{"slug":"ietf-opens-the-door-to-standardizing-agent-to-agent-communication","citations":[{"url":"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto","committed_hash":"sha256:13474fa9cefa73091f0074d443ff54b62054c17b8b0d378f2d625bcc226294cb","committed_hash_short":"sha256:13474fa9…226294cb","mime_type":"text/html","committed_at":"2026-07-26T10:00:28.632871+00:00","content_snapshot":"<!DOCTYPE html><html lang=\"en\" dir=\"ltr\" class=\"__variable_bbcc58 __variable_948ce5 __variable_9ded40 __variable_3f4575 __variable_16cd69\"><head><meta charSet=\"utf-8\"/><meta name=\"viewport\" content=\"width=device-width, initial-scale=1, viewport-fit=cover\"/><link rel=\"preload\" as=\"image\" href=\"https://www.facebook.com/tr?id=1937494190493436&amp;ev=PageView&amp;noscript=1\"/><link rel=\"stylesheet\" href=\"/_next/static/css/a78fa145c089ec40.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/css/838b9eb00883d6da.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/css/d7a984aa9a9fcc2c.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" data-precedence=\"next\"/><link rel=\"preload\" as=\"script\" fetchPriority=\"low\" href=\"/_next/static/chunks/webpack-7162da525ac05067.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\"/><script src=\"/_next/static/chunks/fd9d1056-3473d42f2c06b95a.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/2117-37ca1fb636a38c95.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/main-app-be3d940aef6bd3eb.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/5878-43bbacc376acddee.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/2957-135fdf77983e5820.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/7363-1b3fd7d0da0ebc28.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/4182-e96c5784a81e1858.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/8041-f3df4595b34e4e85.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/482-e3c47234496c384c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/app/%5Blang%5D/%5Bslug%5D/page-e0c122d0071f8e69.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/app/layout-4e6ae73d356025e1.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script src=\"/_next/static/chunks/app/not-found-a3276cd1dbc10332.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script><script async=\"\" src=\"https://www.googletagmanager.com/gtag/js?id=G-7LWRNQMJYQ\"></script><title>IETF Weighs an AI Agent Protocol Standard in 2026 | Nerd Level Tech</title><meta name=\"description\" content=\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\"/><link rel=\"canonical\" href=\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"/><link rel=\"alternate\" hrefLang=\"en-US\" href=\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"/><link rel=\"alternate\" hrefLang=\"ar-EG\" href=\"https://nerdleveltech.com/ar/ietf-ai-agent-protocol-standard-agentproto\"/><meta property=\"og:title\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><meta property=\"og:description\" content=\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\"/><meta property=\"og:url\" content=\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"/><meta property=\"og:image\" content=\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\"/><meta property=\"og:image:width\" content=\"1200\"/><meta property=\"og:image:height\" content=\"630\"/><meta property=\"og:image:alt\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><meta property=\"og:type\" content=\"article\"/><meta property=\"article:published_time\" content=\"2026-07-24T00:00:00.000Z\"/><meta name=\"twitter:card\" content=\"summary_large_image\"/><meta name=\"twitter:title\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><meta name=\"twitter:description\" content=\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\"/><meta name=\"twitter:image\" content=\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\"/><meta name=\"twitter:image:width\" content=\"1200\"/><meta name=\"twitter:image:height\" content=\"630\"/><meta name=\"twitter:image:alt\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><link rel=\"icon\" href=\"/favicon.svg\" type=\"image/svg+xml\"/><link rel=\"icon\" href=\"/icon.svg\" type=\"image/svg+xml\"/><meta name=\"next-size-adjust\"/><meta name=\"msvalidate.01\" content=\"63B94FDFC56A65B5E9E316E474AB9D0D\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Articles\" href=\"/rss.xml\"/><link rel=\"alternate\" type=\"application/atom+xml\" title=\"NerdLevelTech — Articles\" href=\"/atom.xml\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Podcast\" href=\"/podcast.xml\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Courses\" href=\"/courses-rss.xml\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Remote Tech Jobs\" href=\"/jobs-rss.xml\"/><script>(() => {\n var t = localStorage.getItem('theme');\n var d = document.documentElement;\n if (t === 'dark' || (!t || t === 'system') && window.matchMedia('(prefers-color-scheme: dark)').matches) {\n d.classList.add('dark');\n } else {\n d.classList.remove('dark');\n }\n try {\n var consent = localStorage.getItem('nlt-cookie-consent');\n if (consent) d.setAttribute('data-nlt-consent', consent);\n } catch (e) {}\n})();</script><script>(function(){\n  window.clarity = window.clarity || function(){ (window.clarity.q = window.clarity.q || []).push(arguments); };\n  var loaded = false;\n  function loadClarity() {\n    if (loaded) return;\n    loaded = true;\n    var s = document.createElement('script');\n    s.async = true;\n    s.src = 'https://www.clarity.ms/tag/uiskr3p74z';\n    document.head.appendChild(s);\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\n      document.removeEventListener(e, loadClarity);\n    });\n  }\n  if (document.readyState === 'complete') {\n    setTimeout(loadClarity, 3000);\n  } else {\n    window.addEventListener('load', function() { setTimeout(loadClarity, 3000); });\n  }\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\n    document.addEventListener(e, loadClarity, { once: true, passive: true });\n  });\n})();</script><script>\n window.dataLayer = window.dataLayer || [];\n function gtag(){dataLayer.push(arguments);}\n\n // Default consent to 'denied' for GDPR compliance (EU/EEA users)\n gtag('consent', 'default', {\n 'ad_storage': 'denied',\n 'ad_user_data': 'denied',\n 'ad_personalization': 'denied',\n 'analytics_storage': 'denied'\n });\n\n gtag('js', new Date());\n // Skip the initial config + pageview for admin routes. SPA navigations\n // away from /admin still work — AnalyticsListeners fires page_view on\n // route change for any non-admin path it sees next.\n if (!/^\\/admin(\\/|$)/.test(window.location.pathname)) {\n gtag('config', 'G-7LWRNQMJYQ');\n }\n\n // Check if user already consented and update consent accordingly\n try {\n var consent = localStorage.getItem('nlt-cookie-consent');\n if (consent === 'accepted') {\n gtag('consent', 'update', {\n 'ad_storage': 'granted',\n 'ad_user_data': 'granted',\n 'ad_personalization': 'granted',\n 'analytics_storage': 'granted'\n });\n }\n } catch(e) {}\n</script><script>(function(){\n var loaded = false;\n function loadBrevo() {\n if (loaded) return;\n loaded = true;\n var s = document.createElement('script');\n s.src = 'https://cdn.brevo.com/js/sdk-loader.js';\n s.async = true;\n s.onload = function() {\n window.Brevo = window.Brevo || [];\n Brevo.push([\"init\", { client_key:\"07ps0c5debu6rk7jhbq1fkyj\" }]);\n };\n document.head.appendChild(s);\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\n document.removeEventListener(e, loadBrevo);\n });\n }\n if (document.readyState === 'complete') {\n setTimeout(loadBrevo, 3000);\n } else {\n window.addEventListener('load', function() { setTimeout(loadBrevo, 3000); });\n }\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\n document.addEventListener(e, loadBrevo, { once: true, passive: true });\n });\n})();</script><script>(function(){\n  if (window.fbq) return;\n  var n = window.fbq = function(){ n.callMethod ? n.callMethod.apply(n, arguments) : n.queue.push(arguments); };\n  if (!window._fbq) window._fbq = n;\n  n.push = n; n.loaded = true; n.version = '2.0'; n.queue = [];\n  fbq('init', '1937494190493436');\n  fbq('track', 'PageView');\n  var loaded = false;\n  function loadPixel() {\n    if (loaded) return;\n    loaded = true;\n    var s = document.createElement('script');\n    s.async = true;\n    s.src = 'https://connect.facebook.net/en_US/fbevents.js';\n    document.head.appendChild(s);\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\n      document.removeEventListener(e, loadPixel);\n    });\n  }\n  if (document.readyState === 'complete') {\n    setTimeout(loadPixel, 3000);\n  } else {\n    window.addEventListener('load', function() { setTimeout(loadPixel, 3000); });\n  }\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\n    document.addEventListener(e, loadPixel, { once: true, passive: true });\n  });\n})();</script><noscript><img height=\"1\" width=\"1\" style=\"display:none\" src=\"https://www.facebook.com/tr?id=1937494190493436&amp;ev=PageView&amp;noscript=1\" alt=\"\"/></noscript><script src=\"/_next/static/chunks/polyfills-42372ed130431b0a.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" noModule=\"\"></script><style id=\"__jsx-69e97639d407de6e\">.nlt-nav-link{padding:8px 14px;-webkit-border-radius:999px;-moz-border-radius:999px;border-radius:999px;font-size:16px;color:var(--txt-1);font-weight:500;text-decoration:none;-webkit-transition:color.2s ease,background.2s ease;-moz-transition:color.2s ease,background.2s ease;-o-transition:color.2s ease,background.2s ease;transition:color.2s ease,background.2s ease}.nlt-nav-link:hover{color:var(--txt-0);background:rgba(10,14,22,.04)}.dark .nlt-nav-link:hover{background:rgba(255,255,255,.04)}.nlt-icon-btn{width:38px;height:38px;-webkit-border-radius:12px;-moz-border-radius:12px;border-radius:12px;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-webkit-justify-content:center;-moz-box-pack:center;-ms-flex-pack:center;justify-content:center;background:transparent;border:1px solid var(--line);color:var(--txt-1);-webkit-transition:all.2s ease;-moz-transition:all.2s ease;-o-transition:all.2s ease;transition:all.2s ease;text-decoration:none;cursor:pointer}.nlt-icon-btn:hover{color:var(--brand-300);border-color:var(--line-strong)}.nlt-avatar-btn{width:34px;height:34px;-webkit-border-radius:999px;-moz-border-radius:999px;border-radius:999px;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-webkit-justify-content:center;-moz-box-pack:center;-ms-flex-pack:center;justify-content:center;background:-webkit-linear-gradient(315deg,var(--brand-500),var(--brand-700));background:-moz-linear-gradient(315deg,var(--brand-500),var(--brand-700));background:-o-linear-gradient(315deg,var(--brand-500),var(--brand-700));background:linear-gradient(135deg,var(--brand-500),var(--brand-700));color:#001520;font-weight:700;font-size:13px;border:1px solid rgba(56,182,240,.4);cursor:pointer}.nlt-avatar-btn:hover{-webkit-box-shadow:0 0 0 4px rgba(56,182,240,.12);-moz-box-shadow:0 0 0 4px rgba(56,182,240,.12);box-shadow:0 0 0 4px rgba(56,182,240,.12)}.nlt-user-wrap{position:relative;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;gap:8px}.nlt-user-menu{position:absolute;top:46px;inset-inline-end:0;min-width:220px;padding:8px;background:var(--ink-2);border:1px solid var(--line-strong);-webkit-border-radius:14px;-moz-border-radius:14px;border-radius:14px;-webkit-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);-moz-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);box-shadow:0 30px 60px -20px rgba(0,0,0,.5);z-index:60}.nlt-user-menu-head{padding:8px 10px 10px;border-bottom:1px solid var(--line);margin-bottom:4px}.nlt-user-menu-item{display:block;width:100%;padding:8px 10px;-webkit-border-radius:8px;-moz-border-radius:8px;border-radius:8px;font-size:13px;color:var(--txt-1);background:transparent;border:0;font-family:inherit;text-align:start;cursor:pointer;text-decoration:none}.nlt-user-menu-item:hover{color:var(--txt-0);background:rgba(10,14,22,.04)}.dark .nlt-user-menu-item:hover{background:rgba(255,255,255,.04)}.nlt-user-menu-danger{color:#f87171}.nlt-user-menu-danger:hover{color:#fca5a5!important}.nlt-mobile-only.jsx-69e97639d407de6e{position:relative;display:none}.nlt-mobile-drawer{position:absolute;top:46px;inset-inline-end:0;min-width:240px;padding:8px;background:var(--ink-2);border:1px solid var(--line-strong);-webkit-border-radius:14px;-moz-border-radius:14px;border-radius:14px;-webkit-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);-moz-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);box-shadow:0 30px 60px -20px rgba(0,0,0,.5);z-index:60}.nlt-mobile-nav{display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-webkit-flex-direction:column;-moz-box-orient:vertical;-moz-box-direction:normal;-ms-flex-direction:column;flex-direction:column;gap:2px}.nlt-mobile-link{padding:10px 12px;-webkit-border-radius:10px;-moz-border-radius:10px;border-radius:10px;font-size:14px;color:var(--txt-1);background:transparent;border:0;font-family:inherit;text-align:start;cursor:pointer;text-decoration:none}.nlt-mobile-link:hover{color:var(--txt-0);background:rgba(10,14,22,.04)}.dark .nlt-mobile-link:hover{background:rgba(255,255,255,.04)}@media(max-width:980px){.nlt-nav-desk{display:none!important}.nlt-mobile-only.jsx-69e97639d407de6e{display:block}.nlt-signin-btn{display:none}}@media(max-width:540px){.nlt-topbar-root .nlt-btn-primary{padding:8px 12px!important;font-size:12.5px!important}}</style><style id=\"__jsx-6d81f11809c7f54d\">.nlt-foot.jsx-6d81f11809c7f54d{padding:64px 0 36px;border-top:1px solid var(--line);margin-top:40px}.nlt-foot-top.jsx-6d81f11809c7f54d{display:grid;grid-template-columns:1.6fr repeat(5,1fr);gap:32px;padding-bottom:56px}@media(max-width:1080px){.nlt-foot-top.jsx-6d81f11809c7f54d{grid-template-columns:1fr 1fr 1fr}}@media(max-width:600px){.nlt-foot-top.jsx-6d81f11809c7f54d{grid-template-columns:1fr 1fr}}.nlt-foot-col ul{list-style:none;padding:0;margin:14px 0 0;display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-webkit-flex-direction:column;-moz-box-orient:vertical;-moz-box-direction:normal;-ms-flex-direction:column;flex-direction:column;gap:10px}.nlt-foot-col a{color:var(--txt-1);font-size:13.5px;-webkit-transition:color.15s ease;-moz-transition:color.15s ease;-o-transition:color.15s ease;transition:color.15s ease;text-decoration:none}.nlt-foot-col a:hover{color:var(--brand-300)}.nlt-foot-bot.jsx-6d81f11809c7f54d{display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:justify;-webkit-justify-content:space-between;-moz-box-pack:justify;-ms-flex-pack:justify;justify-content:space-between;gap:24px;padding-top:22px;border-top:1px solid var(--line);-webkit-flex-wrap:wrap;-ms-flex-wrap:wrap;flex-wrap:wrap}.nlt-foot-socials.jsx-6d81f11809c7f54d{display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;gap:8px}.nlt-social{width:34px;height:34px;-webkit-border-radius:10px;-moz-border-radius:10px;border-radius:10px;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-webkit-justify-content:center;-moz-box-pack:center;-ms-flex-pack:center;justify-content:center;background:var(--ink-2);border:1px solid var(--line);color:var(--txt-1);font-size:13px;font-weight:600;-webkit-transition:all.2s ease;-moz-transition:all.2s ease;-o-transition:all.2s ease;transition:all.2s ease;text-decoration:none}.nlt-social:hover{color:var(--brand-300);border-color:var(--brand-500)}.nlt-lang{padding:5px 10px;-webkit-border-radius:8px;-moz-border-radius:8px;border-radius:8px;background:transparent;border:1px solid var(--line);color:var(--txt-2);font-family:var(--f-mono);font-size:11px;letter-spacing:.1em;cursor:pointer}.nlt-lang.on{background:rgba(56,182,240,.12);color:var(--brand-300);border-color:rgba(56,182,240,.3)}.nlt-foot-pub.jsx-6d81f11809c7f54d{margin-top:22px;text-align:center}.nlt-foot-pub-link{font-family:var(--f-mono);font-size:11.5px;letter-spacing:.08em;color:var(--txt-3);text-decoration:none;-webkit-transition:color.15s ease;-moz-transition:color.15s ease;-o-transition:color.15s ease;transition:color.15s ease}.nlt-foot-pub-link:hover{color:var(--brand-300)}.nlt-foot-pub-brand{color:var(--txt-1);font-weight:600}.nlt-foot-pub-link:hover .nlt-foot-pub-brand{color:var(--brand-300)}</style></head><body class=\"nlt-newlook\"><script>(() => {\n var RTL_LANGS = ['ar', 'he', 'fa', 'ur'];\n var pathname = window.location.pathname;\n var langMatch = pathname.match(/^\\/([a-z]{2})(\\/|$)/);\n var lang = langMatch ? langMatch[1] : 'en';\n var isRTL = RTL_LANGS.indexOf(lang) !== -1;\n document.documentElement.dir = isRTL ? 'rtl' : 'ltr';\n document.documentElement.lang = lang;\n})();</script><div style=\"min-height:100vh;display:flex;flex-direction:column;background:var(--ink-1);color:var(--txt-0)\"><header style=\"position:sticky;top:0;z-index:50;background:transparent;backdrop-filter:none;-webkit-backdrop-filter:none;border-bottom:1px solid transparent;transition:all .25s ease\" class=\"jsx-69e97639d407de6e nlt-topbar-root\"><div style=\"display:flex;align-items:center;gap:16px;height:68px\" class=\"jsx-69e97639d407de6e nlt-shell\"><a style=\"display:flex;align-items:center;gap:10px;text-decoration:none;color:inherit\" href=\"/\"><svg width=\"26\" height=\"26\" viewBox=\"0 0 80 80\" aria-hidden=\"true\"><defs><linearGradient id=\"nlt-bm\" x1=\"0\" y1=\"0\" x2=\"1\" y2=\"1\"><stop offset=\"0%\" stop-color=\"#5ec8f7\"></stop><stop offset=\"100%\" stop-color=\"#1e96d4\"></stop></linearGradient></defs><circle cx=\"40\" cy=\"40\" r=\"30\" fill=\"url(#nlt-bm)\" opacity=\"0.18\"></circle><circle cx=\"40\" cy=\"40\" r=\"18\" fill=\"url(#nlt-bm)\"></circle><circle cx=\"46\" cy=\"34\" r=\"5\" fill=\"#fff\"></circle><path d=\"M8 14h12M60 14h12M8 66h12M60 66h12\" stroke=\"url(#nlt-bm)\" stroke-width=\"4\" stroke-linecap=\"round\"></path></svg><span style=\"font-weight:600;letter-spacing:-0.02em;font-size:16px;color:var(--txt-0)\">Nerd<em style=\"font-family:var(--f-display);font-style:italic;color:var(--accent-italic);margin:0 2px;font-weight:400\">Level</em>Tech</span></a><nav style=\"display:flex;gap:4px;margin-inline-start:16px\" class=\"jsx-69e97639d407de6e nlt-nav-desk\"><a class=\"nlt-nav-link\" href=\"/nerdo\">Nerdo</a><a class=\"nlt-nav-link\" href=\"/courses\">Courses</a><a class=\"nlt-nav-link\" href=\"/guides\">Guides</a><a class=\"nlt-nav-link\" href=\"/tools\">Tools</a><a class=\"nlt-nav-link\" href=\"/podcast\">Cast</a><a class=\"nlt-nav-link\" href=\"/jobs\">Jobs</a><a class=\"nlt-nav-link\" href=\"/posts\">Blog</a><a class=\"nlt-nav-link\" href=\"/trending\">Trending</a><a class=\"nlt-nav-link\" href=\"/posts?category=news\">News</a></nav><div style=\"flex:1\" class=\"jsx-69e97639d407de6e\"></div><button type=\"button\" aria-label=\"Search\" title=\"Search (⌘K)\" class=\"jsx-69e97639d407de6e nlt-icon-btn\"><svg width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" class=\"jsx-69e97639d407de6e\"><circle cx=\"11\" cy=\"11\" r=\"7\" class=\"jsx-69e97639d407de6e\"></circle><path d=\"m20 20-3.5-3.5\" class=\"jsx-69e97639d407de6e\"></path></svg></button><button type=\"button\" aria-label=\"Switch to Arabic\" title=\"العربية\" style=\"font-weight:600;font-size:12px;letter-spacing:0.05em;font-family:system-ui, sans-serif\" class=\"jsx-69e97639d407de6e nlt-icon-btn\">ع</button><button aria-label=\"Toggle theme\" type=\"button\" class=\"jsx-69e97639d407de6e nlt-icon-btn\"><svg width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" class=\"jsx-69e97639d407de6e\"><path d=\"M21 12.79A9 9 0 1 1 11.21 3 7 7 0 0 0 21 12.79z\" class=\"jsx-69e97639d407de6e\"></path></svg></button><button type=\"button\" style=\"padding:8px 14px;font-size:13px\" class=\"jsx-69e97639d407de6e nlt-btn nlt-btn-ghost nlt-signin-btn\">Sign in</button><button type=\"button\" style=\"padding:10px 16px\" class=\"jsx-69e97639d407de6e nlt-btn nlt-btn-primary\">Start free<svg width=\"14\" height=\"14\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2.5\" style=\"transform:none\" class=\"jsx-69e97639d407de6e\"><path d=\"M5 12h14M13 5l7 7-7 7\" class=\"jsx-69e97639d407de6e\"></path></svg></button><div class=\"jsx-69e97639d407de6e nlt-mobile-only\"><button type=\"button\" aria-label=\"Open menu\" aria-expanded=\"false\" class=\"jsx-69e97639d407de6e nlt-icon-btn\"><svg width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" class=\"jsx-69e97639d407de6e\"><line x1=\"3\" y1=\"6\" x2=\"21\" y2=\"6\" class=\"jsx-69e97639d407de6e\"></line><line x1=\"3\" y1=\"12\" x2=\"21\" y2=\"12\" class=\"jsx-69e97639d407de6e\"></line><line x1=\"3\" y1=\"18\" x2=\"21\" y2=\"18\" class=\"jsx-69e97639d407de6e\"></line></svg></button></div></div></header><main class=\"nlt-shell nlt-main-shell\" style=\"flex:1;width:100%;min-width:0\"><div style=\"width:100%;min-width:0\"><script type=\"application/ld+json\">[{\"@context\":\"https://schema.org\",\"@type\":\"Article\",\"headline\":\"IETF Weighs an AI Agent Protocol Standard in 2026\",\"description\":\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\",\"image\":\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\",\"author\":{\"@type\":\"Person\",\"name\":\"Nerd Level Tech\",\"url\":\"https://nerdleveltech.com\"},\"publisher\":{\"@type\":\"Organization\",\"name\":\"Nerd Level Tech\",\"url\":\"https://nerdleveltech.com\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https://nerdleveltech.com/images/logo.png\",\"width\":512,\"height\":512}},\"datePublished\":\"2026-07-24T00:00:00.000Z\",\"dateModified\":\"2026-07-24T00:00:00.000Z\",\"mainEntityOfPage\":{\"@type\":\"WebPage\",\"@id\":\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"},\"url\":\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\",\"keywords\":\"IETF, AI agent protocol, agentproto, MCP, A2A, agent interoperability, agentic ai\",\"articleSection\":\"ai-ml\"},{\"@context\":\"https://schema.org\",\"@type\":\"BreadcrumbList\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https://nerdleveltech.com/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https://nerdleveltech.com/blog\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"IETF Weighs an AI Agent Protocol Standard in 2026\",\"item\":\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"}]},{\"@context\":\"https://schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Is the IETF standardizing AI agent protocols?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.\"}},{\"@type\":\"Question\",\"name\":\"What is the agentproto BoF at IETF 126?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Agentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.17\"}},{\"@type\":\"Question\",\"name\":\"How is MCP different from A2A?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"MCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.35 They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.7\"}},{\"@type\":\"Question\",\"name\":\"What would an IETF RFC add that MCP and A2A don't cover?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.7 These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\"}},{\"@type\":\"Question\",\"name\":\"Why is prompt injection worse in multi-agent systems?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Because it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.7 OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.9 Footnotes\\n\\n\\n\\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7\\n\\n\\n\\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/ ↩ ↩2 ↩3 ↩4\\n\\n\\n\\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/ ↩ ↩2 ↩3\\n\\n\\n\\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/ ↩\\n\\n\\n\\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/ ↩ ↩2\\n\\n\\n\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html ↩\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/ ↩\\n\\n\\n\\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf ↩ ↩2\\n\\n\\n\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm ↩ ↩2\"}}]}]</script><div class=\"lg:grid lg:grid-cols-[auto_minmax(0,1fr)_17.5rem] lg:gap-8\" dir=\"ltr\"><aside class=\"hidden lg:block w-14\"><div class=\"sticky top-32 flex flex-col items-center gap-4\"><div class=\"flex flex-col items-center gap-4 rounded-2xl border border-[var(--line)] bg-[color:var(--ink-2)] px-3 py-3 shadow-[0_20px_40px_-30px_rgba(15,23,42,0.45)] dark:border-[var(--line)] dark:bg-[color:var(--ink-1)]\"><button class=\"group flex items-center justify-center rounded-full bg-[color:var(--ink-2)] p-3 shadow-md backdrop-blur-sm transition-all duration-200 hover:bg-[color:var(--ink-2)] hover:shadow-lg hover:scale-110 dark:bg-[color:var(--ink-2)] dark:hover:bg-[color:var(--ink-4)]\" aria-label=\"Share this content\"><svg class=\"h-5 w-5 text-[color:var(--txt-2)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-3)]\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M8.684 13.342C8.886 12.938 9 12.482 9 12c0-.482-.114-.938-.316-1.342m0 2.684a3 3 0 110-2.684m0 2.684l6.632 3.316m-6.632-6l6.632-3.316m0 0a3 3 0 105.367-2.684 3 3 0 00-5.367 2.684zm0 9.316a3 3 0 105.367 2.684 3 3 0 00-5.367-2.684z\"></path></svg></button><span class=\"text-xs text-[color:var(--txt-2)]\">Share</span></div></div></aside><article class=\"prose dark:prose-invert max-w-none\"><div class=\"not-prose mb-3\"><span class=\"font-mono text-[11px] tracking-[0.18em] uppercase text-brand-300\">ai-ml</span></div><h1 class=\"nlt-h-display !mt-0 !mb-2\" style=\"font-size:clamp(32px, 4.6vw, 56px)\">IETF Weighs an AI Agent Protocol Standard in 2026</h1><div class=\"not-prose !mt-3 flex flex-wrap items-center gap-3\"><p class=\"font-mono text-[11px] tracking-[0.14em] uppercase text-[color:var(--txt-2)]\">July 24, 2026</p><div class=\"relative inline-flex \" dir=\"ltr\"><button type=\"button\" title=\"Bookmark\" aria-label=\"Bookmark this item\" aria-pressed=\"false\" class=\"inline-flex items-center gap-1 rounded-s-md border transition-colors disabled:opacity-50 h-7 px-2 border-[var(--line-strong)] bg-[color:var(--ink-2)] text-[color:var(--txt-2)] hover:border-brand-mid hover:text-brand-mid dark:border-[var(--line-strong)] dark:bg-[color:var(--ink-1)] dark:text-[color:var(--txt-3)]\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-bookmark h-3.5 w-3.5\" aria-hidden=\"true\"><path d=\"m19 21-7-4-7 4V5a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v16z\"></path></svg><span class=\"text-xs\">Save</span></button><button type=\"button\" title=\"Choose collection\" aria-label=\"Choose collection\" class=\"inline-flex items-center justify-center rounded-e-md border border-s-0 transition-colors h-7 px-2 border-[var(--line-strong)] bg-[color:var(--ink-2)] text-[color:var(--txt-2)] hover:border-brand-mid hover:text-brand-mid dark:border-[var(--line-strong)] dark:bg-[color:var(--ink-1)] dark:text-[color:var(--txt-3)]\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down h-3.5 w-3.5\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div></div><div class=\"not-prose mt-2 flex flex-wrap gap-2\"><a aria-label=\"Tag IETF\" href=\"/tags/ietf\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->IETF</span></a><a aria-label=\"Tag AI agent protocol\" href=\"/tags/ai-agent-protocol\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->AI agent protocol</span></a><a aria-label=\"Tag agentproto\" href=\"/tags/agentproto\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->agentproto</span></a><a aria-label=\"Tag MCP\" href=\"/tags/mcp\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->MCP</span></a><a aria-label=\"Tag A2A\" href=\"/tags/a2a\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->A2A</span></a><a aria-label=\"Tag agent interoperability\" href=\"/tags/agent-interoperability\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->agent interoperability</span></a><a aria-label=\"Tag agentic ai\" href=\"/tags/agentic-ai\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->agentic ai</span></a></div><div class=\"not-prose mt-7\"><div class=\"relative overflow-hidden rounded-2xl bg-[color:var(--ink-3)] border border-[var(--line)] pb-[56%]\"><img alt=\"IETF Weighs an AI Agent Protocol Standard in 2026\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"absolute inset-0 h-full w-full object-cover\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\"/></div></div><div class=\"not-prose mt-6 lg:hidden\"><button class=\"group flex items-center justify-center rounded-full bg-[color:var(--ink-2)] p-2 shadow-md backdrop-blur-sm transition-all duration-200 hover:bg-[color:var(--ink-2)] hover:shadow-lg hover:scale-110 dark:bg-[color:var(--ink-2)] dark:hover:bg-[color:var(--ink-4)] justify-center rounded-full border border-[var(--line)] bg-[color:var(--ink-2)] px-4 py-2 shadow-sm dark:border-[var(--line)] dark:bg-[color:var(--ink-1)]\" aria-label=\"Share this content\"><svg class=\"h-4 w-4 text-[color:var(--txt-2)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-3)]\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M8.684 13.342C8.886 12.938 9 12.482 9 12c0-.482-.114-.938-.316-1.342m0 2.684a3 3 0 110-2.684m0 2.684l6.632 3.316m-6.632-6l6.632-3.316m0 0a3 3 0 105.367-2.684 3 3 0 00-5.367 2.684zm0 9.316a3 3 0 105.367 2.684 3 3 0 00-5.367-2.684z\"></path></svg></button></div><div class=\"lg:hidden\"><aside class=\"not-prose mb-8 rounded-lg border border-[var(--line)] bg-[color:var(--ink-2)] p-4\" dir=\"ltr\"><div class=\"text-sm font-semibold mb-2 brand-text\" style=\"text-align:left\">Table of contents</div><nav aria-label=\"Table of contents\"><ul class=\"space-y-0.5\"><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-youll-learn\">What you&#x27;ll learn</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-happened-at-the-agentproto-bof\">What happened at the agentproto BoF</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-it-is-rough-consensus-not-a-vote\">Why it is rough consensus, not a vote</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#mcp-vs-a2a-two-layers-one-missing-piece\">MCP vs A2A: two layers, one missing piece</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-problems-the-framework-says-still-need-a-standard\">The problems the framework says still need a standard</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-prompt-injection-is-the-security-test\">Why prompt injection is the security test</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-realistic-timeline--and-what-to-watch\">The realistic timeline — and what to watch</a></li></ul></nav></aside></div><div class=\"mt-6\"><html><head></head><body><p><strong>In one line:</strong> At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup></p>\n<p><strong>TL;DR:</strong> For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup> This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup> What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.</p>\n<h2 id=\"what-youll-learn\"><a class=\"anchor\" href=\"#what-youll-learn\">What you'll learn</a></h2>\n<ul>\n<li>What happened at the agentproto BoF at IETF 126, and what a \"Birds-of-a-Feather\" session actually decides</li>\n<li>Why the IETF works by rough consensus rather than a vote — and why that framing matters here</li>\n<li>How MCP and A2A differ, and the interoperability gap neither one closes</li>\n<li>The specific problems the underlying framework draft says still need a standard</li>\n<li>Why prompt injection is the security test any agent protocol standard has to pass</li>\n<li>The realistic timeline from a BoF to a published RFC, and what to watch next</li>\n</ul>\n<h2 id=\"what-happened-at-the-agentproto-bof\"><a class=\"anchor\" href=\"#what-happened-at-the-agentproto-bof\">What happened at the agentproto BoF</a></h2>\n<p>The IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup> Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was <strong>agentproto</strong> (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup></p>\n<p>The IETF's own framing is precise: the past year produced \"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\" The agentproto session, it says, \"brings that conversation into the IETF,\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \"with a view toward chartering a Working Group to take that work forward.\"<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-5\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup></p>\n<p>That phrase — <em>chartering a Working Group</em> — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup></p>\n<h2 id=\"why-it-is-rough-consensus-not-a-vote\"><a class=\"anchor\" href=\"#why-it-is-rough-consensus-not-a-vote\">Why it is rough consensus, not a vote</a></h2>\n<p>It is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \"rough consensus and running code\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup> A BoF that is \"working-group-forming,\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup></p>\n<p>This is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that <strong>an IETF AI agent protocol standard</strong> belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.</p>\n<h2 id=\"mcp-vs-a2a-two-layers-one-missing-piece\"><a class=\"anchor\" href=\"#mcp-vs-a2a-two-layers-one-missing-piece\">MCP vs A2A: two layers, one missing piece</a></h2>\n<p>To see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.</p>\n<p><strong>MCP (Model Context Protocol)</strong> is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \"over 97 million monthly SDK downloads, 10,000 active servers,\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.<sup><a href=\"#user-content-fn-3\" id=\"user-content-fnref-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">3</a></sup> Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of <a href=\"/mcp-stateless-protocol-enterprise-authorization\">MCP's stateless 2026-07-28 spec</a>.<sup><a href=\"#user-content-fn-9\" id=\"user-content-fnref-9\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">4</a></sup></p>\n<p><strong>A2A (Agent2Agent)</strong> is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.<sup><a href=\"#user-content-fn-4\" id=\"user-content-fnref-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">5</a></sup><sup><a href=\"#user-content-fn-5\" id=\"user-content-fnref-5\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">6</a></sup> If you want the hands-on version of how agents advertise capabilities and hand off work, our <a href=\"/a2a-protocol-python-tutorial\">A2A protocol tutorial</a> walks through it.</p>\n<div data-ad-placement=\"post-in-article-mid\" class=\"not-prose my-8\"></div>\n\n<p>Here is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in <em>your</em> organization needs to prove to an agent in <em>someone else's</em> organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.</p>\n<h2 id=\"the-problems-the-framework-says-still-need-a-standard\"><a class=\"anchor\" href=\"#the-problems-the-framework-says-still-need-a-standard\">The problems the framework says still need a standard</a></h2>\n<p>The intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup> Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \"not endorsed by the IETF\" and have \"no formal standing in the IETF standards process,\" and the early framework draft has already been superseded — the current document is <code>draft-rosenberg-agentproto-usecases</code>.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup><sup><a href=\"#user-content-fn-7\" id=\"user-content-fnref-7\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">8</a></sup></p>\n<p>With that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup> The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup></p>\n<h2 id=\"why-prompt-injection-is-the-security-test\"><a class=\"anchor\" href=\"#why-prompt-injection-is-the-security-test\">Why prompt injection is the security test</a></h2>\n<p>The most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.</p>\n<p>In a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as <strong>LLM01 — the number-one risk</strong> in its Top 10 for LLM Applications.<sup><a href=\"#user-content-fn-8\" id=\"user-content-fnref-8\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">9</a></sup> The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-5\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup> The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-6\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup></p>\n<p>That is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \"just use MCP and A2A\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.</p>\n<h2 id=\"the-realistic-timeline--and-what-to-watch\"><a class=\"anchor\" href=\"#the-realistic-timeline--and-what-to-watch\">The realistic timeline — and what to watch</a></h2>\n<p>Set expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.<sup><a href=\"#user-content-fn-10\" id=\"user-content-fnref-10\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">10</a></sup> Nothing shipped in Vienna this week. What the meeting could produce is a decision to <em>start</em>, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.</p>\n<p>The strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.<sup><a href=\"#user-content-fn-3\" id=\"user-content-fnref-3-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">3</a></sup> The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in <a href=\"/eu-android-ai-agent-interoperability-dma\">the EU's push for AI agent interoperability under the DMA</a>.</p>\n<p>For now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.</p>\n\n\n\n\n\n\n\n\n\n\n\n</div><div class=\"not-prose\"><section class=\"mt-12 pt-8 border-t border-[var(--line-strong)]\"><h2 id=\"faq\" class=\"text-2xl font-bold text-[color:var(--txt-0)] mb-6\">Frequently Asked Questions</h2><div class=\"bg-[color:var(--ink-2)] rounded-xl p-6\"><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"true\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">Is the IETF standardizing AI agent protocols?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-up w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m18 15-6-6-6 6\"></path></svg></button><div class=\"pb-4 text-[color:var(--txt-2)] leading-relaxed\">Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.</div></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">What is the agentproto BoF at IETF 126?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">How is MCP different from A2A?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">What would an IETF RFC add that MCP and A2A don&#x27;t cover?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">Why is prompt injection worse in multi-agent systems?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div></div></section></div><hr class=\"not-prose my-10 border-[var(--line)]\"/><nav class=\"not-prose flex justify-between text-sm text-[color:var(--txt-2)]\"><div><a class=\"hover:text-[color:var(--txt-0)] dark:hover:text-[color:var(--txt-1)] transition-colors\" href=\"/microsoft-agent-framework-go-google-adk\"><span class=\"\">←</span> <!-- -->Previous</a></div><div><a class=\"hover:text-[color:var(--txt-0)] dark:hover:text-[color:var(--txt-1)] transition-colors\" href=\"/pinecone-nexus-knowledge-engine-rag-agents\">Next<!-- --> <span class=\"\">→</span></a></div></nav></article><aside class=\"hidden lg:block\"><div class=\"sticky top-24 space-y-6\"><aside class=\"not-prose mb-8 rounded-lg border border-[var(--line)] bg-[color:var(--ink-2)] p-4\" dir=\"ltr\"><div class=\"text-sm font-semibold mb-2 brand-text\" style=\"text-align:left\">Table of contents</div><nav aria-label=\"Table of contents\"><ul class=\"space-y-0.5\"><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-youll-learn\">What you&#x27;ll learn</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-happened-at-the-agentproto-bof\">What happened at the agentproto BoF</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-it-is-rough-consensus-not-a-vote\">Why it is rough consensus, not a vote</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#mcp-vs-a2a-two-layers-one-missing-piece\">MCP vs A2A: two layers, one missing piece</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-problems-the-framework-says-still-need-a-standard\">The problems the framework says still need a standard</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-prompt-injection-is-the-security-test\">Why prompt injection is the security test</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-realistic-timeline--and-what-to-watch\">The realistic timeline — and what to watch</a></li></ul></nav></aside></div></aside></div><div class=\"mx-auto max-w-3xl px-4\"><section class=\"mt-16 border-t border-[var(--line)] pt-10 dark:border-[var(--line)]\" dir=\"ltr\"><div class=\"mb-6 flex items-center gap-3\"><div class=\"h-8 w-1 rounded-full bg-gradient-to-b from-brand-begin to-brand-end\"></div><div><p class=\"text-xs font-medium uppercase tracking-wider text-[color:var(--txt-2)]\">Continue Learning</p><h2 class=\"text-xl font-bold text-[color:var(--txt-0)]\">Related Posts</h2></div></div><div class=\"grid grid-cols-1 gap-4 sm:grid-cols-2\"><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/claude-adobe-creativity-connector-50-creative-cloud-tools\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Adobe + Claude: 50+ Creative Tools From One Prompt\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/placeholders/cover-general.svg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Adobe + Claude: 50+ Creative Tools From One Prompt</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">claude</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">adobe</span></div></div></a><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/claude-managed-agents-deploy-ai-agents-faster\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Claude Managed Agents: Build Production AI Agents in Days\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/placeholders/cover-general.svg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Claude Managed Agents: Build Production AI Agents in Days</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">anthropic</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">claude</span></div></div></a><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/pinecone-nexus-knowledge-engine-rag-agents\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/covers/pinecone-nexus-knowledge-engine-rag-agents.jpg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Pinecone Nexus: Is RAG Ending for AI Agents? (2026)</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">Pinecone Nexus</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">knowledge engine</span></div></div></a><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/prompt-optimization-ai-agents-gepa\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Prompt Optimization for AI Agents: GEPA and DSPy (2026)\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/covers/prompt-optimization-ai-agents-gepa.jpg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Prompt Optimization for AI Agents: GEPA and DSPy (2026)</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">prompt optimization</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">GEPA</span></div></div></a></div></section></div></div></main><div class=\"nlt-shell\" style=\"padding-bottom:24px\"></div><footer class=\"jsx-6d81f11809c7f54d nlt-foot\"><div class=\"jsx-6d81f11809c7f54d nlt-shell\"><div class=\"jsx-6d81f11809c7f54d nlt-foot-top\"><div class=\"jsx-6d81f11809c7f54d nlt-foot-brand\"><a style=\"display:inline-flex;align-items:center;gap:10px;text-decoration:none;color:inherit\" href=\"/\"><svg width=\"28\" height=\"28\" viewBox=\"0 0 80 80\" aria-hidden=\"true\"><defs><linearGradient id=\"nlt-bm\" x1=\"0\" y1=\"0\" x2=\"1\" y2=\"1\"><stop offset=\"0%\" stop-color=\"#5ec8f7\"></stop><stop offset=\"100%\" stop-color=\"#1e96d4\"></stop></linearGradient></defs><circle cx=\"40\" cy=\"40\" r=\"30\" fill=\"url(#nlt-bm)\" opacity=\"0.18\"></circle><circle cx=\"40\" cy=\"40\" r=\"18\" fill=\"url(#nlt-bm)\"></circle><circle cx=\"46\" cy=\"34\" r=\"5\" fill=\"#fff\"></circle><path d=\"M8 14h12M60 14h12M8 66h12M60 66h12\" stroke=\"url(#nlt-bm)\" stroke-width=\"4\" stroke-linecap=\"round\"></path></svg><span style=\"font-weight:600;letter-spacing:-0.02em;font-size:18px;color:var(--txt-0)\">Nerd<em style=\"font-family:var(--f-display);font-style:italic;color:var(--accent-italic);margin:0 2px;font-weight:400\">Level</em>Tech</span></a><p style=\"margin-top:14px;color:var(--txt-1);max-width:320px;font-size:13.5px;line-height:1.55\" class=\"jsx-6d81f11809c7f54d\">The AI tutor that levels up with you. Independent, multilingual, made by builders for builders.</p><div style=\"display:flex;gap:8px;margin-top:18px\" class=\"jsx-6d81f11809c7f54d\"><button type=\"button\" class=\"jsx-6d81f11809c7f54d nlt-lang on\">EN</button><button type=\"button\" class=\"jsx-6d81f11809c7f54d nlt-lang\">AR</button></div></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Learn</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/courses\">Courses</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/guides\">Guides</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tutorials\">Tutorials</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/courses/paths\">Roadmaps</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/certificates\">Certificates</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Tools</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/resume-optimizer\">Resume Optimizer</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/regex-tester\">Regex Tester</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/api-response-mocker\">API Mocker</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/tech-pulse\">Tech Pulse</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools\">All tools</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Read</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/posts\">Blog</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/posts?category=news\">News</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/podcast\">AI Cast</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/subscribe\">Newsletter</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/trending\">Trending</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tags\">Tags</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Hire</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/jobs\">Jobs board</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/interview-prep\">Interview prep</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/for-agents\">For agents</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/jobs/post\">Post a job</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Co.</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/about\">About</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/about\">Contact</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/privacy-policy\">Privacy</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/terms-of-service\">Terms</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/rss.xml\">RSS</a></li></ul></div></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-bot\"><span style=\"color:var(--txt-3);font-size:11.5px\" class=\"jsx-6d81f11809c7f54d nlt-mono\">©<!-- --> <!-- -->2026<!-- --> <!-- -->NerdLevelTech · made with caffeine and curiosity</span><div class=\"jsx-6d81f11809c7f54d nlt-foot-socials\"><a href=\"https://www.instagram.com/nerdleveltech\" aria-label=\"Instagram\" title=\"Instagram\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-social\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-instagram jsx-6d81f11809c7f54d\" aria-hidden=\"true\"><rect width=\"20\" height=\"20\" x=\"2\" y=\"2\" rx=\"5\" ry=\"5\"></rect><path d=\"M16 11.37A4 4 0 1 1 12.63 8 4 4 0 0 1 16 11.37z\"></path><line x1=\"17.5\" x2=\"17.51\" y1=\"6.5\" y2=\"6.5\"></line></svg></a><a href=\"https://www.linkedin.com/company/nerdleveltech\" aria-label=\"LinkedIn\" title=\"LinkedIn\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-social\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-linkedin jsx-6d81f11809c7f54d\" aria-hidden=\"true\"><path d=\"M16 8a6 6 0 0 1 6 6v7h-4v-7a2 2 0 0 0-2-2 2 2 0 0 0-2 2v7h-4v-7a6 6 0 0 1 6-6z\"></path><rect width=\"4\" height=\"12\" x=\"2\" y=\"9\"></rect><circle cx=\"4\" cy=\"4\" r=\"2\"></circle></svg></a><a href=\"https://x.com/nerdleveltech\" aria-label=\"X\" title=\"X\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-social\"><svg viewBox=\"0 0 24 24\" width=\"16\" height=\"16\" aria-hidden=\"true\" class=\"jsx-6d81f11809c7f54d\" fill=\"currentColor\"><path d=\"M18.244 2.25h3.308l-7.227 8.26 8.502 11.24h-6.66l-5.214-6.817L4.97 21.75H1.658l7.73-8.835L1.25 2.25h6.834l4.713 6.231L18.244 2.25Zm-1.161 17.52h1.833L7.084 4.126H5.117L17.083 19.77Z\"></path></svg></a></div></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-pub\"><a href=\"https://lumabyte.co\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-foot-pub-link\">A <span class=\"jsx-6d81f11809c7f54d nlt-foot-pub-brand\">LumaByte</span> publication</a></div></div></footer><aside id=\"nlt-cookie-banner\" class=\"fixed inset-x-0 bottom-0 z-50 px-4 pb-6\" dir=\"ltr\"><div class=\"mx-auto max-w-4xl rounded-2xl border border-[var(--line-strong)] bg-[color:var(--ink-2)] p-5 shadow-2xl backdrop-blur\"><div class=\"flex flex-col gap-4 sm:flex-row sm:items-center sm:justify-between \"><div class=\"text-sm text-[color:var(--txt-1)]\"><p class=\"font-medium text-[color:var(--txt-0)]\">Cookies help keep Nerd Level Tech running smoothly.</p><p class=\"mt-1 leading-relaxed text-xs sm:text-sm\">We use cookies for analytics (Google Analytics), to remember your theme preferences, and to improve our content. By accepting, you consent to analytics and personalized ads. You can decline or opt out at any time.</p></div><div class=\"flex flex-col gap-2 sm:flex-row sm:items-center \"><button type=\"button\" class=\"rounded-full bg-brand-500 px-4 py-2 text-xs font-semibold text-[#001520] shadow-[0_0_0_1px_rgba(255,255,255,0.06)_inset,0_18px_40px_-16px_var(--glow-strong)] transition-all hover:-translate-y-px hover:bg-brand-400\">Accept</button><button type=\"button\" class=\"rounded-full px-4 py-2 text-xs font-semibold text-[color:var(--txt-1)] transition hover:bg-[color:var(--ink-3)]\">Decline</button></div></div></div></aside><!--$--><!--/$--><!--$--><!--/$--></div><script src=\"/_next/static/chunks/webpack-7162da525ac05067.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\" async=\"\"></script></body></html><script>(self.__next_f=self.__next_f||[]).push([0]);self.__next_f.push([2,null])</script><script>self.__next_f.push([1,\"1:HL[\\\"/_next/static/media/9cc5b37ab1350db7.p.woff2\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n2:HL[\\\"/_next/static/media/e4af272ccee01ff0.p.woff2\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n3:HL[\\\"/_next/static/media/e6099e249fd938cc.p.woff2\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n4:HL[\\\"/_next/static/css/a78fa145c089ec40.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"style\\\"]\\n5:HL[\\\"/_next/static/css/838b9eb00883d6da.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"style\\\"]\\n6:HL[\\\"/_next/static/css/d7a984aa9a9fcc2c.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"style\\\"]\\n\"])</script><script>self.__next_f.push([1,\"7:I[12846,[],\\\"\\\"]\\na:I[4707,[],\\\"\\\"]\\nd:I[36423,[],\\\"\\\"]\\n11:I[61060,[],\\\"\\\"]\\nb:[\\\"lang\\\",\\\"en\\\",\\\"d\\\"]\\nc:[\\\"slug\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"d\\\"]\\n12:[]\\n0:[\\\"$\\\",\\\"$L7\\\",null,{\\\"buildId\\\":\\\"yyrJfn-asRlx7UUbdUkPd\\\",\\\"assetPrefix\\\":\\\"\\\",\\\"urlParts\\\":[\\\"\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\"],\\\"initialTree\\\":[\\\"\\\",{\\\"children\\\":[[\\\"lang\\\",\\\"en\\\",\\\"d\\\"],{\\\"children\\\":[[\\\"slug\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"d\\\"],{\\\"children\\\":[\\\"__PAGE__\\\",{}]}]}]},\\\"$undefined\\\",\\\"$undefined\\\",true],\\\"initialSeedData\\\":[\\\"\\\",{\\\"children\\\":[[\\\"lang\\\",\\\"en\\\",\\\"d\\\"],{\\\"children\\\":[[\\\"slug\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"d\\\"],{\\\"children\\\":[\\\"__PAGE__\\\",{},[[\\\"$L8\\\",\\\"$L9\\\",null],null],null]},[null,[\\\"$\\\",\\\"$La\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"segmentPath\\\":[\\\"children\\\",\\\"$b\\\",\\\"children\\\",\\\"$c\\\",\\\"children\\\"],\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$Ld\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"notFoundStyles\\\":\\\"$undefined\\\"}]],null]},[[null,\\\"$Le\\\"],null],null]},[[[[\\\"$\\\",\\\"link\\\",\\\"0\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/css/a78fa145c089ec40.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"link\\\",\\\"1\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/css/838b9eb00883d6da.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"link\\\",\\\"2\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/css/d7a984aa9a9fcc2c.css?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}]],\\\"$Lf\\\"],null],null],\\\"couldBeIntercepted\\\":false,\\\"initialHead\\\":[null,\\\"$L10\\\"],\\\"globalErrorComponent\\\":\\\"$11\\\",\\\"missingSlots\\\":\\\"$W12\\\"}]\\n\"])</script><script>self.__next_f.push([1,\"13:I[34182,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"LanguageProvider\\\"]\\n14:I[44727,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"AuthModalProvider\\\"]\\n15:I[93583,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"ToastProvider\\\"]\\n16:I[56610,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n17:I[10425,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sB\"])</script><script>self.__next_f.push([1,\"r5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n18:I[11176,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n19:I[97526,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n1a:I[5274,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"FeedbackWidget\\\"]\\n1b:I[38156,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8G\"])</script><script>self.__next_f.push([1,\"YcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n1c:I[1880,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n1d:I[38599,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-bbc061b9c503cf16.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n1f:I[74048,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"5878\\\",\\\"static/chunks/5878-43bbacc376acddee.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"2957\\\",\\\"static/chunks/2957-135fdf77983e5820.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7363\\\",\\\"static/chunks/7363-1b3fd7d0da0ebc28.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"4182\\\",\\\"static/chunks/4182-e96c5784a81e1858.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8041\\\",\\\"static/chunks/8041-f3df4595b34e4e85.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"482\\\",\\\"static/chunks/482-e3c47234496c384c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7621\\\",\\\"static/chunks/app/%5Blang%5D/%5Bslug%5D/page-e0c122d0071f8e69.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n24:I[86249,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"5878\\\",\\\"static/chunks/5878-43bbacc376acddee.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF\"])</script><script>self.__next_f.push([1,\"7DpTj\\\",\\\"2957\\\",\\\"static/chunks/2957-135fdf77983e5820.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7363\\\",\\\"static/chunks/7363-1b3fd7d0da0ebc28.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"4182\\\",\\\"static/chunks/4182-e96c5784a81e1858.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8041\\\",\\\"static/chunks/8041-f3df4595b34e4e85.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"482\\\",\\\"static/chunks/482-e3c47234496c384c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"7621\\\",\\\"static/chunks/app/%5Blang%5D/%5Bslug%5D/page-e0c122d0071f8e69.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\ne:[\\\"$\\\",\\\"$L13\\\",null,{\\\"initialLang\\\":\\\"en\\\",\\\"children\\\":[\\\"$\\\",\\\"$L14\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$L15\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"$L16\\\",null,{\\\"headerTranslations\\\":{\\\"navBlog\\\":\\\"Blog\\\",\\\"navGuides\\\":\\\"Guides\\\",\\\"navAICast\\\":\\\"AI Cast\\\",\\\"navAINerdo\\\":\\\"Nerdo\\\",\\\"navCourses\\\":\\\"Courses\\\",\\\"navResources\\\":\\\"Resources\\\",\\\"navTools\\\":\\\"Tools\\\",\\\"searchPlaceholder\\\":\\\"Search articles, tools, or topics...\\\",\\\"searchButton\\\":\\\"Search\\\",\\\"ariaOpenSearch\\\":\\\"Open search\\\",\\\"ariaCloseSearch\\\":\\\"Close search\\\",\\\"ariaOpenMenu\\\":\\\"Open menu\\\",\\\"ariaCloseMenu\\\":\\\"Close menu\\\"},\\\"footerTranslations\\\":{\\\"privacyPolicy\\\":\\\"Privacy Policy\\\",\\\"termsOfService\\\":\\\"Service Terms\\\",\\\"about\\\":\\\"About\\\",\\\"copyright\\\":\\\"© 2026 Nerd Level Tech\\\"},\\\"children\\\":[\\\"$\\\",\\\"$La\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"segmentPath\\\":[\\\"children\\\",\\\"$b\\\",\\\"children\\\"],\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$Ld\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"notFoundStyles\\\":\\\"$undefined\\\"}]}],[\\\"$\\\",\\\"$L17\\\",null,{}],[\\\"$\\\",\\\"$L18\\\",null,{}],[\\\"$\\\",\\\"$L19\\\",null,{}],[\\\"$\\\",\\\"$L1a\\\",null,{}],[\\\"$\\\",\\\"$L1b\\\",null,{}],[\\\"$\\\",\\\"$L1c\\\",null,{}],[\\\"$\\\",\\\"$L1d\\\",null,{}]]}]}]}]\\n1e:T1afb,\"])</script><script>self.__next_f.push([1,\"[{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"Article\\\",\\\"headline\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"description\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\",\\\"image\\\":\\\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\",\\\"author\\\":{\\\"@type\\\":\\\"Person\\\",\\\"name\\\":\\\"Nerd Level Tech\\\",\\\"url\\\":\\\"https://nerdleveltech.com\\\"},\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Nerd Level Tech\\\",\\\"url\\\":\\\"https://nerdleveltech.com\\\",\\\"logo\\\":{\\\"@type\\\":\\\"ImageObject\\\",\\\"url\\\":\\\"https://nerdleveltech.com/images/logo.png\\\",\\\"width\\\":512,\\\"height\\\":512}},\\\"datePublished\\\":\\\"2026-07-24T00:00:00.000Z\\\",\\\"dateModified\\\":\\\"2026-07-24T00:00:00.000Z\\\",\\\"mainEntityOfPage\\\":{\\\"@type\\\":\\\"WebPage\\\",\\\"@id\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"},\\\"url\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\",\\\"keywords\\\":\\\"IETF, AI agent protocol, agentproto, MCP, A2A, agent interoperability, agentic ai\\\",\\\"articleSection\\\":\\\"ai-ml\\\"},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"BreadcrumbList\\\",\\\"itemListElement\\\":[{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":1,\\\"name\\\":\\\"Home\\\",\\\"item\\\":\\\"https://nerdleveltech.com/\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":2,\\\"name\\\":\\\"Blog\\\",\\\"item\\\":\\\"https://nerdleveltech.com/blog\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":3,\\\"name\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"item\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}]},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"FAQPage\\\",\\\"mainEntity\\\":[{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"Is the IETF standardizing AI agent protocols?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"What is the agentproto BoF at IETF 126?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"Agentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.17\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"How is MCP different from A2A?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"MCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.35 They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.7\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"What would an IETF RFC add that MCP and A2A don't cover?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"The framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.7 These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"Why is prompt injection worse in multi-agent systems?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"Because it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.7 OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.9 Footnotes\\\\n\\\\n\\\\n\\\\\\\"Birds of a Feather at IETF 126,\\\\\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7\\\\n\\\\n\\\\n\\\\\\\"Birds of a Feather (BOF),\\\\\\\" IETF process documentation, and \\\\\\\"Introduction to the IETF\\\\\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/ ↩ ↩2 ↩3 ↩4\\\\n\\\\n\\\\n\\\\\\\"MCP joins the Agentic AI Foundation,\\\\\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/ ↩ ↩2 ↩3\\\\n\\\\n\\\\n\\\\\\\"The 2026-07-28 MCP Specification Release Candidate,\\\\\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/ ↩\\\\n\\\\n\\\\n\\\\\\\"Google Cloud donates A2A to Linux Foundation,\\\\\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/ ↩ ↩2\\\\n\\\\n\\\\n\\\\\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\\\\\" Google Open Source Blog, 16 April 2026 (\\\\\\\"over 100 technology companies now supporting the project\\\\\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html ↩\\\\n\\\\n\\\\n\\\\\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\\\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\\\\\"Prompt injection attacks are notoriously difficult to prevent\\\\\\\"). This individual Internet-Draft is expired and \\\\\\\"has no formal standing in the IETF standards process.\\\\\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10\\\\n\\\\n\\\\n\\\\\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\\\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/ ↩\\\\n\\\\n\\\\n\\\\\\\"OWASP Top 10 for LLM Applications 2025,\\\\\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf ↩ ↩2\\\\n\\\\n\\\\n\\\\\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\\\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm ↩ ↩2\\\"}}]}]\"])</script><script>self.__next_f.push([1,\"20:T3dfb,\"])</script><script>self.__next_f.push([1,\"\\n# IETF Weighs an AI Agent Protocol Standard in 2026\\n\\n**In one line:** At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.[^1]\\n\\n**TL;DR:** For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.[^1] This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.[^2] What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.\\n\\n## What you'll learn\\n\\n- What happened at the agentproto BoF at IETF 126, and what a \\\"Birds-of-a-Feather\\\" session actually decides\\n- Why the IETF works by rough consensus rather than a vote — and why that framing matters here\\n- How MCP and A2A differ, and the interoperability gap neither one closes\\n- The specific problems the underlying framework draft says still need a standard\\n- Why prompt injection is the security test any agent protocol standard has to pass\\n- The realistic timeline from a BoF to a published RFC, and what to watch next\\n\\n## What happened at the agentproto BoF\\n\\nThe IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.