{"slug":"four-vendors-one-draft-aws-zscaler-ping-and-defakto-write-an-agent-auth-spec-together","citations":[{"url":"https://datatracker.ietf.org/doc/html/draft-klrc-aiagent-auth-00","committed_hash":"sha256:1a3a9526493a5eb10eac2e0d9a1099ea896ea3d798dedf32715cd02438faa008","committed_hash_short":"sha256:1a3a9526…38faa008","mime_type":"text/html","committed_at":"2026-09-08T15:00:28.729256+00:00","content_snapshot":"\n<!DOCTYPE html>\n\n\n\n\n\n\n\n<html data-bs-theme=\"auto\" lang=\"en\">\n    <head>\n        \n        <meta charset=\"utf-8\">\n        <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n        <title>\n            \n                draft-klrc-aiagent-auth-00\n            \n        </title>\n        <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n        <link href=\"https://static.ietf.org/fonts/inter/import.css\" rel=\"stylesheet\">\n        <link href=\"https://static.ietf.org/fonts/noto-sans-mono/import.css\" rel=\"stylesheet\">\n        \n            <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.74.0/ietf/css/document_html_referenced.css\">\n            \n                <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.74.0/ietf/css/document_html_txt.css\">\n            \n            <script type=\"module\" crossorigin=\"\" src=\"https://static.ietf.org/dt/12.74.0/assets/embedded-fe6c83cf.js\"></script>\n<link href=\"https://static.ietf.org/dt/12.74.0/assets/create-pinia-singleton-608c2f69.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n<link href=\"https://static.ietf.org/dt/12.74.0/assets/Scrollbar-8f078505.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n            <script src=\"https://static.ietf.org/dt/12.74.0/ietf/js/document_html.js\"></script>\n            <script src=\"https://static.ietf.org/dt/12.74.0/ietf/js/theme.js\"></script>\n        \n        <link rel=\"alternate\" type=\"application/atom+xml\" title=\"Document changes\" href=\"/feed/document-changes/draft-klrc-aiagent-auth/\">\n        <meta name=\"description\"\n            \n                content=\"AI Agent Authentication and Authorization (Internet-Draft, 2026)\"\n            >\n        \n\n<link rel=\"apple-touch-icon\"\n      sizes=\"180x180\"\n      href=\"https://static.ietf.org/dt/12.74.0/ietf/images/ietf-logo-nor-180.png\">\n<link rel=\"icon\"\n      sizes=\"32x32\"\n      href=\"https://static.ietf.org/dt/12.74.0/ietf/images/ietf-logo-nor-32.png\">\n<link rel=\"icon\"\n      sizes=\"16x16\"\n      href=\"https://static.ietf.org/dt/12.74.0/ietf/images/ietf-logo-nor-16.png\">\n<link rel=\"manifest\" href=\"/site.webmanifest\">\n<link rel=\"mask-icon\"\n      href=\"https://static.ietf.org/dt/12.74.0/ietf/images/ietf-logo-nor-mask.svg\"\n      color=\"#ffffff\">\n<meta name=\"msapplication-TileColor\"\n      content=\"#ffffff\">\n<meta name=\"theme-color\"\n      content=\"#ffffff\">\n        \n\n\n\n\n<meta property=\"og:title\" content=\"AI Agent Authentication and Authorization\">\n<meta property=\"og:url\" content=\"https://datatracker.ietf.org/doc/html/draft-klrc-aiagent-auth-00\">\n\n\n<link rel=\"canonical\" href=\"https://datatracker.ietf.org/doc/html/draft-klrc-aiagent-auth-00\">\n\n<meta property=\"og:site_name\" content=\"IETF Datatracker\">\n<meta property=\"og:description\" content=\"This document proposes a model for authentication and authorization of AI agent interactions. It leverages existing standards such as the Workload Identity in Multi-System Environments (WIMSE) architecture and OAuth 2.0 family of specifications. Rather than defining new protocols, this document describes how existing and widely deployed standards can be applied or extended to establish agent authentication and authorization. By doing so, it aims to provide a framework within which to use existing standards, identify gaps and guide future standardization efforts for agent authentication and authorization.\">\n<meta property=\"og:type\" content=\"article\">\n\n<meta property=\"article:section\" content=\"Individual Internet-Draft\">\n\n<meta property=\"article:author\" content=\"Pieter Kasselman\">\n<meta property=\"article:author\" content=\"Jeff Lombardo\">\n<meta property=\"article:author\" content=\"Yaroslav Rosomakho\">\n<meta property=\"article:author\" content=\"Brian Campbell\">\n\n\n\n        \n        <style>\n            \n            .diff-form .select2-selection__rendered {\n                direction: rtl;\n                text-align: left;\n            }\n        </style>\n    </head>\n    <body>\n        \n        <noscript><iframe class=\"status\" title=\"Site status\" src=\"/status/latest\"></iframe></noscript>\n<div class=\"vue-embed\" data-component=\"Status\"></div>\n        <div class=\"btn-toolbar sidebar-toolbar position-fixed top-0 end-0 m-2 m-lg-3 d-print-none\">\n            <div class=\"dropdown\">\n                <button class=\"btn btn-outline-secondary btn-sm me-1 dropdown-toggle d-flex align-items-center\"\n                    id=\"bd-theme\" type=\"button\" aria-expanded=\"false\" data-bs-toggle=\"dropdown\"\n                    aria-label=\"Toggle theme\">\n                        <i class=\"theme-icon-active bi bi-circle-half\"></i>\n                </button>\n\n                <ul class=\"dropdown-menu\" aria-labelledby=\"bd-theme\">\n                    <li>\n                        <button type=\"button\" class=\"dropdown-item d-flex align-items-center\"\n                            data-bs-theme-value=\"light\" aria-pressed=\"false\">\n                            <i class=\"me-2 opacity-50 theme-icon bi bi-sun-fill\"></i>\n                            Light<i class=\"bi bi-check2 ms-auto d-none\"></i>\n                        </button>\n                    </li>\n                    <li>\n                        <button type=\"button\" class=\"dropdown-item d-flex align-items-center\"\n                            data-bs-theme-value=\"dark\" aria-pressed=\"false\">\n                            <i class=\"me-2 opacity-50 theme-icon bi bi-moon-stars-fill\"></i>\n                            Dark<i class=\"bi bi-check2 ms-auto d-none\"></i>\n                        </button>\n                    </li>\n                    <li>\n                        <button type=\"button\" class=\"dropdown-item d-flex align-items-center active\"\n                            data-bs-theme-value=\"auto\" aria-pressed=\"true\">\n                            <i class=\"me-2 opacity-50 theme-icon bi bi-circle-half\"></i>\n                            Auto<i class=\"bi bi-check2 ms-auto d-none\"></i>\n                        </button>\n                    </li>\n                </ul>\n            </div>\n            <button class=\"btn btn-outline-secondary btn-sm sidebar-toggle\"\n                    type=\"button\"\n                    data-bs-toggle=\"collapse\"\n                    data-bs-target=\"#sidebar\"\n                    aria-expanded=\"true\"\n                    aria-controls=\"sidebar\"\n                    aria-label=\"Toggle metadata sidebar\"\n                    title=\"Toggle metadata sidebar\">\n            <i class=\"bi bi-arrow-bar-left sidebar-shown\"></i>\n            <i class=\"bi bi-arrow-bar-right sidebar-collapsed\"></i>\n            </button>\n        </div>\n        <nav class=\"navbar bg-light-subtle px-1 fixed-top d-print-none d-md-none\">\n            <a class=\"nav-link ps-1\"\n               href=\"/doc/draft-klrc-aiagent-auth/\">\n                 \n                    draft-klrc-aiagent-auth-00\n                \n                <br class=\"d-sm-none\">\n\n                <span class=\"ms-sm-3 badge rounded-pill badge-draft\">\n                    \n                        Internet-Draft\n                    \n                </span>\n            </a>\n            <button class=\"navbar-toggler p-1\"\n                    type=\"button\"\n                    data-bs-toggle=\"collapse\"\n                    data-bs-target=\"#docinfo-collapse\"\n                    aria-controls=\"docinfo-collapse\"\n                    aria-expanded=\"false\"\n                    aria-label=\"Show document information\">\n                <span class=\"navbar-toggler-icon small\"></span>\n            </button>\n            <div class=\"navbar-nav navbar-nav-scroll overscroll-none collapse pt-1\" id=\"docinfo-collapse\">\n                <div class=\"bg-light-subtle p-0\">\n                    <table class=\"table table-sm table-borderless small\">\n                        <tbody class=\"meta align-top\">\n                            <tr>\n                                <th scope=\"row\"></th>\n                                <th scope=\"row\">Title</th>\n                                <td class=\"edit\"></td>\n                                <td>AI Agent Authentication and Authorization</td>\n                            </tr>\n                        </tbody>\n                        \n\n\n\n\n\n\n\n<tbody class=\"meta align-top \">\n    <tr>\n        <th scope=\"row\">Document</th>\n        <th scope=\"row\">Document type</th>\n        <td class=\"edit\"></td>\n        <td>\n            \n\n\n\n\n\n\n\n    <div>This is an older version of an Internet-Draft whose latest revision state is \"Active\".</div>\n\n            \n            \n            \n                \n\n\n\n\n    <div class=\"alert alert-warning small p-2 mt-2\" role=\"alert\">\n        This document is an Internet-Draft (I-D).\n        Anyone may submit an I-D to the IETF.\n        This I-D is <strong>not endorsed by the IETF</strong> and has <strong>no formal standing</strong> in the\n        <a href=\"/doc/rfc2026/\">IETF standards process</a>.\n    </div>\n\n\n            \n        </td>\n    </tr>\n    \n        <tr>\n            <td></td>\n            <th scope=\"row\">Select version</th>\n            <td class=\"edit\"></td>\n            <td>\n                \n\n\n\n    <ul class=\"revision-list pagination pagination-sm text-center flex-wrap my-0\">\n        \n            \n                 \n                    <li class=\"page-item active\">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-00\"\n                        >\n                            00\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-01\"\n                        rel=\"nofollow\">\n                            01\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-02\"\n                        rel=\"nofollow\">\n                            02\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-03\"\n                        >\n                            03\n                        </a>\n                    </li>\n                \n            \n            \n        \n    </ul>\n\n            </td>\n        </tr>\n        \n            <tr>\n                <td></td>\n                <th scope=\"row\">Compare versions</th>\n                <td class=\"edit\"></td>\n                <td>\n                    \n\n\n\n<form class=\"form-horizontal diff-form\"\n      action=\"https://author-tools.ietf.org/iddiff\"\n      method=\"get\"\n      target=\"_blank\">\n\n            <select class=\"form-select form-select-sm mb-1 select2-field\"\n                    data-max-entries=\"1\"\n                    data-width=\"resolve\"\n                    data-allow-clear=\"false\"\n                    data-minimum-input-length=\"0\"\n                    aria-label=\"From revision\"\n                    name=\"url1\">\n                \n                    <option value=\"draft-klrc-aiagent-auth-03\">\n                        draft-klrc-aiagent-auth-03\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-02\" selected>\n                        draft-klrc-aiagent-auth-02\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-01\">\n                        draft-klrc-aiagent-auth-01\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-00\">\n                        draft-klrc-aiagent-auth-00\n                        \n                    </option>\n                \n                \n            </select>\n\n            <select class=\"form-select form-select-sm mb-1 select2-field\"\n                    data-max-entries=\"1\"\n                    data-width=\"resolve\"\n                    data-allow-clear=\"false\"\n                    data-minimum-input-length=\"0\"\n                    aria-label=\"To revision\"\n                    name=\"url2\">\n                \n                    <option value=\"draft-klrc-aiagent-auth-03\" selected>\n                        draft-klrc-aiagent-auth-03\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-02\">\n                        draft-klrc-aiagent-auth-02\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-01\">\n                        draft-klrc-aiagent-auth-01\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-00\">\n                        draft-klrc-aiagent-auth-00\n                        \n                    </option>\n                \n                \n            </select>\n\n            <button type=\"submit\"\n                    class=\"btn btn-primary btn-sm\"\n                    value=\"--html\"\n                    name=\"difftype\">\n                Side-by-side\n            </button>\n            \n            <button type=\"submit\"\n                    class=\"btn btn-primary btn-sm\"\n                    value=\"--hwdiff\"\n                    name=\"difftype\">\n                Inline\n            </button>\n\n</form>\n                </td>\n            </tr>\n        \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Authors</th>\n        <td class=\"edit\">\n            \n        </td>\n        <td>\n            \n            \n                <span ><a \n           title=\"Datatracker profile of Pieter Kasselman\"\n            href=\"/person/prkasselman@gmail.com\" >Pieter Kasselman</a> <a \n               href=\"mailto:prkasselman%40gmail.com\"\n               aria-label=\"Compose email to prkasselman@gmail.com\"\n               title=\"Compose email to prkasselman@gmail.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Jeff Lombardo\"\n            href=\"/person/jeffsec@amazon.com\" >Jeff Lombardo</a> <a \n               href=\"mailto:jeffsec%40amazon.com\"\n               aria-label=\"Compose email to jeffsec@amazon.com\"\n               title=\"Compose email to jeffsec@amazon.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Yaroslav Rosomakho\"\n            href=\"/person/yrosomakho@zscaler.com\" >Yaroslav Rosomakho</a> <a \n               href=\"mailto:yrosomakho%40zscaler.com\"\n               aria-label=\"Compose email to yrosomakho@zscaler.com\"\n               title=\"Compose email to yrosomakho@zscaler.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Brian Campbell\"\n            href=\"/person/bcampbell@pingidentity.com\" >Brian Campbell</a> <a \n               href=\"mailto:bcampbell%40pingidentity.com\"\n               aria-label=\"Compose email to bcampbell@pingidentity.com\"\n               title=\"Compose email to bcampbell@pingidentity.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>\n            \n            \n        </td>\n    </tr>\n    \n    \n        \n        \n        \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            RFC stream\n        </th>\n        <td class=\"edit\">\n            \n        </td>\n        <td class=\"text-body-secondary\">\n            \n                (None)\n            \n        </td>\n    </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            Other formats\n        </th>\n        <td class=\"edit\">\n        </td>\n        <td>\n            \n                \n    <div class=\"buttonlist\">\n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.txt\">\n            \n                <i class=\"bi bi-file-text\"></i> txt\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.html\">\n            \n                <i class=\"bi bi-file-code\"></i> html\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> xml\n            \n        </a>\n        \n    \n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/draft-klrc-aiagent-auth/00/bibtex/\">\n            \n                <i class=\"bi bi-file-ruled\"></i> bibtex\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/bibxml3/draft-klrc-aiagent-auth-00.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> bibxml\n            \n        </a>\n        \n    \n</div>\n\n            \n        </td>\n    </tr>\n    \n    \n        \n    \n</tbody>\n                        <tr>\n                            <th scope=\"row\"></th>\n                            <th scope=\"row\"></th>\n                            <td class=\"edit\"></td>\n                            <td>\n                                <a class=\"btn btn-sm btn-warning mb-3\"\n                                target=\"_blank\"\n                                href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n                                    Report a bug\n                                    <i class=\"bi bi-bug\"></i>\n                                </a>\n                            </td>\n                        </tr>\n                    </table>\n                </div>\n            </div>\n        </nav>\n        <div class=\"row g-0\">\n            <div class=\"col-md-9 d-flex justify-content-center lh-sm\"\n                 data-bs-spy=\"scroll\"\n                 data-bs-target=\"#toc-nav\"\n                 data-bs-smooth-scroll=\"true\"\n                 tabindex=\"0\"\n                 id=\"content\">\n                \n                    <div class=\"rfchtml\">\n                        <br class=\"noprint\">\n                        <div class=\"xml2rfc\">\n<table class=\"ears\">\n<thead><tr>\n<td class=\"left\">Internet-Draft</td>\n<td class=\"center\">AI-Auth</td>\n<td class=\"right\">March 2026</td>\n</tr></thead>\n<tfoot><tr>\n<td class=\"left\">Kasselman, et al.</td>\n<td class=\"center\">Expires 3 September 2026</td>\n<td class=\"right\">[Page]</td>\n</tr></tfoot>\n</table>\n<div id=\"external-metadata\" class=\"document-information\"></div>\n<div id=\"internal-metadata\" class=\"document-information\">\n<dl id=\"identifiers\">\n<dt class=\"label-workgroup\">Workgroup:</dt>\n<dd class=\"workgroup\">Network Working Group</dd>\n<dt class=\"label-internet-draft\">Internet-Draft:</dt>\n<dd class=\"internet-draft\">draft-klrc-aiagent-auth-00</dd>\n<dt class=\"label-published\">Published:</dt>\n<dd class=\"published\">\n<time datetime=\"2026-03-02\" class=\"published\">2 March 2026</time>\n    </dd>\n<dt class=\"label-intended-status\">Intended Status:</dt>\n<dd class=\"intended-status\">Informational</dd>\n<dt class=\"label-expires\">Expires:</dt>\n<dd class=\"expires\"><time datetime=\"2026-09-03\">3 September 2026</time></dd>\n<dt class=\"label-authors\">Authors:</dt>\n<dd class=\"authors\">\n<div class=\"author\">\n      <div class=\"author-name\">P. Kasselman</div>\n<div class=\"org\">Defakto Security</div>\n</div>\n<div class=\"author\">\n      <div class=\"author-name\">J. Lombardo</div>\n<div class=\"org\">AWS</div>\n</div>\n<div class=\"author\">\n      <div class=\"author-name\">Y. Rosomakho</div>\n<div class=\"org\">Zscaler</div>\n</div>\n<div class=\"author\">\n      <div class=\"author-name\">B. Campbell</div>\n<div class=\"org\">Ping Identity</div>\n</div>\n</dd>\n</dl>\n</div>\n<h1 id=\"title\">AI Agent Authentication and Authorization</h1>\n<section id=\"section-abstract\">\n      <h2 id=\"abstract\"><a href=\"#abstract\" class=\"selfRef\">Abstract</a></h2>\n<p id=\"section-abstract-1\">This document proposes a model for authentication and authorization of AI agent interactions. It leverages existing standards such as the Workload Identity in Multi-System Environments (WIMSE) architecture and OAuth 2.0 family of specifications. Rather than defining new protocols, this document describes how existing and widely deployed standards can be applied or extended to establish agent authentication and authorization. By doing so, it aims to provide a framework within which to use existing standards, identify gaps and guide future standardization efforts for agent authentication and authorization.<a href=\"#section-abstract-1\" class=\"pilcrow\">¶</a></p>\n</section>\n<section class=\"note rfcEditorRemove\" id=\"section-note.1\">\n      <h2 id=\"name-about-this-document\">\n<a href=\"#name-about-this-document\" class=\"section-name selfRef\">About This Document</a>\n      </h2>\n<p id=\"section-note.1-1\">This note is to be removed before publishing as an RFC.<a href=\"#section-note.1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-note.1-2\">\n        The latest revision of this draft can be found at <span><a href=\"https://PieterKas.github.io/agent2agent-auth-framework/draft-klrc-aiagent-auth.html\">https://PieterKas.github.io/agent2agent-auth-framework/draft-klrc-aiagent-auth.html</a></span>.\n        Status information for this document may be found at <span><a href=\"https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/\">https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/</a></span>.<a href=\"#section-note.1-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-note.1-3\">Source for this draft and an issue tracker can be found at\n        <span><a href=\"https://github.com/PieterKas/agent2agent-auth-framework\">https://github.com/PieterKas/agent2agent-auth-framework</a></span>.<a href=\"#section-note.1-3\" class=\"pilcrow\">¶</a></p>\n</section>\n<div id=\"status-of-memo\">\n<section id=\"section-boilerplate.1\">\n        <h2 id=\"name-status-of-this-memo\">\n<a href=\"#name-status-of-this-memo\" class=\"section-name selfRef\">Status of This Memo</a>\n        </h2>\n<p id=\"section-boilerplate.1-1\">\n        This Internet-Draft is submitted in full conformance with the\n        provisions of BCP 78 and BCP 79.<a href=\"#section-boilerplate.1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.1-2\">\n        Internet-Drafts are working documents of the Internet Engineering Task\n        Force (IETF). Note that other groups may also distribute working\n        documents as Internet-Drafts. The list of current Internet-Drafts is\n        at <span><a href=\"https://datatracker.ietf.org/drafts/current/\">https://datatracker.ietf.org/drafts/current/</a></span>.<a href=\"#section-boilerplate.1-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.1-3\">\n        Internet-Drafts are draft documents valid for a maximum of six months\n        and may be updated, replaced, or obsoleted by other documents at any\n        time. It is inappropriate to use Internet-Drafts as reference\n        material or to cite them other than as \"work in progress.\"<a href=\"#section-boilerplate.1-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.1-4\">\n        This Internet-Draft will expire on 3 September 2026.<a href=\"#section-boilerplate.1-4\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"copyright\">\n<section id=\"section-boilerplate.2\">\n        <h2 id=\"name-copyright-notice\">\n<a href=\"#name-copyright-notice\" class=\"section-name selfRef\">Copyright Notice</a>\n        </h2>\n<p id=\"section-boilerplate.2-1\">\n            Copyright (c) 2026 IETF Trust and the persons identified as the\n            document authors. All rights reserved.<a href=\"#section-boilerplate.2-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.2-2\">\n            This document is subject to BCP 78 and the IETF Trust's Legal\n            Provisions Relating to IETF Documents\n            (<span><a href=\"https://trustee.ietf.org/license-info\">https://trustee.ietf.org/license-info</a></span>) in effect on the date of\n            publication of this document. Please review these documents\n            carefully, as they describe your rights and restrictions with\n            respect to this document. Code Components extracted from this\n            document must include Revised BSD License text as described in\n            Section 4.e of the Trust Legal Provisions and are provided without\n            warranty as described in the Revised BSD License.<a href=\"#section-boilerplate.2-2\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"toc\">\n<section id=\"section-toc.1\">\n        <a href=\"#\" onclick=\"scroll(0,0)\" class=\"toplink\">▲</a><h2 id=\"name-table-of-contents\">\n<a href=\"#name-table-of-contents\" class=\"section-name selfRef\">Table of Contents</a>\n        </h2>\n<nav class=\"toc\"><ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.1\">\n            <p id=\"section-toc.1-1.1.1\" class=\"keepWithNext\"><a href=\"#section-1\" class=\"auto internal xref\">1</a>.  <a href=\"#name-introduction\" class=\"internal xref\">Introduction</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.2\">\n            <p id=\"section-toc.1-1.2.1\" class=\"keepWithNext\"><a href=\"#section-2\" class=\"auto internal xref\">2</a>.  <a href=\"#name-conventions-and-definitions\" class=\"internal xref\">Conventions and Definitions</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.3\">\n            <p id=\"section-toc.1-1.3.1\" class=\"keepWithNext\"><a href=\"#section-3\" class=\"auto internal xref\">3</a>.  <a href=\"#name-agents-are-workloads\" class=\"internal xref\">Agents are workloads</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4\">\n            <p id=\"section-toc.1-1.4.1\"><a href=\"#section-4\" class=\"auto internal xref\">4</a>.  <a href=\"#name-agent-identity-management-s\" class=\"internal xref\">Agent Identity Management System</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.5\">\n            <p id=\"section-toc.1-1.5.1\"><a href=\"#section-5\" class=\"auto internal xref\">5</a>.  <a href=\"#name-agent-identifier\" class=\"internal xref\">Agent Identifier</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.6\">\n            <p id=\"section-toc.1-1.6.1\"><a href=\"#section-6\" class=\"auto internal xref\">6</a>.  <a href=\"#name-agent-credentials\" class=\"internal xref\">Agent Credentials</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.7\">\n            <p id=\"section-toc.1-1.7.1\"><a href=\"#section-7\" class=\"auto internal xref\">7</a>.  <a href=\"#name-agent-attestation\" class=\"internal xref\">Agent Attestation</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.8\">\n            <p id=\"section-toc.1-1.8.1\"><a href=\"#section-8\" class=\"auto internal xref\">8</a>.  <a href=\"#name-agent-credential-provisioni\" class=\"internal xref\">Agent Credential Provisioning</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9\">\n            <p id=\"section-toc.1-1.9.1\"><a href=\"#section-9\" class=\"auto internal xref\">9</a>.  <a href=\"#name-agent-authentication\" class=\"internal xref\">Agent Authentication</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9.2.1\">\n                <p id=\"section-toc.1-1.9.2.1.1\"><a href=\"#section-9.1\" class=\"auto internal xref\">9.1</a>.  <a href=\"#name-transport-layer-authenticat\" class=\"internal xref\">Transport Layer Authentication</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9.2.1.2.1\">\n                    <p id=\"section-toc.1-1.9.2.1.2.1.1\"><a href=\"#section-9.1.1\" class=\"auto internal xref\">9.1.1</a>.  <a href=\"#name-limitations\" class=\"internal xref\">Limitations</a></p>\n</li>\n                </ul>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9.2.2\">\n                <p id=\"section-toc.1-1.9.2.2.1\"><a href=\"#section-9.2\" class=\"auto internal xref\">9.2</a>.  <a href=\"#name-application-layer-authentic\" class=\"internal xref\">Application Layer Authentication</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9.2.2.2.1\">\n                    <p id=\"section-toc.1-1.9.2.2.2.1.1\"><a href=\"#section-9.2.1\" class=\"auto internal xref\">9.2.1</a>.  <a href=\"#name-wimse-proof-tokens-wpts\" class=\"internal xref\">WIMSE Proof Tokens (WPTs)</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9.2.2.2.2\">\n                    <p id=\"section-toc.1-1.9.2.2.2.2.1\"><a href=\"#section-9.2.2\" class=\"auto internal xref\">9.2.2</a>.  <a href=\"#name-http-message-signatures\" class=\"internal xref\">HTTP Message Signatures</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9.2.2.2.3\">\n                    <p id=\"section-toc.1-1.9.2.2.2.3.1\"><a href=\"#section-9.2.3\" class=\"auto internal xref\">9.2.3</a>.  <a href=\"#name-limitations-2\" class=\"internal xref\">Limitations</a></p>\n</li>\n                </ul>\n</li>\n            </ul>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10\">\n            <p id=\"section-toc.1-1.10.1\"><a href=\"#section-10\" class=\"auto internal xref\">10</a>. <a href=\"#name-agent-authorization\" class=\"internal xref\">Agent Authorization</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.1\">\n                <p id=\"section-toc.1-1.10.2.1.1\"><a href=\"#section-10.1\" class=\"auto internal xref\">10.1</a>.  <a href=\"#name-leverage-oauth-20-as-a-dele\" class=\"internal xref\">Leverage OAuth 2.0 as a Delegation Authorization Framework</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.2\">\n                <p id=\"section-toc.1-1.10.2.2.1\"><a href=\"#section-10.2\" class=\"auto internal xref\">10.2</a>.  <a href=\"#name-use-of-oauth-20-access-toke\" class=\"internal xref\">Use of OAuth 2.0 Access Tokens</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.3\">\n                <p id=\"section-toc.1-1.10.2.3.1\"><a href=\"#section-10.3\" class=\"auto internal xref\">10.3</a>.  <a href=\"#name-obtaining-an-oauth-20-acces\" class=\"internal xref\">Obtaining an OAuth 2.0 Access Token</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.3.2.1\">\n                    <p id=\"section-toc.1-1.10.2.3.2.1.1\"><a href=\"#section-10.3.1\" class=\"auto internal xref\">10.3.1</a>.  <a href=\"#name-user-delegates-authorizatio\" class=\"internal xref\">User Delegates Authorization</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.3.2.2\">\n                    <p id=\"section-toc.1-1.10.2.3.2.2.1\"><a href=\"#section-10.3.2\" class=\"auto internal xref\">10.3.2</a>.  <a href=\"#name-agent-obtains-own-authoriza\" class=\"internal xref\">Agent Obtains Own Authorization</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.3.2.3\">\n                    <p id=\"section-toc.1-1.10.2.3.2.3.1\"><a href=\"#section-10.3.3\" class=\"auto internal xref\">10.3.3</a>.  <a href=\"#name-agents-accessed-by-systems-\" class=\"internal xref\">Agents Accessed by Systems or Other Agents</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.3.2.4\">\n                    <p id=\"section-toc.1-1.10.2.3.2.4.1\"><a href=\"#section-10.3.4\" class=\"auto internal xref\">10.3.4</a>.  <a href=\"#name-oauth-20-security-best-prac\" class=\"internal xref\">OAuth 2.0 Security Best Practices</a></p>\n</li>\n                </ul>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.4\">\n                <p id=\"section-toc.1-1.10.2.4.1\"><a href=\"#section-10.4\" class=\"auto internal xref\">10.4</a>.  <a href=\"#name-risk-reduction-with-transac\" class=\"internal xref\">Risk Reduction with Transaction Tokens</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.5\">\n                <p id=\"section-toc.1-1.10.2.5.1\"><a href=\"#section-10.5\" class=\"auto internal xref\">10.5</a>.  <a href=\"#name-cross-domain-access\" class=\"internal xref\">Cross Domain Access</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.6\">\n                <p id=\"section-toc.1-1.10.2.6.1\"><a href=\"#section-10.6\" class=\"auto internal xref\">10.6</a>.  <a href=\"#name-human-in-the-loop\" class=\"internal xref\">Human in the Loop</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.7\">\n                <p id=\"section-toc.1-1.10.2.7.1\"><a href=\"#section-10.7\" class=\"auto internal xref\">10.7</a>.  <a href=\"#name-tool-to-service-access\" class=\"internal xref\">Tool-to-Service Access</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.8\">\n                <p id=\"section-toc.1-1.10.2.8.1\"><a href=\"#section-10.8\" class=\"auto internal xref\">10.8</a>.  <a href=\"#name-privacy-considerations-priv\" class=\"internal xref\">Privacy Considerations {privacy-considerations}</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.9\">\n                <p id=\"section-toc.1-1.10.2.9.1\"><a href=\"#section-10.9\" class=\"auto internal xref\">10.9</a>.  <a href=\"#name-oauth-20-discovery-in-dynam\" class=\"internal xref\">OAuth 2.0 Discovery in Dynamic Environments</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.9.2.1\">\n                    <p id=\"section-toc.1-1.10.2.9.2.1.1\"><a href=\"#section-10.9.1\" class=\"auto internal xref\">10.9.1</a>.  <a href=\"#name-authorization-server-capabi\" class=\"internal xref\">Authorization Server Capability Discovery</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.9.2.2\">\n                    <p id=\"section-toc.1-1.10.2.9.2.2.1\"><a href=\"#section-10.9.2\" class=\"auto internal xref\">10.9.2</a>.  <a href=\"#name-protected-resource-capabili\" class=\"internal xref\">Protected Resource Capability Discovery</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10.2.9.2.3\">\n                    <p id=\"section-toc.1-1.10.2.9.2.3.1\"><a href=\"#section-10.9.3\" class=\"auto internal xref\">10.9.3</a>.  <a href=\"#name-client-capability-discovery\" class=\"internal xref\">Client Capability Discovery</a></p>\n</li>\n                </ul>\n</li>\n            </ul>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.11\">\n            <p id=\"section-toc.1-1.11.1\"><a href=\"#section-11\" class=\"auto internal xref\">11</a>. <a href=\"#name-agent-monitoring-observabil\" class=\"internal xref\">Agent Monitoring, Observability and Remediation</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.12\">\n            <p id=\"section-toc.1-1.12.1\"><a href=\"#section-12\" class=\"auto internal xref\">12</a>. <a href=\"#name-agent-authentication-and-au\" class=\"internal xref\">Agent Authentication and Authorization Policy</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.13\">\n            <p id=\"section-toc.1-1.13.1\"><a href=\"#section-13\" class=\"auto internal xref\">13</a>. <a href=\"#name-agent-compliance\" class=\"internal xref\">Agent Compliance</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.14\">\n            <p id=\"section-toc.1-1.14.1\"><a href=\"#section-14\" class=\"auto internal xref\">14</a>. <a href=\"#name-security-considerations\" class=\"internal xref\">Security Considerations</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.15\">\n            <p id=\"section-toc.1-1.15.1\"><a href=\"#section-15\" class=\"auto internal xref\">15</a>. <a href=\"#name-privacy-considerations\" class=\"internal xref\">Privacy Considerations</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.16\">\n            <p id=\"section-toc.1-1.16.1\"><a href=\"#section-16\" class=\"auto internal xref\">16</a>. <a href=\"#name-iana-considerations\" class=\"internal xref\">IANA Considerations</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.17\">\n            <p id=\"section-toc.1-1.17.1\"><a href=\"#section-17\" class=\"auto internal xref\">17</a>. <a href=\"#name-normative-references\" class=\"internal xref\">Normative References</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.18\">\n            <p id=\"section-toc.1-1.18.1\"><a href=\"#appendix-A\" class=\"auto internal xref\">Appendix A</a>.  <a href=\"#name-acknowledgments\" class=\"internal xref\">Acknowledgments</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.19\">\n            <p id=\"section-toc.1-1.19.1\"><a href=\"#appendix-B\" class=\"auto internal xref\"></a><a href=\"#name-authors-addresses\" class=\"internal xref\">Authors' Addresses</a></p>\n</li>\n        </ul>\n</nav>\n</section>\n</div>\n<div id=\"introduction\">\n<section id=\"section-1\">\n      <h2 id=\"name-introduction\">\n<a href=\"#section-1\" class=\"section-number selfRef\">1. </a><a href=\"#name-introduction\" class=\"section-name selfRef\">Introduction</a>\n      </h2>\n<p id=\"section-1-1\">The rapid emergence of AI agents as autonomous workloads has sparked considerable innovation in authentication and authorization approaches. However, many of these efforts develop solutions in isolation, often reinventing existing mechanisms unaware of applicable prior art. This fragmentation risks creating incompatible implementations, duplicated development effort, and missed opportunities to leverage decades of established identity and authorization standards.<a href=\"#section-1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-1-2\">This document aims to help close that gap by providing a comprehensive model demonstrating how existing, well-established standards and some emergent specifications can be composed and applied to solve agent authentication and authorization challenges. Rather than proposing new protocols, this work focuses on integrating proven standards into a coherent framework tailored to the specific requirements of AI agent workloads.<a href=\"#section-1-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-1-3\">By doing so, this document serves two complementary goals:<a href=\"#section-1-3\" class=\"pilcrow\">¶</a></p>\n<ol start=\"1\" type=\"1\" class=\"normal type-1\" id=\"section-1-4\">\n<li id=\"section-1-4.1\">\n          <p id=\"section-1-4.1.1\"><strong>Consolidation of prior art</strong>: It establishes a baseline by showing how existing standards address the core identity, authentication, authorization, monitoring and observability needs of agent-based systems. Implementers and standards developers can reference this framework to avoid redundant work and ensure interoperability.<a href=\"#section-1-4.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-1-4.2\">\n          <p id=\"section-1-4.2.1\"><strong>Foundation for future work</strong>: As the agent ecosystem matures, having such a framework aids in identifying gaps and clarifies where extensions or profiles of existing standards are needed. This provides a foundation for more focused standardization efforts in areas needing novel work rather than variations of existing approaches.<a href=\"#section-1-4.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ol>\n</section>\n</div>\n<div id=\"conventions-and-definitions\">\n<section id=\"section-2\">\n      <h2 id=\"name-conventions-and-definitions\">\n<a href=\"#section-2\" class=\"section-number selfRef\">2. </a><a href=\"#name-conventions-and-definitions\" class=\"section-name selfRef\">Conventions and Definitions</a>\n      </h2>\n<p id=\"section-2-1\">The key words \"<span class=\"bcp14\">MUST</span>\", \"<span class=\"bcp14\">MUST NOT</span>\", \"<span class=\"bcp14\">REQUIRED</span>\", \"<span class=\"bcp14\">SHALL</span>\", \"<span class=\"bcp14\">SHALL NOT</span>\", \"<span class=\"bcp14\">SHOULD</span>\", \"<span class=\"bcp14\">SHOULD NOT</span>\", \"<span class=\"bcp14\">RECOMMENDED</span>\", \"<span class=\"bcp14\">NOT RECOMMENDED</span>\",\n\"<span class=\"bcp14\">MAY</span>\", and \"<span class=\"bcp14\">OPTIONAL</span>\" in this document are to be interpreted as\ndescribed in BCP 14 <span>[<a href=\"#RFC2119\" class=\"cite xref\">RFC2119</a>]</span> <span>[<a href=\"#RFC8174\" class=\"cite xref\">RFC8174</a>]</span> when, and only when, they\nappear in all capitals, as shown here.<a href=\"#section-2-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agents-are-workloads\">\n<section id=\"section-3\">\n      <h2 id=\"name-agents-are-workloads\">\n<a href=\"#section-3\" class=\"section-number selfRef\">3. </a><a href=\"#name-agents-are-workloads\" class=\"section-name selfRef\">Agents are workloads</a>\n      </h2>\n<p id=\"section-3-1\">An Agent is a workload that iteratively interacts with a Large Language Model (LLM) and a set of Tools, Services and Resources. An agent performs its operations until a terminating condition, determined either by the LLM or by the agent's internal logic, is reached. It may receive input from a user, or act autonomously. <a href=\"#fig-ai-agent-workload\" class=\"auto internal xref\">Figure 1</a> shows a conceptual model of the AI Agent as a workload and illustrates the high-level interaction model between the User or System, the AI Agent, the Large Language Model (LLM), Tools, Services, and Resources.<a href=\"#section-3-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-3-2\">In this document, Tools, Services, and Resources are treated as a single category of external endpoints that an agent invokes or interacts with to complete a task. Communication within or between Tools, Services, and Resources is out of scope.<a href=\"#section-3-2\" class=\"pilcrow\">¶</a></p>\n<span id=\"name-ai-agent-as-a-workload\"></span><div id=\"fig-ai-agent-workload\">\n<figure id=\"figure-1\">\n        <div id=\"section-3-3.1\">\n          <div class=\"alignLeft art-svg artwork\" id=\"section-3-3.1.1\">\n<svg xmlns=\"http://www.w3.org/2000/svg\" version=\"1.1\" height=\"224\" width=\"416\" viewbox=\"0 0 416 224\" class=\"diagram\" text-anchor=\"middle\" font-family=\"monospace\" font-size=\"13px\" stroke-linecap=\"round\">\n              <path d=\"M 8,144 L 8,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 80,144 L 80,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 136,32 L 136,80\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 144,144 L 144,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 248,144 L 248,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 272,32 L 272,80\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 312,144 L 312,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 408,144 L 408,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 136,32 L 272,32\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 136,80 L 272,80\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 8,144 L 80,144\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 144,144 L 248,144\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 312,144 L 408,144\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 8,208 L 80,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 144,208 L 248,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 312,208 L 408,208\" fill=\"none\" stroke=\"black\"></path>\n              <g class=\"text\">\n                <text x=\"168\" y=\"52\">Large</text>\n                <text x=\"228\" y=\"52\">Language</text>\n                <text x=\"184\" y=\"68\">Model</text>\n                <text x=\"232\" y=\"68\">(LLM)</text>\n                <text x=\"184\" y=\"100\">▲</text>\n                <text x=\"216\" y=\"100\">|</text>\n                <text x=\"184\" y=\"116\">(2)</text>\n                <text x=\"216\" y=\"116\">(3)</text>\n                <text x=\"184\" y=\"132\">|</text>\n                <text x=\"216\" y=\"132\">▼</text>\n                <text x=\"44\" y=\"164\">User</text>\n                <text x=\"112\" y=\"164\">──(1)─►</text>\n                <text x=\"172\" y=\"164\">AI</text>\n                <text x=\"208\" y=\"164\">Agent</text>\n                <text x=\"280\" y=\"164\">──(4)─►</text>\n                <text x=\"360\" y=\"164\">Tools</text>\n                <text x=\"44\" y=\"180\">or</text>\n                <text x=\"196\" y=\"180\">(workload)</text>\n                <text x=\"356\" y=\"180\">Services</text>\n                <text x=\"44\" y=\"196\">System</text>\n                <text x=\"112\" y=\"196\">◄─(6)──</text>\n                <text x=\"280\" y=\"196\">◄─(5)──</text>\n                <text x=\"360\" y=\"196\">Resources</text>\n              </g>\n            </svg><a href=\"#section-3-3.1.1\" class=\"pilcrow\">¶</a>\n</div>\n</div>\n<figcaption><a href=\"#figure-1\" class=\"selfRef\">Figure 1</a>:\n<a href=\"#name-ai-agent-as-a-workload\" class=\"selfRef\">AI Agent as a Workload</a>\n        </figcaption></figure>\n</div>\n<ol start=\"1\" type=\"1\" class=\"normal type-1\" id=\"section-3-4\">\n<li id=\"section-3-4.1\">\n          <p id=\"section-3-4.1.1\">Optional: The User or System (e.g. a batch job or another Agent) provides an initial request or instruction to the AI Agent.<a href=\"#section-3-4.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-3-4.2\">\n          <p id=\"section-3-4.2.1\">The AI Agent provides the available context to the LLM. Context is implementation, and deployment, specific and may include User or System input, system prompts, Tool descriptions, prior Tool, Service and Resource outputs, and other relevant state.<a href=\"#section-3-4.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-3-4.3\">\n          <p id=\"section-3-4.3.1\">The LLM returns output to the AI Agent facilitating selection of Tools, Services or Resources to invoke.<a href=\"#section-3-4.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-3-4.4\">\n          <p id=\"section-3-4.4.1\">The AI Agent invokes one or more external endpoints of selected Tools, Services or Resources. A Tool endpoint may itself be implemented by another AI agent.<a href=\"#section-3-4.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-3-4.5\">\n          <p id=\"section-3-4.5.1\">The external endpoint of the Tools, Services or Resources returns a result of the operation to the AI Agent, which may send the information as additional context to the Large Language Model, repeating steps 2-5 until the exit condition is reached and the task is completed.<a href=\"#section-3-4.5.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-3-4.6\">\n          <p id=\"section-3-4.6.1\">Optional: Once the exit condition is reached in step 5, the AI Agent may return a response to the User or System. The AI Agent may also return intermediate results or request additional input.<a href=\"#section-3-4.6.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ol>\n<p id=\"section-3-5\">As shown in <a href=\"#fig-ai-agent-workload\" class=\"auto internal xref\">Figure 1</a>, the AI agent is a workload that needs an identifier and credentials so it can be authenticated by the Tools, Services, Resources, Large Language Model, System and the User (via the underlying operating system or platform, similar to existing applications and services). Once authenticated, these parties determine if the AI Agent is authorized to access the requested Large Language Model, Tools, Services or Resources. If the AI Agent is acting on behalf of a User or System, the User or System needs to delegate authority to the AI Agent, and the User or System context is preserved and used as input to authorization decisions and recorded in audit trails.<a href=\"#section-3-5\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-3-6\">This document describes how AI Agents should leverage existing standards defined by SPIFFE <span>[<a href=\"#SPIFFE\" class=\"cite xref\">SPIFFE</a>]</span>, WIMSE, OAuth and OpenID SSF <span>[<a href=\"#SSF\" class=\"cite xref\">SSF</a>]</span>.<a href=\"#section-3-6\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent-identity-management-system\">\n<section id=\"section-4\">\n      <h2 id=\"name-agent-identity-management-s\">\n<a href=\"#section-4\" class=\"section-number selfRef\">4. </a><a href=\"#name-agent-identity-management-s\" class=\"section-name selfRef\">Agent Identity Management System</a>\n      </h2>\n<p id=\"section-4-1\">This document defines the term Agent Identity Management System (AIMS) as a conceptual model describing the set of functions required to establish, maintain, and evaluate the identity and permissions of an agent workload. AIMS does not refer to a single product, protocol, or deployment architecture. AIMS may be implemented by one component or distributed across multiple systems (such as identity providers, attestation services, authorization servers, policy engines, and runtime enforcement points).<a href=\"#section-4-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4-2\">An Agent Identity Management System ensures that the right Agent has access to the right resources and tools at the right time for the right reason. An Agent identity management system depends on the following components to achieve its goals:<a href=\"#section-4-2\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-4-3.1\">\n          <p id=\"section-4-3.1.1\"><strong>Agent Identifiers:</strong> Unique identifier assigned to every Agent.<a href=\"#section-4-3.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.2\">\n          <p id=\"section-4-3.2.1\"><strong>Agent Credentials:</strong> Cryptographic binding between the Agent Identifier and attributes of the Agent.<a href=\"#section-4-3.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.3\">\n          <p id=\"section-4-3.3.1\"><strong>Agent Attestation:</strong> Mechanisms for determining and assigning the identifier and issue credentials based on measurements of the Agent's environment.<a href=\"#section-4-3.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.4\">\n          <p id=\"section-4-3.4.1\"><strong>Agent Credential Provisioning:</strong> The mechanism for provisioning credentials to the agent at runtime.<a href=\"#section-4-3.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.5\">\n          <p id=\"section-4-3.5.1\"><strong>Agent Authentication:</strong> Protocols and mechanisms used by the Agent to authenticate itself to Large Language Models or Tools (resource or server) in the system.<a href=\"#section-4-3.5.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.6\">\n          <p id=\"section-4-3.6.1\"><strong>Agent Authorization:</strong> Protocols and systems used to determine if an Agent is allowed to access a Large Language Model or Tool (resource or server).<a href=\"#section-4-3.6.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.7\">\n          <p id=\"section-4-3.7.1\"><strong>Agent Observability and Remediation:</strong> Protocols and mechanisms to dynamically modify the authorization decisions based on observed behavior and system state.<a href=\"#section-4-3.7.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.8\">\n          <p id=\"section-4-3.8.1\"><strong>Agent Authentication and Authorization Policy:</strong> The configuration and rules for each of the Agent Identity Management System.<a href=\"#section-4-3.8.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-4-3.9\">\n          <p id=\"section-4-3.9.1\"><strong>Agent Compliance:</strong> Measurement of the state and functioning of the system against the stated policies.<a href=\"#section-4-3.9.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ul>\n<p id=\"section-4-4\">The components form a logical stack in which higher layers depend on guarantees provided by lower layers, as illustrated in <a href=\"#fig-agent-identity-management-system\" class=\"auto internal xref\">Figure 2</a>.<a href=\"#section-4-4\" class=\"pilcrow\">¶</a></p>\n<span id=\"name-agent-identity-management-sy\"></span><div id=\"fig-agent-identity-management-system\">\n<figure id=\"figure-2\">\n        <div id=\"section-4-5.1\">\n          <div class=\"alignLeft art-svg artwork\" id=\"section-4-5.1.1\">\n<svg xmlns=\"http://www.w3.org/2000/svg\" version=\"1.1\" height=\"288\" width=\"560\" viewbox=\"0 0 560 288\" class=\"diagram\" text-anchor=\"middle\" font-family=\"monospace\" font-size=\"13px\" stroke-linecap=\"round\">\n              <path d=\"M 8,32 L 8,272\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 128,32 L 128,272\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 408,32 L 408,272\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 552,32 L 552,272\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 8,32 L 552,32\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 128,80 L 408,80\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 128,112 L 408,112\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 128,144 L 408,144\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 128,176 L 408,176\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 128,208 L 408,208\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 128,240 L 408,240\" fill=\"none\" stroke=\"black\"></path>\n              <path d=\"M 8,272 L 552,272\" fill=\"none\" stroke=\"black\"></path>\n              <g class=\"text\">\n                <text x=\"68\" y=\"52\">Policy</text>\n                <text x=\"216\" y=\"52\">Monitoring,</text>\n                <text x=\"320\" y=\"52\">Observability</text>\n                <text x=\"484\" y=\"52\">Compliance</text>\n                <text x=\"216\" y=\"68\">&amp;</text>\n                <text x=\"272\" y=\"68\">Remediation</text>\n                <text x=\"264\" y=\"100\">Authorization</text>\n                <text x=\"268\" y=\"132\">Authentication</text>\n                <text x=\"260\" y=\"164\">Provisioning</text>\n                <text x=\"264\" y=\"196\">Attestation</text>\n                <text x=\"264\" y=\"228\">Credentials</text>\n                <text x=\"260\" y=\"260\">Identifier</text>\n              </g>\n            </svg><a href=\"#section-4-5.1.1\" class=\"pilcrow\">¶</a>\n</div>\n</div>\n<figcaption><a href=\"#figure-2\" class=\"selfRef\">Figure 2</a>:\n<a href=\"#name-agent-identity-management-sy\" class=\"selfRef\">Agent Identity Management System</a>\n        </figcaption></figure>\n</div>\n</section>\n</div>\n<div id=\"agent_identifiers\">\n<section id=\"section-5\">\n      <h2 id=\"name-agent-identifier\">\n<a href=\"#section-5\" class=\"section-number selfRef\">5. </a><a href=\"#name-agent-identifier\" class=\"section-name selfRef\">Agent Identifier</a>\n      </h2>\n<p id=\"section-5-1\">Agents <span class=\"bcp14\">MUST</span> be uniquely identified in order to support authentication, authorization, auditing, and delegation.<a href=\"#section-5-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5-2\">The Workload Identity in Multi-System Environments (WIMSE) identifier as defined by <span>[<a href=\"#WIMSE-ID\" class=\"cite xref\">WIMSE-ID</a>]</span> is the primary identifier for agents in this framework.<a href=\"#section-5-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5-3\">A WIMSE identifier is a URI that uniquely identifies a workload within a trust domain. Authorization decisions, delegation semantics, and audit records rely on this identifier remaining stable for the lifetime of the workload identity.<a href=\"#section-5-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5-4\">The Secure Production Identity Framework for Everyone (<span>[<a href=\"#SPIFFE\" class=\"cite xref\">SPIFFE</a>]</span>) identifier is a widely deployed and operationally mature implementation of the WIMSE identifier model. A SPIFFE identifier (<span>[<a href=\"#SPIFFE-ID\" class=\"cite xref\">SPIFFE-ID</a>]</span>) is a URI in the form of <code>spiffe://&lt;trust-domain&gt;/&lt;path&gt;</code> that uniquely identifies a workload within a trust domain.<a href=\"#section-5-4\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5-5\">An agent participating in this framework <span class=\"bcp14\">MUST</span> be assigned exactly one WIMSE identifier, which <span class=\"bcp14\">MAY</span> be a SPIFFE ID.<a href=\"#section-5-5\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent_credentials\">\n<section id=\"section-6\">\n      <h2 id=\"name-agent-credentials\">\n<a href=\"#section-6\" class=\"section-number selfRef\">6. </a><a href=\"#name-agent-credentials\" class=\"section-name selfRef\">Agent Credentials</a>\n      </h2>\n<p id=\"section-6-1\">Agents <span class=\"bcp14\">MUST</span> possess credentials that provide a cryptographic binding to the agent identifier. These credentials are considered primary credentials that are provisioned at runtime. An identifier alone is insufficient unless it can be verified to be controlled by the communicating agent through a cryptographic binding.<a href=\"#section-6-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-2\">WIMSE credentials (<span>[<a href=\"#WIMSE-CRED\" class=\"cite xref\">WIMSE-CRED</a>]</span>) are defined as a profile of X.509 certificates and Workload Identity Tokens (WITs), while SPIFFE defines SPIFFE Verified ID (SVID) profiles of JSON Web Token (JWT-SVID), X.509 certificates (X.509-SVID) and WIMSE Workload Identity Tokens (WIT-SVID). SPIFFE SVID credentials are compatible with WIMSE defined credentials. The choice of an appropriate format depends on the trust model and integration requirements.<a href=\"#section-6-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-3\">Agent credentials <span class=\"bcp14\">SHOULD</span> be short-lived to minimize the risk of credential theft, <span class=\"bcp14\">MUST</span> include an explicit expiration time after which it is no longer accepted, and <span class=\"bcp14\">MAY</span> carry additional attributes relevant to the agent (for example trust domain, attestation evidence, or workload metadata).<a href=\"#section-6-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-4\">Deployments can improve the assurance of agent identity by protecting private keys using hardware-backed or isolated cryptographic storage such as TPMs, secure enclaves, or platform security modules when such capabilities are available. These mechanisms reduce key exfiltration risk but are not required for interoperability.<a href=\"#section-6-4\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-5\">In some cases, agents <span class=\"bcp14\">MAY</span> need secondary credentials to access a proprietary or legacy environment that is not compatible with the X.509, JWT or WIT it is provisioned with. In these cases an agent <span class=\"bcp14\">MAY</span> exchange their primary credentials through a credential exchange mechanisms (e.g., OAuth 2.0 Token Exchange <span>[<a href=\"#OAUTH-TOKEN-EXCHANGE\" class=\"cite xref\">OAUTH-TOKEN-EXCHANGE</a>]</span>, Transaction Tokens <span>[<a href=\"#OAUTH-TXN-TOKENS\" class=\"cite xref\">OAUTH-TXN-TOKENS</a>]</span> or Workload Identity Federation). This allows an agent to obtain a credential targeted to a specific environment by leveraging the primary credential in its possession.<a href=\"#section-6-5\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-6\"><strong>Note</strong>: Static API keys are an antipattern for agent identity. They are bearer artifacts that are not cryptographically bound, do not convey identity, are typically long-lived and are operationally difficult to rotate, making them unsuitable for secure agent authentication or authorization.<a href=\"#section-6-6\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent_attestation\">\n<section id=\"section-7\">\n      <h2 id=\"name-agent-attestation\">\n<a href=\"#section-7\" class=\"section-number selfRef\">7. </a><a href=\"#name-agent-attestation\" class=\"section-name selfRef\">Agent Attestation</a>\n      </h2>\n<p id=\"section-7-1\">Agent attestation is the identity-proofing mechanism for AI agents. Just as humans rely on identity proofing during account creation or credential issuance, agents require a means to demonstrate what they are, how they were instantiated, and under what conditions they are operating. Attestation evidence feeds into the credential issuance process and determines whether a credential is issued, the type of credential issued and the contents of the credential.<a href=\"#section-7-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-7-2\">Multiple attestation mechanisms exist, and the appropriate choice is deployment and risk specific. These mechanisms may include hardware-based attestations (e.g., TEE evidence), software integrity measurements, supply-chain provenance, platform and orchestration-layer attestations, or operator assertions to name a few. Depending on the risk involved, a single attestation may be sufficient, or, in higher risk scenarios, multi-attestation may be required.<a href=\"#section-7-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-7-3\">There are numerous systems that perform some form of attestation, any of which can contribute to establishing agent identity. For example, SPIFFE implementations can attest workloads using platform and environment specific mechanisms. At a high level, an attesting component gathers workload and execution context signals (such as where the workload is running and relevant platform identity attributes), presents those signals for verification to an issuer, and, as long as verification succeeds, binds the workload to a SPIFFE identifier and issues credentials (such as SVID) for subsequent authentication and authorization.<a href=\"#section-7-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-7-4\">An agent identity management system may incorporate multiple attestation mechanisms and implementations to collect evidence and supply it to credential provisioning components. The selection of mechanisms depends on deployment constraints (such as the underlying platform and available identity signals) and the desired level of trust assurance.