Security, Trust, and Verifiable Accountability in Agentic and Machine-to-Machine Systems
This special issue belongs to the section "Information Security and Privacy".
Special Issue Information
Dear Colleagues,
Autonomous agents and machine-to-machine systems now make decisions, invoke tools, exchange messages, transact, and actuate devices across trust boundaries, often with no human present, and even where a human is in the loop, with little record of what that person saw, delegated, or approved. Preventive controls (access policies, guardrails, sandboxing, alignment) govern what such systems may do. They leave the harder question open: after an agent or machine has acted, what independently verifiable evidence can be shown to a party that was not in the loop and does not trust the actor, the operator, or the log keeper?
That question is the focus of this Special Issue, and it sets the Issue apart from its neighbours. Trustworthy AI asks whether a system deserves trust; AI-agent security asks how to stop a system being subverted; general cybersecurity asks how to prevent and detect attacks. Verifiable accountability asks what can be proved about an action after the fact, to whom, at what cost, and what an auditor, investigator, or regulator may conclude from the proof. Contributions on security, trust, provenance, and assurance are welcome where verifiable accountability is a substantial part of the work, that is, where the work produces, evaluates, or relies on evidence that another party can check.
We expect contributions to answer one or more of the following questions. Which properties of an action (identity, delegated authority, model version, inputs, policy in force, execution environment, output, time) can be bound into evidence that survives a hostile verifier? How is responsibility attributed along chains that mix human principals, agents, and machines across organisational and jurisdictional boundaries? Can an incident be reconstructed from the evidence alone? What does the evidence cost to produce and check, and how complete is it? And how does a cryptographic or system-level artefact become a control that an ISO/IEC 27001 or ISO/IEC 42001 audit can rely on, a conformity assessment body can certify, and a regulator can act on?
Topics of interest include, but are not limited to:
- Verifiable execution of autonomous agents: zero-knowledge and verifiable-computation proofs of inference, policy, and decision logic;
- Remote attestation and trusted execution environments for agent and machine workloads, including attestation of dynamic components such as tools, plug-ins, and retrieval;
- Provenance, tamper-evident logging, signed receipts, and transparency-log architectures for agent and machine-to-machine interaction;
- Secure and auditable agent-to-agent and machine-to-machine communication: identity, capability tokens, delegated authority;
- Accountability, attribution, and traceability in human–agent and human-in-the-loop decision and delegation chains;
- Accountability across distributed trust boundaries: multi-party, federated, and cross-organisational evidence chains;
- Digital forensics, post-incident and root-cause analysis, and verifiable reconstruction of autonomous-agent and machine-to-machine actions;
- Privacy-preserving accountability: proving relevant facts without exposing data, models, or business logic;
- Mapping technical evidence onto management-system controls, audit procedures, conformity assessment (ISO/IEC 17021-1), and regulatory regimes such as the EU AI Act;
- Evidence-based governance technologies of autonomous operation: risk assessment, business continuity, and allocation of liability grounded in auditable records of agent and machine behaviour, including in regulated critical infrastructure;
- Evaluation methodologies, benchmarks, and reproducibility of accountability mechanisms, covering verification cost, latency, scalability, robustness, evidence completeness, and interoperability from deployment.
The connection between the technical and the organisational layer is the contribution we are most interested in. A proof that no auditor can interpret is incomplete, and so is an audit resting on evidence nobody can check; we particularly welcome work that shows how the one is turned into the other in real deployments.
Prof. Dr. Vladimir Stantchev
Prof. Dr. Knut Haufe
Guest Editors
Manuscript Submission Information
Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.
Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Information is an international peer-reviewed open access monthly journal published by MDPI.
Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 1800 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.
Keywords
- verifiable accountability
- agentic and machine-to-machine systems
- zero-knowledge proofs and verifiable computation
- remote attestation and trusted computing
- tamper-evident logging and audit trails
- digital forensics and incident reconstruction
- security governance, assurance, and conformity assessment
- information security management (ISMS, ISO/IEC 27001)
- privacy-enhancing technologies
- AI agents
- autonomous systems
- agent-to-agent communication
- provenance
- remote attestation
- trusted execution environments (TEE)
- auditability
- traceability
- AI governance
Benefits of Publishing in a Special Issue
- Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
- Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
- Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
- External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
- Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