[^1] Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was **agentproto** (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.[^1]\\n\\nThe IETF's own framing is precise: the past year produced \\\"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\\\" The agentproto session, it says, \\\"brings that conversation into the IETF,\\\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \\\"with a view toward chartering a Working Group to take that work forward.\\\"[^1]\\n\\nThat phrase — *chartering a Working Group* — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.[^2]\\n\\n## Why it is rough consensus, not a vote\\n\\nIt is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \\\"rough consensus and running code\\\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.[^2] A BoF that is \\\"working-group-forming,\\\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.[^2]\\n\\nThis is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that **an IETF AI agent protocol standard** belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.\\n\\n## MCP vs A2A: two layers, one missing piece\\n\\nTo see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.\\n\\n**MCP (Model Context Protocol)** is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \\\"over 97 million monthly SDK downloads, 10,000 active servers,\\\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.[^3] Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of [MCP's stateless 2026-07-28 spec](/mcp-stateless-protocol-enterprise-authorization).[^9]\\n\\n**A2A (Agent2Agent)** is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.[^4][^5] If you want the hands-on version of how agents advertise capabilities and hand off work, our [A2A protocol tutorial](/a2a-protocol-python-tutorial) walks through it.\\n\\nHere is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in *your* organization needs to prove to an agent in *someone else's* organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.\\n\\n## The problems the framework says still need a standard\\n\\nThe intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.[^6] Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \\\"not endorsed by the IETF\\\" and have \\\"no formal standing in the IETF standards process,\\\" and the early framework draft has already been superseded — the current document is `draft-rosenberg-agentproto-usecases`.[^6][^7]\\n\\nWith that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).[^6] The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.[^6]\\n\\n## Why prompt injection is the security test\\n\\nThe most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.\\n\\nIn a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as **LLM01 — the number-one risk** in its Top 10 for LLM Applications.[^8] The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.[^6] The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.[^6]\\n\\nThat is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \\\"just use MCP and A2A\\\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.\\n\\n## The realistic timeline — and what to watch\\n\\nSet expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.[^10] Nothing shipped in Vienna this week. What the meeting could produce is a decision to *start*, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.\\n\\nThe strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.[^3] The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in [the EU's push for AI agent interoperability under the DMA](/eu-android-ai-agent-interoperability-dma).\\n\\nFor now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.\\n\\n## FAQ\\n\\n### Is the IETF standardizing AI agent protocols?\\n\\nNot yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.[^1] A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.[^10] The authoritative outcome of the session is posted to the IETF Datatracker.\\n\\n### What is the agentproto BoF at IETF 126?\\n\\nAgentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.[^1][^6]\\n\\n### How is MCP different from A2A?\\n\\nMCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.[^3][^4] They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.[^6]\\n\\n### What would an IETF RFC add that MCP and A2A don't cover?\\n\\nThe framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.[^6] These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\n\\n### Why is prompt injection worse in multi-agent systems?\\n\\nBecause it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.[^6] OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.[^8]\\n\\n[^1]: \\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/\\n[^2]: \\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/\\n[^3]: \\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/\\n[^4]: \\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/\\n[^5]: \\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html\\n[^6]: \\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/\\n[^7]: \\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/\\n[^8]: \\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf\\n[^9]: \\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/\\n[^10]: \\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm\\n\"])</script><script>self.__next_f.push([1,\"21:T6d06,\"])</script><script>self.__next_f.push([1,\"\\u003cp\\u003e\\u003cstrong\\u003eIn one line:\\u003c/strong\\u003e At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eTL;DR:\\u003c/strong\\u003e For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"what-youll-learn\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-youll-learn\\\"\\u003eWhat you'll learn\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cul\\u003e\\n\\u003cli\\u003eWhat happened at the agentproto BoF at IETF 126, and what a \\\"Birds-of-a-Feather\\\" session actually decides\\u003c/li\\u003e\\n\\u003cli\\u003eWhy the IETF works by rough consensus rather than a vote — and why that framing matters here\\u003c/li\\u003e\\n\\u003cli\\u003eHow MCP and A2A differ, and the interoperability gap neither one closes\\u003c/li\\u003e\\n\\u003cli\\u003eThe specific problems the underlying framework draft says still need a standard\\u003c/li\\u003e\\n\\u003cli\\u003eWhy prompt injection is the security test any agent protocol standard has to pass\\u003c/li\\u003e\\n\\u003cli\\u003eThe realistic timeline from a BoF to a published RFC, and what to watch next\\u003c/li\\u003e\\n\\u003c/ul\\u003e\\n\\u003ch2 id=\\\"what-happened-at-the-agentproto-bof\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-happened-at-the-agentproto-bof\\\"\\u003eWhat happened at the agentproto BoF\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was \\u003cstrong\\u003eagentproto\\u003c/strong\\u003e (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThe IETF's own framing is precise: the past year produced \\\"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\\\" The agentproto session, it says, \\\"brings that conversation into the IETF,\\\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \\\"with a view toward chartering a Working Group to take that work forward.\\\"\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat phrase — \\u003cem\\u003echartering a Working Group\\u003c/em\\u003e — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-it-is-rough-consensus-not-a-vote\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-it-is-rough-consensus-not-a-vote\\\"\\u003eWhy it is rough consensus, not a vote\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eIt is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \\\"rough consensus and running code\\\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e A BoF that is \\\"working-group-forming,\\\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThis is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that \\u003cstrong\\u003ean IETF AI agent protocol standard\\u003c/strong\\u003e belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003eMCP vs A2A: two layers, one missing piece\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eTo see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eMCP (Model Context Protocol)\\u003c/strong\\u003e is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \\\"over 97 million monthly SDK downloads, 10,000 active servers,\\\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of \\u003ca href=\\\"/mcp-stateless-protocol-enterprise-authorization\\\"\\u003eMCP's stateless 2026-07-28 spec\\u003c/a\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-9\\\" id=\\\"user-content-fnref-9\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e4\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eA2A (Agent2Agent)\\u003c/strong\\u003e is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-4\\\" id=\\\"user-content-fnref-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e5\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-5\\\" id=\\\"user-content-fnref-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e6\\u003c/a\\u003e\\u003c/sup\\u003e If you want the hands-on version of how agents advertise capabilities and hand off work, our \\u003ca href=\\\"/a2a-protocol-python-tutorial\\\"\\u003eA2A protocol tutorial\\u003c/a\\u003e walks through it.\\u003c/p\\u003e\\n\\u003cp\\u003eHere is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in \\u003cem\\u003eyour\\u003c/em\\u003e organization needs to prove to an agent in \\u003cem\\u003esomeone else's\\u003c/em\\u003e organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-problems-the-framework-says-still-need-a-standard\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-problems-the-framework-says-still-need-a-standard\\\"\\u003eThe problems the framework says still need a standard\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \\\"not endorsed by the IETF\\\" and have \\\"no formal standing in the IETF standards process,\\\" and the early framework draft has already been superseded — the current document is \\u003ccode\\u003edraft-rosenberg-agentproto-usecases\\u003c/code\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-7\\\" id=\\\"user-content-fnref-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e8\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eWith that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-prompt-injection-is-the-security-test\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-prompt-injection-is-the-security-test\\\"\\u003eWhy prompt injection is the security test\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.\\u003c/p\\u003e\\n\\u003cp\\u003eIn a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as \\u003cstrong\\u003eLLM01 — the number-one risk\\u003c/strong\\u003e in its Top 10 for LLM Applications.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-8\\\" id=\\\"user-content-fnref-8\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e9\\u003c/a\\u003e\\u003c/sup\\u003e The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \\\"just use MCP and A2A\\\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-realistic-timeline--and-what-to-watch\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-realistic-timeline--and-what-to-watch\\\"\\u003eThe realistic timeline — and what to watch\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eSet expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-10\\\" id=\\\"user-content-fnref-10\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e10\\u003c/a\\u003e\\u003c/sup\\u003e Nothing shipped in Vienna this week. What the meeting could produce is a decision to \\u003cem\\u003estart\\u003c/em\\u003e, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.\\u003c/p\\u003e\\n\\u003cp\\u003eThe strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in \\u003ca href=\\\"/eu-android-ai-agent-interoperability-dma\\\"\\u003ethe EU's push for AI agent interoperability under the DMA\\u003c/a\\u003e.\\u003c/p\\u003e\\n\\u003cp\\u003eFor now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"faq\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#faq\\\"\\u003eFAQ\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003ch3 id=\\\"is-the-ietf-standardizing-ai-agent-protocols\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#is-the-ietf-standardizing-ai-agent-protocols\\\"\\u003eIs the IETF standardizing AI agent protocols?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eNot yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-10\\\" id=\\\"user-content-fnref-10-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e10\\u003c/a\\u003e\\u003c/sup\\u003e The authoritative outcome of the session is posted to the IETF Datatracker.\\u003c/p\\u003e\\n\\u003ch3 id=\\\"what-is-the-agentproto-bof-at-ietf-126\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-is-the-agentproto-bof-at-ietf-126\\\"\\u003eWhat is the agentproto BoF at IETF 126?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eAgentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch3 id=\\\"how-is-mcp-different-from-a2a\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#how-is-mcp-different-from-a2a\\\"\\u003eHow is MCP different from A2A?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eMCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-4\\\" id=\\\"user-content-fnref-4-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e5\\u003c/a\\u003e\\u003c/sup\\u003e They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-8\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch3 id=\\\"what-would-an-ietf-rfc-add-that-mcp-and-a2a-dont-cover\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-would-an-ietf-rfc-add-that-mcp-and-a2a-dont-cover\\\"\\u003eWhat would an IETF RFC add that MCP and A2A don't cover?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eThe framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-9\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\u003c/p\\u003e\\n\\u003ch3 id=\\\"why-is-prompt-injection-worse-in-multi-agent-systems\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-is-prompt-injection-worse-in-multi-agent-systems\\\"\\u003eWhy is prompt injection worse in multi-agent systems?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eBecause it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-10\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-8\\\" id=\\\"user-content-fnref-8-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e9\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003csection data-footnotes=\\\"\\\" class=\\\"footnotes\\\"\\u003e\\u003ch2 class=\\\"sr-only\\\" id=\\\"footnote-label\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#footnote-label\\\"\\u003eFootnotes\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003col\\u003e\\n\\u003cli id=\\\"user-content-fn-1\\\"\\u003e\\n\\u003cp\\u003e\\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). \\u003ca href=\\\"https://www.ietf.org/blog/ietf126-bofs/\\\"\\u003ehttps://www.ietf.org/blog/ietf126-bofs/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e4\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-5\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-5\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e5\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-6\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-6\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e6\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-7\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-7\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e7\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-2\\\"\\u003e\\n\\u003cp\\u003e\\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). \\u003ca href=\\\"https://www.ietf.org/process/bofs/\\\"\\u003ehttps://www.ietf.org/process/bofs/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2-4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e4\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-3\\\"\\u003e\\n\\u003cp\\u003e\\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). \\u003ca href=\\\"https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/\\\"\\u003ehttps://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-3-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 3-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-3-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 3-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-9\\\"\\u003e\\n\\u003cp\\u003e\\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. \\u003ca href=\\\"https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/\\\"\\u003ehttps://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-9\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-4\\\"\\u003e\\n\\u003cp\\u003e\\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. \\u003ca href=\\\"https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/\\\"\\u003ehttps://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 5\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-4-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 5-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-5\\\"\\u003e\\n\\u003cp\\u003e\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). \\u003ca href=\\\"https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html\\\"\\u003ehttps://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-5\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 6\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-6\\\"\\u003e\\n\\u003cp\\u003e\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: \\u003ca href=\\\"https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt\\\"\\u003ehttps://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt\\u003c/a\\u003e — status: \\u003ca href=\\\"https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/\\\"\\u003ehttps://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e4\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-5\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-5\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e5\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-6\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-6\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e6\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-7\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-7\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e7\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-8\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-8\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e8\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-9\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-9\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e9\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-10\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-10\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e10\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-7\\\"\\u003e\\n\\u003cp\\u003e\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). \\u003ca href=\\\"https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/\\\"\\u003ehttps://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-7\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 8\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-8\\\"\\u003e\\n\\u003cp\\u003e\\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. \\u003ca href=\\\"https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf\\\"\\u003ehttps://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-8\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 9\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-8-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 9-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-10\\\"\\u003e\\n\\u003cp\\u003e\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). \\u003ca href=\\\"https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm\\\"\\u003ehttps://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-10\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 10\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-10-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 10-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003c/ol\\u003e\\n\\u003c/section\\u003e\"])</script><script>self.__next_f.push([1,\"22:T3adb,\"])</script><script>self.__next_f.push([1,\"\\u003chtml\\u003e\\u003chead\\u003e\\u003c/head\\u003e\\u003cbody\\u003e\\u003cp\\u003e\\u003cstrong\\u003eIn one line:\\u003c/strong\\u003e At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eTL;DR:\\u003c/strong\\u003e For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"what-youll-learn\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-youll-learn\\\"\\u003eWhat you'll learn\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cul\\u003e\\n\\u003cli\\u003eWhat happened at the agentproto BoF at IETF 126, and what a \\\"Birds-of-a-Feather\\\" session actually decides\\u003c/li\\u003e\\n\\u003cli\\u003eWhy the IETF works by rough consensus rather than a vote — and why that framing matters here\\u003c/li\\u003e\\n\\u003cli\\u003eHow MCP and A2A differ, and the interoperability gap neither one closes\\u003c/li\\u003e\\n\\u003cli\\u003eThe specific problems the underlying framework draft says still need a standard\\u003c/li\\u003e\\n\\u003cli\\u003eWhy prompt injection is the security test any agent protocol standard has to pass\\u003c/li\\u003e\\n\\u003cli\\u003eThe realistic timeline from a BoF to a published RFC, and what to watch next\\u003c/li\\u003e\\n\\u003c/ul\\u003e\\n\\u003ch2 id=\\\"what-happened-at-the-agentproto-bof\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-happened-at-the-agentproto-bof\\\"\\u003eWhat happened at the agentproto BoF\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was \\u003cstrong\\u003eagentproto\\u003c/strong\\u003e (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThe IETF's own framing is precise: the past year produced \\\"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\\\" The agentproto session, it says, \\\"brings that conversation into the IETF,\\\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \\\"with a view toward chartering a Working Group to take that work forward.\\\"\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat phrase — \\u003cem\\u003echartering a Working Group\\u003c/em\\u003e — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-it-is-rough-consensus-not-a-vote\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-it-is-rough-consensus-not-a-vote\\\"\\u003eWhy it is rough consensus, not a vote\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eIt is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \\\"rough consensus and running code\\\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e A BoF that is \\\"working-group-forming,\\\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThis is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that \\u003cstrong\\u003ean IETF AI agent protocol standard\\u003c/strong\\u003e belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003eMCP vs A2A: two layers, one missing piece\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eTo see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eMCP (Model Context Protocol)\\u003c/strong\\u003e is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \\\"over 97 million monthly SDK downloads, 10,000 active servers,\\\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of \\u003ca href=\\\"/mcp-stateless-protocol-enterprise-authorization\\\"\\u003eMCP's stateless 2026-07-28 spec\\u003c/a\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-9\\\" id=\\\"user-content-fnref-9\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e4\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eA2A (Agent2Agent)\\u003c/strong\\u003e is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-4\\\" id=\\\"user-content-fnref-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e5\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-5\\\" id=\\\"user-content-fnref-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e6\\u003c/a\\u003e\\u003c/sup\\u003e If you want the hands-on version of how agents advertise capabilities and hand off work, our \\u003ca href=\\\"/a2a-protocol-python-tutorial\\\"\\u003eA2A protocol tutorial\\u003c/a\\u003e walks through it.\\u003c/p\\u003e\\n\\u003cdiv data-ad-placement=\\\"post-in-article-mid\\\" class=\\\"not-prose my-8\\\"\\u003e\\u003c/div\\u003e\\n\\n\\u003cp\\u003eHere is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in \\u003cem\\u003eyour\\u003c/em\\u003e organization needs to prove to an agent in \\u003cem\\u003esomeone else's\\u003c/em\\u003e organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-problems-the-framework-says-still-need-a-standard\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-problems-the-framework-says-still-need-a-standard\\\"\\u003eThe problems the framework says still need a standard\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \\\"not endorsed by the IETF\\\" and have \\\"no formal standing in the IETF standards process,\\\" and the early framework draft has already been superseded — the current document is \\u003ccode\\u003edraft-rosenberg-agentproto-usecases\\u003c/code\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-7\\\" id=\\\"user-content-fnref-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e8\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eWith that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-prompt-injection-is-the-security-test\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-prompt-injection-is-the-security-test\\\"\\u003eWhy prompt injection is the security test\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.\\u003c/p\\u003e\\n\\u003cp\\u003eIn a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as \\u003cstrong\\u003eLLM01 — the number-one risk\\u003c/strong\\u003e in its Top 10 for LLM Applications.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-8\\\" id=\\\"user-content-fnref-8\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e9\\u003c/a\\u003e\\u003c/sup\\u003e The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \\\"just use MCP and A2A\\\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-realistic-timeline--and-what-to-watch\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-realistic-timeline--and-what-to-watch\\\"\\u003eThe realistic timeline — and what to watch\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eSet expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-10\\\" id=\\\"user-content-fnref-10\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e10\\u003c/a\\u003e\\u003c/sup\\u003e Nothing shipped in Vienna this week. What the meeting could produce is a decision to \\u003cem\\u003estart\\u003c/em\\u003e, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.\\u003c/p\\u003e\\n\\u003cp\\u003eThe strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in \\u003ca href=\\\"/eu-android-ai-agent-interoperability-dma\\\"\\u003ethe EU's push for AI agent interoperability under the DMA\\u003c/a\\u003e.\\u003c/p\\u003e\\n\\u003cp\\u003eFor now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.\\u003c/p\\u003e\\n\\n\\n\\n\\n\\n\\n\\n\\n\\n\\n\\n\\u003c/body\\u003e\\u003c/html\\u003e\"])</script><script>self.__next_f.push([1,\"23:Tbf3,\"])</script><script>self.__next_f.push([1,\"Because it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.7 OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.9 Footnotes\\n\\n\\n\\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7\\n\\n\\n\\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/ ↩ ↩2 ↩3 ↩4\\n\\n\\n\\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/ ↩ ↩2 ↩3\\n\\n\\n\\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/ ↩\\n\\n\\n\\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/ ↩ ↩2\\n\\n\\n\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html ↩\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/ ↩\\n\\n\\n\\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf ↩ ↩2\\n\\n\\n\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm ↩ ↩2\"])</script><script>self.__next_f.push([1,\"25:T520e,\"])</script><script>self.__next_f.push([1,\"\\n## TL;DR\\n\\nOn April 28, 2026 Anthropic launched **Claude for Creative Work** — a coordinated release of nine creative-tool connectors, with the **Adobe for creativity** connector as the marquee partnership.[^1][^2][^3] The Adobe connector exposes **50+ pro-grade tools** across Photoshop, Lightroom, Illustrator, Firefly, Premiere, Express, InDesign, and Adobe Stock to Claude through the Model Context Protocol (MCP), letting users describe a creative outcome in chat and have Claude orchestrate the multi-step workflow across Adobe apps.[^2][^4]\\n\\nThe other eight connectors that shipped the same day cover Blender, Ableton Live, Autodesk Fusion, Splice, SketchUp, Affinity by Canva, and Resolume's Arena and Wire — turning Claude into an orchestration layer over the 2D, 3D, audio, and live-visual stacks creative pros already pay for.[^1][^5] Anthropic also launched programs with **RISD, Ringling College of Art and Design, and Goldsmiths, University of London** to put the connectors in front of art-school students and faculty.[^1][^6]\\n\\nFor Adobe, the release lands the day after the Firefly AI Assistant entered public beta on April 27, 2026 — back-to-back agentic-AI launches from Adobe in two weeks. For Anthropic, it is the most coordinated push yet to put Claude inside the daily software of professional creatives rather than asking them to come to claude.ai.[^7]\\n\\n## What You'll Learn\\n\\nBy the end of this article you will understand:\\n\\n- What the Adobe for creativity connector actually does and how it works under MCP\\n- The full list of nine creative connectors that shipped together\\n- How the connector's free, Adobe-account, and Claude-plan tiers stack\\n- How Anthropic's strategy compares with Adobe's own Firefly AI Assistant\\n- Why \\\"Claude orchestrating Photoshop\\\" is a different bet from \\\"Claude generating images\\\"\\n- What Claude Design — Anthropic's same-day Canva-exporting design product — adds to the picture\\n- What this means for image-generation incumbents like OpenAI and Midjourney\\n\\n---\\n\\n## What Adobe and Anthropic Actually Shipped\\n\\nOn April 28, 2026, Adobe and Anthropic jointly launched the **Adobe for creativity** connector inside Claude. Adobe published the announcement on its corporate blog the same day; Anthropic packaged the partnership inside a broader \\\"Claude for Creative Work\\\" launch covering nine connectors and three educational programs.[^1][^2]\\n\\nThe mechanic is straightforward. A user signs into Claude on the web, desktop, or mobile, opens the Connectors panel under Customize, finds **Adobe for creativity** in the directory, and installs it. Once enabled in a conversation, Claude can call any of the connector's exposed tools — read a Photoshop layer, generate a Firefly image, trim a Premiere clip, render an InDesign page — by emitting an [MCP tool call](/mcp-servers-explained-claudes-new-ai-backbone-for-real-automation). The user types a goal; Claude decides which Adobe tools to call, in what order, and with what parameters.[^2][^3][^4]\\n\\nThe set of exposed tools spans **eight Creative Cloud surfaces**:[^2][^3]\\n\\n| Adobe surface | Sample capability through the connector |\\n|---|---|\\n| Photoshop | Open files, read and edit layers, apply masks, run automated retouching |\\n| Illustrator | Vector edits, asset generation, format conversion |\\n| Lightroom | Photo organisation, presets, batch adjustments |\\n| Premiere | Clip operations and video formatting |\\n| Firefly | Generative image creation with Adobe's licensed-content models |\\n| Express | Quick template-driven design |\\n| InDesign | Page layout operations |\\n| Adobe Stock | Asset search and licensing |\\n\\nTotal tool count published by both vendors: **50+ pro-grade tools** behind the connector.[^2][^4] It is the same tool surface Adobe will eventually expose through its own [Firefly AI Assistant](https://blog.adobe.com/en/publish/2026/04/27/firefly-ai-assistant-public-beta), but with Claude — not Adobe's first-party agent — as the controller.\\n\\n## The Nine Connectors That Shipped Together\\n\\nAdobe got the headline, but eight other creative tools went live on April 28, 2026 alongside it. The full list:[^1][^5][^8]\\n\\n| Connector | What Claude can do with it |\\n|---|---|\\n| **Adobe for creativity** | Orchestrate 50+ Creative Cloud tools across Photoshop, Lightroom, Illustrator, Firefly, Premiere, Express, InDesign, and Stock |\\n| **Blender** | Natural-language interface to Blender's Python API; analyse scenes, batch-edit objects, add custom tools to the Blender UI |\\n| **Autodesk Fusion** | Create and modify 3D CAD models through conversation (requires a Fusion subscription) |\\n| **Ableton Live** | Grounded Q\\u0026A against the official Live and Push documentation |\\n| **Splice** | Search Splice's royalty-free sample catalogue from inside Claude |\\n| **SketchUp** | Use a chat session as the starting point for a 3D model, then open it in SketchUp for refinement |\\n| **Affinity by Canva** | Automate batch image adjustments, layer renaming, and file export across Affinity's unified Pixel, Vector, and Layout studios |\\n| **Resolume Arena** | Real-time natural-language control of live visuals for performance and AV production |\\n| **Resolume Wire** | Real-time natural-language control of Wire's node-based patches and effects, alongside Arena and Avenue |\\n\\nThat covers raster graphics (Adobe, Affinity), vector design (Adobe, Affinity), photo editing (Adobe, Affinity), 3D modelling (Blender, SketchUp, Autodesk Fusion), motion design (Adobe Premiere), audio production (Ableton, Splice), and live performance visuals (Resolume's pair) — essentially the bulk of the modern creative pro's toolchain in a single coordinated release.\\n\\nAnthropic also made a financial contribution to support continued work on Blender's Python API, which is what makes the Blender connector possible.[^1] Anthropic's contribution was initially structured as Blender Development Fund patronage, but Blender elected to receive it as a one-time donation instead — Anthropic's own announcement was updated on May 1, 2026 to reflect that change.[^1] And because the Blender integration is built on the open MCP protocol rather than as a Claude-exclusive plugin, it works with any other LLM that speaks MCP — a deliberate signal that Anthropic is prioritising ecosystem compatibility over lock-in.[^1]\\n\\n## Claude Design: The Other Product That Launched the Same Day\\n\\nLess covered, but bundled into the same April 28 announcement, is **Claude Design** — a new product from Anthropic Labs aimed at exploring ideas for software experiences. Claude Design lets users visualise options, iterate on them based on feedback, and **export the results to other tools, starting with Canva.**[^1]\\n\\nClaude Design is not a connector — it is a first-party Anthropic surface, in the same family as the Claude Code CLI. Its launch alongside the nine creative connectors makes the broader strategy clearer: Anthropic is building both an *orchestrator* over creative software (the connectors) and a *destination* for early-stage creative ideation (Claude Design), with Canva as the first export target on the destination side. That is a different bet from purely \\\"be the agent that runs Photoshop.\\\"\\n\\n## How the Free vs. Paid Tiers Actually Work\\n\\nThis is the part most coverage gets slightly wrong, because there are **two stacked subscriptions** in play — your Claude plan and your Adobe plan — and they interact in a non-obvious way.[^4][^9][^10]\\n\\n| What you have | What you get from the Adobe connector |\\n|---|---|\\n| Free Claude plan, no Adobe account (\\\"guest mode\\\") | About 40 free tools and two pre-built skills (**Retouch Portraits**, **Batch Edit Photos**) directly in chat |\\n| Free Claude plan + free Adobe ID | All six published skills, higher usage limits, work that persists across sessions |\\n| Free Claude plan + paid Creative Cloud | Same as above plus Creative Cloud storage and access to your existing assets |\\n| Paid Claude plan (Pro / Max / Team / Enterprise) + any Adobe state | Same connector behaviour as above; the Claude plan unlocks plugins generally and lifts Claude's own usage limits |\\n\\nA few things follow from that structure:\\n\\n- **The connector is genuinely usable for free.** You do not need a Creative Cloud subscription to invoke ~40 of the connector's tools and run two end-to-end skills. The free tier is more useful than the typical \\\"demo mode\\\" framing suggests.\\n- **An Adobe ID — even a free one — unlocks more.** Six skills, higher limits, persistent work. This is Adobe's hook to get Claude users into its identity stack.\\n- **A paid Creative Cloud account isn't strictly required to use the connector**, but it is required to read or write the assets in your Creative Cloud library and to use any feature that calls a paid Adobe service (e.g., generating high-resolution Firefly outputs at scale).\\n- **A paid Claude plan isn't required for connectors specifically**, but is required for Claude Plugins generally (Pro, Max, Team, or Enterprise) — and the Adobe connector itself is invoked the same way as any other directory connector.\\n\\nThe friction graph for a brand-new user: **install in 30 seconds on a free Claude account → get ~40 free Adobe tools immediately**. That is dramatically less friction than installing Photoshop on a desktop.\\n\\n## How Each Specialised Connector Differs\\n\\nThe connectors are not all identical wrappers around a backend. Three different patterns showed up in the launch documentation:[^1][^5][^8]\\n\\n- **Tool wrappers** — Adobe for creativity, Affinity by Canva, Resolume Arena, Resolume Wire. Each tool the host app exposes becomes an MCP tool Claude can call. Claude does the orchestration; the host app does the work.\\n- **API bridges** — Blender's connector exposes Blender's Python API to Claude as a natural-language layer. Claude can write and run Python in your Blender session, which is much more open-ended than a fixed tool list.\\n- **Documentation-grounded chat** — Ableton Live's connector grounds Claude's answers in official Live and Push documentation rather than letting Claude actually drive the DAW. Useful for \\\"how do I sidechain compress in Live?\\\" not for \\\"produce me a track.\\\"\\n\\nThe split matters because it tells you what each tool's parent company was willing to expose. Blender (open source, owned by the Blender Foundation) gave Claude a Python API — the maximum surface. Adobe (publicly traded, with a large licensed-content liability) gave Claude a curated set of 50+ tools and a permission gate. Ableton (privately held, smaller engineering team) shipped a documentation grounder. The technical surface is partly a strategy signal.\\n\\n## Adobe + Claude vs. Adobe Firefly AI Assistant\\n\\nAdobe's own Firefly AI Assistant entered public beta on **April 27, 2026** — exactly one day before the Claude connector launched.[^7] The two products solve overlapping problems:\\n\\n| Capability | Firefly AI Assistant | Adobe for creativity (Claude) |\\n|---|---|---|\\n| Where you live | Adobe's Firefly app and Creative Cloud surfaces | Claude (web, desktop, mobile, Cowork) |\\n| Underlying agent | Adobe's first-party \\\"creative agent\\\" | Anthropic's Claude (any model the user has access to) |\\n| Integration depth | Native — built by Adobe | MCP connector — vended by Adobe, executed by Claude |\\n| Available outside Adobe stack | No | Yes — Claude can also call your other 50+ directory connectors in the same chat |\\n| Account needed | Adobe account required | Adobe account optional (~40 free tools without one) |\\n| Public beta / GA | Public beta, April 27, 2026 | Live globally, April 28, 2026 |\\n\\nIf you live inside Creative Cloud all day, Firefly AI Assistant is the more obvious entry point — it shares Adobe's UI conventions and your asset library is already there. If you live in Claude or you need Adobe to be one tool in a longer chain (e.g., pull a transcript from Granola, summarise it, generate a thumbnail in Firefly, post it through your Slack connector), the Claude-side connector is structurally better. The two products are not direct competitors so much as the same underlying capability fronted by two different agents.\\n\\nThe interesting framing: Adobe shipped both. The same week they launched their own creative agent, they also gave Anthropic the keys. That signals Adobe sees agentic AI as the new application surface and wants to be present on every meaningful agent — including the ones it does not own.\\n\\n## What This Says About Anthropic's Strategy\\n\\nAnthropic's framing at launch was deliberate. The Anthropic page is titled *Claude for Creative Work*, and the lede is a quote that explicitly disclaims replacement: \\\"Claude can't replace taste or imagination, but it can open up new ways of working.\\\"[^1][^11]\\n\\nThe strategic move under the marketing language is more pointed. Three things are happening at once:\\n\\n1. **MCP is becoming the application layer.** Nine partner connectors ship simultaneously, all using the same protocol. That makes \\\"MCP-native\\\" a real procurement category for Adobe, Autodesk, and Ableton — not a research project.\\n2. **Connectors compose.** The same Claude conversation that runs Photoshop can also call your Slack, Notion, Gmail, and Linear connectors — and even task-routing agents like [Claude Managed Agents](/claude-managed-agents-deploy-ai-agents-faster). Adobe's own Firefly AI Assistant is locked inside Adobe; Claude's Adobe connector is composable with the rest of the user's working stack.\\n3. **The educational beachhead is real.** Putting connectors in front of RISD, Ringling, and Goldsmiths students is how you train a generation of creatives whose default reach is \\\"ask Claude to do it in Photoshop\\\" rather than \\\"open Photoshop.\\\" Anthropic is buying the muscle memory of the next cohort.[^1][^6]\\n\\nThis is not a feature drop. It is Anthropic positioning Claude as the orchestration layer over the creative software industry, with Adobe — historically the most defensive incumbent in the category — willingly contributing the most strategically valuable surface area.\\n\\n## What It Means for Image-Generation Incumbents\\n\\nThe Claude + Adobe play sits oddly on top of the consumer image-generation market. OpenAI's GPT Image 2 (now [available in Adobe Firefly](https://news.adobe.com/news/2026/04/adobe-new-creative-agent) alongside Google's Nano Banana 2, Veo 3.1, Runway's Gen-4.5, and several others), Midjourney, and Stability all live in a different shape: they generate pixels from prompts.[^7]\\n\\nThe Adobe-for-Claude connector does not replace those models. It replaces the **manual labour** of running them inside Adobe's editors:\\n\\n- The connector reads a layered Photoshop document and asks Firefly (or whatever is configured) to fill in a missing element.\\n- The connector applies a Lightroom preset to 200 photos in batch via natural language instead of clicking.\\n- The connector pulls a stock image from Adobe Stock, places it in an InDesign layout at the right size, and exports a PDF.\\n\\nThese are workflows where the value-add is **knowing which tool to use at which step**, not which generative model produces the prettiest image. That is a different ceiling. Generative model leaderboards plateau quickly; orchestration leaderboards depend on integration depth, which is exactly what 50+ Adobe tools through MCP delivers.\\n\\n## FAQ\\n\\n**Q: Do I need a paid Adobe Creative Cloud account to use the connector?**\\nA: No. Guest mode gives you about 40 free tools and two skills (Retouch Portraits, Batch Edit Photos) without any Adobe account. Signing in with a free Adobe ID unlocks all six skills and higher limits. A paid Creative Cloud subscription adds storage and access to your existing assets.[^4][^9]\\n\\n**Q: Do I need a paid Claude plan?**\\nA: Not for the connector itself — directory connectors work on the free Claude plan. A paid plan (Pro, Max, Team, Enterprise) is required for Claude Plugins generally and for higher Claude usage limits.[^10]\\n\\n**Q: How does this differ from Adobe's own Firefly AI Assistant?**\\nA: Firefly AI Assistant is Adobe's first-party creative agent, launched in public beta on April 27, 2026, and it lives inside Adobe's surfaces. The Adobe for creativity connector is the same kind of orchestration surface but executed by Claude on Anthropic's side, which means it composes with all your other Claude connectors.[^7]\\n\\n**Q: Is this built on MCP?**\\nA: Yes. Adobe for creativity is implemented as a Model Context Protocol connector that Claude can install from its Connectors directory.[^4][^9]\\n\\n**Q: What other creative tools shipped Claude connectors the same day?**\\nA: Eight more, for a total of nine: Adobe Creative Cloud, Blender, Autodesk Fusion, Ableton Live, Splice, SketchUp, Affinity by Canva, Resolume Arena, and Resolume Wire.[^1][^5][^8]\\n\\n**Q: Can the connector use my existing Photoshop documents and Creative Cloud library?**\\nA: Yes, but only if you sign in with an Adobe account that has access to those assets. Without an Adobe account you are working inside a guest sandbox.[^4][^9]\\n\\n**Q: What's Anthropic's educational angle here?**\\nA: Three programs at launch: Art and Computation at RISD, Fundamentals of AI for Creatives at Ringling, and the MA/MFA Computational Arts program at Goldsmiths. Students and faculty get access to Claude and the new connectors and feed back into product direction.[^1][^6]\\n\\n## Bottom Line\\n\\nThe Adobe for creativity connector for Claude does not generate prettier images than the existing image-gen models. What it does is much more strategically loaded: it puts the entire Adobe Creative Cloud tool surface — 50+ pro-grade operations across eight applications — behind a single Claude prompt, on the same protocol that runs your Slack, Notion, and Linear connectors. The other eight connectors that shipped the same day do the same for Blender, Ableton, Autodesk Fusion, Splice, SketchUp, Affinity, and Resolume.\\n\\nFor working creatives, the most useful tier is the most surprising: a free Claude account plus a free Adobe ID gets you all six skills and persistent work, with no Creative Cloud subscription required. For Adobe, the bet is that being present on every meaningful agent — including the ones it does not own — is more valuable than locking customers into Firefly AI Assistant. For Anthropic, this is the clearest statement yet that Claude is meant to be the orchestration layer over the working software stack, not a destination of its own.\\n\\nThe most consequential line in the whole launch is not in any spec sheet. It is the educational programs at RISD, Ringling, and Goldsmiths. The students learning to ship creative work in 2026 will reach for \\\"ask Claude to do it\\\" as a first instinct. That is a long bet, but it is the kind of bet that has actually moved the centre of gravity of software in past decades — and in this round, it lands with Adobe quietly opening the door.\\n\\n---\\n\\n[^1]: [Claude for Creative Work — Anthropic (April 28, 2026)](https://www.anthropic.com/news/claude-for-creative-work)\\n\\n[^2]: [Adobe for creativity: a new way to create with Adobe, now in Claude — Adobe Blog (April 28, 2026)](https://blog.adobe.com/en/publish/2026/04/28/adobe-for-creativity-connector)\\n\\n[^3]: [Anthropic releases 9 Claude connectors for creative tools, including Blender and Adobe — 9to5Mac](https://9to5mac.com/2026/04/28/anthropic-releases-9-new-claude-connectors-for-creative-tools-including-blender-and-adobe/)\\n\\n[^4]: [Adobe for Creativity available in Claude — Adobe Developer documentation](https://developer.adobe.com/adobe-for-creativity/)\\n\\n[^5]: [Claude Connectors for Creative Tools: All 9 Explained (2026) — Build Fast With AI](https://www.buildfastwithai.com/blogs/claude-connectors-creative-tools-2026)\\n\\n[^6]: [Anthropic unveils \\\"Claude for Creative Work,\\\" expanding AI into professional creative tools — Neowin](https://www.neowin.net/news/anthropic-unveils-claude-for-creative-work-expanding-ai-into-professional-creative-tools/)\\n\\n[^7]: [Firefly AI Assistant now available in public beta — Adobe Blog (April 27, 2026)](https://blog.adobe.com/en/publish/2026/04/27/firefly-ai-assistant-public-beta)\\n\\n[^8]: [Anthropic Claude Now Connects With Affinity, Adobe, and Other Creator Solutions — Thurrott.com](https://www.thurrott.com/a-i/anthropic/335498/anthropic-claude-now-connects-with-affinity-adobe-and-other-creator-solutions)\\n\\n[^9]: [Adobe for Creativity — Getting started — Adobe Developer documentation](https://developer.adobe.com/adobe-for-creativity/getting-started/)\\n\\n[^10]: [Use connectors to extend Claude's capabilities — Claude Help Center](https://support.claude.com/en/articles/11176164-use-connectors-to-extend-claude-s-capabilities)\\n\\n[^11]: ['Claude can't replace taste or imagination, but it can open up new ways of working': Anthropic signs up Adobe, Blender and more — TechRadar](https://www.techradar.com/pro/claude-cant-replace-taste-or-imagination-but-it-can-open-up-new-ways-of-working-anthropic-signs-up-adobe-blender-and-more-to-push-claude-into-creative-work)\\n\"])</script><script>self.__next_f.push([1,\"26:T3c03,\"])</script><script>self.__next_f.push([1,\"\\n## TL;DR\\n\\nOn April 8, 2026, Anthropic launched **Claude Managed Agents** in public beta — a hosted platform that handles sandboxing, state management, tool execution, and error recovery so developers can ship autonomous AI agents in days instead of months. Pricing follows standard Claude API token rates plus **$0.08 per active session-hour**. Early adopters include Notion, Rakuten, Asana, Sentry, and Vibecode, with Allianz deploying custom agents across insurance operations. The architecture separates sessions, harnesses, and sandboxes into independent components — a design Anthropic says cut time-to-first-token by roughly 60% at P50.[^1][^2]\\n\\n---\\n\\n## What You'll Learn\\n\\n- What Claude Managed Agents is and the problem it solves\\n- How the session–harness–sandbox architecture works under the hood\\n- Pricing breakdown and what \\\"active session-hour\\\" means\\n- Which companies are already using it and for what\\n- How Managed Agents compares to OpenAI Agents SDK, Google ADK, and open-source frameworks\\n- What features are still in research preview and when to expect them\\n\\n---\\n\\n## The Problem: Agent Infrastructure Is Expensive to Build\\n\\nBuilding a production AI agent requires more than a good model. Developers need secure sandboxing, credential management, long-running session persistence, error recovery, tool orchestration, and tracing — infrastructure that typically takes months to build and maintain.[^1]\\n\\nIndustry analysis suggests that enterprises consistently underestimate the infrastructure investment required for production agent deployments — often by 40–60% relative to the agent development cost itself. Observability, identity management, and integration layers consume more resources than the agent implementation.[^3]\\n\\nClaude Managed Agents addresses this gap directly: it is a hosted service in the Claude Platform that runs long-horizon agents on your behalf through a small set of APIs.[^1]\\n\\n---\\n\\n## How Managed Agents Works\\n\\n### Core Concepts\\n\\nThe platform is built around four primitives:[^4]\\n\\n**Agent** — the model (currently Claude models only), system prompt, tools, MCP servers, and skills that define what the agent can do.\\n\\n**Environment** — a configured container template specifying pre-installed packages (Python, Node.js, Go, and others), network access rules, and mounted files.\\n\\n**Session** — a running agent instance performing a specific task within an environment, generating outputs that persist even through disconnections.\\n\\n**Events** — messages exchanged between your application and the agent, including user turns, tool results, and status updates. Events stream back via server-sent events (SSE).[^4]\\n\\n### The Brain-and-Hands Architecture\\n\\nUnder the hood, Anthropic's engineering team decoupled the agent into three independent components inspired by operating system design — what they call \\\"virtualizing the components of an agent.\\\"[^2]\\n\\n**Session (the state)** stores an append-only event log durably, independent of the harness or sandbox. If the harness crashes, no work is lost because the session persists outside it. Developers can query the event log with positional slices — picking up from the last read point, rewinding to see the lead-up to a decision, or re-reading context before taking action.[^2]\\n\\n**Harness (the brain)** is a stateless orchestration layer. It calls Claude, routes tool results, and manages context transformations. Because it is stateless, it can be replaced instantly: a crash is caught as a tool-call error, a new harness wakes with `wake(sessionId)`, and execution resumes from the last event.[^2]\\n\\n**Sandbox (the hands)** is the execution environment where code runs, files are edited, and tools are invoked. Sandboxes are provisioned on demand via a `provision({resources})` call and are treated as disposable — replaced rather than repaired. Each tool is exposed through a uniform `execute(name, input) → string` interface, whether it is a container, an MCP server, or a custom integration.[^2]\\n\\nThis separation matters for performance. In Anthropic's original coupled design, the session, harness, and sandbox lived inside a single container. When it failed, the session was lost. After decoupling, P50 time-to-first-token dropped roughly 60%, and P95 dropped over 90% — because inference no longer waits for container startup.[^2]\\n\\n### Security Boundaries\\n\\nCredentials never reach the code-execution sandbox. Git tokens are injected during initialization but remain unavailable to generated code. OAuth tokens sit in a secure vault, accessed only through an MCP proxy that maps the session token to the right credentials. Claude never sees raw authentication material.[^2]\\n\\n---\\n\\n## Built-In Tools and MCP Support\\n\\nManaged Agents gives Claude access to several built-in tool categories:[^4]\\n\\n**Bash** — shell commands run inside the container. **File operations** — read, write, edit, glob, and grep across the container's file system. **Web search and fetch** — search the web and retrieve content from URLs. **MCP servers** — connect to any external tool provider using the Model Context Protocol.\\n\\nMCP integration is handled through a dedicated proxy. The proxy fetches authentication from the vault, calls the MCP server, and returns results — all without the agent or sandbox ever seeing raw credentials.[^2]\\n\\nThis tool-use-first design means any custom tool, any MCP server, and any Anthropic-provided tool looks identical to the harness: a name and input go in, a string comes back.[^2]\\n\\n---\\n\\n## Pricing\\n\\nClaude Managed Agents follows a consumption model:[^1]\\n\\nStandard Claude Platform token rates apply (the same rates you pay for the Messages API). On top of that, there is a **$0.08 per session-hour** charge for active runtime. \\\"Active\\\" means the session is processing work — idle sessions do not accrue charges. When agents perform web searches through the platform, Anthropic charges **$10 per 1,000 searches** on top of model usage costs.[^5]\\n\\nFor context: an agent running Claude Sonnet 4.6 for one hour of active work would cost roughly $0.08 in session fees plus whatever token costs the task generates. This compares to the alternative of provisioning, securing, and maintaining your own container infrastructure — which Anthropic argues costs orders of magnitude more when accounting for engineering time.[^1]\\n\\n---\\n\\n## Who Is Already Using It\\n\\nSeveral high-profile companies are building on Managed Agents:[^1]\\n\\n**Notion** launched Custom Agents publicly in February 2026 and is now integrating Claude Managed Agents into the platform (currently in private alpha) for code shipping and content creation workflows. **Rakuten** deploys enterprise agents across product, sales, marketing, and finance teams via Slack and Microsoft Teams. **Asana** has integrated AI Teammates — collaborative agents that work within Asana projects. **Sentry** built a debugging agent that pairs with patch-writing and PR-opening capabilities. **Vibecode** reports that Managed Agents enables customers to deploy applications ten times faster.[^1]\\n\\nBeyond these, **Allianz** — the global insurance conglomerate — signed a partnership with Anthropic in January 2026 that includes building custom AI agents for multistep workflows with a human in the loop, deploying Claude Code for all technical teams, and implementing an AI logging system for regulatory transparency.[^6]\\n\\n---\\n\\n## Research Preview Features\\n\\nTwo capabilities launched in research preview, requiring a separate access request:[^1]\\n\\n**Multi-agent coordination** — an orchestrator agent can spawn and coordinate multiple sub-agents in parallel, with Managed Agents handling communication and state sharing between them.\\n\\n**Outcomes (self-evaluation)** — developers define success criteria for a task, and Claude self-evaluates and iterates until it meets them, adding a goal-directed quality-control loop to the agent pipeline. In Anthropic's internal testing on structured file generation, Outcomes improved task success by up to 10 points over a standard prompting loop, with the largest gains on the hardest problems.[^1]\\n\\nAnthropic has not announced a timeline for graduating these features to general availability. Persistent memory tooling was not part of the April 8 launch — Anthropic added it as a separate public-beta feature on April 23, 2026, roughly two weeks later.[^9]\\n\\n---\\n\\n## How It Compares to Alternatives\\n\\nThe [agentic AI landscape](/mastering-agent-orchestration-patterns-from-theory-to-production) in 2026 offers several paths to building production agents. Here is how they differ:[^7][^8]\\n\\n**Claude Managed Agents** is a fully hosted service. Developers define an agent, point it at an environment, and start sessions. The platform handles orchestration, sandboxing, and recovery. The trade-off is model lock-in: only Claude models run in the harness. If you later want to switch models, you rebuild the orchestration layer.[^7]\\n\\n**OpenAI Agents SDK** takes an open-source, code-first approach. Its core abstraction is the handoff — agents transfer control to each other explicitly, carrying conversation context through the transition. A working multi-agent system can be defined in under twenty lines of Python. The SDK supports non-OpenAI models through custom providers, though it is optimized for OpenAI's own models.[^8]\\n\\n**Google Agent Development Kit (ADK)** provides a hierarchical agent tree with deep integration into Google Cloud (Vertex AI Agent Engine) and Google's search infrastructure. Its differentiator is grounding — agents can search Google in real time and base responses on cited information, which addresses hallucination at the infrastructure level.[^8]\\n\\n**LangGraph** leads on production maturity among open-source frameworks, with built-in checkpointing, time-travel debugging, and LangSmith integration for observability. It supports any model but requires learning its graph abstraction — expect one to two weeks before a team is productive.[^7]\\n\\n**CrewAI** offers the lowest barrier to entry with a role-based DSL and processes over 12 million executions per day as of early 2026. It has raised $18 million in funding led by Insight Partners and reports 60% Fortune 500 adoption.[^7]\\n\\nThe key distinction is hosted versus self-managed. Managed Agents eliminates infrastructure work but binds you to Claude. The SDKs and frameworks give you flexibility but require you to build and maintain the operational layer yourself.\\n\\n---\\n\\n## What This Means for Developers\\n\\nClaude Managed Agents represents Anthropic's bet that most teams building [AI agents](/ai-agents-the-next-frontier-in-software-development) do not want to be in the infrastructure business. The platform absorbs the operational complexity — sandboxing, permissions, state management, error recovery — and exposes a clean API surface.\\n\\nFor teams already building on [Claude Code](/mastering-claude-code-a-complete-hands-on-tutorial-guide) or the Claude Agent SDK, Managed Agents provides a natural upgrade path to production deployment. For teams evaluating the [MCP ecosystem](/mcp-servers-explained-claudes-new-ai-backbone-for-real-automation), the platform's first-class MCP support means existing MCP servers plug in without modification.\\n\\nThe $0.08-per-session-hour pricing is aggressive enough that many teams will find it cheaper than maintaining their own agent infrastructure, especially when factoring in engineering time for security, recovery, and scaling.\\n\\nThe open question is whether model lock-in matters. In a landscape where the performance gap between frontier models narrows with each release, betting your agent infrastructure on a single provider is a real trade-off. Anthropic is clearly betting that Claude's capabilities — extended thinking, computer use, and deep MCP integration — are compelling enough to justify it.[^8]\\n\\n---\\n\\n## Getting Started\\n\\nClaude Managed Agents is available today in public beta. To start building, you need a Claude API key and the `managed-agents-2026-04-01` beta header on all requests (the SDK sets this automatically). The service is enabled by default for all API accounts — no waitlist required for the core platform.[^4]\\n\\nMulti-agent coordination, memory, and outcomes (self-evaluation) require a separate access request through Anthropic's form.[^4]\\n\\n---\\n\\n## Frequently Asked Questions\\n\\n**What models does Claude Managed Agents support?**\\nCurrently, only Claude models run in the Managed Agents harness. This includes Claude Sonnet 4.6, Claude Opus 4.6, and Claude Haiku 4.5.[^4]\\n\\n**Can I use my existing MCP servers?**\\nYes. MCP servers connect through the platform's proxy layer, which handles authentication via a secure vault. Existing MCP servers work without modification.[^2][^4]\\n\\n**What happens if a session crashes?**\\nSessions persist independently of the harness and sandbox. If either component fails, a new instance boots and resumes from the last event in the session log. No work is lost.[^2]\\n\\n**Is there a free tier?