<a href=\"#section-7-4\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent_credential_provisioning\">\n<section id=\"section-8\">\n      <h2 id=\"name-agent-credential-provisioni\">\n<a href=\"#section-8\" class=\"section-number selfRef\">8. </a><a href=\"#name-agent-credential-provisioni\" class=\"section-name selfRef\">Agent Credential Provisioning</a>\n      </h2>\n<p id=\"section-8-1\">Agent credential provisioning refers to the runtime issuance, renewal, lifecycle state and rotation of the credentials an agent uses to authenticate and authorize itself to other agents. Agents may be provisioned with one or more credential types as described in <a href=\"#agent_credentials\" class=\"auto internal xref\">Section 6</a>. Unlike static secrets, agent credentials are provisioned dynamically and are intentionally short-lived, eliminating the operational burden of manual expiration management and reducing the impact of credential compromise. Agent credential provisioning must operate autonomously, scale to high-churn environments, and integrate closely with the attestation mechanisms that establish trust in the agent at each issuance or rotation event.<a href=\"#section-8-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-8-2\">Agent credential provisioning typically includes two phases:<a href=\"#section-8-2\" class=\"pilcrow\">¶</a></p>\n<ol start=\"1\" type=\"1\" class=\"normal type-1\" id=\"section-8-3\">\n<li id=\"section-8-3.1\">\n          <p id=\"section-8-3.1.1\"><strong>Initial Provisioning</strong>: The process by which an agent first acquires a credential bound to its identity. This often occurs immediately after deployment or instantiation and is based on verified properties of the agent (e.g., deployment context, attestation evidence, or orchestration metadata).<a href=\"#section-8-3.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-8-3.2\">\n          <p id=\"section-8-3.2.1\"><strong>Rotation/Renewal</strong>: The automatic refresh of short-lived credentials before expiration. Continuous rotation ensures that credentials remain valid only for the minimum necessary time and that authorization state reflects current operational conditions.<a href=\"#section-8-3.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ol>\n<p id=\"section-8-4\">The use of short-lived credentials provides a significant improvement in the risk profile and risk of credential exposure. It provides an alternative to explicit revocation mechanisms and simplifies lifecycle management in large, automated environments while removing the risks of downtime as a result of credential expiry.<a href=\"#section-8-4\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-8-5\">Deployed frameworks such as <span>[<a href=\"#SPIFFE\" class=\"cite xref\">SPIFFE</a>]</span> provide proven mechanisms for automated, short-lived credential provisioning at runtime. In addition to issuing short-lived credentials, <span>[<a href=\"#SPIFFE\" class=\"cite xref\">SPIFFE</a>]</span> also provisions ephemeral cryptographic key material bound to each credential, further reducing the risks associated with compromising long-lived keys.<a href=\"#section-8-5\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent_authentication\">\n<section id=\"section-9\">\n      <h2 id=\"name-agent-authentication\">\n<a href=\"#section-9\" class=\"section-number selfRef\">9. </a><a href=\"#name-agent-authentication\" class=\"section-name selfRef\">Agent Authentication</a>\n      </h2>\n<p id=\"section-9-1\">Agents may authenticate using a variety of mechanisms, depending on the credentials they possess, the protocols supported in the deployment environment, and the risk profile of the application. As described in the WIMSE Architecture <span>[<a href=\"#WIMSE-ARCH\" class=\"cite xref\">WIMSE-ARCH</a>]</span>, authentication can occur at either the transport layer or the application layer, and many deployments rely on a combination of both.<a href=\"#section-9-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"transport-layer-authentication\">\n<section id=\"section-9.1\">\n        <h3 id=\"name-transport-layer-authenticat\">\n<a href=\"#section-9.1\" class=\"section-number selfRef\">9.1. </a><a href=\"#name-transport-layer-authenticat\" class=\"section-name selfRef\">Transport Layer Authentication</a>\n        </h3>\n<p id=\"section-9.1-1\">Transport-layer authentication establishes trust during the establishment of a secure transport channel. The most common mechanism used by agents is mutually-authenticated TLS (mTLS), in which both endpoints present X.509-based credentials and perform a bidirectional certificate exchange as part of the TLS negotiation. When paired with short-lived workload identities, such as those issued by SPIFFE or WIMSE, mTLS provides strong channel binding and cryptographic proof of control over the agent’s private key.<a href=\"#section-9.1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-9.1-2\">mTLS is particularly well-suited for environments where transport-level protection, peer authentication, and ephemeral workload identity are jointly required. It also simplifies authorization decisions by enabling agents to associate application-layer requests with an authenticated transport identity. One example of this is the use of mTLS in service mesh architectures such as Istio or LinkerD.<a href=\"#section-9.1-2\" class=\"pilcrow\">¶</a></p>\n<div id=\"limitations\">\n<section id=\"section-9.1.1\">\n          <h4 id=\"name-limitations\">\n<a href=\"#section-9.1.1\" class=\"section-number selfRef\">9.1.1. </a><a href=\"#name-limitations\" class=\"section-name selfRef\">Limitations</a>\n          </h4>\n<p id=\"section-9.1.1-1\">There are scenarios where transport-layer authentication is not desirable or cannot be relied upon. In architectures involving intermediaries, such as proxies, API gateways, service meshes, load balancers, or protocol translators, TLS sessions are often terminated and re-established, breaking the end-to-end continuity of transport-layer identity. Similarly, some deployment models (such as serverless platforms, multi-tenant edge environments, or cross-domain topologies) may obscure or abstract identity presented at the transport layer, making it difficult to bind application-layer actions to a credential presented at the transport layer. In these cases, application-layer authentication provides a more robust and portable mechanism for expressing agent identity and conveying attestation or policy-relevant attributes.<a href=\"#section-9.1.1-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n</section>\n</div>\n<div id=\"application-layer-authentication\">\n<section id=\"section-9.2\">\n        <h3 id=\"name-application-layer-authentic\">\n<a href=\"#section-9.2\" class=\"section-number selfRef\">9.2. </a><a href=\"#name-application-layer-authentic\" class=\"section-name selfRef\">Application Layer Authentication</a>\n        </h3>\n<p id=\"section-9.2-1\">Application-layer authentication allows agents to authenticate independently of the underlying transport. This enables end-to-end identity preservation even when requests traverse proxies, load balancers, or protocol translation layers.<a href=\"#section-9.2-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-9.2-2\">The WIMSE working group defines WIMSE Proof Tokens and HTTP Message Signatures as authentication mechanisms that may be used by agents.<a href=\"#section-9.2-2\" class=\"pilcrow\">¶</a></p>\n<div id=\"wpt\">\n<section id=\"section-9.2.1\">\n          <h4 id=\"name-wimse-proof-tokens-wpts\">\n<a href=\"#section-9.2.1\" class=\"section-number selfRef\">9.2.1. </a><a href=\"#name-wimse-proof-tokens-wpts\" class=\"section-name selfRef\">WIMSE Proof Tokens (WPTs)</a>\n          </h4>\n<p id=\"section-9.2.1-1\">WIMSE Workload Proof Tokens (WPTs, <span>[<a href=\"#WIMSE-WPT\" class=\"cite xref\">WIMSE-WPT</a>]</span>) are a protocol-independent, application-layer mechanism for proving possession of the private key associated with a Workload Identity Token (WIT). WPTs are generated by the agent, using the private key matching the public key in the WIT. A WPT is defined as a signed JSON Web Token (JWT) that binds an agent’s authentication to a specific message context, for example, an HTTP request, thereby providing proof of possession rather than relying on bearer semantics.<a href=\"#section-9.2.1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-9.2.1-2\">WPTs are designed to work alongside WITs <span>[<a href=\"#WIMSE-CRED\" class=\"cite xref\">WIMSE-CRED</a>]</span> and are typically short-lived to reduce the window for replay attacks. They carry claims such as audience (aud), expiration (exp), a unique token identifier (jti), and a hash of the associated WIT (wth). A WPT may also include hashes of other related tokens (e.g., a Transaction Token) to bind the authentication contexts to specific transaction or authorizations details.<a href=\"#section-9.2.1-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-9.2.1-3\">Although the draft currently defines a protocol binding for HTTP (via a Workload-Proof-Token header), the core format is protocol-agnostic, making it applicable to other protocols. Its JWT structure and claims model allow WPTs to be bound to different protocols and transports, including asynchronous or non-HTTP messaging systems such as Kafka and gRPC, or other future protocol bindings. This design enables receiving systems to verify identity, key possession, and message binding at the application layer even in environments where transport-layer identity (e.g., mutual TLS) is insufficient or unavailable.<a href=\"#section-9.2.1-3\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"http-message-signatures\">\n<section id=\"section-9.2.2\">\n          <h4 id=\"name-http-message-signatures\">\n<a href=\"#section-9.2.2\" class=\"section-number selfRef\">9.2.2. </a><a href=\"#name-http-message-signatures\" class=\"section-name selfRef\">HTTP Message Signatures</a>\n          </h4>\n<p id=\"section-9.2.2-1\">The WIMSE Workload-to-Workload Authentication with HTTP Signatures specification <span>[<a href=\"#WIMSE-HTTPSIG\" class=\"cite xref\">WIMSE-HTTPSIG</a>]</span> defines an application-layer authentication profile built on the HTTP Message Signatures standard <span>[<a href=\"#HTTP-SIG\" class=\"cite xref\">HTTP-SIG</a>]</span>. It is one of the mechanisms WIMSE defines for authenticating workloads in HTTP-based interactions where transport-layer protections may be insufficient or unavailable. The protocol combines a workload's Workload Identity Token (WIT) (which binds the agent's identity to a public key) with HTTP Message Signatures (using the corresponding private key), thereby providing proof of possession and message integrity for individual HTTP requests and responses. This approach ensures end-to-end authentication and integrity even when traffic traverses intermediaries such as TLS proxies or load balancers that break transport-layer identity continuity. The profile mandates signing of some request components (e.g., method, request-target (which likely cover what you'd expect), content digest, and the WIT itself) and supports optional response signing.<a href=\"#section-9.2.2-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"limitations-1\">\n<section id=\"section-9.2.3\">\n          <h4 id=\"name-limitations-2\">\n<a href=\"#section-9.2.3\" class=\"section-number selfRef\">9.2.3. </a><a href=\"#name-limitations-2\" class=\"section-name selfRef\">Limitations</a>\n          </h4>\n<p id=\"section-9.2.3-1\">Unlike transport-layer authentication, application-layer authentication does not inherently provide channel binding to the underlying secure transport. As a result, implementations <span class=\"bcp14\">MUST</span> consider the risk of message relay or replay if tokens or signed messages are accepted outside their intended context. Deployments typically mitigate these risks through short token lifetimes, audience restrictions, nonce or unique identifier checks, and binding authentication to specific requests or transaction parameters.<a href=\"#section-9.2.3-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n</section>\n</div>\n</section>\n</div>\n<div id=\"agent_authorization\">\n<section id=\"section-10\">\n      <h2 id=\"name-agent-authorization\">\n<a href=\"#section-10\" class=\"section-number selfRef\">10. </a><a href=\"#name-agent-authorization\" class=\"section-name selfRef\">Agent Authorization</a>\n      </h2>\n<p id=\"section-10-1\">Agents act on behalf of a user, a system, or on their own behalf as shown in <a href=\"#fig-ai-agent-workload\" class=\"auto internal xref\">Figure 1</a> and need to obtain authorization when interacting with protected resources.<a href=\"#section-10-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"leverage-oauth-20-as-a-delegation-authorization-framework\">\n<section id=\"section-10.1\">\n        <h3 id=\"name-leverage-oauth-20-as-a-dele\">\n<a href=\"#section-10.1\" class=\"section-number selfRef\">10.1. </a><a href=\"#name-leverage-oauth-20-as-a-dele\" class=\"section-name selfRef\">Leverage OAuth 2.0 as a Delegation Authorization Framework</a>\n        </h3>\n<p id=\"section-10.1-1\">The widely deployed OAuth 2.0 Authorization Framework <span>[<a href=\"#OAUTH-FRAMEWORK\" class=\"cite xref\">OAUTH-FRAMEWORK</a>]</span> is a mechanism for delegated authorization that enables an Agent to obtain limited access to a protected resource (e.g., a service or API), intermediated by an Authorization Server, often with the explicit approval of the authenticated User. An Agent uses OAuth 2.0-based mechanisms to obtain authorization from a User, a System, or on its own behalf. OAuth 2.0 defines a wide range of authorization grant flows that supports these scenarios. In these Oauth 2.0 flows, an Agent acts as an OAuth 2.0 Client to an OAuth 2.0 Authorization Server, which receives the request, evaluate the authorization policy and returns an access token, which the Agent presents to the Resource Server (i.e. the protected resources such as the LLM or Tools in <a href=\"#fig-ai-agent-workload\" class=\"auto internal xref\">Figure 1</a>, which can evaluate its authorization policy and complete the request.<a href=\"#section-10.1-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"use-of-oauth-20-access-tokens\">\n<section id=\"section-10.2\">\n        <h3 id=\"name-use-of-oauth-20-access-toke\">\n<a href=\"#section-10.2\" class=\"section-number selfRef\">10.2. </a><a href=\"#name-use-of-oauth-20-access-toke\" class=\"section-name selfRef\">Use of OAuth 2.0 Access Tokens</a>\n        </h3>\n<p id=\"section-10.2-1\">An OAuth access token represents the authorization granted to the Agent. In many deployments, access tokens are structured as JSON Web Tokens (JWTs) <span>[<a href=\"#OAUTH-ACCESSTOKEN-JWT\" class=\"cite xref\">OAUTH-ACCESSTOKEN-JWT</a>]</span>, which include claims such as 'client_id', 'sub', 'aud', 'scope', and other attributes relevant to authorization. The access token includes the Agent identity as the 'client_id' claim as defined in <span><a href=\"https://rfc-editor.org/rfc/rfc9068#section-2.2\" class=\"relref\">Section 2.2</a> of [<a href=\"#OAUTH-ACCESSTOKEN-JWT\" class=\"cite xref\">OAUTH-ACCESSTOKEN-JWT</a>]</span>.<a href=\"#section-10.2-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.2-2\">When the Agent is acting on-behalf of another User or System, the User or System identifier is conveyed in the 'sub' claim as defined in <span><a href=\"https://rfc-editor.org/rfc/rfc9068#section-2.2\" class=\"relref\">Section 2.2</a> of [<a href=\"#OAUTH-ACCESSTOKEN-JWT\" class=\"cite xref\">OAUTH-ACCESSTOKEN-JWT</a>]</span>. These identifiers <span class=\"bcp14\">MUST</span> be used by resource servers protected by the OAuth 2.0 authorization service, along with other claims in the access token, to determine if access to a resource should be allowed. The access token typically includes additional claims to convey contextual, attestation-derived, or policy-related information that enables fine-grained access control. The resource server uses the access token and the information it contains along with other authorization systems (e.g. policy based, attribute based or role based authorization systems) when enforcing access control. JWT access tokens can be validated directly by resource servers while other formats that are opaque to the resource server can be validated through a mechanism that calls back to the authorization server (the mechanism is called introspection despite the word having nearly the opposite meaning). This framework supports both models and does not require a specific token format, provided that equivalent authorization semantics are maintained.<a href=\"#section-10.2-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.2-3\">A resource server in receipt of tokens opaque to it are able to obtain authorization and other information from the token through OAuth 2.0 Token Introspection <span>[<a href=\"#OAUTH-TOKEN-INTROSPECTION\" class=\"cite xref\">OAUTH-TOKEN-INTROSPECTION</a>]</span>. The introspection response provides the active state of the token and associated authorization attributes equivalent to those conveyed in structured tokens.<a href=\"#section-10.2-3\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"obtaining-an-oauth-20-access-token\">\n<section id=\"section-10.3\">\n        <h3 id=\"name-obtaining-an-oauth-20-acces\">\n<a href=\"#section-10.3\" class=\"section-number selfRef\">10.3. </a><a href=\"#name-obtaining-an-oauth-20-acces\" class=\"section-name selfRef\">Obtaining an OAuth 2.0 Access Token</a>\n        </h3>\n<p id=\"section-10.3-1\">OAuth 2.0 defines a number authorization grant flows in support of different authorization scenarios. The appropriate flow depends on the specific authorization scenario and the nature of User involvement. The following subsections describe the most relevant flows for Agent authorization.<a href=\"#section-10.3-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"user-delegates-authorization\">\n<section id=\"section-10.3.1\">\n          <h4 id=\"name-user-delegates-authorizatio\">\n<a href=\"#section-10.3.1\" class=\"section-number selfRef\">10.3.1. </a><a href=\"#name-user-delegates-authorizatio\" class=\"section-name selfRef\">User Delegates Authorization</a>\n          </h4>\n<p id=\"section-10.3.1-1\">When a User grants authorization to an Agent for access to one or more resources (Tools, LLMs, etc.), the Authorization Code Grant, as described in <span><a href=\"https://rfc-editor.org/rfc/rfc6749#section-4.1\" class=\"relref\">Section 4.1</a> of [<a href=\"#OAUTH-FRAMEWORK\" class=\"cite xref\">OAUTH-FRAMEWORK</a>]</span>, is the canonical means of obtaining an access token. This redirection-based flow involves an interactive authorization process in which the user authenticates to the authorization server and explicitly approves the requested access. The resulting access token reflects the authorization delegated to the Agent by the User and can be used by the Agent to access resources on behalf of the user.<a href=\"#section-10.3.1-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent_obtains_own_access_token\">\n<section id=\"section-10.3.2\">\n          <h4 id=\"name-agent-obtains-own-authoriza\">\n<a href=\"#section-10.3.2\" class=\"section-number selfRef\">10.3.2. </a><a href=\"#name-agent-obtains-own-authoriza\" class=\"section-name selfRef\">Agent Obtains Own Authorization</a>\n          </h4>\n<p id=\"section-10.3.2-1\">Agents obtaining access tokens on their own behalf can use the Client Credentials Grant as described in <span><a href=\"https://rfc-editor.org/rfc/rfc6749#section-4.4\" class=\"relref\">Section 4.4</a> of [<a href=\"#OAUTH-FRAMEWORK\" class=\"cite xref\">OAUTH-FRAMEWORK</a>]</span> or the JWT Authorization Grant as described in <span><a href=\"https://rfc-editor.org/rfc/rfc7523#section-2.1\" class=\"relref\">Section 2.1</a> of [<a href=\"#OAUTH-CLIENTAUTH-JWT\" class=\"cite xref\">OAUTH-CLIENTAUTH-JWT</a>]</span>. When using the Client Credentials Grant, the Agent authenticates itself using one of the mechanisms described in <a href=\"#agent_authentication\" class=\"auto internal xref\">Section 9</a> and not with the use of static, long-lived client secrets. When using the JWT Authorization Grant, the Agent will be identified in the subject of the JWT assertion.<a href=\"#section-10.3.2-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agents-accessed-by-systems-or-other-agents\">\n<section id=\"section-10.3.3\">\n          <h4 id=\"name-agents-accessed-by-systems-\">\n<a href=\"#section-10.3.3\" class=\"section-number selfRef\">10.3.3. </a><a href=\"#name-agents-accessed-by-systems-\" class=\"section-name selfRef\">Agents Accessed by Systems or Other Agents</a>\n          </h4>\n<p id=\"section-10.3.3-1\">Agents themselves can act in the role of an OAuth protected resource and be invoked by a System (e.g. a batch job) or another Agent. The System obtains an access token using an appropriate mechanism and then invokes the Agent presenting the access token.<a href=\"#section-10.3.3-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"oauth-20-security-best-practices\">\n<section id=\"section-10.3.4\">\n          <h4 id=\"name-oauth-20-security-best-prac\">\n<a href=\"#section-10.3.4\" class=\"section-number selfRef\">10.3.4. </a><a href=\"#name-oauth-20-security-best-prac\" class=\"section-name selfRef\">OAuth 2.0 Security Best Practices</a>\n          </h4>\n<p id=\"section-10.3.4-1\">The Best Current Practice for OAuth 2.0 Security as described in <span>[<a href=\"#OAUTH-BCP\" class=\"cite xref\">OAUTH-BCP</a>]</span> are applicable when requesting and using access tokens.<a href=\"#section-10.3.4-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n</section>\n</div>\n<div id=\"txn-tokens-risk-reduction\">\n<section id=\"section-10.4\">\n        <h3 id=\"name-risk-reduction-with-transac\">\n<a href=\"#section-10.4\" class=\"section-number selfRef\">10.4. </a><a href=\"#name-risk-reduction-with-transac\" class=\"section-name selfRef\">Risk Reduction with Transaction Tokens</a>\n        </h3>\n<p id=\"section-10.4-1\">Resources servers, whether they are LLMs, Tools or Agents (in the Agent-to-Agent case) may be composed of multiple microservices that are invoked to complete a request. The access tokens presented to the Agent, LLM or Tools can typically be used with multiple transactions and consequently have broader scope than needed to complete any specific transaction. Passing the access token from one microservice to another within an invoked Agent, LLM or the Tools increases the risk of token theft and replay attacks. For example, an attacker may discover and access token passed between microservices in a log file or crash dump, exfiltrate it, and use it to invoke a new transaction with different parameters (e.g. increase the transaction amount, or invoke an unrelated call as part of executing a lateral move).<a href=\"#section-10.4-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.4-2\">To avoid passing access tokens between microservices, the Agent, LLM or Tools can exchange the received access token for a transaction token, as defined in the Transaction Token specification <span>[<a href=\"#OAUTH-TXN-TOKENS\" class=\"cite xref\">OAUTH-TXN-TOKENS</a>]</span>. The transaction token allows for identity and authorization information to be passed along the internal call chain of microservices. The transaction token issuer enriches the transaction token with context of the caller that presented the access token (e.g. IP address, etc.), transaction context (transaction amount), identity information and a unique transaction identifier. This results in a downscoped token that is bound to a specific transaction and cannot be used as an access token, with another transaction, or within the same transaction with modified transaction details (e.g. change in transaction amount). Transaction tokens are typically short-lived, further limiting the risk in case they are obtained by an attacker by limiting the time window during which these tokens will be accepted.<a href=\"#section-10.4-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.4-3\">A transaction token <span class=\"bcp14\">MAY</span> be used to obtain an access token to call another service (e.g. another Agent, Tool or LLM) by using OAuth 2.0 Token Exchange as defined in <span>[<a href=\"#OAUTH-TOKEN-EXCHANGE\" class=\"cite xref\">OAUTH-TOKEN-EXCHANGE</a>]</span>.<a href=\"#section-10.4-3\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"cross-domain-access\">\n<section id=\"section-10.5\">\n        <h3 id=\"name-cross-domain-access\">\n<a href=\"#section-10.5\" class=\"section-number selfRef\">10.5. </a><a href=\"#name-cross-domain-access\" class=\"section-name selfRef\">Cross Domain Access</a>\n        </h3>\n<p id=\"section-10.5-1\">Agents often require access to resources that are protected by different OAuth 2.0 authorization servers. When the components in <a href=\"#fig-ai-agent-workload\" class=\"auto internal xref\">Figure 1</a> are protected by different logical authorization servers, an Agent <span class=\"bcp14\">SHOULD</span> use OAuth Identity and Authorization Chaining Across Domains as defined in (<span>[<a href=\"#OAUTH-ID-CHAIN\" class=\"cite xref\">OAUTH-ID-CHAIN</a>]</span>), or a derived specification such as the Identity Assertion JWT Authorization Grant <span>[<a href=\"#OAUTH-JWT-ASSERTION\" class=\"cite xref\">OAUTH-JWT-ASSERTION</a>]</span>, to obtain an access token from the relevant authorization servers.<a href=\"#section-10.5-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.5-2\">When using OAuth Identity and Authorization Chaining Across Domains (<span>[<a href=\"#OAUTH-ID-CHAIN\" class=\"cite xref\">OAUTH-ID-CHAIN</a>]</span>), an Agent <span class=\"bcp14\">SHOULD</span> use the access token or transaction token it received to obtain a JWT authorization grant as described in <span><a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-chaining-08#section-2.3\" class=\"relref\">Section 2.3</a> of [<a href=\"#OAUTH-ID-CHAIN\" class=\"cite xref\">OAUTH-ID-CHAIN</a>]</span> and then use the JWT authorization grant it receives to obtain an access token for the resource it is trying to access as defined in <span><a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-chaining-08#section-2.4\" class=\"relref\">Section 2.4</a> of [<a href=\"#OAUTH-ID-CHAIN\" class=\"cite xref\">OAUTH-ID-CHAIN</a>]</span>.<a href=\"#section-10.5-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.5-3\">When using the Identity Assertion JWT Authorization Grant <span>[<a href=\"#OAUTH-JWT-ASSERTION\" class=\"cite xref\">OAUTH-JWT-ASSERTION</a>]</span>, the identity assertion (e.g. the OpenID Connect ID Token or SAML assertion) for the target end-user is used to obtain a JWT assertion as described in <span><a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-assertion-authz-grant-01#section-4.3\" class=\"relref\">Section 4.3</a> of [<a href=\"#OAUTH-JWT-ASSERTION\" class=\"cite xref\">OAUTH-JWT-ASSERTION</a>]</span>, which is then used to obtain an access token as described in <span><a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-assertion-authz-grant-01#section-4.4\" class=\"relref\">Section 4.4</a> of [<a href=\"#OAUTH-JWT-ASSERTION\" class=\"cite xref\">OAUTH-JWT-ASSERTION</a>]</span>.<a href=\"#section-10.5-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.5-4\">OAuth Identity and Authorization Chaining Across Domains (<span>[<a href=\"#OAUTH-ID-CHAIN\" class=\"cite xref\">OAUTH-ID-CHAIN</a>]</span>) provides a general mechanism for obtaining cross-domain access that can be used whether an identity assertion like a SAML or OpenID Connect token is available or not. The Identity Assertion JWT Authorization Grant <span>[<a href=\"#OAUTH-JWT-ASSERTION\" class=\"cite xref\">OAUTH-JWT-ASSERTION</a>]</span> is optimized for cases where an identity assertion like a SAML or OpenID Connect token is available from an identity provider that is trusted by all the OAuth authorization servers as it removes the need for the user to re-authenticate. This is typically used within enterprise deployments to simplify authorization delegation for multiple software-as-a-service offerings.<a href=\"#section-10.5-4\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"human-in-the-loop\">\n<section id=\"section-10.6\">\n        <h3 id=\"name-human-in-the-loop\">\n<a href=\"#section-10.6\" class=\"section-number selfRef\">10.6. </a><a href=\"#name-human-in-the-loop\" class=\"section-name selfRef\">Human in the Loop</a>\n        </h3>\n<p id=\"section-10.6-1\">An OAuth authorization server <span class=\"bcp14\">MAY</span> conclude that the level of access requested by an Agent requires explicit user confirmation. In such cases the authorization server <span class=\"bcp14\">SHOULD</span> either decline the request or obtain additional authorization from the User. An Agent, acting as an OAuth client, may use the OpenID Client Initiated Backchannel Authentication (CIBA) protocol. This triggers an out-of-band interaction allowing the user to approve or deny the requested operation without exposing credentials to the agent (for example a push notification requesting the user to approve a request through an authenticator application on their mobile device).<a href=\"#section-10.6-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.6-2\">Interactive agent frameworks may also solicit user confirmation directly during task execution (for example tool invocation approval or parameter confirmation). Such interactions do not by themselves constitute authorization and <span class=\"bcp14\">MUST</span> be bound to a verifiable authorization grant issued by the authorization server. The agent <span class=\"bcp14\">SHOULD</span> therefore translate user confirmation into an OAuth authorization event (e.g., step-up authorization via CIBA) before accessing protected resources.<a href=\"#section-10.6-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.6-3\">This model aligns with user-solicitation patterns such as those described by the Model Context Protocol (<span>[<a href=\"#MCP\" class=\"cite xref\">MCP</a>]</span>), where an agent pauses execution and requests user confirmation before performing sensitive actions. The final authorization decision remains with the authorization server, and the agent <span class=\"bcp14\">MUST NOT</span> treat local UI confirmation alone as sufficient authorization.<a href=\"#section-10.6-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.6-4\"><strong>Note:</strong> Additional specification or design work may be needed to define how out-of-band interactions with the User occur at different stages of execution. CIBA itself only accounts for client initiation, which doesn't map well to cases that envision the need for User confirmation to occur mid-execution.<a href=\"#section-10.6-4\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"tool-to-service-access\">\n<section id=\"section-10.7\">\n        <h3 id=\"name-tool-to-service-access\">\n<a href=\"#section-10.7\" class=\"section-number selfRef\">10.7. </a><a href=\"#name-tool-to-service-access\" class=\"section-name selfRef\">Tool-to-Service Access</a>\n        </h3>\n<p id=\"section-10.7-1\">Tools expose interfaces to underlying services and resources. Access to the Tools can be controlled by OAuth and augmented by policy, attribute or role based authorization systems (amongst others). If the Tools are implemented as one or more microservices, it should use transaction tokens to reduce risk as described in <a href=\"#txn-tokens-risk-reduction\" class=\"auto internal xref\">Section 10.4</a> to avoid passing access tokens around within the Tool implementation.<a href=\"#section-10.7-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.7-2\">Access from the Tools to the resources and services <span class=\"bcp14\">MAY</span> be controlled through a variety of authorization mechanisms, including OAuth. If access is controlled through OAuth, the Tools can use OAuth 2.0 Token Exchange as defined in <span>[<a href=\"#OAUTH-TOKEN-EXCHANGE\" class=\"cite xref\">OAUTH-TOKEN-EXCHANGE</a>]</span> to exchange the access token it received for a new access token to access the resource or service in question. When the Tool needs access to a resource protected by an authorization server other than the Tool's own authorization server, the OAuth Identity and Authorization Chaining Across Domains (<span>[<a href=\"#OAUTH-ID-CHAIN\" class=\"cite xref\">OAUTH-ID-CHAIN</a>]</span>) can be used to obtain an access token from the authorization server protecting that resource.<a href=\"#section-10.7-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.7-3\"><strong>Note:</strong> It is an anti-pattern for Tools to forward access tokens it received from the Agent to Services or Resources. It increases the risk of credential theft and lateral attacks.<a href=\"#section-10.7-3\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"privacy-considerations-privacy-considerations\">\n<section id=\"section-10.8\">\n        <h3 id=\"name-privacy-considerations-priv\">\n<a href=\"#section-10.8\" class=\"section-number selfRef\">10.8. </a><a href=\"#name-privacy-considerations-priv\" class=\"section-name selfRef\">Privacy Considerations {privacy-considerations}</a>\n        </h3>\n<p id=\"section-10.8-1\">Authorization tokens may contain user identifiers, agent identifiers, audience restrictions, transaction details, and contextual attributes. Deployments <span class=\"bcp14\">SHOULD</span> minimize disclosure of personally identifiable or sensitive information in tokens and prefer audience-restricted and short-lived tokens. Where possible, opaque tokens with introspection <span class=\"bcp14\">SHOULD</span> be preferred when claim minimization is required.<a href=\"#section-10.8-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.8-2\">Agents <span class=\"bcp14\">SHOULD</span> request only the minimum scopes and authorization details necessary to complete a task. Resource servers <span class=\"bcp14\">SHOULD</span> avoid logging full tokens and instead log token identifiers or hashes. When authorization context is propagated across services, derived or down-scoped tokens (such as transaction tokens) <span class=\"bcp14\">SHOULD</span> be used to reduce correlation and replay risk.<a href=\"#section-10.8-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.8-3\">Implementations <span class=\"bcp14\">MUST</span> ensure that user identity information delegated to agents is not exposed to unrelated services and that cross-domain authorization exchanges only disclose information required for the target authorization decision.<a href=\"#section-10.8-3\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"oauth-20-discovery-in-dynamic-environments\">\n<section id=\"section-10.9\">\n        <h3 id=\"name-oauth-20-discovery-in-dynam\">\n<a href=\"#section-10.9\" class=\"section-number selfRef\">10.9. </a><a href=\"#name-oauth-20-discovery-in-dynam\" class=\"section-name selfRef\">OAuth 2.0 Discovery in Dynamic Environments</a>\n        </h3>\n<p id=\"section-10.9-1\">In dynamic Agent deployments (e.g., ephemeral workloads, multi-tenant services, and frequently changing endpoint topology), Agents and other participants <span class=\"bcp14\">MAY</span> use OAuth discovery mechanisms to reduce static configuration and to bind runtime decisions to verifiable metadata.<a href=\"#section-10.9-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"authorization-server-capability-discovery\">\n<section id=\"section-10.9.1\">\n          <h4 id=\"name-authorization-server-capabi\">\n<a href=\"#section-10.9.1\" class=\"section-number selfRef\">10.9.1. </a><a href=\"#name-authorization-server-capabi\" class=\"section-name selfRef\">Authorization Server Capability Discovery</a>\n          </h4>\n<p id=\"section-10.9.1-1\">An Agent that needs to obtain tokens can discover authorization server endpoints and capabilities using OAuth 2.0 Authorization Server Metadata <span>[<a href=\"#OAUTH-SERVER-METADATA\" class=\"cite xref\">OAUTH-SERVER-METADATA</a>]</span> and/or OpenID Connect Discovery <span>[<a href=\"#OpenIDConnect.Discovery\" class=\"cite xref\">OpenIDConnect.Discovery</a>]</span>. This allows the Agent to learn the authorization server issuer identifier, authorization and token endpoints, supported grant types, client authentication methods, signing keys (via jwks_uri), and other relevant capabilities without preconfiguring them.<a href=\"#section-10.9.1-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"protected-resource-capability-discovery\">\n<section id=\"section-10.9.2\">\n          <h4 id=\"name-protected-resource-capabili\">\n<a href=\"#section-10.9.2\" class=\"section-number selfRef\">10.9.2. </a><a href=\"#name-protected-resource-capabili\" class=\"section-name selfRef\">Protected Resource Capability Discovery</a>\n          </h4>\n<p id=\"section-10.9.2-1\">When an Agent is invoking a Tool, the Agent <span class=\"bcp14\">MAY</span> use OAuth 2.0 Protected Resource Metadata <span>[<a href=\"#OAUTH-RESOURCE-METADATA\" class=\"cite xref\">OAUTH-RESOURCE-METADATA</a>]</span> to discover how the resource is protected, including the resource identifier and the applicable Authorization Server(s) that protects Tool access. This enables an Agent to select the correct issuer/audience and token acquisition flow at runtime, even when resources are deployed or moved dynamically.<a href=\"#section-10.9.2-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.9.2-2\">A Tool that attempts to access and OAuth protected resource <span class=\"bcp14\">MAY</span> use OAuth 2.0 Protected Resource Metadata <span>[<a href=\"#OAUTH-RESOURCE-METADATA\" class=\"cite xref\">OAUTH-RESOURCE-METADATA</a>]</span> in a similar way as an Agent. Similarly, a System may use <span>[<a href=\"#OAUTH-RESOURCE-METADATA\" class=\"cite xref\">OAUTH-RESOURCE-METADATA</a>]</span> when accessing an Agent.<a href=\"#section-10.9.2-2\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"client-capability-discovery\">\n<section id=\"section-10.9.3\">\n          <h4 id=\"name-client-capability-discovery\">\n<a href=\"#section-10.9.3\" class=\"section-number selfRef\">10.9.3. </a><a href=\"#name-client-capability-discovery\" class=\"section-name selfRef\">Client Capability Discovery</a>\n          </h4>\n<p id=\"section-10.9.3-1\">Other actors (e.g., Authorization Servers, registrars, or policy systems) may need to learn about any entities (System, Agent, Tool) that acts as OAuth clients. Where supported, they <span class=\"bcp14\">MAY</span> use Client ID Metadata Documents <span>[<a href=\"#OAUTH-CLIENT-METADATA\" class=\"cite xref\">OAUTH-CLIENT-METADATA</a>]</span>, which allow a client to host its metadata at a URL-valued client_id so that the relying party can retrieve client properties (e.g., redirect URIs, display information, and other registered client metadata) without prior bilateral registration.<a href=\"#section-10.9.3-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-10.9.3-2\">As an alternative, entities acting as OAuth clients <span class=\"bcp14\">MAY</span> register their capabilities with authorization servers as defined in the OAuth 2.0 Dynamic Client Registration Protocol <span>[<a href=\"#OAUTH-REGISTRATION\" class=\"cite xref\">OAUTH-REGISTRATION</a>]</span>.<a href=\"#section-10.9.3-2\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n</section>\n</div>\n</section>\n</div>\n<div id=\"agent_monitoring_and_remediation\">\n<section id=\"section-11\">\n      <h2 id=\"name-agent-monitoring-observabil\">\n<a href=\"#section-11\" class=\"section-number selfRef\">11. </a><a href=\"#name-agent-monitoring-observabil\" class=\"section-name selfRef\">Agent Monitoring, Observability and Remediation</a>\n      </h2>\n<p id=\"section-11-1\">Because agents may perform sensitive actions autonomously or on behalf of users, deployments <span class=\"bcp14\">MUST</span> maintain sufficient monitoring and observability to reconstruct agent behavior and authorization context after execution. Observability is therefore a security control, not solely an operational feature.<a href=\"#section-11-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-11-2\">Any participant in the system, including the Agent, Tool, System, LLM or other resources and service <span class=\"bcp14\">MAY</span> subscribe to change notifications using eventing mechanisms such as the OpenID Shared Signals Framework <span>[<a href=\"#SSF\" class=\"cite xref\">SSF</a>]</span> with either the Continuous Access Evaluation Profile <span>[<a href=\"#CAEP\" class=\"cite xref\">CAEP</a>]</span> or Risk Incident Sharing and Coordination <span>[<a href=\"#RISC\" class=\"cite xref\">RISC</a>]</span> to receive security and authorization-relevant signals. Upon receipt of a relevant signal (e.g., session revoked, risk level change, subject disabled, token replay suspected, risk elevated), the recipient <span class=\"bcp14\">SHOULD</span> remediate by attenuating access, such as terminating local sessions, discarding cached tokens, re-acquiring tokens with updated constraints, reducing privileges, or re-running policy evaluation before continuing to allow access. Recipients of such signals <span class=\"bcp14\">MUST</span> ensure that revoked or downgraded authorization is enforced without undue delay. Cached authorization decisions and tokens that are no longer valid <span class=\"bcp14\">MUST NOT</span> continue to be used after a revocation or risk notification is received.<a href=\"#section-11-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-11-3\">To support detection, investigation, and accountability, deployments <span class=\"bcp14\">MUST</span> produce durable audit logs covering authorization decisions and subsequent remediations. Audit records <span class=\"bcp14\">MUST</span> be tamper-evident and retained according to the security policy of the deployment.<a href=\"#section-11-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-11-4\">At a minimum, audit events <span class=\"bcp14\">MUST</span> record:<a href=\"#section-11-4\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-11-5.1\">\n          <p id=\"section-11-5.1.1\">authenticated agent identifier<a href=\"#section-11-5.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-11-5.2\">\n          <p id=\"section-11-5.2.1\">delegated subject (user or system), when present<a href=\"#section-11-5.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-11-5.3\">\n          <p id=\"section-11-5.3.1\">resource or tool being accessed<a href=\"#section-11-5.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-11-5.4\">\n          <p id=\"section-11-5.4.1\">action requested and authorization decision<a href=\"#section-11-5.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-11-5.5\">\n          <p id=\"section-11-5.5.1\">timestamp and transaction or request correlation identifier<a href=\"#section-11-5.5.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-11-5.6\">\n          <p id=\"section-11-5.6.1\">attestation or risk state influencing the decision<a href=\"#section-11-5.6.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-11-5.7\">\n          <p id=\"section-11-5.7.1\">remediation or revocation events and their cause<a href=\"#section-11-5.7.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ul>\n<p id=\"section-11-6\">Monitoring / Observability systems <span class=\"bcp14\">SHOULD</span> correlate events across Agents, Tools, Services, Resources and LLMs to detect misuse patterns such as replay, confused deputy behavior, privilege escalation, or unexpected action sequences.<a href=\"#section-11-6\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-11-7\">End-to-end audit is enabled when Agents, Users, Systems, LLMs, Tools, services and resources have stable, verifiable identifiers that allow auditors to trace \"which entity did what, using which authorization context, and why access changed over time.\"<a href=\"#section-11-7\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-11-8\">Implementations <span class=\"bcp14\">SHOULD</span> provide operators the ability to reconstruct a complete execution chain of an agent task, including delegated authority, intermediate calls, and resulting actions across service boundaries.<a href=\"#section-11-8\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent_auhtentication_and_authorization_policy\">\n<section id=\"section-12\">\n      <h2 id=\"name-agent-authentication-and-au\">\n<a href=\"#section-12\" class=\"section-number selfRef\">12. </a><a href=\"#name-agent-authentication-and-au\" class=\"section-name selfRef\">Agent Authentication and Authorization Policy</a>\n      </h2>\n<p id=\"section-12-1\">The configuration and runtime parameters for Agent Identifiers <a href=\"#agent_identifiers\" class=\"auto internal xref\">Section 5</a>, Agent Credentials <a href=\"#agent_credentials\" class=\"auto internal xref\">Section 6</a>, Agent Attestation <a href=\"#agent_attestation\" class=\"auto internal xref\">Section 7</a>, Agent Credential Provisioning <a href=\"#agent_credential_provisioning\" class=\"auto internal xref\">Section 8</a>, Agent Authentication <a href=\"#agent_authentication\" class=\"auto internal xref\">Section 9</a>, Agent Authorization <a href=\"#agent_authorization\" class=\"auto internal xref\">Section 10</a> and Agent Monitoring, Observability and Remediation <a href=\"#agent_monitoring_and_remediation\" class=\"auto internal xref\">Section 11</a> collectively constitute the authentication and authorization policy within which the Agent operates.<a href=\"#section-12-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-12-2\">Because these parameters are highly deployment and risk-model-specific (and often reflect local governance, regulatory, and operational constraints), the policy model and document format are out of scope for this framework and are not recommended as a target for standardization within this specification. Implementations <span class=\"bcp14\">MAY</span> represent policy in any suitable “policy-as-code” or configuration format (e.g., JSON/YAML), provided it is versioned, reviewable, and supports consistent evaluation across the components participating in the end-to-end flow.<a href=\"#section-12-2\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent_compliance\">\n<section id=\"section-13\">\n      <h2 id=\"name-agent-compliance\">\n<a href=\"#section-13\" class=\"section-number selfRef\">13. </a><a href=\"#name-agent-compliance\" class=\"section-name selfRef\">Agent Compliance</a>\n      </h2>\n<p id=\"section-13-1\">Compliance for Agent-based systems <span class=\"bcp14\">SHOULD</span> be assessed by auditing observed behavior and recorded evidence (logs, signals, and authorization decisions) against the deployment’s Agent Authentication and Authorization Policy <a href=\"#agent_auhtentication_and_authorization_policy\" class=\"auto internal xref\">Section 12</a>. Since compliance criteria are specific to individual deployments, organizations, industries and jurisdictions, they are out of scope for this framework though implementers <span class=\"bcp14\">SHOULD</span> ensure strong observability and accountable governance, subject to their specific business needs.<a href=\"#section-13-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"security-considerations\">\n<section id=\"section-14\">\n      <h2 id=\"name-security-considerations\">\n<a href=\"#section-14\" class=\"section-number selfRef\">14. </a><a href=\"#name-security-considerations\" class=\"section-name selfRef\">Security Considerations</a>\n      </h2>\n<p id=\"section-14-1\">TODO Security<a href=\"#section-14-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"privacy-considerations\">\n<section id=\"section-15\">\n      <h2 id=\"name-privacy-considerations\">\n<a href=\"#section-15\" class=\"section-number selfRef\">15. </a><a href=\"#name-privacy-considerations\" class=\"section-name selfRef\">Privacy Considerations</a>\n      </h2>\n<p id=\"section-15-1\">TODO Privacy but there's also <a href=\"#privacy-considerations\" class=\"auto internal xref\">Section 15</a>...<a href=\"#section-15-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"iana-considerations\">\n<section id=\"section-16\">\n      <h2 id=\"name-iana-considerations\">\n<a href=\"#section-16\" class=\"section-number selfRef\">16. </a><a href=\"#name-iana-considerations\" class=\"section-name selfRef\">IANA Considerations</a>\n      </h2>\n<p id=\"section-16-1\">This document has no IANA actions.<a href=\"#section-16-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"sec-normative-references\">\n<section id=\"section-17\">\n      <h2 id=\"name-normative-references\">\n<a href=\"#section-17\" class=\"section-number selfRef\">17. </a><a href=\"#name-normative-references\" class=\"section-name selfRef\">Normative References</a>\n      </h2>\n<dl class=\"references\">\n<dt id=\"A2A\">[A2A]</dt>\n      <dd>\n<span class=\"refTitle\">\"Agent2Agent (A2A) Protocol\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://github.com/a2aproject/A2A\">https://github.com/a2aproject/A2A</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"ACP\">[ACP]</dt>\n      <dd>\n<span class=\"refTitle\">\"Agentic Commerce Protocol\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://www.agenticcommerce.dev/docs\">https://www.agenticcommerce.dev/docs</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"AP2\">[AP2]</dt>\n      <dd>\n<span class=\"refTitle\">\"Agent Payments Protocol (AP2)\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://github.com/google-agentic-commerce/AP2\">https://github.com/google-agentic-commerce/AP2</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"CAEP\">[CAEP]</dt>\n      <dd>\n<span class=\"refTitle\">\"OpenID Continuous Access Evaluation Profile 1.0\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://openid.net/specs/openid-caep-1_0-final.html\">https://openid.net/specs/openid-caep-1_0-final.html</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"HTTP-SIG\">[HTTP-SIG]</dt>\n      <dd>\n<span class=\"refAuthor\">Backman, A., Ed.</span>, <span class=\"refAuthor\">Richer, J., Ed.</span>, and <span class=\"refAuthor\">M. Sporny</span>, <span class=\"refTitle\">\"HTTP Message Signatures\"</span>, <span class=\"seriesInfo\">RFC 9421</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC9421</span>, <time datetime=\"2024-02\" class=\"refDate\">February 2024</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc9421\">https://www.rfc-editor.org/rfc/rfc9421</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"MCP\">[MCP]</dt>\n      <dd>\n<span class=\"refTitle\">\"Model Context Protocol\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://modelcontextprotocol.io/specification\">https://modelcontextprotocol.io/specification</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-ACCESSTOKEN-JWT\">[OAUTH-ACCESSTOKEN-JWT]</dt>\n      <dd>\n<span class=\"refAuthor\">Bertocci, V.</span>, <span class=\"refTitle\">\"JSON Web Token (JWT) Profile for OAuth 2.0 Access Tokens\"</span>, <span class=\"seriesInfo\">RFC 9068</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC9068</span>, <time datetime=\"2021-10\" class=\"refDate\">October 2021</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc9068\">https://www.rfc-editor.org/rfc/rfc9068</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-BCP\">[OAUTH-BCP]</dt>\n      <dd>\n<span class=\"refAuthor\">Lodderstedt, T.</span>, <span class=\"refAuthor\">Bradley, J.</span>, <span class=\"refAuthor\">Labunets, A.</span>, and <span class=\"refAuthor\">D. Fett</span>, <span class=\"refTitle\">\"Best Current Practice for OAuth 2.0 Security\"</span>, <span class=\"seriesInfo\">BCP 240</span>, <span class=\"seriesInfo\">RFC 9700</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC9700</span>, <time datetime=\"2025-01\" class=\"refDate\">January 2025</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc9700\">https://www.rfc-editor.org/rfc/rfc9700</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-CLIENT-METADATA\">[OAUTH-CLIENT-METADATA]</dt>\n      <dd>\n<span class=\"refAuthor\">Parecki, A.</span> and <span class=\"refAuthor\">E. Smith</span>, <span class=\"refTitle\">\"OAuth Client ID Metadata Document\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-oauth-client-id-metadata-document-01</span>, <time datetime=\"2026-03-01\" class=\"refDate\">1 March 2026</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-client-id-metadata-document-01\">https://datatracker.ietf.org/doc/html/draft-ietf-oauth-client-id-metadata-document-01</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-CLIENTAUTH-JWT\">[OAUTH-CLIENTAUTH-JWT]</dt>\n      <dd>\n<span class=\"refAuthor\">Jones, M.</span>, <span class=\"refAuthor\">Campbell, B.</span>, and <span class=\"refAuthor\">C. Mortimore</span>, <span class=\"refTitle\">\"JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization Grants\"</span>, <span class=\"seriesInfo\">RFC 7523</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC7523</span>, <time datetime=\"2015-05\" class=\"refDate\">May 2015</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc7523\">https://www.rfc-editor.org/rfc/rfc7523</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-FRAMEWORK\">[OAUTH-FRAMEWORK]</dt>\n      <dd>\n<span class=\"refAuthor\">Hardt, D., Ed.</span>, <span class=\"refTitle\">\"The OAuth 2.0 Authorization Framework\"</span>, <span class=\"seriesInfo\">RFC 6749</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC6749</span>, <time datetime=\"2012-10\" class=\"refDate\">October 2012</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc6749\">https://www.rfc-editor.org/rfc/rfc6749</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-ID-CHAIN\">[OAUTH-ID-CHAIN]</dt>\n      <dd>\n<span class=\"refAuthor\">Schwenkschuster, A.</span>, <span class=\"refAuthor\">Kasselman, P.</span>, <span class=\"refAuthor\">Burgin, K.</span>, <span class=\"refAuthor\">Jenkins, M. J.</span>, and <span class=\"refAuthor\">B. Campbell</span>, <span class=\"refTitle\">\"OAuth Identity and Authorization Chaining Across Domains\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-oauth-identity-chaining-08</span>, <time datetime=\"2026-02-09\" class=\"refDate\">9 February 2026</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-chaining-08\">https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-chaining-08</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-JWT-ASSERTION\">[OAUTH-JWT-ASSERTION]</dt>\n      <dd>\n<span class=\"refAuthor\">Parecki, A.</span>, <span class=\"refAuthor\">McGuinness, K.</span>, and <span class=\"refAuthor\">B. Campbell</span>, <span class=\"refTitle\">\"Identity Assertion JWT Authorization Grant\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-oauth-identity-assertion-authz-grant-01</span>, <time datetime=\"2025-10-19\" class=\"refDate\">19 October 2025</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-assertion-authz-grant-01\">https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-assertion-authz-grant-01</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-REGISTRATION\">[OAUTH-REGISTRATION]</dt>\n      <dd>\n<span class=\"refAuthor\">Richer, J., Ed.</span>, <span class=\"refAuthor\">Jones, M.</span>, <span class=\"refAuthor\">Bradley, J.</span>, <span class=\"refAuthor\">Machulak, M.</span>, and <span class=\"refAuthor\">P. Hunt</span>, <span class=\"refTitle\">\"OAuth 2.0 Dynamic Client Registration Protocol\"</span>, <span class=\"seriesInfo\">RFC 7591</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC7591</span>, <time datetime=\"2015-07\" class=\"refDate\">July 2015</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc7591\">https://www.rfc-editor.org/rfc/rfc7591</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-RESOURCE-METADATA\">[OAUTH-RESOURCE-METADATA]</dt>\n      <dd>\n<span class=\"refAuthor\">Jones, M.B.</span>, <span class=\"refAuthor\">Hunt, P.</span>, and <span class=\"refAuthor\">A. Parecki</span>, <span class=\"refTitle\">\"OAuth 2.0 Protected Resource Metadata\"</span>, <span class=\"seriesInfo\">RFC 9728</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC9728</span>, <time datetime=\"2025-04\" class=\"refDate\">April 2025</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc9728\">https://www.rfc-editor.org/rfc/rfc9728</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-SERVER-METADATA\">[OAUTH-SERVER-METADATA]</dt>\n      <dd>\n<span class=\"refAuthor\">Jones, M.</span>, <span class=\"refAuthor\">Sakimura, N.</span>, and <span class=\"refAuthor\">J. Bradley</span>, <span class=\"refTitle\">\"OAuth 2.0 Authorization Server Metadata\"</span>, <span class=\"seriesInfo\">RFC 8414</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC8414</span>, <time datetime=\"2018-06\" class=\"refDate\">June 2018</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc8414\">https://www.rfc-editor.org/rfc/rfc8414</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-TOKEN-EXCHANGE\">[OAUTH-TOKEN-EXCHANGE]</dt>\n      <dd>\n<span class=\"refAuthor\">Jones, M.</span>, <span class=\"refAuthor\">Nadalin, A.</span>, <span class=\"refAuthor\">Campbell, B., Ed.</span>, <span class=\"refAuthor\">Bradley, J.</span>, and <span class=\"refAuthor\">C. Mortimore</span>, <span class=\"refTitle\">\"OAuth 2.0 Token Exchange\"</span>, <span class=\"seriesInfo\">RFC 8693</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC8693</span>, <time datetime=\"2020-01\" class=\"refDate\">January 2020</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc8693\">https://www.rfc-editor.org/rfc/rfc8693</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-TOKEN-INTROSPECTION\">[OAUTH-TOKEN-INTROSPECTION]</dt>\n      <dd>\n<span class=\"refAuthor\">Richer, J., Ed.</span>, <span class=\"refTitle\">\"OAuth 2.0 Token Introspection\"</span>, <span class=\"seriesInfo\">RFC 7662</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC7662</span>, <time datetime=\"2015-10\" class=\"refDate\">October 2015</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc7662\">https://www.rfc-editor.org/rfc/rfc7662</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OAUTH-TXN-TOKENS\">[OAUTH-TXN-TOKENS]</dt>\n      <dd>\n<span class=\"refAuthor\">Tulshibagwale, A.</span>, <span class=\"refAuthor\">Fletcher, G.</span>, and <span class=\"refAuthor\">P. Kasselman</span>, <span class=\"refTitle\">\"Transaction Tokens\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-oauth-transaction-tokens-07</span>, <time datetime=\"2026-01-24\" class=\"refDate\">24 January 2026</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-oauth-transaction-tokens-07\">https://datatracker.ietf.org/doc/html/draft-ietf-oauth-transaction-tokens-07</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OpenIDConnect.AuthZEN\">[OpenIDConnect.AuthZEN]</dt>\n      <dd>\n<span class=\"refAuthor\">Gazitt, O., Ed.</span>, <span class=\"refAuthor\">Brossard, D., Ed.</span>, and <span class=\"refAuthor\">A. Tulshibagwale, Ed.</span>, <span class=\"refTitle\">\"Authorization API 1.0\"</span>, <time datetime=\"2026\" class=\"refDate\">2026</time>, <span>&lt;<a href=\"https://openid.net/specs/authorization-api-1_0.html\">https://openid.net/specs/authorization-api-1_0.html</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OpenIDConnect.CIBA\">[OpenIDConnect.CIBA]</dt>\n      <dd>\n<span class=\"refTitle\">\"OpenID Connect Client-Initiated Backchannel Authentication Flow - Core 1.0\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html\">https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"OpenIDConnect.Discovery\">[OpenIDConnect.Discovery]</dt>\n      <dd>\n<span class=\"refTitle\">\"OpenID Connect Discovery 1.0\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://openid.net/specs/openid-connect-discovery-1_0-final.html\">https://openid.net/specs/openid-connect-discovery-1_0-final.html</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RFC2119\">[RFC2119]</dt>\n      <dd>\n<span class=\"refAuthor\">Bradner, S.