Mohamad Amin Hasbini · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22892182
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Regulation for financial entities and for essential and important entities does not name AI agents, but its obligations are technology-neutral and already reach agentic systems: inventory your ICT assets, limit and authenticate access, detect anomalies, log incidents, and prove all of it to a supervisor. This paper reads DORA and NIS2 against how agents are actually run, and finds the gap in one place: on the three agent platforms reviewed, agent-level identifiers and traces are starting to arrive, but identity still authenticates at the organisation and its credentials, and none of the three is documented as handing the entity a portable, independently verifiable record binding an agent's action to the authority it acted under. The cryptography that would make agent evidence durable is the part underneath, and it is the part no inventory lists. Version 2 (September 2026). Corrects how DORA and NIS2 apply to financial entities, fixes article wordings, dates and references, adds the logging, identification and certificate provisions of the RTS on ICT risk management (Delegated Regulation (EU) 2024/1774), updates statuses that moved after July (Regulation (EU) 2026/1744, the 2026-07-28 MCP revision, IETF work, NIS2 transposition), limits the platform finding to the three platforms reviewed, and adds a dated update of 22 September 2026 on them. The central argument is unchanged. Version 1: 15 July 2026, doi:10.5281/zenodo.21325135.
No comments yet — start the discussion below.