Vienna, Tuesday, 16 September 2031. Mara is a fictional character. This is a thought experiment built from systems already emerging in 2026. It is a plausible trajectory, not a prediction.
What this is about
This is a scenario about one ordinary day in which AI agents act under delegated authority. It is not a prediction that every detail will arrive by 2031. Following one person across work, money, health, media and home life makes the usually invisible infrastructure easier to see: identity, scoped permission, runtime controls, evidence, provenance, revocation and human recourse.
The point is not that the future will look exactly like this. It is to ask what must be true before software can safely act on our behalf.
07:42. The first permission
The flat adjusted ventilation through the night. The system recorded the setting and Mara could change it.
Mara set down her coffee. A pale line appeared on the wall display.
Two changes need you.
Her personal agent had already moved a team call around a delayed train, declined a newsletter renewal, and joined the waiting list for a restaurant on her wishlist on Friday. Those actions sat inside standing permissions she had set months earlier. The agent could reorganise work calls if no external attendee was displaced. It could renew subscriptions below twelve euros. It could express interest in a booking, but it could not make a deposit.
The first new request was a rail ticket to Graz. The price had crossed the travel limit by seven euros. The screen showed the train, the reason for the increase, the cheaper alternative, and the permission being requested: one payment, to one operator, for one journey.
She approved it with her thumb.
The second request concerned a medical appointment. The clinic had offered an earlier slot after a cancellation. Her agent was allowed to read availability but not to change a health appointment. Mara moved it herself.
Nothing about this felt futuristic. It felt like sorting post, except that every envelope stated what opening it would permit.
The distinction had taken years to become ordinary. Early assistants asked for broad access because broad access was easy to build. They could read a calendar, or they could not. They could spend, or they could not. In this scenario, the useful unit is narrower: this agent, acting for this person, can perform this action for this purpose until this time.
The permissions were still imperfect. People accepted defaults they did not understand. Services found ways to make the generous option smoother. Yet the absence of a permission had become visible. When Mara’s agent could not move the appointment, it stopped. It did not improvise consent.
08:31. Identity without autobiography
At the tram stop, Mara held her phone near the reader. The city wallet supplied one fact: a valid annual pass existed for this zone at this time.
It did not send her name, address, date of birth, or payment history. The reader did not need them.
The transaction appeared in the wallet as a small receipt. Transit entitlement checked. Attribute shared: valid / invalid. Retention: 24 hours for dispute. She had stopped reading those receipts daily. She still checked the monthly summary, mostly to see which services had asked for more than they needed.
At the office entrance, the same wallet presented a different credential. This one said that she was an active employee permitted on the sixth floor until 19:00. The building learned nothing about her tram pass. The tram operator learned nothing about her employer.
The separation was less elegant than the diagrams had promised. Some older buildings still used central directories. Cross-border credentials failed often enough that frequent travellers carried backups. A wallet could disclose selectively only when the service on the other side had been designed to ask selectively.
Mara kept a plastic identity card in the back of her phone case. Infrastructure became invisible when it worked. The plastic remained for the days it did not.
09:16. The claim that stopped
Mara worked in operations at a mutual insurer. Overnight storms had damaged roofs across Lower Austria, and the claims queue was long enough that the morning forecast estimated eleven hours before every urgent case received a first response.
The claims agent had already assembled photographs, policy terms, weather records, prior correspondence, and repair estimates. It grouped straightforward cases for payment and routed ambiguous ones to people. The model produced recommendations. A separate policy service decided which proposed actions could proceed.
One case had stopped.
The screen did not say AI confidence low. Confidence was only one piece of evidence. The action record said that the claim itself was covered, the estimated amount sat within the agent’s payment authority, and the customer identity matched. The destination account had changed after the claim was opened. A rule required independent confirmation before money could move to a new account.
The agent had proposed three actions: request confirmation from the customer through the registered channel, pause the payment, and notify the case owner. The first two were permitted. The notification was held because it included a contractor’s report containing an address outside the case owner’s region.
Mara opened the record.
She could see who had delegated the claims workflow, which policy version evaluated each action, what information the model had used, what fields the proposed message would disclose, and why the final step had stopped. The record did not reveal the model’s private chain of thought. It showed the inputs and rules needed to review an operational decision.
She removed the unnecessary attachment and sent the notification. The customer confirmed the new account through the registered channel twenty minutes later. The payment resumed.
Nothing dramatic had happened. That was the point.
Five years earlier, the same event might have produced one of two bad outcomes. A fully automated system could have paid the new destination because the claim looked legitimate. A cautious system could have sent the whole case to a person and erased most of the promised efficiency. The 2031 workflow did neither. It stopped at the action whose authority was incomplete and allowed the rest to continue.
At 10:04, an auditor asked for the record. The request was not exceptional. The insurer sampled automated claims every week, including successful ones. Failure records taught the team where controls broke. Successful records showed whether the controls were becoming ceremonial.
Mara exported the bounded event history. It was not proof that every underlying statement was true. It was enough to reconstruct which system proposed what, which rule applied, where a person intervened, and what happened next.