</span>, <span class=\"refTitle\">\"Key words for use in RFCs to Indicate Requirement Levels\"</span>, <span class=\"seriesInfo\">BCP 14</span>, <span class=\"seriesInfo\">RFC 2119</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC2119</span>, <time datetime=\"1997-03\" class=\"refDate\">March 1997</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc2119\">https://www.rfc-editor.org/rfc/rfc2119</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RFC8174\">[RFC8174]</dt>\n      <dd>\n<span class=\"refAuthor\">Leiba, B.</span>, <span class=\"refTitle\">\"Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words\"</span>, <span class=\"seriesInfo\">BCP 14</span>, <span class=\"seriesInfo\">RFC 8174</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC8174</span>, <time datetime=\"2017-05\" class=\"refDate\">May 2017</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc8174\">https://www.rfc-editor.org/rfc/rfc8174</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RISC\">[RISC]</dt>\n      <dd>\n<span class=\"refTitle\">\"OpenID Risk Incident Sharing and Coordination Profile 1.0\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://openid.net/specs/openid-risc-1_0-final.html\">https://openid.net/specs/openid-risc-1_0-final.html</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"SPIFFE\">[SPIFFE]</dt>\n      <dd>\n<span class=\"refTitle\">\"Secure Production Identity Framework for Everyone\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://spiffe.io/docs/latest/spiffe-about/overview/\">https://spiffe.io/docs/latest/spiffe-about/overview/</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"SPIFFE-ID\">[SPIFFE-ID]</dt>\n      <dd>\n<span class=\"refTitle\">\"SPIFFE-ID\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE-ID.md\">https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE-ID.md</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"SSF\">[SSF]</dt>\n      <dd>\n<span class=\"refTitle\">\"OpenID Shared Signals Framework Specification 1.0\"</span>, <span>n.d.</span>, <span>&lt;<a href=\"https://openid.net/specs/openid-sharedsignals-framework-1_0-final.html\">https://openid.net/specs/openid-sharedsignals-framework-1_0-final.html</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"WIMSE-ARCH\">[WIMSE-ARCH]</dt>\n      <dd>\n<span class=\"refAuthor\">Salowey, J. A.</span>, <span class=\"refAuthor\">Rosomakho, Y.</span>, and <span class=\"refAuthor\">H. Tschofenig</span>, <span class=\"refTitle\">\"Workload Identity in a Multi System Environment (WIMSE) Architecture\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-wimse-arch-07</span>, <time datetime=\"2026-03-02\" class=\"refDate\">2 March 2026</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-wimse-arch-07\">https://datatracker.ietf.org/doc/html/draft-ietf-wimse-arch-07</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"WIMSE-CRED\">[WIMSE-CRED]</dt>\n      <dd>\n<span class=\"refAuthor\">Campbell, B.</span>, <span class=\"refAuthor\">Salowey, J. A.</span>, <span class=\"refAuthor\">Schwenkschuster, A.</span>, <span class=\"refAuthor\">Sheffer, Y.</span>, and <span class=\"refAuthor\">Y. Rosomakho</span>, <span class=\"refTitle\">\"WIMSE Workload Credentials\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-wimse-workload-creds-00</span>, <time datetime=\"2025-11-03\" class=\"refDate\">3 November 2025</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-wimse-workload-creds-00\">https://datatracker.ietf.org/doc/html/draft-ietf-wimse-workload-creds-00</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"WIMSE-HTTPSIG\">[WIMSE-HTTPSIG]</dt>\n      <dd>\n<span class=\"refAuthor\">Salowey, J. A.</span> and <span class=\"refAuthor\">Y. Sheffer</span>, <span class=\"refTitle\">\"WIMSE Workload-to-Workload Authentication with HTTP Signatures\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-wimse-http-signature-02</span>, <time datetime=\"2026-03-01\" class=\"refDate\">1 March 2026</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-wimse-http-signature-02\">https://datatracker.ietf.org/doc/html/draft-ietf-wimse-http-signature-02</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"WIMSE-ID\">[WIMSE-ID]</dt>\n      <dd>\n<span class=\"refAuthor\">Rosomakho, Y.</span> and <span class=\"refAuthor\">J. A. Salowey</span>, <span class=\"refTitle\">\"Workload Identifier\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-wimse-identifier-01</span>, <time datetime=\"2025-12-29\" class=\"refDate\">29 December 2025</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-wimse-identifier-01\">https://datatracker.ietf.org/doc/html/draft-ietf-wimse-identifier-01</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"WIMSE-WPT\">[WIMSE-WPT]</dt>\n    <dd>\n<span class=\"refAuthor\">Campbell, B.</span> and <span class=\"refAuthor\">A. Schwenkschuster</span>, <span class=\"refTitle\">\"WIMSE Workload Proof Token\"</span>, <span class=\"refContent\">Work in Progress</span>, <span class=\"seriesInfo\">Internet-Draft, draft-ietf-wimse-wpt-00</span>, <time datetime=\"2025-11-03\" class=\"refDate\">3 November 2025</time>, <span>&lt;<a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-wimse-wpt-00\">https://datatracker.ietf.org/doc/html/draft-ietf-wimse-wpt-00</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n</dl>\n</section>\n</div>\n<div id=\"acknowledgments\">\n<section id=\"appendix-A\">\n      <h2 id=\"name-acknowledgments\">\n<a href=\"#appendix-A\" class=\"section-number selfRef\">Appendix A. </a><a href=\"#name-acknowledgments\" class=\"section-name selfRef\">Acknowledgments</a>\n      </h2>\n<p id=\"appendix-A-1\">The authors would like to thank Sean O'Dell for providing valuable input and feedback on this work.<a href=\"#appendix-A-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"authors-addresses\">\n<section id=\"appendix-B\">\n      <h2 id=\"name-authors-addresses\">\n<a href=\"#name-authors-addresses\" class=\"section-name selfRef\">Authors' Addresses</a>\n      </h2>\n<address class=\"vcard\">\n        <div dir=\"auto\" class=\"left\"><span class=\"fn nameRole\">Pieter Kasselman</span></div>\n<div dir=\"auto\" class=\"left\"><span class=\"org\">Defakto Security</span></div>\n<div class=\"email\">\n<span>Email:</span>\n<a href=\"mailto:pieter@defakto.security\" class=\"email\">pieter@defakto.security</a>\n</div>\n</address>\n<address class=\"vcard\">\n        <div dir=\"auto\" class=\"left\"><span class=\"fn nameRole\">Jean-François Lombardo</span></div>\n<div dir=\"auto\" class=\"left\"><span class=\"org\">AWS</span></div>\n<div class=\"email\">\n<span>Email:</span>\n<a href=\"mailto:jeffsec@amazon.com\" class=\"email\">jeffsec@amazon.com</a>\n</div>\n</address>\n<address class=\"vcard\">\n        <div dir=\"auto\" class=\"left\"><span class=\"fn nameRole\">Yaroslav Rosomakho</span></div>\n<div dir=\"auto\" class=\"left\"><span class=\"org\">Zscaler</span></div>\n<div class=\"email\">\n<span>Email:</span>\n<a href=\"mailto:yrosomakho@zscaler.com\" class=\"email\">yrosomakho@zscaler.com</a>\n</div>\n</address>\n<address class=\"vcard\">\n        <div dir=\"auto\" class=\"left\"><span class=\"fn nameRole\">Brian Campbell</span></div>\n<div dir=\"auto\" class=\"left\"><span class=\"org\">Ping Identity</span></div>\n<div class=\"email\">\n<span>Email:</span>\n<a href=\"mailto:bcampbell@pingidentity.com\" class=\"email\">bcampbell@pingidentity.com</a>\n</div>\n</address>\n</section>\n</div>\n</div>\n\n                    </div>\n                \n            </div>\n            <div class=\"d-print-none col-md-3 bg-light-subtle collapse show\" id=\"sidebar\">\n                <div class=\"position-fixed border-start sidebar overflow-scroll overscroll-none no-scrollbar\">\n                    <div class=\"d-flex flex-column vh-100 pt-2 pt-lg-3 ps-3 pl-md-2 pl-lg-3\">\n                        <div>\n                            <a class=\"btn btn-primary btn-sm\" href=\"/doc/draft-klrc-aiagent-auth/\">Datatracker</a>\n                            <p class=\"fw-bold pt-2\">\n                                \n                                    draft-klrc-aiagent-auth-00\n                                \n                                <br>\n                                \n\n\n\n\n\n\n\n    <div>This is an older version of an Internet-Draft whose latest revision state is \"Active\".</div>\n\n                            </p>\n                        </div>\n                        \n                        <ul class=\"nav nav-tabs nav-fill small me-2\" role=\"tablist\">\n                            <li class=\"nav-item\" role=\"presentation\" title=\"Document information\">\n                                <button class=\"nav-link px-2\"\n                                        id=\"docinfo-tab\"\n                                        data-bs-toggle=\"tab\"\n                                        data-bs-target=\"#docinfo-tab-pane\"\n                                        type=\"button\"\n                                        role=\"tab\"\n                                        aria-controls=\"docinfo-tab-pane\"\n                                        aria-selected=\"true\">\n                                    <i class=\"bi bi-info-circle\"></i><span class=\"d-none d-md-block d-xl-inline ms-xl-1\">Info</span>\n                                </button>\n                            </li>\n                            <li class=\"nav-item\" role=\"presentation\" title=\"Table of contents\">\n                                <button class=\"nav-link px-2\"\n                                        id=\"toc-tab\"\n                                        data-bs-toggle=\"tab\"\n                                        data-bs-target=\"#toc-tab-pane\"\n                                        type=\"button\"\n                                        role=\"tab\"\n                                        aria-controls=\"toc-tab-pane\"\n                                        aria-selected=\"false\">\n                                    <i class=\"bi bi-list-ol\"></i><span class=\"d-none d-md-block d-xl-inline ms-xl-1\">Contents</span>\n                                </button>\n                            </li>\n                            <li class=\"nav-item\" role=\"presentation\" title=\"Preferences\">\n                                <button class=\"nav-link px-2\"\n                                        id=\"pref-tab\"\n                                        data-bs-toggle=\"tab\"\n                                        data-bs-target=\"#pref-tab-pane\"\n                                        type=\"button\"\n                                        role=\"tab\"\n                                        aria-controls=\"pref-tab-pane\"\n                                        aria-selected=\"false\">\n                                    <i class=\"bi bi-gear\"></i><span class=\"d-none d-md-block d-xl-inline ms-xl-1\">Prefs</span>\n                                </button>\n                            </li>\n                        </ul>\n                        <div class=\"overflow-auto tab-content pt-2 me-2\">\n                            <div class=\"tab-pane\"\n                                 id=\"docinfo-tab-pane\"\n                                 role=\"tabpanel\"\n                                 aria-labelledby=\"docinfo-tab\"\n                                 tabindex=\"0\">\n                                <table class=\"table table-sm table-borderless\">\n                                    \n\n\n\n\n\n\n\n<tbody class=\"meta align-top \">\n    <tr>\n        <th scope=\"row\">Document</th>\n        <th scope=\"row\">Document type</th>\n        <td class=\"edit\"></td>\n        <td>\n            \n\n\n\n\n\n\n\n    <div>This is an older version of an Internet-Draft whose latest revision state is \"Active\".</div>\n\n            \n            \n            \n                \n\n\n\n\n    <div class=\"alert alert-warning small p-2 mt-2\" role=\"alert\">\n        This document is an Internet-Draft (I-D).\n        Anyone may submit an I-D to the IETF.\n        This I-D is <strong>not endorsed by the IETF</strong> and has <strong>no formal standing</strong> in the\n        <a href=\"/doc/rfc2026/\">IETF standards process</a>.\n    </div>\n\n\n            \n        </td>\n    </tr>\n    \n        <tr>\n            <td></td>\n            <th scope=\"row\">Select version</th>\n            <td class=\"edit\"></td>\n            <td>\n                \n\n\n\n    <ul class=\"revision-list pagination pagination-sm text-center flex-wrap my-0\">\n        \n            \n                 \n                    <li class=\"page-item active\">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-00\"\n                        >\n                            00\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-01\"\n                        rel=\"nofollow\">\n                            01\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-02\"\n                        rel=\"nofollow\">\n                            02\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/html/draft-klrc-aiagent-auth-03\"\n                        >\n                            03\n                        </a>\n                    </li>\n                \n            \n            \n        \n    </ul>\n\n            </td>\n        </tr>\n        \n            <tr>\n                <td></td>\n                <th scope=\"row\">Compare versions</th>\n                <td class=\"edit\"></td>\n                <td>\n                    \n\n\n\n<form class=\"form-horizontal diff-form\"\n      action=\"https://author-tools.ietf.org/iddiff\"\n      method=\"get\"\n      target=\"_blank\">\n\n            <select class=\"form-select form-select-sm mb-1 select2-field\"\n                    data-max-entries=\"1\"\n                    data-width=\"resolve\"\n                    data-allow-clear=\"false\"\n                    data-minimum-input-length=\"0\"\n                    aria-label=\"From revision\"\n                    name=\"url1\">\n                \n                    <option value=\"draft-klrc-aiagent-auth-03\">\n                        draft-klrc-aiagent-auth-03\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-02\" selected>\n                        draft-klrc-aiagent-auth-02\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-01\">\n                        draft-klrc-aiagent-auth-01\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-00\">\n                        draft-klrc-aiagent-auth-00\n                        \n                    </option>\n                \n                \n            </select>\n\n            <select class=\"form-select form-select-sm mb-1 select2-field\"\n                    data-max-entries=\"1\"\n                    data-width=\"resolve\"\n                    data-allow-clear=\"false\"\n                    data-minimum-input-length=\"0\"\n                    aria-label=\"To revision\"\n                    name=\"url2\">\n                \n                    <option value=\"draft-klrc-aiagent-auth-03\" selected>\n                        draft-klrc-aiagent-auth-03\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-02\">\n                        draft-klrc-aiagent-auth-02\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-01\">\n                        draft-klrc-aiagent-auth-01\n                        \n                    </option>\n                \n                    <option value=\"draft-klrc-aiagent-auth-00\">\n                        draft-klrc-aiagent-auth-00\n                        \n                    </option>\n                \n                \n            </select>\n\n            <button type=\"submit\"\n                    class=\"btn btn-primary btn-sm\"\n                    value=\"--html\"\n                    name=\"difftype\">\n                Side-by-side\n            </button>\n            \n            <button type=\"submit\"\n                    class=\"btn btn-primary btn-sm\"\n                    value=\"--hwdiff\"\n                    name=\"difftype\">\n                Inline\n            </button>\n\n</form>\n                </td>\n            </tr>\n        \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Authors</th>\n        <td class=\"edit\">\n            \n        </td>\n        <td>\n            \n            \n                <span ><a \n           title=\"Datatracker profile of Pieter Kasselman\"\n            href=\"/person/prkasselman@gmail.com\" >Pieter Kasselman</a> <a \n               href=\"mailto:prkasselman%40gmail.com\"\n               aria-label=\"Compose email to prkasselman@gmail.com\"\n               title=\"Compose email to prkasselman@gmail.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Jeff Lombardo\"\n            href=\"/person/jeffsec@amazon.com\" >Jeff Lombardo</a> <a \n               href=\"mailto:jeffsec%40amazon.com\"\n               aria-label=\"Compose email to jeffsec@amazon.com\"\n               title=\"Compose email to jeffsec@amazon.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Yaroslav Rosomakho\"\n            href=\"/person/yrosomakho@zscaler.com\" >Yaroslav Rosomakho</a> <a \n               href=\"mailto:yrosomakho%40zscaler.com\"\n               aria-label=\"Compose email to yrosomakho@zscaler.com\"\n               title=\"Compose email to yrosomakho@zscaler.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Brian Campbell\"\n            href=\"/person/bcampbell@pingidentity.com\" >Brian Campbell</a> <a \n               href=\"mailto:bcampbell%40pingidentity.com\"\n               aria-label=\"Compose email to bcampbell@pingidentity.com\"\n               title=\"Compose email to bcampbell@pingidentity.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>\n            \n            \n        </td>\n    </tr>\n    \n    \n        \n        \n        \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            RFC stream\n        </th>\n        <td class=\"edit\">\n            \n        </td>\n        <td class=\"text-body-secondary\">\n            \n                (None)\n            \n        </td>\n    </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            Other formats\n        </th>\n        <td class=\"edit\">\n        </td>\n        <td>\n            \n                \n    <div class=\"buttonlist\">\n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.txt\">\n            \n                <i class=\"bi bi-file-text\"></i> txt\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.html\">\n            \n                <i class=\"bi bi-file-code\"></i> html\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-00.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> xml\n            \n        </a>\n        \n    \n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/draft-klrc-aiagent-auth/00/bibtex/\">\n            \n                <i class=\"bi bi-file-ruled\"></i> bibtex\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/bibxml3/draft-klrc-aiagent-auth-00.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> bibxml\n            \n        </a>\n        \n    \n</div>\n\n            \n        </td>\n    </tr>\n    \n    \n        \n    \n</tbody>\n                                </table>\n                                <a class=\"btn btn-sm btn-warning mb-3\"\n                                target=\"_blank\"\n                                href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n                                    Report a datatracker bug\n                                    <i class=\"bi bi-bug\"></i>\n                                </a>\n                            </div>\n                            <div class=\"tab-pane mb-5\"\n                                 id=\"toc-tab-pane\"\n                                 role=\"tabpanel\"\n                                 aria-labelledby=\"toc-tab\"\n                                 tabindex=\"0\">\n                                <nav class=\"nav nav-pills flex-column small\" id=\"toc-nav\">\n                                </nav>\n                            </div>\n                            <div class=\"tab-pane mb-5 small\"\n                                 id=\"pref-tab-pane\"\n                                 role=\"tabpanel\"\n                                 aria-labelledby=\"pref-tab\"\n                                 tabindex=\"0\">\n                                <label class=\"form-label fw-bold mb-2\">Show sidebar by default</label>\n                                <div class=\"btn-group-vertical btn-group-sm d-flex\" role=\"group\">\n                                    <input type=\"radio\" class=\"btn-check\" name=\"sidebar\" id=\"on-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"on-radio\">Yes</label>\n                                    <input type=\"radio\" class=\"btn-check\" name=\"sidebar\" id=\"off-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"off-radio\">No</label>\n                                </div>\n                                <label class=\"form-label fw-bold mt-4 mb-2\">Tab to show by default</label>\n                                <div class=\"btn-group-vertical btn-group-sm d-flex\" role=\"group\">\n                                    <input type=\"radio\" class=\"btn-check\" name=\"deftab\" id=\"docinfo-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"docinfo-radio\">\n                                        <i class=\"bi bi-info-circle me-1\"></i>Info\n                                    </label>\n                                    <input type=\"radio\" class=\"btn-check\" name=\"deftab\" id=\"toc-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"toc-radio\">\n                                        <i class=\"bi bi-list-ol me-1\"></i>Contents\n                                    </label>\n                                </div>\n                                <label class=\"form-label fw-bold mt-4 mb-2\">HTMLization configuration</label>\n                                <div class=\"btn-group-vertical btn-group-sm d-flex\" role=\"group\">\n                                    <input type=\"radio\" class=\"btn-check\" name=\"htmlconf\" id=\"txt-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"txt-radio\" title=\"This is the traditional HTMLization method.\">\n                                        <i class=\"bi bi-badge-sd me-1\"></i>HTMLize the plaintext\n                                    </label>\n                                    <input type=\"radio\" class=\"btn-check\" name=\"htmlconf\" id=\"html-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"html-radio\" title=\"This is the modern HTMLization method.\">\n                                        <i class=\"bi bi-badge-hd me-1\"></i>Plaintextify the HTML\n                                    </label>\n                                </div>\n                                <label class=\"form-label fw-bold mt-4 mb-2\" for=\"ptsize\">Maximum font size</label>\n                                <input type=\"range\" class=\"form-range\" min=\"7\" max=\"16\" id=\"ptsize\" oninput=\"ptdemo.value = ptsize.value\">\n                                <label class=\"form-label fw-bold mt-4 mb-2\">Page dependencies</label>\n                                <div class=\"btn-group-vertical btn-group-sm d-flex\" role=\"group\">\n                                    <input type=\"radio\" class=\"btn-check\" name=\"pagedeps\" id=\"inline-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"inline-radio\" title=\"Generate larger, standalone web pages that do not require network access to render.\">\n                                        <i class=\"bi bi-box me-1\"></i>Inline\n                                    </label>\n                                    <input type=\"radio\" class=\"btn-check\" name=\"pagedeps\" id=\"reference-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"reference-radio\" title=\"Generate regular web pages that require network access to render.\">\n                                        <i class=\"bi bi-link-45deg me-1\"></i>Reference\n                                    </label>\n                                </div>\n                                <label class=\"form-label fw-bold mt-4 mb-2\">Citation links</label>\n                                <div class=\"btn-group-vertical btn-group-sm d-flex\" role=\"group\">\n                                    <input type=\"radio\" class=\"btn-check\" name=\"reflinks\" id=\"refsection-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"refsection-radio\" title=\"Citation links go to the reference section.\">\n                                        <i class=\"bi bi-arrow-clockwise\"></i> Go to reference section\n                                    </label>\n                                    <input type=\"radio\" class=\"btn-check\" name=\"reflinks\" id=\"citation-radio\">\n                                    <label class=\"btn btn-outline-primary\" for=\"citation-radio\" title=\"Citation links go directly to the cited document.\">\n                                        <i class=\"bi bi-link-45deg me-1\"></i>Go to linked document\n                                    </label>\n                                </div>\n                            </div>\n                        </div>\n                    </div>\n                </div>\n            </div>\n        </div>\n    \n<script>\n  var _paq = window._paq || [];\n  \n  _paq.push(['disableCookies']);\n  _paq.push(['trackPageView']);\n  _paq.push(['enableLinkTracking']);\n  (function() {\n    var u=\"//analytics.ietf.org/\";\n    _paq.push(['setTrackerUrl', u+'matomo.php']);\n    _paq.push(['setSiteId', 7]);\n    var d=document, g=d.createElement('script'), s=d.getElementsByTagName('script')[0];\n    g.type='text/javascript'; g.async=true; g.defer=true; g.src=u+'matomo.js'; s.parentNode.insertBefore(g,s);\n  })();\n</script>\n<noscript><p><img src=\"//analytics.ietf.org/matomo.php?idsite=7\" style=\"border:0;\" alt=\"\" /></p></noscript>\n\n    <script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML=\"window.__CF$cv$params={r:'a37ed23abf546cd4',t:'MTc4ODg3OTYxMA=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);\";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>\n</html>\n","snapshot_chars":150155,"live_check":"matches"},{"url":"https://arxiv.org/html/2604.23280v1","committed_hash":"sha256:e7b1417f1a1dd8f4d94ff5b7aa2844a4472483942ad5006c96e718b839a3bb12","committed_hash_short":"sha256:e7b1417f…39a3bb12","mime_type":"text/html","committed_at":"2026-09-08T15:00:28.780688+00:00","content_snapshot":"<!DOCTYPE html><html lang=\"en\">\n<head>\n<meta http-equiv=\"content-type\" content=\"text/html; charset=UTF-8\">\n<title>Executive Summary</title>\n<!--Generated by LaTeXML oxide (version 0.7.6) http://dlmf.nist.gov/LaTeXML/.-->\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1, shrink-to-fit=no\">\n<link rel=\"stylesheet\" href=\"/static/browse/0.3.4/css/arxiv-html-papers-20260823.css\" type=\"text/css\">\n<script src=\"/static/browse/0.3.4/js/arxiv-html-papers-20260131.js\"> </script>\n<script>\n  // Restore the saved color scheme preference, or\n  // enact the browser preference if \"automatic\", \n  // without expecting DOM load to have completed.\n  //\n  // Also restore any saved readingmode and ToC display preferences.\n  function initializeReadingPreferences() {\n    let saved_theme = localStorage.getItem(\"ar5iv_theme\") || \"automatic\";\n    if (saved_theme === \"automatic\") {\n      if (window.matchMedia(\"(prefers-color-scheme: dark)\").matches) {\n        saved_theme = \"dark\";\n      }\n    }\n    if (saved_theme == \"dark\") {\n      document.documentElement.setAttribute(\"data-theme\", \"dark\");\n    } else {\n      document.documentElement.setAttribute(\"data-theme\", \"light\");\n    }\n\n    const tocDisplay = localStorage.getItem('arxiv_html_paper_toc_display');\n    if (tocDisplay) {\n      document.documentElement.setAttribute(\"data-toc-display\", tocDisplay);\n    }\n    const readingMode = localStorage.getItem('arxiv_html_paper_reading_mode');\n    if (readingMode) {\n      document.documentElement.setAttribute(\"data-reading-mode\", readingMode);\n    }\n    // Pre-apply spinout-banner dismissal here, before the banner paints, so it\n    // never flashes in only to be hidden later by the deferred arxiv-header.js.\n    // Key matches arxiv-header.js: \"arxiv-banner-dismissed:\" + data-banner-name.\n    if (localStorage.getItem('arxiv-banner-dismissed:spinout-nonprofit')) {\n      document.documentElement.setAttribute(\"data-banner-dismissed\", \"\");\n    }\n  }\n  // Run as soon as JS starts, to minimize repainting\n  initializeReadingPreferences();\n</script>\n<link rel=\"apple-touch-icon\" sizes=\"180x180\"\n  href=\"/static/browse/0.3.4/images/icons/apple-touch-icon.png\">\n<link rel=\"icon\" type=\"image/png\" sizes=\"32x32\"\n  href=\"/static/browse/0.3.4/images/icons/favicon-32x32.png\">\n<link rel=\"icon\" type=\"image/png\" sizes=\"16x16\"\n  href=\"/static/browse/0.3.4/images/icons/favicon-16x16.png\">\n<link rel=\"manifest\" href=\"/static/browse/0.3.4/images/icons/site.webmanifest\">\n<link rel=\"mask-icon\" href=\"/static/browse/0.3.4/images/icons/safari-pinned-tab.svg\" color=\"#5bbad5\">\n<link rel=\"stylesheet\" type=\"text/css\" media=\"screen\" href=\"https://use.typekit.net/utz6mli.css\"><link rel=\"stylesheet\" type=\"text/css\" media=\"screen\"\n  href=\"/static/base/1.0.1/css/arxiv-header-footer.css?v=20260626\"><style>\n  /* Banner pre-dismissal (set above before paint -> no flash-then-hide) and\n     reading-mode chrome hiding. */\n  html[data-banner-dismissed] .ds-announcement { display: none; }\n  html[data-reading-mode=\"enabled\"] .ds-announcement,\n  html[data-reading-mode=\"enabled\"] .ds-site-footer { display: none; }\n  /* Keep the announcement text dark on the Open-Blue band in both colour themes\n     (otherwise it inherits the paper's warm-wash text in dark mode and washes out). */\n  .ds-announcement-text { color: var(--arxiv-ink, #1c1a17); }\n</style>\n<script defer src=\"/static/base/1.0.1/js/arxiv-header.js?v=20260626\"></script>\n</head>\n<body>\n<dialog id=\"modal-form\" aria-labelledby=\"modal-title\" closedby=\"any\">\n  <form id=\"modal-form-content\" method=\"dialog\" enctype=\"multipart/form-data\">\n    <header class=\"modal-header\">\n      <h5 id=\"modal-title\" class=\"modal-title\">Report GitHub Issue</h5>\n      <button type=\"submit\" formnovalidate class=\"modal-close\" aria-label=\"Close\">×</button>\n    </header>\n\n    <div class=\"modal-body\">\n      <label for=\"form_title\">Title:</label>\n      <input class=\"form-control\" id=\"form_title\" name=\"form_title\" required placeholder=\"Enter title\">\n\n      <p id=\"selectedTextModalDescription\" hidden>Content selection saved. Describe the issue below:</p>\n\n      <label for=\"description\">Description:</label>\n      <textarea class=\"form-control\" id=\"description\" name=\"description\" required maxlength=\"500\"\n        placeholder=\"500 characters maximum\"></textarea>\n    </div>\n\n    <footer class=\"modal-footer\">\n      <button type=\"submit\" value=\"internal-report\" class=\"sr-only modal-submit\">Submit without GitHub</button>\n      <button type=\"submit\" value=\"github-report\" class=\"modal-submit\">Submit in GitHub</button>\n    </footer>\n  </form>\n</dialog><div class=\"ds-announcement\" id=\"announcement-banner\" role=\"region\" aria-label=\"Announcement\"\n    data-banner-name=\"spinout-nonprofit\">\n    <img class=\"ds-announcement-glyph\" src=\"/static/base/1.0.1/images/icons/smileybones-small.svg\" alt=\"\" aria-hidden=\"true\">\n    <span class=\"ds-announcement-text\">arXiv is now an independent nonprofit!</span>\n    <a class=\"ds-announcement-link\" href=\"https://info.arxiv.org/about\">Learn more</a>\n    <button type=\"button\" class=\"ds-announcement-close\" aria-label=\"Dismiss announcement\">&times;</button>\n  </div>\n\n<header class=\"arxiv-html-header\">\n  <div class=\"html-header-logo\">\n    <a href=\"/\"><img alt=\"arXiv logo\" class=\"logo desktop-only\" width=\"100\"\n        src=\"/static/base/1.0.1/images/arxiv-logo-primary-light.svg\">\n      <span class=\"sr-only\">Back to arXiv</span>\n    </a>\n  </div>\n  <!--TOC, dark mode, links-->\n  <nav class=\"html-header-nav\">\n    <a class=\"header-button hover-effect desktop-only\" href=\"https://info.arxiv.org/about/accessible_HTML.html\"\n      target=\"_blank\">Why HTML?</a>\n    <a class=\"header-button\" title=\"Report an Issue\" href=\"#\" title=\"Report an issue\"\n      onclick=\"event.preventDefault(); showModalForm();\">\n      <svg role=\"presentation\" class=\"mobile-only toggle-icon\" aria-hidden=\"true\" height=\"1.25rem\"\n        viewBox=\"0 0 640 640\">\n        <path\n          d=\"M224 160C224 107 267 64 320 64C373 64 416 107 416 160L416 163.6C416 179.3 403.3 192 387.6 192L252.5 192C236.8 192 224.1 179.3 224.1 163.6L224.1 160zM569.6 172.8C580.2 186.9 577.3 207 563.2 217.6L465.4 290.9C470.7 299.8 474.7 309.6 477.2 320L576 320C593.7 320 608 334.3 608 352C608 369.7 593.7 384 576 384L480 384L480 416C480 418.6 479.9 421.3 479.8 423.9L563.2 486.4C577.3 497 580.2 517.1 569.6 531.2C559 545.3 538.9 548.2 524.8 537.6L461.7 490.3C438.5 534.5 395.2 566.5 344 574.2L344 344C344 330.7 333.3 320 320 320C306.7 320 296 330.7 296 344L296 574.2C244.8 566.5 201.5 534.5 178.3 490.3L115.2 537.6C101.1 548.2 81 545.3 70.4 531.2C59.8 517.1 62.7 497 76.8 486.4L160.2 423.9C160.1 421.3 160 418.7 160 416L160 384L64 384C46.3 384 32 369.7 32 352C32 334.3 46.3 320 64 320L162.8 320C165.3 309.6 169.3 299.8 174.6 290.9L76.8 217.6C62.7 207 59.8 186.9 70.4 172.8C81 158.7 101.1 155.8 115.2 166.4L224 248C236.3 242.9 249.8 240 264 240L376 240C390.2 240 403.7 242.8 416 248L524.8 166.4C538.9 155.8 559 158.7 569.6 172.8z\" />\n      </svg>\n      <span class=\"desktop-only\">Report Issue</span></a>\n    <!--back to abstract-->\n    <a class=\"header-button\" title=\"Back to abstract page\" aria-label=\"Back to abstract page\"\n      href=\"/abs/2604.23280v1\">\n      <svg class=\"mobile-only toggle-icon\" role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 512 512\" fill=\"#ffffff\"\n        aria-hidden=\"true\">\n        <path\n          d=\"M502.6 278.6c12.5-12.5 12.5-32.8 0-45.3l-128-128c-12.5-12.5-32.8-12.5-45.3 0s-12.5 32.8 0 45.3L402.7 224 192 224c-17.7 0-32 14.3-32 32s14.3 32 32 32l210.7 0-73.4 73.4c-12.5 12.5-12.5 32.8 0 45.3s32.8 12.5 45.3 0l128-128zM160 96c17.7 0 32-14.3 32-32s-14.3-32-32-32L96 32C43 32 0 75 0 128L0 384c0 53 43 96 96 96l64 0c17.7 0 32-14.3 32-32s-14.3-32-32-32l-64 0c-17.7 0-32-14.3-32-32l0-256c0-17.7 14.3-32 32-32l64 0z\">\n        </path>\n      </svg>\n      <span class=\"desktop-only\">Back to Abstract</span>\n    </a>\n    <!-- PDF download link -->\n    <a class=\"header-button\" title=\"Download PDF\" href=\"/pdf/2604.23280v1\"\n      target=\"_blank\">\n      <svg class=\"mobile-only toggle-icon\" role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 576 542\">\n        <path\n          d=\"M208 48L96 48c-8.8 0-16 7.2-16 16l0 384c0 8.8 7.2 16 16 16l80 0 0 48-80 0c-35.3 0-64-28.7-64-64L32 64C32 28.7 60.7 0 96 0L229.5 0c17 0 33.3 6.7 45.3 18.7L397.3 141.3c12 12 18.7 28.3 18.7 45.3l0 149.5-48 0 0-128-88 0c-39.8 0-72-32.2-72-72l0-88zM348.1 160L256 67.9 256 136c0 13.3 10.7 24 24 24l68.1 0zM240 380l32 0c33.1 0 60 26.9 60 60s-26.9 60-60 60l-12 0 0 28c0 11-9 20-20 20s-20-9-20-20l0-128c0-11 9-20 20-20zm32 80c11 0 20-9 20-20s-9-20-20-20l-12 0 0 40 12 0zm96-80l32 0c28.7 0 52 23.3 52 52l0 64c0 28.7-23.3 52-52 52l-32 0c-11 0-20-9-20-20l0-128c0-11 9-20 20-20zm32 128c6.6 0 12-5.4 12-12l0-64c0-6.6-5.4-12-12-12l-12 0 0 88 12 0zm76-108c0-11 9-20 20-20l48 0c11 0 20 9 20 20s-9 20-20 20l-28 0 0 24 28 0c11 0 20 9 20 20s-9 20-20 20l-28 0 0 44c0 11-9 20-20 20s-20-9-20-20l0-128z\" />\n      </svg>\n      <span class=\"desktop-only\">Download PDF</span></a>\n    <!-- navigational table of contents toggle -->\n    <a class=\"header-button toggle-icon\" href=\"javascript:toggleNavTOC();\" title=\"Toggle navigation\"\n      aria-label=\"Toggle navigation\">\n      <svg height=\"1.25rem\" role=\"presentation\" viewBox=\"0 0 512 512\">\n        <path\n          d=\"M40 48C26.7 48 16 58.7 16 72v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V72c0-13.3-10.7-24-24-24H40zM192 64c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zm0 160c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zm0 160c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zM16 232v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V232c0-13.3-10.7-24-24-24H40c-13.3 0-24 10.7-24 24zM40 368c-13.3 0-24 10.7-24 24v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V392c0-13.3-10.7-24-24-24H40z\">\n        </path>\n      </svg>\n    </a>\n    <!--- collapsable header / reading mode toggle -->\n    <a class=\"header-button toggle-icon\" href=\"javascript:toggleReadingMode();\"\n      title=\"Disable reading mode, show header and footer\">\n      <svg role=\"presentation\" height=\"1.25rem\"\n        viewBox=\"0 0 448 512\"><!--!Font Awesome Free v7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free Copyright 2026 Fonticons, Inc.-->\n        <path\n          d=\"M32 32C14.3 32 0 46.3 0 64l0 96c0 17.7 14.3 32 32 32s32-14.3 32-32l0-64 64 0c17.7 0 32-14.3 32-32s-14.3-32-32-32L32 32zM64 352c0-17.7-14.3-32-32-32S0 334.3 0 352l0 96c0 17.7 14.3 32 32 32l96 0c17.7 0 32-14.3 32-32s-14.3-32-32-32l-64 0 0-64zM320 32c-17.7 0-32 14.3-32 32s14.3 32 32 32l64 0 0 64c0 17.7 14.3 32 32 32s32-14.3 32-32l0-96c0-17.7-14.3-32-32-32l-96 0zM448 352c0-17.7-14.3-32-32-32s-32 14.3-32 32l0 64-64 0c-17.7 0-32 14.3-32 32s14.3 32 32 32l96 0c17.7 0 32-14.3 32-32l0-96z\" />\n      </svg>\n    </a>\n    <!--- colored theme toggle -->\n    <button type=\"button\" class=\"header-button color-tog\" onclick=\"toggleColorScheme();\" title=\"Toggle dark/light mode\" aria-label=\"Toggle color scheme\">\n      <span class=\"toggle-icon automatic-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"m14.3 16-.7-2h-3.2l-.7 2H7.8L11 7h2l3.2 9h-1.9M20 8.69V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69m-9.15 3.96h2.3L12 9l-1.15 3.65Z\">\n          </path>\n        </svg>\n      </span>\n      <span class=\"toggle-icon light-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"M12 8a4 4 0 0 0-4 4 4 4 0 0 0 4 4 4 4 0 0 0 4-4 4 4 0 0 0-4-4m0 10a6 6 0 0 1-6-6 6 6 0 0 1 6-6 6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69Z\">\n          </path>\n        </svg>\n      </span>\n      <span class=\"toggle-icon dark-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"M12 18c-.89 0-1.74-.2-2.5-.55C11.56 16.5 13 14.42 13 12c0-2.42-1.44-4.5-3.5-5.45C10.26 6.2 11.11 6 12 6a6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69Z\">\n          </path>\n        </svg>\n      </span>\n    </button>\n  </nav>\n</header><nav class=\"ltx_page_navbar\">\n<nav class=\"ltx_TOC\">\n<ol class=\"ltx_toclist\">\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S1\" title=\"\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">1 </span>Introduction</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S2\" title=\"\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2 </span>RQ1: Comparison of Human and Non-Human Identities</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS1\" title=\"In 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.1 </span>Human Identity</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS2\" title=\"In 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.2 </span>Non-Human Identity</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS3\" title=\"In 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.3 </span>A Four-Dimension Comparison</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S3\" title=\"\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3 </span>RQ2: Industry Trends</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S3.SS1\" title=\"In 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3.1 </span>Vendor Direction and Emerging Players</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S3.SS2\" title=\"In 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3.2 </span>Standards Landscape</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S3.SS3\" title=\"In 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3.3 </span>Regulatory Landscape</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S4\" title=\"\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4 </span>RQ3: Technologies for AI Identity</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS1\" title=\"In 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.1 </span>Authentication</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS2\" title=\"In 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.2 </span>Authorization and Delegation</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS3\" title=\"In 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.3 </span>Credentials and Portable Identity</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS4\" title=\"In 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.4 </span>Provenance and Content Integrity</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS5\" title=\"In 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.5 </span>Governance and Monitoring</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS6\" title=\"In 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.6 </span>Audit Logging and Attestation</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S5\" title=\"\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5 </span>RQ4: Gap Analysis and Research Directions</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS1\" title=\"In 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.1 </span>The Semantic Intent Gap</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS2\" title=\"In 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.2 </span>The Recursive Delegation and Accountability Gap</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS3\" title=\"In 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.3 </span>The Agent Identity Integrity Gap</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS4\" title=\"In 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.4 </span>The Governance Opacity and Enforcement Paradox</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS5\" title=\"In 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.5 </span>Operational Cost and Sustainability</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S6\" title=\"\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">6 </span>Conclusion</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_bibliography\"><a href=\"#bib\" title=\"\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\">References</span></a></li>\n</ol></nav>\n</nav>\n<div class=\"ltx_page_main\">\n<div id=\"infobox\" class=\"infobox\">\n  <a id=\"license-tr\" href=\"https://info.arxiv.org/help/license/index.html#licenses-available\">\n    License: CC BY 4.0\n  </a>\n  <div id=\"watermark-tr\">\narXiv:2604.23280v1 [cs.AI] 25 Apr 2026</div>\n</div><div class=\"ltx_page_content\">\n<article class=\"ltx_document\">\n<div id=\"p1\" class=\"ltx_para\"><span id=\"p1.1\" class=\"ltx_ERROR undefined\">\\reporttitle</span>\n<p id=\"p1.2\" class=\"ltx_p\">AI Identity: Standards, Gaps, and Research Directions for AI Agents\n<span id=\"p1.2.1\" class=\"ltx_ERROR undefined\">\\reportsubtitle</span>Analysis Report\n\n<span id=\"p1.2.2\" class=\"ltx_ERROR undefined\">\\reportauthors</span>Takumi Otsuka<sup id=\"p1.2.3\" class=\"ltx_sup\"><span id=\"p1.2.3.1\" class=\"ltx_ERROR undefined\">\\robotocondensed</span>1, 2</sup>, Kentaroh Toyoda<sup id=\"p1.2.4\" class=\"ltx_sup\"><span id=\"p1.2.4.1\" class=\"ltx_ERROR undefined\">\\robotocondensed</span>1, 3</sup>, Alex Leung<sup id=\"p1.2.5\" class=\"ltx_sup\"><span id=\"p1.2.5.1\" class=\"ltx_ERROR undefined\">\\robotocondensed</span>1</sup>\n\n\n<span id=\"p1.2.6\" class=\"ltx_ERROR undefined\">\\reportdate</span>August 24, 2026\n<span id=\"p1.2.7\" class=\"ltx_ERROR undefined\">\\leftheadercontent</span><span id=\"p1.2.8\" class=\"ltx_ERROR undefined\">\\rightheadercontent</span><object type=\"image/svg+xml\" data=\"2604.23280v1/vulcan-logo.svg\" id=\"p1.g1\" class=\"ltx_graphics ltx_img_landscape\" style=\"aspect-ratio:118/35;\" width=\"118\" height=\"35\"></object></p>\n</div>\n<div id=\"p2\" class=\"ltx_para\"><object type=\"image/svg+xml\" data=\"2604.23280v1/x1.svg\" id=\"p2.g1\" class=\"ltx_graphics ltx_img_landscape\" style=\"aspect-ratio:197/57;\" width=\"197\" height=\"57\"></object>\n</div>\n<div id=\"p3\" class=\"ltx_para ltx_align_left\"><span id=\"p3.1\" class=\"ltx_ERROR undefined\">\\reportdate</span>\n</div>\n<div id=\"p4\" class=\"ltx_para ltx_align_left\"><span id=\"p4.1\" class=\"ltx_ERROR undefined\">\\reporttitle</span>\n</div>\n<div id=\"p5\" class=\"ltx_para ltx_align_left\"><span id=\"p5.1\" class=\"ltx_ERROR undefined\">\\reportsubtitle</span>\n</div>\n<div id=\"p6\" class=\"ltx_para ltx_align_left\"><span id=\"p6.1\" class=\"ltx_ERROR undefined\">\\reportauthors</span>\n</div>\n<div id=\"p7\" class=\"ltx_para ltx_align_left\">\n<p id=\"p7.1\" class=\"ltx_p\"><sup id=\"p7.1.1\" class=\"ltx_sup\"><span id=\"p7.1.1.1\" class=\"ltx_ERROR undefined\">\\robotocondensed</span><span id=\"p7.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">1</span></sup><span id=\"p7.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">AIFT, Singapore\n<br class=\"ltx_break\" style=\"--ltx-break-space:2.0pt;\"><sup id=\"p7.1.2.1\" class=\"ltx_sup\"><span id=\"p7.1.2.1.1\" class=\"ltx_ERROR undefined\">\\robotocondensed</span>2</sup>Graduate School of Fundamental Science and Engineering, Department of Computer Science and Communications Engineering, Waseda University, Japan\n<br class=\"ltx_break\" style=\"--ltx-break-space:2.0pt;\"><sup id=\"p7.1.2.2\" class=\"ltx_sup\"><span id=\"p7.1.2.2.1\" class=\"ltx_ERROR undefined\">\\robotocondensed</span>3</sup>Keio Global Research Institute (KGRI), Japan</span></p>\n</div>\n<section id=\"Sx1\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\">Executive Summary</h2>\n\n<div id=\"Sx1.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"Sx1.p1.1\" class=\"ltx_p\">AI agents are now running real transactions, workflows, and sub-agent chains across organizational boundaries, mostly without continuous human supervision. This creates a problem that no current infrastructure is equipped to solve: how do you identify, verify, and hold accountable an entity with no body, no persistent memory, and no legal standing? <span id=\"Sx1.p1.1.1\" class=\"ltx_text ltx_font_italic\">AI Identity is the continuous relationship between what an AI agent is declared to be and what it is observed to do, bounded by the confidence that those two things correspond at any given moment.</span> The identity systems that governed digital life for three decades (passwords, biometrics, and single sign-on) were built for human users, and they have collapsed under the weight of agents that are not human.</p>\n</div>\n<div id=\"Sx1.p2\" class=\"ltx_para\">\n<p id=\"Sx1.p2.1\" class=\"ltx_p\">To understand what identity infrastructure an agent-saturated world actually requires, we surveyed industry trends, emerging standards, and the technical literature, and conducted a structured gap analysis across the full agent identity lifecycle. This report makes three contributions:</p>\n<ol id=\"Sx1.I1\" class=\"ltx_enumerate\">\n<li id=\"Sx1.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"Sx1.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"Sx1.I1.i1.p1.1\" class=\"ltx_p\">A structural comparison of human and AI identity across four dimensions: substrate, persistence, verifiability, and legal standing. The asymmetry is fundamental and extending human frameworks to agents without structural modification produces systematic failures (§<a href=\"#S2\" title=\"2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a>).</p>\n</div></li>\n<li id=\"Sx1.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"Sx1.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"Sx1.I1.i2.p1.1\" class=\"ltx_p\">An evaluation of the state-of-the-art technical and regulatory documents against the identity requirements of autonomous agents, revealing that none adequately address the core challenge of governing nondeterministic, boundary-crossing entities (§<a href=\"#S3\" title=\"3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a>).</p>\n</div></li>\n<li id=\"Sx1.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"Sx1.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"Sx1.I1.i3.p1.1\" class=\"ltx_p\">Identification of five critical gaps (semantic intent verification, recursive delegation accountability, agent identity integrity, governance opacity and enforcement, and operational sustainability), none of which current technology or regulatory instruments resolve (§<a href=\"#S4\" title=\"4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a> to <a href=\"#S5\" title=\"5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a>).</p>\n</div></li>\n</ol>\n</div>\n<div id=\"Sx1.p3\" class=\"ltx_para\">\n<p id=\"Sx1.p3.1\" class=\"ltx_p\">These gaps are structural; more engineering effort alone will not close them. Foundational research on AI identity is therefore the central conclusion of this report.</p>\n</div>\n</section>\n<section id=\"S1\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">1 </span>Introduction</h2>\n\n<div id=\"S1.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S1.p1.1\" class=\"ltx_p\">AI agents have moved from research demonstrations to operational infrastructure. Enterprises across finance, healthcare, and enterprise IT now run autonomous agents that chain multi-step API (Application Programming Interface) calls via protocols such as MCP (Model Context Protocol) and A2A (Agent2Agent), spawn sub-agents, and act across organizational boundaries without continuous human supervision <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>, <a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">44</a>]</cite>. Unlike the scripts and bots of earlier generations, modern agents acquire credentials, accumulate context through memory systems, and take irreversible actions at machine speed. This shift is outpacing the governance frameworks meant to oversee it.</p>\n</div>\n<div id=\"S1.p2\" class=\"ltx_para\">\n<p id=\"S1.p2.1\" class=\"ltx_p\">That infrastructure has collapsed under three concurrent failures.</p>\n</div>\n<div id=\"S1.p3\" class=\"ltx_para\">\n<p id=\"S1.p3.1\" class=\"ltx_p\"><span id=\"S1.p3.1.1\" class=\"ltx_text ltx_font_bold\">Organization</span>: non-human identities now outnumber human identities in enterprise environments (a recent analysis of 27 million enterprise NHIs (Non-Human Identities) found a ratio of 144 to 1 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib33\" title=\"\" class=\"ltx_ref\">13</a>]</cite>), yet only 21.9% of organizations treat agents as independent identity principals; the remainder run agents on shared API keys (45.6%) or inherited human credentials never designed for non-human use <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>]</cite>; OAuth and SAML (Security Assertion Markup Language), designed for humans at browsers, are structurally unable to govern agents that spawn sub-agents without human-in-the-loop oversight.</p>\n</div>\n<div id=\"S1.p4\" class=\"ltx_para\">\n<p id=\"S1.p4.1\" class=\"ltx_p\"><span id=\"S1.p4.1.1\" class=\"ltx_text ltx_font_bold\">Regulation</span>: no jurisdiction has established a liability framework for autonomous AI agents: the EU (European Union) AI Act classifies risk but does not assign responsibility when a delegated agent acts outside its mandate <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib8\" title=\"\" class=\"ltx_ref\">18</a>]</cite>; the US (United States) has no federal AI identity legislation; no technical standard covers the full delegation lifecycle.</p>\n</div>\n<div id=\"S1.p5\" class=\"ltx_para\">\n<p id=\"S1.p5.1\" class=\"ltx_p\"><span id=\"S1.p5.1.1\" class=\"ltx_text ltx_font_bold\">Technology</span>: agents are nondeterministic: the same model weights produce different outputs even on the same inputs, so a credential that verifies what an agent <span id=\"S1.p5.1.2\" class=\"ltx_text ltx_font_italic\">is</span> cannot guarantee what it will <span id=\"S1.p5.1.3\" class=\"ltx_text ltx_font_italic\">do</span>; agents are cloneable: model weights can be copied and run across many concurrent instances, making instance uniqueness unenforceable without hardware binding; and agents can be sessionless: lacking persistent memory across interactions by default, there is no stable substrate to anchor a continuous identity to.</p>\n</div>\n<div id=\"S1.p6\" class=\"ltx_para ltx_noindent\">\n<p id=\"S1.p6.1\" class=\"ltx_p\">These concurrent failures define the central question this report addresses: <span id=\"S1.p6.1.1\" class=\"ltx_text ltx_font_italic\">what identity infrastructure does an agent-saturated world require?</span> We address it through four research sub-questions, each answered in a dedicated section:</p>\n</div>\n<div id=\"S1.p7\" class=\"ltx_para\">\n<ol id=\"S1.I1\" class=\"ltx_enumerate\">\n<li id=\"S1.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S1.I1.i1.1\" class=\"ltx_text ltx_font_bold\">RQ1.</span></span> \n<div id=\"S1.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i1.p1.1\" class=\"ltx_p\">How should identity for AI agents fundamentally differ from identity for humans, and what should be the structural consequences of that asymmetry? (§<a href=\"#S2\" title=\"2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a>)</p>\n</div></li>\n<li id=\"S1.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S1.I1.i2.1\" class=\"ltx_text ltx_font_bold\">RQ2.</span></span> \n<div id=\"S1.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i2.p1.1\" class=\"ltx_p\">Do current market solutions and emerging standards adequately address the identity requirements of autonomous, nondeterministic AI agents? (§<a href=\"#S3\" title=\"3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a>)</p>\n</div></li>\n<li id=\"S1.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S1.I1.i3.1\" class=\"ltx_text ltx_font_bold\">RQ3.</span></span> \n<div id=\"S1.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i3.p1.1\" class=\"ltx_p\">What technologies are available to address the identity requirements of autonomous AI agents, and where do current solutions fall short? (§<a href=\"#S4\" title=\"4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a>)</p>\n</div></li>\n<li id=\"S1.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S1.I1.i4.1\" class=\"ltx_text ltx_font_bold\">RQ4.</span></span> \n<div id=\"S1.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i4.p1.1\" class=\"ltx_p\">What structural gaps persist across all current approaches, what are the hard boundaries of existing solutions, and what research directions does each gap motivate? (§<a href=\"#S5\" title=\"5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a>)</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S1.p8\" class=\"ltx_para\">\n<p id=\"S1.p8.1\" class=\"ltx_p\">Answering these questions directly benefits both industry and research: practitioners gain structured criteria for evaluating and deploying agent identity infrastructure, standards bodies gain a precise map of where current proposals fall short, and researchers gain a set of hard open problems with clear boundaries, the starting conditions for rigorous scientific progress.</p>\n</div>\n<div id=\"S1.p9\" class=\"ltx_para\">\n<p id=\"S1.p9.1\" class=\"ltx_p\">To scope the analysis, we searched academic literature, standards corpora (e.g., IETF, OpenID Foundation, W3C, and NIST), regulatory documents, and gray literature including industry reports, market analyses, and vendor whitepapers. Search terms combined identity-related concepts (such as non-human identity, authentication, authorization, delegation, and workload identity) with agent-related terms (such as AI agent, agentic AI, autonomous agent, and multi-agent system). Sources were prioritized from 2024–2026 to capture the rapidly evolving landscape, supplemented by foundational prior work where necessary. In total, approximately 80 sources were reviewed; those directly supporting the analysis are cited throughout the report.</p>\n</div>\n<div id=\"S1.p10\" class=\"ltx_para\">\n<p id=\"S1.p10.1\" class=\"ltx_p\">The remainder of the report proceeds as follows. Section <a href=\"#S2\" title=\"2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> establishes the conceptual foundation by comparing human and AI identity across four structural dimensions. Section <a href=\"#S3\" title=\"3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> maps the market landscape, standards trajectory, and regulatory context. Section <a href=\"#S4\" title=\"4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a> surveys the technologies that the market has proposed as solutions and identifies critical gaps where those solutions fail. Section <a href=\"#S5\" title=\"5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a> analyzes the structural nature of those gaps and embeds research directions within each gap subsection. Section <a href=\"#S6\" title=\"6 Conclusion\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6</span></a> synthesizes the findings and proposes a unifying theoretical frame for the research agenda.</p>\n</div>\n</section>\n<section id=\"S2\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">2 </span>RQ1: Comparison of Human and Non-Human Identities</h2>\n\n<div id=\"S2.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.p1.1\" class=\"ltx_p\">Before surveying technologies or markets, we need to understand what identity means for humans and machines, and why the difference is structural rather than incremental. This section builds the conceptual foundation that everything else depends on.</p>\n</div>\n<section id=\"S2.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">2.1 </span>Human Identity</h3>\n\n<div id=\"S2.SS1.p1\" class=\"ltx_para\">\n<p id=\"S2.SS1.p1.1\" class=\"ltx_p\">Human identity rests on a biological substrate, namely DNA, neural tissue, and the physiological continuity of a living body, that persists across time and context <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">55</a>]</cite>.\nA person remains recognizably the same individual through sleep, conversation, and shifts in social role. This continuity anchors every major identity system. Biometric verification assumes that fingerprints, facial geometry, and iris patterns are stable signatures of a unique biological entity. Social institutions, including birth certificates, passports, and employment records, assume a persistent subject to whom rights and obligations attach. Legal frameworks reinforce this by treating identity as both a fundamental right (e.g., GDPR (General Data Protection Regulation) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib5\" title=\"\" class=\"ltx_ref\">15</a>]</cite>, eIDAS 2.0 (Electronic Identification, Authentication and Trust Services) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib7\" title=\"\" class=\"ltx_ref\">16</a>]</cite>) and, increasingly, as commercial property subject to explicit consent and control <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib6\" title=\"\" class=\"ltx_ref\">8</a>, <a href=\"#bib.bib9\" title=\"\" class=\"ltx_ref\">47</a>]</cite>.</p>\n</div>\n</section>\n<section id=\"S2.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">2.2 </span>Non-Human Identity</h3>\n\n<figure id=\"S2.T1\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_table\">Table 1: </span>Summary of non-human identity types.</figcaption>\n<table id=\"S2.T1.2\" class=\"ltx_tabular ltx_centering ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S2.T1.2.1\" class=\"ltx_tr\">\n<th id=\"S2.T1.2.1.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S2.T1.2.1.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:51.2pt;\">\n<span id=\"S2.T1.2.1.1.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Type</span></span>\n</span></th>\n<th id=\"S2.T1.2.1.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S2.T1.2.1.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:142.3pt;\">\n<span id=\"S2.T1.2.1.2.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">What it represents</span></span>\n</span></th>\n<th id=\"S2.T1.2.1.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S2.T1.2.1.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:119.5pt;\">\n<span id=\"S2.T1.2.1.3.