**\\nNo dedicated free tier has been announced. Standard Claude API pricing applies, plus the $0.08 per active session-hour. Anthropic provides usage credits for new API accounts, which can be used for Managed Agents.[^4]\\n\\n**How does this relate to Claude Code?**\\nClaude Code is a CLI tool for agentic coding on your local machine. Managed Agents is a cloud-hosted platform for deploying agents at scale. They share the same underlying model capabilities but serve different use cases — local development versus production deployment.[^1]\\n\\n---\\n\\n## Bottom Line\\n\\nClaude Managed Agents is Anthropic's infrastructure play for the agentic AI era. By handling sandboxing, state management, and tool execution as a managed service, it removes the primary barrier that keeps most agent prototypes from reaching production. The brain-and-hands architecture is technically sound, the early customer list is strong, and the $0.08-per-session-hour pricing undercuts the true cost of self-hosted alternatives. The trade-off is model lock-in — a bet that Claude's capabilities justify the commitment. For teams already in the Anthropic ecosystem, this is a straightforward upgrade. For everyone else, it is a compelling argument to evaluate one.\\n\\n---\\n\\n[^1]: Anthropic, \\\"Claude Managed Agents: get to production 10x faster,\\\" claude.com/blog/claude-managed-agents, April 8, 2026.\\n[^2]: Anthropic Engineering, \\\"Scaling Managed Agents: Decoupling the brain from the hands,\\\" anthropic.com/engineering/managed-agents, April 2026.\\n[^3]: Industry analysis from LangChain's \\\"State of Agent Engineering\\\" survey and related enterprise infrastructure reports, 2026.\\n[^4]: Anthropic, \\\"Claude Managed Agents overview,\\\" platform.claude.com/docs/en/managed-agents/overview, April 2026.\\n[^5]: Anthropic pricing documentation, platform.claude.com/docs/en/about-claude/pricing, accessed April 2026.\\n[^6]: Allianz, \\\"Allianz and Anthropic forge global partnership to advance responsible AI in insurance,\\\" allianz.com, January 9, 2026.\\n[^7]: Multiple sources including Composio, Gurusup, and MorphLLM framework comparisons, April 2026.\\n[^8]: Composio, \\\"Claude Agents SDK vs. OpenAI Agents SDK vs. Google ADK,\\\" composio.dev, April 2026.\\n[^9]: Anthropic, \\\"Built-in memory for Claude Managed Agents,\\\" claude.com/blog/claude-managed-agents-memory, April 23, 2026.\\n\"])</script><script>self.__next_f.push([1,\"27:T5134,\"])</script><script>self.__next_f.push([1,\"\\n# Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\n\\n**In one line:** Pinecone Nexus is a \\\"knowledge engine\\\" for AI agents that compiles an enterprise's scattered data into structured, pre-built artifacts agents query in one step — moving reasoning and token spend out of the per-query retrieval loop that defines RAG and into a one-time curation stage.[^1][^3]\\n\\n**TL;DR:** On July 1, 2026, Pinecone — the vector-database company that, by its own account, \\\"defined RAG as a standard pattern\\\" — moved Pinecone Nexus into public preview, nearly two months after opening early access.[^1][^3] Nexus reframes the problem: rather than letting an agent search, retrieve, and reassemble context on every task, it compiles a company's knowledge into typed artifacts ahead of time and serves them through a declarative query language called KnowQL.[^1][^2] Benchmarks published by Pinecone and by customers evaluating it during early access show large accuracy and token-cost gains over agentic RAG on bounded document corpora.[^2][^3] The framing in the trade press — that \\\"the RAG era is ending\\\" — is louder than the evidence: Nexus targets bounded corpora, none of the numbers have been independently reproduced, and the more defensible reading is that retrieval is bifurcating, not dying.[^5][^6][^7]\\n\\n## What you'll learn\\n\\n- What Pinecone actually announced across May and July 2026, and what \\\"public preview\\\" does and does not mean\\n- What a \\\"knowledge engine\\\" is, and how it differs from RAG and from a vector database\\n- How Nexus is put together — Connectors, Workspaces, Contexts, Manifests, and KnowQL\\n- The specific numbers Pinecone is pointing to, including the ones it leads with, and why the \\\"vendor benchmark\\\" label matters\\n- Whether RAG is actually \\\"dead\\\" — the evenhanded version, with the counterarguments\\n- What this means if you are building agents right now\\n\\n## What Pinecone actually announced\\n\\nNexus arrived on May 4, 2026 in a pair of same-day posts: a company-level launch announcement from Ash Ashutosh and Edo Liberty introducing Nexus and its query language KnowQL, and an engineering deep dive from Jeff Zhu and Siva Ragavan bluntly titled \\\"Better Models Won't Save Your Agent.\\\"[^1][^2] At that point it was early access only, open to a limited set of design partners.[^2] On July 1, 2026, Pinecone opened Nexus to public preview, telling anyone with a business use case they could request access.[^3] Public preview is not general availability: access is still request-gated, and the production deployment path is a separate request.[^3]\\n\\nThe pitch behind the product is a diagnosis, and Pinecone states it aggressively. Frontier models, the company argues, are rarely the limiting factor; the reasoning step is usually fine. What breaks is everything before it. An agent gets a task, searches, retrieves, evaluates, decides it needs more, searches again, and loops — and by the time it can answer, most of the token and latency budget is gone.[^2] Pinecone puts a number on it, claiming that \\\"roughly 85% of an agent's effort is spent on knowledge retrieval,\\\" with task completion rates \\\"stuck at 50–60%,\\\" and it dismisses retrieval-at-inference as \\\"the 'ten blue links' era of agentic retrieval.\\\"[^1] That last line is the one the trade press seized on.[^5]\\n\\nThe discipline Pinecone is invoking has a name: *context engineering*, which it describes as shaping data into knowledge the model can use, instead of asking the agent to reassemble it from raw data at query time.[^2][^8] Nexus is Pinecone's bet on productizing it.\\n\\n## What a \\\"knowledge engine\\\" is\\n\\nIn Pinecone's framing, a knowledge engine \\\"compiles an enterprise's distributed knowledge into a structured layer agents can query directly, shifting token spend out of the per-query retrieval loop and into a one-time curation step.\\\"[^3] The contrast it is drawing is with retrieval-augmented generation. Classic RAG solves a specific problem well: give a language model access to external knowledge at inference time by retrieving relevant document chunks. That worked because early use cases were request-response — a user asks, the system retrieves, the model answers.[^2]\\n\\nAgent workloads break that assumption. A single agent task can touch dozens of documents across years and departments, and standard chunk-and-retrieve either misses facts that are not co-located or burns the budget looping to reassemble them.[^2][^3] A knowledge engine moves that assembly work upstream. Instead of handing the agent chunks and asking it to stitch an answer together, Nexus pre-shapes source data into *artifacts* — typed, governed pieces of information built for a specific task — so the agent reads a mostly-finished answer rather than reconstructing one.[^2]\\n\\nPinecone's own formulation is that Nexus is \\\"a knowledge engine, not a retrieval system,\\\" and the distinction it wants is with inference-time retrieval, not with vector search as such.[^1] It is not retiring its vector index: the company says plainly that \\\"the Pinecone vector database is the foundation; vector primitives and their management remain essential,\\\" and Nexus runs on the retrieval substrate Pinecone has spent years building.[^1][^2] The layer sits above search, aimed at a third kind of knowledge that neither model weights nor vector search captures well — business context, \\\"what a three-year employee knows without searching,\\\" scattered across contracts, wikis, HR docs, meeting notes, support tickets, and financial records.[^3]\\n\\nIs any of this new? Pinecone answers both ways in the same week. The engineering post concedes that \\\"knowledge graphs, entity catalogs, and semantic layers have existed for decades\\\" and that the hard part was never the concept but operationalizing it per domain — while its own section heading insists this is \\\"a new category, not a better pipeline,\\\" and the launch post claims a knowledge engine that moves reasoning from retrieval to curation \\\"did not exist until today.\\\"[^1][^2] The honest read is that the instinct is old and the packaging is new.\\n\\n## Inside Nexus: Manifests, Contexts, and KnowQL\\n\\nIn the public-preview build, the moving parts are organized like this.[^3] **Connectors** handle ingestion; local file upload, Box, and Microsoft OneLake are live, with Google Drive, Slack, GitHub, Notion, Confluence, and S3 described as close behind.[^3][^4] A **Workspace** is the top-level container, one per team or business unit that owns its own data sources and access controls. Inside a Workspace, data is organized into **Contexts** — one per dataset or knowledge domain.[^3]\\n\\nThe most interesting design choice is the **Manifest**. A Manifest is a blueprint that tells Nexus how to turn raw documents into structured knowledge artifacts tuned to a domain, and it is meant to be authored by a subject-matter expert rather than a retrieval engineer.[^3] The patent attorney who knows how patent standards are organized, or the M\\u0026A analyst who knows which document categories to cross-reference, designs the artifact types and relationships before any query runs. The agent then inherits that understanding instead of rediscovering the corpus structure on every call.[^3] This is a real shift in emphasis from May: the launch materials led with an autonomous \\\"context compiler\\\" — a coding agent that iterates on curation and query code against an eval set — whereas the public-preview messaging centers the human-in-the-loop Manifest, with re-curation as the answer to what Pinecone calls knowledge drift.[^1][^2][^3]\\n\\nWork runs as **Tasks** — import, curate, and search — inside isolated sandboxes, and everything is queried through **KnowQL** (Knowledge Query Language), the single interface agents talk to.[^2][^3] The declarative design is the point: like SQL, the agent states what answer it needs, in what shape, and with what constraints, and the engine decides which contexts to search and which artifacts to compose.[^1][^2] Pinecone's two May posts describe its surface slightly differently — the engineering post organizes a query into four categories (intent, filter, provenance, and a control budget), while the launch post advertises six core primitives, adding output shape and confidence.[^1][^2] Either way the ambition is explicit: Pinecone wants KnowQL to be a shared interface rather than a private one, and it has LangChain and Teradata publicly signed up to help advance it.[^1] That ambition has an obvious hurdle, as The New Stack put it: \\\"KnowQL has to clear the standardization bar SQL cleared, and standards do not get declared into existence by a single vendor.\\\"[^5]\\n\\nFor production, Pinecone points to a bring-your-own-cloud deployment where the cluster runs in the customer's own VPC and, the company says, documents never leave the customer's infrastructure. That deployment is request-gated, and as of the May launch Pinecone described BYOC support for Nexus specifically as coming \\\"very soon.\\\"[^1][^3]\\n\\n## The numbers Pinecone is pointing to\\n\\nPinecone leads with headline figures: task completion rates above 90%, \\\"30x faster time-to-completion,\\\" and up to 90% less token spend.[^1] The trade press repeated them, though not uncritically. Reviewing the completion-rate and token-spend claims, The New Stack wrote: \\\"Take this claim with a grain of salt until production teams confirm\\\" — while arguing that Pinecone's structural case \\\"does not need the numbers to hold.\\\"[^5] Everything below is either Pinecone's own benchmark or a customer evaluation conducted during early access. None of it has been independently reproduced.\\n\\nPinecone's named internal benchmark, KRAFTBench, pits Nexus against an agentic-RAG pipeline and a sandboxed coding agent on 493 free-form 10-K filings (about 245MB) from S\\u0026P 500 companies, asking 150 hard financial questions with a 120-second, one-million-token budget each.[^2] Pinecone reports Nexus completing every question at 22.7 seconds average latency and about 6,700 tokens per task, versus 37.9 seconds and roughly 49,000 tokens for agentic RAG, and 84.1 seconds and about 528,000 tokens for the coding agent, which finished only 63% of the questions.[^2] That is roughly 7× fewer tokens than RAG and about 80× fewer than the coding agent. The accuracy column is more sobering than the headline claims suggest: Nexus scores 0.680, against 0.413 for agentic RAG and 0.585 for the coding agent.[^2] Nexus wins the comparison clearly, but 68% on the vendor's own harness is not a solved problem.\\n\\nThe public-preview post adds three customer-facing evaluations, all on small question sets. Q2, a digital-banking infrastructure provider, ran its own benchmark without Pinecone in the loop and reported a 95% F1 score across a 20-question eval set; its chief data scientist, Jesse Barbour, said his team could \\\"easily stand up a vector database and run RAG\\\" over its corpus, and that \\\"the hard part is getting an agent to reliably and efficiently assemble the right knowledge for genuinely difficult questions.\\\"[^3] A second benchmark, which Pinecone says it ran with a legal-research AI company over 30,000 documents of EU case law and legislation, pitted Nexus against agentic RAG and a coding agent across 35 questions: Pinecone reports 100% completion at 87% accuracy for Nexus versus 66% completion at 45% accuracy for RAG and 6% completion at 4% accuracy for the coding agent, with token use roughly 9–15× lower.[^3][^4] A third, run with a data-protection vendor across 598 municipal-meeting documents, reports 90% accuracy against a 65% RAG baseline on a 100-question set, with a one-time curation cost of $2.31 to compile the corpus into twelve artifact types in 34 minutes.[^3]\\n\\nThe direction is consistent across all four: compile once, and the per-query cost collapses. The evidentiary weight is thinner than it first appears. Only the KRAFTBench and legal benchmarks report a full head-to-head against RAG on completion, accuracy, and tokens together; Q2 published no RAG baseline or token comparison beyond its executive's assertion, and the municipal benchmark reports cost per query rather than a token comparison. The corpora are large; the question sets are 20, 35, 100, and 150 items.\\n\\n## Is RAG actually \\\"dead\\\"?\\n\\nHeadlines raced ahead of the product back in May, when Nexus was still early access. VentureBeat framed it as \\\"the RAG era is ending for agentic AI\\\" on the day of the announcement, and The New Stack ran \\\"the company that made RAG mainstream is now betting against it\\\" two days later.[^5][^6] That is a good story, and an incomplete one.\\n\\nStart with scope. Pinecone says Nexus is \\\"built for bounded corpora where agents need to reason across documents,\\\" at its best where a single question touches dozens of files and standard retrieval starts falling apart.[^3] That is a real and common shape — financial filings, case law, support archives, government records — but it is a shape, not the whole space. A knowledge base that changes hourly, an open-ended web search, or a lookup that only ever needs one chunk are not obviously improved by paying an upfront compilation cost. Pinecone scopes Nexus to bounded corpora but does not extend that caution to the cases above; its launch materials illustrate Nexus working over fast-moving operational estates that include Slack, Gong, and Jira (as example data sources rather than shipped connectors), and it launched a marketplace of more than 90 knowledge applications spanning sales, HR, and support.[^1] Exactly where the limits fall is a reading of the evidence, not a line the vendor draws.\\n\\nThe counterargument that holds up best is that retrieval is not disappearing so much as being re-drawn. In January 2026 — months before Nexus existed publicly — Algolia published a rebuttal to a viral essay titled \\\"The RAG Obituary,\\\" arguing that the case against RAG is really a case against \\\"naive, slow, passive implementations,\\\" and that once hybrid keyword-and-vector retrieval is \\\"fast, structured, predictable, and directly callable by the model, the distinction of RAG vs agents becomes obsolete.\\\"[^7] Algolia sells retrieval, so read it with the same skepticism as Pinecone's benchmarks; but the continuum argument is the one that survives contact with real systems. Compiling knowledge upfront and retrieving it at query time are points on a spectrum, and where a given workload lands depends on how bounded and how stable its corpus is. Pinecone is also not alone in the compilation direction — InfoQ points to comparable efforts from Cognite, RelationalAI, and LlamaIndex, among others.[^4]\\n\\nWhere boosters and skeptics agree is the underlying insight, and it is worth taking seriously even if you never touch Nexus: for agents working a fixed corpus, making the model rediscover the same structure on every task is waste. That is the same lesson showing up in adjacent work on [agent memory systems](/microsoft-memora-huawei-jiuwenmemory-agent-memory) and on [how many tools an agent can realistically juggle](/how-many-tools-can-an-ai-agent-handle) — the bottleneck in 2026 is less often the model and more often the context you hand it.\\n\\n## Why it matters if you are building agents\\n\\nThe practical takeaway is not \\\"rip out your RAG pipeline.\\\" It is a question worth asking about any agent you are shipping: how much of its token bill and latency is spent re-deriving structure it could have been handed? If an agent repeatedly loops over the same bounded set of documents to answer variations of the same question, the compilation-first model is a genuinely different cost curve, because the reasoning-about-the-corpus work is amortized once instead of paid per query.[^2][^3]\\n\\nThere are trade-offs the benchmarks do not foreground. Compilation adds an upstream step — someone has to author the Manifest and re-curate when the corpus drifts — which shifts effort rather than erasing it, and it fits corpora stable enough to be worth compiling.[^3] It also concentrates a great deal in one vendor's curation layer and query surface; the LangChain and Teradata collaborations suggest Pinecone knows a single-vendor interface is a hard sell, and the bring-your-own-cloud option and field-level provenance are the answers it offers to the governance version of the same worry.[^1][^3] For teams already thinking in terms of [context engineering rather than prompt engineering](/claude-memory-tool-context-editing-typescript-tutorial), and for anyone weighing how much agent behavior should be pinned down at build time versus discovered at run time (the same tension underneath [agent tooling protocols like MCP](/mcp-stateless-protocol-enterprise-authorization)), Nexus is a clear, well-argued data point — provided you read its benchmarks as the vendor's case rather than a settled result.\\n\\n## FAQ\\n\\n**What is Pinecone Nexus?** It is a \\\"knowledge engine\\\" for AI agents, announced May 4, 2026 and in public preview since July 1, 2026. It compiles an enterprise's scattered documents into structured, task-specific artifacts ahead of time, so agents query a pre-built knowledge layer through the KnowQL query language instead of retrieving and reassembling raw chunks on every request.[^1][^3]\\n\\n**Is RAG dead in 2026?** No — but standard \\\"retrieve-then-generate\\\" RAG is being narrowed. For bounded, slow-changing corpora, compilation-first approaches can beat agentic RAG on accuracy and token cost; for fast-changing or open-ended data, retrieval remains the right tool. The realistic framing is a spectrum, not a death.[^5][^7]\\n\\n**How is a knowledge engine different from a vector database?** A vector database finds relevant chunks at query time. A knowledge engine sits above search and pre-compiles those sources into typed, governed artifacts, so the agent reads a mostly-finished answer instead of assembling one. Pinecone describes Nexus as \\\"a knowledge engine, not a retrieval system,\\\" and says its vector database remains the foundation underneath.[^1][^2]\\n\\n**What is KnowQL?** KnowQL — Knowledge Query Language — is Pinecone's declarative query language and the single interface agents use to talk to Nexus. Like SQL, the agent declares the answer it needs, the shape it wants, and its constraints, and the engine plans how to compose it, returning typed responses with field-level citations.[^2] LangChain and Teradata have said they are working with Pinecone to advance it.[^1]\\n\\n**Are the performance numbers independent?** No. They come from Pinecone's own KRAFTBench harness and from early customers evaluating on Pinecone's preview environment — one of whom, Q2, ran its evaluation without Pinecone involved, though still on Pinecone's platform. The eval sets range from 20 to 150 questions. Treat them as the vendor's case until third parties reproduce them.[^2][^3][^5]\\n\\n**Can I run it without sending Pinecone my data?** Pinecone points to a bring-your-own-cloud deployment where the cluster runs inside your own VPC, which the company says means your documents never leave your infrastructure. It is request-gated for production workloads, and Pinecone described BYOC coverage for Nexus as arriving \\\"very soon\\\" as of its May launch. The hosted preview playground is the lower-commitment way to try it.[^1][^3]\\n\\n[^1]: Pinecone, \\\"Pinecone Nexus: The Knowledge Engine for Agents\\\" (launch announcement; Ash Ashutosh and Edo Liberty, May 4, 2026). https://www.pinecone.io/blog/knowledge-infrastructure-for-agents/\\n[^2]: Pinecone, \\\"Better Models Won't Save Your Agent\\\" (engineering deep dive and KRAFTBench results; Jeff Zhu and Siva Ragavan, May 4, 2026). https://www.pinecone.io/blog/introducing-nexus-knowledge-engine/\\n[^3]: Pinecone, \\\"Pinecone Nexus Is Now in Public Preview\\\" (Jasmeet Singh Gujral and Lea Wang-Tomic, July 1, 2026). https://www.pinecone.io/blog/pinecone-nexus-public-preview/\\n[^4]: Sergio De Simone, \\\"Pinecone Introduces Nexus Engine for Compiling Business Context into Structured Data for AI Agents,\\\" InfoQ, July 18, 2026. https://www.infoq.com/news/2026/07/pinecon-nexus-knowledge-engine/\\n[^5]: Janakiram MSV, \\\"The company that made RAG mainstream is now betting against it,\\\" The New Stack, May 6, 2026. https://thenewstack.io/pinecone-nexus-rag-obsolete/\\n[^6]: \\\"The RAG era is ending for agentic AI — a new compilation-stage knowledge layer is what comes next,\\\" VentureBeat, May 4, 2026. https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next\\n[^7]: Alex Webb, \\\"No, RAG is not dead,\\\" Algolia, January 15, 2026 — a response to the viral essay \\\"The RAG Obituary: Killed By Agents, Buried By Context Windows.\\\" https://www.algolia.com/blog/ai/rag-is-not-dead\\n[^8]: Pinecone, \\\"What is Context Engineering?\\\" https://www.pinecone.io/learn/context-engineering/\\n\"])</script><script>self.__next_f.push([1,\"28:T39f4,\"])</script><script>self.__next_f.push([1,\"\\n# Prompt Optimization for AI Agents: GEPA and DSPy (2026)\\n\\n**In one line:** Prompt optimization for AI agents is becoming automatic. GEPA — a Genetic-Pareto optimizer accepted as an ICLR 2026 Oral — rewrites an agent's prompts by reflecting on its own reasoning and tool-call traces, beating reinforcement learning across six tasks with up to 35x fewer runs.[^1]\\n\\n**TL;DR:** For two years the advice for making an agent reliable was \\\"write a better system prompt.\\\" In 2026 that job is being handed to an optimizer. GEPA (Genetic-Pareto) reads an agent's own execution traces — the reasoning, the tool calls, the tool outputs — diagnoses what went wrong in plain English, and evolves the prompt from there. It landed as an Oral at ICLR 2026, ships as a first-class DSPy optimizer (`dspy.GEPA`) and a standalone library with several thousand GitHub stars, and reports beating the reinforcement-learning method GRPO by up to 20% while using up to 35x fewer rollouts.[^1][^2][^3] The catch, published in June, is that the same technique gets unpredictable the moment you point it at a multi-agent system.[^4]\\n\\n## What you'll learn\\n\\n- What GEPA is and how \\\"reflective prompt evolution\\\" differs from hand-tuning a prompt\\n- The benchmark numbers that got it an ICLR 2026 Oral — and what they do and don't claim\\n- Why reading tool-call traces makes this specifically an *agent* technique, not just an LLM trick\\n- Where it already lives in your stack: `dspy.GEPA`, the standalone library, and the big-lab prompt tools\\n- The catch: what MAS-PromptBench found when the same optimizer met multi-agent systems\\n- What to actually do about it if you build agents\\n\\n## What GEPA actually is\\n\\nGEPA — short for **Genetic-Pareto** — is a prompt optimizer that \\\"thoroughly incorporates natural language reflection to learn high-level rules from trial and error.\\\"[^1] That definition, from the paper's own abstract, is the whole idea in one sentence. Instead of adjusting model weights or nudging a numeric reward, GEPA works in the medium the model already understands best: language.\\n\\nHere is the loop. You give GEPA an AI system that contains one or more prompts, plus a way to score its output. GEPA runs the system on a handful of training tasks and records the full trajectory — the model's reasoning, the tool calls it made, and the outputs those tools returned. A reflection step then reads those traces in natural language, diagnoses what failed, and writes a revised prompt. Crucially, it keeps a *Pareto frontier* of its best attempts rather than a single \\\"current best,\\\" so it can combine complementary lessons from prompts that each won on different examples.[^1] The result is a rewritten instruction that a human never typed.\\n\\nThe reason this matters is the medium. The paper's core argument is that \\\"the interpretable nature of language often provides a much richer learning medium for LLMs, compared to policy gradients derived from sparse, scalar rewards.\\\"[^1] A reinforcement-learning signal tells the model *that* it scored 0.3; a reflection tells it *why* — \\\"you called the search tool before you had the user's account ID.\\\" One of those is far more actionable, and it is the one GEPA uses.\\n\\n## The numbers that got it an ICLR 2026 Oral\\n\\nGEPA was accepted to ICLR 2026 as an Oral — the top tier of acceptance — after a v2 revision posted in February 2026.[^1] The author list is not a group of unknowns: it includes DSPy's creator Omar Khattab, Databricks co-founders Matei Zaharia and Ion Stoica, Stanford's Christopher Potts, and Berkeley's Dan Klein, among a dozen others.[^1] That pedigree is part of why the results traveled.\\n\\nThe headline comparison is against reinforcement learning. Across six tasks, GEPA \\\"outperforms GRPO by 6% on average and by up to 20%, while using up to 35x fewer rollouts.\\\"[^1] GRPO — Group Relative Policy Optimization — is a mainstream RL method that, per the same paper, \\\"often require[s] thousands of rollouts to learn new tasks.\\\"[^1] Read the claim carefully, because the framing matters: the *average* edge over GRPO is 6%, and 20% is the *best-case* gap, not the typical one. The efficiency number is the genuinely striking part. Turning \\\"thousands of rollouts\\\" into a job that can run with dramatically fewer is what makes prompt optimization cheap enough to reach for by default.\\n\\nGEPA also went after the prior state of the art in *prompt* optimization. It \\\"outperforms the leading prompt optimizer, MIPROv2, by over 10% (e.g., +12% accuracy on AIME-2025).\\\"[^1] MIPROv2 is the optimizer GEPA effectively supersedes inside DSPy, so this is the more direct apples-to-apples result for anyone already doing automated prompt search.\\n\\n| Comparison | GEPA's reported result | What the baseline is |\\n|---|---|---|\\n| vs. GRPO (reinforcement learning) | +6% average, up to +20%, with up to 35x fewer rollouts | An RL method needing thousands of rollouts[^1] |\\n| vs. MIPROv2 (prior prompt optimizer) | Over 10% better; +12% on AIME-2025 | The previous \\\"leading prompt optimizer\\\"[^1] |\\n\\n## Why this is an agent technique, not just an LLM trick\\n\\nPlenty of tools rewrite a prompt. What makes GEPA land squarely in agent territory is *what it reflects on*. The trajectories it samples explicitly include \\\"reasoning, tool calls, and tool outputs.\\\"[^1] That is the anatomy of an agent run, not a single completion. When an agent fails, the failure usually is not \\\"the wording was slightly off\\\" — it is that the agent called the wrong tool, called the right tool in the wrong order, or misread a tool's output and kept going. Those are exactly the events sitting in a trace, and they are exactly what a reflection step can name and correct.\\n\\nThis reframes what \\\"prompt engineering for agents\\\" even means. The old craft was a human staring at a system prompt, guessing at phrasings, and re-running a few examples by hand. The new shape is an optimization loop: define a metric, capture real traces, and let a reflector propose changes it can defend against those traces. Prompt engineering starts to look less like copywriting and more like the evaluation-and-iteration discipline this site has covered around [testing LLM prompts in CI](/promptfoo-test-llm-prompts-ci-tutorial) — with the human moving from author to reviewer.\\n\\nIt also connects to a problem agents are already drowning in: tool sprawl. We have written before about [how many tools an agent can handle before accuracy drops](/how-many-tools-can-an-ai-agent-handle), and a big part of the answer is how well the agent's instructions steer it through a crowded tool surface. A prompt that has been optimized against real tool-call traces is directly attacking that failure mode, rather than hoping a longer hand-written instruction happens to help.\\n\\n## It is already in your toolchain\\n\\nNone of this is a research artifact you have to reimplement. GEPA ships two ways.\\n\\nInside DSPy it is a built-in optimizer, documented as \\\"`dspy.GEPA`: Reflective Prompt Optimizer.\\\"[^3] You hand it a `GEPAFeedbackMetric` that returns both a score and a text `feedback` string — that textual feedback is the optimization signal, which is the whole point — and you pick a budget with an `auto` parameter set to `light`, `medium`, or `heavy`.[^3] The feedback-carrying metric is the part worth internalizing: GEPA is at its best when your metric can *say something*, not just emit a number.\\n\\nIt also exists as a standalone library, `gepa-ai/gepa`, that bills itself as a way to \\\"optimize prompts, code, and more\\\" through AI-powered reflective optimization.[^2] As of this writing the repository has several thousand stars and hundreds of forks — fast traction for an optimizer whose paper is a year old.[^2]\\n\\nAnd GEPA is not alone in mainstreaming this idea. The major labs now ship their own prompt-refinement tooling: Anthropic's Prompt Improver rewrites an existing prompt using prompt-engineering best practices,[^5] and OpenAI offers a dashboard Prompt Optimizer that does the same against current guidance.[^6] Those are lighter-weight refiners rather than trace-driven evolutionary loops, but the direction is unmistakable — hand-authored prompts are becoming a starting point, not a deliverable.\\n\\n## The catch: multi-agent systems break the clean story\\n\\nHere is the part most write-ups skip. GEPA's numbers are single-agent numbers. What happens when you extend the same reflective optimization to a *team* of agents was measured directly in **MAS-PromptBench**, a June 2026 benchmark whose title asks the operative question: \\\"When Does Prompt Optimization Improve Multi-Agent LLM Systems?\\\"[^4]\\n\\nThe answer is: sometimes, and sometimes it makes things much worse. The benchmark's own Figure 1 puts it plainly: \\\"While GEPA consistently improves single-agent performance across all five diverse tasks, its natural multi-agent extension yields highly variable effects across tasks and workflow topologies, ranging from large gains to severe performance drops.\\\"[^4] Quantified, \\\"improvements reach up to 24.0 percentage points,\\\" but \\\"performance can drop by as much as 16.0 percentage points for certain configurations.\\\"[^4]\\n\\n| Setting | What the optimizer does | Reported outcome |\\n|---|---|---|\\n| Single agent | Reflect on one agent's traces, rewrite its prompt | Consistent gains across all five tasks[^4] |\\n| Multi-agent (natural extension) | Apply the same reflection across the team | Anywhere from +24.0 to −16.0 percentage points[^4] |\\n\\nThe benchmark also points at *why*. Optimization worked best when an agent's local behavior was \\\"explicit, controllable, and verifiable,\\\" and when the team's communication protocol had explicit shared structure; larger teams introduced coordination overhead that made optimization harder.[^4] In other words, the more of your system lives in the murky space *between* agents — handoffs, implicit conventions, who-does-what — the less a single-agent-style prompt optimizer can help, and the more it can accidentally hurt. Automated prompt optimization is a real tool, not a magic wand, and the multi-agent case is where the difference shows.\\n\\n## What this means if you build agents\\n\\nA few practical takeaways fall out of the research.\\n\\nFirst, treat prompt engineering as an optimization problem with a metric, not a wording exercise. GEPA and every tool like it needs a way to score outputs; the quality of your optimized prompt is bounded by the quality of that metric. If you cannot measure it, you cannot optimize it.\\n\\nSecond, make your metric *talk*. The single biggest lever in GEPA's design is that its feedback is natural language, not a scalar.[^1][^3] A metric that returns \\\"failed: called `refund` before verifying the order status\\\" will produce a better prompt than one that returns `0.0`. Spend your effort there.\\n\\nThird, optimize against real traces, including tool calls. The whole reason this beats generic prompt-rewriting for agents is that it reflects on what the agent actually did. Feed it representative runs, not toy examples.\\n\\nFourth, do not assume single-agent wins transfer to your multi-agent setup. If you run an orchestrator with sub-agents, MAS-PromptBench is the caution to keep pinned to your monitor: measure before and after per topology, and be ready for the optimizer to make a configuration worse.[^4] This is one more reason the [production infrastructure being built around agent runtimes](/managed-agent-runtimes-aws-google-alibaba) increasingly bundles evaluation and tracing — you need both to know whether an \\\"optimized\\\" prompt actually helped.\\n\\n## FAQ\\n\\n**What is GEPA?**\\nGEPA (Genetic-Pareto) is a prompt optimizer that reflects on an AI system's own execution traces in natural language to diagnose failures and evolve better prompts, keeping a Pareto frontier of its best attempts rather than a single best prompt.[^1]\\n\\n**Is prompt engineering being automated?**\\nIncreasingly, yes. Optimizers like GEPA turn prompt tuning into a metric-driven loop, and the major platforms now ship built-in prompt refiners.[^1][^5][^6] Human judgment shifts toward defining good metrics and reviewing results rather than hand-wording every instruction.\\n\\n**Does GEPA really beat reinforcement learning?**\\nOn the paper's six tasks it beats the RL method GRPO by 6% on average and up to 20%, using up to 35x fewer rollouts.[^1] That is a strong, specific result — not a universal law that reflection always beats RL everywhere.\\n\\n**How is GEPA different from MIPROv2?**\\nBoth are automated prompt optimizers in the DSPy lineage. GEPA reports beating MIPROv2 by over 10% (for example, +12% on AIME-2025), largely by using rich natural-language feedback instead of numeric search signals.[^1][^3]\\n\\n**Can I use GEPA today?**\\nYes. It is available as the `dspy.GEPA` optimizer inside DSPy and as the standalone `gepa-ai/gepa` library.[^2][^3]\\n\\n**Does it work for multi-agent systems?**\\nUnreliably. MAS-PromptBench found that extending GEPA to multi-agent systems produced anywhere from +24.0 to −16.0 percentage points depending on the task and topology, with structured, verifiable setups faring best.[^4]\\n\\n## The bottom line\\n\\nPrompt optimization for AI agents crossed a line in 2026: the reflective, trace-driven approach that GEPA represents is now peer-reviewed, packaged, and sitting one import away in DSPy. For single agents, the case is strong — it beats reinforcement learning on the paper's tasks while spending a fraction of the compute, and it does it by reading the exact tool-call traces where agents actually fail.[^1] The honest asterisk is multi-agent systems, where the same idea swings from big wins to real regressions.[^4] The takeaway is not \\\"stop writing prompts.\\\" It is that the highest-leverage work is moving up a level — from wording instructions to defining the metrics, feedback, and traces that let an optimizer write them for you.\\n\\n[^1]: Agrawal et al., \\\"GEPA: Reflective Prompt Evolution Can Outperform Reinforcement Learning,\\\" arXiv:2507.19457 (v1 25 Jul 2025; v2 14 Feb 2026; accepted to ICLR 2026, Oral). https://arxiv.org/abs/2507.19457\\n[^2]: gepa-ai/gepa — the standalone GEPA optimizer library, GitHub (tagline and star/fork counts as of 22 Jul 2026). https://github.com/gepa-ai/gepa\\n[^3]: \\\"dspy.GEPA: Reflective Prompt Optimizer,\\\" DSPy documentation (accessed 22 Jul 2026). https://dspy.ai/api/optimizers/GEPA/overview/\\n[^4]: \\\"MAS-PromptBench: When Does Prompt Optimization Improve Multi-Agent LLM Systems?\\\" arXiv:2606.23664 (June 2026). https://arxiv.org/abs/2606.23664\\n[^5]: \\\"Console prompting tools\\\" (Prompt improver), Claude Platform documentation (accessed 22 Jul 2026). https://platform.claude.com/docs/en/build-with-claude/prompt-engineering/prompting-tools\\n[^6]: \\\"Prompt optimizer,\\\" OpenAI API documentation (accessed 22 Jul 2026). https://developers.openai.com/api/docs/guides/prompt-optimizer\\n\"])</script><script>self.__next_f.push([1,\"9:[[\\\"$\\\",\\\"script\\\",null,{\\\"type\\\":\\\"application/ld+json\\\",\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$1e\\\"}}],[\\\"$\\\",\\\"$L1f\\\",null,{\\\"post\\\":{\\\"slug\\\":\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"content\\\":\\\"$20\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\",\\\"title\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"keywords\\\":[\\\"IETF AI agent protocol standard\\\",\\\"agentproto BoF\\\",\\\"MCP vs A2A\\\",\\\"AI agent protocol interoperability\\\",\\\"IETF 126 Vienna AI agents\\\",\\\"will the IETF standardize AI agent protocols\\\",\\\"cross-domain agent identity federation\\\"],\\\"tags\\\":[\\\"IETF\\\",\\\"AI agent protocol\\\",\\\"agentproto\\\",\\\"MCP\\\",\\\"A2A\\\",\\\"agent interoperability\\\",\\\"agentic ai\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\",\\\"date\\\":\\\"2026-07-24T00:00:00.000Z\\\"}},\\\"translatedContent\\\":{\\\"title\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"description\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\",\\\"body\\\":\\\"$21\\\",\\\"prevTitle\\\":\\\"AI Agents in Go: Microsoft Joins Google's Bet in 2026\\\",\\\"nextTitle\\\":\\\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\\",\\\"tocHeader\\\":\\\"Table of contents\\\",\\\"tocAriaLabel\\\":\\\"Table of contents\\\"},\\\"toc\\\":[{\\\"id\\\":\\\"what-youll-learn\\\",\\\"text\\\":\\\"What you'll learn\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"what-happened-at-the-agentproto-bof\\\",\\\"text\\\":\\\"What happened at the agentproto BoF\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"why-it-is-rough-consensus-not-a-vote\\\",\\\"text\\\":\\\"Why it is rough consensus, not a vote\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"mcp-vs-a2a-two-layers-one-missing-piece\\\",\\\"text\\\":\\\"MCP vs A2A: two layers, one missing piece\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"the-problems-the-framework-says-still-need-a-standard\\\",\\\"text\\\":\\\"The problems the framework says still need a standard\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"why-prompt-injection-is-the-security-test\\\",\\\"text\\\":\\\"Why prompt injection is the security test\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"the-realistic-timeline--and-what-to-watch\\\",\\\"text\\\":\\\"The realistic timeline — and what to watch\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"faq\\\",\\\"text\\\":\\\"FAQ\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"is-the-ietf-standardizing-ai-agent-protocols\\\",\\\"text\\\":\\\"Is the IETF standardizing AI agent protocols?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"what-is-the-agentproto-bof-at-ietf-126\\\",\\\"text\\\":\\\"What is the agentproto BoF at IETF 126?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"how-is-mcp-different-from-a2a\\\",\\\"text\\\":\\\"How is MCP different from A2A?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"what-would-an-ietf-rfc-add-that-mcp-and-a2a-dont-cover\\\",\\\"text\\\":\\\"What would an IETF RFC add that MCP and A2A don't cover?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"why-is-prompt-injection-worse-in-multi-agent-systems\\\",\\\"text\\\":\\\"Why is prompt injection worse in multi-agent systems?\\\",\\\"depth\\\":3}],\\\"prevSlug\\\":\\\"microsoft-agent-framework-go-google-adk\\\",\\\"nextSlug\\\":\\\"pinecone-nexus-knowledge-engine-rag-agents\\\",\\\"prevTitle\\\":\\\"AI Agents in Go: Microsoft Joins Google's Bet in 2026\\\",\\\"nextTitle\\\":\\\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\\",\\\"shareUrl\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\",\\\"prevHref\\\":\\\"/microsoft-agent-framework-go-google-adk\\\",\\\"nextHref\\\":\\\"/pinecone-nexus-knowledge-engine-rag-agents\\\",\\\"lang\\\":\\\"en\\\",\\\"tocHeader\\\":\\\"Table of contents\\\",\\\"tocAriaLabel\\\":\\\"Table of contents\\\",\\\"updatedLabel\\\":\\\"Updated\\\",\\\"bodyWithoutFAQ\\\":\\\"$22\\\",\\\"faqItems\\\":[{\\\"question\\\":\\\"Is the IETF standardizing AI agent protocols?\\\",\\\"answer\\\":\\\"Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.\\\"},{\\\"question\\\":\\\"What is the agentproto BoF at IETF 126?\\\",\\\"answer\\\":\\\"Agentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.17\\\"},{\\\"question\\\":\\\"How is MCP different from A2A?\\\",\\\"answer\\\":\\\"MCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.35 They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.7\\\"},{\\\"question\\\":\\\"What would an IETF RFC add that MCP and A2A don't cover?\\\",\\\"answer\\\":\\\"The framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.7 These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\\"},{\\\"question\\\":\\\"Why is prompt injection worse in multi-agent systems?\\\",\\\"answer\\\":\\\"$23\\\"}],\\\"faqHeadingId\\\":\\\"faq\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mx-auto max-w-3xl px-4\\\",\\\"children\\\":[\\\"$\\\",\\\"$L24\\\",null,{\\\"posts\\\":[{\\\"slug\\\":\\\"claude-adobe-creativity-connector-50-creative-cloud-tools\\\",\\\"content\\\":\\\"$25\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Adobe and Anthropic launched the Adobe for creativity connector for Claude on April 28, 2026, exposing 50+ Photoshop, Premiere, and Firefly tools via MCP.\\\",\\\"title\\\":\\\"Adobe + Claude: 50+ Creative Tools From One Prompt\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"tags\\\":[\\\"claude\\\",\\\"adobe\\\",\\\"adobe-creative-cloud\\\",\\\"mcp\\\",\\\"claude-connectors\\\",\\\"anthropic\\\",\\\"creative-ai\\\",\\\"agentic-ai\\\",\\\"photoshop\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/placeholders/cover-general.svg\\\",\\\"date\\\":\\\"2026-05-01T00:00:00.000Z\\\"}},{\\\"slug\\\":\\\"claude-managed-agents-deploy-ai-agents-faster\\\",\\\"content\\\":\\\"$26\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Claude Managed Agents (public beta, April 2026): hosted sandboxing, state, tool execution, and error recovery — production agents in days instead of weeks.\\\",\\\"title\\\":\\\"Claude Managed Agents: Build Production AI Agents in Days\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"tags\\\":[\\\"anthropic\\\",\\\"claude\\\",\\\"ai-agents\\\",\\\"managed-agents\\\",\\\"mcp\\\",\\\"enterprise-ai\\\",\\\"agentic-ai\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/placeholders/cover-general.svg\\\",\\\"date\\\":\\\"2026-04-13T00:00:00.000Z\\\"}},{\\\"slug\\\":\\\"pinecone-nexus-knowledge-engine-rag-agents\\\",\\\"content\\\":\\\"$27\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Pinecone Nexus, a knowledge engine for AI agents, compiles enterprise data upfront to cut the RAG retrieval loop. What changes in 2026 — and if RAG is dead.\\\",\\\"title\\\":\\\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"keywords\\\":[\\\"Pinecone Nexus\\\",\\\"knowledge engine for AI agents\\\",\\\"is RAG dead 2026\\\",\\\"knowledge compilation vs RAG\\\",\\\"context engineering for AI agents\\\",\\\"KnowQL declarative query language\\\",\\\"what is Pinecone Nexus\\\",\\\"reduce agent token cost retrieval\\\"],\\\"tags\\\":[\\\"Pinecone Nexus\\\",\\\"knowledge engine\\\",\\\"RAG\\\",\\\"context engineering\\\",\\\"KnowQL\\\",\\\"AI agents\\\",\\\"agentic ai\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/covers/pinecone-nexus-knowledge-engine-rag-agents.jpg\\\",\\\"date\\\":\\\"2026-07-25T00:00:00.000Z\\\"}},{\\\"slug\\\":\\\"prompt-optimization-ai-agents-gepa\\\",\\\"content\\\":\\\"$28\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Prompt engineering for AI agents is going automatic. GEPA, an ICLR 2026 Oral, rewrites agent prompts from their traces and beats RL with up to 35x fewer runs.\\\",\\\"title\\\":\\\"Prompt Optimization for AI Agents: GEPA and DSPy (2026)\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"keywords\\\":[\\\"prompt optimization for AI agents\\\",\\\"GEPA reflective prompt optimizer\\\",\\\"dspy.GEPA\\\",\\\"reflective prompt evolution\\\",\\\"automatic prompt engineering\\\",\\\"prompt optimization multi-agent systems\\\"],\\\"tags\\\":[\\\"prompt optimization\\\",\\\"GEPA\\\",\\\"DSPy\\\",\\\"prompt engineering\\\",\\\"AI agents\\\",\\\"reflective prompt evolution\\\",\\\"MAS-PromptBench\\\",\\\"agentic ai\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/covers/prompt-optimization-ai-agents-gepa.jpg\\\",\\\"date\\\":\\\"2026-07-22T00:00:00.000Z\\\"}}],\\\"lang\\\":\\\"en\\\",\\\"translatedTitles\\\":\\\"$undefined\\\"}]}]]\\n\"])</script><script>self.__next_f.push([1,\"10:[[\\\"$\\\",\\\"meta\\\",\\\"0\\\",{\\\"name\\\":\\\"viewport\\\",\\\"content\\\":\\\"width=device-width, initial-scale=1, viewport-fit=cover\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"1\\\",{\\\"charSet\\\":\\\"utf-8\\\"}],[\\\"$\\\",\\\"title\\\",\\\"2\\\",{\\\"children\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026 | Nerd Level Tech\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"3\\\",{\\\"name\\\":\\\"description\\\",\\\"content\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\"}],[\\\"$\\\",\\\"link\\\",\\\"4\\\",{\\\"rel\\\":\\\"canonical\\\",\\\"href\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"link\\\",\\\"5\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"en-US\\\",\\\"href\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"link\\\",\\\"6\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"ar-EG\\\",\\\"href\\\":\\\"https://nerdleveltech.com/ar/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"7\\\",{\\\"property\\\":\\\"og:title\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"8\\\",{\\\"property\\\":\\\"og:description\\\",\\\"content\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"9\\\",{\\\"property\\\":\\\"og:url\\\",\\\"content\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"10\\\",{\\\"property\\\":\\\"og:image\\\",\\\"content\\\":\\\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"11\\\",{\\\"property\\\":\\\"og:image:width\\\",\\\"content\\\":\\\"1200\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"12\\\",{\\\"property\\\":\\\"og:image:height\\\",\\\"content\\\":\\\"630\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"13\\\",{\\\"property\\\":\\\"og:image:alt\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"14\\\",{\\\"property\\\":\\\"og:type\\\",\\\"content\\\":\\\"article\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"15\\\",{\\\"property\\\":\\\"article:published_time\\\",\\\"content\\\":\\\"2026-07-24T00:00:00.000Z\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"16\\\",{\\\"name\\\":\\\"twitter:card\\\",\\\"content\\\":\\\"summary_large_image\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"17\\\",{\\\"name\\\":\\\"twitter:title\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"18\\\",{\\\"name\\\":\\\"twitter:description\\\",\\\"content\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"19\\\",{\\\"name\\\":\\\"twitter:image\\\",\\\"content\\\":\\\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"20\\\",{\\\"name\\\":\\\"twitter:image:width\\\",\\\"content\\\":\\\"1200\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"21\\\",{\\\"name\\\":\\\"twitter:image:height\\\",\\\"content\\\":\\\"630\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"22\\\",{\\\"name\\\":\\\"twitter:image:alt\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"23\\\",{\\\"rel\\\":\\\"icon\\\",\\\"href\\\":\\\"/favicon.svg\\\",\\\"type\\\":\\\"image/svg+xml\\\"}],[\\\"$\\\",\\\"link\\\",\\\"24\\\",{\\\"rel\\\":\\\"icon\\\",\\\"href\\\":\\\"/icon.svg\\\",\\\"type\\\":\\\"image/svg+xml\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"25\\\",{\\\"name\\\":\\\"next-size-adjust\\\"}]]\\n\"])</script><script>self.__next_f.push([1,\"8:null\\n\"])</script><script>self.__next_f.push([1,\"2a:I[81025,[\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3185\\\",\\\"static/chunks/app/layout-4e6ae73d356025e1.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n2b:I[68259,[\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"3185\\\",\\\"static/chunks/app/layout-4e6ae73d356025e1.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n29:T403,(function(){\\n  if (window.fbq) return;\\n  var n = window.fbq = function(){ n.callMethod ? n.callMethod.apply(n, arguments) : n.queue.push(arguments); };\\n  if (!window._fbq) window._fbq = n;\\n  n.push = n; n.loaded = true; n.version = '2.0'; n.queue = [];\\n  fbq('init', '1937494190493436');\\n  fbq('track', 'PageView');\\n  var loaded = false;\\n  function loadPixel() {\\n    if (loaded) return;\\n    loaded = true;\\n    var s = document.createElement('script');\\n    s.async = true;\\n    s.src = 'https://connect.facebook.net/en_US/fbevents.js';\\n    document.head.appendChild(s);\\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\\n      document.removeEventListener(e, loadPixel);\\n    });\\n  }\\n  if (document.readyState === 'complete') {\\n    setTimeout(loadPixel, 3000);\\n  } else {\\n    window.addEventListener('load', function() { setTimeout(loadPixel, 3000); });\\n  }\\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\\n    document.addEventListener(e, loadPixel, { once: true, passive: true });\\n  });\\n})();\"])</script><script>self.__next_f.push([1,\"f:[\\\"$\\\",\\\"html\\\",null,{\\\"lang\\\":\\\"en\\\",\\\"dir\\\":\\\"ltr\\\",\\\"className\\\":\\\"__variable_bbcc58 __variable_948ce5 __variable_9ded40 __variable_3f4575 __variable_16cd69\\\",\\\"suppressHydrationWarning\\\":true,\\\"children\\\":[[\\\"$\\\",\\\"head\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(() =\\u003e {\\\\n var t = localStorage.getItem('theme');\\\\n var d = document.documentElement;\\\\n if (t === 'dark' || (!t || t === 'system') \\u0026\\u0026 window.matchMedia('(prefers-color-scheme: dark)').matches) {\\\\n d.classList.add('dark');\\\\n } else {\\\\n d.classList.remove('dark');\\\\n }\\\\n try {\\\\n var consent = localStorage.getItem('nlt-cookie-consent');\\\\n if (consent) d.setAttribute('data-nlt-consent', consent);\\\\n } catch (e) {}\\\\n})();\\\"}}],[\\\"$\\\",\\\"meta\\\",null,{\\\"name\\\":\\\"msvalidate.01\\\",\\\"content\\\":\\\"63B94FDFC56A65B5E9E316E474AB9D0D\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Articles\\\",\\\"href\\\":\\\"/rss.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/atom+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Articles\\\",\\\"href\\\":\\\"/atom.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Podcast\\\",\\\"href\\\":\\\"/podcast.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Courses\\\",\\\"href\\\":\\\"/courses-rss.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Remote Tech Jobs\\\",\\\"href\\\":\\\"/jobs-rss.xml\\\"}],[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(function(){\\\\n  window.clarity = window.clarity || function(){ (window.clarity.q = window.clarity.q || []).push(arguments); };\\\\n  var loaded = false;\\\\n  function loadClarity() {\\\\n    if (loaded) return;\\\\n    loaded = true;\\\\n    var s = document.createElement('script');\\\\n    s.async = true;\\\\n    s.src = 'https://www.clarity.ms/tag/uiskr3p74z';\\\\n    document.head.appendChild(s);\\\\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n      document.removeEventListener(e, loadClarity);\\\\n    });\\\\n  }\\\\n  if (document.readyState === 'complete') {\\\\n    setTimeout(loadClarity, 3000);\\\\n  } else {\\\\n    window.addEventListener('load', function() { setTimeout(loadClarity, 3000); });\\\\n  }\\\\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n    document.addEventListener(e, loadClarity, { once: true, passive: true });\\\\n  });\\\\n})();\\\"}}],[\\\"$\\\",\\\"script\\\",null,{\\\"async\\\":true,\\\"src\\\":\\\"https://www.googletagmanager.com/gtag/js?id=G-7LWRNQMJYQ\\\"}],[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"\\\\n window.dataLayer = window.dataLayer || [];\\\\n function gtag(){dataLayer.push(arguments);}\\\\n\\\\n // Default consent to 'denied' for GDPR compliance (EU/EEA users)\\\\n gtag('consent', 'default', {\\\\n 'ad_storage': 'denied',\\\\n 'ad_user_data': 'denied',\\\\n 'ad_personalization': 'denied',\\\\n 'analytics_storage': 'denied'\\\\n });\\\\n\\\\n gtag('js', new Date());\\\\n // Skip the initial config + pageview for admin routes. SPA navigations\\\\n // away from /admin still work — AnalyticsListeners fires page_view on\\\\n // route change for any non-admin path it sees next.\\\\n if (!/^\\\\\\\\/admin(\\\\\\\\/|$)/.test(window.location.pathname)) {\\\\n gtag('config', 'G-7LWRNQMJYQ');\\\\n }\\\\n\\\\n // Check if user already consented and update consent accordingly\\\\n try {\\\\n var consent = localStorage.getItem('nlt-cookie-consent');\\\\n if (consent === 'accepted') {\\\\n gtag('consent', 'update', {\\\\n 'ad_storage': 'granted',\\\\n 'ad_user_data': 'granted',\\\\n 'ad_personalization': 'granted',\\\\n 'analytics_storage': 'granted'\\\\n });\\\\n }\\\\n } catch(e) {}\\\\n\\\"}}],[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(function(){\\\\n var loaded = false;\\\\n function loadBrevo() {\\\\n if (loaded) return;\\\\n loaded = true;\\\\n var s = document.createElement('script');\\\\n s.src = 'https://cdn.brevo.com/js/sdk-loader.js';\\\\n s.async = true;\\\\n s.onload = function() {\\\\n window.Brevo = window.Brevo || [];\\\\n Brevo.push([\\\\\\\"init\\\\\\\", { client_key:\\\\\\\"07ps0c5debu6rk7jhbq1fkyj\\\\\\\" }]);\\\\n };\\\\n document.head.appendChild(s);\\\\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n document.removeEventListener(e, loadBrevo);\\\\n });\\\\n }\\\\n if (document.readyState === 'complete') {\\\\n setTimeout(loadBrevo, 3000);\\\\n } else {\\\\n window.addEventListener('load', function() { setTimeout(loadBrevo, 3000); });\\\\n }\\\\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n document.addEventListener(e, loadBrevo, { once: true, passive: true });\\\\n });\\\\n})();\\\"}}],[[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$29\\\"}}],[\\\"$\\\",\\\"noscript\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"img\\\",null,{\\\"height\\\":\\\"1\\\",\\\"width\\\":\\\"1\\\",\\\"style\\\":{\\\"display\\\":\\\"none\\\"},\\\"src\\\":\\\"https://www.facebook.com/tr?id=1937494190493436\\u0026ev=PageView\\u0026noscript=1\\\",\\\"alt\\\":\\\"\\\"}]}]]]}],[\\\"$\\\",\\\"body\\\",null,{\\\"className\\\":\\\"nlt-newlook\\\",\\\"children\\\":[[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(() =\\u003e {\\\\n var RTL_LANGS = ['ar', 'he', 'fa', 'ur'];\\\\n var pathname = window.location.pathname;\\\\n var langMatch = pathname.match(/^\\\\\\\\/([a-z]{2})(\\\\\\\\/|$)/);\\\\n var lang = langMatch ? langMatch[1] : 'en';\\\\n var isRTL = RTL_LANGS.indexOf(lang) !== -1;\\\\n document.documentElement.dir = isRTL ? 'rtl' : 'ltr';\\\\n document.documentElement.lang = lang;\\\\n})();\\\"}}],[\\\"$\\\",\\\"$L2a\\\",null,{}],[\\\"$\\\",\\\"$L2b\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$La\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"segmentPath\\\":[\\\"children\\\"],\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$Ld\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$L2c\\\",\\\"notFoundStyles\\\":[]}]}]]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"2d:I[86654,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\",\\\"9160\\\",\\\"static/chunks/app/not-found-a3276cd1dbc10332.js?dpl=dpl_5cPb7sBr5qSNi8GYcmBX7sF7DpTj\\\"],\\\"default\\\"]\\n\"])</script><script>self.__next_f.push([1,\"2c:[\\\"$\\\",\\\"$L2d\\\",null,{\\\"lang\\\":\\\"en\\\",\\\"recentPosts\\\":[{\\\"slug\\\":\\\"pinecone-nexus-knowledge-engine-rag-agents\\\",\\\"title\\\":\\\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\\",\\\"description\\\":\\\"Pinecone Nexus, a knowledge engine for AI agents, compiles enterprise data upfront to cut the RAG retrieval loop. What changes in 2026 — and if RAG is dead.\\\",\\\"date\\\":\\\"2026-07-25T00:00:00.000Z\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"tags\\\":[\\\"Pinecone Nexus\\\",\\\"knowledge engine\\\"]},{\\\"slug\\\":\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"title\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"description\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\",\\\"date\\\":\\\"2026-07-24T00:00:00.000Z\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"tags\\\":[\\\"IETF\\\",\\\"AI agent protocol\\\"]},{\\\"slug\\\":\\\"microsoft-agent-framework-go-google-adk\\\",\\\"title\\\":\\\"AI Agents in Go: Microsoft Joins Google's Bet in 2026\\\",\\\"description\\\":\\\"Microsoft Agent Framework for Go entered public preview in July 2026, joining Google's ADK for Go — while OpenAI and Anthropic stay Python and TypeScript only.\\\",\\\"date\\\":\\\"2026-07-24T00:00:00.000Z\\\",\\\"category\\\":\\\"news\\\",\\\"tags\\\":[\\\"Go\\\",\\\"AI agents\\\"]}],\\\"guides\\\":[{\\\"slug\\\":\\\"n8n-rag-chat-webpage\\\",\\\"title\\\":{\\\"en\\\":\\\"Build a RAG Chatbot That Answers From Any Webpage in n8n (7 Nodes)\\\",\\\"ar\\\":\\\"ابنِ روبوت RAG يُجيب من أي صفحة ويب في n8n (7 عقد)\\\"},\\\"description\\\":{\\\"en\\\":\\\"Wire a chat trigger to an AI agent with windowed memory and retrieval from a live URL. The workflow fetches the page on every question, chunks it, ranks chunks by query relevance, and grounds gpt-5-mini's answer with source citations — no vector DB, no embeddings bill.\\\",\\\"ar\\\":\\\"وصل مُشغِّل دردشة بوكيل AI مع ذاكرة نافذة واسترجاع من رابط مباشر. السير يجلب الصفحة مع كل سؤال، يُقسمها إلى chunks، يُرتبها بالصلة بالاستعلام، ويُؤصل إجابة gpt-5-mini بمراجع مصدر — بدون قاعدة بيانات متجهية، بدون فاتورة embeddings.\\\"},\\\"category\\\":\\\"tooling\\\",\\\"estimatedReadingMinutes\\\":17,\\\"isFeatured\\\":true},{\\\"slug\\\":\\\"n8n-ai-workflows\\\",\\\"title\\\":{\\\"en\\\":\\\"Build an AI Research Digest with n8n — No Code, Real Output in 6 Steps\\\",\\\"ar\\\":\\\"بناء ملخص بحثي بالذكاء الاصطناعي مع n8n — بلا كود، نتائج حقيقية في 6 خطوات\\\"},\\\"description\\\":{\\\"en\\\":\\\"Build a fully automated AI newsletter that fetches the top 10 Hacker News stories daily, summarizes each with GPT, and formats a polished digest email — all in n8n's visual canvas. Every node was wired and executed live on n8n cloud. No code required beyond one simple JavaScript snippet.\\\",\\\"ar\\\":\\\"ابنِ نشرة إخبارية AI مؤتمتة بالكامل تجلب أهم 10 قصص من Hacker News يومياً وتلخصها بـ GPT وتُنسّق بريداً إلكترونياً أنيقاً — كل ذلك في لوحة n8n البصرية. كل عقدة وُصِّلت ونُفِّذت مباشرةً على n8n cloud. لا حاجة لكود سوى مقطع JavaScript بسيط.\\\"},\\\"category\\\":\\\"tooling\\\",\\\"estimatedReadingMinutes\\\":25,\\\"isFeatured\\\":true},{\\\"slug\\\":\\\"dify-rag-chatbot\\\",\\\"title\\\":{\\\"en\\\":\\\"Build a RAG Chatbot with Dify — No Code, Real Output in 5 Steps\\\",\\\"ar\\\":\\\"بناء شات بوت RAG مع Dify — بلا كود، نتائج حقيقية في 5 خطوات\\\"},\\\"description\\\":{\\\"en\\\":\\\"Build a fully working RAG chatbot in Dify's visual builder — no code required. Every step was executed live on cloud.dify.ai and produces real output. Covers model setup, Knowledge Base creation with hybrid search, Chatflow wiring, live testing, and API integration.\\\",\\\"ar\\\":\\\"ابنِ شات بوت RAG كامل الوظائف في Dify — بدون كود. كل خطوة نُفِّذت مباشرةً على cloud.dify.ai وتنتج نتائج حقيقية. يغطي إعداد النماذج وقاعدة المعرفة والبحث الهجين واختبار التطبيق الحي وتكامل API.\\\"},\\\"category\\\":\\\"llm-integration\\\",\\\"estimatedReadingMinutes\\\":20,\\\"isFeatured\\\":true}],\\\"recentCourses\\\":[{\\\"slug\\\":\\\"prompt-engineering-path-code\\\",\\\"title\\\":{\\\"en\\\":\\\"Prompts for Code \\u0026 Engineering — The Prompt Engineering Path\\\",\\\"ar\\\":\\\"أوامر للكود والهندسة — مسار هندسة الأوامر\\\"},\\\"description\\\":{\\\"en\\\":\\\"The expansion course for engineers. Master code-generation prompts, debugging prompts, refactor locks, structured code-review prompts, and the prompt patterns that make Cursor, Claude Code, Aider, and Copilot productive. Every example is a real, verified Claude output you can re-run.\\\",\\\"ar\\\":\\\"دورة التوسع للمهندسين. أتقن أوامر توليد الكود، أوامر تصحيح الأخطاء، أقفال إعادة الهيكلة، أوامر مراجعة الكود المنظمة، وأنماط الأوامر التي تجعل Cursor و Claude Code و Aider و Copilot منتجة. كل مثال هو مخرج حقيقي موثق من Claude يمكنك إعادة تشغيله.