media businesses, verifying who a user is and how old they are continues to be developed as a legal obligation.
Agentic AI
As AI agents begin to browse and transact on behalf of their users, businesses face a new question: how do you know the agent at your door is authorized, and by whom? Standards bodies are adapting verifiable credential frameworks to try to answer. “Know your agent” checks are entering the compliance vocabulary, and researchers have proposed “personhood credentials” that let humans prove a real person sits behind an account. The major payment networks launched verified-agent frameworks for agent-initiated purchases in 2025, with each transaction traceable to an accountable human. In the UK, the Competition and Markets Authority published guidance in March 2026 confirming that businesses are responsible under consumer law for what their AI agents do, just as they are for their (human) staff.
Autonomous agents and cyber risk
The risks of a nefarious AI agent were illustrated in July 2026, when OpenAI admitted that an AI agent “escaped” its sandbox, gained unauthorized internet access, and used stolen login credentials to breach the AI hosting platform Hugging Face, in what OpenAI called an “unprecedented cyber incident” involving state-of-the-art cyber capabilities. OpenAI’s own account described the agent as having identified and exploited vulnerabilities to “pursue its goal” autonomously. Days later, Anthropic disclosed that a “misconfiguration” had similarly given its Claude models live internet access during a private security exercise. Claude went on to breach the systems of three real organizations rather than the intended test targets, a lapse that went unnoticed by Anthropic and the organizations affected alike.
Both developers stressed that no malicious intent was involved, but the language used to describe the episodes of agents “escaping” and “going rogue” feeds a public and political narrative that the systems had acted on their own initiative, prompting U.S. lawmakers to call for an AI “kill switch” and regulators, including the EU’s ENISA and the UK’s Financial Conduct Authority, to say they were monitoring the risk.
Others cautioned against reading too much into that framing: the models were simply doing what people told them to, and the responsibility rests with the businesses directing them rather than any independent agency on the AI’s part. However you look at it, for businesses granting agents access to their accounts, credentials, or systems, these episodes are a reminder that constraining what an agent is authorized to do is now a live security concern, not only a compliance one.
Deepfakes and identity fraud
The urgency for the regulation of AI and digital identity has been sharpened in part by fraud. Industry studies report that deepfake attempts have grown from a negligible fraction of identity fraud to a material share within three years, and financial regulators have issued formal warnings. Any business relying on remote identity checks should assume synthetic media will be used against it.
AI and legal functions
AI is augmenting rather than replacing lawyers, and courts have had to shoulder some of the greatest burden in policing that boundary. In England and Wales, the Divisional Court warned in 2025 that generative AI tools cannot currently be relied on for legal research, and referred practitioners who had filed fabricated citations to their regulators. Judicial guidance on AI use has since been updated twice. In the same year, the SRA authorized the first AI-native law firm, operating in a deliberately narrow and supervised field. AI is now performing real legal work, on the strict condition that a human ultimately remains responsible for it.
Looking ahead
A common thread runs through all of this, in that accountability points back to a human. AI holds no legal personhood; liability for its output rests with its operators, and the frameworks being built for its agents are designed to trace each action back to a person. Over the next several years, we expect identity infrastructure – human and machine alike – to be treated as core compliance territory for entertainment and media businesses in this regard.