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Typical artifact</span></span>\n</span></th>\n<th id=\"S2.T1.2.1.4\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S2.T1.2.1.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:79.7pt;\">\n<span id=\"S2.T1.2.1.4.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.1.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Lifecycle</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S2.T1.2.2\" class=\"ltx_tr\">\n<td id=\"S2.T1.2.2.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.2.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:51.2pt;\">\n<span id=\"S2.T1.2.2.1.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.2.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Model</span></span>\n</span></td>\n<td id=\"S2.T1.2.2.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.2.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:142.3pt;\">\n<span id=\"S2.T1.2.2.2.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Trained artifact: weights, architecture, provenance</span></span>\n</span></td>\n<td id=\"S2.T1.2.2.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.2.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:119.5pt;\">\n<span id=\"S2.T1.2.2.3.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Model card, weight hash</span></span>\n</span></td>\n<td id=\"S2.T1.2.2.4\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.2.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:79.7pt;\">\n<span id=\"S2.T1.2.2.4.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.2.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Stable until retrained</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.2.3\" class=\"ltx_tr\">\n<td id=\"S2.T1.2.3.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.3.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:51.2pt;\">\n<span id=\"S2.T1.2.3.1.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.3.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agent</span></span>\n</span></td>\n<td id=\"S2.T1.2.3.2\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.3.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:142.3pt;\">\n<span id=\"S2.T1.2.3.2.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Configured deployment: system prompt, persona, tool grants</span></span>\n</span></td>\n<td id=\"S2.T1.2.3.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.3.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:119.5pt;\">\n<span id=\"S2.T1.2.3.3.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agent card, system prompt hash</span></span>\n</span></td>\n<td id=\"S2.T1.2.3.4\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.3.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:79.7pt;\">\n<span id=\"S2.T1.2.3.4.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.3.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Session / task</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.2.4\" class=\"ltx_tr\">\n<td id=\"S2.T1.2.4.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.4.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:51.2pt;\">\n<span id=\"S2.T1.2.4.1.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.4.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Workload</span></span>\n</span></td>\n<td id=\"S2.T1.2.4.2\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.4.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:142.3pt;\">\n<span id=\"S2.T1.2.4.2.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Running process / container / service instance</span></span>\n</span></td>\n<td id=\"S2.T1.2.4.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.4.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:119.5pt;\">\n<span id=\"S2.T1.2.4.3.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">SPIFFE SVID (X.509 / JWT)</span></span>\n</span></td>\n<td id=\"S2.T1.2.4.4\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.4.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:79.7pt;\">\n<span id=\"S2.T1.2.4.4.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.4.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Ephemeral</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.2.5\" class=\"ltx_tr\">\n<td id=\"S2.T1.2.5.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.5.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:51.2pt;\">\n<span id=\"S2.T1.2.5.1.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.5.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Delegated</span></span>\n</span></td>\n<td id=\"S2.T1.2.5.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.5.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:142.3pt;\">\n<span id=\"S2.T1.2.5.2.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Authorization derived from a human / org principal</span></span>\n</span></td>\n<td id=\"S2.T1.2.5.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.5.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:119.5pt;\">\n<span id=\"S2.T1.2.5.3.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">OAuth token, JWT </span><span id=\"S2.T1.2.5.3.1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">act</span><span id=\"S2.T1.2.5.3.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> claim</span></span>\n</span></td>\n<td id=\"S2.T1.2.5.4\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.2.5.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:79.7pt;\">\n<span id=\"S2.T1.2.5.4.1.1\" class=\"ltx_p\"><span id=\"S2.T1.2.5.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Scoped to grant</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n<div id=\"S2.SS2.p1\" class=\"ltx_para\">\n<p id=\"S2.SS2.p1.1\" class=\"ltx_p\">This biological foundation, and the continuity and legal standing that rest on it, has no counterpart in AI. There is no biological substrate, no subjective continuity, and no inherent social standing. It is useful to separate NHI into four distinct types, because conflating them leads to mismatched solutions (Table <a href=\"#S2.T1\" title=\"Table 1 ‣ 2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1</span></a>).</p>\n</div>\n<div id=\"S2.SS2.p2\" class=\"ltx_para\">\n<p id=\"S2.SS2.p2.1\" class=\"ltx_p\">At the <span id=\"S2.SS2.p2.1.1\" class=\"ltx_text ltx_font_italic\">model level</span>, identity is the trained artifact itself: the <span id=\"S2.SS2.p2.1.2\" class=\"ltx_text ltx_font_italic\">weights</span> (learned behavior), the <span id=\"S2.SS2.p2.1.3\" class=\"ltx_text ltx_font_italic\">architecture</span> (how those weights process inputs), and the training provenance (what data shaped them). These properties stay stable between deployments, but they are not uniquely identifying in the way a fingerprint is: two deployments of the same weights are the same model-level identity, even if they behave differently in context <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib15\" title=\"\" class=\"ltx_ref\">2</a>, <a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">55</a>, <a href=\"#bib.bib17\" title=\"\" class=\"ltx_ref\">30</a>]</cite>. Model cards <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib10\" title=\"\" class=\"ltx_ref\">34</a>]</cite> are the closest existing artifact to a model-level identity document, recording training data, intended use, and evaluation results. They are, however, descriptive and non-binding: a model card is a disclosure, not a verifiable credential, and it provides no cryptographic guarantee that a deployed model corresponds to what the card describes.</p>\n</div>\n<div id=\"S2.SS2.p3\" class=\"ltx_para\">\n<p id=\"S2.SS2.p3.1\" class=\"ltx_p\">At the <span id=\"S2.SS2.p3.1.1\" class=\"ltx_text ltx_font_italic\">agent level</span>, identity is constituted by the configuration and runtime state that shapes a specific deployment: a <span id=\"S2.SS2.p3.1.2\" class=\"ltx_text ltx_font_italic\">system prompt</span> that defines the agent’s role and constraints but is manipulable via prompt injection; a <span id=\"S2.SS2.p3.1.3\" class=\"ltx_text ltx_font_italic\">persona or behavioral specification</span> (such as OpenClaw’s <span id=\"S2.SS2.p3.1.4\" class=\"ltx_text ltx_font_typewriter\">SOUL.md</span> file) that encodes persistent values and goals; the <span id=\"S2.SS2.p3.1.5\" class=\"ltx_text ltx_font_italic\">tool calls and capabilities</span> the agent has been granted access to; and externally assigned <span id=\"S2.SS2.p3.1.6\" class=\"ltx_text ltx_font_italic\">credentials</span> that can be revoked, rotated, or shared <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">44</a>]</cite>. All of these are mutable, and none is uniquely tied to a singular entity in the way a fingerprint is tied to a body. This level is where most identity-related vulnerabilities arise: a system prompt can be injected, credentials can be stolen, and tool access can be abused without any change to the underlying model.</p>\n</div>\n<div id=\"S2.SS2.p4\" class=\"ltx_para\">\n<p id=\"S2.SS2.p4.1\" class=\"ltx_p\">At the <span id=\"S2.SS2.p4.1.1\" class=\"ltx_text ltx_font_italic\">workload level</span>, identity is the runtime instance of a process, container, or service: not which model or which configuration, but <span id=\"S2.SS2.p4.1.2\" class=\"ltx_text ltx_font_italic\">which specific execution</span> is on the wire right now, on which host, under which cloud account. The operative credential is an ephemeral, attestation-bound certificate or JWT (JSON Web Token) issued by a workload identity authority such as SPIFFE (Secure Production Identity Framework For Everyone)/SPIRE (SPIFFE Runtime Environment), which verifies properties of the requesting process before issuing it an SVID (SPIFFE Verifiable Identity Document) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>]</cite>. The same agent configuration may run as thousands of simultaneous workload instances; workload identity distinguishes them at the infrastructure layer without requiring per-instance enrollment. Its critical limitation is scope: it authenticates the container and not the content, proving that a trusted process is on the wire but providing no guarantee about what that process will do next.</p>\n</div>\n<div id=\"S2.SS2.p5\" class=\"ltx_para\">\n<p id=\"S2.SS2.p5.1\" class=\"ltx_p\">At the <span id=\"S2.SS2.p5.1.1\" class=\"ltx_text ltx_font_italic\">delegated level</span>, identity is constituted not by what an entity <span id=\"S2.SS2.p5.1.2\" class=\"ltx_text ltx_font_italic\">is</span> but by what it has been <span id=\"S2.SS2.p5.1.3\" class=\"ltx_text ltx_font_italic\">authorized to do on behalf of</span> a human or organizational principal. A delegated identity is carried by a verifiable grant, such as an OAuth 2.0 access token, a JWT (JSON Web Token) with an <span id=\"S2.SS2.p5.1.4\" class=\"ltx_text ltx_font_typewriter\">act</span> (actor) claim, or a signed capability document, that traces the authorization chain back to a principal with legal standing <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">44</a>, <a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>]</cite>. The defining constraint is <span id=\"S2.SS2.p5.1.5\" class=\"ltx_text ltx_font_italic\">scope attenuation</span>: each delegation hop must narrow, never widen, the set of permitted actions, so that no sub-agent can accumulate capabilities the original human principal did not authorize. Delegated identity is not a peer type in the same sense as the other three; any model, agent, or workload identity can carry a delegated grant. It is named separately here because the <span id=\"S2.SS2.p5.1.6\" class=\"ltx_text ltx_font_italic\">absence</span> of a deployed standard for multi-hop delegation chain verification is the central accountability gap examined in §<a href=\"#S4.SS2\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.2</span></a> and §<a href=\"#S5\" title=\"5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a>.</p>\n</div>\n</section>\n<section id=\"S2.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">2.3 </span>A Four-Dimension Comparison</h3>\n\n<figure id=\"S2.T2\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_table\">Table 2: </span>Four-dimension comparison of human and AI identity.</figcaption>\n<table id=\"S2.T2.2\" class=\"ltx_tabular ltx_centering ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S2.T2.2.1\" class=\"ltx_tr\">\n<th id=\"S2.T2.2.1.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S2.T2.2.1.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:68.3pt;\">\n<span id=\"S2.T2.2.1.1.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Dimension</span></span>\n</span></th>\n<th id=\"S2.T2.2.1.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S2.T2.2.1.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:136.6pt;\">\n<span id=\"S2.T2.2.1.2.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Human</span></span>\n</span></th>\n<th id=\"S2.T2.2.1.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S2.T2.2.1.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:165.0pt;\">\n<span id=\"S2.T2.2.1.3.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">AI Agent</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S2.T2.2.2\" class=\"ltx_tr\">\n<td id=\"S2.T2.2.2.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.2.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:68.3pt;\">\n<span id=\"S2.T2.2.2.1.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.2.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Substrate</span></span>\n</span></td>\n<td id=\"S2.T2.2.2.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.2.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:136.6pt;\">\n<span id=\"S2.T2.2.2.2.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Biological (DNA, neural tissue)</span></span>\n</span></td>\n<td id=\"S2.T2.2.2.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.2.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:165.0pt;\">\n<span id=\"S2.T2.2.2.3.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Computational (model weights, architecture, system prompt, credentials; all mutable)</span></span>\n</span></td></tr>\n<tr id=\"S2.T2.2.3\" class=\"ltx_tr\">\n<td id=\"S2.T2.2.3.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.3.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:68.3pt;\">\n<span id=\"S2.T2.2.3.1.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.3.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Persistence</span></span>\n</span></td>\n<td id=\"S2.T2.2.3.2\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.3.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:136.6pt;\">\n<span id=\"S2.T2.2.3.2.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Continuous across time and context</span></span>\n</span></td>\n<td id=\"S2.T2.2.3.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.3.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:165.0pt;\">\n<span id=\"S2.T2.2.3.3.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Continuous at the model level, but operational context resets frequently; shorter lifecycle and higher sensitivity to configuration changes than human identity</span></span>\n</span></td></tr>\n<tr id=\"S2.T2.2.4\" class=\"ltx_tr\">\n<td id=\"S2.T2.2.4.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.4.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:68.3pt;\">\n<span id=\"S2.T2.2.4.1.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.4.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Verifiability</span></span>\n</span></td>\n<td id=\"S2.T2.2.4.2\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.4.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:136.6pt;\">\n<span id=\"S2.T2.2.4.2.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Biometric features serve as stable anchors for point-in-time verification</span></span>\n</span></td>\n<td id=\"S2.T2.2.4.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.4.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:165.0pt;\">\n<span id=\"S2.T2.2.4.3.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">No stable behavioral anchor; point-in-time verification is inherently incomplete because identical inputs can produce different outputs (due to temperature sampling and context drift), and configuration changes alter behavior between enrollment and action</span></span>\n</span></td></tr>\n<tr id=\"S2.T2.2.5\" class=\"ltx_tr\">\n<td id=\"S2.T2.2.5.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.5.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:68.3pt;\">\n<span id=\"S2.T2.2.5.1.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.5.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Legal standing</span></span>\n</span></td>\n<td id=\"S2.T2.2.5.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.5.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:136.6pt;\">\n<span id=\"S2.T2.2.5.2.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Fundamental right (GDPR) and commercial property (AB 2602, ELVIS Act)</span></span>\n</span></td>\n<td id=\"S2.T2.2.5.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T2.2.5.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:165.0pt;\">\n<span id=\"S2.T2.2.5.3.1.1\" class=\"ltx_p\"><span id=\"S2.T2.2.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">No legal personhood; identity is delegated from a human or organizational principal</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n<div id=\"S2.SS3.p1\" class=\"ltx_para\">\n<p id=\"S2.SS3.p1.1\" class=\"ltx_p\">To make the structural asymmetry precise, Table <a href=\"#S2.T2\" title=\"Table 2 ‣ 2.3 A Four-Dimension Comparison ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> compares human and AI identity across four key dimensions. <span id=\"S2.SS3.p1.1.1\" class=\"ltx_text ltx_font_italic\">It is clear that the identity infrastructure required for AI agents cannot be derived by relaxing or extending the infrastructure designed for humans.</span> It must be designed from first principles, with the four asymmetries in Table <a href=\"#S2.T2\" title=\"Table 2 ‣ 2.3 A Four-Dimension Comparison ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> treated as architectural constraints rather than edge cases. How the market and standards community have begun to respond to this challenge is the subject of the next section.</p>\n</div>\n</section>\n</section>\n<section id=\"S3\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">3 </span>RQ2: Industry Trends</h2>\n\n<div id=\"S3.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S3.p1.1\" class=\"ltx_p\">With the conceptual distinction between human and AI identity established, this section surveys the commercial, standards, and regulatory context in which AI identity is developing. We look at how vendors are positioning, what standards bodies have proposed, and what regulators are requiring, to assess whether the response to the structural asymmetry identified in §<a href=\"#S2\" title=\"2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> is adequate.</p>\n</div>\n<section id=\"S3.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">3.1 </span>Vendor Direction and Emerging Players</h3>\n\n<div id=\"S3.SS1.p1\" class=\"ltx_para\">\n<p id=\"S3.SS1.p1.1\" class=\"ltx_p\">The vendor landscape can be read as a set of partial answers to distinct stages of the agent identity lifecycle, with no single product spanning enrollment, runtime authorization, and behavioral accountability.</p>\n</div>\n<div id=\"S3.SS1.p2\" class=\"ltx_para\">\n<p id=\"S3.SS1.p2.1\" class=\"ltx_p\"><span id=\"S3.SS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Governance and lifecycle consolidation.</span> One cluster addresses the enrollment and lifecycle problem: who provisions an agent, under what policy, and how is it decommissioned. Saviynt <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib18\" title=\"\" class=\"ltx_ref\">46</a>]</cite> unifies human IAM (Identity and Access Management), machine identity, and privileged access under a single governance platform, while RadiantOne <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib36\" title=\"\" class=\"ltx_ref\">43</a>]</cite> provides correlation across identity silos so that agent accounts do not fragment into shadow inventories. Astrix has been recognized by Gartner for NHI-specific posture management <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib34\" title=\"\" class=\"ltx_ref\">3</a>]</cite>, focusing on discovery and risk scoring of existing non-human principals. Coordinating this direction, the NHIMG (Non-Human Identity Management Group) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">36</a>]</cite> is defining governance baselines that treat agents as first-class principals rather than elevated service accounts. These tools solve visibility and policy attachment, but operate above the credential layer and assume the existence of a trustworthy identity to govern.</p>\n</div>\n<div id=\"S3.SS1.p3\" class=\"ltx_para\">\n<p id=\"S3.SS1.p3.1\" class=\"ltx_p\"><span id=\"S3.SS1.p3.1.1\" class=\"ltx_text ltx_font_bold\">Runtime credentials and trust verification.</span> A second cluster targets the issuance and verification problem: producing cryptographic identities an agent can present at runtime and evaluating whether a counterparty should accept them. HashiCorp’s Vault 1.21 introduced native SPIFFE (Secure Production Identity Framework For Everyone) authentication <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib37\" title=\"\" class=\"ltx_ref\">22</a>]</cite>, enabling ephemeral, attestation-bound workload identities issued directly within the secrets management layer. Vouched’s KYA (Know Your Agent) platform <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib19\" title=\"\" class=\"ltx_ref\">52</a>]</cite> extends KYC (Know Your Customer)-style verification to autonomous software. HUMAN Security’s AgenticTrust <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib35\" title=\"\" class=\"ltx_ref\">25</a>]</cite> sits at the relying-party side, treating the boundary between a malicious bot and an authorized agent as a contextual judgment over provenance and delegation rather than a network-signature problem. Collectively, these products issue, verify, and govern agent identities, but they do so against incompatible credential formats, trust roots, and delegation semantics, a fragmentation that motivates the standards survey in the next section.</p>\n</div>\n</section>\n<section id=\"S3.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">3.2 </span>Standards Landscape</h3>\n\n<figure id=\"S3.T3\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption ltx_centering\" style=\"font-size:90%;\"><span class=\"ltx_tag ltx_tag_table\">Table 3: </span>Standards evaluation for agentic identity, grouped by document type.</figcaption>\n<table id=\"S3.T3.4\" class=\"ltx_tabular ltx_centering ltx_guessed_headers ltx_align_middle\">\n<tbody class=\"ltx_tbody\">\n<tr id=\"S3.T3.4.1\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.1.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_tt\"><span id=\"S3.T3.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Category</span></th>\n<th id=\"S3.T3.4.1.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row ltx_border_tt\">\n<span id=\"S3.T3.4.1.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.1.2.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Standard</span></span>\n</span></th>\n<td id=\"S3.T3.4.1.3\" class=\"ltx_td ltx_align_left ltx_border_tt\"><span id=\"S3.T3.4.1.3.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Verdict</span></td>\n<td id=\"S3.T3.4.1.4\" class=\"ltx_td ltx_align_left ltx_border_tt\"><span id=\"S3.T3.4.1.4.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Key Limitation</span></td></tr>\n<tr id=\"S3.T3.4.2\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.2.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_t\" rowspan=\"5\"><span id=\"S3.T3.4.2.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Protocol</span></th>\n<th id=\"S3.T3.4.2.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row ltx_border_t\">\n<span id=\"S3.T3.4.2.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.2.2.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">OAuth 2.0</span></span>\n</span></th>\n<td id=\"S3.T3.4.2.3\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.2.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Partial</span></td>\n<td id=\"S3.T3.4.2.4\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.2.4.1\" class=\"ltx_text\" style=\"font-size:90%;\">No multi-hop or scope-to-skill mapping</span></td></tr>\n<tr id=\"S3.T3.4.3\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.3.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row\">\n<span id=\"S3.T3.4.3.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.3.1.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.3.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">SAML</span></span>\n</span></th>\n<td id=\"S3.T3.4.3.2\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Fails</span></td>\n<td id=\"S3.T3.4.3.3\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.3.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Session-based; assumes human browser</span></td></tr>\n<tr id=\"S3.T3.4.4\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.4.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row\">\n<span id=\"S3.T3.4.4.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.4.1.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.4.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">WIMSE/SPIFFE</span></span>\n</span></th>\n<td id=\"S3.T3.4.4.2\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Available</span></td>\n<td id=\"S3.T3.4.4.3\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.4.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Identity layer only; no authorization</span></td></tr>\n<tr id=\"S3.T3.4.5\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.5.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row\">\n<span id=\"S3.T3.4.5.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.5.1.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.5.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">MCP</span></span>\n</span></th>\n<td id=\"S3.T3.4.5.2\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.5.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Partial</span></td>\n<td id=\"S3.T3.4.5.3\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.5.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Identity out of scope by design</span></td></tr>\n<tr id=\"S3.T3.4.6\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.6.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row\">\n<span id=\"S3.T3.4.6.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.6.1.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.6.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">A2A</span></span>\n</span></th>\n<td id=\"S3.T3.4.6.2\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.6.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Partial</span></td>\n<td id=\"S3.T3.4.6.3\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.6.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">JWS integrity only; token lifetime, scope, and consent gaps</span></td></tr>\n<tr id=\"S3.T3.4.7\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.7.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_t\" rowspan=\"2\"><span id=\"S3.T3.4.7.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Specification</span></th>\n<th id=\"S3.T3.4.7.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row ltx_border_t\">\n<span id=\"S3.T3.4.7.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.7.2.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.7.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">OpenID Agentic AI</span></span>\n</span></th>\n<td id=\"S3.T3.4.7.3\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.7.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Partial</span></td>\n<td id=\"S3.T3.4.7.4\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.7.4.1\" class=\"ltx_text\" style=\"font-size:90%;\">CIBA cannot scale; two-tiered web risk</span></td></tr>\n<tr id=\"S3.T3.4.8\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.8.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row\">\n<span id=\"S3.T3.4.8.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.8.1.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.8.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">IETF AIMS</span></span>\n</span></th>\n<td id=\"S3.T3.4.8.2\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.8.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Partial</span></td>\n<td id=\"S3.T3.4.8.3\" class=\"ltx_td ltx_align_left\"><span id=\"S3.T3.4.8.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Architecture draft composing existing standards; security sections TODO</span></td></tr>\n<tr id=\"S3.T3.4.9\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.9.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_t\"><span id=\"S3.T3.4.9.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Regulation</span></th>\n<th id=\"S3.T3.4.9.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row ltx_border_t\">\n<span id=\"S3.T3.4.9.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.9.2.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.9.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">eIDAS 2.0</span></span>\n</span></th>\n<td id=\"S3.T3.4.9.3\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.9.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Infra/Human</span></td>\n<td id=\"S3.T3.4.9.4\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.9.4.1\" class=\"ltx_text\" style=\"font-size:90%;\">Wallet mandate; designed for citizens</span></td></tr>\n<tr id=\"S3.T3.4.10\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.10.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_bb ltx_border_t\" rowspan=\"3\"><span id=\"S3.T3.4.10.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Guideline</span></th>\n<th id=\"S3.T3.4.10.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row ltx_border_t\">\n<span id=\"S3.T3.4.10.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.10.2.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.10.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">NIST NCCoE</span></span>\n</span></th>\n<td id=\"S3.T3.4.10.3\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.10.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Directional</span></td>\n<td id=\"S3.T3.4.10.4\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S3.T3.4.10.4.1\" class=\"ltx_text\" style=\"font-size:90%;\">Concept paper; no implementation guidance</span></td></tr>\n<tr id=\"S3.T3.4.11\" class=\"ltx_tr\">\n<th id=\"S3.T3.4.11.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_row ltx_border_bb\">\n<span id=\"S3.T3.4.11.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:91.0pt;\">\n<span id=\"S3.T3.4.11.1.1.1\" class=\"ltx_p\"><span id=\"S3.T3.4.11.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">OWASP Top 10 for Agentic Applications</span></span>\n</span></th>\n<td id=\"S3.T3.4.11.2\" class=\"ltx_td ltx_align_left ltx_border_bb\"><span id=\"S3.T3.4.11.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Directional</span></td>\n<td id=\"S3.T3.4.11.3\" class=\"ltx_td ltx_align_left ltx_border_bb\"><span id=\"S3.T3.4.11.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">Top 10 risks with mitigation guidelines; no identity protocol</span></td></tr>\n</tbody>\n</table>\n</figure>\n<div id=\"S3.SS2.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S3.SS2.p1.1\" class=\"ltx_p\">We evaluated technical and regulatory documents by asking what function each performs in the AI identity lifecycle (Table <a href=\"#S3.T3\" title=\"Table 3 ‣ 3.2 Standards Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a>): How does it handle <span id=\"S3.SS2.p1.1.1\" class=\"ltx_text ltx_font_italic\">authentication</span>, <span id=\"S3.SS2.p1.1.2\" class=\"ltx_text ltx_font_italic\">authorization and delegation</span>, <span id=\"S3.SS2.p1.1.3\" class=\"ltx_text ltx_font_italic\">credential issuance and portability</span>, and <span id=\"S3.SS2.p1.1.4\" class=\"ltx_text ltx_font_italic\">governance and diagnostics</span>? For each, we assigned a verdict: <span id=\"S3.SS2.p1.1.5\" class=\"ltx_text ltx_font_italic\">Available</span> (production-ready), <span id=\"S3.SS2.p1.1.6\" class=\"ltx_text ltx_font_italic\">Partial</span> (structural gaps), <span id=\"S3.SS2.p1.1.7\" class=\"ltx_text ltx_font_italic\">Fails</span> (architecturally incompatible), <span id=\"S3.SS2.p1.1.8\" class=\"ltx_text ltx_font_italic\">Directional</span> (conceptually sound but no implementation guidance), or <span id=\"S3.SS2.p1.1.9\" class=\"ltx_text ltx_font_italic\">Diagnostic</span> (identifies problems without solutions). Table <a href=\"#S3.T3\" title=\"Table 3 ‣ 3.2 Standards Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> summarizes the results. The structural pattern is clear: no single standard spans the full agent identity lifecycle, and the gaps are not random: they cluster at the hardest parts of the problem.</p>\n</div>\n<div id=\"S3.SS2.p2\" class=\"ltx_para\">\n<p id=\"S3.SS2.p2.1\" class=\"ltx_p\">For <span id=\"S3.SS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">authentication</span>, WIMSE (Workload Identity in Multi-cloud and Service Environments)/SPIFFE is the most mature option, providing ephemeral, attestation-bound workload credentials at scale <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>]</cite> (see §<a href=\"#S4.SS1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.1</span></a>). The IETF AIMS draft (an individual submission to the WIMSE working group) offers a more comprehensive vision including dual-identity credentials and explicit agent lifecycle management, but leaves key security considerations unresolved. SAML fails outright: its session-based, browser-mediated architecture cannot accommodate non-human principals.</p>\n</div>\n<div id=\"S3.SS2.p3\" class=\"ltx_para\">\n<p id=\"S3.SS2.p3.1\" class=\"ltx_p\">For <span id=\"S3.SS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">authorization and delegation</span>, OAuth 2.0 handles one-hop delegation well but lacks multi-hop chaining, cross-domain asynchronous flows, and any mapping between OAuth scopes and agent capabilities. MCP has achieved remarkable adoption <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>]</cite> and added OAuth 2.1 support, but it suffers from specific authorization failures (see §<a href=\"#S4.SS2\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.2</span></a>). Google’s A2A provides agent discovery and integrity via JWS (JSON Web Signature) signing but delegates all authorization and identity decisions to other protocols. The OpenID Foundation’s proposed OBO (On-Behalf-Of) flows acknowledge the impersonation accountability gap, but reliance on CIBA (Client-Initiated Backchannel Authentication) for human-in-the-loop consent cannot scale to autonomous agent throughput.</p>\n</div>\n<div id=\"S3.SS2.p4\" class=\"ltx_para\">\n<p id=\"S3.SS2.p4.1\" class=\"ltx_p\">For <span id=\"S3.SS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">governance and diagnostics</span>, eIDAS 2.0 mandates EU-wide wallet infrastructure but targets citizens rather than agents. The NIST (National Institute of Standards and Technology) NCCoE (National Cybersecurity Center of Excellence) has published a concept paper identifying five focus areas but no implementation guidance <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">5</a>]</cite>. OWASP’s (Open Web Application Security Project) Top 10 for Agentic Applications catalogs the ten highest-impact agentic security risks and provides mitigation guidelines for each, but does not define identity protocols or prescribe implementable authorization controls <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">41</a>]</cite>. These three are valuable as orientation documents, but the absence of implementation guidance means practitioners cannot derive concrete controls from them.</p>\n</div>\n<div id=\"S3.SS2.p5\" class=\"ltx_para\">\n<p id=\"S3.SS2.p5.1\" class=\"ltx_p\">The overall picture that emerges is that authentication is the most mature function, authorization and delegation are partially addressed for simple cases and completely unaddressed for multi-hop chains, and governance remains largely diagnostic.</p>\n</div>\n</section>\n<section id=\"S3.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">3.3 </span>Regulatory Landscape</h3>\n\n<figure id=\"S3.T4\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption ltx_centering\" style=\"font-size:90%;\"><span class=\"ltx_tag ltx_tag_table\">Table 4: </span>AI identity regulation across five jurisdictions.</figcaption>\n<table id=\"S3.T4.4\" class=\"ltx_tabular ltx_centering ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S3.T4.4.1\" class=\"ltx_tr\">\n<th id=\"S3.T4.4.1.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_th_row ltx_border_tt\"><span id=\"S3.T4.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Jurisdiction</span></th>\n<th id=\"S3.T4.4.1.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S3.T4.4.1.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:341.4pt;\">\n<span id=\"S3.T4.4.1.2.1.1\" class=\"ltx_p\"><span id=\"S3.T4.4.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Key Instruments</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S3.T4.4.2\" class=\"ltx_tr\">\n<th id=\"S3.T4.4.2.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_t\"><span id=\"S3.T4.4.2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">EU</span></th>\n<td id=\"S3.T4.4.2.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top ltx_border_t\">\n<span id=\"S3.T4.4.2.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:341.4pt;\">\n<span id=\"S3.T4.4.2.2.1.1\" class=\"ltx_p\"><span id=\"S3.T4.4.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">AI Act Art. 50 (transparency obligations, effective Aug 2026) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.2.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib8\" title=\"\" class=\"ltx_ref\">18</a><span id=\"S3.T4.4.2.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.2.2.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">; Code of Practice on AI-generated content (Dec 2025) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.2.2.1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib24\" title=\"\" class=\"ltx_ref\">14</a><span id=\"S3.T4.4.2.2.1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.2.2.1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\">; eIDAS 2.0 EUDI Wallet </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.2.2.1.1.8\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib7\" title=\"\" class=\"ltx_ref\">16</a><span id=\"S3.T4.4.2.2.1.1.9\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.2.2.1.1.10\" class=\"ltx_text\" style=\"font-size:90%;\">; Cyber Resilience Act (Dec 2024) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.2.2.1.1.11\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib25\" title=\"\" class=\"ltx_ref\">17</a><span id=\"S3.T4.4.2.2.1.1.12\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite></span>\n</span></td></tr>\n<tr id=\"S3.T4.4.3\" class=\"ltx_tr\">\n<th id=\"S3.T4.4.3.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\"><span id=\"S3.T4.4.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">US</span></th>\n<td id=\"S3.T4.4.3.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top\">\n<span id=\"S3.T4.4.3.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:341.4pt;\">\n<span id=\"S3.T4.4.3.2.1.1\" class=\"ltx_p\"><span id=\"S3.T4.4.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">NIST NCCoE concept paper </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.3.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">5</a><span id=\"S3.T4.4.3.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.3.2.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\"> (5 focus areas); CAISI AI Agent Standards Initiative (Feb 2026) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.3.2.1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib49\" title=\"\" class=\"ltx_ref\">37</a><span id=\"S3.T4.4.3.2.1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.3.2.1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\"> (3 pillars); OMB M-25-21 </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.3.2.1.1.8\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib26\" title=\"\" class=\"ltx_ref\">38</a><span id=\"S3.T4.4.3.2.1.1.9\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.3.2.1.1.10\" class=\"ltx_text\" style=\"font-size:90%;\"> (high-impact AI categories); no federal AI identity law</span></span>\n</span></td></tr>\n<tr id=\"S3.T4.4.4\" class=\"ltx_tr\">\n<th id=\"S3.T4.4.4.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\"><span id=\"S3.T4.4.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">China</span></th>\n<td id=\"S3.T4.4.4.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top\">\n<span id=\"S3.T4.4.4.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:341.4pt;\">\n<span id=\"S3.T4.4.4.2.1.1\" class=\"ltx_p\"><span id=\"S3.T4.4.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Measures for Labeling AI-Generated Content (Sep 2025, GB 45438-2025) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.4.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib27\" title=\"\" class=\"ltx_ref\">12</a><span id=\"S3.T4.4.4.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.4.2.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">; CAC Generative AI Measures (Aug 2023) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.4.2.1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib28\" title=\"\" class=\"ltx_ref\">11</a><span id=\"S3.T4.4.4.2.1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.4.2.1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\">; Revised Cybersecurity Law Art. 20 </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.4.2.1.1.8\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib43\" title=\"\" class=\"ltx_ref\">49</a><span id=\"S3.T4.4.4.2.1.1.9\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.4.2.1.1.10\" class=\"ltx_text\" style=\"font-size:90%;\">; draft virtual-human rules (authentication-bypass prohibition)</span></span>\n</span></td></tr>\n<tr id=\"S3.T4.4.5\" class=\"ltx_tr\">\n<th id=\"S3.T4.4.5.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\"><span id=\"S3.T4.4.5.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Japan</span></th>\n<td id=\"S3.T4.4.5.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top\">\n<span id=\"S3.T4.4.5.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:341.4pt;\">\n<span id=\"S3.T4.4.5.2.1.1\" class=\"ltx_p\"><span id=\"S3.T4.4.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">AI Promotion Act (May 2025, innovation-first, no binding obligations) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.5.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib29\" title=\"\" class=\"ltx_ref\">35</a><span id=\"S3.T4.4.5.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.5.2.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">; METI/MIC AI Business Guidelines v1.1 (Mar 2025) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.5.2.1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">33</a><span id=\"S3.T4.4.5.2.1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.5.2.1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\">; Hiroshima AI Process Reporting Framework (Feb 2025) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.5.2.1.1.8\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib31\" title=\"\" class=\"ltx_ref\">19</a><span id=\"S3.T4.4.5.2.1.1.9\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite></span>\n</span></td></tr>\n<tr id=\"S3.T4.4.6\" class=\"ltx_tr\">\n<th id=\"S3.T4.4.6.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_bb\"><span id=\"S3.T4.4.6.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Singapore</span></th>\n<td id=\"S3.T4.4.6.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top ltx_border_bb\">\n<span id=\"S3.T4.4.6.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:341.4pt;\">\n<span id=\"S3.T4.4.6.2.1.1\" class=\"ltx_p\"><span id=\"S3.T4.4.6.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">IMDA Model Governance Framework for Agentic AI (Jan 2026) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.6.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">26</a><span id=\"S3.T4.4.6.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.6.2.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">; four governance dimensions. CSA Addendum on Securing Agentic AI (Oct 2025) </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S3.T4.4.6.2.1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">10</a><span id=\"S3.T4.4.6.2.1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite><span id=\"S3.T4.4.6.2.1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\">; threat T9 (identity spoofing) and authentication controls</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n<div id=\"S3.SS3.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S3.SS3.p1.1\" class=\"ltx_p\">We studied the regulatory landscape across five major jurisdictions to understand what legal obligations an AI agent operating internationally must satisfy and where the gaps are. The most consequential structural challenge for AI identity is not that regulation is absent but that it is fragmented: an agent that complies with the EU’s transparency requirements under AI Act Article 50 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib8\" title=\"\" class=\"ltx_ref\">18</a>]</cite> may violate China’s mandatory content labeling rules. Harmonization will not resolve this: the jurisdictions disagree at a structural level about what problem AI identity regulation is meant to solve (Table <a href=\"#S3.T4\" title=\"Table 4 ‣ 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a>).</p>\n</div>\n<div id=\"S3.SS3.p2\" class=\"ltx_para\">\n<p id=\"S3.SS3.p2.1\" class=\"ltx_p\">The <span id=\"S3.SS3.p2.1.1\" class=\"ltx_text ltx_font_bold\">EU</span> AI Act Article 50 (effective August 2026) requires machine-readable marking of AI-generated content and real-time disclosure to users <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib8\" title=\"\" class=\"ltx_ref\">18</a>]</cite>. The EU AI Office is developing a Code of Practice to implement these obligations <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib24\" title=\"\" class=\"ltx_ref\">14</a>]</cite>. Two instruments address the underlying identity infrastructure: eIDAS 2.0 (Regulation 2024/1183) establishes the EUDI (European Digital Identity) Wallet whose cryptographic foundations could extend to AI-agent authorization through government-issued digital identities <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib7\" title=\"\" class=\"ltx_ref\">16</a>]</cite>, and the CRA (Cyber Resilience Act, in force December 2024) mandates cybersecurity controls for products with digital elements, with AI systems satisfying CRA requirements deemed compliant with AI Act Article 15 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib25\" title=\"\" class=\"ltx_ref\">17</a>]</cite>.</p>\n</div>\n<div id=\"S3.SS3.p3\" class=\"ltx_para\">\n<p id=\"S3.SS3.p3.1\" class=\"ltx_p\">The <span id=\"S3.SS3.p3.1.1\" class=\"ltx_text ltx_font_bold\">US</span> has no federal AI identity legislation. The NIST NCCoE concept paper (February 2026) directly targets the gap, identifying agent authentication, zero-trust authorization, non-repudiation, prompt injection controls, and governance as the five focus areas for AI agent identity management <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">5</a>]</cite>; the CAISI (Center for AI Standards and Innovation) AI Agent Standards Initiative (launched February 2026) is translating these into interoperability standards <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib49\" title=\"\" class=\"ltx_ref\">37</a>]</cite>. OMB Memorandum M-25-21 establishes pre-deployment testing and human oversight requirements for federal agencies deploying biometric AI identification systems, but carries no private-sector mandate <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib26\" title=\"\" class=\"ltx_ref\">38</a>]</cite>.</p>\n</div>\n<div id=\"S3.SS3.p4\" class=\"ltx_para\">\n<p id=\"S3.SS3.p4.1\" class=\"ltx_p\"><span id=\"S3.SS3.p4.1.1\" class=\"ltx_text ltx_font_bold\">China</span> addresses AI identity through output attribution and service registration. The CAC (Cyberspace Administration of China) Measures for Labeling AI-Generated Content (effective September 2025) mandate machine-readable metadata that attributes AI-generated output to the producing system, alongside visible indicators, backed by mandatory national standard GB 45438-2025 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib27\" title=\"\" class=\"ltx_ref\">12</a>]</cite>; the CAC Generative AI filing regime creates an official identity record for each registered public-facing AI service <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib28\" title=\"\" class=\"ltx_ref\">11</a>]</cite>. Draft measures on AI virtual-human services further prohibit synthetic personas from bypassing biometric authentication mechanisms, targeting AI-enabled identity fraud directly.</p>\n</div>\n<div id=\"S3.SS3.p5\" class=\"ltx_para\">\n<p id=\"S3.SS3.p5.1\" class=\"ltx_p\"><span id=\"S3.SS3.p5.1.1\" class=\"ltx_text ltx_font_bold\">Japan</span> takes a principles-based, non-binding approach. The AI Promotion Act (enacted May 2025) enshrines transparency as a statutory principle but imposes no obligations or penalties <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib29\" title=\"\" class=\"ltx_ref\">35</a>]</cite>, and voluntary METI/MIC AI Business Guidelines v1.1 (March 2025) operationalize governance expectations covering security and accountability for AI providers <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">33</a>]</cite>. Japan also leads the G7 Hiroshima AI Process (HAIP) Reporting Framework (February 2025), through which participating developers publicly disclose their AI practices <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib31\" title=\"\" class=\"ltx_ref\">19</a>]</cite>, and operates Gennai (“Government AI,” May 2025), a secure AI environment for approximately 180,000 civil servants built to ISMAP (Information Security Management and Assessment Program) security standards <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib44\" title=\"\" class=\"ltx_ref\">28</a>]</cite>.</p>\n</div>\n<div id=\"S3.SS3.p6\" class=\"ltx_para\">\n<p id=\"S3.SS3.p6.1\" class=\"ltx_p\"><span id=\"S3.SS3.p6.1.1\" class=\"ltx_text ltx_font_bold\">Singapore</span> deploys two complementary instruments. The IMDA (Infocomm Media Development Authority) Model Governance Framework for Agentic AI, launched at WEF (World Economic Forum) Davos in January 2026, addresses four governance dimensions (accountability, transparency, human oversight, and data governance), providing principles-based guidance for agentic AI deployments <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">26</a>]</cite>. The CSA (Cyber Security Agency of Singapore) Addendum on Securing Agentic AI (October 2025) takes a cybersecurity angle directly relevant to AI identity: it designates identity spoofing and impersonation as threat T9, requires organizations to maintain a trusted agent registry and authenticate agents using verifiable credentials with short-lived OAuth 2.0/OIDC tokens, and prohibits cross-agent privilege delegation unless explicitly authorized <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">10</a>]</cite>. A companion discussion paper identifies agent identity and delegation schemes as an architecturally unresolved gap and calls for standardized identity protocols as a research priority <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib22\" title=\"\" class=\"ltx_ref\">9</a>]</cite>.</p>\n</div>\n</section>\n</section>\n<section id=\"S4\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">4 </span>RQ3: Technologies for AI Identity</h2>\n\n<div id=\"S4.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S4.p1.1\" class=\"ltx_p\">Despite this market momentum, rapid standardization activity, and regulatory attention across jurisdictions, the technologies that underpin AI identity have structural limitations that market investment alone cannot resolve. This section surveys the technologies available for each function of agent identity management, organized around six capabilities: authentication, authorization and delegation, credentials and portable identity, provenance and content integrity, governance and monitoring, and audit logging and attestation, tracing how each addresses the identity requirements identified in §<a href=\"#S2\" title=\"2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a>.</p>\n</div>\n<section id=\"S4.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.1 </span>Authentication</h3>\n\n<div id=\"S4.SS1.p1\" class=\"ltx_para\">\n<p id=\"S4.SS1.p1.1\" class=\"ltx_p\">Authenticating an AI agent differs structurally from authenticating a human user. Human authentication ultimately rests on something the person <span id=\"S4.SS1.p1.1.1\" class=\"ltx_text ltx_font_italic\">is</span> (a biometric), <span id=\"S4.SS1.p1.1.2\" class=\"ltx_text ltx_font_italic\">has</span> (a device), or <span id=\"S4.SS1.p1.1.3\" class=\"ltx_text ltx_font_italic\">knows</span> (a secret), anchored to a single embodied identity that persists across sessions and resists cloning. AI agents satisfy none of these properties. An agent instance is <span id=\"S4.SS1.p1.1.4\" class=\"ltx_text ltx_font_italic\">nondeterministic</span>: the same prompt may yield materially different actions on successive invocations, so behavior cannot be used as an identity signal. It is <span id=\"S4.SS1.p1.1.5\" class=\"ltx_text ltx_font_italic\">cloneable</span>: a container image, a model checkpoint, or an API key can be replicated indefinitely with no cryptographic distinction between the copies. It is frequently <span id=\"S4.SS1.p1.1.6\" class=\"ltx_text ltx_font_italic\">sessionless</span>: short-lived function invocations or one-shot tool calls may begin and end faster than conventional session lifetimes. And it has no <span id=\"S4.SS1.p1.1.7\" class=\"ltx_text ltx_font_italic\">biometric anchor</span> of any kind. These properties force authentication to shift from verifying a persistent embodied subject to attesting ephemeral, replaceable workloads and binding them cryptographically to the humans or organizations on whose behalf they act <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>, <a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">36</a>, <a href=\"#bib.bib12\" title=\"\" class=\"ltx_ref\">24</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS1.p2\" class=\"ltx_para\">\n<p id=\"S4.SS1.p2.1\" class=\"ltx_p\">The dominant response in the standards community has been to treat agents as <span id=\"S4.SS1.p2.1.1\" class=\"ltx_text ltx_font_italic\">workloads</span> rather than users. The IETF (Internet Engineering Task Force) AIMS draft (<span id=\"S4.SS1.p2.1.2\" class=\"ltx_text ltx_font_typewriter\">draft-klrc-aiagent-auth-00</span>), an individual submission to the WIMSE working group, formalizes this posture and composes two layers of identity primitive <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>]</cite>. At the transport layer, agents are issued <span id=\"S4.SS1.p2.1.3\" class=\"ltx_text ltx_font_italic\">SVIDs</span> (SPIFFE Verifiable Identity Documents, either X.509 certificates or JWTs (JSON Web Tokens)) whose subject is a SPIFFE ID of the form <span id=\"S4.SS1.p2.1.4\" class=\"ltx_text ltx_font_typewriter\">spiffe://trust-domain/path</span>. These SVIDs are provisioned by SPIRE (SPIFFE Runtime Environment), the reference implementation of SPIFFE, which runs an agent daemon on each node and performs <span id=\"S4.SS1.p2.1.5\" class=\"ltx_text ltx_font_italic\">workload attestation</span>: before issuing an SVID, SPIRE verifies properties of the requesting process (its Unix UID, its Kubernetes service account, its container image digest, its cloud instance metadata) against selectors registered for that identity, so a rogue process on the same host cannot simply ask for another workload’s credential. Two SPIFFE-identified peers then establish mutual TLS (Transport Layer Security) directly, without a shared secret or a human-mediated enrollment step. Block has deployed the full SPIFFE+WIMSE+OAuth stack in production, offering one of the first real-world validations that the standards-based workload-identity approach is operationally viable <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib51\" title=\"\" class=\"ltx_ref\">7</a>]</cite>. HashiCorp Vault 1.21 added native SPIFFE authentication, allowing an agent that already holds an SVID to exchange it directly for a Vault token and retrieve secrets without a separately managed credential, closing one of the classic bootstrap gaps for AI agents that must reach into secret stores during a task <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib37\" title=\"\" class=\"ltx_ref\">22</a>]</cite>. The NHIMG (Non-Human Identity Management Group) complements this plumbing with enrollment, lifecycle, and revocation practices specific to non-human identities, arguing that workload-style credentials must be accompanied by an authoritative registry and an owner of record for every issued identity <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">36</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS1.p3\" class=\"ltx_para\">\n<p id=\"S4.SS1.p3.1\" class=\"ltx_p\">Mutual TLS alone, however, is insufficient for agent authentication. It authenticates the <span id=\"S4.SS1.p3.1.1\" class=\"ltx_text ltx_font_italic\">channel</span> between two endpoints, but an agent call often traverses multiple hops (an orchestrator, a tool gateway, a downstream API) and the original caller’s identity is invisible to anything past the first TLS terminator. To carry identity end-to-end at the application layer, AIMS layers <span id=\"S4.SS1.p3.1.2\" class=\"ltx_text ltx_font_italic\">WIMSE Proof Tokens</span> over the transport channel <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>]</cite>. Unlike a bearer OAuth access token, which any party that captures it can replay, a proof token is <span id=\"S4.SS1.p3.1.3\" class=\"ltx_text ltx_font_italic\">proof-of-possession</span>: it is cryptographically bound to a key held by the legitimate agent, and each use requires a fresh signature over request-specific data (method, URI, timestamp, nonce), so a stolen token is unusable without the corresponding private key. AIMS further introduces <span id=\"S4.SS1.p3.1.4\" class=\"ltx_text ltx_font_italic\">dual-identity credentials</span> that bind the agent to its human or organizational owner through three delegation flows (Agent-Mediate, Owner-Mediate, and Server-Mediate), each producing an auditable chain of accountability back to a human principal <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>, <a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">45</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS1.p4\" class=\"ltx_para\">\n<p id=\"S4.SS1.p4.1\" class=\"ltx_p\">For agent-to-agent discovery and authentication across organizational boundaries, Google’s A2A protocol takes a lighter-weight, Web-native approach. An agent publishes an <span id=\"S4.SS1.p4.1.1\" class=\"ltx_text ltx_font_italic\">Agent Card</span>, a JSON document served at <span id=\"S4.SS1.p4.1.2\" class=\"ltx_text ltx_font_typewriter\">/.well-known/agent.json</span>, which advertises its name, endpoint, supported skills, and authentication requirements <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib48\" title=\"\" class=\"ltx_ref\">1</a>]</cite>. The card may be signed using JWS, giving a remote caller integrity over the advertised metadata and a cryptographic link to a publisher key. MCP, which standardizes how agents connect to tools and data sources, added OAuth 2.1 support for its HTTP transport in January 2026, adopting a tightened profile that mandates PKCE (Proof Key for Code Exchange), prohibits the implicit and password grants, and imposes stricter redirect handling <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>]</cite>. Together, A2A and MCP with OAuth 2.1 cover the two most common agent interaction surfaces: agents talking to other agents, and agents talking to tools. Their limitations, however, are as significant as their contributions. Agent Cards are <span id=\"S4.SS1.p4.1.3\" class=\"ltx_text ltx_font_italic\">self-declared</span>: the document asserts what an agent can do and who operates it, but no third party attests to model provenance, training lineage, or behavioral conformance, so a malicious or misconfigured operator can publish any card it chooses <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>]</cite>. OAuth 2.1 terminates at the resource server boundary: it confirms that a token is valid and that the agent holds the right scopes, but it does not prevent <span id=\"S4.SS1.p4.1.4\" class=\"ltx_text ltx_font_italic\">confused-deputy</span> patterns in which a correctly authenticated agent is induced by attacker-controlled input to exercise its privileges against the wrong target <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib40\" title=\"\" class=\"ltx_ref\">40</a>, <a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">44</a>]</cite>. And the IETF AIMS specification’s own Security Considerations section still reads “TODO Security” in the current draft, signaling that even the authors regard the threat model as unfinished <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS1.p5\" class=\"ltx_para\">\n<p id=\"S4.SS1.p5.1\" class=\"ltx_p\">Despite rapid enterprise adoption of non-human identity tooling <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib18\" title=\"\" class=\"ltx_ref\">46</a>, <a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>]</cite>, a structural gap persists across all of these mechanisms. Every current mechanism authenticates the <span id=\"S4.SS1.p5.1.1\" class=\"ltx_text ltx_font_italic\">container</span> of identity (a token, a certificate, an SVID, a signed agent card) and not the <span id=\"S4.SS1.p5.1.2\" class=\"ltx_text ltx_font_italic\">content</span> of the agent: the model weights that produce its behavior, the system prompt that constrains its mandate, or the intent behind its next tool call. A perfectly authenticated agent, holding a valid SVID and a fresh proof-of-possession token, can still act outside its mandate the moment after authentication completes, whether through a prompt injection that rewrites its goals, a hallucinated tool invocation, or a drift in model behavior between versions. Authentication, as currently standardized, establishes <span id=\"S4.SS1.p5.1.3\" class=\"ltx_text ltx_font_italic\">who</span> is on the wire; it does not establish <span id=\"S4.SS1.p5.1.4\" class=\"ltx_text ltx_font_italic\">what</span> that party is about to do, and it provides no primitive by which a relying party can decide whether the next action falls inside or outside the agent’s authorized scope.