\\\"},\\\"difficultyLevel\\\":\\\"intermediate\\\",\\\"category\\\":\\\"ai\\\",\\\"lessonCount\\\":26},{\\\"slug\\\":\\\"prompt-engineering-path-cross-model\\\",\\\"title\\\":{\\\"en\\\":\\\"Cross-Model Mastery — The Prompt Engineering Path\\\",\\\"ar\\\":\\\"إتقان النماذج المتعددة — مسار هندسة الأوامر\\\"},\\\"description\\\":{\\\"en\\\":\\\"The same prompt sent to Claude, GPT, and Gemini lands three different responses. Learn the dialects: tone, instruction-following, structured output, refusal shape, system-prompt loyalty. Every comparison in this course was captured live from the three frontier APIs — not from training data, not from screenshots.\\\",\\\"ar\\\":\\\"نفس الأمر المُرسَل إلى Claude و GPT و Gemini يحصل على ثلاث ردود مختلفة. تعلم اللهجات: النبرة، اتباع التعليمات، المخرج المنظم، شكل الرفض، الولاء لأمر النظام. كل مقارنة في هذه الدورة تم التقاطها مباشرةً من الـAPIs الثلاثة الرائدة — ليست من بيانات التدريب، ولا من لقطات الشاشة.\\\"},\\\"difficultyLevel\\\":\\\"intermediate\\\",\\\"category\\\":\\\"ai\\\",\\\"lessonCount\\\":24},{\\\"slug\\\":\\\"prompt-engineering-path-foundations\\\",\\\"title\\\":{\\\"en\\\":\\\"The Prompt Engineering Path — Foundations\\\",\\\"ar\\\":\\\"مسار هندسة الأوامر — الأساسيات\\\"},\\\"description\\\":{\\\"en\\\":\\\"Learn the craft of prompting — from your first ChatGPT message to a tight production-grade system prompt. Real, verified outputs from Claude, GPT, and Gemini. Day-to-day scenarios, no fluff. The gateway to the full Prompt Engineering learning path.\\\",\\\"ar\\\":\\\"تعلم حرفة كتابة الأوامر — من أول رسالة في ChatGPT إلى أمر نظام محكم بمستوى الإنتاج. أمثلة حقيقية موثقة من Claude و GPT و Gemini. سيناريوهات يومية بدون حشو. البوابة لكامل مسار هندسة الأوامر.\\\"},\\\"difficultyLevel\\\":\\\"beginner\\\",\\\"category\\\":\\\"ai\\\",\\\"lessonCount\\\":42}],\\\"tools\\\":[{\\\"name\\\":\\\"API Response Mocker\\\",\\\"nameAr\\\":\\\"محاكي استجابة API\\\",\\\"description\\\":\\\"Generate realistic mock API responses with dynamic data using Faker.js. 18 pre-built templates for testing and development.\\\",\\\"descriptionAr\\\":\\\"أنشئ استجابات API وهمية واقعية مع بيانات ديناميكية باستخدام Faker.js. 18 قالباً جاهزاً للاختبار والتطوير.\\\",\\\"href\\\":\\\"/tools/api-response-mocker\\\"},{\\\"name\\\":\\\"Tech Pulse\\\",\\\"nameAr\\\":\\\"نبض التقنية\\\",\\\"description\\\":\\\"AI-curated tech news feed for developers. Get the latest AI, Cloud, DevOps, and Security updates in one place.\\\",\\\"descriptionAr\\\":\\\"موجز أخبار تقنية منتقى بالذكاء الاصطناعي للمطورين. احصل على آخر تحديثات الذكاء الاصطناعي والسحابة وDevOps والأمان في مكان واحد.\\\",\\\"href\\\":\\\"/tools/tech-pulse\\\"},{\\\"name\\\":\\\"Resume Optimizer\\\",\\\"nameAr\\\":\\\"محسّن السيرة الذاتية\\\",\\\"description\\\":\\\"Transform your resume for ATS compliance with AI-powered optimization. Upload and download improved DOCX/PDF versions.\\\",\\\"descriptionAr\\\":\\\"حوّل سيرتك الذاتية لتتوافق مع أنظمة ATS بتحسين مدعوم بالذكاء الاصطناعي. ارفع وحمّل نسخ DOCX/PDF محسّنة.\\\",\\\"href\\\":\\\"/tools/resume-optimizer\\\"},{\\\"name\\\":\\\"IP Checker + Browser Info\\\",\\\"nameAr\\\":\\\"فاحص IP + معلومات المتصفح\\\",\\\"description\\\":\\\"Discover your IP address, location, ISP details, and comprehensive browser information.\\\",\\\"descriptionAr\\\":\\\"اكتشف عنوان IP الخاص بك وموقعك وتفاصيل مزود الخدمة ومعلومات المتصفح الشاملة.\\\",\\\"href\\\":\\\"/tools/ip-checker\\\"}],\\\"nerdoModes\\\":[{\\\"id\\\":\\\"fast\\\",\\\"name\\\":\\\"nerdo.modes.fast.name\\\",\\\"description\\\":\\\"nerdo.modes.fast.description\\\",\\\"icon\\\":\\\"zap\\\"},{\\\"id\\\":\\\"learning\\\",\\\"name\\\":\\\"nerdo.modes.learning.name\\\",\\\"description\\\":\\\"nerdo.modes.learning.description\\\",\\\"icon\\\":\\\"graduation-cap\\\"},{\\\"id\\\":\\\"create-content\\\",\\\"name\\\":\\\"nerdo.modes.createContent.name\\\",\\\"description\\\":\\\"nerdo.modes.createContent.description\\\",\\\"icon\\\":\\\"pen-tool\\\"}],\\\"categories\\\":[{\\\"slug\\\":\\\"ai-ml\\\",\\\"name\\\":\\\"AI \\u0026 Machine Learning\\\",\\\"color\\\":\\\"text-purple-500 dark:text-purple-400\\\"},{\\\"slug\\\":\\\"llm-integration\\\",\\\"name\\\":\\\"LLM \\u0026 Integration\\\",\\\"color\\\":\\\"text-indigo-500 dark:text-indigo-400\\\"},{\\\"slug\\\":\\\"cloud-devops\\\",\\\"name\\\":\\\"Cloud \\u0026 DevOps\\\",\\\"color\\\":\\\"text-sky-500 dark:text-sky-400\\\"},{\\\"slug\\\":\\\"frontend\\\",\\\"name\\\":\\\"Frontend Development\\\",\\\"color\\\":\\\"text-blue-500 dark:text-blue-400\\\"},{\\\"slug\\\":\\\"backend\\\",\\\"name\\\":\\\"Backend Development\\\",\\\"color\\\":\\\"text-green-500 dark:text-green-400\\\"},{\\\"slug\\\":\\\"tooling\\\",\\\"name\\\":\\\"Tooling \\u0026 Productivity\\\",\\\"color\\\":\\\"text-orange-500 dark:text-orange-400\\\"},{\\\"slug\\\":\\\"architecture\\\",\\\"name\\\":\\\"Architecture \\u0026 Design\\\",\\\"color\\\":\\\"text-pink-500 dark:text-pink-400\\\"},{\\\"slug\\\":\\\"performance\\\",\\\"name\\\":\\\"Performance \\u0026 Optimization\\\",\\\"color\\\":\\\"text-yellow-500 dark:text-yellow-400\\\"},{\\\"slug\\\":\\\"security\\\",\\\"name\\\":\\\"Security \\u0026 Privacy\\\",\\\"color\\\":\\\"text-red-500 dark:text-red-400\\\"},{\\\"slug\\\":\\\"news\\\",\\\"name\\\":\\\"News\\\",\\\"color\\\":\\\"text-gray-500 dark:text-gray-400\\\"},{\\\"slug\\\":\\\"career\\\",\\\"name\\\":\\\"Career \\u0026 Growth\\\",\\\"color\\\":\\\"text-purple-500 dark:text-purple-400\\\"}]}]\\n\"])</script></body></html>","snapshot_chars":265335,"live_check":"changed"},{"url":"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era","committed_hash":"sha256:85b2d47e7fbe77853cfb98cf533e7febaad59243b136d7a3d3248fb4e8474a1e","committed_hash_short":"sha256:85b2d47e…e8474a1e","mime_type":"text/html","committed_at":"2026-07-26T10:00:28.870777+00:00","content_snapshot":"<!DOCTYPE html>\n<!--\nDevelopment:\nJULIO FOULQUIE, @j3j5@hachyderm.io, ✈Montevideo, UY\nMARC TORAL, ✈Amsterdam, NL\nJULIAN SZNAIDER, ✈Buenos Aires, AR\n——————————\nConcept and Design by:\nALEXANDER GRIFFIOEN, @oscaralexander, ✈Amsterdam, NL\nSÄINA SEEDORF, ✈Amsterdam, NL\n——————————\nAlumni:\nJACK DUNN, ✈Amsterdam, NL\nJULIAN AIJAL, @Jaijal, ✈Amsterdam, NL\nSAM BLOK, ✈Amsterdam, NL\nLAURA GENNO, ✈Amsterdam, NL\nIRENE DE NICOLO, ✈Amsterdam, NL\nDANIEL TARA, ✈Amsterdam, NL\nEVGENY ASTAPOV, ✈Rotterdam, NL\nRONAN O'LEARY, @ro_oleary, ✈Amsterdam, NL\nPABLO ROMÁN, ✈Amsterdam, NL\nJAMES SCOTT, ✈Amsterdam, NL\nJELLE VAN WIJHE, ✈Amsterdam, NL\nMATTHEW ELWORTHY, ✈Amsterdam, NL\nOSCAR VAN ZIJVERDEN, ✈Amsterdam, NL\nSTEPHAN LAGERWAARD, ✈Amsterdam, NL\n-->\n\n<html lang=\"en\">\n    <head>\n        <meta charset=\"utf-8\">\n        <meta name=\"viewport\" content=\"width=device-width, initial-scale=1, maximum-scale=1\">\n        <meta content=\"IE=edge,chrome=1\" http-equiv=\"X-UA-Compatible\">\n        <meta content=\"telephone=no\" name=\"format-detection\">\n        <meta content=\"unsafe-url\" name=\"referrer\">\n        <meta content=\"The Next Web\" name=\"apple-mobile-web-app-title\">\n\n                <link rel=\"preload\" href=\"//static.thenextweb.com/assets/next/css/base.css?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" as=\"style\">\n        <link rel=\"preload\" as=\"script\" href=\"//static.thenextweb.com/assets/next/js/base.js?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" >\n                    <link rel=\"preload\" href=\"//static.thenextweb.com/assets/next/css/media.css?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" as=\"style\">\n                <link rel=\"preload\" href='https://static.thenextweb.com/assets/next/fonts/graphik-wide-black.woff2' as='font' type='font/woff2' crossorigin='anonymous'>\n\n                    <link rel='preload' as=\"image\" href=\"https://media.thenextweb.com/2026/04/google-cloud-next-ai-agents-agentic-era.avif\">\n        \n        \n                \n        \n                                                                                                \n                                                                                                                                                <title>Google Cloud Next 2026: AI agents, A2A protocol, Workspace Studio, and the full-stack bet against OpenAI and Anthropic</title>\n            \n        \n                \n                                                                \n                            \n                \n\n    <!-- OpenGraph -->\n    <meta name=\"author\" content=\"Alina Maria Stan\">\n    <meta name=\"original-source\" content=\"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era\" />\n    <meta content=\"TNW | Corporates-Innovation\" property=\"og:site_name\" />\n    <meta content=\"Google Cloud Next 2026: AI agents, A2A protocol, Workspace Studio, and the full-stack bet against OpenAI and Anthropic\" property=\"og:title\" />\n    <meta name=\"description\" content=\"Google launches AI agent suite at Cloud Next 2026 with Workspace Studio, A2A protocol at 150 orgs, and Project Mariner. The pitch: only Google owns the full stack.\" property=\"description\" />\n    <meta content=\"Google launches AI agent suite at Cloud Next 2026 with Workspace Studio, A2A protocol at 150 orgs, and Project Mariner. The pitch: only Google owns the full stack.\" property=\"og:description\" />\n    <meta content=\"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era\" property=\"og:url\" />\n    <meta content=\"640\" property=\"og:image:height\" />\n    <meta content=\"1280\" property=\"og:image:width\" />\n    <meta content=\"https://media.thenextweb.com/2026/04/google-cloud-next-ai-agents-agentic-era.avif\" property=\"og:image\" />\n    <meta content=\"article\" property=\"og:type\" />\n    <meta property=\"og:locale\" content=\"en_US\">\n    <meta property=\"og:updated_time\" content=\"2026-05-06 20:17:20\" />\n    <meta property=\"article:published_time\" content=\"2026-04-22 14:26:39\" />\n    <meta property=\"article:modified_time\" content=\"2026-05-06 20:17:20\" />\n    <meta property=\"article:section\" content=\"Corporates and innovation\">\n\n    <!-- Twitter Card -->\n    <meta name=\"twitter:card\" content=\"summary_large_image\" />\n    <meta name=\"twitter:site\" content=\"@thenextweb\" />\n    <meta name=\"twitter:creator\" content=\"@thenextweb\" />\n    <meta name=\"twitter:title\" content=\"Google Cloud Next 2026: AI agents, A2A protocol, Workspace Studio, and the full-stack bet against OpenAI and Anthropic\" />\n    <meta name=\"twitter:image\" content=\"https://media.thenextweb.com/2026/04/google-cloud-next-ai-agents-agentic-era.avif\" />\n    <meta name=\"twitter:description\" content=\"Google launches AI agent suite at Cloud Next 2026 with Workspace Studio, A2A protocol at 150 orgs, and Project Mariner. The pitch: only Google owns the full stack.\" />\n\n\n    <!-- General Meta -->\n    <meta name=\"robots\" content=\"max-image-preview:large\">\n    <meta content=\"Google Cloud Next 2026: AI agents, A2A protocol, Workspace Studio, and the full-stack bet against OpenAI and Anthropic\" property=\"title\" />\n    <meta content=\"Google launches AI agent suite at Cloud Next 2026 with Workspace Studio, A2A protocol at 150 orgs, and Project Mariner. The pitch: only Google owns the full stack.\" property=\"description\" />\n    <meta content=\"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era\" property=\"url\" />\n\n        <link rel=\"apple-touch-icon\" sizes=\"57x57\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-57x57.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"60x60\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-60x60.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"72x72\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-72x72.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"76x76\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-76x76.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"114x114\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-114x114.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"120x120\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-120x120.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"144x144\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-144x144.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"152x152\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-152x152.png\">\n        <link rel=\"apple-touch-icon\" sizes=\"180x180\" href=\"//static.thenextweb.com/assets/img/favicon/apple-touch-icon-180x180.png\">\n        <link rel=\"icon\" type=\"image/png\" href=\"//static.thenextweb.com/assets/img/favicon/favicon-32x32.png\" sizes=\"32x32\">\n        <link rel=\"icon\" type=\"image/png\" href=\"//static.thenextweb.com/assets/img/favicon/favicon-48x48.png\" sizes=\"48x48\">\n        <link rel=\"icon\" type=\"image/png\" href=\"//static.thenextweb.com/assets/img/favicon/favicon-194x194.png\" sizes=\"194x194\">\n        <link rel=\"icon\" type=\"image/png\" href=\"//static.thenextweb.com/assets/img/favicon/favicon-96x96.png\" sizes=\"96x96\">\n        <link rel=\"icon\" type=\"image/png\" href=\"//static.thenextweb.com/assets/img/favicon/favicon-192x192.png\" sizes=\"192x192\">\n        <link rel=\"icon\" type=\"image/png\" href=\"//static.thenextweb.com/assets/img/favicon/favicon-16x16.png\" sizes=\"16x16\">\n        <link rel=\"shortcut icon\" href=\"//static.thenextweb.com/assets/img/favicon/favicon-16x16.png\">\n        <link rel=\"icon\" href=\"/favicon.ico\">\n        <script src=\"//static.thenextweb.com/assets/js/lib/modernizr-custom.js?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" async></script>\n        <link rel=\"manifest\" href=\"/manifest.json\">\n        <script type=\"module\" src=\"https://cdn.jsdelivr.net/npm/@justinribeiro/lite-youtube@1.3.1/lite-youtube.js\"></script>\n\n        <style>body{visibility:hidden;}</style>\n\n        <!-- Google Tag Manager -->\n        <script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':\n        new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],\n        j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src=\n        'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);\n        })(window,document,'script','dataLayer','GTM-NNKTCH4W');</script>\n        <!-- End Google Tag Manager -->\n\n        <script type=\"text/javascript\">\n            window.dataLayer = window.dataLayer || [];\n        </script>\n\n                \n    \n\n        <script>\n            !function(t,e){var o,n,p,r;e.__SV||(window.posthog && window.posthog.__loaded)||(window.posthog=e,e._i=[],e.init=function(i,s,a){function g(t,e){var o=e.split(\".\");2==o.length&&(t=t[o[0]],e=o[1]),t[e]=function(){t.push([e].concat(Array.prototype.slice.call(arguments,0)))}}(p=t.createElement(\"script\")).type=\"text/javascript\",p.crossOrigin=\"anonymous\",p.async=!0,p.src=s.api_host.replace(\".i.posthog.com\",\"-assets.i.posthog.com\")+\"/static/array.js\",(r=t.getElementsByTagName(\"script\")[0]).parentNode.insertBefore(p,r);var u=e;for(void 0!==a?u=e[a]=[]:a=\"posthog\",u.people=u.people||[],u.toString=function(t){var e=\"posthog\";return\"posthog\"!==a&&(e+=\".\"+a),t||(e+=\" (stub)\"),e},u.people.toString=function(){return u.toString(1)+\".people (stub)\"},o=\"init ts ns yi rs os Qr es capture Hi calculateEventProperties hs register register_once register_for_session unregister unregister_for_session fs getFeatureFlag getFeatureFlagPayload isFeatureEnabled reloadFeatureFlags updateFlags updateEarlyAccessFeatureEnrollment getEarlyAccessFeatures on onFeatureFlags onSurveysLoaded onSessionId getSurveys getActiveMatchingSurveys renderSurvey displaySurvey cancelPendingSurvey canRenderSurvey canRenderSurveyAsync identify setPersonProperties group resetGroups setPersonPropertiesForFlags resetPersonPropertiesForFlags setGroupPropertiesForFlags resetGroupPropertiesForFlags reset get_distinct_id getGroups get_session_id get_session_replay_url alias set_config startSessionRecording stopSessionRecording sessionRecordingStarted captureException startExceptionAutocapture stopExceptionAutocapture loadToolbar get_property getSessionProperty vs us createPersonProfile cs Yr ps opt_in_capturing opt_out_capturing has_opted_in_capturing has_opted_out_capturing get_explicit_consent_status is_capturing clear_opt_in_out_capturing ls debug O ds getPageViewId captureTraceFeedback captureTraceMetric Vr\".split(\" \"),n=0;n<o.length;n++)g(u,o[n]);e._i.push([i,s,a])},e.__SV=1)}(document,window.posthog||[]);\n            posthog.init('phc_U6GxCW1e025EJZwgZdk8dI6LjxInuuygM3K2AswPHYW', {\n                api_host: 'https://eu.i.posthog.com',\n                defaults: '2025-11-30',\n                person_profiles: 'identified_only'\n            })\n        </script>\n\n        <!-- Calendly embed script and styles -->\n        <link href=\"https://calendly.com/assets/external/widget.css\" rel=\"stylesheet\">\n        <script src=\"https://calendly.com/assets/external/widget.js\" type=\"text/javascript\"></script>\n\n        <link href=\"//static.thenextweb.com/assets/next/css/base.css?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" rel=\"stylesheet\" type=\"text/css\">\n                    <link href=\"//static.thenextweb.com/assets/next/css/media.css?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" rel=\"stylesheet\" type=\"text/css\">\n            <noscript>\n                <link href=\"//static.thenextweb.com/assets/next/css/media.css?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" rel=\"stylesheet\" type=\"text/css\">\n            </noscript>\n        \n        <meta http-equiv=\"Content-Security-Policy\" content=\"upgrade-insecure-requests\">\n        <link rel=\"dns-prefetch\" href=\"//media.thenextweb.com/\">\n        <link rel=\"dns-prefetch\" href=\"//static.thenextweb.com/\">\n        <link rel=\"preconnect\" href=\"//media.thenextweb.com/\">\n        <link rel=\"preconnect\" href=\"//static.thenextweb.com/\">\n        <link rel=\"stylesheet preload\" as=\"style\" href=\"//use.fontawesome.com/releases/v5.6.3/css/all.css\" integrity=\"sha384-UHRtZLI+pbxtHCWp1t77Bi1L4ZtiqrqD80Kn4Z8NTSRyMA2Fd33n5dQ8lWUE00s/\" crossorigin=\"anonymous\" async>\n                    <link rel=\"canonical\" href=\"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era\"/>\n        \n        \n                        \n                \n                                        \n                                <!-- JSON-LD Breadcrumbs -->\n    <script type=\"application/ld+json\">\n        {\"@context\":\"http:\\/\\/schema.org\",\"@id\":\"#Breadcrumb\",\"@type\":\"BreadcrumbList\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@id\":\"https:\\/\\/thenextweb.com\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":2,\"item\":{\"@id\":\"https:\\/\\/thenextweb.com\\/corporates-innovation\",\"name\":\"Corporates-innovation\"}},{\"@type\":\"ListItem\",\"position\":3,\"item\":{\"@id\":\"https:\\/\\/thenextweb.com\\/news\\/google-cloud-next-ai-agents-agentic-era\",\"name\":\"Google just launched its agentic enterprise play, and it runs from chip to inbox\"}}]}\n    </script>\n    <!-- JSON-LD schema -->\n    <script type=\"application/ld+json\">\n        {\"@id\": \"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era\", \"url\": \"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era/\", \"name\": \"Google just launched its agentic enterprise play, and it runs from chip to inbox\", \"@type\": \"NewsArticle\", \"@context\": \"http://schema.org\", \"headline\": \"Google just launched its agentic enterprise play, and it runs from chip to inbox\", \"publisher\": {\"url\": \"https://thenextweb.com\", \"logo\": {\"url\": \"https://thenextweb.com/logo.png\", \"@type\": \"ImageObject\", \"width\": 284, \"height\": 60}, \"name\": \"The Next Web\", \"@type\": \"Organization\"}, \"wordCount\": 1770, \"inLanguage\": \"en-US\", \"articleBody\": \"Summary: Google rebranded and consolidated its AI platform at Cloud Next 2026, renaming Vertex AI to the Gemini Enterprise Agent Platform and absorbing Agentspace into a unified Gemini Enterprise product. The announcements include Workspace Studio (no-code agent builder), 200+ models in the Model Garden including Anthropic Claude, partner agents from Box, Workday, Salesforce, and ServiceNow, ADK v1.0 stable releases across four languages, Project Mariner (web-browsing agent), managed MCP servers with Apigee as an API-to-agent bridge, and A2A protocol v1.0 in production at 150 organisations. Kurian framed the strategy as owning the full stack from chip to inbox while competitors “hand you the pieces, not the platform.”\\n\\n\\n \\n\\n\\nGoogle used the opening keynote of Cloud Next 2026 on Tuesday to unveil what amounts to a full rebranding and consolidation of its AI platform around agents. Vertex AI is now the Gemini Enterprise Agent Platform. Google Agentspace, the employee-facing AI assistant, has been absorbed into a unified product called Gemini Enterprise. The announcements span a no-code agent builder for Google Workspace, a redesigned developer platform with more than 200 models including third-party options such as Anthropic’s Claude, a web-browsing agent called Project Mariner, managed MCP servers across Google Cloud services, and the production-grade Agent2Agent protocol for cross-platform agent communication. Thomas Kurian, Google Cloud’s chief executive, titled the keynote “The Agentic Cloud” and drew a deliberate contrast with competitors: other vendors, he said, are “handing you the pieces, not the platform,” leaving teams to integrate components themselves.\\n\\n\\nThe timing is deliberate. OpenAI’s Operator is scoring 87% on complex browser task benchmarks and the company has recruited Cognizant and CGI to push its Codex coding agent into enterprise software shops, with enterprise revenue now accounting for 40% of OpenAI’s total. Anthropic has launched a marketplace for Claude-powered enterprise tools and its Model Context Protocol has reached 10,000 servers and 97 million monthly SDK downloads. Google is fighting from third position in cloud market share, behind AWS and Microsoft Azure, but exited the fourth quarter of 2025 with the fastest growth rate of the three at 50% year on year, and is betting that vertical integration, owning the model, the runtime, the silicon, and the distribution channel through Workspace, gives it an advantage neither competitor can replicate.\\n\\n\\nThe agent stack\\nGoogle Workspace Studio is the most consumer-facing announcement. It is a no-code platform that lets business users build and deploy AI agents across Gmail, Docs, Sheets, Drive, Meet, and Chat by describing automations in plain language. A user can type “every Friday, ping me to update my tracker” and Gemini creates the automation. Workspace Studio connects to third-party applications including Asana, Jira, Mailchimp, and Salesforce, and can call external APIs via webhooks or run custom logic through Apps Script. It is rolling out to Google Workspace business, enterprise, and education customers.\\n\\n\\nThe developer-facing platform, now called the Gemini Enterprise Agent Platform, received deeper upgrades. Agent Designer, a visual flow canvas for building agent workflows, is in preview. Agent Engine Sessions and Memory Bank, which give agents persistent context across interactions, are generally available. A new Agent Garden provides prebuilt agent solutions for customer service, data analysis, and creative tasks. A free tier via Express mode lowers the entry barrier. The Model Garden now hosts more than 200 models spanning Google’s own Gemini and Gemma families, third-party models including Anthropic Claude, and open models such as Llama. Google also announced six new agents for data engineering and coding in BigQuery, including a data engineering agent that automates pipeline creation from natural language prompts and a code interpreter that translates queries into executable Python with visualisations. Partner agents from Box, Workday, Salesforce, ServiceNow, Dun and Bradstreet, and S&P Global are integrated into the platform, giving enterprise customers prebuilt capabilities for document intelligence, HR self-service, IT operations, and financial data.\\n\\n\\nProject Mariner, Google DeepMind’s web-browsing agent powered by Gemini 2.0, scores 83.5% on the WebVoyager benchmark and handles ten concurrent tasks on cloud-based virtual machines. It automates shopping, information retrieval, and form-filling, and is available to Google AI Ultra subscribers in the United States. The roadmap includes a visual builder called Mariner Studio in the second quarter, cross-device synchronisation in the third quarter, and an agent marketplace in the fourth quarter.\\n\\n\\nThe protocol play\\nThe most strategically significant announcement may be the least visible to end users. Google’s Agent2Agent (A2A) protocol, originally launched with more than 50 technology partners, has reached 150 organisations in production, not pilot, routing real tasks between agents built on different platforms. The protocol is now governed by the Linux Foundation’s Agentic AI Foundation and has reached version 1.2, with signed agent cards using cryptographic signatures for domain verification. Microsoft, AWS, Salesforce, SAP, and ServiceNow are running A2A in production environments.\\n\\n\\nA2A is designed to complement rather than compete with Anthropic’s Model Context Protocol (MCP). MCP handles how an agent connects to tools and data sources. A2A handles how agents communicate with each other across organisational and platform boundaries. Google adopted MCP across its own services in December 2025, launching fully managed remote MCP servers for Google Maps, BigQuery, Compute Engine, and Kubernetes Engine, with Cloud Run, Cloud Storage, AlloyDB, Cloud SQL, Spanner, Looker, and Pub/Sub on the roadmap. Apigee, Google’s API management platform, now functions as an MCP bridge, translating any standard API into a discoverable agent tool with existing security and governance controls. Google is simultaneously positioning A2A as the standard for the layer above: the orchestration of multiple agents from multiple vendors working together on a single task.\\n\\n\\nThe practical implication is that a Salesforce agent built on Agentforce can hand off a task to a Google agent running on Vertex AI, which can query a ServiceNow agent for IT asset data, all through A2A without any of the three systems needing to understand each other’s internal architecture. Native A2A support is now built into Google’s Agent Development Kit, LangGraph, CrewAI, LlamaIndex Agents, Semantic Kernel, and AutoGen. Google’s open-source Agent Development Kit reached stable v1.0 releases across Python, Go, and Java, with TypeScript support also available. It is a code-first framework optimised for Gemini but model-agnostic and deployable to any container or Kubernetes environment. The security layer includes Model Armor for defence against indirect prompt injection, zero-trust architecture applied to decentralised agent systems, and access management through Google Cloud IAM with audit logging.\\n\\n\\nThe competitive landscape\\nOpenAI’s own enterprise agent push through Codex and systems integrator partnerships has reached three million weekly users. Anthropic’s enterprise marketplace for Claude-powered tools is building an ecosystem through partners including Snowflake. Microsoft’s Copilot is embedded in virtually every Fortune 500 company. AWS has Bedrock with its own agents framework maturing rapidly. The enterprise AI agent market is not a two-horse race. It is a five-way contest in which each competitor has a structural advantage the others lack.\\n\\n\\nOpenAI has the strongest consumer brand and the most advanced reasoning models. Anthropic has the most trusted safety positioning and the fastest-growing enterprise revenue. Microsoft has the deepest enterprise distribution through Office and Azure. AWS has the largest cloud infrastructure base and the strongest developer gravity. Google’s argument is that it is the only company that owns all four layers of the stack: the custom silicon (Ironwood TPUs), the frontier models (Gemini), the cloud platform (now unified as the Gemini Enterprise Agent Platform), and the enterprise distribution channel (Workspace with more than three billion users across Google’s productivity tools). Kurian framed the strategy explicitly: “If you want to adopt a technology successfully, you need to pick a few important projects and do them well, rather than spraying on a lot of little projects.” No other competitor controls the full vertical from chip to application.\\n\\n\\nGoogle’s own AI Agent Trends report, published ahead of the conference, found that 89% of business teams are already using AI agents and the average organisation runs 12. The most common enterprise use cases are customer service at 49%, marketing at 46%, security operations at 46%, and IT support at 45%. Early customer deployments suggest the productivity claims are not purely theoretical: Danfoss, the Danish industrial manufacturer, automated 80% of transactional decisions in email-based order processing using Google’s agents, reducing response times from 42 hours to near real-time. Suzano, a Brazilian pulp and paper company, built an agent with Gemini Pro that translates natural language into SQL queries, cutting query time by 95% for 50,000 employees.\\n\\n\\nThe model foundation\\nThe agents run on Google’s Gemini model family, with the Gemini 2.5 generation being retired in October in favour of the 3.x line. Gemini 3 Pro and Gemini 3 Flash, released in late 2025 and iterated through early 2026, provide the reasoning backbone. Gemini 3 Flash delivers a 15% improvement in overall accuracy over Gemini 2.5 Flash and is optimised for high-frequency agentic workflows and real-time processing. Gemini 3.1 Pro, the most advanced reasoning variant, is available in preview. A new experimental model, GLM 5, targets complex systems engineering and long-horizon agentic tasks through the Model Garden. Gemini 3.2 is expected to be formally announced during the conference, with an expanded context window beyond one million tokens and optimised parameter counts for reduced inference latency. Demis Hassabis, DeepMind’s chief executive, stated in January that his team is “focusing on Gemini 4 this year.” Google also recently launched Gemma 4 open models under Apache 2.0 licensing, built from the same research as Gemini 3 and providing an open-weight alternative for enterprise customers who need to run models on their own infrastructure.\\n\\n\\nThe infrastructure beneath the models is equally central to the pitch. Ironwood, Google’s seventh-generation TPU announced the same day, delivers 4.6 petaFLOPS per chip and scales to 9,216-chip superpods producing 42.5 exaFLOPS. Anthropic has committed to up to one million Ironwood units. The custom silicon means Google can offer inference at costs that customers buying Nvidia GPUs at retail cannot match, which in a market where inference is the dominant and growing expense, translates directly into pricing power for the agent services that run on top.\\n\\n\\nGoogle Cloud holds roughly 11% of the cloud infrastructure market. AWS holds 31%. Azure holds 25%. The gap is significant and Cloud Next will not close it. But the agentic era, if it materialises at the scale Google is projecting, reshuffles the competitive dynamics in ways that favour a company with a vertically integrated stack over companies that assemble their AI capabilities from multiple vendors. Google is betting that the enterprise customer who adopts AI agents at scale will choose the platform where the model, the runtime, the silicon, the governance, and the productivity suite are all built by the same company and optimised to work together. It is a large bet. Cloud Next 2026 is where Google is asking enterprises to take it.\", \"dateCreated\": \"2026-04-22T14:26:39+00:00\", \"description\": \"Summary: Google rebranded and consolidated its AI platform at Cloud Next 2026, renaming Vertex AI to the Gemini Enterprise Agent Platform and absorbing Agentspace into a unified Gemini Enterprise product. The announcements include Workspace Studio (no-code agent builder), 200+ models in the Model Garden including Anthropic Claude, partner agents from Box, Workday, Salesforce, and ServiceNow, […]\", \"commentCount\": 0, \"dateModified\": \"2026-05-06T20:17:20+00:00\", \"copyrightYear\": \"2026\", \"datePublished\": \"2026-04-22T14:26:39+00:00\", \"copyrightHolder\": {\"url\": \"https://thenextweb.com\", \"logo\": {\"url\": \"https://thenextweb.com/logo.png\", \"@type\": \"ImageObject\", \"width\": 284, \"height\": 60}, \"name\": \"The Next Web\", \"@type\": \"Organization\"}, \"mainEntityOfPage\": {\"@id\": \"https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era/\", \"@type\": \"WebPage\"}, \"sourceOrganization\": {\"url\": \"https://thenextweb.com\", \"logo\": {\"url\": \"https://thenextweb.com/logo.png\", \"@type\": \"ImageObject\", \"width\": 284, \"height\": 60}, \"name\": \"The Next Web\", \"@type\": \"Organization\"}}\n    </script>\n        <script>\n            var APP_ENV = {\n                'site_url': 'https://next.thenextweb.com/' + '',\n                'cookie_domain': '.thenextweb.com'\n            };\n        </script>\n                                    \n        <script>\n        \n        (function () {\n          window.dataLayer = window.dataLayer || [];\n\n          window.dataLayer.push(arguments);\n\n          window.dataLayer.push({\n            event: 'defaultConsentSet',\n            consentStatus: arguments[2],\n          });\n\n          window.dispatchEvent(new CustomEvent('defaultConsentSet', {\n            detail: {\n              consent: arguments[2],\n            },\n          }));\n        }('consent', 'default', (function () {\n          const defaults = {\n            ad_storage: 'denied',\n            analytics_storage: 'denied'\n          };\n\n          let cookie = document.cookie.split('; ').find(function(row) {\n            return row.startsWith('__tnw_cookieConsent=');\n          });\n\n          if (typeof cookie === 'undefined') {\n            return defaults;\n          }\n\n          cookie = cookie.slice(20);\n\n          try {\n            cookie = JSON.parse(decodeURIComponent(cookie));\n          } catch (e) {\n            return defaults;\n          }\n\n          return cookie;\n        }())));\n        \n        </script>\n    </head>\n\n                    \n        \n        \n            \n    \n                \n    \n    \n    <body class=\"site-tnwNext preload\" id=\"next-top\">\n        <!-- Google Tag Manager (noscript) -->\n        <noscript><iframe src=\"https://www.googletagmanager.com/ns.html?id=GTM-NNKTCH4W\"\n        height=\"0\" width=\"0\" style=\"display:none;visibility:hidden\"></iframe></noscript>\n        <!-- End Google Tag Manager (noscript) -->\n        <a class=\"skip-link\" href=\"#main\">Skip to content</a>\n\n        \n\n        <div id=\"fb-root\"></div>\n            <div id=\"_progress\" class=\"corporates-innovation\"></div>\n\n                <nav class=\"c-nav has-level2\" id=\"nav\" role=\"navigation\" style=\"top: 0;\">\n        <div class=\"c-nav__level1\">\n        <button class=\"c-nav__menuToggle c-nav__menuToggle--level-1 js-menuToggleLevel\" data-nav-level=\"1\" id=\"nav-menuLevel1\" type=\"button\" aria-haspopup=\"true\" aria-controls=\"overlay__hook\" aria-expanded=\"false\">\n          <span class=\"visually-hidden\">Toggle Navigation</span>\n        </button>\n\n        <div class=\"navLabel_dt\">\n            <a class=\"c-nav__logo\" href=\"/\" data-event-category=\"Article\" data-event-action=\"Navigation bar\" data-event-label=\"TNW Logo\" name=\"TNW Logo\" data-event-non-interaction=\"false\">\n                <svg preserveAspectRatio=\"xMidYMid meet\" viewBox=\"0 0 66 16\">\n                    <path d=\"M32.23993 5A6.00284 6.00284 0 0 1 34 9.24261V16h-6v-5.929a2.00249 2.00249 0 0 0-.58856-1.41424l-2.07239-2.07101A2.00315 2.00315 0 0 0 23.92346 6H22v10h-6V0h8.75189a6 6 0 0 1 4.24268 1.75739zM60 0v5.929a2.00245 2.00245 0 0 1-.58856 1.41418l-2.07385 2.071A1.99969 1.99969 0 0 1 55.9234 10h-2.88214A5.99166 5.99166 0 0 0 54 6.75732V0h-6v5.929a2.00245 2.00245 0 0 1-.58856 1.41418l-2.07385 2.071A1.99969 1.99969 0 0 1 43.9234 10H42V0h-6v16h8.75189a6.003 6.003 0 0 0 4.244-1.75739L51 12.23938V16h5.75189a6.003 6.003 0 0 0 4.244-1.75739l3.244-3.24267A6.00264 6.00264 0 0 0 66 6.75732V0zM0 6h4v10h6V6h4V0H0z\"></path>\n                </svg>\n            </a>\n\n                                            \n            \n            \n                    \n                                                \n                                                                        \n                \n                        </div>\n\n        <div class=\"c-nav__menuContainer c-nav__menuContainer--1\" id=\"overlay__hook\">\n            \n            <ul class=\"c-nav__menu\">\n\n                \n                                                                \n                                                    \n                        \n                                                                                                            \n                                        \n                            \n                        \n                                                                                <li class=\"c-nav__menuItem\">\n                                <a class=\"c-nav__menuLink\" data-event-category=\"Navigation bar\" data-event-action=\"News\" data-event-label=\"/\" data-event-non-interaction=\"false\" href=\"/\" >\n                                    News\n                                </a>\n                            </li>\n                        \n                                                        \n                        \n                                                            \n                            \n                        \n                        \n                                                        \n                                                                    \n                            \n                                                                                                                            \n\n                                                        <li class=\"c-nav__menuItem has-menu\">\n                                <button class=\"c-nav__menuLink\" type=\"button\" aria-haspopup=\"true\" aria-expanded=\"false\">Events</button>\n\n                                <ul class=\"c-nav__submenu\" role=\"menu\">\n                                                                            \n                                        \n                                        <li class=\"c-nav__submenuItem\">\n                                            <a class=\"c-nav__submenuLink\" href=\"/conference\" data-event-category=\"Navigation bar\" data-event-action=\"TNW Conference\" data-event-label=\"/conference\" data-event-non-interaction=\"false\"  >\n                                                <span class=\"c-nav__submenuLinkTitle\" data-event-category=\"Navigation bar\" data-event-action=\"TNW Conference\" data-event-label=\"/conference\" data-event-non-interaction=\"false\">TNW Conference</span>\n                                                <span class=\"c-nav__submenuLinkNote\">June 19 &amp; 20, 2025</span>\n                                            </a>\n                                        </li>\n                                                                            \n                                        \n                                        <li class=\"c-nav__submenuItem\">\n                                            <a class=\"c-nav__submenuLink\" href=\"/events\" data-event-category=\"Navigation bar\" data-event-action=\"All events\" data-event-label=\"/events\" data-event-non-interaction=\"false\"  >\n                                                <span class=\"c-nav__submenuLinkTitle\" data-event-category=\"Navigation bar\" data-event-action=\"All events\" data-event-label=\"/events\" data-event-non-interaction=\"false\">All events</span>\n                                                <span class=\"c-nav__submenuLinkNote\"></span>\n                                            </a>\n                                        </li>\n                                                                    </ul>\n                            </li>\n                        \n                                                                                                                        </ul>\n\n            \n                                    \n                            <hr class=\"mobile_menu_divider \"/>\n                <ul class=\"c-nav__menu c-nav__icons\">\n                                                      \t\t\t\t\t\n              \t\t\t\t\t\n                        \n                                        \t\t\t\t\t\t              \t\t\t\t\t\n              \t\t\t\t\t<li class=\"c-nav__menuItem c-nav__iconsItem\">\n                \t\t\t\t\t\t<a href=\"/newsletters\" class=\"c-nav__menuLink\" data-event-category=\"Navigation bar\" data-event-action=\"Newsletter\" data-event-label=\"Newsletters top right - click\" data-event-non-interaction=\"false\">\n                               \t\t\t    <span data-event-category=\"Navigation bar\" data-event-action=\"Newsletters\" data-event-label=\"/newsletters\" data-event-non-interaction=\"false\" class=\"c-nav__iconsItem--label\">Newsletters</span>\n                \t\t\t\t\t\t</a>\n              \t\t\t\t\t</li>\n                                  \t\t\t\t\t\n              \t\t\t\t\t\n                        \n                        \n              \t\t\t\t\t<li class=\"c-nav__menuItem c-nav__iconsItem\">\n                \t\t\t\t\t\t<a href=\"/partnerships\" class=\"c-nav__menuLink\">\n                               \t\t\t    <span data-event-category=\"Navigation bar\" data-event-action=\"Partner with us\" data-event-label=\"/partnerships\" data-event-non-interaction=\"false\" class=\"c-nav__iconsItem--label\">Partner with us</span>\n                \t\t\t\t\t\t</a>\n              \t\t\t\t\t</li>\n                            \t\t\t\t</ul>\n\n\n            \n                        \n            <footer class=\"c-nav__footer\">\n                <ul class=\"c-nav__social\">\n                    <li class=\"c-nav__socialItem\">\n                        <a class=\"c-nav__socialLink\" href=\"https://facebook.com/thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Facebook Social Link\">\n                            <svg class=\"c-nav__socialIcon\"><use xlink:href=\"/assets/next/img/icons.svg#facebook\"></use></svg>\n                        </a>\n                    </li>\n                    <li class=\"c-nav__socialItem\">\n                        <a class=\"c-nav__socialLink\" href=\"https://www.instagram.com/thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Instagram Social Link\">\n                            <svg class=\"c-nav__socialIcon\"><use xlink:href=\"/assets/next/img/icons.svg#instagram\"></use></svg>\n                        </a>\n                    </li>\n                    <li class=\"c-nav__socialItem\">\n                        <a class=\"c-nav__socialLink\" href=\"https://twitter.com/thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Twitter Social Link\">\n                            <svg class=\"c-nav__socialIcon\"><use xlink:href=\"/assets/next/img/icons.svg#twitter\"></use></svg>\n                        </a>\n                    </li>\n                    <li class=\"c-nav__socialItem\">\n                        <a class=\"c-nav__socialLink\" href=\"https://youtube.com/user/thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Youtube Social Link\">\n                            <svg class=\"c-nav__socialIcon\"><use xlink:href=\"/assets/next/img/icons.svg#youtube\"></use></svg>\n                        </a>\n                    </li>\n                    <li class=\"c-nav__socialItem\">\n                        <a class=\"c-nav__socialLink\" href=\"https://flipboard.com/@thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Flipboard Social Link\">\n                            <svg class=\"c-nav__socialIcon\"><use xlink:href=\"/assets/next/img/icons.svg#flipboard\"></use></svg>\n                        </a>\n                    </li>\n                    <li class=\"c-nav__socialItem\">\n                        <a class=\"c-nav__socialLink\" href=\"/newsletters\" name=\"Email Social Link\">\n                            <svg class=\"c-nav__socialIcon\"><use xlink:href=\"/assets/next/img/icons.svg#mail\"></use></svg>\n                        </a>\n                    </li>\n                </ul>\n\n                <ul class=\"c-nav__company\">\n                    <li class=\"c-nav__companyItem\">\n                        <a class=\"c-nav__companyLink\" href=\"https://thenextweb.homerun.co/\" target=\"_blank\" rel=\"noopener noreferrer\">Jobs</a>\n                    </li>\n                    <li class=\"c-nav__companyItem\"><a class=\"c-nav__companyLink\" href=\"/cdn-cgi/l/email-protection#086b67666e6d7a6d666b6d487c606d666d707c7f6d6a266b6765\">Contact</a></li>\n                </ul>\n            </footer>\n\n        </div>\n    </div>\n    \n    \n    \n                \n    \n        \n            <div class=\"c-nav__level2 tnw news\">\n                <div class=\"c-nav__pwd\">\n                                            <a class=\"c-nav__pwdLogo\" href=\"/\">\n                            <svg class=\"tnwLogo__ft\"><use xlink:href=\"/assets/next/img/icons.svg#tnwFT\"></use></svg>\n                            <svg class=\"tnwLogo__tnw\"><use xlink:href=\"/assets/next/img/icons.svg#tnw\"></use></svg>\n                        </a>\n                                                                                    \n                    <span class=\"c-nav__pwdSection\">News</span>\n                </div>\n\n                                \n                \n                                    <div class=\"c-nav__menuContainer c-nav__menuContainer--2 hidden\">\n                        <ul class=\"c-nav__menu\">\n                            \n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"/latest\" data-event-category=\"Navigation bar\" data-event-action=\"Latest\" data-event-label=\"/latest\" data-event-non-interaction=\"false\">Latest</a>\n                                </li>\n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"/deep-tech\" data-event-category=\"Navigation bar\" data-event-action=\"Deep tech\" data-event-label=\"/deep-tech\" data-event-non-interaction=\"false\">Deep tech</a>\n                                </li>\n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"/sustainability\" data-event-category=\"Navigation bar\" data-event-action=\"Sustainability\" data-event-label=\"/sustainability\" data-event-non-interaction=\"false\">Sustainability</a>\n                                </li>\n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"/ecosystems\" data-event-category=\"Navigation bar\" data-event-action=\"Ecosystems\" data-event-label=\"/ecosystems\" data-event-non-interaction=\"false\">Ecosystems</a>\n                                </li>\n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"/data-security\" data-event-category=\"Navigation bar\" data-event-action=\"Data and security\" data-event-label=\"/data-security\" data-event-non-interaction=\"false\">Data and security</a>\n                                </li>\n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"/fintech-ecommerce\" data-event-category=\"Navigation bar\" data-event-action=\"Fintech and ecommerce\" data-event-label=\"/fintech-ecommerce\" data-event-non-interaction=\"false\">Fintech and ecommerce</a>\n                                </li>\n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"/future-of-work\" data-event-category=\"Navigation bar\" data-event-action=\"Future of work\" data-event-label=\"/future-of-work\" data-event-non-interaction=\"false\">Future of work</a>\n                                </li>\n                                                            \n                                \n                                <li class=\"c-nav__menuItem\">\n                                    <a class=\"c-nav__menuLink\" href=\"https://thenextweb.com/topic/tnw-conference\" data-event-category=\"Navigation bar\" data-event-action=\"Conference media hub\" data-event-label=\"https://thenextweb.com/topic/tnw-conference\" data-event-non-interaction=\"false\">Conference media hub</a>\n                                </li>\n                            \n                            \n                                                            \n                                                                                                                                                                                                                                                                                                                                                                                    \n                                <li class=\"c-nav__menuItem has-menu\">\n                                    <button class=\"c-nav__menuLink\" type=\"button\" aria-haspopup=\"true\" aria-expanded=\"false\">More</button>\n\n                                    <ul class=\"c-nav__submenu\">\n                                                                                    \n                                            \n                                            <li class=\"c-nav__submenuItem\">\n                                                <a class=\"c-nav__submenuLink\" href=\"/startups-technology\">\n                                                    <span class=\"c-nav__submenuLinkTitle\" data-event-category=\"Navigation bar\" data-event-action=\"Startups and technology\" data-event-label=\"/startups-technology\" data-event-non-interaction=\"false\">Startups and technology</span>\n                                                </a>\n                                            </li>\n                                                                                    \n                                            \n                                            <li class=\"c-nav__submenuItem\">\n                                                <a class=\"c-nav__submenuLink\" href=\"/investors-funding\">\n                                                    <span class=\"c-nav__submenuLinkTitle\" data-event-category=\"Navigation bar\" data-event-action=\"Investors and funding\" data-event-label=\"/investors-funding\" data-event-non-interaction=\"false\">Investors and funding</span>\n                                                </a>\n                                            </li>\n                                                                                    \n                                            \n                                            <li class=\"c-nav__submenuItem\">\n                                                <a class=\"c-nav__submenuLink\" href=\"/government-policy\">\n                                                    <span class=\"c-nav__submenuLinkTitle\" data-event-category=\"Navigation bar\" data-event-action=\"Government and policy\" data-event-label=\"/government-policy\" data-event-non-interaction=\"false\">Government and policy</span>\n                                                </a>\n                                            </li>\n                                                                                    \n                                            \n                                            <li class=\"c-nav__submenuItem\">\n                                                <a class=\"c-nav__submenuLink\" href=\"/corporates-innovation\">\n                                                    <span class=\"c-nav__submenuLinkTitle\" data-event-category=\"Navigation bar\" data-event-action=\"Corporates and innovation\" data-event-label=\"/corporates-innovation\" data-event-non-interaction=\"false\">Corporates and innovation</span>\n                                                </a>\n                                            </li>\n                                                                                    \n                                            \n                                            <li class=\"c-nav__submenuItem\">\n                                                <a class=\"c-nav__submenuLink\" href=\"https://fast.wistia.com/embed/channel/hckmzyzq7e\">\n                                                    <span class=\"c-nav__submenuLinkTitle\" data-event-category=\"Navigation bar\" data-event-action=\"Podcast\" data-event-label=\"https://fast.wistia.com/embed/channel/hckmzyzq7e\" data-event-non-interaction=\"false\">Podcast</span>\n                                                </a>\n                                            </li>\n                                                                            </ul>\n                                </li>\n                                                    </ul>\n\n                        <button class=\"c-nav__menuScroller\" type=\"button\" aria-hidden=\"true\"></button>\n                    </div>\n                            </div>\n\n        \n        </nav>\n                        <div class=\"o-page\" id=\"main\">\n            <div class=\"o-page__main\">\n                        \n    \n        \n    \n    <main class=\"c-channel c-channel--latest o-page__main\" id=\"article_container\">\n        \n        <div class=\"c-articles\">\n                        <div class=\"c-articles__backdrop\"><div class=\"c-articles__backdrop--sticky\"></div></div>\n\n                                                <div class=\"c-nav__message c-nav__message--article news\" style=\"top:0\">\n                        <p>This article was published on <strong>April 22, 2026</strong></p>\n                    </div>\n                \n\n                \n                <header class=\"c-header\">\n                    <div class=\"o-wrapper\">\n                        <div class=\"c-header__text\">\n                            <ul class=\"c-header__tags c-tags c-tags--centered\">\n                                <li class=\"c-tags__tag\">\n                                    <a class=\"c-tags__link c-article-leadtag\" data-event-category=\"Article\" data-event-action=\"Tags\" data-event-label=\"Corporates and innovation\" data-event-non-interaction=\"false\" href=\"/corporates-innovation\">Corporates and innovation</a>\n                                </li>\n                            </ul>\n\n                            <h1 class=\"c-header__heading\">\n                                Google just launched its agentic enterprise play, and it runs from chip to inbox\n                            </h1>\n\n                            \n                            <br/>\n\n                            <div>\n                                <time datetime=\"April 22, 2026 - 2:26 pm\">April 22, 2026 - 2:26 pm</time>\n                            </div>\n                        </div>\n\n                        <div aria-hidden=\"true\" class=\"c-share lg:hidden\">\n                            <a class=\"c-share__link c-share__link--facebook\" rel=\"noopener\" target=\"_blank\" onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\" href=\"https://www.facebook.com/sharer/sharer.php?s=100&amp;p[url]=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dfacebook%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button&amp;p[title]=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox&amp;p[images][0]=https%3A%2F%2Fmedia.thenextweb.com%2F2026%2F04%2Fgoogle-cloud-next-ai-agents-agentic-era.avif&amp;u=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era&amp;t=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox\">\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#facebook\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-share__link c-share__link--twitter\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://twitter.com/intent/tweet?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dtwitter%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button%26referral&amp;via=thenextweb&amp;related=thenextweb&amp;text=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#twitter\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-share__link c-share__link--flipboard\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://share.flipboard.com/bookmarklet/popout?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dflipboard%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#flipboard\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-share__link c-share__link--linkedin\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=500,height=500'); return false;\"\n                                href=\"https://www.linkedin.com/shareArticle/?mini=true&amp;url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dlinkedin%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#linkedin\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-share__link c-share__link--telegram\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://t.me/share/url?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dtelegram%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#telegram\"></use></svg>\n                            </a>\n\n                            <a class=\"c-share__link c-share__link--mail\" href=\"/cdn-cgi/l/email-protection#3e014d4b5c545b5d4a0379515159525b1e544b4d4a1e525f4b505d565b5a1e574a4d1e5f595b504a575d1e5b504a5b4c4e4c574d5b1e4e525f47121e5f505a1e574a1e4c4b504d1e584c51531e5d56574e1e4a511e57505c5146185f534e055c515a4703564a4a4e4d0411114a565b505b464a495b5c105d515311505b494d1159515159525b135d52514b5a13505b464a135f57135f595b504a4d135f595b504a575d135b4c5f1b0d784b4a53614d514b4c5d5b1b0d7a5b535f57521b0c084b4a5361535b5a574b531b0d7a4d565f4c5b1b0c084b4a53615d5f534e5f5759501b0d7a5f4c4a575d525b134d565f4c5b135c4b4a4a5150\">\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#mail\"></use></svg>\n                            </a>\n                        </div>\n                    </div>\n                </header>\n            \n                            <div class=\"e-empty__hidden\"></div>\n\n                                    <div class=\"screen-size desktop-screen\">\n                        <style scoped>#tnw-next-header{height:250px;}@media(min-width:768px){#tnw-next-header{height:250px;}@media(min-width:1024px){#tnw-next-header{height:250px;}</style><div class=\"tnw-ad tnw-ad--billboard tnw-ad--has-placeholder\" id=\"tnw-next-header\" data-args='{\"networkCode\":5117602,\"slot\":\"TNW_NEXT_HEADER\",\"googletagAttempts\":20,\"animate\":false,\"fallback\":false,\"sizes\":[[320,240],[300,250],[970,250],[970,90],[728,90],[320,50],[300,100],[300,50],[320,100]],\"sizeMapping\":[[[1024,0],[[970,250],[970,90],[728,90]]],[[0,0],[[300,250],[320,50],[300,50],[300,100],[320,100],[320,240]]]],\"targeting\":{\"title\":[\"Google just launched its agentic enterprise play, and it runs from chip to inbox\"],\"category\":[\"corporates-innovation\"],\"isSponsored\":[\"No\"]},\"lazyLoad\":\"true\",\"refreshEvery\":\"\",\"debugMode\":false}'></div>\n                    </div>\n\n                    <script data-cfasync=\"false\" src=\"/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js\"></script><script>\n                        document.getElementsByClassName('tnw-ad-wrapper')[0]?.classList.add('ad-wrapper__growth-quarters');\n                    </script>\n                            \n            <div class=\"o-wrapper mb-4xl\" >\n                <article class=\"c-article js-article mt-m\" id=\"articleOutput\"  style=\"margin-top: 0px;\" >\n                                                                        <div class=\"c-article__media c-article__growth-mobile\">\n                                <figure class=\"o-media o-media--16:9\">\n                                    <img\n                                        alt=\"Google just launched its agentic enterprise play, and it runs from chip to inbox\"\n                                        class=\"js-lazy c-article__mediaImage w-full absolute top-0\"\n                                                                                src=\"https://media.thenextweb.com/2026/04/google-cloud-next-ai-agents-agentic-era.avif\"\n                                                                            >\n                                                                            <a class=\"c-article__mediaCredit\" href=\"https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/gemini-enterprise-agent-platform/\">\n                                            <svg class=\"c-article__mediaCreditIcon\"><use xlink:href=\"/assets/next/img/icons.svg#camera\"></use></svg>\n\n                                            <span class=\"c-article__mediaCreditText\">Image by: Google</span>\n                                        </a>\n                                                                    </figure>\n                            </div>\n                        \n                                                    <div class=\"screen-size mobile-screen\" style=\"text-align: center\"></div>\n                            <script>\n                                document.getElementsByClassName('tnw-ad-wrapper')[1]?.classList?.add('ad-wrapper__growth-quarters');\n                            </script>\n                                            \n                    \n                    \n\n                    \n                    <div class=\"c-article__main max-lg:mb-xxl\">\n                        <div class=\"c-richText c-richText--large\" id=\"article-main-content\">\n                            <p><em>Summary: Google rebranded and consolidated its AI platform at Cloud Next 2026, renaming Vertex AI to the Gemini Enterprise Agent Platform and absorbing Agentspace into a unified Gemini Enterprise product. The announcements include Workspace Studio (no-code agent builder), 200+ models in the Model Garden including Anthropic Claude, partner agents from Box, Workday, Salesforce, and ServiceNow, ADK v1.0 stable releases across four languages, Project Mariner (web-browsing agent), managed MCP servers with Apigee as an API-to-agent bridge, and A2A protocol v1.0 in production at 150 organisations. Kurian framed the strategy as owning the full stack from chip to inbox while competitors “hand you the pieces, not the platform.”