Spherity Research Academic Paper
From Trustworthy AI to Trusted, Operational Agentic Systems
A comparative capability and assurance framework analysis for China, the European Union and the United States
Browse this paper
In brief
What does this research establish?
Agentic AI turns AI assurance into a deployment-capability race. This paper separates AI Governance, Trustworthy AI, and Trusted AI, then compares China, the European Union, and the United States across the institutional, engineering, identity, provenance, runtime-control, and lifecycle capabilities needed for agents to act with legal, economic, industrial, or physical consequences.
Key takeaways
- The decisive unit of competition in agentic AI is not only model capability, but deployment capability under verifiable authority, evidence, status, policy, and accountability.
- AI Governance, Trustworthy AI, and Trusted AI are cumulative but non-substitutable: law does not replace safety engineering, and cryptographic identity does not replace lawful authority or evidence.
- China shows the most coherent emerging national stack for agent identity, credential lifecycle, delegation, tool access, traceability, and content labelling.
- The United States is strongest in TEVV, cybersecurity, zero-trust engineering, cloud workload identity, and sector-specific assurance.
- Europe's USP is the combination of risk-based law, eIDAS trust services, trusted lists, authoritative registers, European Business Wallets, product regulation, and industrial safety practice.
- Europe can convert these assets into trusted-autonomy infrastructure if semantics, reference implementations, conformance testing, and sector deployment move together.
From Trustworthy AI to Trusted, Operational Agentic Systems. A 41-page comparative capability and assurance framework analysis for China, the European Union and the United States.
Geography in one sentence
China is coordinating a national agent-trust stack, the United States leads in engineering assurance and zero-trust implementation, and Europe has the strongest legal trust foundation if it converts eIDAS, European Business Wallets, trusted lists, registers, and product-assurance regimes into a shared operational runtime layer for Trusted AI.
That geography matters because the AI race is becoming a deployment race. Model capability is only useful in regulated, industrial, and cyber-physical settings when agents can act under current authority, current evidence, current policy, and current accountability. The paper therefore treats jurisdictional maturity as a vector, not a single score.
Three-level taxonomy: AI Governance, Trustworthy AI, Trusted AI
The paper separates three cumulative layers that are often blurred in AI policy and vendor messaging.
| Layer | Core question | Evidence and controls | Decision function |
|---|---|---|---|
| AI Governance | Is the deployment legitimate, accountable, and subject to oversight? | Law, policy, risk tier, institutional responsibility, enforcement, remedies | Determines whether deployment is permitted and accountable |
| Trustworthy AI | Does the system achieve the required qualities for this context? | Risk management, QMS, TEVV, safety case, monitoring, robustness, security, fairness | Supports confidence in system behaviour |
| Trusted AI | Can the actor, authority, evidence, status, and action be verified now? | Legal-person identity, agent identity, mandates, provenance, semantic claims, status, policy decisions, runtime attestation, receipts | Enables verifiable and enforceable reliance at the point of action |
The layers are non-substitutable. Strong cryptographic identity does not prove safety. Strong safety testing does not prove legal authority. Strong regulation does not create executable trust unless it is translated into credentials, status, semantics, policies, and evidence that machines can verify.
Comparative capability map
The analysis evaluates China, the European Union and the United States across twelve capability areas. The scores are provisional, single-author ordinal estimates, designed for reproducible comparison and future independent validation rather than as a statistical league table.
| Geography | Comparative strength | Priority integration area |
|---|---|---|
| China | Coordinated governance, national standards, agent identity, interconnection, content labels, and emerging distributed-identity infrastructure | Legal-person authority, cross-border reliance, independent runtime assurance, and mature audit or transaction standards |
| European Union | Risk-based law, legal-person identity, qualified trust services, trusted lists, sector safety, and cross-border mandate pilots | Agent workload identity, runtime authorisation binding, semantic evidence profiles, action receipts, and continuous assurance |
| United States | TEVV, cybersecurity, zero trust, cloud workload identity, modular authorisation standards, and critical-infrastructure practice | Portable legal-person identity, authoritative cross-company mandates, issuer governance, and common trust-list semantics |
This comparison yields a practical lesson for boards and policymakers: an agent can draft, recommend, and simulate before the trust stack is complete, but legally binding cross-company or physical actions stall when identity, authority, evidence, status, and safety cases cannot be verified together.
Europe's USP and opportunity
Europe’s distinctive advantage is not only regulation. It is the possibility of turning regulation into operational trust infrastructure. eIDAS 2.0, qualified trust services, trusted lists, authoritative registers, European Business Wallets, company-representation credentials, the AI Act, cyber rules, product safety, Data Spaces and Digital Product Passports can become a machine-verifiable chain from legal entity to agent action.
The opportunity is structural:
- Use European Business Wallets to express legal-person identity, representation, mandates and trusted documents.
- Bind technical agents and workloads to narrowly scoped powers of attorney, sector roles, value limits and time limits.
- Connect AI Service Passports to model, system, operator, purpose, version, risk, conformity, monitoring, incident and credential status.
- Use verifiable evidence graphs to preserve provenance, validation, freshness, uncertainty, issuer status and auditable evidence paths.