</p>\n</div>\n</section>\n<section id=\"S4.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.2 </span>Authorization and Delegation</h3>\n\n<div id=\"S4.SS2.p1\" class=\"ltx_para\">\n<p id=\"S4.SS2.p1.1\" class=\"ltx_p\">Authentication establishes who an entity is; authorization determines what it may do. The dominant human-centric authorization frameworks (OAuth 2.0, OpenID Connect, and SAML) are not merely <span id=\"S4.SS2.p1.1.1\" class=\"ltx_text ltx_font_italic\">designed for humans</span> in a loose sense: they encode a small number of very specific structural assumptions that autonomous agents violate by construction. OAuth 2.0 presumes a <span id=\"S4.SS2.p1.1.2\" class=\"ltx_text ltx_font_italic\">synchronous human consent</span> event and <span id=\"S4.SS2.p1.1.3\" class=\"ltx_text ltx_font_italic\">single-hop delegation</span> from one client to one resource server; SAML’s assertion model assumes a bounded interactive <span id=\"S4.SS2.p1.1.4\" class=\"ltx_text ltx_font_italic\">session</span> anchored to a browser cookie <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>, <a href=\"#bib.bib45\" title=\"\" class=\"ltx_ref\">50</a>]</cite>. Agents violate all of these: they act asynchronously, often long after any human interaction, and chain calls across multiple services in a single task. The result is that applying OAuth 2.0 to agents without modification either forces impersonation (in which the agent simply replays the user’s token) or overly broad static API keys, both of which destroy the accountability properties that made OAuth valuable in the first place <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>, <a href=\"#bib.bib12\" title=\"\" class=\"ltx_ref\">24</a>, <a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS2.p2\" class=\"ltx_para\">\n<p id=\"S4.SS2.p2.1\" class=\"ltx_p\">The OpenID Foundation’s <span id=\"S4.SS2.p2.1.1\" class=\"ltx_text ltx_font_italic\">OBO</span> (On-Behalf-Of) flows address the first of these gaps by replacing direct impersonation with a token-exchange protocol <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>, <a href=\"#bib.bib45\" title=\"\" class=\"ltx_ref\">50</a>]</cite>. Technically, an OBO token is a new access token minted by the authorization server in response to a token-exchange request in which the calling agent presents both its own client credential and the user’s original token; the resulting token carries the original user’s identity and the delegating agent’s identity as <span id=\"S4.SS2.p2.1.2\" class=\"ltx_text ltx_font_italic\">separate</span> claims, typically expressed as distinct <span id=\"S4.SS2.p2.1.3\" class=\"ltx_text ltx_font_typewriter\">sub</span> and <span id=\"S4.SS2.p2.1.4\" class=\"ltx_text ltx_font_typewriter\">act</span> (actor) fields, so a downstream resource server can verify the full principal chain <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>, <a href=\"#bib.bib45\" title=\"\" class=\"ltx_ref\">50</a>]</cite>. <span id=\"S4.SS2.p2.1.5\" class=\"ltx_text ltx_font_italic\">CIBA</span>, also standardized by the OpenID Foundation <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">45</a>, <a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>]</cite>, addresses the synchrony gap by decoupling the device that initiates an authorization request from the device on which the user approves it. In a CIBA flow, the agent sends an authorization request directly to the identity provider (IdP) over a back channel; the IdP then pushes a consent prompt to the user’s pre-registered device; the user approves out-of-band; and the IdP subsequently issues a token to the agent. This matters for agents specifically because their actions are often initiated long after the user last interacted with any session, and because a human-in-the-loop approval step must be reachable without assuming that a browser session is still live <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">45</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS2.p3\" class=\"ltx_para\">\n<p id=\"S4.SS2.p3.1\" class=\"ltx_p\">Two further architectural patterns are emerging around these flows. The <span id=\"S4.SS2.p3.1.1\" class=\"ltx_text ltx_font_italic\">Triangle of Trust</span> model <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">45</a>]</cite> formalizes the three-way relationship between user, agent, and service as three bilateral trust relationships that must all be independently established: user-agent, agent-service, and user-service. Each pair authenticates on its own footing, so that no single link can be bypassed by leveraging another; an agent cannot act on a service using only the user’s trust relationship with that service, because the service must itself have independently verified the agent. <span id=\"S4.SS2.p3.1.2\" class=\"ltx_text ltx_font_italic\">Token Vault</span> architectures <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib37\" title=\"\" class=\"ltx_ref\">22</a>, <a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">45</a>]</cite> attack the credential-handling problem from a different angle. Rather than issuing tokens directly to agents, a vault holds the underlying credentials and exposes only opaque references, or handles, to callers. When an agent needs to invoke an API, it presents a handle to the vault, which either resolves the handle to a credential and makes the outbound call itself or returns a short-lived derived token scoped to that single invocation. Because the agent never holds the raw credential, exfiltration yields nothing usable and revocation reduces to invalidating a handle <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib37\" title=\"\" class=\"ltx_ref\">22</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS2.p4\" class=\"ltx_para\">\n<p id=\"S4.SS2.p4.1\" class=\"ltx_p\">The harder problem, and the one that these mechanisms only partially address, is <span id=\"S4.SS2.p4.1.1\" class=\"ltx_text ltx_font_italic\">multi-hop delegation</span>: when Agent A delegates to Agent B, which in turn delegates to Agent C, no production-ready standard traces the authorization chain back to the originating human principal in a way that every resource server along the chain can verify. The governing principle, <span id=\"S4.SS2.p4.1.2\" class=\"ltx_text ltx_font_italic\">scope attenuation</span>, holds that each delegation step must narrow, never widen, the set of permitted actions, so that capabilities monotonically shrink down the chain <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">44</a>, <a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">39</a>]</cite>. Enforcing scope attenuation in production is difficult for two reasons. First, there is no widely deployed token format that carries an explicit, cryptographically verifiable delegation chain: the IETF AIMS draft <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>]</cite> is still at an early stage and no production-ready standard has yet emerged. Second, even where a chain can be represented, resource servers lack a shared vocabulary for comparing scope claims across hops, so an attenuation check that should reject a widening step cannot be mechanically performed. OWASP’s Top 10 for Agentic Applications <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">41</a>]</cite> flags identity and privilege abuse (ASI03), which explicitly covers exploitation of delegation chains and role inheritance, among its headline risks, and both NIST’s NCCoE project on software and AI identity <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">5</a>]</cite> and industry baselines for non-human identity governance <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">36</a>]</cite> flag the absence of a standard delegation-chain format as a blocking gap for enterprise adoption.</p>\n</div>\n<div id=\"S4.SS2.p5\" class=\"ltx_para\">\n<p id=\"S4.SS2.p5.1\" class=\"ltx_p\">The Model Context Protocol compounds the difficulty, and the literature on agentic threats has crystallized a specific catalog of its authorization failure modes <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">41</a>]</cite>. First, there is <span id=\"S4.SS2.p5.1.1\" class=\"ltx_text ltx_font_italic\">no per-tool authentication</span>: once an agent authenticates to an MCP server, it implicitly gains access to every tool that server exposes, with no per-tool credential check. Second, <span id=\"S4.SS2.p5.1.2\" class=\"ltx_text ltx_font_italic\">confused-deputy risk</span> (§<a href=\"#S4.SS1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.1</span></a>) arises because tools share the server’s execution context, so a tool invoked with low-sensitivity input can be induced to perform high-sensitivity actions using the server’s ambient privileges. Third, <span id=\"S4.SS2.p5.1.3\" class=\"ltx_text ltx_font_italic\">privilege concentration</span> places all tool capabilities behind a single MCP server whose compromise yields the union of every tool’s permissions. Fourth, <span id=\"S4.SS2.p5.1.4\" class=\"ltx_text ltx_font_italic\">fragmented audit</span> means that invocations scatter across tool-specific logs with no unified trail linking a user request to the downstream calls it produced. Fifth, <span id=\"S4.SS2.p5.1.5\" class=\"ltx_text ltx_font_italic\">overly broad tool discovery</span> exposes to the agent, and to any prompt it ingests, the existence and schema of capabilities it should never have seen, enlarging the attack surface for prompt injection. Sixth, there is <span id=\"S4.SS2.p5.1.6\" class=\"ltx_text ltx_font_italic\">no binding between a tool invocation and the context that authorized it</span>: a tool call carries no verifiable reference back to the user consent, policy evaluation, or principal chain that justified it, so post-hoc accountability collapses <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">41</a>, <a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>]</cite>. Taken together, these failures mean that even a well-authenticated agent operating through a well-configured MCP server can accumulate effective permissions far beyond what any human principal intended to grant, and that the cleanest OBO or CIBA flow at the front door is undone by the tool surface behind it.</p>\n</div>\n<div id=\"S4.SS2.p6\" class=\"ltx_para\">\n<p id=\"S4.SS2.p6.1\" class=\"ltx_p\">Part of what makes these authorization failures so difficult to contain is that agents do not operate within a single trust domain: they move across organizational boundaries, carrying identity claims with them. When an agent crosses such a boundary, the receiving service typically has no prior basis to trust the issuing identity provider, no shared schema for interpreting scope claims embedded in a presented token, and no mechanism to verify that any delegation chain asserted on the sending side was legitimately constructed <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib12\" title=\"\" class=\"ltx_ref\">24</a>, <a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">5</a>]</cite>. The question of how those claims are packaged, presented, and verified across contexts is the subject of portable credentials.</p>\n</div>\n</section>\n<section id=\"S4.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.3 </span>Credentials and Portable Identity</h3>\n\n<div id=\"S4.SS3.p1\" class=\"ltx_para\">\n<p id=\"S4.SS3.p1.1\" class=\"ltx_p\">Beyond point-in-time authentication, persistent and portable credentials enable identity to travel across contexts. The W3C’s DID (Decentralized Identifier) and VC (Verifiable Credential) standards provide the foundation: a subject holds cryptographically signed credentials in a digital wallet and presents them to verifiers without requiring a centralized identity provider. Indicio’s ProvenAI platform issues verifiable credentials to agents directly <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">27</a>]</cite>, enabling them to present machine-readable proof of their capabilities, authorizations, and provenance. The MCP-I specification, donated to the DIF (Decentralized Identity Foundation) in March 2026 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib52\" title=\"\" class=\"ltx_ref\">53</a>]</cite>, extends this model to agents operating within the Model Context Protocol ecosystem. A complementary effort is the TRAIL (Trust Registry for AI Identity Layer) <span id=\"S4.SS3.p1.1.1\" class=\"ltx_text ltx_font_typewriter\">did:trail</span> method <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib50\" title=\"\" class=\"ltx_ref\">23</a>]</cite>, a draft DID specification designed specifically for AI agents that defines distinct identifier types for organizations, agents, and self-signed identities, with a W3C registry submission pending. The W3C also published a dedicated Threat Model for Decentralized Credentials in January 2026 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib41\" title=\"\" class=\"ltx_ref\">54</a>]</cite>, cataloguing the attack surfaces that wallet-based architectures introduce.</p>\n</div>\n<div id=\"S4.SS3.p2\" class=\"ltx_para\">\n<p id=\"S4.SS3.p2.1\" class=\"ltx_p\">Several emerging primitives deserve particular attention. <span id=\"S4.SS3.p2.1.1\" class=\"ltx_text ltx_font_italic\">ZKPs</span> (Zero-Knowledge Proofs) are cryptographic protocols that allow one party to prove the truth of a statement, such as “I hold a valid credential,” without revealing the underlying data <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib23\" title=\"\" class=\"ltx_ref\">21</a>]</cite>. In the agent context, ZKPs enable selective disclosure (presenting only the credential attributes a verifier needs) and transaction unlinkability, preventing verifiers from correlating an agent’s presentations across contexts. A Zero-Trust Identity Framework <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib12\" title=\"\" class=\"ltx_ref\">24</a>]</cite> extends this by hashing model parameters and software version into the DID document itself, so that any modification to the agent’s model invalidates its identity, binding the credential not just to a key pair but to the specific model the agent was issued with.\nThese primitives are attempts to bind AI identity to something deeper than externally assigned tokens, but none can verify whether an agent’s reasoning is genuine or adversarially manipulated. A separate question is whether the agent’s own origin can be verified: where it came from, what data shaped it, and who deployed it. That is the function of provenance.</p>\n</div>\n</section>\n<section id=\"S4.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.4 </span>Provenance and Content Integrity</h3>\n\n<div id=\"S4.SS4.p1\" class=\"ltx_para\">\n<p id=\"S4.SS4.p1.1\" class=\"ltx_p\">Credentials declare what an entity is authorized to do; provenance establishes where that entity came from. For AI agents, provenance operates at two distinct levels: the provenance of the agent itself (what model, trained on what data, deployed by whom) and the provenance of the content or actions the agent produces. The C2PA (Coalition for Content Provenance and Authenticity) specification addresses the second level <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib46\" title=\"\" class=\"ltx_ref\">6</a>]</cite>. A C2PA manifest is a cryptographically signed record embedded in a digital asset that declares which AI model produced or modified it, what inputs were supplied, and the full chain of edits since creation. Major AI platforms have adopted this in practice: OpenAI embeds C2PA metadata in images generated by DALL·E 3, making it possible for a recipient to verify machine-readable provenance of AI-generated output. The 2026 conformance program enables interoperability testing across content creation tools, publishing platforms, and verification services <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib46\" title=\"\" class=\"ltx_ref\">6</a>]</cite>. Regulatory pressure reinforces adoption: EU AI Act Article 50 and California SB 942 both require machine-readable disclosure of AI-generated content, and C2PA provides the cryptographic layer that makes those declarations tamper-evident. For agent identity, C2PA’s contribution is output attribution, binding a specific agent’s identity to the content it produces, so that downstream parties can verify not just what was produced but which agent produced it.</p>\n</div>\n<div id=\"S4.SS4.p2\" class=\"ltx_para\">\n<p id=\"S4.SS4.p2.1\" class=\"ltx_p\">At the model level, the SLSA (Supply-chain Levels for Software Artifacts) framework and Sigstore <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib47\" title=\"\" class=\"ltx_ref\">48</a>]</cite> extend software supply-chain attestation to AI artifacts, creating verifiable records of model training pipelines, fine-tuning steps, and deployment lineage. A model’s training pipeline is, in effect, its developmental biography, and SLSA’s graduated assurance levels provide a vocabulary for expressing how much of that biography can be independently verified.</p>\n</div>\n<div id=\"S4.SS4.p3\" class=\"ltx_para\">\n<p id=\"S4.SS4.p3.1\" class=\"ltx_p\">A deeper limitation applies to agent provenance specifically: provenance proves <span id=\"S4.SS4.p3.1.1\" class=\"ltx_text ltx_font_italic\">where</span> an agent came from and <span id=\"S4.SS4.p3.1.2\" class=\"ltx_text ltx_font_italic\">how</span> it was constructed, but it cannot prove <span id=\"S4.SS4.p3.1.3\" class=\"ltx_text ltx_font_italic\">why</span> it acts as it does or whether its behavior at the point of execution is consistent with the principal’s intent.</p>\n</div>\n<div id=\"S4.SS4.p4\" class=\"ltx_para\">\n<p id=\"S4.SS4.p4.1\" class=\"ltx_p\">Authentication, authorization, credentials, and provenance each address a specific moment in an agent’s lifecycle: enrollment, access request, credential presentation, or content creation. None of them addresses what happens <span id=\"S4.SS4.p4.1.1\" class=\"ltx_text ltx_font_italic\">between</span> those moments: whether an agent’s behavior remains consistent with the identity and permissions it was granted over time. That is the function of governance and monitoring.</p>\n</div>\n</section>\n<section id=\"S4.SS5\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.5 </span>Governance and Monitoring</h3>\n\n<div id=\"S4.SS5.p1\" class=\"ltx_para\">\n<p id=\"S4.SS5.p1.1\" class=\"ltx_p\">Unlike human sessions, which begin at login and terminate when the user logs out, agent tasks can run for hours or days, chain across multiple services, and cross organizational trust boundaries without any intervening re-authentication. A token issued at enrollment may remain valid long after the conditions that justified its issuance have changed, and the downstream services that honor it typically have no direct channel back to the issuer. Governance for agents must therefore operate <span id=\"S4.SS5.p1.1.1\" class=\"ltx_text ltx_font_italic\">continuously</span> rather than at the enrollment or login boundary alone <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib40\" title=\"\" class=\"ltx_ref\">40</a>]</cite>, which in turn requires mechanisms that bind tokens to their legitimate holders, propagate risk signals in near-real-time, enforce behavioral constraints before each action reaches a downstream service, and tie those constraints directly to the agent’s identity record. The vendor products that implement these mechanisms in commercial form are surveyed in §<a href=\"#S3.SS1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3.1</span></a>.</p>\n</div>\n<div id=\"S4.SS5.p2\" class=\"ltx_para\">\n<p id=\"S4.SS5.p2.1\" class=\"ltx_p\">The first mechanism, <span id=\"S4.SS5.p2.1.1\" class=\"ltx_text ltx_font_italic\">DPoP</span> (Demonstration of Proof-of-Possession, RFC 9449), addresses token replay. The client generates an asymmetric key pair and signs each HTTP request with the private key, producing a DPoP proof header; the authorization server binds the issued access token to the corresponding public key, and a relying party verifies both the bearer token and the DPoP proof on every request. A token exfiltrated from logs or an intermediate proxy cannot be replayed from a different client without the associated private key. This property matters disproportionately for agents because agent tokens are typically longer-lived than human-session tokens and are more likely to traverse untrusted intermediaries, tool servers, and sub-agents during the course of a single task <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib45\" title=\"\" class=\"ltx_ref\">50</a>]</cite>. The complementary mechanism, <span id=\"S4.SS5.p2.1.2\" class=\"ltx_text ltx_font_italic\">CAEP</span> (Continuous Access Evaluation Protocol), is a push-based event protocol standardized by the OpenID Foundation in which authorization servers and identity providers emit real-time security event signals (token revocation, session anomaly, credential change) to subscribed relying parties via a shared signals framework. Rather than waiting for a bearer token to expire and relying on introspection polling for freshness, a relying party receives an event the moment the authorization server determines that access should be withdrawn. For agents this is load-bearing: agent sessions routinely outlast any human-supervised window, risk signals such as a compromised credential or anomalous tool-use pattern may surface long after the original token was issued, and conventional token expiry is too coarse-grained for the speed at which autonomous actions can propagate through chained tool calls <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib45\" title=\"\" class=\"ltx_ref\">50</a>]</cite>.</p>\n</div>\n<div id=\"S4.SS5.p3\" class=\"ltx_para\">\n<p id=\"S4.SS5.p3.1\" class=\"ltx_p\">While DPoP and CAEP govern who holds a token and when it remains valid, they say nothing about which actions that token legitimately authorizes. The <span id=\"S4.SS5.p3.1.1\" class=\"ltx_text ltx_font_italic\">MAPL</span> (Multi-Agent Policy Language) introduced in Authenticated Workflows <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">44</a>]</cite> addresses this gap by expressing fine-grained behavioral constraints (which tools an agent may invoke, in what sequence, and under what pre- and post-conditions) as a verifiable policy evaluated before each action. Distributed <span id=\"S4.SS5.p3.1.2\" class=\"ltx_text ltx_font_italic\">PEPs</span> (Policy Enforcement Points) sit at the tool boundary, intercepting agent actions before they reach downstream services, evaluating the proposed action against the applicable MAPL policy, and either admitting or blocking the call based on the result <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">44</a>]</cite>. This is a pre-execution enforcement model: an action that violates the policy never executes, in contrast to the post-hoc audit approach examined in §<a href=\"#S4.SS6\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.6</span></a>. <span id=\"S4.SS5.p3.1.3\" class=\"ltx_text ltx_font_italic\">ABCs</span> (Agent Behavioral Contracts) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib14\" title=\"\" class=\"ltx_ref\">4</a>]</cite> push this logic further by binding the behavioral specification directly to the agent’s identity record rather than relying on external policy evaluation alone. An ABC is a formal specification of runtime invariants (what the agent must and must not do) attached to the agent identity at issuance and enforced programmatically, with violations triggering automatic remediation or shutdown. ABCs thus extend the governance question from “what is this agent permitted to do at enrollment?” to “is this agent currently behaving as its contract specifies?”</p>\n</div>\n<div id=\"S4.SS5.p4\" class=\"ltx_para\">\n<p id=\"S4.SS5.p4.1\" class=\"ltx_p\">Taken together, DPoP, CAEP, MAPL with distributed PEPs, and ABCs span the continuum from token binding through real-time revocation to pre-execution policy enforcement and identity-bound behavioral invariants. <span id=\"S4.SS5.p4.1.1\" class=\"ltx_text ltx_font_italic\">Each mechanism, however, operates exclusively at the level of observable actions and token metadata: none can inspect an agent’s internal reasoning or verify that its intent is legitimate before an action is initiated, and the records they emit are only as trustworthy as the execution environments that generate them.</span></p>\n</div>\n</section>\n<section id=\"S4.SS6\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.6 </span>Audit Logging and Attestation</h3>\n\n<div id=\"S4.SS6.p1\" class=\"ltx_para\">\n<p id=\"S4.SS6.p1.1\" class=\"ltx_p\">Audit logging and attestation provide the evidentiary foundation for accountability; without them, governance and monitoring lack verifiable records. The most powerful primitive in this category is the <span id=\"S4.SS6.p1.1.1\" class=\"ltx_text ltx_font_italic\">TEE</span> (Trusted Execution Environment): a hardware-isolated enclave, implemented in technologies such as Intel SGX (Software Guard Extensions) and TDX (Trust Domain Extensions), and ARM TrustZone, that guarantees both code integrity and data confidentiality during execution. Code running inside a TEE is protected from the operating system, the hypervisor, and even the hardware owner; data processed within the enclave is encrypted in memory and inaccessible to external processes. TEEs also support <span id=\"S4.SS6.p1.1.2\" class=\"ltx_text ltx_font_italic\">remote attestation</span>: a verifier can obtain a cryptographic proof that an agent is running specific, unmodified code in an uncompromised environment, without needing physical access to the machine. CrossGuard <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">42</a>]</cite> extends this to multi-cloud AI deployments, binding each agent’s identity cryptographically to its TEE through on-chain attestation records and establishing a cross-TEE attestation protocol that enables mutual trust between enclaves from different hardware vendors (Intel TDX and AMD SEV-SNP (Secure Encrypted Virtualization-Scalable Nested Paging)) without requiring shared trust infrastructure. TPM (Trusted Platform Module)-based attestation complements TEEs by anchoring the chain of trust in dedicated hardware that records the boot sequence and runtime configuration of the host system.</p>\n</div>\n<div id=\"S4.SS6.p2\" class=\"ltx_para\">\n<p id=\"S4.SS6.p2.1\" class=\"ltx_p\">Beyond hardware attestation, immutable audit trails record agent actions, delegation events, and credential usage in tamper-evident logs that span organizational boundaries. The AuditableLLM framework <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib53\" title=\"\" class=\"ltx_ref\">31</a>]</cite> implements this at the model level, recording each LLM (Large Language Model) update event (fine-tuning, continual learning, and unlearning steps) as a hash-chain-backed, tamper-evident entry in which each record cryptographically references its predecessor, making undetected modification of any entry computationally infeasible. When Agent A delegates to Agent B across a corporate boundary, both organizations’ audit systems must produce consistent, cross-referenceable records of the delegation and its scope <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib55\" title=\"\" class=\"ltx_ref\">32</a>]</cite>. Standardized audit formats and cross-organizational log interoperability protocols are emerging to enable multi-party verification of agent behavior histories, though no single standard has yet achieved broad adoption.</p>\n</div>\n<div id=\"S4.SS6.p3\" class=\"ltx_para\">\n<p id=\"S4.SS6.p3.1\" class=\"ltx_p\">A complementary approach attempts to bring attestation inside the model itself. <span id=\"S4.SS6.p3.1.1\" class=\"ltx_text ltx_font_italic\">SVIP (Secret-based Verifiable LLM Inference Protocol)</span> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib13\" title=\"\" class=\"ltx_ref\">51</a>]</cite> converts an LLM’s internal hidden-state representations into an external identity signal, collapsing the gap between what a model computes internally and what it presents externally. Where TEEs attest that an agent is running specific code in a trusted environment, SVIP attests that a specific model is producing a specific output, a form of inference-level provenance that external audit logs cannot provide. The fundamental limitation of audit and attestation, however, is the same limitation that recurs throughout this section: a TEE will faithfully execute whatever code it is given, an audit trail will faithfully record whatever actions an agent takes, and SVIP will attest whatever outputs a model produces, but none can verify that the agent’s <span id=\"S4.SS6.p3.1.2\" class=\"ltx_text ltx_font_italic\">intent</span> was legitimate, a gap that §<a href=\"#S5\" title=\"5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a> examines in detail.</p>\n</div>\n</section>\n</section>\n<section id=\"S5\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">5 </span>RQ4: Gap Analysis and Research Directions</h2>\n\n<div id=\"S5.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.p1.1\" class=\"ltx_p\">The technologies and standards surveyed in Sections <a href=\"#S3\" title=\"3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> and <a href=\"#S4\" title=\"4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a> represent substantial progress. Yet five structural gaps remain unsolved, gaps where no current technology or framework provides an adequate answer: semantic intent verification, recursive delegation accountability, agent identity integrity, governance opacity and enforcement, and operational sustainability. This section examines each in turn. Table <a href=\"#S5.T5\" title=\"Table 5 ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a> maps each gap against the partial coverage of existing technologies and the research required to close it.</p>\n</div>\n<figure id=\"S5.T5\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_table\">Table 5: </span>Coverage of existing technologies and standards against each structural gap, and the research required to close it.</figcaption>\n<table id=\"S5.T5.2\" class=\"ltx_tabular ltx_centering ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S5.T5.2.1\" class=\"ltx_tr\">\n<th id=\"S5.T5.2.1.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S5.T5.2.1.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:71.1pt;\">\n<span id=\"S5.T5.2.1.1.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Gap</span></span>\n</span></th>\n<th id=\"S5.T5.2.1.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S5.T5.2.1.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.1.2.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Existing partial coverage</span></span>\n</span></th>\n<th id=\"S5.T5.2.1.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_t\">\n<span id=\"S5.T5.2.1.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.1.3.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Research needed</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S5.T5.2.2\" class=\"ltx_tr\">\n<td id=\"S5.T5.2.2.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.2.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:71.1pt;\">\n<span id=\"S5.T5.2.2.1.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.2.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Semantic intent</span></span>\n</span></td>\n<td id=\"S5.T5.2.2.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.2.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.2.2.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">TEE (code integrity), ZKP (authorization proof), SVIP (hidden-state</span><math id=\"S5.T5.m1\" class=\"ltx_Math\" alttext=\"\\leftrightarrow\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.900em\" stretchy=\"false\">↔</mo><annotation encoding=\"application/x-tex\">\\leftrightarrow</annotation></semantics></math><span id=\"S5.T5.2.2.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">identity consistency), ABCs (runtime behavioral invariants)</span></span>\n</span></td>\n<td id=\"S5.T5.2.2.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.2.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.2.3.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Verification that behavior reflects genuine rather than hijacked reasoning; intent verification beyond observable action; sociotechnical governance at semantic decision points</span></span>\n</span></td></tr>\n<tr id=\"S5.T5.2.3\" class=\"ltx_tr\">\n<td id=\"S5.T5.2.3.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.3.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:71.1pt;\">\n<span id=\"S5.T5.2.3.1.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.3.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Recursive delegation</span></span>\n</span></td>\n<td id=\"S5.T5.2.3.2\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.3.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.3.2.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">OAuth OBO/CIBA (one-hop delegation with principal chaining), WIMSE/AIMS (draft multi-hop framework, pre-production), scope attenuation principle</span></span>\n</span></td>\n<td id=\"S5.T5.2.3.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.3.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.3.3.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Production protocol for cryptographic delegation-chain provenance; cross-organizational log correlation standard; enforceable monotonic scope attenuation; multi-principal liability assignment</span></span>\n</span></td></tr>\n<tr id=\"S5.T5.2.4\" class=\"ltx_tr\">\n<td id=\"S5.T5.2.4.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.4.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:71.1pt;\">\n<span id=\"S5.T5.2.4.1.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.4.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agent identity integrity</span></span>\n</span></td>\n<td id=\"S5.T5.2.4.2\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.4.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.4.2.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">TEE instance attestation (raises cloning cost), ABCs (behavioral anomaly detection), mTLS (channel authentication), rate limiting</span></span>\n</span></td>\n<td id=\"S5.T5.2.4.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.4.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.4.3.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Instance binding resilient to cross-machine TEE replication; hijack detection integrated into credential validation path; lightweight Sybil resistance without proof-of-personhood</span></span>\n</span></td></tr>\n<tr id=\"S5.T5.2.5\" class=\"ltx_tr\">\n<td id=\"S5.T5.2.5.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.5.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:71.1pt;\">\n<span id=\"S5.T5.2.5.1.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.5.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Governance opacity</span></span>\n</span></td>\n<td id=\"S5.T5.2.5.2\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.5.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.5.2.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">DPoP (token-to-client binding), CAEP (real-time revocation events), MAPL + distributed PEPs (pre-execution policy enforcement)</span></span>\n</span></td>\n<td id=\"S5.T5.2.5.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.5.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.5.3.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Continuous behavioral telemetry without per-call credential presentation; tiered enforcement proportionate to risk rather than organizational capacity; resolving the compliance-bar/evasion paradox</span></span>\n</span></td></tr>\n<tr id=\"S5.T5.2.6\" class=\"ltx_tr\">\n<td id=\"S5.T5.2.6.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.6.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:71.1pt;\">\n<span id=\"S5.T5.2.6.1.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.6.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Operational sustainability</span></span>\n</span></td>\n<td id=\"S5.T5.2.6.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.6.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.6.2.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.6.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Efficient ZKP constructions (STARKs, Bulletproofs), TEE hardware improvements, bearer token shortcuts for low-risk interactions</span></span>\n</span></td>\n<td id=\"S5.T5.2.6.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_b\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S5.T5.2.6.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:162.2pt;\">\n<span id=\"S5.T5.2.6.3.1.1\" class=\"ltx_p\"><span id=\"S5.T5.2.6.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Verification overhead baselines at agent-fleet scale; amortization and batching strategies that preserve security guarantees; ecological cost accounting for cryptographic identity infrastructure</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n<section id=\"S5.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">5.1 </span>The Semantic Intent Gap</h3>\n\n<div id=\"S5.SS1.p1\" class=\"ltx_para\">\n<p id=\"S5.SS1.p1.1\" class=\"ltx_p\">The most fundamental gap in the current identity landscape is not a missing standard or an immature technology but a category error: the assumption that cryptographic correctness implies semantic correctness. Consider an agent whose reasoning has been compromised by prompt injection. A TEE (§<a href=\"#S4.SS6\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.6</span></a>) will faithfully execute the corrupted agent, because the TEE’s guarantee is code integrity, <span id=\"S5.SS1.p1.1.1\" class=\"ltx_text ltx_font_italic\">not intent integrity</span>: the enclave confirms that the code running is the code that was loaded, but it cannot distinguish between an agent reasoning genuinely and an agent whose reasoning has been hijacked. Simultaneously, a ZKP (§<a href=\"#S4.SS3\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.3</span></a>) will produce a mathematically perfect proof that the agent held valid authorization to access the database from which it exfiltrated sensitive data. <span id=\"S5.SS1.p1.1.2\" class=\"ltx_text ltx_font_italic\">The cryptographic proof is flawless. The intent is malicious. No component in the verification chain detected anything wrong, because no component was designed to evaluate why the agent acted as it did.</span></p>\n</div>\n<div id=\"S5.SS1.p2\" class=\"ltx_para\">\n<p id=\"S5.SS1.p2.1\" class=\"ltx_p\">Partial approaches narrow the gap without closing it. Agent Behavioral Contracts (ABCs; introduced in §<a href=\"#S4.SS5\" title=\"4.5 Governance and Monitoring ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.5</span></a>) enforce runtime invariants, hard constraints on what an agent may and may not do, and can detect violations in real time. But ABCs operate on observable behavior, not on the reasoning process that produced it: an agent that satisfies every behavioral constraint while pursuing a misaligned objective will pass every ABC check. SVIP (introduced in §<a href=\"#S4.SS6\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.6</span></a>) takes a deeper approach by converting internal hidden-state representations into externally verifiable identity signals, linking what a model computes to who it claims to be. Yet SVIP proves consistency between hidden states and identity, not that those hidden states reflect uncorrupted reasoning. The question that neither primitive answers, and that may define the hard boundary of technical identity infrastructure, is whether semantic intent can ever be cryptographically proven, or whether this is the point where formal verification ends and sociotechnical governance must begin.</p>\n</div>\n<div id=\"S5.SS1.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS1.p3.1\" class=\"ltx_p\"><span id=\"S5.SS1.p3.1.1\" class=\"ltx_text\">\n<span id=\"S5.SS1.p3.1.1.1\" class=\"ltx_inline-block ltx_minipage ltx_align_middle\" style=\"width:329.0pt;\">\n<span id=\"S5.SS1.p3.1.1.1.1\" class=\"ltx_p\"><span id=\"S5.SS1.p3.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Research directions:</span></span>\n<span id=\"S5.I1\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S5.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I1.i1.p1\" class=\"ltx_para\">\n<span id=\"S5.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I1.i1.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Extend SVIP beyond syntactic correctness to incorporate behavioral intent.</span></span>\n</span></span>\n<span id=\"S5.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I1.i2.p1\" class=\"ltx_para\">\n<span id=\"S5.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I1.i2.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Design ABCs that encode intent claims alongside identity claims.</span></span>\n</span></span>\n<span id=\"S5.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I1.i3.p1\" class=\"ltx_para\">\n<span id=\"S5.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I1.i3.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Develop human-in-the-loop attestation protocols that insert meaningful oversight at semantically critical decision points without creating throughput bottlenecks.</span></span>\n</span></span>\n</span>\n</span></span></p>\n</div>\n</section>\n<section id=\"S5.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">5.2 </span>The Recursive Delegation and Accountability Gap</h3>\n\n<div id=\"S5.SS2.p1\" class=\"ltx_para\">\n<p id=\"S5.SS2.p1.1\" class=\"ltx_p\">When a human user authorizes an agent, and that agent delegates to a second agent, which in turn delegates to a third, the question of who authorized the final action, and who bears responsibility for its consequences, has no answer in any production system. KYA frameworks (§<a href=\"#S3.SS1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3.1</span></a>), the most developed identity-lifecycle approach, fail here directly: once Agent A has been assessed and credentialed, KYA provides no mechanism to constrain what Agent B does when Agent A delegates to it, and multi-principal modeling (determining which human principal bears responsibility for the delegated action) remains an unsolved problem. OAuth 2.0 and its extensions handle one-hop delegation well: a user grants scoped access to a client, and the resource server can verify both the grant and its scope. But the moment delegation becomes recursive, the authorization chain loses its anchor. <span id=\"S5.SS2.p1.1.1\" class=\"ltx_text ltx_font_italic\">No deployed protocol can cryptographically prove which human principal authorized which specific agent to perform which specific action at the third or fourth hop of a delegation chain.</span> The Gravitee 2026 survey quantifies the resulting opacity: only 24.4% of organizations report full visibility into agent-to-agent communications <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>]</cite>, meaning that more than three-quarters lack comprehensive oversight of inter-agent interactions.</p>\n</div>\n<div id=\"S5.SS2.p2\" class=\"ltx_para\">\n<p id=\"S5.SS2.p2.1\" class=\"ltx_p\">The technical proposals described in §<a href=\"#S4.SS2\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.2</span></a>, scope attenuation, which requires each delegation step to narrow the set of permitted actions, and bidirectional signing of delegation tokens, which would allow any party in the chain to verify the full provenance of an authorization, remain pre-production. The IETF AIMS draft includes audit trail requirements (§<a href=\"#S4.SS1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.1</span></a>), though its Security Considerations section remains incomplete <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">29</a>]</cite>, and cross-organizational log correlation is unsolved: when Agent A in Organization X delegates to Agent B in Organization Y, which delegates to Agent C in Organization Z, no standard ensures that the three organizations’ audit logs are consistent, cross-referenceable, or even formatted compatibly. The consequence is that an agent three hops deep in a delegation chain can cause real harm, accessing data it should not see and triggering transactions it was never authorized to initiate, with the resulting liability untraceable to any responsible human party. Until recursive delegation carries cryptographic proof of provenance at every hop and enforceable scope constraints that cannot be widened by intermediate agents, multi-agent systems will remain fundamentally unaccountable.</p>\n</div>\n<div id=\"S5.SS2.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS2.p3.1\" class=\"ltx_p\"><span id=\"S5.SS2.p3.1.1\" class=\"ltx_text\">\n<span id=\"S5.SS2.p3.1.1.1\" class=\"ltx_inline-block ltx_minipage ltx_align_middle\" style=\"width:329.0pt;\">\n<span id=\"S5.SS2.p3.1.1.1.1\" class=\"ltx_p\"><span id=\"S5.SS2.p3.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Research directions:</span></span>\n<span id=\"S5.I2\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S5.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I2.i1.p1\" class=\"ltx_para\">\n<span id=\"S5.I2.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I2.i1.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Develop scope attenuation protocols that enforce monotonic privilege reduction at each delegation hop.</span></span>\n</span></span>\n<span id=\"S5.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I2.i2.p1\" class=\"ltx_para\">\n<span id=\"S5.I2.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I2.i2.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Design bidirectional signing schemes where each agent cryptographically commits to both its upstream principal and its downstream delegate.</span></span>\n</span></span>\n<span id=\"S5.I2.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I2.i3.p1\" class=\"ltx_para\">\n<span id=\"S5.I2.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I2.i3.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Build immutable delegation audit trails that persist across organizational boundaries without exposing proprietary workflow details.</span></span>\n</span></span>\n</span>\n</span></span></p>\n</div>\n</section>\n<section id=\"S5.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">5.3 </span>The Agent Identity Integrity Gap</h3>\n\n<div id=\"S5.SS3.p1\" class=\"ltx_para\">\n<p id=\"S5.SS3.p1.1\" class=\"ltx_p\">An agent credential proves what model is running and that it was issued by a trusted operator. It cannot prove that the agent is executing its registered principal’s intent, nor that the agent identity is unique across instances. KYA assessment faces the same structural problem: agent identity is temporal and relational rather than static, so the same model weights can behave differently depending on context, system prompt, and interaction history, making any point-in-time enrollment assessment inherently incomplete. Three attack surfaces expose this gap.</p>\n</div>\n<div id=\"S5.SS3.p2\" class=\"ltx_para\">\n<p id=\"S5.SS3.p2.1\" class=\"ltx_p\"><span id=\"S5.SS3.p2.1.1\" class=\"ltx_text ltx_font_bold\">Puppeteering via prompt injection.</span> A verified agent can be hijacked mid-session by adversarial content embedded in its context window. Its credentials remain valid throughout: the token is correctly signed, the model hash matches, and every cryptographic check passes. Yet the agent is now executing an adversary’s instructions rather than its principal’s. This is distinct from the semantic gap in §<a href=\"#S5.SS1\" title=\"5.1 The Semantic Intent Gap ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5.1</span></a>, which concerns the unverifiability of intent in general; here the identity infrastructure has no mechanism to detect that control has been transferred or to revoke trust in response.</p>\n</div>\n<div id=\"S5.SS3.p3\" class=\"ltx_para\">\n<p id=\"S5.SS3.p3.1\" class=\"ltx_p\"><span id=\"S5.SS3.p3.1.1\" class=\"ltx_text ltx_font_bold\">Credential sharing and instance cloning.</span> Model weights are copyable and agent instances are trivially parallelizable. A single agent identity can be run across hundreds of concurrent instances, each presenting the same credential to inflate participation counts in multi-agent reputation systems or voting mechanisms, a Sybil attack executed at machine speed rather than through the slow recruitment of human proxies. Unlike human collusion, which requires finding willing participants, agent-scale Sybil attacks require only sufficient compute.</p>\n</div>\n<div id=\"S5.SS3.p4\" class=\"ltx_para\">\n<p id=\"S5.SS3.p4.1\" class=\"ltx_p\"><span id=\"S5.SS3.p4.1.1\" class=\"ltx_text ltx_font_bold\">Impersonation in delegation chains.</span> Without strong instance binding that ties a credential to a specific running enclave, an agent can present another agent’s identity at any hop in a delegation chain. The receiving agent has no way to distinguish the legitimate principal from an impersonator holding a replicated credential. This attack surface compounds the delegation gap (§<a href=\"#S5.SS2\" title=\"5.2 The Recursive Delegation and Accountability Gap ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5.2</span></a>): not only can the authorization chain lose its provenance anchor across hops, but the identity presented at each hop is itself unverifiable without hardware-level instance binding.</p>\n</div>\n<div id=\"S5.SS3.p5\" class=\"ltx_para\">\n<p id=\"S5.SS3.p5.1\" class=\"ltx_p\">Partial mitigations exist. TEE instance attestation ties a credential to a specific enclave measurement, raising the cost of cloning. ABCs can detect behavioral anomalies that suggest hijacking. Rate limiting increases the expense of Sybil attacks. But none closes the gap: TEEs can be replicated across machines, ABCs operate on observable behavior rather than the intent behind it, and rate limits impose costs without providing cryptographic proof of uniqueness. <span id=\"S5.SS3.p5.1.1\" class=\"ltx_text ltx_font_italic\">Credential validity is a necessary but not sufficient condition for authentic agency in AI agent systems.</span></p>\n</div>\n<div id=\"S5.SS3.p6\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS3.p6.1\" class=\"ltx_p\"><span id=\"S5.SS3.p6.1.1\" class=\"ltx_text\">\n<span id=\"S5.SS3.p6.1.1.1\" class=\"ltx_inline-block ltx_minipage ltx_align_middle\" style=\"width:329.0pt;\">\n<span id=\"S5.SS3.p6.1.1.1.1\" class=\"ltx_p\"><span id=\"S5.SS3.p6.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Research directions:</span></span>\n<span id=\"S5.I3\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S5.I3.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I3.i1.p1\" class=\"ltx_para\">\n<span id=\"S5.I3.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I3.i1.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Design instance binding schemes that cryptographically tie a credential to a specific running enclave and detect replication.</span></span>\n</span></span>\n<span id=\"S5.I3.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I3.i2.p1\" class=\"ltx_para\">\n<span id=\"S5.I3.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I3.i2.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Integrate behavioral anomaly detection into the credential validation path so that a hijacked agent triggers revocation rather than continuing under valid credentials.</span></span>\n</span></span>\n<span id=\"S5.I3.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I3.i3.p1\" class=\"ltx_para\">\n<span id=\"S5.I3.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I3.i3.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Develop lightweight Sybil-resistance mechanisms for multi-agent systems that do not require full proof-of-personhood at the model level.</span></span>\n</span></span>\n</span>\n</span></span></p>\n</div>\n</section>\n<section id=\"S5.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">5.4 </span>The Governance Opacity and Enforcement Paradox</h3>\n\n<div id=\"S5.SS4.p1\" class=\"ltx_para\">\n<p id=\"S5.SS4.p1.1\" class=\"ltx_p\">The dominant failure mode in deployed AI agent governance is not misconfiguration but blindness: organizations enforce access policies for agents they cannot observe. The Gravitee 2026 survey quantifies the disparity precisely: organizations report 82% confidence in their ability to govern AI agents, yet on average only 47.1% of their deployed agents are actively monitored or secured <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">20</a>]</cite>. A near-twofold gap between perceived control and operational reality means that governance confidence is largely untethered from evidence.</p>\n</div>\n<div id=\"S5.SS4.p2\" class=\"ltx_para\">\n<p id=\"S5.SS4.p2.1\" class=\"ltx_p\">This opacity produces a structural paradox in enforcement. When zero-trust architectures block agents that lack enterprise-issued credentials, the intended effect is to reduce risk by excluding unverified actors. The actual effect is the shadow agent problem: employees who deploy AI agents for legitimate workflows, but whose agents lack enterprise DIDs or managed credential lifecycles, find those agents treated as rogue. Blocked from sanctioned infrastructure, these agents and their users move to unsanctioned channels (outside logging, outside policy enforcement, and outside any audit framework). The enforcement mechanism creates the evasion it was designed to prevent. This is a structural property of two-sided enforcement, not a deployment deficiency: any identity requirement strict enough to exclude untrustworthy actors will simultaneously exclude actors who are legitimate but under-resourced, and those actors do not stop operating; they move to unsanctioned channels. Lowering the compliance bar reduces security; subsidized onboarding paths are an unsolved governance problem in their own right. Neither exit is clean.</p>\n</div>\n<div id=\"S5.SS4.p3\" class=\"ltx_para\">\n<p id=\"S5.SS4.p3.1\" class=\"ltx_p\">A second structural problem is credential inequality across the agent ecosystem. Enterprise agents benefit from dedicated identity infrastructure: managed credential lifecycles, automated rotation, and compliance teams. Open-source agents, hobbyist deployments, and agents from organizations without identity engineering capacity lack equivalent infrastructure. Default-deny architectures therefore filter by organizational capacity rather than by actual trustworthiness, producing a two-tiered agent ecosystem in which verification burden correlates with resource availability, not with risk. DID/Wallet architectures reproduce this asymmetry at the infrastructure level: despite decentralized branding, governance of the DID infrastructure itself remains centralized (method registries, trust frameworks, and revocation lists all require coordinating authorities), so organizations without the capacity to participate in those frameworks face the same exclusion.</p>\n</div>\n<div id=\"S5.SS4.p4\" class=\"ltx_para\">\n<p id=\"S5.SS4.p4.1\" class=\"ltx_p\">ZKPs (§<a href=\"#S4.SS3\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.3</span></a>) are often proposed as the solution to verification-privacy tension for agents, and they do conceal credential contents. But at 144 machine identities per human in enterprise environments <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib33\" title=\"\" class=\"ltx_ref\">13</a>]</cite>, ZKPs cannot conceal the <span id=\"S5.SS4.p4.1.1\" class=\"ltx_text ltx_font_italic\">pattern</span> of verification events. Every API call an agent makes leaves an observable record: that verification was sought, when, and from which verifier. Aggregated across all agent interactions in an organization, this event log constitutes a detailed behavioral map of the entire agent fleet, even if no individual credential is ever exposed. Aggregate monitoring and differential privacy can reduce individual exposure, but they cannot resolve the underlying tension: forensically useful audit logs require correlating events across agents and time, while meaningful privacy preservation requires unlinking those same events. No current framework achieves both.</p>\n</div>\n<div id=\"S5.SS4.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS4.p5.1\" class=\"ltx_p\"><span id=\"S5.SS4.p5.1.1\" class=\"ltx_text\">\n<span id=\"S5.SS4.p5.1.1.1\" class=\"ltx_inline-block ltx_minipage ltx_align_middle\" style=\"width:329.0pt;\">\n<span id=\"S5.SS4.p5.1.1.1.1\" class=\"ltx_p\"><span id=\"S5.SS4.p5.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Research directions:</span></span>\n<span id=\"S5.I4\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S5.I4.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I4.i1.p1\" class=\"ltx_para\">\n<span id=\"S5.I4.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I4.i1.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Design tiered verification models that apply strong credential requirements only at high-risk decision points.</span></span>\n</span></span>\n<span id=\"S5.I4.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I4.i2.p1\" class=\"ltx_para\">\n<span id=\"S5.I4.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I4.i2.