</em></p>\n<p> </p>\n<p>Google used the opening keynote of Cloud Next 2026 on Tuesday to unveil what amounts to a full rebranding and consolidation of its AI platform around agents. Vertex AI is now the Gemini Enterprise Agent Platform. Google Agentspace, the employee-facing AI assistant, has been absorbed into a unified product called Gemini Enterprise. The announcements span a no-code agent builder for Google Workspace, a redesigned developer platform with more than 200 models including third-party options such as Anthropic’s Claude, a web-browsing agent called Project Mariner, managed MCP servers across Google Cloud services, and the production-grade Agent2Agent protocol for cross-platform agent communication. Thomas Kurian, Google Cloud’s chief executive, titled the keynote “The Agentic Cloud” and drew a deliberate contrast with competitors: other vendors, he said, are “handing you the pieces, not the platform,” leaving teams to integrate components themselves.</p>\n<p>The timing is deliberate. OpenAI’s Operator is scoring 87% on complex browser task benchmarks and the company has recruited Cognizant and CGI to push its Codex coding agent into enterprise software shops, with enterprise revenue now accounting for 40% of OpenAI’s total. Anthropic has launched a marketplace for Claude-powered enterprise tools and its Model Context Protocol has reached 10,000 servers and 97 million monthly SDK downloads. Google is fighting from third position in cloud market share, behind AWS and Microsoft Azure, but exited the fourth quarter of 2025 with the fastest growth rate of the three at 50% year on year, and is betting that vertical integration, owning the model, the runtime, the silicon, and the distribution channel through Workspace, gives it an advantage neither competitor can replicate.</p>\n<h2>The agent stack</h2>\n<div class=\"inarticle-wrapper channel-cta\"><div class=\"ica-text\"><a href=\"https://thenextweb.com/spaces/book-a-tour\" data-event-category=\"Article\" data-event-action=\"In Article Block\" data-event-label=\"TNW City Coworking space - Where your best work happens\" target=\"_blank\"><p class=\"ica-text__title\">TNW City Coworking space - Where your best work happens</p><p>A workspace designed for growth, collaboration, and endless networking opportunities in the heart of tech.</p></a></div><div class=\"ica-button\">\n                        <a class=\"c-button c-button--primary\" data-event-category=\"Article\" data-event-action=\"In Article Block\" data-event-label=\"Book a tour now\" href=\"https://thenextweb.com/spaces/book-a-tour\" target=\"_blank\">Book a tour now</a>\n                    </div></div><p>Google Workspace Studio is the most consumer-facing announcement. It is a no-code platform that lets business users build and deploy AI agents across Gmail, Docs, Sheets, Drive, Meet, and Chat by describing automations in plain language. A user can type “every Friday, ping me to update my tracker” and Gemini creates the automation. Workspace Studio connects to third-party applications including Asana, Jira, Mailchimp, and Salesforce, and can call external APIs via webhooks or run custom logic through Apps Script. It is rolling out to Google Workspace business, enterprise, and education customers.</p>\n<p>The developer-facing platform, now called the Gemini Enterprise Agent Platform, received deeper upgrades. Agent Designer, a visual flow canvas for building agent workflows, is in preview. Agent Engine Sessions and Memory Bank, which give agents persistent context across interactions, are generally available. A new Agent Garden provides prebuilt agent solutions for customer service, data analysis, and creative tasks. A free tier via Express mode lowers the entry barrier. The Model Garden now hosts more than 200 models spanning Google’s own Gemini and Gemma families, third-party models including Anthropic Claude, and open models such as Llama. Google also announced six new agents for data engineering and coding in BigQuery, including a data engineering agent that automates pipeline creation from natural language prompts and a code interpreter that translates queries into executable Python with visualisations. Partner agents from Box, Workday, Salesforce, ServiceNow, Dun and Bradstreet, and S&amp;P Global are integrated into the platform, giving enterprise customers prebuilt capabilities for document intelligence, HR self-service, IT operations, and financial data.</p>\n<p>Project Mariner, Google DeepMind’s web-browsing agent powered by Gemini 2.0, scores 83.5% on the WebVoyager benchmark and handles ten concurrent tasks on cloud-based virtual machines. It automates shopping, information retrieval, and form-filling, and is available to Google AI Ultra subscribers in the United States. The roadmap includes a visual builder called Mariner Studio in the second quarter, cross-device synchronisation in the third quarter, and an agent marketplace in the fourth quarter.</p>\n<h2>The protocol play</h2>\n<p>The most strategically significant announcement may be the least visible to end users. Google’s<span> </span><a href=\"https://thenextweb.com/news/stop-talking-to-ai-let-them-talk-to-each-other-the-a2a-protocol\">Agent2Agent (A2A) protocol</a>, originally launched with more than 50 technology partners, has reached 150 organisations in production, not pilot, routing real tasks between agents built on different platforms. The protocol is now governed by the Linux Foundation’s Agentic AI Foundation and has reached version 1.2, with signed agent cards using cryptographic signatures for domain verification. Microsoft, AWS, Salesforce, SAP, and ServiceNow are running A2A in production environments.</p>\n<p>A2A is designed to complement rather than compete with Anthropic’s<span> </span><a href=\"https://thenextweb.com/news/rise-of-model-context-protocol-in-the-agentic-era\">Model Context Protocol (MCP)</a>. MCP handles how an agent connects to tools and data sources. A2A handles how agents communicate with each other across organisational and platform boundaries. Google adopted MCP across its own services in December 2025, launching fully managed remote MCP servers for Google Maps, BigQuery, Compute Engine, and Kubernetes Engine, with Cloud Run, Cloud Storage, AlloyDB, Cloud SQL, Spanner, Looker, and Pub/Sub on the roadmap. Apigee, Google’s API management platform, now functions as an MCP bridge, translating any standard API into a discoverable agent tool with existing security and governance controls. Google is simultaneously positioning A2A as the standard for the layer above: the orchestration of multiple agents from multiple vendors working together on a single task.</p>\n<p>The practical implication is that a Salesforce agent built on Agentforce can hand off a task to a Google agent running on Vertex AI, which can query a ServiceNow agent for IT asset data, all through A2A without any of the three systems needing to understand each other’s internal architecture. Native A2A support is now built into Google’s Agent Development Kit, LangGraph, CrewAI, LlamaIndex Agents, Semantic Kernel, and AutoGen. Google’s open-source Agent Development Kit reached stable v1.0 releases across Python, Go, and Java, with TypeScript support also available. It is a code-first framework optimised for Gemini but model-agnostic and deployable to any container or Kubernetes environment. The security layer includes Model Armor for defence against indirect prompt injection, zero-trust architecture applied to decentralised agent systems, and access management through Google Cloud IAM with audit logging.</p>\n<h2>The competitive landscape</h2>\n<p><a href=\"https://thenextweb.com/news/openai-codex-enterprise-partners-cognizant-cgi\">OpenAI’s own enterprise agent push</a><span> </span>through Codex and systems integrator partnerships has reached three million weekly users.<span> </span><a href=\"https://thenextweb.com/news/anthropic-marketplace-claude-enterprise-software\">Anthropic’s enterprise marketplace</a><span> </span>for Claude-powered tools is building an ecosystem through partners including Snowflake. Microsoft’s Copilot is embedded in virtually every Fortune 500 company. AWS has Bedrock with its own agents framework maturing rapidly. The enterprise AI agent market is not a two-horse race. It is a five-way contest in which each competitor has a structural advantage the others lack.</p>\n<p>OpenAI has the strongest consumer brand and the most advanced reasoning models. Anthropic has the most trusted safety positioning and the fastest-growing enterprise revenue. Microsoft has the deepest enterprise distribution through Office and Azure. AWS has the largest cloud infrastructure base and the strongest developer gravity. Google’s argument is that it is the only company that owns all four layers of the stack: the custom silicon (Ironwood TPUs), the frontier models (Gemini), the cloud platform (now unified as the Gemini Enterprise Agent Platform), and the enterprise distribution channel (Workspace with more than three billion users across Google’s productivity tools). Kurian framed the strategy explicitly: “If you want to adopt a technology successfully, you need to pick a few important projects and do them well, rather than spraying on a lot of little projects.” No other competitor controls the full vertical from chip to application.</p>\n<p>Google’s own AI Agent Trends report, published ahead of the conference, found that 89% of business teams are already using AI agents and the average organisation runs 12. The most common enterprise use cases are customer service at 49%, marketing at 46%, security operations at 46%, and IT support at 45%. Early customer deployments suggest the productivity claims are not purely theoretical: Danfoss, the Danish industrial manufacturer, automated 80% of transactional decisions in email-based order processing using Google’s agents, reducing response times from 42 hours to near real-time. Suzano, a Brazilian pulp and paper company, built an agent with Gemini Pro that translates natural language into SQL queries, cutting query time by 95% for 50,000 employees.</p>\n<h2>The model foundation</h2>\n<p>The agents run on Google’s Gemini model family, with the Gemini 2.5 generation being retired in October in favour of the 3.x line. Gemini 3 Pro and Gemini 3 Flash, released in late 2025 and iterated through early 2026, provide the reasoning backbone. Gemini 3 Flash delivers a 15% improvement in overall accuracy over Gemini 2.5 Flash and is optimised for high-frequency agentic workflows and real-time processing. Gemini 3.1 Pro, the most advanced reasoning variant, is available in preview. A new experimental model, GLM 5, targets complex systems engineering and long-horizon agentic tasks through the Model Garden. Gemini 3.2 is expected to be formally announced during the conference, with an expanded context window beyond one million tokens and optimised parameter counts for reduced inference latency. Demis Hassabis, DeepMind’s chief executive, stated in January that his team is “focusing on Gemini 4 this year.” Google also recently launched<span> </span><a href=\"https://thenextweb.com/news/google-gemma-4-open-models-apache-2-launch\">Gemma 4 open models</a><span> </span>under Apache 2.0 licensing, built from the same research as Gemini 3 and providing an open-weight alternative for enterprise customers who need to run models on their own infrastructure.</p>\n<p>The infrastructure beneath the models is equally central to the pitch. Ironwood, Google’s seventh-generation TPU announced the same day, delivers 4.6 petaFLOPS per chip and scales to 9,216-chip superpods producing 42.5 exaFLOPS. Anthropic has committed to up to one million Ironwood units. The custom silicon means Google can offer inference at costs that customers buying Nvidia GPUs at retail cannot match, which in a market where inference is the dominant and growing expense, translates directly into pricing power for the agent services that run on top.</p>\n<p>Google Cloud holds roughly 11% of the cloud infrastructure market. AWS holds 31%. Azure holds 25%. The gap is significant and Cloud Next will not close it. But the agentic era, if it materialises at the scale Google is projecting, reshuffles the competitive dynamics in ways that favour a company with a vertically integrated stack over companies that assemble their AI capabilities from multiple vendors. Google is betting that the enterprise customer who adopts AI agents at scale will choose the platform where the model, the runtime, the silicon, the governance, and the productivity suite are all built by the same company and optimised to work together. It is a large bet. Cloud Next 2026 is where Google is asking enterprises to take it.</p>\n                        </div>\n\n                        <aside class=\"c-contributor latest\">\n                            <a\n                                href=\"/author/alina\"\n                                target=\"_blank\"\n                                rel=\"noopener\"\n                                data-event-category=\"Article\"\n                                data-event-action=\"Author\"\n                                data-event-label=\"Alina Maria Stan\"\n                                data-event-non-interaction=\"false\"\n                            >\n                                <img\n                                    alt=\"Alina Maria Stan\"\n                                    class=\"c-contributor__photo js-lazy\"\n                                    src=\"https://media.thenextweb.com/2025/12/Alina-Maria-Stan.avif\"\n                                >\n                            </a>\n                            <div aria-label=\"Author Bio\" class=\"c-contributor__main\">\n                                <h2 class=\"c-contributor__wrapper\">\n                                    <span class=\"c-contributor__heading\">\n                                        Story by\n                                    </span>\n\n                                    <span class=\"c-contributor__name\" >\n                                        <a href=\"/author/alina\" class=\"latest\">\n                                            Alina Maria Stan\n                                        </a>\n                                    </span>\n                                </h2>\n\n                                \n                                                                    <p class=\"c-contributor__text\">\n                                        <input class=\"c-contributor__expandInput\" id=\"contributorExpandInput123\" name=\"expand\" type=\"checkbox\">\n\n                                        <span class=\"c-contributor__bio c-contributor__bio--truncated\">\n                                            Alina Maria Stan builds connections that people actually feel. As co-founder and COO of Tekpon, she turns product intuition into real moment\n\n                                                                                            <label class=\"c-contributor__expand corporates-innovation\" for=\"contributorExpandInput123\">\n                                                    (show all)\n                                                </label>\n                                                                                    </span>\n\n                                        <span class=\"c-contributor__bio c-contributor__bio--full\">\n                                            Alina Maria Stan builds connections that people actually feel. As co-founder and COO of Tekpon, she turns product intuition into real moments of discovery, shaping how teams find and adopt SaaS every day. Since 2020, she has led Tekpon’s brand voice, media strategy, and growth plays with a clear focus on human outcomes behind every metric.\r\nBefore Tekpon, Alina followed curiosity across industries and countries. She was CEO of King Casino Bonus and led affiliate and brand strategy at Extremoo Media and Fable Media in Denmark, where she learned how to build partnerships that last. Early on, she sharpened her CRM and pricing instincts at K.H. ApS, always asking why customers choose what they choose.\r\nHer approach is rooted in more than a decade of international experience and two master’s degrees, one in Sustainable Consumption from the Technical University of Munich and one in Consumer Affairs Management from Aarhus University.\n                                        </span>\n                                    </p>\n                                                            </div>\n                        </aside>\n\n                        <div class=\"c-channel__cta\" id='nl-container'>\n                                                        <h2 class=\"c-channel__ctaHeading text-dark\">Get the TNW newsletter</h2>\n                            <p class=\"c-channel__ctaDescription text-white\">Get the most important tech news in your inbox each week.</p>\n                            <div id='in-article-newsletter' style=\"color: #fff\"></div>\n                        </div>\n\n                                                    <div class=\"sponsored_legal\">\n                                <div class=\"sponsorDisclaimer latest\">\n                                    <p></p>\n                                                                        </div>\n                            </div>\n                        \n                        \n                        <footer class=\"c-article__pubDate md:flex md:justify-between\">\n                            <div>\n                                Published <time datetime=\"2019-02-11 12:07:00\">April 22, 2026 - 2:26 pm UTC</time>\n                            </div>\n\n                            <a\n                                href=\"#\"\n                                data-event-category=\"Article\"\n                                data-event-action=\"Back to top\"\n                                data-event-label=\"Back to top - click\"\n                                data-event-non-interaction=\"true\"\n                                class=\"scrolly latest\"\n                                data-target=\"#next-top\"\n                            >Back to top</a>\n                        </footer>\n\n                        <div aria-label=\"Social share options\" class=\"c-share lg:hidden\">\n                            <a aria-label=\"Share on Facebook\" class=\"c-share__link c-share__link--facebook\" rel=\"noopener\" target=\"_blank\" onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\" href=\"https://www.facebook.com/sharer/sharer.php?s=100&amp;p[url]=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dfacebook%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button&amp;p[title]=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox&amp;p[images][0]=https%3A%2F%2Fmedia.thenextweb.com%2F2026%2F04%2Fgoogle-cloud-next-ai-agents-agentic-era.avif&amp;u=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era&amp;t=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox\">\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#facebook\"></use></svg>\n                            </a>\n\n                            <a\n                                aria-label=\"Share on Twitter\"\n                                class=\"c-share__link c-share__link--twitter\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://twitter.com/intent/tweet?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dtwitter%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button%26referral&amp;via=thenextweb&amp;related=thenextweb&amp;text=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#twitter\"></use></svg>\n                            </a>\n\n                            <a\n                                aria-label=\"Share on Flipboard\"\n                                class=\"c-share__link c-share__link--flipboard\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://share.flipboard.com/bookmarklet/popout?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dflipboard%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#flipboard\"></use></svg>\n                            </a>\n\n                            <a\n                                aria-label=\"Share on Linkedin\"\n                                class=\"c-share__link c-share__link--linkedin\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=500,height=500'); return false;\"\n                                href=\"https://www.linkedin.com/shareArticle/?mini=true&amp;url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dlinkedin%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#linkedin\"></use></svg>\n                            </a>\n\n                            <a\n                                aria-label=\"Share on Telegram\"\n                                class=\"c-share__link c-share__link--telegram\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://t.me/share/url?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dtelegram%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#telegram\"></use></svg>\n                            </a>\n\n                            <a aria-label=\"Share via Email\" class=\"c-share__link c-share__link--mail\" href=\"/cdn-cgi/l/email-protection#dde2aea8bfb7b8bea9e09ab2b2bab1b8fdb7a8aea9fdb1bca8b3beb5b8b9fdb4a9aefdbcbab8b3a9b4befdb8b3a9b8afadafb4aeb8fdadb1bca4f1fdbcb3b9fdb4a9fdafa8b3aefdbbafb2b0fdbeb5b4adfda9b2fdb4b3bfb2a5fbbcb0ade6bfb2b9a4e0b5a9a9adaee7f2f2a9b5b8b3b8a5a9aab8bff3beb2b0f2b3b8aaaef2bab2b2bab1b8f0beb1b2a8b9f0b3b8a5a9f0bcb4f0bcbab8b3a9aef0bcbab8b3a9b4bef0b8afbcf8ee9ba8a9b082aeb2a8afbeb8f8ee99b8b0bcb4b1f8efeba8a9b082b0b8b9b4a8b0f8ee99aeb5bcafb8f8efeba8a9b082bebcb0adbcb4bab3f8ee99bcafa9b4beb1b8f0aeb5bcafb8f0bfa8a9a9b2b3\">\n                                <svg class=\"c-share__icon\" style=\"fill: #fff\"><use xlink:href=\"/assets/next/img/icons.svg#mail\"></use></svg>\n                            </a>\n                        </div>\n                    </div>\n                    <aside aria-hidden=\"true\" class=\"c-article__side\">\n                        <aside class=\"c-article__author\">\n                            <a\n                                href=\"/author/alina\"\n                                class=\"corporates-innovation\"\n                                data-event-category=\"Article\"\n                                data-event-action=\"Author\"\n                                data-event-label=\"Alina Maria Stan\"\n                                data-event-non-interaction=\"false\"\n                            >\n                                <img\n                                    alt=\"Alina Maria Stan\"\n                                    id=\"duotone\"\n                                    width=\"96\"\n                                    height=\"96\"\n                                    class=\"c-article__authorImage blend-blue-dark js-lazy\"\n                                    src=\"https://media.thenextweb.com/2025/12/Alina-Maria-Stan.avif\"\n                                >\n                                <span class=\"c-article__authorHeading\">Story by</span>\n                                <span class=\"c-article__authorName latest\" >Alina Maria Stan</span>\n                            </a>\n                        </aside>\n                        <div class=\"c-engage\">\n                                                        <a class=\"c-engage__link\" rel=\"noopener\" target=\"_blank\" data-event-category=\"Article\" data-event-action=\"Share\" data-event-label=\"Facebook\" data-event-non-interaction=\"false\" onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\" href=\"https://www.facebook.com/sharer/sharer.php?s=100&amp;p[url]=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dfacebook%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button&amp;p[title]=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox&amp;p[images][0]=https%3A%2F%2Fmedia.thenextweb.com%2F2026%2F04%2Fgoogle-cloud-next-ai-agents-agentic-era.avif&amp;u=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era&amp;t=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox\">\n                                <svg class=\"c-engage__icon\"><use xlink:href=\"/assets/next/img/icons.svg#facebook\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-engage__link\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                data-event-category=\"Article\"\n                                data-event-action=\"Share\"\n                                data-event-label=\"Twitter\"\n                                data-event-non-interaction=\"false\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\" href=\"https://twitter.com/intent/tweet?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dtwitter%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button%26referral&amp;via=thenextweb&amp;related=thenextweb&amp;text=Google%20just%20launched%20its%20agentic%20enterprise%20play%2C%20and%20it%20runs%20from%20chip%20to%20inbox\"\n                            >\n                                <svg class=\"c-engage__icon\"><use xlink:href=\"/assets/next/img/icons.svg#twitter\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-engage__link\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                data-event-category=\"Article\"\n                                data-event-action=\"Share\"\n                                data-event-label=\"Linkedin\"\n                                data-event-non-interaction=\"false\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=500,height=500'); return false;\"\n                                href=\"https://www.linkedin.com/shareArticle/?mini=true&amp;url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dlinkedin%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-engage__icon\"><use xlink:href=\"/assets/next/img/icons.svg#linkedin\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-engage__link\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                data-event-category=\"Article\"\n                                data-event-action=\"Share\"\n                                data-event-label=\"Flipboard\"\n                                data-event-non-interaction=\"false\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://share.flipboard.com/bookmarklet/popout?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dflipboard%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-engage__icon\"><use xlink:href=\"/assets/next/img/icons.svg#flipboard\"></use></svg>\n                            </a>\n\n                            <a\n                                class=\"c-engage__link\"\n                                rel=\"noopener\"\n                                target=\"_blank\"\n                                data-event-category=\"Article\"\n                                data-event-action=\"Share\"\n                                data-event-label=\"Telegram\"\n                                data-event-non-interaction=\"false\"\n                                onClick=\"window.open(this.href,'targetWindow','toolbar=no,location=0,status=no,menubar=no,scrollbars=yes,resizable=yes,width=600,height=250'); return false;\"\n                                href=\"https://t.me/share/url?url=https://thenextweb.com/news/google-cloud-next-ai-agents-agentic-era%3Futm_source%3Dtelegram%26utm_medium%3Dshare%26utm_campaign%3Darticle-share-button\"\n                            >\n                                <svg class=\"c-engage__icon\"><use xlink:href=\"/assets/next/img/icons.svg#telegram\"></use></svg>\n                            </a>\n\n                            <a class=\"c-engage__link\" data-event-category=\"Article\" data-event-action=\"Share\" data-event-label=\"Email\" data-event-non-interaction=\"false\" href=\"/cdn-cgi/l/email-protection#4a75393f28202f293e770d25252d262f6a203f393e6a262b3f2429222f2e6a233e396a2b2d2f243e23296a2f243e2f383a3823392f6a3a262b33666a2b242e6a233e6a383f24396a2c3825276a2922233a6a3e256a23242825326c2b273a7128252e3377223e3e3a397065653e222f242f323e3d2f286429252765242f3d39652d25252d262f672926253f2e67242f323e672b23672b2d2f243e39672b2d2f243e2329672f382b6f790c3f3e271539253f38292f6f790e2f272b23266f787c3f3e2715272f2e233f276f790e39222b382f6f787c3f3e2715292b273a2b232d246f790e2b383e2329262f6739222b382f67283f3e3e2524\">\n                                <svg class=\"c-engage__icon\"><use xlink:href=\"/assets/next/img/icons.svg#mail\"></use></svg>\n                            </a>\n                        </div>\n                    </aside>\n\n                    <aside class=\"c-split__side mb-m\" id=\"sidebar\">\n                                                <div class=\"c-split__sticky \">\n                            <aside aria-label=\"Popular articles\" class=\"sidebarRelated\">\n                                <h2 class=\"c-bodyNews__heading mb-l\">Popular articles</h2>\n\n                                <ol>\n                                                                            <li class=\"c-listItem\">\n                                            <span class=\"relatedIndex tnw\">1</span>\n\n                                            <div class=\"c-listItem__text\">\n                                                <h3 class=\"c-listItem__heading\">\n                                                    <a class=\"title_link\" href=\"/news/meta-india-data-centre-reliance-jamnagar\">Meta signs its first India data-centre deal, leasing a 168MW AI facility from Reliance</a>\n                                                </h3>\n                                            </div>\n                                        </li>\n                                                                            <li class=\"c-listItem\">\n                                            <span class=\"relatedIndex tnw\">2</span>\n\n                                            <div class=\"c-listItem__text\">\n                                                <h3 class=\"c-listItem__heading\">\n                                                    <a class=\"title_link\" href=\"/news/amazon-uk-investment-1bn-northamptonshire-jobs\">Amazon’s UK investment passes £1bn in Northamptonshire with 4,000 jobs, and a floor full of robots</a>\n                                                </h3>\n                                            </div>\n                                        </li>\n                                                                            <li class=\"c-listItem\">\n                                            <span class=\"relatedIndex tnw\">3</span>\n\n                                            <div class=\"c-listItem__text\">\n                                                <h3 class=\"c-listItem__heading\">\n                                                    <a class=\"title_link\" href=\"/news/salesforce-acquires-m3ter-consumption-billing-agentforce\">Salesforce acquires m3ter to add consumption-based billing to Agentforce</a>\n                                                </h3>\n                                            </div>\n                                        </li>\n                                                                            <li class=\"c-listItem\">\n                                            <span class=\"relatedIndex tnw\">4</span>\n\n                                            <div class=\"c-listItem__text\">\n                                                <h3 class=\"c-listItem__heading\">\n                                                    <a class=\"title_link\" href=\"/news/apple-and-google-both-want-to-monitor-the-web-for-you\">Apple and Google both want to monitor the web for you</a>\n                                                </h3>\n                                            </div>\n                                        </li>\n                                                                            <li class=\"c-listItem\">\n                                            <span class=\"relatedIndex tnw\">5</span>\n\n                                            <div class=\"c-listItem__text\">\n                                                <h3 class=\"c-listItem__heading\">\n                                                    <a class=\"title_link\" href=\"/news/ninjaone-12-3-billion-valuation-secondary-round\">NinjaOne’s valuation more than doubles to $12.3bn, and it says it didn’t even need the money</a>\n                                                </h3>\n                                            </div>\n                                        </li>\n                                                                    </ol>\n                            </aside>\n\n                            <div class=\"tnw-ad tnw-ad--article-mpu\" id=\"tnw-next-mpu-atf\" data-args='{\"networkCode\":5117602,\"slot\":\"TNW_NEXT_MPU_ATF\",\"googletagAttempts\":20,\"animate\":false,\"fallback\":false,\"sizes\":[[300,50],[300,250],[300,600]],\"sizeMapping\":[],\"targeting\":{\"title\":[\"Google just launched its agentic enterprise play, and it runs from chip to inbox\"],\"category\":[\"corporates-innovation\"],\"isSponsored\":[\"No\"],\"nsc\":[\"false\"]},\"lazyLoad\":\"false\",\"refreshEvery\":\"\",\"debugMode\":false}'></div>\n                            <div class=\"tnw-ad tnw-ad--article-mpu-btf\" id=\"tnw-next-mpu-btf\" data-args='{\"networkCode\":5117602,\"slot\":\"TNW_NEXT_MPU_BTF\",\"googletagAttempts\":20,\"animate\":false,\"fallback\":false,\"sizes\":[[300,250],[300,600]],\"sizeMapping\":[],\"targeting\":{\"title\":[\"Google just launched its agentic enterprise play, and it runs from chip to inbox\"],\"category\":[\"corporates-innovation\"],\"isSponsored\":[\"No\"],\"nsc\":[\"false\"]},\"lazyLoad\":\"false\",\"refreshEvery\":\"\",\"debugMode\":false}'></div>\n                        </div>\n                    </aside>\n                </article>\n            </div>\n        </div>\n\n        \n\n    <aside aria-label=\"Related Articles\" class=\"c-article__suggested\">\n        <div class=\"c-nextRelatedGrid\">\n            <section class=\"o-wrapper o-wrapper--wide\">\n                <header class=\"c-bodyNews__header\">\n                    <h2 class=\"c-bodyNews__heading\">Related Articles</h2>\n                </header>\n\n                <div class=\"c-showcase__grid\">\n                    <section class=\"c-showcase__grid c-showcase__scroller js-parallaxRoot\">\n                                                                            \n                                                        \n                                                                                                \n                            \n                            <article class=\"c-showcase__article\">\n                                <div class=\"c-card c-card--visual\">\n                                    <a\n                                      class=\"c-card__image js-parallax o-media md:o-media--stretch relcon_link_fix\"\n                                      data-event-non-interaction=\"false\"\n                                      href=\"/news/india-sovereign-ai-anthropic-fable-suspension-debate\"\n                                    >\n                                        <img\n                                            class=\"c-card__imageImage js-parallaxLayer o-parallax__layer js-lazy\"\n                                                                                        src=\"https://media.thenextweb.com/2026/06/india-sovereign-ai-anthropic-fable-suspension-debate.avif\"\n\t\t\t\t\t\t\t\t\t                                                    alt=\"Anthropic’s model shutdown just handed India’s sovereign AI movement its strongest argument yet\"\n                                        />\n                                    </a>\n\n                                    <header class=\"c-card__header\">\n                                        <span class=\"c-card__label\">\n                                            anthropic\n                                        </span>\n                                        <h3 class=\"c-card__heading\">\n                                            <a href=\"/news/india-sovereign-ai-anthropic-fable-suspension-debate\" tabindex=\"-1\">Anthropic’s model shutdown just handed India’s sovereign AI movement its strongest argument yet</a>\n                                        </h3>\n                                    </header>\n                                </div>\n                            </article>\n\n                                                                                \n                                                        \n                                                                                            \n                            \n                            <article class=\"c-showcase__article\">\n                                <div class=\"c-card c-card--visual\">\n                                    <a\n                                      class=\"c-card__image js-parallax o-media md:o-media--stretch relcon_link_fix\"\n                                      data-event-non-interaction=\"false\"\n                                      href=\"/news/texas-lawyer-ai-meta-social-media-addiction-trial\"\n                                    >\n                                        <img\n                                            class=\"c-card__imageImage js-parallaxLayer o-parallax__layer js-lazy\"\n                                                                                        src=\"https://media.thenextweb.com/2026/06/texas-lawyer-ai-meta-social-media-addiction-trial.avif\"\n\t\t\t\t\t\t\t\t\t                                                    alt=\"The lawyer who won a $6 million verdict against Meta says AI let him do 30 hours of work in 10\"\n                                        />\n                                    </a>\n\n                                    <header class=\"c-card__header\">\n                                        <span class=\"c-card__label\">\n                                            meta\n                                        </span>\n                                        <h3 class=\"c-card__heading\">\n                                            <a href=\"/news/texas-lawyer-ai-meta-social-media-addiction-trial\" tabindex=\"-1\">The lawyer who won a $6 million verdict against Meta says AI let him do 30 hours of work in 10</a>\n                                        </h3>\n                                    </header>\n                                </div>\n                            </article>\n\n                                                                                                                                                <article class=\"c-showcase__article\">\n                                    <div class=\"c-card c-card--visual\">\n                                        <a\n                                            class=\"c-card__image js-parallax o-media md:o-media--stretch\"\n                                            href=\"https://thenextweb.com/conference\"\n                                            tabindex=\"-1\"\n                                        >\n                                            <img\n                                                class=\"c-card__imageImage js-parallaxLayer o-parallax__layer\"\n                                                src=\"https://media.thenextweb.com/hardfork-2018/uploads/visuals/Conference-Nebula.png\"\n                                                alt=\"Discover TNW All Access\"\n                                            />\n                                        </a>\n\n                                        <header class=\"c-card__header advertPane\">\n                                            <h3 class=\"ad-title\">Discover TNW All Access</h3>\n                                            <span class=\"ad-description\">Watch videos of our inspiring Talks for free</span>\n                                            <a\n                                                class=\"c-button adpanel c-button--rounded\"\n                                                data-event-category=\"Article\"\n                                                data-event-action=\"Related articles Static Advert\"\n                                                data-event-label=\"Article\"\n                                                data-event-non-interaction=\"false\"\n                                                href=\"https://thenextweb.com/auth/tnw/login-required\"\n                                                target=\"_blank\"\n                                                rel=\"noopener noreferrer\"\n                                            >\n                                                Sign up now\n                                            </a>\n                                        </header>\n                                    </div>\n                                </article>\n                            \n                                                        \n                                                                                            \n                            \n                            <article class=\"c-showcase__article\">\n                                <div class=\"c-card c-card--visual\">\n                                    <a\n                                      class=\"c-card__image js-parallax o-media md:o-media--stretch relcon_link_fix\"\n                                      data-event-non-interaction=\"false\"\n                                      href=\"/news/hong-kong-european-family-offices-wealth-hub\"\n                                    >\n                                        <img\n                                            class=\"c-card__imageImage js-parallaxLayer o-parallax__layer js-lazy\"\n                                                                                        src=\"https://media.thenextweb.com/2026/06/hong-kong-european-family-offices-wealth-hub.avif\"\n\t\t\t\t\t\t\t\t\t                                                    alt=\"30 European family offices are looking to set up in Hong Kong as the city overtakes Switzerland in cross-border wealth\"\n                                        />\n                                    </a>\n\n                                    <header class=\"c-card__header\">\n                                        <span class=\"c-card__label\">\n                                            investors funding\n                                        </span>\n                                        <h3 class=\"c-card__heading\">\n                                            <a href=\"/news/hong-kong-european-family-offices-wealth-hub\" tabindex=\"-1\">30 European family offices are looking to set up in Hong Kong as the city overtakes Switzerland in cross-border wealth</a>\n                                        </h3>\n                                    </header>\n                                </div>\n                            </article>\n\n                                                                                \n                                                        \n                                                                                                \n                            \n                            <article class=\"c-showcase__article\">\n                                <div class=\"c-card c-card--visual\">\n                                    <a\n                                      class=\"c-card__image js-parallax o-media md:o-media--stretch relcon_link_fix\"\n                                      data-event-non-interaction=\"false\"\n                                      href=\"/news/chinese-ai-models-gaming-safety-tests-evaluation-awareness\"\n                                    >\n                                        <img\n                                            class=\"c-card__imageImage js-parallaxLayer o-parallax__layer js-lazy\"\n                                                                                        src=\"https://media.thenextweb.com/2026/06/chinese-ai-models-gaming-safety-tests-evaluation-awareness.avif\"\n\t\t\t\t\t\t\t\t\t                                                    alt=\"Chinese AI models are learning to detect safety tests and adjust their behaviour accordingly\"\n                                        />\n                                    </a>\n\n                                    <header class=\"c-card__header\">\n                                        <span class=\"c-card__label\">\n                                            artificial intelligence\n                                        </span>\n                                        <h3 class=\"c-card__heading\">\n                                            <a href=\"/news/chinese-ai-models-gaming-safety-tests-evaluation-awareness\" tabindex=\"-1\">Chinese AI models are learning to detect safety tests and adjust their behaviour accordingly</a>\n                                        </h3>\n                                    </header>\n                                </div>\n                            </article>\n\n                                                                        </section>\n                </div>\n            </section>\n        </div>\n    </aside>\n    </main>\n\n    <script data-cfasync=\"false\" src=\"/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js\"></script><script>\n        const channelArticlesList = document.getElementById('article_container');\n\n        function timeOutWrapper() {\n            document.addEventListener( 'DOMContentLoaded', function() {\n                document.body.classList.remove( 'preload', 'render-canvas' );\n            } );\n\n            function callback( mutationsList, observer ) {\n                mutationsList.forEach( mutation => {\n                    if ( mutation.attributeName === 'class' ) {\n                        if ( document.body.classList.contains( 'is-canvas' ) ) {\n                            channelArticlesList.classList.add( 'render-canvas' );\n                        }\n                    }\n                } );\n            }\n\n            const mutationObserver = new MutationObserver(callback);\n\n            mutationObserver.observe( document.body, {\n              attributes: true,\n            } );\n        }\n\n        timeOutWrapper();\n    </script>\n            </div>\n        </div>\n        <footer class=\"c-footer\">\n            <div class=\"o-wrapper\">\n                <div class=\"o-grid o-grid--gap-l\">\n                    <div class=\"o-grid__col lg:o-grid__col--1/2\">\n                        <div class=\"c-footer__logoContact\">\n                                <div>\n                                    <a class=\"c-footer__logo\" data-event-category=\"Footer\" data-event-action=\"TNW Logo\" data-event-label=\"Navigation\" data-event-non-interaction=\"false\" href=\"https://next.thenextweb.com/\" title=\"TNW\" tabindex=\"-1\">\n                                        <svg preserveAspectRatio=\"xMidYMid meet\" viewbox=\"0 0 66 16\">\n                                            <path fill=\"#fff\" d=\"M32.23993 5A6.00284 6.00284 0 0 1 34 9.24261V16h-6v-5.929a2.00249 2.00249 0 0 0-.58856-1.41424l-2.07239-2.07101A2.00315 2.00315 0 0 0 23.92346 6H22v10h-6V0h8.75189a6 6 0 0 1 4.24268 1.75739zM60 0v5.929a2.00245 2.00245 0 0 1-.58856 1.41418l-2.07385 2.071A1.99969 1.99969 0 0 1 55.9234 10h-2.88214A5.99166 5.99166 0 0 0 54 6.75732V0h-6v5.929a2.00245 2.00245 0 0 1-.58856 1.41418l-2.07385 2.071A1.99969 1.99969 0 0 1 43.9234 10H42V0h-6v16h8.75189a6.003 6.003 0 0 0 4.244-1.75739L51 12.23938V16h5.75189a6.003 6.003 0 0 0 4.244-1.75739l3.244-3.24267A6.00264 6.00264 0 0 0 66 6.75732V0zM0 6h4v10h6V6h4V0H0z\"></path>\n                                        </svg>\n                                    </a>\n                                    <p class=\"c-footer__tagline\">The heart of tech</p>\n                                </div>\n                            <div>\n                                <ul class=\"c-footer__contact\">\n                                                                        <li class=\"c-footer__contactItem\"><a class=\"c-footer__contactLink\" data-event-category=\"Footer\" data-event-action=\"Socials\" data-event-label=\"Faaaaebook\" href=\"https://facebook.com/thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Facebook Contact Icon\"><svg class=\"c-footer__contactIcon\"><use xlink:href=\"/assets/next/img/icons.svg#facebook\"></use></svg></a></li>\n                                    <li class=\"c-footer__contactItem\"><a class=\"c-footer__contactLink\" data-event-category=\"Footer\" data-event-action=\"Socials\" data-event-label=\"Instagram\" href=\"https://www.instagram.com/thenextweb/\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Instagram Contact Icon\"><svg class=\"c-footer__contactIcon\"><use xlink:href=\"/assets/next/img/icons.svg#instagram\"></use></svg></a></li>\n                                    <li class=\"c-footer__contactItem\"><a class=\"c-footer__contactLink\" data-event-category=\"Footer\" data-event-action=\"Socials\" data-event-label=\"Twitter\" href=\"https://twitter.com/thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Twitter Contact Icon\"><svg class=\"c-footer__contactIcon\"><use xlink:href=\"/assets/next/img/icons.svg#twitter\"></use></svg></a></li>\n                                    <li class=\"c-footer__contactItem\"><a class=\"c-footer__contactLink\" data-event-category=\"Footer\" data-event-action=\"Socials\" data-event-label=\"Youtube\" href=\"https://youtube.com/user/thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Youtube Contact Icon\"><svg class=\"c-footer__contactIcon\"><use xlink:href=\"/assets/next/img/icons.svg#youtube\"></use></svg></a></li>\n                                    <li class=\"c-footer__contactItem\"><a class=\"c-footer__contactLink\" data-event-category=\"Footer\" data-event-action=\"Socials\" data-event-label=\"Flipboard\" href=\"https://flipboard.com/@thenextweb\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"Flipboard Contact Icon\"><svg class=\"c-footer__contactIcon\"><use xlink:href=\"/assets/next/img/icons.svg#flipboard\"></use></svg></a></li>\n                                    <li class=\"c-footer__contactItem\"><a class=\"c-footer__contactLink\" data-event-category=\"Footer\" data-event-action=\"Socials\" data-event-label=\"Mail\" href=\"/newsletters\" name=\"Email Footer Link\"><svg class=\"c-footer__contactIcon\"><use xlink:href=\"/assets/next/img/icons.svg#mail\"></use></svg></a></li>\n                                                                        <li class=\"c-footer__contactItem\"><a class=\"c-footer__contactLink\" data-event-category=\"Footer\" data-event-action=\"Socials\" data-event-label=\"Linkedin\" href=\"https://www.linkedin.com/company/the-next-web\" target=\"_blank\" rel=\"noopener noreferrer\" name=\"LinkedIn Contact Icon\"><svg class=\"c-footer__contactIcon\"><use xlink:href=\"/assets/next/img/icons.svg#linkedin\"></use></svg></a></li>\n                                                                                                    </ul>\n                            </div>\n                        </div>\n                    </div>\n                    <br>\n\n                    <div class=\"o-grid__col--1/2 lg:o-grid__col--1/4 more\">\n                                                <h2 class=\"c-footer__heading\">More TNW</h2>\n                        <ul class=\"c-footer__menu\">\n                            <li><a class=\"c-footer__menuLink\" href=\"/latest\" data-event-category=\"Footer\" data-event-action=\"More TNW\" data-event-label=\"Media\" data-event-non-interaction=\"false\">Media</a></li>\n                            <li><a class=\"c-footer__menuLink\" href=\"/events\" data-event-category=\"Footer\" data-event-action=\"More TNW\" data-event-label=\"Events\" data-event-non-interaction=\"false\">Events</a></li>\n                            <li><a class=\"c-footer__menuLink\" href=\"/spaces\" data-event-category=\"Footer\" data-event-action=\"More TNW\" data-event-label=\"Spaces\" data-event-non-interaction=\"false\">Spaces</a></li>\n                            <li><a class=\"c-footer__menuLink\" href=\"/newsletters\" data-event-category=\"Footer\" data-event-action=\"More TNW\" data-event-label=\"Newsletters\" data-event-non-interaction=\"false\">Newsletters</a></li>\n                        </ul>\n                                            </div>\n                    <div class=\"o-grid__col--1/2 lg:o-grid__col--1/4 about\">\n                        <h2 class=\"c-footer__heading\">About TNW</h2>\n                        <ul class=\"c-footer__menu\">\n                                                        <li><a class=\"c-footer__menuLink\" data-event-category=\"Footer\" data-event-action=\"About TNW\" data-event-label=\"Partner with us\" data-event-non-interaction=\"false\" href=\"/partnerships\" name=\"Partner with us\">Partner with us</a></li>\n                            <li><a class=\"c-footer__menuLink\" data-event-category=\"Footer\" data-event-action=\"About TNW\" data-event-label=\"Terms &amp; Conditions\" data-event-non-interaction=\"false\" href=\"/terms-and-conditions\" name=\"Terms &amp; Conditions\">Terms &amp; Conditions</a></li>\n                            <li><a class=\"c-footer__menuLink\" data-event-category=\"Footer\" data-event-action=\"About TNW\" data-event-label=\"Cookie Statement\" data-event-non-interaction=\"false\" href=\"/cookie-statement\" name=\"Cookie Statement\">Cookie Statement</a></li>\n                            <li><a class=\"c-footer__menuLink\" data-event-category=\"Footer\" data-event-action=\"About TNW\" data-event-label=\"Privacy Statement\" data-event-non-interaction=\"false\" href=\"/privacy-statement \" name=\"Privacy Statement\">Privacy Statement</a></li>\n                                                    </ul>\n                    </div>\n\n                </div>\n            </div>\n            <div class=\"c-footer__legal max-md:px-l\">\n\t\t<p>A Tekpon Company</p>\n\t\t<p>Copyright &copy; 2006&mdash;2026, Cogneve, INC. Made with <3 in Amsterdam.</p>\n\n            </div>\n        </footer>\n\n        <script src=\"//static.thenextweb.com/assets/next/js/base.js?af24e65ec70ba6a3571bc69de0e8f4e09ff399ea\" async defer></script>\n\n        <script type=\"text/javascript\">\n            window.csrfTokenName = \"CRAFT_CSRF_TOKEN\";\n            window.csrfTokenValue = \"NGWo3\\u002D2DC8ikAenl5ANVMAgfSHWr3\\u002D\\u002DoOi2Xb3bd_OB4mPujd5IapA0L0ombslqZ91mdiappI3FAVgtN2bi871UZ\\u002DjwHi5PYM6y6kB3CQ8s\\u003D\";\n        </script>\n        <script>\n            var ENV = {\n                \"paths\": {\n                    \"assets\": \"/assets\"\n                }\n            };\n        </script>\n                                <div class=\"cookie-consent-banner\" id=\"cookie-consent-banner\" data-args='{\"cookieName\":\"__tnw_cookieConsent\",\"cookieExpirationDays\":\"365\",\"consentChoices\":[\"ad_storage\",\"analytics_storage\"],\"redirectOnSave\":true,\"honorDoNotTrack\":false,\"stylesheet\":\"https:\\/\\/thenextweb.com\\/cpresources\\/7aa73511\\/style.css?v=1781280696\",\"titleText\":\"Cookies\",\"descriptionText\":\"<p>We use <a href=\\\"\\/cookie-statement\\\">cookies<\\/a> and other data for a number of reasons, such as keeping TNW sites reliable and secure, personalizing content and ads, providing social media features and to analyze how our sites are used.<\\/p>\",\"linkColor\":\"6644ff\",\"linkHoverColor\":\"7755ff\",\"primaryBtnText\":\"Accept & continue\",\"primaryBtnBgColor\":\"\",\"primaryBtnBgHoverColor\":\"\",\"primaryBtnColor\":\"\",\"primaryBtnHoverColor\":\"\",\"secondaryBtnText\":\"Manage cookies\",\"secondaryBtnURL\":\"\\/cookie-statement\",\"secondaryBtnRedirectURL\":\"https:\\/\\/thenextweb.com\\/news\\/google-cloud-next-ai-agents-agentic-era\",\"secondaryBtnColor\":\"6644ff\",\"secondaryBtnHoverColor\":\"7755ff\",\"debugMode\":false}'></div><script src=\"https://thenextweb.com/cpresources/2c16970e/main.js?v=1781280696\" async=\"async\" defer=\"defer\"></script>\n\n        <script>\n            (function() {\n                function initCalendlyButtons() {\n                    // Get all Calendly buttons\n                    const calendlyButtons = document.querySelectorAll('.book-call[data-platform=\"calendly\"][data-calendly]');\n                    \n                    // If no buttons found, exit\n                    if (!calendlyButtons.length) return;\n                    \n                    // Add click handler to each button\n                    calendlyButtons.forEach(button => {\n                        button.addEventListener('click', openCalendly);\n                    });\n                }\n                \n                function openCalendly(e) {\n                    const button = e.currentTarget;\n                    const url = button.dataset.calendly;\n                    \n                    if (url && typeof Calendly !== 'undefined') {\n                        Calendly.initPopupWidget({url: url});\n                    } else {\n                        console.error('Calendly URL missing or Calendly not loaded');\n                    }\n                }\n\n                if (document.readyState === 'loading') {\n                    document.addEventListener('DOMContentLoaded', initCalendlyButtons);\n                } else {\n                    initCalendlyButtons();\n                }\n            })();\n        </script>\n    </body>\n</html>\n","snapshot_chars":119119,"live_check":"changed"},{"url":"https://articles.idenhq.com/ai-agent-identity-management-2026","committed_hash":"sha256:58ac4b83adda607543a30574244044143450b9aa2aafcbf61cc71de9e8b4fccf","committed_hash_short":"sha256:58ac4b83…e8b4fccf","mime_type":"text/html","committed_at":"2026-07-26T10:00:30.578605+00:00","content_snapshot":"<!DOCTYPE html><html data-dpl-id=\"dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" lang=\"en\" class=\"inter_c15e96cb-module__0bjUvq__variable antialiased\"><head><meta charSet=\"utf-8\"/><meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"/><link rel=\"stylesheet\" href=\"/_next/static/chunks/08_loej5.wuit.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/chunks/0-jf1u_rglope.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/chunks/0_kwzt0c~eysn.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" data-precedence=\"next\"/><link rel=\"preload\" as=\"script\" fetchPriority=\"low\" href=\"/_next/static/chunks/0oqqtf7q0fh8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\"/><script src=\"/_next/static/chunks/0waofks11mx~c.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/08elxagggt6cr.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0gcjxa764g9a3.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0ekb0u26wv.qk.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/turbopack-03zht_1ghj934.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><meta name=\"next-size-adjust\" content=\"\"/><title>AI Agent Identity Management 2026: Standards &amp; Gaps | Iden Blog</title><meta name=\"description\" content=\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.\"/><meta name=\"application-name\" content=\"Iden\"/><link rel=\"author\" href=\"https://www.idenhq.com\"/><meta name=\"author\" content=\"Iden\"/><link rel=\"manifest\" href=\"/manifest.webmanifest\"/><meta name=\"creator\" content=\"Iden\"/><meta name=\"publisher\" content=\"Iden\"/><meta name=\"robots\" content=\"index, follow\"/><meta name=\"googlebot\" content=\"index, follow, max-video-preview:-1, max-image-preview:large, max-snippet:-1\"/><meta name=\"category\" content=\"technology\"/><link rel=\"canonical\" href=\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\"/><link rel=\"alternate\" hrefLang=\"de\" href=\"https://www.idenhq.com/de/blog/ki-agenten-identity-management-2026\"/><link rel=\"alternate\" hrefLang=\"en\" href=\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\"/><link rel=\"alternate\" hrefLang=\"x-default\" href=\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\"/><meta property=\"og:title\" content=\"AI Agent Identity Management 2026: Standards &amp; Gaps\"/><meta property=\"og:description\" content=\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.\"/><meta property=\"og:locale\" content=\"en_US\"/><meta property=\"og:image\" content=\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\"/><meta property=\"og:type\" content=\"article\"/><meta property=\"article:published_time\" content=\"2026-07-15T07:00:17.688+00:00\"/><meta name=\"twitter:card\" content=\"summary_large_image\"/><meta name=\"twitter:title\" content=\"AI Agent Identity Management 2026: Standards &amp; Gaps\"/><meta name=\"twitter:description\" content=\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.\"/><meta name=\"twitter:image\" content=\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\"/><link rel=\"icon\" href=\"/favicon.ico?favicon.0i-q8a6zz7zw~.ico\" sizes=\"48x48\" type=\"image/x-icon\"/><link rel=\"apple-touch-icon\" href=\"/apple-icon.png?apple-icon.0v4oxdav-.ztw.png\" sizes=\"180x180\" type=\"image/png\"/><script src=\"/_next/static/chunks/03~yq9q893hmn.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" noModule=\"\"></script></head><body class=\"overscroll-y-none\"><div hidden=\"\"><!--$--><!--/$--></div><script type=\"application/ld+json\">[{\"@context\":\"https://schema.org\",\"@type\":\"Organization\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\",\"logo\":\"https://www.idenhq.com/logo/iden-wordmark.svg\",\"description\":\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\",\"sameAs\":[\"https://www.wikidata.org/wiki/Q140158373\",\"https://www.linkedin.com/company/idenhq\",\"https://github.com/IdenWorks\",\"https://twitter.com/idenhq\"],\"foundingDate\":\"2024-04\",\"founder\":[{\"@type\":\"Person\",\"name\":\"Pranay Yadav\",\"jobTitle\":\"CEO\",\"sameAs\":[\"https://www.wikidata.org/wiki/Q140158371\"]},{\"@type\":\"Person\",\"name\":\"Anchit Navelkar\",\"jobTitle\":\"CTO\",\"sameAs\":[\"https://www.wikidata.org/wiki/Q140158372\"]}],\"contactPoint\":[{\"@type\":\"ContactPoint\",\"contactType\":\"sales\",\"email\":\"hello@idenhq.com\",\"availableLanguage\":[\"en\",\"de\"]}]},{\"@context\":\"https://schema.org\",\"@type\":\"SoftwareApplication\",\"name\":\"Iden\",\"applicationCategory\":\"BusinessApplication\",\"applicationSubCategory\":\"Identity Governance and Administration (IGA)\",\"operatingSystem\":\"Web\",\"url\":\"https://www.idenhq.com\",\"description\":\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\",\"offers\":{\"@type\":\"Offer\",\"price\":\"7.50\",\"priceCurrency\":\"USD\",\"priceSpecification\":{\"@type\":\"UnitPriceSpecification\",\"price\":\"7.50\",\"priceCurrency\":\"USD\",\"unitText\":\"user/month\"}},\"featureList\":[\"User lifecycle management (Joiner-Mover-Leaver) for employees and contractors\",\"Fine-grained access provisioning across SCIM and non-SCIM apps\",\"Clean, compliant offboarding with data backups and audit trail\",\"Access tickets automation\",\"JIT, time-bound access\",\"Automated user access reviews and access certifications for SOC 2, ISO 27001, GDPR, DPDP, CCPA, CMMC, and other frameworks\",\"Least privilege at scale\",\"Identity security posture management\",\"Human, non-human, and AI agentic identities in one platform\",\"AI agent identity governance\",\"Shadow IT and SaaS discovery\",\"SaaS management and cost optimization\",\"200+ non-SCIM app connectors\",\"Custom app connectors in 48 hours\"],\"publisher\":{\"@type\":\"Organization\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\"}},{\"@context\":\"https://schema.org\",\"@type\":\"WebSite\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\",\"inLanguage\":[\"en\",\"de\"],\"publisher\":{\"@type\":\"Organization\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\"}}]</script><!