- Require conformance tests and reference implementations so that the market can rely on the same semantics across sectors.
This is how Europe can move from “lawful and trustworthy AI” to trusted autonomy that industrial actors can actually deploy.
Trust infrastructure for agentic AI
Agentic AI needs a public and private trust infrastructure stack because agents do more than generate outputs. They select tools, retrieve evidence, negotiate, initiate transactions, modify software, control products, or influence actuators. For material actions, relying parties need a decision envelope that answers six questions:
- Who is the legal person behind the agent?
- Which agent or workload is acting?
- Which mandate, role, scope, value limit, and policy apply?
- Which evidence supports the decision?
- What is the current credential, system, model, data, product, and service status?
- Which receipt proves the policy decision and the executed action?
The proposed AI Service Passport bridges the legal control plane and the evidence data plane. It can bind the AI service and operator, purpose, version, risk and legal status, evaluation evidence, conformity information, incidents, monitoring state, credential status, and action records.
Why this matters for Industrial AI and Physical AI
Industrial AI and Physical AI are the proving ground for Trusted AI because consequences are no longer only informational. Agents may interact with maintenance systems, energy infrastructure, manufacturing workflows, robots, vehicles, connected products, supply-chain commitments, software updates, or safety-relevant operational states.
In these domains, adoption stalls at the first missing trust prerequisite:
- without legal-person identity, the relying party cannot know which organisation stands behind the agent;
- without mandate semantics, the relying party cannot know whether the agent may act;
- without product and service evidence, the relying party cannot know whether the action is safe or compliant;
- without runtime attestation and current status, the relying party cannot know whether the system state is still valid;
- without action receipts, the relying party cannot reconstruct accountability after the event.
Trusted AI therefore becomes deployment infrastructure for regulated markets. It reduces friction between organisations, supports safer automation, improves auditability, and creates a path from pilots to high-impact production use.
CTA for Europe: build the trusted-autonomy infrastructure
Europe should treat Trusted Agentic AI as shared industrial infrastructure, not as scattered compliance work. The paper proposes a coordinated programme that aligns legislation, semantics, reference implementations, conformance testing and sector deployment.
The near-term call to action is simple:
- Define European profiles for legal-person credentials, agent powers of attorney, AI Service Passports, status checks and action receipts.
- Publish reference implementations for EBW-to-agent delegation, policy decisions, tool-call receipts and evidence graphs.
- Fund conformance suites so issuers, wallets, agents, verifiers and sector platforms can test interoperability before market lock-in.
- Pilot high-assurance use cases in manufacturing, energy, mobility, pharma, finance, defence, government and critical infrastructure.
- Make the resulting trust layer usable by SMEs as well as large platforms, so European industrial ecosystems can deploy agentic AI safely across company boundaries.
The strategic message is deliberately practical: Europe does not need to copy either the Chinese or the US path. Europe can compete by making lawful authority, trustworthy engineering and machine-verifiable operational trust work together.
Use the full paper for the complete maturity rubric, evidence classes, assurance gradient, comparative scenario analysis, appendices, and source register.
From Trustworthy AI to Trusted, Operational Agentic Systems is licensed by its named author under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.
How to cite this work
Dr. Carsten Stöcker (2026-08-26). “From Trustworthy AI to Trusted, Operational Agentic Systems: A comparative capability and assurance framework analysis for China, the European Union and the United States.” Spherity GmbH. https://spherity.github.io/spherity-research/trusted-agentic-ai-china-eu-us-comparative-analysis.html. Licensed CC BY 4.0.
Direct answers
Questions this research answers
What is Trusted AI in agentic systems?
Trusted AI is the verifiable operational layer for material agent actions. It binds identity, legal authority, provenance, policy, current status, runtime evidence, and action receipts so a relying party can decide whether to permit, restrict, escalate, or deny a specific action.
How does Trusted AI differ from Trustworthy AI?
Trustworthy AI describes desired lifecycle qualities such as safety, robustness, fairness, transparency, privacy, and accountability. Trusted AI asks whether a specific actor, mandate, system version, evidence state, policy decision, and action record can be verified at the moment an agent acts.
What is the paper's geography comparison in one sentence?
China is moving fastest toward a coordinated national agent-trust stack, the United States is strongest in engineering assurance and zero-trust implementation, and Europe has the strongest legal trust foundation if it turns eIDAS, EBW, trusted lists, registers, and product assurance into an operational runtime layer.
Why is Europe well positioned for Trusted Agentic AI?
Europe can connect risk-based AI law, eIDAS trust services, trusted lists, authoritative registers, European Business Wallets, data spaces, product regulation, cybersecurity, and sector safety traditions into legally recognised machine-verifiable trust infrastructure.
Why does agentic AI need legal-person identity and mandates?
A technical workload identity only proves which process is acting. Cross-company and regulated agentic AI also requires proof of the legal person represented, the mandate, sector role, value or scope limits, issuer status, revocation state, and an auditable receipt.
Why does this matter for Industrial AI and Physical AI?
Industrial AI and Physical AI move from recommendations into actions that can affect machines, products, infrastructure, safety, and liability. They require verifiable product evidence, sensor provenance, safety state, runtime attestation, fail-safe control, and accountable action evidence.