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Develop aggregate behavioral monitoring that detects anomalous agent patterns without requiring per-call verification.</span></span>\n</span></span>\n<span id=\"S5.I4.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I4.i3.p1\" class=\"ltx_para\">\n<span id=\"S5.I4.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I4.i3.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Create lightweight onboarding paths for smaller deployments that reduce the compliance barrier without compromising auditability.</span></span>\n</span></span>\n</span>\n</span></span></p>\n</div>\n</section>\n<section id=\"S5.SS5\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">5.5 </span>Operational Cost and Sustainability</h3>\n\n<div id=\"S5.SS5.p1\" class=\"ltx_para\">\n<p id=\"S5.SS5.p1.1\" class=\"ltx_p\">Every gap identified in the preceding subsections implicitly assumes that the proposed mitigations, including ZKP (§<a href=\"#S4.SS3\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.3</span></a>) generation for every credential presentation, TEE (§<a href=\"#S4.SS6\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4.6</span></a>) attestation for every agent invocation, and immutable audit logging for every delegation event, can be deployed at the scale the problem demands. That assumption has not been examined. At the NHI ratios already noted (§<a href=\"#S5.SS4\" title=\"5.4 The Governance Opacity and Enforcement Paradox ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5.4</span></a>), if each machine identity requires cryptographic verification at every micro-interaction (every API call, every tool invocation, every inter-agent handshake) the aggregate computational cost grows faster than linearly with fleet size and interaction density: each such handshake carries verification overhead on both sides, and the number of handshakes scales with the square of the agent population in a fully connected topology.</p>\n</div>\n<div id=\"S5.SS5.p2\" class=\"ltx_para\">\n<p id=\"S5.SS5.p2.1\" class=\"ltx_p\">The field has not established baseline measurements of verification overhead at operational agent scale, nor identified which combinations of primitives can be safely amortized, batched, or made probabilistic without compromising security guarantees. Until those baselines exist, it is not possible to assess whether universal zero-trust micro-verification is ecologically sustainable at planetary scale. The energy cost of ZKP generation, which involves repeated polynomial evaluations and elliptic curve operations, is non-trivial for a single proof; multiplied across billions of daily agent interactions, it constitutes an infrastructure demand that has been framed exclusively as an engineering and hardware limitation, a problem to be solved by faster chips and more efficient proof systems, and never as an environmental or ethical constraint. Treating verification cost as an implementation detail (a problem for hardware vendors rather than a constraint on system design) risks committing to an architecture whose aggregate overhead is infeasible before that infeasibility becomes apparent. Any viable identity framework must therefore address not only <span id=\"S5.SS5.p2.1.1\" class=\"ltx_text ltx_font_italic\">what</span> to verify and <span id=\"S5.SS5.p2.1.2\" class=\"ltx_text ltx_font_italic\">how</span> to verify it, but whether verification at the proposed granularity is operationally and ecologically defensible.</p>\n</div>\n<div id=\"S5.SS5.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS5.p3.1\" class=\"ltx_p\"><span id=\"S5.SS5.p3.1.1\" class=\"ltx_text\">\n<span id=\"S5.SS5.p3.1.1.1\" class=\"ltx_inline-block ltx_minipage ltx_align_middle\" style=\"width:329.0pt;\">\n<span id=\"S5.SS5.p3.1.1.1.1\" class=\"ltx_p\"><span id=\"S5.SS5.p3.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Research directions:</span></span>\n<span id=\"S5.I5\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S5.I5.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I5.i1.p1\" class=\"ltx_para\">\n<span id=\"S5.I5.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I5.i1.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Establish the ecological ceiling of planetary-scale cryptographic identity enforcement.</span></span>\n</span></span>\n<span id=\"S5.I5.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I5.i2.p1\" class=\"ltx_para\">\n<span id=\"S5.I5.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I5.i2.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Identify which verification operations can be amortized, batched, or made probabilistic without compromising security guarantees.</span></span>\n</span></span>\n<span id=\"S5.I5.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S5.I5.i3.p1\" class=\"ltx_para\">\n<span id=\"S5.I5.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I5.i3.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Determine whether the energy budget of a fully verified agent ecosystem is compatible with global sustainability commitments.</span></span>\n</span></span>\n</span>\n</span></span></p>\n</div>\n</section>\n</section>\n<section id=\"S6\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">6 </span>Conclusion</h2>\n\n<div id=\"S6.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S6.p1.1\" class=\"ltx_p\">This report set out to answer four questions: how AI identity differs from human identity, where the market and standards landscape stands, which technologies are available, and where the critical gaps lie. The answers converge on a single finding: the infrastructure designed to govern who may act, who is accountable, and who is real was built for human principals and deterministic machines, and it has not been structurally rethought for autonomous agents.</p>\n</div>\n<div id=\"S6.p2\" class=\"ltx_para\">\n<p id=\"S6.p2.1\" class=\"ltx_p\">The four structural dimensions identified in §<a href=\"#S2\" title=\"2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> (substrate, persistence, verifiability, and legal standing) show that the asymmetry between human and AI identity is fundamental. Extending human-identity frameworks to agents without structural modification produces systematic failures, and the industry documents evaluated in §<a href=\"#S3\" title=\"3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> confirm that the market has not yet confronted this. The five gaps identified in §<a href=\"#S5\" title=\"5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a> are the result: semantic intent cannot be cryptographically proven; recursive delegation has no production protocol for cross-boundary accountability; agent identity integrity remains unenforceable against puppeteering, cloning, and impersonation at scale; governance confidence is nearly double actual monitoring coverage; and the operational cost of universal verification at planetary scale has never been treated as an ecological constraint. These are boundary conditions, not engineering backlogs, and the research directions embedded in each gap subsection constitute the minimum agenda required to address them.</p>\n</div>\n<section id=\"S6.SSx1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\">AI Identity as Continuous Relationship</h3>\n\n<figure id=\"S6.F1\" class=\"ltx_figure\"><span class=\"ltx_inline-block\"><svg id=\"S6.F1.pic1\" class=\"ltx_picture ltx_centering\" height=\"215.37\" overflow=\"visible\" version=\"1.1\" viewBox=\"0 0 564.13 215.37\" width=\"564.13\"><g transform=\"translate(0,215.37) matrix(1 0 0 -1 0 0) translate(231.41,0) translate(0,186.98)\"><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\"><g stroke-width=\"0.4pt\"><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#999999;\" fill=\"#999999\" stroke=\"#000000\"><path d=\"M 225.6 27.56 L -225.6 27.56 C -228.66 27.56 -231.13 25.08 -231.13 22.02 L -231.13 -22.02 C -231.13 -25.08 -228.66 -27.56 -225.6 -27.56 L 225.6 -27.56 C 228.66 -27.56 231.13 -25.08 231.13 -22.02 L 231.13 22.02 C 231.13 25.08 228.66 27.56 225.6 27.56 Z M -231.13 -27.56\"></path></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 -226.52 -8.65)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 22.14)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 168.92 0)\"><foreignObject style=\"--ltx-fo-width:7.87em;--ltx-fo-height:0.59em;--ltx-fo-depth:0.16em;font-size:10.65pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"116.03\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Declaration Layer</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 19.72)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:35.42em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"453.41\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.2\" class=\"ltx_text\" style=\"font-size:90%;\">Credentials, DIDs, VCs, model hashes, system prompt hashes, regulatory status\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#CCCCCC;\" fill=\"#CCCCCC\" stroke=\"#000000\"><path d=\"M 195.26 -51.73 L -195.26 -51.73 C -198.31 -51.73 -200.79 -54.21 -200.79 -57.27 L -200.79 -101.32 C -200.79 -104.37 -198.31 -106.85 -195.26 -106.85 L 195.26 -106.85 C 198.31 -106.85 200.79 -104.37 200.79 -101.32 L 200.79 -57.27 C 200.79 -54.21 198.31 -51.73 195.26 -51.73 Z M -200.79 -106.85\"></path></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 -196.18 -87.94)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 22.14)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 137.11 0)\"><foreignObject style=\"--ltx-fo-width:8.13em;--ltx-fo-height:0.59em;--ltx-fo-depth:0.16em;font-size:10.65pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"119.78\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.3\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Observation Layer</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 19.72)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:30.77em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"393.79\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.4\" class=\"ltx_text\" style=\"font-size:90%;\">Behavioral monitoring, anomaly detection, continuous authentication\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#EBEBEB;\" fill=\"#EBEBEB\" stroke=\"#000000\"><path d=\"M 191.32 -131.03 L -191.32 -131.03 C -194.37 -131.03 -196.85 -133.51 -196.85 -136.56 L -196.85 -180.61 C -196.85 -183.67 -194.37 -186.15 -191.32 -186.15 L 191.32 -186.15 C 194.37 -186.15 196.85 -183.67 196.85 -180.61 L 196.85 -136.56 C 196.85 -133.51 194.37 -131.03 191.32 -131.03 Z M -196.85 -186.15\"></path></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 -154 -167.24)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 22.14)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 98.02 0)\"><foreignObject style=\"--ltx-fo-width:7.65em;--ltx-fo-height:0.59em;--ltx-fo-depth:0.16em;font-size:10.65pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"112.79\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.5\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Confidence Layer</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 19.72)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:24.2em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"309.79\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.6\" class=\"ltx_text\" style=\"font-size:90%;\">Temporal decay, nondeterminism, bounded estimation\n</span></span></span></foreignObject></g></g></g></g></g><g stroke-width=\"0.8pt\"><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\"><path style=\"fill:none\" d=\"M 0 -27.84 L 0 -47.86\"></path><g transform=\"matrix(0.0 -1.0 1.0 0.0 0 -47.86)\"><path style=\"stroke:none\" d=\"M 3.6 0 L -2.16 2.88 L 0 0 L -2.16 -2.88\"></path></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 13.04 -43.01)\"><foreignObject style=\"--ltx-fo-width:10em;--ltx-fo-height:0.58em;--ltx-fo-depth:0em;font-size:8.44pt;\" height=\"6.73\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"116.88\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.7\" class=\"ltx_text ltx_font_italic\" style=\"font-size:70%;\">“What it claims to be”</span></span></span></foreignObject></g></g><g stroke-width=\"0.8pt\"><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\"><path style=\"fill:none\" d=\"M 0 -107.13 L 0 -127.15\"></path><g transform=\"matrix(0.0 -1.0 1.0 0.0 0 -127.15)\"><path style=\"stroke:none\" d=\"M 3.6 0 L -2.16 2.88 L 0 0 L -2.16 -2.88\"></path></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 13.04 -121.36)\"><foreignObject style=\"--ltx-fo-width:10.36em;--ltx-fo-height:0.58em;--ltx-fo-depth:0.16em;font-size:8.44pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"121.01\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.8\" class=\"ltx_text ltx_font_italic\" style=\"font-size:70%;\">“What it actually does”</span></span></span></foreignObject></g></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" stroke-width=\"0.8pt\"><path style=\"fill:none\" d=\"M 243.22 27.84 M 243.22 27.84 C 246.24 25.67 247.81 21.5 246.94 16.03 L 233.3 -69.24 C 232.42 -74.7 233.99 -78.88 237.01 -81.04 C 233.47 -82.16 230.67 -85.63 229.8 -91.1 L 216.15 -176.36 C 215.28 -181.83 212.48 -185.31 208.94 -186.42\"></path><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 246.99 -86.98)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 19.68)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 7.69)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:6.9em;--ltx-fo-height:0.65em;--ltx-fo-depth:0.18em;font-size:8.5pt;\" height=\"9.84\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.69)\" width=\"81.11\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.F1.pic1.9\" class=\"ltx_text\" style=\"font-size:80%;\">Correspondence</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 17.53)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:4.38em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:8.78pt;\" height=\"9.84\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.69)\" width=\"53.16\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.F1.pic1.m1\" class=\"ltx_Math\" alttext=\"=\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.800em\">=</mo><annotation encoding=\"application/x-tex\">=</annotation></semantics></math><span id=\"S6.F1.pic1.10\" class=\"ltx_text\" style=\"font-size:80%;\"> </span><span id=\"S6.F1.pic1.11\" class=\"ltx_text ltx_font_italic\" style=\"font-size:80%;\">Identity</span></span></span></foreignObject></g></g></g></g></g></g></svg></span>\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\">Figure 1: </span>The three-layer definition of AI identity. Identity is the continuously estimated correspondence between declaration and observation, bounded by confidence.</figcaption>\n</figure>\n<div id=\"S6.SSx1.p1\" class=\"ltx_para\">\n<p id=\"S6.SSx1.p1.1\" class=\"ltx_p\">A unifying theoretical frame for that agenda is to formalize AI identity not as a binary credential but as a <span id=\"S6.SSx1.p1.1.1\" class=\"ltx_text ltx_font_italic\">continuous relationship</span>. Under this model (Figure <a href=\"#S6.F1\" title=\"Figure 1 ‣ AI Identity as Continuous Relationship ‣ 6 Conclusion\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1</span></a>), identity is structured in three layers: a <span id=\"S6.SSx1.p1.1.2\" class=\"ltx_text ltx_font_italic\">declaration layer</span>, where an agent or its principal asserts identity claims; an <span id=\"S6.SSx1.p1.1.3\" class=\"ltx_text ltx_font_italic\">observation layer</span>, where external systems record behavioral evidence; and a <span id=\"S6.SSx1.p1.1.4\" class=\"ltx_text ltx_font_italic\">confidence layer</span>, where the two are reconciled into a probabilistic identity estimate that updates over time. The four identity dimensions from Table <a href=\"#S2.T2\" title=\"Table 2 ‣ 2.3 A Four-Dimension Comparison ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> serve as the primary axes of this model.</p>\n</div>\n<div id=\"S6.SSx1.p2\" class=\"ltx_para\">\n<p id=\"S6.SSx1.p2.1\" class=\"ltx_p\">The declaration layer captures what an agent claims: its identity, authorizing principal, and delegated scope. The observation layer records what it actually does: calls made, tools invoked, and delegation hops traversed. The confidence layer reconciles the two into a probabilistic estimate that updates continuously as evidence accumulates. Unlike a binary credential that is either valid or revoked, a confidence score degrades gracefully when behavioral evidence diverges from declared intent, alerting operators before a threshold is crossed rather than only after a violation is confirmed.</p>\n</div>\n<div id=\"S6.SSx1.p3\" class=\"ltx_para\">\n<p id=\"S6.SSx1.p3.1\" class=\"ltx_p\">Safe and secure AI agents, under this model, are not agents whose credentials are valid but agents whose confidence scores are high and stable. This gives operators, auditors, and regulators a continuous, graded signal rather than a point-in-time pass/fail verdict, making the goal of AI identity precise: close the gap between what an agent declares and what it does, and maintain the confidence that those two things correspond.</p>\n</div>\n</section>\n<section id=\"S6.SSx2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\">Limitations</h3>\n\n<div id=\"S6.SSx2.p1\" class=\"ltx_para\">\n<p id=\"S6.SSx2.p1.1\" class=\"ltx_p\">This report reflects the state of the field as of early 2026. The literature search, while broad, may not be exhaustive; concurrent or shortly subsequent publications may address gaps identified here. The AI identity landscape is evolving rapidly, and standards, products, and regulatory instruments cited in this report may have been revised, superseded, or withdrawn by the time of reading. Readers are encouraged to verify the current status of specific standards and regulatory instruments before making decisions based on this report.</p>\n</div>\n</section>\n</section>\n<section id=\"bib\" class=\"ltx_bibliography\">\n<h2 class=\"ltx_title ltx_title_bibliography\">References</h2>\n\n<ul id=\"bib.L1\" class=\"ltx_biblist\">\n<li id=\"bib.bib48\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[1]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A2A Project (Linux Foundation)</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent2Agent (A2A) Protocol Specification</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Technical Specification; originally by Google, donated to the Linux Foundation</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://a2a-protocol.org/latest/specification/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS1.p4.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>.\n</span></li>\n<li id=\"bib.bib15\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[2]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Adler, Z. Hitzig, S. Jain, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Personhood Credentials: Artificial Intelligence and the Value of Privacy-Preserving Tools to Distinguish Who is Real Online</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2408.07892</span>,\n<a href=\"https://arxiv.org/abs/2408.07892\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS2.p2.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>.\n</span></li>\n<li id=\"bib.bib34\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[3]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Astrix Security</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Astrix Featured in Gartner’s 2025 Hype Cycle for Digital Identity</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Vendor Blog</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://astrix.security/learn/blog/astrix-featured-in-gartners-2025-hype-cycle-for-digital-identity/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS1.p2.1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>.\n</span></li>\n<li id=\"bib.bib14\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[4]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">V. P. Bhardwaj</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent Behavioral Contracts: Formal Specification and Runtime Enforcement for Reliable Autonomous AI Agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Academic Paper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2602.22302</span>,\n<a href=\"https://arxiv.org/abs/2602.22302\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS5.p3.1\" title=\"4.5 Governance and Monitoring ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.5</span></a>.\n</span></li>\n<li id=\"bib.bib4\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[5]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">H. Booth, B. Fisher, R. Galluzzo, and J. Roberts</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Accelerating the Adoption of Software and AI Agent Identity and Authorization</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">National Institute of Standards and Technology</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">NCCoE Concept Paper. Public comment period: February 5–April 2, 2026</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS2.p4.1\" title=\"3.2 Standards Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.2</span></a>,\n<a href=\"#S3.SS3.p3.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.3.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>,\n<a href=\"#S4.SS2.p4.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p6.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>.\n</span></li>\n<li id=\"bib.bib46\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[6]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C2PA (Coalition for Content Provenance and Authenticity)</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">C2PA Content Credentials: Specification and Conformance Programme 2026</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Technical Specification and Conformance Program</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://c2pa.org/conformance/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS4.p1.1\" title=\"4.4 Provenance and Content Integrity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.4</span></a>.\n</span></li>\n<li id=\"bib.bib51\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[7]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">B. Caley</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">WIMSE, OAuth and SPIFFE: A Standards-Based Blueprint for Securing Workloads at Scale</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">CyberArk Workload Identity Day Zero, KubeCon NA 2025, Atlanta. Reported in: GitGuardian, “Workload and Agentic Identity at Scale: Insights from CyberArk’s Workload Identity Day Zero,” <a href=\"https://blog.gitguardian.com/workload-identity-day-zero-atlanta/\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://blog.gitguardian.com/workload-identity-day-zero-atlanta/</a>Conference Talk (Block)</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS1.p2.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>.\n</span></li>\n<li id=\"bib.bib6\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[8]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">California Legislature</span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AB 2602: Contracts Against Public Policy — Personal Replica</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">California State LegislatureSigned into law September 17, 2024 (Chapter 259, California Statutes); effective January 1, 2025</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2602\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p1.1\" title=\"2.1 Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib22\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[9]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Cyber Security Agency of Singapore and FAR.AI</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Securing Agentic AI: A Discussion Paper</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">Cyber Security Agency of Singapore</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.csa.gov.sg/resources/publications/securing-agentic-ai-a-discussion-paper/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p6.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>.\n</span></li>\n<li id=\"bib.bib21\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[10]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Cyber Security Agency of Singapore</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Securing Agentic AI: An Addendum to the Guidelines and Companion Guide on Securing AI Systems</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">Cyber Security Agency of Singapore</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Draft for Public Consultation</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.csa.gov.sg/resources/publications/addendum-on-securing-ai-systems/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p6.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.6.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib28\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[11]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Cyberspace Administration of China</span><span class=\"ltx_text ltx_bib_year\"> (2023)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Interim Measures for the Management of Generative Artificial Intelligence Services</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Effective August 15, 2023. Requires algorithm filing for generative AI services with “public opinion attributes or social mobilization capabilities”; as of April 2025, 346 services had completed filing.</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p4.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.4.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib27\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[12]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Cyberspace Administration of China</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Measures for the Administration of Labeling of Artificial Intelligence-Generated Content</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Released March 14, 2025; effective September 1, 2025. Accompanied by mandatory national standard GB 45438-2025 specifying metadata fields (provider code, content ID, generation timestamp) and watermark formats for text, image, audio, video, and virtual scenes. Fines up to RMB 15 million or 5% of annual turnover.</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.chinalawtranslate.com/en/ai-labeling/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p4.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.4.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib33\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[13]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Entro Security Labs</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">NHI &amp; Secrets Risk Report: H1 2025</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">Entro Security</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Analysis of 27 million non-human identities across enterprise environments</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://entro.security/blog/takeaways-nhi-secrets-risk-report/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p3.1\" title=\"1 Introduction\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S5.SS4.p4.1\" title=\"5.4 The Governance Opacity and Enforcement Paradox ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.4</span></a>.\n</span></li>\n<li id=\"bib.bib24\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[14]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">European Commission AI Office</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Code of Practice on Transparency of AI-Generated Content (First Draft)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">First draft published December 17, 2025; second draft March 2026; final expected June 2026. Addresses obligations under EU AI Act Art. 50(2) and 50(4).</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://digital-strategy.ec.europa.eu/en/library/first-draft-code-practice-transparency-ai-generated-content\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p2.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.2.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib5\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[15]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">European Parliament and Council of the European Union</span><span class=\"ltx_text ltx_bib_year\"> (2016)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (General Data Protection Regulation)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Official Journal of the European Union, L 119, pp. 1–88Legislation</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p1.1\" title=\"2.1 Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib7\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[16]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">European Parliament and Council of the European Union</span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Regulation (EU) 2024/1183 of the European Parliament and of the Council (eIDAS 2.0)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Legislation, entered into force 20 May 2024</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://eur-lex.europa.eu/eli/reg/2024/1183/oj/eng\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p1.1\" title=\"2.1 Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S3.SS3.p2.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.2.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib25\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[17]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">European Parliament and Council of the European Union</span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Regulation (EU) 2024/2847 of the European Parliament and of the Council on Horizontal Cybersecurity Requirements for Products with Digital Elements (Cyber Resilience Act)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Legislation. Entered into force December 10, 2024. Chapter IV applies June 11, 2026; full application December 11, 2027. High-risk AI systems fulfilling CRA cybersecurity requirements are deemed compliant with AI Act Article 15.</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p2.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.2.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib8\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[18]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">European Union</span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">EU Artificial Intelligence Act</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://artificialintelligenceact.eu/article/50/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p4.1\" title=\"1 Introduction\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S3.SS3.p1.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.SS3.p2.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.2.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib31\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[19]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">G7 and OECD</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Hiroshima AI Process (HAIP) Reporting Framework</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Launched February 7, 2025, as a direct outcome of the G7 Hiroshima AI Process (initiated under Japan’s 2023 G7 Presidency). First-round reports from 19 organizations published April 2025 on the OECD transparency platform.</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://transparency.oecd.ai/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p5.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.5.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib32\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[20]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Gravitee</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">State of AI Agent Security 2026: When Adoption Outpaces Control</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">Gravitee</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Industry Report. PDF: <a href=\"https://www.gravitee.io/hubfs/Downloadable%20Resource/state_of_ai_agent_security_report_pdf_2026.pdf\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://www.gravitee.io/hubfs/Downloadable%20Resource/state_of_ai_agent_security_report_pdf_2026.pdf</a></span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S1.p3.1\" title=\"1 Introduction\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S4.SS1.p4.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS1.p5.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p1.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p5.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S5.SS2.p1.1\" title=\"5.2 The Recursive Delegation and Accountability Gap ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.2</span></a>,\n<a href=\"#S5.SS4.p1.1\" title=\"5.4 The Governance Opacity and Enforcement Paradox ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.4</span></a>.\n</span></li>\n<li id=\"bib.bib23\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[21]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Gupta</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Zero-Knowledge Proofs For Privacy-Preserving Systems: A Survey Across Blockchain, Identity, And Beyond</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Engineering and Technology Journal</span> <span class=\"ltx_text ltx_bib_volume\">10</span> (<span class=\"ltx_text ltx_bib_number\">7</span>), <span class=\"ltx_text ltx_bib_pages\">pp. 5755–5761</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Academic Paper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.47191/etj/v10i07.23\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a>,\n<a href=\"https://everant.org/index.php/etj/article/view/2061\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS3.p2.1\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.3</span></a>.\n</span></li>\n<li id=\"bib.bib37\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[22]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">HashiCorp, an IBM Company</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Vault Enterprise 1.21: SPIFFE Auth, FIPS 140-3 Level 1 Compliance, Granular Secret Recovery</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">HashiCorp</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Product Release Blog; Vault 1.21 GA 2026. See also: <a href=\"https://developer.hashicorp.com/vault/docs/v1.21.x/updates/release-notes\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://developer.hashicorp.com/vault/docs/v1.21.x/updates/release-notes</a></span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.hashicorp.com/en/blog/vault-enterprise-1-21-spiffe-auth-fips-140-3-level-1-compliance-granular-secret-recovery\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS1.p3.1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>,\n<a href=\"#S4.SS1.p2.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p3.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>.\n</span></li>\n<li id=\"bib.bib50\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[23]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C. Hommrich</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">TRAIL: A DID Method Specification</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">GitHub, TRAIL Protocol Initiative. v1.2.0-draft (April 2026); W3C DID Registry PR #669 pendingDraft Specification</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://github.com/trailprotocol/trail-did-method\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS3.p1.1\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.3</span></a>.\n</span></li>\n<li id=\"bib.bib12\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[24]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Huang, V. S. Narajala, J. Yeoh, J. Ross, R. Raskar, Y. Harkati, J. Huang, I. Habler, and C. Hughes</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A Novel Zero-Trust Identity Framework for Agentic AI: Decentralized Authentication and Fine-Grained Access Control</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Academic Paper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2505.19301</span>,\n<a href=\"https://arxiv.org/abs/2505.19301\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS1.p1.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p1.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p6.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS3.p2.1\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.3</span></a>.\n</span></li>\n<li id=\"bib.bib35\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[25]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">HUMAN Security</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">HUMAN Introduces the First Adaptive Trust Layer for the Agentic AI Era</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Press Release</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.humansecurity.com/newsroom/first-adaptive-trust-layer-for-agentic-ai-era/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS1.p3.1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>.\n</span></li>\n<li id=\"bib.bib20\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[26]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">IMDA (Infocomm Media Development Authority)</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Model Governance Framework for Agentic AI</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">IMDA, Singapore</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Government Framework</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p6.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.6.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib42\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[27]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Indicio</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">ProvenAI: Verifiable Credentials for AI Agents</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Product Whitepaper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://indicio.tech/proven-ai/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS3.p1.1\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.3</span></a>.\n</span></li>\n<li id=\"bib.bib44\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[28]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Japan Digital Agency</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Government AI “Gennai”</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Government Report</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.digital.go.jp/en/policies/genai\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p5.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>.\n</span></li>\n<li id=\"bib.bib1\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[29]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">P. Kasselman, J. Lombardo, Y. Rosomakho, B. Campbell, and N. Steele</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">draft-klrc-aiagent-auth-00: AI Agent Authentication and Authorization</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">IETF</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Internet-Draft</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS2.p4.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S3.SS2.p2.1\" title=\"3.2 Standards Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.2</span></a>,\n<a href=\"#S4.SS1.p2.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS1.p3.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS1.p4.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p4.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S5.SS2.p2.1\" title=\"5.2 The Recursive Delegation and Accountability Gap ‣ 5 RQ4: Gap Analysis and Research Directions\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.2</span></a>.\n</span></li>\n<li id=\"bib.bib17\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[30]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">J. Z. Leibo, A. S. Vezhnevets, W. A. Cunningham, and S. M. Bileschi</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A Pragmatic View of AI Personhood</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2510.26396</span>,\n<a href=\"https://arxiv.org/abs/2510.26396\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS2.p2.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>.\n</span></li>\n<li id=\"bib.bib53\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[31]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">D. Li, G. Yu, X. Wang, and B. Liang</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AuditableLLM: A Hash-Chain-Backed, Compliance-Aware Auditable Framework for Large Language Models</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Electronics</span> <span class=\"ltx_text ltx_bib_volume\">15</span> (<span class=\"ltx_text ltx_bib_number\">1</span>), <span class=\"ltx_text ltx_bib_pages\">pp. 56</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Published 23 December 2025</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.3390/electronics15010056\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a>,\n<a href=\"https://www.mdpi.com/2079-9292/15/1/56\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS6.p2.1\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.6</span></a>.\n</span></li>\n<li id=\"bib.bib55\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[32]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Microsoft Security</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Observability for AI Systems: Strengthening Visibility for Proactive Risk Detection</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Microsoft Security BlogPublished 18 March 2026</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.microsoft.com/en-us/security/blog/2026/03/18/observability-ai-systems-strengthening-visibility-proactive-risk-detection/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS6.p2.1\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.6</span></a>.\n</span></li>\n<li id=\"bib.bib30\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[33]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Ministry of Economy, Trade and Industry and Ministry of Internal Affairs and Communications</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AI Guidelines for Business (Version 1.1)</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">METI/MIC, Japan</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Published March 28, 2025. Voluntary soft-law framework; ten cross-cutting principles covering transparency, safety, fairness, privacy, security, accountability, literacy, fair competition, and innovation. Living document subject to continuous multi-stakeholder review.</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p5.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.5.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib10\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[34]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">M. Mitchell, S. Wu, A. Zaldivar, P. Barnes, L. Vasserman, B. Hutchinson, E. Spitzer, I. D. Raji, and T. Gebru</span><span class=\"ltx_text ltx_bib_year\"> (2019)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Model Cards for Model Reporting</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">Proceedings of the Conference on Fairness, Accountability, and Transparency</span>,\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_series\">FAT* ’19</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Academic Paper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.1145/3287560.3287596\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a>,\n<a href=\"https://arxiv.org/abs/1810.03993\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS2.p2.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>.\n</span></li>\n<li id=\"bib.bib29\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[35]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">National Diet of Japan</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Act on Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technologies (AI Promotion Act)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Enacted May 28, 2025; effective June 4, 2025 (most provisions). Establishes Cabinet-level AI Strategy Headquarters; codifies four principles (transparency, safety/security, fair competition, international cooperation). Imposes no binding obligations on business operators, no prohibited AI applications, and no financial penalties.</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p5.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.5.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib38\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[36]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">NHIMG</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Non-Human Identity Management Group (NHIMG): Governance Baselines for Machine and Agent Identities</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Standards Body</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.nhimg.org/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS1.p2.1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>,\n<a href=\"#S4.SS1.p1.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS1.p2.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p4.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>.\n</span></li>\n<li id=\"bib.bib49\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[37]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">NIST</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">CAISI (Center for AI Standards and Innovation) — AI Agent Standards Initiative</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">National Institute of Standards and Technology</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Launched February 17, 2026</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.nist.gov/caisi/ai-agent-standards-initiative\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p3.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.3.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib26\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[38]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Office of Management and Budget</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Memorandum M-25-21: Accelerating Federal Use of Artificial Intelligence through Innovation, Governance, and Public Trust</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">OMB Memorandum, 2025. Establishes high-impact AI category including biometric one-to-many identification; requires pre-deployment testing, impact assessments, and human oversight for covered federal agencies.</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS3.p3.1\" title=\"3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#S3.T4.4.3.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib2\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[39]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">OpenID Foundation</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Identity Management for Agentic AI</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">OpenID Foundation</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Standards Whitepaper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS2.p5.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S3.SS2.p3.1\" title=\"3.2 Standards Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.2</span></a>,\n<a href=\"#S4.SS1.p1.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS1.p4.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p1.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p2.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p4.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>.\n</span></li>\n<li id=\"bib.bib40\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[40]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">OWASP GenAI Security Project – Agentic Security Initiative</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agentic AI – Threats and Mitigations</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Version 1.1, December 2025</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS1.p4.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS5.p1.1\" title=\"4.5 Governance and Monitoring ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.5</span></a>.\n</span></li>\n<li id=\"bib.bib39\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[41]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">OWASP GenAI Security Project – Agentic Security Initiative</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">OWASP Top 10 for Agentic Applications 2026</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Version 2026, December 2025</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS2.p4.1\" title=\"3.2 Standards Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.2</span></a>,\n<a href=\"#S4.SS2.p4.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p5.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>.\n</span></li>\n<li id=\"bib.bib54\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[42]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">P. K. Patil</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">CrossGuard: A Zero-Trust Architecture for Privacy-Preserving AI Deployment Across Heterogeneous Multi-Cloud Environments</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Computer Fraud and Security</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Published by Auricle Global Society of Education and Research; note: this journal shares its name with the former Elsevier journal but is a separate, unaffiliated publication</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://computerfraudsecurity.com/index.php/journal/article/view/1024\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS6.p1.1\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.6</span></a>.\n</span></li>\n<li id=\"bib.bib36\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[43]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Radiant Logic</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Gartner’s 2026 IAM Predictions: Identity Visibility Is No Longer Optional</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">Radiant Logic</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Industry Blog, published March 3, 2026</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.radiantlogic.com/blog/gartners-2026-iam-predictions-identity-visibility-is-no-longer-optional/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS1.p2.1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>.\n</span></li>\n<li id=\"bib.bib11\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[44]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">M. Rajagopalan and V. Rao</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Authenticated Workflows: A Systems Approach to Protecting Agentic AI</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Academic Paper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2602.10465</span>,\n<a href=\"https://arxiv.org/abs/2602.10465\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS2.p3.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S2.SS2.p5.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S4.SS1.p4.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p4.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS5.p3.1\" title=\"4.5 Governance and Monitoring ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.5</span></a>.\n</span></li>\n<li id=\"bib.bib3\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[45]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">P. Riley and C. Galan</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Identity for AI Agents</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Auth0/Okta Presentation (YouTube, January 2026)Published January 14, 2026</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.youtube.com/watch?v=VSdV-AdSlis\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS1.p3.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>,\n<a href=\"#S4.SS2.p2.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p3.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>.\n</span></li>\n<li id=\"bib.bib18\" class=\"ltx_bibitem ltx_bib_report\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[46]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Saviynt</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">2026 Identity Security and AI Trends and Predictions</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_type\">Technical report</span>\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">Saviynt</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Industry Report</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://saviynt.com/blog/2026-identity-security-trends\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS1.p2.1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>,\n<a href=\"#S4.SS1.p5.1\" title=\"4.1 Authentication ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1</span></a>.\n</span></li>\n<li id=\"bib.bib9\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[47]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A. Shtefan</span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The Digital Replication Right as the Element of the Right of Publicity in the AI Age</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">SSRN PreprintSSRN, April 2024</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4788701\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p1.1\" title=\"2.1 Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib47\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[48]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Sigstore Project (Linux Foundation / OpenSSF)</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Sigstore: Software Signing and Supply-Chain Security</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Open Source Project; model-transparency sub-project extends attestation to ML artifacts</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.sigstore.dev/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS4.p2.1\" title=\"4.4 Provenance and Content Integrity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.4</span></a>.\n</span></li>\n<li id=\"bib.bib43\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[49]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Standing Committee of the National People’s Congress of China</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Cybersecurity Law of the People’s Republic of China (Revised, Effective January 2026, Article 20)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Legislation</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.T4.4.4.2.1.1\" title=\"In 3.3 Regulatory Landscape ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 4</span></a>.\n</span></li>\n<li id=\"bib.bib45\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[50]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Strata</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">2026 Guide to OAuth Token Exchange &amp; Agentic AI</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Industry Blog, published April 14, 2026; covers OBO flows, DPoP, and CAEP for agentic AI</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.strata.io/blog/agentic-identity/why-agentic-ai-demands-more-from-oauth-6a/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS2.p1.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS2.p2.1\" title=\"4.2 Authorization and Delegation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S4.SS5.p2.1\" title=\"4.5 Governance and Monitoring ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.5</span></a>.\n</span></li>\n<li id=\"bib.bib13\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[51]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Y. Sun, Y. Li, Y. Zhang, Y. Jin, and H. Zhang</span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">SVIP: Towards Verifiable Inference of Open-source Large Language Models</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Academic Paper</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2410.22307</span>,\n<a href=\"https://arxiv.org/abs/2410.22307\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS6.p3.1\" title=\"4.6 Audit Logging and Attestation ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.6</span></a>.\n</span></li>\n<li id=\"bib.bib19\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[52]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Vouched</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AI Agent Identity Verification Platform Secures $17M Series A</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Press Release</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.vouched.id/learn/vouched-secures-17m-series-a-funding-to-advance-ai-agent-identity-verification-technology\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S3.SS1.p3.1\" title=\"3.1 Vendor Direction and Emerging Players ‣ 3 RQ2: Industry Trends\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>.\n</span></li>\n<li id=\"bib.bib52\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[53]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Vouched</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Vouched Donates MCP-I Identity Framework to the Decentralized Identity Foundation to Advance Trust and Security for AI Agents</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Vouched Press ReleasePress Release</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.vouched.id/learn/vouched-donates-mcp-i-identity-framework-to-the-decentralized-identity-foundation-to-advance-trust-and-security-for-ai-agents\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS3.p1.1\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.3</span></a>.\n</span></li>\n<li id=\"bib.bib41\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[54]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">W3C Security Interest Group</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Threat Model for Decentralized Credentials</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">W3C Group Note Draft, published January 20, 2026</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.w3.org/TR/threat-model-decentralized-credentials/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS3.p1.1\" title=\"4.3 Credentials and Portable Identity ‣ 4 RQ3: Technologies for AI Identity\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.3</span></a>.\n</span></li>\n<li id=\"bib.bib16\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[55]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">F. R. Ward</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Towards a Theory of AI Personhood</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2501.13533</span>,\n<a href=\"https://arxiv.org/abs/2501.13533\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p1.1\" title=\"2.1 Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S2.SS2.p2.1\" title=\"2.2 Non-Human Identity ‣ 2 RQ1: Comparison of Human and Non-Human Identities\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>.\n</span></li>\n</ul>\n</section>\n</article>\n</div>\n</div>\n<footer class=\"arxiv-html-footer\">\n  <div class=\"ltx_page_logo\">\n    Experimental support, please\n    <a href=\"./2604.23280v1/__stdout.txt\" class=\"ltx_ref\"\n    target=\"_blank\" rel=\"nofollow\">view the build logs</a>\n    for errors. Generated by\n    <a href=\"https://math.nist.gov/~BMiller/LaTeXML/\" target=\"_blank\" class=\"ltx_ref ltx_LaTeXML_logo\">\n      <span style=\"letter-spacing: -0.2em; margin-right: 0.1em;\">\n        L\n        <span style=\"font-size: 70%; position: relative; bottom: 2.2pt;\">A</span>\n        T\n        <span style=\"position: relative; bottom: -0.4ex;\">E</span>\n      </span>\n      <span class=\"ltx_font_smallcaps\">xml</span>\n      <img alt=\"[LOGO]\"\n        src=\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAsAAAAOCAYAAAD5YeaVAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9wKExQZLWTEaOUAAAAddEVYdENvbW1lbnQAQ3JlYXRlZCB3aXRoIFRoZSBHSU1Q72QlbgAAAdpJREFUKM9tkL+L2nAARz9fPZNCKFapUn8kyI0e4iRHSR1Kb8ng0lJw6FYHFwv2LwhOpcWxTjeUunYqOmqd6hEoRDhtDWdA8ApRYsSUCDHNt5ul13vz4w0vWCgUnnEc975arX6ORqN3VqtVZbfbTQC4uEHANM3jSqXymFI6yWazP2KxWAXAL9zCUa1Wy2tXVxheKA9YNoR8Pt+aTqe4FVVVvz05O6MBhqUIBGk8Hn8HAOVy+T+XLJfLS4ZhTiRJgqIoVBRFIoric47jPnmeB1mW/9rr9ZpSSn3Lsmir1fJZlqWlUonKsvwWwD8ymc/nXwVBeLjf7xEKhdBut9Hr9WgmkyGEkJwsy5eHG5vN5g0AKIoCAEgkEkin0wQAfN9/cXPdheu6P33fBwB4ngcAcByHJpPJl+fn54mD3Gg0NrquXxeLRQAAwzAYj8cwTZPwPH9/sVg8PXweDAauqqr2cDjEer1GJBLBZDJBs9mE4zjwfZ85lAGg2+06hmGgXq+j3+/DsixYlgVN03a9Xu8jgCNCyIegIAgx13Vfd7vdu+FweG8YRkjXdWy329+dTgeSJD3ieZ7RNO0VAXAPwDEAO5VKndi2fWrb9jWl9Esul6PZbDY9Go1OZ7PZ9z/lyuD3OozU2wAAAABJRU5ErkJggg==\">\n    </a>.