--$--><!--/$--><div class=\"blog-root min-h-dvh\"><div class=\"max-w-[620px] px-6 sm:px-0 mx-auto pt-3 pb-3 w-full relative\"><div class=\"flex items-center justify-between\"><a aria-label=\"Iden\" class=\"flex items-center\" href=\"/\"><svg viewBox=\"0 0 101 30\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\" class=\"h-4 w-auto block shrink-0\" style=\"fill:#a3a3a3\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\"></path><path d=\"M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"></path></svg></a><div class=\"flex items-center gap-2 sm:gap-3\"><a href=\"https://cal.com/team/iden/demo\" class=\"sm:hidden inline-flex items-center gap-1.5 rounded-lg px-2 py-1 text-sm text-white font-medium transition-all hover:opacity-90 hover:scale-[1.03] active:scale-[0.98]\" style=\"background:linear-gradient(to top, #3b5bdb 0%, #4c6ef5 100%);border:1px solid #3b5bdb\">Book demo</a><button type=\"button\" aria-label=\"Open menu\" aria-expanded=\"false\" class=\"sm:hidden inline-flex items-center justify-center rounded-lg p-1.5 transition-colors text-neutral-400 hover:bg-neutral-800\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-5 w-5\" aria-hidden=\"true\"><path d=\"M3.75 6.75h16.5M3.75 12h16.5M3.75 17.25h16.5\"></path></svg></button><div class=\"hidden sm:flex flex-row items-center gap-3\"><a href=\"/en/field-notes\" class=\"text-sm text-neutral-400 underline hover:no-underline\">Field Notes</a><a href=\"/en/playbooks\" class=\"text-sm text-neutral-400 underline hover:no-underline\">Playbooks</a><div class=\"relative group/ai inline-flex\"><button class=\"cursor-default group inline-flex items-center gap-1 text-sm text-neutral-400 transition-colors\"><span class=\"underline group-hover:no-underline inline-flex items-center gap-1\">Ask AI<svg viewBox=\"0 0 16 16\" fill=\"currentColor\" class=\"h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M8 1.5c.2 1.8.9 3.3 2.2 4.3C11.4 6.9 13 7.7 14.5 8c-1.5.3-3.1 1.1-4.3 2.2C9 11.2 8.2 12.7 8 14.5c-.2-1.8-.9-3.3-2.2-4.3C4.6 9.1 3 8.3 1.5 8c1.5-.3 3.1-1.1 4.3-2.2C7 4.8 7.8 3.3 8 1.5z\"></path></svg></span></button><div class=\"absolute left-0 top-full pt-1 hidden group-hover/ai:block z-50\"><div class=\"rounded-lg shadow-sm py-0.5 border min-w-[120px] bg-white border-neutral-200\"><a href=\"https://chatgpt.com/?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.282 9.821a6 6 0 0 0-.516-4.91a6.05 6.05 0 0 0-6.51-2.9A6.065 6.065 0 0 0 4.981 4.18a6 6 0 0 0-3.998 2.9a6.05 6.05 0 0 0 .743 7.097a5.98 5.98 0 0 0 .51 4.911a6.05 6.05 0 0 0 6.515 2.9A6 6 0 0 0 13.26 24a6.06 6.06 0 0 0 5.772-4.206a6 6 0 0 0 3.997-2.9a6.06 6.06 0 0 0-.747-7.073M13.26 22.43a4.48 4.48 0 0 1-2.876-1.04l.141-.081l4.779-2.758a.8.8 0 0 0 .392-.681v-6.737l2.02 1.168a.07.07 0 0 1 .038.052v5.583a4.504 4.504 0 0 1-4.494 4.494M3.6 18.304a4.47 4.47 0 0 1-.535-3.014l.142.085l4.783 2.759a.77.77 0 0 0 .78 0l5.843-3.369v2.332a.08.08 0 0 1-.033.062L9.74 19.95a4.5 4.5 0 0 1-6.14-1.646M2.34 7.896a4.5 4.5 0 0 1 2.366-1.973V11.6a.77.77 0 0 0 .388.677l5.815 3.354l-2.02 1.168a.08.08 0 0 1-.071 0l-4.83-2.786A4.504 4.504 0 0 1 2.34 7.872zm16.597 3.855l-5.833-3.387L15.119 7.2a.08.08 0 0 1 .071 0l4.83 2.791a4.494 4.494 0 0 1-.676 8.105v-5.678a.79.79 0 0 0-.407-.667m2.01-3.023l-.141-.085l-4.774-2.782a.78.78 0 0 0-.785 0L9.409 9.23V6.897a.07.07 0 0 1 .028-.061l4.83-2.787a4.5 4.5 0 0 1 6.68 4.66zm-12.64 4.135l-2.02-1.164a.08.08 0 0 1-.038-.057V6.075a4.5 4.5 0 0 1 7.375-3.453l-.142.08L8.704 5.46a.8.8 0 0 0-.393.681zm1.097-2.365l2.602-1.5l2.607 1.5v2.999l-2.597 1.5l-2.607-1.5Z\"></path></svg>ChatGPT<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://claude.ai/new?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M17.3041 3.541h-3.6718l6.696 16.918H24Zm-10.6082 0L0 20.459h3.7442l1.3693-3.5527h7.0052l1.3693 3.5528h3.7442L10.5363 3.5409Zm-.3712 10.2232 2.2914-5.9456 2.2914 5.9456Z\"></path></svg>Claude<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://www.perplexity.ai/?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.3977 7.0896h-2.3106V.0676l-7.5094 6.3542V.1577h-1.1554v6.1966L4.4904 0v7.0896H1.6023v10.3976h2.8882V24l6.932-6.3591v6.2005h1.1554v-6.0469l6.9318 6.1807v-6.4879h2.8882V7.0896zm-3.4657-4.531v4.531h-5.355l5.355-4.531zm-13.2862.0676 4.8691 4.4634H5.6458V2.6262zM2.7576 16.332V8.245h7.8476l-6.1149 6.1147v1.9723H2.7576zm2.8882 5.0404v-3.8852h.0001v-2.6488l5.7763-5.7764v7.0111l-5.7764 5.2993zm12.7086.0248-5.7766-5.1509V9.0618l5.7766 5.7766v6.5588zm2.8882-5.0652h-1.733v-1.9723L13.3948 8.245h7.8478v8.087z\"></path></svg>Perplexity<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://gemini.google.com/app?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M11.04 19.32Q12 21.51 12 24q0-2.49.93-4.68.96-2.19 2.58-3.81t3.81-2.55Q21.51 12 24 12q-2.49 0-4.68-.93a12.3 12.3 0 0 1-3.81-2.58 12.3 12.3 0 0 1-2.58-3.81Q12 2.49 12 0q0 2.49-.96 4.68-.93 2.19-2.55 3.81a12.3 12.3 0 0 1-3.81 2.58Q2.49 12 0 12q2.49 0 4.68.96 2.19.93 3.81 2.55t2.55 3.81\"></path></svg>Gemini<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><div class=\"my-0.5 border-t border-neutral-100\"></div><button class=\"flex w-full items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-400 hover:text-neutral-500 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><rect x=\"9\" y=\"9\" width=\"13\" height=\"13\" rx=\"2\"></rect><path d=\"M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1\"></path></svg>Copy</button></div></div></div><a href=\"https://app.idenhq.com\" class=\"inline-flex items-center gap-1.5 rounded-lg px-2 py-1 text-sm text-neutral-400 border border-neutral-700 hover:bg-neutral-800 transition-colors\">Login</a><a href=\"https://cal.com/team/iden/demo\" class=\"inline-flex items-center gap-1.5 rounded-lg px-2 py-1 text-sm text-white font-medium transition-all hover:opacity-90 hover:scale-[1.03] active:scale-[0.98]\" style=\"background:linear-gradient(to top, #3b5bdb 0%, #4c6ef5 100%);border:1px solid #3b5bdb\">Book demo</a></div></div></div></div><main><article class=\"blog-article\" lang=\"en\"><div class=\"mx-auto max-w-[620px] px-6 sm:px-0\"><div class=\"flex items-center justify-between pt-12 sm:pt-16\"><a class=\"inline-flex items-center gap-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:text-white\" href=\"/en/blog\"><svg viewBox=\"0 0 16 16\" class=\"h-3.5 w-3.5\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M10 3L5 8l5 5\"></path></svg>Blog</a><a hrefLang=\"de\" class=\"rounded-full border border-[var(--blog-border)] px-3 py-1 text-xs text-[var(--blog-muted)] transition-colors hover:border-[var(--blog-accent)] hover:text-[var(--blog-accent)]\" href=\"/de/blog/ki-agenten-identity-management-2026\">Auf Deutsch lesen</a></div><header class=\"mt-10 mb-8\"><h1 class=\"text-3xl font-normal leading-tight tracking-tight text-white sm:text-[34px] sm:leading-[1.15]\">AI Agent Identity Management in 2026: Standards, Players, and the Governance Gap</h1><p class=\"mt-3 text-base leading-relaxed text-[var(--blog-muted)]\">MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards landscape for AI agent identity is taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.</p><div class=\"mt-7 flex flex-wrap items-center gap-4\"><button class=\"inline-flex items-center gap-1.5 text-sm font-medium text-[var(--blog-muted)] hover:text-white transition-colors cursor-pointer \"><svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\"><path d=\"M13.19 8.688a4.5 4.5 0 0 1 1.242 7.244l-4.5 4.5a4.5 4.5 0 0 1-6.364-6.364l1.757-1.757m13.35-.622 1.757-1.757a4.5 4.5 0 0 0-6.364-6.364l-4.5 4.5a4.5 4.5 0 0 0 1.242 7.244\"></path></svg>Copy URL</button><button class=\"inline-flex items-center gap-1.5 text-sm font-medium text-[var(--blog-muted)] hover:text-white transition-colors cursor-pointer \"><svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\"><rect x=\"9\" y=\"9\" width=\"13\" height=\"13\" rx=\"2\"></rect><path d=\"M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1\"></path></svg>Copy page</button><div class=\"relative group/ai inline-flex\"><button class=\"inline-flex items-center gap-1.5 text-sm font-medium text-[var(--blog-muted)] hover:text-white transition-colors cursor-pointer cursor-default\"><svg viewBox=\"0 0 16 16\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M8 1.5c.2 1.8.9 3.3 2.2 4.3C11.4 6.9 13 7.7 14.5 8c-1.5.3-3.1 1.1-4.3 2.2C9 11.2 8.2 12.7 8 14.5c-.2-1.8-.9-3.3-2.2-4.3C4.6 9.1 3 8.3 1.5 8c1.5-.3 3.1-1.1 4.3-2.2C7 4.8 7.8 3.3 8 1.5z\"></path></svg>Ask AI about this page<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-2.5 w-2.5 shrink-0 opacity-60\" aria-hidden=\"true\"><path d=\"M2 4l3 3 3-3\"></path></svg></button><div class=\"absolute left-0 top-full pt-1 hidden group-hover/ai:block z-50\"><div class=\"min-w-[190px] rounded-lg border border-[var(--blog-border)] bg-[var(--blog-surface)] py-0.5 shadow-lg\"><a href=\"https://chatgpt.com/?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.282 9.821a6 6 0 0 0-.516-4.91a6.05 6.05 0 0 0-6.51-2.9A6.065 6.065 0 0 0 4.981 4.18a6 6 0 0 0-3.998 2.9a6.05 6.05 0 0 0 .743 7.097a5.98 5.98 0 0 0 .51 4.911a6.05 6.05 0 0 0 6.515 2.9A6 6 0 0 0 13.26 24a6.06 6.06 0 0 0 5.772-4.206a6 6 0 0 0 3.997-2.9a6.06 6.06 0 0 0-.747-7.073M13.26 22.43a4.48 4.48 0 0 1-2.876-1.04l.141-.081l4.779-2.758a.8.8 0 0 0 .392-.681v-6.737l2.02 1.168a.07.07 0 0 1 .038.052v5.583a4.504 4.504 0 0 1-4.494 4.494M3.6 18.304a4.47 4.47 0 0 1-.535-3.014l.142.085l4.783 2.759a.77.77 0 0 0 .78 0l5.843-3.369v2.332a.08.08 0 0 1-.033.062L9.74 19.95a4.5 4.5 0 0 1-6.14-1.646M2.34 7.896a4.5 4.5 0 0 1 2.366-1.973V11.6a.77.77 0 0 0 .388.677l5.815 3.354l-2.02 1.168a.08.08 0 0 1-.071 0l-4.83-2.786A4.504 4.504 0 0 1 2.34 7.872zm16.597 3.855l-5.833-3.387L15.119 7.2a.08.08 0 0 1 .071 0l4.83 2.791a4.494 4.494 0 0 1-.676 8.105v-5.678a.79.79 0 0 0-.407-.667m2.01-3.023l-.141-.085l-4.774-2.782a.78.78 0 0 0-.785 0L9.409 9.23V6.897a.07.07 0 0 1 .028-.061l4.83-2.787a4.5 4.5 0 0 1 6.68 4.66zm-12.64 4.135l-2.02-1.164a.08.08 0 0 1-.038-.057V6.075a4.5 4.5 0 0 1 7.375-3.453l-.142.08L8.704 5.46a.8.8 0 0 0-.393.681zm1.097-2.365l2.602-1.5l2.607 1.5v2.999l-2.597 1.5l-2.607-1.5Z\"></path></svg>ChatGPT<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://claude.ai/new?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M17.3041 3.541h-3.6718l6.696 16.918H24Zm-10.6082 0L0 20.459h3.7442l1.3693-3.5527h7.0052l1.3693 3.5528h3.7442L10.5363 3.5409Zm-.3712 10.2232 2.2914-5.9456 2.2914 5.9456Z\"></path></svg>Claude<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://www.perplexity.ai/?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.3977 7.0896h-2.3106V.0676l-7.5094 6.3542V.1577h-1.1554v6.1966L4.4904 0v7.0896H1.6023v10.3976h2.8882V24l6.932-6.3591v6.2005h1.1554v-6.0469l6.9318 6.1807v-6.4879h2.8882V7.0896zm-3.4657-4.531v4.531h-5.355l5.355-4.531zm-13.2862.0676 4.8691 4.4634H5.6458V2.6262zM2.7576 16.332V8.245h7.8476l-6.1149 6.1147v1.9723H2.7576zm2.8882 5.0404v-3.8852h.0001v-2.6488l5.7763-5.7764v7.0111l-5.7764 5.2993zm12.7086.0248-5.7766-5.1509V9.0618l5.7766 5.7766v6.5588zm2.8882-5.0652h-1.733v-1.9723L13.3948 8.245h7.8478v8.087z\"></path></svg>Perplexity<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://gemini.google.com/app?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M11.04 19.32Q12 21.51 12 24q0-2.49.93-4.68.96-2.19 2.58-3.81t3.81-2.55Q21.51 12 24 12q-2.49 0-4.68-.93a12.3 12.3 0 0 1-3.81-2.58 12.3 12.3 0 0 1-2.58-3.81Q12 2.49 12 0q0 2.49-.96 4.68-.93 2.19-2.55 3.81a12.3 12.3 0 0 1-3.81 2.58Q2.49 12 0 12q2.49 0 4.68.96 2.19.93 3.81 2.55t2.55 3.81\"></path></svg>Gemini<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><div class=\"my-0.5 border-t border-[var(--blog-border)]\"></div><button class=\"flex w-full items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-faint)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-[var(--blog-muted)]\"><svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\"><rect x=\"9\" y=\"9\" width=\"13\" height=\"13\" rx=\"2\"></rect><path d=\"M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1\"></path></svg>Copy full context</button></div></div></div></div><p class=\"mt-2 text-sm font-medium text-[var(--blog-faint)]\">10<!-- --> <!-- -->min read<!-- --> · <!-- -->Last updated<!-- --> <!-- -->July 2026</p></header></div><div class=\"mx-auto max-w-[620px] px-6 sm:px-0\"><div><div class=\"prose-body\"><p>The numbers are no longer theoretical. More than 80% of Fortune 500 companies now run active AI agents built with low-code and no-code tools<sup class=\"bp-cite\"><a href=\"#source-1\" data-source-idx=\"1\">[1]</a></sup>, and Gartner projects that up to 40% of enterprise applications will include integrated task-specific AI agents by the end of 2026, up from less than 5% today<sup class=\"bp-cite\"><a href=\"#source-2\" data-source-idx=\"2\">[2]</a></sup>. Yet the security posture underneath that deployment wave is alarming: on average, only 47.1% of an organization&#39;s AI agents are actively monitored or secured<sup class=\"bp-cite\"><a href=\"#source-3\" data-source-idx=\"3\">[3]</a></sup>. The other half operate without oversight, logging, or identity controls.</p>\n<p>This is not a future problem. It is the current state of your production environment.</p>\n<p>The good news - if you can call it that - is that the standards community has noticed. In the first half of 2026, more governance specifications landed for AI agent identity than in the entire prior history of the field. This post maps what those standards actually say, which vendor categories are responding, where the real gaps remain, and what a buyer should demand today.</p>\n<hr>\n<h2>The Standards Landscape: What&#39;s Actually Shipping</h2>\n<h3>MCP OAuth 2.1 Under Linux Foundation Governance</h3>\n<p>The Model Context Protocol started as an Anthropic experiment in November 2024. By December 2025, Anthropic had donated MCP to the Agentic AI Foundation (AAIF) under the Linux Foundation, with OpenAI, Block, AWS, Google, Microsoft, Cloudflare, and Bloomberg joining as founding or platinum members<sup class=\"bp-cite\"><a href=\"#source-4\" data-source-idx=\"4\">[4]</a></sup>. Within four months, the AAIF grew to 170 member organizations - more than double the membership CNCF had at the same stage of its life<sup class=\"bp-cite\"><a href=\"#source-5\" data-source-idx=\"5\">[5]</a></sup>.</p>\n<p>The governance shift matters for enterprise buyers. MCP is no longer a single-vendor protocol that any one company can deprecate or fork. It is now closer in structure to CNCF than to a proprietary API.</p>\n<p>On authentication specifically: the MCP spec mandates OAuth 2.1 with PKCE for all protected HTTP-based deployments, requiring HTTPS on all endpoints and discoverable authorization server metadata<sup class=\"bp-cite\"><a href=\"#source-6\" data-source-idx=\"6\">[6]</a></sup>. The 2026 roadmap, published in March, makes enterprise readiness - including audit trails, SSO-integrated auth, and configuration portability - a top priority. The spec&#39;s authorization Working Group had six dedicated sessions at the April 2026 MCP Dev Summit, with the OAuth 2.1 spec author present.</p>\n<p>The 2026 MCP roadmap flagged audit trail infrastructure, SSO-integrated auth, and configuration portability as the top enterprise requests<sup class=\"bp-cite\"><a href=\"#source-7\" data-source-idx=\"7\">[7]</a></sup>. None of those are solved yet. The roadmap is a commitment, not a delivery.</p>\n<div class=\"bp-component bp-callout bp-callout--warning\"><div class=\"bp-callout__header\"><span class=\"material-icons\">warning</span> Warning</div><div class=\"bp-callout__body\"><p><strong>The authentication gap is real.</strong> Research published in early 2026 documented more than 1,800 active MCP servers on the public internet with no authentication whatsoever. Because authentication in MCP is optional — not required by the spec — they are technically compliant and practically insecure. Before deploying any MCP server, verify OAuth 2.1 is enabled and enforced, not just installed.</p></div></div>\n\n\n\n<h3>MCP-I / KYA-OS: Decentralized Identity for Agents</h3>\n<p>OAuth 2.1 handles <em>authentication</em> - proving an agent is who it claims to be. It does not answer the harder questions: Who authorized this agent? What is it allowed to do on behalf of which human? Can a downstream service verify that chain without prior coordination?</p>\n<p>In March 2026, Vouched formally donated the Model Context Protocol - Identity (MCP-I) framework to the Decentralized Identity Foundation (DIF), where it is now stewarded by the DIF Trusted AI Agents Working Group<sup class=\"bp-cite\"><a href=\"#source-8\" data-source-idx=\"8\">[8]</a></sup>. The spec has since been renamed KYA-OS (Know Your Agent Operating System) to reflect its scope beyond MCP alone.</p>\n<p>MCP-I / KYA-OS uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to enable cryptographically secure verification of both agents and their human principals - without requiring prior coordination between parties<sup class=\"bp-cite\"><a href=\"#source-9\" data-source-idx=\"9\">[9]</a></sup>. The framework defines four identity questions every service should be able to answer: Who is the agent? Who authorized it? What is it allowed to do? What is the scope of that delegation?</p>\n<p>This is the right architecture for multi-organization agent workflows - a travel booking agent acting on behalf of a user across airline, hotel, and payment systems, for example. It is also early. The spec is in active community development, and production implementations are sparse.</p>\n<h3>Microsoft Entra Agent ID</h3>\n<p>Microsoft moved fastest among the major identity platforms. Microsoft Entra Agent ID introduces agent identities as a distinct, purpose-built construct - not a repurposed service principal or user account - with agent identity blueprints serving as templates for creating individual agent identities with parent-child relationships<sup class=\"bp-cite\"><a href=\"#source-10\" data-source-idx=\"10\">[10]</a></sup>.</p>\n<p>Agent identities in Entra do not have credentials of their own; they rely on the agent identity blueprint to acquire tokens on their behalf, and they only authenticate using federated identity credentials<sup class=\"bp-cite\"><a href=\"#source-11\" data-source-idx=\"11\">[11]</a></sup>. This is the right model: credentials live in the blueprint, not on the agent, so a compromised agent cannot exfiltrate its own keys.</p>\n<p>Microsoft Agent 365, generally available from May 1, 2026, gives each AI agent its own Entra Agent ID for identity, lifecycle, and access management, and integrates with Conditional Access, identity protection, and Microsoft Purview<sup class=\"bp-cite\"><a href=\"#source-12\" data-source-idx=\"12\">[12]</a></sup>. Third-party agents from AWS Bedrock, n8n, and other frameworks can be onboarded via workload identity federation - no platform-specific credential management required.</p>\n<p>The honest limitation: Entra Agent ID is a strong solution if your agent estate lives inside the Microsoft ecosystem. For organizations running heterogeneous stacks - Anthropic, AWS, open-source frameworks, and custom-built agents - the governance surface extends well beyond what any single IdP can cover.</p>\n<h3>CSA Agentic Trust Framework and CSAI Foundation</h3>\n<p>The Cloud Security Alliance has been the most prolific standards producer in this space. The CSA published the Agentic Trust Framework (ATF) on February 2, 2026 - the first governance specification applying Zero Trust principles to autonomous AI agents with a structured maturity model<sup class=\"bp-cite\"><a href=\"#source-13\" data-source-idx=\"13\">[13]</a></sup>. The ATF was co-authored by John Kindervag, the original creator of Zero Trust.</p>\n<p>A companion survey of 285 IT and security professionals makes the urgency concrete: 84% of organizations cannot pass a compliance audit focused on agent behavior or access controls, and only 23% have a formal agent identity strategy<sup class=\"bp-cite\"><a href=\"#source-14\" data-source-idx=\"14\">[14]</a></sup>.</p>\n<p>The CSA&#39;s MAESTRO threat modeling framework explicitly names <strong>agent impersonation</strong> as a distinct threat class - malicious actors deceiving users or other agents by impersonating legitimate AI agents. The prescribed mitigations are trusted agent registries, cryptographic agent identities, and short-lived OAuth/OIDC tokens scoped to the intersection of what the agent is allowed to do AND what the delegating user is allowed to do. An AND gate, not an OR gate.</p>\n<p>In March 2026, the CSA launched the CSAI Foundation at RSAC 2026, a new 501(c)3 dedicated exclusively to AI security, with a 2026 mission of &quot;Securing the Agentic Control Plane&quot; - governing identity, authorization, orchestration, runtime behavior, and trust assurance for autonomous AI agent ecosystems<sup class=\"bp-cite\"><a href=\"#source-15\" data-source-idx=\"15\">[15]</a></sup>.</p>\n<hr>\n<h2>The Player Map: Four Categories, Different Strengths</h2>\n<p>The vendor landscape has fragmented into four distinct categories. Understanding what each does - and doesn&#39;t do - is essential before buying.</p>\n<div class=\"bp-component bp-data-table\"><div class=\"bp-data-table__title\">AI Agent Identity: Vendor Category Comparison</div><table><thead><tr><th>Category</th><th>Examples</th><th>Core Strength</th><th>Key Gap</th></tr></thead><tbody><tr><td>Identity Providers extending to agents</td><td>Microsoft Entra Agent ID, Okta (MCP server + Auth for MCP), Auth0</td><td>Standards-based auth (OAuth 2.1/OIDC), existing enterprise trust, lifecycle hooks</td><td>Ecosystem lock-in; heterogeneous agent stacks require federation workarounds</td></tr><tr><td>NHI Security Specialists</td><td>Oasis Security, Entro, Teleport</td><td>Discovery, secrets rotation, posture management for service accounts and API keys</td><td>Agent governance is identity-discovery-led, not runtime-enforcement-led; agents treated as NHI subset, not first-class</td></tr><tr><td>MCP Gateways</td><td>Arcade, TrueFoundry, Cloudflare Agents SDK</td><td>Runtime authorization at the tool-call level; per-session ephemeral credentials; low-latency enforcement</td><td>Closed ecosystems; governance doesn&#39;t extend to human identities or non-MCP agents</td></tr><tr><td>IGA Platforms governing agents + humans</td><td>Iden, SailPoint (Agent Identity Security add-on), ServiceNow/Veza</td><td>Unified lifecycle governance across human and non-human identities; policy-driven provisioning and deprovisioning; access reviews</td><td>Legacy IGA platforms bolt on agent support; depth and automation vary significantly</td></tr></tbody></table></div>\n\n\n\n<p>A few notes on the landscape:</p>\n<p><strong>Identity providers</strong> are moving fast. Auth0&#39;s &quot;Auth for MCP&quot; became generally available on May 6, 2026, and Okta released its own MCP server as a secure protocol abstraction layer enabling AI agents to interact with Okta&#39;s scoped management APIs with least-privilege access control enforced at each tool call<sup class=\"bp-cite\"><a href=\"#source-2\" data-source-idx=\"2\">[2]</a></sup>. These are authentication solutions. They do not govern the full identity lifecycle.</p>\n<p><strong>NHI specialists</strong> have the discovery story right. Veza&#39;s 2026 State of Identity and Access report found that a mere 0.01% of non-human identities control 80% of cloud resources, while the average worker holds 96,000 entitlements<sup class=\"bp-cite\"><a href=\"#source-16\" data-source-idx=\"16\">[16]</a></sup>. Knowing that is valuable. Governing it requires more than a posture dashboard.</p>\n<p><strong>MCP gateways</strong> solve the runtime enforcement problem elegantly for agents you build inside their ecosystem. The problem is coverage: only 23.7% of organizations use their existing IAM/IdP as an authorization server for their agentic MCP infrastructure<sup class=\"bp-cite\"><a href=\"#source-3\" data-source-idx=\"3\">[3]</a></sup>. The rest are running disconnected auth stacks.</p>\n<p><strong>IGA platforms</strong> are the natural home for agent governance - if they&#39;ve actually built it. SailPoint expanded Agent Identity Security connectors in 2026 to include SaaS versions of Salesforce, ServiceNow, and Snowflake, but governance of agent identities requires a separate Agent Identity Security license<sup class=\"bp-cite\"><a href=\"#source-17\" data-source-idx=\"17\">[17]</a></sup>. Legacy IGA vendors are adding agent support as a module. That&#39;s not the same as designing for it from the start.</p>\n<hr>\n<h2>The Honest Gaps</h2>\n<p>Standards are immature. The MCP OAuth 2.1 profile is solid for authentication but has no standardized audit trail format. MCP-I / KYA-OS is in active community development with sparse production implementations. The CSA ATF is a governance framework, not an enforcement tool.</p>\n<p>The monitoring gap is severe. Only 14.4% of organizations have achieved full IT and security approval for their entire agent fleet, and 88% of organizations reported confirmed or suspected AI agent security incidents in the past year<sup class=\"bp-cite\"><a href=\"#source-18\" data-source-idx=\"18\">[18]</a></sup>. Only 21.9% of organizations currently treat AI agents as independent, identity-bearing entities within their security model<sup class=\"bp-cite\"><a href=\"#source-3\" data-source-idx=\"3\">[3]</a></sup>. Most still treat agents as extensions of human users or generic service accounts.</p>\n<p>The over-permissioning problem is structural. 70% of security leaders say AI systems have more access than a human in the same role, and 67% of organizations rely on static credentials for AI systems<sup class=\"bp-cite\"><a href=\"#source-19\" data-source-idx=\"19\">[19]</a></sup>. Static, long-lived credentials are the opposite of what every framework recommends. They persist after an agent&#39;s task is complete, survive offboarding, and create the same orphaned-account problem that has plagued human identity governance for decades - just at machine speed.</p>\n<p>The CSA-Oasis State of NHI and AI Security 2026 found that 51% of organizations cite over-permissioned access as a top NHI pain point, and 78% have no documented policy for creating or removing AI identities<sup class=\"bp-cite\"><a href=\"#source-20\" data-source-idx=\"20\">[20]</a></sup>.</p>\n<figure class=\"bp-component bp-image\" data-component-id=\"3a13a849-8155-45c7-8c5c-27430a712e8c\"><img src=\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/6c51af9e-cfc7-42f5-958f-0a84c680cb69.jpg\" alt=\"Isometric diagram showing two parallel governance tracks: on the left, a structured lifecycle flow for human employees (hire, provision, review, offboard) with clear checkpoints; on the right, a chaotic tangle of AI agents with no lifecycle, overlapping permissions, and missing audit trails - visually contrasting governed vs. ungoverned identity\" loading=\"lazy\" /></figure>\n\n\n\n<hr>\n<h2>What IGA Looks Like When It&#39;s Built for This</h2>\n<p>The governance problem for AI agents is structurally identical to the governance problem for human identities - and for the same reason that IGA exists: access sprawl, orphaned accounts, over-permissioning, and the inability to answer &quot;who has access to what, and should they?&quot; at any given moment.</p>\n<p>The difference is velocity and scale. NHIs outnumber human identities 17 to 1 in the average enterprise, and the NHI population grew 44% year-over-year between 2024 and 2025<sup class=\"bp-cite\"><a href=\"#source-21\" data-source-idx=\"21\">[21]</a></sup>. AI agents are the fastest-growing segment within that already-exploding category. Quarterly access reviews cannot keep pace. Neither can spreadsheets.</p>\n<p>What&#39;s needed is a single governance plane that treats human and non-human identities with the same policy engine, the same lifecycle automation, and the same access review workflows - without requiring a separate module, a separate license, or a separate team.</p>\n<p>That&#39;s the design principle behind Iden. Rather than bolting agent governance onto a human-centric IGA platform, or treating agents as a subset of NHI discovery, Iden governs all identity types - employees, contractors, service accounts, bots, and AI agents - through the same policy-driven lifecycle engine. Fine-grained control at the channel, repository, and project level means an agent gets exactly the access its task requires, and that access is revoked when the task is done. No standing permissions. No orphaned agent accounts.</p>\n<p>For organizations evaluating where AI agent governance fits in their stack, the <a href=\"/blog/12-best-iga-vendors-2026\">12 Best IGA Vendors in 2026</a> post maps the full landscape, and our <a href=\"/blog/nhi-explosion-non-human-identity\">NHI explosion piece</a> covers the scale of the underlying problem in detail.</p>\n<hr>\n<h2>How to Evaluate Agent Identity Capabilities Today</h2>\n<p>The standards are immature, the vendor claims are ahead of the implementations, and the threat is real. Here is a practical evaluation framework for buyers.</p>\n<div class=\"bp-component bp-steps\"><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">1</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Inventory your agent estate before you buy anything</strong><p>You cannot govern what you cannot see. Start with a full discovery pass: which agents are running, who deployed them, what credentials they hold, and what systems they can reach. Shadow agents — those with no registry entry, no assigned owner, and no managed identity — are your highest-risk population. Treat them as Critical findings.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">2</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Demand short-lived, scoped credentials — not API keys</strong><p>Any platform that relies on shared API keys or long-lived static credentials for agent authentication is not a governance solution. Require per-session ephemeral tokens scoped to the specific task, with automatic teardown at end of session. This is the single highest-leverage control against prompt injection and credential theft.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">3</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Verify the AND gate, not the OR gate</strong><p>An agent should only be able to do what the agent is authorized to do AND what the delegating user is authorized to do — not the union of both. Service accounts that inherit broad employee credentials create authorization bypass vulnerabilities. Confirm that your chosen platform enforces the intersection, not the superset.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">4</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Require a full audit trail at the tool-call level</strong><p>Logging that an agent &#39;ran&#39; is not an audit trail. You need: which agent, which user delegated, which tool was called, with what arguments, what data was accessed, and what the result was. The EU AI Act&#39;s transparency provisions take effect August 2, 2026. If your platform cannot produce this log on demand, it cannot support compliance.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">5</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Evaluate lifecycle governance, not just runtime enforcement</strong><p>Runtime authorization at the tool-call level is necessary but not sufficient. You also need: agent registration and approval workflows before deployment, access reviews on the same cadence as human identities, and automated deprovisioning when an agent is retired. Ask vendors specifically how they handle agent offboarding — most have no answer.</p></div></div><div class=\"bp-step bp-step--last\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">6</span></div><div class=\"bp-step__content\"><strong>Insist on unified governance across human and non-human identities</strong><p>Separate tools for human IGA and agent governance create blind spots at the seams. An agent acting on behalf of a human should be governed in the same plane as that human — same policy engine, same access review, same audit log. If your IGA platform treats agents as a bolt-on module, you have a coverage gap.</p></div></div></div>\n\n\n\n<hr>\n<h2>The Bottom Line</h2>\n<p>The 2026 standards landscape for AI agent identity is real and moving fast - MCP OAuth 2.1 under Linux Foundation governance, MCP-I / KYA-OS at the DIF, Microsoft Entra Agent ID in GA, and the CSA Agentic Trust Framework providing the governance vocabulary. These are genuine milestones.</p>\n<p>But standards are not implementations. Only 3% of organizations have automated, machine-speed controls governing AI behavior<sup class=\"bp-cite\"><a href=\"#source-19\" data-source-idx=\"19\">[19]</a></sup>. The gap between what the frameworks prescribe and what organizations have actually deployed is enormous.</p>\n<p>The organizations that close that gap fastest will be the ones that stop treating agent governance as a separate problem from identity governance. Agents are identities. They need the same lifecycle controls, the same access reviews, the same deprovisioning workflows, and the same audit trails as every other identity in your environment - just with shorter-lived credentials and faster policy enforcement.</p>\n<p>That&#39;s not a new category of tooling. It&#39;s IGA, built for the full population of identities your enterprise actually runs.</p>\n<div class=\"bp-component bp-widget\"><div class=\"inline-widget-container\" data-island=\"widget\" data-widget-id=\"e5afe1d7-cb52-4acd-8a56-b6970002b90b\" data-widget-lang=\"en\"></div></div>\n\n\n</div></div><div class=\"prose-body mt-12 border-t border-[var(--blog-border)] pt-8\"><ol class=\"bp-sources\"><li id=\"source-1\"><a href=\"https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/\" target=\"_blank\" rel=\"noopener nofollow\">microsoft.com — 80 of fortune 500 use active ai agents observability governance and security shape the new frontier</a></li><li id=\"source-2\"><a href=\"https://www.marktechpost.com/2026/05/25/best-authentication-platforms-for-ai-agents-and-mcp-servers-in-2026/\" target=\"_blank\" rel=\"noopener nofollow\">marktechpost.com — Best authentication platforms for ai agents and mcp servers in 2026</a></li><li id=\"source-3\"><a href=\"https://www.gravitee.io/state-of-ai-agent-security\" target=\"_blank\" rel=\"noopener nofollow\">gravitee.io — State of ai agent security</a></li><li id=\"source-4\"><a href=\"https://workos.com/blog/everything-your-team-needs-to-know-about-mcp-in-2026/\" target=\"_blank\" rel=\"noopener nofollow\">workos.com — Everything your team needs to know about mcp in 2026</a></li><li id=\"source-5\"><a href=\"https://aaif.io/blog/mcp-is-now-enterprise-infrastructure-everything-that-happened-at-mcp-dev-summit-north-america-2026/\" target=\"_blank\" rel=\"noopener nofollow\">aaif.io — Mcp is now enterprise infrastructure everything that happened at mcp dev summit north america 2026</a></li><li id=\"source-6\"><a href=\"https://www.prefect.io/resources/mcp-oauth\" target=\"_blank\" rel=\"noopener nofollow\">prefect.io — Mcp oauth</a></li><li id=\"source-7\"><a href=\"https://epinium.com/en/blog/model-context-protocol-enterprise-guide/\" target=\"_blank\" rel=\"noopener nofollow\">epinium.com — Model context protocol enterprise guide</a></li><li id=\"source-8\"><a href=\"https://www.vouched.id/learn/vouched-donates-mcp-i-identity-framework-to-the-decentralized-identity-foundation-to-advance-trust-and-security-for-ai-agents\" target=\"_blank\" rel=\"noopener nofollow\">vouched.id — Vouched donates mcp i identity framework to the decentralized identity foundation to advance trust and security for ai agents</a></li><li id=\"source-9\"><a href=\"https://blog.identity.foundation/why-dif-said-yes-to-mcp-i/\" target=\"_blank\" rel=\"noopener nofollow\">blog.identity.foundation — Why dif said yes to mcp i</a></li><li id=\"source-10\"><a href=\"https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id\" target=\"_blank\" rel=\"noopener nofollow\">learn.microsoft.com — What is microsoft entra agent id</a></li><li id=\"source-11\"><a href=\"https://learn.microsoft.com/en-us/entra/agent-id/agent-identities\" target=\"_blank\" rel=\"noopener nofollow\">learn.microsoft.com — Agent identities</a></li><li id=\"source-12\"><a href=\"https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/\" target=\"_blank\" rel=\"noopener nofollow\">microsoft.com — Secure agentic ai end to end</a></li><li id=\"source-13\"><a href=\"https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents\" target=\"_blank\" rel=\"noopener nofollow\">cloudsecurityalliance.org — The agentic trust framework zero trust governance for ai agents</a></li><li id=\"source-14\"><a href=\"https://www.oktsec.com/blog/csa-agentic-trust-framework-zero-trust-agents/\" target=\"_blank\" rel=\"noopener nofollow\">oktsec.com — Csa agentic trust framework zero trust agents</a></li><li id=\"source-15\"><a href=\"https://cloudsecurityalliance.org/press-releases/2026/03/23/csa-securing-the-agentic-control-plane\" target=\"_blank\" rel=\"noopener nofollow\">cloudsecurityalliance.org — Csa securing the agentic control plane</a></li><li id=\"source-16\"><a href=\"https://veza.com/blog/forrester-recognizes-veza-for-iga-ispm-and-nhi-ai-identity-management/\" target=\"_blank\" rel=\"noopener nofollow\">veza.com — Forrester recognizes veza for iga ispm and nhi ai identity management</a></li><li id=\"source-17\"><a href=\"https://aimultiple.com/iga-solutions\" target=\"_blank\" rel=\"noopener nofollow\">aimultiple.com — Iga solutions</a></li><li id=\"source-18\"><a href=\"https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control\" target=\"_blank\" rel=\"noopener nofollow\">gravitee.io — State of ai agent security 2026 report when adoption outpaces control</a></li><li id=\"source-19\"><a href=\"https://www.cybersecstats.com/ai-cybersecurity-statistics-2026-q1-q2/\" target=\"_blank\" rel=\"noopener nofollow\">cybersecstats.com — Ai cybersecurity statistics 2026 q1 q2</a></li><li id=\"source-20\"><a href=\"https://secureflo.net/ai-agent-identity-management-a-2026-ciso-playbook/\" target=\"_blank\" rel=\"noopener nofollow\">secureflo.net — Ai agent identity management a 2026 ciso playbook</a></li><li id=\"source-21\"><a href=\"https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/\" target=\"_blank\" rel=\"noopener nofollow\">labs.cloudsecurityalliance.org — Csa whitepaper nonhuman identity agentic ai governance v1 cs</a></li></ol></div></div><section class=\"mx-auto mt-20 max-w-[620px] border-t border-[var(--blog-border)] px-6 pt-12 sm:px-0\"><h2 class=\"mb-6 font-mono text-[11px] uppercase tracking-[0.22em] text-[var(--blog-faint)]\">Related reading</h2><div class=\"grid gap-6 sm:grid-cols-2\"><a class=\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\" href=\"/en/blog/segregation-of-duties-guide-entitlement-level\"><div class=\"relative aspect-[16/9] overflow-hidden\"><div class=\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\"><svg class=\"absolute inset-0 h-full w-full\" viewBox=\"0 0 320 200\" preserveAspectRatio=\"xMidYMid slice\" aria-hidden=\"true\"><defs><linearGradient id=\"blog-grad-segregation-of-duties-guide-entitlement-level\" x1=\"50%\" y1=\"0%\" x2=\"50%\" y2=\"100%\"><stop offset=\"0%\" stop-color=\"#D4DCDA\"></stop><stop offset=\"100%\" stop-color=\"#47585C\"></stop></linearGradient><filter id=\"blog-grain-segregation-of-duties-guide-entitlement-level\" x=\"0\" y=\"0\" width=\"100%\" height=\"100%\"><feTurbulence type=\"fractalNoise\" baseFrequency=\"0.9\" numOctaves=\"2\" seed=\"6543\" result=\"noise\"></feTurbulence><feColorMatrix in=\"noise\" type=\"matrix\" values=\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\"></feColorMatrix></filter><pattern id=\"blog-dither-segregation-of-duties-guide-entitlement-level\" patternUnits=\"userSpaceOnUse\" width=\"4\" height=\"4\"><circle cx=\"1.5\" cy=\"1.5\" r=\"0.3\" fill=\"#000\" fill-opacity=\"0.06\"></circle></pattern></defs><rect width=\"320\" height=\"200\" fill=\"url(#blog-grad-segregation-of-duties-guide-entitlement-level)\"></rect><rect width=\"320\" height=\"220\" filter=\"url(#blog-grain-segregation-of-duties-guide-entitlement-level)\" style=\"mix-blend-mode:overlay\"></rect><rect width=\"320\" height=\"200\" fill=\"url(#blog-dither-segregation-of-duties-guide-entitlement-level)\"></rect></svg><svg viewBox=\"0 0 256 256\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"6\" class=\"absolute left-5 top-5 h-9 w-9 pointer-events-none\" style=\"color:#1c1c1c;opacity:0.78\" aria-hidden=\"true\"><path d=\"M10 128H246M71 69L10 128L71 187M186 187L246 128L186 69\"></path></svg></div><div class=\"absolute right-3 top-3\"><span class=\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\">Segregation of duties</span></div></div><div class=\"flex flex-1 flex-col gap-2.5 p-5\"><h3 class=\"text-[17px] font-normal leading-snug tracking-tight text-white\"><span class=\"blog-underline\">The Definitive Guide to Segregation of Duties (SoD): From Policy to Entitlement-Level Enforcement</span></h3><p class=\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\">A complete SoD guide: definition, toxic combinations, framework mapping (SOC 2, ISO 27001, SOX, PCI DSS), the conflict matrix, and why role-level SoD misses the real violations hiding inside broad entitlements.</p><div class=\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\"><span class=\"tabular-nums\">Jul 24, 2026</span></div></div></a><a class=\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\" href=\"/en/blog/third-party-contractor-access-audit-evidence\"><div class=\"relative aspect-[16/9] overflow-hidden\"><div class=\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\"><svg class=\"absolute inset-0 h-full w-full\" viewBox=\"0 0 320 200\" preserveAspectRatio=\"xMidYMid slice\" aria-hidden=\"true\"><defs><linearGradient id=\"blog-grad-third-party-contractor-access-audit-evidence\" x1=\"50%\" y1=\"0%\" x2=\"50%\" y2=\"100%\"><stop offset=\"0%\" stop-color=\"#E5E4E6\"></stop><stop offset=\"100%\" stop-color=\"#4D80E6\"></stop></linearGradient><filter id=\"blog-grain-third-party-contractor-access-audit-evidence\" x=\"0\" y=\"0\" width=\"100%\" height=\"100%\"><feTurbulence type=\"fractalNoise\" baseFrequency=\"0.9\" numOctaves=\"2\" seed=\"4201\" result=\"noise\"></feTurbulence><feColorMatrix in=\"noise\" type=\"matrix\" values=\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\"></feColorMatrix></filter><pattern id=\"blog-dither-third-party-contractor-access-audit-evidence\" patternUnits=\"userSpaceOnUse\" width=\"4\" height=\"4\"><circle cx=\"1.5\" cy=\"1.5\" r=\"0.3\" fill=\"#000\" fill-opacity=\"0.06\"></circle></pattern></defs><rect width=\"320\" height=\"200\" fill=\"url(#blog-grad-third-party-contractor-access-audit-evidence)\"></rect><rect width=\"320\" height=\"220\" filter=\"url(#blog-grain-third-party-contractor-access-audit-evidence)\" style=\"mix-blend-mode:overlay\"></rect><rect width=\"320\" height=\"200\" fill=\"url(#blog-dither-third-party-contractor-access-audit-evidence)\"></rect></svg><svg viewBox=\"0 0 256 256\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"6\" class=\"absolute left-5 top-5 h-9 w-9 pointer-events-none\" style=\"color:#1c1c1c;opacity:0.78\" aria-hidden=\"true\"><path d=\"M128 8V88M246.5 9.5L156.697 99.3026M168 128H248M246.5 246.5L156.697 156.697M128 168V248M9.5 246.5L99.3026 156.697M8 128H88M9.5 9.5L99.3026 99.3026\"></path></svg></div><div class=\"absolute right-3 top-3\"><span class=\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\">Third-party access audit trail</span></div></div><div class=\"flex flex-1 flex-col gap-2.5 p-5\"><h3 class=\"text-[17px] font-normal leading-snug tracking-tight text-white\"><span class=\"blog-underline\">Third-Party Access Is Your Audit&#x27;s Weakest Link - Here&#x27;s How to Fix It</span></h3><p class=\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\">Contractors and partners don&#x27;t live in your HRIS - so they fall outside JML automation and become orphaned-access hotspots. Here&#x27;s the evidence every auditor demands and how to produce it.</p><div class=\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\"><span class=\"tabular-nums\">Jul 17, 2026</span></div></div></a><a class=\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\" href=\"/en/blog/legacy-iga-migration-guide-checklist\"><div class=\"relative aspect-[16/9] overflow-hidden\"><div class=\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\"><svg class=\"absolute inset-0 h-full w-full\" viewBox=\"0 0 320 200\" preserveAspectRatio=\"xMidYMid slice\" aria-hidden=\"true\"><defs><linearGradient id=\"blog-grad-legacy-iga-migration-guide-checklist\" x1=\"50%\" y1=\"0%\" x2=\"50%\" y2=\"100%\"><stop offset=\"0%\" stop-color=\"#D4DCDA\"></stop><stop offset=\"100%\" stop-color=\"#949495\"></stop></linearGradient><filter id=\"blog-grain-legacy-iga-migration-guide-checklist\" x=\"0\" y=\"0\" width=\"100%\" height=\"100%\"><feTurbulence type=\"fractalNoise\" baseFrequency=\"0.9\" numOctaves=\"2\" seed=\"349\" result=\"noise\"></feTurbulence><feColorMatrix in=\"noise\" type=\"matrix\" values=\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\"></feColorMatrix></filter><pattern id=\"blog-dither-legacy-iga-migration-guide-checklist\" patternUnits=\"userSpaceOnUse\" width=\"4\" height=\"4\"><circle cx=\"1.5\" cy=\"1.5\" r=\"0.3\" fill=\"#000\" fill-opacity=\"0.06\"></circle></pattern></defs><rect width=\"320\" height=\"200\" fill=\"url(#blog-grad-legacy-iga-migration-guide-checklist)\"></rect><rect width=\"320\" height=\"220\" filter=\"url(#blog-grain-legacy-iga-migration-guide-checklist)\" style=\"mix-blend-mode:overlay\"></rect><rect width=\"320\" height=\"200\" fill=\"url(#blog-dither-legacy-iga-migration-guide-checklist)\"></rect></svg><svg viewBox=\"0 0 256 256\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"6\" class=\"absolute left-5 top-5 h-9 w-9 pointer-events-none\" style=\"color:#1c1c1c;opacity:0.78\" aria-hidden=\"true\"><path d=\"M10 128C10 193.17 62.8304 246 128 246C193.17 246 246 193.17 246 128C246 62.8304 193.17 10 128 10C62.8304 10 10 62.8304 10 128ZM10 128L246 128.123M39.4543 50H216.546M39.4543 206H216.546\"></path></svg></div><div class=\"absolute right-3 top-3\"><span class=\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\">Legacy IGA migration</span></div></div><div class=\"flex flex-1 flex-col gap-2.5 p-5\"><h3 class=\"text-[17px] font-normal leading-snug tracking-tight text-white\"><span class=\"blog-underline\">The Legacy IGA Migration Guide: Real Costs, Realistic Timelines, and a Step-by-Step Checklist</span></h3><p class=\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\">Replacing SailPoint IIQ, Oracle, IBM, or One Identity feels terrifying. This guide breaks down the real migration costs, honest timelines, and a step-by-step checklist to de-risk the switch.</p><div class=\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\"><span class=\"tabular-nums\">Jul 13, 2026</span></div></div></a></div></section></article><!--$--><!--/$--></main><div class=\"border-t border-neutral-800\"><footer class=\"w-full bg-neutral-900 overflow-hidden\"><div class=\"px-4 pt-32 pb-3 flex items-center justify-between gap-4\"><span class=\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\">© 2026 IDENHQ, INC.</span><div class=\"hidden sm:flex flex-wrap items-center justify-center gap-x-3 gap-y-1\"><span class=\"flex items-center gap-3\"><a href=\"/charter\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Charter</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"/field-notes\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Field Notes</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"/vs\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Versus</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"/faq\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">FAQ</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"https://trust.idenhq.com\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Trust</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\" href=\"/en/privacy-policy\">Privacy</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\" href=\"/en/terms-of-service\">Terms</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\" href=\"/en/legal-notice\">Legal Notice</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><button class=\"text-base text-neutral-500 transition-colors hover:text-neutral-300\">Cookies</button></span></div><span class=\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\">Backed by<!-- --> <a href=\"https://www.accel.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"hover:text-neutral-300 transition-colors\">Accel</a></span></div><div class=\"pt-1 pb-0 select-none overflow-hidden\"><svg viewBox=\"0.55 0 99.06 29.07\" preserveAspectRatio=\"xMinYMin meet\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\" class=\"w-full h-auto block\" style=\"fill:#262626\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\"></path><path d=\"M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"></path></svg></div></footer></div></div><script src=\"/_next/static/chunks/0oqqtf7q0fh8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" id=\"_R_\" async=\"\"></script><script>(self.__next_f=self.__next_f||[]).push([0])</script><script>self.__next_f.push([1,\"1:\\\"$Sreact.fragment\\\"\\n2:I[65453,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n3:I[92263,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n8:I[58096,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"OutletBoundary\\\"]\\n9:\\\"$Sreact.suspense\\\"\\nc:I[58096,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"ViewportBoundary\\\"]\\ne:I[58096,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"MetadataBoundary\\\"]\\n10:I[17506,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\",1]\\n15:I[10085,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n19:I[4534,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"\\\"]\\n1b:I[8051,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n1c:I[12924,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n1d:I[23133,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n21:I[63369,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"PostHogProvider\\\"]\\n22:I[99132,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.j\"])</script><script>self.__next_f.push([1,\"s?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n23:I[48504,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n24:I[29950,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"FloatingLangSwitch\\\"]\\n25:I[40244,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n26:I[59255,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"VisitTracker\\\"]\\n27:I[64242,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"Analytics\\\"]\\n:HL[\\\"/_next/static/chunks/08_loej5.wuit.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"style\\\"]\\n:HL[\\\"/_next/static/chunks/0-jf1u_rglope.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"style\\\"]\\n:HL[\\\"/_next/static/chunks/0_kwzt0c~eysn.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"style\\\"]\\n:HL[\\\"/_next/static/media/83afe278b6a6bb3c-s.p.0q-301v4kxxnr.woff2?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n\"])</script><script>self.__next_f.push([1,\"0:{\\\"P\\\":null,\\\"c\\\":[\\\"\\\",\\\"en\\\",\\\"blog\\\",\\\"ai-agent-identity-management-2026\\\"],\\\"q\\\":\\\"\\\",\\\"i\\\":false,\\\"f\\\":[[[\\\"\\\",{\\\"children\\\":[[\\\"locale\\\",\\\"en\\\",\\\"d\\\",null],{\\\"children\\\":[\\\"blog\\\",{\\\"children\\\":[[\\\"slug\\\",\\\"ai-agent-identity-management-2026\\\",\\\"d\\\",null],{\\\"children\\\":[\\\"__PAGE__\\\",{}]}]}]}]},\\\"$undefined\\\",\\\"$undefined\\\",16],[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[[[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-1\\\",{\\\"src\\\":\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":[[[\\\"$\\\",\\\"title\\\",null,{\\\"children\\\":\\\"404: This page could not be found.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"style\\\":{\\\"fontFamily\\\":\\\"system-ui,\\\\\\\"Segoe UI\\\\\\\",Roboto,Helvetica,Arial,sans-serif,\\\\\\\"Apple Color Emoji\\\\\\\",\\\\\\\"Segoe UI Emoji\\\\\\\"\\\",\\\"height\\\":\\\"100vh\\\",\\\"textAlign\\\":\\\"center\\\",\\\"display\\\":\\\"flex\\\",\\\"flexDirection\\\":\\\"column\\\",\\\"alignItems\\\":\\\"center\\\",\\\"justifyContent\\\":\\\"center\\\"},\\\"children\\\":[\\\"$\\\",\\\"div\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"style\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"body{color:#000;background:#fff;margin:0}.next-error-h1{border-right:1px solid rgba(0,0,0,.3)}@media (prefers-color-scheme:dark){body{color:#fff;background:#000}.next-error-h1{border-right:1px solid rgba(255,255,255,.3)}}\\\"}}],[\\\"$\\\",\\\"h1\\\",null,{\\\"className\\\":\\\"next-error-h1\\\",\\\"style\\\":{\\\"display\\\":\\\"inline-block\\\",\\\"margin\\\":\\\"0 20px 0 0\\\",\\\"padding\\\":\\\"0 23px 0 0\\\",\\\"fontSize\\\":24,\\\"fontWeight\\\":500,\\\"verticalAlign\\\":\\\"top\\\",\\\"lineHeight\\\":\\\"49px\\\"},\\\"children\\\":404}],[\\\"$\\\",\\\"div\\\",null,{\\\"style\\\":{\\\"display\\\":\\\"inline-block\\\"},\\\"children\\\":[\\\"$\\\",\\\"h2\\\",null,{\\\"style\\\":{\\\"fontSize\\\":14,\\\"fontWeight\\\":400,\\\"lineHeight\\\":\\\"49px\\\",\\\"margin\\\":0},\\\"children\\\":\\\"This page could not be found.\\\"}]}]]}]}]],[]],\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}]]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[[[\\\"$\\\",\\\"link\\\",\\\"0\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/chunks/08_loej5.wuit.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\",\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"link\\\",\\\"1\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/chunks/0-jf1u_rglope.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\",\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-1\\\",{\\\"src\\\":\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-2\\\",{\\\"src\\\":\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],\\\"$L4\\\"]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[[[\\\"$\\\",\\\"link\\\",\\\"0\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/chunks/0_kwzt0c~eysn.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\",\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"blog-root min-h-dvh\\\",\\\"children\\\":[\\\"$L5\\\",[\\\"$\\\",\\\"main\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"border-t border-neutral-800\\\",\\\"children\\\":\\\"$L6\\\"}]]}]]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[null,[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}]]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[\\\"$L7\\\",[[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],[\\\"$\\\",\\\"$L8\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$9\\\",null,{\\\"name\\\":\\\"Next.MetadataOutlet\\\",\\\"children\\\":\\\"$@a\\\"}]}]]}],{},null,false,null]},null,false,\\\"$@b\\\"]},null,false,null]},null,false,null]},null,false,null],[\\\"$\\\",\\\"$1\\\",\\\"h\\\",{\\\"children\\\":[null,[\\\"$\\\",\\\"$Lc\\\",null,{\\\"children\\\":\\\"$Ld\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"hidden\\\":true,\\\"children\\\":[\\\"$\\\",\\\"$Le\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$9\\\",null,{\\\"name\\\":\\\"Next.Metadata\\\",\\\"children\\\":\\\"$Lf\\\"}]}]}],[\\\"$\\\",\\\"meta\\\",null,{\\\"name\\\":\\\"next-size-adjust\\\",\\\"content\\\":\\\"\\\"}]]}],false]],\\\"m\\\":\\\"$undefined\\\",\\\"G\\\":[\\\"$10\\\",[]],\\\"S\\\":false,\\\"h\\\":null,\\\"s\\\":\\\"$undefined\\\",\\\"l\\\":\\\"$undefined\\\",\\\"p\\\":\\\"$undefined\\\",\\\"d\\\":\\\"$undefined\\\"}\\n\"])</script><script>self.__next_f.push([1,\"11:[]\\nb:\\\"$W11\\\"\\n16:T4f2,M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"])</script><script>self.__next_f.push([1,\"6:[\\\"$\\\",\\\"footer\\\",null,{\\\"className\\\":\\\"w-full bg-neutral-900 overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"px-4 pt-32 pb-3 flex items-center justify-between gap-4\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\\\",\\\"children\\\":\\\"© 2026 IDENHQ, INC.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"hidden sm:flex flex-wrap items-center justify-center gap-x-3 gap-y-1\\\",\\\"children\\\":[[[\\\"$\\\",\\\"span\\\",\\\"Charter\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[false,[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/charter\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Charter\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"Field Notes\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/field-notes\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Field Notes\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"Versus\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/vs\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Versus\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"FAQ\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/faq\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"FAQ\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"Trust\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"https://trust.idenhq.com\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Trust\\\"}]]}]],[[\\\"$\\\",\\\"span\\\",\\\"Privacy\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],\\\"$L12\\\"]}],[\\\"$\\\",\\\"span\\\",\\\"Terms\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],\\\"$L13\\\"]}],[\\\"$\\\",\\\"span\\\",\\\"Legal Notice\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],\\\"$L14\\\"]}]],[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"$L15\\\",null,{\\\"light\\\":false}]]}]]}],[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\\\",\\\"children\\\":[\\\"Backed by\\\",\\\" \\\",[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"https://www.accel.com\\\",\\\"target\\\":\\\"_blank\\\",\\\"rel\\\":\\\"noopener noreferrer\\\",\\\"className\\\":\\\"hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Accel\\\"}]]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"pt-1 pb-0 select-none overflow-hidden\\\",\\\"children\\\":[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0.55 0 99.06 29.07\\\",\\\"preserveAspectRatio\\\":\\\"xMinYMin meet\\\",\\\"fill\\\":\\\"none\\\",\\\"xmlns\\\":\\\"http://www.w3.org/2000/svg\\\",\\\"className\\\":\\\"w-full h-auto block\\\",\\\"style\\\":{\\\"fill\\\":\\\"#262626\\\"},\\\"children\\\":[[\\\"$\\\",\\\"path\\\",null,{\\\"fillRule\\\":\\\"evenodd\\\",\\\"clipRule\\\":\\\"evenodd\\\",\\\"d\\\":\\\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\\\"}],[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"$16\\\"}]]}]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"17:Tbbc,\"])</script><script>self.__next_f.push([1,\"[{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\",\\\"logo\\\":\\\"https://www.idenhq.com/logo/iden-wordmark.svg\\\",\\\"description\\\":\\\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\\\",\\\"sameAs\\\":[\\\"https://www.wikidata.org/wiki/Q140158373\\\",\\\"https://www.linkedin.com/company/idenhq\\\",\\\"https://github.com/IdenWorks\\\",\\\"https://twitter.com/idenhq\\\"],\\\"foundingDate\\\":\\\"2024-04\\\",\\\"founder\\\":[{\\\"@type\\\":\\\"Person\\\",\\\"name\\\":\\\"Pranay Yadav\\\",\\\"jobTitle\\\":\\\"CEO\\\",\\\"sameAs\\\":[\\\"https://www.wikidata.org/wiki/Q140158371\\\"]},{\\\"@type\\\":\\\"Person\\\",\\\"name\\\":\\\"Anchit Navelkar\\\",\\\"jobTitle\\\":\\\"CTO\\\",\\\"sameAs\\\":[\\\"https://www.wikidata.org/wiki/Q140158372\\\"]}],\\\"contactPoint\\\":[{\\\"@type\\\":\\\"ContactPoint\\\",\\\"contactType\\\":\\\"sales\\\",\\\"email\\\":\\\"hello@idenhq.com\\\",\\\"availableLanguage\\\":[\\\"en\\\",\\\"de\\\"]}]},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"SoftwareApplication\\\",\\\"name\\\":\\\"Iden\\\",\\\"applicationCategory\\\":\\\"BusinessApplication\\\",\\\"applicationSubCategory\\\":\\\"Identity Governance and Administration (IGA)\\\",\\\"operatingSystem\\\":\\\"Web\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\",\\\"description\\\":\\\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\\\",\\\"offers\\\":{\\\"@type\\\":\\\"Offer\\\",\\\"price\\\":\\\"7.50\\\",\\\"priceCurrency\\\":\\\"USD\\\",\\\"priceSpecification\\\":{\\\"@type\\\":\\\"UnitPriceSpecification\\\",\\\"price\\\":\\\"7.50\\\",\\\"priceCurrency\\\":\\\"USD\\\",\\\"unitText\\\":\\\"user/month\\\"}},\\\"featureList\\\":[\\\"User lifecycle management (Joiner-Mover-Leaver) for employees and contractors\\\",\\\"Fine-grained access provisioning across SCIM and non-SCIM apps\\\",\\\"Clean, compliant offboarding with data backups and audit trail\\\",\\\"Access tickets automation\\\",\\\"JIT, time-bound access\\\",\\\"Automated user access reviews and access certifications for SOC 2, ISO 27001, GDPR, DPDP, CCPA, CMMC, and other frameworks\\\",\\\"Least privilege at scale\\\",\\\"Identity security posture management\\\",\\\"Human, non-human, and AI agentic identities in one platform\\\",\\\"AI agent identity governance\\\",\\\"Shadow IT and SaaS discovery\\\",\\\"SaaS management and cost optimization\\\",\\\"200+ non-SCIM app connectors\\\",\\\"Custom app connectors in 48 hours\\\"],\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\"}},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"WebSite\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\",\\\"inLanguage\\\":[\\\"en\\\",\\\"de\\\"],\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\"}}]\"])</script><script>self.