12:18. Advice without authority
At lunch, Mara’s health portal displayed a message from her clinic. A monitoring service had compared a recent test with her history and suggested moving a follow-up forward by three months.
The page separated three things that earlier systems often blended. The observation came from the test. The recommendation came from a clinical decision-support model. The appointment change came from a physician who had reviewed both and signed the message.
Mara opened Why this recommendation?
The portal showed the measurements involved, the guideline used, the missing information, and the reason the model could not estimate one part of the result. It also showed what had not happened. No diagnosis had been made. No medicine had been changed. No data had been shared with her insurer or employer.
She accepted the earlier appointment but declined a request to combine data from her fitness tracker. The clinic warned that the recommendation would remain less complete. She preferred that trade.
In Mara’s health system, uncertainty has not disappeared. Its ownership is clearer. A model can assemble evidence and propose options. A clinician remains accountable for the medical decision. The patient still controls whether an optional data source enters the record.
This was not how every service worked. Cheap wellness applications continued to make confident claims from thin evidence. Human review ranged from careful judgment to a hurried click. A confirmation button did not become meaningful oversight because a product called it one.
14:07. The city asks for two facts
Mara remembered her parking permit while waiting for a meeting to begin.
The city service already knew which permit she wanted because her agent had prepared the application. It had filled the vehicle identifier, checked the expiry date, and found the relevant district. It could not submit the legal declaration.
Her identity wallet offered the city two verified facts: her principal residence was inside the district, and she was entitled to act for the registered vehicle. Mara could see the requested attributes before sharing them. The city did not receive the other credentials stored in the wallet, and the wallet did not grant her agent permanent access to municipal services.
She reviewed the declaration, signed it, and received a permit reference.
The service took ninety seconds. It still contained government, law, identity, and a database built before she was born. The improvement came from a narrow agreement about what each part needed to prove.
The receipt included a deletion date for the temporary supporting data. Mara added it to the wallet’s monthly review. She knew she would probably approve the deletion automatically. The option mattered because it made retention a visible choice rather than an invisible fact.
17:36. Provenance is not truth
On the tram home, a family group sent Mara a short video of smoke over a railway station. The caption said the central line had closed.
Her media viewer found a signed provenance record. The clip had been captured by a registered camera, trimmed in a phone editor, and reposted twice. No synthetic frames were declared. The signature showed that the history had not been altered after signing.
It did not show whether the smoke was dangerous, whether the station was the one named in the caption, or whether the clip had been recorded that afternoon. Provenance could describe the asset’s history. It could not make the interpretation true.
Mara checked the transit authority before forwarding it. The smoke came from a maintenance test at a different station. The central line was running.
By 2031, unsigned media had not disappeared. Neither had deception. Provenance helped most when a trusted source used it consistently and a viewer understood its limits. It was evidence about origin and editing, not a machine verdict on reality.
19:22. The hour without mediation
Mara played cello on Tuesday evenings in a room above a library. Twelve people arrived with paper scores, folding stands and rosin. On difficult passages, the conductor stopped and brought the second violins in again.
Phones stayed in a wooden box by the door because the conductor had asked, not because a system enforced it. Nobody generated an accompaniment or requested a summary. The rehearsal remained outside the automated record.
The absence of AI was not rebellion. The group used agents to schedule rehearsals, reserve the room, split the fee, and warn them when the tram was late. They did not use one to play.
Infrastructure had captured the coordination around the hour. It had not captured the reason for it.
22:11. Until tomorrow
Before bed, Mara’s assistant asked one final question.
During dinner, she had mentioned that her mother preferred morning appointments. The assistant could retain that detail and use it the next time Mara arranged a visit. The display offered three choices: do not retain, retain until the visit, retain as a standing preference.
Mara chose until the visit.
The flat lowered the blinds. A tram moved along the wet rails below, loud for four seconds and then gone. The permission receipt settled into the daily log with the ticket, the claim, the clinic, and the parking permit.
Tomorrow the systems would act again. Tonight, one small fact knew when to disappear.
What this scenario assumes
The story extrapolates five signals visible by 27 September 2026: work on verifiable agent identity and delegated authority; payment protocols with user limits; supervised clinical decision support; Austrian and EU digital identity infrastructure; and signed media-provenance standards. It assumes these systems become easier to use and more interoperable by 2031. That outcome is plausible, not guaranteed.
The scenario does not assume universal agent identity, autonomous medical authority, complete or immutable logs, passive government access to identity wallets, universal cross-border acceptance, or cryptography that proves a piece of media is true.
Related reading
Source foundation
- NIST, Identity and Authority of Software Agents, 5 February 2026
- Mastercard, Agent Pay, 29 April 2025
- WHO, Agentic Workflows and Human Oversight, 3 June 2026
- European Commission, technical standards for European Digital Identity Wallets, 28 November 2024
- Austrian government, eAusweise
- C2PA Content Credentials Technical Specification 2.4, April 2026