\n  </div>\n  <div class=\"keyboard-glossary\">\n    <h2>Instructions for reporting errors</h2>\n    <p>We are continuing to improve HTML versions of papers, and your feedback helps enhance accessibility and mobile\n      support. To report errors in the HTML that will help us improve conversion and rendering, choose any of the\n      methods listed below:</p>\n    <ul>\n      <li>Click the \"Report Issue\" <span class=\"mobile-only\">(<svg role=\"presentation\"\n            style=\"display: inline-block; vertical-align: middle; fill: var(--text-color);\" aria-hidden=\"true\"\n            height=\"1em\" viewBox=\"0 0 640 640\">\n            <path\n              d=\"M224 160C224 107 267 64 320 64C373 64 416 107 416 160L416 163.6C416 179.3 403.3 192 387.6 192L252.5 192C236.8 192 224.1 179.3 224.1 163.6L224.1 160zM569.6 172.8C580.2 186.9 577.3 207 563.2 217.6L465.4 290.9C470.7 299.8 474.7 309.6 477.2 320L576 320C593.7 320 608 334.3 608 352C608 369.7 593.7 384 576 384L480 384L480 416C480 418.6 479.9 421.3 479.8 423.9L563.2 486.4C577.3 497 580.2 517.1 569.6 531.2C559 545.3 538.9 548.2 524.8 537.6L461.7 490.3C438.5 534.5 395.2 566.5 344 574.2L344 344C344 330.7 333.3 320 320 320C306.7 320 296 330.7 296 344L296 574.2C244.8 566.5 201.5 534.5 178.3 490.3L115.2 537.6C101.1 548.2 81 545.3 70.4 531.2C59.8 517.1 62.7 497 76.8 486.4L160.2 423.9C160.1 421.3 160 418.7 160 416L160 384L64 384C46.3 384 32 369.7 32 352C32 334.3 46.3 320 64 320L162.8 320C165.3 309.6 169.3 299.8 174.6 290.9L76.8 217.6C62.7 207 59.8 186.9 70.4 172.8C81 158.7 101.1 155.8 115.2 166.4L224 248C236.3 242.9 249.8 240 264 240L376 240C390.2 240 403.7 242.8 416 248L524.8 166.4C538.9 155.8 559 158.7 569.6 172.8z\" />\n          </svg>)</span> button, located in the page header.</li>\n    </ul>\n    <p><strong>Tip:</strong> You can select the relevant text first, to include it in your report.</p>\n    <p>Our team has already identified <a class=\"ltx_ref\" href=\"https://github.com/arXiv/html_feedback/issues\"\n        target=\"_blank\">the following issues</a>. We appreciate your time reviewing and reporting rendering errors we\n      may not have found yet. Your efforts will help us improve the HTML versions for all readers, because disability\n      should not be a barrier to accessing research. Thank you for your continued support in championing open access for\n      all.</p>\n    <p>Have a free development cycle? Help support accessibility at arXiv! Our collaborators at LaTeXML maintain a <a\n        class=\"ltx_ref\" href=\"https://github.com/brucemiller/LaTeXML/wiki/Porting-LaTeX-packages-for-LaTeXML\"\n        target=\"_blank\">list of packages that need conversion</a>, and welcome <a class=\"ltx_ref\"\n        href=\"https://github.com/brucemiller/LaTeXML/issues\" target=\"_blank\">developer contributions</a>.</p>\n  </div>\n</footer><footer class=\"ds-site-footer\">\n  <div class=\"ds-site-footer-grid\">\n    <div class=\"ds-site-footer-main\">\n      <div class=\"ds-site-footer-ack\">\n        We gratefully acknowledge support from\n        our <strong>major funders</strong>,\n        <a href=\"https://info.arxiv.org/about/ourmembers.html\"><strong>member institutions</strong></a><span class=\"ack-member-inline\" hidden>, <strong></strong></span>,\n        and all contributors.\n      </div>\n      <nav class=\"ds-site-footer-links\" aria-label=\"Site navigation\">\n        <a href=\"https://info.arxiv.org/about\">About</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help\">Help</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/contact.html\">Contact</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/subscribe\">Subscribe</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/license/index.html\">Copyright</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/policies/privacy_policy.html\">Privacy</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/web_accessibility.html\">Accessibility</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://status.arxiv.org\" target=\"_blank\" rel=\"noopener noreferrer\">Operational Status<span class=\"is-sr-only\"> (opens in new tab)</span></a>\n      </nav>\n    </div>\n\n    <div class=\"ds-site-footer-funders\" aria-label=\"Major funders\">\n      <div class=\"ds-site-footer-funders-label\">Major funding support from</div>\n      <div class=\"ds-site-footer-funders-logos\">\n        <a class=\"ds-funder-link\" href=\"https://www.simonsfoundation.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation.png\" alt=\"Simons Foundation\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.sfi.org.bm/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation-international.png\" alt=\"Simons Foundation International\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.schmidtsciences.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/schmidt-sciences.png\" alt=\"Schmidt Sciences\">\n        </a>\n      </div>\n    </div>\n  </div>\n</footer><div id=\"fixed-buttons-container\">\n  <a id=\"disable-reading-mode-btn\" class=\"header-button\" href=\"javascript:toggleReadingMode();\"\n    title=\"Disable reading mode, show header and footer\">\n    <svg role=\"presentation\" height=\"1.25rem\"\n      viewBox=\"0 0 448 512\"><!--!Font Awesome Free v7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free Copyright 2026 Fonticons, Inc.-->\n      <path\n        d=\"M0 96C0 78.3 14.3 64 32 64l384 0c17.7 0 32 14.3 32 32s-14.3 32-32 32L32 128C14.3 128 0 113.7 0 96zM0 256c0-17.7 14.3-32 32-32l384 0c17.7 0 32 14.3 32 32s-14.3 32-32 32L32 288c-17.7 0-32-14.3-32-32zM448 416c0 17.7-14.3 32-32 32L32 448c-17.7 0-32-14.3-32-32s14.3-32 32-32l384 0c17.7 0 32 14.3 32 32z\" />\n    </svg>\n  </a>\n</div></body>\n</html>\n","snapshot_chars":267230,"live_check":"matches"},{"url":"https://eco.com/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026","committed_hash":"sha256:93cdebc97ee1dec0f10ef81b81a7a35bf25092660fe86d2cddd0020b08a81972","committed_hash_short":"sha256:93cdebc9…08a81972","mime_type":"text/html","committed_at":"2026-09-08T15:00:29.137784+00:00","content_snapshot":"<!DOCTYPE html><html lang=\"en\"><head><meta charSet=\"utf-8\" data-next-head=\"\"/><script type=\"application/ld+json\" data-next-head=\"\">{\"@context\":\"https://schema.org\",\"@type\":\"BreadcrumbList\",\"itemListElement\":[{\"@type\":\"ListItem\",\"item\":\"https://eco.com/support/en/\",\"name\":\"All Collections\",\"position\":1},{\"@type\":\"ListItem\",\"item\":\"https://eco.com/support/en/collections/13190721-stablepedia\",\"name\":\"Stablepedia\",\"position\":2},{\"@type\":\"ListItem\",\"item\":\"https://eco.com/support/en/collections/19622503-ai-agents-agentic-commerce\",\"name\":\"AI Agents & Agentic Commerce\",\"position\":3},{\"@type\":\"ListItem\",\"name\":\"Agent Identity Verification: How AI Agents Authenticate Purchases in 2026\",\"position\":4}]}</script><script type=\"application/ld+json\" data-next-head=\"\">{\"@context\":\"https://schema.org\",\"@type\":\"Article\",\"description\":\"How Mastercard Agent Pay tokens, Visa Trusted Agent attestations, AP2 Verifiable Credentials, and W3C DIDs prove an AI agent is authorized to transact in 2026.\",\"headline\":\"Agent Identity Verification: How AI Agents Authenticate Purchases in 2026\",\"inLanguage\":\"en\",\"publisher\":{\"@type\":\"Organization\",\"name\":\"Support\"},\"url\":\"https://eco.com/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\",\"author\":{\"@type\":\"Person\",\"name\":\"Eco\"},\"dateModified\":\"2026-07-16T22:11:11Z\"}</script><title data-next-head=\"\">Agent Identity Verification: How AI Agents Authenticate Purchases in 2026 | Support</title><meta property=\"og:title\" content=\"Agent Identity Verification: How AI Agents Authenticate Purchases in 2026 | Support\" data-next-head=\"\"/><meta name=\"twitter:title\" content=\"Agent Identity Verification: How AI Agents Authenticate Purchases in 2026 | Support\" data-next-head=\"\"/><meta property=\"og:description\" content=\"How Mastercard Agent Pay tokens, Visa Trusted Agent attestations, AP2 Verifiable Credentials, and W3C DIDs prove an AI agent is authorized to transact in 2026.\" data-next-head=\"\"/><meta name=\"twitter:description\" content=\"How Mastercard Agent Pay tokens, Visa Trusted Agent attestations, AP2 Verifiable Credentials, and W3C DIDs prove an AI agent is authorized to transact in 2026.\" data-next-head=\"\"/><meta name=\"description\" content=\"How Mastercard Agent Pay tokens, Visa Trusted Agent attestations, AP2 Verifiable Credentials, and W3C DIDs prove an AI agent is authorized to transact in 2026.\" data-next-head=\"\"/><meta property=\"og:type\" content=\"article\" data-next-head=\"\"/><meta name=\"twitter:card\" content=\"summary_large_image\" data-next-head=\"\"/><meta property=\"og:image\" content=\"https://downloads.intercomcdn.com/i/o/bswxc49x/872497/7fb618c394dc8b00eb54e89b3ebf/cf910b554cce9ebee74be1d4eb5a9eb5.jpg\" data-next-head=\"\"/><meta property=\"twitter:image\" content=\"https://downloads.intercomcdn.com/i/o/bswxc49x/872497/7fb618c394dc8b00eb54e89b3ebf/cf910b554cce9ebee74be1d4eb5a9eb5.jpg\" data-next-head=\"\"/><meta name=\"robots\" content=\"all\" data-next-head=\"\"/><meta name=\"viewport\" content=\"width=device-width, initial-scale=1\" data-next-head=\"\"/><link href=\"https://intercom.help/ecoprotocol/assets/favicon\" rel=\"icon\" data-next-head=\"\"/><link href=\"https://intercom.help/ecoprotocol/assets/favicon\" rel=\"apple-touch-icon\" data-next-head=\"\"/><link rel=\"canonical\" href=\"https://eco.com/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\" data-next-head=\"\"/><link rel=\"alternate\" href=\"https://eco.com/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\" hrefLang=\"en\" data-next-head=\"\"/><link rel=\"alternate\" href=\"https://eco.com/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\" hrefLang=\"x-default\" data-next-head=\"\"/><link nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" rel=\"preload\" href=\"https://static.intercomassets.com/_next/static/css/0d033cbca92dd9eb.css\" as=\"style\"/><link nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" rel=\"stylesheet\" href=\"https://static.intercomassets.com/_next/static/css/0d033cbca92dd9eb.css\" data-n-g=\"\"/><link nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" rel=\"preload\" href=\"https://static.intercomassets.com/_next/static/css/aca6b59773c71079.css\" as=\"style\"/><link nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" rel=\"stylesheet\" href=\"https://static.intercomassets.com/_next/static/css/aca6b59773c71079.css\" data-n-p=\"\"/><noscript data-n-css=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\"></noscript><script defer=\"\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" nomodule=\"\" src=\"https://static.intercomassets.com/_next/static/chunks/polyfills-42372ed130431b0a.js\"></script><script defer=\"\" src=\"https://static.intercomassets.com/_next/static/chunks/1353.00860067b95d9454.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/webpack-fad9ea01e69b7304.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/framework-e17a833229380640.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/main-871f598a4b5e9081.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/pages/_app-288d63c3ba6c5e4a.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/0f5396a4-fde11be1c3fd610f.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/2478-fd05cb20e00c7a4f.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/4125-559539645ba18ad2.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/6553-814daa1f4ebf9191.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/8703-86e01196ed8de39a.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/8869-2f36176e493e1f76.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/7630-7d261dc238da0573.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/chunks/pages/%5BhelpCenterIdentifier%5D/%5Blocale%5D/articles/%5BarticleSlug%5D-805d763622169e9b.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/E1BXax2uUHtwGP6Qn16b6/_buildManifest.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><script src=\"https://static.intercomassets.com/_next/static/E1BXax2uUHtwGP6Qn16b6/_ssgManifest.js\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\" defer=\"\"></script><style id=\"__jsx-1102008194\">:root{--body-bg: rgb(255, 255, 255);\n--body-image: none;\n--body-bg-rgb: 255, 255, 255;\n--body-border: rgb(230, 230, 230);\n--body-primary-color: #1a1a1a;\n--body-secondary-color: #595959;\n--body-reaction-bg: rgb(242, 242, 242);\n--body-reaction-text-color: rgb(89, 89, 89);\n--body-toc-active-border: #737373;\n--body-toc-inactive-border: #f2f2f2;\n--body-toc-inactive-color: #595959;\n--body-toc-active-font-weight: 400;\n--body-table-border: rgb(204, 204, 204);\n--body-color: hsl(0, 0%, 0%);\n--footer-bg: rgb(28, 83, 189);\n--footer-image: none;\n--footer-border: rgb(44, 106, 224);\n--footer-color: hsl(0, 0%, 100%);\n--header-bg: rgb(28, 83, 189);\n--header-image: none;\n--header-color: hsl(0, 0%, 100%);\n--collection-card-bg: rgb(255, 255, 255);\n--collection-card-image: none;\n--collection-card-color: hsl(220, 74%, 43%);\n--card-bg: rgb(255, 255, 255);\n--card-border-color: rgba(26, 26, 26, 0.15);\n--card-border-inner-radius: 6px;\n--card-border-radius: 8px;\n--card-shadow: 0 1px 2px 0 rgb(0 0 0 / 0.05);\n--search-bar-border-radius: 20px;\n--search-bar-width: 100%;\n--ticket-blue-bg-color: #dce1f9;\n--ticket-blue-text-color: #334bfa;\n--ticket-green-bg-color: #d7efdc;\n--ticket-green-text-color: #0f7134;\n--ticket-orange-bg-color: #ffebdb;\n--ticket-orange-text-color: #b24d00;\n--ticket-red-bg-color: #ffdbdb;\n--ticket-red-text-color: #df2020;\n--header-height: 245px;\n--header-subheader-background-color: #000000;\n--header-subheader-font-color: #FFFFFF;\n--content-block-bg: rgb(255, 255, 255);\n--content-block-image: none;\n--content-block-color: hsl(0, 0%, 10%);\n--content-block-button-bg: rgb(51, 75, 250);\n--content-block-button-image: none;\n--content-block-button-color: hsl(0, 0%, 100%);\n--content-block-button-radius: 6px;\n--content-block-margin: 0;\n--content-block-width: auto;\n--primary-color: hsl(220, 74%, 43%);\n--primary-color-alpha-10: hsla(220, 74%, 43%, 0.1);\n--primary-color-alpha-60: hsla(220, 74%, 43%, 0.6);\n--text-on-primary-color: #ffffff}</style><style id=\"__jsx-4136876520\">:root{--font-family-primary: system-ui, \"Segoe UI\", \"Roboto\", \"Helvetica\", \"Arial\", sans-serif, \"Apple Color Emoji\", \"Segoe UI Emoji\", \"Segoe UI Symbol\"}</style><style id=\"__jsx-469705758\">:root{--font-family-secondary: system-ui, \"Segoe UI\", \"Roboto\", \"Helvetica\", \"Arial\", sans-serif, \"Apple Color Emoji\", \"Segoe UI Emoji\", \"Segoe UI Symbol\"}</style><style id=\"__jsx-cf6f0ea00fa5c760\">.fade-background.jsx-cf6f0ea00fa5c760{background:radial-gradient(333.38%100%at 50%0%,rgba(var(--body-bg-rgb),0)0%,rgba(var(--body-bg-rgb),.00925356)11.67%,rgba(var(--body-bg-rgb),.0337355)21.17%,rgba(var(--body-bg-rgb),.0718242)28.85%,rgba(var(--body-bg-rgb),.121898)35.03%,rgba(var(--body-bg-rgb),.182336)40.05%,rgba(var(--body-bg-rgb),.251516)44.25%,rgba(var(--body-bg-rgb),.327818)47.96%,rgba(var(--body-bg-rgb),.409618)51.51%,rgba(var(--body-bg-rgb),.495297)55.23%,rgba(var(--body-bg-rgb),.583232)59.47%,rgba(var(--body-bg-rgb),.671801)64.55%,rgba(var(--body-bg-rgb),.759385)70.81%,rgba(var(--body-bg-rgb),.84436)78.58%,rgba(var(--body-bg-rgb),.9551)88.2%,rgba(var(--body-bg-rgb),1)100%),var(--header-image),var(--header-bg);background-size:cover;background-position-x:center}</style><style id=\"__jsx-27f84a20f81f6ce9\">.table-of-contents::-webkit-scrollbar{width:8px}.table-of-contents::-webkit-scrollbar-thumb{background-color:#f2f2f2;border-radius:8px}</style><style id=\"__jsx-62724fba150252e0\">.related_articles section a{color:initial}</style><style id=\"__jsx-7b3ac4f8d5337043\">.article_body a:not(.intercom-h2b-button){color:var(--primary-color)}article a.intercom-h2b-button{background-color:var(--primary-color);border:0}.zendesk-article table{overflow-x:scroll!important;display:block!important;height:auto!important}.intercom-interblocks-unordered-nested-list ul,.intercom-interblocks-ordered-nested-list ol{margin-top:16px;margin-bottom:16px}.intercom-interblocks-unordered-nested-list ul .intercom-interblocks-unordered-nested-list ul,.intercom-interblocks-unordered-nested-list ul .intercom-interblocks-ordered-nested-list ol,.intercom-interblocks-ordered-nested-list ol .intercom-interblocks-ordered-nested-list ol,.intercom-interblocks-ordered-nested-list ol .intercom-interblocks-unordered-nested-list ul{margin-top:0;margin-bottom:0}.intercom-interblocks-image a:focus{outline-offset:3px}</style><style id=\"__jsx-33b64116cd598d32\">.table_of_contents.jsx-33b64116cd598d32{max-width:260px;min-width:260px}</style></head><body><div id=\"__next\"><div dir=\"ltr\" class=\"h-full w-full\"><a href=\"#main-content\" class=\"sr-only font-bold text-header-color focus:not-sr-only focus:absolute focus:left-4 focus:top-4 focus:z-50\">Skip to main content</a><main class=\"header__lite\"><header id=\"header\" data-testid=\"header\" class=\"jsx-cf6f0ea00fa5c760 flex flex-col text-header-color\"><div class=\"jsx-cf6f0ea00fa5c760 relative flex grow flex-col mb-9 bg-header-bg bg-header-image bg-cover bg-center pb-9\"><div id=\"sr-announcement\" aria-live=\"polite\" class=\"jsx-cf6f0ea00fa5c760 sr-only\"></div><div class=\"jsx-cf6f0ea00fa5c760 flex h-full flex-col items-center marker:shrink-0\"><section class=\"relative flex w-full flex-col mb-6 pb-6\"><div class=\"header__meta_wrapper flex justify-center px-5 pt-6 leading-none sm:px-10\"><div class=\"flex items-center w-240\" data-testid=\"subheader-container\"><div class=\"mo__body header__site_name\"><div class=\"header__logo\"><a href=\"/support/en/\"><img src=\"https://downloads.intercomcdn.com/i/o/bswxc49x/589158/b7d7ffc062cc9d65848ad33aab14/6fa94b672e312a4371e8e3cecece1edf.png\" height=\"128\" alt=\"Support\"/></a></div></div><div><div class=\"flex items-center font-semibold\"><div class=\"flex items-center md:hidden\" data-testid=\"small-screen-children\"><button class=\"flex items-center border-none bg-transparent px-1.5\" data-testid=\"hamburger-menu-button\" aria-label=\"Open menu\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 16 16\" xmlns=\"http://www.w3.org/2000/svg\" class=\"fill-current\"><path d=\"M1.86861 2C1.38889 2 1 2.3806 1 2.85008C1 3.31957 1.38889 3.70017 1.86861 3.70017H14.1314C14.6111 3.70017 15 3.31957 15 2.85008C15 2.3806 14.6111 2 14.1314 2H1.86861Z\"></path><path d=\"M1 8C1 7.53051 1.38889 7.14992 1.86861 7.14992H14.1314C14.6111 7.14992 15 7.53051 15 8C15 8.46949 14.6111 8.85008 14.1314 8.85008H1.86861C1.38889 8.85008 1 8.46949 1 8Z\"></path><path d=\"M1 13.1499C1 12.6804 1.38889 12.2998 1.86861 12.2998H14.1314C14.6111 12.2998 15 12.6804 15 13.1499C15 13.6194 14.6111 14 14.1314 14H1.86861C1.38889 14 1 13.6194 1 13.1499Z\"></path></svg></button><div class=\"fixed right-0 top-0 z-50 h-full w-full hidden\" data-testid=\"hamburger-menu\"><div class=\"flex h-full w-full justify-end bg-black bg-opacity-30\"><div class=\"flex h-fit w-full flex-col bg-white opacity-100 sm:h-full sm:w-1/2\"><button class=\"text-body-font flex items-center self-end border-none bg-transparent pr-6 pt-6\" data-testid=\"hamburger-menu-close-button\" aria-label=\"Close menu\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 16 16\" xmlns=\"http://www.w3.org/2000/svg\"><path d=\"M3.5097 3.5097C3.84165 3.17776 4.37984 3.17776 4.71178 3.5097L7.99983 6.79775L11.2879 3.5097C11.6198 3.17776 12.158 3.17776 12.49 3.5097C12.8219 3.84165 12.8219 4.37984 12.49 4.71178L9.20191 7.99983L12.49 11.2879C12.8219 11.6198 12.8219 12.158 12.49 12.49C12.158 12.8219 11.6198 12.8219 11.2879 12.49L7.99983 9.20191L4.71178 12.49C4.37984 12.8219 3.84165 12.8219 3.5097 12.49C3.17776 12.158 3.17776 11.6198 3.5097 11.2879L6.79775 7.99983L3.5097 4.71178C3.17776 4.37984 3.17776 3.84165 3.5097 3.5097Z\"></path></svg></button><nav class=\"flex flex-col pl-4 text-black\"><a target=\"_blank\" rel=\"noopener noreferrer\" href=\"https://eco.com/blog\" class=\"mx-5 mb-5 text-md no-underline hover:opacity-80 md:mx-3 md:my-0 md:text-base\" data-testid=\"header-link-0\">Blog</a><a target=\"_blank\" rel=\"noopener noreferrer\" href=\"https://docs.eco.com\" class=\"mx-5 mb-5 text-md no-underline hover:opacity-80 md:mx-3 md:my-0 md:text-base\" data-testid=\"header-link-1\">Docs</a></nav></div></div></div></div><nav class=\"hidden items-center md:flex\" data-testid=\"large-screen-children\"><a target=\"_blank\" rel=\"noopener noreferrer\" href=\"https://eco.com/blog\" class=\"mx-5 mb-5 text-md no-underline hover:opacity-80 md:mx-3 md:my-0 md:text-base\" data-testid=\"header-link-0\">Blog</a><a target=\"_blank\" rel=\"noopener noreferrer\" href=\"https://docs.eco.com\" class=\"mx-5 mb-5 text-md no-underline hover:opacity-80 md:mx-3 md:my-0 md:text-base\" data-testid=\"header-link-1\">Docs</a></nav></div></div></div></div></section><section class=\"relative mx-5 flex h-full w-full flex-col items-center px-5 sm:px-10\"><div class=\"flex h-full max-w-full flex-col w-240 justify-center\" data-testid=\"main-header-container\"><div id=\"search-bar\" class=\"relative w-full\"><form action=\"/support/en/\" autoComplete=\"off\"><div class=\"flex w-full flex-col items-center\"><div class=\"relative flex w-full sm:w-search-bar\"><label for=\"search-input\" class=\"sr-only\">Search for articles...</label><input id=\"search-input\" type=\"text\" autoComplete=\"off\" class=\"peer w-full rounded-search-bar border border-black-alpha-8 bg-white-alpha-20 p-4 ps-12 font-secondary text-lg text-header-color shadow-search-bar outline-none transition ease-linear placeholder:text-header-color hover:bg-white-alpha-27 hover:shadow-search-bar-hover focus:border-transparent focus:bg-white focus:text-black-10 focus:shadow-search-bar-focused placeholder:focus:text-black-45\" placeholder=\"Search for articles...\" name=\"q\" aria-label=\"Search for articles...\" value=\"\"/><div class=\"absolute inset-y-0 start-0 flex items-center fill-header-color peer-focus-visible:fill-black-45 pointer-events-none ps-5\"><svg width=\"22\" height=\"21\" viewBox=\"0 0 22 21\" xmlns=\"http://www.w3.org/2000/svg\" class=\"fill-inherit\" aria-hidden=\"true\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M3.27485 8.7001C3.27485 5.42781 5.92757 2.7751 9.19985 2.7751C12.4721 2.7751 15.1249 5.42781 15.1249 8.7001C15.1249 11.9724 12.4721 14.6251 9.19985 14.6251C5.92757 14.6251 3.27485 11.9724 3.27485 8.7001ZM9.19985 0.225098C4.51924 0.225098 0.724854 4.01948 0.724854 8.7001C0.724854 13.3807 4.51924 17.1751 9.19985 17.1751C11.0802 17.1751 12.8176 16.5627 14.2234 15.5265L19.0981 20.4013C19.5961 20.8992 20.4033 20.8992 20.9013 20.4013C21.3992 19.9033 21.3992 19.0961 20.9013 18.5981L16.0264 13.7233C17.0625 12.3176 17.6749 10.5804 17.6749 8.7001C17.6749 4.01948 13.8805 0.225098 9.19985 0.225098Z\"></path></svg></div></div></div></form></div></div></section></div></div></header><div class=\"z-1 flex shrink-0 grow basis-auto justify-center px-5 sm:px-10\"><section data-testid=\"main-content\" id=\"main-content\" class=\"max-w-full w-240\"><section data-testid=\"article-section\" class=\"section section__article\"><div class=\"justify-between flex\"><div class=\"relative z-3 w-full lg:max-w-160 \"><div class=\"flex pb-6 max-md:pb-2 lg:max-w-160\"><div tabindex=\"-1\" class=\"focus:outline-none\"><nav class=\"pb-4 text-base\" aria-label=\"Breadcrumb\"><ol class=\"m-0 flex list-none flex-wrap items-baseline p-0\"><li class=\"contents\"><a href=\"/support/en/\" class=\"pr-2 text-body-primary-color no-underline hover:text-body-secondary-color\">All Collections</a><div class=\"pr-2\" aria-hidden=\"true\"><svg width=\"6\" height=\"10\" viewBox=\"0 0 6 10\" class=\"block h-2 w-2 fill-body-secondary-color rtl:rotate-180\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M0.648862 0.898862C0.316916 1.23081 0.316916 1.769 0.648862 2.10094L3.54782 4.9999L0.648862 7.89886C0.316916 8.23081 0.316917 8.769 0.648862 9.10094C0.980808 9.43289 1.519 9.43289 1.85094 9.10094L5.35094 5.60094C5.68289 5.269 5.68289 4.73081 5.35094 4.39886L1.85094 0.898862C1.519 0.566916 0.980807 0.566916 0.648862 0.898862Z\"></path></svg></div></li><li class=\"contents\"><a href=\"https://eco.com/support/en/collections/13190721-stablepedia\" class=\"pr-2 text-body-primary-color no-underline hover:text-body-secondary-color\" data-testid=\"breadcrumb-0\">Stablepedia</a><div class=\"pr-2\" aria-hidden=\"true\"><svg width=\"6\" height=\"10\" viewBox=\"0 0 6 10\" class=\"block h-2 w-2 fill-body-secondary-color rtl:rotate-180\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M0.648862 0.898862C0.316916 1.23081 0.316916 1.769 0.648862 2.10094L3.54782 4.9999L0.648862 7.89886C0.316916 8.23081 0.316917 8.769 0.648862 9.10094C0.980808 9.43289 1.519 9.43289 1.85094 9.10094L5.35094 5.60094C5.68289 5.269 5.68289 4.73081 5.35094 4.39886L1.85094 0.898862C1.519 0.566916 0.980807 0.566916 0.648862 0.898862Z\"></path></svg></div></li><li class=\"contents\"><a href=\"https://eco.com/support/en/collections/19622503-ai-agents-agentic-commerce\" class=\"pr-2 text-body-primary-color no-underline hover:text-body-secondary-color\" data-testid=\"breadcrumb-1\">AI Agents &amp; Agentic Commerce</a><div class=\"pr-2\" aria-hidden=\"true\"><svg width=\"6\" height=\"10\" viewBox=\"0 0 6 10\" class=\"block h-2 w-2 fill-body-secondary-color rtl:rotate-180\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M0.648862 0.898862C0.316916 1.23081 0.316916 1.769 0.648862 2.10094L3.54782 4.9999L0.648862 7.89886C0.316916 8.23081 0.316917 8.769 0.648862 9.10094C0.980808 9.43289 1.519 9.43289 1.85094 9.10094L5.35094 5.60094C5.68289 5.269 5.68289 4.73081 5.35094 4.39886L1.85094 0.898862C1.519 0.566916 0.980807 0.566916 0.648862 0.898862Z\"></path></svg></div></li><li aria-current=\"page\" class=\"text-body-secondary-color\">Agent Identity Verification: How AI Agents Authenticate Purchases in 2026</li></ol></nav></div></div><div class=\"\"><div class=\"article intercom-force-break\"><div class=\"mb-10 max-lg:mb-6\"><div class=\"flex flex-col gap-4\"><div class=\"flex flex-col\"><h1 class=\"mb-1 font-primary text-2xl font-bold leading-10 text-body-primary-color\">Agent Identity Verification: How AI Agents Authenticate Purchases in 2026</h1><div class=\"text-md font-normal leading-normal text-body-secondary-color\"><p>How Mastercard Agent Pay tokens, Visa Trusted Agent attestations, AP2 Verifiable Credentials, and W3C DIDs prove an AI agent is authorized to transact in 2026.</p></div></div><div class=\"avatar\"><div class=\"avatar__photo\"><span aria-hidden=\"true\" class=\"inline-flex items-center justify-center rounded-full bg-primary text-lg font-bold leading-6 text-primary-text shadow-solid-2 shadow-body-bg [&amp;:nth-child(n+2)]:hidden lg:[&amp;:nth-child(n+2)]:inline-flex h-8 w-8 sm:h-9 sm:w-9 bg-cover bg-center\" style=\"background-image:url(&quot;https://static.intercomassets.com/avatars/7798162/square_128/custom_avatar-1729195774.png&quot;)\"></span></div><div class=\"avatar__info -mt-0.5 text-base\"><span class=\"text-body-secondary-color\"><div>Written by <span>Eco</span></div> <time dateTime=\"2026-07-16T22:11:11Z\" title=\"Updated over 2 months ago\">July 16, 2026</time></span></div></div></div></div><div class=\"flex-col\"><div class=\"mb-7 ml-0 text-md max-messenger:mb-6 lg:hidden\"><div class=\"jsx-27f84a20f81f6ce9 table-of-contents max-h-[calc(100vh-96px)] overflow-y-auto rounded-2xl text-body-primary-color hover:text-primary max-lg:border max-lg:border-solid max-lg:border-body-border max-lg:shadow-solid-1\"><div data-testid=\"toc-dropdown\" class=\"jsx-27f84a20f81f6ce9 hidden cursor-pointer justify-between border-b max-lg:flex max-lg:flex-row max-lg:border-x-0 max-lg:border-t-0 max-lg:border-solid max-lg:border-b-body-border border-b-0\"><div class=\"jsx-27f84a20f81f6ce9 my-2 max-lg:pl-4\">Table of contents</div><div class=\"jsx-27f84a20f81f6ce9 \"><svg class=\"ml-2 mr-4 mt-3 transition-transform\" transform=\"\" width=\"16\" height=\"16\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M3.93353 5.93451C4.24595 5.62209 4.75248 5.62209 5.0649 5.93451L7.99922 8.86882L10.9335 5.93451C11.246 5.62209 11.7525 5.62209 12.0649 5.93451C12.3773 6.24693 12.3773 6.75346 12.0649 7.06588L8.5649 10.5659C8.25249 10.8783 7.74595 10.8783 7.43353 10.5659L3.93353 7.06588C3.62111 6.75346 3.62111 6.24693 3.93353 5.93451Z\" fill=\"currentColor\"></path></svg></div></div><div data-testid=\"toc-body\" class=\"jsx-27f84a20f81f6ce9 hidden my-2\"><section data-testid=\"toc-section-0\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none border-body-toc-active-border px-4\"><a id=\"#h_055097e994\" href=\"#h_055097e994\" data-testid=\"toc-link-0\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base font-toc-active text-body-primary-color\"></a></section><section data-testid=\"toc-section-1\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_7d47e378e2\" href=\"#h_7d47e378e2\" data-testid=\"toc-link-1\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-2\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_234b3d8422\" href=\"#h_234b3d8422\" data-testid=\"toc-link-2\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-3\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_7dae204731\" href=\"#h_7dae204731\" data-testid=\"toc-link-3\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-4\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_da727e8894\" href=\"#h_da727e8894\" data-testid=\"toc-link-4\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-5\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_8c466d77a7\" href=\"#h_8c466d77a7\" data-testid=\"toc-link-5\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-6\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_89a6467403\" href=\"#h_89a6467403\" data-testid=\"toc-link-6\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-7\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_2a8725ffa5\" href=\"#h_2a8725ffa5\" data-testid=\"toc-link-7\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-8\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_7f80770d8b\" href=\"#h_7f80770d8b\" data-testid=\"toc-link-8\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-9\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_df273ff7d5\" href=\"#h_df273ff7d5\" data-testid=\"toc-link-9\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-10\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_8388d1a443\" href=\"#h_8388d1a443\" data-testid=\"toc-link-10\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-11\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_cb63c8071a\" href=\"#h_cb63c8071a\" data-testid=\"toc-link-11\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section></div></div></div><div class=\"jsx-7b3ac4f8d5337043 article_body\"><article class=\"jsx-7b3ac4f8d5337043 \"><div class=\"intercom-interblocks-image intercom-interblocks-align-left\"><a href=\"https://eco-c1bf1945b488.intercom-attachments-1.com/i/o/bswxc49x/2405982990/f3213875862a394c11759d745c53/hero_15192005.png?expires=1788881400&amp;signature=0c41162378ac9e4c3b61ee1db192e39bb68f80786f7ddb1f4f6ca8284169c24c&amp;req=diQnE8B2n4hWWfMW1HO4zdwJ9S8PWYq%2FD9TnwZxbkeKdbZTo%2B8EuuBQSACjg%0ABw9Q0rExR6U8cn8RUQY%3D%0A\" target=\"_blank\" rel=\"noreferrer nofollow noopener\"><img src=\"https://eco-c1bf1945b488.intercom-attachments-1.com/i/o/bswxc49x/2405982990/f3213875862a394c11759d745c53/hero_15192005.png?expires=1788881400&amp;signature=0c41162378ac9e4c3b61ee1db192e39bb68f80786f7ddb1f4f6ca8284169c24c&amp;req=diQnE8B2n4hWWfMW1HO4zdwJ9S8PWYq%2FD9TnwZxbkeKdbZTo%2B8EuuBQSACjg%0ABw9Q0rExR6U8cn8RUQY%3D%0A\" alt=\"\"/></a></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><br/>AI agents now hold payment credentials, browse merchant catalogs, and submit checkout requests on behalf of human principals. The acquirer at the other end of the transaction has a problem no card network was designed to solve: how do you tell a legitimately delegated agent from a scripted attacker reusing a stolen token? Agent identity verification is the layer that answers that question. This article maps the four production approaches shipping in 2026, the consent flow that ties them to a human, and the threat model each is built to defeat.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_055097e994\">What Is Agent Identity Verification?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Agent identity verification is the cryptographic process of proving that a software agent submitting a payment is (a) a known agent registered with a network or issuer, (b) currently authorized by a specific human principal, and (c) acting within a scoped mandate. It binds agent, user, and intent into a single signed credential the merchant or acquirer can verify before settlement.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>The 2026 landscape splits into four implementation models: <b>tokenized agent identities</b> (Mastercard Agent Pay), <b>attestation headers</b> (Visa Trusted Agent Protocol), <b>Verifiable Credentials with signed mandates</b> (Google&#x27;s AP2), and <b>decentralized identifiers</b> (DIDs, used by crypto-native agents settling onchain). Each maps to a different trust anchor: card network, acquirer, issuer-signed VC, or self-sovereign DID document.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_7d47e378e2\">Why Can&#x27;t Existing Card Authentication Handle Agents?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Existing 3-D Secure flows assume a human cardholder is present at checkout to complete a challenge. An AI agent cannot solve a CAPTCHA, receive an SMS OTP on the user&#x27;s phone, or pass a biometric prompt. Networks classify agent traffic as card-not-present with no liability shift, which spikes decline rates and shifts chargeback exposure onto merchants. A purpose-built identity layer was required.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Mastercard&#x27;s own April 2025 announcement framed the gap explicitly: &quot;today&#x27;s payment systems weren&#x27;t built for AI agents to transact.&quot; Visa&#x27;s Intelligent Commerce program described a parallel finding, that agent transactions were being blocked by issuer fraud rules trained on human session patterns. Both networks now layer agent-specific identity on top of EMV tokenization rather than replacing it.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_234b3d8422\">How Does Mastercard Agent Pay Encode Agent Identity?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Mastercard Agent Pay issues an Agentic Token through the Mastercard Digital Enablement Service that binds three identities into one credential: the cardholder, the registered AI agent, and the scope of the mandate. When the agent presents the token at checkout, the network verifies the agent&#x27;s certificate, decrypts the cardholder PAN, and enforces the mandate&#x27;s spending limits before authorization.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Agents must be enrolled by their developer through Mastercard&#x27;s program (announced with Microsoft, IBM, Braintree, and Checkout.com as launch partners). Enrollment produces a cryptographic agent ID that the network associates with the developer&#x27;s KYC&#x27;d entity. At checkout, the token carries the agent ID alongside the cardholder token, letting the issuer score risk per agent rather than per session. See <a href=\"support/en/articles/15192001\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">our full Mastercard Agent Pay explainer</a> for the token lifecycle.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_7dae204731\">How Does Visa Trusted Agent Protocol Attest Agents?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Visa&#x27;s Trusted Agent Protocol takes a different architectural choice. Rather than embedding agent identity in the payment token, it adds signed HTTP headers to the merchant request that attest the agent&#x27;s identity, the user&#x27;s consent, and the transaction intent. Merchants verify the signature against Visa&#x27;s registry before routing the authorization, preserving the existing card rails.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>The attestation header carries the agent operator&#x27;s identifier, a user-consent reference, and a payload hash binding the attestation to the specific cart. Visa published the protocol in late 2025 as an open standard with Adyen, Cloudflare, and Stripe in the early signatory cohort. Because the protocol lives at the HTTP layer, it works with any underlying card brand. Compare the architecture side-by-side in our <a href=\"support/en/articles/15192003\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Agent Pay vs Trusted Agent breakdown</a>.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_da727e8894\">How Do AP2&#x27;s Verifiable Credentials Bind User Intent?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Google&#x27;s Agent Payments Protocol (AP2) uses W3C Verifiable Credentials to make user consent cryptographically auditable. The protocol defines two mandate types: an <b>Intent Mandate</b>, which the user signs to authorize an agent to shop within a scope (e.g., &quot;buy size-9 running shoes under $200&quot;), and a <b>Cart Mandate</b>, signed when the agent presents the final cart for explicit human approval.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Each mandate is a VC issued by a wallet the user controls, signed with the user&#x27;s key, and presented by the agent to the merchant or payment processor. The merchant verifies the signature and checks the mandate scope before charging. Google open-sourced the AP2 specification with more than 60 launch partners including Mastercard, American Express, PayPal, Coinbase, and Salesforce. For protocol depth see our <a href=\"support/en/articles/15192002\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">AP2 protocol explainer</a>.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_8c466d77a7\">How Do DIDs Verify Crypto-Native Agents?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Decentralized Identifiers (DIDs), standardized by the W3C in 2022, give an agent a self-sovereign identifier resolvable to a DID document containing public keys and service endpoints. A crypto-native agent settling in stablecoins on Base or Solana can sign a transaction with the key referenced in its DID document, and a counterparty can verify the agent by resolving the DID without consulting a central registry.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>DIDs pair naturally with VC mandates: the user&#x27;s wallet issues a VC delegating spending authority to the agent&#x27;s DID, and the agent attaches the VC to onchain payments. AP2 explicitly supports DID-anchored issuers and holders, which is why protocols like Coinbase&#x27;s x402 micropayment standard and Skyfire&#x27;s agent-payment network use DIDs as the primary identity primitive for autonomous-agent commerce.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_89a6467403\">Identity Models Compared</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>The four models differ in trust anchor, transport, and how user consent is captured. The table summarizes the production characteristics relevant for merchants and developers choosing an integration path in 2026.</p></div><div class=\"intercom-interblocks-table\"><table><tbody><tr><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Model<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Trust anchor<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Transport<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>User consent<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Best fit<br/>​</p></div></td></tr><tr><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Agentic Tokens (Mastercard Agent Pay)<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Card network registry<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>EMV token in authorization<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Tokenization enrollment + mandate scope<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Card-rails merchants on Mastercard<br/>​</p></div></td></tr><tr><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Trusted Agent Attestation (Visa)<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Visa agent registry<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Signed HTTP headers<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Consent reference in attestation<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Any card brand, HTTP-layer checkout<br/>​</p></div></td></tr><tr><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Verifiable Credentials (AP2)<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>User wallet (issuer-signed VC)<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>VC presentation in protocol message<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Signed Intent + Cart Mandates<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Multi-rail (cards, ACH, stablecoins)<br/>​</p></div></td></tr><tr><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>DIDs (W3C)<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Self-sovereign DID document<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Onchain signature or DIDComm<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>VC mandate to agent&#x27;s DID<br/>​</p></div></td><td><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Crypto-native, stablecoin settlement<br/>​</p></div></td></tr></tbody></table></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_2a8725ffa5\">What Does the Consent Flow Look Like?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Across all four models the consent flow follows the same three-leg pattern. A human principal authorizes an agent with a scoped mandate. The agent shops within scope and presents a cart. The merchant verifies the agent&#x27;s identity and the mandate&#x27;s binding to the cart before settling. The verification step is what each protocol implements differently.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>In a typical AP2 + Agent Pay hybrid flow, a user opens a wallet app, signs an Intent Mandate (&quot;$500 monthly grocery budget, only at approved retailers&quot;), and delegates to a registered agent. The agent fills a cart at an enrolled merchant. Before authorization, the merchant requests a Cart Mandate, which the user signs after reviewing the line items. The agent submits the Agentic Token plus the Cart Mandate VC. The issuer validates both before approving.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_7f80770d8b\">What Attacks Does Agent Identity Defend Against?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>The threat model agent identity verification addresses includes rogue agents (unauthorized agents impersonating a registered one), replay attacks (reusing a captured mandate or token for a second transaction), scope escalation (an agent transacting outside its mandate), and merchant collusion (a merchant fabricating a mandate the user never signed). Each protocol layers defenses against this set.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Agentic Tokens defeat replay by binding each token to a single authorization window and a specific agent certificate. Trusted Agent headers prevent merchant collusion through user-consent references that are independently verifiable. AP2 Cart Mandates defeat scope escalation because the merchant must obtain a freshly signed mandate for each transaction. DIDs defeat impersonation by anchoring the agent&#x27;s public key in a tamper-evident document the user can revoke. The remaining residual risk is principally key compromise, which falls back on wallet-level protections such as hardware-bound keys, biometric re-prompts, and revocation lists.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_df273ff7d5\">How Does Eco Fit Into Agent Identity?</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Eco&#x27;s orchestration layer settles agent payments in stablecoins across 15 chains, which means agents using AP2 or DID-based identity can route a verified mandate to the cheapest execution venue without human intervention. The Eco Routes API accepts a DID-signed payload, validates the attached mandate, and dispatches the transaction through Hyperlane or CCTP rails depending on destination chain.<br/>​</p></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>For builders integrating agent commerce, the practical pattern is: use AP2 mandates for human-to-agent consent, use DIDs for agent-to-agent identity, and use Eco for the stablecoin settlement leg. See the <a href=\"support/en/articles/15192004\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Agent Pay implementation guide</a> for the integration checklist.<br/>​</p></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_8388d1a443\">Methodology and Sources</h1></div><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>This article synthesizes primary documentation from the four protocol families plus the W3C identity standards underpinning them. All claims about partner cohorts, mandate types, and protocol mechanics trace to the original announcements and specifications listed below. Dated stats use Q1 2026 qualifiers where supply or partner counts change weekly.</p></div><div class=\"intercom-interblocks-unordered-nested-list\"><ul><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Mastercard Agent Pay press release, April 2025: <a href=\"https://www.mastercard.com/news/press/2025/april/mastercard-unveils-agent-pay-pioneering-agentic-payments-technology-to-power-commerce-in-the-age-of-ai/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">mastercard.com/news</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Visa Intelligent Commerce and Trusted Agent Protocol: <a href=\"https://corporate.visa.com/en/products/intelligent-commerce.html\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Visa Perspectives</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>AP2 specification (Agent Payments Protocol), Google: <a href=\"https://ap2-protocol.org/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Ap2-protocol</a> and <a href=\"https://github.com/google-agentic-commerce/AP2\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">GitHub repository</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>W3C Decentralized Identifiers (DIDs) v1.0 Recommendation, July 2022: <a href=\"https://www.w3.org/TR/did-core/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">w3.org/TR/did-core</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>W3C Verifiable Credentials Data Model v2.0: <a href=\"https://www.w3.org/TR/vc-data-model-2.0/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">w3.org/TR/vc-data-model-2.0</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p>Coinbase x402 micropayment protocol documentation: <a href=\"https://www.x402.org/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">X402</a></p></div></li></ul></div><div class=\"intercom-interblocks-heading intercom-interblocks-align-left\"><h1 id=\"h_cb63c8071a\">Related Reading</h1></div><div class=\"intercom-interblocks-unordered-nested-list\"><ul><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><a href=\"support/en/articles/15192001\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">What Is Mastercard Agent Pay? AI Agent Commerce Protocol 2026</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><a href=\"support/en/articles/15192002\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">AP2 Protocol Explained: Google&#x27;s Agentic Commerce Standard</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><a href=\"support/en/articles/15192003\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Mastercard Agent Pay vs Visa Trusted Agent 2026</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><a href=\"support/en/articles/15192004\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Agent Pay Implementation: Developer Guide for AI Checkout</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><a href=\"https://eco.com/support/support/en/articles/15082537\">USDC vs USDT: Stablecoin Comparison</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><a href=\"https://eco.com/support/support/en/articles/14998923\">CCTP: Cross-Chain USDC Transfers</a></p></div></li><li><div class=\"intercom-interblocks-paragraph no-margin intercom-interblocks-align-left\"><p><a href=\"https://eco.com/support/support/en/articles/14009181\">LI.FI&#x27;s API for Agentic Commerce: How Cross-Chain AI Execution Works</a></p></div></li></ul></div><section class=\"jsx-62724fba150252e0 related_articles my-6\"><hr class=\"jsx-62724fba150252e0 my-6 sm:my-8\"/><div class=\"jsx-62724fba150252e0 mb-3 text-xl font-bold\">Related Articles</div><section class=\"flex flex-col rounded-card border border-solid border-card-border bg-card-bg p-2 sm:p-3\"><ul role=\"list\" class=\"!m-0 list-none !p-0\"><li class=\"!m-0 !list-none\"><a class=\"duration-250 group/article flex flex-row justify-between gap-2 py-2 no-underline transition ease-linear hover:bg-primary-alpha-10 hover:text-primary sm:rounded-card-inner sm:py-3 rounded-card-inner px-3\" href=\"https://eco.com/support/en/articles/14846277-know-your-agent-kya-identity-for-agent-payments\" data-testid=\"article-link\"><div class=\"flex flex-col p-0\"><span class=\"m-0 text-md text-body-primary-color group-hover/article:text-primary\">Know Your Agent (KYA): Identity for Agent Payments</span></div><div class=\"flex shrink-0 flex-col justify-center p-0\"><svg class=\"block h-4 w-4 text-primary ltr:-rotate-90 rtl:rotate-90\" fill=\"currentColor\" viewBox=\"0 0 20 20\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" d=\"M5.293 7.293a1 1 0 011.414 0L10 10.586l3.293-3.293a1 1 0 111.414 1.414l-4 4a1 1 0 01-1.414 0l-4-4a1 1 0 010-1.414z\" clip-rule=\"evenodd\"></path></svg></div></a></li><li class=\"!m-0 !list-none\"><a class=\"duration-250 group/article flex flex-row justify-between gap-2 py-2 no-underline transition ease-linear hover:bg-primary-alpha-10 hover:text-primary sm:rounded-card-inner sm:py-3 rounded-card-inner px-3\" href=\"https://eco.com/support/en/articles/15192001-what-is-mastercard-agent-pay-ai-agent-commerce-protocol-in-2026\" data-testid=\"article-link\"><div class=\"flex flex-col p-0\"><span class=\"m-0 text-md text-body-primary-color group-hover/article:text-primary\">What Is Mastercard Agent Pay? AI Agent Commerce Protocol in 2026</span></div><div class=\"flex shrink-0 flex-col justify-center p-0\"><svg class=\"block h-4 w-4 text-primary ltr:-rotate-90 rtl:rotate-90\" fill=\"currentColor\" viewBox=\"0 0 20 20\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" d=\"M5.293 7.293a1 1 0 011.414 0L10 10.586l3.293-3.293a1 1 0 111.414 1.414l-4 4a1 1 0 01-1.414 0l-4-4a1 1 0 010-1.414z\" clip-rule=\"evenodd\"></path></svg></div></a></li><li class=\"!m-0 !list-none\"><a class=\"duration-250 group/article flex flex-row justify-between gap-2 py-2 no-underline transition ease-linear hover:bg-primary-alpha-10 hover:text-primary sm:rounded-card-inner sm:py-3 rounded-card-inner px-3\" href=\"https://eco.com/support/en/articles/15192002-ap2-protocol-explained-google-s-agentic-commerce-standard-2026\" data-testid=\"article-link\"><div class=\"flex flex-col p-0\"><span class=\"m-0 text-md text-body-primary-color group-hover/article:text-primary\">AP2 Protocol Explained: Google&#x27;s Agentic Commerce Standard 2026</span></div><div class=\"flex shrink-0 flex-col justify-center p-0\"><svg class=\"block h-4 w-4 text-primary ltr:-rotate-90 rtl:rotate-90\" fill=\"currentColor\" viewBox=\"0 0 20 20\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" d=\"M5.293 7.293a1 1 0 011.414 0L10 10.586l3.293-3.293a1 1 0 111.414 1.414l-4 4a1 1 0 01-1.414 0l-4-4a1 1 0 010-1.414z\" clip-rule=\"evenodd\"></path></svg></div></a></li><li class=\"!m-0 !list-none\"><a class=\"duration-250 group/article flex flex-row justify-between gap-2 py-2 no-underline transition ease-linear hover:bg-primary-alpha-10 hover:text-primary sm:rounded-card-inner sm:py-3 rounded-card-inner px-3\" href=\"https://eco.com/support/en/articles/15192003-mastercard-agent-pay-vs-visa-trusted-agent-2026-compared\" data-testid=\"article-link\"><div class=\"flex flex-col p-0\"><span class=\"m-0 text-md text-body-primary-color group-hover/article:text-primary\">Mastercard Agent Pay vs Visa Trusted Agent 2026: Compared</span></div><div class=\"flex shrink-0 flex-col justify-center p-0\"><svg class=\"block h-4 w-4 text-primary ltr:-rotate-90 rtl:rotate-90\" fill=\"currentColor\" viewBox=\"0 0 20 20\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" d=\"M5.293 7.293a1 1 0 011.414 0L10 10.586l3.293-3.293a1 1 0 111.414 1.414l-4 4a1 1 0 01-1.414 0l-4-4a1 1 0 010-1.414z\" clip-rule=\"evenodd\"></path></svg></div></a></li><li class=\"!m-0 !list-none\"><a class=\"duration-250 group/article flex flex-row justify-between gap-2 py-2 no-underline transition ease-linear hover:bg-primary-alpha-10 hover:text-primary sm:rounded-card-inner sm:py-3 rounded-card-inner px-3\" href=\"https://eco.com/support/en/articles/15192004-agent-pay-implementation-developer-guide-for-ai-checkout-in-2026\" data-testid=\"article-link\"><div class=\"flex flex-col p-0\"><span class=\"m-0 text-md text-body-primary-color group-hover/article:text-primary\">Agent Pay Implementation: Developer Guide for AI Checkout in 2026</span></div><div class=\"flex shrink-0 flex-col justify-center p-0\"><svg class=\"block h-4 w-4 text-primary ltr:-rotate-90 rtl:rotate-90\" fill=\"currentColor\" viewBox=\"0 0 20 20\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" d=\"M5.293 7.293a1 1 0 011.414 0L10 10.586l3.293-3.293a1 1 0 111.414 1.414l-4 4a1 1 0 01-1.414 0l-4-4a1 1 0 010-1.414z\" clip-rule=\"evenodd\"></path></svg></div></a></li></ul></section></section></article></div></div></div></div><fieldset class=\"intercom-reaction-picker m-0 -mb-4 -ml-4 -mr-4 mt-6 rounded-card border-0 sm:-mb-2 sm:-ml-1 sm:-mr-1 sm:mt-8\"><legend class=\"intercom-reaction-prompt float-start w-full\">Did this answer your question?