__next_f.push([1,\"4:[\\\"$\\\",\\\"html\\\",null,{\\\"lang\\\":\\\"en\\\",\\\"className\\\":\\\"inter_c15e96cb-module__0bjUvq__variable antialiased\\\",\\\"suppressHydrationWarning\\\":true,\\\"children\\\":[\\\"$\\\",\\\"body\\\",null,{\\\"className\\\":\\\"overscroll-y-none\\\",\\\"children\\\":[[\\\"$\\\",\\\"script\\\",null,{\\\"type\\\":\\\"application/ld+json\\\",\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$17\\\"}}],\\\"$L18\\\"]}]}]\\n1a:T4f2,M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"])</script><script>self.__next_f.push([1,\"5:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"max-w-[620px] px-6 sm:px-0 mx-auto pt-3 pb-3 w-full relative\\\",\\\"children\\\":[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex items-center justify-between\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L19\\\",null,{\\\"href\\\":\\\"/\\\",\\\"aria-label\\\":\\\"Iden\\\",\\\"className\\\":\\\"flex items-center\\\",\\\"children\\\":[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 101 30\\\",\\\"fill\\\":\\\"none\\\",\\\"xmlns\\\":\\\"http://www.w3.org/2000/svg\\\",\\\"className\\\":\\\"h-4 w-auto block shrink-0\\\",\\\"style\\\":{\\\"fill\\\":\\\"#a3a3a3\\\"},\\\"children\\\":[[\\\"$\\\",\\\"path\\\",null,{\\\"fillRule\\\":\\\"evenodd\\\",\\\"clipRule\\\":\\\"evenodd\\\",\\\"d\\\":\\\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\\\"}],[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"$1a\\\"}]]}]}],[\\\"$\\\",\\\"$L1b\\\",null,{\\\"dark\\\":true,\\\"bookDemo\\\":true,\\\"fieldNotes\\\":true,\\\"playbooks\\\":true,\\\"demoUrl\\\":\\\"https://cal.com/team/iden/demo\\\",\\\"askAILabel\\\":\\\"Ask AI\\\",\\\"loginLabel\\\":\\\"Login\\\",\\\"demoCtaLabel\\\":\\\"Book demo\\\",\\\"showLanguageSwitcher\\\":false}]]}]}]\\n\"])</script><script>self.__next_f.push([1,\"12:[\\\"$\\\",\\\"$L1c\\\",null,{\\\"ref\\\":\\\"$undefined\\\",\\\"href\\\":\\\"/en/privacy-policy\\\",\\\"locale\\\":\\\"$undefined\\\",\\\"localeCookie\\\":{\\\"name\\\":\\\"NEXT_LOCALE\\\",\\\"sameSite\\\":\\\"lax\\\"},\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Privacy\\\"}]\\n13:[\\\"$\\\",\\\"$L1c\\\",null,{\\\"ref\\\":\\\"$undefined\\\",\\\"href\\\":\\\"/en/terms-of-service\\\",\\\"locale\\\":\\\"$undefined\\\",\\\"localeCookie\\\":\\\"$12:props:localeCookie\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Terms\\\"}]\\n14:[\\\"$\\\",\\\"$L1c\\\",null,{\\\"ref\\\":\\\"$undefined\\\",\\\"href\\\":\\\"/en/legal-notice\\\",\\\"locale\\\":\\\"$undefined\\\",\\\"localeCookie\\\":\\\"$12:props:localeCookie\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Legal Notice\\\"}]\\n\"])</script><script>self.__next_f.push([1,\"18:[\\\"$\\\",\\\"$L1d\\\",null,{\\\"formats\\\":\\\"$undefined\\\",\\\"locale\\\":\\\"en\\\",\\\"messages\\\":{\\\"nav\\\":{\\\"docs\\\":\\\"Docs\\\",\\\"trust\\\":\\\"Trust\\\",\\\"contact\\\":\\\"Contact\\\",\\\"askAI\\\":\\\"Ask AI\\\",\\\"login\\\":\\\"Login\\\",\\\"demoCta\\\":\\\"Book demo\\\"},\\\"hero\\\":{\\\"headlineLine1\\\":\\\"Identity governance for your entire stack.\\\",\\\"headlineLine2\\\":\\\"SCIM or not.\\\",\\\"body\\\":\\\"Iden automates the full identity lifecycle across all your apps – SaaS, internal or legacy. Purpose-built for IT teams who have outgrown spreadsheets but don't want the enterprise bloat.\\\",\\\"cta\\\":\\\"Try Iden for your stack\\\",\\\"watchDemo\\\":\\\"Watch 2-min demo\\\",\\\"statsConnectors\\\":\\\"180+ connectors\\\",\\\"statsRevoke\\\":\\\"30s to grant/revoke access\\\",\\\"statsLive\\\":\\\"go live in \\u003c1h\\\",\\\"statsTrial\\\":\\\"2-week trial\\\"},\\\"productFeatures\\\":{\\\"heading\\\":\\\"Why Iden?\\\",\\\"engineerCta\\\":\\\"Talk to our engineer\\\",\\\"noUpgrade\\\":\\\"Iden works even on standard plans. No upgrade required.\\\",\\\"scimTaxHeading\\\":\\\"\\u003cu\\u003eSCIM Tax\\u003c/u\\u003e: why your current tools stop at 20%\\\",\\\"scimTaxBody\\\":\\\"~70% of your stack locks SCIM behind enterprise plans, forcing an expensive upgrade just to automate provisioning.\\\",\\\"scimTaxRead\\\":\\\"Read: What is the SCIM Tax? -\\u003e\\\",\\\"scimTaxSource\\\":\\\"Source: SCIM Tax Index -\\u003e\\\",\\\"scimTable\\\":{\\\"appCol\\\":\\\"App\\\",\\\"standardCol\\\":\\\"Standard plan\\\",\\\"enterpriseCol\\\":\\\"Enterprise (for SCIM)\\\",\\\"multCol\\\":\\\"×\\\"},\\\"pillars\\\":{\\\"coverage\\\":{\\\"stat\\\":\\\"Coverage\\\",\\\"heading\\\":\\\"Every app. SCIM or not.\\\",\\\"body\\\":\\\"Other IGA tools stop at SCIM or require custom dev. Iden covers every app out of the box: SCIM, API or neither.\\\"},\\\"controls\\\":{\\\"stat\\\":\\\"Controls\\\",\\\"heading\\\":\\\"Fine-grained. Fully automated.\\\",\\\"body\\\":\\\"You need more than groups. Iden offers fine-grained access controls and workflows across your stack.\\\"},\\\"cost\\\":{\\\"stat\\\":\\\"Cost\\\",\\\"heading\\\":\\\"IGA that pays for itself.\\\",\\\"body\\\":\\\"No SCIM tax. No wasted SaaS licenses. No manual tickets. No hidden costs. Starts at $7.50/user/mo.\\\"}}},\\\"howItWorks\\\":{\\\"heading\\\":\\\"How it works\\\",\\\"demoCta\\\":\\\"Book a demo\\\",\\\"steps\\\":[{\\\"number\\\":\\\"01\\\",\\\"title\\\":\\\"Connect every app\\\",\\\"body\\\":\\\"180+ connectors out of the box. Connect your HRIS, SSO and every app in your stack: SCIM, API or neither. Custom connectors in 48h.\\\"},{\\\"number\\\":\\\"02\\\",\\\"title\\\":\\\"Define your policies once\\\",\\\"body\\\":\\\"Who gets what, when, and for how long. Set once, enforced across your apps. Birthright by role, time-bound JIT for everything else.\\\"},{\\\"number\\\":\\\"03\\\",\\\"title\\\":\\\"Everything runs itself\\\",\\\"body\\\":\\\"New hires get access by 8am. Clean, compliant offboarding with data backups. Auto-provisioned access tickets. Your entire stack governed.\\\"}]},\\\"comparison\\\":{\\\"heading\\\":\\\"Not SailPoint. Not a spreadsheet.\\\",\\\"tagline\\\":\\\"Coverage they didn't. Controls they won't. Cost they can't.\\\",\\\"table\\\":{\\\"featureCol\\\":\\\"Feature\\\",\\\"othersCol\\\":\\\"Others\\\",\\\"idenCol\\\":\\\"Iden\\\"},\\\"groups\\\":{\\\"Coverage\\\":\\\"Coverage\\\",\\\"Controls\\\":\\\"Controls\\\",\\\"Cost\\\":\\\"Cost\\\"},\\\"rows\\\":{\\\"Apps without SCIM/API\\\":\\\"Apps without SCIM/API\\\",\\\"Human + Non-human\\\":\\\"Human + Non-human\\\",\\\"Custom connectors in 48h\\\":\\\"Custom connectors in 48h\\\",\\\"Fine-grained permissions (SCIM++)\\\":\\\"Fine-grained permissions (SCIM++)\\\",\\\"Granular policies + workflows\\\":\\\"Granular policies + workflows\\\",\\\"Data backups/migrations\\\":\\\"Data backups/migrations\\\",\\\"No SCIM tax\\\":\\\"No SCIM tax\\\",\\\"Flat pricing\\\":\\\"Flat pricing\\\",\\\"SaaS spend optimization\\\":\\\"SaaS spend optimization\\\"},\\\"vsLumos\\\":\\\"Iden vs Lumos\\\",\\\"vsConductorOne\\\":\\\"Iden vs ConductorOne\\\",\\\"sailPointAlt\\\":\\\"SailPoint alternative\\\",\\\"soon\\\":\\\"soon\\\"},\\\"trustTestimonials\\\":{\\\"heading\\\":\\\"Built for teams like yours.\\\",\\\"tagline\\\":\\\"Used by teams where IT is a person and a department. Loved by all.\\\",\\\"quotes\\\":{\\\"kat\\\":\\\"Found \\u003cb\\u003e47 orphaned accounts\\u003c/b\\u003e we didn't know existed. We're only 120 people.\\\",\\\"ajeesh\\\":\\\"Finally, \\u003cb\\u003ehuman and machine identities in one dashboard\\u003c/b\\u003e, not three.\\\",\\\"shiv\\\":\\\"Access reviews with teeth that \\u003cb\\u003eemployees don't dread\\u003c/b\\u003e. Security, GRC, auditors – all happy.\\\",\\\"evan\\\":\\\"Without the SCIM tax, \\u003cb\\u003eIden pays for itself multiple times over\\u003c/b\\u003e.\\\"}},\\\"featureShowcase\\\":{\\\"heading\\\":\\\"Capabilities.\\\",\\\"features\\\":{\\\"onboarding\\\":{\\\"title\\\":\\\"Onboarding\\\",\\\"body\\\":\\\"Every app provisioned on day 1. Role-based, automated, zero tickets.\\\"},\\\"offboarding\\\":{\\\"title\\\":\\\"Offboarding\\\",\\\"body\\\":\\\"Every access revoked in 30s. No checklist. No gaps.\\\"},\\\"jit\\\":{\\\"title\\\":\\\"Time-based Access\\\",\\\"body\\\":\\\"JIT permissions that expire automatically. Right access, right window.\\\"},\\\"tickets\\\":{\\\"title\\\":\\\"Access Tickets\\\",\\\"body\\\":\\\"Self-serve tickets with automatic provisioning. Your ITSM or ours.\\\"},\\\"governance\\\":{\\\"title\\\":\\\"Real-time Governance\\\",\\\"body\\\":\\\"Detect and fix overprovisioned or unauthorized access across your stack.\\\"},\\\"reviews\\\":{\\\"title\\\":\\\"User Access Reviews\\\",\\\"body\\\":\\\"Multi-stage, automated access certifications with full audit trail.\\\"},\\\"shadow\\\":{\\\"title\\\":\\\"Shadow IT \\u0026 Risk\\\",\\\"body\\\":\\\"Monitor usage and access risks from apps outside your scope today.\\\"},\\\"finance\\\":{\\\"title\\\":\\\"Finance\\\",\\\"body\\\":\\\"Reclaim unused licenses. SaaS spend tied to actual access.\\\"},\\\"nhi\\\":{\\\"title\\\":\\\"NHI Management\\\",\\\"body\\\":\\\"Service accounts, OAuth grants, API keys, MCP/AI agents, all in one place.\\\"}},\\\"mockupUI\\\":{\\\"apps\\\":\\\"apps\\\",\\\"users\\\":\\\"users\\\",\\\"more\\\":\\\"more\\\",\\\"riskCol\\\":\\\"Risk\\\",\\\"riskCritical\\\":\\\"critical\\\",\\\"riskHigh\\\":\\\"high\\\",\\\"riskMedium\\\":\\\"medium\\\",\\\"riskLow\\\":\\\"low\\\",\\\"policyMatched\\\":\\\"policy matched\\\",\\\"onbScheduled\\\":\\\"onboarding scheduled\\\",\\\"offbScheduled\\\":\\\"offboarding scheduled\\\",\\\"onboarding\\\":\\\"Onboarding\\\",\\\"offboarding\\\":\\\"Offboarding\\\",\\\"onboardedIn\\\":\\\"Onboarded in\\\",\\\"offboardedIn\\\":\\\"Offboarded in\\\",\\\"removed\\\":\\\"removed\\\",\\\"deactivated\\\":\\\"deactivated\\\",\\\"migrated\\\":\\\"migrated\\\",\\\"revoked\\\":\\\"revoked\\\",\\\"provisioning\\\":\\\"Provisioning\\\",\\\"deprovisioning\\\":\\\"Deprovisioning\\\",\\\"fulfilledIn\\\":\\\"Fulfilled in\\\",\\\"approve\\\":\\\"Approve\\\",\\\"approved\\\":\\\"Approved\\\",\\\"deny\\\":\\\"Deny\\\",\\\"routedTo\\\":\\\"routed to\\\",\\\"govMinAgo\\\":\\\"1 min ago\\\",\\\"govAlerts\\\":\\\"alerts\\\",\\\"govScanning\\\":\\\"scanning...\\\",\\\"govOrphaned\\\":\\\"Orphaned accounts\\\",\\\"govSoD\\\":\\\"SoD violations\\\",\\\"govNewPrivileged\\\":\\\"New privileged accounts\\\",\\\"govZombie\\\":\\\"Zombie accounts\\\",\\\"govOverprovisioned\\\":\\\"Overprovisioned\\\",\\\"govNewExternal\\\":\\\"New external accounts\\\",\\\"reviewItems\\\":\\\"items\\\",\\\"reviewReviewers\\\":\\\"reviewers\\\",\\\"reviewStage1\\\":\\\"Stage 1 · Reporting Managers\\\",\\\"reviewStage2\\\":\\\"Stage 2 · App Owners\\\",\\\"reviewFlagged\\\":\\\"flagged\\\",\\\"reviewFlaggedLabel\\\":\\\"Flagged:\\\",\\\"reviewRemediated\\\":\\\"Remediated:\\\",\\\"reviewRetained\\\":\\\"Retained:\\\",\\\"reviewAuditReady\\\":\\\"Audit evidence for SOC2 JFM 2026 UAR ready\\\",\\\"shadowUserCol\\\":\\\"User\\\",\\\"shadowLastSignup\\\":\\\"last signup\\\",\\\"shadowWatchlist\\\":\\\"Watchlist\\\",\\\"shadowBlock\\\":\\\"Block\\\",\\\"shadowManage\\\":\\\"Manage via Iden\\\",\\\"finAppBilling\\\":\\\"App Billing\\\",\\\"finPotentialSavings\\\":\\\"Potential Savings\\\",\\\"finTotalSpend\\\":\\\"Total Spend:\\\",\\\"finSavingsLabel\\\":\\\"Potential savings:\\\",\\\"finMonthly\\\":\\\"Monthly\\\",\\\"finAnnual\\\":\\\"Annual\\\",\\\"finActive\\\":\\\"active\\\",\\\"nhiNonHuman\\\":\\\"Non-human identities\\\",\\\"nhiOverdue\\\":\\\"overdue\\\",\\\"nhiName\\\":\\\"Name\\\",\\\"nhiOwner\\\":\\\"Owner\\\",\\\"nhiAge\\\":\\\"Age\\\"}},\\\"security\\\":{\\\"heading\\\":\\\"Security\\\",\\\"viewTrustCta\\\":\\\"View trust center\\\",\\\"body\\\":\\\"Iden is designed to meet rigorous security and compliance requirements. AES-256 at rest. TLS 1.3 in transit. Our connectors do not ask or store login credentials and are built security-first with bank-grade encryption. On-prem deployment available for full data sovereignty. Every action logged with a full audit trail, export-ready for any compliance review.\\\"},\\\"faq\\\":{\\\"heading\\\":\\\"Good questions.\\\",\\\"askCta\\\":\\\"Ask a question\\\",\\\"items\\\":[{\\\"question\\\":\\\"We already have Okta/Entra ID. Why do we need Iden?\\\",\\\"answer\\\":\\\"Okta and Entra handle auth and basic IGA for apps that support SCIM. Iden handles the rest of your stack. Nothing gets replaced.\\\"},{\\\"question\\\":\\\"What about apps not in our SSO on standard plans?\\\",\\\"answer\\\":\\\"That's the whole point. Iden supports standard plans too via our custom connectors. If we don't have one for your app yet, we'll ship it in 48h.\\\"},{\\\"question\\\":\\\"How long does this actually take?\\\",\\\"answer\\\":\\\"First 15 apps in under 1 hour. Most of your stack in a week or two.\\\"},{\\\"question\\\":\\\"What does it cost, really?\\\",\\\"answer\\\":\\\"Starts at $7.50/user/mo – volume discounts apply. All connectors included. No enterprise upgrades for your SaaS apps.\\\"},{\\\"question\\\":\\\"How do I know offboarding is actually complete?\\\",\\\"answer\\\":\\\"Every workflow and action is audit logged. Because Iden connects with all of your apps, our offboarding is clean, complete and compliant.\\\"},{\\\"question\\\":\\\"Can I try it before I commit?\\\",\\\"answer\\\":\\\"Yes. Two-week trial. Connect your stack, run a real offboarding. You'll know if it works before you commit anything.\\\"}]},\\\"about\\\":{\\\"heading\\\":\\\"Who are we?\\\",\\\"charterCta\\\":\\\"Read our charter\\\",\\\"body1\\\":\\\"We're second-time founders, investors and operators who've watched dozens of companies scale, their stacks outgrowing the tools meant to govern them. Iden is what we wish had existed.\\\",\\\"body2\\\":\\\"Quietly building what IGA should have always been from SF, BCN and BLR.\\\",\\\"body3\\\":\\\"Backed by \\u003clink\\u003eAccel\\u003c/link\\u003e.\\\"},\\\"closingCta\\\":{\\\"headline1\\\":\\\"You've been patching gaps for years.\\\",\\\"headline2\\\":\\\"You don't have to anymore.\\\",\\\"body\\\":\\\"Pick the apps you use. See how Iden handles them, including the ones not on the list yet.\\\",\\\"primaryCta\\\":\\\"Try Iden for your stack\\\",\\\"askAILabel\\\":\\\"Ask your AI\\\",\\\"emailLink\\\":\\\"Or email us -\\u003e\\\"},\\\"footer\\\":{\\\"copyright\\\":\\\"© 2026 IDENHQ, INC.\\\",\\\"backedBy\\\":\\\"Backed by\\\",\\\"links\\\":{\\\"charter\\\":\\\"Charter\\\",\\\"fieldNotes\\\":\\\"Field Notes\\\",\\\"versus\\\":\\\"Versus\\\",\\\"faq\\\":\\\"FAQ\\\",\\\"docs\\\":\\\"Docs\\\",\\\"trustCenter\\\":\\\"Trust\\\",\\\"privacy\\\":\\\"Privacy\\\",\\\"terms\\\":\\\"Terms\\\",\\\"impressum\\\":\\\"Legal Notice\\\"}},\\\"impressum\\\":{\\\"meta\\\":{\\\"title\\\":\\\"Legal Notice | Iden\\\",\\\"description\\\":\\\"Legal notice for IdenHQ Inc. — service provider information pursuant to Section 5 of the German Digital Services Act (DDG).\\\"},\\\"pageTitle\\\":\\\"Legal Notice\\\",\\\"legalCitation\\\":\\\"Information pursuant to Section 5 DDG\\\",\\\"lastUpdated\\\":\\\"Last updated: April 27, 2026\\\",\\\"sections\\\":{\\\"entity\\\":{\\\"heading\\\":\\\"Service Provider\\\",\\\"name\\\":\\\"IdenHQ Inc.\\\",\\\"type\\\":\\\"Corporation incorporated under the laws of the State of Delaware, USA\\\"},\\\"rep\\\":{\\\"heading\\\":\\\"Authorized Representative\\\",\\\"name\\\":\\\"Pranay Yadav\\\",\\\"role\\\":\\\"Chief Executive Officer\\\"},\\\"address\\\":{\\\"heading\\\":\\\"Registered Address\\\",\\\"street\\\":\\\"108 W 13th Street, Suite 100\\\",\\\"city\\\":\\\"Wilmington, Delaware 19801\\\",\\\"country\\\":\\\"United States of America\\\"},\\\"contact\\\":{\\\"heading\\\":\\\"Contact\\\",\\\"emailLabel\\\":\\\"E-mail\\\",\\\"email\\\":\\\"legal@idenhq.com\\\",\\\"phoneLabel\\\":\\\"Telephone\\\",\\\"phone\\\":\\\"+1 (650) 509-7775\\\"},\\\"registry\\\":{\\\"heading\\\":\\\"Company Registry\\\",\\\"authorityLabel\\\":\\\"Registry Authority\\\",\\\"authority\\\":\\\"Delaware Division of Corporations, State of Delaware, USA\\\",\\\"numberLabel\\\":\\\"Registration Number\\\",\\\"number\\\":\\\"File No. 3369197\\\"},\\\"vat\\\":{\\\"heading\\\":\\\"VAT Identification Number\\\",\\\"content\\\":\\\"No VAT identification number pursuant to § 27a of the German Value Added Tax Act (UStG) has been issued.\\\"},\\\"liability\\\":{\\\"heading\\\":\\\"Liability Disclaimer\\\",\\\"contentHeading\\\":\\\"Content\\\",\\\"contentText\\\":\\\"The contents of this website have been prepared with due care and diligence. However, IdenHQ Inc. makes no representations or warranties of any kind, express or implied, as to the accuracy, completeness, currency, or fitness for any particular purpose of the information contained herein. The information provided on this website is subject to change without notice and does not constitute legal, financial, or professional advice of any kind. IdenHQ Inc. expressly disclaims all liability for any loss or damage of any nature — whether direct, indirect, incidental, or consequential — arising from reliance on the content of this website. Liability claims arising from material or immaterial damage caused by the use or non-use of the information provided, or by the use of erroneous or incomplete information, are excluded to the extent that IdenHQ Inc. has not acted with willful intent or gross negligence.\\\",\\\"linksHeading\\\":\\\"External Links\\\",\\\"linksText\\\":\\\"This website contains hyperlinks to external third-party websites over which IdenHQ Inc. exercises no editorial control and for which IdenHQ Inc. assumes no responsibility. The respective provider or operator of each linked website is solely responsible for that website's content. The linked pages were reviewed by IdenHQ Inc. for potential legal violations at the time each link was established; no unlawful content was apparent at that time. Ongoing monitoring of all linked websites is neither feasible nor reasonable in the absence of specific evidence of a legal violation. Should IdenHQ Inc. become aware of any legal infringement on a linked website, the relevant link will be removed without undue delay. If you identify a potential infringement on any linked page, please contact us at the address set out in the Contact section above.\\\",\\\"copyrightHeading\\\":\\\"Copyright\\\",\\\"copyrightText\\\":\\\"The content, works, and materials published on this website — including but not limited to text, graphics, logos, images, and software — are the property of IdenHQ Inc. or its respective content suppliers and are protected by applicable United States and international copyright law. Any reproduction, adaptation, translation, distribution, transmission, display, or other commercial exploitation of such materials beyond the scope expressly permitted by applicable copyright law is strictly prohibited without the prior written consent of IdenHQ Inc. Permitted private, non-commercial use does not extend to systematic reproduction, redistribution, or the creation of derivative works. Where content on this website has not been created by IdenHQ Inc., the intellectual property rights of the respective third party apply and are respected accordingly.\\\"},\\\"dispute\\\":{\\\"heading\\\":\\\"Dispute Resolution\\\",\\\"intro\\\":\\\"IdenHQ Inc. is neither obligated nor willing to participate in dispute resolution proceedings before a consumer arbitration board.\\\",\\\"odrText\\\":\\\"The European Commission provides a platform for online dispute resolution (ODR) at\\\",\\\"odrUrl\\\":\\\"https://ec.europa.eu/consumers/odr/\\\",\\\"emailText\\\":\\\"Our designated contact address for matters relating to online dispute resolution is: legal@idenhq.com.\\\"}}},\\\"cookieLink\\\":\\\"Cookies\\\",\\\"cookieBanner\\\":{\\\"body1\\\":\\\"We use cookies for analytics\\\",\\\"body2\\\":\\\"and to improve your experience.\\\",\\\"acceptAll\\\":\\\"Accept all\\\",\\\"decline\\\":\\\"Decline\\\",\\\"manage\\\":\\\"Manage\\\",\\\"prefsTitle\\\":\\\"Cookie preferences\\\",\\\"save\\\":\\\"Save\\\",\\\"declineAll\\\":\\\"Decline all\\\",\\\"essential\\\":\\\"Essential\\\",\\\"essentialDesc\\\":\\\"Required for the site to function.\\\",\\\"analytics\\\":\\\"Analytics\\\",\\\"analyticsDesc\\\":\\\"Help us understand how visitors use the site.\\\",\\\"marketing\\\":\\\"Marketing\\\",\\\"marketingDesc\\\":\\\"Deliver relevant ads and measure campaigns.\\\",\\\"privacyLabel\\\":\\\"Privacy Policy\\\",\\\"impressumLabel\\\":\\\"Legal Notice\\\"},\\\"askAI\\\":{\\\"label\\\":\\\"Ask your AI\\\",\\\"copied\\\":\\\"Copied - paste into Claude, ChatGPT or any AI\\\"},\\\"meta\\\":{\\\"title\\\":\\\"Iden | Identity Governance for IT Teams\\\",\\\"description\\\":\\\"Automates provisioning, offboarding, and access reviews across every app, SCIM or not. For IT teams of 50 to 2,000. $7.50/user/month.\\\"},\\\"roiCalculator\\\":{\\\"meta\\\":{\\\"title\\\":\\\"Identity Governance ROI Calculator | Iden\\\",\\\"description\\\":\\\"Calculate savings from replacing manual IGA tools with Iden. Factors in licensing, IT operations time, and SaaS overhead from the SCIM tax.\\\"},\\\"header\\\":{\\\"label\\\":\\\"ROI Calculator\\\",\\\"copyLink\\\":\\\"Copy link\\\",\\\"copied\\\":\\\"Copied\\\",\\\"export\\\":\\\"Export\\\"},\\\"leftPanel\\\":{\\\"headcount\\\":\\\"Headcount\\\",\\\"employeesUnit\\\":\\\"employees\\\",\\\"contractorsUnit\\\":\\\"contractors\\\",\\\"addContractors\\\":\\\"+ contractors\\\",\\\"removeContractors\\\":\\\"− contractors\\\",\\\"identityOps\\\":\\\"Identity Operations\\\",\\\"hiresUnit\\\":\\\"hires / mo\\\",\\\"departuresUnit\\\":\\\"departures / mo\\\",\\\"ticketsUnit\\\":\\\"manual access tickets / wk\\\",\\\"reviewDaysUnit\\\":\\\"UAR days / qtr\\\",\\\"scimTax\\\":\\\"SCIM Tax\\\",\\\"appsUnit\\\":\\\"apps to manage\\\",\\\"scimTaxLink\\\":\\\"See which apps gate SCIM at scimtax.org\\\",\\\"saasSpend\\\":\\\"SaaS Spend\\\",\\\"saasUnit\\\":\\\"/ mo\\\"},\\\"rightPanel\\\":{\\\"heading\\\":\\\"What you're paying for\\\",\\\"othersCol\\\":\\\"Others\\\",\\\"licensing\\\":\\\"Licensing\\\",\\\"igaTool\\\":\\\"IGA Tool\\\",\\\"empLicenses\\\":\\\"Employee licenses\\\",\\\"conLicenses\\\":\\\"Contractor licenses\\\",\\\"saas\\\":\\\"SaaS\\\",\\\"scimTax\\\":\\\"SCIM tax\\\",\\\"operations\\\":\\\"Operations\\\",\\\"itOverhead\\\":\\\"IT Overhead\\\",\\\"onboarding\\\":\\\"Onboarding\\\",\\\"offboarding\\\":\\\"Offboarding\\\",\\\"accessTickets\\\":\\\"Access tickets\\\",\\\"accessReviews\\\":\\\"Access reviews\\\",\\\"productivity\\\":\\\"Productivity\\\",\\\"newHireWait\\\":\\\"New hire wait\\\",\\\"ticketWait\\\":\\\"Ticket wait\\\",\\\"licenseWaste\\\":\\\"License waste\\\",\\\"totalYear\\\":\\\"Total / year\\\",\\\"netSavings\\\":\\\"Net savings / year\\\",\\\"itHrsReturned\\\":\\\"IT hrs returned / month\\\",\\\"hrsUnit\\\":\\\"hrs\\\",\\\"roi\\\":\\\"Return on Investment\\\",\\\"excluding\\\":\\\"Excluding\\\",\\\"tagRisk\\\":\\\"Reduced Risk Exposure\\\",\\\"tagPrivilege\\\":\\\"Least Privilege At Scale\\\",\\\"tagAudit\\\":\\\"No Audit Qualification\\\",\\\"tagExp\\\":\\\"Superior Employee Experience\\\",\\\"subOnboarding\\\":\\\"{hrs} hr → 0 per hire\\\",\\\"subOffboarding\\\":\\\"{hrs} hr → 0 per departure\\\",\\\"subTickets\\\":\\\"{mins} min → 0 per ticket\\\",\\\"subReviews\\\":\\\"{days} days/qtr → 0\\\",\\\"subNewHireWait\\\":\\\"{days, number} days/hire → 0\\\",\\\"subTicketWait\\\":\\\"{hrs} hr → 0 per ticket\\\",\\\"subLicenseWaste\\\":\\\"{waste}% → 0% of SaaS spend\\\",\\\"subScimApps\\\":\\\"{scimApps} apps × ~{covPct}% users × ${premium}/user\\\",\\\"subScimNoApps\\\":\\\"enter app count\\\",\\\"subEmpLicenses\\\":\\\"$${legacyIga} → ${idenPrice} /u/mo (vol discounted)\\\",\\\"subConLicenses\\\":\\\"$${legacyIga} → ${idenConPrice} /u/mo (half rate)\\\"},\\\"print\\\":{\\\"headerLabel\\\":\\\"ROI Calculator\\\",\\\"preparedFor\\\":\\\"Prepared for\\\",\\\"employees\\\":\\\"Employees\\\",\\\"contractors\\\":\\\"Contractors\\\",\\\"calibratedOn\\\":\\\"Calibrated on\\\",\\\"monthlySpend\\\":\\\"Monthly spend\\\",\\\"disclaimer\\\":\\\"Estimates based on industry benchmarks. Actual savings vary.\\\",\\\"generatedBy\\\":\\\"Generated by Iden · idenhq.com/roi-calculator\\\"}}},\\\"now\\\":\\\"$undefined\\\",\\\"timeZone\\\":\\\"UTC\\\",\\\"children\\\":[\\\"$L1e\\\",\\\"$L1f\\\",\\\"$L20\\\"]}]\\n\"])</script><script>self.__next_f.push([1,\"1e:[\\\"$\\\",\\\"$L21\\\",null,{\\\"isEU\\\":false,\\\"children\\\":[[\\\"$\\\",\\\"$L22\\\",null,{}],[\\\"$\\\",\\\"$L23\\\",null,{}],[\\\"$\\\",\\\"$L24\\\",null,{}],[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"$L25\\\",null,{\\\"isEU\\\":false}]]}]\\n1f:[\\\"$\\\",\\\"$L26\\\",null,{}]\\n20:[\\\"$\\\",\\\"$L27\\\",null,{}]\\nd:[[\\\"$\\\",\\\"meta\\\",\\\"0\\\",{\\\"charSet\\\":\\\"utf-8\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"1\\\",{\\\"name\\\":\\\"viewport\\\",\\\"content\\\":\\\"width=device-width, initial-scale=1\\\"}]]\\n\"])</script><script>self.__next_f.push([1,\"28:I[27707,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"IconMark\\\"]\\na:null\\n\"])</script><script>self.__next_f.push([1,\"f:[[\\\"$\\\",\\\"title\\\",\\\"0\\\",{\\\"children\\\":\\\"AI Agent Identity Management 2026: Standards \\u0026 Gaps | Iden Blog\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"1\\\",{\\\"name\\\":\\\"description\\\",\\\"content\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"2\\\",{\\\"name\\\":\\\"application-name\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"link\\\",\\\"3\\\",{\\\"rel\\\":\\\"author\\\",\\\"href\\\":\\\"https://www.idenhq.com\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"4\\\",{\\\"name\\\":\\\"author\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"link\\\",\\\"5\\\",{\\\"rel\\\":\\\"manifest\\\",\\\"href\\\":\\\"/manifest.webmanifest\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"6\\\",{\\\"name\\\":\\\"creator\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"7\\\",{\\\"name\\\":\\\"publisher\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"8\\\",{\\\"name\\\":\\\"robots\\\",\\\"content\\\":\\\"index, follow\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"9\\\",{\\\"name\\\":\\\"googlebot\\\",\\\"content\\\":\\\"index, follow, max-video-preview:-1, max-image-preview:large, max-snippet:-1\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"10\\\",{\\\"name\\\":\\\"category\\\",\\\"content\\\":\\\"technology\\\"}],[\\\"$\\\",\\\"link\\\",\\\"11\\\",{\\\"rel\\\":\\\"canonical\\\",\\\"href\\\":\\\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"12\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"de\\\",\\\"href\\\":\\\"https://www.idenhq.com/de/blog/ki-agenten-identity-management-2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"13\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"en\\\",\\\"href\\\":\\\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"14\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"x-default\\\",\\\"href\\\":\\\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"15\\\",{\\\"property\\\":\\\"og:title\\\",\\\"content\\\":\\\"AI Agent Identity Management 2026: Standards \\u0026 Gaps\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"16\\\",{\\\"property\\\":\\\"og:description\\\",\\\"content\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"17\\\",{\\\"property\\\":\\\"og:locale\\\",\\\"content\\\":\\\"en_US\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"18\\\",{\\\"property\\\":\\\"og:image\\\",\\\"content\\\":\\\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"19\\\",{\\\"property\\\":\\\"og:type\\\",\\\"content\\\":\\\"article\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"20\\\",{\\\"property\\\":\\\"article:published_time\\\",\\\"content\\\":\\\"2026-07-15T07:00:17.688+00:00\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"21\\\",{\\\"name\\\":\\\"twitter:card\\\",\\\"content\\\":\\\"summary_large_image\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"22\\\",{\\\"name\\\":\\\"twitter:title\\\",\\\"content\\\":\\\"AI Agent Identity Management 2026: Standards \\u0026 Gaps\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"23\\\",{\\\"name\\\":\\\"twitter:description\\\",\\\"content\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"24\\\",{\\\"name\\\":\\\"twitter:image\\\",\\\"content\\\":\\\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\\\"}],[\\\"$\\\",\\\"link\\\",\\\"25\\\",{\\\"rel\\\":\\\"icon\\\",\\\"href\\\":\\\"/favicon.ico?favicon.0i-q8a6zz7zw~.ico\\\",\\\"sizes\\\":\\\"48x48\\\",\\\"type\\\":\\\"image/x-icon\\\"}],[\\\"$\\\",\\\"link\\\",\\\"26\\\",{\\\"rel\\\":\\\"apple-touch-icon\\\",\\\"href\\\":\\\"/apple-icon.png?apple-icon.0v4oxdav-.ztw.png\\\",\\\"sizes\\\":\\\"180x180\\\",\\\"type\\\":\\\"image/png\\\"}],[\\\"$\\\",\\\"$L28\\\",\\\"27\\\",{}]]\\n\"])</script><script>self.__next_f.push([1,\"29:I[35546,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"BlogArticleHeader\\\"]\\n2a:T394c,\"])</script><script>self.__next_f.push([1,\"IMPORTANT: Do not answer yet. Read this context, then ask me what I want to know before giving any assessment.\\n\\n---\\n\\nI'm reading \\\"AI Agent Identity Management in 2026: Standards, Players, and the Governance Gap\\\" on Iden's blog. Iden is a modern identity governance platform for IT teams at companies with 50 to 2,000 employees. It automates provisioning, access reviews, and offboarding across every app in the stack, including the apps that don't support SCIM. Pricing starts at $7.50/user/month. Two-week trial. No professional services.\\n\\n## Article summary\\nMCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards landscape for AI agent identity is taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\n\\n## Article content\\n\\nThe numbers are no longer theoretical. {{fact}}More than 80% of Fortune 500 companies now run active AI agents built with low-code and no-code tools{{cite:1}}, and {{fact}}Gartner projects that up to 40% of enterprise applications will include integrated task-specific AI agents by the end of 2026, up from less than 5% today{{cite:2}}.{{/fact}}{{/fact}} Yet the security posture underneath that deployment wave is alarming: {{fact}}on average, only 47.1% of an organization's AI agents are actively monitored or secured{{cite:3}}.{{/fact}} The other half operate without oversight, logging, or identity controls.\\n\\nThis is not a future problem. It is the current state of your production environment.\\n\\nThe good news - if you can call it that - is that the standards community has noticed. In the first half of 2026, more governance specifications landed for AI agent identity than in the entire prior history of the field. This post maps what those standards actually say, which vendor categories are responding, where the real gaps remain, and what a buyer should demand today.\\n\\n---\\n\\n## The Standards Landscape: What's Actually Shipping\\n\\n### MCP OAuth 2.1 Under Linux Foundation Governance\\n\\nThe Model Context Protocol started as an Anthropic experiment in November 2024. {{fact}}By December 2025, Anthropic had donated MCP to the Agentic AI Foundation (AAIF) under the Linux Foundation, with OpenAI, Block, AWS, Google, Microsoft, Cloudflare, and Bloomberg joining as founding or platinum members{{cite:4}}.{{/fact}} {{fact}}Within four months, the AAIF grew to 170 member organizations - more than double the membership CNCF had at the same stage of its life{{cite:5}}.{{/fact}}\\n\\nThe governance shift matters for enterprise buyers. MCP is no longer a single-vendor protocol that any one company can deprecate or fork. It is now closer in structure to CNCF than to a proprietary API.\\n\\nOn authentication specifically: {{fact}}the MCP spec mandates OAuth 2.1 with PKCE for all protected HTTP-based deployments, requiring HTTPS on all endpoints and discoverable authorization server metadata{{cite:6}}.{{/fact}} The 2026 roadmap, published in March, makes enterprise readiness - including audit trails, SSO-integrated auth, and configuration portability - a top priority. The spec's authorization Working Group had six dedicated sessions at the April 2026 MCP Dev Summit, with the OAuth 2.1 spec author present.\\n\\n{{fact}}The 2026 MCP roadmap flagged audit trail infrastructure, SSO-integrated auth, and configuration portability as the top enterprise requests{{cite:7}}.{{/fact}} None of those are solved yet. The roadmap is a commitment, not a delivery.\\n\\n{{component:e30cc0b7-1878-4e09-b948-931b4ea6d29d}}\\n\\n### MCP-I / KYA-OS: Decentralized Identity for Agents\\n\\nOAuth 2.1 handles *authentication* - proving an agent is who it claims to be. It does not answer the harder questions: Who authorized this agent? What is it allowed to do on behalf of which human? Can a downstream service verify that chain without prior coordination?\\n\\n{{fact}}In March 2026, Vouched formally donated the Model Context Protocol - Identity (MCP-I) framework to the Decentralized Identity Foundation (DIF), where it is now stewarded by the DIF Trusted AI Agents Working Group{{cite:8}}.{{/fact}} The spec has since been renamed KYA-OS (Know Your Agent Operating System) to reflect its scope beyond MCP alone.\\n\\n{{fact}}MCP-I / KYA-OS uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to enable cryptographically secure verification of both agents and their human principals - without requiring prior coordination between parties{{cite:9}}.{{/fact}} The framework defines four identity questions every service should be able to answer: Who is the agent? Who authorized it? What is it allowed to do? What is the scope of that delegation?\\n\\nThis is the right architecture for multi-organization agent workflows - a travel booking agent acting on behalf of a user across airline, hotel, and payment systems, for example. It is also early. The spec is in active community development, and production implementations are sparse.\\n\\n### Microsoft Entra Agent ID\\n\\nMicrosoft moved fastest among the major identity platforms. {{fact}}Microsoft Entra Agent ID introduces agent identities as a distinct, purpose-built construct - not a repurposed service principal or user account - with agent identity blueprints serving as templates for creating individual agent identities with parent-child relationships{{cite:10}}.{{/fact}}\\n\\n{{fact}}Agent identities in Entra do not have credentials of their own; they rely on the agent identity blueprint to acquire tokens on their behalf, and they only authenticate using federated identity credentials{{cite:11}}.{{/fact}} This is the right model: credentials live in the blueprint, not on the agent, so a compromised agent cannot exfiltrate its own keys.\\n\\n{{fact}}Microsoft Agent 365, generally available from May 1, 2026, gives each AI agent its own Entra Agent ID for identity, lifecycle, and access management, and integrates with Conditional Access, identity protection, and Microsoft Purview{{cite:12}}.{{/fact}} Third-party agents from AWS Bedrock, n8n, and other frameworks can be onboarded via workload identity federation - no platform-specific credential management required.\\n\\nThe honest limitation: Entra Agent ID is a strong solution if your agent estate lives inside the Microsoft ecosystem. For organizations running heterogeneous stacks - Anthropic, AWS, open-source frameworks, and custom-built agents - the governance surface extends well beyond what any single IdP can cover.\\n\\n### CSA Agentic Trust Framework and CSAI Foundation\\n\\nThe Cloud Security Alliance has been the most prolific standards producer in this space. {{fact}}The CSA published the Agentic Trust Framework (ATF) on February 2, 2026 - the first governance specification applying Zero Trust principles to autonomous AI agents with a structured maturity model{{cite:13}}.{{/fact}} The ATF was co-authored by John Kindervag, the original creator of Zero Trust.\\n\\nA companion survey of 285 IT and security professionals makes the urgency concrete: {{fact}}84% of organizations cannot pass a compliance audit focused on agent behavior or access controls, and only 23% have a formal agent identity strategy{{cite:14}}.{{/fact}}\\n\\nThe CSA's MAESTRO threat modeling framework explicitly names **agent impersonation** as a distinct threat class - malicious actors deceiving users or other agents by impersonating legitimate AI agents. The prescribed mitigations are trusted agent registries, cryptographic agent identities, and short-lived OAuth/OIDC tokens scoped to the intersection of what the agent is allowed to do AND what the delegating user is allowed to do. An AND gate, not an OR gate.\\n\\n{{fact}}In March 2026, the CSA launched the CSAI Foundation at RSAC 2026, a new 501(c)3 dedicated exclusively to AI security, with a 2026 mission of \\\"Securing the Agentic Control Plane\\\" - governing identity, authorization, orchestration, runtime behavior, and trust assurance for autonomous AI agent ecosystems{{cite:15}}.{{/fact}}\\n\\n---\\n\\n## The Player Map: Four Categories, Different Strengths\\n\\nThe vendor landscape has fragmented into four distinct categories. Understanding what each does - and doesn't do - is essential before buying.\\n\\n{{component:f0d62597-013b-4953-b03d-747adcaf9cba}}\\n\\nA few notes on the landscape:\\n\\n**Identity providers** are moving fast. {{fact}}Auth0's \\\"Auth for MCP\\\" became generally available on May 6, 2026, and Okta released its own MCP server as a secure protocol abstraction layer enabling AI agents to interact with Okta's scoped management APIs with least-privilege access control enforced at each tool call{{cite:2}}.{{/fact}} These are authentication solutions. They do not govern the full identity lifecycle.\\n\\n**NHI specialists** have the discovery story right. {{fact}}Veza's 2026 State of Identity and Access report found that a mere 0.01% of non-human identities control 80% of cloud resources, while the average worker holds 96,000 entitlements{{cite:16}}.{{/fact}} Knowing that is valuable. Governing it requires more than a posture dashboard.\\n\\n**MCP gateways** solve the runtime enforcement problem elegantly for agents you build inside their ecosystem. The problem is coverage: {{fact}}only 23.7% of organizations use their existing IAM/IdP as an authorization server for their agentic MCP infrastructure{{cite:3}}.{{/fact}} The rest are running disconnected auth stacks.\\n\\n**IGA platforms** are the natural home for agent governance - if they've actually built it. {{fact}}SailPoint expanded Agent Identity Security connectors in 2026 to include SaaS versions of Salesforce, ServiceNow, and Snowflake, but governance of agent identities requires a separate Agent Identity Security license{{cite:17}}.{{/fact}} Legacy IGA vendors are adding agent support as a module. That's not the same as designing for it from the start.\\n\\n---\\n\\n## The Honest Gaps\\n\\nStandards are immature. The MCP OAuth 2.1 profile is solid for authentication but has no standardized audit trail format. MCP-I / KYA-OS is in active community development with sparse production implementations. The CSA ATF is a governance framework, not an enforcement tool.\\n\\nThe monitoring gap is severe. {{fact}}Only 14.4% of organizations have achieved full IT and security approval for their entire agent fleet, and 88% of organizations reported confirmed or suspected AI agent security incidents in the past year{{cite:18}}.{{/fact}} {{fact}}Only 21.9% of organizations currently treat AI agents as independent, identity-bearing entities within their security model{{cite:3}}.{{/fact}} Most still treat agents as extensions of human users or generic service accounts.\\n\\nThe over-permissioning problem is structural. {{fact}}70% of security leaders say AI systems have more access than a human in the same role, and 67% of organizations rely on static credentials for AI systems{{cite:19}}.{{/fact}} Static, long-lived credentials are the opposite of what every framework recommends. They persist after an agent's task is complete, survive offboarding, and create the same orphaned-account problem that has plagued human identity governance for decades - just at machine speed.\\n\\n{{fact}}The CSA-Oasis State of NHI and AI Security 2026 found that 51% of organizations cite over-permissioned access as a top NHI pain point, and 78% have no documented policy for creating or removing AI identities{{cite:20}}.{{/fact}}\\n\\n{{component:3a13a849-8155-45c7-8c5c-27430a712e8c}}\\n\\n---\\n\\n## What IGA Looks Like When It's Built for This\\n\\nThe governance problem for AI agents is structurally identical to the governance problem for human identities - and for the same reason that IGA exists: access sprawl, orphaned accounts, over-permissioning, and the inability to answer \\\"who has access to what, and should they?\\\" at any given moment.\\n\\nThe difference is velocity and scale. {{fact}}NHIs outnumber human identities 17 to 1 in the average enterprise, and the NHI population grew 44% year-over-year between 2024 and 2025{{cite:21}}.{{/fact}} AI agents are the fastest-growing segment within that already-exploding category. Quarterly access reviews cannot keep pace. Neither can spreadsheets.\\n\\nWhat's needed is a single governance plane that treats human and non-human identities with the same policy engine, the same lifecycle automation, and the same access review workflows - without requiring a separate module, a separate license, or a separate team.\\n\\nThat's the design principle behind Iden. Rather than bolting agent governance onto a human-centric IGA platform, or treating agents as a subset of NHI discovery, Iden governs all identity types - employees, contractors, service accounts, bots, and AI agents - through the same policy-driven lifecycle engine. Fine-grained control at the channel, repository, and project level means an agent gets exactly the access its task requires, and that access is revoked when the task is done. No standing permissions. No orphaned agent accounts.\\n\\nFor organizations evaluating where AI agent governance fits in their stack, the [12 Best IGA Vendors in 2026](/blog/12-best-iga-vendors-2026) post maps the full landscape, and our [NHI explosion piece](/blog/nhi-explosion-non-human-identity) covers the scale of the underlying problem in detail.\\n\\n{{component:a30e26b9-c278-4c10-b474-e6bceaaaa120}}\\n\\n---\\n\\n## How to Evaluate Agent Identity Capabilities Today\\n\\nThe standards are immature, the vendor claims are ahead of the implementations, and the threat is real. Here is a practical evaluation framework for buyers.\\n\\n{{component:1d887c11-0b30-41a3-afdc-9d89b2f6ccfd}}\\n\\n---\\n\\n## The Bottom Line\\n\\nThe 2026 standards landscape for AI agent identity is real and moving fast - MCP OAuth 2.1 under Linux Foundation governance, MCP-I / KYA-OS at the DIF, Microsoft Entra Agent ID in GA, and the CSA Agentic Trust Framework providing the governance vocabulary. These are genuine milestones.\\n\\nBut standards are not implementations. {{fact}}Only 3% of organizations have automated, machine-speed controls governing AI behavior{{cite:19}}.{{/fact}} The gap between what the frameworks prescribe and what organizations have actually deployed is enormous.\\n\\nThe organizations that close that gap fastest will be the ones that stop treating agent governance as a separate problem from identity governance. Agents are identities. They need the same lifecycle controls, the same access reviews, the same deprovisioning workflows, and the same audit trails as every other identity in your environment - just with shorter-lived credentials and faster policy enforcement.\\n\\nThat's not a new category of tooling. It's IGA, built for the full population of identities your enterprise actually runs.\\n\\n{{component:e5afe1d7-cb52-4acd-8a56-b6970002b90b}}\\n\\n\\n## What I want\\n[Ask your question here.]\"])</script><script>self.__next_f.push([1,\"7:[\\\"$\\\",\\\"article\\\",null,{\\\"className\\\":\\\"blog-article\\\",\\\"lang\\\":\\\"en\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mx-auto max-w-[620px] px-6 sm:px-0\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex items-center justify-between pt-12 sm:pt-16\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L19\\\",null,{\\\"href\\\":\\\"/en/blog\\\",\\\"className\\\":\\\"inline-flex items-center gap-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:text-white\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 16 16\\\",\\\"className\\\":\\\"h-3.5 w-3.5\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"1.5\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"strokeLinecap\\\":\\\"round\\\",\\\"strokeLinejoin\\\":\\\"round\\\",\\\"d\\\":\\\"M10 3L5 8l5 5\\\"}]}],\\\"Blog\\\"]}],[\\\"$\\\",\\\"$L19\\\",null,{\\\"href\\\":\\\"/de/blog/ki-agenten-identity-management-2026\\\",\\\"hrefLang\\\":\\\"de\\\",\\\"className\\\":\\\"rounded-full border border-[var(--blog-border)] px-3 py-1 text-xs text-[var(--blog-muted)] transition-colors hover:border-[var(--blog-accent)] hover:text-[var(--blog-accent)]\\\",\\\"children\\\":\\\"Auf Deutsch lesen\\\"}]]}],[\\\"$\\\",\\\"$L29\\\",null,{\\\"title\\\":\\\"AI Agent Identity Management in 2026: Standards, Players, and the Governance Gap\\\",\\\"description\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards landscape for AI agent identity is taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\",\\\"readingTime\\\":10,\\\"updated\\\":\\\"2026-07-15T07:00:17.688+00:00\\\",\\\"aiContext\\\":\\\"$2a\\\",\\\"lang\\\":\\\"en-US\\\"}]]}],\\\"$L2b\\\",\\\"$L2c\\\"]}]\\n\"])</script><script>self.__next_f.push([1,\"2d:I[91729,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"ArticleBody\\\"]\\n2e:T3613,\"])</script><script>self.__next_f.push([1,\"The numbers are no longer theoretical. {{fact}}More than 80% of Fortune 500 companies now run active AI agents built with low-code and no-code tools{{cite:1}}, and {{fact}}Gartner projects that up to 40% of enterprise applications will include integrated task-specific AI agents by the end of 2026, up from less than 5% today{{cite:2}}.{{/fact}}{{/fact}} Yet the security posture underneath that deployment wave is alarming: {{fact}}on average, only 47.1% of an organization's AI agents are actively monitored or secured{{cite:3}}.{{/fact}} The other half operate without oversight, logging, or identity controls.\\n\\nThis is not a future problem. It is the current state of your production environment.\\n\\nThe good news - if you can call it that - is that the standards community has noticed. In the first half of 2026, more governance specifications landed for AI agent identity than in the entire prior history of the field. This post maps what those standards actually say, which vendor categories are responding, where the real gaps remain, and what a buyer should demand today.\\n\\n---\\n\\n## The Standards Landscape: What's Actually Shipping\\n\\n### MCP OAuth 2.1 Under Linux Foundation Governance\\n\\nThe Model Context Protocol started as an Anthropic experiment in November 2024. {{fact}}By December 2025, Anthropic had donated MCP to the Agentic AI Foundation (AAIF) under the Linux Foundation, with OpenAI, Block, AWS, Google, Microsoft, Cloudflare, and Bloomberg joining as founding or platinum members{{cite:4}}.{{/fact}} {{fact}}Within four months, the AAIF grew to 170 member organizations - more than double the membership CNCF had at the same stage of its life{{cite:5}}.{{/fact}}\\n\\nThe governance shift matters for enterprise buyers. MCP is no longer a single-vendor protocol that any one company can deprecate or fork. It is now closer in structure to CNCF than to a proprietary API.\\n\\nOn authentication specifically: {{fact}}the MCP spec mandates OAuth 2.1 with PKCE for all protected HTTP-based deployments, requiring HTTPS on all endpoints and discoverable authorization server metadata{{cite:6}}.{{/fact}} The 2026 roadmap, published in March, makes enterprise readiness - including audit trails, SSO-integrated auth, and configuration portability - a top priority. The spec's authorization Working Group had six dedicated sessions at the April 2026 MCP Dev Summit, with the OAuth 2.1 spec author present.\\n\\n{{fact}}The 2026 MCP roadmap flagged audit trail infrastructure, SSO-integrated auth, and configuration portability as the top enterprise requests{{cite:7}}.{{/fact}} None of those are solved yet. The roadmap is a commitment, not a delivery.\\n\\n{{component:e30cc0b7-1878-4e09-b948-931b4ea6d29d}}\\n\\n### MCP-I / KYA-OS: Decentralized Identity for Agents\\n\\nOAuth 2.1 handles *authentication* - proving an agent is who it claims to be. It does not answer the harder questions: Who authorized this agent? What is it allowed to do on behalf of which human? Can a downstream service verify that chain without prior coordination?\\n\\n{{fact}}In March 2026, Vouched formally donated the Model Context Protocol - Identity (MCP-I) framework to the Decentralized Identity Foundation (DIF), where it is now stewarded by the DIF Trusted AI Agents Working Group{{cite:8}}.{{/fact}} The spec has since been renamed KYA-OS (Know Your Agent Operating System) to reflect its scope beyond MCP alone.\\n\\n{{fact}}MCP-I / KYA-OS uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to enable cryptographically secure verification of both agents and their human principals - without requiring prior coordination between parties{{cite:9}}.{{/fact}} The framework defines four identity questions every service should be able to answer: Who is the agent? Who authorized it? What is it allowed to do? What is the scope of that delegation?\\n\\nThis is the right architecture for multi-organization agent workflows - a travel booking agent acting on behalf of a user across airline, hotel, and payment systems, for example. It is also early. The spec is in active community development, and production implementations are sparse.\\n\\n### Microsoft Entra Agent ID\\n\\nMicrosoft moved fastest among the major identity platforms. {{fact}}Microsoft Entra Agent ID introduces agent identities as a distinct, purpose-built construct - not a repurposed service principal or user account - with agent identity blueprints serving as templates for creating individual agent identities with parent-child relationships{{cite:10}}.{{/fact}}\\n\\n{{fact}}Agent identities in Entra do not have credentials of their own; they rely on the agent identity blueprint to acquire tokens on their behalf, and they only authenticate using federated identity credentials{{cite:11}}.{{/fact}} This is the right model: credentials live in the blueprint, not on the agent, so a compromised agent cannot exfiltrate its own keys.\\n\\n{{fact}}Microsoft Agent 365, generally available from May 1, 2026, gives each AI agent its own Entra Agent ID for identity, lifecycle, and access management, and integrates with Conditional Access, identity protection, and Microsoft Purview{{cite:12}}.{{/fact}} Third-party agents from AWS Bedrock, n8n, and other frameworks can be onboarded via workload identity federation - no platform-specific credential management required.\\n\\nThe honest limitation: Entra Agent ID is a strong solution if your agent estate lives inside the Microsoft ecosystem. For organizations running heterogeneous stacks - Anthropic, AWS, open-source frameworks, and custom-built agents - the governance surface extends well beyond what any single IdP can cover.\\n\\n### CSA Agentic Trust Framework and CSAI Foundation\\n\\nThe Cloud Security Alliance has been the most prolific standards producer in this space. {{fact}}The CSA published the Agentic Trust Framework (ATF) on February 2, 2026 - the first governance specification applying Zero Trust principles to autonomous AI agents with a structured maturity model{{cite:13}}.{{/fact}} The ATF was co-authored by John Kindervag, the original creator of Zero Trust.\\n\\nA companion survey of 285 IT and security professionals makes the urgency concrete: {{fact}}84% of organizations cannot pass a compliance audit focused on agent behavior or access controls, and only 23% have a formal agent identity strategy{{cite:14}}.{{/fact}}\\n\\nThe CSA's MAESTRO threat modeling framework explicitly names **agent impersonation** as a distinct threat class - malicious actors deceiving users or other agents by impersonating legitimate AI agents. The prescribed mitigations are trusted agent registries, cryptographic agent identities, and short-lived OAuth/OIDC tokens scoped to the intersection of what the agent is allowed to do AND what the delegating user is allowed to do. An AND gate, not an OR gate.\\n\\n{{fact}}In March 2026, the CSA launched the CSAI Foundation at RSAC 2026, a new 501(c)3 dedicated exclusively to AI security, with a 2026 mission of \\\"Securing the Agentic Control Plane\\\" - governing identity, authorization, orchestration, runtime behavior, and trust assurance for autonomous AI agent ecosystems{{cite:15}}.{{/fact}}\\n\\n---\\n\\n## The Player Map: Four Categories, Different Strengths\\n\\nThe vendor landscape has fragmented into four distinct categories. Understanding what each does - and doesn't do - is essential before buying.\\n\\n{{component:f0d62597-013b-4953-b03d-747adcaf9cba}}\\n\\nA few notes on the landscape:\\n\\n**Identity providers** are moving fast. {{fact}}Auth0's \\\"Auth for MCP\\\" became generally available on May 6, 2026, and Okta released its own MCP server as a secure protocol abstraction layer enabling AI agents to interact with Okta's scoped management APIs with least-privilege access control enforced at each tool call{{cite:2}}.{{/fact}} These are authentication solutions. They do not govern the full identity lifecycle.\\n\\n**NHI specialists** have the discovery story right. {{fact}}Veza's 2026 State of Identity and Access report found that a mere 0.01% of non-human identities control 80% of cloud resources, while the average worker holds 96,000 entitlements{{cite:16}}.{{/fact}} Knowing that is valuable. Governing it requires more than a posture dashboard.\\n\\n**MCP gateways** solve the runtime enforcement problem elegantly for agents you build inside their ecosystem. The problem is coverage: {{fact}}only 23.7% of organizations use their existing IAM/IdP as an authorization server for their agentic MCP infrastructure{{cite:3}}.{{/fact}} The rest are running disconnected auth stacks.\\n\\n**IGA platforms** are the natural home for agent governance - if they've actually built it. {{fact}}SailPoint expanded Agent Identity Security connectors in 2026 to include SaaS versions of Salesforce, ServiceNow, and Snowflake, but governance of agent identities requires a separate Agent Identity Security license{{cite:17}}.{{/fact}} Legacy IGA vendors are adding agent support as a module. That's not the same as designing for it from the start.\\n\\n---\\n\\n## The Honest Gaps\\n\\nStandards are immature. The MCP OAuth 2.1 profile is solid for authentication but has no standardized audit trail format. MCP-I / KYA-OS is in active community development with sparse production implementations. The CSA ATF is a governance framework, not an enforcement tool.\\n\\nThe monitoring gap is severe. {{fact}}Only 14.4% of organizations have achieved full IT and security approval for their entire agent fleet, and 88% of organizations reported confirmed or suspected AI agent security incidents in the past year{{cite:18}}.{{/fact}} {{fact}}Only 21.9% of organizations currently treat AI agents as independent, identity-bearing entities within their security model{{cite:3}}.{{/fact}} Most still treat agents as extensions of human users or generic service accounts.\\n\\nThe over-permissioning problem is structural. {{fact}}70% of security leaders say AI systems have more access than a human in the same role, and 67% of organizations rely on static credentials for AI systems{{cite:19}}.{{/fact}} Static, long-lived credentials are the opposite of what every framework recommends. They persist after an agent's task is complete, survive offboarding, and create the same orphaned-account problem that has plagued human identity governance for decades - just at machine speed.\\n\\n{{fact}}The CSA-Oasis State of NHI and AI Security 2026 found that 51% of organizations cite over-permissioned access as a top NHI pain point, and 78% have no documented policy for creating or removing AI identities{{cite:20}}.{{/fact}}\\n\\n{{component:3a13a849-8155-45c7-8c5c-27430a712e8c}}\\n\\n---\\n\\n## What IGA Looks Like When It's Built for This\\n\\nThe governance problem for AI agents is structurally identical to the governance problem for human identities - and for the same reason that IGA exists: access sprawl, orphaned accounts, over-permissioning, and the inability to answer \\\"who has access to what, and should they?\\\" at any given moment.\\n\\nThe difference is velocity and scale. {{fact}}NHIs outnumber human identities 17 to 1 in the average enterprise, and the NHI population grew 44% year-over-year between 2024 and 2025{{cite:21}}.{{/fact}} AI agents are the fastest-growing segment within that already-exploding category. Quarterly access reviews cannot keep pace. Neither can spreadsheets.\\n\\nWhat's needed is a single governance plane that treats human and non-human identities with the same policy engine, the same lifecycle automation, and the same access review workflows - without requiring a separate module, a separate license, or a separate team.\\n\\nThat's the design principle behind Iden. Rather than bolting agent governance onto a human-centric IGA platform, or treating agents as a subset of NHI discovery, Iden governs all identity types - employees, contractors, service accounts, bots, and AI agents - through the same policy-driven lifecycle engine. Fine-grained control at the channel, repository, and project level means an agent gets exactly the access its task requires, and that access is revoked when the task is done. No standing permissions. No orphaned agent accounts.\\n\\nFor organizations evaluating where AI agent governance fits in their stack, the [12 Best IGA Vendors in 2026](/blog/12-best-iga-vendors-2026) post maps the full landscape, and our [NHI explosion piece](/blog/nhi-explosion-non-human-identity) covers the scale of the underlying problem in detail.\\n\\n{{component:a30e26b9-c278-4c10-b474-e6bceaaaa120}}\\n\\n---\\n\\n## How to Evaluate Agent Identity Capabilities Today\\n\\nThe standards are immature, the vendor claims are ahead of the implementations, and the threat is real. Here is a practical evaluation framework for buyers.\\n\\n{{component:1d887c11-0b30-41a3-afdc-9d89b2f6ccfd}}\\n\\n---\\n\\n## The Bottom Line\\n\\nThe 2026 standards landscape for AI agent identity is real and moving fast - MCP OAuth 2.1 under Linux Foundation governance, MCP-I / KYA-OS at the DIF, Microsoft Entra Agent ID in GA, and the CSA Agentic Trust Framework providing the governance vocabulary. These are genuine milestones.\\n\\nBut standards are not implementations. {{fact}}Only 3% of organizations have automated, machine-speed controls governing AI behavior{{cite:19}}.{{/fact}} The gap between what the frameworks prescribe and what organizations have actually deployed is enormous.\\n\\nThe organizations that close that gap fastest will be the ones that stop treating agent governance as a separate problem from identity governance. Agents are identities. They need the same lifecycle controls, the same access reviews, the same deprovisioning workflows, and the same audit trails as every other identity in your environment - just with shorter-lived credentials and faster policy enforcement.\\n\\nThat's not a new category of tooling. It's IGA, built for the full population of identities your enterprise actually runs.\\n\\n{{component:e5afe1d7-cb52-4acd-8a56-b6970002b90b}}\\n\"])</script><script>self.__next_f.push([1,\"2f:T43f,Build an interactive AI Agent Identity Governance Readiness Assessment. It should be a short quiz (6 questions) that helps a CISO or security engineer assess their organization's current maturity for governing AI agent identities. Questions should cover: 1) What percentage of your AI agents have unique, managed identities (vs shared credentials or API keys)? 2) Do you have a formal approval process before agents go to production? 3) How are agent credentials managed (static API keys / short-lived tokens / no formal process)? 4) Can you produce a per-tool-call audit trail for any agent on demand? 5) Are AI agent identities included in your regular access review cycles? 6) Do you have automated deprovisioning when an agent is retired? Each answer should be scored (0-2 points). At the end, display a maturity score out of 12 with a label (0-4: 'Shadow Agent Risk', 5-8: 'Emerging Governance', 9-12: 'Governed Agent Estate') and a 2-sentence recommendation for the next step. Style it cleanly with a progress bar and color-coded result. Use only HTML, CSS, and vanilla JavaScript.30:T6db0,\"])</script><script>self.__next_f.push([1,\"\\u003c!DOCTYPE html\\u003e\\n\\u003chtml lang=\\\"en\\\"\\u003e\\n\\u003chead\\u003e\\n  \\u003cmeta charset=\\\"UTF-8\\\" /\\u003e\\n  \\u003cmeta name=\\\"viewport\\\" content=\\\"width=device-width, initial-scale=1.0\\\" /\\u003e\\n  \\u003cmeta http-equiv=\\\"Content-Security-Policy\\\" content=\\\"default-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com https://cdn.jsdelivr.net; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; img-src https: data:;\\\"\\u003e\\n  \\u003ctitle\\u003eAI Agent Identity Governance Readiness Assessment\\u003c/title\\u003e\\n  \\u003clink href=\\\"https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700\\u0026display=swap\\\" rel=\\\"stylesheet\\\"\\u003e\\n  \\u003cstyle\\u003e\\n    *, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; }\\n\\n    html, body {\\n      overflow: hidden;\\n      margin: 0;\\n      padding: 0 0 24px 0;\\n      background: #ffffff;\\n      font-family: 'Inter', 'Alliance No.1', sans-serif;\\n      color: #000000;\\n    }\\n\\n    :root {\\n      --primary: #486BF0;\\n      --accent: #4669ED;\\n      --bg: #ffffff;\\n      --text: #000000;\\n      --text-muted: #555e78;\\n      --border: #dde3f5;\\n      --card-bg: #f5f7ff;\\n      --success: #10b981;\\n      --warn: #f59e0b;\\n      --danger: #ef4444;\\n      --radius: 12px;\\n      --radius-sm: 8px;\\n    }\\n\\n    .widget {\\n      max-width: 680px;\\n      margin: 0 auto;\\n      padding: 20px 16px 0;\\n    }\\n\\n    /* HEADER */\\n    .header {\\n      text-align: center;\\n      margin-bottom: 18px;\\n    }\\n    .header-badge {\\n      display: inline-flex;\\n      align-items: center;\\n      gap: 6px;\\n      background: #eef1fd;\\n      color: var(--primary);\\n      font-size: 11px;\\n      font-weight: 600;\\n      letter-spacing: .06em;\\n      text-transform: uppercase;\\n      padding: 4px 12px;\\n      border-radius: 20px;\\n      margin-bottom: 10px;\\n    }\\n    .header-badge svg { width: 13px; height: 13px; flex-shrink: 0; }\\n    .header h1 {\\n      font-size: clamp(17px, 3.5vw, 22px);\\n      font-weight: 700;\\n      color: var(--text);\\n      line-height: 1.25;\\n      margin-bottom: 5px;\\n    }\\n    .header p {\\n      font-size: clamp(12px, 2.5vw, 13.5px);\\n      color: var(--text-muted);\\n      line-height: 1.5;\\n    }\\n\\n    /* PROGRESS BAR */\\n    .progress-wrap {\\n      margin-bottom: 16px;\\n    }\\n    .progress-meta {\\n      display: flex;\\n      justify-content: space-between;\\n      align-items: center;\\n      margin-bottom: 6px;\\n    }\\n    .progress-label {\\n      font-size: 12px;\\n      font-weight: 600;\\n      color: var(--text-muted);\\n    }\\n    .progress-count {\\n      font-size: 12px;\\n      font-weight: 700;\\n      color: var(--primary);\\n    }\\n    .progress-track {\\n      height: 6px;\\n      background: #e8ecfd;\\n      border-radius: 99px;\\n      overflow: hidden;\\n    }\\n    .progress-fill {\\n      height: 100%;\\n      background: linear-gradient(90deg, var(--primary), var(--accent));\\n      border-radius: 99px;\\n      transition: width .4s cubic-bezier(.4,0,.2,1);\\n      width: 0%;\\n    }\\n\\n    /* QUIZ CARD */\\n    .quiz-card {\\n      background: var(--card-bg);\\n      border: 1.5px solid var(--border);\\n      border-radius: var(--radius);\\n      padding: 18px 18px 16px;\\n      position: relative;\\n      transition: opacity .3s;\\n    }\\n    .q-header {\\n      display: flex;\\n      align-items: flex-start;\\n      gap: 10px;\\n      margin-bottom: 14px;\\n    }\\n    .q-num {\\n      min-width: 28px;\\n      height: 28px;\\n      border-radius: 50%;\\n      background: var(--primary);\\n      color: #fff;\\n      font-size: 12px;\\n      font-weight: 700;\\n      display: flex;\\n      align-items: center;\\n      justify-content: center;\\n      flex-shrink: 0;\\n      margin-top: 1px;\\n    }\\n    .q-text {\\n      font-size: clamp(13px, 2.8vw, 14.5px);\\n      font-weight: 600;\\n      color: var(--text);\\n      line-height: 1.45;\\n    }\\n    .q-icon {\\n      font-size: 17px;\\n      margin-right: 2px;\\n      vertical-align: middle;\\n    }\\n\\n    /* OPTIONS */\\n    .options { display: flex; flex-direction: column; gap: 7px; }\\n    .option-btn {\\n      display: flex;\\n      align-items: flex-start;\\n      gap: 10px;\\n      background: #fff;\\n      border: 1.5px solid var(--border);\\n      border-radius: var(--radius-sm);\\n      padding: 10px 12px;\\n      cursor: pointer;\\n      text-align: left;\\n      transition: border-color .18s, background .18s, box-shadow .18s;\\n      font-family: inherit;\\n      width: 100%;\\n      position: relative;\\n    }\\n    .option-btn:hover {\\n      border-color: var(--primary);\\n      background: #f0f3fe;\\n      box-shadow: 0 2px 8px rgba(72,107,240,.08);\\n    }\\n    .option-btn.selected {\\n      border-color: var(--primary);\\n      background: #eef1fd;\\n      box-shadow: 0 0 0 2px rgba(72,107,240,.18);\\n    }\\n    .option-btn.selected .opt-radio { background: var(--primary); border-color: var(--primary); }\\n    .option-btn.selected .opt-radio::after { opacity: 1; }\\n    .opt-radio {\\n      width: 16px;\\n      height: 16px;\\n      border-radius: 50%;\\n      border: 2px solid #b0bbd9;\\n      flex-shrink: 0;\\n      margin-top: 2px;\\n      display: flex;\\n      align-items: center;\\n      justify-content: center;\\n      transition: background .18s, border-color .18s;\\n      position: relative;\\n    }\\n    .opt-radio::after {\\n      content: '';\\n      width: 7px;\\n      height: 7px;\\n      border-radius: 50%;\\n      background: #fff;\\n      opacity: 0;\\n      transition: opacity .18s;\\n    }\\n    .opt-content { flex: 1; }\\n    .opt-label {\\n      font-size: clamp(12px, 2.5vw, 13px);\\n      font-weight: 500;\\n      color: var(--text);\\n      line-height: 1.4;\\n      display: block;\\n    }\\n    .opt-score {\\n      font-size: 10.5px;\\n      color: var(--text-muted);\\n      margin-top: 2px;\\n    }\\n    .score-dot {\\n      display: inline-block;\\n      width: 7px; height: 7px;\\n      border-radius: 50%;\\n      margin-right: 3px;\\n      vertical-align: middle;\\n    }\\n    .score-0 { background: var(--danger); }\\n    .score-1 { background: var(--warn); }\\n    .score-2 { background: var(--success); }\\n\\n    /* NAV BUTTONS */\\n    .nav-row {\\n      display: flex;\\n      justify-content: space-between;\\n      align-items: center;\\n      margin-top: 14px;\\n      gap: 8px;\\n    }\\n    .btn {\\n      display: inline-flex;\\n      align-items: center;\\n      gap: 6px;\\n      padding: 9px 20px;\\n      border-radius: var(--radius-sm);\\n      font-family: inherit;\\n      font-size: 13px;\\n      font-weight: 600;\\n      cursor: pointer;\\n      border: none;\\n      transition: background .18s, opacity .18s, transform .12s;\\n      line-height: 1;\\n    }\\n    .btn:active { transform: scale(.97); }\\n    .btn-primary {\\n      background: var(--primary);\\n      color: #fff;\\n      box-shadow: 0 2px 10px rgba(72,107,240,.28);\\n    }\\n    .btn-primary:hover { background: var(--accent); }\\n    .btn-primary:disabled { opacity: .4; cursor: not-allowed; }\\n    .btn-ghost {\\n      background: transparent;\\n      color: var(--text-muted);\\n      border: 1.5px solid var(--border);\\n    }\\n    .btn-ghost:hover { border-color: #b0bbd9; color: var(--text); }\\n    .btn svg { width: 15px; height: 15px; }\\n\\n    /* RESULT PANEL */\\n    .result-panel { display: none; }\\n    .result-panel.visible { display: block; }\\n    .quiz-active.hidden { display: none; }\\n\\n    .result-card {\\n      border-radius: var(--radius);\\n      padding: 20px 18px 18px;\\n      border: 1.5px solid var(--border);\\n      margin-bottom: 12px;\\n      text-align: center;\\n    }\\n    .result-card.shadow-risk  { background: #fff5f5; border-color: #fca5a5; }\\n    .result-card.emerging     { background: #fffbeb; border-color: #fcd34d; }\\n    .result-card.governed     { background: #f0fdf4; border-color: #6ee7b7; }\\n\\n    .result-tier-badge {\\n      display: inline-flex;\\n      align-items: center;\\n      gap: 6px;\\n      padding: 5px 14px;\\n      border-radius: 20px;\\n      font-size: 11px;\\n      font-weight: 700;\\n      letter-spacing: .07em;\\n      text-transform: uppercase;\\n      margin-bottom: 10px;\\n    }\\n    .shadow-risk  .result-tier-badge { background: #fee2e2; color: #b91c1c; }\\n    .emerging     .result-tier-badge { background: #fef3c7; color: #92400e; }\\n    .governed     .result-tier-badge { background: #dcfce7; color: #166534; }\\n\\n    .result-score-wrap {\\n      display: flex;\\n      align-items: center;\\n      justify-content: center;\\n      gap: 4px;\\n      margin-bottom: 8px;\\n    }\\n    .result-score-num {\\n      font-size: clamp(36px, 8vw, 48px);\\n      font-weight: 800;\\n      line-height: 1;\\n    }\\n    .shadow-risk  .result-score-num { color: var(--danger); }\\n    .emerging     .result-score-num { color: #d97706; }\\n    .governed     .result-score-num { color: #059669; }\\n\\n    .result-score-denom {\\n      font-size: 18px;\\n      font-weight: 600;\\n      color: var(--text-muted);\\n      align-self: flex-end;\\n      margin-bottom: 6px;\\n    }\\n    .result-label {\\n      font-size: clamp(15px, 3.2vw, 18px);\\n      font-weight: 700;\\n      color: var(--text);\\n      margin-bottom: 6px;\\n    }\\n\\n    /* Score bar */\\n    .result-bar-track {\\n      height: 10px;\\n      background: #e5e7eb;\\n      border-radius: 99px;\\n      overflow: hidden;\\n      margin: 10px 0 14px;\\n    }\\n    .result-bar-fill {\\n      height: 100%;\\n      border-radius: 99px;\\n      transition: width 1s cubic-bezier(.4,0,.2,1);\\n      width: 0%;\\n    }\\n    .shadow-risk  .result-bar-fill { background: linear-gradient(90deg,#f87171,#ef4444); }\\n    .emerging     .result-bar-fill { background: linear-gradient(90deg,#fbbf24,#f59e0b); }\\n    .governed     .result-bar-fill { background: linear-gradient(90deg,#34d399,#059669); }\\n\\n    .result-rec {\\n      font-size: clamp(12px, 2.5vw, 13.5px);\\n      color: var(--text-muted);\\n      line-height: 1.6;\\n      text-align: left;\\n      background: rgba(255,255,255,.7);\\n      border-radius: var(--radius-sm);\\n      padding: 12px 14px;\\n      border: 1px solid rgba(0,0,0,.07);\\n      margin-top: 4px;\\n    }\\n    .result-rec strong { color: var(--text); }\\n\\n    /* BREAKDOWN */\\n    .breakdown-title {\\n      font-size: 12px;\\n      font-weight: 700;\\n      letter-spacing: .06em;\\n      text-transform: uppercase;\\n      color: var(--text-muted);\\n      margin-bottom: 8px;\\n    }\\n    .breakdown-grid {\\n      display: grid;\\n      grid-template-columns: 1fr 1fr;\\n      gap: 7px;\\n    }\\n    @media (max-width: 380px) { .breakdown-grid { grid-template-columns: 1fr; } }\\n    .breakdown-item {\\n      background: var(--card-bg);\\n      border: 1.5px solid var(--border);\\n      border-radius: var(--radius-sm);\\n      padding: 9px 11px;\\n      display: flex;\\n      align-items: center;\\n      gap: 8px;\\n    }\\n    .bi-icon { font-size: 18px; flex-shrink: 0; }\\n    .bi-info { flex: 1; min-width: 0; }\\n    .bi-label {\\n      font-size: 11px;\\n      color: var(--text-muted);\\n      line-height: 1.3;\\n      display: block;\\n    }\\n    .bi-score {\\n      font-size: 12px;\\n      font-weight: 700;\\n      display: flex;\\n      align-items: center;\\n      gap: 4px;\\n      margin-top: 2px;\\n    }\\n    .bi-pip {\\n      width: 8px; height: 8px;\\n      border-radius: 50%;\\n      flex-shrink: 0;\\n    }\\n    .pip-0 { background: var(--danger); }\\n    .pip-1 { background: var(--warn); }\\n    .pip-2 { background: var(--success); }\\n\\n    .restart-row {\\n      text-align: center;\\n      margin-top: 12px;\\n    }\\n    .btn-outline-primary {\\n      background: #fff;\\n      color: var(--primary);\\n      border: 1.5px solid var(--primary);\\n    }\\n    .btn-outline-primary:hover { background: #eef1fd; }\\n\\n    /* Transitions */\\n    .fade-in { animation: fadeIn .35s ease; }\\n    @keyframes fadeIn { from { opacity:0; transform:translateY(8px); } to { opacity:1; transform:translateY(0); } }\\n  \\u003c/style\\u003e\\n\\u003c/head\\u003e\\n\\u003cbody\\u003e\\n\\u003cdiv class=\\\"widget\\\" id=\\\"root\\\"\\u003e\\n\\n  \\u003c!-- HEADER --\\u003e\\n  \\u003cdiv class=\\\"header\\\"\\u003e\\n    \\u003cdiv class=\\\"header-badge\\\"\\u003e\\n      \\u003csvg viewBox=\\\"0 0 16 16\\\" fill=\\\"currentColor\\\"\\u003e\\u003cpath d=\\\"M8 1a5 5 0 100 10A5 5 0 008 1zm0 9a4 4 0 110-8 4 4 0 010 8z\\\"/\\u003e\\u003cpath d=\\\"M8 4a1 1 0 100 2 1 1 0 000-2zm0 3a.75.75 0 01.75.75v2.5a.75.75 0 01-1.5 0v-2.5A.75.75 0 018 7z\\\"/\\u003e\\u003c/svg\\u003e\\n      AI Identity Governance\\n    \\u003c/div\\u003e\\n    \\u003ch1 id=\\\"h-title\\\"\\u003eAI Agent Identity Governance\\u003cbr\\u003eReadiness Assessment\\u003c/h1\\u003e\\n    \\u003cp id=\\\"h-sub\\\"\\u003e6 questions · ~2 min · Instant maturity score for CISOs \\u0026amp; security engineers\\u003c/p\\u003e\\n  \\u003c/div\\u003e\\n\\n  \\u003c!-- PROGRESS --\\u003e\\n  \\u003cdiv class=\\\"progress-wrap\\\" id=\\\"progressWrap\\\"\\u003e\\n    \\u003cdiv class=\\\"progress-meta\\\"\\u003e\\n      \\u003cspan class=\\\"progress-label\\\" id=\\\"pLabel\\\"\\u003eQuestion\\u003c/span\\u003e\\n      \\u003cspan class=\\\"progress-count\\\" id=\\\"pCount\\\"\\u003e1 / 6\\u003c/span\\u003e\\n    \\u003c/div\\u003e\\n    \\u003cdiv class=\\\"progress-track\\\"\\u003e\\u003cdiv class=\\\"progress-fill\\\" id=\\\"progressFill\\\"\\u003e\\u003c/div\\u003e\\u003c/div\\u003e\\n  \\u003c/div\\u003e\\n\\n  \\u003c!-- QUIZ --\\u003e\\n  \\u003cdiv class=\\\"quiz-active fade-in\\\" id=\\\"quizSection\\\"\\u003e\\n    \\u003cdiv class=\\\"quiz-card\\\" id=\\\"quizCard\\\"\\u003e\\n      \\u003cdiv class=\\\"q-header\\\"\\u003e\\n        \\u003cdiv class=\\\"q-num\\\" id=\\\"qNum\\\"\\u003e1\\u003c/div\\u003e\\n        \\u003cdiv class=\\\"q-text\\\" id=\\\"qText\\\"\\u003e\\u003c/div\\u003e\\n      \\u003c/div\\u003e\\n      \\u003cdiv class=\\\"options\\\" id=\\\"optionsContainer\\\"\\u003e\\u003c/div\\u003e\\n    \\u003c/div\\u003e\\n    \\u003cdiv class=\\\"nav-row\\\"\\u003e\\n      \\u003cbutton class=\\\"btn btn-ghost\\\" id=\\\"btnBack\\\" onclick=\\\"goBack()\\\"\\u003e\\n        \\u003csvg viewBox=\\\"0 0 20 20\\\" fill=\\\"currentColor\\\"\\u003e\\u003cpath fill-rule=\\\"evenodd\\\" d=\\\"M9.707 16.707a1 1 0 01-1.414 0l-6-6a1 1 0 010-1.414l6-6a1 1 0 011.414 1.414L5.414 9H17a1 1 0 110 2H5.414l4.293 4.293a1 1 0 010 1.414z\\\" clip-rule=\\\"evenodd\\\"/\\u003e\\u003c/svg\\u003e\\n        \\u003cspan id=\\\"btnBackText\\\"\\u003eBack\\u003c/span\\u003e\\n      \\u003c/button\\u003e\\n      \\u003cbutton class=\\\"btn btn-primary\\\" id=\\\"btnNext\\\" onclick=\\\"goNext()\\\" disabled\\u003e\\n        \\u003cspan id=\\\"btnNextText\\\"\\u003eNext\\u003c/span\\u003e\\n        \\u003csvg viewBox=\\\"0 0 20 20\\\" fill=\\\"currentColor\\\"\\u003e\\u003cpath fill-rule=\\\"evenodd\\\" d=\\\"M10.293 3.293a1 1 0 011.414 0l6 6a1 1 0 010 1.414l-6 6a1 1 0 01-1.414-1.414L14.586 11H3a1 1 0 110-2h11.586l-4.293-4.293a1 1 0 010-1.414z\\\" clip-rule=\\\"evenodd\\\"/\\u003e\\u003c/svg\\u003e\\n      \\u003c/button\\u003e\\n    \\u003c/div\\u003e\\n  \\u003c/div\\u003e\\n\\n  \\u003c!-- RESULT --\\u003e\\n  \\u003cdiv class=\\\"result-panel\\\" id=\\\"resultPanel\\\"\\u003e\\n    \\u003cdiv class=\\\"result-card\\\" id=\\\"resultCard\\\"\\u003e\\n      \\u003cdiv class=\\\"result-tier-badge\\\" id=\\\"tierBadge\\\"\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-score-wrap\\\"\\u003e\\n        \\u003cdiv class=\\\"result-score-num\\\" id=\\\"scoreNum\\\"\\u003e0\\u003c/div\\u003e\\n        \\u003cdiv class=\\\"result-score-denom\\\"\\u003e\\u0026thinsp;/ 12\\u003c/div\\u003e\\n      \\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-label\\\" id=\\\"resultLabel\\\"\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-bar-track\\\"\\u003e\\u003cdiv class=\\\"result-bar-fill\\\" id=\\\"resultBarFill\\\"\\u003e\\u003c/div\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-rec\\\" id=\\\"resultRec\\\"\\u003e\\u003c/div\\u003e\\n    \\u003c/div\\u003e\\n\\n    \\u003cdiv class=\\\"breakdown-title\\\" id=\\\"bdTitle\\\"\\u003eScore Breakdown\\u003c/div\\u003e\\n    \\u003cdiv class=\\\"breakdown-grid\\\" id=\\\"breakdownGrid\\\"\\u003e\\u003c/div\\u003e\\n\\n    \\u003cdiv class=\\\"restart-row\\\"\\u003e\\n      \\u003cbutton class=\\\"btn btn-outline-primary\\\" onclick=\\\"restart()\\\"\\u003e\\n        \\u003csvg viewBox=\\\"0 0 20 20\\\" fill=\\\"currentColor\\\" style=\\\"width:14px;height:14px\\\"\\u003e\\u003cpath fill-rule=\\\"evenodd\\\" d=\\\"M4 2a1 1 0 011 1v2.101a7.002 7.002 0 0111.601 2.566 1 1 0 11-1.885.666A5.002 5.002 0 005.999 7H9a1 1 0 010 2H4a1 1 0 01-1-1V3a1 1 0 011-1zm.008 9.057a1 1 0 011.276.61A5.002 5.002 0 0014.001 13H11a1 1 0 110-2h5a1 1 0 011 1v5a1 1 0 11-2 0v-2.101a7.002 7.002 0 01-11.601-2.566 1 1 0 01.61-1.276z\\\" clip-rule=\\\"evenodd\\\"/\\u003e\\u003c/svg\\u003e\\n        \\u003cspan id=\\\"btnRestartText\\\"\\u003eRetake Assessment\\u003c/span\\u003e\\n      \\u003c/button\\u003e\\n    \\u003c/div\\u003e\\n  \\u003c/div\\u003e\\n\\n\\u003c/div\\u003e\\n\\n\\u003cscript\\u003e\\nconst i18n = {\\n  en: { title:\\\"AI Agent Identity Governance Readiness Assessment\\\", sub:\\\"6 questions · ~2 min · Instant maturity score for CISOs \\u0026 security engineers\\\", question:\\\"Question\\\", back:\\\"Back\\\", next:\\\"Next\\\", seeResults:\\\"See Results\\\", retake:\\\"Retake Assessment\\\", breakdown:\\\"Score Breakdown\\\", rec:\\\"Recommendation\\\" },\\n  de: { title:\\\"KI-Agenten-Identitäts-Governance Bereitschaftsbewertung\\\", sub:\\\"6 Fragen · ~2 Min · Sofortiger Reifegrad für CISOs\\\", question:\\\"Frage\\\", back:\\\"Zurück\\\", next:\\\"Weiter\\\", seeResults:\\\"Ergebnisse anzeigen\\\", retake:\\\"Neu starten\\\", breakdown:\\\"Punkteübersicht\\\", rec:\\\"Empfehlung\\\" },\\n  es: { title:\\\"Evaluación de Madurez en Gobernanza de Identidad de Agentes IA\\\", sub:\\\"6 preguntas · ~2 min · Puntuación instantánea para CISOs\\\", question:\\\"Pregunta\\\", back:\\\"Atrás\\\", next:\\\"Siguiente\\\", seeResults:\\\"Ver resultados\\\", retake:\\\"Volver a evaluar\\\", breakdown:\\\"Desglose de puntuación\\\", rec:\\\"Recomendación\\\" },\\n  fr: { title:\\\"Évaluation de Maturité en Gouvernance des Identités d'Agents IA\\\", sub:\\\"6 questions · ~2 min · Score instantané pour les RSSI\\\", question:\\\"Question\\\", back:\\\"Retour\\\", next:\\\"Suivant\\\", seeResults:\\\"Voir les résultats\\\", retake:\\\"Recommencer\\\", breakdown:\\\"Détail du score\\\", rec:\\\"Recommandation\\\" },\\n  it: { title:\\\"Valutazione della Maturità nella Governance delle Identità degli Agenti IA\\\", sub:\\\"6 domande · ~2 min · Punteggio istantaneo per CISO\\\", question:\\\"Domanda\\\", back:\\\"Indietro\\\", next:\\\"Avanti\\\", seeResults:\\\"Vedi risultati\\\", retake:\\\"Ricomincia\\\", breakdown:\\\"Dettaglio punteggio\\\", rec:\\\"Raccomandazione\\\" },\\n  pt: { title:\\\"Avaliação de Maturidade em Governança de Identidade de Agentes IA\\\", sub:\\\"6 perguntas · ~2 min · Pontuação instantânea para CISOs\\\", question:\\\"Pergunta\\\", back:\\\"Voltar\\\", next:\\\"Próximo\\\", seeResults:\\\"Ver resultados\\\", retake:\\\"Refazer avaliação\\\", breakdown:\\\"Detalhamento do score\\\", rec:\\\"Recomendação\\\" },\\n  \\\"pt-BR\\\": { title:\\\"Avaliação de Maturidade em Governança de Identidade de Agentes IA\\\", sub:\\\"6 perguntas · ~2 min · Pontuação instantânea para CISOs\\\", question:\\\"Pergunta\\\", back:\\\"Voltar\\\", next:\\\"Próximo\\\", seeResults:\\\"Ver resultados\\\", retake:\\\"Refazer avaliação\\\", breakdown:\\\"Detalhamento do score\\\", rec:\\\"Recomendação\\\" },\\n  pl: { title:\\\"Ocena Dojrzałości Zarządzania Tożsamością Agentów AI\\\", sub:\\\"6 pytań · ~2 min · Natychmiastowy wynik dla CISO\\\", question:\\\"Pytanie\\\", back:\\\"Wstecz\\\", next:\\\"Dalej\\\", seeResults:\\\"Zobacz wyniki\\\", retake:\\\"Zacznij od nowa\\\", breakdown:\\\"Szczegóły wyniku\\\", rec:\\\"Zalecenie\\\" },\\n  ar: { title:\\\"تقييم جاهزية حوكمة هوية عملاء الذكاء الاصطناعي\\\", sub:\\\"٦ أسئلة · دقيقتان · نتيجة فورية للمسؤولين الأمنيين\\\", question:\\\"سؤال\\\", back:\\\"رجوع\\\", next:\\\"التالي\\\", seeResults:\\\"عرض النتائج\\\", retake:\\\"إعادة التقييم\\\", breakdown:\\\"تفصيل النتيجة\\\", rec:\\\"توصية\\\" }\\n};\\nconst lang = (window.__LANG || 'en');\\nconst t = i18n[lang] || i18n.en;\\nif (lang === 'ar') document.getElementById('root').setAttribute('dir', 'rtl');\\n\\nconst questions = [\\n  {\\n    icon: \\\"🪪\\\",\\n    text: \\\"What percentage of your AI agents have unique, individually managed identities — rather than shared credentials or generic API keys?\\\",\\n    options: [\\n      { label: \\\"Less than 25% — most agents share credentials or use untracked API keys\\\", score: 0 },\\n      { label: \\\"25–74% — we've started assigning identities but coverage is incomplete\\\", score: 1 },\\n      { label: \\\"75% or more — nearly all agents have unique, managed identities\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"✅\\\",\\n    text: \\\"Do you have a formal approval or security review process that every AI agent must pass before it is deployed to production?\\\",\\n    options: [\\n      { label: \\\"No — agents are deployed by developers without a centralized review\\\", score: 0 },\\n      { label: \\\"Informally — some teams do ad-hoc reviews, but it's not policy-enforced\\\", score: 1 },\\n      { label: \\\"Yes — a documented, mandatory approval workflow exists and is consistently followed\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"🔑\\\",\\n    text: \\\"How are credentials and secrets for AI agents currently managed in your environment?\\\",\\n    options: [\\n      { label: \\\"No formal process — static API keys stored in code, config files, or informally shared\\\", score: 0 },\\n      { label: \\\"Partial controls — secrets manager used by some teams, but no org-wide standard\\\", score: 1 },\\n      { label: \\\"Short-lived / JIT tokens — agents receive time-bound credentials via a vault or secrets manager, with rotation enforced\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"📋\\\",\\n    text: \\\"Can your team produce a complete, per-tool-call audit trail for any specific AI agent on demand (e.g., for an incident response or compliance review)?\\\",\\n    options: [\\n      { label: \\\"No — we have little to no visibility into individual agent actions or tool calls\\\", score: 0 },\\n      { label: \\\"Partially — some logs exist but they're incomplete, unstructured, or hard to query\\\", score: 1 },\\n      { label: \\\"Yes — we have structured, queryable logs that capture every tool call per agent, available on demand\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"🔄\\\",\\n    text: \\\"Are AI agent identities explicitly included in your organization's regular access review or certification cycles (e.g., quarterly entitlement reviews)?\\\",\\n    options: [\\n      { label: \\\"No — AI agents are not part of any access review program\\\", score: 0 },\\n      { label: \\\"Partially — some agents are reviewed, but it's inconsistent or manual\\\", score: 1 },\\n      { label: \\\"Yes — AI agent identities are systematically included in scheduled access reviews\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"🗑️\\\",\\n    text: \\\"When an AI agent is retired or decommissioned, do you have an automated process to revoke its credentials and remove its access?\\\",\\n    options: [\\n      { label: \\\"No — deprovisioning is manual, ad hoc, or often neglected entirely\\\", score: 0 },\\n      { label: \\\"Partially — we revoke some access manually but have no automated or guaranteed process\\\", score: 1 },\\n      { label: \\\"Yes — automated deprovisioning is triggered on agent retirement, with verification\\\", score: 2 }\\n    ]\\n  }\\n];\\n\\nconst tiers = [\\n  {\\n    min: 0, max: 4,\\n    cls: \\\"shadow-risk\\\",\\n    label: \\\"Shadow Agent Risk\\\",\\n    badge: \\\"⚠️ Shadow Agent Risk\\\",\\n    rec: \\\"\\u003cstrong\\u003eImmediate priority:\\u003c/strong\\u003e Start by building a full inventory of every AI agent, its owner, and the credentials it uses — you cannot govern what you cannot see. Once inventoried, enforce unique identities and migrate away from shared API keys using a secrets manager to eliminate your most critical exposure.\\\"\\n  },\\n  {\\n    min: 5, max: 8,\\n    cls: \\\"emerging\\\",\\n    label: \\\"Emerging Governance\\\",\\n    badge: \\\"🔧 Emerging Governance\\\",\\n    rec: \\\"\\u003cstrong\\u003eNext step:\\u003c/strong\\u003e Formalize the controls you've started by closing coverage gaps — ensure every agent goes through the same approval workflow and is included in access review cycles. Prioritize deploying short-lived, JIT credentials across all agents and wiring agent lifecycle events (creation, retirement) into automated provisioning/deprovisioning pipelines.\\\"\\n  },\\n  {\\n    min: 9, max: 12,\\n    cls: \\\"governed\\\",\\n    label: \\\"Governed Agent Estate\\\",\\n    badge: \\\"✅ Governed Agent Estate\\\",\\n    rec: \\\"\\u003cstrong\\u003eSustain and scale:\\u003c/strong\\u003e You have strong foundational controls — now focus on continuous assurance. Integrate per-tool-call audit telemetry into your SIEM for real-time anomaly detection, and extend your governance framework to cover third-party and low-code agents that teams are likely spinning up outside your current perimeter.\\\"\\n  }\\n];\\n\\nconst shortLabels = [\\\"Unique Identities\\\",\\\"Pre-prod Approval\\\",\\\"Credential Mgmt\\\",\\\"Audit Trail\\\",\\\"Access Reviews\\\",\\\"Auto-deprovision\\\"];\\n\\nlet current = 0;\\nlet answers = new Array(questions.length).fill(null);\\n\\nfunction init() {\\n  document.getElementById('h-title').textContent = t.title;\\n  document.getElementById('h-sub').textContent = t.sub;\\n  document.getElementById('pLabel').textContent = t.question;\\n  document.getElementById('btnBackText').textContent = t.back;\\n  document.getElementById('btnNextText').textContent = t.next;\\n  document.getElementById('bdTitle').textContent = t.breakdown;\\n  document.getElementById('btnRestartText').textContent = t.retake;\\n  renderQuestion();\\n}\\n\\nfunction renderQuestion() {\\n  const q = questions[current];\\n  document.getElementById('qNum').textContent = current + 1;\\n  document.getElementById('qText').innerHTML = `\\u003cspan class=\\\"q-icon\\\"\\u003e${q.icon}\\u003c/span\\u003e ${q.text}`;\\n\\n  const container = document.getElementById('optionsContainer');\\n  container.innerHTML = '';\\n  q.options.forEach((opt, i) =\\u003e {\\n    const scoreLabel = ['0 pts','1 pt','2 pts'][opt.score];\\n    const dotClass = ['score-0','score-1','score-2'][opt.score];\\n    const btn = document.createElement('button');\\n    btn.className = 'option-btn' + (answers[current] === i ? ' selected' : '');\\n    btn.innerHTML = `\\n      \\u003cdiv class=\\\"opt-radio\\\"\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"opt-content\\\"\\u003e\\n        \\u003cspan class=\\\"opt-label\\\"\\u003e${opt.label}\\u003c/span\\u003e\\n        \\u003cspan class=\\\"opt-score\\\"\\u003e\\u003cspan class=\\\"score-dot ${dotClass}\\\"\\u003e\\u003c/span\\u003e${scoreLabel}\\u003c/span\\u003e\\n      \\u003c/div\\u003e`;\\n    btn.onclick = () =\\u003e selectOption(i);\\n    container.appendChild(btn);\\n  });\\n\\n  const isLast = current === questions.length - 1;\\n  document.getElementById('btnNextText').textContent = isLast ? t.seeResults : t.next;\\n  document.getElementById('btnNext').disabled = answers[current] === null;\\n  document.getElementById('btnBack').style.visibility = current === 0 ? 'hidden' : 'visible';\\n\\n  const pct = (current / questions.length) * 100;\\n  document.getElementById('progressFill').style.width = pct + '%';\\n  document.getElementById('pCount').textContent = `${current + 1} / ${questions.length}`;\\n}\\n\\nfunction selectOption(i) {\\n  answers[current] = i;\\n  document.querySelectorAll('.option-btn').forEach((b, idx) =\\u003e {\\n    b.classList.toggle('selected', idx === i);\\n  });\\n  document.getElementById('btnNext').disabled = false;\\n}\\n\\nfunction goNext() {\\n  if (answers[current] === null) return;\\n  if (current \\u003c questions.length - 1) {\\n    current++;\\n    document.getElementById('quizCard').classList.remove('fade-in');\\n    void document.getElementById('quizCard').offsetWidth;\\n    document.getElementById('quizCard').classList.add('fade-in');\\n    renderQuestion();\\n  } else {\\n    showResults();\\n  }\\n}\\n\\nfunction goBack() {\\n  if (current \\u003e 0) {\\n    current--;\\n    document.getElementById('quizCard').classList.remove('fade-in');\\n    void document.getElementById('quizCard').offsetWidth;\\n    document.getElementById('quizCard').classList.add('fade-in');\\n    renderQuestion();\\n  }\\n}\\n\\nfunction showResults() {\\n  let total = 0;\\n  answers.forEach((ans, qi) =\\u003e {\\n    if (ans !== null) total += questions[qi].options[ans].score;\\n  });\\n\\n  const tier = tiers.find(t =\\u003e total \\u003e= t.min \\u0026\\u0026 total \\u003c= t.max);\\n\\n  document.getElementById('quizSection').classList.add('hidden');\\n  document.getElementById('progressWrap').style.display = 'none';\\n\\n  const panel = document.getElementById('resultPanel');\\n  panel.classList.add('visible', 'fade-in');\\n\\n  const card = document.getElementById('resultCard');\\n  card.className = 'result-card ' + tier.cls;\\n\\n  document.getElementById('tierBadge').textContent = tier.badge;\\n  document.getElementById('scoreNum').textContent = total;\\n  document.getElementById('resultLabel').textContent = tier.label;\\n  document.getElementById('resultRec').innerHTML = `\\u003cstrong\\u003e${t.rec}:\\u003c/strong\\u003e ` + tier.rec.replace(/\\u003cstrong\\u003e.*?\\u003c\\\\/strong\\u003e\\\\s*/,'');\\n  document.getElementById('resultRec').innerHTML = tier.rec;\\n\\n  const fillPct = (total / 12) * 100;\\n  setTimeout(() =\\u003e { document.getElementById('resultBarFill').style.width = fillPct + '%'; }, 80);\\n\\n  const grid = document.getElementById('breakdownGrid');\\n  grid.innerHTML = '';\\n  answers.forEach((ans, qi) =\\u003e {\\n    const sc = ans !== null ? questions[qi].options[ans].score : 0;\\n    const pipClass = ['pip-0','pip-1','pip-2'][sc];\\n    const scoreText = ['0 / 2','1 / 2','2 / 2'][sc];\\n    const div = document.createElement('div');\\n    div.className = 'breakdown-item';\\n    div.innerHTML = `\\n      \\u003cdiv class=\\\"bi-icon\\\"\\u003e${questions[qi].icon}\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"bi-info\\\"\\u003e\\n        \\u003cspan class=\\\"bi-label\\\"\\u003e${shortLabels[qi]}\\u003c/span\\u003e\\n        \\u003cdiv class=\\\"bi-score\\\"\\u003e\\u003cspan class=\\\"bi-pip ${pipClass}\\\"\\u003e\\u003c/span\\u003e${scoreText}\\u003c/div\\u003e\\n      \\u003c/div\\u003e`;\\n    grid.appendChild(div);\\n  });\\n}\\n\\nfunction restart() {\\n  current = 0;\\n  answers = new Array(questions.length).fill(null);\\n  document.getElementById('quizSection').classList.remove('hidden');\\n  document.getElementById('progressWrap').style.display = '';\\n  const panel = document.getElementById('resultPanel');\\n  panel.classList.remove('visible','fade-in');\\n  document.getElementById('resultBarFill').style.width = '0%';\\n  document.getElementById('quizCard').classList.remove('fade-in');\\n  void document.getElementById('quizCard').offsetWidth;\\n  document.getElementById('quizCard').classList.add('fade-in');\\n  renderQuestion();\\n}\\n\\ninit();\\n\\u003c/script\\u003e\\n\\n\\u003cscript\\u003e\\n  window.addEventListener('load', () =\\u003e {\\n    const sendHeight = () =\\u003e {\\n      const height = document.body.offsetHeight + 24;\\n      window.parent.postMessage({ type: 'widget-resize', height }, '*');\\n    };\\n    sendHeight();\\n    new ResizeObserver(sendHeight).observe(document.body);\\n  });\\n\\u003c/script\\u003e\\n\\u003c/body\\u003e\\n\\u003c/html\\u003e\"])</script><script>self.__next_f.push([1,\"2b:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mx-auto max-w-[620px] px-6 sm:px-0\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L2d\\\",null,{\\\"body\\\":\\\"$2e\\\",\\\"components\\\":[{\\\"id\\\":\\\"e30cc0b7-1878-4e09-b948-931b4ea6d29d\\\",\\\"content\\\":{\\\"level\\\":\\\"warning\\\",\\\"content\\\":\\\"**The authentication gap is real.** Research published in early 2026 documented more than 1,800 active MCP servers on the public internet with no authentication whatsoever. Because authentication in MCP is optional — not required by the spec — they are technically compliant and practically insecure. Before deploying any MCP server, verify OAuth 2.1 is enabled and enforced, not just installed.\\\"},\\\"position_hint\\\":0,\\\"component_type\\\":\\\"callout\\\"},{\\\"id\\\":\\\"f0d62597-013b-4953-b03d-747adcaf9cba\\\",\\\"content\\\":{\\\"rows\\\":[{\\\"gap\\\":\\\"Ecosystem lock-in; heterogeneous agent stacks require federation workarounds\\\",\\\"category\\\":\\\"Identity Providers extending to agents\\\",\\\"examples\\\":\\\"Microsoft Entra Agent ID, Okta (MCP server + Auth for MCP), Auth0\\\",\\\"strength\\\":\\\"Standards-based auth (OAuth 2.1/OIDC), existing enterprise trust, lifecycle hooks\\\"},{\\\"gap\\\":\\\"Agent governance is identity-discovery-led, not runtime-enforcement-led; agents treated as NHI subset, not first-class\\\",\\\"category\\\":\\\"NHI Security Specialists\\\",\\\"examples\\\":\\\"Oasis Security, Entro, Teleport\\\",\\\"strength\\\":\\\"Discovery, secrets rotation, posture management for service accounts and API keys\\\"},{\\\"gap\\\":\\\"Closed ecosystems; governance doesn't extend to human identities or non-MCP agents\\\",\\\"category\\\":\\\"MCP Gateways\\\",\\\"examples\\\":\\\"Arcade, TrueFoundry, Cloudflare Agents SDK\\\",\\\"strength\\\":\\\"Runtime authorization at the tool-call level; per-session ephemeral credentials; low-latency enforcement\\\"},{\\\"gap\\\":\\\"Legacy IGA platforms bolt on agent support; depth and automation vary significantly\\\",\\\"category\\\":\\\"IGA Platforms governing agents + humans\\\",\\\"examples\\\":\\\"Iden, SailPoint (Agent Identity Security add-on), ServiceNow/Veza\\\",\\\"strength\\\":\\\"Unified lifecycle governance across human and non-human identities; policy-driven provisioning and deprovisioning; access reviews\\\"}],\\\"title\\\":\\\"AI Agent Identity: Vendor Category Comparison\\\",\\\"columns\\\":[{\\\"key\\\":\\\"category\\\",\\\"label\\\":\\\"Category\\\"},{\\\"key\\\":\\\"examples\\\",\\\"label\\\":\\\"Examples\\\"},{\\\"key\\\":\\\"strength\\\",\\\"label\\\":\\\"Core Strength\\\"},{\\\"key\\\":\\\"gap\\\",\\\"label\\\":\\\"Key Gap\\\"}]},\\\"position_hint\\\":1,\\\"component_type\\\":\\\"data_table\\\"},{\\\"id\\\":\\\"3a13a849-8155-45c7-8c5c-27430a712e8c\\\",\\\"content\\\":{\\\"alt\\\":\\\"Isometric diagram showing two parallel governance tracks: on the left, a structured lifecycle flow for human employees (hire, provision, review, offboard) with clear checkpoints; on the right, a chaotic tangle of AI agents with no lifecycle, overlapping permissions, and missing audit trails - visually contrasting governed vs. ungoverned identity\\\",\\\"url\\\":\\\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/6c51af9e-cfc7-42f5-958f-0a84c680cb69.jpg\\\",\\\"aspect\\\":\\\"16:9\\\",\\\"intent\\\":\\\"inline\\\",\\\"prompt\\\":\\\"Isometric diagram showing two parallel governance tracks: on the left, a structured lifecycle flow for human employees (hire, provision, review, offboard) with clear checkpoints; on the right, a chaotic tangle of AI agents with no lifecycle, overlapping permissions, and missing audit trails - visually contrasting governed vs. ungoverned identity\\\",\\\"status\\\":\\\"ready\\\",\\\"asset_id\\\":\\\"112c5483-c3cf-40dc-a2f0-57345e5c8c19\\\",\\\"error_message\\\":null},\\\"position_hint\\\":2,\\\"component_type\\\":\\\"image\\\"},{\\\"id\\\":\\\"a30e26b9-c278-4c10-b474-e6bceaaaa120\\\",\\\"content\\\":{\\\"cta_key\\\":\\\"book_demo\\\",\\\"label_override\\\":\\\"See Iden's Agent Governance in Action\\\",\\\"description_override\\\":\\\"Book a 30-minute walkthrough to see how Iden governs human and non-human identities — including AI agents — in a single policy plane.\\\",\\\"_resolved\\\":null},\\\"position_hint\\\":3,\\\"component_type\\\":\\\"cta\\\"},{\\\"id\\\":\\\"1d887c11-0b30-41a3-afdc-9d89b2f6ccfd\\\",\\\"content\\\":{\\\"items\\\":[{\\\"title\\\":\\\"Inventory your agent estate before you buy anything\\\",\\\"description\\\":\\\"You cannot govern what you cannot see. Start with a full discovery pass: which agents are running, who deployed them, what credentials they hold, and what systems they can reach. Shadow agents — those with no registry entry, no assigned owner, and no managed identity — are your highest-risk population. Treat them as Critical findings.\\\"},{\\\"title\\\":\\\"Demand short-lived, scoped credentials — not API keys\\\",\\\"description\\\":\\\"Any platform that relies on shared API keys or long-lived static credentials for agent authentication is not a governance solution. Require per-session ephemeral tokens scoped to the specific task, with automatic teardown at end of session. This is the single highest-leverage control against prompt injection and credential theft.\\\"},{\\\"title\\\":\\\"Verify the AND gate, not the OR gate\\\",\\\"description\\\":\\\"An agent should only be able to do what the agent is authorized to do AND what the delegating user is authorized to do — not the union of both. Service accounts that inherit broad employee credentials create authorization bypass vulnerabilities. Confirm that your chosen platform enforces the intersection, not the superset.\\\"},{\\\"title\\\":\\\"Require a full audit trail at the tool-call level\\\",\\\"description\\\":\\\"Logging that an agent 'ran' is not an audit trail. You need: which agent, which user delegated, which tool was called, with what arguments, what data was accessed, and what the result was. The EU AI Act's transparency provisions take effect August 2, 2026. If your platform cannot produce this log on demand, it cannot support compliance.\\\"},{\\\"title\\\":\\\"Evaluate lifecycle governance, not just runtime enforcement\\\",\\\"description\\\":\\\"Runtime authorization at the tool-call level is necessary but not sufficient. You also need: agent registration and approval workflows before deployment, access reviews on the same cadence as human identities, and automated deprovisioning when an agent is retired. Ask vendors specifically how they handle agent offboarding — most have no answer.\\\"},{\\\"title\\\":\\\"Insist on unified governance across human and non-human identities\\\",\\\"description\\\":\\\"Separate tools for human IGA and agent governance create blind spots at the seams. An agent acting on behalf of a human should be governed in the same plane as that human — same policy engine, same access review, same audit log. If your IGA platform treats agents as a bolt-on module, you have a coverage gap.\\\"}]},\\\"position_hint\\\":4,\\\"component_type\\\":\\\"steps\\\"},{\\\"id\\\":\\\"e5afe1d7-cb52-4acd-8a56-b6970002b90b\\\",\\\"content\\\":{\\\"prompt\\\":\\\"$2f\\\",\\\"status\\\":\\\"ready\\\",\\\"csv_data\\\":null,\\\"edit_history\\\":[],\\\"generated_at\\\":\\\"2026-06-08T10:13:20.451Z\\\",\\\"html_content\\\":\\\"$30\\\",\\\"error_message\\\":null},\\\"position_hint\\\":5,\\\"component_type\\\":\\\"widget\\\"}],\\\"sources\\\":[{\\\"id\\\":\\\"26e9916a-0ddc-4009-b3db-19495fb4bf3a\\\",\\\"idx\\\":1,\\\"url\\\":\\\"https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/\\\",\\\"title\\\":\\\"microsoft.com — 80 of fortune 500 use active ai agents observability governance and security shape the new frontier\\\",\\\"snippet\\\":\\\"Microsoft Security Blog\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"f23a24f8-886a-4d06-9a8c-2334e7761c55\\\",\\\"idx\\\":2,\\\"url\\\":\\\"https://www.marktechpost.com/2026/05/25/best-authentication-platforms-for-ai-agents-and-mcp-servers-in-2026/\\\",\\\"title\\\":\\\"marktechpost.com — Best authentication platforms for ai agents and mcp servers in 2026\\\",\\\"snippet\\\":\\\"MarkTechPost\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"80a9ba39-24c7-4ce5-a886-58761a7a498e\\\",\\\"idx\\\":3,\\\"url\\\":\\\"https://www.gravitee.io/state-of-ai-agent-security\\\",\\\"title\\\":\\\"gravitee.io — State of ai agent security\\\",\\\"snippet\\\":\\\"Gravitee State of AI Agent Security 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"2a710a07-8e89-4357-a601-455cc7829d15\\\",\\\"idx\\\":4,\\\"url\\\":\\\"https://workos.com/blog/everything-your-team-needs-to-know-about-mcp-in-2026/\\\",\\\"title\\\":\\\"workos.com — Everything your team needs to know about mcp in 2026\\\",\\\"snippet\\\":\\\"WorkOS MCP 2026 Guide\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"ae2a8a19-4f01-48a1-b34e-08bd312d4a89\\\",\\\"idx\\\":5,\\\"url\\\":\\\"https://aaif.io/blog/mcp-is-now-enterprise-infrastructure-everything-that-happened-at-mcp-dev-summit-north-america-2026/\\\",\\\"title\\\":\\\"aaif.io — Mcp is now enterprise infrastructure everything that happened at mcp dev summit north america 2026\\\",\\\"snippet\\\":\\\"AAIF MCP Dev Summit 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"e556aa2b-3346-42e0-9758-a890213b0902\\\",\\\"idx\\\":6,\\\"url\\\":\\\"https://www.prefect.io/resources/mcp-oauth\\\",\\\"title\\\":\\\"prefect.io — Mcp oauth\\\",\\\"snippet\\\":\\\"Prefect MCP OAuth Guide\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"44dd868e-8148-4dbc-a948-26a420cf737d\\\",\\\"idx\\\":7,\\\"url\\\":\\\"https://epinium.com/en/blog/model-context-protocol-enterprise-guide/\\\",\\\"title\\\":\\\"epinium.com — Model context protocol enterprise guide\\\",\\\"snippet\\\":\\\"Epinium MCP Enterprise Guide\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c496d355-e449-414d-9edc-46f8f62e24ec\\\",\\\"idx\\\":8,\\\"url\\\":\\\"https://www.vouched.id/learn/vouched-donates-mcp-i-identity-framework-to-the-decentralized-identity-foundation-to-advance-trust-and-security-for-ai-agents\\\",\\\"title\\\":\\\"vouched.id — Vouched donates mcp i identity framework to the decentralized identity foundation to advance trust and security for ai agents\\\",\\\"snippet\\\":\\\"Vouched MCP-I Donation\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"9843ca43-ff6c-4357-8018-76be068b927c\\\",\\\"idx\\\":9,\\\"url\\\":\\\"https://blog.identity.foundation/why-dif-said-yes-to-mcp-i/\\\",\\\"title\\\":\\\"blog.identity.foundation — Why dif said yes to mcp i\\\",\\\"snippet\\\":\\\"DIF Blog on MCP-I\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c8b0257d-426a-45c7-86a6-4d04dc98f2b2\\\",\\\"idx\\\":10,\\\"url\\\":\\\"https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id\\\",\\\"title\\\":\\\"learn.microsoft.com — What is microsoft entra agent id\\\",\\\"snippet\\\":\\\"Microsoft Entra Agent ID Docs\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"0fa2a0fa-fbeb-4076-885d-5ab791191d2a\\\",\\\"idx\\\":11,\\\"url\\\":\\\"https://learn.microsoft.com/en-us/entra/agent-id/agent-identities\\\",\\\"title\\\":\\\"learn.microsoft.com — Agent identities\\\",\\\"snippet\\\":\\\"Microsoft Entra Agent Identities\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"15e64e30-ed80-481e-b3f3-94f419304dbb\\\",\\\"idx\\\":12,\\\"url\\\":\\\"https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/\\\",\\\"title\\\":\\\"microsoft.com — Secure agentic ai end to end\\\",\\\"snippet\\\":\\\"Microsoft Secure Agentic AI\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"71b77171-b91f-4f44-9b0e-6688e2ff8788\\\",\\\"idx\\\":13,\\\"url\\\":\\\"https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents\\\",\\\"title\\\":\\\"cloudsecurityalliance.org — The agentic trust framework zero trust governance for ai agents\\\",\\\"snippet\\\":\\\"CSA Agentic Trust Framework\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"e7b0fde9-dc42-4e0a-8e92-6004ff059be1\\\",\\\"idx\\\":14,\\\"url\\\":\\\"https://www.oktsec.com/blog/csa-agentic-trust-framework-zero-trust-agents/\\\",\\\"title\\\":\\\"oktsec.com — Csa agentic trust framework zero trust agents\\\",\\\"snippet\\\":\\\"Oktsec CSA ATF Analysis\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"fbaa1471-c215-4927-9185-b853bd1f385f\\\",\\\"idx\\\":15,\\\"url\\\":\\\"https://cloudsecurityalliance.org/press-releases/2026/03/23/csa-securing-the-agentic-control-plane\\\",\\\"title\\\":\\\"cloudsecurityalliance.org — Csa securing the agentic control plane\\\",\\\"snippet\\\":\\\"CSA CSAI Foundation Launch\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"3bef993e-4e22-4872-80c9-e5e280b23ead\\\",\\\"idx\\\":16,\\\"url\\\":\\\"https://veza.com/blog/forrester-recognizes-veza-for-iga-ispm-and-nhi-ai-identity-management/\\\",\\\"title\\\":\\\"veza.com — Forrester recognizes veza for iga ispm and nhi ai identity management\\\",\\\"snippet\\\":\\\"Veza Forrester Recognition\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c1b17401-81c6-42d2-9715-f539ce234d63\\\",\\\"idx\\\":17,\\\"url\\\":\\\"https://aimultiple.com/iga-solutions\\\",\\\"title\\\":\\\"aimultiple.com — Iga solutions\\\",\\\"snippet\\\":\\\"AIMultiple IGA Solutions\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"41500841-fdeb-4f0c-8ddc-b402708baffa\\\",\\\"idx\\\":18,\\\"url\\\":\\\"https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control\\\",\\\"title\\\":\\\"gravitee.io — State of ai agent security 2026 report when adoption outpaces control\\\",\\\"snippet\\\":\\\"Gravitee State of AI Agent Security 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"192b69b1-d9c0-4687-abd4-3c6ca1466679\\\",\\\"idx\\\":19,\\\"url\\\":\\\"https://www.cybersecstats.com/ai-cybersecurity-statistics-2026-q1-q2/\\\",\\\"title\\\":\\\"cybersecstats.com — Ai cybersecurity statistics 2026 q1 q2\\\",\\\"snippet\\\":\\\"AI Cybersecurity Statistics 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c8371ea6-ba08-4327-ae31-8c8b818bb89e\\\",\\\"idx\\\":20,\\\"url\\\":\\\"https://secureflo.net/ai-agent-identity-management-a-2026-ciso-playbook/\\\",\\\"title\\\":\\\"secureflo.net — Ai agent identity management a 2026 ciso playbook\\\",\\\"snippet\\\":\\\"SecureFlo CISO Playbook\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"df68d143-4627-4dab-ae88-9c4f37a6a64c\\\",\\\"idx\\\":21,\\\"url\\\":\\\"https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/\\\",\\\"title\\\":\\\"labs.cloudsecurityalliance.org — Csa whitepaper nonhuman identity agentic ai governance v1 cs\\\",\\\"snippet\\\":\\\"CSA NHI Governance Vacuum\\\",\\\"metadata\\\":{}}],\\\"postId\\\":\\\"bd8d9626-eb18-40e6-89dd-f59e9670a423\\\",\\\"lang\\\":\\\"en-US\\\"}],false,\\\"$L31\\\"]}]\\n\"])</script><script>self.__next_f.push([1,\"2c:[\\\"$\\\",\\\"section\\\",null,{\\\"className\\\":\\\"mx-auto mt-20 max-w-[620px] border-t border-[var(--blog-border)] px-6 pt-12 sm:px-0\\\",\\\"children\\\":[[\\\"$\\\",\\\"h2\\\",null,{\\\"className\\\":\\\"mb-6 font-mono text-[11px] uppercase tracking-[0.22em] text-[var(--blog-faint)]\\\",\\\"children\\\":\\\"Related reading\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"grid gap-6 sm:grid-cols-2\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L19\\\",\\\"30e99d62-3d1b-4856-b662-a5f98ad64f9d\\\",{\\\"href\\\":\\\"/en/blog/segregation-of-duties-guide-entitlement-level\\\",\\\"className\\\":\\\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative aspect-[16/9] overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"className\\\":\\\"absolute inset-0 h-full w-full\\\",\\\"viewBox\\\":\\\"0 0 320 200\\\",\\\"preserveAspectRatio\\\":\\\"xMidYMid slice\\\",\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[[\\\"$\\\",\\\"defs\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"linearGradient\\\",null,{\\\"id\\\":\\\"blog-grad-segregation-of-duties-guide-entitlement-level\\\",\\\"x1\\\":\\\"50%\\\",\\\"y1\\\":\\\"0%\\\",\\\"x2\\\":\\\"50%\\\",\\\"y2\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"0%\\\",\\\"stopColor\\\":\\\"#D4DCDA\\\"}],[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"100%\\\",\\\"stopColor\\\":\\\"#47585C\\\"}]]}],[\\\"$\\\",\\\"filter\\\",null,{\\\"id\\\":\\\"blog-grain-segregation-of-duties-guide-entitlement-level\\\",\\\"x\\\":\\\"0\\\",\\\"y\\\":\\\"0\\\",\\\"width\\\":\\\"100%\\\",\\\"height\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"feTurbulence\\\",null,{\\\"type\\\":\\\"fractalNoise\\\",\\\"baseFrequency\\\":\\\"0.9\\\",\\\"numOctaves\\\":\\\"2\\\",\\\"seed\\\":6543,\\\"result\\\":\\\"noise\\\"}],[\\\"$\\\",\\\"feColorMatrix\\\",null,{\\\"in\\\":\\\"noise\\\",\\\"type\\\":\\\"matrix\\\",\\\"values\\\":\\\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\\\"}]]}],[\\\"$\\\",\\\"pattern\\\",null,{\\\"id\\\":\\\"blog-dither-segregation-of-duties-guide-entitlement-level\\\",\\\"patternUnits\\\":\\\"userSpaceOnUse\\\",\\\"width\\\":\\\"4\\\",\\\"height\\\":\\\"4\\\",\\\"children\\\":[\\\"$\\\",\\\"circle\\\",null,{\\\"cx\\\":\\\"1.5\\\",\\\"cy\\\":\\\"1.5\\\",\\\"r\\\":\\\"0.3\\\",\\\"fill\\\":\\\"#000\\\",\\\"fillOpacity\\\":\\\"0.06\\\"}]}]]}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-grad-segregation-of-duties-guide-entitlement-level)\\\"}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"220\\\",\\\"filter\\\":\\\"url(#blog-grain-segregation-of-duties-guide-entitlement-level)\\\",\\\"style\\\":{\\\"mixBlendMode\\\":\\\"overlay\\\"}}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-dither-segregation-of-duties-guide-entitlement-level)\\\"}]]}],[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 256 256\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"6\\\",\\\"className\\\":\\\"absolute left-5 top-5 h-9 w-9 pointer-events-none\\\",\\\"style\\\":{\\\"color\\\":\\\"#1c1c1c\\\",\\\"opacity\\\":0.78},\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"M10 128H246M71 69L10 128L71 187M186 187L246 128L186 69\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"absolute right-3 top-3\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Segregation of duties\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex flex-1 flex-col gap-2.5 p-5\\\",\\\"children\\\":[[\\\"$\\\",\\\"h3\\\",null,{\\\"className\\\":\\\"text-[17px] font-normal leading-snug tracking-tight text-white\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"blog-underline\\\",\\\"children\\\":\\\"The Definitive Guide to Segregation of Duties (SoD): From Policy to Entitlement-Level Enforcement\\\"}]}],[\\\"$\\\",\\\"p\\\",null,{\\\"className\\\":\\\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"A complete SoD guide: definition, toxic combinations, framework mapping (SOC 2, ISO 27001, SOX, PCI DSS), the conflict matrix, and why role-level SoD misses the real violations hiding inside broad entitlements.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\\\",\\\"children\\\":[\\\"$undefined\\\",\\\"$undefined\\\",[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"tabular-nums\\\",\\\"children\\\":\\\"Jul 24, 2026\\\"}]]}]]}]]}],[\\\"$\\\",\\\"$L19\\\",\\\"a6e043fd-3d60-4e22-99b8-d4aee093492d\\\",{\\\"href\\\":\\\"/en/blog/third-party-contractor-access-audit-evidence\\\",\\\"className\\\":\\\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\\\",\\\"children\\\":[\\\"$L32\\\",\\\"$L33\\\"]}],\\\"$L34\\\"]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"35:T137b,\"])</script><script>self.__next_f.push([1,\"\\u003col class=\\\"bp-sources\\\"\\u003e\\u003cli id=\\\"source-1\\\"\\u003e\\u003ca href=\\\"https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003emicrosoft.com — 80 of fortune 500 use active ai agents observability governance and security shape the new frontier\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-2\\\"\\u003e\\u003ca href=\\\"https://www.marktechpost.com/2026/05/25/best-authentication-platforms-for-ai-agents-and-mcp-servers-in-2026/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003emarktechpost.com — Best authentication platforms for ai agents and mcp servers in 2026\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-3\\\"\\u003e\\u003ca href=\\\"https://www.gravitee.io/state-of-ai-agent-security\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003egravitee.io — State of ai agent security\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-4\\\"\\u003e\\u003ca href=\\\"https://workos.com/blog/everything-your-team-needs-to-know-about-mcp-in-2026/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eworkos.com — Everything your team needs to know about mcp in 2026\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-5\\\"\\u003e\\u003ca href=\\\"https://aaif.io/blog/mcp-is-now-enterprise-infrastructure-everything-that-happened-at-mcp-dev-summit-north-america-2026/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eaaif.io — Mcp is now enterprise infrastructure everything that happened at mcp dev summit north america 2026\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-6\\\"\\u003e\\u003ca href=\\\"https://www.prefect.io/resources/mcp-oauth\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eprefect.io — Mcp oauth\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-7\\\"\\u003e\\u003ca href=\\\"https://epinium.com/en/blog/model-context-protocol-enterprise-guide/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eepinium.com — Model context protocol enterprise guide\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-8\\\"\\u003e\\u003ca href=\\\"https://www.vouched.id/learn/vouched-donates-mcp-i-identity-framework-to-the-decentralized-identity-foundation-to-advance-trust-and-security-for-ai-agents\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003evouched.id — Vouched donates mcp i identity framework to the decentralized identity foundation to advance trust and security for ai agents\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-9\\\"\\u003e\\u003ca href=\\\"https://blog.identity.foundation/why-dif-said-yes-to-mcp-i/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eblog.identity.foundation — Why dif said yes to mcp i\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-10\\\"\\u003e\\u003ca href=\\\"https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003elearn.microsoft.com — What is microsoft entra agent id\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-11\\\"\\u003e\\u003ca href=\\\"https://learn.microsoft.com/en-us/entra/agent-id/agent-identities\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003elearn.microsoft.com — Agent identities\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-12\\\"\\u003e\\u003ca href=\\\"https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003emicrosoft.com — Secure agentic ai end to end\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-13\\\"\\u003e\\u003ca href=\\\"https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003ecloudsecurityalliance.org — The agentic trust framework zero trust governance for ai agents\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-14\\\"\\u003e\\u003ca href=\\\"https://www.oktsec.com/blog/csa-agentic-trust-framework-zero-trust-agents/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eoktsec.com — Csa agentic trust framework zero trust agents\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-15\\\"\\u003e\\u003ca href=\\\"https://cloudsecurityalliance.org/press-releases/2026/03/23/csa-securing-the-agentic-control-plane\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003ecloudsecurityalliance.org — Csa securing the agentic control plane\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-16\\\"\\u003e\\u003ca href=\\\"https://veza.com/blog/forrester-recognizes-veza-for-iga-ispm-and-nhi-ai-identity-management/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eveza.com — Forrester recognizes veza for iga ispm and nhi ai identity management\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-17\\\"\\u003e\\u003ca href=\\\"https://aimultiple.com/iga-solutions\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eaimultiple.com — Iga solutions\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-18\\\"\\u003e\\u003ca href=\\\"https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003egravitee.io — State of ai agent security 2026 report when adoption outpaces control\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-19\\\"\\u003e\\u003ca href=\\\"https://www.cybersecstats.com/ai-cybersecurity-statistics-2026-q1-q2/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003ecybersecstats.com — Ai cybersecurity statistics 2026 q1 q2\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-20\\\"\\u003e\\u003ca href=\\\"https://secureflo.net/ai-agent-identity-management-a-2026-ciso-playbook/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003esecureflo.net — Ai agent identity management a 2026 ciso playbook\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-21\\\"\\u003e\\u003ca href=\\\"https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003elabs.cloudsecurityalliance.org — Csa whitepaper nonhuman identity agentic ai governance v1 cs\\u003c/a\\u003e\\u003c/li\\u003e\\u003c/ol\\u003e\"])</script><script>self.__next_f.push([1,\"31:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"prose-body mt-12 border-t border-[var(--blog-border)] pt-8\\\",\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$35\\\"}}]\\n\"])</script><script>self.__next_f.push([1,\"32:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative aspect-[16/9] overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"className\\\":\\\"absolute inset-0 h-full w-full\\\",\\\"viewBox\\\":\\\"0 0 320 200\\\",\\\"preserveAspectRatio\\\":\\\"xMidYMid slice\\\",\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[[\\\"$\\\",\\\"defs\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"linearGradient\\\",null,{\\\"id\\\":\\\"blog-grad-third-party-contractor-access-audit-evidence\\\",\\\"x1\\\":\\\"50%\\\",\\\"y1\\\":\\\"0%\\\",\\\"x2\\\":\\\"50%\\\",\\\"y2\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"0%\\\",\\\"stopColor\\\":\\\"#E5E4E6\\\"}],[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"100%\\\",\\\"stopColor\\\":\\\"#4D80E6\\\"}]]}],[\\\"$\\\",\\\"filter\\\",null,{\\\"id\\\":\\\"blog-grain-third-party-contractor-access-audit-evidence\\\",\\\"x\\\":\\\"0\\\",\\\"y\\\":\\\"0\\\",\\\"width\\\":\\\"100%\\\",\\\"height\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"feTurbulence\\\",null,{\\\"type\\\":\\\"fractalNoise\\\",\\\"baseFrequency\\\":\\\"0.9\\\",\\\"numOctaves\\\":\\\"2\\\",\\\"seed\\\":4201,\\\"result\\\":\\\"noise\\\"}],[\\\"$\\\",\\\"feColorMatrix\\\",null,{\\\"in\\\":\\\"noise\\\",\\\"type\\\":\\\"matrix\\\",\\\"values\\\":\\\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\\\"}]]}],[\\\"$\\\",\\\"pattern\\\",null,{\\\"id\\\":\\\"blog-dither-third-party-contractor-access-audit-evidence\\\",\\\"patternUnits\\\":\\\"userSpaceOnUse\\\",\\\"width\\\":\\\"4\\\",\\\"height\\\":\\\"4\\\",\\\"children\\\":[\\\"$\\\",\\\"circle\\\",null,{\\\"cx\\\":\\\"1.5\\\",\\\"cy\\\":\\\"1.5\\\",\\\"r\\\":\\\"0.3\\\",\\\"fill\\\":\\\"#000\\\",\\\"fillOpacity\\\":\\\"0.06\\\"}]}]]}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-grad-third-party-contractor-access-audit-evidence)\\\"}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"220\\\",\\\"filter\\\":\\\"url(#blog-grain-third-party-contractor-access-audit-evidence)\\\",\\\"style\\\":{\\\"mixBlendMode\\\":\\\"overlay\\\"}}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-dither-third-party-contractor-access-audit-evidence)\\\"}]]}],[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 256 256\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"6\\\",\\\"className\\\":\\\"absolute left-5 top-5 h-9 w-9 pointer-events-none\\\",\\\"style\\\":{\\\"color\\\":\\\"#1c1c1c\\\",\\\"opacity\\\":0.78},\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"M128 8V88M246.5 9.5L156.697 99.3026M168 128H248M246.5 246.5L156.697 156.697M128 168V248M9.5 246.5L99.3026 156.697M8 128H88M9.5 9.5L99.3026 99.3026\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"absolute right-3 top-3\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Third-party access audit trail\\\"}]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"33:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex flex-1 flex-col gap-2.5 p-5\\\",\\\"children\\\":[[\\\"$\\\",\\\"h3\\\",null,{\\\"className\\\":\\\"text-[17px] font-normal leading-snug tracking-tight text-white\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"blog-underline\\\",\\\"children\\\":\\\"Third-Party Access Is Your Audit's Weakest Link - Here's How to Fix It\\\"}]}],[\\\"$\\\",\\\"p\\\",null,{\\\"className\\\":\\\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Contractors and partners don't live in your HRIS - so they fall outside JML automation and become orphaned-access hotspots. Here's the evidence every auditor demands and how to produce it.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\\\",\\\"children\\\":[\\\"$undefined\\\",\\\"$undefined\\\",[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"tabular-nums\\\",\\\"children\\\":\\\"Jul 17, 2026\\\"}]]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"34:[\\\"$\\\",\\\"$L19\\\",\\\"965d11ba-e6aa-43a5-a258-7c495ed20b58\\\",{\\\"href\\\":\\\"/en/blog/legacy-iga-migration-guide-checklist\\\",\\\"className\\\":\\\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative aspect-[16/9] overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"className\\\":\\\"absolute inset-0 h-full w-full\\\",\\\"viewBox\\\":\\\"0 0 320 200\\\",\\\"preserveAspectRatio\\\":\\\"xMidYMid slice\\\",\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[[\\\"$\\\",\\\"defs\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"linearGradient\\\",null,{\\\"id\\\":\\\"blog-grad-legacy-iga-migration-guide-checklist\\\",\\\"x1\\\":\\\"50%\\\",\\\"y1\\\":\\\"0%\\\",\\\"x2\\\":\\\"50%\\\",\\\"y2\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"0%\\\",\\\"stopColor\\\":\\\"#D4DCDA\\\"}],[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"100%\\\",\\\"stopColor\\\":\\\"#949495\\\"}]]}],[\\\"$\\\",\\\"filter\\\",null,{\\\"id\\\":\\\"blog-grain-legacy-iga-migration-guide-checklist\\\",\\\"x\\\":\\\"0\\\",\\\"y\\\":\\\"0\\\",\\\"width\\\":\\\"100%\\\",\\\"height\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"feTurbulence\\\",null,{\\\"type\\\":\\\"fractalNoise\\\",\\\"baseFrequency\\\":\\\"0.9\\\",\\\"numOctaves\\\":\\\"2\\\",\\\"seed\\\":349,\\\"result\\\":\\\"noise\\\"}],[\\\"$\\\",\\\"feColorMatrix\\\",null,{\\\"in\\\":\\\"noise\\\",\\\"type\\\":\\\"matrix\\\",\\\"values\\\":\\\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\\\"}]]}],[\\\"$\\\",\\\"pattern\\\",null,{\\\"id\\\":\\\"blog-dither-legacy-iga-migration-guide-checklist\\\",\\\"patternUnits\\\":\\\"userSpaceOnUse\\\",\\\"width\\\":\\\"4\\\",\\\"height\\\":\\\"4\\\",\\\"children\\\":[\\\"$\\\",\\\"circle\\\",null,{\\\"cx\\\":\\\"1.5\\\",\\\"cy\\\":\\\"1.5\\\",\\\"r\\\":\\\"0.3\\\",\\\"fill\\\":\\\"#000\\\",\\\"fillOpacity\\\":\\\"0.06\\\"}]}]]}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-grad-legacy-iga-migration-guide-checklist)\\\"}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"220\\\",\\\"filter\\\":\\\"url(#blog-grain-legacy-iga-migration-guide-checklist)\\\",\\\"style\\\":{\\\"mixBlendMode\\\":\\\"overlay\\\"}}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-dither-legacy-iga-migration-guide-checklist)\\\"}]]}],[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 256 256\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"6\\\",\\\"className\\\":\\\"absolute left-5 top-5 h-9 w-9 pointer-events-none\\\",\\\"style\\\":{\\\"color\\\":\\\"#1c1c1c\\\",\\\"opacity\\\":0.78},\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"M10 128C10 193.17 62.8304 246 128 246C193.17 246 246 193.17 246 128C246 62.8304 193.17 10 128 10C62.8304 10 10 62.8304 10 128ZM10 128L246 128.123M39.4543 50H216.546M39.4543 206H216.546\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"absolute right-3 top-3\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Legacy IGA migration\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex flex-1 flex-col gap-2.5 p-5\\\",\\\"children\\\":[[\\\"$\\\",\\\"h3\\\",null,{\\\"className\\\":\\\"text-[17px] font-normal leading-snug tracking-tight text-white\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"blog-underline\\\",\\\"children\\\":\\\"The Legacy IGA Migration Guide: Real Costs, Realistic Timelines, and a Step-by-Step Checklist\\\"}]}],[\\\"$\\\",\\\"p\\\",null,{\\\"className\\\":\\\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Replacing SailPoint IIQ, Oracle, IBM, or One Identity feels terrifying. This guide breaks down the real migration costs, honest timelines, and a step-by-step checklist to de-risk the switch.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\\\",\\\"children\\\":[\\\"$undefined\\\",\\\"$undefined\\\",[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"tabular-nums\\\",\\\"children\\\":\\\"Jul 13, 2026\\\"}]]}]]}]]}]\\n\"])</script></body></html>","snapshot_chars":230483,"live_check":"changed"}]}