</legend><div class=\"intercom-reactions-container\"><button class=\"intercom-reaction\" aria-label=\"Disappointed Reaction\" tabindex=\"0\" data-reaction-text=\"disappointed\" aria-pressed=\"false\"><span aria-hidden=\"true\" title=\"Disappointed\">😞</span></button><button class=\"intercom-reaction\" aria-label=\"Neutral Reaction\" tabindex=\"0\" data-reaction-text=\"neutral\" aria-pressed=\"false\"><span aria-hidden=\"true\" title=\"Neutral\">😐</span></button><button class=\"intercom-reaction\" aria-label=\"Smiley Reaction\" tabindex=\"0\" data-reaction-text=\"smiley\" aria-pressed=\"false\"><span aria-hidden=\"true\" title=\"Smiley\">😃</span></button></div></fieldset></div><div class=\"jsx-33b64116cd598d32 w-61 sticky top-8 ml-7 max-w-61 self-start max-lg:hidden mt-16\"><div class=\"jsx-27f84a20f81f6ce9 table-of-contents max-h-[calc(100vh-96px)] overflow-y-auto rounded-2xl text-body-primary-color hover:text-primary max-lg:border max-lg:border-solid max-lg:border-body-border max-lg:shadow-solid-1\"><div data-testid=\"toc-dropdown\" class=\"jsx-27f84a20f81f6ce9 hidden cursor-pointer justify-between border-b max-lg:flex max-lg:flex-row max-lg:border-x-0 max-lg:border-t-0 max-lg:border-solid max-lg:border-b-body-border\"><div class=\"jsx-27f84a20f81f6ce9 my-2 max-lg:pl-4\">Table of contents</div><div class=\"jsx-27f84a20f81f6ce9 \"><svg class=\"ml-2 mr-4 mt-3 transition-transform\" transform=\"rotate(180)\" width=\"16\" height=\"16\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M3.93353 5.93451C4.24595 5.62209 4.75248 5.62209 5.0649 5.93451L7.99922 8.86882L10.9335 5.93451C11.246 5.62209 11.7525 5.62209 12.0649 5.93451C12.3773 6.24693 12.3773 6.75346 12.0649 7.06588L8.5649 10.5659C8.25249 10.8783 7.74595 10.8783 7.43353 10.5659L3.93353 7.06588C3.62111 6.75346 3.62111 6.24693 3.93353 5.93451Z\" fill=\"currentColor\"></path></svg></div></div><div data-testid=\"toc-body\" class=\"jsx-27f84a20f81f6ce9 my-2\"><section data-testid=\"toc-section-0\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none border-body-toc-active-border px-4\"><a id=\"#h_055097e994\" href=\"#h_055097e994\" data-testid=\"toc-link-0\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base font-toc-active text-body-primary-color\"></a></section><section data-testid=\"toc-section-1\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_7d47e378e2\" href=\"#h_7d47e378e2\" data-testid=\"toc-link-1\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-2\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_234b3d8422\" href=\"#h_234b3d8422\" data-testid=\"toc-link-2\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-3\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_7dae204731\" href=\"#h_7dae204731\" data-testid=\"toc-link-3\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-4\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_da727e8894\" href=\"#h_da727e8894\" data-testid=\"toc-link-4\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-5\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_8c466d77a7\" href=\"#h_8c466d77a7\" data-testid=\"toc-link-5\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-6\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_89a6467403\" href=\"#h_89a6467403\" data-testid=\"toc-link-6\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-7\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_2a8725ffa5\" href=\"#h_2a8725ffa5\" data-testid=\"toc-link-7\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-8\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_7f80770d8b\" href=\"#h_7f80770d8b\" data-testid=\"toc-link-8\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-9\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_df273ff7d5\" href=\"#h_df273ff7d5\" data-testid=\"toc-link-9\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-10\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_8388d1a443\" href=\"#h_8388d1a443\" data-testid=\"toc-link-10\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section><section data-testid=\"toc-section-11\" class=\"jsx-27f84a20f81f6ce9 flex border-y-0 border-e-0 border-s-2 border-solid py-1.5 max-lg:border-none px-4\"><a id=\"#h_cb63c8071a\" href=\"#h_cb63c8071a\" data-testid=\"toc-link-11\" class=\"jsx-27f84a20f81f6ce9 w-full no-underline hover:text-body-primary-color max-lg:inline-block max-lg:text-body-primary-color max-lg:hover:text-primary lg:text-base text-body-toc-inactive-color\"></a></section></div></div></div></div></section></section></div><footer id=\"footer\" class=\"mt-24 shrink-0 bg-footer-bg px-0 py-12 text-left text-base text-footer-color\"><div class=\"shrink-0 grow basis-auto px-5 sm:px-10\"><div class=\"mx-auto max-w-240 sm:w-auto\"><div><div class=\"text-center\" data-testid=\"simple-footer-layout\"><div class=\"align-middle text-lg text-footer-color\"><a class=\"no-underline\" href=\"/support/en/\"><img data-testid=\"logo-img\" src=\"https://downloads.intercomcdn.com/i/o/bswxc49x/589159/3aadf7a3357c918e7757ea06a65b/6fa94b672e312a4371e8e3cecece1edf.png\" alt=\"Support\" class=\"max-h-8 contrast-80 inline\"/></a></div><div class=\"mt-10\" data-testid=\"simple-footer-links\"><div class=\"flex flex-row justify-center\"></div><ul data-testid=\"social-links\" class=\"flex flex-wrap items-center gap-4 p-0 justify-center\" id=\"social-links\"><li class=\"list-none align-middle\"><a target=\"_blank\" href=\"https://www.twitter.com/eco\" rel=\"nofollow noreferrer noopener\" data-testid=\"footer-social-link-0\" class=\"no-underline\"><img src=\"https://intercom.help/ecoprotocol/assets/svg/icon:social-twitter/ffffff\" alt=\"\" aria-label=\"https://www.twitter.com/eco\" width=\"16\" height=\"16\" loading=\"lazy\" data-testid=\"social-icon-twitter\"/></a></li><li class=\"list-none align-middle\"><a target=\"_blank\" href=\"https://www.linkedin.com/company/ecoproto/\" rel=\"nofollow noreferrer noopener\" data-testid=\"footer-social-link-1\" class=\"no-underline\"><img src=\"https://intercom.help/ecoprotocol/assets/svg/icon:social-linkedin/ffffff\" alt=\"\" aria-label=\"https://www.linkedin.com/company/ecoproto/\" width=\"16\" height=\"16\" loading=\"lazy\" data-testid=\"social-icon-linkedin\"/></a></li><li class=\"list-none align-middle\"><a target=\"_blank\" href=\"https://www.youtube.com/@ecoprotocol\" rel=\"nofollow noreferrer noopener\" data-testid=\"footer-social-link-2\" class=\"no-underline\"><img src=\"https://intercom.help/ecoprotocol/assets/svg/icon:social-youtube/ffffff\" alt=\"\" aria-label=\"https://www.youtube.com/@ecoprotocol\" width=\"16\" height=\"16\" loading=\"lazy\" data-testid=\"social-icon-youtube\"/></a></li></ul></div><div class=\"flex justify-center\"></div></div></div></div></div></footer></main></div></div><script id=\"__NEXT_DATA__\" type=\"application/json\" nonce=\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\">{\"props\":{\"pageProps\":{\"app\":{\"id\":\"bswxc49x\",\"messengerUrl\":\"https://widget.intercom.io/widget/bswxc49x\",\"name\":\"Eco\",\"poweredByIntercomUrl\":\"https://www.intercom.com/intercom-link?company=Eco\\u0026solution=customer-support\\u0026utm_campaign=intercom-link\\u0026utm_content=We+run+on+Intercom\\u0026utm_medium=help-center\\u0026utm_referrer=https%3A%2F%2Feco.com%2Fsupport%2Fen%2Farticles%2F15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\\u0026utm_source=desktop-web\",\"features\":{\"consentBannerBeta\":false,\"copyForLlmItems\":true,\"customNotFoundErrorMessage\":false,\"deferVideoEmbeds\":false,\"disableFontPreloading\":false,\"disableNoMarginClassTransformation\":false,\"disableNoMarginCss\":false,\"dsaReportLink\":false,\"finOnHelpCenter\":false,\"firefoxIntlShimFix\":false,\"hideIconsWithBackgroundImages\":false,\"messengerCustomFonts\":false,\"ticketsPortalAiTitleColumn\":false,\"ticketsPortalCompanyGrants\":false,\"ticketsPortalConversationCreation\":false,\"ticketsPortalConversations\":false,\"ticketsPortalFullContentSearch\":true,\"ticketsPortalFullPageMessenger\":false,\"ticketsPortalTicketCreation\":false},\"apiBase\":\"https://api-iam.intercom.io\"},\"helpCenterSite\":{\"customDomain\":\"eco.com\",\"defaultLocale\":\"en\",\"disableBranding\":true,\"externalLoginName\":null,\"externalLoginUrl\":null,\"externalLoginAppendReturnUrl\":false,\"footerContactDetails\":null,\"footerLinks\":{\"custom\":[],\"socialLinks\":[{\"iconUrl\":\"https://intercom.help/ecoprotocol/assets/svg/icon:social-twitter\",\"provider\":\"twitter\",\"url\":\"https://www.twitter.com/eco\"},{\"iconUrl\":\"https://intercom.help/ecoprotocol/assets/svg/icon:social-linkedin\",\"provider\":\"linkedin\",\"url\":\"https://www.linkedin.com/company/ecoproto/\"},{\"iconUrl\":\"https://intercom.help/ecoprotocol/assets/svg/icon:social-youtube\",\"provider\":\"youtube\",\"url\":\"https://www.youtube.com/@ecoprotocol\"}],\"linkGroups\":[]},\"headerLinks\":[{\"site_link_group_id\":114942,\"id\":90079,\"help_center_site_id\":4056521,\"title\":\"Blog\",\"url\":\"https://eco.com/blog\",\"sort_order\":1,\"link_location\":\"header\"},{\"site_link_group_id\":114942,\"id\":90080,\"help_center_site_id\":4056521,\"title\":\"Docs\",\"url\":\"https://docs.eco.com\",\"sort_order\":2,\"link_location\":\"header\"}],\"homeCollectionCols\":1,\"googleAnalyticsTrackingId\":\"G-KN3SEBFY15\",\"googleTagManagerId\":null,\"pathPrefixForCustomDomain\":\"support\",\"seoIndexingEnabled\":true,\"helpCenterId\":4056521,\"url\":\"https://eco.com/support\",\"customizedFooterTextContent\":null,\"consentBannerConfig\":null,\"canInjectCustomScripts\":false,\"showTableOfContents\":true,\"showArticleDescriptions\":false,\"scriptSection\":1,\"customScriptFilesExist\":false},\"localeLinks\":[{\"id\":\"en\",\"absoluteUrl\":\"https://eco.com/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\",\"available\":true,\"name\":\"English\",\"selected\":true,\"url\":\"/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\"}],\"requestContext\":{\"articleSource\":null,\"academy\":false,\"canonicalUrl\":\"https://eco.com/support/en/articles/15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\",\"experience\":\"legacy\",\"headerless\":false,\"isDefaultDomainRequest\":false,\"nonce\":\"uv/0lmsPTVFl9H3C3woWSrYv9sp7Q7di0XHqIVXmryQ=\",\"rootUrl\":\"/support/en/\",\"sheetUserCipher\":null,\"type\":\"help-center\"},\"theme\":{\"color\":\"1C53BD\",\"siteName\":\"Support\",\"headline\":\"Get answers and human support for all things Eco\",\"headerFontColor\":\"FFFFFF\",\"logo\":\"https://downloads.intercomcdn.com/i/o/bswxc49x/589158/b7d7ffc062cc9d65848ad33aab14/6fa94b672e312a4371e8e3cecece1edf.png\",\"logoHeight\":\"128\",\"header\":null,\"favicon\":\"https://intercom.help/ecoprotocol/assets/favicon\",\"locale\":\"en\",\"homeUrl\":null,\"social\":\"https://downloads.intercomcdn.com/i/o/bswxc49x/872497/7fb618c394dc8b00eb54e89b3ebf/cf910b554cce9ebee74be1d4eb5a9eb5.jpg\",\"urlPrefixForDefaultDomain\":\"https://intercom.help/ecoprotocol\",\"customDomain\":\"eco.com\",\"customDomainUsesSsl\":true,\"customizationOptions\":{\"customizationType\":1,\"header\":{\"backgroundColor\":\"#1C53BD\",\"fontColor\":\"#FFFFFF\",\"fadeToEdge\":false,\"backgroundGradient\":null,\"backgroundImageId\":null,\"backgroundImageUrl\":null},\"body\":{\"backgroundColor\":\"#ffffff\",\"fontColor\":null,\"fadeToEdge\":null,\"backgroundGradient\":null,\"backgroundImageId\":null},\"footer\":{\"backgroundColor\":\"#1C53BD\",\"fontColor\":\"#ffffff\",\"fadeToEdge\":null,\"backgroundGradient\":null,\"backgroundImageId\":null,\"showRichTextField\":false},\"layout\":{\"homePage\":{\"blocks\":[{\"type\":\"tickets-portal-link\",\"enabled\":false},{\"type\":\"collection-list\",\"columns\":1,\"template\":0},{\"type\":\"article-list\",\"columns\":2,\"enabled\":false,\"localizedContent\":[{\"title\":\"\",\"locale\":\"en\",\"links\":[{\"articleId\":\"empty_article_slot\",\"type\":\"article-link\"},{\"articleId\":\"empty_article_slot\",\"type\":\"article-link\"},{\"articleId\":\"empty_article_slot\",\"type\":\"article-link\"},{\"articleId\":\"empty_article_slot\",\"type\":\"article-link\"},{\"articleId\":\"empty_article_slot\",\"type\":\"article-link\"},{\"articleId\":\"empty_article_slot\",\"type\":\"article-link\"}]}]},{\"type\":\"content-block\",\"enabled\":false,\"columns\":1}]},\"collectionsPage\":{\"showArticleDescriptions\":false},\"articlePage\":{},\"searchPage\":{}},\"collectionCard\":{\"global\":{\"backgroundColor\":null,\"fontColor\":\"#1C53BD\",\"fadeToEdge\":null,\"backgroundGradient\":null,\"backgroundImageId\":null,\"showIcons\":true,\"backgroundImageUrl\":null},\"collections\":[]},\"global\":{\"font\":{\"customFontFaces\":[],\"primary\":null,\"secondary\":null},\"componentStyle\":{\"card\":{\"type\":\"bordered\",\"borderRadius\":8}},\"namedComponents\":{\"header\":{\"subheader\":{\"enabled\":false,\"style\":{\"backgroundColor\":\"#000000\",\"fontColor\":\"#FFFFFF\"}},\"style\":{\"height\":\"245px\",\"align\":\"center\",\"justify\":\"center\"}},\"searchBar\":{\"style\":{\"width\":\"400px\",\"borderRadius\":20}},\"footer\":{\"type\":0}},\"brand\":{\"colors\":[],\"websiteUrl\":\"\"},\"secondaryColor\":null,\"accentRoles\":{\"link\":null,\"button\":null},\"showDotTexture\":null,\"showCopyForLlm\":null,\"copyForLlmItems\":null},\"contentBlock\":{\"blockStyle\":{\"backgroundColor\":\"#ffffff\",\"fontColor\":\"#1a1a1a\",\"fadeToEdge\":null,\"backgroundGradient\":null,\"backgroundImageId\":null,\"backgroundImageUrl\":null},\"buttonOptions\":{\"backgroundColor\":\"#334BFA\",\"fontColor\":\"#ffffff\",\"borderRadius\":6},\"isFullWidth\":false,\"align\":null}},\"helpCenterName\":\"Eco Help Center\",\"footerLogo\":\"https://downloads.intercomcdn.com/i/o/bswxc49x/589159/3aadf7a3357c918e7757ea06a65b/6fa94b672e312a4371e8e3cecece1edf.png\",\"footerLogoHeight\":\"128\",\"localisedInformation\":{\"contentBlock\":{\"locale\":\"en\",\"title\":\"Content section title\",\"withButton\":false,\"description\":\"\",\"buttonTitle\":\"Button title\",\"buttonUrl\":\"\"}}},\"articleContent\":{\"articleId\":\"15192005\",\"author\":{\"avatar\":\"https://static.intercomassets.com/avatars/7798162/square_128/custom_avatar-1729195774.png\",\"name\":\"Eco\",\"first_name\":\"Eco\",\"avatar_shape\":\"squircle\"},\"blocks\":[{\"type\":\"image\",\"url\":\"https://eco-c1bf1945b488.intercom-attachments-1.com/i/o/bswxc49x/2405982990/f3213875862a394c11759d745c53/hero_15192005.png?expires=1788881400\\u0026signature=0c41162378ac9e4c3b61ee1db192e39bb68f80786f7ddb1f4f6ca8284169c24c\\u0026req=diQnE8B2n4hWWfMW1HO4zdwJ9S8PWYq%2FD9TnwZxbkeKdbZTo%2B8EuuBQSACjg%0ABw9Q0rExR6U8cn8RUQY%3D%0A\"},{\"type\":\"paragraph\",\"text\":\"\\u003cbr\\u003eAI agents now hold payment credentials, browse merchant catalogs, and submit checkout requests on behalf of human principals. The acquirer at the other end of the transaction has a problem no card network was designed to solve: how do you tell a legitimately delegated agent from a scripted attacker reusing a stolen token? Agent identity verification is the layer that answers that question. This article maps the four production approaches shipping in 2026, the consent flow that ties them to a human, and the threat model each is built to defeat.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"What Is Agent Identity Verification?\",\"idAttribute\":\"h_055097e994\"},{\"type\":\"paragraph\",\"text\":\"Agent identity verification is the cryptographic process of proving that a software agent submitting a payment is (a) a known agent registered with a network or issuer, (b) currently authorized by a specific human principal, and (c) acting within a scoped mandate. It binds agent, user, and intent into a single signed credential the merchant or acquirer can verify before settlement.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"The 2026 landscape splits into four implementation models: \\u003cb\\u003etokenized agent identities\\u003c/b\\u003e (Mastercard Agent Pay), \\u003cb\\u003eattestation headers\\u003c/b\\u003e (Visa Trusted Agent Protocol), \\u003cb\\u003eVerifiable Credentials with signed mandates\\u003c/b\\u003e (Google's AP2), and \\u003cb\\u003edecentralized identifiers\\u003c/b\\u003e (DIDs, used by crypto-native agents settling onchain). Each maps to a different trust anchor: card network, acquirer, issuer-signed VC, or self-sovereign DID document.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"Why Can't Existing Card Authentication Handle Agents?\",\"idAttribute\":\"h_7d47e378e2\"},{\"type\":\"paragraph\",\"text\":\"Existing 3-D Secure flows assume a human cardholder is present at checkout to complete a challenge. An AI agent cannot solve a CAPTCHA, receive an SMS OTP on the user's phone, or pass a biometric prompt. Networks classify agent traffic as card-not-present with no liability shift, which spikes decline rates and shifts chargeback exposure onto merchants. A purpose-built identity layer was required.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"Mastercard's own April 2025 announcement framed the gap explicitly: \\\"today's payment systems weren't built for AI agents to transact.\\\" Visa's Intelligent Commerce program described a parallel finding, that agent transactions were being blocked by issuer fraud rules trained on human session patterns. Both networks now layer agent-specific identity on top of EMV tokenization rather than replacing it.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"How Does Mastercard Agent Pay Encode Agent Identity?\",\"idAttribute\":\"h_234b3d8422\"},{\"type\":\"paragraph\",\"text\":\"Mastercard Agent Pay issues an Agentic Token through the Mastercard Digital Enablement Service that binds three identities into one credential: the cardholder, the registered AI agent, and the scope of the mandate. When the agent presents the token at checkout, the network verifies the agent's certificate, decrypts the cardholder PAN, and enforces the mandate's spending limits before authorization.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"Agents must be enrolled by their developer through Mastercard's program (announced with Microsoft, IBM, Braintree, and Checkout.com as launch partners). Enrollment produces a cryptographic agent ID that the network associates with the developer's KYC'd entity. At checkout, the token carries the agent ID alongside the cardholder token, letting the issuer score risk per agent rather than per session. See \\u003ca href=\\\"support/en/articles/15192001\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eour full Mastercard Agent Pay explainer\\u003c/a\\u003e for the token lifecycle.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"How Does Visa Trusted Agent Protocol Attest Agents?\",\"idAttribute\":\"h_7dae204731\"},{\"type\":\"paragraph\",\"text\":\"Visa's Trusted Agent Protocol takes a different architectural choice. Rather than embedding agent identity in the payment token, it adds signed HTTP headers to the merchant request that attest the agent's identity, the user's consent, and the transaction intent. Merchants verify the signature against Visa's registry before routing the authorization, preserving the existing card rails.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"The attestation header carries the agent operator's identifier, a user-consent reference, and a payload hash binding the attestation to the specific cart. Visa published the protocol in late 2025 as an open standard with Adyen, Cloudflare, and Stripe in the early signatory cohort. Because the protocol lives at the HTTP layer, it works with any underlying card brand. Compare the architecture side-by-side in our \\u003ca href=\\\"support/en/articles/15192003\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAgent Pay vs Trusted Agent breakdown\\u003c/a\\u003e.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"How Do AP2's Verifiable Credentials Bind User Intent?\",\"idAttribute\":\"h_da727e8894\"},{\"type\":\"paragraph\",\"text\":\"Google's Agent Payments Protocol (AP2) uses W3C Verifiable Credentials to make user consent cryptographically auditable. The protocol defines two mandate types: an \\u003cb\\u003eIntent Mandate\\u003c/b\\u003e, which the user signs to authorize an agent to shop within a scope (e.g., \\\"buy size-9 running shoes under $200\\\"), and a \\u003cb\\u003eCart Mandate\\u003c/b\\u003e, signed when the agent presents the final cart for explicit human approval.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"Each mandate is a VC issued by a wallet the user controls, signed with the user's key, and presented by the agent to the merchant or payment processor. The merchant verifies the signature and checks the mandate scope before charging. Google open-sourced the AP2 specification with more than 60 launch partners including Mastercard, American Express, PayPal, Coinbase, and Salesforce. For protocol depth see our \\u003ca href=\\\"support/en/articles/15192002\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAP2 protocol explainer\\u003c/a\\u003e.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"How Do DIDs Verify Crypto-Native Agents?\",\"idAttribute\":\"h_8c466d77a7\"},{\"type\":\"paragraph\",\"text\":\"Decentralized Identifiers (DIDs), standardized by the W3C in 2022, give an agent a self-sovereign identifier resolvable to a DID document containing public keys and service endpoints. A crypto-native agent settling in stablecoins on Base or Solana can sign a transaction with the key referenced in its DID document, and a counterparty can verify the agent by resolving the DID without consulting a central registry.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"DIDs pair naturally with VC mandates: the user's wallet issues a VC delegating spending authority to the agent's DID, and the agent attaches the VC to onchain payments. AP2 explicitly supports DID-anchored issuers and holders, which is why protocols like Coinbase's x402 micropayment standard and Skyfire's agent-payment network use DIDs as the primary identity primitive for autonomous-agent commerce.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"Identity Models Compared\",\"idAttribute\":\"h_89a6467403\"},{\"type\":\"paragraph\",\"text\":\"The four models differ in trust anchor, transport, and how user consent is captured. The table summarizes the production characteristics relevant for merchants and developers choosing an integration path in 2026.\",\"class\":\"no-margin\"},{\"type\":\"table\",\"responsive\":false,\"container\":false,\"stacked\":true,\"rows\":[{\"cells\":[{\"content\":[{\"type\":\"paragraph\",\"text\":\"Model\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Trust anchor\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Transport\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"User consent\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Best fit\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]}]},{\"cells\":[{\"content\":[{\"type\":\"paragraph\",\"text\":\"Agentic Tokens (Mastercard Agent Pay)\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Card network registry\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"EMV token in authorization\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Tokenization enrollment + mandate scope\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Card-rails merchants on Mastercard\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]}]},{\"cells\":[{\"content\":[{\"type\":\"paragraph\",\"text\":\"Trusted Agent Attestation (Visa)\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Visa agent registry\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Signed HTTP headers\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Consent reference in attestation\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Any card brand, HTTP-layer checkout\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]}]},{\"cells\":[{\"content\":[{\"type\":\"paragraph\",\"text\":\"Verifiable Credentials (AP2)\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"User wallet (issuer-signed VC)\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"VC presentation in protocol message\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Signed Intent + Cart Mandates\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Multi-rail (cards, ACH, stablecoins)\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]}]},{\"cells\":[{\"content\":[{\"type\":\"paragraph\",\"text\":\"DIDs (W3C)\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Self-sovereign DID document\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Onchain signature or DIDComm\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"VC mandate to agent's DID\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Crypto-native, stablecoin settlement\\u003cbr\\u003e​\",\"class\":\"no-margin\"}]}]}]},{\"type\":\"heading\",\"text\":\"What Does the Consent Flow Look Like?\",\"idAttribute\":\"h_2a8725ffa5\"},{\"type\":\"paragraph\",\"text\":\"Across all four models the consent flow follows the same three-leg pattern. A human principal authorizes an agent with a scoped mandate. The agent shops within scope and presents a cart. The merchant verifies the agent's identity and the mandate's binding to the cart before settling. The verification step is what each protocol implements differently.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"In a typical AP2 + Agent Pay hybrid flow, a user opens a wallet app, signs an Intent Mandate (\\\"$500 monthly grocery budget, only at approved retailers\\\"), and delegates to a registered agent. The agent fills a cart at an enrolled merchant. Before authorization, the merchant requests a Cart Mandate, which the user signs after reviewing the line items. The agent submits the Agentic Token plus the Cart Mandate VC. The issuer validates both before approving.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"What Attacks Does Agent Identity Defend Against?\",\"idAttribute\":\"h_7f80770d8b\"},{\"type\":\"paragraph\",\"text\":\"The threat model agent identity verification addresses includes rogue agents (unauthorized agents impersonating a registered one), replay attacks (reusing a captured mandate or token for a second transaction), scope escalation (an agent transacting outside its mandate), and merchant collusion (a merchant fabricating a mandate the user never signed). Each protocol layers defenses against this set.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"Agentic Tokens defeat replay by binding each token to a single authorization window and a specific agent certificate. Trusted Agent headers prevent merchant collusion through user-consent references that are independently verifiable. AP2 Cart Mandates defeat scope escalation because the merchant must obtain a freshly signed mandate for each transaction. DIDs defeat impersonation by anchoring the agent's public key in a tamper-evident document the user can revoke. The remaining residual risk is principally key compromise, which falls back on wallet-level protections such as hardware-bound keys, biometric re-prompts, and revocation lists.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"How Does Eco Fit Into Agent Identity?\",\"idAttribute\":\"h_df273ff7d5\"},{\"type\":\"paragraph\",\"text\":\"Eco's orchestration layer settles agent payments in stablecoins across 15 chains, which means agents using AP2 or DID-based identity can route a verified mandate to the cheapest execution venue without human intervention. The Eco Routes API accepts a DID-signed payload, validates the attached mandate, and dispatches the transaction through Hyperlane or CCTP rails depending on destination chain.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"paragraph\",\"text\":\"For builders integrating agent commerce, the practical pattern is: use AP2 mandates for human-to-agent consent, use DIDs for agent-to-agent identity, and use Eco for the stablecoin settlement leg. See the \\u003ca href=\\\"support/en/articles/15192004\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAgent Pay implementation guide\\u003c/a\\u003e for the integration checklist.\\u003cbr\\u003e​\",\"class\":\"no-margin\"},{\"type\":\"heading\",\"text\":\"Methodology and Sources\",\"idAttribute\":\"h_8388d1a443\"},{\"type\":\"paragraph\",\"text\":\"This article synthesizes primary documentation from the four protocol families plus the W3C identity standards underpinning them. All claims about partner cohorts, mandate types, and protocol mechanics trace to the original announcements and specifications listed below. Dated stats use Q1 2026 qualifiers where supply or partner counts change weekly.\",\"class\":\"no-margin\"},{\"type\":\"unorderedNestedList\",\"text\":\"- Mastercard Agent Pay press release, April 2025: \\u003ca href=\\\"https://www.mastercard.com/news/press/2025/april/mastercard-unveils-agent-pay-pioneering-agentic-payments-technology-to-power-commerce-in-the-age-of-ai/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003emastercard.com/news\\u003c/a\\u003e\\n- Visa Intelligent Commerce and Trusted Agent Protocol: \\u003ca href=\\\"https://corporate.visa.com/en/products/intelligent-commerce.html\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eVisa Perspectives\\u003c/a\\u003e\\n- AP2 specification (Agent Payments Protocol), Google: \\u003ca href=\\\"https://ap2-protocol.org/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAp2-protocol\\u003c/a\\u003e and \\u003ca href=\\\"https://github.com/google-agentic-commerce/AP2\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eGitHub repository\\u003c/a\\u003e\\n- W3C Decentralized Identifiers (DIDs) v1.0 Recommendation, July 2022: \\u003ca href=\\\"https://www.w3.org/TR/did-core/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003ew3.org/TR/did-core\\u003c/a\\u003e\\n- W3C Verifiable Credentials Data Model v2.0: \\u003ca href=\\\"https://www.w3.org/TR/vc-data-model-2.0/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003ew3.org/TR/vc-data-model-2.0\\u003c/a\\u003e\\n- Coinbase x402 micropayment protocol documentation: \\u003ca href=\\\"https://www.x402.org/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eX402\\u003c/a\\u003e\",\"items\":[{\"content\":[{\"type\":\"paragraph\",\"text\":\"Mastercard Agent Pay press release, April 2025: \\u003ca href=\\\"https://www.mastercard.com/news/press/2025/april/mastercard-unveils-agent-pay-pioneering-agentic-payments-technology-to-power-commerce-in-the-age-of-ai/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003emastercard.com/news\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Visa Intelligent Commerce and Trusted Agent Protocol: \\u003ca href=\\\"https://corporate.visa.com/en/products/intelligent-commerce.html\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eVisa Perspectives\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"AP2 specification (Agent Payments Protocol), Google: \\u003ca href=\\\"https://ap2-protocol.org/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAp2-protocol\\u003c/a\\u003e and \\u003ca href=\\\"https://github.com/google-agentic-commerce/AP2\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eGitHub repository\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"W3C Decentralized Identifiers (DIDs) v1.0 Recommendation, July 2022: \\u003ca href=\\\"https://www.w3.org/TR/did-core/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003ew3.org/TR/did-core\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"W3C Verifiable Credentials Data Model v2.0: \\u003ca href=\\\"https://www.w3.org/TR/vc-data-model-2.0/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003ew3.org/TR/vc-data-model-2.0\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"Coinbase x402 micropayment protocol documentation: \\u003ca href=\\\"https://www.x402.org/\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eX402\\u003c/a\\u003e\",\"class\":\"no-margin\"}]}]},{\"type\":\"heading\",\"text\":\"Related Reading\",\"idAttribute\":\"h_cb63c8071a\"},{\"type\":\"unorderedNestedList\",\"text\":\"- \\u003ca href=\\\"support/en/articles/15192001\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eWhat Is Mastercard Agent Pay? AI Agent Commerce Protocol 2026\\u003c/a\\u003e\\n- \\u003ca href=\\\"support/en/articles/15192002\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAP2 Protocol Explained: Google's Agentic Commerce Standard\\u003c/a\\u003e\\n- \\u003ca href=\\\"support/en/articles/15192003\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eMastercard Agent Pay vs Visa Trusted Agent 2026\\u003c/a\\u003e\\n- \\u003ca href=\\\"support/en/articles/15192004\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAgent Pay Implementation: Developer Guide for AI Checkout\\u003c/a\\u003e\\n- \\u003ca href=\\\"https://eco.com/support/support/en/articles/15082537\\\"\\u003eUSDC vs USDT: Stablecoin Comparison\\u003c/a\\u003e\\n- \\u003ca href=\\\"https://eco.com/support/support/en/articles/14998923\\\"\\u003eCCTP: Cross-Chain USDC Transfers\\u003c/a\\u003e\\n- \\u003ca href=\\\"https://eco.com/support/support/en/articles/14009181\\\"\\u003eLI.FI's API for Agentic Commerce: How Cross-Chain AI Execution Works\\u003c/a\\u003e\",\"items\":[{\"content\":[{\"type\":\"paragraph\",\"text\":\"\\u003ca href=\\\"support/en/articles/15192001\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eWhat Is Mastercard Agent Pay? AI Agent Commerce Protocol 2026\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"\\u003ca href=\\\"support/en/articles/15192002\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAP2 Protocol Explained: Google's Agentic Commerce Standard\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"\\u003ca href=\\\"support/en/articles/15192003\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eMastercard Agent Pay vs Visa Trusted Agent 2026\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"\\u003ca href=\\\"support/en/articles/15192004\\\" rel=\\\"nofollow noopener noreferrer\\\" target=\\\"_blank\\\"\\u003eAgent Pay Implementation: Developer Guide for AI Checkout\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"\\u003ca href=\\\"https://eco.com/support/support/en/articles/15082537\\\"\\u003eUSDC vs USDT: Stablecoin Comparison\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"\\u003ca href=\\\"https://eco.com/support/support/en/articles/14998923\\\"\\u003eCCTP: Cross-Chain USDC Transfers\\u003c/a\\u003e\",\"class\":\"no-margin\"}]},{\"content\":[{\"type\":\"paragraph\",\"text\":\"\\u003ca href=\\\"https://eco.com/support/support/en/articles/14009181\\\"\\u003eLI.FI's API for Agentic Commerce: How Cross-Chain AI Execution Works\\u003c/a\\u003e\",\"class\":\"no-margin\"}]}]}],\"collectionId\":\"19622503\",\"description\":\"How Mastercard Agent Pay tokens, Visa Trusted Agent attestations, AP2 Verifiable Credentials, and W3C DIDs prove an AI agent is authorized to transact in 2026.\",\"id\":\"17958488\",\"lastUpdated\":\"Updated over 2 months ago\",\"lastUpdatedDate\":\"2026-07-16T22:11:11Z\",\"markdown\":null,\"relatedArticles\":[{\"title\":\"Know Your Agent (KYA): Identity for Agent Payments\",\"url\":\"https://eco.com/support/en/articles/14846277-know-your-agent-kya-identity-for-agent-payments\"},{\"title\":\"What Is Mastercard Agent Pay? AI Agent Commerce Protocol in 2026\",\"url\":\"https://eco.com/support/en/articles/15192001-what-is-mastercard-agent-pay-ai-agent-commerce-protocol-in-2026\"},{\"title\":\"AP2 Protocol Explained: Google's Agentic Commerce Standard 2026\",\"url\":\"https://eco.com/support/en/articles/15192002-ap2-protocol-explained-google-s-agentic-commerce-standard-2026\"},{\"title\":\"Mastercard Agent Pay vs Visa Trusted Agent 2026: Compared\",\"url\":\"https://eco.com/support/en/articles/15192003-mastercard-agent-pay-vs-visa-trusted-agent-2026-compared\"},{\"title\":\"Agent Pay Implementation: Developer Guide for AI Checkout in 2026\",\"url\":\"https://eco.com/support/en/articles/15192004-agent-pay-implementation-developer-guide-for-ai-checkout-in-2026\"}],\"targetUserType\":\"everyone\",\"title\":\"Agent Identity Verification: How AI Agents Authenticate Purchases in 2026\",\"showTableOfContents\":true,\"synced\":false,\"isStandaloneApp\":false},\"breadcrumbs\":[{\"url\":\"https://eco.com/support/en/collections/13190721-stablepedia\",\"name\":\"Stablepedia\"},{\"url\":\"https://eco.com/support/en/collections/19622503-ai-agents-agentic-commerce\",\"name\":\"AI Agents \\u0026 Agentic Commerce\"}],\"selectedReaction\":null,\"showReactions\":true,\"themeCSSCustomProperties\":{\"--body-bg\":\"rgb(255, 255, 255)\",\"--body-image\":\"none\",\"--body-bg-rgb\":\"255, 255, 255\",\"--body-border\":\"rgb(230, 230, 230)\",\"--body-primary-color\":\"#1a1a1a\",\"--body-secondary-color\":\"#595959\",\"--body-reaction-bg\":\"rgb(242, 242, 242)\",\"--body-reaction-text-color\":\"rgb(89, 89, 89)\",\"--body-toc-active-border\":\"#737373\",\"--body-toc-inactive-border\":\"#f2f2f2\",\"--body-toc-inactive-color\":\"#595959\",\"--body-toc-active-font-weight\":400,\"--body-table-border\":\"rgb(204, 204, 204)\",\"--body-color\":\"hsl(0, 0%, 0%)\",\"--footer-bg\":\"rgb(28, 83, 189)\",\"--footer-image\":\"none\",\"--footer-border\":\"rgb(44, 106, 224)\",\"--footer-color\":\"hsl(0, 0%, 100%)\",\"--header-bg\":\"rgb(28, 83, 189)\",\"--header-image\":\"none\",\"--header-color\":\"hsl(0, 0%, 100%)\",\"--collection-card-bg\":\"rgb(255, 255, 255)\",\"--collection-card-image\":\"none\",\"--collection-card-color\":\"hsl(220, 74%, 43%)\",\"--card-bg\":\"rgb(255, 255, 255)\",\"--card-border-color\":\"rgba(26, 26, 26, 0.15)\",\"--card-border-inner-radius\":\"6px\",\"--card-border-radius\":\"8px\",\"--card-shadow\":\"0 1px 2px 0 rgb(0 0 0 / 0.05)\",\"--search-bar-border-radius\":\"20px\",\"--search-bar-width\":\"100%\",\"--ticket-blue-bg-color\":\"#dce1f9\",\"--ticket-blue-text-color\":\"#334bfa\",\"--ticket-green-bg-color\":\"#d7efdc\",\"--ticket-green-text-color\":\"#0f7134\",\"--ticket-orange-bg-color\":\"#ffebdb\",\"--ticket-orange-text-color\":\"#b24d00\",\"--ticket-red-bg-color\":\"#ffdbdb\",\"--ticket-red-text-color\":\"#df2020\",\"--header-height\":\"245px\",\"--header-subheader-background-color\":\"#000000\",\"--header-subheader-font-color\":\"#FFFFFF\",\"--content-block-bg\":\"rgb(255, 255, 255)\",\"--content-block-image\":\"none\",\"--content-block-color\":\"hsl(0, 0%, 10%)\",\"--content-block-button-bg\":\"rgb(51, 75, 250)\",\"--content-block-button-image\":\"none\",\"--content-block-button-color\":\"hsl(0, 0%, 100%)\",\"--content-block-button-radius\":\"6px\",\"--content-block-margin\":\"0\",\"--content-block-width\":\"auto\",\"--primary-color\":\"hsl(220, 74%, 43%)\",\"--primary-color-alpha-10\":\"hsla(220, 74%, 43%, 0.1)\",\"--primary-color-alpha-60\":\"hsla(220, 74%, 43%, 0.6)\",\"--text-on-primary-color\":\"#ffffff\"},\"intl\":{\"defaultLocale\":\"en\",\"locale\":\"en\",\"messages\":{\"layout.skip_to_main_content\":\"Skip to main content\",\"article.attachment_icon\":\"Attachment icon\",\"article.related_articles\":\"Related Articles\",\"article.written_by\":\"Written by \\u003cb\\u003e{author}\\u003c/b\\u003e\",\"article.table_of_contents\":\"Table of contents\",\"breadcrumb.all_collections\":\"All Collections\",\"breadcrumb.aria_label\":\"Breadcrumb\",\"collection.article_count.one\":\"{count} article\",\"collection.article_count.other\":\"{count} articles\",\"collection.articles_heading\":\"Articles\",\"collection.sections_heading\":\"Collections\",\"collection.written_by.one\":\"Written by \\u003cb\\u003e{author}\\u003c/b\\u003e\",\"collection.written_by.two\":\"Written by \\u003cb\\u003e{author1}\\u003c/b\\u003e and \\u003cb\\u003e{author2}\\u003c/b\\u003e\",\"collection.written_by.three\":\"Written by \\u003cb\\u003e{author1}\\u003c/b\\u003e, \\u003cb\\u003e{author2}\\u003c/b\\u003e and \\u003cb\\u003e{author3}\\u003c/b\\u003e\",\"collection.written_by.four\":\"Written by \\u003cb\\u003e{author1}\\u003c/b\\u003e, \\u003cb\\u003e{author2}\\u003c/b\\u003e, \\u003cb\\u003e{author3}\\u003c/b\\u003e and 1 other\",\"collection.written_by.other\":\"Written by \\u003cb\\u003e{author1}\\u003c/b\\u003e, \\u003cb\\u003e{author2}\\u003c/b\\u003e, \\u003cb\\u003e{author3}\\u003c/b\\u003e and {count} others\",\"collection.by.one\":\"By {author}\",\"collection.by.two\":\"By {author1} and 1 other\",\"collection.by.other\":\"By {author1} and {count} others\",\"collection.by.count_one\":\"1 author\",\"collection.by.count_plural\":\"{count} authors\",\"community_banner.tip\":\"Tip\",\"community_banner.label\":\"\\u003cb\\u003eNeed more help?\\u003c/b\\u003e Get support from our {link}\",\"community_banner.link_label\":\"Community Forum\",\"community_banner.description\":\"Find answers and get help from Intercom Support and Community Experts\",\"header.headline\":\"Advice and answers from the {appName} Team\",\"header.menu.open\":\"Open menu\",\"header.menu.close\":\"Close menu\",\"locale_picker.aria_label\":\"Change language\",\"not_authorized.cta\":\"You can try sending us a message or logging in at {link}\",\"not_found.title\":\"Uh oh. That page doesn’t exist.\",\"not_found.not_authorized\":\"Unable to load this article, you may need to sign in first\",\"not_found.try_searching\":\"Try searching for your answer or just send us a message.\",\"tickets_portal_bad_request.title\":\"No access to tickets portal\",\"tickets_portal_bad_request.learn_more\":\"Learn more\",\"tickets_portal_bad_request.send_a_message\":\"Please contact your admin.\",\"no_articles.title\":\"Empty Help Center\",\"no_articles.no_articles\":\"This Help Center doesn't have any articles or collections yet.\",\"preview.invalid_preview\":\"There is no preview available for {previewType}\",\"reaction_picker.did_this_answer_your_question\":\"Did this answer your question?\",\"reaction_picker.reaction.disappointed.title\":\"Disappointed\",\"reaction_picker.reaction.disappointed.aria_label\":\"Disappointed Reaction\",\"reaction_picker.reaction.neutral.title\":\"Neutral\",\"reaction_picker.reaction.neutral.aria_label\":\"Neutral Reaction\",\"reaction_picker.reaction.smiley.title\":\"Smiley\",\"reaction_picker.reaction.smiley.aria_label\":\"Smiley Reaction\",\"search.box_placeholder_fin\":\"Ask a question\",\"search.box_placeholder\":\"Search for articles...\",\"search.clear_search\":\"Clear search query\",\"search.fin_card_ask_text\":\"Ask\",\"search.fin_loading_title_1\":\"Thinking...\",\"search.fin_loading_title_2\":\"Searching through sources...\",\"search.fin_loading_title_3\":\"Analyzing...\",\"search.fin_card_description\":\"Find the answer with Fin AI\",\"search.fin_empty_state\":\"Sorry, Fin AI wasn't able to answer your question. Try rephrasing it or asking something different\",\"search.no_results\":\"We couldn't find any articles for:\",\"search.number_of_results\":\"{count} search results found\",\"search.submit_btn\":\"Search for articles\",\"search.successful\":\"Search results for:\",\"footer.powered_by\":\"We run on Fin\",\"footer.privacy.choice\":\"Your Privacy Choices\",\"footer.report_content\":\"Report Content\",\"footer.social.facebook\":\"Facebook\",\"footer.social.linkedin\":\"LinkedIn\",\"footer.social.twitter\":\"Twitter\",\"page.title.home\":\"Home\",\"page.title.search\":\"Search results\",\"tickets.title\":\"Tickets\",\"tickets.view_type.tickets\":\"Tickets\",\"tickets.view_type.conversations\":\"Conversations\",\"tickets.view_type.all\":\"All\",\"tickets.company_selector_option\":\"{companyName}’s tickets\",\"tickets.company_selector.your_companies\":\"Your companies\",\"tickets.company_selector.shared_with_you\":\"Shared with you\",\"tickets.all_states\":\"All states\",\"tickets.filters.company_tickets\":\"All tickets\",\"tickets.filters.my_tickets\":\"Created by me\",\"tickets.filters.all\":\"All\",\"tickets.no_tickets_found\":\"No tickets found\",\"tickets.empty-state.generic.title\":\"No tickets found\",\"tickets.empty-state.generic.description\":\"Try using different keywords or filters.\",\"tickets.empty-state.empty-own-tickets.title\":\"No tickets created by you\",\"tickets.empty-state.empty-own-tickets.description\":\"Tickets submitted through the messenger or by a support agent in your conversation will appear here.\",\"tickets.empty-state.empty-q.description\":\"Try using different keywords or checking for typos.\",\"tickets.navigation.home\":\"Home\",\"tickets.navigation.tickets_portal\":\"Tickets portal\",\"tickets.navigation.customer_portal\":\"Customer Portal\",\"tickets.navigation.ticket_details\":\"Ticket #{ticketId}\",\"tickets.navigation.conversation_details\":\"Conversation\",\"tickets.navigation.new_conversation\":\"New conversation\",\"tickets.create_new.button\":\"Create new\",\"tickets.create_new.conversation\":\"Conversation\",\"tickets.create_new.ticket\":\"Ticket\",\"tickets.create.attribute.select_option\":\"Select an option\",\"tickets.create.attribute.error.required\":\"This field is required\",\"tickets.create.error.blocked\":\"We couldn’t confirm which company this ticket belongs to. Reload the page and try again.\",\"tickets.create.error.session\":\"Your session has expired. Reload the page and try again.\",\"tickets.create.error.failed\":\"Your ticket wasn’t created. Please try again.\",\"tickets.create.required_hint\":\"Fields marked with * are required.\",\"tickets.create.cancel\":\"Cancel\",\"tickets.create.attach_files\":\"Attach files\",\"tickets.create.upload_in_progress\":\"Uploading…\",\"tickets.create.upload_retry\":\"Retry\",\"tickets.create.upload_remove\":\"Remove\",\"tickets.create.upload_error.failed\":\"{name} couldn’t be uploaded\",\"tickets.create.upload_error.file_size\":\"{name} is too large to upload\",\"tickets.create.upload_error.file_type_not_allowed\":\"{name} isn’t a file type we can accept\",\"tickets.create.upload_error.file_max_limit\":\"{name} wasn’t attached — you’ve reached the file limit\",\"tickets.create.submit\":\"Create ticket\",\"tickets.navigation.tickets\":\"Tickets\",\"tickets.navigation.insights\":\"Insights\",\"tickets.insights.title\":\"Insights\",\"tickets.insights.subtitle\":\"Volume, creators and topics for your company.\",\"tickets.insights.date_range\":\"Created on\",\"tickets.insights.loading\":\"Loading insights…\",\"tickets.insights.error\":\"We couldn’t load insights. Please try again.\",\"tickets.insights.filters.company\":\"Company\",\"tickets.insights.filters.requester\":\"Created by\",\"tickets.insights.volume.total\":\"Total\",\"tickets.insights.volume.open\":\"Open\",\"tickets.insights.volume.closed\":\"Closed\",\"tickets.insights.volume.total_tooltip\":\"Total conversations and tickets\",\"tickets.insights.volume.open_tooltip\":\"Open conversations and tickets\",\"tickets.insights.volume.closed_tooltip\":\"Closed conversations and tickets, including resolved tickets\",\"tickets.insights.top_requesters.title\":\"Top creators\",\"tickets.insights.top_requesters.empty\":\"No creators in this period.\",\"tickets.insights.topics.title\":\"AI topics\",\"tickets.insights.topics.empty\":\"No topics in this period.\",\"tickets.insights.subtopics.empty\":\"No subtopics for this topic.\",\"tickets.insights.subtopics.loading\":\"Loading subtopics…\",\"tickets.insights.subtopics.more\":\"+{count} more\",\"tickets.insights.drilldown.empty\":\"No tickets for this selection.\",\"tickets.insights.drilldown.load_more\":\"Load more\",\"tickets.insights.drilldown.button_label\":\"View tickets in {label}\",\"tickets.insights.drilldown.column.id\":\"ID\",\"tickets.insights.drilldown.column.title\":\"Title\",\"tickets.insights.drilldown.column.state\":\"State\",\"tickets.insights.drilldown.column.created_by\":\"Created by\",\"tickets.insights.sidebar.title\":\"Conversations and tickets in {topic}\",\"tickets.insights.sidebar.title_with_subtopic\":\"Conversations and tickets in {topic} // {subtopic}\",\"tickets.insights.sidebar.close\":\"Close\",\"tickets.insights.sidebar.search\":\"Search subtopics…\",\"tickets.view_conversation\":\"View conversation\",\"tickets.view_ticket_details\":\"View ticket details\",\"tickets.send_message\":\"Send us a message\",\"tickets.continue_conversation\":\"Continue the conversation\",\"tickets.full_page_messenger.fallback\":\"If your conversation doesn’t load, \\u003clink\\u003ego back to all tickets\\u003c/link\\u003e.\",\"tickets.full_page_messenger.loading\":\"Loading…\",\"tickets.avatar_image.image_alt\":\"{firstName}’s avatar\",\"tickets.fields.id\":\"Ticket ID\",\"tickets.fields.type\":\"Ticket type\",\"tickets.fields.title\":\"Title\",\"tickets.fields.ai_title\":\"AI title\",\"tickets.fields.description\":\"Description\",\"tickets.fields.created_by\":\"Created by\",\"tickets.fields.email_for_notification\":\"You will be notified here and by email\",\"tickets.fields.created_at\":\"Created on\",\"tickets.fields.sorting_updated_at\":\"Updated on\",\"tickets.fields.state\":\"Ticket state\",\"tickets.fields.assignee\":\"Assignee\",\"tickets.fields.preview\":\"Preview\",\"tickets.columns.add_column\":\"Add column\",\"tickets.columns.all_visible\":\"All columns are visible\",\"tickets.columns.column_options\":\"{column} column options\",\"tickets.columns.hide_column\":\"Hide column\",\"tickets.preview.unknown_teammate\":\"Unknown Teammate\",\"tickets.preview.ticket\":\"Ticket\",\"tickets.preview.more_matches\":\"+{count} more\",\"tickets.link-block.title\":\"Tickets portal.\",\"tickets.link-block.description\":\"Track the progress of all tickets related to your company.\",\"tickets.link-block.customer_portal_title\":\"Customer Portal.\",\"tickets.link-block.customer_portal_description\":\"Track the progress of all tickets and conversations related to your company.\",\"tickets.states.submitted\":\"Submitted\",\"tickets.states.in_progress\":\"In progress\",\"tickets.states.waiting_on_customer\":\"Waiting on you\",\"tickets.states.resolved\":\"Resolved\",\"tickets.states.description.unassigned.submitted\":\"We will pick this up soon\",\"tickets.states.description.assigned.submitted\":\"{assigneeName} will pick this up soon\",\"tickets.states.description.unassigned.in_progress\":\"We are working on this!\",\"tickets.states.description.assigned.in_progress\":\"{assigneeName} is working on this!\",\"tickets.states.description.unassigned.waiting_on_customer\":\"We need more information from you\",\"tickets.states.description.assigned.waiting_on_customer\":\"{assigneeName} needs more information from you\",\"tickets.states.description.unassigned.resolved\":\"We have completed your ticket\",\"tickets.states.description.assigned.resolved\":\"{assigneeName} has completed your ticket\",\"tickets.attributes.boolean.true\":\"Yes\",\"tickets.attributes.boolean.false\":\"No\",\"tickets.filter_any\":\"\\u003cb\\u003e{name}\\u003c/b\\u003e is any\",\"tickets.filter_single\":\"\\u003cb\\u003e{name}\\u003c/b\\u003e is {value}\",\"tickets.filter_multiple\":\"\\u003cb\\u003e{name}\\u003c/b\\u003e is one of {count}\",\"tickets.no_options_found\":\"No options found\",\"tickets.filters.any_option\":\"Any\",\"tickets.filters.state\":\"State\",\"tickets.filters.type\":\"Type\",\"tickets.filters.created_by\":\"Created by\",\"tickets.filters.assigned_to\":\"Assigned to\",\"tickets.filters.created_on\":\"Created on\",\"tickets.filters.updated_on\":\"Updated on\",\"tickets.filters.date_range.today\":\"Today\",\"tickets.filters.date_range.yesterday\":\"Yesterday\",\"tickets.filters.date_range.last_week\":\"Last week\",\"tickets.filters.date_range.last_30_days\":\"Last 30 days\",\"tickets.filters.date_range.last_90_days\":\"Last 90 days\",\"tickets.filters.date_range.custom\":\"Custom\",\"tickets.filters.date_range.apply_custom_range\":\"Apply\",\"tickets.filters.date_range.custom_range.start_date\":\"From\",\"tickets.filters.date_range.custom_range.end_date\":\"To\",\"tickets.filters.clear_filters\":\"Clear filters\",\"tickets.filters.add_filter\":\"Add filter\",\"tickets.filters.search_placeholder\":\"Search...\",\"conversations.fields.id\":\"Conversation ID\",\"conversations.fields.title\":\"Title\",\"conversations.fields.ai_title\":\"AI title\",\"conversations.fields.created_by\":\"Created by\",\"conversations.fields.created_at\":\"Created on\",\"conversations.fields.sorting_updated_at\":\"Last Updated\",\"conversations.fields.state\":\"State\",\"conversations.fields.assignee\":\"Assignee\",\"conversations.fields.preview\":\"Preview\",\"conversations.states.open\":\"Open\",\"conversations.states.closed\":\"Closed\",\"conversations.empty-state.generic.title\":\"No conversations found\",\"conversations.empty-state.generic.description\":\"Try using different keywords or filters.\",\"conversations.empty-state.empty-own-conversations.title\":\"No conversations created by you\",\"conversations.empty-state.empty-own-conversations.description\":\"Conversations you've started through the messenger will appear here.\",\"conversations.empty-state.empty-q.description\":\"Try using different keywords or checking for typos.\",\"all.empty-state.generic.title\":\"No tickets or conversations found\",\"all.empty-state.generic.description\":\"Try using different keywords or filters.\",\"all.empty-state.empty-own-all.title\":\"No tickets or conversations created by you\",\"all.empty-state.empty-own-all.description\":\"Tickets and conversations you've started through the messenger will appear here.\",\"all.empty-state.empty-q.description\":\"Try using different keywords or checking for typos.\",\"all.empty-state.empty-combined_state.title\":\"No tickets or conversations found\",\"all.empty-state.empty-combined_state.description\":\"Try selecting a different state.\",\"all.empty-state.empty-created_on.title\":\"No tickets or conversations found\",\"all.empty-state.empty-created_on.description\":\"Try selecting a different creation date range.\",\"all.empty-state.empty-updated_on.title\":\"No tickets or conversations found\",\"all.empty-state.empty-updated_on.description\":\"Try selecting a different update date range.\",\"all.empty-state.empty-creator_id.title\":\"No tickets or conversations found\",\"all.empty-state.empty-creator_id.description\":\"Try selecting a different creator.\",\"all.fields.id\":\"ID\",\"cookie_banner.default_text\":\"This site uses cookies and similar technologies (\\\"cookies\\\") as strictly necessary for site operation. We and our partners also would like to set additional cookies to enable site performance analytics, functionality, advertising and social media features. See our {cookiePolicyLink} for details. You can change your cookie preferences in our Cookie Settings.\",\"cookie_banner.gdpr_text\":\"This site uses cookies and similar technologies (\\\"cookies\\\") as strictly necessary for site operation. We and our partners also would like to set additional cookies to enable site performance analytics, functionality, advertising and social media features. See our {cookiePolicyLink} for details. You can change your cookie preferences in our Cookie Settings.\",\"cookie_banner.ccpa_text\":\"This site employs cookies and other technologies that we and our third party vendors use to monitor and record personal information about you and your interactions with the site (including content viewed, cursor movements, screen recordings, and chat contents) for the purposes described in our Cookie Policy. By continuing to visit our site, you agree to our {websiteTermsLink}, {privacyPolicyLink} and {cookiePolicyLink}.\",\"cookie_banner.simple_text\":\"We use cookies to make our site work and also for analytics and advertising purposes. You can enable or disable optional cookies as desired. See our {cookiePolicyLink} for more details.\",\"cookie_banner.cookie_policy\":\"Cookie Policy\",\"cookie_banner.website_terms\":\"Website Terms of Use\",\"cookie_banner.privacy_policy\":\"Privacy Policy\",\"cookie_banner.accept_all\":\"Accept All\",\"cookie_banner.accept\":\"Accept\",\"cookie_banner.reject_all\":\"Reject All\",\"cookie_banner.manage_cookies\":\"Manage Cookies\",\"cookie_banner.close\":\"Close banner\",\"cookie_settings.close\":\"Close\",\"cookie_settings.title\":\"Cookie Settings\",\"cookie_settings.description\":\"We use cookies to enhance your experience. You can customize your cookie preferences below. See our {cookiePolicyLink} for more details.\",\"cookie_settings.ccpa_title\":\"Your Privacy Choices\",\"cookie_settings.ccpa_description\":\"You have the right to opt out of the sale of your personal information. See our {cookiePolicyLink} for more details about how we use your data.\",\"cookie_settings.save_preferences\":\"Save Preferences\",\"cookie_categories.necessary.name\":\"Strictly Necessary Cookies\",\"cookie_categories.necessary.description\":\"These cookies are necessary for the website to function and cannot be switched off in our systems.\",\"cookie_categories.functional.name\":\"Functional Cookies\",\"cookie_categories.functional.description\":\"These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.\",\"cookie_categories.performance.name\":\"Performance Cookies\",\"cookie_categories.performance.description\":\"These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site.\",\"cookie_categories.advertisement.name\":\"Advertising and Social Media Cookies\",\"cookie_categories.advertisement.description\":\"Advertising cookies are set by our advertising partners to collect information about your use of the site, our communications, and other online services over time and with different browsers and devices. They use this information to show you ads online that they think will interest you and measure the ads' performance. Social media cookies are set by social media platforms to enable you to share content on those platforms, and are capable of tracking information about your activity across other online services for use as described in their privacy policies.\",\"cookie_consent.site_access_blocked\":\"Site access blocked until cookie consent\",\"v2.common.article_count\":\"{count, plural, one {# article} other {# articles}}\",\"v2.common.article_navigation\":\"Article navigation\",\"v2.common.breadcrumb\":\"Breadcrumb\",\"v2.common.docs_navigation\":\"Docs navigation\",\"v2.common.collapse\":\"Collapse {title}\",\"v2.common.expand\":\"Expand {title}\",\"v2.docs.article.related_articles\":\"Related articles\",\"v2.docs.article.related_articles_aria_label\":\"Related articles\",\"v2.docs.article.next\":\"Next\",\"v2.docs.article.previous\":\"Previous\",\"v2.docs.home.headline\":\"{appName} Help Center\",\"v2.docs.home.subheadline\":\"Search for answers or browse popular topics.\",\"v2.docs.home.view_collection\":\"View collection\",\"v2.docs.search.results\":\"{count, plural, one {# result} other {# results}} for {term}\",\"v2.docs.search.no_results\":\"No results for {term}\",\"v2.docs.toc.label\":\"On this page\",\"v2.docs.top_bar.brand_home\":\"{siteName} home\",\"v2.docs.top_bar.default_site_name\":\"Help Center\",\"v2.docs.top_bar.help_center_links\":\"Help center links\",\"v2.docs.top_bar.open_navigation\":\"Open docs navigation\",\"v2.docs.top_bar.close_navigation\":\"Close docs navigation\",\"v2.docs.top_bar.mobile_navigation\":\"Mobile docs navigation\",\"v2.docs.top_bar.search\":\"Search\",\"v2.docs.top_bar.search_aria_label\":\"Search docs ({shortcut})\",\"v2.presentation.selector_aria_label\":\"V2 prototype presentation selector\",\"v2.presentation.selector_label\":\"V2 prototype\",\"v2.presentation.selector_group_aria_label\":\"Visual presentation\",\"v2.presentation.option.docs\":\"Docs\",\"v2.presentation.option.minimal\":\"Minimal\",\"v2.presentation.option.ai_resident\":\"AI resident\",\"v2.presentation.option.editorial\":\"Editorial\",\"v2.presentation.option.conversational\":\"Conversational\",\"v2.action_bar.toolbar_aria_label\":\"Article actions\",\"v2.action_bar.copy_for_llm\":\"Copy for LLM\",\"v2.action_bar.copied\":\"Copied\",\"v2.action_bar.copying\":\"Copying…\",\"v2.action_bar.copy_failed\":\"Copy failed\",\"v2.action_bar.loading\":\"Loading…\",\"v2.action_bar.view_as_markdown\":\"View as markdown\",\"v2.action_bar.view_raw\":\"View raw\",\"v2.action_bar.send_to_ai\":\"Send to AI\",\"v2.action_bar.send_to_ai_aria_label\":\"Send this article to an AI assistant\",\"v2.action_bar.more_actions_aria_label\":\"More article actions\",\"v2.action_bar.open_in_claude\":\"Open in Claude\",\"v2.action_bar.open_in_claude_app\":\"Open in Claude app\",\"v2.action_bar.open_in_chatgpt\":\"Open in ChatGPT\",\"v2.action_bar.external_ai_prompt\":\"Read {markdownUrl} and help me with questions about it.\",\"v2.code_block.copy\":\"Copy\",\"v2.code_block.copied\":\"Copied\",\"v2.code_block.copy_failed\":\"Copy failed\",\"v2.code_block.copy_aria_label\":\"Copy code to clipboard\",\"v2.markdown_modal.article_source\":\"Article source\",\"v2.markdown_modal.close\":\"Close\",\"v2.markdown_modal.copy\":\"Copy markdown\",\"v2.fin.ask\":\"Ask\",\"v2.fin.name\":\"Fin\",\"v2.fin.ask_fin\":\"Ask Fin\",\"v2.fin.ask_question\":\"Ask Fin a question\",\"v2.fin.ask_about_page\":\"Ask Fin about this page\",\"v2.fin.close\":\"Close\",\"v2.fin.send_question\":\"Send question\",\"v2.fin.thinking\":\"Fin is thinking\",\"v2.fin.sources\":\"Sources\",\"v2.fin.prototype.disclosure\":\"Prototype demo: answers are scripted and do not come from a production Fin API.\",\"v2.fin.suggestion.get_started\":\"How do I get started?\",\"v2.fin.suggestion.invite_team\":\"How do I invite my team?\",\"v2.fin.suggestion.configure_integrations\":\"How do I configure integrations?\",\"v2.fin.suggestion.read_invoice\":\"How do I read my invoice?\",\"v2.fin.resident.companion_aria_label\":\"Fin reading companion\",\"v2.fin.resident.name_with_app\":\"{appName} · Fin\",\"v2.fin.resident.status\":\"Online · Reading: {title}\",\"v2.fin.resident.intro_title\":\"Reading along with you\",\"v2.fin.resident.intro_body\":\"I’ve got this page open. Ask me anything about it and I’ll answer from the docs.\",\"v2.fin.resident.try_asking\":\"Try asking\",\"v2.fin.prototype.unavailable.body\":\"This prototype demo does not have a scripted answer for that question yet. Try asking how to invite your team or open a source article. No production Fin API was called.\",\"v2.fin.prototype.unavailable.title\":\"Prototype answer unavailable\",\"v2.fin.prototype.follow_up.body\":\"Because you already asked about invitations, this prototype demo can add the follow-up: use the role selector before sending each invite to limit access to the teammate responsibilities.\",\"v2.fin.prototype.follow_up.title\":\"Prototype role-limiting follow-up\",\"v2.fin.prototype.invite.body\":\"In this prototype demo, invite teammates from workspace settings, then choose the access each teammate needs before sending the invitation.\",\"v2.fin.prototype.invite.title\":\"Prototype invite-team answer\",\"v2.fin.prototype.get_started.body\":\"This prototype demo suggests starting with your workspace profile, inviting the team members who need access, and then connecting the integrations you use.\",\"v2.fin.prototype.get_started.title\":\"Prototype getting-started answer\",\"v2.fin.prototype.integrations.body\":\"In this prototype demo, integrations are configured from workspace settings. Choose the integration, connect the account, and review the enabled permissions.\",\"v2.fin.prototype.integrations.title\":\"Prototype integrations answer\",\"v2.fin.prototype.article.body\":\"This prototype demo is aware that you are reading “{title}”. It can point you back to the current article, but a production article-aware Fin contract is still follow-up work.\",\"v2.fin.prototype.article.title\":\"Prototype article-aware answer\",\"v2.fin.prototype.source.invite\":\"Invite teammates and choose their access\",\"v2.fin.prototype.source.get_started\":\"Getting started guide\",\"v2.fin.prototype.source.integrations\":\"Configure integrations\",\"v2.command_palette.title\":\"Search\",\"v2.command_palette.empty\":\"Start typing to search for articles.\",\"v2.command_palette.searching\":\"Searching…\",\"v2.command_palette.no_results\":\"No results.\",\"v2.command_palette.navigate\":\"navigate\",\"v2.command_palette.select\":\"select\",\"v2.command_palette.close\":\"close\",\"v2.command_palette.filter_all\":\"All\",\"v2.command_palette.filter_label\":\"Filter by collection\",\"v2.command_palette.filter_more\":\"More\",\"v2.command_palette.no_results_in_collection\":\"No results in this collection.\",\"v2.editorial.featured\":\"Featured\",\"v2.editorial.this_week\":\"This week\",\"v2.editorial.welcome\":\"Welcome to {appName}\",\"v2.editorial.read_feature\":\"Read the feature\",\"v2.editorial.take_tour\":\"Take the tour\",\"v2.editorial.tour_title\":\"{appName} in 60 seconds\",\"v2.editorial.tour_body\":\"A quick lap of the product so you know where everything lives.\",\"v2.editorial.ask_fin\":\"Ask Fin anything\",\"v2.editorial.ask_fin_body\":\"Skip the search. Describe what you’re trying to do and get a grounded answer.\",\"v2.editorial.start_conversation\":\"Start a conversation\",\"v2.editorial.featured_collection\":\"Featured collection\",\"v2.editorial.collection_body\":\"Browse articles and guides in this topic.\",\"v2.editorial.browse_collection\":\"Browse collection\",\"v2.editorial.trending\":\"Trending\",\"v2.editorial.most_read\":\"Most read this week\",\"v2.editorial.get_started\":\"Get started in three steps\",\"v2.editorial.browse_topics\":\"Browse all topics\",\"v2.editorial.step.account.title\":\"Set up your account\",\"v2.editorial.step.account.body\":\"Create your workspace and invite the people you work with.\",\"v2.editorial.step.stack.title\":\"Connect your stack\",\"v2.editorial.step.stack.body\":\"Connect the tools your team already uses to bring data in.\",\"v2.editorial.step.ship.title\":\"Ship something\",\"v2.editorial.step.ship.body\":\"Build your first workflow and watch it run end to end.\",\"v2.conversational.headline\":\"What can I help you with?\",\"v2.conversational.subhead\":\"Ask Fin anything about {appName} — answers come straight from the docs.\",\"v2.conversational.placeholder\":\"Ask a question…\",\"v2.conversational.add_screenshot\":\"Add a screenshot\",\"v2.conversational.attach_file\":\"Attach a file\",\"v2.conversational.prefer_browse\":\"Prefer to browse?\"}},\"collectionCardCustomProperties\":{}},\"__N_SSP\":true},\"page\":\"/[helpCenterIdentifier]/[locale]/articles/[articleSlug]\",\"query\":{\"helpCenterIdentifier\":\"ecoprotocol\",\"locale\":\"en\",\"articleSlug\":\"15192005-agent-identity-verification-how-ai-agents-authenticate-purchases-in-2026\"},\"buildId\":\"E1BXax2uUHtwGP6Qn16b6\",\"assetPrefix\":\"https://static.intercomassets.com\",\"isFallback\":false,\"isExperimentalCompile\":false,\"dynamicIds\":[91353],\"gssp\":true,\"scriptLoader\":[]}</script></body></html>","snapshot_chars":122808,"live_check":"matches"}]}